Logfile of random's system information tool 1.10 (written by random/random) Run by Stegisoft at 2014-09-06 05:06:12 Microsoft Windows 8.1 Pro System drive C: has 201 GB (84%) free of 238 GB Total RAM: 12007 MB (88% free) ======Listing Processes====== wininit.exe winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS "dwm.exe" C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" taskhostex.exe C:\Windows\Explorer.EXE "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service "C:\Program Files\ma-config.com\MaConfigAgent.exe" dashost.exe {4751300a-9e48-4fd0-bae5f3860a3e3034} C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe" C:\Windows\system32\wbem\wmiprvse.exe "C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000718 "C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Windows\System32\igfxtray.exe" "C:\Windows\System32\hkcmd.exe" "C:\Windows\System32\igfxpers.exe" "C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min "C:\Program Files (x86)\Common Files\Isabel\isacertupdate.exe" "C:\Windows\twain_32\Dell\DELL2145\Scan2Pc.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --channel="4964.0.1276416949\1875205724" /prefetch:3 "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568 "C:\Users\Stegisoft\Desktop\RSITx64.exe" /u ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler =========Mozilla firefox========= ProfilePath - C:\Users\Stegisoft\AppData\Roaming\Mozilla\Firefox\Profiles\5estv4im.default [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 14.0.0.179 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf] "Description"= "Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qnap.com/QVR] "Description"=QNAP VSMonitor Firefox Plugin 1.0 "Path"=C:\Program Files (x86)\QNAP\QVR\npQvrHost.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\synology.com/SurveillanceHelper] "Description"= "Path"=C:\Program Files (x86)\Synology\SurveillanceHelper\1.0.0.3\npSurveillanceHelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\synology.com/SurveillancePlugin] "Description"= "Path"=C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.419\npSurveillancePlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 14.0.0.179 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.65.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.65.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll C:\Users\Stegisoft\AppData\Roaming\Mozilla\Firefox\Profiles\5estv4im.default\extensions\ npapi@n.com ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-08-23 218776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-02 553896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-08-23 2335960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-02 211880] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-01-29 171992] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-01-29 399832] "Persistence"=C:\Windows\system32\igfxpers.exe [2014-01-29 442328] "IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352] "AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ANT Agent"=C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [2013-02-15 14731776] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2014-08-13 751184] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-05-08 959904] "IsaCertUpdate"=C:\Program Files (x86)\Common Files\Isabel\isacertupdate.exe [2013-10-22 1085960] "2145cn Scan2PC"=C:\Windows\twain_32\Dell\DELL2145\Scan2Pc.exe [2013-01-15 907264] "Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-07-22 2694040] "MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2013-02-05 76288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2014-01-29 442880] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll, schannel.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.yuy2"=msyuv.dll "vidc.i420"=iyuv_32.dll "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "vidc.yvyu"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "vidc.uyvy"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.msvc"=msvidc32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* .txt - open - "C:\Program Files\Just Great Software\EditPad Pro 7\EditPadPro7.exe" "%1" ======List of files/folders created in the last 1 month====== 2014-09-06 05:06:12 ----D---- C:\rsit 2014-09-06 05:06:12 ----D---- C:\Program Files\trend micro 2014-09-06 04:24:53 ----A---- C:\Windows\SYSWOW64\sqlite3.dll 2014-09-06 04:24:32 ----D---- C:\AdwCleaner 2014-09-04 05:02:03 ----A---- C:\Windows\SYSWOW64\unrar.dll 2014-09-04 05:02:03 ----A---- C:\Windows\system32\unrar64.dll 2014-09-04 05:02:01 ----D---- C:\Program Files (x86)\K-Lite Codec Pack 2014-09-02 17:44:41 ----D---- C:\Program Files (x86)\FOSCAM 2014-09-02 17:16:45 ----D---- C:\TimHillOne 2014-09-01 12:54:59 ----D---- C:\Users\Stegisoft\AppData\Roaming\NAPS2 2014-09-01 12:54:53 ----D---- C:\Program Files (x86)\NAPS2 2014-08-31 23:36:23 ----D---- C:\Program Files\WinRAR 2014-08-31 12:37:08 ----A---- C:\Windows\system32\win32k.sys 2014-08-23 12:09:09 ----D---- C:\Program Files (x86)\IPCamSetup 2014-08-23 01:53:04 ----A---- C:\Windows\system32\drivers\ew_juwwanecm.sys 2014-08-23 01:53:04 ----A---- C:\Windows\system32\drivers\ew_juextctrl.sys 2014-08-23 01:53:03 ----A---- C:\Windows\system32\drivers\ew_jucdcacm.sys 2014-08-23 01:53:01 ----A---- C:\Windows\system32\drivers\ew_jubusenum.sys 2014-08-23 01:52:45 ----D---- C:\ProgramData\Macrovision 2014-08-23 01:52:45 ----D---- C:\Program Files (x86)\Vodafone 2014-08-23 01:46:40 ----A---- C:\Windows\system32\drivers\tcpipBM.sys 2014-08-23 01:46:40 ----A---- C:\Windows\system32\drivers\BMLoad.sys 2014-08-23 01:30:26 ----D---- C:\Users\Stegisoft\AppData\Roaming\Vodafone 2014-08-23 01:30:12 ----A---- C:\Windows\system32\wdfcoinstaller01007.dll 2014-08-23 01:30:12 ----A---- C:\Windows\system32\drivers\ew_hwusbdev.sys 2014-08-23 01:30:07 ----D---- C:\ProgramData\Vodafone 2014-08-23 01:30:01 ----D---- C:\ProgramData\FLEXnet 2014-08-21 16:40:24 ----D---- C:\Recordfiles_192.168.0.202 2014-08-17 14:28:07 ----D---- C:\Users\Stegisoft\AppData\Roaming\Mozilla 2014-08-17 14:28:01 ----D---- C:\ProgramData\Mozilla 2014-08-17 14:28:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-17 14:27:59 ----D---- C:\Program Files (x86)\Mozilla Firefox 2014-08-14 17:16:55 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2014-08-14 17:16:55 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2014-08-14 17:16:54 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2014-08-14 17:16:54 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-08-14 17:16:54 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2014-08-14 17:16:54 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll 2014-08-14 17:16:54 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll 2014-08-14 17:16:54 ----A---- C:\Windows\system32\ie4uinit.exe 2014-08-14 17:16:53 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2014-08-14 17:16:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll 2014-08-14 17:16:53 ----A---- C:\Windows\system32\urlmon.dll 2014-08-14 17:16:53 ----A---- C:\Windows\system32\msfeeds.dll 2014-08-14 17:16:53 ----A---- C:\Windows\system32\iedkcs32.dll 2014-08-14 17:16:53 ----A---- C:\Windows\system32\dxtmsft.dll 2014-08-14 17:16:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2014-08-14 17:16:51 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2014-08-14 17:16:51 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2014-08-14 17:16:51 ----A---- C:\Windows\system32\iertutil.dll 2014-08-14 17:16:50 ----A---- C:\Windows\system32\mshtmled.dll 2014-08-14 17:16:50 ----A---- C:\Windows\system32\jscript9diag.dll 2014-08-14 17:16:50 ----A---- C:\Windows\system32\ieframe.dll 2014-08-14 17:16:50 ----A---- C:\Windows\system32\dxtrans.dll 2014-08-14 17:16:49 ----A---- C:\Windows\system32\mshtml.dll 2014-08-14 17:16:49 ----A---- C:\Windows\system32\jscript9.dll 2014-08-14 17:16:49 ----A---- C:\Windows\system32\ieapfltr.dll 2014-08-14 17:16:47 ----A---- C:\Windows\SYSWOW64\wininet.dll 2014-08-14 17:16:46 ----A---- C:\Windows\system32\wininet.dll 2014-08-14 17:16:45 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll 2014-08-14 17:16:45 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-14 17:16:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll 2014-08-14 17:16:44 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll 2014-08-14 17:16:44 ----A---- C:\Windows\system32\vbscript.dll 2014-08-14 17:16:44 ----A---- C:\Windows\system32\MshtmlDac.dll 2014-08-14 17:15:59 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll 2014-08-14 17:15:59 ----A---- C:\Windows\system32\rpcrt4.dll 2014-08-14 17:15:22 ----A---- C:\Windows\SYSWOW64\dxgi.dll 2014-08-14 17:15:22 ----A---- C:\Windows\system32\dxgi.dll 2014-08-14 17:15:22 ----A---- C:\Windows\system32\dwmcore.dll 2014-08-14 17:15:22 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys 2014-08-14 17:15:20 ----A---- C:\Windows\SYSWOW64\mfcore.dll 2014-08-14 17:15:20 ----A---- C:\Windows\system32\mfcore.dll 2014-08-14 17:15:20 ----A---- C:\Windows\system32\d3d9.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\SkyDriveShell.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\framedynos.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll 2014-08-14 17:15:19 ----A---- C:\Windows\SYSWOW64\d3d9.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\vpnike.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\SkyDriveShell.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\ntdll.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\localspl.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\fveapi.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\framedynos.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\drivers\mrxsmb.sys 2014-08-14 17:15:19 ----A---- C:\Windows\system32\dhcpcore6.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\dhcpcore.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\BFE.DLL 2014-08-14 17:15:19 ----A---- C:\Windows\system32\bdesvc.dll 2014-08-14 17:15:19 ----A---- C:\Windows\system32\actxprxy.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\WebClnt.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\Robocopy.exe 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\ncobjapi.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\framedyn.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\dhcpcsvc.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\d3d8thk.dll 2014-08-14 17:15:18 ----A---- C:\Windows\SYSWOW64\actxprxy.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\winbici.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\WebClnt.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\srms.dat 2014-08-14 17:15:18 ----A---- C:\Windows\system32\Robocopy.exe 2014-08-14 17:15:18 ----A---- C:\Windows\system32\reseteng.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\ncobjapi.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\IKEEXT.DLL 2014-08-14 17:15:18 ----A---- C:\Windows\system32\fvewiz.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\fvecpl.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\framedyn.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\drivers\vwifimp.sys 2014-08-14 17:15:18 ----A---- C:\Windows\system32\drivers\vwififlt.sys 2014-08-14 17:15:18 ----A---- C:\Windows\system32\drivers\agilevpn.sys 2014-08-14 17:15:18 ----A---- C:\Windows\system32\dhcpcsvc6.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\dhcpcsvc.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\BulkOperationHost.exe 2014-08-14 17:15:18 ----A---- C:\Windows\system32\BdeHdCfgLib.dll 2014-08-14 17:15:18 ----A---- C:\Windows\system32\BdeHdCfg.exe 2014-08-14 17:15:17 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2014-08-14 17:15:16 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe 2014-08-14 17:15:16 ----A---- C:\Windows\system32\TsWpfWrp.exe 2014-08-14 17:15:13 ----A---- C:\Windows\SYSWOW64\Wpc.dll 2014-08-14 17:15:13 ----A---- C:\Windows\system32\WpcWebSync.dll 2014-08-14 17:15:13 ----A---- C:\Windows\system32\WpcMon.exe 2014-08-14 17:15:13 ----A---- C:\Windows\system32\Wpc.dll 2014-08-14 17:15:13 ----A---- C:\Windows\system32\SyncEngine.dll 2014-08-14 17:15:13 ----A---- C:\Windows\system32\SkyDriveTelemetry.dll 2014-08-14 17:15:13 ----A---- C:\Windows\system32\SkyDrive.exe 2014-08-14 17:14:01 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll 2014-08-14 17:14:00 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll 2014-08-14 17:14:00 ----A---- C:\Windows\system32\drivers\tcpip.sys 2014-08-14 17:13:59 ----AC---- C:\Windows\system32\drivers\usbport.sys 2014-08-14 17:13:59 ----AC---- C:\Windows\system32\drivers\usbhub.sys 2014-08-14 17:13:59 ----A---- C:\Windows\SYSWOW64\gpprefcl.dll 2014-08-14 17:13:59 ----A---- C:\Windows\system32\rsaenh.dll 2014-08-14 17:13:59 ----A---- C:\Windows\system32\gpprefcl.dll 2014-08-14 17:13:58 ----AC---- C:\Windows\system32\drivers\usbuhci.sys 2014-08-14 17:13:58 ----AC---- C:\Windows\system32\drivers\USBHUB3.SYS 2014-08-14 17:13:58 ----AC---- C:\Windows\system32\drivers\usbehci.sys 2014-08-14 17:13:58 ----AC---- C:\Windows\system32\drivers\usbd.sys 2014-08-14 17:13:58 ----A---- C:\Windows\SYSWOW64\rsaenh.dll 2014-08-14 17:13:58 ----A---- C:\Windows\system32\WUDFSvc.dll 2014-08-14 17:13:58 ----A---- C:\Windows\system32\WUDFPlatform.dll 2014-08-14 17:13:58 ----A---- C:\Windows\system32\WUDFHost.exe 2014-08-14 17:13:58 ----A---- C:\Windows\system32\hal.dll 2014-08-14 17:13:58 ----A---- C:\Windows\system32\drivers\WUDFRd.sys 2014-08-14 17:13:58 ----A---- C:\Windows\system32\drivers\WUDFPf.sys 2014-08-14 17:13:58 ----A---- C:\Windows\system32\DaOtpCredentialProvider.dll 2014-08-14 17:13:58 ----A---- C:\Windows\system32\cscui.dll 2014-08-14 17:13:57 ----A---- C:\Windows\SYSWOW64\DaOtpCredentialProvider.dll 2014-08-14 17:13:17 ----A---- C:\Windows\SYSWOW64\msihnd.dll 2014-08-14 17:13:17 ----A---- C:\Windows\SYSWOW64\msi.dll 2014-08-14 17:13:17 ----A---- C:\Windows\SYSWOW64\authui.dll 2014-08-14 17:13:17 ----A---- C:\Windows\system32\msihnd.dll 2014-08-14 17:13:17 ----A---- C:\Windows\system32\msi.dll 2014-08-14 17:13:17 ----A---- C:\Windows\system32\consent.exe 2014-08-14 17:13:17 ----A---- C:\Windows\system32\authui.dll 2014-08-14 17:13:15 ----A---- C:\Windows\system32\aepdu.dll 2014-08-14 17:13:15 ----A---- C:\Windows\system32\aeinv.dll 2014-08-14 17:13:13 ----A---- C:\Windows\system32\MrmCoreR.dll 2014-08-14 17:12:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll 2014-08-14 17:12:51 ----A---- C:\Windows\system32\gdi32.dll 2014-08-14 17:12:50 ----A---- C:\Windows\system32\MDMAgent.exe 2014-08-12 13:42:21 ----D---- C:\Program Files (x86)\MetaGeek 2014-08-11 00:13:02 ----D---- C:\ProgramData\regid.1986-12.com.adobe 2014-08-11 00:12:40 ----D---- C:\Program Files\Adobe 2014-08-11 00:11:52 ----D---- C:\Program Files\Common Files\Adobe 2014-08-10 06:11:57 ----D---- C:\Program Files\Speccy 2014-08-10 00:59:41 ----D---- C:\ProgramData\Canneverbe Limited 2014-08-09 23:14:40 ----RHD---- C:\MSOCache 2014-08-07 02:02:07 ----SD---- C:\Windows\system32\CompatTel 2014-08-07 01:58:30 ----A---- C:\Windows\system32\termsrv.dll ======List of files/folders modified in the last 1 month====== 2014-09-06 05:06:20 ----D---- C:\Windows\Prefetch 2014-09-06 05:06:17 ----D---- C:\Windows\Temp 2014-09-06 05:06:12 ----RD---- C:\Program Files 2014-09-06 05:00:00 ----D---- C:\Windows\system32\sru 2014-09-06 04:47:41 ----RD---- C:\Windows\System32 2014-09-06 04:47:41 ----D---- C:\Windows\Inf 2014-09-06 04:47:41 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-09-06 04:42:40 ----RD---- C:\Program Files (x86) 2014-09-06 04:42:40 ----HD---- C:\ProgramData 2014-09-06 04:24:53 ----D---- C:\Windows\SysWOW64 2014-09-06 03:26:40 ----D---- C:\Windows\Microsoft.NET 2014-09-04 12:22:37 ----D---- C:\Windows\AppReadiness 2014-09-04 04:48:22 ----SHD---- C:\System Volume Information 2014-09-03 23:43:24 ----D---- C:\Users\Stegisoft\AppData\Roaming\FileZilla 2014-09-03 10:57:00 ----D---- C:\Windows\Tasks 2014-09-03 10:57:00 ----D---- C:\Windows\system32\Tasks 2014-09-03 10:37:30 ----D---- C:\Windows\rescache 2014-09-03 08:12:17 ----D---- C:\Windows\system32\config 2014-09-02 17:55:36 ----D---- C:\Windows 2014-09-02 17:50:41 ----SD---- C:\Windows\Downloaded Program Files 2014-09-02 17:44:42 ----SHD---- C:\Windows\Installer 2014-09-02 17:35:13 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2014-09-02 17:17:09 ----D---- C:\Windows\WinSxS 2014-09-02 17:17:09 ----D---- C:\Windows\CbsTemp 2014-09-02 17:17:06 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-09-02 17:17:06 ----D---- C:\Windows\system32\nl-NL 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpwsockx.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpnsvr.exe 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpnhupnp.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpnhpast.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpnet.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpnathlp.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dpmodemx.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dplayx.dll 2014-09-02 17:17:05 ----A---- C:\Windows\SYSWOW64\dplaysvr.exe 2014-09-02 17:17:05 ----A---- C:\Windows\system32\dpnsvr.exe 2014-09-02 17:17:05 ----A---- C:\Windows\system32\dpnhupnp.dll 2014-09-02 17:17:05 ----A---- C:\Windows\system32\dpnhpast.dll 2014-09-02 17:17:05 ----A---- C:\Windows\system32\dpnet.dll 2014-09-02 17:17:05 ----A---- C:\Windows\system32\dpnathlp.dll 2014-09-01 16:55:30 ----D---- C:\Windows\tracing 2014-09-01 16:55:09 ----D---- C:\Windows\ModemLogs 2014-09-01 15:06:55 ----D---- C:\Windows\system32\drivers\UMDF 2014-09-01 15:06:55 ----D---- C:\Windows\system32\drivers 2014-08-31 23:43:46 ----HD---- C:\Program Files\WindowsApps 2014-08-31 23:32:05 ----D---- C:\Windows\system32\catroot 2014-08-31 22:25:36 ----D---- C:\Program Files (x86)\FileZilla FTP Client 2014-08-31 12:42:08 ----RSD---- C:\Windows\assembly 2014-08-23 11:34:18 ----D---- C:\ProgramData\regid.1991-06.com.microsoft 2014-08-23 11:33:54 ----D---- C:\Program Files\Microsoft Office 15 2014-08-23 01:53:09 ----D---- C:\Windows\system32\DriverStore 2014-08-23 01:52:55 ----RSD---- C:\Windows\Fonts 2014-08-23 01:31:31 ----SD---- C:\Users\Stegisoft\AppData\Roaming\Microsoft 2014-08-23 01:30:12 ----D---- C:\Windows\system32\catroot2 2014-08-16 12:49:56 ----D---- C:\Program Files\CDBurnerXP 2014-08-15 01:30:54 ----D---- C:\Windows\PolicyDefinitions 2014-08-15 01:30:54 ----D---- C:\Program Files\Internet Explorer 2014-08-15 01:30:54 ----D---- C:\Program Files (x86)\Internet Explorer 2014-08-15 01:30:51 ----RD---- C:\Windows\ToastData 2014-08-15 01:30:51 ----D---- C:\Windows\SYSWOW64\wbem 2014-08-15 01:30:51 ----D---- C:\Windows\SYSWOW64\migration 2014-08-15 01:30:51 ----D---- C:\Windows\system32\wbem 2014-08-15 01:30:51 ----D---- C:\Windows\system32\migration 2014-08-15 01:30:51 ----D---- C:\Windows\system32\en-US 2014-08-15 01:30:51 ----D---- C:\Windows\MediaViewer 2014-08-15 01:30:51 ----D---- C:\Windows\Camera 2014-08-15 01:30:50 ----D---- C:\Windows\FileManager 2014-08-15 01:30:28 ----D---- C:\Windows\system32\MRT 2014-08-15 01:29:27 ----A---- C:\Windows\system32\MRT.exe 2014-08-15 00:25:15 ----SHD---- C:\$Recycle.Bin 2014-08-14 17:12:45 ----A---- C:\Windows\SYSWOW64\msrating.dll 2014-08-14 17:12:45 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2014-08-14 17:12:41 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe 2014-08-14 17:12:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2014-08-14 17:12:41 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2014-08-14 17:12:41 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll 2014-08-14 17:12:41 ----A---- C:\Windows\system32\ieUnatt.exe 2014-08-14 17:12:41 ----A---- C:\Windows\system32\iesetup.dll 2014-08-14 17:12:41 ----A---- C:\Windows\system32\iernonce.dll 2014-08-14 17:12:41 ----A---- C:\Windows\system32\ieetwproxystub.dll 2014-08-14 17:12:41 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2014-08-14 17:12:41 ----A---- C:\Windows\system32\ieetwcollector.exe 2014-08-14 17:12:40 ----A---- C:\Windows\system32\msrating.dll 2014-08-14 17:12:40 ----A---- C:\Windows\system32\jsproxy.dll 2014-08-14 17:12:23 ----A---- C:\Windows\system32\mfps.dll 2014-08-11 00:20:38 ----D---- C:\Users\Stegisoft\AppData\Roaming\Adobe 2014-08-11 00:20:17 ----D---- C:\ProgramData\Adobe 2014-08-11 00:14:50 ----D---- C:\Program Files (x86)\Adobe 2014-08-11 00:11:56 ----D---- C:\Program Files\Common Files\microsoft shared 2014-08-11 00:11:52 ----D---- C:\Program Files\Common Files 2014-08-11 00:05:52 ----D---- C:\ProgramData\Package Cache 2014-08-10 01:12:31 ----D---- C:\Windows\system32\appmgmt 2014-08-09 11:52:00 ----D---- C:\Windows\Logs 2014-08-07 02:02:10 ----D---- C:\Windows\apppatch 2014-08-07 02:02:10 ----D---- C:\Program Files\Windows Defender 2014-08-07 02:02:10 ----D---- C:\Program Files (x86)\Windows Defender 2014-08-07 02:02:08 ----RD---- C:\Windows\ImmersiveControlPanel 2014-08-07 02:02:08 ----D---- C:\Windows\system32\oobe 2014-08-07 02:02:08 ----D---- C:\Windows\system32\drivers\nl-NL 2014-08-07 02:02:07 ----D---- C:\Program Files\Windows Journal 2014-08-07 02:02:06 ----D---- C:\Windows\WinStore ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-21 632168] R1 avfwot;avfwot; C:\Windows\system32\DRIVERS\avfwot.sys [2014-08-02 141376] R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2014-07-02 130584] R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2014-07-02 28600] R1 ElRawDisk;ElRawDisk; \??\C:\Windows\system32\drivers\ffs64.sys [2012-05-15 26080] R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680] R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2014-07-02 117712] R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2014-07-02 42040] R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2008-09-03 11576] R3 asmthub3;@oem6.inf,%asmthub3_ServiceDescription%;ASMedia USB3 Hub Service; C:\Windows\System32\drivers\asmthub3.sys [2014-01-09 138456] R3 asmtxhci;@oem7.inf,%asmtxhci_ServiceDescription%;ASMEDIA XHCI Service; C:\Windows\System32\drivers\asmtxhci.sys [2014-01-09 423128] R3 avfwim;@oem12.inf,%avfw_9MP_Desc%;AvFw Packet Filter Miniport; C:\Windows\system32\DRIVERS\avfwim.sys [2014-08-02 114608] R3 huawei_enumerator;huawei_enumerator; C:\Windows\System32\drivers\ew_jubusenum.sys [2013-01-30 90112] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-29 5363200] R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0; C:\Windows\system32\DRIVERS\libusb0.sys [2011-05-17 44480] R3 MEIx64;@oem2.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\HECIx64.sys [2010-10-19 56344] R3 netr28ux;@netr28ux.inf,%Generic.Service.DispName%;Stuurprogramma voor RT2870 USB Extensible draadloze LAN-kaart; C:\Windows\system32\DRIVERS\netr28ux.sys [2013-06-18 2408208] R3 RTL8168;@oem8.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-06-17 873688] R3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum; C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys [2010-09-01 75776] R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912] S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [] S3 APG8201;@oem13.inf,%ACS.APG8201.DevDesc%;APG8201 Smart Card Reader; C:\Windows\system32\DRIVERS\apg8201.sys [2014-05-14 62592] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-12-30 117248] S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2013-01-30 104960] S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\System32\drivers\ew_juextctrl.sys [2013-01-30 30720] S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2013-01-30 239104] S3 ma-config_amd64;ma-config_amd64; \??\C:\Program Files\ma-config.com\Drivers\ma-config_amd64.sys [2014-02-24 17568] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432] R2 AntiVirFirewallService;Avira FireWall; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [2014-08-13 1043024] R2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [2014-08-13 804944] R2 AntiVirSchedulerService;Avira Planner; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2014-08-13 430160] R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2014-08-13 430160] R2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2014-08-13 1021520] R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-08-01 2369720] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720] R2 MaConfigAgent;Ma-Config Agent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2014-06-24 2820424] R2 VmbService;Vodafone Mobile Broadband-service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2013-02-05 8704] S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-05 116648] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-03 262320] S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-01-29 279000] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-05 116648] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-17 119408] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-07-19 150600] -----------------EOF-----------------