Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o pomoc - vysoké vyťaženie CPU, adware

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Prosím o pomoc - vysoké vyťaženie CPU, adware

#1 Příspěvek od Lord_3D »

Dobrý deň,
priateľka mi dnes dala NTB, že sa jej rýchlo vybíja baterka. Tak som sa na to trošku pozrel a zistil som, že PC pravdepodobne obsahuje nejaký bordel na bitcoin minig a takisto aj adware v prehliadači.

Prikladám log z RSIT.
Vopred ďakujem za každú pomoc.

edit: práve som si všimol že nemá ani žiaden antivir ( :roll: ). Zajtra to napravím a kúpim ESET Smart Security.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2016-04-28 20:22:14
Microsoft Windows 8.1
System drive C: has 105 GB (30%) free of 351 GB
Total RAM: 4007 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:22:22, on 28.4.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\trend micro\Lenovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ic-0.8e2ee3e1092dc.exe -start] C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe -start
O4 - HKLM\..\Run: [2] C:\Users\Lenovo\AppData\Local\Temp\2.exe /start
O4 - HKCU\..\Run: [HP Deskjet 3540 series (NET)] "C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: brsrv - Unknown owner - C:\Users\Lenovo\AppData\Local\brsrv\brsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: DeskTop DispalyName (DeskTop_F) - DeskTopService - C:\ProgramData\desktopfind\desktop154.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Condusiv Technologies - C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem6.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Protect Service(jIxmRfR_protect) (jIxmRfR_protect) - Unknown owner - C:\ProgramData\jIxmRfR\protect\protect.exe
O23 - Service: Update Service(jIxmRfR_update) (jIxmRfR_update) - Unknown owner - C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Search Module Update (SMUpd) - Search Module Ltd. - C:\Program Files\Common Files\Soobzo\GDUpdate\smu.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12393 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
C:\Windows\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservice
C:\Windows\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k networkservice
C:\Windows\system32\WLANExt.exe 196398889152
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Users\Lenovo\AppData\Local\brsrv\brsrv.exe
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\system32\CxAudMsg64.exe
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
dashost.exe {69a56ac1-c6dc-46e5-ab857926665d6135}
"C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"C:\Program Files\Common Files\Soobzo\GDUpdate\smu.exe" /service
c:\windows\system32\svchost.exe -k imgsvc

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fc1698e3-d4d2-41de-ac11-819aa94cbdb8 -SystemEventPortName:HostProcess-91d6588c-f51e-474f-9851-4e218687b8f1 -IoCancelEventPortName:HostProcess-465c0b6d-3ab3-4b07-9704-ee6c031aa91c -NonStateChangingEventPortName:HostProcess-8e488eb1-52c8-405c-85a1-df5320443443 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7a81d575-7d76-436b-af82-92d1c1b40fdf -DeviceGroupId:WudfDefaultDevicePool
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\ProgramData\jIxmRfR\protect\protect.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"


C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe -Embedding
C:\Windows\Explorer.EXE
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
taskeng.exe {388297DD-F310-4D38-AB43-2051F5870F3C}
taskhostex.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe150_ Global\UsGthrCtrlFltPipeMssGthrPipe150 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\System32\skydrive.exe -Embedding
/QuitInfo:0000000000000944;0000000000000898;
/loadhooks /Parent:000000000000058c
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=jIxmRfR --annotation=ver=50.2.2661.78 --handshake-handle=0x190
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=gpu-process --channel="8888.0.1727892420\699412563" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,15,24,53,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.14.4264 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="8888.2.552906635\1528591447" --font-cache-shared-handle=2508 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="8888.3.1399364628\564876873" --font-cache-shared-handle=2508 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="8888.4.2031500241\354120492" --font-cache-shared-handle=2508 /prefetch:1
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Windows\RtsCM64.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="8888.6.1584266539\1878083955" --font-cache-shared-handle=5272 /prefetch:1
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Users\Lenovo\AppData\Roaming\cpuminer\cpm.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="8888.7.219447050\1888315625" --font-cache-shared-handle=3636 /prefetch:1
"C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 492D5161-F4E2-8B54-7171-CF08BDC4A3C1 -Reinvoke
"C:\Users\Lenovo\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

prefs.js - "browser.startup.homepage" - "http://www.nicesearches.com?type=hp&ts= ... 9m0z0e1w3o"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\
{a00bef25-f21a-4539-adbb-b179b29e2b92}

C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\
DD1B66D4.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30 140344]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-10 1830616]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-25 935104]
"RtsCM"=C:\Windows\RTSCM64.EXE [2013-11-30 153816]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2014-11-07 341448]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2014-03-26 7825720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-03-19 176952]
"cpuminer"=C:\Users\Lenovo\AppData\Roaming\cpuminer\cpm.exe [2016-03-31 1399808]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Deskjet 3540 series (NET)"=C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe [2014-03-06 3487240]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-03-01 50670720]
"Spotify Web Helper"=C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-04-25 1525360]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []
"ic-0.8e2ee3e1092dc.exe -start"=C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe -start []
"2"=C:\Users\Lenovo\AppData\Local\Temp\2.exe /start []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-04-28 20:22:14 ----D---- C:\rsit
2016-04-28 20:22:14 ----D---- C:\Program Files\trend micro
2016-04-25 21:01:28 ----D---- C:\Users\Lenovo\AppData\Roaming\Spotify
2016-04-25 15:27:49 ----D---- C:\Program Files (x86)\Adobe
2016-04-21 15:50:31 ----D---- C:\ProgramData\jIxmRfR
2016-04-21 15:50:02 ----A---- C:\Windows\SYSWOW64\temAB45.tmp
2016-04-21 15:49:36 ----D---- C:\Program Files (x86)\jIxmRfR
2016-04-18 15:06:53 ----D---- C:\Windows\system32\log
2016-04-18 15:06:53 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2016-04-18 15:06:53 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2016-04-18 15:06:50 ----D---- C:\Program Files (x86)\Elex-tech
2016-04-18 15:06:49 ----D---- C:\Users\Lenovo\AppData\Roaming\Elex-tech
2016-04-16 07:08:07 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-15 17:02:31 ----D---- C:\ProgramData\desktopfind
2016-04-15 14:02:33 ----D---- C:\Users\Lenovo\AppData\Roaming\WinZiper
2016-04-15 14:02:33 ----D---- C:\Users\Lenovo\AppData\Roaming\eCyber
2016-04-15 14:02:16 ----D---- C:\ProgramData\pwinpp
2016-04-15 14:02:15 ----D---- C:\Program Files (x86)\QQBrowser
2016-04-13 23:02:16 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-04-13 23:02:16 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-04-13 23:02:15 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2016-04-13 23:02:14 ----A---- C:\Windows\system32\rpcss.dll
2016-04-13 23:02:11 ----A---- C:\Windows\system32\VSSVC.exe
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAgent.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAgent.dll
2016-04-13 23:02:08 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2016-04-13 23:02:06 ----A---- C:\Windows\system32\invagent.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\generaltel.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\devinv.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-04-13 23:02:06 ----A---- C:\Windows\system32\appraiser.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aepic.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aeinv.dll
2016-04-13 23:02:05 ----A---- C:\Windows\system32\acmigration.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\twinui.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-04-13 23:01:35 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-04-13 23:01:34 ----A---- C:\Windows\explorer.exe
2016-04-13 23:01:33 ----A---- C:\Windows\system32\twinui.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\shell32.dll
2016-04-13 23:01:31 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-04-13 23:01:31 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\usercpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\themecpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\stobject.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingsHandlers.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingMonitor.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\stobject.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingMonitor.dll
2016-04-13 23:01:29 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\mtxoci.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\workfolderssvc.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-04-13 23:01:27 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\KernelBase.dll
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winresume.exe
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winload.exe
2016-04-13 23:01:25 ----A---- C:\Windows\SYSWOW64\dhcpsapi.dll
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\vpci.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\storport.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\dhcpsapi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\system32\storagewmi.dll
2016-04-13 23:01:23 ----A---- C:\Windows\system32\wbengine.exe
2016-04-13 23:01:22 ----AC---- C:\Windows\system32\drivers\disk.sys
2016-04-13 23:01:22 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeui.exe
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\BFE.DLL
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-04-13 14:50:09 ----A---- C:\Windows\system32\mshtml.dll
2016-04-13 14:50:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-04-13 14:50:07 ----A---- C:\Windows\system32\ieframe.dll
2016-04-13 14:50:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\wininet.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\jscript9.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iedkcs32.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\urlmon.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\ie4uinit.exe
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\vbscript.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\ieapfltr.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\msxml3.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samsrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\cng.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\basesrv.dll
2016-04-13 14:48:16 ----A---- C:\Windows\system32\win32k.sys
2016-04-10 10:29:12 ----A---- C:\Windows\SYSWOW64\drivers\TS888x64.sys
2016-04-09 21:22:04 ----A---- C:\Users\Lenovo\AppData\Roaming\GiftBag.db
2016-04-09 21:22:02 ----D---- C:\Program Files\Common Files\Tencent
2016-04-09 21:22:01 ----D---- C:\ProgramData\TXQMPC
2016-04-09 21:22:01 ----A---- C:\Windows\system32\drivers\TAOKernelEx64.sys
2016-04-09 21:21:55 ----A---- C:\Windows\system32\drivers\TFsFltX64.sys
2016-04-09 21:21:06 ----D---- C:\Program Files (x86)\Tencent
2016-04-09 21:20:57 ----D---- C:\Users\Lenovo\AppData\Roaming\Tencent
2016-04-09 21:20:54 ----D---- C:\ProgramData\Tencent
2016-04-09 21:10:53 ----D---- C:\ProgramData\SearchModule
2016-04-09 21:10:49 ----D---- C:\Program Files\Common Files\Soobzo
2016-04-09 21:10:35 ----A---- C:\ProgramData\smp2.exe
2016-04-09 21:10:11 ----D---- C:\Users\Lenovo\AppData\Roaming\vnlgp
2016-04-09 19:02:40 ----D---- C:\ProgramData\Thunder Network
2016-04-09 19:02:27 ----D---- C:\Users\Lenovo\AppData\Roaming\gplyra
2016-04-09 19:02:22 ----D---- C:\Users\Lenovo\AppData\Roaming\cpuminer
2016-04-09 19:01:11 ----A---- C:\Windows\chromebrowser.exe
2016-04-09 19:00:51 ----D---- C:\ProgramData\DivX
2016-04-06 15:09:54 ----A---- C:\Windows\system32\bi.exe
2016-03-31 13:55:19 ----D---- C:\Windows\Minidump
2016-03-29 15:30:54 ----D---- C:\Program Files (x86)\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iPod
2016-03-29 15:29:51 ----D---- C:\Program Files (x86)\Apple Software Update

======List of files/folders modified in the last 1 month======

2016-04-28 20:22:18 ----D---- C:\Windows\Prefetch
2016-04-28 20:22:14 ----RD---- C:\Program Files
2016-04-28 20:21:57 ----D---- C:\Windows\Temp
2016-04-28 20:21:20 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2016-04-28 20:19:47 ----D---- C:\Windows\system32\Tasks
2016-04-28 20:18:56 ----D---- C:\Windows\system32\sru
2016-04-28 18:27:42 ----D---- C:\Users\Lenovo\AppData\Roaming\tixati
2016-04-28 15:18:11 ----D---- C:\Windows\Microsoft.NET
2016-04-28 15:17:20 ----SHD---- C:\System Volume Information
2016-04-28 10:48:26 ----D---- C:\Windows\system32\config
2016-04-28 10:25:35 ----HD---- C:\Program Files\WindowsApps
2016-04-28 10:25:35 ----D---- C:\Windows\AppReadiness
2016-04-27 12:52:59 ----RD---- C:\Program Files (x86)
2016-04-26 00:12:32 ----D---- C:\Windows
2016-04-25 02:31:32 ----D---- C:\Windows\system32\DriverStore
2016-04-25 02:31:29 ----D---- C:\Windows\WinSxS
2016-04-25 02:31:13 ----D---- C:\Windows\system32\catroot2
2016-04-23 13:41:35 ----RD---- C:\Windows\System32
2016-04-23 13:41:35 ----D---- C:\Windows\Inf
2016-04-23 13:41:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-22 09:57:45 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 15:50:31 ----HD---- C:\ProgramData
2016-04-21 15:50:02 ----D---- C:\Windows\SysWOW64
2016-04-19 12:25:30 ----D---- C:\Windows\system32\NDF
2016-04-18 19:48:22 ----D---- C:\Windows\rescache
2016-04-18 15:06:53 ----D---- C:\Windows\system32\drivers
2016-04-18 14:44:12 ----RD---- C:\Windows\assembly
2016-04-16 06:33:02 ----SHD---- C:\Windows\Installer
2016-04-16 06:32:59 ----RD---- C:\Program Files (x86)\Skype
2016-04-16 06:32:59 ----D---- C:\Program Files (x86)\Common Files
2016-04-16 06:32:36 ----D---- C:\ProgramData\Skype
2016-04-16 05:17:05 ----RD---- C:\Windows\ToastData
2016-04-16 05:17:05 ----D---- C:\Windows\SYSWOW64\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\wbem
2016-04-16 05:17:05 ----D---- C:\Windows\system32\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\en-US
2016-04-16 05:17:05 ----D---- C:\Windows\system32\appraiser
2016-04-16 05:17:05 ----D---- C:\Windows\apppatch
2016-04-16 05:17:04 ----D---- C:\Windows\system32\Boot
2016-04-16 05:17:04 ----D---- C:\Program Files\Internet Explorer
2016-04-16 05:17:04 ----D---- C:\Program Files (x86)\Internet Explorer
2016-04-15 17:02:28 ----HD---- C:\Windows\system32\GroupPolicy
2016-04-15 17:02:28 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2016-04-15 10:06:14 ----D---- C:\Windows\CbsTemp
2016-04-15 10:04:23 ----D---- C:\Windows\system32\MRT
2016-04-15 09:57:39 ----A---- C:\Windows\system32\MRT.exe
2016-04-13 22:54:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-04-13 22:54:51 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-04-13 22:54:50 ----A---- C:\Windows\system32\ntdll.dll
2016-04-10 10:29:12 ----D---- C:\Windows\SYSWOW64\drivers
2016-04-09 21:22:02 ----D---- C:\Program Files\Common Files
2016-04-09 21:21:56 ----RSD---- C:\Windows\Fonts
2016-04-09 18:44:39 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2016-04-05 23:53:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-04-05 22:27:29 ----D---- C:\ProgramData\Microsoft Help
2016-03-29 15:30:53 ----D---- C:\Program Files\Common Files\Apple

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 excsd;ExpressCache Storage Filter Driver; C:\Windows\system32\DRIVERS\excsd.sys [2013-11-18 117488]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-08-02 644968]
R1 excfs;ExpressCache File System Filter Driver; C:\Windows\system32\DRIVERS\excfs.sys [2013-11-18 25840]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2015-05-14 260856]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2015-08-19 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2015-08-19 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2015-08-19 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2015-06-30 52392]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btmaux;@oem66.inf,%BTMAUX.ServiceDesc%;Intel Bluetooth Auxiliary Service; C:\Windows\system32\DRIVERS\btmaux.sys [2014-03-26 140600]
R3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2014-04-22 1424184]
R3 CnxtHdAudService;@oem7.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-18 1534656]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-09-03 74432]
R3 ibtusb;@oem67.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\Windows\system32\DRIVERS\ibtusb.sys [2014-05-10 192456]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-09 4928256]
R3 ISCT;@oem68.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\Windows\System32\drivers\ISCTD64.sys [2012-08-24 46016]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-05-26 30512]
R3 MEIx64;@oem2.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-12-19 99288]
R3 NETwNb64;@oem62.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\Netwbw02.sys [2014-04-16 3440096]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTSPER;@oem1.inf,%Rts5227PER%;Realtek PCIE Card Reader - PER; C:\Windows\system32\DRIVERS\RtsPer.sys [2014-08-15 508120]
R3 rtsuvc;@oem48.inf,%rtsuvc.DeviceDesc%;Integrated Camera; C:\Windows\system32\DRIVERS\rtsuvc.sys [2013-11-30 9100504]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-02-05 32936]
R3 SMUpdd;Search Module UpdateD; \??\C:\Program Files\Common Files\Soobzo\GDUpdate\smw.sys [2016-04-06 43264]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2014-11-21 11776]
R3 SynTP;@oem60.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2015-02-05 567464]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\QMUdisk64.sys []
S1 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\softaal64.sys []
S1 SRepairDrv;SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv []
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\TsNetHlpX64.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-05-26 42288]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2015-08-19 55056]
S3 Netaapl;@oem75.inf,%Netaapl.Service.DispName%;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2014-08-15 23040]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\Windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 USBAAPL64;@oem76.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2014-03-26 1206648]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2014-03-26 1165688]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 brsrv;brsrv; C:\Users\Lenovo\AppData\Local\brsrv\brsrv.exe [2016-03-06 104448]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2016-01-08 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2016-01-08 1773696]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2013-07-25 206552]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-11-21 38792]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-01-17 632048]
R2 ExpressCache;ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2013-11-18 828656]
R2 IBMPMSVC;@oem6.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-09-03 156912]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-09 355232]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2015-08-19 118048]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 jIxmRfR_protect;Protect Service(jIxmRfR_protect); C:\ProgramData\jIxmRfR\protect\protect.exe [2016-04-21 303016]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2015-11-26 110248]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2015-07-13 114632]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-01-17 154864]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SMUpd;Search Module Update; C:\Program Files\Common Files\Soobzo\GDUpdate\smu.exe [2016-04-06 2454016]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2016-03-11 133136]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-03-19 651576]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 DeskTop_F;DeskTop DispalyName; C:\ProgramData\desktopfind\desktop154.exe [2016-03-16 236728]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S2 jIxmRfR_update;Update Service(jIxmRfR_update); C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21 473000]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-01-29 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-11-21 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-09 288688]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-01 148136]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-01-17 284912]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2016-01-13 21536]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#3 Příspěvek od Lord_3D »

Dobrý deň,
ďakujem za skorú odpoveď. Prikladám oba logy, nakoľko neviem či je potrebný C1 alebo S1.

C1:
# AdwCleaner v5.114 - Logfile created 28/04/2016 at 21:16:13
# Updated 27/04/2016 by Xplode
# Database : 2016-04-27.1 [Server]
# Operating system : Windows 8.1 (X64)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner_5.114.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : iSafeKrnl
[-] Service Deleted : iSafeKrnlBoot
[-] Service Deleted : iSafeKrnlKit
[-] Service Deleted : iSafeKrnlMon
[-] Service Deleted : iSafeKrnlR3
[-] Service Deleted : iSafeNetFilter
[-] Service Deleted : iSafeService
[-] Service Deleted : SMUpd
[-] Service Deleted : SMUpdd
[-] Service Deleted : QMUdisk
[-] Service Deleted : softaal
[-] Service Deleted : brsrv
[-] Service Deleted : SRepairDrv
[-] Service Deleted : tsnethlpx64
[-] Service Deleted : DeskTop_F

***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\SearchModule
[-] Folder Deleted : C:\ProgramData\tencent
[-] Folder Deleted : C:\ProgramData\TXQMPC
[-] Folder Deleted : C:\ProgramData\desktopfind
[-] Folder Deleted : C:\ProgramData\pwinpp
[#] Folder Deleted : C:\ProgramData\Application Data\SearchModule
[#] Folder Deleted : C:\ProgramData\Application Data\tencent
[#] Folder Deleted : C:\ProgramData\Application Data\TXQMPC
[#] Folder Deleted : C:\ProgramData\Application Data\desktopfind
[#] Folder Deleted : C:\ProgramData\Application Data\pwinpp
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
[#] Folder Deleted : C:\Program Files (x86)\Elex-tech
[-] Folder Deleted : C:\Program Files (x86)\tencent
[-] Folder Deleted : C:\Program Files (x86)\QQBrowser
[-] Folder Deleted : C:\Program Files (x86)\Common Files\tencent
[-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\tencent
[-] Folder Deleted : C:\Users\Lenovo\AppData\Local\BrowserAir
[-] Folder Deleted : C:\Users\Lenovo\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\cpuminer
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\eCyber
[#] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\Elex-tech
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\tencent
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\WinZiper
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\vnlgp
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserAir
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder Deleted : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br
[-] Folder Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp
[-] Folder Deleted : C:\Program Files\Common Files\tencent

***** [ Files ] *****

[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\piesearch.xml
[-] File Deleted : C:\Windows\SysWOW64\drivers\TS888x64.sys
[-] File Deleted : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BrowserAir.lnk
[-] File Deleted : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\searchplugins\smod.xml
[-] File Deleted : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\dd1b66d4.xml
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvgamasearch.com_0.localstorage
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvgamasearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
[-] File Deleted : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] File Deleted : C:\Windows\SysNative\log\iSafeKrnlCall.log
[-] File Deleted : C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys
[-] File Deleted : C:\Windows\SysNative\drivers\iSafeNetFilter.sys
[-] File Deleted : C:\Windows\SysNative\drivers\TFsFltX64.sys

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : IBUpd
[-] Task Deleted : IBUpd2
[-] Task Deleted : Browser Updater Task(Core)
[-] Task Deleted : WinTsks
[-] Task Deleted : SMW_UpdateTask_Time_343030303236303937312d4a5b5b345a417845455a376c

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\BrowserAir.exe
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Key Deleted : HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Key Deleted : HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@qq.com/npandroidassistant
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.001
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.7z
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.arj
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.bz2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.bzip2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.cab
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.cpio
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.deb
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.dmg
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.fat
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.gz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.gzip
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.hfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.iso
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lha
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lzh
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lzma
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.ntfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.rar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.rpm
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.squashfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.swm
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.taz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tbz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tbz2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tgz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tpz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.txz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.vhd
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.wim
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.xar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.xz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.z
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.zip
[-] Key Deleted : HKLM\SOFTWARE\Classes\metnsd
[-] Key Deleted : HKLM\SOFTWARE\Classes\qmgcfiles
[-] Key Deleted : HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid
[-] Key Deleted : HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{754DF2CE-51E8-4895-B53C-6381418B84AE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E1533F0-E0B5-465A-9F16-98FF0C76D493}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{754DF2CE-51E8-4895-B53C-6381418B84AE}]
[-] Key Deleted : HKCU\Software\BrowserAir
[-] Key Deleted : HKLM\SOFTWARE\Elex-tech
[-] Key Deleted : HKLM\SOFTWARE\hdcode
[-] Key Deleted : HKLM\SOFTWARE\SearchModule
[-] Key Deleted : HKLM\SOFTWARE\yessearchesSoftware
[-] Key Deleted : HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Key Deleted : HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
[-] Key Deleted : HKLM\SOFTWARE\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BrowserAir
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iSafe
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper
[-] Key Deleted : [x64] HKLM\SOFTWARE\BrowserAir
[-] Key Deleted : [x64] HKLM\SOFTWARE\SearchModule
[-] Key Deleted : [x64] HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cpuminer
[-] Key Deleted : HKU\.DEFAULT\Software\Elex-tech
[-] Key Deleted : HKU\.DEFAULT\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{6B237A13-BD81-4B8C-9641-D1C46988E72A}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{F60A89BA-2410-4BDB-BCD3-7916ED1FC98B}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{E931468F-6D7B-44F9-AD37-94D8882A82D2}]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3E8307AB-66B3-49D8-9ECA-ADE1B3E39A64}
[-] Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [cpuminer]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [2]

***** [ Web browsers ] *****

[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.alias", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://www.nicesearches.com/favicon.ico?t=1");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.name", "nice ");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.ref", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.ts", "1461574053");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.type", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.uid", "ct500bx100ssd1_1507f0034e65");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.search.searchengine.url", "hxxp://www.nicesearches.com/search.php?type=ds ... z0e1w3o&q=[...]
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.startup.homepage", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Deleted : user_pref("browser.newtab.url", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.defaultenginename", "yessearches");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.alias", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEqA38mAHAkBU. ... =ffsengext");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://www.nicesearches.com/favicon.ico?t=1");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.name", "nice ");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.ref", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.sp", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160409");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.ts", "1461574053");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.type", "");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.uid", "ct500bx100ssd1_1507f0034e65");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.searchengine.url", "hxxp://www.nicesearches.com/search.php?type=ds ... z0e1w3o&q=[...]
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.search.selectedEngine", "yessearches");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.startup.homepage", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[-] [C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Deleted : user_pref("browser.newtab.url", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [16345 bytes] - [28/04/2016 21:16:13]
C:\AdwCleaner\AdwCleaner[S1].txt - [15869 bytes] - [28/04/2016 21:14:33]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [16493 bytes] ##########






S1:
# AdwCleaner v5.114 - Logfile created 28/04/2016 at 21:14:33
# Updated 27/04/2016 by Xplode
# Database : 2016-04-27.1 [Server]
# Operating system : Windows 8.1 (X64)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner_5.114.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : iSafeKrnl
Service Found : iSafeKrnlBoot
Service Found : iSafeKrnlKit
Service Found : iSafeKrnlMon
Service Found : iSafeKrnlR3
Service Found : iSafeNetFilter
Service Found : iSafeService
Service Found : SMUpd
Service Found : SMUpdd
Service Found : QMUdisk
Service Found : softaal
Service Found : brsrv
Service Found : SRepairDrv
Service Found : tsnethlpx64
Service Found : DeskTop_F

***** [ Folders ] *****

Folder Found : C:\ProgramData\SearchModule
Folder Found : C:\ProgramData\tencent
Folder Found : C:\ProgramData\TXQMPC
Folder Found : C:\ProgramData\desktopfind
Folder Found : C:\ProgramData\pwinpp
Folder Found : C:\ProgramData\Application Data\SearchModule
Folder Found : C:\ProgramData\Application Data\tencent
Folder Found : C:\ProgramData\Application Data\TXQMPC
Folder Found : C:\ProgramData\Application Data\desktopfind
Folder Found : C:\ProgramData\Application Data\pwinpp
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
Folder Found : C:\Program Files (x86)\Elex-tech
Folder Found : C:\Program Files (x86)\tencent
Folder Found : C:\Program Files (x86)\QQBrowser
Folder Found : C:\Program Files (x86)\Common Files\tencent
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\tencent
Folder Found : C:\Users\Lenovo\AppData\Local\BrowserAir
Folder Found : C:\Users\Lenovo\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
Folder Found : C:\Users\Lenovo\AppData\Roaming\cpuminer
Folder Found : C:\Users\Lenovo\AppData\Roaming\eCyber
Folder Found : C:\Users\Lenovo\AppData\Roaming\Elex-tech
Folder Found : C:\Users\Lenovo\AppData\Roaming\tencent
Folder Found : C:\Users\Lenovo\AppData\Roaming\WinZiper
Folder Found : C:\Users\Lenovo\AppData\Roaming\vnlgp
Folder Found : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserAir
Folder Found : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
Folder Found : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br
Folder Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp
Folder Found : C:\Program Files\Common Files\tencent

***** [ Files ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\piesearch.xml
File Found : C:\Windows\SysWOW64\drivers\TS888x64.sys
File Found : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BrowserAir.lnk
File Found : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\searchplugins\smod.xml
File Found : C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\dd1b66d4.xml
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvgamasearch.com_0.localstorage
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvgamasearch.com_0.localstorage-journal
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage-journal
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage-journal
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
File Found : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
File Found : C:\Windows\SysNative\log\iSafeKrnlCall.log
File Found : C:\Windows\SysNative\drivers\iSafeKrnlBoot.sys
File Found : C:\Windows\SysNative\drivers\iSafeNetFilter.sys
File Found : C:\Windows\SysNative\drivers\TFsFltX64.sys

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : IBUpd
Task Found : IBUpd2
Task Found : Browser Updater Task(Core)
Task Found : WinTsks
Task Found : SMW_UpdateTask_Time_343030303236303937312d4a5b5b345a417845455a376c

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Key Found : HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\BrowserAir.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
Key Found : HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
Key Found : HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@qq.com/npandroidassistant
Key Found : HKLM\SOFTWARE\Classes\WinZippers.001
Key Found : HKLM\SOFTWARE\Classes\WinZippers.7z
Key Found : HKLM\SOFTWARE\Classes\WinZippers.arj
Key Found : HKLM\SOFTWARE\Classes\WinZippers.bz2
Key Found : HKLM\SOFTWARE\Classes\WinZippers.bzip2
Key Found : HKLM\SOFTWARE\Classes\WinZippers.cab
Key Found : HKLM\SOFTWARE\Classes\WinZippers.cpio
Key Found : HKLM\SOFTWARE\Classes\WinZippers.deb
Key Found : HKLM\SOFTWARE\Classes\WinZippers.dmg
Key Found : HKLM\SOFTWARE\Classes\WinZippers.fat
Key Found : HKLM\SOFTWARE\Classes\WinZippers.gz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.gzip
Key Found : HKLM\SOFTWARE\Classes\WinZippers.hfs
Key Found : HKLM\SOFTWARE\Classes\WinZippers.iso
Key Found : HKLM\SOFTWARE\Classes\WinZippers.lha
Key Found : HKLM\SOFTWARE\Classes\WinZippers.lzh
Key Found : HKLM\SOFTWARE\Classes\WinZippers.lzma
Key Found : HKLM\SOFTWARE\Classes\WinZippers.ntfs
Key Found : HKLM\SOFTWARE\Classes\WinZippers.rar
Key Found : HKLM\SOFTWARE\Classes\WinZippers.rpm
Key Found : HKLM\SOFTWARE\Classes\WinZippers.squashfs
Key Found : HKLM\SOFTWARE\Classes\WinZippers.swm
Key Found : HKLM\SOFTWARE\Classes\WinZippers.tar
Key Found : HKLM\SOFTWARE\Classes\WinZippers.taz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.tbz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.tbz2
Key Found : HKLM\SOFTWARE\Classes\WinZippers.tgz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.tpz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.txz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.vhd
Key Found : HKLM\SOFTWARE\Classes\WinZippers.wim
Key Found : HKLM\SOFTWARE\Classes\WinZippers.xar
Key Found : HKLM\SOFTWARE\Classes\WinZippers.xz
Key Found : HKLM\SOFTWARE\Classes\WinZippers.z
Key Found : HKLM\SOFTWARE\Classes\WinZippers.zip
Key Found : HKLM\SOFTWARE\Classes\metnsd
Key Found : HKLM\SOFTWARE\Classes\qmgcfiles
Key Found : HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid
Key Found : HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Key Found : HKCU\Software\Classes\CLSID\{17EF1FFB-0545-4C9A-BE64-78FF53338475}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{50F4150A-48B2-417A-BE4C-C83F580FB904}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{754DF2CE-51E8-4895-B53C-6381418B84AE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6E1533F0-E0B5-465A-9F16-98FF0C76D493}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50F4150A-48B2-417A-BE4C-C83F580FB904}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{754DF2CE-51E8-4895-B53C-6381418B84AE}]
Key Found : HKCU\Software\BrowserAir
Key Found : HKLM\SOFTWARE\Elex-tech
Key Found : HKLM\SOFTWARE\hdcode
Key Found : HKLM\SOFTWARE\SearchModule
Key Found : HKLM\SOFTWARE\yessearchesSoftware
Key Found : HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
Key Found : HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
Key Found : HKLM\SOFTWARE\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BrowserAir
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iSafe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper
Key Found : [x64] HKLM\SOFTWARE\BrowserAir
Key Found : [x64] HKLM\SOFTWARE\SearchModule
Key Found : [x64] HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cpuminer
Key Found : HKU\.DEFAULT\Software\Elex-tech
Key Found : HKU\.DEFAULT\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
Key Found : HKU\S-1-5-21-2569014371-4025574855-1753814657-1001\Software\BrowserAir
Key Found : HKU\S-1-5-21-2569014371-4025574855-1753814657-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\BrowserAir
Key Found : HKU\S-1-5-18\Software\Elex-tech
Key Found : HKU\S-1-5-18\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{6B237A13-BD81-4B8C-9641-D1C46988E72A}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{F60A89BA-2410-4BDB-BCD3-7916ED1FC98B}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{E931468F-6D7B-44F9-AD37-94D8882A82D2}]
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3E8307AB-66B3-49D8-9ECA-ADE1B3E39A64}
Key Found : HKU\S-1-5-21-2569014371-4025574855-1753814657-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3E8307AB-66B3-49D8-9ECA-ADE1B3E39A64}
Value Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [cpuminer]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [2]

***** [ Web browsers ] *****

[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.alias", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.iconURL", "hxxp://www.nicesearches.com/favicon.ico?t=1");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.name", "nice ");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.ref", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.ts", "1461574053");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.type", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.uid", "ct500bx100ssd1_1507f0034e65");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.search.searchengine.url", "hxxp://www.nicesearches.com/search.php?type=ds ... z0e1w3o&q=[...]
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.startup.homepage", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js] Found : user_pref("browser.newtab.url", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.defaultenginename", "yessearches");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.alias", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.hp", "hxxp://www.yessearches.com/?ts=AHEqA38mAHAkBU. ... =ffsengext");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.iconURL", "hxxp://www.nicesearches.com/favicon.ico?t=1");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.name", "nice ");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.ref", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.sp", "hxxp://www.yessearches.com/chrome.php?mode=ffs ... v=20160409");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.ts", "1461574053");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.type", "");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.uid", "ct500bx100ssd1_1507f0034e65");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.searchengine.url", "hxxp://www.nicesearches.com/search.php?type=ds ... z0e1w3o&q=[...]
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.search.selectedEngine", "yessearches");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.startup.homepage", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");
[C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] Found : user_pref("browser.newtab.url", "hxxp://www.nicesearches.com?type=hp&ts=1461574 ... 9m0z0e1w3o");

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [15695 bytes] - [28/04/2016 21:14:33]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [15769 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#5 Příspěvek od Lord_3D »

Nový log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2016-04-28 21:30:19
Microsoft Windows 8.1
System drive C: has 101 GB (29%) free of 351 GB
Total RAM: 4007 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:30:22, on 28.4.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\trend micro\Lenovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ic-0.8e2ee3e1092dc.exe -start] C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe -start
O4 - HKCU\..\Run: [HP Deskjet 3540 series (NET)] "C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Condusiv Technologies - C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem6.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Protect Service(jIxmRfR_protect) (jIxmRfR_protect) - Unknown owner - C:\ProgramData\jIxmRfR\protect\protect.exe
O23 - Service: Update Service(jIxmRfR_update) (jIxmRfR_update) - Unknown owner - C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 11880 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
C:\Windows\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k localservice
C:\Windows\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k networkservice
C:\Windows\system32\WLANExt.exe 938465620544
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\system32\CxAudMsg64.exe
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
dashost.exe {0b034ca4-5234-4ac8-858bd6fdee91d97a}
"C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
c:\windows\system32\svchost.exe -k imgsvc

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c4d7d2fc-e500-4afc-a991-544de5ff8d73 -SystemEventPortName:HostProcess-c459a25c-de68-447c-b110-84fad1663133 -IoCancelEventPortName:HostProcess-137e2738-6bff-4f66-9531-c854cdfbee08 -NonStateChangingEventPortName:HostProcess-06c509f1-8f15-43a1-ac07-1968f7eeaa4c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6e8c685f-b8bc-4206-a649-b5a008bbc03a -DeviceGroupId:WudfDefaultDevicePool

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\iPod\bin\iPodService.exe"

"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 29E6DEB7-6BB0-1F7B-2508-0EE3C5779EBD -Reinvoke
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\ProgramData\jIxmRfR\protect\protect.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
c:\windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\wbem\wmiprvse.exe
taskeng.exe {A3206AF2-6D7F-4FB8-80A3-F4A5204BA141}

C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 568 572 580 65536 576
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
taskhostex.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
/QuitInfo:0000000000000AF4;00000000000008B0;
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
/loadhooks /Parent:0000000000001b08
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=jIxmRfR --annotation=ver=50.2.2661.78 --handshake-handle=0x18c
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=gpu-process --channel="4764.0.565944504\1578512951" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,15,24,53,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.14.4264 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4764.2.2041341043\1027666706" --font-cache-shared-handle=2556 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4764.3.1166689374\624776834" --font-cache-shared-handle=2640 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4764.4.1325298553\911055301" --font-cache-shared-handle=2640 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4764.6.17193114\1797314443" --font-cache-shared-handle=5372 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4764.7.1865301780\1095227172" --font-cache-shared-handle=5764 /prefetch:1
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Windows\RtsCM64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Windows\system32\GWX\GWX.exe"

wmiadap.exe /F /T /R
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=ppapi --channel="4764.8.1098353542\2040272564" --ppapi-flash-args --lang=sk --device-scale-factor=1 --font-cache-shared-handle=4836 --ignored=" --type=renderer " /prefetch:3
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Lenovo\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\jIxmRfRBrowserUpdateCore.job - C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe -c
C:\Windows\tasks\jIxmRfRCheckTask.job - C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe -t

=========Mozilla firefox=========

ProfilePath - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\
{a00bef25-f21a-4539-adbb-b179b29e2b92}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-10 1830616]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-25 935104]
"RtsCM"=C:\Windows\RTSCM64.EXE [2013-11-30 153816]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2014-11-07 341448]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2014-03-26 7825720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-03-19 176952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Deskjet 3540 series (NET)"=C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe [2014-03-06 3487240]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-03-01 50670720]
"Spotify Web Helper"=C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-04-25 1525360]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []
"ic-0.8e2ee3e1092dc.exe -start"=C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe -start []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-04-28 21:18:45 ----D---- C:\Users\Lenovo\AppData\Roaming\Elex-tech
2016-04-28 21:18:31 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2016-04-28 21:18:25 ----ASH---- C:\pagefile.sys
2016-04-28 21:14:23 ----D---- C:\AdwCleaner
2016-04-28 20:22:14 ----D---- C:\rsit
2016-04-28 20:22:14 ----D---- C:\Program Files\trend micro
2016-04-25 21:01:28 ----D---- C:\Users\Lenovo\AppData\Roaming\Spotify
2016-04-25 15:27:49 ----D---- C:\Program Files (x86)\Adobe
2016-04-21 15:50:31 ----D---- C:\ProgramData\jIxmRfR
2016-04-21 15:50:02 ----A---- C:\Windows\SYSWOW64\temAB45.tmp
2016-04-21 15:49:36 ----D---- C:\Program Files (x86)\jIxmRfR
2016-04-18 15:06:53 ----D---- C:\Windows\system32\log
2016-04-18 15:06:50 ----D---- C:\Program Files (x86)\Elex-tech
2016-04-16 07:08:07 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-13 23:02:16 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-04-13 23:02:16 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-04-13 23:02:15 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2016-04-13 23:02:14 ----A---- C:\Windows\system32\rpcss.dll
2016-04-13 23:02:11 ----A---- C:\Windows\system32\VSSVC.exe
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAgent.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAgent.dll
2016-04-13 23:02:08 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2016-04-13 23:02:06 ----A---- C:\Windows\system32\invagent.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\generaltel.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\devinv.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-04-13 23:02:06 ----A---- C:\Windows\system32\appraiser.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aepic.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aeinv.dll
2016-04-13 23:02:05 ----A---- C:\Windows\system32\acmigration.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\twinui.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-04-13 23:01:35 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-04-13 23:01:34 ----A---- C:\Windows\explorer.exe
2016-04-13 23:01:33 ----A---- C:\Windows\system32\twinui.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\shell32.dll
2016-04-13 23:01:31 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-04-13 23:01:31 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\usercpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\themecpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\stobject.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingsHandlers.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingMonitor.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\stobject.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingMonitor.dll
2016-04-13 23:01:29 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\mtxoci.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\workfolderssvc.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-04-13 23:01:27 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\KernelBase.dll
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winresume.exe
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winload.exe
2016-04-13 23:01:25 ----A---- C:\Windows\SYSWOW64\dhcpsapi.dll
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\vpci.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\storport.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\dhcpsapi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\system32\storagewmi.dll
2016-04-13 23:01:23 ----A---- C:\Windows\system32\wbengine.exe
2016-04-13 23:01:22 ----AC---- C:\Windows\system32\drivers\disk.sys
2016-04-13 23:01:22 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeui.exe
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\BFE.DLL
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-04-13 14:50:09 ----A---- C:\Windows\system32\mshtml.dll
2016-04-13 14:50:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-04-13 14:50:07 ----A---- C:\Windows\system32\ieframe.dll
2016-04-13 14:50:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\wininet.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\jscript9.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iedkcs32.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\urlmon.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\ie4uinit.exe
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\vbscript.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\ieapfltr.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\msxml3.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samsrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\cng.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\basesrv.dll
2016-04-13 14:48:16 ----A---- C:\Windows\system32\win32k.sys
2016-04-09 21:22:04 ----A---- C:\Users\Lenovo\AppData\Roaming\GiftBag.db
2016-04-09 21:22:01 ----A---- C:\Windows\system32\drivers\TAOKernelEx64.sys
2016-04-09 21:10:49 ----D---- C:\Program Files\Common Files\Soobzo
2016-04-09 21:10:35 ----A---- C:\ProgramData\smp2.exe
2016-04-09 19:02:40 ----D---- C:\ProgramData\Thunder Network
2016-04-09 19:02:27 ----D---- C:\Users\Lenovo\AppData\Roaming\gplyra
2016-04-09 19:01:11 ----A---- C:\Windows\chromebrowser.exe
2016-04-09 19:00:51 ----D---- C:\ProgramData\DivX
2016-04-06 15:09:54 ----A---- C:\Windows\system32\bi.exe
2016-03-31 13:55:19 ----D---- C:\Windows\Minidump
2016-03-29 15:30:54 ----D---- C:\Program Files (x86)\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iPod
2016-03-29 15:29:51 ----D---- C:\Program Files (x86)\Apple Software Update

======List of files/folders modified in the last 1 month======

2016-04-28 21:30:15 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2016-04-28 21:29:53 ----D---- C:\Windows\Prefetch
2016-04-28 21:23:59 ----D---- C:\Windows\Temp
2016-04-28 21:23:26 ----D---- C:\Windows\system32\sru
2016-04-28 21:20:34 ----D---- C:\Windows\Tasks
2016-04-28 21:18:31 ----D---- C:\Windows\system32\drivers
2016-04-28 21:18:29 ----D---- C:\Windows
2016-04-28 21:17:20 ----D---- C:\Windows\system32\Tasks
2016-04-28 21:17:19 ----D---- C:\Windows\SYSWOW64\drivers
2016-04-28 21:17:19 ----D---- C:\Program Files\Common Files
2016-04-28 21:16:30 ----RD---- C:\Program Files (x86)
2016-04-28 21:16:16 ----HD---- C:\ProgramData
2016-04-28 20:22:14 ----RD---- C:\Program Files
2016-04-28 18:27:42 ----D---- C:\Users\Lenovo\AppData\Roaming\tixati
2016-04-28 15:18:11 ----D---- C:\Windows\Microsoft.NET
2016-04-28 15:17:20 ----SHD---- C:\System Volume Information
2016-04-28 10:48:26 ----D---- C:\Windows\system32\config
2016-04-28 10:25:35 ----HD---- C:\Program Files\WindowsApps
2016-04-28 10:25:35 ----D---- C:\Windows\AppReadiness
2016-04-25 02:31:32 ----D---- C:\Windows\system32\DriverStore
2016-04-25 02:31:29 ----D---- C:\Windows\WinSxS
2016-04-25 02:31:13 ----D---- C:\Windows\system32\catroot2
2016-04-23 13:41:35 ----RD---- C:\Windows\System32
2016-04-23 13:41:35 ----D---- C:\Windows\Inf
2016-04-23 13:41:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-22 09:57:45 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 15:50:02 ----D---- C:\Windows\SysWOW64
2016-04-19 12:25:30 ----D---- C:\Windows\system32\NDF
2016-04-18 19:48:22 ----D---- C:\Windows\rescache
2016-04-18 14:44:12 ----RD---- C:\Windows\assembly
2016-04-16 06:33:02 ----SHD---- C:\Windows\Installer
2016-04-16 06:32:59 ----RD---- C:\Program Files (x86)\Skype
2016-04-16 06:32:59 ----D---- C:\Program Files (x86)\Common Files
2016-04-16 06:32:36 ----D---- C:\ProgramData\Skype
2016-04-16 05:17:05 ----RD---- C:\Windows\ToastData
2016-04-16 05:17:05 ----D---- C:\Windows\SYSWOW64\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\wbem
2016-04-16 05:17:05 ----D---- C:\Windows\system32\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\en-US
2016-04-16 05:17:05 ----D---- C:\Windows\system32\appraiser
2016-04-16 05:17:05 ----D---- C:\Windows\apppatch
2016-04-16 05:17:04 ----D---- C:\Windows\system32\Boot
2016-04-16 05:17:04 ----D---- C:\Program Files\Internet Explorer
2016-04-16 05:17:04 ----D---- C:\Program Files (x86)\Internet Explorer
2016-04-15 17:02:28 ----HD---- C:\Windows\system32\GroupPolicy
2016-04-15 17:02:28 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2016-04-15 10:06:14 ----D---- C:\Windows\CbsTemp
2016-04-15 10:04:23 ----D---- C:\Windows\system32\MRT
2016-04-15 09:57:39 ----A---- C:\Windows\system32\MRT.exe
2016-04-13 22:54:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-04-13 22:54:51 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-04-13 22:54:50 ----A---- C:\Windows\system32\ntdll.dll
2016-04-09 21:21:56 ----RSD---- C:\Windows\Fonts
2016-04-09 18:44:39 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2016-04-05 23:53:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-04-05 22:27:29 ----D---- C:\ProgramData\Microsoft Help
2016-03-29 15:30:53 ----D---- C:\Program Files\Common Files\Apple

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 excsd;ExpressCache Storage Filter Driver; C:\Windows\system32\DRIVERS\excsd.sys [2013-11-18 117488]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-08-02 644968]
R1 excfs;ExpressCache File System Filter Driver; C:\Windows\system32\DRIVERS\excfs.sys [2013-11-18 25840]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2015-05-14 260856]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2015-08-19 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2015-08-19 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2015-08-19 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2015-06-30 52392]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btmaux;@oem66.inf,%BTMAUX.ServiceDesc%;Intel Bluetooth Auxiliary Service; C:\Windows\system32\DRIVERS\btmaux.sys [2014-03-26 140600]
R3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2014-04-22 1424184]
R3 CnxtHdAudService;@oem7.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-18 1534656]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-09-03 74432]
R3 ibtusb;@oem67.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\Windows\system32\DRIVERS\ibtusb.sys [2014-05-10 192456]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-09 4928256]
R3 ISCT;@oem68.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\Windows\System32\drivers\ISCTD64.sys [2012-08-24 46016]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-05-26 30512]
R3 MEIx64;@oem2.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-12-19 99288]
R3 NETwNb64;@oem62.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\Netwbw02.sys [2014-04-16 3440096]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTSPER;@oem1.inf,%Rts5227PER%;Realtek PCIE Card Reader - PER; C:\Windows\system32\DRIVERS\RtsPer.sys [2014-08-15 508120]
R3 rtsuvc;@oem48.inf,%rtsuvc.DeviceDesc%;Integrated Camera; C:\Windows\system32\DRIVERS\rtsuvc.sys [2013-11-30 9100504]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-02-05 32936]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2014-11-21 11776]
R3 SynTP;@oem60.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2015-02-05 567464]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-05-26 42288]
S3 Netaapl;@oem75.inf,%Netaapl.Service.DispName%;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2014-08-15 23040]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\Windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 USBAAPL64;@oem76.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2014-03-26 1206648]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2014-03-26 1165688]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2016-01-08 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2016-01-08 1773696]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2013-07-25 206552]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-11-21 38792]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-01-17 632048]
R2 ExpressCache;ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2013-11-18 828656]
R2 IBMPMSVC;@oem6.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-09-03 156912]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-09 355232]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 iSafeService;iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2015-08-19 118048]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 jIxmRfR_protect;Protect Service(jIxmRfR_protect); C:\ProgramData\jIxmRfR\protect\protect.exe [2016-04-21 303016]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2015-11-26 110248]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2015-07-13 114632]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-01-17 154864]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-01-29 327296]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2016-03-11 133136]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-03-19 651576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S2 jIxmRfR_update;Update Service(jIxmRfR_update); C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21 473000]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-11-21 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-09 288688]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-01 148136]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-01-17 284912]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2016-01-13 21536]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Skype\Toolbars
C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\jIxmRfRBrowserUpdateCore.job
C:\Windows\tasks\jIxmRfRCheckTask.job
C:\Windows\SYSWOW64\temAB45.tmp
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ic-0.8e2ee3e1092dc.exe -start"=-

:services
Bonjour Service
c2cautoupdatesvc
c2cpnrsvc

:commands
[Purity]
[Emptytemp]
[Emptyflash]


a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#7 Příspěvek od Lord_3D »

Takže, log z OTM:

All processes killed
========== FILES ==========
C:\Program Files (x86)\Skype\Toolbars\PNRSvc folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64 folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\FirefoxAddOn folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate folder moved successfully.
C:\Program Files (x86)\Skype\Toolbars folder moved successfully.
File/Folder C:\Users\Lenovo\AppData\Local\Temp\537735187\ic-0.8e2ee3e1092dc.exe not found.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File/Folder C:\Windows\tasks\jIxmRfRBrowserUpdateCore.job not found.
File/Folder C:\Windows\tasks\jIxmRfRCheckTask.job not found.
C:\Windows\SYSWOW64\temAB45.tmp moved successfully.
File/Folder C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat not found.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\ic-0.8e2ee3e1092dc.exe -start deleted successfully.
========== SERVICES/DRIVERS ==========
Service Bonjour Service stopped successfully!
Service Bonjour Service deleted successfully!
Service c2cautoupdatesvc stopped successfully!
Service c2cautoupdatesvc deleted successfully!
Service c2cpnrsvc stopped successfully!
Service c2cpnrsvc deleted successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Lenovo
->Temp folder emptied: 60537015 bytes
->Temporary Internet Files folder emptied: 11094311 bytes
->FireFox cache emptied: 18570002 bytes
->Google Chrome cache emptied: 265365501 bytes
->Flash cache emptied: 1161 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 30114760 bytes
RecycleBin emptied: 25980108590 bytes

Total Files Cleaned = 25 144,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Lenovo
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 04282016_223329

Files moved on Reboot...
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.

Registry entries deleted on Reboot...









A tu je nový log z RSIT:


Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenovo at 2016-04-28 22:36:29
Microsoft Windows 8.1
System drive C: has 126 GB (36%) free of 351 GB
Total RAM: 4007 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:36:31, on 28.4.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Program Files\trend micro\Lenovo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [HP Deskjet 3540 series (NET)] "C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Condusiv Technologies - C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem6.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: Protect Service(jIxmRfR_protect) (jIxmRfR_protect) - Unknown owner - C:\ProgramData\jIxmRfR\protect\protect.exe
O23 - Service: Update Service(jIxmRfR_update) (jIxmRfR_update) - Unknown owner - C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 11498 bytes

======Listing Processes======





wininit.exe


C:\Windows\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
winlogon.exe
C:\Windows\system32\ibmpmsvc.exe
"dwm.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservice
C:\Windows\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k networkservice
C:\Windows\system32\WLANExt.exe 799770107280
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\Windows\system32\CxAudMsg64.exe
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
dashost.exe {06bb54ec-45ea-466f-a32299c27817584d}
"C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
c:\windows\system32\svchost.exe -k imgsvc

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f92e22b5-d7db-4de2-8d7a-6698f7a94d16 -SystemEventPortName:HostProcess-fd02bcb3-48ce-4008-bb1f-3ac7e4943b9a -IoCancelEventPortName:HostProcess-f34b68f1-e34f-4304-abf0-715373079fb5 -NonStateChangingEventPortName:HostProcess-5a88dad8-fcba-445c-bf3d-16ff9a641d3c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:505dc3bf-62f5-45eb-a18b-c9cdc66ef8d2 -DeviceGroupId:WudfDefaultDevicePool
C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
taskeng.exe {51E6AD35-C2D1-468F-BB28-D7B9B1033F4B}
taskhostex.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPOSD.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
/QuitInfo:0000000000000B04;0000000000000B08;
/loadhooks /Parent:0000000000000fd4
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=jIxmRfR --annotation=ver=50.2.2661.78 --handshake-handle=0x188
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=gpu-process --channel="5772.0.706870425\744216678" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,15,24,53,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.14.4264 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="5772.2.1465194394\2054023355" --font-cache-shared-handle=2340 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="5772.3.1030102622\620066594" --font-cache-shared-handle=2660 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="5772.4.1206087090\2044738698" --font-cache-shared-handle=2660 /prefetch:1
"C:\Windows\RtsCM64.exe"
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 26CCF778-8963-21EA-6793-996E33843958 -Reinvoke
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51K232MN05X5:NW" -scfn "HP Deskjet 3540 series (NET)" -AutoStart 1
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding
"C:\Program Files\iPod\bin\iPodService.exe"

"C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=renderer --lang=sk --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="5772.7.2100270436\421971092" --font-cache-shared-handle=5580 /prefetch:1
"C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" --type=ppapi --channel="5772.8.1107653522\1299369737" --ppapi-flash-args --lang=sk --device-scale-factor=1 --font-cache-shared-handle=3648 --ignored=" --type=renderer " /prefetch:3
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Lenovo\Desktop\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\
{a00bef25-f21a-4539-adbb-b179b29e2b92}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-10 1830616]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-25 935104]
"RtsCM"=C:\Windows\RTSCM64.EXE [2013-11-30 153816]
"LenovoOptMouseUpdate"=C:\Program Files\Lenovo\HOTKEY\extapsup.exe [2014-11-07 341448]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2014-03-26 7825720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-03-19 176952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Deskjet 3540 series (NET)"=C:\Program Files\HP\HP Deskjet 3540 series\Bin\ScanToPCActivationApp.exe [2014-03-06 3487240]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-03-01 50670720]
"Spotify Web Helper"=C:\Users\Lenovo\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-04-25 1525360]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
""= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 6723984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-04-28 22:33:29 ----D---- C:\_OTM
2016-04-28 21:18:45 ----D---- C:\Users\Lenovo\AppData\Roaming\Elex-tech
2016-04-28 21:18:31 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2016-04-28 21:18:25 ----ASH---- C:\pagefile.sys
2016-04-28 21:14:23 ----D---- C:\AdwCleaner
2016-04-28 20:22:14 ----D---- C:\rsit
2016-04-28 20:22:14 ----D---- C:\Program Files\trend micro
2016-04-25 21:01:28 ----D---- C:\Users\Lenovo\AppData\Roaming\Spotify
2016-04-25 15:27:49 ----D---- C:\Program Files (x86)\Adobe
2016-04-21 15:50:31 ----D---- C:\ProgramData\jIxmRfR
2016-04-21 15:49:36 ----D---- C:\Program Files (x86)\jIxmRfR
2016-04-18 15:06:53 ----D---- C:\Windows\system32\log
2016-04-18 15:06:50 ----D---- C:\Program Files (x86)\Elex-tech
2016-04-16 07:08:07 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-04-13 23:02:16 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-04-13 23:02:16 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-04-13 23:02:15 ----A---- C:\Windows\system32\drivers\rasl2tp.sys
2016-04-13 23:02:14 ----A---- C:\Windows\system32\rpcss.dll
2016-04-13 23:02:11 ----A---- C:\Windows\system32\VSSVC.exe
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\SYSWOW64\WsmAgent.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmSvc.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAuto.dll
2016-04-13 23:02:09 ----A---- C:\Windows\system32\WsmAgent.dll
2016-04-13 23:02:08 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2016-04-13 23:02:06 ----A---- C:\Windows\system32\invagent.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\generaltel.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\devinv.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-04-13 23:02:06 ----A---- C:\Windows\system32\appraiser.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aepic.dll
2016-04-13 23:02:06 ----A---- C:\Windows\system32\aeinv.dll
2016-04-13 23:02:05 ----A---- C:\Windows\system32\acmigration.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\twinui.dll
2016-04-13 23:01:36 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-04-13 23:01:35 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-04-13 23:01:34 ----A---- C:\Windows\explorer.exe
2016-04-13 23:01:33 ----A---- C:\Windows\system32\twinui.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2016-04-13 23:01:32 ----A---- C:\Windows\system32\shell32.dll
2016-04-13 23:01:31 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-04-13 23:01:31 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\usercpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\twinui.appcore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\themecpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\stobject.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSyncCore.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingSync.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingsHandlers.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\SettingMonitor.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\hgcpl.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-04-13 23:01:30 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\usercpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\themecpl.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\stobject.dll
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-04-13 23:01:29 ----A---- C:\Windows\SYSWOW64\SettingMonitor.dll
2016-04-13 23:01:29 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\mtxoci.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\msorcl32.dll
2016-04-13 23:01:28 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\workfolderssvc.dll
2016-04-13 23:01:28 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-04-13 23:01:27 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-13 23:01:27 ----A---- C:\Windows\system32\KernelBase.dll
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winresume.exe
2016-04-13 23:01:26 ----A---- C:\Windows\system32\winload.exe
2016-04-13 23:01:25 ----A---- C:\Windows\SYSWOW64\dhcpsapi.dll
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\vpci.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\drivers\storport.sys
2016-04-13 23:01:25 ----A---- C:\Windows\system32\dhcpsapi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2016-04-13 23:01:24 ----A---- C:\Windows\system32\storagewmi.dll
2016-04-13 23:01:23 ----A---- C:\Windows\system32\wbengine.exe
2016-04-13 23:01:22 ----AC---- C:\Windows\system32\drivers\disk.sys
2016-04-13 23:01:22 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeui.exe
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\nshwfp.dll
2016-04-13 23:01:18 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2016-04-13 23:01:18 ----A---- C:\Windows\system32\BFE.DLL
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2016-04-13 23:01:17 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-04-13 14:50:09 ----A---- C:\Windows\system32\mshtml.dll
2016-04-13 14:50:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-04-13 14:50:07 ----A---- C:\Windows\system32\ieframe.dll
2016-04-13 14:50:06 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\wininet.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\jscript9.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iertutil.dll
2016-04-13 14:50:05 ----A---- C:\Windows\system32\iedkcs32.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-04-13 14:50:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\urlmon.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-13 14:50:04 ----A---- C:\Windows\system32\ie4uinit.exe
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-04-13 14:50:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\webcheck.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\vbscript.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\inetcomm.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\iepeers.dll
2016-04-13 14:50:02 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\jscript.dll
2016-04-13 14:50:01 ----A---- C:\Windows\system32\ieapfltr.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\ole32.dll
2016-04-13 14:48:48 ----A---- C:\Windows\system32\msxml3.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samsrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\samlib.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\drivers\cng.sys
2016-04-13 14:48:46 ----A---- C:\Windows\system32\certcli.dll
2016-04-13 14:48:46 ----A---- C:\Windows\system32\basesrv.dll
2016-04-13 14:48:16 ----A---- C:\Windows\system32\win32k.sys
2016-04-09 21:22:04 ----A---- C:\Users\Lenovo\AppData\Roaming\GiftBag.db
2016-04-09 21:22:01 ----A---- C:\Windows\system32\drivers\TAOKernelEx64.sys
2016-04-09 21:10:49 ----D---- C:\Program Files\Common Files\Soobzo
2016-04-09 21:10:35 ----A---- C:\ProgramData\smp2.exe
2016-04-09 19:02:40 ----D---- C:\ProgramData\Thunder Network
2016-04-09 19:02:27 ----D---- C:\Users\Lenovo\AppData\Roaming\gplyra
2016-04-09 19:01:11 ----A---- C:\Windows\chromebrowser.exe
2016-04-09 19:00:51 ----D---- C:\ProgramData\DivX
2016-04-06 15:09:54 ----A---- C:\Windows\system32\bi.exe
2016-03-31 13:55:19 ----D---- C:\Windows\Minidump
2016-03-29 15:30:54 ----D---- C:\Program Files (x86)\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iTunes
2016-03-29 15:30:53 ----D---- C:\Program Files\iPod
2016-03-29 15:29:51 ----D---- C:\Program Files (x86)\Apple Software Update

======List of files/folders modified in the last 1 month======

2016-04-28 22:35:55 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2016-04-28 22:35:34 ----D---- C:\Windows\Prefetch
2016-04-28 22:35:19 ----D---- C:\Windows\Temp
2016-04-28 22:33:29 ----RD---- C:\Program Files (x86)\Skype
2016-04-28 22:33:29 ----D---- C:\Windows\Tasks
2016-04-28 22:33:29 ----D---- C:\Windows\SysWOW64
2016-04-28 22:31:21 ----D---- C:\Windows\system32\Tasks
2016-04-28 22:30:31 ----D---- C:\Windows\system32\sru
2016-04-28 21:32:08 ----RD---- C:\Windows\System32
2016-04-28 21:32:08 ----D---- C:\Windows\Inf
2016-04-28 21:32:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-28 21:18:31 ----D---- C:\Windows\system32\drivers
2016-04-28 21:18:29 ----D---- C:\Windows
2016-04-28 21:17:19 ----D---- C:\Windows\SYSWOW64\drivers
2016-04-28 21:17:19 ----D---- C:\Program Files\Common Files
2016-04-28 21:16:30 ----RD---- C:\Program Files (x86)
2016-04-28 21:16:16 ----HD---- C:\ProgramData
2016-04-28 20:22:14 ----RD---- C:\Program Files
2016-04-28 18:27:42 ----D---- C:\Users\Lenovo\AppData\Roaming\tixati
2016-04-28 15:18:11 ----D---- C:\Windows\Microsoft.NET
2016-04-28 15:17:20 ----SHD---- C:\System Volume Information
2016-04-28 10:48:26 ----D---- C:\Windows\system32\config
2016-04-28 10:25:35 ----HD---- C:\Program Files\WindowsApps
2016-04-28 10:25:35 ----D---- C:\Windows\AppReadiness
2016-04-25 02:31:32 ----D---- C:\Windows\system32\DriverStore
2016-04-25 02:31:29 ----D---- C:\Windows\WinSxS
2016-04-25 02:31:13 ----D---- C:\Windows\system32\catroot2
2016-04-22 09:57:45 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-19 12:25:30 ----D---- C:\Windows\system32\NDF
2016-04-18 19:48:22 ----D---- C:\Windows\rescache
2016-04-18 14:44:12 ----RD---- C:\Windows\assembly
2016-04-16 06:33:02 ----SHD---- C:\Windows\Installer
2016-04-16 06:32:59 ----D---- C:\Program Files (x86)\Common Files
2016-04-16 06:32:36 ----D---- C:\ProgramData\Skype
2016-04-16 05:17:05 ----RD---- C:\Windows\ToastData
2016-04-16 05:17:05 ----D---- C:\Windows\SYSWOW64\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\wbem
2016-04-16 05:17:05 ----D---- C:\Windows\system32\sk-SK
2016-04-16 05:17:05 ----D---- C:\Windows\system32\en-US
2016-04-16 05:17:05 ----D---- C:\Windows\system32\appraiser
2016-04-16 05:17:05 ----D---- C:\Windows\apppatch
2016-04-16 05:17:04 ----D---- C:\Windows\system32\Boot
2016-04-16 05:17:04 ----D---- C:\Program Files\Internet Explorer
2016-04-16 05:17:04 ----D---- C:\Program Files (x86)\Internet Explorer
2016-04-15 17:02:28 ----HD---- C:\Windows\system32\GroupPolicy
2016-04-15 17:02:28 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2016-04-15 10:06:14 ----D---- C:\Windows\CbsTemp
2016-04-15 10:04:23 ----D---- C:\Windows\system32\MRT
2016-04-15 09:57:39 ----A---- C:\Windows\system32\MRT.exe
2016-04-13 22:54:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-04-13 22:54:51 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-04-13 22:54:50 ----A---- C:\Windows\system32\ntdll.dll
2016-04-09 21:21:56 ----RSD---- C:\Windows\Fonts
2016-04-09 18:44:39 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2016-04-05 23:53:01 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-04-05 22:27:29 ----D---- C:\ProgramData\Microsoft Help
2016-03-29 15:30:53 ----D---- C:\Program Files\Common Files\Apple

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 excsd;ExpressCache Storage Filter Driver; C:\Windows\system32\DRIVERS\excsd.sys [2013-11-18 117488]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-08-02 644968]
R1 excfs;ExpressCache File System Filter Driver; C:\Windows\system32\DRIVERS\excfs.sys [2013-11-18 25840]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2015-05-14 260856]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2015-08-19 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2015-08-19 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2015-08-19 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2015-06-30 52392]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btmaux;@oem66.inf,%BTMAUX.ServiceDesc%;Intel Bluetooth Auxiliary Service; C:\Windows\system32\DRIVERS\btmaux.sys [2014-03-26 140600]
R3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2014-04-22 1424184]
R3 CnxtHdAudService;@oem7.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-18 1534656]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2015-09-03 74432]
R3 ibtusb;@oem67.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R) 4.0 + HS Adapter; C:\Windows\system32\DRIVERS\ibtusb.sys [2014-05-10 192456]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-08-09 4928256]
R3 ISCT;@oem68.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\Windows\System32\drivers\ISCTD64.sys [2012-08-24 46016]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-05-26 30512]
R3 MEIx64;@oem2.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-12-19 99288]
R3 NETwNb64;@oem62.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\Netwbw02.sys [2014-04-16 3440096]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTSPER;@oem1.inf,%Rts5227PER%;Realtek PCIE Card Reader - PER; C:\Windows\system32\DRIVERS\RtsPer.sys [2014-08-15 508120]
R3 rtsuvc;@oem48.inf,%rtsuvc.DeviceDesc%;Integrated Camera; C:\Windows\system32\DRIVERS\rtsuvc.sys [2013-11-30 9100504]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-11-21 226304]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-02-05 32936]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2014-11-21 11776]
R3 SynTP;@oem60.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2015-02-05 567464]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-05-26 42288]
S3 Netaapl;@oem75.inf,%Netaapl.Service.DispName%;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2014-08-15 23040]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\Windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 USBAAPL64;@oem76.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-11-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2014-03-26 1206648]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2014-03-26 1165688]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2013-07-25 206552]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-11-21 38792]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-01-17 632048]
R2 ExpressCache;ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [2013-11-18 828656]
R2 IBMPMSVC;@oem6.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2015-09-03 156912]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-08-09 355232]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 iSafeService;iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2015-08-19 118048]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2015-11-26 110248]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2015-07-13 114632]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-01-17 154864]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-01-29 327296]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2016-03-11 133136]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-03-19 651576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
S2 jIxmRfR_protect;Protect Service(jIxmRfR_protect); C:\ProgramData\jIxmRfR\protect\protect.exe [2016-04-21 303016]
S2 jIxmRfR_update;Update Service(jIxmRfR_update); C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21 473000]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-11-21 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-08-09 288688]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-02 144200]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-01 148136]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-01-17 284912]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2016-01-13 21536]

-----------------EOF-----------------

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#8 Příspěvek od Lord_3D »

Po zakúpení ESET Smart Security bolo odstránených skoro 30 infiltrácií. Po RR a ďalšej kontrole ESS už nehlási nič.
Stále sa ale neviem zbaviť neporiadku v Chrome; pri jeho zapnutí to hádže nejaký "vyhľadávač" a bežnými cestami mu to neviem vyhovoriť.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#9 Příspěvek od Rudy »

Zkuste ještě tyto skeny:

1. Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;





Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#10 Příspěvek od Lord_3D »

Dobrý deň, prikladám Zoek log.


Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Lenovo on po 02.05.2016 at 13:27:12,65.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Lenovo\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

2.5.2016 13:28:23 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\Users\Lenovo\AppData\Roaming\gplyra deleted successfully
C:\Users\Lenovo\AppData\Local\brsrv deleted successfully
C:\Users\Lenovo\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Lenovo\AppData\Local\EmieSiteList deleted successfully
C:\Users\Lenovo\AppData\Local\EmieUserList deleted successfully
C:\Users\Lenovo\AppData\Local\GHISLER deleted successfully
C:\Users\Lenovo\AppData\Local\Skype deleted successfully
C:\Users\Lenovo\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2569014371-4025574855-1753814657-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1B5D5DBD-C857-4377-A755-06E50B4AC2B0} deleted successfully
HKEY_USERS\S-1-5-21-2569014371-4025574855-1753814657-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639B74F1-0594-432C-97C8-68C8C17A1E1D} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeService deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeKrnl deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:

Added to C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "http://www.yessearches.com/?ts=AHEqA38m ... ode=ffseng");
user_pref("browser.newtab.url", "http://www.yessearches.com/?ts=AHEqA38m ... ode=ffseng");
user_pref("browser.search.defaultenginename", "yessearches");
user_pref("browser.search.selectedEngine", "yessearches");

Added to C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js:

Added to C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

user.js not found
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- FireFox user.js and prefs.js backups ----

prefs_02.05.2016_1348_.backup

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F

user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.yessearches.com/?ts=AHEqA38m ... B&ptid=wak&
user_pref("browser.search.searchengine.sp", "http://www.yessearches.com/chrome.php?m ... ..&uid=52B
user_pref("browser.search.searchengine.url", "http://www.yessearches.com/chrome.php?m ... U..&uid=52
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- FireFox user.js and prefs.js backups ----

prefs_02.05.2016_1348_.backup

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_02.05.2016_1348_.backup

==== Deleting Files \ Folders ======================

C:\windows\SysNative\Tasks\SMW_P deleted
C:\PROGRA~3\DivX deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Public\Documents\dmp deleted
C:\windows\SysNative\drivers\TAOKernelEx64.sys deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92} deleted

==== Orphaned Tasks deleted from Registry ======================

SMW_P deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"arthurj8283@gmail.com"="C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\extensions\arthurj8283@gmail.com" [25.04.2016 10:47]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
- GsearchFinder - %ProfilePath%\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Undetermined - %ProfilePath%\extensions\staged
- GsearchFinder - %ProfilePath%\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi

ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default
- xRocket Toolbar - %ProfilePath%\extensions\arthurj8283@gmail.com
- Undetermined - %ProfilePath%\extensions\staged

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi

==== Firefox Plugins ======================


==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bknbnapaddjdnbilpmlacdkjdkjmbjhd - No path found[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
bknbnapaddjdnbilpmlacdkjdkjmbjhd - No path found[]

PicMonkey - Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm
Skype - Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
GIFPAL - Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\noohoboklgjeccnihfkbdakbchbhjlch
PicMonkey - Lenovo\AppData\Local\jIxmRfR\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm
Chrome Adr - Lenovo\AppData\Local\jIxmRfR\User Data\Default\Extensions\knbdkcpkcpmiakimkhhmlgkjmchgahil
GIFPAL - Lenovo\AppData\Local\jIxmRfR\User Data\Default\Extensions\noohoboklgjeccnihfkbdakbchbhjlch

==== Chromium Fix ======================

C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_media.mtvnservices.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_media.mtvnservices.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_media.mtvnservices.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_media.mtvnservices.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.medianewtabsearch.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.medianewtabsearch.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.medianewtabsearch.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.medianewtabsearch.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.newtabtvgamasearch.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.newtabtvgamasearch.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.newtabtvplussearch.com_0.localstorage deleted successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Local Storage\http_search.newtabtvplussearch.com_0.localstorage-journal deleted successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID= ... C32C3FCD29"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... DF&pc=MSE1
HKCU\SearchScopes\{A4BDEAD1-6321-496B-6451-E19AA256CC93} - http://www.bing.com/search?q={searchTer ... ORM=IESR02

==== Reset Google Chrome ======================

C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Preferences was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Secure Preferences was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Secure Preferencesgbak was reset successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Web Datagbak was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Web Data was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Web Data-journal was reset successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Web Datagbak was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\Lenovo\Desktop\Spotify.lnk - C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe
C:\Users\Public\Desktop\ESET Ochrana online platieb.lnk - C:\Program Files (x86)\ESET\ESET Smart Security\ecmd.exe /startprotectedbrowser
C:\Users\Public\Desktop\HP Deskjet 3540 series.lnk - C:\Program Files (x86)\HP\HP Deskjet 3540 series\Bin\HP Deskjet 3540 series.exe -Start UDCDevicePage
C:\Users\Public\Desktop\HP Photo Creations.lnk - C:\Program Files (x86)\HP Photo Creations\PhotoProduct.exe
C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk - C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
C:\Users\Public\Desktop\Shop for Supplies - HP Deskjet 3540 series.lnk - C:\Program Files (x86)\HP\HP Deskjet 3540 series\Bin\hpqDTSS.exe
C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe
C:\Users\Public\Desktop\The Sims 4.lnk - C:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk - C:\Users\Lenovo\AppData\Roaming\Spotify\Spotify.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk - C:\Windows\Installer\{56EC47AA-5813-4FF6-8E75-544026FBEA83}\AppleSoftwareUpdateIco.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Help.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Home Page.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Digital Editions 3.0\Uninstall.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET Smart Security\ESET Ochrana online platieb.lnk - C:\Program Files (x86)\ESET\ESET Smart Security\ecmd.exe /startprotectedbrowser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET Smart Security\ESET Smart Security.lnk - C:\Program Files (x86)\ESET\ESET Smart Security\egui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET\ESET Smart Security\ESET SysInspector.lnk - C:\Program Files (x86)\ESET\ESET Smart Security\SysInspector.exe /blank
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Čo je iTunes.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo\System Update.lnk - C:\Program Files (x86)\Lenovo\System Update\tvsu.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools\System Update.lnk - C:\Program Files (x86)\Lenovo\System Update\tvsu.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\Uninstall.lnk - C:\Program Files (x86)\WinZipper\wzUninstall.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions 3.0.lnk - C:\Program Files (x86)\Adobe\Adobe Digital Editions 3.0\DigitalEditions.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk - C:\Program Files (x86)\Winamp\winamp.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe http://www%2dsearching.com/?prd=set_epf&s=g49zamobl3137bk,7553000d-bfef-417e-90a1-2699f9028b63,
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Word 2010.lnk - C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\wordicon.exe

==== shortcuts After Repair ======================

C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe
C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\78UC7PMV will be deleted at reboot
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\OGDL8XY2 will be deleted at reboot
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\ST64IADS will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Lenovo\AppData\Local\jIxmRfR\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=119 folders=38 102502688 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Lenovo\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Lenovo\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\78UC7PMV" not found
"C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\OGDL8XY2" not found
"C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\IE\ST64IADS" not found

==== EOF on po 02.05.2016 at 13:54:09,77 ======================

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#11 Příspěvek od Lord_3D »

Takže, úvodná stránka v Chrome sa spúšťa už tak, ako má.
Ale vyhľadávanie je zasa nastavené cez nejakú pofidérnu stránku (Chromium niečo). Takisto sa Chrome snaží permanentne otvárať nejaké URLs, ktoré ESET SS blokuje..


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 8.1 x64
Ran by Lenovo (Administrator) on po 02.05.2016 at 14:00:11,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 12

Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\elex-tech (Folder)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi (File)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\staged (Folder)
Successfully deleted: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\th7liulg.default\extensions\staged (Folder)
Successfully deleted: C:\Users\Public\asr.dat (File)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\Windows\chromebrowser.exe (File)
Successfully deleted: C:\Program Files (x86)\elex-tech (Folder)



Registry: 3

Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlKit (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlMon (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlR3 (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 02.05.2016 at 14:02:47,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#12 Příspěvek od Rudy »

Zkuste tu stránku změnit.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#13 Příspěvek od Lord_3D »

Dobrý deň,

takže som sa tým hral a zistil som nasledovné:
  • Akonáhle použijem iný ako predvolený google vyhľadávač, tak všetko funguje korektne
  • Keď použijem predvolený google vyhľadávač, tak to automaticky presmeruje na tento web (http://i.imgur.com/hAZr4c4.jpg)
U google vyhľadávača som skúšal použiť predvolené nastavenia z počítača na ktorom to funguje korektne, no bez výsledku. Stále to presmeruje vyhľadávanie na web ktorý je v screenshote.
{google:baseURL}search?q=%s&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:iOSSearchLanguage}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:contextualSearchVersion}ie={inputEncoding}

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119315
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#14 Příspěvek od Rudy »

To je divbné. Který prohlížeč to dělá?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Lord_3D
Návštěvník
Návštěvník
Příspěvky: 60
Registrován: 11 bře 2007 12:13

Re: Prosím o pomoc - vysoké vyťaženie CPU, adware

#15 Příspěvek od Lord_3D »

Robí to Chrome.
  • Pokiaľ tú "hlavnú" lištu použijem na zadanie internetovej adresy, všetko funguje v poriadku.
  • Pokiaľ tú "hlavnú" lištu použijem na vyhľadávanie, tak ma to automaticky presmeruje na web kt. som postoval v predchádzajúcom príspevku.
  • Pokiaľ tú "hlavnú" lištu použijem na vyhľadávanie, ale zvolím v nastaveniach iný vyhľadávač ako je predvolený google (napríklad som skúšal Facebook), tak to tiež funguje bez problémov.

Zamčeno