Prosím o preventivku 1/2
Napsal: 12 říj 2017 17:20
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2017-10-12 17:57:40
Microsoft Windows 10 Home
System drive C: has 78 GB (34%) free of 231 GB
Total RAM: 3982 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:57:44, on 12. 10. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0608)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
C:\Program Files (x86)\eM Client\MailClient.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files (x86)\eM Client\MailClient.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\Xianzhi\Service\XianZhiDeviceProxy.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [331BigDog] "C:\Program Files (x86)\USB Camera\VM331STI.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{77a2dced-c301-442e-bef8-8021202dffe3}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Updater Service (AviraUpdaterService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
O23 - Service: @oem31.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem4.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @oem12.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Limited - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LnvMHService (LnvHotSpotSvc) - Lenovo - C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Lenovo Solution Center System Service (LSC.Services.SystemService) - Lenovo - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XianzhiDeviceService - Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd - C:\Program Files (x86)\Xianzhi\Service\XianzhiDeviceService.exe
--
End of file - 11377 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
"fontdrvhost.exe"
"fontdrvhost.exe"
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs -s gpsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-4b36bb16-d77a-4e03-9f30-8acc362b5b9b -SystemEventPortName:HostProcess-4457606b-9476-4c70-b2a3-48e0779a1199 -IoCancelEventPortName:HostProcess-9bd2da78-4a72-44c9-ba27-a2f25faa2512 -NonStateChangingEventPortName:HostProcess-5e918aa7-8897-4889-a613-a2ab2f3ef4a3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b1f83af9-675c-43b3-809b-fec9dbeb5e15 -DeviceGroupId:
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e8f9b93e-c3ec-488d-9ebd-82fc5ad944db -SystemEventPortName:HostProcess-4c4136de-c54c-42cc-9ec1-0a937d1e9e4d -IoCancelEventPortName:HostProcess-d5d087a3-37b5-47e2-942f-f512d9a7de0f -NonStateChangingEventPortName:HostProcess-98f6113b-5fc7-4baa-9b0f-46cebf06a643 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:603f0700-477c-4a4b-acab-3f045aafe4aa -DeviceGroupId:WpdFsGroup
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
C:\WINDOWS\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s SENS
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservice -s netprofm
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-22a132fd-a7c9-4a39-878e-88dffb4a44bf -SystemEventPortName:HostProcess-37949adb-3c21-46d1-89d9-6d8b9b14a437 -IoCancelEventPortName:HostProcess-3036af5a-509f-40eb-ab3c-723fa5b95857 -NonStateChangingEventPortName:HostProcess-5cfd8ed4-9a62-4219-a8a4-ff2e62a2dfa3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:96135758-554e-4c32-9f1b-011e5e981160 -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-14f8eaad-57ef-43f2-b444-9648d345421a -SystemEventPortName:HostProcess-36f4e1bf-a445-4816-8834-35aeecebbfba -IoCancelEventPortName:HostProcess-6a58b5a8-dde7-428b-8902-a2359cd8577b -NonStateChangingEventPortName:HostProcess-0d79b958-1ce9-42b6-96df-07262ec84eb2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b4bb396f-2171-4169-b4b4-40dfd56b9cd0 -DeviceGroupId:
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e910548d-ba9f-4120-b1a1-e85acc6b7dad -SystemEventPortName:HostProcess-408d7226-a466-4a40-9cd3-717afbeb1b90 -IoCancelEventPortName:HostProcess-c4e70326-0d65-4827-8653-bd626dead5bf -NonStateChangingEventPortName:HostProcess-fa5319ec-3d7e-4815-9b70-9b4c123aa475 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bd57ad33-7f13-449b-90b8-67a27faf6570 -DeviceGroupId:
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
dashost.exe {b077cdfd-bc81-4854-8bfafd71b714a106}
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\system32\AUDIODG.EXE 0x3b0
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
"C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe"
c:\windows\system32\svchost.exe -k netsvcs -s Browser
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s NgcCtnrSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
"C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe"
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_00000cb4
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
c:\windows\system32\svchost.exe -k netsvcs -s wlidsvc
"C:\Program Files (x86)\BatteryCare\BatteryCare.exe"
C:\WINDOWS\Explorer.EXE
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
igfxEM.exe
igfxHK.exe
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Martin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=61.0.3163.100 --initial-client-data=0x1e8,0x1ec,0x1f0,0x1e4,0x1f4,0x7ff87fc71988,0x7ff87fc71948,0x7ff87fc71958
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6736 --on-initialized-event-handle=636 --parent-handle=640 /prefetch:6
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,23,27,29,49,70,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0156 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4358 --gpu-driver-date=12-21-2015 --service-request-channel-token=2D5A7D22E944D5A557EDF37F8FE08A52 --mojo-platform-channel-handle=1436 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=6FD347687D734EFD43AD0484C7EAF5D2 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=6FD347687D734EFD43AD0484C7EAF5D2 --renderer-client-id=4 --mojo-platform-channel-handle=3464 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=3F37CAD42E38C690762326E61621A2A3 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=3F37CAD42E38C690762326E61621A2A3 --renderer-client-id=5 --mojo-platform-channel-handle=3472 /prefetch:1
"C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe"
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=E6DC8489D508E51C844C80752B7B2333 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=E6DC8489D508E51C844C80752B7B2333 --renderer-client-id=8 --mojo-platform-channel-handle=5848 /prefetch:1
"C:\Program Files (x86)\eM Client\MailClient.exe"
-name 3ae7c4db-93b6-42d8-81f3-6cd8ca03fc51 -runas -pluginName LenovoAudioPlugin -pluginVersion 1.2.189.0
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\eM Client\MailClient.exe" --type=renderer --no-sandbox --disable-databases --lang=en-US --lang=en-US --log-file="C:\Users\Martin\AppData\Roaming\eM Client\Logs\cef.log" --log-severity=error --uncaught-exception-stack-size=8 --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="8672.0.1804867183\779344784" /prefetch:1
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
c:\windows\system32\svchost.exe -k localservice -s SstpSvc
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
c:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=5053CFA4BC728FF7AEC259E6A5D6F600 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=5053CFA4BC728FF7AEC259E6A5D6F600 --renderer-client-id=11 --mojo-platform-channel-handle=3628 /prefetch:1
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Xianzhi\Service\XianzhiDeviceService.exe"
"C:\Program Files (x86)\Xianzhi\Service\XianZhiDeviceProxy.exe" -first
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 692 696 704 8192 700
"C:\Users\Martin\AppData\Local\Apps\2.0\LMMWYGP1.R6T\JNHGCGXC.ZBK\lsb...tion_2d7b41b05b24775e_0001.0006_3b0a905c8de4f74a\LSB.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Users\Martin\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NOUACCHECK
C:\WINDOWS\tasks\SlimCleaner Plus (Scheduled Scan - Martin).job - C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe /doScheduledScan
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xn9lknim.default-1448133334052
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xn9lknim.default-1448133334052\extensions\
abs@avira.com
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-12-04 16408320]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-12-04 1407104]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LnvMobHotspotClient"=C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [2014-08-12 937968]
"LenovoUtility"=C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [2017-07-27 911272]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-01-01 3952800]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2016-01-01 561672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideSCAPower"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-10-12 17:57:40 ----D---- C:\rsit
2017-10-09 18:16:27 ----D---- C:\ProgramData\Microsoft OneDrive
2017-10-09 04:40:12 ----SHD---- C:\Recovery
2017-10-09 04:36:21 ----D---- C:\Windows.old
2017-10-09 04:31:37 ----A---- C:\WINDOWS\SYSWOW64\IpNatHlpClient.dll
2017-10-09 04:31:37 ----A---- C:\WINDOWS\SYSWOW64\CredentialUIBroker.exe
2017-10-09 04:31:35 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\tetheringclient.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\dmcmnutils.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Vpn.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Phoneutil.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\cmintegrator.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\rasman.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\qasf.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\ntprint.exe
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\ntprint.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\GamePanel.exe
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\dinput8.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\dinput.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\DolbyDecMFT.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\bcd.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\msvproc.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfps.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfds.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2017-10-09 04:31:23 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\inetpp.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\webplatstorageserver.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\ieproxy.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\iepeers.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-10-09 04:31:04 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-10-09 04:31:04 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-10-09 04:31:02 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-10-09 04:31:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-10-09 04:31:01 ----A---- C:\WINDOWS\system32\dab.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\spbcd.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shsvcs.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shlwapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shdocvw.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\setupapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\RstrtMgr.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rastlsext.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasplap.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\offreg.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\fdeploy.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\autofmt.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\autoconv.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\appidapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\winsrvext.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\werui.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\wercplsupport.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\UIRibbon.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\dwmredir.dll
2017-10-09 04:30:59 ----A---- C:\WINDOWS\system32\DWWIN.EXE
2017-10-09 04:30:59 ----A---- C:\WINDOWS\system32\dui70.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\StartTileData.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\NotificationController.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\twinui.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shsvcs.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shlwapi.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shell32.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shdocvw.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\fdeploy.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\comdlg32.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\printfilterpipelinesvc.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\ntprint.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\ntprint.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\localspl.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\httpprxm.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\cmintegrator.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\explorer.exe
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\wininet.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\PhoneService.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\IpNatHlpClient.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\efscore.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\rastls.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\officecsp.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\ofdeploy.exe
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\lpasvc.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\dmcsps.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\RasMediaManager.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\rasman.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\msIso.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\dmcmnutils.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\csplte.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\coredpus.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wpx.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wevtapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\untfs.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\srpapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\rasapi32.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\OpcServices.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\nltest.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\configmanager2.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\cldapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\bcdedit.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\bcdboot.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\autochk.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\SIHClient.exe
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rastlsext.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rasplap.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rasgcw.dll
Run by Martin at 2017-10-12 17:57:40
Microsoft Windows 10 Home
System drive C: has 78 GB (34%) free of 231 GB
Total RAM: 3982 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:57:44, on 12. 10. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0608)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
C:\Program Files (x86)\eM Client\MailClient.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files (x86)\eM Client\MailClient.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
C:\Program Files (x86)\Xianzhi\Service\XianZhiDeviceProxy.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [331BigDog] "C:\Program Files (x86)\USB Camera\VM331STI.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{77a2dced-c301-442e-bef8-8021202dffe3}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Updater Service (AviraUpdaterService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
O23 - Service: @oem31.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem4.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @oem12.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Limited - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: LnvMHService (LnvHotSpotSvc) - Lenovo - C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe
O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
O23 - Service: Lenovo Solution Center System Service (LSC.Services.SystemService) - Lenovo - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XianzhiDeviceService - Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd - C:\Program Files (x86)\Xianzhi\Service\XianzhiDeviceService.exe
--
End of file - 11377 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
"fontdrvhost.exe"
"fontdrvhost.exe"
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs -s gpsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-4b36bb16-d77a-4e03-9f30-8acc362b5b9b -SystemEventPortName:HostProcess-4457606b-9476-4c70-b2a3-48e0779a1199 -IoCancelEventPortName:HostProcess-9bd2da78-4a72-44c9-ba27-a2f25faa2512 -NonStateChangingEventPortName:HostProcess-5e918aa7-8897-4889-a613-a2ab2f3ef4a3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b1f83af9-675c-43b3-809b-fec9dbeb5e15 -DeviceGroupId:
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e8f9b93e-c3ec-488d-9ebd-82fc5ad944db -SystemEventPortName:HostProcess-4c4136de-c54c-42cc-9ec1-0a937d1e9e4d -IoCancelEventPortName:HostProcess-d5d087a3-37b5-47e2-942f-f512d9a7de0f -NonStateChangingEventPortName:HostProcess-98f6113b-5fc7-4baa-9b0f-46cebf06a643 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:603f0700-477c-4a4b-acab-3f045aafe4aa -DeviceGroupId:WpdFsGroup
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
C:\WINDOWS\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s SENS
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservice -s netprofm
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-22a132fd-a7c9-4a39-878e-88dffb4a44bf -SystemEventPortName:HostProcess-37949adb-3c21-46d1-89d9-6d8b9b14a437 -IoCancelEventPortName:HostProcess-3036af5a-509f-40eb-ab3c-723fa5b95857 -NonStateChangingEventPortName:HostProcess-5cfd8ed4-9a62-4219-a8a4-ff2e62a2dfa3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:96135758-554e-4c32-9f1b-011e5e981160 -DeviceGroupId:
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-14f8eaad-57ef-43f2-b444-9648d345421a -SystemEventPortName:HostProcess-36f4e1bf-a445-4816-8834-35aeecebbfba -IoCancelEventPortName:HostProcess-6a58b5a8-dde7-428b-8902-a2359cd8577b -NonStateChangingEventPortName:HostProcess-0d79b958-1ce9-42b6-96df-07262ec84eb2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b4bb396f-2171-4169-b4b4-40dfd56b9cd0 -DeviceGroupId:
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e910548d-ba9f-4120-b1a1-e85acc6b7dad -SystemEventPortName:HostProcess-408d7226-a466-4a40-9cd3-717afbeb1b90 -IoCancelEventPortName:HostProcess-c4e70326-0d65-4827-8653-bd626dead5bf -NonStateChangingEventPortName:HostProcess-fa5319ec-3d7e-4815-9b70-9b4c123aa475 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:bd57ad33-7f13-449b-90b8-67a27faf6570 -DeviceGroupId:
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
dashost.exe {b077cdfd-bc81-4854-8bfafd71b714a106}
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe"
"C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\system32\AUDIODG.EXE 0x3b0
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
"C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe"
c:\windows\system32\svchost.exe -k netsvcs -s Browser
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s NgcCtnrSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
"C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe"
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_00000cb4
C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
c:\windows\system32\svchost.exe -k netsvcs -s wlidsvc
"C:\Program Files (x86)\BatteryCare\BatteryCare.exe"
C:\WINDOWS\Explorer.EXE
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
igfxEM.exe
igfxHK.exe
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Martin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=61.0.3163.100 --initial-client-data=0x1e8,0x1ec,0x1f0,0x1e4,0x1f4,0x7ff87fc71988,0x7ff87fc71948,0x7ff87fc71958
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6736 --on-initialized-event-handle=636 --parent-handle=640 /prefetch:6
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,23,27,29,49,70,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0156 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4358 --gpu-driver-date=12-21-2015 --service-request-channel-token=2D5A7D22E944D5A557EDF37F8FE08A52 --mojo-platform-channel-handle=1436 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=6FD347687D734EFD43AD0484C7EAF5D2 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=6FD347687D734EFD43AD0484C7EAF5D2 --renderer-client-id=4 --mojo-platform-channel-handle=3464 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=3F37CAD42E38C690762326E61621A2A3 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=3F37CAD42E38C690762326E61621A2A3 --renderer-client-id=5 --mojo-platform-channel-handle=3472 /prefetch:1
"C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe"
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=E6DC8489D508E51C844C80752B7B2333 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=E6DC8489D508E51C844C80752B7B2333 --renderer-client-id=8 --mojo-platform-channel-handle=5848 /prefetch:1
"C:\Program Files (x86)\eM Client\MailClient.exe"
-name 3ae7c4db-93b6-42d8-81f3-6cd8ca03fc51 -runas -pluginName LenovoAudioPlugin -pluginVersion 1.2.189.0
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\eM Client\MailClient.exe" --type=renderer --no-sandbox --disable-databases --lang=en-US --lang=en-US --log-file="C:\Users\Martin\AppData\Roaming\eM Client\Logs\cef.log" --log-severity=error --uncaught-exception-stack-size=8 --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="8672.0.1804867183\779344784" /prefetch:1
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
c:\windows\system32\svchost.exe -k localservice -s SstpSvc
"C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe"
c:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420,5845109646770529521,14316598202299005028,131072 --service-pipe-token=5053CFA4BC728FF7AEC259E6A5D6F600 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=5053CFA4BC728FF7AEC259E6A5D6F600 --renderer-client-id=11 --mojo-platform-channel-handle=3628 /prefetch:1
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe"
"C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Xianzhi\Service\XianzhiDeviceService.exe"
"C:\Program Files (x86)\Xianzhi\Service\XianZhiDeviceProxy.exe" -first
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 692 696 704 8192 700
"C:\Users\Martin\AppData\Local\Apps\2.0\LMMWYGP1.R6T\JNHGCGXC.ZBK\lsb...tion_2d7b41b05b24775e_0001.0006_3b0a905c8de4f74a\LSB.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Users\Martin\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NOUACCHECK
C:\WINDOWS\tasks\SlimCleaner Plus (Scheduled Scan - Martin).job - C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe /doScheduledScan
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xn9lknim.default-1448133334052
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\xn9lknim.default-1448133334052\extensions\
abs@avira.com
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-12-04 16408320]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-12-04 1407104]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-07-20 373760]
"LnvMobHotspotClient"=C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [2014-08-12 937968]
"LenovoUtility"=C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [2017-07-27 911272]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-01-01 3952800]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2016-01-01 561672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideSCAPower"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-10-12 17:57:40 ----D---- C:\rsit
2017-10-09 18:16:27 ----D---- C:\ProgramData\Microsoft OneDrive
2017-10-09 04:40:12 ----SHD---- C:\Recovery
2017-10-09 04:36:21 ----D---- C:\Windows.old
2017-10-09 04:31:37 ----A---- C:\WINDOWS\SYSWOW64\IpNatHlpClient.dll
2017-10-09 04:31:37 ----A---- C:\WINDOWS\SYSWOW64\CredentialUIBroker.exe
2017-10-09 04:31:35 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2017-10-09 04:31:29 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\tetheringclient.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\dmcmnutils.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-10-09 04:31:28 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Vpn.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\Phoneutil.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\cmintegrator.dll
2017-10-09 04:31:27 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\rasman.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\qasf.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\ntprint.exe
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\ntprint.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\GamePanel.exe
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\dinput8.dll
2017-10-09 04:31:26 ----A---- C:\WINDOWS\SYSWOW64\dinput.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\DolbyDecMFT.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\SYSWOW64\bcd.dll
2017-10-09 04:31:25 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\msvproc.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfps.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfds.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-10-09 04:31:24 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2017-10-09 04:31:23 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-10-09 04:31:23 ----A---- C:\WINDOWS\system32\inetpp.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\webplatstorageserver.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\ieproxy.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-10-09 04:31:11 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2017-10-09 04:31:10 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2017-10-09 04:31:06 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\iepeers.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2017-10-09 04:31:05 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-10-09 04:31:04 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-10-09 04:31:04 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-10-09 04:31:03 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-10-09 04:31:02 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-10-09 04:31:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-10-09 04:31:01 ----A---- C:\WINDOWS\system32\dab.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\spbcd.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shsvcs.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shlwapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\shdocvw.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\setupapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\RstrtMgr.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rastlsext.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasplap.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\offreg.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\fdeploy.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\autofmt.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\autoconv.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\SYSWOW64\appidapi.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\winsrvext.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\werui.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\wercplsupport.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\UIRibbon.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-10-09 04:31:00 ----A---- C:\WINDOWS\system32\dwmredir.dll
2017-10-09 04:30:59 ----A---- C:\WINDOWS\system32\DWWIN.EXE
2017-10-09 04:30:59 ----A---- C:\WINDOWS\system32\dui70.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\StartTileData.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\NotificationController.dll
2017-10-09 04:30:58 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\twinui.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shsvcs.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shlwapi.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shell32.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\shdocvw.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\fdeploy.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-10-09 04:30:57 ----A---- C:\WINDOWS\system32\comdlg32.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\printfilterpipelinesvc.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\ntprint.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\ntprint.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\localspl.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\httpprxm.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2017-10-09 04:30:56 ----A---- C:\WINDOWS\system32\cmintegrator.dll
2017-10-09 04:30:56 ----A---- C:\WINDOWS\explorer.exe
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\wininet.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\PhoneService.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\IpNatHlpClient.dll
2017-10-09 04:30:55 ----A---- C:\WINDOWS\system32\efscore.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\rastls.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\officecsp.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\ofdeploy.exe
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\lpasvc.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2017-10-09 04:30:54 ----A---- C:\WINDOWS\system32\dmcsps.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\RasMediaManager.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\rasman.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\msIso.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\dmcmnutils.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\csplte.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\coredpus.dll
2017-10-09 04:30:48 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wpx.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\wevtapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\untfs.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\srpapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\rasapi32.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\OpcServices.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\nltest.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\configmanager2.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\cldapi.dll
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\bcdedit.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\bcdboot.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\autochk.exe
2017-10-09 04:30:47 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\SIHClient.exe
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rastlsext.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rasplap.dll
2017-10-09 04:30:46 ----A---- C:\WINDOWS\system32\rasgcw.dll