Logfile of random's system information tool 1.10 (written by random/random) Run by Christel Meeus at 2015-09-13 11:22:55 Microsoft Windows 7 Professional Service Pack 1 System drive C: has 91 GB (32%) free of 283 GB Total RAM: 8142 MB (62% free) HijackThis download failed ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe C:\windows\system32\services.exe C:\windows\system32\lsass.exe C:\windows\system32\lsm.exe winlogon.exe C:\windows\system32\svchost.exe -k DcomLaunch "C:\Program Files\Bitdefender\Bitdefender\vsserv.exe" /service C:\windows\system32\nvvsvc.exe "C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe" C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k netsvcs "C:\Program Files\IDT\WDM\STacSV64.exe" C:\windows\system32\svchost.exe -k GPSvcGroup C:\windows\system32\Hpservice.exe C:\windows\system32\vcsFPService.exe "C:\Program Files\HitmanPro\hmpsched.exe" C:\windows\system32\svchost.exe -k NetworkService C:\windows\System32\spoolsv.exe taskeng.exe {801F851E-B78D-431F-86B7-C7467AB4AE79} C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe" "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\windows\system32\nvvsvc.exe -session -first C:\windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\IDT\WDM\AESTSr64.exe" "C:\Program Files\LSI SoftModem\agr64svc.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe" C:\windows\System32\svchost.exe -k utcsvc "C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe" /DisableUI "taskhost.exe" "C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe" "C:\Program Files\HitmanPro\HitmanPro_x64.exe" /scan:boot /quiet /quick "C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe" "C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe" "c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe" "C:\windows\system32\Dwm.exe" C:\windows\Explorer.EXE "C:\windows\system32\GWX\GWX.exe" "C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe" "C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe" "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe" "C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE" "C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe" "C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe" "c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS "C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService "C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe" "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" "C:\Program Files\IDT\WDM\sttray64.exe" "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" C:\windows\system32\svchost.exe -k imgsvc "C:\Program Files\Bitdefender\Bitdefender\bdagent.exe" "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" "C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe" C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe "C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe" /service "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" C:\WINDOWS\SYSWOW64\VMNAT.EXE "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" C:\WINDOWS\SYSWOW64\VMNETDHCP.EXE "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" WLIDSvcM.exe 4804 "C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe" "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" C:\windows\system32\wbem\unsecapp.exe -Embedding "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe" "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe" C:\windows\system32\wbem\wmiprvse.exe C:\windows\system32\wbem\wmiprvse.exe "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" C:\windows\system32\SearchIndexer.exe /Embedding "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2020 CREDAT:267521 /prefetch:2 "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe" "C:\Program Files\Synaptics\SynTP\SynTPHelper.exe" "C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe" C:\windows\system32\wbem\unsecapp.exe -Embedding "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" "C:\windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch; "C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" /hidden "C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe" "C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe" -Embedding "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\windows\system32\NOTEPAD.EXE" C:\rsit\info.txt "C:\windows\system32\NOTEPAD.EXE" C:\rsit\log.txt "C:\Program Files\Bitdefender\Bitdefender\downloader.exe" /download /trace /stopevent 764 \??\C:\windows\system32\conhost.exe "-6552470031710898888427907005-1717587961194179173-8460590401654199224-247389904 "C:\Program Files\Bitdefender\Bitdefender\odscanui.exe" /UserScanTask db7af1a4-0db8-4f42-903a-9d200e40d03c /TempClone /StartMinimized /CloseNoThreats /RegWndMsg db7af1a4-0db8-4f42-903a-9d200e40d03c-1442136163 /InitFile C:\Users\CHRIST~1\AppData\Local\Temp\bd6BA0.tmp "C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a2a36f9a-fa45-4bcb-826d-e6fb155093f0 -SystemEventPortName:HostProcess-89774f0d-1f94-4fca-80b8-f66f38d25db4 -IoCancelEventPortName:HostProcess-09ca06aa-1a86-427e-8f53-e6f754358f97 -NonStateChangingEventPortName:HostProcess-913cc84d-2c7c-44db-a6b8-d03f10753fb6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e5cfd156-65bd-4039-b062-1b5a2ad71d40 -DeviceGroupId:WpdFsGroup "H:\RSITx64.exe" ======Scheduled tasks folder====== C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler =========Mozilla firefox========= ProfilePath - C:\Users\Christel Meeus\AppData\Roaming\Mozilla\Firefox\Profiles\ybg4y9yb.default prefs.js - "browser.startup.homepage" - "http://www.default-search.net?sid=476&aid=135&itype=a&ver=13337&tm=383&src=hmp" prefs.js - "keyword.URL" - "http://www.default-search.net/search?sid=476&aid=135&itype=a&ver=13337&tm=383&src=ds&p=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 18.0.0.232 Plugin "Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Bitdefender.com/PasswordManager;version=17.8] "Description"=Bitdefender Wallet "Path"=C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0] "Description"=DivX Plus Web Player "Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin] "Description"=Google Earth in your browser "Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3522.0110] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@UtilityChest_49.com/Plugin] "Description"=Utility Chest Plugin "Path"=C:\Program Files (x86)\UtilityChest_49\bar\1.bin\NP49Stub.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 18.0.0.232 Plugin "Path"=C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL C:\Users\Christel Meeus\AppData\Roaming\Mozilla\Firefox\Profiles\ybg4y9yb.default\searchplugins\ default-search.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}] Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-10-02 193992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-24 256456] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}] Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll [2014-10-02 156400] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}] File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-03-10 117248] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}] DivX Plus Web Player HTML5