Prosim o preventivnu kontrolu
Napsal: 15 bře 2015 21:36
Logfile of random's system information tool 1.10 (written by random/random)
Run by smolko at 2015-03-15 21:33:12
Microsoft Windows 8.1
System drive C: has 165 GB (81%) free of 203 GB
Total RAM: 8107 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:33:35 PM, on 3/15/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\windows\TEMP\DPTF\esif_assist.exe
C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\XTab\cmdshell.exe
C:\Program Files (x86)\XTab\HPNotify.exe
C:\windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe
C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui\updateui.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe
C:\windows\syswow64\wwahost.exe
C:\Program Files\trend micro\smolko.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O4 - HKLM\..\Run: [HarmonyPicks] C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe s
O4 - HKLM\..\Run: [HarmonySetting] C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe s
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [Pokki] "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: @oem22.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: CCSDK - Unknown owner - C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESIF Upper Framework Service (esifsvc) - Intel Corporation - C:\windows\SysWOW64\esif_uf.exe
O23 - Service: FastbootService - Lenovo - C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HarmonyPicksService - Unknown owner - C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe
O23 - Service: HarmonySettingService - Unknown owner - C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\windows\system32\igfxCUIService.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel® ME Service (Intel(R) ME Service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo OKO Service - Unknown owner - C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo PAWD Service (LenovoPAWDService) - Unknown owner - C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe
O23 - Service: LenovoSetSvr - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: OKOControlSvc - Lenovo(beijing) Limited - C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe
O23 - Service: PaperLookingSrv - Lenovo - C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe
O23 - Service: PGService - PointGrab LTD - C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
O23 - Service: PG_Service_Launcher - PointGrab LTD - C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: PLHotkeyService - Unknown owner - C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - SysTool PasSame LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ymc - Lenovo - C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
--
End of file - 14664 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\igfxCUIService.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 622439340352
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
\??\C:\windows\system32\conhost.exe 0x4
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\windows\SysWOW64\esif_uf.exe
"C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe"
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe"
"C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe"
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe" -Embedding
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe"
C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8d33399e-0917-4c64-b916-bf1f6657bd6f -SystemEventPortName:HostProcess-2e5ba0bd-a573-44fc-9d1b-9de7a8ce7386 -IoCancelEventPortName:HostProcess-c42e3a23-ec3d-4f42-b205-6731373ab149 -NonStateChangingEventPortName:HostProcess-33d9df28-66a8-476e-984f-fb5fac52c313 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2e34a970-0c1f-40e7-97a5-5ff6ae2806a2 -DeviceGroupId:WudfDefaultDevicePool
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b1a3394e-f233-4c04-9353-e84bd1a2dbdd -SystemEventPortName:HostProcess-556ce6e4-4c49-467f-996a-e746883e7496 -IoCancelEventPortName:HostProcess-6d03bc78-c47f-4356-b087-dd7829160a40 -NonStateChangingEventPortName:HostProcess-321ead04-26eb-43e2-897a-9b7d52b8f930 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0dbef8c2-9ee7-4e47-9502-0486dc866f0a -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-da11d323-68f0-4440-95d7-3c77f9653aa9 -SystemEventPortName:HostProcess-5c3f9933-182a-4202-bb46-61e3a227ff3d -IoCancelEventPortName:HostProcess-acaa14a4-3643-4904-9002-87bd82b948da -NonStateChangingEventPortName:HostProcess-24db8830-0f3d-4375-a70b-5c2f6b0246be -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:33a448db-7e19-4117-ab53-fa6f5a8f737f -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f3d5072f-40ff-4896-b018-3ccda0e97aac -SystemEventPortName:HostProcess-53e45136-daa1-499f-abc4-0b3e8314c10b -IoCancelEventPortName:HostProcess-23b29607-2dbd-4960-8b44-93541c370a93 -NonStateChangingEventPortName:HostProcess-1425a657-eb14-4ddf-89de-0f606a3bdce0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:085b6321-9a2a-4689-8da6-50fadec30a50 -DeviceGroupId:
"C:\windows\TEMP\DPTF\esif_assist.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\Explorer.EXE
taskeng.exe {6DF3A350-A1FA-43B3-B5B9-2455F95C4740}
taskhostex.exe
C:\windows\system32\wbem\unsecapp.exe -Embedding
taskeng.exe {6316A120-4DE5-4C21-81D4-F349A2FDAEC6}
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe" /rawdata=DvlwjSn03XksASpb/WhtqGG1qENbIfABfVNNndMiCavTtPFJQx61q36o/nlv11auVkcWpBRl+8ZuWUDhg7MCKSx4if1aIA70WzcJfld5WK1elxMw/njxsUuhRdnJ8aj/e/M2QtxrlP3llh6PPrBR62XDtPQtJkpG9GSf7zkqWqmQs1RNNjxnfxMR3qtaNuJ83tUjcQOAw4tuOjKR4RKMKPlc4G2PFo9dYghogHpwXm8HZLdmzjSImfJPewNTNkDS1pBev8LwMbKYHEmQtcqEFKHGa6XjAhsmeVS370JcjN437tyOoSeEBq+cGG/mOBJT3+PDrs2o3OncIaJg6zP2hKwGvLOsGNQNBSVTkLNnj+Iq9m1DJNMVSNA8PMgqT5T1PCjRAfx3fC9fXWAZB1MjY+zRSYSqh1NWsXNKmZ1r/0O06kiBUrochH6EDjItLA0rFBAk+7pVOlc6H0gN4cBqcKC0g6/RqhlMC7B9Pv4QGiBoewYjb/1wRWLFDtFuNdOPSe4B2pgmNcLFqsJ0uQp9VywyJUbv/irLa1Xc4KYhhoW6bE/4tD/BWbfDgrWjT95eQzISNFkVSKZuqzDHSK6+/kFGv2fsOR6ZMrsYgSau7d0P/PBI5PYDiIBNIle8qWng5QyeuZaVUA8baPdYae4KGnmlrjB6IzoLCDQx1sof0jUACf40gc9mt0HiEtpTFeAGOrYeKJZmYZxR1ih6IPrugJ3qJXHofZjx9ycTax3VlXoI31CP5IK8hPLM/rhCFQJ+oPLgfnLRBC3roiuqb5OY42m6LHM4GKnp258Ms2ODle1hockxGOTV2Au7yS5MFL0MQstFzNd1UKW/fPVgk/AaaQ==
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-6.exe" /rawdata=QalPho5naK6t/foK47NPfRelNhW6yQsTpFIOL4KQwQLczY77ZZGxC9fndtRiMc6L2K+4e/VpmmR8UhVecl0ntUKUwrtZ3Ex4ksjL1PjXvMgOYbWrD/Qazqr6kHomMnML/9iEiBmTNbDfmNOctRypH5UBIlzahRguwQ5nMnZ3/ZSsMJ/MnrLsuFFJgpylz+6ij92oI+BCTBuYzJalM8XVJN44XyRwjm4ppPq1txPCKdze9BMwxLcRDJt8+sPkNWJzB6zhiMvEDmTwOmqotditNP9763p+O36iQwW4iu60eoxu+bRCtpJsKsZaaVLYrclPBXHU7DpxoYek6Fk48+j4Gqw7o8NjhYQtZsM16Am9UrOBhbBWwuCpGMQbyuyf+AuXeZJnUXAhpIwEPOY7YMwBGkvk5udDTgcuU9/4azc9Dh7NsgamM81RHzJkcNKUbDt7DYehPghakhpHm36msbPGMB8m8mk2j4ylJIVZis6f4xS5OQDwBDIwZmYCbry6BtMHIX9tY7Zg+XupIGguEIJJiKbBaIWWjQ9IEzBYod6OjZ22xYHX8eqAoAuKAPB8zerOGMOqJ8V22mwV38BvxkTKqpRg81iFfUHPkk+0Jx6lhhm/bw8hMzdkZY7bEzZAlJZpXJy9L9bPn0SFF3qhUUTBlgH8VxmJiYUrK+64hCY+BKi1HqBJTHUv097Dt+k7oYNncSJR7le+K1IfugWIF3b1++P84eTi/geG059Tf1eF0HcpAdXLVhtFQlBQ0Tbcj3EgjyuQ7oTOH64UkngFoKHnJ/Y/5BWOakvN2ezHYfWuj0M/vAKxsBIhAz8WckfpjpgEmP9BejuebcOhz6tGlZ/sf0wluMSJ0f6WyMdZc3DztpMh6L4G/obMeEdWiXmuAaLWSMemh36fGosM8KaTQJhZa2OJ8ewUEJI11o4ogQAKvUabGIBgLioqb8cw//vzgqhKQjPARJyuu9ugND698+45DxYTN9rORk0bp32U7Xch2npRLpT5gtpvPgbb2QFuMBOeM+w1xlqtVt3TiU5OuWJJNQi4C58M6GVJFrJKdAzbXTRhjwUlOayJuwXU0e0fqwH6E5LwD5xSZ/vxS+XNxpZgZ4Qwkv8vhqcJo+ywILw3kTbVmbd+izcgBIpR5KmYksLeDxxwW6iwFVHpY+QmIqm8G8GdKHzQblq+q31rtx0mu4BekQYmH/d2rBrkPGAV0gyWL+P/ZWgclh6KYKsNaQGeLxQ9fEL5rX8Ii6bNDEj1p9kDB0n6577C0DcuIfzHtW9Mdiwf6jN+R+ET0xZTD9yQmyPac0BA2e/nPMBmrehQJuwXb9t0U6KALgkB7N4htvamNpF4fY4mEHwcoPFfcoW6zCjnZwZmUrDPqI1ylhQg8AkmSuAZ9Q9pHU7fuKYgeQGBWhvGLJhavrgtMSQ8R0fRDyfFoWgBvZv9clMR3sET44aVRBC973SmYwWg0e4hCClGxWJUiCSA+w5KlGt/IV3NW6Q7/2UUjm4L9qWonF9ANET/qywUfnoRgxfOue5/rc0eOlKSydN9WkKkydnVcAWv/augifxc59h4Zn47IRXfE++y3I59Fl0o6bXuH71BTCai2HJHmd2P42d9SVcxFEgusP5Q43u1g83cvJJ+dpCXuZ2d1qKo+4JBtFqaInG2eu8af1fuf3MRUEFewmYxbTVu9d5CqPYQ8c4fvAvBmKKc2fluR/H/DT+vMn03k4K/f6OG7OuIagNu+PH2jZFymCKUmRlljGCP5nXvH5wQeAE9z7TOFszXuIvsmDcOEd21ULLj0vzdXUgF86lXGsaQhsDtWtlYEuMwsZWZ36P0QsgppfLvVpEPJf62vNTyduAqibs5F7+GLl/5ddeGuacnOINBvUpDii6l4V6wM0T7NnYp2VdVHs6Pm6o1zKpf0Sv1VAINaMh0fdikMB7wlVf6w1TB7j/fqYSS8UFLwV8BZyAc2P/qTt84mF79NB/BO5CALuTgu+OHhDH3VgZSzrED2Ppr3C1vOvEMvfsZoTFIWyvokfa95qNXcnUckZCGf2SJrOaUNw99692w1vixGIkSP26lqDC+k3YfEuvLycJkj7AeCwMgCbiltc2ilKBlx5o7pDc62zYJ53oMP3wHIizFIHZidFAHVNwMY6zZOeydcReIKtWGpSud2i3L7iFrDbKQY00BuxTMNsue1tbF7O5bTJe5k5kkLenXYJy5xLnEoGFEhdW6FkYAXez0h5ERHHeo/R4bbfg4ftGlPx2e7AysDFJ3ByQsXyvLYM1JBE4jc4IIdv8haEGfnWUBR/fZpuwFbEHNyjbKAm2uvxx//Ha/brNeKQ3FRBB1WTbCCWKWQLLOtod7WjIzwkiDMvg9Uiwq9qNQgVVSmYqyku1vu5uUkXcggVi9ULjeIXsTJX26GA8zz6D8Y9YtXI6FQkQsz7lCBtUxamccob7sX9cIXcrFk+gPDx2bcny80/jZQMLB0mM1bhqGReNjF5DJSePsiDEdlO1X50Ycn64x7ULeXm2m6Upun3kuW3TWqfaB6JtyI7WNGAQINKHCs1nn945Yf/zEMPVB
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe" /rawdata=vetMwqelm8qcK+XjkuQolXWB7VnatxCwQj383+IQ+fgqfdfsHa1vGUgypHTXV9mA2C0ZNVVQO2DzE5npYtdgIDQ+m2Mn2fy+y7ENkR5ujikkwz4mrRwjACSZ/2Zzfjl5Q8YdJ3pzPmoe2HErJPcXFh6ROVoc2itj2TUq98bsCcKu8DjEIGY6IwHuFqJFKvOa2CyN48Y8RSGLunTzjvXAhUMtlMW0Drqi4VTcJPyRJneQF9u+7TUFNmjK8Aii2EYVwa57PHFY18Fi4Z5ANDVtyQspdVY0YAO9m39teqqtxluZaB4LRmv4UhrGpB0YXJrIB+EVyN1kxaEKcPqz18FHIrpp1SqNpujNb4HbH+btSx9hnWjiy5T6PZz7l7WksfVRtBw1igk7B7D7GDfDtV0mAk1NR/uE8IdseNOrfOKYXDWyoClClijpoJpwfLOgP9k+6E9dtHYMdTtITOIEEbKK2MORI0wuiYGOuZf1yyC6XPc3H1paMeMUzi2curccIkqaEQPY3LKb8U1FboN8udSVeVtclzLPe7iUpQfbJHOUeZrV/G+ZZs3GsnkrQq8lSI/g2An3cJr6l6s3wZg2GuggPXMlPfA1NRYLzv6wZJ6Ypwo4Rr8O6zycSBz6gwb+mqdMM2yziZVVZ6jm8Jruk+7RP7ZAQpSiYE7AHV7RAAJfUQ92JN0R9ofunI8KK7vtSIj8qxKjOJXpJhrebznFAtztIAIM7RW6o1dKY8GHQhIbU0nnVd+G1X5FQFGilrwndJKAP2N/8nNVFIE3OOLqOmjLetgBwSiLHo427aq/uOXhnVMHfO7q9AHPys9kyUHsJcvHE+Qf8PVWDjQ0MeByEToeK8RN6Ix1bKI9VqXJMGl4HvKf/ACcb8EDOYPVWffykLWEbjZ6d0VamNt8QOPH1C+XQPpSojcMpy0xhst35Op9EoRDDOr+luTWpIpzeluMZUd4yuBFz2/Uq7q/VZPWi1S/Emv09/xcyI4wnnWGeOV5/N8ggeRVDNv9i+jKwUXF5vuOL6EcLb9ZCSrQ7+69/M2U5CJ1HCe8M/8+0Z3uJwCzkUR4v23e9bOW3QDLDhwugZFRRaT9vzHLoYItgQ15q/L6fS9zyDKrmDzAre+JApku1PSGkRnAOYsYHL4TZv7Fcw/3+PecBocmaf3G61IZP+OqTV+if1t71/G/V0S3ziEBFlJs7OOQJcONnTPURvDhzt/iZ/ZizWN4Y1qLaEuSytKGoayHfdFkbxeqLqaAwWF5hwhRr0/Td/pFflIBk+XNxorYOGQq24gfAxd1DdZcbWh8lADodBVGStGnCyg/0bfhqTB5nYZNm8Inb7kqOnWtNCuw8QKkBJ6/ejiQGW4XtSEfDQ==
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
igfxEM.exe
igfxHK.exe
igfxTray.exe
/QuitInfo:0000000000000B38;0000000000000B3C;
/loadhooks /Parent:0000000000001390
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\XTab\cmdshell.exe"
HPNotify.exe -run
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX6
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
C:\windows\SysWOW64\UMonit64.exe
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe"
"C:\Program Files\Lenovo\LenovoUtility\utility.exe"
"C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe"
"C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe"
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe" /run
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OnekeyOptimizerUpdata.exe"
"C:\Windows\System32\cpuminer-gw64.exe"
\??\C:\windows\system32\conhost.exe 0x4
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe" s
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe" s
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1800.0.573305785\783547639" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x161e --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3871 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1800.4.1218664764\2026113154" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Enabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_10/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Disabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=2.5 --font-cache-shared-mem-suffix=1800 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="1800.6.1563073542\1538441955" /prefetch:673131151
adb fork-server server
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe" 1 1 1 1
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe"
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --enable-touch-events --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/17/OneClickSignIn/Standard/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_47/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="5180.1.1506253021\585983495" /prefetch:3
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --enable-touch-events --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/17/OneClickSignIn/Standard/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_47/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="5180.2.1936170563\539773649" /prefetch:3
"C:\Users\smolko\AppData\Local\Pokki\Engine\StartMenuIndexer.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizer.exe" /hide
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui\updateui.exe" --port 35600
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey A0D7D719-FF98-6B55-DBA3-DDC493E2F8D4 -Reinvoke
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Users\smolko\Downloads\RSITx64.exe"
"C:\windows\syswow64\wwahost.exe" -ServerName:App.wwa
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
======Scheduled tasks folder======
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe /rawdata=vetMwqelm8qcK+XjkuQolXWB7VnatxCwQj383+IQ+fgqfdfsHa1vGUgypHTXV9mA2C0ZNVVQO2DzE5npYtdgIDQ+m2Mn2fy+y7ENkR5ujikkwz4mrRwjACSZ/2Zzfjl5Q8YdJ3pzPmoe2HErJPcXFh6ROVoc2itj2TUq98bsCcKu8DjEIGY6IwHuFqJFKvOa2CyN48Y8RSGLunTzjvXAhUMtlMW0Drqi4VTcJPyRJneQF9u+7TUFNmjK8Aii2EYVwa57PHFY18Fi4Z5ANDVtyQspdVY0YAO9m39teqqtxluZaB4LRmv4UhrGpB0YXJrIB+EVyN1kxaEKcPqz18FHIrpp1SqNpujNb4HbH+btSx9hnWjiy5T6PZz7l7WksfVRtBw1igk7B7D7GDfDtV0mAk1NR/uE8IdseNOrfOKYXDWyoClClijpoJpwfLOgP9k+6E9dtHYMdTtITOIEEbKK2MORI0wuiYGOuZf1yyC6XPc3H1paMeMUzi2curccIkqaEQPY3LKb8U1FboN8udSVeVtclzLPe7iUpQfbJHOUeZrV/G+ZZs3GsnkrQq8lSI/g2An3cJr6l6s3wZg2GuggPXMlPfA1NRYLzv6wZJ6Ypwo4Rr8O6zycSBz6gwb+mqdMM2yziZVVZ6jm8Jruk+7RP7ZAQpSiYE7AHV7RAAJfUQ92JN0R9ofunI8KK7vtSIj8qxKjOJXpJhrebznFAtztIAIM7RW6o1dKY8GHQhIbU0nnVd+G1X5FQFGilrwndJKAP2N/8nNVFIE3OOLqOmjLetgBwSiLHo427aq/uOXhnVMHfO7q9AHPys9kyUHsJcvHE+Qf8PVWDjQ0MeByEToeK8RN6Ix1bKI9VqXJMGl4HvKf/ACcb8EDOYPVWffykLWEbjZ6d0VamNt8QOPH1C+XQPpSojcMpy0xhst35Op9EoRDDOr+luTWpIpzeluMZUd4yuBFz2/Uq7q/VZPWi1S/Emv09/xcyI4wnnWGeOV5/N8ggeRVDNv9i+jKwUXF5vuOL6EcLb9ZCSrQ7+69/M2U5CJ1HCe8M/8+0Z3uJwCzkUR4v23e9bOW3QDLDhwugZFRRaT9vzHLoYItgQ15q/L6fS9zyDKrmDzAre+JApku1PSGkRnAOYsYHL4TZv7Fcw/3+PecBocmaf3G61IZP+OqTV+if1t71/G/V0S3ziEBFlJs7OOQJcONnTPURvDhzt/iZ/ZizWN4Y1qLaEuSytKGoayHfdFkbxeqLqaAwWF5hwhRr0/Td/pFflIBk+XNxorYOGQq24gfAxd1DdZcbWh8lADodBVGStGnCyg/0bfhqTB5nYZNm8Inb7kqOnWtNCuw8QKkBJ6/ejiQGW4XtSEfDQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-7.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-7.exe /rawdata=qZA8xx3OS0sOr4dzUHSw2N6oiraYQ+meQYdMaKRFj0w3tM3m4ftfASPEdlG325tbBXwBcsVAWpV+rWBRrzf6hLdC1ptNRkWXWVsalTO5Z3lTO/UMTJkoCm0EA880o9LejxvCx+R80J09WdqMJ++xQbtIsE5eP2mAXqOfO5WGQb06DSQuTbj6jkv5fJPTDr3bhrYfau4ikNHOzEd0WikLBn+/o5rK8Q1R8/6H2dk/eBgCb8BX/LNURfwv/vfynfu8KoGp/HplnRlAN3qWqLigImdcUhtaIaD2O5cLWdg0qlEQa7NSKPYGSYKhg4TmP8qt/XMoLzpn7ZgGa0fZG2ThObz3+hyU72VRn0gfMvJNjl9SNlxbMjJgZL6CJz1ggPMCLuUirHH+lNeVskIvdxu3dtB2bPgZsJxWuvkqG2hwUcya0Zlkkm2rel+8/5DLer8uHNmsbd3CkbCYRQGfmNth/39T7cPMs5WtALlGwsCi+lvnpa2sjs+TRsqokrMqhHsrPS8xSa76DyJgrb9P0tjnhQybyhP61e29e+gogmKMdhCBxAPMznP5LqmFGI156MOLFoCifGfZDbKSeU9j+3068zIsjyyjGJYtZfQXqvzSsbjgNhM1pJlwFoclHeniajR/xeAwPaP5vZIbKgMDAQkR08VslAoSJ52rQpIhd6pEXq49Oqyvgk/AtqICNW+oNE7gK5UA5zirW4sYanEULVBrIJlNisr9lI9ZzsG5TXTUxJJ+0Zko5Sc6uxJl6wswO8W+h5EDgxRiMlUMb5ZJ4evMRKvYgdYjqB2dFGHctpcZ/6LlQGgozNWw4SGnquZIkRh9l6L1sZreH77+hFPe3KUTiZ+AHhfdOEtDTN3xb+bto0+57O3Oe3HpPBUBgM8RgE+vDJU+lh3q/6Lyn5kbmep6nMDUySrvL1+PGNpont3sha1VMfVGm5+LIgt3b7eDptcOlYpdvVKkCHwweBx2QBf07rkw2NHJ7dLPanrCYjRwzNcyqj78Gv5OJacIE6mzfw2ckLwdmGQKFVfsRAX/n0knubEvXNMnqSw3THD6UxR2iK16aHBMYbA9KJ3m7fz0APBekKydZ55PD0qg0dPFKxie0KolXurpnOvoPSxR562eoXEG3res8RiR2OOZEFVD29jHtAi/slCjPBfSqQ6yxdfHVLCfouMIbeM90+7Z1MRUjMUOMoJC4oNt+EUTGG8+bdDtefXhf6fvNhANU6fZHgDm6zQYdB/ExlCvkH5u0NLOaFtkCxRSXzQMeqZ9b/esU9viy6D2vWek29+v8UOAkiZ61Z8xCV6O8NH37b098+IbcSgwSzDz96FkKS7CrjnOnIVvc2F00tq6rRz1IgW/3tgHTcEfica2xEYAeGI824qzdLmdUm4XMnPe3bDzgyGZOCisiZCN6RTyV0sS8mmm0WIorySRXw4zlBCF67jK6PH/nFu7/ZtKag/ZRPAYiPTpbakf/gIQ/B55zGlH81ngoLBxc8QgsqULevszz4jROjRqSmSyW/9XUBLNrOJgPKxjootG
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe /rawdata=DvlwjSn03XksASpb/WhtqGG1qENbIfABfVNNndMiCavTtPFJQx61q36o/nlv11auVkcWpBRl+8ZuWUDhg7MCKSx4if1aIA70WzcJfld5WK1elxMw/njxsUuhRdnJ8aj/e/M2QtxrlP3llh6PPrBR62XDtPQtJkpG9GSf7zkqWqmQs1RNNjxnfxMR3qtaNuJ83tUjcQOAw4tuOjKR4RKMKPlc4G2PFo9dYghogHpwXm8HZLdmzjSImfJPewNTNkDS1pBev8LwMbKYHEmQtcqEFKHGa6XjAhsmeVS370JcjN437tyOoSeEBq+cGG/mOBJT3+PDrs2o3OncIaJg6zP2hKwGvLOsGNQNBSVTkLNnj+Iq9m1DJNMVSNA8PMgqT5T1PCjRAfx3fC9fXWAZB1MjY+zRSYSqh1NWsXNKmZ1r/0O06kiBUrochH6EDjItLA0rFBAk+7pVOlc6H0gN4cBqcKC0g6/RqhlMC7B9Pv4QGiBoewYjb/1wRWLFDtFuNdOPSe4B2pgmNcLFqsJ0uQp9VywyJUbv/irLa1Xc4KYhhoW6bE/4tD/BWbfDgrWjT95eQzISNFkVSKZuqzDHSK6+/kFGv2fsOR6ZMrsYgSau7d0P/PBI5PYDiIBNIle8qWng5QyeuZaVUA8baPdYae4KGnmlrjB6IzoLCDQx1sof0jUACf40gc9mt0HiEtpTFeAGOrYeKJZmYZxR1ih6IPrugJ3qJXHofZjx9ycTax3VlXoI31CP5IK8hPLM/rhCFQJ+oPLgfnLRBC3roiuqb5OY42m6LHM4GKnp258Ms2ODle1hockxGOTV2Au7yS5MFL0MQstFzNd1UKW/fPVgk/AaaQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-3.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-3.exe /rawdata=biksGKUMyOw1q3YbtJmfGvmnvFbU3AT9pjUQGX0wROtTB4mmZGuSvlqp6BvSkC+RUzEr4YtEr4L2HyVi8N4nDT+fIlbqidasOFp9dYnidNIrGwfG6zfNv2GzEqtUAm7yZQIM3Uja89wLbm1B1Rqshjm+GW2JIIOUDLRCkJlw3EktYucdDTvqmI5kSzYQJv4NwzbkgXk1ocaIYD6iQbiQeG67plF3lnhZyWlka9IB5e7lnavfL+iNJyVK/vls+2NHMRFFevx0A26Vj0tLTbRKlMFsPuxpbz98rMRLwlUnPL5dAKolaK/VmWL0xZLI6laNHWuQlYhnBhCPilnEKCy7E2lDoLXCKy9j6giadHdLVVEIUHazkhoHF2xoeUH+MQ6YPNuCi1SmTru6fVOG07wlYZLC55U3jKBwMn2Q9OQtJMUwax0w2zWhZXCo1V0bVTVP5SahBm8mIkTsK19dkLrM6ulLLc+0rzQ9DRa1MctpCn5Z2S/cI0kCI5ThHslkDkyCXaMdCcTyKXyXU6HN9vwfKHjCrkp7gWP49wm37tx2qu/TCtk/y0w9lIKkC4TfNArE16WxLTeuPBBvsLHNT65nmVZNDWFbayRazmnCvVhX4THvtXbsoVvxq5y9SlCyCalV3NF8+HAEG7itembfqre8mYySef4/JHIe8FNhSn7vb9yv1Y96iOGQRmMMz8f5tDUJrtfx9IsR03nKwIjkKp7WE1dML9cSv3YUTWNhhKHaXzRfum8qCZQBoU06tEC1+IFBjJoChDyPotEIa+LJ/H3Lh4pkPrPUzuUv2HdKHJXtA6q+eFas9PHrlkJ4ewowPJtl8xYWyP2Jolhou4XABRNhWzg/bqtRoLgVVPp9UStG3MdZxHcFpZXEn0ItebUPUaGKuBZKUU802HlBbXsP6HLHvVwjoB4e+dDUHif9aQtX/y1BPrYESy0we6kdCaXjwbUywSaQBtMNgHD/koV5LFQOArD5Llfbj2RiKjhQvIOwFjRIo0gWMsvAywDTpDXAdCoTm3lv2rkZJpNLMpBtXZwkcisIp2FJknhpcntc3AvB5qdHIrijZwtGo1LKUVKMu3NoyCiMIUVVfdTrN5Fx1uiTFpFDq6nPtY7WAg6sYeO9XPGkccPc8TqUhg7CyVuidBCuqx1wfmVkmsyYW421X3A+XLB5ssKH8UTu2hgiKpFOlf3HF+vSt12ROd//4VfwWoJd7l6nyfUHYBPKE3uCsw0WW0hRfZF0NZVNeqBPInSbRUEindrEDmgVHLKK+Xl9PvtroHYavC3hsfmVv8WIE19WlzLennKIZI9gS/G8APoU18xYXlEIVl3HYBxDvC6ruYrs7+SoLJe5q5cy8letUPVfljJ/CJ9zmsKuCzkxYsIjZYKlNd3ZeqzXQtvEkUVG03kjZ+gFpGyJDE8zohxn3EpIyZS1ylArx/NI60r1YfVYDukOPlrgHr8P5bMrZDgEZiEUuftxTvcbgwcVKTuN9YLQpF/iMdrmMJ6bVUVzCuSvpYJedIX/GnpBUjMlh07OwKvzLUT9jJP/JZpzSV6ShTXbqwXPOZ5hyxxf9eF1xkgR1D0Fxxj5SFyiPQ12UBuopfJHdq8V55s5FSXoGCKzce3XbgQjeFowY2+FyxwYQRxmDrraT7pZ+tpDc72uHE8sruUgJdii+mMam1oza6RNhQn92/xgk0/+UfgCm+xmkFTaAtiHeqR68zKezbQr1FiC2/p/kLjDk2DZMK8z9dX9lw6FzIdLUHwn7hDhoNUjPUiS2KClyLgfT0LRnVbwYELVu7z6t5ZhRwpQ9mCZ1rClPJxlg/Ytb9VUsMbv2Sez1YU2tPADOLr3Mz4I4wEILkmt5JqVbAjDosDhiYonVMLMiyrOxQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-4.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-4.exe /rawdata=jo1ZCcsbm2H2hMuc48IFR8NEF91zFnkRD/nfMdqMz3C6tc2nacr8JVWuaC2xWEV8iPN1xWX8Nd6zBPE67UKq3RC5Cga3yAop+OADLum0RY7hIROQTDVlNJ5lOtO30wUPoKjC8MfW7NhPpK2s0YkvN33nN/qL5v0H/JFiwcidXRVn2FZUHSrpg7vnq+kvpS5WLUFpmgLRmM4uwJOQPn+QGzwoViT/3wTRNuWMjgYLfTHuHBKsX+MIrd1ChRjakCheYLOQmlK7vVxHnia3ZuEjWyAcgg6GdlIuC2YqrNT6CgX2s74XY53Qrr5KFaJG1ldl67tXUlyjneark+9tgajeORAzx7WTaIxCB+NkPD+UKpiVqbAnBnhVBaEbCJe1rw+GESvK0aLxhX1xBwsMYR5NnLbmr+cK+HeQFFDPE02HbbH73S8crqfmh78G1acLc/aZPPD7cPp6k8BFhSNTtjONtkJrVxRLYWlaTJ0PENoMIADt2qHDL1Yw3w2HDVrM6zS2SUGBjKewCRvKQwgTln+xHDD6WZWP9fXUmMNWocc5cpFoToc913++Dc7YSZhcpkXXemzeJGyubl8jBmjknq7Di5doNNNI8r6hkUF+cNwk2Yk3AwyLQ8QyC5Q0wFsu/+8Dv4vwe9udjnGKpeE56ghrURzRlx0/U5IwROaRFYvfYhg0dgObyN1O/IsKNOWoL0xHZ7UzkLtPXOJV9jo5jKy8jqh35ShlcwtgEZOjXgUs1miAnhIP7D+nDSxyZLv2oWkVx/uBu9KPrBoZkK/Fpcq1XCTlTELY3NPWXf5RWuZspHol3bcQf9do7XH7QuxQgqxUdb0UpuGysEzLJF1vHRUW5aDnB9Wt7d95EzflRM8pQkYoD/iypoUemvO0M2haVvGrf9fW0YvOq5W5YHSGxXokbCKDkS4ekdEs/VE66Tw0PZ9aRYYqvjdHLh+UkQ8DQqsnR3syH91cGzPul157eZodqqhMjsj8ZCT5UkM3aEhOPaqP2dPCdvTAbEVyaIW3k2QcC3aqeAuLXztJpczjcs4Hi/o9X2YaJHn5ycXxH/MBEYyRJ7/Ow1GB4kNjAjeyBM1w9aXtCL4mJssT8UXp6ijlHk1BNyOCAZXvDTFvUOA61aGX7lQXwo8EyqOOWjx5+DoMBrBc/LzZkg70oSpV7S6YgD1clHpOuonaSSkaeH0PfURoLCdV4MM0JjWk9e9Fbv8/E6WJk2l1ZOKQDRNQZETsZSUZHb6jGWWuuNXKDDtemzplQk4m46YOmLVIM+hAAKKiAUslsGzuxx6uFuxsAHjI+goI07bbNS5JbHVB86J1m6VTlEEr0XgrbqpgDH08cQ6y/NdBZLKf8gNrvpQfAQvAyI2qYZHRzJ21rG1TdynBEZjycDuMVE74iDZMNzq5RSXotBk0n79BSBL0gOq8vDo28R2KMq2BpQ297OfsGzNYEgqI9at458yoQB5Sm9OeNhntv+sQXeQfzHZMbBUIVGaUClsy2dB8mhda/oshq2eWO9iQIBS3o7B9Y3PaJJJHMrsKi2fZJrURlGUmLKZgK5p8Knvp75RO9WzJ0hzF4qRRZL6CuAMlRM4DTc7KDY/bdFBMe/V6ctBYho7NWeRX0NstW7uhVys5gZOvKy7WOUBFSbthzk5AidOmB4Mbv2ra8pC5hb2fdfA4aTeMIeEypa/seZr7HrG8SqbvVNZDz6BilTAHrd6rmspLXP4IwZQfbW59wfk6F0+4ZYZBM6k92SVEjjpA7V3iHPV45oGJPEy142gxUT446V4FTn2pT9pI8nRyd0rotZR2CX+46JdeMrroaWOnNOsXzcEUljUGnh6eRP5xmALqur0/Kx0j4x5V1undslTcbKeJ5z/NQfFAisR4mw==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-5.exe /rawdata=m595UO7IC9YSW4rYPULjJtG/NSnE5hMHQlUyMkR1NkuRyWgerHaRqLRh6uhw5jDuEUdlHrAuVg1ioHrKKucwuN3b7w4idE77Iwo7C1FMmzlljT4rSSF56RxmLIcTkfdofwZjOeoosma+Irpk0VKPX0oz0+ypCRW8A0FNyjQsgE2E+4y4iKCfyafo9WC/dQA9OQhw21KAg+gumNBje5pSSBxo8HbjGV62iHzr0OBBxdVBGzhxsWzHEauRbHGI6WpJBr38eFlrouKnp3+m03PXSi8jYt4xB+twLTSm208LxaR2xxKktOY31SP1vQd1BKmo9CiifrEYM44tSgR8Dd0pTwcc3LL53S+rUSNRqLHhM/KVrXdCiCNCeU7lHXl+BS7cw9fmUG/867/m7gLZ7Q7370UAOnn+8A3AL5vd9sFVexlDZoohn+LqeKuSEwzend7lcv0sCLkcgGYSFeQ8cRqo57SDJeZE+VoWCitLH0NmVtHTX4g9EDs4OQkrQU0elV3sdq6v2JuMadzVctCFvTcs7Lw89xAPNNE0sc0jugXXYXPSQSckMuccGiWjFmvMbqVub22jJd5ejcrC5TB9fMhVqaLeZhETtqH4S8q/1XGSgoRaOFaGnYe+3ZZDOHQJW4o266P7O4tniq2/dRtiJOaGkZ6GHR8x/+7OAYb31fw4IbwvJFaLCh4+qQ5tiimx1Z0iFsv1GzXrCKcpy+P4m1gOdpYihNYkG9ZFXnLRDyB+lbxFgeSrFhT4vXURSb5i3OBpq5iLBLS7XozoB5Lca5Y+lEsU0lWxk9OFUmGW6biqvR6mJFVm6/PJeRhP1W01gy2g3ktlOjpVtMBq5PpoauVRe61y/LHT2XDmU60B/ClaNMnhiGeUKEKguPcfaG6/nWkLl5MPpaHSgIQZqk0grdhdxFmVcga+I1UjKfr6/+577y60KMNoPIKlCNRbUgYt2LkJj+FO3AQuUJ5MTLtIViVlqV4HSersmsM8qn73V4sMyXFYe5hZRpHVUbfsS6lIB2Mn
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-5.exe /rawdata=m595UO7IC9YSW4rYPULjJtG/NSnE5hMHQlUyMkR1NkuRyWgerHaRqLRh6uhw5jDuEUdlHrAuVg1ioHrKKucwuN3b7w4idE77Iwo7C1FMmzlljT4rSSF56RxmLIcTkfdofwZjOeoosma+Irpk0VKPX0oz0+ypCRW8A0FNyjQsgE2E+4y4iKCfyafo9WC/dQA9OQhw21KAg+gumNBje5pSSBxo8HbjGV62iHzr0OBBxdVBGzhxsWzHEauRbHGI6WpJBr38eFlrouKnp3+m03PXSi8jYt4xB+twLTSm208LxaR2xxKktOY31SP1vQd1BKmo9CiifrEYM44tSgR8Dd0pTwcc3LL53S+rUSNRqLHhM/KVrXdCiCNCeU7lHXl+BS7cw9fmUG/867/m7gLZ7Q7370UAOnn+8A3AL5vd9sFVexlDZoohn+LqeKuSEwzend7lcv0sCLkcgGYSFeQ8cRqo57SDJeZE+VoWCitLH0NmVtHTX4g9EDs4OQkrQU0elV3sdq6v2JuMadzVctCFvTcs7Lw89xAPNNE0sc0jugXXYXPSQSckMuccGiWjFmvMbqVub22jJd5ejcrC5TB9fMhVqaLeZhETtqH4S8q/1XGSgoRaOFaGnYe+3ZZDOHQJW4o266P7O4tniq2/dRtiJOaGkZ6GHR8x/+7OAYb31fw4IbwvJFaLCh4+qQ5tiimx1Z0iFsv1GzXrCKcpy+P4m1gOdpYihNYkG9ZFXnLRDyB+lbxFgeSrFhT4vXURSb5i3OBpq5iLBLS7XozoB5Lca5Y+lEsU0lWxk9OFUmGW6biqvR6mJFVm6/PJeRhP1W01gy2g3ktlOjpVtMBq5PpoauVRe7pyZCnDInphxQa/f11Fxicukd3DC4j9HBS47DWBcd6xV3eSynzuUDaaraNdBo9/dS9F3rU5J0c1Mko8dyK7UhYtLrCxJFtpzrTu593n9k+TfKpNOHgHA9TZ6qibrXUWXI04GXEadUjZ4cM17ocxABemXGG4Xd9aRHYUC6UV0fZf
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-6.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-6.exe /rawdata=QalPho5naK6t/foK47NPfRelNhW6yQsTpFIOL4KQwQLczY77ZZGxC9fndtRiMc6L2K+4e/VpmmR8UhVecl0ntUKUwrtZ3Ex4ksjL1PjXvMgOYbWrD/Qazqr6kHomMnML/9iEiBmTNbDfmNOctRypH5UBIlzahRguwQ5nMnZ3/ZSsMJ/MnrLsuFFJgpylz+6ij92oI+BCTBuYzJalM8XVJN44XyRwjm4ppPq1txPCKdze9BMwxLcRDJt8+sPkNWJzB6zhiMvEDmTwOmqotditNP9763p+O36iQwW4iu60eoxu+bRCtpJsKsZaaVLYrclPBXHU7DpxoYek6Fk48+j4Gqw7o8NjhYQtZsM16Am9UrOBhbBWwuCpGMQbyuyf+AuXeZJnUXAhpIwEPOY7YMwBGkvk5udDTgcuU9/4azc9Dh7NsgamM81RHzJkcNKUbDt7DYehPghakhpHm36msbPGMB8m8mk2j4ylJIVZis6f4xS5OQDwBDIwZmYCbry6BtMHIX9tY7Zg+XupIGguEIJJiKbBaIWWjQ9IEzBYod6OjZ22xYHX8eqAoAuKAPB8zerOGMOqJ8V22mwV38BvxkTKqpRg81iFfUHPkk+0Jx6lhhm/bw8hMzdkZY7bEzZAlJZpXJy9L9bPn0SFF3qhUUTBlgH8VxmJiYUrK+64hCY+BKi1HqBJTHUv097Dt+k7oYNncSJR7le+K1IfugWIF3b1++P84eTi/geG059Tf1eF0HcpAdXLVhtFQlBQ0Tbcj3EgjyuQ7oTOH64UkngFoKHnJ/Y/5BWOakvN2ezHYfWuj0M/vAKxsBIhAz8WckfpjpgEmP9BejuebcOhz6tGlZ/sf0wluMSJ0f6WyMdZc3DztpMh6L4G/obMeEdWiXmuAaLWSMemh36fGosM8KaTQJhZa2OJ8ewUEJI11o4ogQAKvUabGIBgLioqb8cw//vzgqhKQjPARJyuu9ugND698+45DxYTN9rORk0bp32U7Xch2npRLpT5gtpvPgbb2QFuMBOeM+w1xlqtVt3TiU5OuWJJNQi4C58M6GVJFrJKdAzbXTRhjwUlOayJuwXU0e0fqwH6E5LwD5xSZ/vxS+XNxpZgZ4Qwkv8vhqcJo+ywILw3kTbVmbd+izcgBIpR5KmYksLeDxxwW6iwFVHpY+QmIqm8G8GdKHzQblq+q31rtx0mu4BekQYmH/d2rBrkPGAV0gyWL+P/ZWgclh6KYKsNaQGeLxQ9fEL5rX8Ii6bNDEj1p9kDB0n6577C0DcuIfzHtW9Mdiwf6jN+R+ET0xZTD9yQmyPac0BA2e/nPMBmrehQJuwXb9t0U6KALgkB7N4htvamNpF4fY4mEHwcoPFfcoW6zCjnZwZmUrDPqI1ylhQg8AkmSuAZ9Q9pHU7fuKYgeQGBWhvGLJhavrgtMSQ8R0fRDyfFoWgBvZv9clMR3sET44aVRBC973SmYwWg0e4hCClGxWJUiCSA+w5KlGt/IV3NW6Q7/2UUjm4L9qWonF9ANET/qywUfnoRgxfOue5/rc0eOlKSydN9WkKkydnVcAWv/augifxc59h4Zn47IRXfE++y3I59Fl0o6bXuH71BTCai2HJHmd2P42d9SVcxFEgusP5Q43u1g83cvJJ+dpCXuZ2d1qKo+4JBtFqaInG2eu8af1fuf3MRUEFewmYxbTVu9d5CqPYQ8c4fvAvBmKKc2fluR/H/DT+vMn03k4K/f6OG7OuIagNu+PH2jZFymCKUmRlljGCP5nXvH5wQeAE9z7TOFszXuIvsmDcOEd21ULLj0vzdXUgF86lXGsaQhsDtWtlYEuMwsZWZ36P0QsgppfLvVpEPJf62vNTyduAqibs5F7+GLl/5ddeGuacnOINBvUpDii6l4V6wM0T7NnYp2VdVHs6Pm6o1zKpf0Sv1VAINaMh0fdikMB7wlVf6w1TB7j/fqYSS8UFLwV8BZyAc2P/qTt84mF79NB/BO5CALuTgu+OHhDH3VgZSzrED2Ppr3C1vOvEMvfsZoTFIWyvokfa95qNXcnUckZCGf2SJrOaUNw99692w1vixGIkSP26lqDC+k3YfEuvLycJkj7AeCwMgCbiltc2ilKBlx5o7pDc62zYJ53oMP3wHIizFIHZidFAHVNwMY6zZOeydcReIKtWGpSud2i3L7iFrDbKQY00BuxTMNsue1tbF7O5bTJe5k5kkLenXYJy5xLnEoGFEhdW6FkYAXez0h5ERHHeo/R4bbfg4ftGlPx2e7AysDFJ3ByQsXyvLYM1JBE4jc4IIdv8haEGfnWUBR/fZpuwFbEHNyjbKAm2uvxx//Ha/brNeKQ3FRBB1WTbCCWKWQLLOtod7WjIzwkiDMvg9Uiwq9qNQgVVSmYqyku1vu5uUkXcggVi9ULjeIXsTJX26GA8zz6D8Y9YtXI6FQkQsz7lCBtUxamccob7sX9cIXcrFk+gPDx2bcny80/jZQMLB0mM1bhqGReNjF5DJSePsiDEdlO1X50Ycn64x7ULeXm2m6Upun3kuW3TWqfaB6JtyI7WNGAQINKHCs1nn945Yf/zEMPVB
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-7.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-7.exe /rawdata=EIlcdt04eYq+27SF8vdL4pcZ6wc1vW2TZMdeHv8PNncx5/q4ta5i0IIEyGNVbVpJagnU3vv4GnixB0im9DmGO3rq2A6jLNcSTwM3LtmuR2Utb/4zE3IBDK996cdY+VdHxWhug6pP3x/ik8kXZte+VlBlATWNtcUB2sWfHHmyAauqPhiMupmU1rzV9V3rXoTDrY3bhUQzkGHmdueTsqh0zcnox4mSPbCxdsz6LOKV1lYX713+fujjOn3SohMlr3Cx1l/Rq14vP4lL7xDbbayGmRNh0LaQGH/p3rDA9UStELuLt3/7kWvZ8wBaNK0ZijDF3gN8FA9IGA3RXG9s1TQAT0BNJkzLZvLM0t62g24SNZ38kIKw0oo7PDnqz+7RMONkUrOX4b4HisDThUCkoU4BDk8Z4lx96mvANUH3d63k8MUQpjVsu4aJkf0RDbZWmnDuZTgzdNp1dYSMmvauVg7qatC+etcQ9i8CaMLJ2vc7I99RtD9pOMJ33A563gnhNJvyGZMy6DPtfXuFStcvtnB/aO6dLSr1u+772SbY+gHYp2Qj6WNj0ijwWoBomQ5/KJBYnEYD6QfM4Si8a3xfAJhH+lNoZQJNfeKGVT0G7F+qE9EQtbSjaMXSbyjM14MS7PWsdcBcKxWnbvgRPqfXTGzKbTf55qTgWZSRj/Sn8E7vV2nHwR2Oo93FUHT+We4tQPoOWNwPPTk6ovT0RNqKTVHn5LOqJ71JJ0/bpbmIm6vy7y8MvJeCo52ae71JZPLB0xIvlLwzGjmK4u4GLi3AzM5vSjbK0ZEJcqluHoGd208LNtbnIcOQs7ePluK7+Y+s48WHPdFNM6Qp78IHLr8kwD6nBhj21KR1SIVfZhlT4A6dxWeLdbjUxpL35+lZLwU9RhMwHC6ZW9wfFel0gN02WcAkyt8stCK2vExvsLijY4hhBO+VNlidqPAfhIi7ubp6hrvi2fizKxb82L1THNGNzeRJVzvYqDXIYkd3WGk/KeJQN8Uv99Hn774OS4ehcmEdhphqpZpc5jTwzLekw32pogfrx3QitCgDYdM5Tuv9jsXt15SbzmOTevdr4wNSrDAO54zXJz4U0QcaIpJzMTN+RynSw7HnY+eok38EdlqOjix9A3Zv8Mo3lhJZFF+4lNhVNkJrJETQACkvfiTwF/bkK1qJ1uLabIfjbhiOTDcsf5XWsH4Hxr5D7RxZtH59mVbrT+M7qytADzQjtIeNNzZGyQ7wcVS6ABSIA2myvPuc1mYhn904YRxhbEUh9pqsr3BzzyAtaPx3eC1x0guqyYSG+KGqPKL7eXd67cSeeP88qFvx6Jc3SEOmIwCR8WK0tOi3iG2JnDn7Q9AqK0awTG4Ztopq24g0ZO9rxRMMFoABR/ABsrrSfTiKOU2qvjtz3ul+vwGBeAJ5QLP3iNw97rsuvwYEYi7J5FcP4tdpCL5mpBrgRYryLm70Dci1mgkpedhZewEue05kKjSWwltv4OJefb9AZWC4SI5VBbBmimBYys/rCISbc4zcKhLL0U+6NLQwXwlCD6H3B6aUVNpguPNzCeYWYlVPB/bRFLWs5qrkf+mXBpJtIgQZJO9X0OA4MtR/xPIJ+Xmsdz7ARZ/gWurgY7wKXQPzqHNyJqbh+BgXsjxwQZq5fhF40/oyO4aG21fZ14pr7GstbdKy1pvzuq4bkVKeyWukGn9pR4MiMmP7/fzWQlsPaxtXCFYk9CFCDRZBncYme06PskmEhBPgWqMKbarOu7bg2PPZntNK1LbrgZmtRZYeTF9f5eP8ver2iNN4SUfwsGk7wJASzaJ5iobxoMmB2kkXlbXk+mh61sBotViRepkEeojiJ1D/NKEdyIq3UIOCPS9sg48ZzsswCVqUqhtGEyf0Y8FezgHnO3rT/IjOTaoTZurBqZ/g8JVWFQUggVT5h7SSjhNjbev7lMmehnfFt0BeGic5kp7UhLb+9Jo4SlZICyr2CPbOLxSja2wM3Dfz3cXj/DWEteZCNgMo3/ehlh6roo1aFx9ifrY0A7mOxmwnzEBI00NbvhKBR99Y3qX4xM5dUQIVDJuHduSgsVSHxV90RJ+8qQL4l9hmtSyIs9ZFHUpQ4ywNrgqkd2nWMnvwYy/ljn1mWEbUEFgY6S60zW/i83uMO2DupHDTx8ax4R5fedeFrH74Jg3SNGMYHjEGan98EXa8k9w7JywyOTlbR5q/zBXFH0bmrLEaP3gpXoAbTMQf794Zz4wSZ03O+ayJWSDX1yIEbcfY8JV79COWFaH0H3jugxnStXEvoGkCKNlgdG/Ooo5QQDjkL1nPwjYupo8QxEmUI7Cap1UKO3Ml5o2pwPa7dLQS7OzOrPl3zEQBX07qaDIethzxihRKxu60B1pnNn0PmLPv76uwOKytng==
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\FHIGIC.job - C:\Users\smolko\AppData\Roaming\FHIGIC.exe /infocmdline=G9gIEXHW6mWu8vSn94yB5rOOK8JNdniw67mBIZ9VEsBROWmT5FDczDYv2ZQugNeU/zurCbnodA9S1okJHUGhTWEAqpSZ2y0vZkEnRImbKt+V2PTOfRfMIBy8uM1kyo1F2jz3Z2ysWp9L47PHRxuIYzN54G5ukVys0aFYsj7jbMhmdyi9YU0JH32QLlel0hvjacYFbY6CdkdUxxSbi+KjYUBR6nGHouiuv/wUmqldjmdssi/ufHp98yefqnX9TQxqudEgxqQIV2mzHSqYq4MP53wmDd2FCDZRTc3cstVRv/CkKMVmfXelH0HsJLOX+bQnYU3+DRO2u14xWCo4baR4NgFhgJ0Yfti/j+sZHRUOrMvN+bdfg8unD8EELw+g94E2DxwarpSJQO0m0/K3pDPukopIoSsdQxQsJ7zhhIjgoRhxbjit/p6wPhuPNIzSzSQ6I4som91rCHnXmbi6tMXRiaLuyajeVcDZr4M2x0SjJ2GHw3h/ZxAZ7DGKK8b+yAx+
C:\windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\OEM.job - C:\Users\smolko\AppData\Roaming\OEM.exe /infocmdline=bZQk2wXFLMrXkukc43Ixdpvan00z6Atmt9BF0fLRF2XP0AqYAU/vpOC0HddUDNiXoszBzr63v5VXMNB4kEDtulrdWmqakNzPLyXRYXlgHo4pzJ3aVJIKpdsvorcIYhYsK5X9aG6jjsA1DxE28AtQ+GaTPrbLl5J6xPlldwLbl+6/TbfxvMx6qL3tWfOHwhX3nA6ZIwn0DeM02zl2W+esVoM5IQwJv2r0bXmVZhwT7AzFzd/hSRDHxOOUGW7ih2oB8g5hiketo7gIMGneaeP7VlccO1arW7VNu2vOzO/n7Uh9LCGrt7n+M9U3LarnqNh+gEY0v8WRgc2Qp5h+Wrt6DxGLxGWjegj8+BtJEDUOhRuVjlcZkO/Uh9s8bFWAxaUY++LKiuJzWY8AAUU7vV7WQGoKZqt6XCkaGVW7E5k2ThaGtlpvbQ+wuAruKwnmPUkKOBNUE51OH6qXjxbhHDbzSYjbL9TFx3rT5ltK8zEKPjj5pgPFBk6Hut41PL6+y/ys
=========Mozilla firefox=========
ProfilePath - C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://google.com/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll
C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default\extensions\
istart_ffnt@gmail.com
NLQUCQ35648598@KRFIE97629948.com
searchengine@gmail.com
C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default\searchplugins\
omniboxes.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-15 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-15 881880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-15 2333400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2015-03-10 538208]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-15 707800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-08-14 13675736]
"RtHDVBg_MAXX6"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"WavesSvc"=C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [2014-07-15 604928]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-08-04 2809072]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-06-25 36352]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-08-06 87536]
"LenovoUtility"=C:\Program Files\Lenovo\LenovoUtility\utility.exe [2014-11-19 10828056]
"AutoStartTransition"=C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe [2014-08-14 109840]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-11-19 802800]
"OneKeyOptimizer"=C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe [2014-08-16 461080]
"cpuminer"=C:\windows\system32\cpuminer-gw64.exe [2015-03-11 1316400]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pokki"=C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe [2015-02-05 10354504]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HarmonyPicks"=C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe [2014-08-28 1341720]
"HarmonySetting"=C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe [2014-08-28 2657048]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2014-11-20 126200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-03-15 21:33:12 ----D---- C:\rsit
2015-03-15 21:33:12 ----D---- C:\Program Files\trend micro
2015-03-15 15:55:12 ----A---- C:\windows\SYSWOW64\MrmCoreR.dll
2015-03-15 15:55:12 ----A---- C:\windows\SYSWOW64\explorer.exe
2015-03-15 15:55:12 ----A---- C:\windows\system32\MrmCoreR.dll
2015-03-15 15:55:12 ----A---- C:\windows\explorer.exe
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappprxy.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eapphost.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappgnui.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappcfg.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eapp3hst.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\LockScreenContentServer.exe
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappprxy.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eapphost.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappgnui.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappcfg.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eapp3hst.dll
2015-03-15 15:06:12 ----RHD---- C:\MSOCache
2015-03-15 14:59:03 ----D---- C:\ProgramData\Microsoft OneDrive
2015-03-15 14:56:07 ----D---- C:\Program Files\Microsoft Office 15
2015-03-15 12:14:37 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-03-15 12:14:37 ----A---- C:\windows\system32\atmfd.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\lpk.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\fontsub.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\dciman32.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\atmlib.dll
2015-03-15 12:14:35 ----A---- C:\windows\system32\rdpcorets.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\ubpm.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\rfxvmt.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\rdpudd.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys
2015-03-15 12:14:33 ----A---- C:\windows\system32\ntoskrnl.exe
2015-03-15 12:14:32 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-03-15 12:14:32 ----A---- C:\windows\system32\ntdll.dll
2015-03-15 12:14:30 ----A---- C:\windows\system32\win32k.sys
2015-03-15 12:14:28 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-03-15 12:14:28 ----A---- C:\windows\system32\schannel.dll
2015-03-15 12:14:16 ----A---- C:\windows\system32\mshtml.dll
2015-03-15 12:14:14 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-03-15 12:14:10 ----A---- C:\windows\system32\jscript9.dll
2015-03-15 12:14:10 ----A---- C:\windows\system32\ieframe.dll
2015-03-15 12:14:08 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-03-15 12:14:07 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-03-15 12:14:07 ----A---- C:\windows\system32\wininet.dll
2015-03-15 12:14:07 ----A---- C:\windows\system32\iertutil.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-03-15 12:14:06 ----A---- C:\windows\system32\urlmon.dll
2015-03-15 12:14:06 ----A---- C:\windows\system32\inetcomm.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2015-03-15 12:14:05 ----A---- C:\windows\system32\vbscript.dll
2015-03-15 12:14:04 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\MshtmlDac.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\msfeeds.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\iepeers.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\dxtrans.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\iepeers.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\webcheck.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\mshtmled.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\jscript9diag.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\jscript.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\iedkcs32.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\actxprxy.dll
2015-03-15 12:14:02 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-03-15 12:14:02 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-03-15 12:14:02 ----A---- C:\windows\system32\ieapfltr.dll
2015-03-15 12:13:49 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2015-03-15 12:13:49 ----A---- C:\windows\system32\WindowsCodecs.dll
2015-03-15 12:13:49 ----A---- C:\windows\system32\shell32.dll
2015-03-15 12:13:48 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-03-15 12:13:39 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2015-03-15 12:13:39 ----A---- C:\windows\SYSWOW64\msctf.dll
2015-03-15 12:13:39 ----A---- C:\windows\system32\WMPhoto.dll
2015-03-15 12:13:39 ----A---- C:\windows\system32\msctf.dll
2015-03-15 12:00:24 ----A---- C:\Users\smolko\AppData\Roaming\OEM.exe
2015-03-15 12:00:06 ----D---- C:\Program Files (x86)\43d45ddb-733d-4a4f-9d91-4e3253112627
2015-03-15 12:00:06 ----A---- C:\Users\smolko\AppData\Roaming\FHIGIC.exe
2015-03-15 12:00:02 ----D---- C:\Program Files (x86)\globalUpdate
2015-03-15 11:59:56 ----D---- C:\Program Files (x86)\CinemaP-1.9cV05.03
2015-03-15 11:59:46 ----D---- C:\Users\smolko\AppData\Roaming\cpuminer
2015-03-15 11:59:46 ----D---- C:\ProgramData\IHProtectUpDate
2015-03-15 11:59:41 ----D---- C:\Program Files (x86)\XTab
2015-03-15 11:59:35 ----D---- C:\ProgramData\WindowsMangerProtect
2015-03-15 11:59:25 ----D---- C:\Users\smolko\AppData\Roaming\omniboxes
2015-03-11 17:24:42 ----A---- C:\windows\system32\cpuminer-gw64.exe
2015-02-21 18:58:48 ----A---- C:\windows\SYSWOW64\scesrv.dll
2015-02-21 18:58:48 ----A---- C:\windows\system32\scesrv.dll
2015-02-21 18:58:40 ----A---- C:\windows\system32\wow64.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\user.exe
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-02-21 18:58:39 ----A---- C:\windows\system32\wow64cpu.dll
2015-02-21 18:58:39 ----A---- C:\windows\system32\ntvdm64.dll
2015-02-21 18:58:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-02-21 18:58:35 ----A---- C:\windows\system32\drivers\cng.sys
2015-02-21 18:58:35 ----A---- C:\windows\system32\certcli.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\certcli.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\msaudite.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\lsasrv.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\adtschema.dll
2015-02-21 18:57:41 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-02-21 18:57:41 ----A---- C:\windows\system32\dxtmsft.dll
2015-02-21 18:57:40 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-02-21 18:57:40 ----A---- C:\windows\system32\ie4uinit.exe
======List of files/folders modified in the last 1 month======
2015-03-15 21:33:12 ----RD---- C:\Program Files
2015-03-15 21:31:56 ----D---- C:\windows\Prefetch
2015-03-15 21:28:52 ----D---- C:\windows\Inf
2015-03-15 21:28:52 ----AD---- C:\windows\System32
2015-03-15 21:28:52 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-03-15 21:28:08 ----D---- C:\windows\Microsoft.NET
2015-03-15 21:25:10 ----D---- C:\windows\Temp
2015-03-15 21:23:14 ----D---- C:\windows\system32\config
2015-03-15 21:23:12 ----D---- C:\windows\WinSxS
2015-03-15 21:23:12 ----D---- C:\windows\SysWOW64
2015-03-15 21:21:57 ----AD---- C:\Windows
2015-03-15 21:21:56 ----D---- C:\windows\system32\drivers
2015-03-15 21:21:56 ----D---- C:\Program Files\Internet Explorer
2015-03-15 21:21:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-15 21:21:55 ----RD---- C:\windows\ToastData
2015-03-15 21:21:43 ----D---- C:\windows\system32\MRT
2015-03-15 21:19:34 ----D---- C:\windows\CbsTemp
2015-03-15 21:00:00 ----D---- C:\windows\system32\sru
2015-03-15 18:09:53 ----SD---- C:\Users\smolko\AppData\Roaming\Microsoft
2015-03-15 16:18:30 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-03-15 15:55:02 ----D---- C:\windows\system32\catroot2
2015-03-15 14:59:14 ----D---- C:\windows\system32\Tasks
2015-03-15 14:59:03 ----SHD---- C:\windows\Installer
2015-03-15 14:59:03 ----HD---- C:\ProgramData
2015-03-15 14:58:57 ----D---- C:\ProgramData\Microsoft
2015-03-15 14:58:51 ----RD---- C:\windows\assembly
2015-03-15 14:58:45 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-03-15 14:58:44 ----D---- C:\Program Files (x86)\Common Files
2015-03-15 14:58:43 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-03-15 14:58:32 ----D---- C:\windows\system32\DriverStore
2015-03-15 14:56:20 ----RSD---- C:\windows\Fonts
2015-03-15 12:10:46 ----D---- C:\windows\system32\wdi
2015-03-15 12:07:57 ----SHD---- C:\System Volume Information
2015-03-15 12:02:15 ----RD---- C:\Program Files (x86)
2015-03-15 12:00:41 ----D---- C:\windows\Tasks
2015-03-15 12:00:12 ----D---- C:\Program Files (x86)\Avira
2015-03-04 22:24:42 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-03-03 14:17:35 ----N---- C:\windows\system32\MpSigStub.exe
2015-02-26 21:14:44 ----A---- C:\windows\system32\MRT.exe
2015-02-22 11:37:10 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-21 22:36:57 ----D---- C:\windows\SYSWOW64\en-US
2015-02-21 22:36:57 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-02-21 22:36:57 ----D---- C:\windows\system32\en-US
2015-02-21 22:36:57 ----D---- C:\windows\system32\cs-CZ
2015-02-21 22:36:57 ----D---- C:\windows\apppatch
2015-02-21 18:59:05 ----SHD---- C:\$Recycle.Bin
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 Fastboot;Fastboot; C:\windows\system32\drivers\Fastboot.sys [2014-08-16 69144]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2014-06-25 670056]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 ACPIVPC;@oem29.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\windows\System32\drivers\AcpiVpc.sys [2014-11-19 35064]
R3 bcbtums;@oem22.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\windows\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM43XX;@oem16.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl63a.sys [2014-11-19 7578328]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\windows\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\windows\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2014-03-18 81920]
R3 btwampfl;@oem22.inf,%btwampfl.ServiceName%;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2014-02-03 166616]
R3 btwaudio;@oem18.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2014-05-13 190168]
R3 btwavdt;@oem18.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\windows\System32\drivers\btwavdt.sys [2014-03-19 229080]
R3 btwl2cap;@oem21.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 dptf_cpu;dptf_cpu; C:\windows\System32\drivers\dptf_cpu.sys [2014-06-10 35136]
R3 dptf_pch;dptf_pch; C:\windows\System32\drivers\dptf_pch.sys [2014-06-10 34072]
R3 esif_lf;esif_lf; C:\windows\System32\drivers\esif_lf.sys [2014-06-10 192624]
R3 iaLPSS_GPIO;@oem6.inf,%iaLPSS_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Driver; C:\windows\System32\drivers\iaLPSS_GPIO.sys [2014-06-11 35832]
R3 iaLPSS_I2C;@oem7.inf,%iaLPSS_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver; C:\windows\System32\drivers\iaLPSS_I2C.sys [2014-06-11 120312]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-07-25 4783472]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-08-19 4026840]
R3 iwdbus;@oem9.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2014-07-14 27000]
R3 KMDFVirtualKbd;@oem33.inf,%KMDFVirtualKbd.SVCDESC%;Lenovo Virtual Keyboard Device; C:\windows\System32\drivers\KMDFVirtualKbd.sys [2014-08-05 22264]
R3 KMDFVirtualMouse;@oem34.inf,%KMDFVirtualMouse.SVCDESC%;Lenovo Virtual Mouse Device; C:\windows\System32\drivers\KMDFVirtualMouse.sys [2014-08-05 21240]
R3 MEIx64;@oem3.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\TeeDriverx64.sys [2014-07-03 125952]
R3 mxtBootBridge;@oem17.inf,%mxtBootBridge.SVCDESC%;maxTouch I2C Boot Bridge Peripheral Service; C:\windows\System32\drivers\mxtBootBridge.sys [2013-12-19 36160]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\System32\drivers\rfcomm.sys [2014-03-18 167424]
R3 rtsuvc;@oem25.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\windows\system32\DRIVERS\rtsuvc.sys [2014-08-30 7239384]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\windows\system32\DRIVERS\WUDFRd.sys [2014-05-31 227840]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\windows\system32\DRIVERS\WUDFRd.sys [2014-05-31 227840]
R3 SynRMIHID;@oem14.inf,%SynRMIHID.SVCDESC%;Synaptics HID Service; C:\windows\system32\DRIVERS\SynRMIHID.sys [2014-08-04 41200]
R3 SynTP;@oem13.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2014-08-04 550128]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 AX88772;@netax88772.inf,%AX88772.DeviceDesc%;ASIX AX88772 USB2.0 to Fast Ethernet Adapter; C:\windows\system32\DRIVERS\ax88772.sys [2013-07-18 113864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 btwrchid;btwrchid; C:\windows\System32\drivers\btwrchid.sys [2014-03-19 38616]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem8.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2014-07-14 38264]
S3 IntcDAud;@oem4.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-07-25 451576]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2014-06-03 977664]
R2 CCSDK;CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [2014-07-10 592880]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-01-02 2169016]
R2 esifsvc;ESIF Upper Framework Service; C:\windows\SysWOW64\esif_uf.exe [2014-06-10 953352]
R2 FastbootService;FastbootService; C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe [2014-08-16 191256]
R2 HarmonyPicksService;HarmonyPicksService; C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe [2014-08-14 17176]
R2 HarmonySettingService;HarmonySettingService; C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe [2014-08-14 18712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-06-25 16232]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\windows\system32\igfxCUIService.exe [2014-07-25 324568]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2015-03-10 158816]
R2 Intel(R) ME Service;Intel® ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-07-03 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-07-03 154584]
R2 Lenovo OKO Service;Lenovo OKO Service; C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe [2014-07-31 2543896]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-08-07 2013680]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2014-05-22 584960]
R2 LenovoPAWDService;Lenovo PAWD Service; C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe [2014-11-19 133440]
R2 LenovoSetSvr;LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe [2014-06-19 258544]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [2014-08-02 218440]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-07-03 405976]
R2 OKOControlSvc;OKOControlSvc; C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe [2014-08-16 113944]
R2 PaperLookingSrv;PaperLookingSrv; C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe [2014-08-12 173336]
R2 PG_Service_Launcher;PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [2014-05-28 524552]
R2 PGService;PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [2014-05-28 167176]
R2 PhoneCompanionPusher;Lenovo PhoneCompanionPusher Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [2014-11-19 321520]
R2 PLHotkeyService;PLHotkeyService; C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe [2014-08-12 25368]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2014-08-04 190704]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [2014-11-19 68880]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-04-09 174368]
S2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-11-20 166192]
S2 BcmBtRSupport;@oem22.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\windows\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-15 68608]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-18 107912]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-21 267440]
S3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-08-06 599024]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-07-25 274736]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-15 68608]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-18 107912]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-05-13 887256]
S3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [2014-06-03 533760]
S3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-08-06 525296]
S3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-08-06 535024]
S3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-08-06 727536]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-17 114800]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneCompanionVap;Lenovo PhoneCompanionVap Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [2014-11-19 338416]
-----------------EOF-----------------
Run by smolko at 2015-03-15 21:33:12
Microsoft Windows 8.1
System drive C: has 165 GB (81%) free of 203 GB
Total RAM: 8107 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:33:35 PM, on 3/15/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\windows\TEMP\DPTF\esif_assist.exe
C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\XTab\cmdshell.exe
C:\Program Files (x86)\XTab\HPNotify.exe
C:\windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe
C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui\updateui.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe
C:\windows\syswow64\wwahost.exe
C:\Program Files\trend micro\smolko.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... NYAFA04996
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O4 - HKLM\..\Run: [HarmonyPicks] C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe s
O4 - HKLM\..\Run: [HarmonySetting] C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe s
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKCU\..\Run: [Pokki] "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: @oem22.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: CCSDK - Unknown owner - C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESIF Upper Framework Service (esifsvc) - Intel Corporation - C:\windows\SysWOW64\esif_uf.exe
O23 - Service: FastbootService - Lenovo - C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HarmonyPicksService - Unknown owner - C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe
O23 - Service: HarmonySettingService - Unknown owner - C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\windows\system32\igfxCUIService.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel® ME Service (Intel(R) ME Service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo OKO Service - Unknown owner - C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe
O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo PAWD Service (LenovoPAWDService) - Unknown owner - C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe
O23 - Service: LenovoSetSvr - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: OKOControlSvc - Lenovo(beijing) Limited - C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe
O23 - Service: PaperLookingSrv - Lenovo - C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe
O23 - Service: PGService - PointGrab LTD - C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
O23 - Service: PG_Service_Launcher - PointGrab LTD - C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: PLHotkeyService - Unknown owner - C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - SysTool PasSame LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ymc - Lenovo - C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
--
End of file - 14664 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\igfxCUIService.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 622439340352
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
\??\C:\windows\system32\conhost.exe 0x4
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\windows\SysWOW64\esif_uf.exe
"C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe"
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe"
"C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe"
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe"
"C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe" -Embedding
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe"
C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8d33399e-0917-4c64-b916-bf1f6657bd6f -SystemEventPortName:HostProcess-2e5ba0bd-a573-44fc-9d1b-9de7a8ce7386 -IoCancelEventPortName:HostProcess-c42e3a23-ec3d-4f42-b205-6731373ab149 -NonStateChangingEventPortName:HostProcess-33d9df28-66a8-476e-984f-fb5fac52c313 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2e34a970-0c1f-40e7-97a5-5ff6ae2806a2 -DeviceGroupId:WudfDefaultDevicePool
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b1a3394e-f233-4c04-9353-e84bd1a2dbdd -SystemEventPortName:HostProcess-556ce6e4-4c49-467f-996a-e746883e7496 -IoCancelEventPortName:HostProcess-6d03bc78-c47f-4356-b087-dd7829160a40 -NonStateChangingEventPortName:HostProcess-321ead04-26eb-43e2-897a-9b7d52b8f930 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0dbef8c2-9ee7-4e47-9502-0486dc866f0a -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-da11d323-68f0-4440-95d7-3c77f9653aa9 -SystemEventPortName:HostProcess-5c3f9933-182a-4202-bb46-61e3a227ff3d -IoCancelEventPortName:HostProcess-acaa14a4-3643-4904-9002-87bd82b948da -NonStateChangingEventPortName:HostProcess-24db8830-0f3d-4375-a70b-5c2f6b0246be -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:33a448db-7e19-4117-ab53-fa6f5a8f737f -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f3d5072f-40ff-4896-b018-3ccda0e97aac -SystemEventPortName:HostProcess-53e45136-daa1-499f-abc4-0b3e8314c10b -IoCancelEventPortName:HostProcess-23b29607-2dbd-4960-8b44-93541c370a93 -NonStateChangingEventPortName:HostProcess-1425a657-eb14-4ddf-89de-0f606a3bdce0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:085b6321-9a2a-4689-8da6-50fadec30a50 -DeviceGroupId:
"C:\windows\TEMP\DPTF\esif_assist.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\Explorer.EXE
taskeng.exe {6DF3A350-A1FA-43B3-B5B9-2455F95C4740}
taskhostex.exe
C:\windows\system32\wbem\unsecapp.exe -Embedding
taskeng.exe {6316A120-4DE5-4C21-81D4-F349A2FDAEC6}
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe" /rawdata=DvlwjSn03XksASpb/WhtqGG1qENbIfABfVNNndMiCavTtPFJQx61q36o/nlv11auVkcWpBRl+8ZuWUDhg7MCKSx4if1aIA70WzcJfld5WK1elxMw/njxsUuhRdnJ8aj/e/M2QtxrlP3llh6PPrBR62XDtPQtJkpG9GSf7zkqWqmQs1RNNjxnfxMR3qtaNuJ83tUjcQOAw4tuOjKR4RKMKPlc4G2PFo9dYghogHpwXm8HZLdmzjSImfJPewNTNkDS1pBev8LwMbKYHEmQtcqEFKHGa6XjAhsmeVS370JcjN437tyOoSeEBq+cGG/mOBJT3+PDrs2o3OncIaJg6zP2hKwGvLOsGNQNBSVTkLNnj+Iq9m1DJNMVSNA8PMgqT5T1PCjRAfx3fC9fXWAZB1MjY+zRSYSqh1NWsXNKmZ1r/0O06kiBUrochH6EDjItLA0rFBAk+7pVOlc6H0gN4cBqcKC0g6/RqhlMC7B9Pv4QGiBoewYjb/1wRWLFDtFuNdOPSe4B2pgmNcLFqsJ0uQp9VywyJUbv/irLa1Xc4KYhhoW6bE/4tD/BWbfDgrWjT95eQzISNFkVSKZuqzDHSK6+/kFGv2fsOR6ZMrsYgSau7d0P/PBI5PYDiIBNIle8qWng5QyeuZaVUA8baPdYae4KGnmlrjB6IzoLCDQx1sof0jUACf40gc9mt0HiEtpTFeAGOrYeKJZmYZxR1ih6IPrugJ3qJXHofZjx9ycTax3VlXoI31CP5IK8hPLM/rhCFQJ+oPLgfnLRBC3roiuqb5OY42m6LHM4GKnp258Ms2ODle1hockxGOTV2Au7yS5MFL0MQstFzNd1UKW/fPVgk/AaaQ==
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-6.exe" /rawdata=QalPho5naK6t/foK47NPfRelNhW6yQsTpFIOL4KQwQLczY77ZZGxC9fndtRiMc6L2K+4e/VpmmR8UhVecl0ntUKUwrtZ3Ex4ksjL1PjXvMgOYbWrD/Qazqr6kHomMnML/9iEiBmTNbDfmNOctRypH5UBIlzahRguwQ5nMnZ3/ZSsMJ/MnrLsuFFJgpylz+6ij92oI+BCTBuYzJalM8XVJN44XyRwjm4ppPq1txPCKdze9BMwxLcRDJt8+sPkNWJzB6zhiMvEDmTwOmqotditNP9763p+O36iQwW4iu60eoxu+bRCtpJsKsZaaVLYrclPBXHU7DpxoYek6Fk48+j4Gqw7o8NjhYQtZsM16Am9UrOBhbBWwuCpGMQbyuyf+AuXeZJnUXAhpIwEPOY7YMwBGkvk5udDTgcuU9/4azc9Dh7NsgamM81RHzJkcNKUbDt7DYehPghakhpHm36msbPGMB8m8mk2j4ylJIVZis6f4xS5OQDwBDIwZmYCbry6BtMHIX9tY7Zg+XupIGguEIJJiKbBaIWWjQ9IEzBYod6OjZ22xYHX8eqAoAuKAPB8zerOGMOqJ8V22mwV38BvxkTKqpRg81iFfUHPkk+0Jx6lhhm/bw8hMzdkZY7bEzZAlJZpXJy9L9bPn0SFF3qhUUTBlgH8VxmJiYUrK+64hCY+BKi1HqBJTHUv097Dt+k7oYNncSJR7le+K1IfugWIF3b1++P84eTi/geG059Tf1eF0HcpAdXLVhtFQlBQ0Tbcj3EgjyuQ7oTOH64UkngFoKHnJ/Y/5BWOakvN2ezHYfWuj0M/vAKxsBIhAz8WckfpjpgEmP9BejuebcOhz6tGlZ/sf0wluMSJ0f6WyMdZc3DztpMh6L4G/obMeEdWiXmuAaLWSMemh36fGosM8KaTQJhZa2OJ8ewUEJI11o4ogQAKvUabGIBgLioqb8cw//vzgqhKQjPARJyuu9ugND698+45DxYTN9rORk0bp32U7Xch2npRLpT5gtpvPgbb2QFuMBOeM+w1xlqtVt3TiU5OuWJJNQi4C58M6GVJFrJKdAzbXTRhjwUlOayJuwXU0e0fqwH6E5LwD5xSZ/vxS+XNxpZgZ4Qwkv8vhqcJo+ywILw3kTbVmbd+izcgBIpR5KmYksLeDxxwW6iwFVHpY+QmIqm8G8GdKHzQblq+q31rtx0mu4BekQYmH/d2rBrkPGAV0gyWL+P/ZWgclh6KYKsNaQGeLxQ9fEL5rX8Ii6bNDEj1p9kDB0n6577C0DcuIfzHtW9Mdiwf6jN+R+ET0xZTD9yQmyPac0BA2e/nPMBmrehQJuwXb9t0U6KALgkB7N4htvamNpF4fY4mEHwcoPFfcoW6zCjnZwZmUrDPqI1ylhQg8AkmSuAZ9Q9pHU7fuKYgeQGBWhvGLJhavrgtMSQ8R0fRDyfFoWgBvZv9clMR3sET44aVRBC973SmYwWg0e4hCClGxWJUiCSA+w5KlGt/IV3NW6Q7/2UUjm4L9qWonF9ANET/qywUfnoRgxfOue5/rc0eOlKSydN9WkKkydnVcAWv/augifxc59h4Zn47IRXfE++y3I59Fl0o6bXuH71BTCai2HJHmd2P42d9SVcxFEgusP5Q43u1g83cvJJ+dpCXuZ2d1qKo+4JBtFqaInG2eu8af1fuf3MRUEFewmYxbTVu9d5CqPYQ8c4fvAvBmKKc2fluR/H/DT+vMn03k4K/f6OG7OuIagNu+PH2jZFymCKUmRlljGCP5nXvH5wQeAE9z7TOFszXuIvsmDcOEd21ULLj0vzdXUgF86lXGsaQhsDtWtlYEuMwsZWZ36P0QsgppfLvVpEPJf62vNTyduAqibs5F7+GLl/5ddeGuacnOINBvUpDii6l4V6wM0T7NnYp2VdVHs6Pm6o1zKpf0Sv1VAINaMh0fdikMB7wlVf6w1TB7j/fqYSS8UFLwV8BZyAc2P/qTt84mF79NB/BO5CALuTgu+OHhDH3VgZSzrED2Ppr3C1vOvEMvfsZoTFIWyvokfa95qNXcnUckZCGf2SJrOaUNw99692w1vixGIkSP26lqDC+k3YfEuvLycJkj7AeCwMgCbiltc2ilKBlx5o7pDc62zYJ53oMP3wHIizFIHZidFAHVNwMY6zZOeydcReIKtWGpSud2i3L7iFrDbKQY00BuxTMNsue1tbF7O5bTJe5k5kkLenXYJy5xLnEoGFEhdW6FkYAXez0h5ERHHeo/R4bbfg4ftGlPx2e7AysDFJ3ByQsXyvLYM1JBE4jc4IIdv8haEGfnWUBR/fZpuwFbEHNyjbKAm2uvxx//Ha/brNeKQ3FRBB1WTbCCWKWQLLOtod7WjIzwkiDMvg9Uiwq9qNQgVVSmYqyku1vu5uUkXcggVi9ULjeIXsTJX26GA8zz6D8Y9YtXI6FQkQsz7lCBtUxamccob7sX9cIXcrFk+gPDx2bcny80/jZQMLB0mM1bhqGReNjF5DJSePsiDEdlO1X50Ycn64x7ULeXm2m6Upun3kuW3TWqfaB6JtyI7WNGAQINKHCs1nn945Yf/zEMPVB
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe" /rawdata=vetMwqelm8qcK+XjkuQolXWB7VnatxCwQj383+IQ+fgqfdfsHa1vGUgypHTXV9mA2C0ZNVVQO2DzE5npYtdgIDQ+m2Mn2fy+y7ENkR5ujikkwz4mrRwjACSZ/2Zzfjl5Q8YdJ3pzPmoe2HErJPcXFh6ROVoc2itj2TUq98bsCcKu8DjEIGY6IwHuFqJFKvOa2CyN48Y8RSGLunTzjvXAhUMtlMW0Drqi4VTcJPyRJneQF9u+7TUFNmjK8Aii2EYVwa57PHFY18Fi4Z5ANDVtyQspdVY0YAO9m39teqqtxluZaB4LRmv4UhrGpB0YXJrIB+EVyN1kxaEKcPqz18FHIrpp1SqNpujNb4HbH+btSx9hnWjiy5T6PZz7l7WksfVRtBw1igk7B7D7GDfDtV0mAk1NR/uE8IdseNOrfOKYXDWyoClClijpoJpwfLOgP9k+6E9dtHYMdTtITOIEEbKK2MORI0wuiYGOuZf1yyC6XPc3H1paMeMUzi2curccIkqaEQPY3LKb8U1FboN8udSVeVtclzLPe7iUpQfbJHOUeZrV/G+ZZs3GsnkrQq8lSI/g2An3cJr6l6s3wZg2GuggPXMlPfA1NRYLzv6wZJ6Ypwo4Rr8O6zycSBz6gwb+mqdMM2yziZVVZ6jm8Jruk+7RP7ZAQpSiYE7AHV7RAAJfUQ92JN0R9ofunI8KK7vtSIj8qxKjOJXpJhrebznFAtztIAIM7RW6o1dKY8GHQhIbU0nnVd+G1X5FQFGilrwndJKAP2N/8nNVFIE3OOLqOmjLetgBwSiLHo427aq/uOXhnVMHfO7q9AHPys9kyUHsJcvHE+Qf8PVWDjQ0MeByEToeK8RN6Ix1bKI9VqXJMGl4HvKf/ACcb8EDOYPVWffykLWEbjZ6d0VamNt8QOPH1C+XQPpSojcMpy0xhst35Op9EoRDDOr+luTWpIpzeluMZUd4yuBFz2/Uq7q/VZPWi1S/Emv09/xcyI4wnnWGeOV5/N8ggeRVDNv9i+jKwUXF5vuOL6EcLb9ZCSrQ7+69/M2U5CJ1HCe8M/8+0Z3uJwCzkUR4v23e9bOW3QDLDhwugZFRRaT9vzHLoYItgQ15q/L6fS9zyDKrmDzAre+JApku1PSGkRnAOYsYHL4TZv7Fcw/3+PecBocmaf3G61IZP+OqTV+if1t71/G/V0S3ziEBFlJs7OOQJcONnTPURvDhzt/iZ/ZizWN4Y1qLaEuSytKGoayHfdFkbxeqLqaAwWF5hwhRr0/Td/pFflIBk+XNxorYOGQq24gfAxd1DdZcbWh8lADodBVGStGnCyg/0bfhqTB5nYZNm8Inb7kqOnWtNCuw8QKkBJ6/ejiQGW4XtSEfDQ==
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
igfxEM.exe
igfxHK.exe
igfxTray.exe
/QuitInfo:0000000000000B38;0000000000000B3C;
/loadhooks /Parent:0000000000001390
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\XTab\cmdshell.exe"
HPNotify.exe -run
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX6
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
C:\windows\SysWOW64\UMonit64.exe
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe"
"C:\Program Files\Lenovo\LenovoUtility\utility.exe"
"C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe"
"C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe"
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe" /run
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OnekeyOptimizerUpdata.exe"
"C:\Windows\System32\cpuminer-gw64.exe"
\??\C:\windows\system32\conhost.exe 0x4
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe" s
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe" s
"C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1800.0.573305785\783547639" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x161e --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3871 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1800.4.1218664764\2026113154" --ppapi-flash-args=enable_hw_video_decode=1 --lang=sk --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/CTRequiredForEVTrial/RequirementEnforced/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/MaterialDesignNTP/Enabled/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Enabled/RefreshTokenDeviceId/Disabled/RememberCertificateErrorDecisions/Default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_10/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Disabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=2.5 --font-cache-shared-mem-suffix=1800 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="1800.6.1563073542\1538441955" /prefetch:673131151
adb fork-server server
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe" 1 1 1 1
"C:\Program Files\Lenovo\Communications Utility\tpknrres.exe"
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe"
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --enable-touch-events --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/17/OneClickSignIn/Standard/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_47/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="5180.1.1506253021\585983495" /prefetch:3
"C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppService.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --enable-touch-events --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/17/OneClickSignIn/Standard/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_47/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="5180.2.1936170563\539773649" /prefetch:3
"C:\Users\smolko\AppData\Local\Pokki\Engine\StartMenuIndexer.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizer.exe" /hide
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui\updateui.exe" --port 35600
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe"
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey A0D7D719-FF98-6B55-DBA3-DDC493E2F8D4 -Reinvoke
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Users\smolko\Downloads\RSITx64.exe"
"C:\windows\syswow64\wwahost.exe" -ServerName:App.wwa
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
======Scheduled tasks folder======
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe /rawdata=vetMwqelm8qcK+XjkuQolXWB7VnatxCwQj383+IQ+fgqfdfsHa1vGUgypHTXV9mA2C0ZNVVQO2DzE5npYtdgIDQ+m2Mn2fy+y7ENkR5ujikkwz4mrRwjACSZ/2Zzfjl5Q8YdJ3pzPmoe2HErJPcXFh6ROVoc2itj2TUq98bsCcKu8DjEIGY6IwHuFqJFKvOa2CyN48Y8RSGLunTzjvXAhUMtlMW0Drqi4VTcJPyRJneQF9u+7TUFNmjK8Aii2EYVwa57PHFY18Fi4Z5ANDVtyQspdVY0YAO9m39teqqtxluZaB4LRmv4UhrGpB0YXJrIB+EVyN1kxaEKcPqz18FHIrpp1SqNpujNb4HbH+btSx9hnWjiy5T6PZz7l7WksfVRtBw1igk7B7D7GDfDtV0mAk1NR/uE8IdseNOrfOKYXDWyoClClijpoJpwfLOgP9k+6E9dtHYMdTtITOIEEbKK2MORI0wuiYGOuZf1yyC6XPc3H1paMeMUzi2curccIkqaEQPY3LKb8U1FboN8udSVeVtclzLPe7iUpQfbJHOUeZrV/G+ZZs3GsnkrQq8lSI/g2An3cJr6l6s3wZg2GuggPXMlPfA1NRYLzv6wZJ6Ypwo4Rr8O6zycSBz6gwb+mqdMM2yziZVVZ6jm8Jruk+7RP7ZAQpSiYE7AHV7RAAJfUQ92JN0R9ofunI8KK7vtSIj8qxKjOJXpJhrebznFAtztIAIM7RW6o1dKY8GHQhIbU0nnVd+G1X5FQFGilrwndJKAP2N/8nNVFIE3OOLqOmjLetgBwSiLHo427aq/uOXhnVMHfO7q9AHPys9kyUHsJcvHE+Qf8PVWDjQ0MeByEToeK8RN6Ix1bKI9VqXJMGl4HvKf/ACcb8EDOYPVWffykLWEbjZ6d0VamNt8QOPH1C+XQPpSojcMpy0xhst35Op9EoRDDOr+luTWpIpzeluMZUd4yuBFz2/Uq7q/VZPWi1S/Emv09/xcyI4wnnWGeOV5/N8ggeRVDNv9i+jKwUXF5vuOL6EcLb9ZCSrQ7+69/M2U5CJ1HCe8M/8+0Z3uJwCzkUR4v23e9bOW3QDLDhwugZFRRaT9vzHLoYItgQ15q/L6fS9zyDKrmDzAre+JApku1PSGkRnAOYsYHL4TZv7Fcw/3+PecBocmaf3G61IZP+OqTV+if1t71/G/V0S3ziEBFlJs7OOQJcONnTPURvDhzt/iZ/ZizWN4Y1qLaEuSytKGoayHfdFkbxeqLqaAwWF5hwhRr0/Td/pFflIBk+XNxorYOGQq24gfAxd1DdZcbWh8lADodBVGStGnCyg/0bfhqTB5nYZNm8Inb7kqOnWtNCuw8QKkBJ6/ejiQGW4XtSEfDQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-7.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-7.exe /rawdata=qZA8xx3OS0sOr4dzUHSw2N6oiraYQ+meQYdMaKRFj0w3tM3m4ftfASPEdlG325tbBXwBcsVAWpV+rWBRrzf6hLdC1ptNRkWXWVsalTO5Z3lTO/UMTJkoCm0EA880o9LejxvCx+R80J09WdqMJ++xQbtIsE5eP2mAXqOfO5WGQb06DSQuTbj6jkv5fJPTDr3bhrYfau4ikNHOzEd0WikLBn+/o5rK8Q1R8/6H2dk/eBgCb8BX/LNURfwv/vfynfu8KoGp/HplnRlAN3qWqLigImdcUhtaIaD2O5cLWdg0qlEQa7NSKPYGSYKhg4TmP8qt/XMoLzpn7ZgGa0fZG2ThObz3+hyU72VRn0gfMvJNjl9SNlxbMjJgZL6CJz1ggPMCLuUirHH+lNeVskIvdxu3dtB2bPgZsJxWuvkqG2hwUcya0Zlkkm2rel+8/5DLer8uHNmsbd3CkbCYRQGfmNth/39T7cPMs5WtALlGwsCi+lvnpa2sjs+TRsqokrMqhHsrPS8xSa76DyJgrb9P0tjnhQybyhP61e29e+gogmKMdhCBxAPMznP5LqmFGI156MOLFoCifGfZDbKSeU9j+3068zIsjyyjGJYtZfQXqvzSsbjgNhM1pJlwFoclHeniajR/xeAwPaP5vZIbKgMDAQkR08VslAoSJ52rQpIhd6pEXq49Oqyvgk/AtqICNW+oNE7gK5UA5zirW4sYanEULVBrIJlNisr9lI9ZzsG5TXTUxJJ+0Zko5Sc6uxJl6wswO8W+h5EDgxRiMlUMb5ZJ4evMRKvYgdYjqB2dFGHctpcZ/6LlQGgozNWw4SGnquZIkRh9l6L1sZreH77+hFPe3KUTiZ+AHhfdOEtDTN3xb+bto0+57O3Oe3HpPBUBgM8RgE+vDJU+lh3q/6Lyn5kbmep6nMDUySrvL1+PGNpont3sha1VMfVGm5+LIgt3b7eDptcOlYpdvVKkCHwweBx2QBf07rkw2NHJ7dLPanrCYjRwzNcyqj78Gv5OJacIE6mzfw2ckLwdmGQKFVfsRAX/n0knubEvXNMnqSw3THD6UxR2iK16aHBMYbA9KJ3m7fz0APBekKydZ55PD0qg0dPFKxie0KolXurpnOvoPSxR562eoXEG3res8RiR2OOZEFVD29jHtAi/slCjPBfSqQ6yxdfHVLCfouMIbeM90+7Z1MRUjMUOMoJC4oNt+EUTGG8+bdDtefXhf6fvNhANU6fZHgDm6zQYdB/ExlCvkH5u0NLOaFtkCxRSXzQMeqZ9b/esU9viy6D2vWek29+v8UOAkiZ61Z8xCV6O8NH37b098+IbcSgwSzDz96FkKS7CrjnOnIVvc2F00tq6rRz1IgW/3tgHTcEfica2xEYAeGI824qzdLmdUm4XMnPe3bDzgyGZOCisiZCN6RTyV0sS8mmm0WIorySRXw4zlBCF67jK6PH/nFu7/ZtKag/ZRPAYiPTpbakf/gIQ/B55zGlH81ngoLBxc8QgsqULevszz4jROjRqSmSyW/9XUBLNrOJgPKxjootG
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe /rawdata=DvlwjSn03XksASpb/WhtqGG1qENbIfABfVNNndMiCavTtPFJQx61q36o/nlv11auVkcWpBRl+8ZuWUDhg7MCKSx4if1aIA70WzcJfld5WK1elxMw/njxsUuhRdnJ8aj/e/M2QtxrlP3llh6PPrBR62XDtPQtJkpG9GSf7zkqWqmQs1RNNjxnfxMR3qtaNuJ83tUjcQOAw4tuOjKR4RKMKPlc4G2PFo9dYghogHpwXm8HZLdmzjSImfJPewNTNkDS1pBev8LwMbKYHEmQtcqEFKHGa6XjAhsmeVS370JcjN437tyOoSeEBq+cGG/mOBJT3+PDrs2o3OncIaJg6zP2hKwGvLOsGNQNBSVTkLNnj+Iq9m1DJNMVSNA8PMgqT5T1PCjRAfx3fC9fXWAZB1MjY+zRSYSqh1NWsXNKmZ1r/0O06kiBUrochH6EDjItLA0rFBAk+7pVOlc6H0gN4cBqcKC0g6/RqhlMC7B9Pv4QGiBoewYjb/1wRWLFDtFuNdOPSe4B2pgmNcLFqsJ0uQp9VywyJUbv/irLa1Xc4KYhhoW6bE/4tD/BWbfDgrWjT95eQzISNFkVSKZuqzDHSK6+/kFGv2fsOR6ZMrsYgSau7d0P/PBI5PYDiIBNIle8qWng5QyeuZaVUA8baPdYae4KGnmlrjB6IzoLCDQx1sof0jUACf40gc9mt0HiEtpTFeAGOrYeKJZmYZxR1ih6IPrugJ3qJXHofZjx9ycTax3VlXoI31CP5IK8hPLM/rhCFQJ+oPLgfnLRBC3roiuqb5OY42m6LHM4GKnp258Ms2ODle1hockxGOTV2Au7yS5MFL0MQstFzNd1UKW/fPVgk/AaaQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-3.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-3.exe /rawdata=biksGKUMyOw1q3YbtJmfGvmnvFbU3AT9pjUQGX0wROtTB4mmZGuSvlqp6BvSkC+RUzEr4YtEr4L2HyVi8N4nDT+fIlbqidasOFp9dYnidNIrGwfG6zfNv2GzEqtUAm7yZQIM3Uja89wLbm1B1Rqshjm+GW2JIIOUDLRCkJlw3EktYucdDTvqmI5kSzYQJv4NwzbkgXk1ocaIYD6iQbiQeG67plF3lnhZyWlka9IB5e7lnavfL+iNJyVK/vls+2NHMRFFevx0A26Vj0tLTbRKlMFsPuxpbz98rMRLwlUnPL5dAKolaK/VmWL0xZLI6laNHWuQlYhnBhCPilnEKCy7E2lDoLXCKy9j6giadHdLVVEIUHazkhoHF2xoeUH+MQ6YPNuCi1SmTru6fVOG07wlYZLC55U3jKBwMn2Q9OQtJMUwax0w2zWhZXCo1V0bVTVP5SahBm8mIkTsK19dkLrM6ulLLc+0rzQ9DRa1MctpCn5Z2S/cI0kCI5ThHslkDkyCXaMdCcTyKXyXU6HN9vwfKHjCrkp7gWP49wm37tx2qu/TCtk/y0w9lIKkC4TfNArE16WxLTeuPBBvsLHNT65nmVZNDWFbayRazmnCvVhX4THvtXbsoVvxq5y9SlCyCalV3NF8+HAEG7itembfqre8mYySef4/JHIe8FNhSn7vb9yv1Y96iOGQRmMMz8f5tDUJrtfx9IsR03nKwIjkKp7WE1dML9cSv3YUTWNhhKHaXzRfum8qCZQBoU06tEC1+IFBjJoChDyPotEIa+LJ/H3Lh4pkPrPUzuUv2HdKHJXtA6q+eFas9PHrlkJ4ewowPJtl8xYWyP2Jolhou4XABRNhWzg/bqtRoLgVVPp9UStG3MdZxHcFpZXEn0ItebUPUaGKuBZKUU802HlBbXsP6HLHvVwjoB4e+dDUHif9aQtX/y1BPrYESy0we6kdCaXjwbUywSaQBtMNgHD/koV5LFQOArD5Llfbj2RiKjhQvIOwFjRIo0gWMsvAywDTpDXAdCoTm3lv2rkZJpNLMpBtXZwkcisIp2FJknhpcntc3AvB5qdHIrijZwtGo1LKUVKMu3NoyCiMIUVVfdTrN5Fx1uiTFpFDq6nPtY7WAg6sYeO9XPGkccPc8TqUhg7CyVuidBCuqx1wfmVkmsyYW421X3A+XLB5ssKH8UTu2hgiKpFOlf3HF+vSt12ROd//4VfwWoJd7l6nyfUHYBPKE3uCsw0WW0hRfZF0NZVNeqBPInSbRUEindrEDmgVHLKK+Xl9PvtroHYavC3hsfmVv8WIE19WlzLennKIZI9gS/G8APoU18xYXlEIVl3HYBxDvC6ruYrs7+SoLJe5q5cy8letUPVfljJ/CJ9zmsKuCzkxYsIjZYKlNd3ZeqzXQtvEkUVG03kjZ+gFpGyJDE8zohxn3EpIyZS1ylArx/NI60r1YfVYDukOPlrgHr8P5bMrZDgEZiEUuftxTvcbgwcVKTuN9YLQpF/iMdrmMJ6bVUVzCuSvpYJedIX/GnpBUjMlh07OwKvzLUT9jJP/JZpzSV6ShTXbqwXPOZ5hyxxf9eF1xkgR1D0Fxxj5SFyiPQ12UBuopfJHdq8V55s5FSXoGCKzce3XbgQjeFowY2+FyxwYQRxmDrraT7pZ+tpDc72uHE8sruUgJdii+mMam1oza6RNhQn92/xgk0/+UfgCm+xmkFTaAtiHeqR68zKezbQr1FiC2/p/kLjDk2DZMK8z9dX9lw6FzIdLUHwn7hDhoNUjPUiS2KClyLgfT0LRnVbwYELVu7z6t5ZhRwpQ9mCZ1rClPJxlg/Ytb9VUsMbv2Sez1YU2tPADOLr3Mz4I4wEILkmt5JqVbAjDosDhiYonVMLMiyrOxQ==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-4.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-4.exe /rawdata=jo1ZCcsbm2H2hMuc48IFR8NEF91zFnkRD/nfMdqMz3C6tc2nacr8JVWuaC2xWEV8iPN1xWX8Nd6zBPE67UKq3RC5Cga3yAop+OADLum0RY7hIROQTDVlNJ5lOtO30wUPoKjC8MfW7NhPpK2s0YkvN33nN/qL5v0H/JFiwcidXRVn2FZUHSrpg7vnq+kvpS5WLUFpmgLRmM4uwJOQPn+QGzwoViT/3wTRNuWMjgYLfTHuHBKsX+MIrd1ChRjakCheYLOQmlK7vVxHnia3ZuEjWyAcgg6GdlIuC2YqrNT6CgX2s74XY53Qrr5KFaJG1ldl67tXUlyjneark+9tgajeORAzx7WTaIxCB+NkPD+UKpiVqbAnBnhVBaEbCJe1rw+GESvK0aLxhX1xBwsMYR5NnLbmr+cK+HeQFFDPE02HbbH73S8crqfmh78G1acLc/aZPPD7cPp6k8BFhSNTtjONtkJrVxRLYWlaTJ0PENoMIADt2qHDL1Yw3w2HDVrM6zS2SUGBjKewCRvKQwgTln+xHDD6WZWP9fXUmMNWocc5cpFoToc913++Dc7YSZhcpkXXemzeJGyubl8jBmjknq7Di5doNNNI8r6hkUF+cNwk2Yk3AwyLQ8QyC5Q0wFsu/+8Dv4vwe9udjnGKpeE56ghrURzRlx0/U5IwROaRFYvfYhg0dgObyN1O/IsKNOWoL0xHZ7UzkLtPXOJV9jo5jKy8jqh35ShlcwtgEZOjXgUs1miAnhIP7D+nDSxyZLv2oWkVx/uBu9KPrBoZkK/Fpcq1XCTlTELY3NPWXf5RWuZspHol3bcQf9do7XH7QuxQgqxUdb0UpuGysEzLJF1vHRUW5aDnB9Wt7d95EzflRM8pQkYoD/iypoUemvO0M2haVvGrf9fW0YvOq5W5YHSGxXokbCKDkS4ekdEs/VE66Tw0PZ9aRYYqvjdHLh+UkQ8DQqsnR3syH91cGzPul157eZodqqhMjsj8ZCT5UkM3aEhOPaqP2dPCdvTAbEVyaIW3k2QcC3aqeAuLXztJpczjcs4Hi/o9X2YaJHn5ycXxH/MBEYyRJ7/Ow1GB4kNjAjeyBM1w9aXtCL4mJssT8UXp6ijlHk1BNyOCAZXvDTFvUOA61aGX7lQXwo8EyqOOWjx5+DoMBrBc/LzZkg70oSpV7S6YgD1clHpOuonaSSkaeH0PfURoLCdV4MM0JjWk9e9Fbv8/E6WJk2l1ZOKQDRNQZETsZSUZHb6jGWWuuNXKDDtemzplQk4m46YOmLVIM+hAAKKiAUslsGzuxx6uFuxsAHjI+goI07bbNS5JbHVB86J1m6VTlEEr0XgrbqpgDH08cQ6y/NdBZLKf8gNrvpQfAQvAyI2qYZHRzJ21rG1TdynBEZjycDuMVE74iDZMNzq5RSXotBk0n79BSBL0gOq8vDo28R2KMq2BpQ297OfsGzNYEgqI9at458yoQB5Sm9OeNhntv+sQXeQfzHZMbBUIVGaUClsy2dB8mhda/oshq2eWO9iQIBS3o7B9Y3PaJJJHMrsKi2fZJrURlGUmLKZgK5p8Knvp75RO9WzJ0hzF4qRRZL6CuAMlRM4DTc7KDY/bdFBMe/V6ctBYho7NWeRX0NstW7uhVys5gZOvKy7WOUBFSbthzk5AidOmB4Mbv2ra8pC5hb2fdfA4aTeMIeEypa/seZr7HrG8SqbvVNZDz6BilTAHrd6rmspLXP4IwZQfbW59wfk6F0+4ZYZBM6k92SVEjjpA7V3iHPV45oGJPEy142gxUT446V4FTn2pT9pI8nRyd0rotZR2CX+46JdeMrroaWOnNOsXzcEUljUGnh6eRP5xmALqur0/Kx0j4x5V1undslTcbKeJ5z/NQfFAisR4mw==
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-5.exe /rawdata=m595UO7IC9YSW4rYPULjJtG/NSnE5hMHQlUyMkR1NkuRyWgerHaRqLRh6uhw5jDuEUdlHrAuVg1ioHrKKucwuN3b7w4idE77Iwo7C1FMmzlljT4rSSF56RxmLIcTkfdofwZjOeoosma+Irpk0VKPX0oz0+ypCRW8A0FNyjQsgE2E+4y4iKCfyafo9WC/dQA9OQhw21KAg+gumNBje5pSSBxo8HbjGV62iHzr0OBBxdVBGzhxsWzHEauRbHGI6WpJBr38eFlrouKnp3+m03PXSi8jYt4xB+twLTSm208LxaR2xxKktOY31SP1vQd1BKmo9CiifrEYM44tSgR8Dd0pTwcc3LL53S+rUSNRqLHhM/KVrXdCiCNCeU7lHXl+BS7cw9fmUG/867/m7gLZ7Q7370UAOnn+8A3AL5vd9sFVexlDZoohn+LqeKuSEwzend7lcv0sCLkcgGYSFeQ8cRqo57SDJeZE+VoWCitLH0NmVtHTX4g9EDs4OQkrQU0elV3sdq6v2JuMadzVctCFvTcs7Lw89xAPNNE0sc0jugXXYXPSQSckMuccGiWjFmvMbqVub22jJd5ejcrC5TB9fMhVqaLeZhETtqH4S8q/1XGSgoRaOFaGnYe+3ZZDOHQJW4o266P7O4tniq2/dRtiJOaGkZ6GHR8x/+7OAYb31fw4IbwvJFaLCh4+qQ5tiimx1Z0iFsv1GzXrCKcpy+P4m1gOdpYihNYkG9ZFXnLRDyB+lbxFgeSrFhT4vXURSb5i3OBpq5iLBLS7XozoB5Lca5Y+lEsU0lWxk9OFUmGW6biqvR6mJFVm6/PJeRhP1W01gy2g3ktlOjpVtMBq5PpoauVRe61y/LHT2XDmU60B/ClaNMnhiGeUKEKguPcfaG6/nWkLl5MPpaHSgIQZqk0grdhdxFmVcga+I1UjKfr6/+577y60KMNoPIKlCNRbUgYt2LkJj+FO3AQuUJ5MTLtIViVlqV4HSersmsM8qn73V4sMyXFYe5hZRpHVUbfsS6lIB2Mn
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-5.exe /rawdata=m595UO7IC9YSW4rYPULjJtG/NSnE5hMHQlUyMkR1NkuRyWgerHaRqLRh6uhw5jDuEUdlHrAuVg1ioHrKKucwuN3b7w4idE77Iwo7C1FMmzlljT4rSSF56RxmLIcTkfdofwZjOeoosma+Irpk0VKPX0oz0+ypCRW8A0FNyjQsgE2E+4y4iKCfyafo9WC/dQA9OQhw21KAg+gumNBje5pSSBxo8HbjGV62iHzr0OBBxdVBGzhxsWzHEauRbHGI6WpJBr38eFlrouKnp3+m03PXSi8jYt4xB+twLTSm208LxaR2xxKktOY31SP1vQd1BKmo9CiifrEYM44tSgR8Dd0pTwcc3LL53S+rUSNRqLHhM/KVrXdCiCNCeU7lHXl+BS7cw9fmUG/867/m7gLZ7Q7370UAOnn+8A3AL5vd9sFVexlDZoohn+LqeKuSEwzend7lcv0sCLkcgGYSFeQ8cRqo57SDJeZE+VoWCitLH0NmVtHTX4g9EDs4OQkrQU0elV3sdq6v2JuMadzVctCFvTcs7Lw89xAPNNE0sc0jugXXYXPSQSckMuccGiWjFmvMbqVub22jJd5ejcrC5TB9fMhVqaLeZhETtqH4S8q/1XGSgoRaOFaGnYe+3ZZDOHQJW4o266P7O4tniq2/dRtiJOaGkZ6GHR8x/+7OAYb31fw4IbwvJFaLCh4+qQ5tiimx1Z0iFsv1GzXrCKcpy+P4m1gOdpYihNYkG9ZFXnLRDyB+lbxFgeSrFhT4vXURSb5i3OBpq5iLBLS7XozoB5Lca5Y+lEsU0lWxk9OFUmGW6biqvR6mJFVm6/PJeRhP1W01gy2g3ktlOjpVtMBq5PpoauVRe7pyZCnDInphxQa/f11Fxicukd3DC4j9HBS47DWBcd6xV3eSynzuUDaaraNdBo9/dS9F3rU5J0c1Mko8dyK7UhYtLrCxJFtpzrTu593n9k+TfKpNOHgHA9TZ6qibrXUWXI04GXEadUjZ4cM17ocxABemXGG4Xd9aRHYUC6UV0fZf
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-6.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-6.exe /rawdata=QalPho5naK6t/foK47NPfRelNhW6yQsTpFIOL4KQwQLczY77ZZGxC9fndtRiMc6L2K+4e/VpmmR8UhVecl0ntUKUwrtZ3Ex4ksjL1PjXvMgOYbWrD/Qazqr6kHomMnML/9iEiBmTNbDfmNOctRypH5UBIlzahRguwQ5nMnZ3/ZSsMJ/MnrLsuFFJgpylz+6ij92oI+BCTBuYzJalM8XVJN44XyRwjm4ppPq1txPCKdze9BMwxLcRDJt8+sPkNWJzB6zhiMvEDmTwOmqotditNP9763p+O36iQwW4iu60eoxu+bRCtpJsKsZaaVLYrclPBXHU7DpxoYek6Fk48+j4Gqw7o8NjhYQtZsM16Am9UrOBhbBWwuCpGMQbyuyf+AuXeZJnUXAhpIwEPOY7YMwBGkvk5udDTgcuU9/4azc9Dh7NsgamM81RHzJkcNKUbDt7DYehPghakhpHm36msbPGMB8m8mk2j4ylJIVZis6f4xS5OQDwBDIwZmYCbry6BtMHIX9tY7Zg+XupIGguEIJJiKbBaIWWjQ9IEzBYod6OjZ22xYHX8eqAoAuKAPB8zerOGMOqJ8V22mwV38BvxkTKqpRg81iFfUHPkk+0Jx6lhhm/bw8hMzdkZY7bEzZAlJZpXJy9L9bPn0SFF3qhUUTBlgH8VxmJiYUrK+64hCY+BKi1HqBJTHUv097Dt+k7oYNncSJR7le+K1IfugWIF3b1++P84eTi/geG059Tf1eF0HcpAdXLVhtFQlBQ0Tbcj3EgjyuQ7oTOH64UkngFoKHnJ/Y/5BWOakvN2ezHYfWuj0M/vAKxsBIhAz8WckfpjpgEmP9BejuebcOhz6tGlZ/sf0wluMSJ0f6WyMdZc3DztpMh6L4G/obMeEdWiXmuAaLWSMemh36fGosM8KaTQJhZa2OJ8ewUEJI11o4ogQAKvUabGIBgLioqb8cw//vzgqhKQjPARJyuu9ugND698+45DxYTN9rORk0bp32U7Xch2npRLpT5gtpvPgbb2QFuMBOeM+w1xlqtVt3TiU5OuWJJNQi4C58M6GVJFrJKdAzbXTRhjwUlOayJuwXU0e0fqwH6E5LwD5xSZ/vxS+XNxpZgZ4Qwkv8vhqcJo+ywILw3kTbVmbd+izcgBIpR5KmYksLeDxxwW6iwFVHpY+QmIqm8G8GdKHzQblq+q31rtx0mu4BekQYmH/d2rBrkPGAV0gyWL+P/ZWgclh6KYKsNaQGeLxQ9fEL5rX8Ii6bNDEj1p9kDB0n6577C0DcuIfzHtW9Mdiwf6jN+R+ET0xZTD9yQmyPac0BA2e/nPMBmrehQJuwXb9t0U6KALgkB7N4htvamNpF4fY4mEHwcoPFfcoW6zCjnZwZmUrDPqI1ylhQg8AkmSuAZ9Q9pHU7fuKYgeQGBWhvGLJhavrgtMSQ8R0fRDyfFoWgBvZv9clMR3sET44aVRBC973SmYwWg0e4hCClGxWJUiCSA+w5KlGt/IV3NW6Q7/2UUjm4L9qWonF9ANET/qywUfnoRgxfOue5/rc0eOlKSydN9WkKkydnVcAWv/augifxc59h4Zn47IRXfE++y3I59Fl0o6bXuH71BTCai2HJHmd2P42d9SVcxFEgusP5Q43u1g83cvJJ+dpCXuZ2d1qKo+4JBtFqaInG2eu8af1fuf3MRUEFewmYxbTVu9d5CqPYQ8c4fvAvBmKKc2fluR/H/DT+vMn03k4K/f6OG7OuIagNu+PH2jZFymCKUmRlljGCP5nXvH5wQeAE9z7TOFszXuIvsmDcOEd21ULLj0vzdXUgF86lXGsaQhsDtWtlYEuMwsZWZ36P0QsgppfLvVpEPJf62vNTyduAqibs5F7+GLl/5ddeGuacnOINBvUpDii6l4V6wM0T7NnYp2VdVHs6Pm6o1zKpf0Sv1VAINaMh0fdikMB7wlVf6w1TB7j/fqYSS8UFLwV8BZyAc2P/qTt84mF79NB/BO5CALuTgu+OHhDH3VgZSzrED2Ppr3C1vOvEMvfsZoTFIWyvokfa95qNXcnUckZCGf2SJrOaUNw99692w1vixGIkSP26lqDC+k3YfEuvLycJkj7AeCwMgCbiltc2ilKBlx5o7pDc62zYJ53oMP3wHIizFIHZidFAHVNwMY6zZOeydcReIKtWGpSud2i3L7iFrDbKQY00BuxTMNsue1tbF7O5bTJe5k5kkLenXYJy5xLnEoGFEhdW6FkYAXez0h5ERHHeo/R4bbfg4ftGlPx2e7AysDFJ3ByQsXyvLYM1JBE4jc4IIdv8haEGfnWUBR/fZpuwFbEHNyjbKAm2uvxx//Ha/brNeKQ3FRBB1WTbCCWKWQLLOtod7WjIzwkiDMvg9Uiwq9qNQgVVSmYqyku1vu5uUkXcggVi9ULjeIXsTJX26GA8zz6D8Y9YtXI6FQkQsz7lCBtUxamccob7sX9cIXcrFk+gPDx2bcny80/jZQMLB0mM1bhqGReNjF5DJSePsiDEdlO1X50Ycn64x7ULeXm2m6Upun3kuW3TWqfaB6JtyI7WNGAQINKHCs1nn945Yf/zEMPVB
C:\windows\tasks\2300726e-d013-4e97-93b8-82cdb2191e24-7.job - C:\Program Files (x86)\CinemaP-1.9cV05.03\2300726e-d013-4e97-93b8-82cdb2191e24-7.exe /rawdata=EIlcdt04eYq+27SF8vdL4pcZ6wc1vW2TZMdeHv8PNncx5/q4ta5i0IIEyGNVbVpJagnU3vv4GnixB0im9DmGO3rq2A6jLNcSTwM3LtmuR2Utb/4zE3IBDK996cdY+VdHxWhug6pP3x/ik8kXZte+VlBlATWNtcUB2sWfHHmyAauqPhiMupmU1rzV9V3rXoTDrY3bhUQzkGHmdueTsqh0zcnox4mSPbCxdsz6LOKV1lYX713+fujjOn3SohMlr3Cx1l/Rq14vP4lL7xDbbayGmRNh0LaQGH/p3rDA9UStELuLt3/7kWvZ8wBaNK0ZijDF3gN8FA9IGA3RXG9s1TQAT0BNJkzLZvLM0t62g24SNZ38kIKw0oo7PDnqz+7RMONkUrOX4b4HisDThUCkoU4BDk8Z4lx96mvANUH3d63k8MUQpjVsu4aJkf0RDbZWmnDuZTgzdNp1dYSMmvauVg7qatC+etcQ9i8CaMLJ2vc7I99RtD9pOMJ33A563gnhNJvyGZMy6DPtfXuFStcvtnB/aO6dLSr1u+772SbY+gHYp2Qj6WNj0ijwWoBomQ5/KJBYnEYD6QfM4Si8a3xfAJhH+lNoZQJNfeKGVT0G7F+qE9EQtbSjaMXSbyjM14MS7PWsdcBcKxWnbvgRPqfXTGzKbTf55qTgWZSRj/Sn8E7vV2nHwR2Oo93FUHT+We4tQPoOWNwPPTk6ovT0RNqKTVHn5LOqJ71JJ0/bpbmIm6vy7y8MvJeCo52ae71JZPLB0xIvlLwzGjmK4u4GLi3AzM5vSjbK0ZEJcqluHoGd208LNtbnIcOQs7ePluK7+Y+s48WHPdFNM6Qp78IHLr8kwD6nBhj21KR1SIVfZhlT4A6dxWeLdbjUxpL35+lZLwU9RhMwHC6ZW9wfFel0gN02WcAkyt8stCK2vExvsLijY4hhBO+VNlidqPAfhIi7ubp6hrvi2fizKxb82L1THNGNzeRJVzvYqDXIYkd3WGk/KeJQN8Uv99Hn774OS4ehcmEdhphqpZpc5jTwzLekw32pogfrx3QitCgDYdM5Tuv9jsXt15SbzmOTevdr4wNSrDAO54zXJz4U0QcaIpJzMTN+RynSw7HnY+eok38EdlqOjix9A3Zv8Mo3lhJZFF+4lNhVNkJrJETQACkvfiTwF/bkK1qJ1uLabIfjbhiOTDcsf5XWsH4Hxr5D7RxZtH59mVbrT+M7qytADzQjtIeNNzZGyQ7wcVS6ABSIA2myvPuc1mYhn904YRxhbEUh9pqsr3BzzyAtaPx3eC1x0guqyYSG+KGqPKL7eXd67cSeeP88qFvx6Jc3SEOmIwCR8WK0tOi3iG2JnDn7Q9AqK0awTG4Ztopq24g0ZO9rxRMMFoABR/ABsrrSfTiKOU2qvjtz3ul+vwGBeAJ5QLP3iNw97rsuvwYEYi7J5FcP4tdpCL5mpBrgRYryLm70Dci1mgkpedhZewEue05kKjSWwltv4OJefb9AZWC4SI5VBbBmimBYys/rCISbc4zcKhLL0U+6NLQwXwlCD6H3B6aUVNpguPNzCeYWYlVPB/bRFLWs5qrkf+mXBpJtIgQZJO9X0OA4MtR/xPIJ+Xmsdz7ARZ/gWurgY7wKXQPzqHNyJqbh+BgXsjxwQZq5fhF40/oyO4aG21fZ14pr7GstbdKy1pvzuq4bkVKeyWukGn9pR4MiMmP7/fzWQlsPaxtXCFYk9CFCDRZBncYme06PskmEhBPgWqMKbarOu7bg2PPZntNK1LbrgZmtRZYeTF9f5eP8ver2iNN4SUfwsGk7wJASzaJ5iobxoMmB2kkXlbXk+mh61sBotViRepkEeojiJ1D/NKEdyIq3UIOCPS9sg48ZzsswCVqUqhtGEyf0Y8FezgHnO3rT/IjOTaoTZurBqZ/g8JVWFQUggVT5h7SSjhNjbev7lMmehnfFt0BeGic5kp7UhLb+9Jo4SlZICyr2CPbOLxSja2wM3Dfz3cXj/DWEteZCNgMo3/ehlh6roo1aFx9ifrY0A7mOxmwnzEBI00NbvhKBR99Y3qX4xM5dUQIVDJuHduSgsVSHxV90RJ+8qQL4l9hmtSyIs9ZFHUpQ4ywNrgqkd2nWMnvwYy/ljn1mWEbUEFgY6S60zW/i83uMO2DupHDTx8ax4R5fedeFrH74Jg3SNGMYHjEGan98EXa8k9w7JywyOTlbR5q/zBXFH0bmrLEaP3gpXoAbTMQf794Zz4wSZ03O+ayJWSDX1yIEbcfY8JV79COWFaH0H3jugxnStXEvoGkCKNlgdG/Ooo5QQDjkL1nPwjYupo8QxEmUI7Cap1UKO3Ml5o2pwPa7dLQS7OzOrPl3zEQBX07qaDIethzxihRKxu60B1pnNn0PmLPv76uwOKytng==
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\FHIGIC.job - C:\Users\smolko\AppData\Roaming\FHIGIC.exe /infocmdline=G9gIEXHW6mWu8vSn94yB5rOOK8JNdniw67mBIZ9VEsBROWmT5FDczDYv2ZQugNeU/zurCbnodA9S1okJHUGhTWEAqpSZ2y0vZkEnRImbKt+V2PTOfRfMIBy8uM1kyo1F2jz3Z2ysWp9L47PHRxuIYzN54G5ukVys0aFYsj7jbMhmdyi9YU0JH32QLlel0hvjacYFbY6CdkdUxxSbi+KjYUBR6nGHouiuv/wUmqldjmdssi/ufHp98yefqnX9TQxqudEgxqQIV2mzHSqYq4MP53wmDd2FCDZRTc3cstVRv/CkKMVmfXelH0HsJLOX+bQnYU3+DRO2u14xWCo4baR4NgFhgJ0Yfti/j+sZHRUOrMvN+bdfg8unD8EELw+g94E2DxwarpSJQO0m0/K3pDPukopIoSsdQxQsJ7zhhIjgoRhxbjit/p6wPhuPNIzSzSQ6I4som91rCHnXmbi6tMXRiaLuyajeVcDZr4M2x0SjJ2GHw3h/ZxAZ7DGKK8b+yAx+
C:\windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\OEM.job - C:\Users\smolko\AppData\Roaming\OEM.exe /infocmdline=bZQk2wXFLMrXkukc43Ixdpvan00z6Atmt9BF0fLRF2XP0AqYAU/vpOC0HddUDNiXoszBzr63v5VXMNB4kEDtulrdWmqakNzPLyXRYXlgHo4pzJ3aVJIKpdsvorcIYhYsK5X9aG6jjsA1DxE28AtQ+GaTPrbLl5J6xPlldwLbl+6/TbfxvMx6qL3tWfOHwhX3nA6ZIwn0DeM02zl2W+esVoM5IQwJv2r0bXmVZhwT7AzFzd/hSRDHxOOUGW7ih2oB8g5hiketo7gIMGneaeP7VlccO1arW7VNu2vOzO/n7Uh9LCGrt7n+M9U3LarnqNh+gEY0v8WRgc2Qp5h+Wrt6DxGLxGWjegj8+BtJEDUOhRuVjlcZkO/Uh9s8bFWAxaUY++LKiuJzWY8AAUU7vV7WQGoKZqt6XCkaGVW7E5k2ThaGtlpvbQ+wuAruKwnmPUkKOBNUE51OH6qXjxbhHDbzSYjbL9TFx3rT5ltK8zEKPjj5pgPFBk6Hut41PL6+y/ys
=========Mozilla firefox=========
ProfilePath - C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://google.com/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll
C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default\extensions\
istart_ffnt@gmail.com
NLQUCQ35648598@KRFIE97629948.com
searchengine@gmail.com
C:\Users\smolko\AppData\Roaming\Mozilla\Firefox\Profiles\qynluvkg.default\searchplugins\
omniboxes.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-15 218784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-15 881880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-15 2333400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2015-03-10 538208]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-15 707800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-08-14 13675736]
"RtHDVBg_MAXX6"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-08-14 1391832]
"WavesSvc"=C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [2014-07-15 604928]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-08-04 2809072]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-06-25 36352]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll [2014-08-06 87536]
"LenovoUtility"=C:\Program Files\Lenovo\LenovoUtility\utility.exe [2014-11-19 10828056]
"AutoStartTransition"=C:\Program Files (x86)\Lenovo\LenovoTransition\TransitionServer.exe [2014-08-14 109840]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-11-19 802800]
"OneKeyOptimizer"=C:\Program Files\Lenovo\OneKey Optimizer\bin\OneKeyOptimizerTray.exe [2014-08-16 461080]
"cpuminer"=C:\windows\system32\cpuminer-gw64.exe [2015-03-11 1316400]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pokki"=C:\Users\smolko\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe [2015-02-05 10354504]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HarmonyPicks"=C:\Program Files (x86)\Lenovo\Harmony\Picks\Lenovo.HarmonyPicks.exe [2014-08-28 1341720]
"HarmonySetting"=C:\Program Files (x86)\Lenovo\Harmony\Setting\Lenovo.HarmonySetting.exe [2014-08-28 2657048]
"Avira Systray"=C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [2014-11-20 126200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-03-15 21:33:12 ----D---- C:\rsit
2015-03-15 21:33:12 ----D---- C:\Program Files\trend micro
2015-03-15 15:55:12 ----A---- C:\windows\SYSWOW64\MrmCoreR.dll
2015-03-15 15:55:12 ----A---- C:\windows\SYSWOW64\explorer.exe
2015-03-15 15:55:12 ----A---- C:\windows\system32\MrmCoreR.dll
2015-03-15 15:55:12 ----A---- C:\windows\explorer.exe
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappprxy.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eapphost.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappgnui.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eappcfg.dll
2015-03-15 15:55:11 ----A---- C:\windows\SYSWOW64\eapp3hst.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\LockScreenContentServer.exe
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappprxy.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eapphost.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappgnui.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eappcfg.dll
2015-03-15 15:55:11 ----A---- C:\windows\system32\eapp3hst.dll
2015-03-15 15:06:12 ----RHD---- C:\MSOCache
2015-03-15 14:59:03 ----D---- C:\ProgramData\Microsoft OneDrive
2015-03-15 14:56:07 ----D---- C:\Program Files\Microsoft Office 15
2015-03-15 12:14:37 ----A---- C:\windows\SYSWOW64\atmfd.dll
2015-03-15 12:14:37 ----A---- C:\windows\system32\atmfd.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\lpk.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\fontsub.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\dciman32.dll
2015-03-15 12:14:36 ----A---- C:\windows\SYSWOW64\atmlib.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\lpk.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\fontsub.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\dciman32.dll
2015-03-15 12:14:36 ----A---- C:\windows\system32\atmlib.dll
2015-03-15 12:14:35 ----A---- C:\windows\system32\rdpcorets.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\ubpm.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\rfxvmt.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\rdpudd.dll
2015-03-15 12:14:34 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys
2015-03-15 12:14:33 ----A---- C:\windows\system32\ntoskrnl.exe
2015-03-15 12:14:32 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-03-15 12:14:32 ----A---- C:\windows\system32\ntdll.dll
2015-03-15 12:14:30 ----A---- C:\windows\system32\win32k.sys
2015-03-15 12:14:28 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-03-15 12:14:28 ----A---- C:\windows\system32\schannel.dll
2015-03-15 12:14:16 ----A---- C:\windows\system32\mshtml.dll
2015-03-15 12:14:14 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-03-15 12:14:10 ----A---- C:\windows\system32\jscript9.dll
2015-03-15 12:14:10 ----A---- C:\windows\system32\ieframe.dll
2015-03-15 12:14:08 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-03-15 12:14:07 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-03-15 12:14:07 ----A---- C:\windows\system32\wininet.dll
2015-03-15 12:14:07 ----A---- C:\windows\system32\iertutil.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-03-15 12:14:06 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-03-15 12:14:06 ----A---- C:\windows\system32\urlmon.dll
2015-03-15 12:14:06 ----A---- C:\windows\system32\inetcomm.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-03-15 12:14:05 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2015-03-15 12:14:05 ----A---- C:\windows\system32\vbscript.dll
2015-03-15 12:14:04 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\MshtmlDac.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\msfeeds.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\iepeers.dll
2015-03-15 12:14:04 ----A---- C:\windows\system32\dxtrans.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-03-15 12:14:03 ----A---- C:\windows\SYSWOW64\iepeers.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\webcheck.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\mshtmled.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\jscript9diag.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\jscript.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\iedkcs32.dll
2015-03-15 12:14:03 ----A---- C:\windows\system32\actxprxy.dll
2015-03-15 12:14:02 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-03-15 12:14:02 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-03-15 12:14:02 ----A---- C:\windows\system32\ieapfltr.dll
2015-03-15 12:13:49 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2015-03-15 12:13:49 ----A---- C:\windows\system32\WindowsCodecs.dll
2015-03-15 12:13:49 ----A---- C:\windows\system32\shell32.dll
2015-03-15 12:13:48 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-03-15 12:13:39 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2015-03-15 12:13:39 ----A---- C:\windows\SYSWOW64\msctf.dll
2015-03-15 12:13:39 ----A---- C:\windows\system32\WMPhoto.dll
2015-03-15 12:13:39 ----A---- C:\windows\system32\msctf.dll
2015-03-15 12:00:24 ----A---- C:\Users\smolko\AppData\Roaming\OEM.exe
2015-03-15 12:00:06 ----D---- C:\Program Files (x86)\43d45ddb-733d-4a4f-9d91-4e3253112627
2015-03-15 12:00:06 ----A---- C:\Users\smolko\AppData\Roaming\FHIGIC.exe
2015-03-15 12:00:02 ----D---- C:\Program Files (x86)\globalUpdate
2015-03-15 11:59:56 ----D---- C:\Program Files (x86)\CinemaP-1.9cV05.03
2015-03-15 11:59:46 ----D---- C:\Users\smolko\AppData\Roaming\cpuminer
2015-03-15 11:59:46 ----D---- C:\ProgramData\IHProtectUpDate
2015-03-15 11:59:41 ----D---- C:\Program Files (x86)\XTab
2015-03-15 11:59:35 ----D---- C:\ProgramData\WindowsMangerProtect
2015-03-15 11:59:25 ----D---- C:\Users\smolko\AppData\Roaming\omniboxes
2015-03-11 17:24:42 ----A---- C:\windows\system32\cpuminer-gw64.exe
2015-02-21 18:58:48 ----A---- C:\windows\SYSWOW64\scesrv.dll
2015-02-21 18:58:48 ----A---- C:\windows\system32\scesrv.dll
2015-02-21 18:58:40 ----A---- C:\windows\system32\wow64.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\user.exe
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-02-21 18:58:39 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-02-21 18:58:39 ----A---- C:\windows\system32\wow64cpu.dll
2015-02-21 18:58:39 ----A---- C:\windows\system32\ntvdm64.dll
2015-02-21 18:58:35 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-02-21 18:58:35 ----A---- C:\windows\system32\drivers\cng.sys
2015-02-21 18:58:35 ----A---- C:\windows\system32\certcli.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\certcli.dll
2015-02-21 18:58:34 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\msaudite.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\lsasrv.dll
2015-02-21 18:58:34 ----A---- C:\windows\system32\adtschema.dll
2015-02-21 18:57:41 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-02-21 18:57:41 ----A---- C:\windows\system32\dxtmsft.dll
2015-02-21 18:57:40 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-02-21 18:57:40 ----A---- C:\windows\system32\ie4uinit.exe
======List of files/folders modified in the last 1 month======
2015-03-15 21:33:12 ----RD---- C:\Program Files
2015-03-15 21:31:56 ----D---- C:\windows\Prefetch
2015-03-15 21:28:52 ----D---- C:\windows\Inf
2015-03-15 21:28:52 ----AD---- C:\windows\System32
2015-03-15 21:28:52 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-03-15 21:28:08 ----D---- C:\windows\Microsoft.NET
2015-03-15 21:25:10 ----D---- C:\windows\Temp
2015-03-15 21:23:14 ----D---- C:\windows\system32\config
2015-03-15 21:23:12 ----D---- C:\windows\WinSxS
2015-03-15 21:23:12 ----D---- C:\windows\SysWOW64
2015-03-15 21:21:57 ----AD---- C:\Windows
2015-03-15 21:21:56 ----D---- C:\windows\system32\drivers
2015-03-15 21:21:56 ----D---- C:\Program Files\Internet Explorer
2015-03-15 21:21:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-03-15 21:21:55 ----RD---- C:\windows\ToastData
2015-03-15 21:21:43 ----D---- C:\windows\system32\MRT
2015-03-15 21:19:34 ----D---- C:\windows\CbsTemp
2015-03-15 21:00:00 ----D---- C:\windows\system32\sru
2015-03-15 18:09:53 ----SD---- C:\Users\smolko\AppData\Roaming\Microsoft
2015-03-15 16:18:30 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-03-15 15:55:02 ----D---- C:\windows\system32\catroot2
2015-03-15 14:59:14 ----D---- C:\windows\system32\Tasks
2015-03-15 14:59:03 ----SHD---- C:\windows\Installer
2015-03-15 14:59:03 ----HD---- C:\ProgramData
2015-03-15 14:58:57 ----D---- C:\ProgramData\Microsoft
2015-03-15 14:58:51 ----RD---- C:\windows\assembly
2015-03-15 14:58:45 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-03-15 14:58:44 ----D---- C:\Program Files (x86)\Common Files
2015-03-15 14:58:43 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-03-15 14:58:32 ----D---- C:\windows\system32\DriverStore
2015-03-15 14:56:20 ----RSD---- C:\windows\Fonts
2015-03-15 12:10:46 ----D---- C:\windows\system32\wdi
2015-03-15 12:07:57 ----SHD---- C:\System Volume Information
2015-03-15 12:02:15 ----RD---- C:\Program Files (x86)
2015-03-15 12:00:41 ----D---- C:\windows\Tasks
2015-03-15 12:00:12 ----D---- C:\Program Files (x86)\Avira
2015-03-04 22:24:42 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-03-03 14:17:35 ----N---- C:\windows\system32\MpSigStub.exe
2015-02-26 21:14:44 ----A---- C:\windows\system32\MRT.exe
2015-02-22 11:37:10 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-21 22:36:57 ----D---- C:\windows\SYSWOW64\en-US
2015-02-21 22:36:57 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-02-21 22:36:57 ----D---- C:\windows\system32\en-US
2015-02-21 22:36:57 ----D---- C:\windows\system32\cs-CZ
2015-02-21 22:36:57 ----D---- C:\windows\apppatch
2015-02-21 18:59:05 ----SHD---- C:\$Recycle.Bin
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 Fastboot;Fastboot; C:\windows\system32\drivers\Fastboot.sys [2014-08-16 69144]
R0 iaStorA;iaStorA; C:\windows\System32\drivers\iaStorA.sys [2014-06-25 670056]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 ACPIVPC;@oem29.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\windows\System32\drivers\AcpiVpc.sys [2014-11-19 35064]
R3 bcbtums;@oem22.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\windows\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM43XX;@oem16.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl63a.sys [2014-11-19 7578328]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\windows\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\windows\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2014-03-18 81920]
R3 btwampfl;@oem22.inf,%btwampfl.ServiceName%;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2014-02-03 166616]
R3 btwaudio;@oem18.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2014-05-13 190168]
R3 btwavdt;@oem18.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\windows\System32\drivers\btwavdt.sys [2014-03-19 229080]
R3 btwl2cap;@oem21.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 dptf_cpu;dptf_cpu; C:\windows\System32\drivers\dptf_cpu.sys [2014-06-10 35136]
R3 dptf_pch;dptf_pch; C:\windows\System32\drivers\dptf_pch.sys [2014-06-10 34072]
R3 esif_lf;esif_lf; C:\windows\System32\drivers\esif_lf.sys [2014-06-10 192624]
R3 iaLPSS_GPIO;@oem6.inf,%iaLPSS_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Driver; C:\windows\System32\drivers\iaLPSS_GPIO.sys [2014-06-11 35832]
R3 iaLPSS_I2C;@oem7.inf,%iaLPSS_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver; C:\windows\System32\drivers\iaLPSS_I2C.sys [2014-06-11 120312]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-07-25 4783472]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-08-19 4026840]
R3 iwdbus;@oem9.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2014-07-14 27000]
R3 KMDFVirtualKbd;@oem33.inf,%KMDFVirtualKbd.SVCDESC%;Lenovo Virtual Keyboard Device; C:\windows\System32\drivers\KMDFVirtualKbd.sys [2014-08-05 22264]
R3 KMDFVirtualMouse;@oem34.inf,%KMDFVirtualMouse.SVCDESC%;Lenovo Virtual Mouse Device; C:\windows\System32\drivers\KMDFVirtualMouse.sys [2014-08-05 21240]
R3 MEIx64;@oem3.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\TeeDriverx64.sys [2014-07-03 125952]
R3 mxtBootBridge;@oem17.inf,%mxtBootBridge.SVCDESC%;maxTouch I2C Boot Bridge Peripheral Service; C:\windows\System32\drivers\mxtBootBridge.sys [2013-12-19 36160]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\System32\drivers\rfcomm.sys [2014-03-18 167424]
R3 rtsuvc;@oem25.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\windows\system32\DRIVERS\rtsuvc.sys [2014-08-30 7239384]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\windows\system32\DRIVERS\WUDFRd.sys [2014-05-31 227840]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\windows\system32\DRIVERS\WUDFRd.sys [2014-05-31 227840]
R3 SynRMIHID;@oem14.inf,%SynRMIHID.SVCDESC%;Synaptics HID Service; C:\windows\system32\DRIVERS\SynRMIHID.sys [2014-08-04 41200]
R3 SynTP;@oem13.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2014-08-04 550128]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 AX88772;@netax88772.inf,%AX88772.DeviceDesc%;ASIX AX88772 USB2.0 to Fast Ethernet Adapter; C:\windows\system32\DRIVERS\ax88772.sys [2013-07-18 113864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 btwrchid;btwrchid; C:\windows\System32\drivers\btwrchid.sys [2014-03-19 38616]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem8.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2014-07-14 38264]
S3 IntcDAud;@oem4.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-07-25 451576]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2014-06-03 977664]
R2 CCSDK;CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [2014-07-10 592880]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-01-02 2169016]
R2 esifsvc;ESIF Upper Framework Service; C:\windows\SysWOW64\esif_uf.exe [2014-06-10 953352]
R2 FastbootService;FastbootService; C:\Program Files\Lenovo\OneKey Optimizer\bin\FbService.exe [2014-08-16 191256]
R2 HarmonyPicksService;HarmonyPicksService; C:\Program Files (x86)\Lenovo\Harmony\Picks\HarmonyPicksService.exe [2014-08-14 17176]
R2 HarmonySettingService;HarmonySettingService; C:\Program Files (x86)\Lenovo\Harmony\Setting\HarmonySettingService.exe [2014-08-14 18712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-06-25 16232]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\windows\system32\igfxCUIService.exe [2014-07-25 324568]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2015-03-10 158816]
R2 Intel(R) ME Service;Intel® ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-07-03 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-07-03 154584]
R2 Lenovo OKO Service;Lenovo OKO Service; C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOUpdataService.exe [2014-07-31 2543896]
R2 Lenovo Settings Service;Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2014-08-07 2013680]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2014-05-22 584960]
R2 LenovoPAWDService;Lenovo PAWD Service; C:\Program Files\Lenovo PhoneCompanion\LPAWDService.exe [2014-11-19 133440]
R2 LenovoSetSvr;LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\x86\LenovoSetSvr.exe [2014-06-19 258544]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [2014-08-02 218440]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-07-03 405976]
R2 OKOControlSvc;OKOControlSvc; C:\Program Files\Lenovo\OneKey Optimizer\bin\OKOControlSvc.exe [2014-08-16 113944]
R2 PaperLookingSrv;PaperLookingSrv; C:\Program Files (x86)\Lenovo\PaperDisplay\PaperLookingSrv.exe [2014-08-12 173336]
R2 PG_Service_Launcher;PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [2014-05-28 524552]
R2 PGService;PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [2014-05-28 167176]
R2 PhoneCompanionPusher;Lenovo PhoneCompanionPusher Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [2014-11-19 321520]
R2 PLHotkeyService;PLHotkeyService; C:\Program Files (x86)\Lenovo\PaperDisplay\PLHotkeyService.exe [2014-08-12 25368]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2014-08-04 190704]
R2 VeriFaceSrv;VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [2014-11-19 68880]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-04-09 174368]
S2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-11-20 166192]
S2 BcmBtRSupport;@oem22.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\windows\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-15 68608]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-18 107912]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-21 267440]
S3 AVControlCenter;AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [2014-08-06 599024]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-07-25 274736]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-15 68608]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-18 107912]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-05-13 887256]
S3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [2014-06-03 533760]
S3 LENOVO.CAMMUTE;Lenovo AVFramework Camera Privacy Controller; C:\Program Files\Lenovo\Communications Utility\cammute.exe [2014-08-06 525296]
S3 LENOVO.TPKNRSVC;Lenovo AVFramework Microphone Volume Controller and Dolby Interface; C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe [2014-08-06 535024]
S3 LENOVO.TVTVCAM;Lenovo AVFramework Virtual Camera Controller Service; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-08-06 727536]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-17 114800]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneCompanionVap;Lenovo PhoneCompanionVap Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [2014-11-19 338416]
-----------------EOF-----------------