Logfile of random's system information tool 1.10 (written by random/random) Run by Tim at 2014-10-02 18:31:08 Microsoft Windows 8.1 Pro System drive C: has 50 GB (26%) free of 189 GB Total RAM: 6135 MB (80% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 6:31:15 PM, on 10/2/2014 Platform: Unknown Windows (WinNT 6.03.1408) MSIE: Internet Explorer v11.0 (11.00.9600.17278) Boot mode: Safe mode with network support Running processes: C:\Program Files\trend micro\Tim.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M8A2BC923-4C9F-46C8-BA79-672ACA973F4C&SearchSource=55&CUI=&UM=5&UP=SPB9CCDA55-80DE-4B7D-837D-662AA5DDB986&SSPV= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (file missing) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true O4 - HKLM\..\Run: [PMG Start] C:\ProgramData\PMG\PMG.exe O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe" O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKCU\..\Run: [CyberGhost] "C:\Program Files\CyberGhost 5\CyberGhost.EXE" /autostart O4 - HKCU\..\Run: [Winlogon] C:\Users\Tim\AppData\Roaming\system\winlogon.exe O4 - Startup: Curse.lnk = Tim\AppData\Roaming\Curse Client\Bin\Curse.exe O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://*.aeriagames.com O17 - HKLM\System\CCS\Services\Tcpip\..\{0207C40E-5902-4147-AC8A-A66661DFD66C}: NameServer = 192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{0207C40E-5902-4147-AC8A-A66661DFD66C}: NameServer = 192.168.0.1 O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: c:\progra~3\winspeed\winspeed.dll c:\progra~3\perfor~1\perfor~1.dll O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: CyberGhost 5 Client Service (CGVPNCliService) - CyberGhost S.R.L - C:\Program Files\CyberGhost 5\Service.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - F:\Games\HiPatchService.exe O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Local Synchronization Host (MainLSyncHost) - Unknown owner - c:\windows\syswow64\mpk\lsynchost.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe (file missing) O23 - Service: MediaFire NTFS Monitor (MF NTFS Monitor) - Unknown owner - C:\Users\Tim\AppData\Local\MEDIAF~1\MFUSNM~1.EXE O23 - Service: mental ray Satellite for Autodesk 3ds Max 2015 64-bit (mi-raysat_3dsmax2015_64) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - C:\Program Files\OpenVPN\bin\openvpnserv.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10504 bytes ======Listing Processes====== wininit.exe winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted "dwm.exe" C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\Explorer.EXE ctfmon.exe C:\Windows\helppane.exe -Embedding C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Users\Tim\Desktop\RSITx64.exe" C:\Windows\system32\wbem\wmiprvse.exe ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\update-S-1-5-21-2171773818-881262542-3018635925-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate C:\Windows\tasks\update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate =========Mozilla firefox========= ProfilePath - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\7qjwrpbi.default [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 15.0.0.152 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0] "Description"= "Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.60.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision] "Description"=NVIDIA stereo images plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming] "Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin] "Description"=This plugin detects and launches Pando Media Booster "Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 15.0.0.152 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.65.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.65.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\7qjwrpbi.default\extensions\ jid1-4P0kohSJxU1qGg@jetpack ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-24 553896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-06-15 581824] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 688528] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-24 211880] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}] MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-21 462760] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-06-15 436600] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL [2010-02-28 561552] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-21 171944] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CyberGhost"=C:\Program Files\CyberGhost 5\CyberGhost.EXE [2014-06-12 404080] "Winlogon"=C:\Users\Tim\AppData\Roaming\system\winlogon.exe [2014-09-28 1032192] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-08 3890208] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896] "Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-07-03 2694040] "PMG Start"=C:\ProgramData\PMG\PMG.exe [2014-08-25 2516992] ""= [] "Razer Synapse"=C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [2014-06-23 585560] "Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [] "KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2014-02-07 311616] "BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520] "MS Shell Services"= [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Curse.lnk - C:\Users\Tim\AppData\Roaming\Curse Client\Bin\Curse.exe [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "AllowLegacyWebView"=1 "AllowUnhashedWebView"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.yuy2"=msyuv.dll "vidc.i420"=iyuv_32.dll "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "vidc.yvyu"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "vidc.uyvy"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.msvc"=msvidc32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux2"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "aux3"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "aux4"=wdmaud.drv "wave5"=wdmaud.drv "midi5"=wdmaud.drv "mixer5"=wdmaud.drv "wave6"=wdmaud.drv "midi6"=wdmaud.drv "mixer6"=wdmaud.drv "wave7"=wdmaud.drv "midi7"=wdmaud.drv "mixer7"=wdmaud.drv "wave8"=wdmaud.drv "midi8"=wdmaud.drv "mixer8"=wdmaud.drv "wave9"=wdmaud.drv "midi9"=wdmaud.drv "mixer9"=wdmaud.drv "aux5"=wdmaud.drv "vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll "vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll "VIDC.FPS1"=frapsv64.dll "aux6"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-10-02 18:31:09 ----D---- C:\Program Files\trend micro 2014-10-02 18:31:08 ----D---- C:\rsit 2014-10-02 18:06:45 ----D---- C:\ProgramData\ParetoLogic 2014-10-02 18:06:45 ----D---- C:\Program Files (x86)\ParetoLogic 2014-10-02 18:02:36 ----A---- C:\Windows\ntbtlog.txt 2014-10-02 05:44:20 ----A---- C:\Recovery.txt 2014-10-01 19:34:53 ----SHD---- C:\found.003 2014-10-01 18:28:53 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe 2014-10-01 18:26:09 ----A---- C:\Windows\system32\shell32.dll 2014-10-01 18:26:05 ----A---- C:\Windows\SYSWOW64\shell32.dll 2014-10-01 18:26:05 ----A---- C:\Windows\system32\Windows.UI.Search.dll 2014-10-01 18:26:04 ----A---- C:\Windows\SYSWOW64\mstscax.dll 2014-10-01 18:26:04 ----A---- C:\Windows\system32\mstscax.dll 2014-10-01 18:26:03 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll 2014-10-01 18:26:03 ----A---- C:\Windows\system32\SyncEngine.dll 2014-10-01 18:26:03 ----A---- C:\Windows\system32\drivers\tcpip.sys 2014-10-01 18:26:02 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2014-10-01 18:26:02 ----A---- C:\Windows\system32\propsys.dll 2014-10-01 18:26:02 ----A---- C:\Windows\system32\ntdll.dll 2014-10-01 18:26:02 ----A---- C:\Windows\system32\MrmCoreR.dll 2014-10-01 18:26:02 ----A---- C:\Windows\system32\KernelBase.dll 2014-10-01 18:26:01 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll 2014-10-01 18:26:01 ----A---- C:\Windows\system32\SearchFolder.dll 2014-10-01 18:26:00 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll 2014-10-01 18:26:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll 2014-10-01 18:26:00 ----A---- C:\Windows\system32\Wldap32.dll 2014-10-01 18:26:00 ----A---- C:\Windows\system32\iphlpsvc.dll 2014-10-01 18:25:59 ----A---- C:\Windows\SYSWOW64\Wldap32.dll 2014-10-01 18:25:59 ----A---- C:\Windows\SYSWOW64\propsys.dll 2014-10-01 18:25:59 ----A---- C:\Windows\system32\SystemEventsBrokerServer.dll 2014-10-01 18:25:58 ----A---- C:\Windows\SYSWOW64\WSShared.dll 2014-10-01 18:25:58 ----A---- C:\Windows\system32\WSShared.dll 2014-10-01 18:25:58 ----A---- C:\Windows\system32\SkyDriveTelemetry.dll 2014-10-01 18:25:58 ----A---- C:\Windows\system32\SkyDrive.exe 2014-10-01 18:25:58 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS 2014-10-01 18:25:58 ----A---- C:\Windows\system32\bisrv.dll 2014-10-01 18:25:57 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-01 18:25:57 ----A---- C:\Windows\SYSWOW64\SkyDriveShell.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\SkyDriveShell.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\ProximityService.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\pcsvDevice.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\httpprxm.dll 2014-10-01 18:25:57 ----A---- C:\Windows\system32\adhsvc.dll 2014-10-01 18:25:52 ----A---- C:\Windows\SYSWOW64\msi.dll 2014-10-01 18:25:52 ----A---- C:\Windows\system32\win32k.sys 2014-10-01 18:25:52 ----A---- C:\Windows\system32\msi.dll 2014-10-01 18:25:51 ----A---- C:\Windows\SYSWOW64\authui.dll 2014-10-01 18:25:51 ----A---- C:\Windows\system32\authui.dll 2014-10-01 18:25:51 ----A---- C:\Windows\system32\appinfo.dll 2014-10-01 17:46:28 ----SHD---- C:\found.002 2014-10-01 16:06:28 ----D---- C:\Users\Tim\AppData\Roaming\dclogs 2014-10-01 16:02:08 ----N---- C:\bootsqm.dat 2014-10-01 16:02:01 ----SHD---- C:\found.001 2014-09-28 13:15:00 ----D---- C:\Users\Tim\AppData\Roaming\system 2014-09-27 17:55:31 ----D---- C:\Users\Tim\AppData\Roaming\IconChanger 2014-09-27 17:45:37 ----D---- C:\Program Files (x86)\Resource Hacker 2014-09-27 17:39:56 ----D---- C:\Program Files (x86)\IconChanger 2014-09-27 13:58:14 ----A---- C:\Users\Tim\AppData\Roaming\Downloader.exe 2014-09-27 12:26:47 ----RD---- C:\Program Files (x86)\Skype 2014-09-27 09:54:22 ----D---- C:\Windows\EasyBind 2014-09-25 18:54:32 ----HD---- C:\KMSEMUTEMP 2014-09-25 18:51:32 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services 2014-09-25 18:51:20 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-09-25 18:50:45 ----D---- C:\Program Files\Microsoft Office 2014-09-25 18:50:42 ----D---- C:\Program Files (x86)\Microsoft Office 2014-09-25 18:50:41 ----D---- C:\ProgramData\Microsoft Help 2014-09-25 18:50:28 ----RHD---- C:\MSOCache 2014-09-24 13:08:18 ----D---- C:\ProgramData\Performance Optimizer 2014-09-17 16:41:45 ----A---- C:\Windows\system32\WSDMon.dll 2014-09-17 16:41:45 ----A---- C:\Windows\system32\tcpmon.dll 2014-09-17 16:41:25 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll 2014-09-17 16:41:21 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll 2014-09-17 16:41:17 ----A---- C:\Windows\system32\ntoskrnl.exe 2014-09-17 16:41:16 ----A---- C:\Windows\system32\d3d10warp.dll 2014-09-17 16:41:15 ----A---- C:\Windows\system32\SettingsHandlers.dll 2014-09-17 16:41:12 ----A---- C:\Windows\system32\mfcore.dll 2014-09-17 16:41:11 ----A---- C:\Windows\SYSWOW64\mfcore.dll 2014-09-17 16:41:10 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll 2014-09-17 16:41:10 ----A---- C:\Windows\system32\gpsvc.dll 2014-09-17 16:41:09 ----A---- C:\Windows\system32\workfolderssvc.dll 2014-09-17 16:41:09 ----A---- C:\Windows\system32\wlansvc.dll 2014-09-17 16:41:08 ----A---- C:\Windows\system32\Windows.Media.dll 2014-09-17 16:41:06 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll 2014-09-17 16:41:06 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll 2014-09-17 16:41:06 ----A---- C:\Windows\system32\mfmp4srcsnk.dll 2014-09-17 16:41:06 ----A---- C:\Windows\system32\localspl.dll 2014-09-17 16:41:05 ----A---- C:\Windows\system32\drivers\srv.sys 2014-09-17 16:41:04 ----A---- C:\Windows\SYSWOW64\mfplat.dll 2014-09-17 16:41:04 ----A---- C:\Windows\system32\WMVDECOD.DLL 2014-09-17 16:41:04 ----A---- C:\Windows\system32\SRH.dll 2014-09-17 16:41:04 ----A---- C:\Windows\system32\mfplat.dll 2014-09-17 16:41:03 ----A---- C:\Windows\system32\printui.dll 2014-09-17 16:41:03 ----A---- C:\Windows\system32\drivers\ntfs.sys 2014-09-17 16:41:02 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL 2014-09-17 16:41:02 ----A---- C:\Windows\system32\wuaueng.dll 2014-09-17 16:41:02 ----A---- C:\Windows\system32\drivers\srv2.sys 2014-09-17 16:41:01 ----A---- C:\Windows\system32\XpsPrint.dll 2014-09-17 16:41:01 ----A---- C:\Windows\system32\mispace.dll 2014-09-17 16:41:01 ----A---- C:\Windows\system32\drivers\netio.sys 2014-09-17 16:41:00 ----A---- C:\Windows\system32\WorkfoldersControl.dll 2014-09-17 16:41:00 ----A---- C:\Windows\system32\netcfgx.dll 2014-09-17 16:40:59 ----A---- C:\Windows\SYSWOW64\printui.dll 2014-09-17 16:40:59 ----A---- C:\Windows\SYSWOW64\netcfgx.dll 2014-09-17 16:40:59 ----A---- C:\Windows\SYSWOW64\mispace.dll 2014-09-17 16:40:59 ----A---- C:\Windows\system32\AppxPackaging.dll 2014-09-17 16:40:59 ----A---- C:\Windows\system32\aclui.dll 2014-09-17 16:40:58 ----A---- C:\Windows\SYSWOW64\SRH.dll 2014-09-17 16:40:58 ----A---- C:\Windows\system32\wlanmsm.dll 2014-09-17 16:40:58 ----A---- C:\Windows\system32\srvsvc.dll 2014-09-17 16:40:58 ----A---- C:\Windows\system32\drivers\spaceport.sys 2014-09-17 16:40:57 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll 2014-09-17 16:40:57 ----A---- C:\Windows\SYSWOW64\AppxPackaging.dll 2014-09-17 16:40:57 ----A---- C:\Windows\SYSWOW64\aclui.dll 2014-09-17 16:40:57 ----A---- C:\Windows\system32\spoolsv.exe 2014-09-17 16:40:57 ----A---- C:\Windows\system32\mfreadwrite.dll 2014-09-17 16:40:56 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll 2014-09-17 16:40:56 ----A---- C:\Windows\system32\SHCore.dll 2014-09-17 16:40:56 ----A---- C:\Windows\system32\puiobj.dll 2014-09-17 16:40:56 ----A---- C:\Windows\system32\drivers\volsnap.sys 2014-09-17 16:40:56 ----A---- C:\Windows\system32\drivers\usbccgp.sys 2014-09-17 16:40:55 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll 2014-09-17 16:40:55 ----A---- C:\Windows\SYSWOW64\mftranscode.dll 2014-09-17 16:40:54 ----A---- C:\Windows\SYSWOW64\SHCore.dll 2014-09-17 16:40:54 ----A---- C:\Windows\system32\storagewmi.dll 2014-09-17 16:40:54 ----A---- C:\Windows\system32\mftranscode.dll 2014-09-17 16:40:54 ----A---- C:\Windows\system32\clusapi.dll 2014-09-17 16:40:53 ----A---- C:\Windows\system32\wuapi.dll 2014-09-17 16:40:53 ----A---- C:\Windows\system32\WebClnt.dll 2014-09-17 16:40:53 ----A---- C:\Windows\system32\usbmon.dll 2014-09-17 16:40:53 ----A---- C:\Windows\system32\comdlg32.dll 2014-09-17 16:40:52 ----A---- C:\Windows\system32\winload.exe 2014-09-17 16:40:52 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS 2014-09-17 16:40:51 ----A---- C:\Windows\system32\wisp.dll 2014-09-17 16:40:51 ----A---- C:\Windows\system32\defragsvc.dll 2014-09-17 16:40:50 ----A---- C:\Windows\SYSWOW64\comdlg32.dll 2014-09-17 16:40:50 ----A---- C:\Windows\system32\winresume.exe 2014-09-17 16:40:50 ----A---- C:\Windows\system32\lsasrv.dll 2014-09-17 16:40:49 ----A---- C:\Windows\system32\wsecedit.dll 2014-09-17 16:40:49 ----A---- C:\Windows\system32\drivers\srvnet.sys 2014-09-17 16:40:48 ----A---- C:\Windows\SYSWOW64\WebClnt.dll 2014-09-17 16:40:48 ----A---- C:\Windows\SYSWOW64\clusapi.dll 2014-09-17 16:40:48 ----A---- C:\Windows\system32\winmmbase.dll 2014-09-17 16:40:48 ----A---- C:\Windows\system32\user32.dll 2014-09-17 16:40:48 ----A---- C:\Windows\system32\profsvc.dll 2014-09-17 16:40:48 ----A---- C:\Windows\system32\drivers\nwifi.sys 2014-09-17 16:40:47 ----A---- C:\Windows\system32\wpdbusenum.dll 2014-09-17 16:40:47 ----A---- C:\Windows\system32\win32spl.dll 2014-09-17 16:40:47 ----A---- C:\Windows\system32\WiFiDisplay.dll 2014-09-17 16:40:47 ----A---- C:\Windows\system32\rdpcorets.dll 2014-09-17 16:40:47 ----A---- C:\Windows\system32\drivers\usbhub.sys 2014-09-17 16:40:46 ----A---- C:\Windows\SYSWOW64\puiobj.dll 2014-09-17 16:40:46 ----A---- C:\Windows\SYSWOW64\Display.dll 2014-09-17 16:40:46 ----A---- C:\Windows\system32\SettingSync.dll 2014-09-17 16:40:46 ----A---- C:\Windows\system32\rdvidcrl.dll 2014-09-17 16:40:46 ----A---- C:\Windows\system32\conhost.exe 2014-09-17 16:40:45 ----A---- C:\Windows\SYSWOW64\wlanapi.dll 2014-09-17 16:40:45 ----A---- C:\Windows\SYSWOW64\storagewmi.dll 2014-09-17 16:40:45 ----A---- C:\Windows\system32\WUSettingsProvider.dll 2014-09-17 16:40:45 ----A---- C:\Windows\system32\VAN.dll 2014-09-17 16:40:45 ----A---- C:\Windows\system32\Display.dll 2014-09-17 16:40:45 ----A---- C:\Windows\system32\AppxSip.dll 2014-09-17 16:40:44 ----A---- C:\Windows\SYSWOW64\winmmbase.dll 2014-09-17 16:40:44 ----A---- C:\Windows\system32\WorkFoldersGPExt.dll 2014-09-17 16:40:44 ----A---- C:\Windows\system32\SndVol.exe 2014-09-17 16:40:44 ----A---- C:\Windows\system32\osk.exe 2014-09-17 16:40:43 ----A---- C:\Windows\SYSWOW64\wuapi.dll 2014-09-17 16:40:43 ----A---- C:\Windows\SYSWOW64\wisp.dll 2014-09-17 16:40:43 ----A---- C:\Windows\system32\mfps.dll 2014-09-17 16:40:43 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys 2014-09-17 16:40:43 ----A---- C:\Windows\system32\DafPrintProvider.dll 2014-09-17 16:40:43 ----A---- C:\Windows\system32\bcryptprimitives.dll 2014-09-17 16:40:42 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll 2014-09-17 16:40:42 ----A---- C:\Windows\system32\drivers\NdisImPlatform.sys 2014-09-17 16:40:42 ----A---- C:\Windows\system32\drivers\ndis.sys 2014-09-17 16:40:42 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2014-09-17 16:40:41 ----A---- C:\Windows\system32\winmm.dll 2014-09-17 16:40:41 ----A---- C:\Windows\system32\Windows.Networking.dll 2014-09-17 16:40:41 ----A---- C:\Windows\system32\twinapi.dll 2014-09-17 16:40:41 ----A---- C:\Windows\system32\dwmapi.dll 2014-09-17 16:40:41 ----A---- C:\Windows\system32\drivers\hdaudbus.sys 2014-09-17 16:40:40 ----A---- C:\Windows\SYSWOW64\wsecedit.dll 2014-09-17 16:40:40 ----A---- C:\Windows\SYSWOW64\AppxSip.dll 2014-09-17 16:40:40 ----A---- C:\Windows\system32\wucltux.dll 2014-09-17 16:40:40 ----A---- C:\Windows\system32\prnntfy.dll 2014-09-17 16:40:40 ----A---- C:\Windows\system32\GdiPlus.dll 2014-09-17 16:40:40 ----A---- C:\Windows\system32\drivers\bridge.sys 2014-09-17 16:40:39 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll 2014-09-17 16:40:39 ----A---- C:\Windows\SYSWOW64\prnntfy.dll 2014-09-17 16:40:39 ----A---- C:\Windows\system32\WorkFoldersShell.dll 2014-09-17 16:40:39 ----A---- C:\Windows\system32\gpedit.dll 2014-09-17 16:40:38 ----A---- C:\Windows\SYSWOW64\winmm.dll 2014-09-17 16:40:38 ----A---- C:\Windows\SYSWOW64\puiapi.dll 2014-09-17 16:40:38 ----A---- C:\Windows\system32\puiapi.dll 2014-09-17 16:40:38 ----A---- C:\Windows\system32\ppcsnap.dll 2014-09-17 16:40:38 ----A---- C:\Windows\system32\iasnap.dll 2014-09-17 16:40:37 ----A---- C:\Windows\SYSWOW64\VAN.dll 2014-09-17 16:40:37 ----A---- C:\Windows\SYSWOW64\SndVol.exe 2014-09-17 16:40:37 ----A---- C:\Windows\SYSWOW64\dwmapi.dll 2014-09-17 16:40:36 ----A---- C:\Windows\system32\wups.dll 2014-09-17 16:40:36 ----A---- C:\Windows\system32\drivers\pci.sys 2014-09-17 16:40:36 ----A---- C:\Windows\system32\drivers\ks.sys 2014-09-17 16:40:35 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll 2014-09-17 16:40:35 ----A---- C:\Windows\system32\wcmcsp.dll 2014-09-17 16:40:35 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe 2014-09-17 16:40:35 ----A---- C:\Windows\system32\stobject.dll 2014-09-17 16:40:35 ----A---- C:\Windows\system32\AppxSysprep.dll 2014-09-17 16:40:34 ----A---- C:\Windows\SYSWOW64\iasnap.dll 2014-09-17 16:40:34 ----A---- C:\Windows\system32\wwanconn.dll 2014-09-17 16:40:34 ----A---- C:\Windows\system32\wuauclt.exe 2014-09-17 16:40:34 ----A---- C:\Windows\system32\dab.dll 2014-09-17 16:40:33 ----A---- C:\Windows\SYSWOW64\rsaenh.dll 2014-09-17 16:40:33 ----A---- C:\Windows\SYSWOW64\gpedit.dll 2014-09-17 16:40:33 ----A---- C:\Windows\system32\rsaenh.dll 2014-09-17 16:40:33 ----A---- C:\Windows\system32\pmcsnap.dll 2014-09-17 16:40:33 ----A---- C:\Windows\system32\ActionCenter.dll 2014-09-17 16:40:32 ----A---- C:\Windows\SYSWOW64\osk.exe 2014-09-17 16:40:32 ----A---- C:\Windows\system32\wups2.dll 2014-09-17 16:40:32 ----A---- C:\Windows\system32\wlanapi.dll 2014-09-17 16:40:31 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll 2014-09-17 16:40:31 ----A---- C:\Windows\SYSWOW64\SettingSync.dll 2014-09-17 16:40:31 ----A---- C:\Windows\system32\wshbth.dll 2014-09-17 16:40:31 ----A---- C:\Windows\system32\schannel.dll 2014-09-17 16:40:30 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll 2014-09-17 16:40:30 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll 2014-09-17 16:40:30 ----A---- C:\Windows\system32\PrintDialogs.dll 2014-09-17 16:40:30 ----A---- C:\Windows\system32\browser.dll 2014-09-17 16:40:29 ----A---- C:\Windows\SYSWOW64\wshbth.dll 2014-09-17 16:40:29 ----A---- C:\Windows\SYSWOW64\stobject.dll 2014-09-17 16:40:29 ----A---- C:\Windows\system32\wlansvcpal.dll 2014-09-17 16:40:28 ----A---- C:\Windows\SYSWOW64\KBDRUM.DLL 2014-09-17 16:40:28 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll 2014-09-17 16:40:28 ----A---- C:\Windows\system32\KBDRUM.DLL 2014-09-17 16:40:28 ----A---- C:\Windows\system32\Defrag.exe 2014-09-17 16:40:27 ----A---- C:\Windows\SYSWOW64\wups.dll 2014-09-17 16:40:27 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll 2014-09-17 16:40:26 ----A---- C:\Windows\SYSWOW64\user32.dll 2014-09-17 16:40:26 ----A---- C:\Windows\SYSWOW64\schannel.dll 2014-09-17 16:40:26 ----A---- C:\Windows\system32\KBDYAK.DLL 2014-09-17 16:40:26 ----A---- C:\Windows\system32\KBDRU1.DLL 2014-09-17 16:40:26 ----A---- C:\Windows\system32\KBDRU.DLL 2014-09-17 16:40:26 ----A---- C:\Windows\system32\KBDBASH.DLL 2014-09-17 16:40:25 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL 2014-09-17 16:40:25 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL 2014-09-17 16:40:25 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL 2014-09-17 16:40:25 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL 2014-09-17 16:40:25 ----A---- C:\Windows\system32\BluetoothApis.dll 2014-09-17 16:40:22 ----A---- C:\Windows\SYSWOW64\PrintDialogs.dll 2014-09-17 16:40:22 ----A---- C:\Windows\SYSWOW64\certcli.dll 2014-09-17 16:40:22 ----A---- C:\Windows\system32\wwanmm.dll 2014-09-17 16:40:22 ----A---- C:\Windows\system32\KBDTAT.DLL 2014-09-17 16:40:22 ----A---- C:\Windows\system32\certcli.dll 2014-09-17 16:40:21 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL 2014-09-17 16:40:21 ----A---- C:\Windows\system32\SndVolSSO.dll 2014-09-17 16:40:21 ----A---- C:\Windows\system32\compstui.dll 2014-09-17 16:40:20 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll 2014-09-17 16:40:20 ----A---- C:\Windows\system32\wlansec.dll 2014-09-17 16:40:20 ----A---- C:\Windows\system32\rdpudd.dll 2014-09-17 16:40:18 ----A---- C:\Windows\system32\wudriver.dll 2014-09-17 16:40:18 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll 2014-09-17 16:40:17 ----A---- C:\Windows\SYSWOW64\wudriver.dll 2014-09-17 16:40:17 ----A---- C:\Windows\system32\KBDTT102.DLL 2014-09-17 16:40:16 ----A---- C:\Windows\SYSWOW64\KBDTT102.DLL 2014-09-17 16:32:15 ----A---- C:\Windows\system32\drivers\msgpioclx.sys 2014-09-17 16:32:13 ----A---- C:\Windows\SYSWOW64\explorer.exe 2014-09-17 16:32:13 ----A---- C:\Windows\system32\uDWM.dll 2014-09-17 16:32:12 ----A---- C:\Windows\system32\twinui.dll 2014-09-17 16:32:12 ----A---- C:\Windows\explorer.exe 2014-09-17 16:32:10 ----A---- C:\Windows\SYSWOW64\twinui.dll 2014-09-17 16:32:09 ----A---- C:\Windows\system32\actxprxy.dll 2014-09-17 16:32:08 ----A---- C:\Windows\SYSWOW64\UXInit.dll 2014-09-17 16:32:08 ----A---- C:\Windows\SYSWOW64\actxprxy.dll 2014-09-17 16:32:08 ----A---- C:\Windows\system32\UXInit.dll 2014-09-10 17:26:10 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll 2014-09-10 17:26:10 ----A---- C:\Windows\system32\MshtmlDac.dll 2014-09-10 17:26:09 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2014-09-10 17:26:09 ----A---- C:\Windows\system32\mshtmled.dll 2014-09-10 17:26:08 ----A---- C:\Windows\SYSWOW64\vbscript.dll 2014-09-10 17:26:08 ----A---- C:\Windows\system32\vbscript.dll 2014-09-10 17:26:08 ----A---- C:\Windows\system32\jscript9diag.dll 2014-09-10 17:26:08 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-09-10 17:26:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll 2014-09-10 17:26:05 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll 2014-09-10 17:26:05 ----A---- C:\Windows\system32\dxtrans.dll 2014-09-10 17:26:05 ----A---- C:\Windows\system32\dxtmsft.dll 2014-09-10 17:26:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2014-09-10 17:26:04 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll 2014-09-10 17:26:04 ----A---- C:\Windows\system32\msfeeds.dll 2014-09-10 17:26:04 ----A---- C:\Windows\system32\iedkcs32.dll 2014-09-10 17:26:04 ----A---- C:\Windows\system32\ie4uinit.exe 2014-09-10 17:26:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2014-09-10 17:26:03 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll 2014-09-10 17:26:03 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2014-09-10 17:26:03 ----A---- C:\Windows\system32\ieapfltr.dll 2014-09-10 17:26:02 ----A---- C:\Windows\system32\mshtml.dll 2014-09-10 17:25:59 ----A---- C:\Windows\SYSWOW64\wininet.dll 2014-09-10 17:25:59 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2014-09-10 17:25:59 ----A---- C:\Windows\system32\wininet.dll 2014-09-10 17:25:58 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2014-09-10 17:25:58 ----A---- C:\Windows\system32\urlmon.dll 2014-09-10 17:25:58 ----A---- C:\Windows\system32\iertutil.dll 2014-09-10 17:25:57 ----A---- C:\Windows\system32\ieframe.dll 2014-09-10 17:25:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-09-10 17:25:56 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2014-09-10 17:25:55 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2014-09-10 17:25:55 ----A---- C:\Windows\system32\jscript9.dll 2014-09-10 17:01:20 ----A---- C:\Windows\system32\aeinv.dll 2014-09-10 17:01:19 ----A---- C:\Windows\system32\aepic.dll 2014-09-10 17:01:19 ----A---- C:\Windows\system32\aepdu.dll 2014-09-10 16:59:56 ----A---- C:\Windows\system32\schedsvc.dll 2014-09-10 16:59:06 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll 2014-09-10 16:59:06 ----A---- C:\Windows\system32\msvcr120_clr0400.dll 2014-09-07 13:17:22 ----D---- C:\My Web Sites 2014-09-07 13:17:03 ----D---- C:\Program Files\WinHTTrack 2014-09-06 21:54:56 ----D---- C:\dclogs 2014-09-06 21:09:04 ----A---- C:\Windows\system32\drivers\ssudmdm.sys 2014-09-06 21:09:04 ----A---- C:\Windows\system32\drivers\ssudbus.sys 2014-09-06 21:08:41 ----A---- C:\Windows\SYSWOW64\secman.dll 2014-09-06 21:06:34 ----D---- C:\Users\Tim\AppData\Roaming\Samsung 2014-09-06 21:05:33 ----D---- C:\Program Files (x86)\MyFree Codec 2014-09-06 21:05:08 ----A---- C:\Windows\SYSWOW64\Redemption.dll 2014-09-06 21:03:47 ----A---- C:\Windows\SYSWOW64\dgderapi.dll 2014-09-06 21:03:14 ----D---- C:\ProgramData\Samsung 2014-09-06 21:03:14 ----D---- C:\Program Files (x86)\Samsung 2014-09-06 20:52:07 ----D---- C:\Users\Tim\AppData\Roaming\Wondershare 2014-09-04 16:16:25 ----D---- C:\ProgramData\Razer 2014-09-04 16:16:03 ----D---- C:\Program Files (x86)\Razer ======List of files/folders modified in the last 1 month====== 2014-10-02 18:31:09 ----RD---- C:\Program Files 2014-10-02 18:23:32 ----SHD---- C:\System Volume Information 2014-10-02 18:06:45 ----RD---- C:\Program Files (x86) 2014-10-02 18:06:45 ----HD---- C:\ProgramData 2014-10-02 18:02:36 ----D---- C:\Windows 2014-10-02 18:01:00 ----D---- C:\Windows\system32\sru 2014-10-02 18:00:57 ----SHD---- C:\ProgramData\MPK 2014-10-02 18:00:57 ----D---- C:\Windows\Prefetch 2014-10-02 17:58:06 ----D---- C:\Windows\Inf 2014-10-02 17:57:25 ----D---- C:\Windows\Temp 2014-10-02 17:53:03 ----D---- C:\ProgramData\VMware 2014-10-02 17:52:01 ----D---- C:\ProgramData\NVIDIA 2014-10-02 17:36:12 ----SD---- C:\ProgramData\Microsoft 2014-10-02 05:44:03 ----D---- C:\Windows\Logs 2014-10-01 19:51:43 ----RD---- C:\Windows\System32 2014-10-01 19:51:40 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-10-01 19:50:04 ----D---- C:\Windows\AppReadiness 2014-10-01 19:49:26 ----HD---- C:\Program Files\WindowsApps 2014-10-01 19:08:29 ----D---- C:\Windows\system32\config 2014-10-01 18:33:44 ----D---- C:\Windows\WinSxS 2014-10-01 18:30:30 ----RD---- C:\Windows\ToastData 2014-10-01 18:30:30 ----D---- C:\Windows\SysWOW64 2014-10-01 18:30:29 ----D---- C:\Windows\WinStore 2014-10-01 18:30:28 ----D---- C:\Windows\system32\drivers 2014-10-01 18:30:27 ----D---- C:\Windows\system32\DriverStore 2014-10-01 18:29:56 ----D---- C:\Windows\CbsTemp 2014-10-01 18:29:00 ----D---- C:\Program Files (x86)\NVIDIA Corporation 2014-10-01 18:27:04 ----D---- C:\Program Files\NVIDIA Corporation 2014-10-01 18:21:29 ----D---- C:\Windows\Microsoft.NET 2014-10-01 17:31:56 ----SHD---- C:\Windows\Installer 2014-10-01 17:31:56 ----SHD---- C:\Config.Msi 2014-10-01 17:24:42 ----D---- C:\Users\Tim\AppData\Roaming\VMware 2014-10-01 16:31:31 ----D---- C:\Windows\system32\catroot2 2014-10-01 16:30:01 ----RSD---- C:\Windows\assembly 2014-10-01 16:17:31 ----SD---- C:\Users\Tim\AppData\Roaming\Microsoft 2014-10-01 16:09:57 ----D---- C:\Users\Tim\AppData\Roaming\Skype 2014-10-01 15:31:27 ----SHD---- C:\MSDCSC 2014-10-01 14:17:05 ----D---- C:\Program Files (x86)\Common Files 2014-10-01 13:17:27 ----D---- C:\Windows\system32\MRT 2014-10-01 13:17:22 ----A---- C:\Windows\system32\MRT.exe 2014-09-28 16:16:22 ----D---- C:\Program Files (x86)\Mozilla Firefox 2014-09-28 10:44:27 ----D---- C:\Program Files\CyberGhost 5 2014-09-27 23:17:23 ----D---- C:\Users\Tim\AppData\Roaming\Spotify 2014-09-27 22:31:47 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe 2014-09-27 20:54:39 ----D---- C:\Program Files (x86)\KidLogger 2014-09-27 12:26:57 ----D---- C:\ProgramData\Skype 2014-09-26 16:24:40 ----D---- C:\Program Files (x86)\Opera 2014-09-26 16:24:39 ----D---- C:\Windows\system32\Tasks 2014-09-25 18:58:02 ----D---- C:\Users\Tim\AppData\Roaming\uTorrent 2014-09-25 18:51:35 ----RSD---- C:\Windows\Fonts 2014-09-25 18:51:20 ----D---- C:\Program Files (x86)\Microsoft.NET 2014-09-25 18:51:00 ----D---- C:\Program Files\Common Files\microsoft shared 2014-09-24 18:56:53 ----D---- C:\Windows\SYSWOW64\en-US 2014-09-24 18:56:53 ----D---- C:\Windows\system32\en-US 2014-09-24 13:09:00 ----D---- C:\ProgramData\374311380 2014-09-21 11:10:36 ----D---- C:\ProgramData\Nimoru 2014-09-20 15:58:25 ----D---- C:\Program Files (x86)\No-IP 2014-09-17 21:06:27 ----D---- C:\Windows\system32\catroot 2014-09-17 21:05:28 ----D---- C:\Windows\SYSWOW64\wbem 2014-09-17 21:05:28 ----D---- C:\Windows\SYSWOW64\setup 2014-09-17 21:05:28 ----D---- C:\Program Files\Windows Journal 2014-09-17 21:05:23 ----RD---- C:\Windows\ImmersiveControlPanel 2014-09-17 21:05:23 ----D---- C:\Windows\system32\wbem 2014-09-17 21:05:23 ----D---- C:\Windows\system32\setup 2014-09-17 21:05:23 ----D---- C:\Windows\system32\oobe 2014-09-17 21:05:23 ----D---- C:\Windows\system32\drivers\en-US 2014-09-17 21:05:23 ----D---- C:\Windows\system32\Boot 2014-09-17 21:05:23 ----D---- C:\Windows\PolicyDefinitions 2014-09-17 21:05:22 ----D---- C:\Windows\apppatch 2014-09-17 21:05:21 ----D---- C:\Windows\SYSWOW64\migration 2014-09-17 21:05:21 ----D---- C:\Windows\SYSWOW64\InputMethod 2014-09-17 21:05:21 ----D---- C:\Windows\system32\migration 2014-09-13 16:16:21 ----D---- C:\Windows\rescache 2014-09-10 19:45:02 ----SD---- C:\Windows\system32\CompatTel 2014-09-10 19:45:01 ----D---- C:\Program Files\Internet Explorer 2014-09-10 19:45:01 ----D---- C:\Program Files (x86)\Internet Explorer 2014-09-10 17:26:32 ----A---- C:\Windows\SYSWOW64\msrating.dll 2014-09-10 17:26:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2014-09-10 17:26:26 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll 2014-09-10 17:26:26 ----A---- C:\Windows\system32\ieUnatt.exe 2014-09-10 17:26:26 ----A---- C:\Windows\system32\ieetwproxystub.dll 2014-09-10 17:26:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2014-09-10 17:26:26 ----A---- C:\Windows\system32\ieetwcollector.exe 2014-09-10 17:26:25 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe 2014-09-10 17:26:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2014-09-10 17:26:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2014-09-10 17:26:25 ----A---- C:\Windows\system32\iesetup.dll 2014-09-10 17:26:25 ----A---- C:\Windows\system32\iernonce.dll 2014-09-10 17:26:23 ----A---- C:\Windows\system32\msrating.dll 2014-09-10 17:26:23 ----A---- C:\Windows\system32\jsproxy.dll 2014-09-06 21:08:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2014-09-06 21:06:38 ----D---- C:\Windows\ModemLogs 2014-09-06 20:40:36 ----D---- C:\Windows\system32\drivers\UMDF 2014-09-04 20:11:10 ----A---- C:\ProgramData\exploit.exe.tmp ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 vmci;@oem19.inf,%vmci.Service.DispName%;VMware VMCI Bus Driver; C:\Windows\System32\drivers\vmci.sys [2012-10-24 85104] R0 vsock;vSockets Driver; C:\Windows\system32\drivers\vsock.sys [2012-10-24 70296] R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-06-15 93568] R1 dtsoftbus01;@oem20.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2014-07-23 283064] R1 HssDRV6;@oem23.inf,%HssDRV6_Desc%;Hotspot Shield Routing Driver 6; C:\Windows\system32\DRIVERS\hssdrv6.sys [2014-05-17 44744] R3 MTsensor;@oem1.inf,%ASACPI.DisplayName%;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2013-05-17 17280] R3 rzendpt;@oem29.inf,%rzendpt.SvcDesc%;rzendpt; C:\Windows\System32\drivers\rzendpt.sys [2014-05-19 39080] R3 rzudd;@oem37.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\Windows\System32\drivers\rzudd.sys [2014-05-19 155816] R3 tap0901;@oem21.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664] R3 taphss6;@oem22.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2014-05-17 42184] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2014-05-16 141600] R3 VBoxNetFlt;@oem14.inf,%VBoxNetFltService_Desc%;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2014-05-16 156448] R3 vmkbd;VMware kbd; \??\C:\Windows\system32\drivers\VMkbd.sys [2013-11-05 34008] R3 VMnetAdapter;@oem18.inf,%VMnetAdapter.Service.DispName%;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2013-11-05 20120] S0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-06-15 65776] S0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-06-15 208416] S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-06-15 1039096] S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-06-15 423240] S1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2014-05-16 254240] S1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2014-05-16 128288] S2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-06-15 29208] S2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-06-15 79184] S2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-06-15 85328] S2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2013-10-29 53976] S2 mfmonitor;mfmonitor; C:\Windows\system32\DRIVERS\mfmonitor_x64.sys [2014-07-02 20696] S2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2014-04-18 36600] S2 VMnetBridge;@oem17.inf,%VMware_Desc%;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2013-11-05 45720] S2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2013-11-05 31448] S2 vmx86;VMware vmx86; \??\C:\Windows\system32\drivers\vmx86.sys [2013-11-05 68312] S3 dg_ssudbus;@oem41.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-06-16 110336] S3 NVHDA;@oem46.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2014-03-21 197408] S3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-08-19 12866008] S3 ssudmdm;@oem42.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-06-16 206080] S3 TIEHDUSB;@oem11.inf,%ServiceDesc%;TI Core USB Driver; C:\Windows\System32\drivers\tiehdusb.sys [2012-03-07 128512] S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088] S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== S2 892cc6a3;Performance Optimizer; C:\Windows\syswow64\rundll32.exe [2013-08-22 49664] S2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-04-01 581000] S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-06-15 50344] S2 CGVPNCliService;CyberGhost 5 Client Service; C:\Program Files\CyberGhost 5\Service.exe [2014-06-12 64624] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; F:\Games\HiPatchService.exe [2014-07-18 9216] S2 hshld;Hotspot Shield Service; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [2014-05-17 919040] S2 HssWd;Hotspot Shield Monitoring Service; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [2014-05-17 430344] S2 MainLSyncHost;Local Synchronization Host; c:\windows\syswow64\mpk\lsynchost.exe [2014-08-07 1695544] S2 MF NTFS Monitor;MediaFire NTFS Monitor; C:\Users\Tim\AppData\Local\MEDIAF~1\MFUSNM~1.EXE [2014-07-02 456504] S2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-07-02 935368] S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-13 76888] S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-12 1050904] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008] S2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-04-20 129424] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936] S2 VMAuthdService;VMware Authorization Service; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [2013-11-05 87768] S2 VMnetDHCP;VMware DHCP Service; C:\Windows\syswow64\vmnetdhcp.exe [2013-11-05 358104] S2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2013-10-29 919768] S2 VMware NAT Service;VMware NAT Service; C:\Windows\syswow64\vmnat.exe [2013-11-05 437464] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440] S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2014-06-27 1357104] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2014-07-23 1044816] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696] S3 HssTrayService;Hotspot Shield Tray Service; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [2014-05-17 78512] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [] S3 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max 2015 64-bit; C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-06 119408] S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2014-06-05 37176] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-07-16 542912] -----------------EOF-----------------