Logfile of random's system information tool 1.10 (written by random/random) Run by robke at 2014-12-23 20:49:33 Microsoft® Windows Vista™ Home Premium Service Pack 1 System drive C: has 33 GB (48%) free of 68 GB Total RAM: 1790 MB (22% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:51:56, on 23/12/2014 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18444) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_246_ActiveX.exe C:\Windows\system32\wuauclt.exe C:\Users\robke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5COTAFTM\HijackThis[1].exe C:\Users\robke\Downloads\RSIT.exe C:\Program Files\trend micro\robke.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=BENL&range=AD&phase=8&key=IESTART R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe -- End of file - 5308 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3723894691-1265959471-2415864850-1002Core.job - C:\Users\robke\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3723894691-1265959471-2415864850-1002UA.job - C:\Users\robke\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\HDReg.job - C:\Program Files\HDReg\HDRegRem.exe C:\Windows\tasks\User_Feed_Synchronization-{FA5BB042-30F9-427A-9F0A-4A90A31DFB6A}.job - C:\Windows\system32\msfeedssync.exe sync ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Help bij koppelingen - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}] Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2010-04-28 113512] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Aanmelden - Help - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184] "MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 974432] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-02-09 845360] "NvSvc"=C:\Windows\system32\nvsvc.dll [2007-09-19 86016] "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-09-19 8497696] "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-09-19 81920] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvgUninstallURL] cmd.exe /c start http://www.avg.com/nl.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYATgBKADMAMgAtAEcAMwBMAEEAQQAtAEEANAA4ADkAUgAtADkAVQBKAEsARgAtAEUASwBLADMAWAA&inst=NwA3AC0ANAAxADQANwAzADUAMAAzADcALQBGAEwAKwA5AC0AWABPADMANgArADEALQBYAE8AOQArADEALQBEAEQAVAArADIAMQA2ADEANAAtAEQARAA5ADAARgArADEALQBTAFQAOQAwAEYAQQBQAFAAKwAxAC0ARgA5ADAATQAxADIARQBUACsAMQAtAFQAQgBOACsAMQAtAEwAOQAwAE0ASgArADIALQBGADkAMABNADEAMgBKAE4AKwAxAC0ARgA5ADAATQAxADIAUgArADEALQBWAEkAUAAxADIAKwAxAA&prod=90&ver=9.0.894 [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CardReaderMonitor] C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe [2007-07-25 643072] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe] C:\Windows\ehome\ehTray.exe [2008-01-19 125952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update] C:\Users\robke\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-22 138096] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fssui] C:\Program Files\Windows Live\Family Safety\fsui.exe [2010-04-28 647528] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-26 30192] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] C:\Windows\system32\NvCpl.dll [2007-09-19 8497696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] C:\Windows\system32\NvMcTray.dll [2007-09-19 81920] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc] C:\Windows\system32\nvsvc.dll [2007-09-19 86016] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Program Files\Skype\Phone\Skype.exe [2014-10-01 22059616] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-02-09 845360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [2004-08-27 90112] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "VIDC.JDCT"=jl_jdct.drv "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "aux3"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux2"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======List of files/folders created in the last 1 month====== 2014-12-23 20:49:36 ----D---- C:\Program Files\trend micro 2014-12-23 20:49:33 ----D---- C:\rsit 2014-12-18 20:11:12 ----D---- C:\PerfLogs 2014-12-18 18:48:07 ----D---- C:\Windows\system32\MRT 2014-12-17 09:59:30 ----D---- C:\Program Files\Microsoft Security Client 2014-12-16 20:06:11 ----A---- C:\Windows\system32\drivers\hitmanpro37.sys 2014-12-16 14:41:39 ----D---- C:\ProgramData\HitmanPro 2014-12-16 14:26:02 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2014-12-16 14:25:46 ----D---- C:\ProgramData\Malwarebytes 2014-12-16 14:25:46 ----D---- C:\Program Files\Malwarebytes Anti-Malware 2014-12-16 14:25:46 ----A---- C:\Windows\system32\drivers\mwac.sys 2014-12-16 14:25:46 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2014-12-16 14:25:46 ----A---- C:\Windows\system32\drivers\mbam.sys 2014-12-16 14:19:13 ----D---- C:\AdwCleaner 2014-12-16 14:19:13 ----A---- C:\AdwCleanerDebug.txt ======List of files/folders modified in the last 1 month====== 2014-12-23 20:51:54 ----D---- C:\Windows\Temp 2014-12-23 20:49:53 ----D---- C:\Windows\Prefetch 2014-12-23 20:49:36 ----RD---- C:\Program Files 2014-12-23 20:39:50 ----D---- C:\Windows\system32\catroot 2014-12-23 20:39:49 ----D---- C:\Windows\system32\catroot2 2014-12-23 20:39:45 ----D---- C:\Windows\winsxs 2014-12-23 20:13:16 ----D---- C:\Windows\rescache 2014-12-23 20:02:10 ----D---- C:\Windows\inf 2014-12-23 20:02:10 ----AD---- C:\Windows\System32 2014-12-23 20:02:10 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-12-23 20:00:36 ----SHD---- C:\System Volume Information 2014-12-20 12:29:07 ----RSD---- C:\Windows\assembly 2014-12-18 20:31:23 ----D---- C:\Windows\Microsoft.NET 2014-12-18 20:30:56 ----D---- C:\Windows 2014-12-18 20:30:29 ----SHD---- C:\boot 2014-12-18 20:29:08 ----ASH---- C:\Program Files\desktop.ini 2014-12-18 20:15:26 ----D---- C:\Program Files\Windows Mail 2014-12-18 20:15:26 ----D---- C:\Program Files\Windows Calendar 2014-12-18 20:15:25 ----D---- C:\Program Files\Movie Maker 2014-12-18 20:15:24 ----D---- C:\Program Files\Windows Sidebar 2014-12-18 20:15:24 ----D---- C:\Program Files\Windows Media Player 2014-12-18 20:15:24 ----D---- C:\Program Files\Internet Explorer 2014-12-18 20:15:20 ----D---- C:\Program Files\Windows Collaboration 2014-12-18 20:15:19 ----D---- C:\Windows\servicing 2014-12-18 20:15:19 ----D---- C:\Windows\ehome 2014-12-18 20:15:19 ----D---- C:\Program Files\Windows Photo Gallery 2014-12-18 20:15:19 ----D---- C:\Program Files\Windows Journal 2014-12-18 20:15:19 ----D---- C:\Program Files\Windows Defender 2014-12-18 20:15:19 ----D---- C:\Program Files\Common Files\System 2014-12-18 20:15:18 ----D---- C:\Windows\MSAgent 2014-12-18 20:15:18 ----D---- C:\Windows\L2Schemas 2014-12-18 20:15:18 ----D---- C:\Windows\IME 2014-12-18 20:15:18 ----D---- C:\Windows\DigitalLocker 2014-12-18 20:15:17 ----D---- C:\Windows\system32\sysprep 2014-12-18 20:15:17 ----D---- C:\Windows\system32\oobe 2014-12-18 20:15:17 ----D---- C:\Windows\system32\migration 2014-12-18 20:15:17 ----D---- C:\Windows\system32\ko-KR 2014-12-18 20:15:17 ----D---- C:\Windows\system32\it-IT 2014-12-18 20:15:17 ----D---- C:\Windows\system32\en-US 2014-12-18 20:15:17 ----D---- C:\Windows\system32\el-GR 2014-12-18 20:15:17 ----D---- C:\Windows\system32\de-DE 2014-12-18 20:15:17 ----D---- C:\Windows\system32\da-DK 2014-12-18 20:15:17 ----D---- C:\Windows\system32\com 2014-12-18 20:15:17 ----D---- C:\Windows\PolicyDefinitions 2014-12-18 20:15:15 ----D---- C:\Windows\system32\sv-SE 2014-12-18 20:15:15 ----D---- C:\Windows\system32\SLUI 2014-12-18 20:15:15 ----D---- C:\Windows\system32\setup 2014-12-18 20:15:15 ----D---- C:\Windows\system32\ru-RU 2014-12-18 20:15:15 ----D---- C:\Windows\system32\pt-PT 2014-12-18 20:15:15 ----D---- C:\Windows\system32\ias 2014-12-18 20:15:15 ----D---- C:\Windows\system32\hu-HU 2014-12-18 20:15:15 ----D---- C:\Windows\system32\he-IL 2014-12-18 20:15:15 ----D---- C:\Windows\system32\fr-FR 2014-12-18 20:15:15 ----D---- C:\Windows\system32\fi-FI 2014-12-18 20:15:15 ----D---- C:\Windows\system32\cs-CZ 2014-12-18 20:15:15 ----D---- C:\Windows\system32\AdvancedInstallers 2014-12-18 20:15:03 ----D---- C:\Windows\system32\zh-CN 2014-12-18 20:15:02 ----D---- C:\Windows\system32\zh-TW 2014-12-18 20:15:02 ----D---- C:\Windows\system32\manifeststore 2014-12-18 20:15:02 ----D---- C:\Windows\system32\es-ES 2014-12-18 20:15:01 ----D---- C:\Windows\system32\ro-RO 2014-12-18 20:15:01 ----D---- C:\Windows\system32\pl-PL 2014-12-18 20:15:01 ----D---- C:\Windows\system32\ja-JP 2014-12-18 20:14:59 ----D---- C:\Windows\system32\drivers\nl-NL 2014-12-18 20:14:57 ----D---- C:\Windows\system32\drivers 2014-12-18 20:14:51 ----D---- C:\Windows\system32\wbem 2014-12-18 20:14:51 ----D---- C:\Windows\system32\tr-TR 2014-12-18 20:14:50 ----D---- C:\Windows\system32\nb-NO 2014-12-18 20:14:49 ----D---- C:\Windows\system32\nl-NL 2014-12-18 20:14:27 ----D---- C:\Windows\system32\ar-SA 2014-12-18 20:14:16 ----D---- C:\Windows\system32\migwiz 2014-12-18 20:14:14 ----D---- C:\Windows\system32\pt-BR 2014-12-18 20:12:07 ----D---- C:\Windows\AppPatch 2014-12-18 20:11:27 ----D---- C:\Windows\Boot 2014-12-18 20:11:16 ----D---- C:\Windows\system32\Boot 2014-12-18 20:07:21 ----D---- C:\ProgramData\NVIDIA 2014-12-18 20:04:06 ----D---- C:\Windows\system32\drivers\UMDF 2014-12-18 19:39:06 ----A---- C:\Windows\system32\ifxcardm.dll 2014-12-18 19:39:03 ----A---- C:\Windows\system32\axaltocm.dll 2014-12-18 18:56:37 ----SHD---- C:\Windows\Installer 2014-12-18 18:56:35 ----D---- C:\Program Files\Microsoft Office 2014-12-18 18:48:02 ----D---- C:\Windows\Debug 2014-12-17 09:59:36 ----SD---- C:\ProgramData\Microsoft 2014-12-17 09:40:27 ----HD---- C:\ProgramData 2014-12-17 09:36:32 ----D---- C:\Users\robke\AppData\Roaming\Skype 2014-12-16 20:15:02 ----D---- C:\Windows\Minidump 2014-12-16 15:27:23 ----D---- C:\Windows\Help 2014-12-16 14:41:33 ----D---- C:\Program Files\Common Files 2014-12-16 14:41:32 ----D---- C:\Windows\Tasks 2014-12-16 14:41:31 ----D---- C:\Windows\system32\Tasks 2014-12-10 19:57:12 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2014-12-07 10:08:00 ----D---- C:\Windows\system32\mjcm 2014-11-27 16:40:04 ----A---- C:\Windows\system32\mrt.exe 2014-11-27 09:15:14 ----A---- C:\Windows\system32\msvcr80.dll 2014-11-27 09:15:14 ----A---- C:\Windows\system32\msvcp80.dll 2014-11-27 09:15:14 ----A---- C:\Windows\system32\msvcm80.dll ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 231800] R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2006-09-27 36560] R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2014-04-28 42272] R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664] R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-11-05 182272] R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-03-06 1059112] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-19 7626400] R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032] R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-10-05 288256] R3 RTSTOR;USB Mass Storage Device; C:\Windows\system32\drivers\RTSTOR.SYS [2007-06-15 47616] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-02-09 182456] S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632] S3 hitmanpro37;HitmanPro 3.7 Support Driver; \??\C:\Windows\system32\drivers\hitmanpro37.sys [2014-12-16 35992] S3 JL2005C;Dual Mode Camera; C:\Windows\System32\Drivers\jl2005c.sys [2007-01-26 68954] S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-19 73088] S3 usbvideo;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016] S3 WINIO;WINIO; \??\C:\Windows\system32\WinIo.sys [2007-01-04 9336] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 22192] S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-31 135664] S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10 267440] S3 fsssvc;De service Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-04-28 704872] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-26 30192] S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-31 135664] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-21 194032] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] -----------------EOF-----------------