Logfile of random's system information tool 1.10 (written by random/random) Run by Harrie at 2016-03-21 19:24:30 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 324 GB (71%) free of 456 GB Total RAM: 6042 MB (52% free) HijackThis download failed ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe winlogon.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs "C:\Program Files\IDT\WDM\STacSV64.exe" C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService atieclxx C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files\Bonjour\mDNSResponder.exe" "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service "C:\Program Files (x86)\Google\Cloud Print Service\28.0.1493.2\cloud_print_service.exe" --service C:\Windows\System32\svchost.exe -k utcsvc "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service --user-data-dir="C:\Users\Harrie\AppData\Local\Google\Cloud Print Service" --no-service-autorun --auto-launch-at-startup --disable-background-mode --disable-default-apps --disable-extensions --disable-gpu --disable-software-rasterizer --disable-sync --no-first-run --no-startup-window C:\Windows\SysWOW64\ezSharedSvcHost.exe "C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe" "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe" "C:\Program Files\Intel\iCLS Client\HeciServer.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe" "C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\NST.exe" /s "NCO" /m "C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe" "c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe" "taskhost.exe" "C:\Windows\system32\Dwm.exe" "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" WLIDSvcM.exe 2996 C:\Windows\Explorer.EXE C:\Windows\System32\alg.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\servicing\TrustedInstaller.exe "C:\Windows\system32\GWX\GWX.exe" taskeng.exe {3ACA420D-85ED-4168-AEDD-D9E91FA7349A} "C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" /byrunkey "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe" "C:\Program Files (x86)\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe" /s "NSBU" /m "C:\Program Files (x86)\Norton Security with Backup\Engine\22.6.0.142\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" C:\Windows\system32\wbem\wmiprvse.exe "C:\Program Files (x86)\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe" /c /a /s UserSession "C:\Windows\System32\hkcmd.exe" "C:\Windows\System32\igfxpers.exe" "C:\Program Files\IDT\WDM\sttray64.exe" "C:\Program Files\iTunes\iTunesHelper.exe" "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN51F220JH060F:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1 "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe" "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe" "C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe" "C:\Program Files\iPod\bin\iPodService.exe" "C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding "C:\Users\Harrie\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" "C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe" "C:\Program Files (x86)\1Password 4\Agile1pAgent.exe" C:\Windows\system32\SearchIndexer.exe /Embedding "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0 "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k SDRSVC "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --profile-directory="Default" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Harrie\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.87 --handshake-handle=0xd0 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2676.0.1519939235\1801144329" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,9,11,25,54 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.933.0.0 --ignored=" --type=renderer " /prefetch:2 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding \\.\pipe\chrome.nativeMessaging.out.d6fca17ce11caa7f \??\C:\Windows\system32\conhost.exe "1819891447-158544053517554115059555411954284976761529259074493705806813483419 "C:\Program Files (x86)\Norton Security with Backup\Engine\22.6.0.142\coNatHst.exe" --parent-window=0 chrome-extension://cjabmdjcfcfdmffimndhafhblfmpjdpe/ "C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\nacl64" --type=nacl-broker --channel="2676.11.1959843339\217456237" "C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\nacl64.exe" --type=nacl-loader --channel="2676.10.1896051994\1211327459" --ignored=" --type=renderer " "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding