Logfile of random's system information tool 1.10 (written by random/random) Run by Pangea at 2015-08-26 20:40:18 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 230 GB (79%) free of 292 GB Total RAM: 3948 MB (30% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:40:28, on 26-8-2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\Program Files (x86)\Polar\Polar FlowSync\flowsync.exe C:\Program Files (x86)\Launch Manager\LMworker.exe C:\Program Files (x86)\Launch Manager\LManager.exe C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\NAV.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Program Files\trend micro\Pangea.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\coIEPlg.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\coIEPlg.dll O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k O4 - HKCU\..\Run: [Polar FlowSync] C:\Program Files (x86)\Polar\Polar FlowSync\FlowSync.exe O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing) O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\NAV.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) -- End of file - 9194 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe winlogon.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup "C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe" C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Windows\system32\Dwm.exe" C:\Windows\Explorer.EXE "taskhost.exe" "C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe" "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" "C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files\Bonjour\mDNSResponder.exe" C:\Windows\system32\CxAudMsg64.exe C:\Windows\System32\svchost.exe -k utcsvc "C:\Program Files (x86)\Launch Manager\dsiwmis.exe" "C:\Windows\System32\hkcmd.exe" "C:\Windows\System32\igfxpers.exe" "C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe" "C:\Program Files (x86)\Polar\Polar FlowSync\flowsync.exe" "C:\Program Files (x86)\Launch Manager\LMworker.exe" "C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe" "C:\Program Files\Acer ProShield\EgisTSR.exe" "C:\Program Files (x86)\Launch Manager\LManager.exe" "C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}" --enable-wmi-window "C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k "C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe" "C:\Program Files\Acer\Acer Updater\UpdaterService.exe" "C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\NAV.exe" /s "NAV" /m "C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe" "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" "C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe" "C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe" "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\EscSvc64.exe "C:\Program Files (x86)\Launch Manager\LMutilps.exe" --dont-call-wmi-control-method C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Windows\system32\GWX\GWX.exe" C:\Windows\system32\igfxext.exe -Embedding C:\Windows\system32\igfxsrvc.exe -Embedding C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe -Embedding "C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe" "C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\NAV.exe" /c /a /s UserSession C:\Windows\System32\svchost.exe -k LocalServicePeerNet "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe" "C:\Program Files\iPod\bin\iPodService.exe" "C:\Program Files\iTunes\iTunesHelper.exe" "C:\Program Files\iTunes\iTunes.exe" "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe" --pipe \\.\pipe\30466079170836309722073272 --parentPipe \??\C:\Windows\system32\conhost.exe "-6887928441781442254-90668143620549030341559691403-1255031922-996048946699822388 "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe" \??\C:\Windows\system32\conhost.exe "1603764478-776427532-7036302021102892548200410348-867077662-7916426031129741307 "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe" --pipe \\.\pipe\30466079-1390282400413272R \\.\pipe\30466079-1390282400413272W --target 1191cfc1068a257a0ef0e3f2b575007ec9944140 --library FFE8C515E5635764 \??\C:\Windows\system32\conhost.exe "-76702058447435659890610412-13543783178940380321028269982101232302-478283984 "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe" \??\C:\Windows\system32\conhost.exe "1794623335850606422734674876-467875012458972695-5494056381584564621828457618 C:\Windows\system32\sppsvc.exe "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Users\Pangea\Desktop\RSITx64.exe" C:\Windows\system32\wbem\wmiprvse.exe "C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520 ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe# /c# C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe# /ua /installsource scheduler# =========Mozilla firefox========= ProfilePath - C:\Users\Pangea\AppData\Roaming\Mozilla\Firefox\Profiles\ysbs19d7.default prefs.js - "browser.search.useDBForOrder" - "false" prefs.js - "browser.startup.homepage" - "http://www.ekudos.nl/home" prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10, {20a82645-c095-46ed-80e3-08825760534b}:0.0.0, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.2" prefs.js - "keyword.URL" - "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@ABNAMRO/BECON,version=1.00] "Description"=ABN AMRO e.dentifier2 Plug-in 1.0 for Mozilla "Path"=C:\Program Files (x86)\ABN AMRO e.dentifier2\Mozilla\npBECON.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=] "Description"=iTunes Detector Plug-in "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0] "Description"= "Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.25.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\SysWOW64\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll C:\Program Files (x86)\Mozilla Firefox\plugins\ np-mswmp.dll nppdf32.dll npwachk.dll WMP Firefox Plugin License.rtf WMP Firefox Plugin RelNotes.txt C:\Users\Pangea\AppData\Roaming\Mozilla\Firefox\Profiles\ysbs19d7.default\searchplugins\ duckduckgo.xml safesearch.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton AntiVirus\Engine64\22.5.2.15\coIEPlg.dll [2015-07-10 1042744] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\coIEPlg.dll [2015-07-10 798008] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton AntiVirus\Engine64\22.5.2.15\coIEPlg.dll [2015-07-10 1042744] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\coIEPlg.dll [2015-07-10 798008] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-31 167960] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-31 392216] "Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-31 415768] "ProShieldTSR"=C:\Program Files\Acer ProShield\EgisTSR.exe [2011-06-04 165936] "Power Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2011-05-10 1831528] "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-08-13 170256] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Polar FlowSync"=C:\Program Files (x86)\Polar\Polar FlowSync\FlowSync.exe [2014-11-11 1125376] "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-08-20 8455960] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07 1018056] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [2015-04-26 43816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [2008-12-24 114688] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2012-04-02 1058912] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPLTarget] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXRCV] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2015-04-26 43816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe [2012-06-28 74752] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk] C:\PROGRA~2\Acer\ACERVC~1\AcerVCM.exe [2011-05-12 723560] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Timex Trainer Launcher.lnk] C:\PROGRA~2\Timex\TIMEXT~1\TBEGGL~1.EXE [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Pangea^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk] C:\PROGRA~2\Evernote\Evernote\EVERNO~2.EXE [] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2011-07-01 1110096] "BackupManagerTray"=C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [2011-04-24 297280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2011-03-26 385024] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "notification packages"=scecli EgisPwdFilter EgisDSPwdFilter [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2015-08-26 20:40:18 ----D---- C:\rsit 2015-08-26 20:40:18 ----D---- C:\Program Files\trend micro 2015-08-26 18:51:41 ----D---- C:\Windows\LastGood 2015-08-26 18:48:15 ----D---- C:\Program Files\iTunes 2015-08-26 18:48:15 ----D---- C:\Program Files\iPod 2015-08-26 18:48:15 ----D---- C:\Program Files (x86)\iTunes 2015-08-25 18:42:15 ----D---- C:\Program Files (x86)\Adobe 2015-08-20 11:19:57 ----D---- C:\Program Files (x86)\Mozilla Firefox 2015-08-19 13:10:14 ----A---- C:\Windows\system32\mshtml.dll 2015-08-19 13:10:13 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2015-08-13 19:00:41 ----A---- C:\Windows\system32\basesrv.dll 2015-08-13 02:56:30 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 02:56:30 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-13 00:10:08 ----A---- C:\Windows\system32\mstscax.dll 2015-08-13 00:10:07 ----A---- C:\Windows\SYSWOW64\mstscax.dll 2015-08-13 00:10:06 ----A---- C:\Windows\SYSWOW64\tsgqec.dll 2015-08-13 00:10:06 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll 2015-08-13 00:10:06 ----A---- C:\Windows\system32\wksprt.exe 2015-08-13 00:10:06 ----A---- C:\Windows\system32\tsgqec.dll 2015-08-13 00:10:06 ----A---- C:\Windows\system32\rdvidcrl.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\invagent.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\generaltel.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\devinv.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\appraiser.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\aeinv.dll 2015-08-13 00:10:05 ----A---- C:\Windows\system32\acmigration.dll 2015-08-13 00:10:02 ----A---- C:\Windows\system32\CompatTelRunner.exe 2015-08-13 00:10:02 ----A---- C:\Windows\system32\aepdu.dll 2015-08-13 00:09:54 ----A---- C:\Windows\system32\ntoskrnl.exe 2015-08-13 00:09:53 ----A---- C:\Windows\system32\ntdll.dll 2015-08-13 00:09:53 ----A---- C:\Windows\system32\kernel32.dll 2015-08-13 00:09:52 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe 2015-08-13 00:09:51 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2015-08-13 00:09:51 ----A---- C:\Windows\system32\sysmain.dll 2015-08-13 00:09:46 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe 2015-08-13 00:09:45 ----A---- C:\Windows\SYSWOW64\kernel32.dll 2015-08-13 00:09:45 ----A---- C:\Windows\system32\wow64.dll 2015-08-13 00:09:45 ----A---- C:\Windows\system32\rstrui.exe 2015-08-13 00:09:45 ----A---- C:\Windows\system32\lsasrv.dll 2015-08-13 00:09:45 ----A---- C:\Windows\system32\KernelBase.dll 2015-08-13 00:09:45 ----A---- C:\Windows\system32\drivers\mountmgr.sys 2015-08-13 00:09:44 ----A---- C:\Windows\SYSWOW64\kerberos.dll 2015-08-13 00:09:44 ----A---- C:\Windows\system32\srcore.dll 2015-08-13 00:09:44 ----A---- C:\Windows\system32\rpcrt4.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\wdigest.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\TSpkg.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\srclient.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\setup16.exe 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\secur32.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\schannel.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\ncrypt.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\msv1_0.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\KernelBase.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\cryptbase.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\credssp.dll 2015-08-13 00:09:43 ----A---- C:\Windows\SYSWOW64\auditpol.exe 2015-08-13 00:09:43 ----A---- C:\Windows\system32\wow64win.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\wow64cpu.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\winsrv.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\wdigest.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\TSpkg.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\sspisrv.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\sspicli.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\srclient.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\smss.exe 2015-08-13 00:09:43 ----A---- C:\Windows\system32\secur32.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\schannel.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\ntvdm64.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\ncrypt.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\msv1_0.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\msmmsp.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\lsass.exe 2015-08-13 00:09:43 ----A---- C:\Windows\system32\kerberos.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\drivers\mrxsmb.sys 2015-08-13 00:09:43 ----A---- C:\Windows\system32\drivers\ksecpkg.sys 2015-08-13 00:09:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2015-08-13 00:09:43 ----A---- C:\Windows\system32\csrsrv.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\cryptbase.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\credssp.dll 2015-08-13 00:09:43 ----A---- C:\Windows\system32\conhost.exe 2015-08-13 00:09:43 ----A---- C:\Windows\system32\auditpol.exe 2015-08-13 00:09:42 ----A---- C:\Windows\SYSWOW64\sspicli.dll 2015-08-13 00:09:42 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2015-08-13 00:09:42 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-08-13 00:09:41 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-08-13 00:09:41 ----A---- C:\Windows\SYSWOW64\wow32.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-08-13 00:09:40 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-08-13 00:09:39 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-08-13 00:09:39 ----A---- C:\Windows\SYSWOW64\instnm.exe 2015-08-13 00:09:39 ----A---- C:\Windows\SYSWOW64\apisetschema.dll 2015-08-13 00:09:39 ----A---- C:\Windows\system32\apisetschema.dll 2015-08-13 00:09:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-08-13 00:09:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll 2015-08-13 00:09:38 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-08-13 00:09:38 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-08-13 00:09:38 ----A---- C:\Windows\SYSWOW64\user.exe 2015-08-13 00:09:38 ----A---- C:\Windows\SYSWOW64\msobjs.dll 2015-08-13 00:09:38 ----A---- C:\Windows\SYSWOW64\msaudite.dll 2015-08-13 00:09:38 ----A---- C:\Windows\SYSWOW64\adtschema.dll 2015-08-13 00:09:38 ----A---- C:\Windows\system32\msobjs.dll 2015-08-13 00:09:38 ----A---- C:\Windows\system32\msaudite.dll 2015-08-13 00:09:38 ----A---- C:\Windows\system32\adtschema.dll 2015-08-13 00:09:18 ----A---- C:\Windows\SYSWOW64\DWrite.dll 2015-08-13 00:09:18 ----A---- C:\Windows\system32\win32k.sys 2015-08-13 00:09:18 ----A---- C:\Windows\system32\FntCache.dll 2015-08-13 00:09:18 ----A---- C:\Windows\system32\DWrite.dll 2015-08-13 00:09:18 ----A---- C:\Windows\system32\atmfd.dll 2015-08-13 00:09:17 ----A---- C:\Windows\SYSWOW64\atmfd.dll 2015-08-13 00:09:16 ----A---- C:\Windows\SYSWOW64\fontsub.dll 2015-08-13 00:09:16 ----A---- C:\Windows\SYSWOW64\dciman32.dll 2015-08-13 00:09:16 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll 2015-08-13 00:09:16 ----A---- C:\Windows\SYSWOW64\atmlib.dll 2015-08-13 00:09:16 ----A---- C:\Windows\system32\lpk.dll 2015-08-13 00:09:16 ----A---- C:\Windows\system32\fontsub.dll 2015-08-13 00:09:16 ----A---- C:\Windows\system32\dciman32.dll 2015-08-13 00:09:16 ----A---- C:\Windows\system32\d3d10warp.dll 2015-08-13 00:09:16 ----A---- C:\Windows\system32\atmlib.dll 2015-08-13 00:09:15 ----A---- C:\Windows\SYSWOW64\lpk.dll 2015-08-13 00:09:13 ----A---- C:\Windows\SYSWOW64\notepad.exe 2015-08-13 00:09:13 ----A---- C:\Windows\system32\notepad.exe 2015-08-13 00:09:13 ----A---- C:\Windows\notepad.exe 2015-08-13 00:09:12 ----A---- C:\Windows\system32\shell32.dll 2015-08-13 00:09:11 ----A---- C:\Windows\SYSWOW64\shell32.dll 2015-08-13 00:08:58 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll 2015-08-13 00:08:58 ----A---- C:\Windows\system32\iertutil.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\vbscript.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2015-08-13 00:08:57 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll 2015-08-13 00:08:57 ----A---- C:\Windows\system32\iernonce.dll 2015-08-13 00:08:57 ----A---- C:\Windows\system32\ieetwproxystub.dll 2015-08-13 00:08:57 ----A---- C:\Windows\system32\ieetwcollector.exe 2015-08-13 00:08:57 ----A---- C:\Windows\system32\ie4uinit.exe 2015-08-13 00:08:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2015-08-13 00:08:56 ----A---- C:\Windows\SYSWOW64\dxtrans.dll 2015-08-13 00:08:56 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-08-13 00:08:55 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2015-08-13 00:08:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2015-08-13 00:08:55 ----A---- C:\Windows\system32\urlmon.dll 2015-08-13 00:08:55 ----A---- C:\Windows\system32\iedkcs32.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\jscript.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\ieui.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2015-08-13 00:08:54 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll 2015-08-13 00:08:54 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe 2015-08-13 00:08:54 ----A---- C:\Windows\system32\msfeeds.dll 2015-08-13 00:08:54 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2015-08-13 00:08:54 ----A---- C:\Windows\system32\dxtrans.dll 2015-08-13 00:08:53 ----A---- C:\Windows\system32\iesetup.dll 2015-08-13 00:08:53 ----A---- C:\Windows\system32\ieapfltr.dll 2015-08-13 00:08:52 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll 2015-08-13 00:08:52 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2015-08-13 00:08:52 ----A---- C:\Windows\system32\vbscript.dll 2015-08-13 00:08:51 ----A---- C:\Windows\SYSWOW64\wininet.dll 2015-08-13 00:08:51 ----A---- C:\Windows\SYSWOW64\msrating.dll 2015-08-13 00:08:51 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll 2015-08-13 00:08:51 ----A---- C:\Windows\system32\jsproxy.dll 2015-08-13 00:08:51 ----A---- C:\Windows\system32\ieUnatt.exe 2015-08-13 00:08:51 ----A---- C:\Windows\system32\ieui.dll 2015-08-13 00:08:51 ----A---- C:\Windows\system32\dxtmsft.dll 2015-08-13 00:08:50 ----A---- C:\Windows\system32\mshtmlmedia.dll 2015-08-13 00:08:50 ----A---- C:\Windows\system32\mshtmled.dll 2015-08-13 00:08:50 ----A---- C:\Windows\system32\ieframe.dll 2015-08-13 00:08:49 ----A---- C:\Windows\system32\wininet.dll 2015-08-13 00:08:49 ----A---- C:\Windows\system32\jscript9diag.dll 2015-08-13 00:08:49 ----A---- C:\Windows\system32\jscript9.dll 2015-08-13 00:08:49 ----A---- C:\Windows\system32\jscript.dll 2015-08-13 00:08:48 ----A---- C:\Windows\system32\msrating.dll 2015-08-13 00:08:48 ----A---- C:\Windows\system32\MshtmlDac.dll 2015-08-13 00:08:41 ----A---- C:\Windows\SYSWOW64\WebClnt.dll 2015-08-13 00:08:41 ----A---- C:\Windows\SYSWOW64\davclnt.dll 2015-08-13 00:08:41 ----A---- C:\Windows\system32\WebClnt.dll 2015-08-13 00:08:41 ----A---- C:\Windows\system32\davclnt.dll 2015-08-13 00:08:38 ----A---- C:\Windows\SYSWOW64\msxml6r.dll 2015-08-13 00:08:38 ----A---- C:\Windows\SYSWOW64\msxml6.dll 2015-08-13 00:08:38 ----A---- C:\Windows\SYSWOW64\msxml3.dll 2015-08-13 00:08:38 ----A---- C:\Windows\system32\msxml6r.dll 2015-08-13 00:08:38 ----A---- C:\Windows\system32\msxml6.dll 2015-08-13 00:08:38 ----A---- C:\Windows\system32\msxml3.dll 2015-08-13 00:08:37 ----A---- C:\Windows\SYSWOW64\msxml3r.dll 2015-08-13 00:08:37 ----A---- C:\Windows\system32\msxml3r.dll 2015-08-13 00:08:34 ----A---- C:\Windows\system32\wucltux.dll 2015-08-13 00:08:34 ----A---- C:\Windows\system32\wuaueng.dll 2015-08-13 00:08:33 ----A---- C:\Windows\SYSWOW64\wuwebv.dll 2015-08-13 00:08:33 ----A---- C:\Windows\SYSWOW64\wups.dll 2015-08-13 00:08:33 ----A---- C:\Windows\SYSWOW64\wudriver.dll 2015-08-13 00:08:33 ----A---- C:\Windows\SYSWOW64\wuapp.exe 2015-08-13 00:08:33 ----A---- C:\Windows\SYSWOW64\wuapi.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wuwebv.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wups2.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wups.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wudriver.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wuauclt.exe 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wuapp.exe 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wuapi.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\wu.upgrade.ps.dll 2015-08-13 00:08:33 ----A---- C:\Windows\system32\WinSetupUI.dll 2015-08-13 00:08:03 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-08-08 22:34:52 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak ======List of files/folders modified in the last 1 month====== 2015-08-26 20:40:18 ----RD---- C:\Program Files 2015-08-26 19:01:39 ----D---- C:\Windows\system32\config 2015-08-26 18:51:41 ----D---- C:\Windows\Temp 2015-08-26 18:51:41 ----D---- C:\Windows\system32\drivers 2015-08-26 18:51:41 ----D---- C:\Windows\System32 2015-08-26 18:51:41 ----D---- C:\Windows 2015-08-26 18:49:58 ----D---- C:\Windows\inf 2015-08-26 18:49:11 ----SHD---- C:\Windows\Installer 2015-08-26 18:48:15 ----RD---- C:\Program Files (x86) 2015-08-26 18:48:15 ----D---- C:\Program Files\Common Files\Apple 2015-08-26 18:39:12 ----A---- C:\Windows\SYSWOW64\log.txt 2015-08-26 18:37:25 ----SHD---- C:\System Volume Information 2015-08-26 13:07:51 ----D---- C:\ProgramData\boost_interprocess 2015-08-25 18:44:50 ----D---- C:\Windows\system32\Tasks 2015-08-25 18:41:40 ----D---- C:\Windows\SysWOW64 2015-08-25 18:41:13 ----D---- C:\ProgramData\Adobe 2015-08-25 14:24:45 ----D---- C:\Program Files\CCleaner 2015-08-25 14:13:33 ----D---- C:\Program Files\SUPERAntiSpyware 2015-08-25 13:53:27 ----D---- C:\Windows\Tasks 2015-08-24 09:28:43 ----A---- C:\Windows\system32\PerfStringBackup.INI 2015-08-20 15:10:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2015-08-20 11:20:34 ----A---- C:\Windows\wininit.ini 2015-08-19 13:10:25 ----D---- C:\Windows\winsxs 2015-08-19 13:04:44 ----D---- C:\Users\Pangea\AppData\Roaming\.purple 2015-08-19 12:21:23 ----D---- C:\Windows\debug 2015-08-14 01:43:30 ----D---- C:\Program Files (x86)\Launch Manager 2015-08-13 18:50:22 ----D---- C:\Windows\Microsoft.NET 2015-08-13 18:49:50 ----RSD---- C:\Windows\assembly 2015-08-13 18:39:18 ----SD---- C:\Windows\system32\CompatTel 2015-08-13 18:39:17 ----D---- C:\Windows\system32\appraiser 2015-08-13 18:39:17 ----D---- C:\Windows\AppPatch 2015-08-13 18:39:12 ----D---- C:\Windows\SYSWOW64\nl-NL 2015-08-13 18:39:11 ----D---- C:\Windows\system32\nl-NL 2015-08-13 18:39:11 ----D---- C:\Windows\system32\drivers\nl-NL 2015-08-13 18:39:08 ----D---- C:\Program Files\Internet Explorer 2015-08-13 18:39:07 ----D---- C:\Windows\SYSWOW64\en-US 2015-08-13 18:39:05 ----D---- C:\Windows\system32\en-US 2015-08-13 18:39:02 ----D---- C:\Program Files (x86)\Internet Explorer 2015-08-13 02:57:21 ----D---- C:\Windows\system32\catroot2 2015-08-13 02:53:19 ----D---- C:\Program Files\Microsoft Silverlight 2015-08-13 02:53:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight 2015-08-13 02:42:31 ----D---- C:\Windows\system32\MRT 2015-08-13 02:07:34 ----A---- C:\Windows\system32\MRT.exe 2015-08-09 14:38:35 ----D---- C:\Program Files (x86)\NortonInstaller 2015-07-30 18:16:38 ----D---- C:\ProgramData\Norton 2015-07-30 16:27:07 ----D---- C:\Windows\system32\drivers\NAVx64 2015-07-30 15:50:54 ----D---- C:\Program Files\Common Files\Symantec Shared 2015-07-28 21:55:24 ----D---- C:\Windows\SoftwareDistribution ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 gfibto;gfibto; C:\Windows\system32\drivers\gfibto.sys [2013-05-06 14456] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2011-05-20 557848] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888] R0 SymEFASI;Symantec Extended File Attributes (SI); C:\Windows\system32\drivers\NAVx64\1605020.00F\SYMEFASI64.SYS [2015-07-11 1620720] R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton AntiVirus\NortonData\22.5.2.15\Definitions\BASHDefs\20150821.001\BHDrvx64.sys [2015-07-23 1650936] R1 ccSet_NAV;NAV Settings Manager; C:\Windows\system32\drivers\NAVx64\1605020.00F\ccSetx64.sys [2015-07-11 173808] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2015-07-27 498512] R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton AntiVirus\NortonData\22.5.2.15\Definitions\IPSDefs\20150821.001\IDSvia64.sys [2015-07-30 692984] R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2012-06-21 22648] R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2012-06-21 20520] R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2012-06-21 62776] R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NAVx64\1605020.00F\SRTSPX64.SYS [2015-07-11 50936] R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NAVx64\1605020.00F\Ironx64.SYS [2015-07-11 297720] R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NAVx64\1605020.00F\SYMNETS.SYS [2015-07-11 576248] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-11-09 2377216] R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-01-10 1577600] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2015-07-27 153936] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-03-26 12222080] R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-10-20 76912] R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344] R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton AntiVirus\NortonData\22.5.2.15\Definitions\VirusDefs\20150825.034\ENG64.SYS [2015-05-20 138488] R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton AntiVirus\NortonData\22.5.2.15\Definitions\VirusDefs\20150825.034\EX64.SYS [2015-05-20 2146040] R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2011-03-10 18432] R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-01-12 333928] R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NAVx64\1605020.00F\SRTSP64.SYS [2015-07-11 926448] R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2015-07-30 111344] R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2011-03-10 17408] R3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-10 54784] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2; C:\Windows\system32\DRIVERS\aabed2.sys [2008-03-20 28672] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496] S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2014-11-18 172344] R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-03-07 81088] R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-05-29 77128] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2010-12-17 198784] R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136] R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-07-01 353872] R2 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [2011-06-04 212016] R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-05-10 872552] R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208] R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2011-12-12 135824] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-05-20 13592] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-01-13 1751656] R2 IviRegMgr;IviRegMgr; C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2010-05-21 110736] R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-02-07 255376] R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-20 325656] R2 NAV;Norton AntiVirus; C:\Program Files (x86)\Norton AntiVirus\Engine\22.5.2.15\NAV.exe [2015-07-16 282016] R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-04-24 256832] R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824] R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640] R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2015-08-13 644880] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088] S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-14 116648] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-21 655624] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-14 116648] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-20 149160] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-15 1255736] S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] -----------------EOF-----------------