Logfile of random's system information tool 1.10 (written by random/random) Run by Hilario at 2014-06-05 09:12:22 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 158 GB (65%) free of 245 GB Total RAM: 1982 MB (19% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:12:54, on 5/06/2014 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16545) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Memeo\AutoBackup\InstantBackup.exe C:\Program Files\COMODO\COMODO Internet Security\cis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Hilario\Desktop\RSIT.exe C:\Program Files\trend micro\Hilario.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: PrivDogExtension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-21-2677776618-2184422751-3497854544-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User '?') O4 - Global Startup: SetPoint.lnk = ? O9 - Extra button: PrivDog - {2F5C139F-79BD-4C84-A95A-E7140525BC55} - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{FD5D0F06-3095-4DD1-AF2C-3A9FD4CD3145}: NameServer = 156.154.70.25,156.154.71.25 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) - Nitro PDF Software - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe -- End of file - 5246 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe =========Mozilla firefox========= ProfilePath - C:\Users\Hilario\AppData\Roaming\Mozilla\Firefox\Profiles\soaxj3tv.default prefs.js - "browser.search.useDBForOrder" - true prefs.js - "browser.startup.homepage" - "about:home" prefs.js - "keyword.URL" - "http://us.search.yahoo.com/search?fr=ytff-comodo&p=" "{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ "belgiumeid@eid.belgium.be"=C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 13.0.0.214 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\system32\Adobe\Director\np32dsw_1203133.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5] "Description"=Windows Presentation Foundation plug-in for Mozilla browsers "Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nitropdf.com/NitroPDF] "Description"=NitroPDF Web Browser Plugin "Path"=C:\Program Files\Nitro\Reader 3\npnitromozilla.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0] "Description"=VLC Multimedia Plugin "Path"=I:\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3] "Description"=VLC Multimedia Plugin "Path"=I:\VLC\npvlc.dll C:\Users\Hilario\AppData\Roaming\Mozilla\Firefox\Profiles\soaxj3tv.default\extensions\ PrivDog@AdTrustMedia.com C:\Users\Hilario\AppData\Roaming\Mozilla\Firefox\Profiles\soaxj3tv.default\searchplugins\ avira-safesearch.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC}] PrivDog Extension - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15 744616] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184] "Logitech Hardware Abstraction Layer"=C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE [2007-01-11 101136] "Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-01-11 101136] "COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2014-03-25 1225944] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2013-12-20 12017368] "Memeo Instant Backup"=C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe [2011-05-04 136416] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7] C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe /Auto [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo AutoSync] C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe --silent [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe [2011-05-04 136416] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrivDogService] C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe [2013-11-15 525480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup SetPoint.lnk - C:\Program Files\SetPoint\SetPoint.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=lvcodec2.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "MSVideo8"=VfWWDM32.dll "MSVideo"=vfwwdm32.dll "vidc.ffds"=ff_vfw.dll "vidc.xvid"=xvidvfw.dll "vidc.x264"=x264vfw.dll "vidc.lags"=lagarith.dll "msacm.lameacm"=LameACM.acm "msacm.divxa32"=DivXa32.acm "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux2"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-06-04 16:40:15 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2014-06-04 16:39:46 ----D---- C:\Program Files\Malwarebytes Anti-Malware 2014-06-04 16:39:46 ----A---- C:\Windows\system32\drivers\mwac.sys 2014-06-04 16:39:46 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2014-06-04 16:39:46 ----A---- C:\Windows\system32\drivers\mbam.sys 2014-05-31 20:50:17 ----SHD---- C:\Config.Msi 2014-05-31 20:46:57 ----SD---- C:\ProgramData\Shared Space 2014-05-31 20:45:17 ----D---- C:\Program Files\AdTrustMedia 2014-05-31 18:51:00 ----D---- C:\ProgramData\Licenses 2014-05-31 18:50:55 ----A---- C:\Windows\system32\MSSTDFMT.DLL 2014-05-31 18:23:02 ----D---- C:\Users\Hilario\AppData\Roaming\Firetrust 2014-05-31 18:22:36 ----D---- C:\Program Files\Firetrust 2014-05-31 18:21:33 ----D---- C:\ProgramData\Firetrust 2014-05-30 18:59:29 ----D---- C:\ProgramData\CheckPoint 2014-05-29 19:17:32 ----D---- C:\Users\Hilario\AppData\Roaming\LavasoftStatistics 2014-05-29 18:29:11 ----D---- C:\Users\Hilario\AppData\Roaming\SecureSearch 2014-05-29 18:28:52 ----D---- C:\Program Files\Lavasoft 2014-05-29 18:25:30 ----D---- C:\ProgramData\Lavasoft 2014-05-28 15:00:48 ----HD---- C:\_Memeo 2014-05-27 18:42:06 ----D---- C:\Users\Hilario\AppData\Roaming\Memeo 2014-05-27 18:40:58 ----D---- C:\Program Files\Common Files\Memeo 2014-05-27 18:40:54 ----D---- C:\Program Files\Memeo 2014-05-27 16:30:13 ----D---- C:\Users\Hilario\AppData\Roaming\2BrightSparks 2014-05-27 16:13:15 ----D---- C:\Users\Hilario\AppData\Roaming\Softland 2014-05-27 16:12:56 ----D---- C:\ProgramData\Softland 2014-05-22 17:04:49 ----D---- C:\Program Files\Mozilla Thunderbird 2014-05-18 11:55:11 ----D---- C:\Program Files\Wyzo 2014-05-18 11:52:22 ----D---- C:\Program Files\Mozilla Maintenance Service 2014-05-18 11:52:13 ----D---- C:\Program Files\Mozilla Firefox 2014-05-18 08:28:00 ----D---- C:\ProgramData\AVG Security Toolbar 2014-05-18 08:02:54 ----A---- C:\Windows\nsreg.dat 2014-05-17 19:55:26 ----A---- C:\Windows\system32\mshtmled.dll 2014-05-17 19:55:22 ----A---- C:\Windows\system32\mshtml.dll 2014-05-17 19:44:33 ----A---- C:\Windows\system32\shell32.dll 2014-05-09 19:24:43 ----D---- C:\Program Files\COMODO ======List of files/folders modified in the last 1 month====== 2014-06-05 09:12:39 ----D---- C:\Windows\Prefetch 2014-06-05 09:12:32 ----D---- C:\Program Files\Trend Micro 2014-06-05 09:12:15 ----D---- C:\Windows\Temp 2014-06-04 19:30:56 ----D---- C:\Windows\inf 2014-06-04 19:29:55 ----D---- C:\Windows 2014-06-04 19:19:35 ----RD---- C:\Program Files 2014-06-04 19:19:03 ----SHD---- C:\System Volume Information 2014-06-04 17:00:58 ----D---- C:\Windows\system32\drivers 2014-06-04 17:00:58 ----D---- C:\Windows\PLA 2014-06-04 16:39:46 ----D---- C:\ProgramData\Malwarebytes 2014-06-04 11:31:49 ----D---- C:\Users\Hilario\AppData\Roaming\vlc 2014-06-04 11:30:26 ----D---- C:\Program Files\Recuva 2014-06-03 16:53:43 ----D---- C:\Windows\System32 2014-06-03 16:53:43 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-06-01 17:53:47 ----SHD---- C:\Windows\Installer 2014-06-01 17:53:45 ----D---- C:\Program Files\Common Files 2014-06-01 17:31:35 ----D---- C:\ProgramData\ProductData 2014-05-31 21:08:57 ----D---- C:\Users\Hilario\AppData\Roaming\Rovio Entertainment Ltd 2014-05-31 21:05:07 ----D---- C:\Users\Hilario\AppData\Roaming\GlarySoft 2014-05-31 20:59:30 ----D---- C:\Windows\system32\Tasks 2014-05-31 20:58:57 ----HD---- C:\ProgramData 2014-05-31 20:58:56 ----D---- C:\ProgramData\MFAData 2014-05-31 20:48:56 ----D---- C:\Windows\system32\catroot 2014-05-31 20:46:11 ----D---- C:\ProgramData\COMODO 2014-05-31 20:04:35 ----AD---- C:\ProgramData\Temp 2014-05-31 10:21:12 ----D---- C:\Users\Hilario\AppData\Roaming\Nitro PDF 2014-05-31 09:53:20 ----D---- C:\Windows\system32\catroot2 2014-05-28 19:32:29 ----D---- C:\Users\Hilario\AppData\Roaming\Skype 2014-05-28 15:19:18 ----D---- C:\Windows\Minidump 2014-05-28 15:00:35 ----D---- C:\ProgramData\MemeoCommon 2014-05-27 18:40:36 ----D---- C:\Windows\winsxs 2014-05-27 18:04:13 ----D---- C:\ProgramData\tmp 2014-05-27 16:09:25 ----D---- C:\ProgramData\GlarySoft 2014-05-27 16:09:16 ----D---- C:\Windows\Tasks 2014-05-27 16:07:08 ----D---- C:\Program Files\Paragon Software 2014-05-27 09:00:45 ----D---- C:\Windows\SoftwareDistribution 2014-05-25 11:36:36 ----D---- C:\Users\Hilario\AppData\Roaming\DiskDefrag 2014-05-21 22:21:10 ----D---- C:\Windows\LiveKernelReports 2014-05-21 19:13:49 ----D---- C:\ProgramData\hps 2014-05-18 17:43:31 ----D---- C:\Program Files\Google 2014-05-18 08:58:54 ----D---- C:\Users\Hilario\AppData\Roaming\Mozilla 2014-05-18 08:12:52 ----D---- C:\Users\Hilario\AppData\Roaming\Opera Software 2014-05-18 03:28:40 ----D---- C:\Windows\Debug 2014-05-17 21:04:52 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2014-05-17 20:44:10 ----D---- C:\Windows\Microsoft.NET 2014-05-17 20:42:12 ----RSD---- C:\Windows\assembly 2014-05-17 20:37:11 ----D---- C:\Windows\system32\MRT 2014-05-17 20:33:37 ----A---- C:\Windows\system32\mrt.exe 2014-05-10 00:50:48 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-05-09 19:36:43 ----D---- C:\Users\Hilario\AppData\Roaming\Maxthon3 2014-05-09 19:13:40 ----D---- C:\Windows\system32\Msdtc 2014-05-09 19:13:38 ----D---- C:\Windows\system32\wbem 2014-05-09 19:10:26 ----D---- C:\Windows\system32\config 2014-05-09 19:10:11 ----D---- C:\Windows\system32\spool 2014-05-09 19:10:09 ----D---- C:\Windows\system32\CodeIntegrity 2014-05-09 19:10:06 ----D---- C:\Users\Hilario\AppData\Roaming\KeePass 2014-05-09 19:09:26 ----D---- C:\Windows\registration 2014-05-08 19:22:51 ----SD---- C:\Windows\Downloaded Program Files ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2013-12-20 215656] R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2014-04-16 20072] R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2014-04-16 607680] R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2014-04-16 43216] R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2014-04-16 92656] R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528] R3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-18 92160] R3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2013-12-20 2888536] R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2007-01-11 32272] R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2007-01-11 32528] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 23256] R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-06-05 110296] R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 51928] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-12-22 10919200] R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2010-08-12 292712] R3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992] R3 USBCCID;USB-smartcardlezer; C:\Windows\system32\DRIVERS\usbccid.sys [2009-04-10 30208] R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] S1 Uim_IM;UIM Drive Backup Image Plugin; C:\Windows\System32\Drivers\Uim_IM.sys [2013-02-18 452816] S1 Uim_Vim;UIM Virtual Image Plugin; C:\Windows\System32\Drivers\Uim_Vim.sys [2013-02-18 283600] S1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\UimBus.sys [2013-02-18 81232] S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416] S3 Camdrv30;Philips ToUcam XS; C:\Windows\System32\Drivers\camdrv30.sys [2001-08-17 171264] S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632] S3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544] S3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2009-10-07 266008] S3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2008-02-06 41752] S3 LVUVC;Logitech QuickCam E3500(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2009-10-07 6756632] S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192] S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888] S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016] S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2010-08-12 292712] S3 usbaudio;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328] S3 usbvideo;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe [2013-12-20 87968] R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2014-04-16 5306504] R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE [2007-02-20 110592] R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472] R2 MemeoBackgroundService;MemeoBackgroundService; C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-05-04 25824] R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [2013-05-28 196624] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-31 634656] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200] S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-17 257712] S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688] S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2014-03-25 1663192] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-07 119408] S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] -----------------EOF-----------------