start:: CreateRestorePoint: CloseProcesses: Hosts: RemoveProxy: EmptyTemp: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe S3 WsDrvInst; "C:\Program Files (x86)\Aimersoft\Aimersoft iTube Studio\DriverInstall.exe" [X] S1 p1485255560am; \??\C:\Users\lenovo\AppData\Local\Temp\bk59D3.tmp\p1485255560am.sys [X] 2019-02-03 20:12 - 2017-10-15 21:15 - 000000000 ____D C:\Users\lenovo\Downloads\PopcornTime 2017-01-25 14:32 - 2017-01-25 14:32 - 000000000 _____ () C:\Program Files (x86)\metadata 2017-01-25 14:32 - 2019-02-03 21:36 - 000000040 _____ () C:\Program Files (x86)\settings.dat 2017-05-21 19:45 - 2018-04-29 20:13 - 000001155 _____ () C:\Users\lenovo\AppData\Roaming\SAS7_000.DAT Task: {49C527C0-EDF7-427A-BF5D-E6A866D4AB0D} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\task.vbs" Task: {C34A298A-5022-4EE4-9E29-87BDEAD1CD36} - System32\Tasks\Clokisevuboly Reports => C:\Program Files (x86)\Drgaingguloly\nobent.exe WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\":: WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99] WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate] AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [546] cmd: ipconfig /flushdns end::