Logfile of random's system information tool 1.10 (written by random/random) Run by mark at 2014-08-17 17:26:38 Microsoft Windows 8.1 Pro System drive C: has 409 GB (82%) free of 500 GB Total RAM: 10231 MB (75% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:26:45, on 17/08/2014 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.16384) Boot mode: Normal Running processes: C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files\trend micro\mark.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" O4 - HKCU\..\Run: [Bitdefender Wallet Application Agent] "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet] "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet Application Agent] "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" (User 'Default user') O4 - Startup: Sidebar114.lnk = C:\Program Files\Windows Sidebar\sidebar.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe O23 - Service: SafeBox - Bitdefender - C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Bitdefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: Bitdefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender\vsserv.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 8739 bytes ======Listing Processes====== wininit.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS "C:\Program Files\Bitdefender\Bitdefender\vsserv.exe" /service "C:\WINDOWS\system32\nvvsvc.exe" "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files\Bonjour\mDNSResponder.exe" dashost.exe {3a4f75d0-f3e1-42ed-873d99c2abe140f3} "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" C:\WINDOWS\SysWOW64\PnkBstrA.exe "C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe" C:\WINDOWS\system32\svchost.exe -k imgsvc "C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe" /service "C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe" C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-630a3797-d69f-4b99-8253-6060adc957c4 -SystemEventPortName:HostProcess-544dec10-c166-448e-850f-adaa3c88c988 -IoCancelEventPortName:HostProcess-d76c2256-1f50-48f9-b877-a175ee6a1c1a -NonStateChangingEventPortName:HostProcess-06dfb69e-0da0-4146-b9ea-7c96132a70a1 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:30008ed7-ac2b-4251-aca8-b00c17c35761 -DeviceGroupId:WpdFsGroup C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet C:\WINDOWS\system32\SearchIndexer.exe /Embedding C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files\iPod\bin\iPodService.exe" C:\WINDOWS\System32\WinLogon.exe -SpecialSession "LogonUI.exe" /flags:0x0 -hiberboot C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\WinLogon.exe -SpecialSession -hiberboot "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\WINDOWS\system32\nvvsvc.exe -session "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp \??\C:\WINDOWS\system32\conhost.exe 0x4 "c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe" "c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe" C:\WINDOWS\Explorer.EXE taskhostex.exe "C:\Program Files\Bitdefender\Bitdefender\bdagent.exe" C:\Windows\System32\RuntimeBroker.exe -Embedding "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe" "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "C:\Program Files\Windows Sidebar\sidebar.exe" "C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca "C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding "C:\Windows\System32\SettingSyncHost.exe" -Embedding "C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical C:\Windows\System32\skydrive.exe -Embedding "C:\WINDOWS\system32\wwahost.exe" -ServerName:Microsoft.WindowsLive.Mail.wwa "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server "C:\Program Files\Internet Explorer\iexplore.exe" -ServerName:DefaultBrowserServer "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:67624 CREDAT:267777 /prefetch:1 "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:67624 CREDAT:267778 /prefetch:1 "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-379617572-2991067909-4128941990-1001416_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-379617572-2991067909-4128941990-1001416 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:85284 CREDAT:267521 /prefetch:2 "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:85284 CREDAT:791865 /prefetch:2 "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe417_ Global\UsGthrCtrlFltPipeMssGthrPipe417 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588 "C:\Users\mark\Desktop\RSITx64.exe" ======Scheduled tasks folder====== C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\WINDOWS\tasks\RegClean Pro_DEFAULT.job - C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe -default C:\WINDOWS\tasks\RegClean Pro_UPDATES.job - C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe -updatecheck ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}] Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-02-25 193992] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}] Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll [2014-02-25 156400] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11 462760] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184] "XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-09-30 825184] "Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [2013-11-14 1028384] "ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2013-11-14 1064224] "Bdagent"=C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [2014-05-22 1743088] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728] "Bitdefender Wallet Agent"=C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [2014-05-22 568400] "Bitdefender Wallet Application Agent"=C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [2014-05-22 614744] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040] "APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896] "iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392] C:\Users\mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Sidebar114.lnk - C:\Program Files\Windows Sidebar\sidebar.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.yuy2"=msyuv.dll "vidc.i420"=iyuv_32.dll "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "vidc.yvyu"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "vidc.uyvy"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.msvc"=msvidc32.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "VIDC.FPS1"=frapsv64.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 ======List of files/folders created in the last 1 month====== 2014-08-17 17:26:38 ----D---- C:\rsit 2014-08-17 17:26:38 ----D---- C:\Program Files\trend micro 2014-08-10 11:21:56 ----D---- C:\Program Files\iPod 2014-08-10 11:21:55 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-08-10 11:21:55 ----D---- C:\Program Files\iTunes 2014-08-10 11:21:55 ----D---- C:\Program Files (x86)\iTunes 2014-08-05 20:39:12 ----D---- C:\Program Files (x86)\Steam 2014-07-30 21:59:59 ----D---- C:\ProgramData\Riot Games 2014-07-29 22:51:47 ----A---- C:\ProgramData\RUNDLL32.EXE-5356-F.txt 2014-07-29 22:20:52 ----A---- C:\ProgramData\RUNDLL32.EXE-2600-F.txt 2014-07-29 21:45:31 ----A---- C:\ProgramData\RUNDLL32.EXE-5060-F.txt 2014-07-29 20:36:21 ----A---- C:\ProgramData\RUNDLL32.EXE-4220-F.txt 2014-07-29 20:32:29 ----A---- C:\ProgramData\RUNDLL32.EXE-2232-F.txt 2014-07-29 19:35:01 ----D---- C:\WINDOWS\system32\꾯꾯꾯꾯꾯꾯꾯꾯꾯꾯꾯꾯꾯꾯 2014-07-29 19:16:36 ----A---- C:\ProgramData\RUNDLL32.EXE-5752-F.txt 2014-07-29 19:12:40 ----A---- C:\ProgramData\RUNDLL32.EXE-45796-F.txt ======List of files/folders modified in the last 1 month====== 2014-08-17 17:26:41 ----D---- C:\WINDOWS\Temp 2014-08-17 17:26:38 ----RD---- C:\Program Files 2014-08-17 17:25:08 ----D---- C:\WINDOWS\Prefetch 2014-08-17 17:24:59 ----D---- C:\WINDOWS\system32\drivers\etc 2014-08-17 17:24:44 ----D---- C:\WINDOWS\SoftwareDistribution 2014-08-17 17:00:00 ----D---- C:\WINDOWS\system32\sru 2014-08-17 14:46:21 ----D---- C:\WINDOWS\Microsoft.NET 2014-08-15 17:39:06 ----SHD---- C:\System Volume Information 2014-08-15 16:23:44 ----HD---- C:\Program Files\WindowsApps 2014-08-13 16:28:38 ----D---- C:\WINDOWS\system32\drivers 2014-08-13 16:28:37 ----D---- C:\WINDOWS\System32 2014-08-13 16:28:15 ----A---- C:\WINDOWS\system32\bdsandboxuh.dll.upd 2014-08-13 16:27:03 ----A---- C:\WINDOWS\system32\bdsandboxuiskin32.dll.upd 2014-08-11 20:11:19 ----D---- C:\WINDOWS\Inf 2014-08-11 20:11:19 ----D---- C:\Windows 2014-08-11 19:52:30 ----D---- C:\Program Files\CCleaner 2014-08-10 11:22:33 ----SHD---- C:\WINDOWS\Installer 2014-08-10 11:22:31 ----SHD---- C:\Config.Msi 2014-08-10 11:22:16 ----D---- C:\WINDOWS\SysWOW64 2014-08-10 11:21:55 ----RD---- C:\Program Files (x86) 2014-08-10 11:21:55 ----HD---- C:\ProgramData 2014-08-04 20:58:48 ----D---- C:\Users\mark\AppData\Roaming\Skype 2014-08-01 14:36:39 ----D---- C:\WINDOWS\AppReadiness 2014-08-01 13:40:24 ----D---- C:\ProgramData\NVIDIA 2014-08-01 07:01:33 ----A---- C:\bdlog.txt 2014-07-30 23:19:23 ----D---- C:\Program Files (x86)\Desk 365 2014-07-30 23:11:09 ----D---- C:\WINDOWS\system32\config 2014-07-30 22:01:31 ----D---- C:\ProgramData\Oracle 2014-07-30 22:01:10 ----D---- C:\Program Files (x86)\Common Files 2014-07-30 22:01:07 ----D---- C:\Program Files (x86)\Java 2014-07-30 16:44:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2014-07-30 01:18:06 ----D---- C:\WINDOWS\Tasks 2014-07-30 01:18:06 ----D---- C:\WINDOWS\system32\Tasks 2014-07-30 01:18:06 ----D---- C:\WINDOWS\system32\drivers\UMDF 2014-07-30 01:18:06 ----D---- C:\WINDOWS\system32\CodeIntegrity 2014-07-30 01:18:06 ----D---- C:\WINDOWS\system32\catroot2 2014-07-30 01:18:06 ----D---- C:\Users\mark\AppData\Roaming\vlc 2014-07-30 01:18:01 ----D---- C:\Program Files (x86)\Microsoft Works 2014-07-30 01:13:30 ----D---- C:\WINDOWS\registration 2014-07-30 01:12:22 ----D---- C:\ProgramData\Apple Computer 2014-07-30 01:07:59 ----D---- C:\WINDOWS\Logs ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 avc3;avc3; C:\WINDOWS\system32\DRIVERS\avc3.sys [2014-08-13 1260120] R0 trufos;trufos; C:\WINDOWS\system32\DRIVERS\trufos.sys [2014-08-13 419616] R1 BdfNdisf;@oem92.inf,%BdfNdisf_Desc%;BitDefender Firewall NDIS 6 Filter Driver; \??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2014-05-22 98768] R1 bdfwfpf;bdfwfpf; \??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2013-12-21 107008] R1 BDVEDISK;BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [2013-12-21 79192] R1 dtsoftbus01;@oem6.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012-12-12 283200] R3 avchv;@oem100.inf,%ServiceDesc%;avchv Function Driver; C:\WINDOWS\system32\DRIVERS\avchv.sys [2014-08-13 261496] R3 avckf;avckf; C:\WINDOWS\system32\DRIVERS\avckf.sys [2014-08-13 647752] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240] R3 gzflt;gzflt; C:\WINDOWS\system32\DRIVERS\gzflt.sys [2013-12-21 150256] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-06-19 4065296] R3 MTsensor;@oem4.inf,%ASACPI.DisplayName%;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2005-03-29 8192] R3 NVHDA;@oem97.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2013-10-27 196384] R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-11-14 12613408] R3 nvvad_WaveExtensible;@oem99.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2013-11-14 39200] R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360] S0 bdelam;bdelam; C:\WINDOWS\system32\drivers\bdelam.sys [2012-07-11 23456] S2 cpuz135;cpuz135; \??\C:\WINDOWS\system32\drivers\cpuz135_x64.sys [2010-11-09 21992] S3 bdfwfpf_pc;bdfwfpf_pc; \??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [2013-12-21 121928] S3 BDSandBox;BDSandBox; \??\C:\WINDOWS\system32\drivers\bdsandbox.sys [2013-12-21 82824] S3 dg_ssudbus;@oem102.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2013-10-28 107288] S3 ssudmdm;@oem103.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2013-10-28 204568] S3 USBAAPL64;@oem1.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-12-13 54784] S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\D:\Overclock\Real Temp\WinRing0x64.sys [2008-07-26 14544] S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\system32\DRIVERS\WinUsb.sys [2013-08-22 78848] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336] R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-11-14 15125280] R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-11-11 922912] R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2013-12-30 76888] R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2013-11-22 105448] R2 SafeBox;SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [2013-07-08 94624] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496] R2 UPDATESRV;Bitdefender Desktop Update Service; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [2013-12-21 67320] R2 VSSERV;Bitdefender Virus Shield; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [2014-05-22 1526800] R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-08-01 641352] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08 262320] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696] S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-07-16 542912] S4 BdDesktopParental;Bitdefender Desktop Parental Control; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [2013-12-21 77632] -----------------EOF-----------------