Logfile of random's system information tool 1.10 (written by random/random) Run by Marc at 2015-02-12 10:42:38 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 44 GB (58%) free of 75 GB Total RAM: 1013 MB (12% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:09:30, on 12/02/2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17496) Boot mode: Normal Running processes: C:\windows\system32\taskhost.exe C:\Program Files\G DATA\TotalProtection\AVKTray\AVKTray.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\windows\system32\taskeng.exe C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe C:\Program Files\XTab\cmdshell.exe C:\Program Files\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\G DATA\TotalProtection\Firewall\GDFirewallTray.exe C:\Program Files\RocketDock\RocketDock.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\CCleaner\CCleaner.exe C:\Program Files\CCleaner\CCleaner.exe C:\windows\system32\igfxext.exe C:\windows\system32\igfxsrvc.exe C:\Program Files\XTab\HPNotify.exe C:\windows\system32\taskhost.exe C:\Users\Marc\Downloads\RSIT.exe C:\Program Files\trend micro\Marc.exe C:\windows\system32\dfrgui.exe C:\windows\System32\osk.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX&q={searchTerms} R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX&q={searchTerms} R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX&q={searchTerms} R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX&q={searchTerms} R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1422711466&from=amt&uid=HitachiXHTS545016B9A300_100112PB5B03QCEL8SEGX R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\windows\system32\userinit.exe,C:\Program Files\G DATA\TotalProtection\AVKTray\AVKTray.exe,C:\Program Files\G DATA\TotalProtection\AVKKid\AVKCKS.exe, O2 - BHO: (no name) - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - (no file) O2 - BHO: Increase performance and video formats for your HTML5