Logfile of random's system information tool 1.10 (written by random/random) Run by JP at 2015-06-06 14:25:34 Microsoft Windows 8.1 System drive C: has 321 GB (34%) free of 940 GB Total RAM: 8056 MB (61% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:25:35, on 6-6-2015 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.17416) Boot mode: Normal Running processes: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\LogicNow\ControlNow Agent\viprebusiness\SBAMTray.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files\trend micro\JP.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49596;https=127.0.0.1:49596 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\WINDOWS\SysWOW64\userinit.exe, O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTB.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: iSkysoft Video Converter Ultimate 5.1.0 - {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} - C:\PROGRA~3\iSkysoft\VIDEOC~1\WSBROW~1.DLL O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTB.dll O3 - Toolbar: FindWide Toolbar - {428B3185-D796-4106-94BE-0EA9D73C3C38} - C:\Program Files (x86)\TNT2\2.0.0.1950\ietoolbar.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Panda Security Toolbar - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll O4 - HKLM\..\Run: [KSafeTray] "C:\Program files (x86)\Kingsoft\PCDoctor\KSafeTray.exe" -autorun O4 - HKLM\..\Run: [SBAMTray] "C:\PROGRA~2\LogicNow\CONTRO~1\viprebusiness\SBAMTray.exe" O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_D485D20C06BDCDEB626207281C5C94F7] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window O4 - HKCU\..\Run: [CloudSystemBooster] "C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe" /hide /autorun O4 - Startup: Dropbox.lnk = JP\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: eBay Search - res://C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1263.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Protocol: WSISVCUchrome - {78A543EB-3A61-4ED3 - (no file) O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Anvi Cloud System Booster Speed Service (AnviCsbSvc) - Anvisoft - C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Unknown owner - C:\Program Files (x86)\MyPC Backup\BackupStack.exe O23 - Service: @oem32.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing) O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: ControlNow Agent - LogicNow - C:\Program Files (x86)\LogicNow\ControlNow Agent\cloudagent.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Connected Remote Service (HPConnectedRemote) - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe O23 - Service: KSafe service (KSafeSvc) - Kingsoft Corporation - C:\Program files (x86)\Kingsoft\PCDoctor\KSafeSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Panda Protection Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe O23 - Service: Panda Devices Agent (PandaAgent) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe O23 - Service: panda_url_filtering Service (panda_url_filtering) - Panda Security - C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filteringb.exe O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe O23 - Service: Panda Product Service (PSUAService) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: GFI Cloud - Antivirus (SBAMSvc) - ThreatTrack Security, Inc. - C:\PROGRA~2\LogicNow\CONTRO~1\viprebusiness\SBAMSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 16095 bytes ======Listing Processes====== wininit.exe winlogon.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS "dwm.exe" C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\WLANExt.exe 291217646512 "C:\Program files (x86)\Kingsoft\PCDoctor\KSafeSvc.exe" -svc \??\C:\WINDOWS\system32\conhost.exe 0x4 C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service "C:\Program Files (x86)\LogicNow\ControlNow Agent\cloudagent.exe" "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe" C:\WINDOWS\system32\svchost.exe -k imgsvc dashost.exe {66a5994b-f059-491c-b613eb548d72dfdf} C:\PROGRA~2\LogicNow\CONTRO~1\viprebusiness\SBAMSvc.exe C:\WINDOWS\System32\svchost.exe -k utcsvc C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe" "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe" "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-62d1caaf-4b63-48fb-bacb-3a7c35fcce1f -SystemEventPortName:HostProcess-a0dfca74-7bb2-4296-82bf-bfcefdca89bd -IoCancelEventPortName:HostProcess-58adc16c-9029-4ea9-9d05-96838d8b8c33 -NonStateChangingEventPortName:HostProcess-2cd00934-460a-41db-a2f7-8137f0300d5c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4c8903cb-c08a-4cdf-9ec4-6f835b5496f2 -DeviceGroupId:WpdFsGroup "C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe" C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe" "C:\Program Files (x86)\MyPC Backup\BackupStack.exe" "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" C:\windows\system32\svchost.exe -k HPService "c:\Program Files\Intel\iCLS Client\HeciServer.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" C:\windows\System32\svchost.exe -k HPZ12 "C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filteringb.exe" -- "C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe" "C:\Program Files\IDT\WDM\STacSV64.exe" C:\windows\System32\svchost.exe -k HPZ12 "C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe" "C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe" "C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe" "C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe" C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt "C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe" "C:\Program Files\IDT\WDM\AESTSr64.exe" "c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe" "C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe" KMPProcess "c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe" "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2136 C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} C:\WINDOWS\system32\SearchIndexer.exe /Embedding C:\Windows\System32\skydrive.exe -Embedding "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --parent-handle=436 "C:\Program Files (x86)\LogicNow\ControlNow Agent\viprebusiness\SBAMTray.exe" c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5508.0.1670188538\2002111338" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,40 --gpu-vendor-id=0x8086 --gpu-device-id=0x0152 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3325 --ignored=" --type=renderer " /prefetch:822062411 "C:\Windows\System32\SettingSyncHost.exe" -Embedding "C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" "C:\Program Files (x86)\Skype\Phone\Skype.exe" "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchSysTray "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchAnalysis C:\WINDOWS\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding C:\WINDOWS\system32\vssvc.exe C:\WINDOWS\System32\svchost.exe -k swprv "C:\WINDOWS\system32\SearchFilterHost.exe" 0 556 572 584 65536 580 C:\WINDOWS\System32\svchost.exe -k WerSvcGroup "C:\Program Files (x86)\Windows Live\Mail\wlmail.exe" "C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/SuggestFeatureAblation_Control_R1/PasswordGeneration/Disabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group5/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Disabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=5508 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="5508.15.1457137907\320944664" /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/SuggestFeatureAblation_Control_R1/PasswordGeneration/Disabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group5/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Disabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=5508 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="5508.17.1308713911\1271083809" /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/SuggestFeatureAblation_Control_R1/PasswordGeneration/Disabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group5/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_73/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Disabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=5508 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --channel="5508.18.846698790\461493923" /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5508.19.117540007\822425709" --ppapi-flash-args=enable_hw_video_decode=1 --lang=nl --ignored=" --type=renderer " /prefetch:-632637702 "C:\Users\JP\Downloads\RSITx64 (1).exe" C:\WINDOWS\system32\wbem\wmiprvse.exe ======Scheduled tasks folder====== C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\WINDOWS\tasks\KsafeDelay.job - C:\Program Files (x86)\Kingsoft\PCDoctor\KSafeTray.exe -delayruncheck C:\WINDOWS\tasks\User_Feed_Synchronization-{A492CC4E-4162-423E-8886-D7FB34115904}.job - C:\WINDOWS\system32\msfeedssync.exe sync C:\WINDOWS\tasks\{2D8EAB7C-1E04-460E-AC14-BB1920624DCF}.job - C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe {2D8EAB7C-1E04-460E-AC14-BB1920624DCF} ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03 256456] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}] Panda Security Toolbar - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx64.dll [2015-02-10 131096] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}] MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll [2014-01-16 96128] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}] eBay Toolbar Helper - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTB.dll [2013-09-28 525552] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03 194504] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE}] iSkysoft Video Converter Ultimate 5.1.0 - C:\PROGRA~3\iSkysoft\VIDEOC~1\WSBROW~1.DLL [2014-05-22 615936] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}] Panda Security Toolbar - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll [2015-02-10 115224] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {428B3185-D796-4106-94BE-0EA9D73C3C38} - FindWide Toolbar - C:\Program Files (x86)\TNT2\2.0.0.1950\IEToolbar64.dll [2015-03-02 199936] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03 256456] {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - Panda Security Toolbar - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx64.dll [2015-02-10 131096] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - eBay Toolbar - C:\Program Files (x86)\eBay\eBay Toolbar2\eBayTB.dll [2013-09-28 525552] {428B3185-D796-4106-94BE-0EA9D73C3C38} - FindWide Toolbar - C:\Program Files (x86)\TNT2\2.0.0.1950\ietoolbar.dll [2015-03-02 144128] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03 194504] {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - Panda Security Toolbar - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll [2015-02-10 115224] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "GoogleChromeAutoLaunch_D485D20C06BDCDEB626207281C5C94F7"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-03-14 809288] "CloudSystemBooster"=C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe [2015-04-01 577296] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "KSafeTray"=C:\Program files (x86)\Kingsoft\PCDoctor\KSafeTray.exe [2012-04-11 742816] "SBAMTray"=C:\PROGRA~2\LogicNow\CONTRO~1\viprebusiness\SBAMTray.exe [2013-05-28 3232152] C:\Users\JP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Dropbox.lnk - C:\Users\JP\AppData\Roaming\Dropbox\bin\Dropbox.exe MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\windows\SYSTEM32\igfxdev.dll [2013-10-15 623616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NanoServiceMain] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSUAService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "SynchronousUserGroupPolicy"=0 "SynchronousMachineGroupPolicy"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoInstrumentation"=0 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=181 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "VIDC.YUY2"=msyuv.dll "vidc.i420"=iyuv_32.dll "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "VIDC.YVYU"=msyuv.dll "VIDC.YVU9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "VIDC.UYVY"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.mrle"=msrle32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.msvc"=msvidc32.dll "MSVideo8"=VfWWDM32.dll "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave5"=wdmaud.drv "midi5"=wdmaud.drv "mixer5"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "wave6"=wdmaud.drv "midi6"=wdmaud.drv "mixer6"=wdmaud.drv "wave7"=wdmaud.drv "midi7"=wdmaud.drv "mixer7"=wdmaud.drv "wave8"=wdmaud.drv "midi8"=wdmaud.drv "mixer8"=wdmaud.drv "wave9"=wdmaud.drv "midi9"=wdmaud.drv "mixer9"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2015-06-06 14:06:16 ----D---- C:\rsit 2015-06-06 14:06:16 ----D---- C:\Program Files\trend micro 2015-06-05 21:58:26 ----D---- C:\Users\JP\AppData\Roaming\GFI Software 2015-06-05 21:18:02 ----A---- C:\WINDOWS\system32\drivers\gfiutil.sys 2015-06-05 21:18:02 ----A---- C:\WINDOWS\system32\drivers\gfiark.sys 2015-06-05 21:15:47 ----D---- C:\ProgramData\GFI Software 2015-06-05 21:13:01 ----A---- C:\WINDOWS\system32\sbbd.exe 2015-06-05 21:13:01 ----A---- C:\WINDOWS\system32\drivers\gfibto.sys 2015-06-05 20:54:03 ----D---- C:\Program Files (x86)\LogicNow 2015-06-05 19:12:23 ----A---- C:\WINDOWS\ntbtlog.txt 2015-06-04 21:19:42 ----A---- C:\WINDOWS\system32\PCloudBroom64.exe 2015-06-01 14:24:49 ----A---- C:\WINDOWS\SYSWOW64\rascfg.dll 2015-06-01 14:24:49 ----A---- C:\WINDOWS\system32\rascfg.dll 2015-06-01 14:24:49 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys 2015-06-01 14:24:49 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys 2015-06-01 14:23:28 ----A---- C:\WINDOWS\SYSWOW64\rastapi.dll 2015-06-01 14:23:28 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll 2015-06-01 14:23:28 ----A---- C:\WINDOWS\system32\rastapi.dll 2015-06-01 14:23:28 ----A---- C:\WINDOWS\system32\puiobj.dll 2015-06-01 14:23:28 ----A---- C:\WINDOWS\system32\localspl.dll 2015-06-01 14:23:28 ----A---- C:\WINDOWS\system32\compstui.dll 2015-06-01 14:23:14 ----A---- C:\WINDOWS\SYSWOW64\rgb9rast.dll 2015-06-01 14:23:14 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll 2015-06-01 14:23:14 ----A---- C:\WINDOWS\system32\UtcResources.dll 2015-06-01 14:23:14 ----A---- C:\WINDOWS\system32\msftedit.dll 2015-06-01 14:23:14 ----A---- C:\WINDOWS\system32\diagtrack.dll 2015-06-01 14:23:04 ----A---- C:\WINDOWS\SYSWOW64\authz.dll 2015-06-01 14:23:04 ----A---- C:\WINDOWS\system32\authz.dll 2015-06-01 14:23:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll 2015-06-01 14:23:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2015-06-01 14:23:02 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll 2015-06-01 14:23:02 ----A---- C:\WINDOWS\system32\MDMAgent.exe 2015-06-01 14:23:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll 2015-06-01 14:23:00 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll 2015-06-01 14:22:41 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS 2015-06-01 14:22:37 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll 2015-06-01 14:22:36 ----A---- C:\WINDOWS\system32\SyncEngine.dll 2015-06-01 14:22:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll 2015-06-01 14:22:34 ----A---- C:\WINDOWS\system32\drivers\netio.sys 2015-06-01 14:22:33 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\spoolsv.exe 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\SkyDrive.exe 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\mfplat.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\IKEEXT.DLL 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys 2015-06-01 14:22:33 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys 2015-06-01 14:22:32 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\SYSWOW64\untfs.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\SYSWOW64\QSVRMGMT.DLL 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\WSDMon.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\WSDApi.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\WinSCard.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\vpnike.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\untfs.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\drivers\dam.sys 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\dnsrslvr.dll 2015-06-01 14:22:32 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\drivers\pdc.sys 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS 2015-06-01 14:22:31 ----A---- C:\WINDOWS\system32\BFE.DLL 2015-06-01 14:22:30 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll 2015-06-01 14:22:30 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll 2015-06-01 14:22:30 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll 2015-06-01 14:22:30 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll 2015-06-01 14:22:30 ----A---- C:\WINDOWS\system32\rasapi32.dll 2015-06-01 14:22:30 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL 2015-06-01 14:22:30 ----A---- C:\WINDOWS\system32\nshwfp.dll 2015-06-01 14:22:29 ----A---- C:\WINDOWS\SYSWOW64\QSHVHOST.DLL 2015-06-01 14:22:29 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll 2015-06-01 14:22:29 ----A---- C:\WINDOWS\system32\drivers\sermouse.sys 2015-06-01 14:22:29 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys 2015-06-01 14:22:29 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys 2015-06-01 14:22:29 ----A---- C:\WINDOWS\system32\DevicePairing.dll 2015-06-01 14:22:28 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll 2015-06-01 14:22:28 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys 2015-06-01 14:22:28 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys 2015-06-01 14:22:27 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll 2015-06-01 14:22:27 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll 2015-06-01 14:22:27 ----A---- C:\WINDOWS\system32\VSSVC.exe 2015-06-01 14:22:27 ----A---- C:\WINDOWS\system32\vssapi.dll 2015-06-01 14:22:27 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL 2015-06-01 14:22:27 ----A---- C:\WINDOWS\system32\dnsapi.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\vsstrace.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\rasser.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\rasmxs.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\rasdiag.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL 2015-06-01 14:22:26 ----A---- C:\WINDOWS\SYSWOW64\eventcls.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\system32\vsstrace.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\system32\rasser.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\system32\rasmxs.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\system32\rasdiag.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\system32\eventcls.dll 2015-06-01 14:22:26 ----A---- C:\WINDOWS\splwow64.exe 2015-06-01 14:22:11 ----A---- C:\WINDOWS\system32\mssrch.dll 2015-06-01 14:22:10 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll 2015-06-01 14:22:10 ----A---- C:\WINDOWS\system32\tquery.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe 2015-06-01 14:22:09 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe 2015-06-01 14:22:09 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe 2015-06-01 14:22:09 ----A---- C:\WINDOWS\system32\SearchIndexer.exe 2015-06-01 14:22:09 ----A---- C:\WINDOWS\system32\mssvp.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\system32\mssphtb.dll 2015-06-01 14:22:09 ----A---- C:\WINDOWS\system32\mssph.dll 2015-05-31 22:26:16 ----D---- C:\Users\JP\AppData\Roaming\Audacity 2015-05-22 20:09:53 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-22 20:09:53 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-22 20:02:17 ----D---- C:\WINDOWS\Migration 2015-05-19 00:07:31 ----A---- C:\WINDOWS\SYSWOW64\uxtuneup.dll 2015-05-19 00:07:31 ----A---- C:\WINDOWS\system32\uxtuneup.dll 2015-05-19 00:02:54 ----A---- C:\WINDOWS\system32\TURegOpt.exe 2015-05-19 00:02:54 ----A---- C:\WINDOWS\system32\authuitu.dll 2015-05-19 00:02:52 ----A---- C:\WINDOWS\SYSWOW64\authuitu.dll 2015-05-19 00:02:07 ----D---- C:\Program Files (x86)\AVG 2015-05-19 00:00:35 ----D---- C:\Users\JP\AppData\Roaming\How Inc 2015-05-12 22:27:08 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS 2015-05-12 22:26:46 ----A---- C:\WINDOWS\system32\drivers\bthhfenum.sys 2015-05-12 22:24:35 ----A---- C:\WINDOWS\system32\dwmcore.dll 2015-05-12 22:24:15 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll 2015-05-12 22:22:17 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll 2015-05-12 22:22:16 ----A---- C:\WINDOWS\system32\SystemSettingsDatabase.dll 2015-05-12 22:22:15 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll 2015-05-12 22:22:15 ----A---- C:\WINDOWS\system32\lsasrv.dll 2015-05-12 22:22:15 ----A---- C:\WINDOWS\system32\drivers\cng.sys 2015-05-12 22:22:15 ----A---- C:\WINDOWS\system32\certcli.dll 2015-05-12 22:22:09 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe 2015-05-12 22:22:09 ----A---- C:\WINDOWS\system32\sdbinst.exe 2015-05-12 22:22:09 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys 2015-05-12 22:22:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll 2015-05-12 22:22:08 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2015-05-12 22:22:07 ----A---- C:\WINDOWS\system32\wevtsvc.dll 2015-05-12 22:22:06 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll 2015-05-12 22:22:06 ----A---- C:\WINDOWS\system32\SRH.dll 2015-05-12 22:22:06 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys 2015-05-12 22:22:06 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys 2015-05-12 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\dbghelp.dll 2015-05-12 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll 2015-05-12 22:22:05 ----A---- C:\WINDOWS\system32\services.exe 2015-05-12 22:22:05 ----A---- C:\WINDOWS\system32\dbghelp.dll 2015-05-12 22:22:05 ----A---- C:\WINDOWS\system32\dbgeng.dll 2015-05-12 22:22:04 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll 2015-05-12 22:22:04 ----A---- C:\WINDOWS\system32\wpdshext.dll 2015-05-12 22:22:03 ----A---- C:\WINDOWS\system32\dpapisrv.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\win32k.sys 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\schannel.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\FntCache.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\DWrite.dll 2015-05-12 22:22:02 ----A---- C:\WINDOWS\system32\drivers\udfs.sys 2015-05-12 22:21:57 ----A---- C:\WINDOWS\system32\mshtml.dll 2015-05-12 22:21:56 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll 2015-05-12 22:21:54 ----A---- C:\WINDOWS\system32\jscript9.dll 2015-05-12 22:21:53 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll 2015-05-12 22:21:53 ----A---- C:\WINDOWS\system32\ieframe.dll 2015-05-12 22:21:52 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll 2015-05-12 22:21:52 ----A---- C:\WINDOWS\system32\wininet.dll 2015-05-12 22:21:51 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll 2015-05-12 22:21:51 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll 2015-05-12 22:21:51 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll 2015-05-12 22:21:51 ----A---- C:\WINDOWS\system32\urlmon.dll 2015-05-12 22:21:51 ----A---- C:\WINDOWS\system32\iertutil.dll 2015-05-12 22:21:50 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll 2015-05-12 22:21:50 ----A---- C:\WINDOWS\system32\vbscript.dll 2015-05-12 22:21:50 ----A---- C:\WINDOWS\system32\jscript.dll 2015-05-12 22:21:50 ----A---- C:\WINDOWS\system32\ie4uinit.exe 2015-05-12 22:21:49 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll 2015-05-12 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll 2015-05-12 22:21:47 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll 2015-05-12 22:21:47 ----A---- C:\WINDOWS\system32\mshtmled.dll 2015-05-12 22:21:47 ----A---- C:\WINDOWS\system32\msfeeds.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\webcheck.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\inseng.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\ieui.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\iepeers.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\iedkcs32.dll 2015-05-12 22:21:46 ----A---- C:\WINDOWS\system32\dxtrans.dll 2015-05-12 22:21:45 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll 2015-05-12 22:21:45 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll 2015-05-12 22:21:45 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll 2015-05-12 22:21:45 ----A---- C:\WINDOWS\system32\inetcomm.dll 2015-05-12 22:21:45 ----A---- C:\WINDOWS\system32\ieapfltr.dll 2015-05-12 22:10:21 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 2015-05-12 22:10:11 ----A---- C:\WINDOWS\system32\drivers\mwac.sys 2015-05-12 22:10:11 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys 2015-05-12 22:10:11 ----A---- C:\WINDOWS\system32\drivers\mbam.sys ======List of files/folders modified in the last 1 month====== 2015-06-06 14:24:38 ----D---- C:\WINDOWS\system32\drivers 2015-06-06 14:18:14 ----D---- C:\Users\JP\AppData\Roaming\Skype 2015-06-06 14:06:16 ----RD---- C:\Program Files 2015-06-06 14:05:10 ----D---- C:\WINDOWS\Temp 2015-06-06 14:00:00 ----D---- C:\WINDOWS\system32\sru 2015-06-06 13:51:52 ----D---- C:\WINDOWS\AppReadiness 2015-06-06 13:48:36 ----HD---- C:\Program Files\WindowsApps 2015-06-06 13:43:51 ----D---- C:\WINDOWS\system32\Tasks 2015-06-05 23:08:25 ----SHD---- C:\WINDOWS\Installer 2015-06-05 23:08:20 ----D---- C:\WINDOWS\Microsoft.NET 2015-06-05 23:08:14 ----RD---- C:\Program Files (x86) 2015-06-05 23:06:39 ----D---- C:\Users\JP\AppData\Roaming\eM Client 2015-06-05 23:00:10 ----D---- C:\ProgramData\panda_url_filtering 2015-06-05 22:36:40 ----D---- C:\WINDOWS\system32\LogFiles 2015-06-05 22:23:47 ----D---- C:\Users\JP\AppData\Roaming\Dropbox 2015-06-05 22:22:47 ----RD---- C:\WINDOWS\System32 2015-06-05 22:16:10 ----SHD---- C:\System Volume Information 2015-06-05 22:05:11 ----D---- C:\WINDOWS\system32\config 2015-06-05 21:15:53 ----D---- C:\WINDOWS\SoftwareDistribution 2015-06-05 21:15:47 ----HD---- C:\ProgramData 2015-06-05 21:15:46 ----D---- C:\Windows 2015-06-05 21:15:40 ----D---- C:\WINDOWS\SysWOW64 2015-06-05 21:15:33 ----D---- C:\WINDOWS\Inf 2015-06-05 20:43:22 ----SD---- C:\WINDOWS\Downloaded Program Files 2015-06-05 20:42:51 ----D---- C:\WINDOWS\Tasks 2015-06-05 18:09:47 ----D---- C:\found.004 2015-06-05 18:09:47 ----D---- C:\found.003 2015-06-05 16:43:09 ----D---- C:\Program Files (x86)\MyPC Backup 2015-06-05 16:31:36 ----D---- C:\WINDOWS\system32\NDF 2015-06-05 14:24:53 ----RHD---- C:\MSOCache 2015-06-05 02:01:16 ----D---- C:\WINDOWS\system32\wbem 2015-06-05 01:54:16 ----D---- C:\Program Files (x86)\Free YouTube Downloader 2015-06-05 01:54:16 ----D---- C:\Program Files (x86)\Common Files 2015-06-05 01:54:15 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-06-05 01:54:15 ----D---- C:\Program Files (x86)\Internet Explorer 2015-06-05 01:54:11 ----D---- C:\Program Files (x86)\Microsoft Silverlight 2015-06-05 01:54:09 ----RD---- C:\Program Files (x86)\Skype 2015-06-05 01:54:09 ----D---- C:\Program Files\Internet Explorer 2015-06-05 01:54:09 ----D---- C:\Program Files\Common Files\microsoft shared 2015-06-05 01:54:09 ----D---- C:\Program Files (x86)\Windows Media Player 2015-06-05 01:54:04 ----D---- C:\Program Files\Windows Journal 2015-06-05 01:54:04 ----D---- C:\Program Files\Microsoft Silverlight 2015-06-05 01:54:03 ----D---- C:\ProgramData\iSkysoft Video Converter Ultimate 2015-06-05 01:54:03 ----D---- C:\ProgramData\Hewlett-Packard 2015-06-05 01:53:14 ----D---- C:\Users\JP\AppData\Roaming\IrfanView 2015-06-05 01:53:11 ----D---- C:\WINDOWS\apppatch 2015-06-05 01:53:09 ----RSD---- C:\WINDOWS\Fonts 2015-06-05 01:53:09 ----RD---- C:\WINDOWS\ImmersiveControlPanel 2015-06-05 01:53:07 ----RSD---- C:\WINDOWS\Media 2015-06-05 01:53:07 ----D---- C:\WINDOWS\PolicyDefinitions 2015-06-05 01:53:04 ----D---- C:\WINDOWS\system32\drivers\UMDF 2015-06-05 01:53:04 ----D---- C:\WINDOWS\system32\CodeIntegrity 2015-06-05 01:53:04 ----D---- C:\WINDOWS\system32\catroot2 2015-06-05 01:53:04 ----D---- C:\WINDOWS\system32\AdvancedInstallers 2015-06-05 01:53:04 ----D---- C:\WINDOWS\ShellNew 2015-06-05 01:53:03 ----SD---- C:\WINDOWS\SYSWOW64\GWX 2015-06-05 01:53:03 ----SD---- C:\WINDOWS\system32\GWX 2015-06-05 01:53:03 ----D---- C:\WINDOWS\SYSWOW64\setup 2015-06-05 01:53:03 ----D---- C:\WINDOWS\SYSWOW64\ras 2015-06-05 01:53:03 ----D---- C:\WINDOWS\SYSWOW64\nl-NL 2015-06-05 01:53:03 ----D---- C:\WINDOWS\SYSWOW64\migration 2015-06-05 01:53:03 ----D---- C:\WINDOWS\SYSWOW64\inetsrv 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\Sysprep 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\setup 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\ras 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\nl-NL 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\migration 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\inetsrv 2015-06-05 01:53:03 ----D---- C:\WINDOWS\system32\en-US 2015-06-05 01:53:02 ----RD---- C:\WINDOWS\ToastData 2015-06-05 01:53:02 ----D---- C:\WINDOWS\WinSxS 2015-06-05 01:53:02 ----D---- C:\WINDOWS\SYSWOW64\wbem 2015-06-05 01:48:25 ----D---- C:\WINDOWS\registration 2015-06-04 22:26:53 ----D---- C:\ProgramData\Skype 2015-06-04 21:21:36 ----A---- C:\Recovery.txt 2015-06-04 20:48:16 ----D---- C:\Program Files (x86)\Panda Security 2015-06-04 19:49:26 ----D---- C:\ProgramData\APN 2015-06-03 17:55:19 ----RASHD---- C:\SYSTEM.SAV 2015-06-03 17:55:18 ----AD---- C:\SWSETUP 2015-06-03 17:50:34 ----D---- C:\ProgramData\3063715800003a73 2015-06-02 22:30:08 ----D---- C:\ProgramData\NCH Software 2015-06-02 22:30:08 ----D---- C:\Program Files (x86)\NCH Software 2015-06-02 22:30:06 ----D---- C:\Users\JP\AppData\Roaming\NCH Software 2015-06-01 18:03:18 ----D---- C:\WINDOWS\system32\DriverStore 2015-06-01 14:26:23 ----D---- C:\WINDOWS\CbsTemp 2015-05-25 15:44:36 ----D---- C:\WINDOWS\debug 2015-05-22 20:11:55 ----D---- C:\ProgramData\Microsoft Help 2015-05-22 20:09:16 ----D---- C:\WINDOWS\system32\MRT 2015-05-22 20:04:02 ----A---- C:\WINDOWS\system32\MRT.exe 2015-05-21 17:19:02 ----D---- C:\ProgramData\CyberLink 2015-05-19 23:52:55 ----D---- C:\WINDOWS\Minidump 2015-05-19 23:52:55 ----AD---- C:\ProgramData\Temp 2015-05-19 00:12:09 ----D---- C:\ProgramData\AVG 2015-05-19 00:02:32 ----D---- C:\Users\JP\AppData\Roaming\AVG 2015-05-14 15:43:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2015-05-08 20:00:47 ----D---- C:\Program Files\WinZip 2015-05-08 19:57:25 ----D---- C:\Users\JP\AppData\Roaming\Adobe 2015-05-08 19:52:14 ----D---- C:\ProgramData\Recovery ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 gfibto;gfibto; C:\WINDOWS\system32\drivers\gfibto.sys [2015-03-25 14456] R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-11-12 644968] R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2012-06-25 92536] R1 kmodurl;kmodurl; \??\C:\Program files (x86)\Kingsoft\PCDoctor\kmodurl64.sys [2011-12-20 133096] R1 NNSALPC;NNSAlpc; C:\WINDOWS\system32\DRIVERS\NNSAlpc.sys [2015-02-09 93968] R1 NNSHTTP;NNSHttp; C:\WINDOWS\system32\DRIVERS\NNSHttp.sys [2015-02-09 202000] R1 NNSHTTPS;NNSHttps; C:\WINDOWS\system32\DRIVERS\NNSHttps.sys [2015-02-09 110864] R1 NNSIDS;NNSids; C:\WINDOWS\system32\DRIVERS\NNSIds.sys [2015-02-09 116496] R1 NNSNAHSL;@oem30.inf,%NNSNAHSL_Desc%;Network Activity Hook Server LightWeight Filter Driver; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [2014-12-31 49936] R1 NNSPICC;NNSPicc; C:\WINDOWS\system32\DRIVERS\NNSPicc.sys [2015-02-09 99600] R1 NNSPIHSW;NNSPihsw; C:\WINDOWS\system32\DRIVERS\NNSPihsw.sys [2015-02-09 69904] R1 NNSPOP3;NNSPop3; C:\WINDOWS\system32\DRIVERS\NNSPop3.sys [2015-02-09 124176] R1 NNSPROT;NNSProt; C:\WINDOWS\system32\DRIVERS\NNSProt.sys [2015-02-09 299792] R1 NNSPRV;NNSPrv; C:\WINDOWS\system32\DRIVERS\NNSPrv.sys [2015-02-09 166160] R1 NNSSMTP;NNSSmtp; C:\WINDOWS\system32\DRIVERS\NNSSmtp.sys [2015-02-09 113424] R1 NNSSTRM;NNSStrm; C:\WINDOWS\system32\DRIVERS\NNSStrm.sys [2015-02-09 257296] R1 NNSTLSC;NNSTlsc; C:\WINDOWS\system32\DRIVERS\NNSTlsc.sys [2015-02-09 106256] R1 PSINKNC;PSINKnc; C:\WINDOWS\system32\DRIVERS\psinknc.sys [2015-02-25 197392] R2 PSINAflt;PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [2015-02-25 163088] R2 PSINFile;PSINFile; C:\WINDOWS\system32\DRIVERS\PSINFile.sys [2015-02-25 121616] R2 PSINProc;PSINProc; C:\WINDOWS\system32\DRIVERS\PSINProc.sys [2015-02-25 124176] R2 PSINProt;PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [2015-02-25 133904] R2 PSINReg;PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [2015-02-25 107792] R2 sbapifs;sbapifs; C:\WINDOWS\system32\DRIVERS\sbapifs.sys [2013-05-07 86968] R3 bcbtums;@oem32.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-09-04 170712] R3 BCM43XX;@oem40.inf,%BCM43XX_Service_DispName%;Stuurprogramma voor de Broadcom 802.11-netwerkadapter; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-09-13 7480496] R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator-service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248] R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304] R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272] R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;USB-stuurprogramma voor Bluetooth-radio; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920] R3 btwampfl;@oem32.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-04 166104] R3 btwaudio;@oem26.inf,%btaudio.SvcDesc%;Bluetooth-audioapparaat; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-10-04 186584] R3 btwavdt;@oem26.inf,%btwavdt.SvcDesc%;Bluetooth AVDT; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-10-04 227032] R3 btwl2cap;@oem3.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2013-10-04 40248] R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-10-04 22744] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240] R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-15 4187648] R3 iwdbus;@oem38.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-10-03 27032] R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-04-14 25816] R3 MEIx64;@oem4.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2013-10-04 64624] R3 panda_url_filteringd;panda_url_filteringd driver; \??\C:\ProgramData\Panda Security URL Filtering\panda_url_filteringd.sys [2014-03-19 51288] R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424] R3 RSPCIESTOR;@oem10.inf,%Rts5208%;Realtek PCIE CardReader Driver; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys [2013-10-04 353864] R3 RTL8168;@oem24.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2014-06-23 870104] R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10305; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [2013-10-04 543744] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-09-09 14112] S0 sbevkp;sbevkp; C:\WINDOWS\System32\drivers\oqpcs.sys [] S3 bbwfp;bbwfp; \??\C:\Program Files (x86)\Anvisoft\Cloud System Booster\wfp\x64\BBWFP.sys [2015-03-24 40720] S3 BCM42RLY;BCM42RLY; C:\WINDOWS\system32\drivers\BCM42RLY.sys [2013-10-04 22632] S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Stuurprogramma voor Bluetooth-poort; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080] S3 btwpanfl;BTW PAN filter driver; \??\C:\WINDOWS\system32\drivers\btwpanfl.sys [2013-10-04 44912] S3 dg_ssudbus;@oem17.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800] S3 dot4;@oem11.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968] S3 Dot4Print;@oem12.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040] S3 dot4usb;@oem11.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056] S3 gfiark;gfiark; C:\WINDOWS\system32\drivers\gfiark.sys [2013-05-23 41032] S3 gfiutil;gfiutil; C:\WINDOWS\system32\drivers\gfiutil.sys [2013-09-04 31264] S3 intaud_WaveExtensible;@oem37.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-10-03 39320] S3 KMWDFILTER;HIDServiceDesc; C:\WINDOWS\System32\drivers\KMWDFILTER.sys [2009-04-29 30208] S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-04-14 64216] S3 PSKMAD;PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [2015-01-29 61712] S3 ssudmdm;@oem1.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744] R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816] R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672] R2 ControlNow Agent;ControlNow Agent; C:\Program Files (x86)\LogicNow\ControlNow Agent\cloudagent.exe [2015-03-20 8994296] R2 HPConnectedRemote;HP Connected Remote Service; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [2012-08-29 35232] R2 KSafeSvc;KSafe service; C:\Program files (x86)\Kingsoft\PCDoctor\KSafeSvc.exe [2012-04-10 290720] R2 NanoServiceMain;Panda Protection Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [2015-02-27 142584] R2 SBAMSvc;GFI Cloud - Antivirus; C:\PROGRA~2\LogicNow\CONTRO~1\viprebusiness\SBAMSvc.exe [2013-05-28 3681016] R3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088] R3 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2013-10-04 89600] R3 AnviCsbSvc;Anvi Cloud System Booster Speed Service; C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe [2015-04-01 42768] R3 BackupStack;Computer Backup (MyPC Backup); C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2015-06-05 57768] R3 btwdins;Bluetooth Service; c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-03-22 959192] R3 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792] R3 DTSRVC;Portrait Displays Display Tune Service; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [2012-08-16 136784] R3 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160] R3 hpqcxs08;hpqcxs08; C:\WINDOWS\syswow64\svchost.exe [2014-10-29 33088] R3 hpqddsvc;HP CUE DeviceDiscovery-service; C:\WINDOWS\syswow64\svchost.exe [2014-10-29 33088] R3 HPSLPSVC;HP Network Devices Support; C:\windows\system32\svchost.exe [2014-10-29 38792] R3 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [2015-03-28 89840] R3 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2013-10-04 2468496] R3 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160] R3 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-10-04 129336] R3 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-10-04 167736] R3 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2013-01-16 73728] R3 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-10-04 364856] R3 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2014-10-29 38792] R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 panda_url_filtering;panda_url_filtering Service; C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filteringb.exe [2014-09-19 296760] R3 PandaAgent;Panda Devices Agent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [2014-10-09 66808] R3 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [2013-07-08 1922600] R3 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-09-06 109360] R3 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2014-10-29 38792] R3 PSUAService;Panda Product Service; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [2015-02-27 38136] R3 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2013-10-04 327680] R3 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2015-02-25 2604856] S2 KMService;KMService; C:\WINDOWS\syswow64\srvany.exe [2014-12-02 8192] S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-04-14 1080120] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440] S3 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2014-10-29 38792] S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-10 50784] S3 BcmBtRSupport;@oem32.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-09-04 2252504] S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792] S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-15 279000] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696] S3 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-28 116648] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-28 116648] S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-09-28 194032] S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760] S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872] S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880] S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [2014-01-16 289256] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488] -----------------EOF-----------------