Virus - trojský kůň
Napsal: 10 lis 2015 20:06
Dobrý den, prosím o pomoc. Od mého přítele mi přišel přes skype soubor s koncovkou .vbs Ruce byly rychlejší než hlava a já daný soubor stáhla. Od té doby se mi sama zapínala webcamera a bylo vidět, že se někdo pokouší dostat se na můj účet na Facebooku, zjevovaly se mi tu hesla, počítač si prostě dělal co chtěl. Projela jsem počítač windowd defenderem - nic, AVG - nic až nakonec jsem spustila online scan přes ESET našlo a odstranilo to 7 souborů napadených nějakým trojským koněm. Od té doby je vše v pořádku, nezapíná se webcamera ani se mi nikdo nepokouší dostat do PC avšak po zapnutí PC naskočí hláška: Soubor scriptu C:/Users/appData/Roaming/Microsoft/PetraRolincová.vbs nebyl nalezen.
To je problém číslo 1.
Další problém je že mi nejde připojit se k internetu doma. Máme 2 wi-fi. Jedna je v obýváku, jenže má slabý signál a do mého pokoje nedosáhne, mám tedy v pokoji další router, do dnešního dne jsem se připojovala naprosto v pohodě, ale dnes po připojení mi to píše: Systému windows se nepodařilo automaticky zjistit nastavení proxy serveru sítě.
Jsem PC laik nedokáži tedy odhadnout, zda tyto problémy spolu nějak souvisí nebo ne. Přikládám Log RSIT.
Logfile of random's system information tool 1.10 (written by random/random)
Run by User at 2015-11-10 19:56:27
Microsoft Windows 8.1
System drive C: has 302 GB (70%) free of 433 GB
Total RAM: 3979 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:05:14, on 10.11.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
C:\windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
C:\Model\cmssservice\cmssservice.exe
C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\User.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 7886F6223B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [Lenovo Recommends] C:\Program Files (x86)\Lenovo\Lenovo Recommends\Lenovo Recommends.exe -s
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\RunOnce: [Application Restart #3] C:\Users\User\AppData\Local\Pokki\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\User\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O4 - Global Startup: addToTrustedSites.vbs
O4 - Global Startup: cmssservice.lnk = C:\Model\cmssservice\cmssservice.exe
O4 - Global Startup: runModel.vbs
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.http://127.0.0.1
O15 - Trusted Zone: *.http://localhost
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: LenovoRecommends.AppService - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: LsvUIService - Lenovo - C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TESHelper - Lenovo - c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ymc - Lenovo - C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 13267 bytes
======Listing Processes======
wininit.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\igfxCUIService.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\System32\svchost.exe -k utcsvc
dashost.exe {744672ce-bc31-44da-b39f87603c1b642c}
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe"
"c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\sqlservr.exe" -sELISKA4CLIENT
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\eLiska4\eLiska.exe" preloadbackground
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8f80aaca-a11d-4a3c-8fd4-aeee2676613a -SystemEventPortName:HostProcess-c6e04c27-d805-4f02-9a05-1a45c1663325 -IoCancelEventPortName:HostProcess-552a54dd-977d-4c1a-9bcc-b4d92f4827e6 -NonStateChangingEventPortName:HostProcess-f0a4dff4-1c5f-4d00-b388-908f9486f18c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:770ca881-dd77-41a5-9709-9a62e05706df -DeviceGroupId:WudfDefaultDevicePool
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
taskeng.exe {A7F1817E-ED8C-4BB9-84B7-9D66A4EDE494}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\windows\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\windows\Explorer.EXE
igfxHK.exe
igfxTray.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
ClassicStartMenu.exe -startup
C:\Windows\System32\skydrive.exe -Embedding
/QuitInfo:0000000000000DCC;0000000000000E8C;
/loadhooks /Parent:0000000000001bc0
"C:\windows\system32\igfxEM.exe" -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=7772 --on-initialized-event-handle=432 --parent-handle=348
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="980.0.738074802\1184856940" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,20,45 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3496 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.2.39987973\1567063942" --font-cache-shared-handle=2480 /prefetch:673131151
"C:\windows\system32\GWX\GWX.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Windows\RTFTrack.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe" AutoRun
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
C:\windows\system32\cmd.exe /c "C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe" --parent-window=0 chrome-extension://fkepacicchenbjecpbpbclokcabebhah/ < \\.\pipe\chrome.nativeMessaging.in.7a034dd18f091b4a > \\.\pipe\chrome.nativeMessaging.out.7a034dd18f091b4a
\??\C:\windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe" --parent-window=0 chrome-extension://fkepacicchenbjecpbpbclokcabebhah/
"C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe"
C:\windows\SysWOW64\UMonit64.exe
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe"
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe"
"C:\Windows\System32\StikyNot.exe"
"C:\Model\cmssservice\cmssservice.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe" /AutoRun
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe" -run
"C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.15.976197731\293092525" --font-cache-shared-handle=7128 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.21.811237121\167683065" --font-cache-shared-handle=5672 /prefetch:673131151
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 83171C71-E091-D03D-F8F7-742AA1584E8A -Reinvoke
"C:\Users\User\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.22.1285438626\847427506" --font-cache-shared-handle=7040 /prefetch:673131151
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-08-09 809408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12 2134656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-08-09 487360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-08-09 687040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12 1725056]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-08-09 442816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-08-09 809408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-08-09 687040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-02-24 13667032]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtsFT"=C:\windows\RTFTrack.exe [2014-01-21 6340312]
"AutoStartTransition"=C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [2014-08-12 294672]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-08-12 836592]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-08-12 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-08-12 10841584]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2015-08-09 161728]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-10-16 170256]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2014-02-26 134784]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"iCloudServices"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2015-10-21 60688]
"iCloudDrive"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [2015-10-21 103696]
"iCloudPhotos"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [2015-10-21 349968]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2014-10-29 479744]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Application Restart #3"=C:\Users\User\AppData\Local\Pokki\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend=C:\Users\User\AppData\Local\Pokki\Engine\inspector --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Lenovo Recommends"=C:\Program Files (x86)\Lenovo\Lenovo Recommends\Lenovo Recommends.exe [2014-01-10 119280]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2014-02-26 134784]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
addToTrustedSites.vbs
cmssservice.lnk - C:\Model\cmssservice\cmssservice.exe
runModel.vbs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDWFP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"midi4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-11-10 19:56:28 ----D---- C:\Program Files\trend micro
2015-11-10 19:56:27 ----D---- C:\rsit
2015-11-10 13:07:19 ----RD---- C:\Program Files (x86)\Skype
2015-11-10 11:06:36 ----D---- C:\Program Files (x86)\ESET
2015-11-09 21:53:18 ----D---- C:\Users\User\AppData\Roaming\AVG
2015-11-09 21:51:38 ----D---- C:\Users\User\AppData\Roaming\TuneUp Software
2015-11-09 21:51:14 ----HD---- C:\$AVG
2015-11-09 21:49:19 ----D---- C:\ProgramData\MFAData
2015-11-09 21:48:07 ----HD---- C:\ProgramData\Common Files
2015-11-09 21:48:06 ----D---- C:\ProgramData\Avg
2015-11-09 21:31:27 ----D---- C:\ProgramData\STOPzilla!
2015-11-09 21:31:22 ----D---- C:\Program Files (x86)\iS3
2015-11-02 19:20:33 ----D---- C:\Program Files (x86)\EvilLyrics
2015-10-24 10:34:10 ----D---- C:\Program Files\iPod
2015-10-24 10:34:10 ----D---- C:\Program Files (x86)\iTunes
2015-10-24 10:34:07 ----D---- C:\Program Files\iTunes
2015-10-22 16:08:17 ----HD---- C:\ProgramData\CanonBJ
2015-10-22 16:07:18 ----D---- C:\windows\LastGood.Tmp
2015-10-22 14:36:10 ----RD---- C:\Users\User\AppData\Roaming\Brother
2015-10-15 14:57:21 ----A---- C:\windows\system32\devinv.dll
2015-10-15 14:57:21 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 14:57:20 ----A---- C:\windows\system32\invagent.dll
2015-10-15 14:57:19 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 14:57:19 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 14:57:18 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 14:57:18 ----A---- C:\windows\system32\acmigration.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNHMCA.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNC495U.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNC495L.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNHMCA6.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495L.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495I.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495C.dll
2015-10-15 12:54:36 ----A---- C:\windows\system32\CNMLMA9.DLL
2015-10-14 13:44:49 ----A---- C:\windows\SYSWOW64\d2d1.dll
2015-10-14 13:44:30 ----A---- C:\windows\system32\d2d1.dll
2015-10-14 13:42:51 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 13:42:21 ----A---- C:\windows\system32\advapi32.dll
2015-10-14 13:41:20 ----A---- C:\windows\SYSWOW64\advapi32.dll
2015-10-14 13:41:07 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 13:39:58 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:39:58 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:39:58 ----A---- C:\windows\system32\NcdAutoSetup.dll
2015-10-14 13:39:58 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:39:54 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:39:49 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:39:44 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 10:56:24 ----A---- C:\windows\system32\shell32.dll
2015-10-14 10:56:16 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 10:56:13 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 10:56:12 ----A---- C:\windows\system32\winresume.exe
2015-10-14 10:56:12 ----A---- C:\windows\system32\winload.exe
2015-10-14 10:56:11 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\fveapi.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\bdesvc.dll
2015-10-14 10:55:46 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 10:55:43 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 10:55:20 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 10:55:17 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 10:55:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 10:55:14 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 10:55:12 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 10:55:12 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 10:55:11 ----A---- C:\windows\system32\wininet.dll
2015-10-14 10:55:10 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 10:55:10 ----A---- C:\windows\system32\ieui.dll
2015-10-14 10:55:10 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 10:55:09 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 10:55:09 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 10:55:08 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 10:55:08 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 10:55:08 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 10:55:07 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 10:55:04 ----A---- C:\windows\system32\jscript.dll
2015-10-14 10:55:03 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 10:55:00 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 10:54:59 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 10:54:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 10:54:52 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 10:54:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 10:54:49 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 10:54:39 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 10:54:39 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 10:54:37 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 10:54:33 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 10:54:28 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 10:54:26 ----A---- C:\windows\system32\inetcomm.dll
2015-10-14 10:54:14 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 10:54:14 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2015-10-14 10:54:12 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 10:54:11 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 10:54:08 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 10:51:58 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 10:51:58 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 10:51:58 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 10:51:57 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 10:51:57 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\WUSettingsProvider.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 10:51:56 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-11 11:51:19 ----D---- C:\Program Files (x86)\Free AVI to MP4 Converter
2015-10-11 11:02:20 ----D---- C:\Users\User\AppData\Roaming\FlashIntegro
2015-10-11 11:01:42 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2015-10-11 11:01:42 ----A---- C:\windows\SYSWOW64\msvcp71.dll
2015-10-11 11:01:40 ----A---- C:\windows\SYSWOW64\msxml3a.dll
2015-10-11 11:01:40 ----A---- C:\windows\SYSWOW64\Lagarith.dll
2015-10-11 11:01:39 ----A---- C:\windows\SYSWOW64\vp6vfw.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\xvidvfw.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\xvidcore.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\mpg4c32.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\mcdvd_32.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\divx.dll
2015-10-11 10:41:22 ----D---- C:\ProgramData\Pinnacle
2015-10-11 10:18:26 ----D---- C:\Users\User\AppData\Roaming\DVDVideoSoft
2015-10-11 10:16:33 ----D---- C:\Program Files (x86)\WiliSoft Video Splitter
======List of files/folders modified in the last 1 month======
2015-11-10 20:00:02 ----D---- C:\windows\system32\sru
2015-11-10 19:56:41 ----D---- C:\windows\Prefetch
2015-11-10 19:56:28 ----RD---- C:\Program Files
2015-11-10 19:49:52 ----D---- C:\windows\Temp
2015-11-10 19:39:36 ----D---- C:\windows\system32\NDF
2015-11-10 19:31:27 ----D---- C:\windows\Inf
2015-11-10 18:16:17 ----D---- C:\Program Files (x86)\eLiska4
2015-11-10 17:07:35 ----D---- C:\Users\User\AppData\Roaming\Skype
2015-11-10 15:18:24 ----SHD---- C:\windows\Installer
2015-11-10 15:18:24 ----D---- C:\ProgramData\Skype
2015-11-10 15:13:22 ----SD---- C:\Users\User\AppData\Roaming\Microsoft
2015-11-10 13:45:39 ----D---- C:\Users\User\AppData\Roaming\vlc
2015-11-10 13:07:21 ----D---- C:\Program Files (x86)\Common Files
2015-11-10 13:07:19 ----RD---- C:\Program Files (x86)
2015-11-10 13:06:45 ----D---- C:\windows\system32\Tasks
2015-11-10 11:11:25 ----AD---- C:\Windows
2015-11-10 11:06:37 ----SD---- C:\windows\Downloaded Program Files
2015-11-10 09:48:02 ----RAD---- C:\windows\System32
2015-11-10 09:48:02 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-10 03:46:21 ----D---- C:\windows\Microsoft.NET
2015-11-09 23:16:13 ----D---- C:\Program Files\Common Files
2015-11-09 23:13:43 ----HD---- C:\windows\ELAMBKUP
2015-11-09 23:13:43 ----D---- C:\windows\system32\drivers
2015-11-09 22:25:47 ----D---- C:\INVOZ
2015-11-09 22:24:06 ----D---- C:\windows\SysWOW64
2015-11-09 21:57:13 ----HD---- C:\ProgramData
2015-11-09 21:57:13 ----D---- C:\windows\Tasks
2015-11-09 21:30:43 ----SHD---- C:\System Volume Information
2015-11-05 09:26:34 ----HD---- C:\Program Files\WindowsApps
2015-11-05 09:26:34 ----D---- C:\windows\AppReadiness
2015-10-30 10:42:23 ----D---- C:\Users\User\AppData\Roaming\Apple Computer
2015-10-30 10:32:16 ----D---- C:\Program Files\Common Files\Apple
2015-10-24 11:05:03 ----D---- C:\windows\system32\wdi
2015-10-22 16:07:39 ----RSD---- C:\windows\Media
2015-10-22 16:07:21 ----D---- C:\windows\twain_32
2015-10-22 14:59:58 ----A---- C:\windows\BRWMARK.INI
2015-10-21 11:27:16 ----D---- C:\windows\system32\config
2015-10-21 10:15:42 ----D---- C:\windows\WinSxS
2015-10-20 18:59:04 ----D---- C:\windows\CbsTemp
2015-10-20 16:50:07 ----SD---- C:\windows\system32\CompatTel
2015-10-20 16:50:07 ----D---- C:\windows\system32\appraiser
2015-10-20 16:50:07 ----D---- C:\windows\apppatch
2015-10-17 14:31:58 ----SHD---- C:\$RECYCLE.BIN
2015-10-16 12:28:13 ----D---- C:\windows\system32\MRT
2015-10-16 12:20:05 ----A---- C:\windows\system32\MRT.exe
2015-10-16 05:51:29 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-15 18:52:08 ----D---- C:\windows\rescache
2015-10-15 12:54:43 ----D---- C:\windows\system32\DriverStore
2015-10-14 12:48:19 ----D---- C:\ProgramData\Lenovo
2015-10-14 12:47:59 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-10-14 12:47:55 ----D---- C:\Program Files (x86)\Lenovo
2015-10-14 12:35:35 ----D---- C:\windows\system32\en-US
2015-10-14 12:35:35 ----D---- C:\windows\system32\cs-CZ
2015-10-14 12:35:35 ----D---- C:\windows\system32\CodeIntegrity
2015-10-14 12:35:34 ----RD---- C:\windows\ToastData
2015-10-14 12:35:32 ----D---- C:\windows\system32\Boot
2015-10-14 12:35:32 ----D---- C:\Program Files\Internet Explorer
2015-10-14 12:35:32 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 12:35:24 ----D---- C:\ProgramData\Microsoft Help
2015-10-14 12:33:37 ----A---- C:\windows\win.ini
2015-10-14 10:50:14 ----D---- C:\windows\system32\catroot2
2015-10-11 10:59:33 ----RSD---- C:\windows\Fonts
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 BTATH_BUS;@oem15.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\windows\System32\drivers\btath_bus.sys [2014-02-26 35016]
R1 pfmfs_853;pfmfs_853; C:\windows\system32\Drivers\pfmfs_853.sys [2013-04-10 251128]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 ACPIVPC;@oem40.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\windows\System32\drivers\AcpiVpc.sys [2014-08-12 35576]
R3 AthBTPort;@oem18.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2014-02-26 89800]
R3 athr;@oem12.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athwbx.sys [2014-03-07 3892224]
R3 BTATH_A2DP;@oem17.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2014-02-26 355528]
R3 btath_avdt;@oem17.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\windows\system32\drivers\btath_avdt.sys [2014-02-26 118984]
R3 BTATH_HCRP;@oem20.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\windows\System32\drivers\btath_hcrp.sys [2014-02-26 179432]
R3 BTATH_LWFLT;@oem22.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2014-02-26 77464]
R3 BTATH_RCP;@oem24.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\windows\System32\drivers\btath_rcp.sys [2014-02-26 137928]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2014-02-26 598216]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\windows\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\windows\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-03-07 3729920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-03-04 3882456]
R3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-03-07 450520]
R3 iwdbus;@oem8.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2014-03-01 27032]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2013-12-18 839896]
R3 rtsuvc;@oem28.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\windows\system32\DRIVERS\rtsuvc.sys [2014-01-21 9105624]
R3 SmbDrvI;SmbDrvI; C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2014-02-25 34544]
R3 SynTP;@oem14.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2014-02-25 532720]
R3 TXEIx64;@oem4.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 GeneStor;@oem10.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\windows\System32\drivers\GeneStor.sys [2014-04-17 111336]
S3 intaud_WaveExtensible;@oem7.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2014-03-01 38296]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 USBAAPL64;@oem42.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2015-06-10 54784]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2014-10-29 44544]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S4 RsFx0153;RsFx0153 Driver; C:\windows\system32\DRIVERS\RsFx0153.sys [2015-03-29 322736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-10-07 77104]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2014-02-26 319104]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2014-10-29 38792]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\windows\system32\igfxCUIService.exe [2014-03-12 282096]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-02 733696]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2014-05-22 584960]
R2 LenovoRecommends.AppService;LenovoRecommends.AppService; C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe [2014-01-10 19440]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [2014-08-12 198192]
R2 LsvUIService;LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [2014-08-12 70416]
R2 LUService;LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [2014-02-18 38896]
R2 MSSQL$ELISKA4CLIENT;SQL Server (ELISKA4CLIENT); c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\sqlservr.exe [2015-03-29 62382256]
R2 PhoneCompanionPusher;Lenovo PhoneCompanionPusher Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [2014-08-12 288240]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-04-24 390632]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-01 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-03-12 279024]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-01 107848]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-02 822232]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-10-16 644880]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-18 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PhoneCompanionVap;Lenovo PhoneCompanionVap Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [2014-08-12 308720]
S3 TESHelper;TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [2014-08-12 104696]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
S4 SQLAgent$ELISKA4CLIENT;SQL Server Agent (ELISKA4CLIENT); c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\SQLAGENT.EXE [2015-03-29 442536]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2015-03-29 278704]
-----------------EOF-----------------
To je problém číslo 1.
Další problém je že mi nejde připojit se k internetu doma. Máme 2 wi-fi. Jedna je v obýváku, jenže má slabý signál a do mého pokoje nedosáhne, mám tedy v pokoji další router, do dnešního dne jsem se připojovala naprosto v pohodě, ale dnes po připojení mi to píše: Systému windows se nepodařilo automaticky zjistit nastavení proxy serveru sítě.
Jsem PC laik nedokáži tedy odhadnout, zda tyto problémy spolu nějak souvisí nebo ne. Přikládám Log RSIT.
Logfile of random's system information tool 1.10 (written by random/random)
Run by User at 2015-11-10 19:56:27
Microsoft Windows 8.1
System drive C: has 302 GB (70%) free of 433 GB
Total RAM: 3979 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:05:14, on 10.11.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
C:\windows\SysWOW64\UMonit64.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
C:\Model\cmssservice\cmssservice.exe
C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\User.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 7886F6223B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [Lenovo Recommends] C:\Program Files (x86)\Lenovo\Lenovo Recommends\Lenovo Recommends.exe -s
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\RunOnce: [Application Restart #3] C:\Users\User\AppData\Local\Pokki\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\User\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O4 - Global Startup: addToTrustedSites.vbs
O4 - Global Startup: cmssservice.lnk = C:\Model\cmssservice\cmssservice.exe
O4 - Global Startup: runModel.vbs
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.http://127.0.0.1
O15 - Trusted Zone: *.http://localhost
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: LenovoRecommends.AppService - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: LsvUIService - Lenovo - C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TESHelper - Lenovo - c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ymc - Lenovo - C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 13267 bytes
======Listing Processes======
wininit.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\igfxCUIService.exe
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\windows\System32\svchost.exe -k utcsvc
dashost.exe {744672ce-bc31-44da-b39f87603c1b642c}
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe"
"c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\sqlservr.exe" -sELISKA4CLIENT
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\eLiska4\eLiska.exe" preloadbackground
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8f80aaca-a11d-4a3c-8fd4-aeee2676613a -SystemEventPortName:HostProcess-c6e04c27-d805-4f02-9a05-1a45c1663325 -IoCancelEventPortName:HostProcess-552a54dd-977d-4c1a-9bcc-b4d92f4827e6 -NonStateChangingEventPortName:HostProcess-f0a4dff4-1c5f-4d00-b388-908f9486f18c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:770ca881-dd77-41a5-9709-9a62e05706df -DeviceGroupId:WudfDefaultDevicePool
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
taskeng.exe {A7F1817E-ED8C-4BB9-84B7-9D66A4EDE494}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\windows\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\windows\Explorer.EXE
igfxHK.exe
igfxTray.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
ClassicStartMenu.exe -startup
C:\Windows\System32\skydrive.exe -Embedding
/QuitInfo:0000000000000DCC;0000000000000E8C;
/loadhooks /Parent:0000000000001bc0
"C:\windows\system32\igfxEM.exe" -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=7772 --on-initialized-event-handle=432 --parent-handle=348
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="980.0.738074802\1184856940" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,20,45 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3496 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.2.39987973\1567063942" --font-cache-shared-handle=2480 /prefetch:673131151
"C:\windows\system32\GWX\GWX.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Windows\RTFTrack.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe" AutoRun
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
C:\windows\system32\cmd.exe /c "C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe" --parent-window=0 chrome-extension://fkepacicchenbjecpbpbclokcabebhah/ < \\.\pipe\chrome.nativeMessaging.in.7a034dd18f091b4a > \\.\pipe\chrome.nativeMessaging.out.7a034dd18f091b4a
\??\C:\windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe" --parent-window=0 chrome-extension://fkepacicchenbjecpbpbclokcabebhah/
"C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe"
C:\windows\SysWOW64\UMonit64.exe
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe"
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe"
"C:\Windows\System32\StikyNot.exe"
"C:\Model\cmssservice\cmssservice.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe" /AutoRun
"C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe" -run
"C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.15.976197731\293092525" --font-cache-shared-handle=7128 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.21.811237121\167683065" --font-cache-shared-handle=5672 /prefetch:673131151
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 83171C71-E091-D03D-F8F7-742AA1584E8A -Reinvoke
"C:\Users\User\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="980.22.1285438626\847427506" --font-cache-shared-handle=7040 /prefetch:673131151
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-08-09 809408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12 2134656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-08-09 487360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-08-09 687040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12 1725056]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-08-09 442816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-08-09 809408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-08-09 687040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-02-24 13667032]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-02-25 1381744]
"RtsFT"=C:\windows\RTFTrack.exe [2014-01-21 6340312]
"AutoStartTransition"=C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [2014-08-12 294672]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-08-12 836592]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-08-12 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-08-12 10841584]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2015-08-09 161728]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-10-16 170256]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2014-02-26 134784]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"iCloudServices"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2015-10-21 60688]
"iCloudDrive"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [2015-10-21 103696]
"iCloudPhotos"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [2015-10-21 349968]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2014-10-29 479744]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Application Restart #3"=C:\Users\User\AppData\Local\Pokki\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend=C:\Users\User\AppData\Local\Pokki\Engine\inspector --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Lenovo Recommends"=C:\Program Files (x86)\Lenovo\Lenovo Recommends\Lenovo Recommends.exe [2014-01-10 119280]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2014-02-26 134784]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
addToTrustedSites.vbs
cmssservice.lnk - C:\Model\cmssservice\cmssservice.exe
runModel.vbs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDWFP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"midi4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-11-10 19:56:28 ----D---- C:\Program Files\trend micro
2015-11-10 19:56:27 ----D---- C:\rsit
2015-11-10 13:07:19 ----RD---- C:\Program Files (x86)\Skype
2015-11-10 11:06:36 ----D---- C:\Program Files (x86)\ESET
2015-11-09 21:53:18 ----D---- C:\Users\User\AppData\Roaming\AVG
2015-11-09 21:51:38 ----D---- C:\Users\User\AppData\Roaming\TuneUp Software
2015-11-09 21:51:14 ----HD---- C:\$AVG
2015-11-09 21:49:19 ----D---- C:\ProgramData\MFAData
2015-11-09 21:48:07 ----HD---- C:\ProgramData\Common Files
2015-11-09 21:48:06 ----D---- C:\ProgramData\Avg
2015-11-09 21:31:27 ----D---- C:\ProgramData\STOPzilla!
2015-11-09 21:31:22 ----D---- C:\Program Files (x86)\iS3
2015-11-02 19:20:33 ----D---- C:\Program Files (x86)\EvilLyrics
2015-10-24 10:34:10 ----D---- C:\Program Files\iPod
2015-10-24 10:34:10 ----D---- C:\Program Files (x86)\iTunes
2015-10-24 10:34:07 ----D---- C:\Program Files\iTunes
2015-10-22 16:08:17 ----HD---- C:\ProgramData\CanonBJ
2015-10-22 16:07:18 ----D---- C:\windows\LastGood.Tmp
2015-10-22 14:36:10 ----RD---- C:\Users\User\AppData\Roaming\Brother
2015-10-15 14:57:21 ----A---- C:\windows\system32\devinv.dll
2015-10-15 14:57:21 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 14:57:20 ----A---- C:\windows\system32\invagent.dll
2015-10-15 14:57:19 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 14:57:19 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 14:57:18 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 14:57:18 ----A---- C:\windows\system32\acmigration.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNHMCA.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNC495U.dll
2015-10-15 12:54:43 ----A---- C:\windows\SYSWOW64\CNC495L.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNHMCA6.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495L.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495I.dll
2015-10-15 12:54:43 ----A---- C:\windows\system32\CNC495C.dll
2015-10-15 12:54:36 ----A---- C:\windows\system32\CNMLMA9.DLL
2015-10-14 13:44:49 ----A---- C:\windows\SYSWOW64\d2d1.dll
2015-10-14 13:44:30 ----A---- C:\windows\system32\d2d1.dll
2015-10-14 13:42:51 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 13:42:21 ----A---- C:\windows\system32\advapi32.dll
2015-10-14 13:41:20 ----A---- C:\windows\SYSWOW64\advapi32.dll
2015-10-14 13:41:07 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 13:39:58 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:39:58 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:39:58 ----A---- C:\windows\system32\NcdAutoSetup.dll
2015-10-14 13:39:58 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:39:57 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 13:39:56 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 13:39:54 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 13:39:50 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 13:39:49 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 13:39:44 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 10:56:24 ----A---- C:\windows\system32\shell32.dll
2015-10-14 10:56:16 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 10:56:13 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 10:56:12 ----A---- C:\windows\system32\winresume.exe
2015-10-14 10:56:12 ----A---- C:\windows\system32\winload.exe
2015-10-14 10:56:11 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\fveapi.dll
2015-10-14 10:56:11 ----A---- C:\windows\system32\bdesvc.dll
2015-10-14 10:55:46 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 10:55:43 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 10:55:20 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 10:55:17 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 10:55:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 10:55:14 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 10:55:12 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 10:55:12 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 10:55:11 ----A---- C:\windows\system32\wininet.dll
2015-10-14 10:55:10 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 10:55:10 ----A---- C:\windows\system32\ieui.dll
2015-10-14 10:55:10 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 10:55:09 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 10:55:09 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 10:55:08 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 10:55:08 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 10:55:08 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 10:55:07 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 10:55:04 ----A---- C:\windows\system32\jscript.dll
2015-10-14 10:55:03 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 10:55:00 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 10:54:59 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 10:54:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 10:54:52 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 10:54:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 10:54:49 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 10:54:39 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 10:54:39 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 10:54:37 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 10:54:33 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 10:54:28 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 10:54:26 ----A---- C:\windows\system32\inetcomm.dll
2015-10-14 10:54:14 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 10:54:14 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2015-10-14 10:54:12 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 10:54:11 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 10:54:08 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 10:51:58 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 10:51:58 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 10:51:58 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 10:51:57 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 10:51:57 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\WUSettingsProvider.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 10:51:57 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 10:51:56 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-11 11:51:19 ----D---- C:\Program Files (x86)\Free AVI to MP4 Converter
2015-10-11 11:02:20 ----D---- C:\Users\User\AppData\Roaming\FlashIntegro
2015-10-11 11:01:42 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2015-10-11 11:01:42 ----A---- C:\windows\SYSWOW64\msvcp71.dll
2015-10-11 11:01:40 ----A---- C:\windows\SYSWOW64\msxml3a.dll
2015-10-11 11:01:40 ----A---- C:\windows\SYSWOW64\Lagarith.dll
2015-10-11 11:01:39 ----A---- C:\windows\SYSWOW64\vp6vfw.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\xvidvfw.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\xvidcore.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\mpg4c32.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\mcdvd_32.dll
2015-10-11 11:01:38 ----A---- C:\windows\SYSWOW64\divx.dll
2015-10-11 10:41:22 ----D---- C:\ProgramData\Pinnacle
2015-10-11 10:18:26 ----D---- C:\Users\User\AppData\Roaming\DVDVideoSoft
2015-10-11 10:16:33 ----D---- C:\Program Files (x86)\WiliSoft Video Splitter
======List of files/folders modified in the last 1 month======
2015-11-10 20:00:02 ----D---- C:\windows\system32\sru
2015-11-10 19:56:41 ----D---- C:\windows\Prefetch
2015-11-10 19:56:28 ----RD---- C:\Program Files
2015-11-10 19:49:52 ----D---- C:\windows\Temp
2015-11-10 19:39:36 ----D---- C:\windows\system32\NDF
2015-11-10 19:31:27 ----D---- C:\windows\Inf
2015-11-10 18:16:17 ----D---- C:\Program Files (x86)\eLiska4
2015-11-10 17:07:35 ----D---- C:\Users\User\AppData\Roaming\Skype
2015-11-10 15:18:24 ----SHD---- C:\windows\Installer
2015-11-10 15:18:24 ----D---- C:\ProgramData\Skype
2015-11-10 15:13:22 ----SD---- C:\Users\User\AppData\Roaming\Microsoft
2015-11-10 13:45:39 ----D---- C:\Users\User\AppData\Roaming\vlc
2015-11-10 13:07:21 ----D---- C:\Program Files (x86)\Common Files
2015-11-10 13:07:19 ----RD---- C:\Program Files (x86)
2015-11-10 13:06:45 ----D---- C:\windows\system32\Tasks
2015-11-10 11:11:25 ----AD---- C:\Windows
2015-11-10 11:06:37 ----SD---- C:\windows\Downloaded Program Files
2015-11-10 09:48:02 ----RAD---- C:\windows\System32
2015-11-10 09:48:02 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-10 03:46:21 ----D---- C:\windows\Microsoft.NET
2015-11-09 23:16:13 ----D---- C:\Program Files\Common Files
2015-11-09 23:13:43 ----HD---- C:\windows\ELAMBKUP
2015-11-09 23:13:43 ----D---- C:\windows\system32\drivers
2015-11-09 22:25:47 ----D---- C:\INVOZ
2015-11-09 22:24:06 ----D---- C:\windows\SysWOW64
2015-11-09 21:57:13 ----HD---- C:\ProgramData
2015-11-09 21:57:13 ----D---- C:\windows\Tasks
2015-11-09 21:30:43 ----SHD---- C:\System Volume Information
2015-11-05 09:26:34 ----HD---- C:\Program Files\WindowsApps
2015-11-05 09:26:34 ----D---- C:\windows\AppReadiness
2015-10-30 10:42:23 ----D---- C:\Users\User\AppData\Roaming\Apple Computer
2015-10-30 10:32:16 ----D---- C:\Program Files\Common Files\Apple
2015-10-24 11:05:03 ----D---- C:\windows\system32\wdi
2015-10-22 16:07:39 ----RSD---- C:\windows\Media
2015-10-22 16:07:21 ----D---- C:\windows\twain_32
2015-10-22 14:59:58 ----A---- C:\windows\BRWMARK.INI
2015-10-21 11:27:16 ----D---- C:\windows\system32\config
2015-10-21 10:15:42 ----D---- C:\windows\WinSxS
2015-10-20 18:59:04 ----D---- C:\windows\CbsTemp
2015-10-20 16:50:07 ----SD---- C:\windows\system32\CompatTel
2015-10-20 16:50:07 ----D---- C:\windows\system32\appraiser
2015-10-20 16:50:07 ----D---- C:\windows\apppatch
2015-10-17 14:31:58 ----SHD---- C:\$RECYCLE.BIN
2015-10-16 12:28:13 ----D---- C:\windows\system32\MRT
2015-10-16 12:20:05 ----A---- C:\windows\system32\MRT.exe
2015-10-16 05:51:29 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-15 18:52:08 ----D---- C:\windows\rescache
2015-10-15 12:54:43 ----D---- C:\windows\system32\DriverStore
2015-10-14 12:48:19 ----D---- C:\ProgramData\Lenovo
2015-10-14 12:47:59 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-10-14 12:47:55 ----D---- C:\Program Files (x86)\Lenovo
2015-10-14 12:35:35 ----D---- C:\windows\system32\en-US
2015-10-14 12:35:35 ----D---- C:\windows\system32\cs-CZ
2015-10-14 12:35:35 ----D---- C:\windows\system32\CodeIntegrity
2015-10-14 12:35:34 ----RD---- C:\windows\ToastData
2015-10-14 12:35:32 ----D---- C:\windows\system32\Boot
2015-10-14 12:35:32 ----D---- C:\Program Files\Internet Explorer
2015-10-14 12:35:32 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 12:35:24 ----D---- C:\ProgramData\Microsoft Help
2015-10-14 12:33:37 ----A---- C:\windows\win.ini
2015-10-14 10:50:14 ----D---- C:\windows\system32\catroot2
2015-10-11 10:59:33 ----RSD---- C:\windows\Fonts
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 BTATH_BUS;@oem15.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\windows\System32\drivers\btath_bus.sys [2014-02-26 35016]
R1 pfmfs_853;pfmfs_853; C:\windows\system32\Drivers\pfmfs_853.sys [2013-04-10 251128]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 ACPIVPC;@oem40.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\windows\System32\drivers\AcpiVpc.sys [2014-08-12 35576]
R3 AthBTPort;@oem18.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2014-02-26 89800]
R3 athr;@oem12.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athwbx.sys [2014-03-07 3892224]
R3 BTATH_A2DP;@oem17.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2014-02-26 355528]
R3 btath_avdt;@oem17.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\windows\system32\drivers\btath_avdt.sys [2014-02-26 118984]
R3 BTATH_HCRP;@oem20.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\windows\System32\drivers\btath_hcrp.sys [2014-02-26 179432]
R3 BTATH_LWFLT;@oem22.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2014-02-26 77464]
R3 BTATH_RCP;@oem24.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\windows\System32\drivers\btath_rcp.sys [2014-02-26 137928]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2014-02-26 598216]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\windows\System32\drivers\BthEnum.sys [2014-10-29 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\windows\System32\drivers\bthpan.sys [2015-07-10 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2014-03-07 3729920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-03-04 3882456]
R3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2014-03-07 450520]
R3 iwdbus;@oem8.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\windows\System32\drivers\iwdbus.sys [2014-03-01 27032]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
R3 RTL8168;@oem11.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\windows\system32\DRIVERS\Rt630x64.sys [2013-12-18 839896]
R3 rtsuvc;@oem28.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\windows\system32\DRIVERS\rtsuvc.sys [2014-01-21 9105624]
R3 SmbDrvI;SmbDrvI; C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2014-02-25 34544]
R3 SynTP;@oem14.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2014-02-25 532720]
R3 TXEIx64;@oem4.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\windows\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 GeneStor;@oem10.inf,%GENESTOR.SvcDesc%;Genesys Logic Storage Driver; C:\windows\System32\drivers\GeneStor.sys [2014-04-17 111336]
S3 intaud_WaveExtensible;@oem7.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\windows\system32\drivers\intelaud.sys [2014-03-01 38296]
S3 NETwNe64;@netwew02.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\windows\system32\DRIVERS\NETwew02.sys [2013-06-18 4649440]
S3 USBAAPL64;@oem42.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2015-06-10 54784]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2014-10-29 44544]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S4 RsFx0153;RsFx0153 Driver; C:\windows\system32\DRIVERS\RsFx0153.sys [2015-03-29 322736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-10-07 77104]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2014-02-26 319104]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2014-10-29 38792]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\windows\system32\igfxCUIService.exe [2014-03-12 282096]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-02 733696]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2014-05-22 584960]
R2 LenovoRecommends.AppService;LenovoRecommends.AppService; C:\Program Files (x86)\Lenovo\Lenovo Recommends\Service\x64\LenovoRecommends.AppService.exe [2014-01-10 19440]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [2014-08-12 198192]
R2 LsvUIService;LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [2014-08-12 70416]
R2 LUService;LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [2014-02-18 38896]
R2 MSSQL$ELISKA4CLIENT;SQL Server (ELISKA4CLIENT); c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\sqlservr.exe [2015-03-29 62382256]
R2 PhoneCompanionPusher;Lenovo PhoneCompanionPusher Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [2014-08-12 288240]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2012-04-24 390632]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-01 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2014-03-12 279024]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-01 107848]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-02 822232]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-10-16 644880]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-18 30814400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PhoneCompanionVap;Lenovo PhoneCompanionVap Service; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [2014-08-12 308720]
S3 TESHelper;TESHelper; c:\Program Files\Common Files\Lenovo\Magic Transfer\x64\MagicTransferTESHelper.exe [2014-08-12 104696]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
S4 SQLAgent$ELISKA4CLIENT;SQL Server Agent (ELISKA4CLIENT); c:\Program Files (x86)\eLiska4\MSSQL10_50.ELISKA4CLIENT\MSSQL\Binn\SQLAGENT.EXE [2015-03-29 442536]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2015-03-29 278704]
-----------------EOF-----------------