Logfile of random's system information tool 1.10 (written by random/random) Run by CvS at 2016-11-03 10:36:49 Microsoft Windows 7 Starter Service Pack 1 System drive C: has 56 GB (46%) free of 121 GB Total RAM: 2048 MB (31% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:37:29, on 3-11-2016 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.18283) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Trend Micro\DRScanner\DRScanner.exe C:\Program Files\Glary Utilities 5\Integrator.exe C:\Windows\System32\rundll32.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\CvS\Desktop\RSIT.exe C:\Program Files\trend micro\CvS.exe C:\Program Files\Glary Utilities 5\SoftwareUpdate.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (file missing) O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office16\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (file missing) O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - .DEFAULT User Startup: RUN.CMD (User 'Default user') O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office16\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office16\EXCEL.EXE/3000 O10 - Broken Internet access because of LSP provider 'c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll' missing O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Unknown owner - C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe (file missing) O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Avast Firewall (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe O23 - Service: BitDefenderCOM - Digital Care Solutions - C:\Program Files\BDServices\BitDefenderCom.exe O23 - Service: Clean Master Core Service (cmcore) - Kingsoft Corporation - c:\program files\cmcm\Clean Master\cmcore.exe O23 - Service: Dropbox-update-service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files\Dropbox\Update\DropboxUpdate.exe O23 - Service: Dropbox-update-service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files\Dropbox\Update\DropboxUpdate.exe O23 - Service: DbxSvc - Dropbox, Inc. - C:\Windows\system32\DbxSvc.exe O23 - Service: MBAMService - Malwarebytes - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe -- End of file - 4522 bytes ======Scheduled tasks folder====== C:\Windows\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files\Dropbox\Update\DropboxUpdate.exe /c C:\Windows\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler =========Mozilla firefox========= ProfilePath - C:\Users\CvS\AppData\Roaming\Mozilla\Firefox\Profiles\n5b27ig3.default "web2pdfextension@web2pdf.adobedotcom"=C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn "sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF "wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 23.0.0.205 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_23_0_0_205.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.111.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.111.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.1] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Acrobat] "Description"=Handles PDFs in-place in Firefox "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll C:\Program Files\Mozilla Firefox\plugins\ nppdf32.dll nppdf32.NLD ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-10-31 473152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-30 664848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}] Adobe Acrobat Create PDF Helper - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office16\URLREDIR.DLL [2015-07-31 403672] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-31 186944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}] Adobe Acrobat Create PDF from Selection - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-10-30 9099440] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe [2015-09-16 6495144] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmsc] c:\program files\cmcm\Clean Master\cmtray.exe [2016-11-01 771912] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dropbox] C:\Program Files\Dropbox\Client\Dropbox.exe [2016-10-24 25424008] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup] C:\Program Files\Glary Utilities 5\StartupManager.exe [2016-10-21 43984] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMSwissArmy] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoResolveSearch"=1 "NoResolveTrack"=1 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=255 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .ini - open - "%SystemRoot%\system32\NOTEPAD.EXE" %1 .js - edit - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" .txt - open - "%SystemRoot%\system32\NOTEPAD.EXE" %1 ======List of files/folders created in the last 1 month====== 2016-11-03 10:36:49 ----D---- C:\rsit 2016-11-03 10:33:02 ----D---- C:\Program Files\WinPcap 2016-11-02 22:17:06 ----SHD---- C:\Config.Msi 2016-11-02 22:15:28 ----D---- C:\ProgramData\ProductData 2016-11-02 15:00:29 ----D---- C:\Windows\system32\catroot2 2016-11-02 13:24:18 ----D---- C:\Windows\SoftwareDistribution 2016-11-02 00:28:09 ----A---- C:\Windows\Tweaking.com - Windows Repair Setup Log.txt 2016-11-01 13:41:49 ----D---- C:\ec7b58d62884da941082f35987 2016-11-01 13:39:41 ----D---- C:\ProgramData\Kingsoft 2016-11-01 13:06:18 ----D---- C:\ProgramData\GlarySoft 2016-11-01 12:06:06 ----A---- C:\Windows\system32\drivers\GUBootStartup.sys 2016-11-01 12:06:05 ----D---- C:\Users\CvS\AppData\Roaming\GlarySoft 2016-11-01 12:05:55 ----D---- C:\Program Files\Glary Utilities 5 2016-11-01 00:25:54 ----A---- C:\Windows\system32\FNTCACHE.DAT 2016-11-01 00:07:50 ----D---- C:\ProgramData\cmcm 2016-11-01 00:07:44 ----A---- C:\Windows\system32\drivers\ksapi64.sys 2016-11-01 00:07:44 ----A---- C:\Windows\system32\drivers\ksapi.sys 2016-11-01 00:07:42 ----D---- C:\Program Files\cmcm 2016-10-31 23:32:05 ----A---- C:\log.txt 2016-10-31 23:29:49 ----A---- C:\ComboFix.txt 2016-10-31 23:21:10 ----SHD---- C:\$RECYCLE.BIN 2016-10-31 17:53:41 ----D---- C:\Windows\Trend Micro 2016-10-31 17:47:47 ----A---- C:\Windows\system32\drivers\tmcomm.sys 2016-10-31 17:36:24 ----D---- C:\ProgramData\Licenses 2016-10-31 17:36:05 ----A---- C:\Windows\system32\MSSTDFMT.DLL 2016-10-31 17:36:04 ----D---- C:\Program Files\SpywareBlaster 2016-10-31 00:20:09 ----D---- C:\Program Files\Common Files\Java 2016-10-31 00:00:51 ----A---- C:\Windows\system32\drivers\aswKbd.sys 2016-10-30 23:54:37 ----D---- C:\Users\CvS\AppData\Roaming\AVAST Software 2016-10-30 23:51:43 ----D---- C:\Program Files\Common Files\AV 2016-10-30 23:51:26 ----A---- C:\Windows\system32\drivers\aswStm.sys 2016-10-30 23:51:24 ----A---- C:\Windows\system32\drivers\aswvmm.sys 2016-10-30 23:51:24 ----A---- C:\Windows\system32\drivers\aswsp.sys 2016-10-30 23:51:23 ----A---- C:\Windows\system32\drivers\aswRvrt.sys 2016-10-30 23:51:22 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys 2016-10-30 23:51:22 ----A---- C:\Windows\system32\drivers\aswHwid.sys 2016-10-30 23:51:21 ----A---- C:\Windows\system32\drivers\aswRdr2.sys 2016-10-30 23:51:20 ----A---- C:\Windows\system32\drivers\aswsnx.sys 2016-10-30 23:51:19 ----A---- C:\Windows\system32\drivers\aswNetSec.sys 2016-10-30 23:50:50 ----A---- C:\Windows\ucrtbase.dll 2016-10-30 23:50:50 ----A---- C:\Windows\system32\aswBoot.exe 2016-10-30 23:50:34 ----A---- C:\Windows\avastSS.scr 2016-10-30 23:50:18 ----A---- C:\Windows\system32\drivers\aswNetNd6.sys 2016-10-30 23:49:11 ----D---- C:\Program Files\AVAST Software 2016-10-30 23:48:33 ----D---- C:\ProgramData\AVAST Software 2016-10-30 12:47:07 ----D---- C:\Program Files\Uninstall Information 2016-10-30 11:57:45 ----A---- C:\Windows\tweaking.com-regbackup-CVS-PC-Windows-7-Starter-(32-bit).dat 2016-10-30 11:57:19 ----D---- C:\RegBackup 2016-10-30 11:45:12 ----D---- C:\Program Files\Tweaking.com 2016-10-30 08:00:36 ----D---- C:\Program Files\Macromedia 2016-10-28 23:06:08 ----D---- C:\FRST 2016-10-27 18:30:43 ----ASH---- C:\pagefile.sys 2016-10-27 14:08:02 ----D---- C:\Users\CvS\AppData\Roaming\Efficient Software 2016-10-27 14:07:57 ----D---- C:\ProgramData\firebird 2016-10-27 14:07:41 ----D---- C:\Users\CvS\AppData\Roaming\Efficient Address Book 2016-10-27 13:56:05 ----D---- C:\Users\CvS\AppData\Roaming\EfficientPIM 2016-10-27 13:55:47 ----D---- C:\Program Files\Efficient Address Book 2016-10-26 16:38:18 ----A---- C:\Windows\system32\authuitu.dll 2016-10-26 16:38:14 ----A---- C:\Windows\system32\uxtuneup.dll 2016-10-26 11:10:56 ----A---- C:\Windows\system32\TURegOpt.exe 2016-10-25 16:03:54 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys 2016-10-25 16:00:36 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys 2016-10-24 16:37:28 ----D---- C:\Users\CvS\AppData\Roaming\tixati 2016-10-24 16:37:05 ----D---- C:\Program Files\tixati 2016-10-24 14:06:26 ----A---- C:\Windows\system32\DbxSvc.exe 2016-10-24 14:06:10 ----A---- C:\Windows\system32\drivers\dbx-stable.sys 2016-10-24 14:06:10 ----A---- C:\Windows\system32\drivers\dbx-dev.sys 2016-10-24 14:06:10 ----A---- C:\Windows\system32\drivers\dbx-canary.sys 2016-10-21 16:17:36 ----D---- C:\Program Files\Mozilla Firefox 2016-10-13 15:45:22 ----D---- C:\Users\CvS\AppData\Roaming\NotepadPlusPlusApp 2016-10-10 08:30:41 ----A---- C:\Windows\zip.exe 2016-10-10 08:30:41 ----A---- C:\Windows\SWSC.exe 2016-10-10 08:30:41 ----A---- C:\Windows\SWREG.exe 2016-10-10 08:30:41 ----A---- C:\Windows\sed.exe 2016-10-10 08:30:41 ----A---- C:\Windows\PEV.exe 2016-10-10 08:30:41 ----A---- C:\Windows\NIRCMD.exe 2016-10-10 08:30:41 ----A---- C:\Windows\MBR.exe 2016-10-10 08:30:41 ----A---- C:\Windows\grep.exe 2016-10-09 12:10:24 ----D---- C:\Program Files\Notepad++ 2016-10-04 09:52:20 ----D---- C:\xamp ======List of files/folders modified in the last 1 month====== 2016-11-03 10:37:29 ----D---- C:\Program Files\trend micro 2016-11-03 10:37:22 ----D---- C:\Windows\System32 2016-11-03 10:37:22 ----D---- C:\Windows\inf 2016-11-03 10:37:22 ----A---- C:\Windows\system32\PerfStringBackup.INI 2016-11-03 10:37:02 ----D---- C:\Windows\Prefetch 2016-11-03 10:35:57 ----D---- C:\Windows\system32\config 2016-11-03 10:35:10 ----D---- C:\Windows\temp 2016-11-03 10:33:08 ----D---- C:\Windows\system32\drivers 2016-11-03 10:33:02 ----RD---- C:\Program Files 2016-11-03 01:07:01 ----SD---- C:\ProgramData\Microsoft 2016-11-03 01:05:56 ----SD---- C:\Users\CvS\AppData\Roaming\Microsoft 2016-11-03 01:04:44 ----D---- C:\Windows\Tasks 2016-11-03 01:04:44 ----D---- C:\Windows\system32\Tasks 2016-11-03 00:39:54 ----D---- C:\ProgramData 2016-11-03 00:39:54 ----D---- C:\Program Files\Common Files 2016-11-02 22:18:57 ----SHD---- C:\Windows\Installer 2016-11-02 22:17:39 ----D---- C:\Windows\system32\Macromed 2016-11-02 14:10:40 ----SHD---- C:\System Volume Information 2016-11-02 13:24:18 ----D---- C:\Windows 2016-11-02 04:21:48 ----D---- C:\Windows\winsxs 2016-11-02 04:09:32 ----D---- C:\Windows\system32\drivers\etc 2016-11-02 03:55:36 ----D---- C:\Windows\system32\wbem 2016-11-01 15:26:03 ----D---- C:\Users\CvS\AppData\Roaming\Mozilla 2016-11-01 13:35:02 ----D---- C:\Program Files\Dropbox 2016-11-01 13:31:30 ----D---- C:\Program Files\BDServices 2016-11-01 13:31:29 ----D---- C:\Windows\debug 2016-11-01 13:30:25 ----D---- C:\Windows\pss 2016-11-01 13:11:14 ----D---- C:\Users\CvS\AppData\Roaming\Macromedia 2016-11-01 13:11:12 ----D---- C:\Users\CvS\AppData\Roaming\Apple Computer 2016-11-01 13:11:11 ----D---- C:\Users\CvS\AppData\Roaming\.Tribler 2016-11-01 13:11:04 ----D---- C:\TEMP 2016-11-01 13:11:04 ----D---- C:\SnelStart 2016-11-01 13:10:48 ----D---- C:\ProgramData\Trend Micro 2016-11-01 13:10:47 ----D---- C:\ProgramData\IObit 2016-11-01 13:10:46 ----D---- C:\Program Files\Windows Media Player 2016-11-01 13:10:46 ----D---- C:\Program Files\Google 2016-11-01 13:10:46 ----D---- C:\DTLFolder 2016-11-01 12:54:04 ----D---- C:\Windows\Downloaded Program Files 2016-11-01 12:52:00 ----D---- C:\Windows\Minidump 2016-11-01 11:45:35 ----D---- C:\Users\CvS\AppData\Roaming\FileZilla 2016-11-01 10:42:29 ----D---- C:\ProgramData\boost_interprocess 2016-11-01 00:25:46 ----D---- C:\Windows\tracing 2016-10-31 23:29:54 ----D---- C:\Qoobox 2016-10-31 23:21:25 ----A---- C:\Windows\system.ini 2016-10-31 23:03:05 ----D---- C:\Windows\erdnt 2016-10-31 22:55:50 ----D---- C:\Windows\AppPatch 2016-10-31 22:13:06 ----D---- C:\AdwCleaner 2016-10-31 00:18:53 ----A---- C:\Windows\system32\WindowsAccessBridge.dll 2016-10-31 00:18:09 ----D---- C:\Program Files\Java 2016-10-30 23:53:16 ----D---- C:\Windows\system32\DriverStore 2016-10-30 23:52:42 ----RSD---- C:\Windows\Fonts 2016-10-30 23:03:46 ----D---- C:\ProgramData\MFAData 2016-10-30 11:24:18 ----D---- C:\Program Files\Common Files\Macromedia 2016-10-30 08:00:05 ----D---- C:\Windows\Downloaded Installations 2016-10-29 14:14:50 ----D---- C:\Windows\system32\NDF 2016-10-29 11:30:59 ----D---- C:\Users\CvS\AppData\Roaming\PhotoScape 2016-10-28 17:16:09 ----D---- C:\Users\CvS\AppData\Roaming\TweetAdder3 2016-10-28 16:39:43 ----D---- C:\Windows\IME 2016-10-28 10:47:55 ----D---- C:\ProgramData\Microsoft Help 2016-10-27 15:29:06 ----D---- C:\Local Publish 2016-10-27 09:51:06 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2016-10-25 16:16:59 ----D---- C:\Mijn Web paginas 2016-10-23 16:05:05 ----D---- C:\Program Files\Mozilla Maintenance Service 2016-10-23 16:01:24 ----D---- C:\Users\CvS\AppData\Roaming\vlc 2016-10-23 13:03:40 ----D---- C:\Users\CvS\AppData\Roaming\Notepad++ 2016-10-13 17:41:27 ----D---- C:\Windows\schemas 2016-10-13 17:39:31 ----D---- C:\Program Files\KMSpico.uit 2016-10-12 14:33:17 ----D---- C:\Program Files\FileZilla FTP Client 2016-10-09 12:03:16 ----D---- C:\Users\CvS\AppData\Roaming\com.oxygenxml 2016-10-09 12:02:43 ----D---- C:\Windows\Logs 2016-10-07 22:27:01 ----D---- C:\output ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-10-30 60424] R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-10-30 224752] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-01-12 355352] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-10-31 35096] R1 aswNetSec;aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [2016-10-30 338936] R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-10-30 91232] R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-10-30 735488] R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-10-30 433768] R1 GUBootStartup;GUBootStartup; \??\C:\Windows\System32\drivers\GUBootStartup.sys [2016-11-01 17472] R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2016-09-19 23840] R1 PQNTDrv;PQNTDrv; C:\Windows\system32\drivers\PQNTDrv.sys [2004-05-05 4228] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128] R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-10-30 92256] R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-10-30 118664] R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-09-02 48128] R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-09-02 44544] R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2016-09-19 38400] R3 aswNetNd6;Avast Firewall NDIS6 Helper; C:\Windows\system32\DRIVERS\aswNetNd6.sys [2016-10-30 26776] R3 BCM43XX;Stuurprogramma voor de Broadcom 802.11-netwerkadapter; C:\Windows\system32\DRIVERS\bcmwl6.sys [2016-09-19 7058680] R3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-06-18 3240400] R3 ksapi;ksapi; \??\C:\Windows\system32\drivers\ksapi.sys [2016-11-01 81768] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 24448] R3 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2014-08-19 36600] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2016-09-19 771328] R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992] R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-01-21 234800] S1 MpKslf35924df;MpKslf35924df; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F894F6C0-4352-48EF-9E52-902E4243BA06}\MpKslf35924df.sys [] S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704] S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312] S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-10-30 34008] S3 b06diag;Broadcom NetXtreme II Diag Driver; C:\Windows\system32\drivers\bxdiagx.sys [2012-03-08 75816] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888] S3 BFN7x86;Bigfoot Networks Killer Gaming Service; C:\Windows\system32\drivers\Xeno7x86.sys [2012-02-22 130152] S3 BFNVis32;Bigfoot Networks Killer Gaming Service; C:\Windows\system32\drivers\XenoVx86.sys [2012-02-22 130152] S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336] S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816] S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696] S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2014-11-29 393728] S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2014-11-29 60416] S3 bxfcoe;bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [2012-02-22 150568] S3 bxois;bxois; C:\Windows\system32\drivers\bxois.sys [2012-02-22 435240] S3 dbx;dbx; C:\Windows\system32\DRIVERS\dbx.sys [] S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072] S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384] S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Scan.sys [2009-07-14 10752] S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864] S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2016-10-25 26168] S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2016-10-25 40504] S3 IFCoEMP;IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys [2012-04-21 334096] S3 IFCoEVB;IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys [2012-04-21 69392] S3 ioatdma1;ioatdma1; C:\Windows\System32\Drivers\qd16032.sys [2009-11-16 36552] S3 ioatdma2;Intel(R) QuickData Technology device ver.2; C:\Windows\System32\Drivers\qd26032.sys [2009-11-16 37576] S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-11-01 170200] S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 53120] S3 Partizan;Partizan; C:\Windows\system32\drivers\Partizan.sys [2016-08-09 40304] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-11-29 14848] S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304] S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-11-29 24064] S3 Trufos;Trufos; C:\Windows\system32\DRIVERS\Trufos.sys [2016-06-14 408280] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2014-11-29 49152] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-11-29 26880] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-10-30 197128] R2 avast! Firewall;Avast Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2016-10-30 223600] R2 BitDefenderCOM;BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [2016-06-24 759296] R2 cmcore;Clean Master Core Service; c:\program files\cmcm\Clean Master\cmcore.exe [2016-11-01 315208] R2 DbxSvc;DbxSvc; C:\Windows\system32\DbxSvc.exe [2016-10-24 35440] R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-01-29 678968] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144] S2 dbupdate;Dropbox-update-service (dbupdate); C:\Program Files\Dropbox\Update\DropboxUpdate.exe [2015-11-03 136048] S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-27 270016] S3 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [] S3 dbupdatem;Dropbox-update-service (dbupdatem); C:\Program Files\Dropbox\Update\DropboxUpdate.exe [2015-11-03 136048] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-03-31 102912] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 202928] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-07-30 4846168] S3 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992] S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [] S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-11-05 45744] S4 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2016-04-22 2960160] S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-10-21 172488] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848] -----------------EOF-----------------