I have reported this issue, and at the moment i'm in contact with labview tech help on this issue. In This thread -7-takes-15min-to-boot-after-installing-Labview-2012/m-p/2197... I've reported that the problem was solved, but actually it only worked for a few days, then come back again
ComboFix 14-10-29.01 - admin . 11. 2014 18:43:59.1.4 - x64Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.3793.1618 [GMT 1:00]Running from: c:\users\admin\Desktop\ComboFix.exeAV: ESET Endpoint Antivirus 5.0 *Disabled/Updated* 19259FAE-8396-A113-46DB-15B0E7DFA289SP: ESET Endpoint Antivirus 5.0 *Disabled/Updated* A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834SP: Windows Defender *Disabled/Updated* D68DDC3A-831F-4fae-9E44-DA132C1ACF46 * Created a new restore point..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\program files\Lenovo\Lenovo Solution Center\Microsoft Fix it\FixitUi\_desktop.inic:\programdata\Roamingc:\windows\msdownld.tmpc:\windows\security\Database\tmp.edbQ:\Autorun.inf..((((((((((((((((((((((((( Files Created from 2014-10-03 to 2014-11-03 )))))))))))))))))))))))))))))))..2014-11-03 18:19 . 2014-11-03 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp2014-11-03 17:24 . 2014-11-03 17:24 -------- d-----w- c:\windows\ERUNT2014-11-03 17:14 . 2014-11-03 17:16 -------- d-----w- C:\AdwCleaner2014-11-03 06:19 . 2014-11-03 17:34 -------- d-----w- C:\FRST2014-10-31 07:42 . 2014-10-31 07:42 -------- d-----w- c:\users\admin\AppData\Local\Evernote2014-10-31 06:25 . 2014-10-31 06:25 -------- d-----w- c:\program files\CCleaner2014-10-29 09:54 . 2013-07-18 00:43 795632 ----a-w- c:\windows\system32\drivers\iusb3xhc.sys2014-10-29 09:54 . 2013-07-18 00:43 358896 ----a-w- c:\windows\system32\drivers\iusb3hub.sys2014-10-29 09:54 . 2013-07-18 00:43 20464 ----a-w- c:\windows\system32\drivers\iusb3hcs.sys2014-10-29 09:41 . 2012-11-01 08:48 245872 ----a-w- c:\windows\system32\seagcoinst.dll2014-10-29 09:40 . 2014-10-29 09:40 -------- d-----w- c:\users\admin\AppData\Roaming\Seagate2014-10-29 09:40 . 2014-10-29 09:40 86016 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\58053C71-35D9-4F16-9E5A-50C97504B2D0\Seagate_NAS_Discov_25095144CDA545069117E7B7657B7840.exe2014-10-29 09:40 . 2014-10-29 09:40 86016 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\58053C71-35D9-4F16-9E5A-50C97504B2D0\BlackArmor_Discove_90FF9289A03D4ED88DE6D3E499E65F57_1.exe2014-10-29 09:40 . 2014-10-29 09:40 86016 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\58053C71-35D9-4F16-9E5A-50C97504B2D0\ARPPRODUCTICON.exe2014-10-29 09:39 . 2014-10-29 09:39 -------- d-----w- c:\program files (x86)\Seagate2014-10-28 06:18 . 2014-10-28 06:18 -------- d-----w- c:\program files (x86)\Common Files\Java2014-10-28 06:18 . 2014-10-28 06:18 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll2014-10-28 06:18 . 2014-10-28 06:18 -------- d-----w- c:\program files (x86)\Java2014-10-27 14:53 . 2014-10-27 14:55 -------- d-----w- c:\users\admin\AppData\Roaming\SISTEMA2014-10-27 14:53 . 2014-10-27 14:53 -------- d-----w- c:\program files (x86)\SISTEMA2014-10-23 15:14 . 2014-10-28 06:44 -------- d-----w- c:\users\admin\AppData\Roaming\LSC2014-10-22 20:24 . 2014-10-22 20:24 -------- d-----w- C:\DRIVERS2014-10-22 20:22 . 2012-10-02 11:49 443208 ----a-w- c:\windows\system32\drivers\Mbm3CBus.sys2014-10-22 20:22 . 2012-10-02 11:49 17736 ----a-w- c:\windows\system32\drivers\Mbm3whnt.sys2014-10-22 20:22 . 2012-10-02 11:49 17736 ----a-w- c:\windows\system32\drivers\Mbm3wh.sys2014-10-22 20:22 . 2012-03-01 13:09 103184 ----a-w- c:\windows\system32\drivers\l36wgps64.sys2014-10-22 20:22 . 2011-01-14 11:50 61992 ----a-w- c:\windows\system32\drivers\l36wscard.sys2014-10-22 20:22 . 2012-10-02 11:49 506184 ----a-w- c:\windows\system32\drivers\Mbm3Mdm.sys2014-10-22 20:22 . 2012-10-02 11:49 453960 ----a-w- c:\windows\system32\drivers\Mbm3DevMt.sys2014-10-22 20:22 . 2012-10-02 11:49 21832 ----a-w- c:\windows\system32\drivers\Mbm3mdfl.sys2014-10-22 20:22 . 2012-10-02 11:49 17224 ----a-w- c:\windows\system32\drivers\Mbm3cmnt.sys2014-10-22 20:22 . 2012-10-02 11:49 17224 ----a-w- c:\windows\system32\drivers\Mbm3cm.sys2014-10-22 20:21 . 2014-07-28 10:25 461552 ----a-w- c:\windows\system32\drivers\SynTP.sys2014-10-22 20:21 . 2014-07-28 10:25 114416 ----a-w- c:\windows\SysWow64\SynTPCOM.dll2014-10-22 20:21 . 2014-07-28 10:25 173808 ----a-w- c:\windows\system32\SynTPCo14.dll2014-10-22 20:21 . 2014-07-28 10:25 224496 ----a-w- c:\windows\system32\SynTPAPI.dll2014-10-22 20:21 . 2014-07-28 10:25 536304 ----a-w- c:\windows\SysWow64\SynCOM.dll2014-10-22 20:21 . 2014-07-28 10:25 45296 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys2014-10-22 20:21 . 2014-10-22 20:21 -------- d-----w- c:\program files (x86)\Dolby Advanced Audio v22014-10-22 20:16 . 2014-09-05 13:22 40224 ----a-w- c:\windows\system32\tpinspm.dll2014-10-22 20:16 . 2014-09-05 13:22 77088 ----a-w- c:\windows\system32\ibmpmsvc.exe2014-10-22 20:16 . 2014-09-05 13:22 59128 ----a-w- c:\windows\system32\drivers\ibmpmdrv.sys2014-10-22 20:16 . 2014-09-05 13:22 72480 ----a-w- c:\windows\system32\ibmpmctl.exe2014-10-22 19:18 . 2014-10-22 19:18 -------- d-----w- c:\program files (x86)\FileOpen2014-10-22 19:18 . 2014-10-22 19:18 -------- d-----w- c:\program files\FileOpen2014-10-21 11:11 . 2014-10-21 11:11 -------- d-----w- c:\programdata\Malwarebytes2014-10-20 09:46 . 2014-10-20 09:46 -------- d-----w- c:\users\admin\AppData\Roaming\LavasoftStatistics2014-10-20 08:28 . 2014-10-20 08:28 -------- d-----w- c:\program files (x86)\Festo2014-10-17 06:00 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll2014-10-17 06:00 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll2014-10-17 05:54 . 2014-08-01 11:53 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll2014-10-17 05:53 . 2014-06-25 02:05 14175744 ----a-w- c:\windows\system32\shell32.dll2014-10-17 05:53 . 2014-09-04 05:23 424448 ----a-w- c:\windows\system32\rastls.dll2014-10-17 05:53 . 2014-09-04 05:04 372736 ----a-w- c:\windows\SysWow64\rastls.dll2014-10-17 05:50 . 2014-09-05 02:11 6584320 ----a-w- c:\windows\system32\mstscax.dll2014-10-17 05:50 . 2014-09-05 01:52 5703168 ----a-w- c:\windows\SysWow64\mstscax.dll2014-10-17 05:48 . 2014-09-13 01:58 77312 ----a-w- c:\windows\system32\packager.dll2014-10-17 05:48 . 2014-09-13 01:40 67072 ----a-w- c:\windows\SysWow64\packager.dll2014-10-17 05:48 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll2014-10-17 05:48 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll2014-10-17 05:42 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll2014-10-17 05:42 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe2014-10-17 05:42 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll2014-10-17 05:42 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll2014-10-17 05:42 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll2014-10-17 05:42 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll2014-10-17 05:42 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll2014-10-17 05:42 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll2014-10-17 05:42 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll2014-10-17 05:42 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll2014-10-17 05:41 . 2014-05-14 07:23 198600 ----a-w- c:\windows\system32\wuwebv.dll2014-10-17 05:41 . 2014-05-14 07:23 179656 ----a-w- c:\windows\SysWow64\wuwebv.dll2014-10-17 05:41 . 2014-05-14 07:20 36864 ----a-w- c:\windows\system32\wuapp.exe2014-10-17 05:41 . 2014-05-14 07:17 33792 ----a-w- c:\windows\SysWow64\wuapp.exe2014-10-17 05:41 . 2014-10-17 05:41 -------- d-----w- c:\windows\system32\appmgmt2014-10-14 09:21 . 2014-10-14 09:21 -------- d-----w- c:\users\admin\AppData\Local\Siemens_AG2014-10-14 08:18 . 2014-10-14 08:18 -------- d-----w- c:\users\admin\AppData\Roaming\FileOpen2014-10-14 08:18 . 2014-10-14 08:18 -------- d-----w- c:\programdata\FileOpen...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2014-10-03 08:02 . 2014-07-18 13:39 103265616 ----a-w- c:\windows\system32\MRT.exe2014-09-26 05:16 . 2014-07-18 20:15 590536 ----a-w- c:\programdata\Microsoft\ClickToRun\9AC08E99-230B-47e8-9721-4577B7F124EA\integrator.exe2014-09-10 08:50 . 2014-09-10 08:50 4 ----a-w- C:\Project Manager.reg2014-09-10 04:06 . 2013-07-17 05:34 2692896 ------w- c:\windows\PWMBTHLV.EXE2014-09-10 04:06 . 2013-07-17 05:34 29512 ----a-w- c:\windows\system32\drivers\DZHDD64.SYS2014-09-10 04:06 . 2013-07-17 05:34 2861344 ----a-w- c:\windows\system32\PWMCP64V.cpl2014-09-10 04:06 . 2013-07-17 05:34 20736 ----a-w- c:\windows\system32\drivers\TPPWR64V.SYS..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shownREGEDIT4.[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]@="F241C880-6982-4CE5-8CF7-7085BA96DA5A"[HKEY_CLASSES_ROOT\CLSID\F241C880-6982-4CE5-8CF7-7085BA96DA5A]2014-07-18 20:32 222920 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\SkyDriveShell.dll.[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]@="A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E"[HKEY_CLASSES_ROOT\CLSID\A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E]2014-07-18 20:32 222920 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\SkyDriveShell.dll.[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]@="BBACC218-34EA-4666-9D7A-C78F2274A524"[HKEY_CLASSES_ROOT\CLSID\BBACC218-34EA-4666-9D7A-C78F2274A524]2014-07-18 20:32 222920 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\SkyDriveShell.dll.[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"RotateImage"="c:\program files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" [2008-10-30 55808]"USB3MON"="c:\program files (x86)\Intel\Intel USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-07-18 292088]"IMSS"="c:\program files (x86)\Intel\Intel Management Engine Components\IMSS\PIconStartup.exe" [2012-02-28 133400]"PWMTRV"="c:\program files (x86)\ThinkPad\Utilities\PWMTR64V.DLL" [2014-09-10 6363424]"Fastboot"="c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" [2012-01-17 1091376]"MobileAccess"="c:\program files (x86)\Lenovo\MobileAccess\MobileAccess.exe" [2012-07-10 155424]"Intel AppUp(SM) center"="c:\program files (x86)\Intel\IntelAppStore\bin\ismagent.exe" [2012-07-12 155488]"SiemensAutomationFileStorage"="c:\program files (x86)\Siemens\Automation\Portal V12\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe" [2014-02-26 942592]"S7UB Start"="c:\program files (x86)\Common Files\Siemens\S7ubtoox\s7ubtstx.exe" [2010-06-02 102453]"SiemensAutomationFileStorage_TIAP13"="c:\program files (x86)\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe" [2014-07-31 1023488]"WinCC flexible Smart Start"="c:\program files (x86)\Siemens\SIMATIC WinCC flexible\WinCC flexible 2008\HmiSmartStart.exe" [2013-12-14 118784]"Dolby Advanced Audio v2"="c:\program files (x86)\Dolby Advanced Audio v2\pcee4.exe" [2012-08-31 508656].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 5 (0x5)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableUIADesktopToggle"= 0 (0x0).[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkPad\Bluetooth Software\BtwProximityCP.dll c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll.R2 CCDBUtils;CCDBUtils;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCDBUtils.exe;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCDBUtils.exe [x]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [x]R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys;c:\windows\SYSNATIVE\drivers\bcbtums.sys [x]R3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]R3 CCArchiveManagerService;CCArchiveManagerService;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCArchiveManager.exe;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCArchiveManager.exe [x]R3 CCRedundancyAgent-Service;CCRedundancyAgent-Service;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCRedundancyAgent.exe;c:\program files (x86)\Common Files\Siemens\CommonArchiving\CCRedundancyAgent.exe [x]R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]R3 DozeSvc;Lenovo Doze Mode Service;c:\program files (x86)\ThinkPad\Utilities\DZSVC64.EXE;c:\program files (x86)\ThinkPad\Utilities\DZSVC64.EXE [x]R3 dpmcslv;dpmcslv; [x]R3 EPLAN Client Service;EPLAN Client Service;c:\program files\EPLAN\Common\EClientService.exe;c:\program files\EPLAN\Common\EClientService.exe [x]R3 ESHASRV;ESET SHA Service;c:\program files\ESET\ESET Endpoint Antivirus\EShaSrv.exe;c:\program files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [x]R3 Fastboot;Fastboot;c:\windows\system32\DRIVERS\Fastboot.sys;c:\windows\SYSNATIVE\DRIVERS\Fastboot.sys [x]R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]R3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot;c:\program files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe;c:\program files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [x]R3 LSCWinService;LSCWinService;c:\program files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe;c:\program files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [x]R3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys;c:\windows\SYSNATIVE\drivers\lvalarmk.sys [x]R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]R3 ni1006k;NI PXI-1006 Chassis Pilot;c:\windows\system32\drivers\ni1006k.sys;c:\windows\SYSNATIVE\drivers\ni1006k.sys [x]R3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys;c:\windows\SYSNATIVE\drivers\ni1045kl.sys [x]R3 ni1065k;NI PXIe-1065 Chassis Pilot;c:\windows\system32\drivers\ni1065k.sys;c:\windows\SYSNATIVE\drivers\ni1065k.sys [x]R3 nicdcck;nicdcck;c:\windows\system32\drivers\nicdcckl.sys;c:\windows\SYSNATIVE\drivers\nicdcckl.sys [x]R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys;c:\windows\SYSNATIVE\drivers\nicdrkl.sys [x]R3 nicmrk;nicmrk;c:\windows\system32\drivers\nicmrkl.sys;c:\windows\SYSNATIVE\drivers\nicmrkl.sys [x]R3 nicondrk;nicondrk;c:\windows\system32\drivers\nicondrkl.sys;c:\windows\SYSNATIVE\drivers\nicondrkl.sys [x]R3 nicsrk;nicsrk;c:\windows\system32\drivers\nicsrkl.sys;c:\windows\SYSNATIVE\drivers\nicsrkl.sys [x]R3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys;c:\windows\SYSNATIVE\drivers\nidmxfkl.sys [x]R3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys;c:\windows\SYSNATIVE\drivers\nidsarkl.sys [x]R3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys;c:\windows\SYSNATIVE\drivers\niemrkl.sys [x]R3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys;c:\windows\SYSNATIVE\drivers\niesrkl.sys [x]R3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys;c:\windows\SYSNATIVE\drivers\nifslkl.sys [x]R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys;c:\windows\SYSNATIVE\drivers\nimsdrkl.sys [x]R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys;c:\windows\SYSNATIVE\drivers\nimstskl.sys [x]R3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys;c:\windows\SYSNATIVE\drivers\nimxpkl.sys [x]R3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys;c:\windows\SYSNATIVE\drivers\ninshsdkl.sys [x]R3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys;c:\windows\SYSNATIVE\drivers\nipalfwedl.sys [x]R3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys;c:\windows\SYSNATIVE\drivers\nipalusbedl.sys [x]R3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys;c:\windows\SYSNATIVE\drivers\nipxigpk.sys [x]R3 niraptrk;niraptrk;c:\windows\system32\drivers\niraptrkl.sys;c:\windows\SYSNATIVE\drivers\niraptrkl.sys [x]R3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys;c:\windows\SYSNATIVE\drivers\niscdkl.sys [x]R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys;c:\windows\SYSNATIVE\drivers\nisdigkl.sys [x]R3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys;c:\windows\SYSNATIVE\drivers\nisftkl.sys [x]R3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys;c:\windows\SYSNATIVE\drivers\nispdkl.sys [x]R3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys;c:\windows\SYSNATIVE\drivers\nissrkl.sys [x]R3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys;c:\windows\SYSNATIVE\drivers\nistc2kl.sys [x]R3 nistc3rk;nistc3rk;c:\windows\system32\drivers\nistc3rkl.sys;c:\windows\SYSNATIVE\drivers\nistc3rkl.sys [x]R3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys;c:\windows\SYSNATIVE\drivers\nistcrkl.sys [x]R3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys;c:\windows\SYSNATIVE\drivers\niswdkl.sys [x]R3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys;c:\windows\SYSNATIVE\drivers\nitiorkl.sys [x]R3 niufurk;niufurk;c:\windows\system32\drivers\niufurkl.sys;c:\windows\SYSNATIVE\drivers\niufurkl.sys [x]R3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys;c:\windows\SYSNATIVE\drivers\niwfrkl.sys [x]R3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys;c:\windows\SYSNATIVE\drivers\nixsrkl.sys [x]R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [x]R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]R4 NIApplicationWebServer64;NI Application Web Server (64-bit);c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]S0 DzHDD64;DzHDD64;c:\windows\System32\DRIVERS\DzHDD64.sys;c:\windows\SYSNATIVE\DRIVERS\DzHDD64.sys [x]S0 iusb3hcs;Intel USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]S0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\System32\drivers\nipbcfk.sys;c:\windows\SYSNATIVE\drivers\nipbcfk.sys [x]S0 nipxibaf;National Instruments PXI Bridge Access Driver;c:\windows\System32\drivers\nipxibaf.sys;c:\windows\SYSNATIVE\drivers\nipxibaf.sys [x]S0 nipxibrc;National Instruments PXI Bridge Configuration Driver;c:\windows\System32\drivers\nipxibrc.sys;c:\windows\SYSNATIVE\drivers\nipxibrc.sys [x]S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys;c:\windows\SYSNATIVE\DRIVERS\ApsHM64.sys [x]S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [x]S2 aksdf;aksdf;c:\windows\system32\drivers\aksdf.sys;c:\windows\SYSNATIVE\drivers\aksdf.sys [x]S2 almservice;Automation License Manager Service;c:\program files\Common Files\Siemens\sws\almsrv\almsrv64x.exe;c:\program files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [x]S2 ClickToRunSvc;Služba Klikni a spusti balíka Microsoft Office;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe;c:\program files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [x]S2 DraftSight API Service;DraftSight API Service;c:\program files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe;c:\program files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [x]S2 ekrn;ESET Service;c:\program files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [x]S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x]S2 FastbootService;FastbootService;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [x]S2 FileOpenManager;FileOpen Manager Service;c:\program files\FileOpen\Services\FileOpenManager64.exe;c:\program files\FileOpen\Services\FileOpenManager64.exe [x]S2 Intel Capability Licensing Service Interface;Intel Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]S2 jhi_service;Intel Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel Management Engine Components\DAL\jhi_service.exe [x]S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [x]S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x]S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [x]S2 LENOVO.TVTVCAM;Lenovo Virtual Camera Controller;c:\program files\Lenovo\Communications Utility\vcamsvc.exe;c:\program files\Lenovo\Communications Utility\vcamsvc.exe [x]S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [x]S2 MacheenService;Macheen Service;c:\program files (x86)\Lenovo\MobileAccess\MacheenService.exe;c:\program files (x86)\Lenovo\MobileAccess\MacheenService.exe [x]S2 MSSQL$WINCCFLEXEXPRESS;SQL Server (WINCCFLEXEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe;c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [x]S2 ni488enumsvc;NI GPIB Enumeration Service;c:\windows\SysWOW64\nipalsm.exe;c:\windows\SysWOW64\nipalsm.exe [x]S2 NIApplicationWebServer;NI Application Web Server;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x]S2 nidevldu;NI Device Loader;c:\windows\SysWOW64\nidevldu.exe;c:\windows\SysWOW64\nidevldu.exe [x]S2 niLXIDiscovery;NI LXI Discovery Service;c:\program files (x86)\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe;c:\program files (x86)\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe [x]S2 nimDNSResponder;NI mDNS Responder Service;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe;c:\program files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [x]S2 NINetworkDiscovery;NI Network Discovery;c:\program files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe;c:\program files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [x]S2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys;c:\windows\SYSNATIVE\drivers\nipxirmkl.sys [x]S2 NISystemWebServer;NI System Web Server;c:\program files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe;c:\program files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [x]S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys;c:\windows\SYSNATIVE\drivers\NiViPxiKl.sys [x]S2 npdrv;npdrv;c:\windows\system32\drivers\npdrv.sys;c:\windows\SYSNATIVE\drivers\npdrv.sys [x]S2 npdrvfilter;npdrvfilter;c:\windows\system32\drivers\npdrvfilter.sys;c:\windows\SYSNATIVE\drivers\npdrvfilter.sys [x]S2 risdxc;risdxc;c:\windows\system32\DRIVERS\risdxc64.sys;c:\windows\SYSNATIVE\DRIVERS\risdxc64.sys [x]S2 s7hspsvx;S7 HSP Service;c:\program files (x86)\Siemens\Step7\s7bin\s7hspsvx.exe;c:\program files (x86)\Siemens\Step7\s7bin\s7hspsvx.exe [x]S2 s7oiehsx64;SIMATIC S7DOS Help Service;c:\program files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe;c:\program files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [x]S2 s7ousbu64x;SIMATIC USB Service;c:\windows\system32\DRIVERS\s7ousbu64x.sys;c:\windows\SYSNATIVE\DRIVERS\s7ousbu64x.sys [x]S2 s7sn2srtx;PROFINET IO RT-Protocol V2.0;c:\windows\system32\DRIVERS\s7sn2srtx.sys;c:\windows\SYSNATIVE\DRIVERS\s7sn2srtx.sys [x]S2 S7TraceServiceX;S7TraceServiceX;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [x]S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [x]S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [x]S2 UA Local Discovery Server;UA Local Discovery Server;c:\program files (x86)\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe;c:\program files (x86)\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe [x]S2 UNS;Intel Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel Management Engine Components\UNS\UNS.exe [x]S2 VIPAppService;VIPAppService;c:\program files (x86)\Symantec\VIP Access Client\VIPAppService.exe;c:\program files (x86)\Symantec\VIP Access Client\VIPAppService.exe [x]S2 WebUpdate4;Web Update Wizard Service V4;c:\windows\SysWOW64\WebUpdateSvc4.exe;c:\windows\SysWOW64\WebUpdateSvc4.exe [x]S2 WMCoreService;Mobile Broadband Service;c:\program files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode;c:\program files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode [x]S2 ZeroConfigService;Intel PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]S3 5U877;5U877;c:\windows\system32\DRIVERS\5U877.sys;c:\windows\SYSNATIVE\DRIVERS\5U877.sys [x]S3 dpmconv;SIMATIC NET DP Driver;c:\windows\system32\DRIVERS\dpmconv.sys;c:\windows\SYSNATIVE\DRIVERS\dpmconv.sys [x]S3 ecnssndis; Mobile Broadband Driver;c:\windows\system32\Drivers\wwuss64.sys;c:\windows\SYSNATIVE\Drivers\wwuss64.sys [x]S3 ecnssndisfltr; Mobile Broadband Driver Filter;c:\windows\system32\Drivers\wwussf64.sys;c:\windows\SYSNATIVE\Drivers\wwussf64.sys [x]S3 fwkbdrtm;fwkbdrtm;c:\windows\system32\drivers\fwkbdrtm.sys;c:\windows\SYSNATIVE\drivers\fwkbdrtm.sys [x]S3 ICCS;Intel Integrated Clock Controller Service - Intel ICCS;c:\program files (x86)\Intel\Intel Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel Integrated Clock Controller Service\ICCProxy.exe [x]S3 IntcDAud;Intel Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]S3 iusb3hub;Intel USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]S3 iusb3xhc;Intel USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys;c:\windows\SYSNATIVE\DRIVERS\iwdbus.sys [x]S3 l36wgps; Mobile Broadband GPS Port;c:\windows\system32\DRIVERS\l36wgps64.sys;c:\windows\SYSNATIVE\DRIVERS\l36wgps64.sys [x]S3 l36wscard; Mobile Broadband USIM Port;c:\windows\system32\DRIVERS\l36wscard.sys;c:\windows\SYSNATIVE\DRIVERS\l36wscard.sys [x]S3 Mbm3CBus;H5321 gw Mobile Broadband Device (WDM);c:\windows\system32\DRIVERS\Mbm3CBus.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3CBus.sys [x]S3 Mbm3DevMt; Mobile Broadband Device Management Driver (WDM);c:\windows\system32\DRIVERS\Mbm3DevMt.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3DevMt.sys [x]S3 Mbm3mdfl; Mobile Broadband Modem Port Filter;c:\windows\system32\DRIVERS\Mbm3mdfl.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3mdfl.sys [x]S3 Mbm3Mdm; Mobile Broadband Modem Port Driver;c:\windows\system32\DRIVERS\Mbm3Mdm.sys;c:\windows\SYSNATIVE\DRIVERS\Mbm3Mdm.sys [x]S3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys;c:\windows\SYSNATIVE\drivers\nidimkl.sys [x]S3 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver;c:\windows\system32\DRIVERS\niede.sys;c:\windows\SYSNATIVE\DRIVERS\niede.sys [x]S3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys;c:\windows\SYSNATIVE\drivers\nimru2kl.sys [x]S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys;c:\windows\SYSNATIVE\drivers\NiViPciKl.sys [x]S3 Power Manager DBC Service;Power Manager Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [x]S3 s7odpx2x64;SIMATIC Knotentaufe;c:\windows\system32\DRIVERS\s7odpx2x64.sys;c:\windows\SYSNATIVE\DRIVERS\s7odpx2x64.sys [x]S3 s7oppinx64;SIMATIC PPI Transport;c:\windows\system32\DRIVERS\s7oppinx64.sys;c:\windows\SYSNATIVE\DRIVERS\s7oppinx64.sys [x]S3 s7oserix64;Siemens PC Serial Cable;c:\windows\system32\Drivers\s7oserix64.sys;c:\windows\SYSNATIVE\Drivers\s7oserix64.sys [x]S3 s7osmcax64;SIMATIC PC Adapter RS232;c:\windows\system32\DRIVERS\s7osmcax64.sys;c:\windows\SYSNATIVE\DRIVERS\s7osmcax64.sys [x]S3 s7osobux64;SIMATIC SoftBus;c:\windows\system32\DRIVERS\s7osobux64.sys;c:\windows\SYSNATIVE\DRIVERS\s7osobux64.sys [x]S3 s7otmcd64x;SIMATIC Memory Cards;c:\windows\system32\Drivers\s7otmcd64x.sys;c:\windows\SYSNATIVE\Drivers\s7otmcd64x.sys [x]S3 s7otranx64;SIMATIC Transport;c:\windows\system32\DRIVERS\s7otranx64.sys;c:\windows\SYSNATIVE\DRIVERS\s7otranx64.sys [x]S3 s7otsadx64;SIMATIC TS Adapter RS232;c:\windows\system32\DRIVERS\s7otsadx64.sys;c:\windows\SYSNATIVE\DRIVERS\s7otsadx64.sys [x]S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys;c:\windows\SYSNATIVE\DRIVERS\Tvti2c.sys [x]S3 tvtvcamd;ThinkVantage Virtual Camera;c:\windows\system32\DRIVERS\tvtvcamd.sys;c:\windows\SYSNATIVE\DRIVERS\tvtvcamd.sys [x]S3 vsnl2ada;SIMATIC NET FDL Driver;c:\windows\system32\DRIVERS\vsnl2ada.sys;c:\windows\SYSNATIVE\DRIVERS\vsnl2ada.sys [x]S3 WwanUsbServ;Mobile Broadband Driver;c:\windows\system32\DRIVERS\WwanUsbMp64.sys;c:\windows\SYSNATIVE\DRIVERS\WwanUsbMp64.sys [x]..--- Other Services/Drivers In Memory ---.*Deregistered* - FileOpenWebPublisherScreenHookDriver.Contents of the 'Scheduled Tasks' folder.2014-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 03:01].2014-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 03:01]..--------- X64 Entries -----------..[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]@="F241C880-6982-4CE5-8CF7-7085BA96DA5A"[HKEY_CLASSES_ROOT\CLSID\F241C880-6982-4CE5-8CF7-7085BA96DA5A]2014-07-18 20:32 261832 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]@="A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E"[HKEY_CLASSES_ROOT\CLSID\A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E]2014-07-18 20:32 261832 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]@="BBACC218-34EA-4666-9D7A-C78F2274A524"[HKEY_CLASSES_ROOT\CLSID\BBACC218-34EA-4666-9D7A-C78F2274A524]2014-07-18 20:32 261832 ----a-w- c:\users\admin\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]@="8BA85C75-763B-4103-94EB-9470F12FE0F7"[HKEY_CLASSES_ROOT\CLSID\8BA85C75-763B-4103-94EB-9470F12FE0F7]2014-09-25 10:10 2334416 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]@="CD55129A-B1A1-438E-A425-CEBC7DC684EE"[HKEY_CLASSES_ROOT\CLSID\CD55129A-B1A1-438E-A425-CEBC7DC684EE]2014-09-25 10:10 2334416 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll.[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]@="E768CD3B-BDDC-436D-9C13-E1B39CA257B1"[HKEY_CLASSES_ROOT\CLSID\E768CD3B-BDDC-436D-9C13-E1B39CA257B1]2014-09-25 10:10 2334416 ----a-w- c:\program files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll.[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-09-13 13653208]"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-08-30 1321688]"TpShocks"="TpShocks.exe" [2014-02-17 384344]"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2014-08-07 295712]"egui"="c:\program files\ESET\ESET Endpoint Antivirus\egui.exe" [2014-04-04 4148664]"MFNetworkScanUtility"="c:\program files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE" [2012-09-27 486552]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-11-28 165872]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-11-28 407536]"Persistence"="c:\windows\system32\igfxpers.exe" [2013-11-28 444400].------- Supplementary Scan -------.uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENPuLocal Page = c:\windows\system32\blank.htmmLocal Page = c:\windows\SysWOW64\blank.htmIE: &Download using ASU_BitsWrapper - c:\program files (x86)\Common Files\Siemens\ASU\iecontext.htmIE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000IE: Se&nd to OneNote - c:\program files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105IE: {CC963627-B1DC-40E0-B52A-CF21EE748450 - CC963627-B1DC-40E0-B52A-CF21EE748450 - c:\progra2\PCTRAN1\webie.dllIE: {CC963627-B1DC-40E0-B52A-CF21EE748451 - CC963627-B1DC-40E0-B52A-CF21EE748451 - c:\progra2\PCTRAN1\webie.dllIE: {CC963627-B1DC-40E0-B52A-CF21EE748452 - CC963627-B1DC-40E0-B52A-CF21EE748452 - c:\progra2\PCTRAN1\webie.dllTCP: DhcpNameServer = 8.8.8.8 8.8.8.4FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nno330qa.default\FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig.- - - - ORPHANS REMOVED - - - -.Toolbar-Locked - (no file)HKLM_Wow6432Node-ActiveSetup-2D46B6DC-2207-486B-B523-A557E6D54B47 - startToolbar-Locked - (no file)ShellIconOverlayIdentifiers-A759AFF6-5851-457D-A540-F4ECED148351 - (no file)...[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\19114156-8E9A-4D4E-9EE9-17A0E48D3BBB]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\19114156-8E9A-4D4E-9EE9-17A0E48D3BBB\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\19114156-8E9A-4D4E-9EE9-17A0E48D3BBB\LocalServer32]@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\19114156-8E9A-4D4E-9EE9-17A0E48D3BBB\TypeLib]@="FAB3E735-69C7-453B-A446-B6823C6DF1C9".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\InprocServer32]@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\ProgID]@="ShockwaveFlash.ShockwaveFlash.10".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\ToolboxBitmap32]@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\TypeLib]@="D27CDB6B-AE6D-11cf-96B8-444553540000".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB6E-AE6D-11cf-96B8-444553540000\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\InprocServer32]@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\ToolboxBitmap32]@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\TypeLib]@="D27CDB6B-AE6D-11cf-96B8-444553540000".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\D27CDB70-AE6D-11cf-96B8-444553540000\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\1D4C8A81-B7AC-460A-8C23-98713C41D6B3]@Denied: (A 2) (Everyone)@="IFlashBroker3".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\1D4C8A81-B7AC-460A-8C23-98713C41D6B3\ProxyStubClsid32]@="00020424-0000-0000-C000-000000000046".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\1D4C8A81-B7AC-460A-8C23-98713C41D6B3\TypeLib]@="FAB3E735-69C7-453B-A446-B6823C6DF1C9""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\B7EFF951-E52F-45CC-9EF7-57124F2177CC]@Denied: (A) (Everyone)"Solution"="15727DE6-F92D-4E46-ACB4-0E2C58B31A18".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]@Denied: (A) (Everyone).[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]"Key"="ActionsPane3""Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Siemens\StationManager\Catalog]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Siemens\StationManager\General\Groups]"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\4D36E96D-E325-11CE-BFC1-08002BE10318\0000\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\4D36E96D-E325-11CE-BFC1-08002BE10318\0001\AllUserSettings]@Denied: (A) (Users)@Denied: (A) (Everyone)@Allowed: (B 1 2 3 4 5) (S-1-5-20)"BlindDial"=dword:00000000.[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Other Running Processes ------------------------.c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exec:\program files (x86)\Juniper Networks\Common Files\dsNcService.exec:\windows\SysWOW64\lkads.exec:\program files (x86)\National Instruments\MAX\nimxs.exec:\program files (x86)\National Instruments\Shared\Security\nidmsrv.exec:\program files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exec:\program files (x86)\National Instruments\Shared\Tagger\tagsrv.exec:\program files (x86)\Siemens\SIMATIC WinCC flexible\WinCC flexible 2008 Runtime\SmartServer.exec:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exec:\program files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exec:\windows\SysWOW64\lkcitdl.exec:\windows\SysWOW64\lktsrv.exec:\windows\SysWOW64\nipxism.exec:\windows\SysWOW64\pniopcac.exec:\windows\SysWOW64\pniopcac.exec:\windows\SysWOW64\pniopcac.exec:\progra1\Lenovo\HOTKEY\TPONSCR.EXEc:\windows\SysWOW64\rundll32.exec:\program files (x86)\Common Files\Siemens\S7UBTOOX\S7ubtoox.exec:\program files (x86)\Common Files\Siemens\Sqlany\dbsrv9.exec:\program files (x86)\ThinkPad\Utilities\SCHTASK.exec:\program files\Lenovo\Lenovo Solution Center\LSCNotify.exec:\program files (x86)\Lenovo\message center plus\mcplaunch.exec:\program files (x86)\Intel\Intel Management Engine Components\LMS\LMS.exec:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exec:\program files (x86)\Lenovo\System Update\SUService.exe.**************************************************************************.Completion time: 2014-11-03 19:55:32 - machine was rebootedComboFix-quarantined-files.txt 2014-11-03 18:55.Pre-Run: 326 715 953 152 bytes freePost-Run: 326 205 677 568 bytes free.- - End Of File - - F5F44F80785F55BD12F6147618E3F407
National Instruments LabVIEW 2012 v12.0 (x86 x64)
2ff7e9595c
Comments