Logfile of random's system information tool 1.09 (written by random/random)
Run by Rob at 2014-03-06 14:32:17
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 16 GB (18%) free of 86 GB
Total RAM: 3454 MB (37% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-905063731-74274285-34031197-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-905063731-74274285-34031197-1000UA.job
C:\Windows\tasks\One-Click Optimizer.job
C:\Windows\tasks\PC Fresh.job
C:\Windows\tasks\SpeedyPC Pro Startup.job
C:\Windows\tasks\SpeedyPC Pro.job
C:\Windows\tasks\SpeedyPC Registration3.job
C:\Windows\tasks\SpeedyPC Update Version3 Startup Task.job
C:\Windows\tasks\SpeedyPC Update Version3.job
======Registry dump======
IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\8.8\iobitappsToolbarIE.dll
ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
AccelerateTab - C:\PROGRA~1\Secure Speed Dial\IE\SpeedDial.dll
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll
ChromeFrame BHO - C:\Program Files\Google\Chrome Frame\Application\32.0.1700.107\npchrome_frame.dll
Adblock - C:\Program Files\Secure Speed Dial\IE\ADBlock\IE\Adblock.dll
!{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\8.8\iobitappsToolbarIE.dll
“RTHDVCPL”=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
“Ashampoo WinOptimizer Live-Tuner”=C:\Program Files\Ashampoo\Ashampoo WinOptimizer 10\LiveTuner.exe
“”=
“G Data AntiVirus Tray”=C:\Program Files\G Data\InternetSecurity\AVKTray\AVKTray.exe
“GDFirewallTray”=C:\Program Files\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
“Sidebar”=C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Silvercrest MTS2118 driver\StartAutorun.exe
C:\Program Files\GO!Suite\Deployment\Functions\{AA58F999-6D97-42c2-A69F-8CC04D18D944}\OMEA.exe
C:\Program Files\OTB_util\OTB_util.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\USIM Editor\iconcs746203.exe
SDWinLogon.dll
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
“{B5A7F190-DDA6-4420-B3BA-52453494E6CD}”=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
“SecurityProviders”=credssp.dll
“EnableUIADesktopToggle”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“undockwithoutlogon”=1
“ShutdownWithoutLogon”=0
“NoDispCPL”=0
“NoDispSettingsPage”=0
“NoDispScrSavPage”=0
“ConsentPromptBehaviorAdmin”=5
“NoInstrumentation”=1
“NoDriveTypeAutoRun”=145
“NoResolveSearch”=1
“NoResolveTrack”=1
“NoViewContextMenu”=0
“NoFileAssociate”=0
“NoRun”=0
“NoClose”=0
“StartMenuLogoff”=0
“NoResolveTrack”=1
“C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe”=“C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon”
“C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe”=“C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service”
“C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe”=“C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater”
“C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe”=“C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service”
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“VIDC.UYVY”=msyuv.dll
“VIDC.YUY2”=msyuv.dll
“VIDC.YVYU”=msyuv.dll
“VIDC.IYUV”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“VIDC.YVU9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“vidc.cvid”=iccvid.dll
“MSVideo8”=VfWWDM32.dll
“wave1”=wdmaud.drv
“mixer1”=wdmaud.drv
“wave2”=wdmaud.drv
“mixer2”=wdmaud.drv
“wave3”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer3”=wdmaud.drv
“aux1”=wdmaud.drv
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
“wave4”=wdmaud.drv
“midi2”=wdmaud.drv
“mixer4”=wdmaud.drv
“aux2”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - NOTEPAD.EXE “%1”
.reg - open - NOTEPAD.EXE “%1”
.scr - open - “C:\Windows\system32\notepad.exe” “%1”
.scr - install -
.scr - config -
.vbs - open - NOTEPAD.EXE “%1”
======List of files/folders created in the last 1 month======
2014-03-06 14:32:18 —-D—- C:\Program Files\trend micro
2014-03-06 14:32:16 —-D—- C:\rsit
2014-03-04 21:40:34 —-A—- C:\Windows\system32\drivers\PktIcpt.sys
2014-03-04 21:38:26 —-A—- C:\Windows\system32\drivers\gdwfpcd32.sys
2014-03-04 21:38:17 —-A—- C:\Windows\system32\drivers\HookCentre.sys
2014-03-04 21:38:16 —-A—- C:\Windows\system32\drivers\MiniIcpt.sys
2014-03-04 21:38:16 —-A—- C:\Windows\system32\drivers\GDBehave.sys
2014-03-04 17:50:40 —-D—- C:\Program Files\Application Updater
2014-03-04 17:50:39 —-D—- C:\Program Files\IObit Apps Toolbar
2014-03-04 16:46:34 —-A—- C:\Windows\system32\sdnclean.exe
2014-03-04 16:46:28 —-D—- C:\ProgramData\Spybot - Search & Destroy
2014-03-04 16:46:10 —-D—- C:\Program Files\Spybot - Search & Destroy 2
2014-02-28 20:41:47 —-A—- C:\Windows\system32\FlashPlayerApp.exe
2014-02-27 15:41:01 —-D—- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-02-27 15:10:04 —-D—- C:\Windows\Migration
2014-02-22 10:27:29 —-D—- C:\backup
2014-02-20 13:17:46 —-D—- C:\Users\Rob\AppData\Roaming\Spotify
2014-02-19 12:58:18 —-D—- C:\Windows\Replay Music 6
2014-02-19 12:58:17 —-D—- C:\Program Files\Replay Music 6
2014-02-16 22:14:14 —-A—- C:\Windows\system32\ieui.dll
2014-02-16 22:14:14 —-A—- C:\Windows\system32\ie4uinit.exe
2014-02-16 22:14:13 —-A—- C:\Windows\system32\msrating.dll
2014-02-16 22:14:13 —-A—- C:\Windows\system32\jsproxy.dll
2014-02-16 22:14:13 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2014-02-16 22:14:12 —-A—- C:\Windows\system32\ieUnatt.exe
2014-02-16 22:14:12 —-A—- C:\Windows\system32\iesetup.dll
2014-02-16 22:14:12 —-A—- C:\Windows\system32\iernonce.dll
2014-02-16 22:14:12 —-A—- C:\Windows\system32\ieetwproxystub.dll
2014-02-16 22:14:11 —-A—- C:\Windows\system32\jscript9diag.dll
2014-02-16 22:14:11 —-A—- C:\Windows\system32\ieetwcollector.exe
2014-02-16 22:14:11 —-A—- C:\Windows\system32\ieapfltr.dll
2014-02-16 22:14:10 —-A—- C:\Windows\system32\msfeeds.dll
2014-02-16 22:14:09 —-A—- C:\Windows\system32\wininet.dll
2014-02-16 22:14:09 —-A—- C:\Windows\system32\iertutil.dll
2014-02-16 22:14:08 —-A—- C:\Windows\system32\urlmon.dll
2014-02-16 22:14:07 —-A—- C:\Windows\system32\ieframe.dll
2014-02-16 22:14:06 —-A—- C:\Windows\system32\mshtml.dll
2014-02-16 22:14:05 —-A—- C:\Windows\system32\jscript9.dll
2014-02-16 11:14:23 —-A—- C:\Windows\system32\msxml3r.dll
2014-02-16 11:14:23 —-A—- C:\Windows\system32\msxml3.dll
2014-02-15 12:18:45 —-A—- C:\Windows\system32\FNTCACHE.DAT
2014-02-14 10:38:09 —-A—- C:\Windows\system32\drivers\GdPhyMem.sys
2014-02-13 07:32:12 —-A—- C:\Windows\system32\vbscript.dll
2014-02-12 23:29:57 —-D—- C:\Users\Rob\AppData\Roaming\G Data
2014-02-12 23:26:05 —-D—- C:\Program Files\G Data
2014-02-12 23:26:00 —-D—- C:\Program Files\Common Files\G Data
2014-02-12 23:19:00 —-D—- C:\ProgramData\G Data
2014-02-12 22:31:05 —-A—- C:\Windows\system32\d3d10warp.dll
2014-02-12 22:31:05 —-A—- C:\Windows\system32\d2d1.dll
2014-02-12 22:31:02 —-A—- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 22:31:02 —-A—- C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 22:31:02 —-A—- C:\Windows\system32\RMActivate_isv.exe
2014-02-12 22:31:02 —-A—- C:\Windows\system32\RMActivate.exe
2014-02-12 22:31:01 —-A—- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 22:31:01 —-A—- C:\Windows\system32\secproc_ssp.dll
2014-02-12 22:31:01 —-A—- C:\Windows\system32\secproc_isv.dll
2014-02-12 22:31:01 —-A—- C:\Windows\system32\secproc.dll
2014-02-12 22:31:01 —-A—- C:\Windows\system32\msdrm.dll
2014-02-12 15:13:08 —-D—- C:\Windows\IswTmp
2014-02-12 14:47:04 —-D—- C:\Users\Rob\AppData\Roaming\CheckPoint
2014-02-12 14:46:50 —-A—- C:\Windows\system32\drivers\kl1.sys
2014-02-12 14:46:47 —-A—- C:\Windows\system32\drivers\klif.sys
2014-02-12 14:46:47 —-A—- C:\Windows\system32\drivers\klflt.sys
2014-02-12 14:31:42 —-D—- C:\Program Files\CheckPoint
2014-02-12 14:26:37 —-D—- C:\ProgramData\CheckPoint
2014-02-11 18:03:21 —-D—- C:\Users\Rob\AppData\Roaming\AVG2014
2014-02-11 18:02:26 —-D—- C:\ProgramData\AVG2014
2014-02-11 10:41:21 —-A—- C:\Windows\system32\GDIPFONTCACHEV1.DAT
======List of files/folders modified in the last 1 month======
2014-03-06 14:32:18 —-RD—- C:\Program Files
2014-03-06 14:32:16 —-D—- C:\Windows\temp
2014-03-06 14:12:42 —-D—- C:\Windows\system32\catroot2
2014-03-06 14:12:42 —-D—- C:\Windows
2014-03-06 13:48:01 —-D—- C:\ProgramData\MFAData
2014-03-06 13:22:22 —-D—- C:\Windows\system32\config
2014-03-06 12:50:09 —-D—- C:\Windows\system32\Tasks
2014-03-06 08:18:21 —-D—- C:\Program Files\Opera
2014-03-06 08:18:20 —-D—- C:\ProgramData\LogMeIn
2014-03-06 07:19:17 —-D—- C:\Windows\SoftwareDistribution
2014-03-06 07:15:13 —-D—- C:\Users\Rob\AppData\Roaming\iolo
2014-03-05 22:37:20 —-D—- C:\Users\Rob\AppData\Roaming\Opera Software
2014-03-05 22:30:18 —-SHD—- C:\Boot
2014-03-05 16:12:01 —-D—- C:\Program Files\Handbrake
2014-03-05 13:24:46 —-SHD—- C:\Windows\Installer
2014-03-05 13:23:44 —-D—- C:\Windows\System32
2014-03-04 21:40:34 —-D—- C:\Windows\system32\drivers
2014-03-04 21:25:42 —-D—- C:\Windows\system32\wbem
2014-03-04 21:25:20 —-D—- C:\Windows\system32\spool
2014-03-04 21:23:15 —-D—- C:\Windows\system32\catroot
2014-03-04 21:23:01 —-D—- C:\Windows\system32\winevt
2014-03-04 21:23:01 —-D—- C:\Windows\system32\WinBioPlugIns
2014-03-04 21:23:01 —-D—- C:\Windows\system32\wdi
2014-03-04 21:23:00 —-D—- C:\Windows\system32\SMI
2014-03-04 21:23:00 —-D—- C:\Windows\system32\Setup
2014-03-04 21:22:59 —-HD—- C:\Windows\system32\GroupPolicy
2014-03-04 21:22:59 —-D—- C:\Windows\system32\MUI
2014-03-04 21:22:59 —-D—- C:\Windows\system32\LogFiles
2014-03-04 21:22:55 —-D—- C:\Windows\system32\com
2014-03-04 20:44:51 —-D—- C:\Windows\Prefetch
2014-03-04 17:51:38 —-D—- C:\Config.Msi
2014-03-04 17:50:39 —-D—- C:\Program Files\Common Files\Spigot
2014-03-04 16:46:49 —-SD—- C:\ProgramData\Microsoft
2014-03-04 16:46:28 —-HD—- C:\ProgramData
2014-03-04 15:02:14 —-D—- C:\Program Files\Secure Speed Dial
2014-03-04 09:28:28 —-D—- C:\Windows\Downloaded Program Files
2014-03-03 23:03:41 —-D—- C:\Windows\inf
2014-03-03 08:42:28 —-D—- C:\Windows\Minidump
2014-03-03 08:05:42 —-D—- C:\Users\Rob\AppData\Roaming\Dropbox
2014-03-01 23:30:23 —-D—- C:\IDrive
2014-02-28 20:41:50 —-D—- C:\Windows\Tasks
2014-02-28 09:39:55 —-D—- C:\Windows\Microsoft.NET
2014-02-27 23:46:59 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-02-27 15:41:23 —-D—- C:\Program Files\iTunes
2014-02-27 15:41:01 —-D—- C:\Program Files\Common Files\Apple
2014-02-27 15:20:49 —-D—- C:\ProgramData\ProductData
2014-02-27 15:13:06 —-RSD—- C:\Windows\assembly
2014-02-27 15:10:14 —-D—- C:\Windows\system32\en-US
2014-02-27 13:42:54 —-D—- C:\ProgramData\Fighters
2014-02-27 13:42:50 —-D—- C:\Program Files\Common Files
2014-02-27 13:42:47 —-D—- C:\Program Files\Fighters
2014-02-26 10:55:36 —-D—- C:\ProgramData\ParetoLogic
2014-02-25 23:48:48 —-D—- C:\ProgramData\Adobe
2014-02-25 23:48:46 —-D—- C:\Program Files\Common Files\Adobe
2014-02-25 23:48:45 —-D—- C:\Program Files\Adobe
2014-02-25 08:33:38 —-D—- C:\Windows\rescache
2014-02-24 14:10:48 —-D—- C:\Users\Rob\AppData\Roaming\vlc
2014-02-24 14:05:37 —-D—- C:\Users\Rob\AppData\Roaming\dvdcss
2014-02-24 08:19:54 —-RD—- C:\Users
2014-02-19 17:21:41 —-D—- C:\Program Files\East-Tec Eraser 2010
2014-02-19 13:58:37 —-AD—- C:\ProgramData\TEMP
2014-02-17 13:41:33 —-D—- C:\Windows\winsxs
2014-02-17 13:37:52 —-D—- C:\Program Files\Internet Explorer
2014-02-16 22:17:32 —-D—- C:\ProgramData\Microsoft Help
2014-02-14 08:12:42 —-D—- C:\Users\Rob\AppData\Roaming\BitTorrent
2014-02-14 07:55:28 —-A—- C:\Windows\system32\MRT.exe
2014-02-13 08:58:54 —-D—- C:\ProgramData\Berowsye2soavve
2014-02-13 07:32:49 —-A—- C:\Windows\win.ini
2014-02-13 07:22:56 —-D—- C:\Windows\system32\nl-NL
2014-02-12 21:39:40 —-D—- C:\Windows\system32\DriverStore
2014-02-12 15:41:36 —-SHD—- C:\System Volume Information
2014-02-12 14:46:50 —-DC—- C:\Windows\system32\DRVSTORE
2014-02-11 18:02:26 —-HD—- C:\$AVG
2014-02-11 18:02:13 —-D—- C:\Program Files\AVG
2014-02-11 10:53:51 —-D—- C:\ProgramData\AVG2013
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys
R0 GDBehave;GDBehave; C:\Windows\system32\drivers\GDBehave.sys
R0 KL1;kl1; C:\Windows\system32\DRIVERS\kl1.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys
R1 ElRawDisk;ElRawDisk; \??\C:\Windows\system32\drivers\ElRawDsk.sys
R1 FNETURPX;FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS
R1 GDMnIcpt;GDMnIcpt; \??\C:\Windows\system32\drivers\MiniIcpt.sys
R1 gdwfpcd;G Data WFP CD; C:\Windows\system32\drivers\gdwfpcd32.sys
R1 HookCentre;HookCentre; \??\C:\Windows\system32\drivers\HookCentre.sys
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys
R2 ACT2PM;Ashampoo CoreTuner 2 ProcessMonitor Driver; \??\C:\Program Files\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor32.sys
R2 DokanCEDriver;DokanCEDriver; \??\C:\Program Files\PogoplugBackup\dokance.sys
R2 LiveTunerPM;Ashampoo LiveTuner ProcessMonitor Driver; \??\C:\Program Files\Ashampoo\Ashampoo WinOptimizer 10\LiveTunerProcessMonitor32.sys
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys
R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys
R2 PDFsFilter;PDFsFilter; C:\Windows\system32\DRIVERS\PDFsFilter.sys
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys
R3 BrSerIb;Brother Serial Interface Driver(WDM); C:\Windows\system32\DRIVERS\BrSerIb.sys
R3 BrUsbSIb;Brother Serial USB Driver(WDM); C:\Windows\system32\DRIVERS\BrUsbSIb.sys
R3 CMISTOR;CMIUCR.SYS CM320/CM220 Card Reader Driver; C:\Windows\system32\DRIVERS\cmiucr.SYS
R3 GDPkIcpt;GDPkIcpt; \??\C:\Windows\system32\drivers\PktIcpt.sys
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys
R3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys
R3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\Windows\system32\DRIVERS\serscan.sys
R3 sxuptp;SXUPTP Driver; C:\Windows\system32\DRIVERS\sxuptp.sys
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys
R3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver; C:\Windows\System32\Drivers\BrSerIf.sys
S3 cpuz134;cpuz134; \??\C:\Program Files\CPUID\PC Wizard 2010\pcwiz_x32.sys
S3 cpuz135;cpuz135; C:\Windows\system32\drivers\cpuz135.sys
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys
S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys
S3 KMWDFILTERx86;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 rt70x86;RT2500 USB Wireless LAN Driver for Vista; C:\Windows\system32\DRIVERS\netr70.sys
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys
S3 Ser2pl;Prolific Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys
S3 taphss6;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
R2 ACT2_Service;Ashampoo Core Tuner 2 Service; C:\Program Files\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2014\avgwdsvc.exe
R2 AVKProxy;G Data AntiVirus Proxy; C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
R2 AVKService;G Data Scheduler; C:\Program Files\G Data\InternetSecurity\AVK\AVKService.exe
R2 AVKWCtl;G Data Bestandssysteembewaker; C:\Program Files\G Data\InternetSecurity\AVK\AVKWCtl.exe
R2 Belkin Home Base Control Center Service;Belkin Home Base Control Center Service; C:\Program Files\Belkin\Home Base Control Center\Hbapcs.exe
R2 DDService;Drobo Dashboard Service; C:\Program Files\Drobo\Drobo Dashboard\DDService.exe
R2 DokanCEMounter;DokanCEMounter; C:\Program Files\PogoplugBackup\dokanmnt.exe
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe
R2 IDriveE Service;IDriveE Service; C:\IDrive\IDriveE Service.exe
R2 ioloSystemService;iolo System Service; C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files\Silvercrest MTS2118 driver\KMWDSrv.exe
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files\Ralink\Common\RaRegistry.exe
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
R2 Update LemurLeap;Update LemurLeap; C:\Program Files\LemurLeap\updateLemurLeap.exe
R2 Util LemurLeap;Util LemurLeap; C:\Program Files\LemurLeap\bin\utilLemurLeap.exe
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe
R3 GDFwSvc;G Data Personal Firewall; C:\Program Files\G Data\InternetSecurity\Firewall\GDFwSvc.exe
R3 GDScan;G Data Scanner; C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Updateservice (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe
S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
S2 Panorama9 Agent Updater;Panorama9 Agent Updater; C:\Program Files\Panorama9\Panorama9.Agent.UpdateService.exe
S2 SecureUpdateSvc;SecureUpdate; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
S3 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe
S3 CGVPNCliSrvc;CyberGhost VPN Client; C:\Program Files\CyberGhost VPN\CGVPNCliService.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe
S4 AshampooDefragService;Ashampoo Defrag Service; C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
S4 Belkin Local Backup Service;Belkin Local Backup Service; C:\Program Files\Belkin\Home Base Control Center\BkBackupScheduler.exe
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe
S4 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
S4 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
S4 LMIMaint;LogMeIn Maintenance Service; C:\Program Files\LogMeIn\x86\RaMaint.exe
S4 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe
S4 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe
—————–EOF—————–
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Databaseversie: v2013.04.04.07
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16518
Rob :: ROB-PC
6/03/2014 14:40:33
mbam-log-2014-03-06 (14-40-33).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 282923
Verstreken tijd: 18 minuut/minuten, 6 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|Tabs (Trojan.StartPage) -> Data: http://u-search.net/?a=1&e=1 -> Succesvol in quarantaine geplaatst en verwijderd.
Registerdata gedetecteerd: 1
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Slecht: (NOTEPAD.EXE “%1”) Goed: (regedit.exe “%1”) -> Succesvol in quarantaine geplaatst en gerepareerd.
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)