Logfile of random's system information tool 1.10 (written by random/random) Run by Arthur at 2016-02-29 17:54:18 Microsoft Windows 10 Education System drive C: has 203 GB (37%) free of 550 GB Total RAM: 7638 MB (65% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:35:43, on 29/02/2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\Program Files (x86)\IPVanish\VPNClient.exe C:\Program Files (x86)\IPVanish\OpenVPN\openvpn.exe C:\Program Files\trend micro\Arthur.exe C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O1 - Hosts: 127.0.0.2 mefeedia.com O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O2 - BHO: Wondershare Video Converter Ultimate 7.1.0 - {451C804F-C205-4F03-B48E-537EC94937BF} - C:\PROGRA~3\WONDER~1\VIDEOC~1\WSBROW~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe O4 - HKLM\..\Run: [DelaypluginInstall] C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Arthur\AppData\Roaming\Spotify\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Spotify] "C:\Users\Arthur\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O4 - Startup: PRTG Enterprise Console.lnk = C:\Program Files (x86)\PRTG Network Monitor\PRTG Enterprise Console.exe O4 - Startup: Sync.LNK = C:\Program Files (x86)\Sync\sync-taskbar.exe O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{e8cdc793-33bb-4207-b702-043119a7eaff}: NameServer = 198.18.0.1,198.18.0.2 O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: WSWSVCUchrome - {1CA93FF0-A218-44F1 - (no file) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Product Agent Service (ProductAgentService) - Unknown owner - C:\Program Files\Bitdefender Agent\ProductAgentService.exe (file missing) O23 - Service: PRTG Core Server Service (PRTGCoreService) - Paessler AG - C:\Program Files (x86)\PRTG Network Monitor\64 bit\PRTG Server.exe O23 - Service: PRTG Probe Service (PRTGProbeService) - Paessler AG - C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing) O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Bitdefender Desktop Update Service (UPDATESRV) - Unknown owner - C:\Program Files\Bitdefender\Bitdefender 2016\updatesrv.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: Bitdefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Bitdefender\Bitdefender 2016\vsserv.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10518 bytes ======Listing Processes====== winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted "dwm.exe" C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-737421ef-f80b-45ac-adf8-f9fa6a6bf658 -SystemEventPortName:HostProcess-c0afbd14-99de-45c3-ba36-8839cdd53535 -IoCancelEventPortName:HostProcess-234a9523-af1b-40dd-b000-4e4b4a1d01b8 -NonStateChangingEventPortName:HostProcess-a8a01093-ef7d-4660-ada5-331de725547c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c072411a-2bb5-40f4-8482-8c988db9277c -DeviceGroupId:WudfDefaultDevicePool C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 "C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe" C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k appmodel "C:\Program Files\KMSpico\Service_KMS.exe" "C:\Program Files (x86)\PRTG Network Monitor\64 bit\PRTG Server.exe" dashost.exe {161d6d4d-595c-44de-abe587653c54b636} C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted sihost.exe taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E} C:\Windows\Explorer.EXE "C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca C:\Windows\System32\RuntimeBroker.exe -Embedding "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s "C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" "C:\Program Files (x86)\IPVanish\VPNClient.exe" C:\Windows\system32\SettingSyncHost.exe -Embedding "fontdrvhost.exe" "C:\Program Files (x86)\IPVanish\OpenVPN\openvpn.exe" "C:\Users\Arthur\AppData\Local\IPVanish\openvpn.conf" \??\C:\Windows\system32\conhost.exe 0x4 C:\Windows\system32\svchost.exe -k HPService "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" C:\Windows\system32\svchost.exe -k UnistackSvcGroup "C:\Users\Arthur\Downloads\RSITx64.exe" C:\Windows\system32\ApplicationFrameHost.exe -Embedding "C:\Program Files\WindowsApps\Smartschool.Smartschool_1.6.3.3_neutral__e1120bs0kk1yt\Sb.SmartSchool.Windows.exe" -ServerName:App.AppXzf87pqzz53xfr8xxs68ae0v4hmwsqa2c.mca "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\Arthur\AppData\Local\Packages\Smartschool.Smartschool_e1120bs0kk1yt\LocalState\fileDownload\ingevulde opgave (1).doc" /o "" "C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6732.0.475918498\75786030" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,24,52,62 --gpu-vendor-id=0x10de --gpu-device-id=0x1401 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.6143 --ignored=" --type=renderer " /prefetch:822062411 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.2.2146379099\975556080" --font-cache-shared-handle=2568 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.3.680149951\1947151805" --font-cache-shared-handle=2704 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.5.1104003195\1484115088" --font-cache-shared-handle=3708 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.15.878703540\379214738" --font-cache-shared-handle=7128 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.17.1836065435\1229119130" --font-cache-shared-handle=5504 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.19.1565949632\693268787" --font-cache-shared-handle=5736 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.23.495907322\1450503973" --font-cache-shared-handle=6748 /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/28DaySingleProfile/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="6732.28.999914524\1766851290" --font-cache-shared-handle=6216 /prefetch:673131151 C:\Windows\System32\LockAppHost.exe -Embedding taskeng.exe {A2B0253B-83B2-4D3C-AE73-AD6B9CC8A3D6} ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\HPCeeScheduleForabc.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForabc (null) C:\Windows\tasks\HPCeeScheduleForArthur.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForArthur (null) =========Mozilla firefox========= ProfilePath - C:\Users\Arthur\AppData\Roaming\Mozilla\Firefox\Profiles\88qcz0yh.default prefs.js - "browser.search.useDBForOrder" - true prefs.js - "browser.startup.homepage" - "http://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggXcQ5bWA0QEhhCdQpdTA0QEQEOeA4IWBRBQgYSJloJVgASQAYFIk0FA18DB0VXfWFoKB8fHGZGIUtbCXIfTkI=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.74.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.74.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0] "Description"=Microsoft Lync Plug-in for Firefox "Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision] "Description"=NVIDIA stereo images plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming] "Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll C:\Users\Arthur\AppData\Roaming\Mozilla\Firefox\Profiles\88qcz0yh.default\searchplugins\ default.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-02-25 231112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-02-25 2093872] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-02-25 170696] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{451C804F-C205-4F03-B48E-537EC94937BF}] Wondershare Video Converter Ultimate 7.1.0 - C:\PROGRA~3\WONDER~1\VIDEOC~1\WSBROW~1.DLL [2016-01-29 634120] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-02-22 462432] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-02-25 1537328] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-02-22 173152] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-12-09 2771576] "RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-02-22 8783616] "IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-05-28 36352] "ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-12-09 1846016] "Eraser"=C:\Program Files\Eraser\Eraser.exe [2015-09-03 1074088] "AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19 557768] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-02-10 50599552] "Spotify Web Helper"=C:\Users\Arthur\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-01-31 2355312] "Spotify"=C:\Users\Arthur\AppData\Roaming\Spotify\Spotify.exe [2016-01-31 8449136] "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13 1085656] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-29 595504] "Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2015-04-28 2086240] "DelaypluginInstall"=C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [2016-01-29 1971976] C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup PRTG Enterprise Console.lnk - C:\Program Files (x86)\PRTG Network Monitor\PRTG Enterprise Console.exe Sync.LNK - C:\Program Files (x86)\Sync\sync-taskbar.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "DSCAutomationHostEnabled"=2 "PromptOnSecureDesktop"=0 "SoftwareSASGeneration"=1 "SafeModeBlockNonAdmins"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoStrCmpLogical"=1 "AllowLegacyWebView"=1 "AllowUnhashedWebView"=1 "NoThumbnailCache"=1 "DisableThumbnailCache"=1 "NoInstrumentation"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midimapper"=midimap.dll "msacm.imaadpcm"=imaadp32.acm "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "msacm.msadpcm"=msadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "vidc.i420"=iyuv_32.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "vidc.yvyu"=msyuv.dll "wavemapper"=msacm32.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .inf - open - "%SystemRoot%\system32\NOTEPAD.EXE" %1 .ini - open - "%SystemRoot%\system32\NOTEPAD.EXE" %1 .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - "C:\Windows\System32\WScript.exe" "%1" %* .txt - open - "%SystemRoot%\system32\NOTEPAD.EXE" %1 ======List of files/folders created in the last 1 month====== 2016-02-29 17:54:18 ----DC---- C:\rsit 2016-02-29 17:54:18 ----DC---- C:\Program Files\trend micro 2016-02-28 17:22:54 ----D---- C:\Users\Arthur\AppData\Roaming\freac 2016-02-28 17:22:33 ----DC---- C:\Program Files (x86)\freac 2016-02-28 17:16:35 ----D---- C:\Users\Arthur\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} 2016-02-28 17:16:33 ----D---- C:\Users\Arthur\AppData\Roaming\Wondershare Video Converter Ultimate 2016-02-28 17:15:45 ----A---- C:\Windows\SYSWOW64\WSCM64.dll 2016-02-28 17:15:45 ----A---- C:\Windows\SYSWOW64\WSCM32.dll 2016-02-28 17:15:42 ----D---- C:\ProgramData\Wondershare Video Converter Ultimate 2016-02-28 17:15:40 ----DC---- C:\Program Files (x86)\Wondershare 2016-02-28 17:15:40 ----D---- C:\ProgramData\Wondershare 2016-02-27 19:19:04 ----D---- C:\ProgramData\Paessler 2016-02-27 19:18:57 ----D---- C:\ProgramData\Logs 2016-02-27 19:18:57 ----D---- C:\ProgramData\Licenses 2016-02-27 19:18:57 ----AD---- C:\ProgramData\TEMP 2016-02-27 19:18:46 ----DC---- C:\Program Files\WinPcap 2016-02-27 19:18:17 ----DC---- C:\Program Files (x86)\PRTG Network Monitor 2016-02-27 12:40:00 ----D---- C:\ProgramData\regid.1986-12.com.adobe 2016-02-27 12:39:47 ----DC---- C:\Program Files\Adobe 2016-02-24 21:25:18 ----ASH---- C:\pagefile.sys 2016-02-24 19:38:44 ----DC---- C:\Program Files\Microsoft Office 15 2016-02-23 20:01:25 ----D---- C:\Users\Arthur\AppData\Roaming\Battle.net 2016-02-22 18:51:22 ----A---- C:\Windows\SYSWOW64\SRCOM.dll 2016-02-22 18:51:22 ----A---- C:\Windows\SYSWOW64\SFCOM.dll 2016-02-22 18:51:22 ----A---- C:\Windows\SYSWOW64\SECOMN32.DLL 2016-02-22 18:51:22 ----A---- C:\Windows\system32\YamahaAE2.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\YamahaAE.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\WavesGUILib64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tossaemaxapo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tossaeapo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\toseaeapo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tosasfapo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tosade.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tepeqapo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tadefxapo264.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\tadefxapo.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRSWOW64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRSTSX64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRSTSH64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRSHP64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRRPTR64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRCOM64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRCOM.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SRAPO64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\sltech64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\slprp64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\slcnt64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\sl3apo64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SFSS_APO.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SFNHK64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SFCOM64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SFAPO64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SEHDRA64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SECOMN64.dll 2016-02-22 18:51:22 ----A---- C:\Windows\system32\SEAPO64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtPgEx64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtlCPAPI64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RTEEP64A.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RTEEL64A.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RTEEG64A.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RTEED64A.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtDataProc64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RTCOM64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RP3DHT64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RP3DAA64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RCoRes64.dat 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RCoInstII64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\drivers\rtkSSTsetting.dat 2016-02-22 18:51:21 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT 2016-02-22 18:51:20 ----A---- C:\Windows\system32\R4EEP64A.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\R4EEL64A.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\R4EEG64A.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\R4EED64A.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\R4EEA64A.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\NAHIMICV2apo.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\NahimicAPONSControl.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MISS_APO.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll 2016-02-22 18:51:20 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\KAAPORT64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\IntelSSTAPO.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\ICEsoundAPO64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\HiFiDAX2API.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\FMAPO64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSU2PREC64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSU2PLFX64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSU2PGFX64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSLFXAPO64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSGFXAPO64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSBoostDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPP64AF3.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPP64A.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPO64AF3.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPO64A.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPD64AF3.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPD64A.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPA64F3.dll 2016-02-22 18:51:19 ----A---- C:\Windows\system32\DDPA64.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\CX64APO.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\audioLibVc.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\AERTAR64.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\AERTAC64.dll 2016-02-22 18:51:18 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll 2016-02-22 18:51:11 ----D---- C:\Windows\LastGood.Tmp 2016-02-21 19:30:14 ----DC---- C:\Program Files (x86)\American Truck Simulator 2016-02-21 19:13:42 ----DC---- C:\Program Files (x86)\Euro Truck Simulator 2 2016-02-20 16:10:01 ----DC---- C:\Program Files (x86)\R.G. Games 2016-02-19 20:49:47 ----A---- C:\Users\Arthur\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt 2016-02-19 20:49:47 ----A---- C:\Users\Arthur\AppData\Roaming\trace_FilterInstaller.txt 2016-02-19 20:49:46 ----A---- C:\Windows\system32\drivers\stdriverx64.sys 2016-02-19 20:48:44 ----D---- C:\Users\Arthur\AppData\Roaming\Recordpad 2016-02-19 20:48:44 ----D---- C:\ProgramData\NCH Software 2016-02-19 20:48:43 ----DC---- C:\Program Files (x86)\NCH Software 2016-02-19 20:48:42 ----D---- C:\Users\Arthur\AppData\Roaming\NCH Software 2016-02-19 19:38:43 ----DC---- C:\Program Files (x86)\VirtualDJ 2016-02-18 20:32:30 ----A---- C:\Windows\SYSWOW64\msvcr71.dll 2016-02-18 20:32:30 ----A---- C:\Windows\SYSWOW64\msvcp71.dll 2016-02-18 20:32:30 ----A---- C:\Windows\SYSWOW64\MFC71u.dll 2016-02-18 20:32:30 ----A---- C:\Windows\SYSWOW64\MFC71.dll 2016-02-18 20:32:30 ----A---- C:\Windows\SYSWOW64\atl71.dll 2016-02-18 20:32:25 ----DC---- C:\Program Files\DIFX 2016-02-18 20:32:23 ----A---- C:\Windows\system32\drivers\tiehdusb.sys 2016-02-18 20:31:55 ----DC---- C:\Program Files (x86)\TI Education 2016-02-18 18:26:21 ----A---- C:\Windows\SECOH-QAD.exe 2016-02-18 18:26:21 ----A---- C:\Windows\SECOH-QAD.dll 2016-02-18 18:26:19 ----DC---- C:\Program Files\KMSpico 2016-02-18 18:26:19 ----A---- C:\Windows\system32\Vestris.ResourceLib.dll 2016-02-16 20:13:00 ----D---- C:\Users\Arthur\AppData\Roaming\.minecraft 2016-02-16 19:17:44 ----D---- C:\Users\Arthur\AppData\Roaming\Wireshark 2016-02-16 18:48:46 ----DC---- C:\Program Files (x86)\Cain 2016-02-16 18:45:37 ----DC---- C:\Program Files\Acrylic Wi-Fi Professional 2016-02-16 18:45:37 ----D---- C:\Users\Arthur\AppData\Roaming\Acrylic Wi-Fi Professional 2016-02-16 18:11:41 ----A---- C:\Windows\ZooEasy Uninstall Log.txt 2016-02-16 18:00:34 ----D---- C:\Windows\ZooEasy 2016-02-16 18:00:01 ----A---- C:\Windows\ZooEasy Setup Log.txt 2016-02-15 21:49:13 ----A---- C:\Windows\SYSWOW64\combase.dll 2016-02-15 21:49:13 ----A---- C:\Windows\system32\mshtml.dll 2016-02-15 21:49:13 ----A---- C:\Windows\system32\combase.dll 2016-02-15 21:49:12 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll 2016-02-15 21:49:12 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll 2016-02-15 21:49:12 ----A---- C:\Windows\system32\rdpcorets.dll 2016-02-15 21:49:12 ----A---- C:\Windows\system32\edgehtml.dll 2016-02-15 21:49:11 ----A---- C:\Windows\SYSWOW64\twinui.dll 2016-02-15 21:49:11 ----A---- C:\Windows\system32\twinui.dll 2016-02-15 21:49:11 ----A---- C:\Windows\system32\ieframe.dll 2016-02-15 21:49:11 ----A---- C:\Windows\system32\hlink.dll 2016-02-15 21:49:10 ----A---- C:\Windows\SYSWOW64\msctf.dll 2016-02-15 21:49:10 ----A---- C:\Windows\SYSWOW64\KernelBase.dll 2016-02-15 21:49:10 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2016-02-15 21:49:10 ----A---- C:\Windows\SYSWOW64\hlink.dll 2016-02-15 21:49:10 ----A---- C:\Windows\system32\msctf.dll 2016-02-15 21:49:10 ----A---- C:\Windows\system32\KernelBase.dll 2016-02-15 21:49:10 ----A---- C:\Windows\system32\jscript9.dll 2016-02-15 21:49:09 ----A---- C:\Windows\SYSWOW64\WinTypes.dll 2016-02-15 21:49:09 ----A---- C:\Windows\SYSWOW64\wininet.dll 2016-02-15 21:49:09 ----A---- C:\Windows\SYSWOW64\msorcl32.dll 2016-02-15 21:49:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2016-02-15 21:49:09 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2016-02-15 21:49:09 ----A---- C:\Windows\system32\wuaueng.dll 2016-02-15 21:49:09 ----A---- C:\Windows\system32\WinTypes.dll 2016-02-15 21:49:09 ----A---- C:\Windows\system32\wininet.dll 2016-02-15 21:49:09 ----A---- C:\Windows\system32\rasmans.dll 2016-02-15 21:49:09 ----A---- C:\Windows\system32\Chakra.dll 2016-02-15 21:49:08 ----A---- C:\Windows\SYSWOW64\kerberos.dll 2016-02-15 21:49:08 ----A---- C:\Windows\SYSWOW64\edgehtml.dll 2016-02-15 21:49:08 ----A---- C:\Windows\SYSWOW64\Chakra.dll 2016-02-15 21:49:08 ----A---- C:\Windows\system32\win32kfull.sys 2016-02-15 21:49:08 ----A---- C:\Windows\system32\ntdll.dll 2016-02-15 21:49:08 ----A---- C:\Windows\system32\NetworkDesktopSettings.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\ztrace_maps.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\wuapi.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\rasman.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\mtxoci.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\IoTAssignedAccessLockFramework.dll 2016-02-15 21:49:07 ----A---- C:\Windows\SYSWOW64\Chakradiag.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\ztrace_maps.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\wuuhext.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\wups2.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\wups.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\wuapi.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\urlmon.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\rdpudd.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\rasman.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\ngckeyenum.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\mtxoci.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\kerberos.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\IoTAssignedAccessLockFramework.dll 2016-02-15 21:49:07 ----A---- C:\Windows\system32\drivers\mrxdav.sys 2016-02-15 21:49:07 ----A---- C:\Windows\system32\Chakradiag.dll 2016-02-15 20:46:49 ----A---- C:\Windows\system32\drivers\mwac.sys 2016-02-15 20:46:49 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2016-02-15 20:46:49 ----A---- C:\Windows\system32\drivers\mbam.sys 2016-02-15 20:29:16 ----A---- C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys 2016-02-15 20:28:24 ----D---- C:\Users\Arthur\AppData\Roaming\Apowersoft 2016-02-15 19:26:29 ----D---- C:\Users\Arthur\AppData\Roaming\WinAVI 2016-02-15 19:26:27 ----DC---- C:\Program Files (x86)\All in One Converter 2016-02-14 12:51:27 ----AC---- C:\bdlog.txt 2016-02-14 12:10:44 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll 2016-02-14 12:10:43 ----D---- C:\ProgramData\BDLogging 2016-02-14 12:10:41 ----A---- C:\Windows\system32\drivers\bdelam.sys 2016-02-14 12:10:41 ----A---- C:\Windows\capicom.dll 2016-02-14 12:10:38 ----A---- C:\Windows\system32\drivers\bdvedisk.sys 2016-02-14 12:10:38 ----A---- C:\Windows\system32\drivers\avckf.sys 2016-02-14 12:10:38 ----A---- C:\Windows\system32\drivers\avc3.sys 2016-02-14 12:10:36 ----A---- C:\Windows\system32\drivers\ignis.sys 2016-02-14 12:09:35 ----D---- C:\Users\Arthur\AppData\Roaming\Bitdefender 2016-02-14 12:08:59 ----D---- C:\ProgramData\Bitdefender 2016-02-14 12:08:59 ----A---- C:\Windows\system32\drivers\gzflt.sys 2016-02-14 12:08:58 ----DC---- C:\Program Files\Bitdefender 2016-02-14 12:08:58 ----A---- C:\Windows\system32\drivers\trufos.sys 2016-02-14 12:05:15 ----D---- C:\ProgramData\Bitdefender Agent 2016-02-14 12:04:30 ----D---- C:\Users\Arthur\AppData\Roaming\QuickScan 2016-02-14 12:04:28 ----DC---- C:\Program Files\Common Files\Bitdefender 2016-02-10 13:26:26 ----D---- C:\Users\Arthur\AppData\Roaming\.mono 2016-02-10 13:26:26 ----D---- C:\ProgramData\.mono 2016-02-10 13:24:25 ----DC---- C:\Program Files (x86)\R.G. Mechanics 2016-02-10 12:44:02 ----D---- C:\Users\Arthur\AppData\Roaming\BOINC 2016-02-10 12:43:59 ----D---- C:\ProgramData\BOINC 2016-02-10 12:43:41 ----D---- C:\Windows\Downloaded Installations 2016-02-10 12:43:38 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys 2016-02-10 12:43:36 ----DC---- C:\Windows\system32\DRVSTORE 2016-02-10 12:43:36 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys 2016-02-10 12:43:35 ----DC---- C:\Program Files\Oracle 2016-02-09 18:06:27 ----DC---- C:\Program Files (x86)\Adobe 2016-02-09 17:47:27 ----A---- C:\Windows\WebUpdateSvc4.INI 2016-02-09 14:16:00 ----DC---- C:\Program Files\Recuva 2016-02-09 12:31:23 ----DC---- C:\Program Files (x86)\4KDownload 2016-02-09 10:15:33 ----DC---- C:\Program Files\Synaptics 2016-02-09 10:15:31 ----A---- C:\Windows\system32\drivers\Smb_driver_Intel.sys 2016-02-08 20:21:20 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2016-02-08 20:21:09 ----DC---- C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-02-08 20:21:09 ----D---- C:\ProgramData\Malwarebytes 2016-02-08 20:19:38 ----D---- C:\Windows\system32\DAX2 2016-02-08 20:19:06 ----A---- C:\Windows\system32\NicInstD.dll 2016-02-08 20:19:06 ----A---- C:\Windows\system32\NicCo4.dll 2016-02-08 20:19:06 ----A---- C:\Windows\system32\e1dmsg.dll 2016-02-08 20:19:06 ----A---- C:\Windows\system32\drivers\e1d65x64.sys 2016-02-08 20:16:02 ----D---- C:\ProgramData\ProductData 2016-02-08 20:15:56 ----D---- C:\Users\Arthur\AppData\Roaming\IObit 2016-02-08 20:15:56 ----D---- C:\ProgramData\IObit 2016-02-08 20:15:56 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS 2016-02-08 20:15:54 ----DC---- C:\Program Files (x86)\IObit 2016-02-06 17:17:09 ----A---- C:\Windows\ntbtlog.txt 2016-02-06 16:48:06 ----DC---- C:\Program Files (x86)\Rockstar Games 2016-02-06 16:47:58 ----DC---- C:\Program Files\Rockstar Games 2016-02-06 09:13:16 ----D---- C:\ProgramData\x-formation 2016-02-05 19:43:17 ----D---- C:\Users\Arthur\AppData\Roaming\Sony Creative Software Inc 2016-02-05 18:09:33 ----D---- C:\ProgramData\Muvizu 2016-02-05 17:07:57 ----DC---- C:\Program Files\Muvizu 2016-02-05 17:05:18 ----D---- C:\Users\Arthur\AppData\Roaming\Blender Foundation 2016-02-04 20:05:29 ----D---- C:\Users\Arthur\AppData\Roaming\JonDo 2016-02-04 19:34:45 ----D---- C:\Users\Arthur\AppData\Roaming\Ashampoo 2016-02-04 19:33:37 ----D---- C:\ProgramData\Ashampoo 2016-02-04 19:33:36 ----DC---- C:\Program Files (x86)\Ashampoo 2016-02-04 19:25:28 ----D---- C:\ProgramData\AVS4YOU 2016-02-04 19:25:27 ----D---- C:\Users\Arthur\AppData\Roaming\AVS4YOU 2016-02-04 19:25:04 ----A---- C:\Windows\SYSWOW64\msxml3a.dll 2016-02-04 19:25:00 ----DC---- C:\Program Files (x86)\AVS4YOU 2016-02-04 18:35:00 ----D---- C:\ProgramData\KMSAutoS 2016-02-04 17:50:22 ----DC---- C:\Program Files (x86)\IPVanish 2016-02-04 06:21:46 ----D---- C:\ProgramData\Socialclub 2016-02-03 20:56:21 ----D---- C:\Users\Arthur\AppData\Roaming\Hewlett-Packard 2016-02-03 20:49:58 ----D---- C:\System.sav 2016-02-03 20:49:46 ----D---- C:\ProgramData\Hewlett-Packard 2016-02-03 20:49:07 ----D---- C:\Users\Arthur\AppData\Roaming\hpqLog 2016-02-03 17:08:42 ----D---- C:\Users\Arthur\AppData\Roaming\Titanium 2016-02-03 17:08:42 ----D---- C:\Users\Arthur\AppData\Roaming\Apple Computer 2016-02-03 17:08:19 ----A---- C:\Windows\system32\drivers\tap0901.sys 2016-02-03 17:08:18 ----DC---- C:\Program Files\pia_manager 2016-02-03 17:07:41 ----D---- C:\Users\Arthur\AppData\Roaming\Software Tool 2016-02-03 17:02:12 ----D---- C:\Users\Arthur\AppData\Roaming\DMCache 2016-02-03 17:02:12 ----D---- C:\ProgramData\IDM 2016-02-03 16:19:11 ----A---- C:\Windows\system32\hpf3l70w.dll 2016-02-03 16:18:00 ----A---- C:\Windows\system32\hpzids40.dll 2016-02-03 16:16:19 ----D---- C:\ProgramData\HP 2016-02-03 16:10:37 ----DC---- C:\Program Files (x86)\HP 2016-02-03 16:07:41 ----DC---- C:\Program Files (x86)\Hewlett-Packard 2016-02-02 21:39:27 ----D---- C:\ProgramData\Steam 2016-01-31 21:21:13 ----D---- C:\Users\Arthur\AppData\Roaming\GHISLER 2016-01-31 17:02:23 ----D---- C:\Users\Arthur\AppData\Roaming\Softland 2016-01-31 17:02:17 ----D---- C:\ProgramData\Softland 2016-01-31 16:56:24 ----D---- C:\ProgramData\Sync 2016-01-31 16:56:24 ----D---- C:\Program Files (x86)\Sync 2016-01-31 16:45:33 ----D---- C:\Windows\pss 2016-01-31 16:28:00 ----D---- C:\Users\Arthur\AppData\Roaming\ArcticLine 2016-01-31 16:27:54 ----DC---- C:\Program Files (x86)\Folder Marker 2016-01-31 16:25:52 ----D---- C:\Users\Arthur\AppData\Roaming\W10LogonChanger 2016-01-31 14:40:43 ----DC---- C:\Program Files\Microsoft Silverlight 2016-01-31 14:40:43 ----DC---- C:\Program Files (x86)\Microsoft Silverlight 2016-01-31 13:43:15 ----DC---- C:\Program Files (x86)\GlobFX Technologies 2016-01-30 19:21:59 ----D---- C:\Users\Arthur\AppData\Roaming\SuperHideIP 2016-01-30 19:21:59 ----D---- C:\ProgramData\SuperHideIP 2016-01-30 19:21:34 ----D---- C:\Users\Arthur\AppData\Roaming\AutoHideIP 2016-01-30 19:21:34 ----D---- C:\ProgramData\AutoHideIP 2016-01-30 19:19:50 ----D---- C:\Users\Arthur\AppData\Roaming\HideIPEasy 2016-01-30 19:19:50 ----D---- C:\ProgramData\HideIPEasy 2016-01-30 19:17:50 ----D---- C:\Users\Arthur\AppData\Roaming\RealHideIP 2016-01-30 19:17:50 ----D---- C:\ProgramData\RealHideIP 2016-01-30 17:42:03 ----AC---- C:\spklogtest.txt 2016-01-30 17:26:33 ----A---- C:\Windows\SYSWOW64\HackerTyper Screensaver.scr 2016-01-30 17:04:23 ----DC---- C:\Program Files\Speccy 2016-01-30 17:01:10 ----D---- C:\Program Files (x86)\SpeedFan ======List of files/folders modified in the last 1 month====== 2016-02-29 18:35:26 ----D---- C:\Windows\Temp 2016-02-29 18:35:26 ----D---- C:\Windows\System32 2016-02-29 18:29:23 ----D---- C:\Windows\Microsoft.NET 2016-02-29 18:16:17 ----A---- C:\Windows\system32\PerfStringBackup.INI 2016-02-29 18:00:21 ----D---- C:\Windows\AppReadiness 2016-02-29 17:54:27 ----HD---- C:\Program Files\WindowsApps 2016-02-29 17:54:18 ----RDC---- C:\Program Files 2016-02-29 17:49:56 ----D---- C:\Windows\system32\sru 2016-02-28 20:00:32 ----D---- C:\Users\Arthur\AppData\Roaming\Spotify 2016-02-28 19:25:13 ----D---- C:\Windows\system32\config 2016-02-28 19:24:46 ----SHD---- C:\System Volume Information 2016-02-28 19:23:53 ----D---- C:\Users\Arthur\AppData\Roaming\uTorrent 2016-02-28 17:46:04 ----D---- C:\Users\Arthur\AppData\Roaming\vlc 2016-02-28 17:22:33 ----RDC---- C:\Program Files (x86) 2016-02-28 17:15:52 ----DC---- C:\Program Files (x86)\Common Files 2016-02-28 17:15:45 ----D---- C:\Windows\SysWOW64 2016-02-28 17:15:42 ----HD---- C:\ProgramData 2016-02-28 16:55:55 ----SHDC---- C:\$Recycle.Bin 2016-02-28 16:55:34 ----RD---- C:\Users 2016-02-28 16:35:21 ----D---- C:\Windows\system32\NDF 2016-02-27 22:46:36 ----D---- C:\Windows\system32\drivers\etc 2016-02-27 22:46:36 ----D---- C:\Users\Arthur\AppData\Roaming\Adobe 2016-02-27 19:21:11 ----D---- C:\Windows\Prefetch 2016-02-27 19:13:38 ----SD---- C:\ProgramData\Microsoft 2016-02-27 12:40:05 ----D---- C:\ProgramData\Adobe 2016-02-27 12:39:23 ----D---- C:\ProgramData\Package Cache 2016-02-27 12:39:07 ----SHDC---- C:\Config.Msi 2016-02-27 12:39:07 ----SHD---- C:\Windows\Installer 2016-02-26 08:55:44 ----DC---- C:\games 2016-02-25 20:03:44 ----D---- C:\Windows\Tasks 2016-02-25 20:03:44 ----D---- C:\Windows\system32\Tasks 2016-02-25 19:34:19 ----D---- C:\Windows\system32\WDI 2016-02-25 14:12:57 ----RSD---- C:\Windows\assembly 2016-02-25 10:48:55 ----D---- C:\ProgramData\regid.1991-06.com.microsoft 2016-02-25 10:48:23 ----DC---- C:\Program Files (x86)\Microsoft Office 2016-02-24 21:25:18 ----RSD---- C:\Windows\Fonts 2016-02-24 21:25:18 ----DC---- C:\Program Files (x86)\Dropbox 2016-02-24 19:41:57 ----DC---- C:\Program Files (x86)\Microsoft.NET 2016-02-24 19:38:43 ----DC---- C:\Program Files\Common Files\microsoft shared 2016-02-23 20:03:41 ----DC---- C:\Program Files\Internet Explorer 2016-02-23 20:03:17 ----HDC---- C:\Program Files (x86)\InstallShield Installation Information 2016-02-23 19:58:46 ----RDC---- C:\AdwCleaner 2016-02-23 17:29:21 ----D---- C:\Windows\system32\drivers 2016-02-23 17:29:20 ----D---- C:\Windows 2016-02-23 17:28:59 ----D---- C:\Windows\system32\CatRoot 2016-02-22 18:52:10 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll 2016-02-22 18:52:02 ----DC---- C:\Program Files (x86)\Java 2016-02-22 18:51:35 ----D---- C:\Windows\SYSWOW64\RTCOM 2016-02-22 18:51:34 ----D---- C:\Windows\INF 2016-02-22 18:51:33 ----D---- C:\Windows\system32\DriverStore 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtkCoLDR64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtkCfg64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RtkApi64.dll 2016-02-22 18:51:21 ----A---- C:\Windows\system32\RltkAPO64.dll 2016-02-19 19:38:51 ----SD---- C:\Users\Arthur\AppData\Roaming\Microsoft 2016-02-18 20:31:55 ----D---- C:\Windows\twain_32 2016-02-17 17:50:16 ----D---- C:\Windows\WinSxS 2016-02-15 21:49:44 ----D---- C:\Windows\CbsTemp 2016-02-15 21:48:49 ----D---- C:\Windows\system32\catroot2 2016-02-14 17:56:29 ----D---- C:\Windows\rescache 2016-02-14 12:51:51 ----D---- C:\Windows\Setup 2016-02-14 12:49:44 ----D---- C:\ProgramData\Skype 2016-02-14 12:49:43 ----D---- C:\Users\Arthur\AppData\Roaming\Skype 2016-02-14 12:04:28 ----DC---- C:\Program Files\Common Files 2016-02-14 11:39:45 ----DC---- C:\Program Files\Windows Journal 2016-02-14 11:39:45 ----D---- C:\Windows\system32\nl-NL 2016-02-14 11:39:16 ----DC---- C:\Program Files (x86)\Mozilla Maintenance Service 2016-02-12 16:19:15 ----DC---- C:\Program Files (x86)\Mozilla Firefox 2016-02-10 20:43:27 ----D---- C:\Windows\Logs 2016-02-09 13:19:08 ----DC---- C:\Program Files (x86)\Google 2016-02-09 10:10:28 ----D---- C:\Windows\Minidump 2016-02-08 20:15:56 ----D---- C:\Windows\SYSWOW64\drivers 2016-02-08 20:12:39 ----D---- C:\ProgramData\AVAST Software 2016-02-07 10:07:36 ----D---- C:\Windows\SoftwareDistribution 2016-02-04 20:38:04 ----D---- C:\Windows\system32\appmgmt 2016-02-04 18:37:50 ----D---- C:\ProgramData\Microsoft Help 2016-02-04 18:37:38 ----D---- C:\Windows\ShellNew 2016-02-04 18:37:11 ----A---- C:\Windows\win.ini 2016-02-03 16:17:16 ----D---- C:\Windows\system32\LogFiles 2016-02-03 13:23:51 ----D---- C:\Users\Arthur\AppData\Roaming\Steganos VPN 2016-02-03 13:22:26 ----D---- C:\Users\Arthur\AppData\Roaming\Steganos 2016-02-02 23:47:29 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe 2016-02-02 21:49:48 ----D---- C:\Windows\Panther 2016-02-02 21:49:48 ----D---- C:\Windows\ModemLogs 2016-02-02 21:49:48 ----D---- C:\Windows\debug 2016-02-02 20:48:14 ----D---- C:\Windows\ELAMBKUP 2016-02-01 18:08:27 ----D---- C:\ProgramData\GFACE 2016-01-31 20:57:45 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll 2016-01-31 20:57:45 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll 2016-01-31 17:44:21 ----D---- C:\Windows\SYSWOW64\en-US 2016-01-31 16:51:07 ----D---- C:\ProgramData\NVIDIA 2016-01-30 23:08:11 ----DC---- C:\Program Files (x86)\Internet Explorer 2016-01-30 23:08:11 ----D---- C:\Windows\SYSWOW64\nl-NL 2016-01-30 22:29:13 ----DC---- C:\Program Files (x86)\Pidgin ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 avc3;avc3; C:\Windows\system32\DRIVERS\avc3.sys [2016-01-22 1622512] R0 gzflt;gzflt; C:\Windows\system32\DRIVERS\gzflt.sys [2015-04-29 160032] R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2016-02-08 1462720] R0 ignis;ignis Service; C:\Windows\system32\DRIVERS\ignis.sys [2015-10-22 271808] R0 trufos;trufos; C:\Windows\system32\DRIVERS\trufos.sys [2015-06-02 477272] R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2015-12-30 15232] R1 bdfwfpf;bdfwfpf; \??\C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2015-12-03 115800] R1 BDVEDISK;BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [2015-12-04 87912] R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2015-07-10 83968] R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-12-01 8192] R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2016-02-08 26528] R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-07-10 48128] R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2014-08-19 36600] R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664] R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2015-07-10 61952] R3 dot4;@oem28.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2015-12-31 151968] R3 Dot4Print;@oem29.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2015-12-31 27040] R3 dot4usb;@oem28.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2015-12-31 49056] R3 e1dexpress;@oem69.inf,%e1dExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver D; C:\Windows\system32\DRIVERS\e1d65x64.sys [2016-02-08 531424] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-02-22 4705536] R3 MEIx64;@oem66.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverW8x64.sys [2016-02-08 185088] R3 NVHDA;@oem25.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-12-16 205456] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2015-12-18 12426896] R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2015-08-11 50472] R3 ScpVBus;@oem39.inf,%ScpVBus.SVCDESC%;Scp Virtual Bus Driver; C:\Windows\System32\drivers\ScpVBus.sys [2013-05-19 39168] R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2016-02-22 42600] R3 stdriver;SoundTap Filter Driver v6.08.01; C:\Windows\system32\DRIVERS\stdriverx64.sys [2016-02-19 34512] R3 tap0901;@oem41.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\System32\drivers\tap0901.sys [2016-02-03 27136] S0 bdelam;bdelam; C:\Windows\system32\drivers\bdelam.sys [2013-09-08 23568] S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-07-10 104800] S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-07-10 99168] S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-07-10 58208] S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-07-10 58720] S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2015-07-10 40288] S3 Apowersoft_AudioDevice;@oem75.inf,%DriverFile%;Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [2014-04-09 31920] S3 aswTap;@oem55.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\System32\drivers\aswTap.sys [2016-01-22 44640] S3 avckf;avckf; C:\Windows\system32\DRIVERS\avckf.sys [2016-01-22 806344] S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-09-17 36352] S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2015-07-10 116736] S3 cpuz139;cpuz139; \??\C:\Users\Arthur\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [2016-02-24 43312] S3 dg_ssudbus;@oem60.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-01-31 122160] S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\Windows\System32\drivers\e1i63x64.sys [2015-07-10 482328] S3 fcvsc;fcvsc; C:\Windows\System32\drivers\fcvsc.sys [2015-07-10 31232] S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-07-10 20992] S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-07-10 50016] S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-07-10 424800] S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-07-10 26624] S3 ManyCam;@oem56.inf,%ManyCam.DeviceDesc%;ManyCam Virtual Webcam; C:\Windows\system32\DRIVERS\mcvidrv.sys [2014-12-29 49272] S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-02-25 192216] S3 mcaudrv_simple;@oem57.inf,%mcaudrv_simple.SvcDesc%;ManyCam Virtual Microphone; C:\Windows\system32\drivers\mcaudrv_x64.sys [2014-12-29 35960] S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-07-10 705376] S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-07-10 76128] S3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-12-09 19576] S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2015-07-17 934752] S3 ssudmdm;@oem59.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-01-31 214832] S3 taphss6;@oem33.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\System32\drivers\taphss6.sys [2015-09-18 42088] S3 TIEHDUSB;@oem77.inf,%ServiceDesc%;TI Core USB Driver; C:\Windows\System32\drivers\tiehdusb.sys [2012-03-07 128512] S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\Windows\System32\Drivers\UcmCx.sys [2015-07-10 61952] S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\Windows\System32\drivers\UcmUcsi.sys [2015-07-14 46080] S3 UdeCx;USB Device Emulation Support Library; C:\Windows\system32\drivers\udecx.sys [2015-07-10 44032] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-13 82128] R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-02-04 2804976] R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856] R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2015-07-10 39856] R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2015-12-20 26168] R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2015-07-10 39856] R2 OneSyncSvc_Session1;Host synchroniseren_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2015-07-10 39856] R2 PRTGCoreService;PRTG Core Server Service; C:\Program Files (x86)\PRTG Network Monitor\64 bit\PRTG Server.exe [2016-02-23 9654360] R2 PRTGProbeService;PRTG Probe Service; C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe [2016-02-23 15537752] R2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2015-11-30 741056] R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856] R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-07-10 39856] R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856] R3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856] R3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\lsass.exe [2015-07-10 56344] R3 PimIndexMaintenanceSvc_Session1;Contact Data_Session1; C:\Windows\system32\svchost.exe [2015-07-10 39856] R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856] S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-09 154440] S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-07-10 39856] S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-07-10 39856] S2 OneSyncSvc_Session3;Host synchroniseren_Session3; C:\Windows\system32\svchost.exe [2015-07-10 39856] S2 ProductAgentService;Product Agent Service; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296] S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-06-17 43696] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-09 154440] S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-02-04 212176] S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 PimIndexMaintenanceSvc_Session3;Contact Data_Session3; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2015-07-10 39856] S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2015-07-12 1031680] S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2015-07-10 39856] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-02-04 835152] S4 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [2015-12-30 936728] S4 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [2014-07-23 1360016] S4 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136] S4 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-07-10 39856] S4 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-12-09 1156216] S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-05-28 16232] S4 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2014-03-11 260360] S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-12 146888] S4 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-12-09 1872504] S4 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2015-12-09 8185464] S4 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2015-12-09 6477432] S4 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-12-16 1256240] S4 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2015-05-21 743688] S4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-12-16 417584] -----------------EOF-----------------