Start:: CreateRestorePoint: CloseProcesses: Task: {901FE50D-E936-4091-B0CB-4A6390D0EA3C} - System32\Tasks\File Helper => C:\Program Files (x86)\File Helper\File Helper.lnk [Argument = --scan --stack=from-scheduler] Task: C:\Windows\Tasks\File Helper.job => C:\Program Files (x86)\File Helper\File Helper.lnk SearchScopes: HKU\S-1-5-21-3016632431-908110033-473974409-1000 -> DefaultScope {7BEEF91B-54DA-4993-86C7-3FC49E8A7924} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR0D20141007&p={searchTerms} SearchScopes: HKU\S-1-5-21-3016632431-908110033-473974409-1000 -> {3FE41D2E-FEDE-4BDE-9057-E82035A2A143} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR0D19700101&p={searchTerms} SearchScopes: HKU\S-1-5-21-3016632431-908110033-473974409-1000 -> {7BEEF91B-54DA-4993-86C7-3FC49E8A7924} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR0D20141007&p={searchTerms} SearchScopes: HKU\S-1-5-21-3016632431-908110033-473974409-1000 -> {D396D4D6-2E34-44F1-9168-851DE1983F36} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR0D19700101&p={searchTerms} SearchScopes: HKU\S-1-5-21-3016632431-908110033-473974409-1000 -> {E82FD3C9-51D0-4F1D-8B83-2A8CDD9AA4AB} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR0D20141007&p={searchTerms} CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=E211FR0G0&p={searchTerms} C:\Users\Fiat\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiekimdgbphfmnlbiahcfdgcipcopmep C:\Program Files (x86)\File Helper WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\":: WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99] WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate] EmptyTemp: End::