Logfile of random's system information tool 1.10 (written by random/random) Run by Mandy at 2016-08-06 21:03:04 Microsoft Windows 10 Home System drive C: has 169 GB (64%) free of 262 GB Total RAM: 3978 MB (43% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:03:07, on 6-8-2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.10586.0494) Boot mode: Normal Running processes: C:\PROGRA~2\SEARCH~1\SearchProtect\bin\cltmng.exe C:\PROGRA~2\SEARCH~1\UI\bin\cltmngui.exe C:\Program Files (x86)\483439ee973f587d9bb1ffe33f27b80f\d6f7007239bc95aaafcdd9d90837aefd.exe C:\Windows\WebCam\S6000\S6000Mnt.exe C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_desktop.exe C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_metro.exe C:\Program Files (x86)\Lenovo\Password Manager\password_manager.exe C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\Users\mandyyy\AppData\Roaming\Spotify\SpotifyWebHelper.exe C:\Program Files\trend micro\Mandy.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nuesearch.com/search/?type=ds&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10&q={searchTerms} R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nuesearch.com/search/?type=ds&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10&q={searchTerms} R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=c:\windows\syswow64\userinit.exe, O1 - Hosts: ::1 localhost O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" O4 - HKCU\..\Run: [OneDrive] "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\mandyyy\AppData\Roaming\Spotify\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Spotify] "C:\Users\mandyyy\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64" O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O4 - Startup: Google.com.url O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000 O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://*.hola.org O17 - HKLM\System\CCS\Services\Tcpip\..\{06e93ff9-5cb8-4640-8c36-e97bf9762b30}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CCS\Services\Tcpip\..\{433dd68e-d382-4218-aeba-b123b83540c1}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CCS\Services\Tcpip\..\{5bc62d4d-2bb1-4a8e-bb1a-7e0a3d095fc0}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CCS\Services\Tcpip\..\{b16dda32-7752-425b-a707-b04f1121b021}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CS1\Services\Tcpip\..\{06e93ff9-5cb8-4640-8c36-e97bf9762b30}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173 O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: BugreportW - Unknown owner - C:\Program Files (x86)\SpeedSearchesbnd\Bugreportauclt.exe (file missing) O23 - Service: Search Protect Service (CltMngSvc) - Client Connect LTD - C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe O23 - Service: Command Service(CommandHandler) (CommandHandler) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxCommand.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: EOF - Unknown owner - C:\Program Files (x86)\483439ee973f587d9bb1ffe33f27b80f\EOF.exe O23 - Service: Symantec Eraser Service (EraserSvc11520) - Unknown owner - C:\Program Files (x86)\Norton Security\Engine\22.5.4.24\NS.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Update Service(FirefoxU) (FirefoxU) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Protect Service(IHeeaWA_protect) (IHeeaWA_protect) - Unknown owner - C:\ProgramData\IHeeaWA\protect\protect.exe (file missing) O23 - Service: Update Service(IHeeaWA_update) (IHeeaWA_update) - Unknown owner - C:\Program Files (x86)\IHeeaWA\IHeeaWA\bin\IHeeaWA_server.exe (file missing) O23 - Service: IhPul - Trend Corp. - C:\Users\mandyyy\AppData\Roaming\TSv\TSvr.exe O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe O23 - Service: LenovoSetSvr - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing) O23 - Service: LSCWinService - Lenovo - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe O23 - Service: Maxthon Core Update Service (MaxthonUpdateSvc) - Maxthon - C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NitroPDFDriverCreatorReadSpool9 (NitroDriverReadSpool9) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: SSFK - Unknown owner - C:\Program Files (x86)\SFK\SSFK.exe O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Update service - Popcorn Time - C:\Program Files (x86)\Popcorn Time\Updater.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: WFini WdMan Service (WdMan) - WFini LIMITED - C:\ProgramData\GwinpG\WFini.exe O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: winsaber - Unknown owner - C:\Program Files (x86)\WinSaber\WinSaber.exe O23 - Service: WinSvces - Unknown owner - C:\Program Files (x86)\WinSvces\WinSvces\WinSvces.exe (file missing) O23 - Service: WinZiper service (winzipersvc) - ExWzp Pvt Ltd. - C:\Program Files (x86)\WinZipper\winzipersvc.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 17299 bytes ======Listing Processes====== winlogon.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS "dwm.exe" C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-015071fd-1147-4f3b-849e-0e4123a00d4e -SystemEventPortName:HostProcess-6372a3e9-9080-49aa-a47e-46fbe7304365 -IoCancelEventPortName:HostProcess-f904cebb-f544-4632-9ec8-a0fdcb37d03e -NonStateChangingEventPortName:HostProcess-1da18e06-1cfc-487d-8236-029669f02746 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:039663c8-5b60-4c7d-a7fc-f995a7266a61 -DeviceGroupId:WudfDefaultDevicePool C:\WINDOWS\system32\igfxCUIService.exe C:\WINDOWS\system32\svchost.exe -k NetworkService "C:\Program Files (x86)\WinZipper\winzipersvc.exe" C:\WINDOWS\System32\spoolsv.exe "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" C:\WINDOWS\System32\svchost.exe -k utcsvc C:\Users\mandyyy\AppData\Roaming\TSv\TSvr.exe "C:\Program Files (x86)\483439ee973f587d9bb1ffe33f27b80f\EOF.exe" -s "C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe" C:\WINDOWS\system32\WLANExt.exe 2650688335104 "C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe" \??\C:\WINDOWS\system32\conhost.exe 0x4 "C:\Program Files\Bonjour\mDNSResponder.exe" C:\WINDOWS\system32\svchost.exe -k appmodel C:\ProgramData\GwinpG\WFini.exe -svr C:\WINDOWS\system32\svchost.exe -k imgsvc dashost.exe {02cf5737-5d83-4580-91f528a90d3ad892} "C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe" "C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe" C:\windows\SysWOW64\NLSSRV32.EXE "C:\Program Files (x86)\Popcorn Time\Updater.exe" "C:\Program Files (x86)\WinSaber\WinSaber.exe" C:\Windows\System32\LenovoWiFiHotspotSvr.exe "C:\Program Files\Lenovo\iMController\SystemAgentService.exe" "C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe" "C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe" "C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe" "C:\Program Files (x86)\SFK\SSFK.exe" -s "C:\Program Files\CyberLink\Shared files\RichVideo64.exe" C:\WINDOWS\system32\wbem\wmiprvse.exe C:\PROGRA~2\SEARCH~1\SearchProtect\bin\cltmng.exe taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} sihost.exe C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\PROGRA~2\SEARCH~1\UI\bin\cltmngui.exe C:\Windows\System32\RuntimeBroker.exe -Embedding C:\WINDOWS\Explorer.EXE ClassicStartMenu.exe -startup "C:\Program Files (x86)\483439ee973f587d9bb1ffe33f27b80f\d6f7007239bc95aaafcdd9d90837aefd.exe" --set_windows_hook --dll_name="dlqwfu.dll" --dll_name_64="invalid" --dll_folder="1ea26074a12fc219940785426fea2a51\\" igfxEM.exe igfxHK.exe igfxTray.exe "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca C:\WINDOWS\system32\SearchIndexer.exe /Embedding "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4 "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY "C:\Windows\WebCam\S6000\S6000Mnt.exe" "C:\Program Files\Lenovo\Password Manager\password_manager.exe" "C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe" "C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe" "C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_desktop.exe" "C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe" "C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_metro.exe" "C:\Program Files (x86)\Lenovo\Password Manager\password_manager.exe" "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "C:\Program Files\iTunes\iTunesHelper.exe" "C:\Users\mandyyy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background "C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE" "C:\Program Files\iPod\bin\iPodService.exe" C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup C:\WINDOWS\system32\SettingSyncHost.exe -Embedding "C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe" "C:\Program Files (x86)\Firefox\bin\FirefoxCommand.exe" C:\WINDOWS\system32\ie4uinit.exe -ClearIconCache service C:\windows\system32\rundll32.exe C:\windows\system32\pla.dll,PlaHost "LSC Memory" "0x1f98_0x158c_0x5b42881c" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.nuesearch.com/?type=sc&ts=1468232558&z=9c9b02589f27791b1d815bag0z0qabfo3c9ofw1waw&from=wpm0616&uid=WDCXWD3200LPCX-24C6HT0_WD-WX11E44ELE10ELE10 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\mandyyy\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=51.0.2704.103 --handshake-handle=0x18c "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --enable-features=AutomaticTabDiscarding