Logfile of random's system information tool 1.10 (written by random/random) Run by Alain at 2014-05-27 09:10:05 Microsoft Windows 7 Professional Service Pack 1 System drive C: has 124 GB (73%) free of 171 GB Total RAM: 6134 MB (67% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:10:06, on 27/05/2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16866) Boot mode: Normal Running processes: C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe E:\Noads\NoAds.exe C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\NIS.exe C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE E:\Shareaza\Shareaza\Shareaza.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files\trend micro\Alain.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hln.be/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - E:\SNAGIT\SnagItBHO.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - E:\Shareaza\Shareaza\RazaWebHook32.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\IPS\IPSBHO.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Java\bin\ssv.dll O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Java\bin\jp2ssv.dll O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\coIEPlg.dll O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - E:\SNAGIT\SnagItIEAddin.dll O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [NBAgent] "E:\Nero BackItUp\NBAgent.exe" /WinStart O4 - HKLM\..\Run: [Cobian Backup 11 interface] "C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe" -service O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe O4 - HKCU\..\Run: [NoAds] "E:\Noads\NoAds.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: Download with &Shareaza - res://E:\Shareaza\Shareaza\RazaWebHook32.dll/3000 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {49C9FECC-02EE-49D9-8171-F548577E7ACD} (Uploader Control) - http://ua.foto.com/ImageUploader8.cab O16 - DPF: {53049A9A-1122-4673-B8D4-12F545AE3285} (CV781Object Object) - http://avm565a-sn.ddns.eagleeyes.tw:85/AVC_AX_764.cab O16 - DPF: {971FC730-55F1-461F-83FD-B3BF5E1F039E} (AMCCtrl Class) - http://178.118.53.209:8910/AVC_AX_742.cab O16 - DPF: {AA09E7F8-1C11-4B65-9D61-EB6CB0F1E86C} (CV781Object Object) - http://sieuthivienthong.dyndns.org:8081/AVC_AX_35X.cab O16 - DPF: {B513310D-152C-4521-97C4-C92860987AD2} (CameraViewer Class) - http://113.161.84.225:9006/MediaClientAxCtrl.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Cobian Backup 11 Gravity (CobianBackup11) - Luis Cobian, CobianSoft - C:\Program Files (x86)\Cobian Backup 11\cbService.exe O23 - Service: Cron Service for Prey (CronService) - Fork Ltd. - E:\Prey\platform\windows\cronsvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HASP License Manager (hasplms) - Unknown owner - C:\Windows\system32\hasplms.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\NIS.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10743 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\Windows\system32\services.exe winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch "C:\Windows\system32\nvvsvc.exe" "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\Windows\system32\nvvsvc.exe -session -first C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files (x86)\Cobian Backup 11\cbService.exe" "E:\Prey\platform\windows\cronsvc.exe" "C:\Windows\system32\Dwm.exe" C:\Windows\Explorer.EXE "taskhost.exe" C:\Windows\system32\hasplms.exe -run "C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" "C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\NIS.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe" "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" "E:\Noads\NoAds.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe" "C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe" "C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe" -service "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" C:\Windows\system32\SearchIndexer.exe /Embedding "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1 "C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\NIS.exe" /c /a /s UserSession C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE" "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4440 CREDAT:209921 /prefetch:2 "C:\Program Files (x86)\Nero\Update\NASvc.exe" "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4440 CREDAT:603225 /prefetch:2 "E:\Shareaza\Shareaza\Shareaza.exe" "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4440 CREDAT:1651775 /prefetch:2 "C:\Windows\system32\NOTEPAD.EXE" C:\rsit\log.txt taskhost.exe $(Arg0) taskeng.exe {96BCC21D-0275-4F41-9FB3-3F0B52092CD9} "C:\Users\Alain\Downloads\RSITx64 (1).exe" C:\Windows\system32\wbem\wmiprvse.exe ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}] SnagIt Toolbar Loader - E:\SNAGIT\DLLx64\SnagItBHO64.dll [2007-05-01 64584] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EEDB912-C5FA-486F-8334-57288578C627}] Shareaza Web Download Hook - E:\Shareaza\Shareaza\RazaWebHook64.dll [2011-05-29 99840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine64\21.3.0.12\coIEPlg.dll [2014-04-28 916320] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}] Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-05-08 163720] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}] Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-05-08 163720] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}] SnagIt Toolbar Loader - E:\SNAGIT\SnagItBHO.dll [2007-05-01 63048] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0EEDB912-C5FA-486F-8334-57288578C627}] Shareaza Web Download Hook - E:\Shareaza\Shareaza\RazaWebHook32.dll [2011-05-29 84992] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\coIEPlg.dll [2014-04-28 654176] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\IPS\IPSBHO.DLL [2014-02-21 392344] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - E:\Java\bin\ssv.dll [2014-05-08 462760] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}] Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - E:\Java\bin\jp2ssv.dll [2014-05-08 171944] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}] Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine64\21.3.0.12\coIEPlg.dll [2014-04-28 916320] {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2014-05-08 163720] {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - E:\SNAGIT\DLLx64\SnagItIEAddin64.dll [2007-05-01 212552] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\coIEPlg.dll [2014-04-28 654176] {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192] {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - E:\SNAGIT\SnagItIEAddin.dll [2007-05-01 161352] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-03-20 1797064] "AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "NoAds"=E:\Noads\NoAds.exe [2014-05-21 151552] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-07-05 421888] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904] ""= [] "Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [2014-05-08 3499896] "NBAgent"=E:\Nero BackItUp\NBAgent.exe [2010-09-03 1406248] "Cobian Backup 11 interface"=C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [2013-03-07 4407808] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336] "Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2014-04-01 2007392] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Adobe Gamma.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] wlnotify.dll [] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "ConsentPromptBehaviorUser"=3 "EnableLUA"=0 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableLinkedConnections"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NofolderOptions"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave1"=wdmaud.drv "midi"=wdmaud.drv "mixer1"=wdmaud.drv "aux"=wdmaud.drv "wave"=wdmaud.drv "midi3"=wdmaud.drv "mixer"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "wave2"=wdmaud.drv "midi1"=wdmaud.drv "mixer2"=wdmaud.drv "wave3"=wdmaud.drv "midi2"=wdmaud.drv "mixer3"=wdmaud.drv "vidc.CDV5"=cdv5codc.dll "vidc.CLLC"=cllccodc.dll "vidc.CUVC"=cuvccodc.dll "vidc.CDVC"=cdvccodc.dll "vidc.CDVH"=cdvhcodc.dll "vidc.CMIC"=cmiccodc.dll "vidc.CHQX"=chqxcodc.dll "vidc.C210"=c210codc.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-05-27 09:03:20 ----D---- C:\rsit 2014-05-27 09:03:20 ----D---- C:\Program Files\trend micro 2014-05-18 07:13:06 ----D---- C:\Users\Alain\AppData\Roaming\Bigasoft Total Video Converter 4 2014-05-16 05:30:37 ----D---- C:\ProgramData\Xilisoft 2014-05-16 05:02:29 ----D---- C:\Users\Alain\AppData\Roaming\Xilisoft 2014-05-16 04:59:48 ----D---- C:\Users\Alain\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2014-05-16 04:59:25 ----D---- C:\ProgramData\Wondershare Video Converter Ultimate 2014-05-16 04:53:59 ----D---- C:\Users\Alain\AppData\Roaming\Wondershare Video Converter Ultimate 2014-05-16 04:53:50 ----A---- C:\Windows\SYSWOW64\iconv.dll 2014-05-16 04:51:09 ----D---- C:\Users\Alain\AppData\Roaming\ImTOO 2014-05-16 04:50:57 ----D---- C:\ProgramData\ImTOO 2014-05-16 04:44:02 ----D---- C:\Users\Alain\AppData\Roaming\LockTime 2014-05-15 10:01:40 ----D---- C:\ProgramData\eBay 2014-05-14 12:18:58 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2014-05-14 12:18:58 ----A---- C:\Windows\system32\mshtmled.dll 2014-05-14 12:18:57 ----A---- C:\Windows\system32\mshtml.dll 2014-05-14 12:18:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-05-14 12:17:00 ----A---- C:\Windows\system32\lsasrv.dll 2014-05-14 12:17:00 ----A---- C:\Windows\system32\kerberos.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\wdigest.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\TSpkg.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\sspicli.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\secur32.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\schannel.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\objsel.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\msv1_0.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\KernelBase.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\kerberos.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\dimsroam.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\credssp.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\cngprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\capiprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\SYSWOW64\adprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\winlogon.exe 2014-05-14 12:16:59 ----A---- C:\Windows\system32\wincredprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\wdigest.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\TSpkg.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\sspisrv.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\sspicli.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\secur32.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\schannel.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\objsel.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\ntoskrnl.exe 2014-05-14 12:16:59 ----A---- C:\Windows\system32\msv1_0.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\lsass.exe 2014-05-14 12:16:59 ----A---- C:\Windows\system32\KernelBase.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\drivers\ksecpkg.sys 2014-05-14 12:16:59 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2014-05-14 12:16:59 ----A---- C:\Windows\system32\dpapiprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\dimsroam.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\credssp.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\cngprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\capiprovider.dll 2014-05-14 12:16:59 ----A---- C:\Windows\system32\adprovider.dll 2014-05-14 12:16:36 ----A---- C:\Windows\SYSWOW64\shell32.dll 2014-05-14 12:16:36 ----A---- C:\Windows\system32\shell32.dll 2014-05-14 12:16:35 ----A---- C:\Windows\system32\aepdu.dll 2014-05-14 12:16:35 ----A---- C:\Windows\system32\aeinv.dll 2014-05-12 10:14:29 ----D---- C:\Users\Alain\AppData\Roaming\PDAppFlex 2014-05-12 10:00:55 ----D---- C:\Program Files\Common Files\Adobe 2014-05-12 09:46:55 ----D---- C:\ProgramData\Package Cache 2014-05-10 05:44:21 ----A---- C:\Windows\SYSWOW64\BASSMOD.dll 2014-05-10 05:09:53 ----D---- C:\ProgramData\YTD Video Downloader 2014-05-09 17:28:07 ----D---- C:\ProgramData\LightScribe 2014-05-09 14:14:19 ----D---- C:\Users\Alain\AppData\Roaming\Opera 2014-05-09 05:57:18 ----D---- C:\Users\Alain\AppData\Roaming\NVIDIA 2014-05-09 05:57:17 ----D---- C:\ProgramData\Garmin 2014-05-08 10:56:11 ----D---- C:\Windows\Sun 2014-05-08 10:56:07 ----D---- C:\ProgramData\Oracle 2014-05-08 10:56:04 ----D---- C:\ProgramData\Sun 2014-05-08 10:56:04 ----A---- C:\Windows\SYSWOW64\javaws.exe 2014-05-08 10:56:01 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll 2014-05-08 10:56:01 ----A---- C:\Windows\SYSWOW64\javaw.exe 2014-05-08 10:56:01 ----A---- C:\Windows\SYSWOW64\java.exe 2014-05-07 18:00:09 ----D---- C:\Program Files (x86)\Cobian Backup 11 2014-05-07 11:36:11 ----A---- C:\Windows\SYSWOW64\setupempdrv03.exe 2014-05-07 11:36:11 ----A---- C:\Windows\SYSWOW64\EuGdiDrv.sys 2014-05-07 11:36:11 ----A---- C:\Windows\SYSWOW64\EuEpmGdi.dll 2014-05-07 11:36:11 ----A---- C:\Windows\SYSWOW64\epmntdrv.sys 2014-05-07 11:36:11 ----A---- C:\Windows\SYSWOW64\BootMan.exe 2014-05-07 11:36:11 ----A---- C:\Windows\system32\setupempdrvx64.exe 2014-05-07 11:36:11 ----A---- C:\Windows\system32\EuGdiDrv.sys 2014-05-07 11:36:11 ----A---- C:\Windows\system32\EuEpmGdi.dll 2014-05-07 11:36:11 ----A---- C:\Windows\system32\epmntdrv.sys 2014-05-07 11:36:11 ----A---- C:\Windows\system32\BootMan.exe 2014-05-06 14:56:32 ----D---- C:\Program Files (x86)\Garmin GPS Plugin 2014-05-06 14:56:31 ----D---- C:\Program Files\Garmin GPS Plugin 2014-05-06 14:56:25 ----D---- C:\Program Files (x86)\Garmin 2014-05-06 14:42:22 ----D---- C:\Users\Alain\AppData\Roaming\Garmin 2014-05-02 08:22:35 ----D---- C:\Program Files\DIFX 2014-05-02 08:22:26 ----D---- C:\Windows\SYSWOW64\beidpp 2014-05-02 08:22:19 ----D---- C:\Windows\SYSWOW64\siscardplugins 2014-05-02 08:22:19 ----D---- C:\Program Files\log 2014-05-02 08:22:19 ----D---- C:\Program Files (x86)\Mozilla Firefox 2014-05-02 08:22:19 ----D---- C:\Program Files (x86)\Belgium Identity Card 2014-05-02 05:15:18 ----D---- C:\ProgramData\TechSmith 2014-05-02 05:10:41 ----D---- C:\Belast 2014-05-01 11:06:14 ----D---- C:\Users\Alain\AppData\Roaming\FileZilla 2014-05-01 10:34:51 ----A---- C:\Windows\SYSWOW64\TempWmicBatchFile.bat 2014-04-28 05:25:34 ----A---- C:\Windows\SYSWOW64\mstscax.dll 2014-04-28 05:25:34 ----A---- C:\Windows\system32\mstscax.dll 2014-04-28 05:25:19 ----A---- C:\Windows\SYSWOW64\explorer.exe 2014-04-28 05:25:19 ----A---- C:\Windows\explorer.exe 2014-04-28 05:25:12 ----A---- C:\Windows\system32\spoolsv.exe 2014-04-28 05:25:12 ----A---- C:\Windows\splwow64.exe ======List of files/folders modified in the last 1 month====== 2014-05-27 09:05:52 ----D---- C:\Windows\Temp 2014-05-27 09:03:20 ----RD---- C:\Program Files 2014-05-27 08:50:43 ----SH---- C:\Program Files (x86)\desktop.ini 2014-05-27 08:50:43 ----RD---- C:\Program Files (x86) 2014-05-27 08:47:30 ----D---- C:\Windows\System32 2014-05-27 08:47:30 ----D---- C:\Windows\inf 2014-05-27 08:47:30 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-05-27 08:40:38 ----SHD---- C:\System Volume Information 2014-05-27 08:40:32 ----D---- C:\ProgramData\NVIDIA 2014-05-27 07:44:43 ----D---- C:\Windows\system32\config 2014-05-27 05:27:46 ----D---- C:\Windows\system32\catroot2 2014-05-26 10:02:48 ----D---- C:\Windows\system32\wbem 2014-05-26 10:02:48 ----D---- C:\Windows 2014-05-26 10:02:00 ----D---- C:\ProgramData\Norton 2014-05-26 10:01:59 ----D---- C:\Windows\Tasks 2014-05-26 10:01:59 ----D---- C:\Windows\SysWOW64 2014-05-26 10:01:59 ----D---- C:\Windows\system32\Tasks 2014-05-26 10:01:59 ----D---- C:\Windows\system32\DriverStore 2014-05-26 10:01:59 ----D---- C:\Windows\Downloaded Program Files 2014-05-26 10:01:57 ----D---- C:\Windows\registration 2014-05-23 11:11:16 ----D---- C:\Users\Alain\AppData\Roaming\Adobe 2014-05-22 08:11:08 ----HD---- C:\ProgramData 2014-05-21 12:16:04 ----D---- C:\Windows\system32\drivers\NISx64 2014-05-21 05:15:23 ----D---- C:\Users\Alain\AppData\Roaming\FLV and Media Player 2014-05-16 05:43:29 ----D---- C:\Windows\debug 2014-05-16 05:30:40 ----SHD---- C:\Windows\Installer 2014-05-16 05:30:40 ----SHD---- C:\Config.Msi 2014-05-16 04:53:53 ----D---- C:\Program Files (x86)\Common Files 2014-05-16 04:51:06 ----D---- C:\Windows\winsxs 2014-05-15 07:09:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe 2014-05-14 13:01:26 ----D---- C:\Windows\rescache 2014-05-14 12:46:11 ----D---- C:\Windows\Microsoft.NET 2014-05-14 12:45:52 ----RSD---- C:\Windows\assembly 2014-05-14 12:33:37 ----SD---- C:\Windows\system32\CompatTel 2014-05-14 12:33:37 ----D---- C:\Windows\system32\nl-NL 2014-05-14 12:33:37 ----D---- C:\Windows\PolicyDefinitions 2014-05-14 12:33:36 ----D---- C:\Windows\system32\drivers 2014-05-14 12:19:00 ----D---- C:\Windows\system32\catroot 2014-05-14 12:18:50 ----D---- C:\ProgramData\Microsoft Help 2014-05-14 12:18:26 ----D---- C:\Windows\system32\MRT 2014-05-14 12:17:44 ----A---- C:\Windows\system32\MRT.exe 2014-05-12 14:45:03 ----D---- C:\Program Files (x86)\Adobe 2014-05-12 14:44:34 ----D---- C:\ProgramData\Adobe 2014-05-12 14:21:54 ----D---- C:\ProgramData\regid.1986-12.com.adobe 2014-05-12 10:01:31 ----RSD---- C:\Windows\Fonts 2014-05-12 10:00:55 ----D---- C:\Program Files\Common Files 2014-05-11 09:28:04 ----SD---- C:\Users\Alain\AppData\Roaming\Microsoft 2014-05-11 09:28:04 ----SD---- C:\ProgramData\Microsoft 2014-05-09 14:18:11 ----A---- C:\Windows\win.ini 2014-05-09 06:59:07 ----D---- C:\Windows\system32\wdi 2014-05-09 06:25:45 ----D---- C:\Windows\system32\CodeIntegrity 2014-05-02 08:22:11 ----D---- C:\drivers 2014-04-29 06:09:45 ----D---- C:\Users\Alain\AppData\Roaming\Shareaza 2014-04-29 06:04:31 ----SH---- C:\Program Files\desktop.ini 2014-04-28 08:43:02 ----D---- C:\Windows\system32\NDF 2014-04-28 05:31:10 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-04-28 05:28:20 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI 2014-04-28 05:28:03 ----D---- C:\Program Files (x86)\Microsoft Office ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888] R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1503000.00C\SYMDS64.SYS [2013-10-30 493656] R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1503000.00C\SYMEFA64.SYS [2014-03-04 1148120] R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552] R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.2.0.38\Definitions\BASHDefs\20140510.001\BHDrvx64.sys [2014-05-10 1530160] R1 ccSet_NIS;NIS Settings Manager; C:\Windows\system32\drivers\NISx64\1503000.00C\ccSetx64.sys [2014-02-25 162392] R1 cdrblock;cdrblock; C:\Windows\system32\DRIVERS\cdrblock.sys [2011-04-21 36696] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2014-04-25 484952] R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.2.0.38\Definitions\IPSDefs\20140526.001\IDSvia64.sys [2014-04-25 525016] R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1503000.00C\SRTSPX64.SYS [2013-10-30 36952] R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1503000.00C\Ironx64.SYS [2013-10-30 264280] R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NISx64\1503000.00C\SYMNETS.SYS [2014-02-18 593112] R2 aksdf;aksdf; C:\Windows\system32\DRIVERS\aksdf.sys [2013-08-09 91784] R2 aksfridge;Sentinel Fridge; C:\Windows\system32\DRIVERS\aksfridge.sys [2013-08-09 140736] R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2013-08-09 331328] R3 akshasp;SafeNet Inc. HASP Key; C:\Windows\system32\DRIVERS\akshasp.sys [2013-08-09 60488] R3 akshhl;SafeNet Inc. Sentinel HL Key; C:\Windows\system32\DRIVERS\akshhl.sys [2013-08-09 63944] R3 aksusb;SafeNet Inc. USB Key; C:\Windows\system32\DRIVERS\aksusb.sys [2013-08-09 303624] R3 e1yexpress;Stuurprogramma voor Intel(R) Gigabit-netwerkverbindingen; C:\Windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088] R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.2.0.38\Definitions\VirusDefs\20140526.008\ENG64.SYS [2014-05-07 126040] R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\21.2.0.38\Definitions\VirusDefs\20140526.008\EX64.SYS [2014-05-07 2099288] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-03-10 86120] R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NISx64\1503000.00C\SRTSP64.SYS [2014-02-13 875736] R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2014-04-26 177752] R3 VMHybrid64;VMHybrid service; C:\Windows\system32\DRIVERS\VMHybr64.sys [2011-03-14 1410048] S3 cxbu0x64;OMNIKEY 3x21; C:\Windows\system32\DRIVERS\cxbu0x64.sys [2014-04-05 191224] S3 epmntdrv;epmntdrv; \??\C:\Windows\syswow64\epmntdrv.sys [2010-07-15 14216] S3 EuGdiDrv;EuGdiDrv; \??\C:\Windows\syswow64\EuGdiDrv.sys [2010-07-15 8456] S3 Ph3xIB64;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB64.sys [2009-06-10 1627520] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496] S3 usbser;USB Serial emulation driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432] R2 CobianBackup11;Cobian Backup 11 Gravity; C:\Program Files (x86)\Cobian Backup 11\cbService.exe [2013-03-07 1131008] R2 CronService;Cron Service for Prey; E:\Prey\platform\windows\cronsvc.exe [2013-05-08 23552] R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136] R2 hasplms;HASP License Manager; C:\Windows\system32\hasplms.exe [2013-08-09 4609928] R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120] R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2013-07-18 762192] R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\NIS.exe [2014-05-11 276376] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 922968] R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088] S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-26 116648] S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2014-04-26 72704] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-15 257712] S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-26 116648] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136] S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-26 1255736] S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] -----------------EOF-----------------