Goedenavond,
ik wil vragen of jullie kunnen zien of ik eventueel een virus heb
ik vraag dit naar aanleiding omdat ik een paar x een virus heb gehad
die stonden malware bytes maar die kon ze niet verwijderen
Avast heeft ook veel bestanden die hij niet kan scannen omdat ze
beschermd worden…. ik zou het fijn vinden om te weten of mijn laptop
virus vrij is, ik heb verder geen klachten over traagheid oid…
alvast bedankt Irma.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Irma at 2014-08-31 20:38:28
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 128 GB (28%) free of 463 GB
Total RAM: 5813 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:38:39, on 31-8-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Users\Irma\AppData\Roaming\BitTorrent\BitTorrent.exe
C:\Users\Irma\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\trend micro\Irma.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {2d8d9acc-f6d7-4362-8876-a275ca929591} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: “C:\Program Files\AVAST Software\Avast\AvastUI.exe” /nogui
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
O4 - HKCU\..\Run: “C:\Users\Irma\AppData\Roaming\BitTorrent\BitTorrent.exe” /MINIMIZED
O4 - HKCU\..\Run: C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18\..\RunOnce: msiexec.exe /qn /x{voidguid} (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\RunOnce: msiexec.exe /qn /x{voidguid} (User ‘Default user’)
O4 - Startup: Dropbox.lnk = Irma\AppData\Roaming\Dropbox\bin\Dropbox.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10148 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
“C:\Program Files\AVAST Software\Avast\AvastSvc.exe”
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”
“C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe”
“C:\Program Files\Bonjour\mDNSResponder.exe”
“C:\Program Files (x86)\Launch Manager\dsiwmis.exe”
“C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe”
“C:\Program Files (x86)\Launch Manager\LMutilps32.exe” –system-level-mutex=“Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}” –enable-wmi-window
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
“C:\Program Files (x86)\Acer\Registration\GREGsvc.exe”
“C:\Program Files\Acer\Acer Updater\UpdaterService.exe”
“C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe”
“C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe”
C:\Windows\system32\svchost.exe -k imgsvc
“C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe”
“taskhost.exe”
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
“C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE”
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
taskeng.exe {37DC1A40-B94E-4EE0-A4C9-0796B70C266E}
“C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe”
“C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe”
“C:\Windows\System32\igfxtray.exe”
“C:\Windows\System32\hkcmd.exe”
“C:\Windows\System32\igfxpers.exe”
“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe”
C:\Windows\system32\SearchIndexer.exe /Embedding
“C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe” -s
“C:\Users\Irma\AppData\Roaming\BitTorrent\BitTorrent.exe” /MINIMIZED
“C:\Windows\System32\StikyNot.exe”
“C:\Program Files\Synaptics\SynTP\SynTPHelper.exe”
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
“C:\Users\Irma\AppData\Roaming\Dropbox\bin\Dropbox.exe” /systemstartup
“C:\Program Files\AVAST Software\Avast\avastui.exe” /nogui
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
“C:\Program Files (x86)\iTunes\iTunesHelper.exe”
“C:\Program Files\iPod\bin\iPodService.exe”
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
“C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe”
C:\Windows\System32\svchost.exe -k secsvcs
“C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe”
“C:\Program Files\EgisTec IPS\PMMUpdate.exe”
“C:\Program Files\EgisTec IPS\EgisUpdate.exe”
C:\Windows\servicing\TrustedInstaller.exe
“C:\Users\Irma\Desktop\RSITx64.exe”
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Irma\AppData\Roaming\Mozilla\Firefox\Profiles\0snpc061.default
prefs.js - “browser.search.useDBForOrder” - “false”
prefs.js - “browser.startup.homepage” - “www.startpagina.nl”
prefs.js - “keyword.URL” - “http://www.google.com/search?q=”
“Description”=Adobe® Flash® Player 14.0.0.179 Plugin
“Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
“Description”=
“Path”=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
“Description”=Microsoft SharePoint Plug-in for Firefox
“Path”=C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
“Description”=WildTangent Games App V2 Presence Detector Plugin
“Path”=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
“Description”=Adobe® Flash® Player 14.0.0.179 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Irma\AppData\Roaming\Mozilla\Firefox\Profiles\0snpc061.default\extensions\
{e001c731-5e37-4538-a5cb-8168736a2360}
======Registry dump======
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
“IgfxTray”=C:\Windows\system32\igfxtray.exe
“HotKeysCmds”=C:\Windows\system32\hkcmd.exe
“Persistence”=C:\Windows\system32\igfxpers.exe
“SynTPEnh”=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
“RTHDVCPL”=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
“BitTorrent”=C:\Users\Irma\AppData\Roaming\BitTorrent\BitTorrent.exe
“RESTART_STICKY_NOTES”=C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files (x86)\QuickTime\QTTask.exe
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
“AvastUI.exe”=C:\Program Files\AVAST Software\Avast\AvastUI.exe
“Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
“QuickTime Task”=C:\Program Files (x86)\QuickTime\QTTask.exe
“SunJavaUpdateSched”=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
“iTunesHelper”=C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\Irma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Irma\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\igfxdev.dll
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=5
“ConsentPromptBehaviorUser”=3
“EnableUIADesktopToggle”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“VIDC.UYVY”=msyuv.dll
“VIDC.YUY2”=msyuv.dll
“VIDC.YVYU”=msyuv.dll
“VIDC.IYUV”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“VIDC.YVU9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“MSVideo8”=VfWWDM32.dll
“wave1”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer1”=wdmaud.drv
“aux1”=wdmaud.drv
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
“wave2”=wdmaud.drv
“midi2”=wdmaud.drv
“mixer2”=wdmaud.drv
“aux2”=wdmaud.drv
“wave3”=wdmaud.drv
“midi3”=wdmaud.drv
“mixer3”=wdmaud.drv
“aux3”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-08-31 20:38:28 —-D—- C:\rsit
2014-08-31 20:38:28 —-D—- C:\Program Files\trend micro
2014-08-28 20:01:39 —-A—- C:\Windows\system32\win32k.sys
2014-08-28 20:01:39 —-A—- C:\Windows\system32\gdi32.dll
2014-08-28 20:01:38 —-A—- C:\Windows\SYSWOW64\gdi32.dll
2014-08-26 23:15:13 —-A—- C:\Windows\system32\drivers\PSKMAD.sys
2014-08-26 23:15:11 —-D—- C:\Windows\SYSWOW64\DASBOOT
2014-08-26 23:14:59 —-D—- C:\Program Files (x86)\Panda Security
2014-08-26 14:28:50 —-D—- C:\Users\Irma\AppData\Roaming\QuickScan
2014-08-26 14:02:18 —-A—- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-08-26 14:02:18 —-A—- C:\Windows\system32\rdpcorets.dll
2014-08-26 13:56:11 —-A—- C:\Windows\system32\drivers\tmcomm.sys
2014-08-26 00:35:16 —-A—- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-08-26 00:35:10 —-A—- C:\Windows\SYSWOW64\rdpendp_winip.dll
2014-08-26 00:35:10 —-A—- C:\Windows\system32\rdpudd.dll
2014-08-26 00:35:10 —-A—- C:\Windows\system32\rdpendp_winip.dll
2014-08-25 16:37:51 —-D—- C:\Users\Irma\AppData\Roaming\Fighters
2014-08-25 16:37:27 —-D—- C:\ProgramData\Fighters
2014-08-20 13:18:17 —-D—- C:\Program Files\iPod
2014-08-20 13:18:16 —-D—- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-20 13:18:16 —-D—- C:\Program Files\iTunes
2014-08-20 13:18:16 —-D—- C:\Program Files (x86)\iTunes
2014-08-14 00:09:52 —-A—- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-14 00:09:52 —-A—- C:\Windows\SYSWOW64\icardagt.exe
2014-08-14 00:09:52 —-A—- C:\Windows\system32\infocardapi.dll
2014-08-14 00:09:52 —-A—- C:\Windows\system32\icardagt.exe
2014-08-14 00:09:49 —-A—- C:\Windows\SYSWOW64\icardres.dll
2014-08-14 00:09:49 —-A—- C:\Windows\system32\icardres.dll
2014-08-14 00:09:28 —-A—- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-14 00:09:28 —-A—- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 20:36:47 —-A—- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 20:36:47 —-A—- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 20:36:47 —-A—- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 20:36:46 —-A—- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 20:36:46 —-A—- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 20:36:46 —-A—- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 20:36:44 —-A—- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 20:36:44 —-A—- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 20:36:44 —-A—- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 20:36:44 —-A—- C:\Windows\system32\urlmon.dll
2014-08-13 20:36:44 —-A—- C:\Windows\system32\iernonce.dll
2014-08-13 20:36:44 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 20:36:44 —-A—- C:\Windows\system32\ie4uinit.exe
2014-08-13 20:36:43 —-A—- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 20:36:43 —-A—- C:\Windows\SYSWOW64\ieui.dll
2014-08-13 20:36:43 —-A—- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 20:36:43 —-A—- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 20:36:43 —-A—- C:\Windows\system32\msfeeds.dll
2014-08-13 20:36:43 —-A—- C:\Windows\system32\ieetwcollector.exe
2014-08-13 20:36:43 —-A—- C:\Windows\system32\dxtmsft.dll
2014-08-13 20:36:42 —-A—- C:\Windows\system32\iesetup.dll
2014-08-13 20:36:42 —-A—- C:\Windows\system32\iedkcs32.dll
2014-08-13 20:36:41 —-A—- C:\Windows\system32\iertutil.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 20:36:40 —-A—- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 20:36:40 —-A—- C:\Windows\system32\jsproxy.dll
2014-08-13 20:36:39 —-A—- C:\Windows\system32\ieui.dll
2014-08-13 20:36:39 —-A—- C:\Windows\system32\dxtrans.dll
2014-08-13 20:36:38 —-A—- C:\Windows\system32\mshtmlmedia.dll
2014-08-13 20:36:38 —-A—- C:\Windows\system32\mshtmled.dll
2014-08-13 20:36:38 —-A—- C:\Windows\system32\ieframe.dll
2014-08-13 20:36:37 —-A—- C:\Windows\system32\vbscript.dll
2014-08-13 20:36:37 —-A—- C:\Windows\system32\jscript9diag.dll
2014-08-13 20:36:37 —-A—- C:\Windows\system32\jscript9.dll
2014-08-13 20:36:37 —-A—- C:\Windows\system32\ieUnatt.exe
2014-08-13 20:36:36 —-A—- C:\Windows\system32\wininet.dll
2014-08-13 20:36:36 —-A—- C:\Windows\system32\ieapfltr.dll
2014-08-13 20:36:35 —-A—- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 20:36:35 —-A—- C:\Windows\system32\msrating.dll
2014-08-13 20:36:35 —-A—- C:\Windows\system32\MshtmlDac.dll
2014-08-13 20:36:34 —-A—- C:\Windows\system32\mshtml.dll
2014-08-13 20:25:29 —-A—- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 20:25:29 —-A—- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 20:25:29 —-A—- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 20:25:29 —-A—- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 20:25:29 —-A—- C:\Windows\system32\KBDTAT.DLL
2014-08-13 20:25:28 —-A—- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 20:25:28 —-A—- C:\Windows\system32\KBDYAK.DLL
2014-08-13 20:25:28 —-A—- C:\Windows\system32\KBDRU1.DLL
2014-08-13 20:25:28 —-A—- C:\Windows\system32\KBDRU.DLL
2014-08-13 20:25:28 —-A—- C:\Windows\system32\KBDBASH.DLL
2014-08-13 20:21:41 —-A—- C:\Windows\SYSWOW64\tzres.dll
2014-08-13 20:21:41 —-A—- C:\Windows\system32\tzres.dll
2014-08-13 20:21:37 —-A—- C:\Windows\system32\msi.dll
2014-08-13 20:21:36 —-A—- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 20:21:36 —-A—- C:\Windows\SYSWOW64\msi.dll
2014-08-13 20:21:36 —-A—- C:\Windows\SYSWOW64\authui.dll
2014-08-13 20:21:36 —-A—- C:\Windows\system32\msihnd.dll
2014-08-13 20:21:36 —-A—- C:\Windows\system32\consent.exe
2014-08-13 20:21:36 —-A—- C:\Windows\system32\authui.dll
2014-08-13 20:21:27 —-A—- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 20:21:06 —-A—- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 20:21:06 —-A—- C:\Windows\system32\shell32.dll
2014-08-13 20:15:01 —-A—- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 20:15:01 —-A—- C:\Windows\system32\rpcrt4.dll
2014-08-13 20:15:00 —-A—- C:\Windows\system32\aepdu.dll
2014-08-13 20:14:59 —-A—- C:\Windows\system32\aeinv.dll
2014-08-07 11:12:20 —-A—- C:\Windows\SYSWOW64\javaws.exe
2014-08-07 11:12:12 —-A—- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-08-07 11:12:12 —-A—- C:\Windows\SYSWOW64\javaw.exe
2014-08-07 11:12:12 —-A—- C:\Windows\SYSWOW64\java.exe
2014-08-07 11:12:03 —-D—- C:\Program Files (x86)\Java
2014-08-01 11:06:58 —-A—- C:\Windows\system32\wups2.dll
2014-08-01 11:06:58 —-A—- C:\Windows\system32\wucltux.dll
2014-08-01 11:06:58 —-A—- C:\Windows\system32\wuaueng.dll
2014-08-01 11:06:58 —-A—- C:\Windows\system32\wuauclt.exe
2014-08-01 11:06:43 —-A—- C:\Windows\SYSWOW64\wups.dll
2014-08-01 11:06:43 —-A—- C:\Windows\SYSWOW64\wudriver.dll
2014-08-01 11:06:43 —-A—- C:\Windows\SYSWOW64\wuapi.dll
2014-08-01 11:06:43 —-A—- C:\Windows\system32\wups.dll
2014-08-01 11:06:43 —-A—- C:\Windows\system32\wudriver.dll
2014-08-01 11:06:43 —-A—- C:\Windows\system32\wuapi.dll
2014-08-01 11:06:15 —-A—- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-01 11:06:15 —-A—- C:\Windows\SYSWOW64\wuapp.exe
2014-08-01 11:06:15 —-A—- C:\Windows\system32\wuwebv.dll
2014-08-01 11:06:15 —-A—- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-08-31 20:38:39 —-D—- C:\Windows\Prefetch
2014-08-31 20:38:36 —-D—- C:\Windows\Temp
2014-08-31 20:38:28 —-D—- C:\Program Files
2014-08-31 20:37:00 —-D—- C:\Users\Irma\AppData\Roaming\BitTorrent
2014-08-31 20:30:47 —-D—- C:\Windows\system32\config
2014-08-31 20:28:57 —-SHD—- C:\System Volume Information
2014-08-31 19:23:35 —-D—- C:\Users\Irma\AppData\Roaming\vlc
2014-08-31 17:03:36 —-A—- C:\Windows\SYSWOW64\log.txt
2014-08-31 17:02:33 —-D—- C:\Users\Irma\AppData\Roaming\Dropbox
2014-08-31 17:02:00 —-D—- C:\ProgramData\clear.fi
2014-08-30 00:17:13 —-SHD—- C:\Windows\Installer
2014-08-30 00:04:48 —-D—- C:\Windows
2014-08-29 18:43:00 —-AD—- C:\ProgramData\Temp
2014-08-29 18:42:54 —-D—- C:\Program Files (x86)\SpywareBlaster
2014-08-29 15:00:47 —-D—- C:\Windows\winsxs
2014-08-29 14:59:03 —-D—- C:\Windows\SysWOW64
2014-08-29 14:59:03 —-D—- C:\Windows\System32
2014-08-29 14:31:01 —-D—- C:\Windows\inf
2014-08-29 14:31:01 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-08-28 19:59:53 —-D—- C:\Windows\system32\catroot
2014-08-26 23:15:13 —-D—- C:\Windows\system32\drivers
2014-08-26 23:14:59 —-RD—- C:\Program Files (x86)
2014-08-26 22:28:14 —-D—- C:\Windows\system32\catroot2
2014-08-26 13:45:15 —-D—- C:\Windows\rescache
2014-08-26 12:44:17 —-D—- C:\Windows\Branding
2014-08-26 00:36:26 —-D—- C:\Windows\SYSWOW64\nl-NL
2014-08-26 00:36:26 —-D—- C:\Windows\system32\nl-NL
2014-08-26 00:36:26 —-D—- C:\Windows\system32\DriverStore
2014-08-26 00:36:26 —-D—- C:\Windows\system32\drivers\nl-NL
2014-08-26 00:36:26 —-D—- C:\Windows\PolicyDefinitions
2014-08-26 00:16:48 —-D—- C:\Windows\system32\Tasks
2014-08-26 00:16:47 —-D—- C:\Windows\Tasks
2014-08-25 16:37:27 —-HD—- C:\ProgramData
2014-08-25 12:11:53 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-08-15 11:04:01 —-D—- C:\Program Files (x86)\Internet Explorer
2014-08-14 19:29:39 —-D—- C:\Windows\debug
2014-08-14 10:38:49 —-A—- C:\Windows\wininit.ini
2014-08-14 01:10:29 —-D—- C:\Windows\Microsoft.NET
2014-08-14 01:10:01 —-RSD—- C:\Windows\assembly
2014-08-14 00:52:18 —-RSD—- C:\Windows\Fonts
2014-08-14 00:52:18 —-D—- C:\Windows\ehome
2014-08-14 00:52:13 —-D—- C:\Program Files\Internet Explorer
2014-08-14 00:52:12 —-D—- C:\Windows\SYSWOW64\en-US
2014-08-14 00:52:12 —-D—- C:\Windows\system32\en-US
2014-08-14 00:17:48 —-D—- C:\Windows\system32\MRT
2014-08-14 00:15:08 —-A—- C:\Windows\system32\MRT.exe
2014-08-14 00:08:49 —-SD—- C:\Windows\system32\CompatTel
2014-08-12 23:31:56 —-D—- C:\Users\Irma\AppData\Roaming\dvdcss
2014-08-07 11:12:36 —-D—- C:\ProgramData\Oracle
2014-08-07 11:12:25 —-D—- C:\Program Files (x86)\Common Files
2014-08-05 09:20:00 —-N—- C:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\drivers\HECIx64.sys
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys
S3 cleanhlp;cleanhlp; \??\C:\Users\Irma\Desktop\EmsisoftEmergencyKit\Run\cleanhlp64.sys
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
S3 PSKMAD;PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys
S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe
R2 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe
S3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
—————–EOF—————–