Logfile of random's system information tool 1.10 (written by random/random) Run by Bits&Co at 2015-07-09 13:33:15 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 368 GB (77%) free of 477 GB Total RAM: 1014 MB (9% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:35:15, on 9/07/2015 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16659) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\AVG SafeGuard toolbar\vprot.exe C:\Program Files\MarineAquarium3Free_57\bar\1.bin\APPINTEGRATOR.EXE C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57brmon.exe C:\Program Files\MapsGalaxy_39\bar\1.bin\APPINTEGRATOR.EXE C:\Program Files\MapsGalaxy_39\bar\1.bin\39brmon.exe C:\Program Files\AVG\AVG2015\avgui.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Users\Bits&Co\AppData\Roaming\Spotify\SpotifyWebHelper.exe C:\Users\Bits&Co\AppData\Roaming\Spotify\Spotify.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\ehome\ehmsas.exe C:\Users\Bits&Co\AppData\Roaming\Spotify\SpotifyCrashService.exe C:\Users\Bits&Co\AppData\Roaming\Spotify\Spotify.exe C:\Windows\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_191_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Bits&Co\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T253SPAD\RSIT.exe C:\Program Files\trend micro\Bits&Co.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - (no file) R3 - URLSearchHook: (no name) - {327f75ed-061b-4339-8cc6-5dd45ad1396d} - C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57SrcAs.dll R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll O1 - Hosts: ::1 localhost O2 - BHO: Toolbar BHO - {074d3229-0a22-491b-b9dd-ff3171d75f25} - C:\PROGRA~1\MARINE~2\bar\1.bin\57bar.dll O2 - BHO: Search Assistant BHO - {0eeaa2c3-0cd7-4364-b82e-f9257081c860} - C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57SrcAs.dll O2 - BHO: Toolbar BHO - {1e91a655-bb4b-4693-a05e-2edebc4c9d89} - C:\PROGRA~1\MAPSGA~2\bar\1.bin\39bar.dll O2 - BHO: PasswordBox Helper - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files\PasswordBox\Application\pbbtn.dll O2 - BHO: Search Assistant BHO - {71c1d63a-c944-428a-a5bd-ba513190e5d2} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.5.0.909\AVG SafeGuard toolbar_toolbar.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll O2 - BHO: TubeSaver - {F97D5AE6-80E0-49F4-B30C-B2DD6902B105} - C:\Program Files\TubeSaver\133.dll O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.5.0.909\AVG SafeGuard toolbar_toolbar.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: Marine Aquarium Lite - {07189b84-b33b-4a1e-9b32-ad203c983c20} - C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57bar.dll O3 - Toolbar: MapsGalaxy - {364ea597-e728-4ce4-bb4a-ed846ef47970} - C:\Program Files\MapsGalaxy_39\bar\1.bin\39bar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG SafeGuard toolbar\vprot.exe" O4 - HKLM\..\Run: [Marine Aquarium Lite EPM Support] "C:\PROGRA~1\MARINE~2\bar\1.bin\57medint.exe" T8EPMSUP.DLL,S O4 - HKLM\..\Run: [Marine Aquarium Lite Home Page Guard 32 bit] "C:\PROGRA~1\MARINE~2\bar\1.bin\AppIntegrator.exe" O4 - HKLM\..\Run: [Marine Aquarium Lite Search Scope Monitor] "C:\PROGRA~1\MARINE~2\bar\1.bin\57srchmn.exe" /m=2 /w /h O4 - HKLM\..\Run: [MarineAquarium3Free_57 Browser Plugin Loader] C:\PROGRA~1\MARINE~2\bar\1.bin\57brmon.exe O4 - HKLM\..\Run: [MapsGalaxy EPM Support] "C:\PROGRA~1\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S O4 - HKLM\..\Run: [MapsGalaxy Home Page Guard 32 bit] "C:\PROGRA~1\MAPSGA~2\bar\1.bin\AppIntegrator.exe" O4 - HKLM\..\Run: [MapsGalaxy Search Scope Monitor] "C:\PROGRA~1\MAPSGA~2\bar\1.bin\39srchmn.exe" /m=2 /w /h O4 - HKLM\..\Run: [MapsGalaxy_39 Browser Plugin Loader] C:\PROGRA~1\MAPSGA~2\bar\1.bin\39brmon.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Bits&Co\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Bits&Co\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Bits&Co\AppData\Roaming\Spotify\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Spotify] "C:\Users\Bits&Co\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - (no file) O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file) O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.5.0\ViProtocol.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: MapsGalaxyService (MapsGalaxy_39Service) - COMPANYVERS_NAME - C:\PROGRA~1\MAPSGA~2\bar\1.bin\39barsvc.exe O23 - Service: Marine Aquarium LiteService (MarineAquarium3Free_57Service) - COMPANYVERS_NAME - C:\PROGRA~1\MARINE~2\bar\1.bin\57barsvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: PasswordBox - PasswordBox, Inc. - C:\Program Files\PasswordBox\pbbtnService.exe O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: Torch Crash Handler (TorchCrashHandler) - TorchMedia Inc. - C:\Users\Bits&Co\AppData\Local\Torch\Update\TorchCrashHandler.exe O23 - Service: vToolbarUpdater18.5.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.5.0\ToolbarUpdater.exe -- End of file - 10473 bytes ======Scheduled tasks folder====== C:\Windows\tasks\0215tb_RML.job - C:\Program Files\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0215tb.exe /PROMPT /CMPID=0215tb C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1403478352-2808326535-236861570-1000Core.job - C:\Users\Bits&Co\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1403478352-2808326535-236861570-1000UA.job - C:\Users\Bits&Co\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineCore1d08fb0864882dc.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1403478352-2808326535-236861570-1000Core.job - C:\Users\Bits&Co\AppData\Local\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1403478352-2808326535-236861570-1000UA.job - C:\Users\Bits&Co\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\Open Chrome.job - c:\program files\Google\Chrome\Application\chrome.exe --new-window C:\Windows\tasks\TubeSaver Update.job - C:\Program Files\TubeSaver\tbsUd.exe /update =========Mozilla firefox========= ProfilePath - C:\Users\Bits&Co\AppData\Roaming\Mozilla\Firefox\Profiles\b3fdiyuj.default prefs.js - "browser.startup.homepage" - "http://www.google.nl/" "{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin] "Description"= "Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.5.0\\npsitesafety.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@MapsGalaxy_39.com/Plugin] "Description"=MapsGalaxy Plugin "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@MarineAquarium3Free_57.com/Plugin] "Description"=Marine Aquarium Lite Plugin "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5] "Description"=Windows Presentation Foundation plug-in for Mozilla browsers "Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\TorchVLC] "Description"=VLC Multimedia Plugin "Path"=C:\Users\Bits&Co\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074d3229-0a22-491b-b9dd-ff3171d75f25}] Toolbar BHO - C:\PROGRA~1\MARINE~2\bar\1.bin\57bar.dll [2014-03-16 859720] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0eeaa2c3-0cd7-4364-b82e-f9257081c860}] Search Assistant BHO - C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57SrcAs.dll [2014-03-16 139336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1e91a655-bb4b-4693-a05e-2edebc4c9d89}] Toolbar BHO - C:\PROGRA~1\MAPSGA~2\bar\1.bin\39bar.dll [2014-03-18 859720] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5DB69B97-934B-451D-94DB-32EF802A01CD}] PasswordBox Helper - C:\Program Files\PasswordBox\Application\pbbtn.dll [2015-05-04 141832] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71c1d63a-c944-428a-a5bd-ba513190e5d2}] Search Assistant BHO - C:\Program Files\MapsGalaxy_39\bar\1.bin\39SrcAs.dll [2014-03-18 139336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27 460712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] AVG SafeGuard toolbar - C:\Program Files\AVG SafeGuard toolbar\18.5.0.909\AVG SafeGuard toolbar_toolbar.dll [2015-05-14 3516864] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27 172968] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F97D5AE6-80E0-49F4-B30C-B2DD6902B105}] TubeSaver - C:\Program Files\TubeSaver\133.dll [2013-09-11 145920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {95B7759C-8C7F-4BF1-B163-73684A933233} - AVG SafeGuard toolbar - C:\Program Files\AVG SafeGuard toolbar\18.5.0.909\AVG SafeGuard toolbar_toolbar.dll [2015-05-14 3516864] {8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072] {07189b84-b33b-4a1e-9b32-ad203c983c20} - Marine Aquarium Lite - C:\Program Files\MarineAquarium3Free_57\bar\1.bin\57bar.dll [2014-03-16 859720] {364ea597-e728-4ce4-bb4a-ed846ef47970} - MapsGalaxy - C:\Program Files\MapsGalaxy_39\bar\1.bin\39bar.dll [2014-03-18 859720] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424] "Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656] "Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2006-11-02 215552] "vProt"=C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2015-05-14 2510784] "Marine Aquarium Lite EPM Support"=C:\PROGRA~1\MARINE~2\bar\1.bin\57medint.exe [2014-03-16 12872] "Marine Aquarium Lite Home Page Guard 32 bit"=C:\PROGRA~1\MARINE~2\bar\1.bin\AppIntegrator.exe [2014-03-16 421448] "Marine Aquarium Lite Search Scope Monitor"=C:\PROGRA~1\MARINE~2\bar\1.bin\57srchmn.exe [2014-03-16 55368] "MarineAquarium3Free_57 Browser Plugin Loader"=C:\PROGRA~1\MARINE~2\bar\1.bin\57brmon.exe [2014-03-16 61512] "MapsGalaxy EPM Support"=C:\PROGRA~1\MAPSGA~2\bar\1.bin\39medint.exe [2014-03-18 12872] "MapsGalaxy Home Page Guard 32 bit"=C:\PROGRA~1\MAPSGA~2\bar\1.bin\AppIntegrator.exe [2014-03-18 421448] "MapsGalaxy Search Scope Monitor"=C:\PROGRA~1\MAPSGA~2\bar\1.bin\39srchmn.exe [2014-03-18 55368] "MapsGalaxy_39 Browser Plugin Loader"=C:\PROGRA~1\MAPSGA~2\bar\1.bin\39brmon.exe [2014-03-18 61512] "AVG_UI"=C:\Program Files\AVG\AVG2015\avgui.exe [2015-06-30 3730344] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-18 125952] "Google Update"=C:\Users\Bits&Co\AppData\Local\Google\Update\GoogleUpdate.exe [2013-08-16 116648] "Facebook Update"=C:\Users\Bits&Co\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-25 138096] "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-06-29 53288576] "Spotify Web Helper"=C:\Users\Bits&Co\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2015-07-01 2030648] "Spotify"=C:\Users\Bits&Co\AppData\Roaming\Spotify\Spotify.exe [2015-07-01 7504952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2008-02-11 204800] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2015-07-09 13:33:20 ----D---- C:\Program Files\trend micro 2015-07-09 13:33:15 ----D---- C:\rsit 2015-07-08 19:20:35 ----A---- C:\Windows\system32\FlashPlayerInstaller.exe 2015-06-26 09:49:36 ----A---- C:\Windows\system32\drivers\avgidsdriverx.sys 2015-06-16 15:54:52 ----A---- C:\Windows\system32\drivers\avgldx86.sys 2015-06-13 09:45:24 ----A---- C:\Windows\system32\comctl32.dll 2015-06-13 09:43:14 ----A---- C:\Windows\system32\win32k.sys 2015-06-13 09:42:48 ----A---- C:\Windows\system32\kernel32.dll 2015-06-13 09:12:05 ----A---- C:\Windows\system32\spwmp.dll 2015-06-13 09:11:49 ----A---- C:\Windows\system32\dxmasf.dll 2015-06-13 09:11:42 ----A---- C:\Windows\system32\wmploc.DLL 2015-06-13 09:11:38 ----A---- C:\Windows\system32\wmp.dll 2015-06-12 08:08:03 ----A---- C:\Windows\system32\msfeedsbs.dll 2015-06-12 08:07:59 ----A---- C:\Windows\system32\ieUnatt.exe 2015-06-12 08:07:58 ----A---- C:\Windows\system32\url.dll 2015-06-12 08:07:58 ----A---- C:\Windows\system32\iertutil.dll 2015-06-12 08:07:56 ----A---- C:\Windows\system32\urlmon.dll 2015-06-12 08:07:56 ----A---- C:\Windows\system32\mshta.exe 2015-06-12 08:07:54 ----A---- C:\Windows\system32\jsproxy.dll 2015-06-12 08:07:51 ----A---- C:\Windows\system32\msfeedssync.exe 2015-06-12 08:07:48 ----A---- C:\Windows\system32\vbscript.dll 2015-06-12 08:07:48 ----A---- C:\Windows\system32\dxtmsft.dll 2015-06-12 08:07:46 ----A---- C:\Windows\system32\msfeeds.dll 2015-06-12 08:07:43 ----A---- C:\Windows\system32\wininet.dll 2015-06-12 08:07:43 ----A---- C:\Windows\system32\jscript.dll 2015-06-12 08:07:43 ----A---- C:\Windows\system32\dxtrans.dll 2015-06-12 08:07:42 ----A---- C:\Windows\system32\ieui.dll 2015-06-12 08:07:42 ----A---- C:\Windows\system32\ieframe.dll 2015-06-12 08:07:40 ----A---- C:\Windows\system32\mshtmled.dll 2015-06-12 08:07:38 ----A---- C:\Windows\system32\mshtml.dll 2015-06-12 08:07:37 ----A---- C:\Windows\system32\jscript9.dll 2015-06-10 16:38:10 ----A---- C:\Windows\system32\drivers\avgmfx86.sys ======List of files/folders modified in the last 1 month====== 2015-07-09 13:33:20 ----RD---- C:\Program Files 2015-07-09 13:33:09 ----D---- C:\Windows\Temp 2015-07-09 13:21:25 ----D---- C:\Users\Bits&Co\AppData\Roaming\Spotify 2015-07-09 13:17:27 ----D---- C:\Users\Bits&Co\AppData\Roaming\Skype 2015-07-09 13:14:27 ----SHD---- C:\Windows\Installer 2015-07-09 13:14:26 ----SHD---- C:\Config.Msi 2015-07-09 13:13:49 ----D---- C:\ProgramData\MFAData 2015-07-09 13:12:43 ----D---- C:\Windows\system32\drivers 2015-07-09 12:59:35 ----D---- C:\ProgramData\TorchCrashHandler 2015-07-08 19:21:33 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2015-07-08 19:20:35 ----D---- C:\Windows\System32 2015-07-06 10:41:55 ----D---- C:\ProgramData\Skype 2015-07-06 10:36:19 ----RD---- C:\Program Files\Skype 2015-06-23 06:48:46 ----D---- C:\Windows\system32\catroot2 2015-06-20 06:35:44 ----D---- C:\Users\Bits&Co\AppData\Roaming\DataMgr 2015-06-18 13:01:03 ----D---- C:\Users\Bits&Co\AppData\Roaming\VOPackage 2015-06-18 13:00:51 ----D---- C:\Users\Bits&Co\AppData\Roaming\SCheck 2015-06-18 12:42:03 ----D---- C:\Program Files\glindorus 2015-06-15 11:17:30 ----D---- C:\Windows\rescache 2015-06-13 09:46:02 ----D---- C:\Windows\system32\migration 2015-06-13 09:46:00 ----D---- C:\Program Files\Internet Explorer 2015-06-13 09:45:43 ----D---- C:\Windows\winsxs 2015-06-13 09:45:40 ----D---- C:\Windows\system32\catroot 2015-06-13 09:45:23 ----D---- C:\ProgramData\Microsoft Help 2015-06-13 09:42:43 ----D---- C:\Windows\system32\MRT 2015-06-13 09:29:41 ----A---- C:\Windows\system32\mrt.exe 2015-06-13 09:24:03 ----SHD---- C:\System Volume Information 2015-06-13 09:19:06 ----D---- C:\Windows\system32\nl-NL 2015-06-13 09:19:05 ----D---- C:\Program Files\Windows Media Player 2015-06-11 11:51:56 ----D---- C:\Users\Bits&Co\AppData\Roaming\Snz 2015-06-11 10:44:46 ----D---- C:\Windows\Tasks 2015-06-11 10:44:44 ----HD---- C:\ProgramData 2015-06-11 10:41:02 ----D---- C:\Windows\system32\Tasks ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2015-05-12 190944] R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2015-05-07 290272] R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2015-06-10 170464] R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2015-03-20 35808] R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2015-03-11 132576] R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2015-06-26 231856] R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-05-14 29664] R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2015-06-16 207328] R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2015-05-12 213984] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-08-18 921600] R3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544] R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648] R3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976] R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336] R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048] S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272] S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192] S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888] S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016] S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072] S3 RT2500USB;ASUS USB Wireless LAN Driver; C:\Windows\system32\DRIVERS\rt2500usb.sys [2004-08-13 140544] S3 SG320 Video Capture;SG320 Video Capture; C:\Windows\System32\Drivers\SGCam3UVC.sys [2011-04-22 2503832] S3 usbvideo;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 134016] S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-10 31616] S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [2015-06-30 314304] R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 MapsGalaxy_39Service;MapsGalaxyService; C:\PROGRA~1\MAPSGA~2\bar\1.bin\39barsvc.exe [2014-03-18 88648] R2 MarineAquarium3Free_57Service;Marine Aquarium LiteService; C:\PROGRA~1\MARINE~2\bar\1.bin\57barsvc.exe [2014-03-16 88648] R2 PasswordBox;PasswordBox; C:\Program Files\PasswordBox\pbbtnService.exe [2014-05-14 67584] R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 SeaPort;SeaPort; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-03-28 249648] R2 TorchCrashHandler;Torch Crash Handler; C:\Users\Bits&Co\AppData\Local\Torch\Update\TorchCrashHandler.exe [2014-10-29 1217032] R2 vToolbarUpdater18.5.0;vToolbarUpdater18.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.5.0\ToolbarUpdater.exe [2015-05-14 1812416] R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536] S2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2015\avgfws.exe [2015-01-06 1507632] S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [2015-06-30 3518376] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-03 116648] S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-03 327296] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-26 268464] S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688] S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-03 116648] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-14 148080] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376] S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168] S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] -----------------EOF-----------------