Logfile of random's system information tool 1.10 (written by random/random) Run by Rita_2 at 2016-10-12 16:26:53 Microsoft Windows 7 Ultimate Service Pack 1 System drive C: has 361 GB (78%) free of 464 GB Total RAM: 3070 MB (63% free) ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler =========Mozilla firefox========= ProfilePath - C:\Users\Rita_2\AppData\Roaming\Mozilla\Firefox\Profiles\4ho5ngta.default "belgiumeid@eid.belgium.be"=C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 23.0.0.162 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_23_0_0_162.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0] "Description"=Picasa3 plugin "Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.21.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308] "Description"=WLPG Install MIME type "Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll C:\Program Files\Mozilla Firefox\extensions\ belgiumeid@eid.belgium.be C:\Users\Rita_2\AppData\Roaming\Mozilla\Firefox\Profiles\4ho5ngta.default\extensions\ flashgestures@patwonder ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56B38F40-4E70-11d4-A076-0080AD86BA2F}] WebCGMHlprObj Class - C:\Windows\system32\cgmopenbho.dll [2005-06-09 90112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29 460712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-08-05 194504] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1dac034-9fd9-4c13-a388-d2e10e57707f}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29 172968] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}] ChromeFrame BHO - C:\Program Files\Google\Chrome Frame\Application\31.0.1650.63\npchrome_frame.dll [2013-12-04 2103760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {d1dac034-9fd9-4c13-a388-d2e10e57707f} {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-08-05 194504] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040] "Nikon Message Center 2"=C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe [2013-12-27 570880] "HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152] ""= [] "HPUsageTracking"=C:\Program Files\Hewlett-Packard\HP UT\bin\hppusg.exe [2007-11-02 36864] "PrnStatusMX"=C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [2007-08-29 1077248] "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16 1156824] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2012-01-05 39408] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe PHOTOfunSTUDIO 8.0 LE.lnk - C:\Program Files\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe C:\Users\Rita_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "MSVideo8"=VfWWDM32.dll "msacm.siren"=sirenacm.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2016-10-12 16:26:53 ----D---- C:\rsit 2016-10-12 16:26:53 ----D---- C:\Program Files\trend micro 2016-10-12 14:45:36 ----D---- C:\Windows\system32\MRT 2016-10-12 14:44:43 ----AC---- C:\Windows\system32\MRT.exe 2016-09-22 15:32:31 ----A---- C:\Windows\system32\tzres.dll 2016-09-16 11:52:13 ----A---- C:\Windows\system32\ntkrnlpa.exe 2016-09-16 11:52:12 ----A---- C:\Windows\system32\ntoskrnl.exe 2016-09-16 11:52:12 ----A---- C:\Windows\system32\ntdll.dll 2016-09-16 11:52:12 ----A---- C:\Windows\system32\advapi32.dll 2016-09-16 11:52:11 ----A---- C:\Windows\system32\srcore.dll 2016-09-16 11:52:11 ----A---- C:\Windows\system32\appidsvc.dll 2016-09-16 11:52:11 ----A---- C:\Windows\system32\appidpolicyconverter.exe 2016-09-16 11:52:09 ----A---- C:\Windows\system32\wdigest.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\srclient.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\smss.exe 2016-09-16 11:52:09 ----A---- C:\Windows\system32\setbcdlocale.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\schannel.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\rstrui.exe 2016-09-16 11:52:09 ----A---- C:\Windows\system32\rpcrt4.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\ncrypt.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\msv1_0.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\lsasrv.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\kerberos.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\mrxsmb.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\drivers\appid.sys 2016-09-16 11:52:09 ----A---- C:\Windows\system32\csrsrv.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\appidcertstorecheck.exe 2016-09-16 11:52:09 ----A---- C:\Windows\system32\appidapi.dll 2016-09-16 11:52:09 ----A---- C:\Windows\system32\apisetschema.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\TSpkg.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\sspisrv.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\sspicli.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\secur32.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\rpchttp.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\msobjs.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\msaudite.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\lsass.exe 2016-09-16 11:52:08 ----A---- C:\Windows\system32\cryptbase.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\credssp.dll 2016-09-16 11:52:08 ----A---- C:\Windows\system32\auditpol.exe 2016-09-16 11:52:08 ----A---- C:\Windows\system32\adtschema.dll 2016-09-16 11:51:51 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe 2016-09-16 11:51:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-09-16 11:51:51 ----A---- C:\Windows\system32\inseng.dll 2016-09-16 11:51:51 ----A---- C:\Windows\system32\iernonce.dll 2016-09-16 11:51:51 ----A---- C:\Windows\system32\ieetwproxystub.dll 2016-09-16 11:51:51 ----A---- C:\Windows\system32\ieetwcollector.exe 2016-09-16 11:51:51 ----A---- C:\Windows\system32\ie4uinit.exe 2016-09-16 11:51:50 ----A---- C:\Windows\system32\urlmon.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\occache.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\msfeeds.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\jsproxy.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\jscript9diag.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\ieUnatt.exe 2016-09-16 11:51:50 ----A---- C:\Windows\system32\iedkcs32.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\ieapfltr.dll 2016-09-16 11:51:50 ----A---- C:\Windows\system32\dxtmsft.dll 2016-09-16 11:51:48 ----A---- C:\Windows\system32\webcheck.dll 2016-09-16 11:51:48 ----A---- C:\Windows\system32\msrating.dll 2016-09-16 11:51:47 ----A---- C:\Windows\system32\wininet.dll 2016-09-16 11:51:47 ----A---- C:\Windows\system32\iesetup.dll 2016-09-16 11:51:47 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2016-09-16 11:51:46 ----A---- C:\Windows\system32\dxtrans.dll 2016-09-16 11:51:45 ----A---- C:\Windows\system32\ieui.dll 2016-09-16 11:51:45 ----A---- C:\Windows\system32\ieframe.dll 2016-09-16 11:51:43 ----A---- C:\Windows\system32\mshtmled.dll 2016-09-16 11:51:42 ----A---- C:\Windows\system32\mshtmlmedia.dll 2016-09-16 11:51:42 ----A---- C:\Windows\system32\MshtmlDac.dll 2016-09-16 11:51:41 ----A---- C:\Windows\system32\iertutil.dll 2016-09-16 11:51:39 ----A---- C:\Windows\system32\mshtml.dll 2016-09-16 11:51:38 ----A---- C:\Windows\system32\jscript9.dll 2016-09-16 11:51:36 ----A---- C:\Windows\system32\vbscript.dll 2016-09-16 11:51:36 ----A---- C:\Windows\system32\jscript.dll 2016-09-16 11:50:49 ----A---- C:\Windows\system32\win32k.sys 2016-09-16 11:50:48 ----A---- C:\Windows\system32\user32.dll 2016-09-16 11:50:48 ----A---- C:\Windows\system32\drivers\srvnet.sys 2016-09-16 11:50:48 ----A---- C:\Windows\system32\drivers\srv2.sys 2016-09-16 11:50:48 ----A---- C:\Windows\system32\drivers\srv.sys 2016-09-16 11:50:47 ----A---- C:\Windows\system32\oleaut32.dll ======List of files/folders modified in the last 1 month====== 2016-10-12 16:26:58 ----D---- C:\Windows\Prefetch 2016-10-12 16:26:54 ----D---- C:\Windows\Temp 2016-10-12 16:26:53 ----RD---- C:\Program Files 2016-10-12 16:03:08 ----D---- C:\Windows\system32\config 2016-10-12 15:01:32 ----SHD---- C:\Windows\Installer 2016-10-12 15:01:31 ----SHD---- C:\Config.Msi 2016-10-12 15:01:06 ----D---- C:\Windows\System32 2016-10-12 14:56:31 ----D---- C:\Windows\system32\NDF 2016-10-12 14:45:36 ----D---- C:\Windows\debug 2016-10-12 14:44:33 ----D---- C:\Program Files\Microsoft Office 2016-10-12 14:44:10 ----SHD---- C:\System Volume Information 2016-10-11 19:05:28 ----A---- C:\Windows\win.ini 2016-10-08 13:22:49 ----D---- C:\Windows\Minidump 2016-10-08 13:22:39 ----D---- C:\Windows 2016-09-28 21:31:24 ----D---- C:\Windows\system32\Tasks 2016-09-25 09:13:32 ----D---- C:\Windows\inf 2016-09-25 09:13:32 ----A---- C:\Windows\system32\PerfStringBackup.INI 2016-09-23 15:54:58 ----D---- C:\Windows\rescache 2016-09-22 17:06:14 ----D---- C:\Windows\winsxs 2016-09-22 17:06:02 ----D---- C:\Windows\system32\en-US 2016-09-16 12:15:54 ----D---- C:\Windows\system32\drivers 2016-09-16 12:15:49 ----D---- C:\Program Files\Internet Explorer 2016-09-16 12:13:37 ----D---- C:\ProgramData\Microsoft Help 2016-09-16 12:11:12 ----D---- C:\Program Files\Microsoft Silverlight 2016-09-16 11:49:20 ----D---- C:\Windows\system32\catroot2 2016-09-14 18:18:10 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2016-09-14 18:18:08 ----D---- C:\Windows\system32\Macromed ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2010-06-17 14392] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360] R1 {26d264d2-014c-4f07-bf2c-ebf9aed40cef}w;{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w; C:\Windows\system32\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w.sys [2014-04-24 52920] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-14 1096704] S0 AFS;AFS; C:\Windows\system32\drivers\AFS.sys [2015-10-25 77004] S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312] S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-28 6465024] S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-10-28 228352] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2010-09-24 102416] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272] S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\Windows\system32\DRIVERS\HPZid412.sys [2009-02-26 49920] S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\Windows\system32\DRIVERS\HPZipr12.sys [2009-02-26 16496] S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\Windows\system32\DRIVERS\HPZius12.sys [2003-03-09 21456] S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176] S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbo.sys [2011-08-17 23168] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-06-11 15872] S3 RT-USB;Ross-Tech USB driver; C:\Windows\system32\drivers\RT-USB.SYS [2010-06-16 59464] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032] S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224] S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [] S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2011-08-17 8192] S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\drivers\usb8023x.sys [2013-02-12 15872] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352] S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 28160] S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2011-08-17 8192] S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920] S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-16 82128] R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 iOSinstallerUpdater;iOSinstallerUpdater; C:\Program Files\iOSinstaller\updater.exe [2015-04-08 165376] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 gupdate;Google Updateservice (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-05 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-14 270016] S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-05 136176] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-25 194032] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-01 102912] S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [2016-07-19 270600] S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-13 148080] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-24 1343400] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] -----------------EOF-----------------