Logfile of random's system information tool 1.10 (written by random/random) Run by Gebruiker at 2015-02-23 16:40:12 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 97 GB (67%) free of 145 GB Total RAM: 3037 MB (52% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 16:40:24, on 23/02/2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17631) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Brownie\BrStsWnd.exe C:\Program Files\Brownie\brpjp04a.exe C:\ProgramData\RegTool Pro\RegToolPro.exe C:\Users\Gebruiker\AppData\Roaming\TweakBCD\TweakBCD.res C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\Brownie\brpjp04a.exe C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\Program Files\CCleaner\CCleaner.exe C:\Program Files\TeamViewer\TeamViewer.exe C:\Users\Gebruiker\Desktop\RSIT.exe C:\Program Files\trend micro\Gebruiker.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file) O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file) O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe -- End of file - 5859 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\ROC_REG_JAN_DELETE.job - C:\ProgramData\AVG January 2013 Campaign\ROC.exe /DELETE_FROM_SYSTEM=1 ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2012-10-15 1417336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-07-20 42272] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "BrStsWnd"=C:\Program Files\Brownie\BrstsWnd.exe [2011-03-25 3618160] "AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2012-11-19 2598520] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-01-20 5496600] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LivePlayer] C:\Program Files\LivePlayer\LivePlayer.exe [2015-02-18 3740160] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Gebruiker^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MP3Convertor.exe] [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2011-02-11 228864] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2015-02-23 16:40:13 ----D---- C:\Program Files\trend micro 2015-02-23 16:40:12 ----D---- C:\rsit 2015-02-23 13:19:06 ----D---- C:\Program Files\TeamViewer 2015-02-23 11:09:36 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2015-02-23 11:09:19 ----D---- C:\ProgramData\Malwarebytes 2015-02-23 11:09:19 ----D---- C:\Program Files\Malwarebytes Anti-Malware 2015-02-23 11:09:19 ----A---- C:\Windows\system32\drivers\mwac.sys 2015-02-23 11:09:19 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2015-02-23 11:09:19 ----A---- C:\Windows\system32\drivers\mbam.sys 2015-02-23 10:11:21 ----D---- C:\Users\Gebruiker\AppData\Roaming\Eusing 2015-02-23 10:11:13 ----D---- C:\Program Files\Eusing Free Registry Cleaner 2015-02-23 10:07:51 ----D---- C:\ProgramData\VS Revo Group 2015-02-23 10:07:50 ----A---- C:\Windows\system32\drivers\revoflt.sys 2015-02-23 10:07:46 ----D---- C:\Program Files\VS Revo Group 2015-02-23 10:06:42 ----SHD---- C:\Config.Msi 2015-02-23 10:00:35 ----A---- C:\Windows\system32\wdi.dll 2015-02-23 10:00:35 ----A---- C:\Windows\system32\powertracker.dll 2015-02-23 10:00:35 ----A---- C:\Windows\system32\perftrack.dll 2015-02-23 09:41:24 ----D---- C:\Program Files\CCleaner 2015-02-23 09:23:00 ----HD---- C:\$AVG 2015-02-19 12:57:51 ----A---- C:\Users\Gebruiker\AppData\Roaming\rprt.txt 2015-02-19 12:57:44 ----D---- C:\Users\Gebruiker\AppData\Roaming\TweakBCD 2015-02-19 12:57:44 ----D---- C:\ProgramData\RegTool Pro 2015-02-19 12:57:44 ----D---- C:\ProgramData\Realtek WiFi Mod 2015-02-19 12:57:44 ----D---- C:\Program Files\LivePlayer 2015-02-19 12:57:40 ----D---- C:\Users\Gebruiker\AppData\Roaming\Notification Center 2015-02-12 07:39:43 ----A---- C:\Windows\system32\jscript9diag.dll 2015-02-12 07:39:43 ----A---- C:\Windows\system32\jscript9.dll 2015-02-11 07:48:32 ----A---- C:\Windows\system32\win32k.sys 2015-02-11 07:48:25 ----A---- C:\Windows\system32\sspisrv.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\sspicli.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\secur32.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\msobjs.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\msaudite.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\lsass.exe 2015-02-11 07:48:25 ----A---- C:\Windows\system32\lsasrv.dll 2015-02-11 07:48:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys 2015-02-11 07:48:25 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2015-02-11 07:48:25 ----A---- C:\Windows\system32\drivers\cng.sys 2015-02-11 07:48:25 ----A---- C:\Windows\system32\auditpol.exe 2015-02-11 07:48:25 ----A---- C:\Windows\system32\adtschema.dll 2015-02-11 07:48:14 ----A---- C:\Windows\system32\ntoskrnl.exe 2015-02-11 07:48:14 ----A---- C:\Windows\system32\ntkrnlpa.exe 2015-02-11 07:48:12 ----A---- C:\Windows\system32\mstscax.dll 2015-02-11 07:48:12 ----A---- C:\Windows\system32\aaclient.dll 2015-02-11 07:48:11 ----A---- C:\Windows\system32\oleaut32.dll 2015-02-11 07:48:11 ----A---- C:\Windows\system32\generaltel.dll 2015-02-11 07:48:11 ----A---- C:\Windows\system32\appraiser.dll 2015-02-11 07:48:10 ----A---- C:\Windows\system32\invagent.dll 2015-02-11 07:48:10 ----A---- C:\Windows\system32\devinv.dll 2015-02-11 07:48:10 ----A---- C:\Windows\system32\aitstatic.exe 2015-02-11 07:48:10 ----A---- C:\Windows\system32\aepic.dll 2015-02-11 07:48:10 ----A---- C:\Windows\system32\aepdu.dll 2015-02-11 07:48:10 ----A---- C:\Windows\system32\aeinv.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\wdigest.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\TSpkg.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\schannel.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\ncrypt.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\msv1_0.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\kerberos.dll 2015-02-11 07:48:05 ----A---- C:\Windows\system32\credssp.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\urlmon.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe 2015-02-11 07:48:03 ----A---- C:\Windows\system32\jsproxy.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\iernonce.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\ieetwproxystub.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\ieetwcollector.exe 2015-02-11 07:48:03 ----A---- C:\Windows\system32\iedkcs32.dll 2015-02-11 07:48:03 ----A---- C:\Windows\system32\ie4uinit.exe 2015-02-11 07:48:02 ----A---- C:\Windows\system32\msfeeds.dll 2015-02-11 07:48:02 ----A---- C:\Windows\system32\ieUnatt.exe 2015-02-11 07:48:02 ----A---- C:\Windows\system32\ieapfltr.dll 2015-02-11 07:48:02 ----A---- C:\Windows\system32\dxtmsft.dll 2015-02-11 07:48:01 ----A---- C:\Windows\system32\wininet.dll 2015-02-11 07:48:01 ----A---- C:\Windows\system32\msrating.dll 2015-02-11 07:48:01 ----A---- C:\Windows\system32\iesetup.dll 2015-02-11 07:48:01 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2015-02-11 07:48:00 ----A---- C:\Windows\system32\ieui.dll 2015-02-11 07:48:00 ----A---- C:\Windows\system32\ieframe.dll 2015-02-11 07:48:00 ----A---- C:\Windows\system32\dxtrans.dll 2015-02-11 07:47:59 ----A---- C:\Windows\system32\mshtmlmedia.dll 2015-02-11 07:47:59 ----A---- C:\Windows\system32\mshtmled.dll 2015-02-11 07:47:58 ----A---- C:\Windows\system32\MshtmlDac.dll 2015-02-11 07:47:58 ----A---- C:\Windows\system32\iertutil.dll 2015-02-11 07:47:57 ----A---- C:\Windows\system32\vbscript.dll 2015-02-11 07:47:57 ----A---- C:\Windows\system32\mshtml.dll 2015-02-11 07:47:50 ----A---- C:\Windows\system32\wintrust.dll 2015-02-11 07:47:50 ----A---- C:\Windows\system32\cryptsvc.dll 2015-02-11 07:47:50 ----A---- C:\Windows\system32\crypt32.dll 2015-02-11 07:47:49 ----A---- C:\Windows\system32\WindowsCodecs.dll 2015-02-11 07:47:49 ----A---- C:\Windows\system32\scesrv.dll 2015-02-11 07:39:26 ----D---- C:\Program Files\Assets Manager ======List of files/folders modified in the last 1 month====== 2015-02-23 16:40:22 ----D---- C:\Windows\Temp 2015-02-23 16:40:13 ----RD---- C:\Program Files 2015-02-23 16:35:47 ----D---- C:\Windows\system32\config 2015-02-23 16:35:33 ----A---- C:\Windows\Brownie.ini 2015-02-23 16:30:24 ----D---- C:\Program Files\Steam 2015-02-23 14:14:17 ----D---- C:\Program Files\Common Files\Steam 2015-02-23 13:19:15 ----D---- C:\Windows\system32\Tasks 2015-02-23 13:19:12 ----RSD---- C:\Windows\Fonts 2015-02-23 12:13:13 ----D---- C:\Windows\Microsoft.NET 2015-02-23 11:50:58 ----D---- C:\Windows\Tasks 2015-02-23 11:50:55 ----HD---- C:\ProgramData 2015-02-23 11:50:55 ----D---- C:\Program Files\Common Files 2015-02-23 11:50:30 ----D---- C:\Windows\inf 2015-02-23 11:49:55 ----SD---- C:\Windows\system32\Microsoft 2015-02-23 11:49:55 ----D---- C:\Windows\System32 2015-02-23 11:22:37 ----D---- C:\Windows\system32\drivers 2015-02-23 11:22:37 ----D---- C:\Windows\Sun 2015-02-23 10:38:31 ----A---- C:\Windows\system32\PerfStringBackup.INI 2015-02-23 10:32:39 ----D---- C:\Windows\winsxs 2015-02-23 10:32:23 ----D---- C:\Windows 2015-02-23 10:32:20 ----D---- C:\Windows\system32\Samsung_USB_Drivers 2015-02-23 10:30:33 ----D---- C:\Windows\tracing 2015-02-23 10:29:55 ----SHD---- C:\Windows\Installer 2015-02-23 10:21:40 ----SHD---- C:\System Volume Information 2015-02-23 10:15:33 ----HD---- C:\Program Files\InstallShield Installation Information 2015-02-23 10:15:33 ----D---- C:\Users\Gebruiker\AppData\Roaming\Samsung 2015-02-23 09:47:52 ----D---- C:\Windows\debug 2015-02-23 09:44:18 ----D---- C:\Program Files\Google 2015-02-23 09:35:01 ----D---- C:\ProgramData\TS 2015-02-23 09:34:53 ----D---- C:\Users\Gebruiker\AppData\Roaming\TS 2015-02-23 09:33:10 ----D---- C:\Windows\system32\drivers\AVG 2015-02-23 09:32:00 ----D---- C:\ProgramData\MFAData 2015-02-23 09:23:28 ----D---- C:\ProgramData\AVG2012 2015-02-23 09:23:07 ----D---- C:\Windows\system32\DriverStore 2015-02-23 09:18:13 ----D---- C:\Windows\Prefetch 2015-02-23 09:09:51 ----D---- C:\Windows\pss 2015-02-23 09:03:47 ----D---- C:\Users\Gebruiker\AppData\Roaming\TeamViewer 2015-02-23 08:43:44 ----D---- C:\Windows\system32\wbem 2015-02-23 08:43:07 ----D---- C:\Program Files\Internet Explorer 2015-02-23 08:43:07 ----D---- C:\Program Files\Common Files\microsoft shared 2015-02-23 08:43:04 ----D---- C:\Users\Gebruiker\AppData\Roaming\AVG2012 2015-02-23 08:43:03 ----D---- C:\Windows\rescache 2015-02-23 08:43:02 ----SD---- C:\Windows\system32\CompatTel 2015-02-23 08:43:02 ----D---- C:\Windows\system32\nl-NL 2015-02-23 08:43:02 ----D---- C:\Windows\system32\NDF 2015-02-23 08:43:02 ----D---- C:\Windows\system32\en-US 2015-02-23 08:43:02 ----D---- C:\Windows\system32\CodeIntegrity 2015-02-23 08:43:02 ----D---- C:\Windows\system32\catroot2 2015-02-23 08:43:02 ----D---- C:\Windows\system32\appraiser 2015-02-23 08:42:58 ----D---- C:\Windows\registration 2015-02-11 12:54:32 ----D---- C:\Windows\system32\MRT 2015-02-11 12:51:45 ----A---- C:\Windows\system32\MRT.exe 2015-02-11 12:50:53 ----D---- C:\ProgramData\Microsoft Help 2015-02-11 07:47:48 ----D---- C:\Windows\system32\catroot 2015-02-05 11:07:03 ----A---- C:\Windows\system32\FlashPlayerApp.exe ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2012-04-19 24896] R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2012-01-31 31952] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2009-06-05 330264] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2011-05-23 47968] R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2012-11-08 250080] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2011-12-23 41040] R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2014-11-04 302368] R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2006-07-24 5632] R2 BrPar;BrPar; C:\Windows\System32\drivers\BrPar.sys [2000-07-24 19537] R2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704] R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2012-12-10 142176] R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfilterx.sys [2011-12-23 24144] R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2011-12-23 17232] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-05-30 260648] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-20 2664032] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 23256] R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-02-23 114904] R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 51928] R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2013-06-26 583848] R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2013-06-26 197800] R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2013-06-26 24232] R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2013-06-26 20136] S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368] S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088] R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2012\avgfws.exe [2014-11-04 2322000] R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2013-10-16 5175856] R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] R2 cvhsvc;Client Virtualization Handler; C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2013-04-22 822504] R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2011-06-14 30080] R2 GREGService;GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [2011-05-30 36456] R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840] R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-02-07 255376] R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016] R2 sftlist;Application Virtualization Client; C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe [2013-06-26 523944] R2 TeamViewer;TeamViewer 10; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176] R3 sftvsa;Application Virtualization Service Agent; C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe [2013-06-26 207528] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05 267440] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 102912] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-02-19 835776] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-20 1343400] S3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 1713536] S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040] -----------------EOF-----------------