[Unregistered version]
Scan started at: 21:10:13 19 feb 2015
Using Database v8631
Operating System: Windows 7 x64 Ultimate (SP1) [Build: 6.1.7601]
File System: NTFS
UAC is ENABLED [default level]
UserData directory: C:\Users\PAINKILLER\AppData\Roaming\Simply Super Software\Trojan Remover\
Database directory: C:\ProgramData\Simply Super Software\Trojan Remover\Data\
Logfile directory: C:\Users\PAINKILLER\Documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files (x86)\Trojan Remover\
Running with Administrator privileges
************************************************************
21:10:14: ----- Checking Default File Associations -----
No modified default file associations detected
************************************************************
21:10:15: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
21:10:15: Scanning ----- Windows Registry -----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
Key value: [explorer.exe]
File: C:\Windows\Explorer.exe
C:\Windows\Explorer.exe (verified signer: [Microsoft Windows])
2871808 bytes
Created: 28/04/2014 3:37
Modified: 28/04/2014 3:37
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
Key value: [C:\Windows\system32\userinit.exe,]
File: C:\Windows\system32\userinit.exe
C:\Windows\System32\userinit.exe (verified signer: [Microsoft Windows])
30720 bytes
Created: 21/11/2010 4:24
Modified: 21/11/2010 4:24
Company: Microsoft Corporation
----------
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: [USB3MON]
Value Data: ["C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"]
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (verified signer: [Intel Corporation])
-R- 291648 bytes
Created: 27/03/2013 23:06
Modified: 20/05/2012 17:26
Company: Intel Corporation
--------------------
Value Name: [IMSS]
Value Data: ["C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"]
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe (verified signer: [Intel Corporation])
133440 bytes
Created: 27/03/2013 23:01
Modified: 19/07/2012 9:53
Company: Intel Corporation
--------------------
Value Name: [IAStorIcon]
Value Data: [C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60]
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (verified signer: [Intel Corporation])
56088 bytes
Created: 27/03/2013 23:05
Modified: 29/02/2012 12:43
Company: Intel Corporation
--------------------
Value Name: [hpqSRMon]
Value Data: [C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe]
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
150528 bytes
Created: 22/07/2008 17:33
Modified: 22/07/2008 17:33
Company: Hewlett-Packard
--------------------
Value Name: [CTxfiHlp]
Value Data: [CTXFIHLP.EXE]
C:\Windows\SysWoW64\CTXFIHLP.EXE (verified signer: [Creative Technology])
26112 bytes
Created: 01/03/2014 0:20
Modified: 01/03/2014 0:20
Company: Creative Technology Ltd
--------------------
Value Name: [UpdReg]
Value Data: [C:\Windows\UpdReg.EXE]
C:\Windows\UpdReg.EXE
90112 bytes
Created: 10/10/2014 19:25
Modified: 11/05/2000 0:00
Company: Creative Technology Ltd.
--------------------
Value Name: [Sound Blaster Z-Series Control Panel]
Value Data: ["C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r]
C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe
735744 bytes
Created: 27/02/2013 5:45
Modified: 27/02/2013 5:45
Company: Creative Technology Ltd
--------------------
Value Name: [TrojanScanner]
Value Data: [C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot]
C:\Program Files (x86)\Trojan Remover\Trjscan.exe (verified signer: [Simply Super Software])
1791856 bytes
Created: 19/02/2015 21:04
Modified: 19/02/2015 21:05
Company: Simply Super Software
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: [CCleaner Monitoring]
Value Data: ["C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR]
C:\Program Files\CCleaner\CCleaner64.exe (verified signer: [Piriform Ltd])
6160152 bytes
Created: 20/05/2014 14:29
Modified: 20/05/2014 14:29
Company: Piriform Ltd
--------------------
Value Name: [CCleaner]
Value Data: ["C:\Program Files\CCleaner\CCleaner64.exe" /AUTO]
C:\Program Files\CCleaner\CCleaner64.exe (verified signer: [Piriform Ltd])
6160152 bytes
Created: 20/05/2014 14:29
Modified: 20/05/2014 14:29
Company: Piriform Ltd
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry key appears to be empty
************************************************************
21:10:18: Scanning ----- Windows 64-Bit Registry -----
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: [ShadowPlay]
Value Data: [C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart]
C:\Windows\System32\nvspcap64.dll
1514528 bytes
Created: 01/11/2013 19:59
Modified: 16/01/2015 7:41
Company: NVIDIA Corporation
--------------------
Value Name: [NvBackend]
Value Data: ["C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"]
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (verified signer: [NVIDIA Corporation])
2585928 bytes
Created: 02/12/2013 22:03
Modified: 16/01/2015 7:42
Company: NVIDIA Corporation
--------------------
Value Name: [MSC]
Value Data: ["C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey]
C:\Program Files\Microsoft Security Client\msseces.exe (verified signer: [Microsoft Corporation])
1332296 bytes
Created: 30/01/2015 3:09
Modified: 30/01/2015 3:09
Company: Microsoft Corporation
--------------------
Value Name: [EvtMgr6]
Value Data: [C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming]
C:\Program Files\Logitech\SetPointP\SetPoint.exe (verified signer: [Logitech])
3091224 bytes
Created: 31/07/2013 21:31
Modified: 31/07/2013 21:31
Company: Logitech, Inc.
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry key appears to be empty
************************************************************
21:10:19: Scanning -----SHELLEXECUTEHOOKS-----
ShellExecuteHooks key is empty
************************************************************
21:10:19: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
21:10:19: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
************************************************************
21:10:19: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {8A69D345-D564-463c-AFF1-A69D9E530F96}
Path: "C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\Installer\chrmstp.exe (verified signer: [Google Inc])
1087304 bytes
Created: 18/11/2014 21:56
Modified: 18/11/2014 21:56
Company: Google Inc.
----------
************************************************************
21:10:19: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: HPSLPSVC
Path: C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
1037824 bytes
Created: 20/09/2009 10:55
Modified: 20/09/2009 10:55
Company: Hewlett-Packard Co.
----------
************************************************************
21:10:23: Scanning ----- SERVICES REGISTRY KEYS -----
----------
Key: AppleCharger
ImagePath: system32\DRIVERS\AppleCharger.sys
C:\Windows\System32\DRIVERS\AppleCharger.sys
22680 bytes
Created: 27/03/2013 23:06
Modified: 25/10/2012 9:01
Company: [no info]
----------
----------
Key: AppleChargerSrv
ImagePath: system32\AppleChargerSrv.exe
C:\Windows\System32\AppleChargerSrv.exe
31272 bytes
Created: 27/03/2013 23:06
Modified: 06/04/2010 16:30
Company: [no info]
----------
----------
Key: AxAutoMntSrv
ImagePath: C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (verified signer: [Alcohol Soft])
75624 bytes
Created: 05/01/2012 16:42
Modified: 05/01/2012 16:42
Company: Alcohol Soft Development Team
----------
----------
Key: BstHdAndroidSvc
ImagePath: "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android
C:\Program Files (x86)\BlueStacks\HD-Service.exe (verified signer: [Bluestack Systems, Inc.])
398096 bytes
Created: 18/11/2013 23:06
Modified: 18/11/2013 23:06
Company: BlueStack Systems, Inc.
----------
----------
Key: BstHdDrv
ImagePath: \?\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys
C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys
77584 bytes
Created: 18/11/2013 23:06
Modified: 18/11/2013 23:06
Company: BlueStack Systems
----------
----------
Key: BstHdLogRotatorSvc
ImagePath: C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (verified signer: [Bluestack Systems, Inc.])
385808 bytes
Created: 18/11/2013 23:06
Modified: 18/11/2013 23:06
Company: BlueStack Systems, Inc.
----------
----------
Key: Creative ALchemy AL6 Licensing Service
ImagePath: "C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe"
C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
79360 bytes
Created: 10/10/2014 19:24
Modified: 10/10/2014 19:24
Company: Creative Labs
----------
----------
Key: Creative Audio Engine Licensing Service
ImagePath: "C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe"
C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
79360 bytes
Created: 01/06/2014 18:16
Modified: 01/06/2014 18:16
Company: Creative Labs
----------
----------
Key: CT20XUT
ImagePath: system32\drivers\CT20XUT.SYS
C:\Windows\System32\drivers\CT20XUT.SYS
205080 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: CT20XUT.SYS
ImagePath: \SystemRoot\System32\drivers\CT20XUT.SYS
C:\Windows\System32\drivers\CT20XUT.SYS
205080 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: ctac32k
ImagePath: system32\drivers\ctac32k.sys
C:\Windows\System32\drivers\ctac32k.sys
582936 bytes
Created: 01/03/2014 2:55
Modified: 01/03/2014 2:55
Company: Creative Technology Ltd
----------
----------
Key: ctaud2k
ImagePath: system32\drivers\ctaud2k.sys
C:\Windows\System32\drivers\ctaud2k.sys
689048 bytes
Created: 01/03/2014 2:55
Modified: 01/03/2014 2:55
Company: Creative Technology Ltd
----------
----------
Key: CTAudSvcService
ImagePath: C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
423424 bytes
Created: 08/10/2012 10:53
Modified: 08/10/2012 10:53
Company: Creative Technology Ltd
----------
----------
Key: CTEXFIFX
ImagePath: system32\drivers\CTEXFIFX.SYS
C:\Windows\System32\drivers\CTEXFIFX.SYS
1419544 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: CTEXFIFX.SYS
ImagePath: \SystemRoot\System32\drivers\CTEXFIFX.SYS
C:\Windows\System32\drivers\CTEXFIFX.SYS
1419544 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: cthda
ImagePath: system32\drivers\cthda.sys
C:\Windows\System32\drivers\cthda.sys
1060632 bytes
Created: 22/05/2013 7:48
Modified: 22/05/2013 7:48
Company: Creative Technology Ltd
----------
----------
Key: CtHdaSvc
ImagePath: %SystemRoot%\sysWow64\CtHdaSvc.exe
C:\Windows\sysWow64\CtHdaSvc.exe (verified signer: [Creative Technology])
112640 bytes
Created: 22/05/2013 7:40
Modified: 22/05/2013 7:40
Company: Creative Technology Ltd
----------
----------
Key: cthdb
ImagePath: system32\DRIVERS\cthdb.sys
C:\Windows\System32\DRIVERS\cthdb.sys
33560 bytes
Created: 22/05/2013 7:48
Modified: 22/05/2013 7:48
Company: Creative Technology Ltd
----------
----------
Key: CTHWIUT
ImagePath: system32\drivers\CTHWIUT.SYS
C:\Windows\System32\drivers\CTHWIUT.SYS
97048 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: CTHWIUT.SYS
ImagePath: \SystemRoot\System32\drivers\CTHWIUT.SYS
C:\Windows\System32\drivers\CTHWIUT.SYS
97048 bytes
Created: 01/03/2014 2:54
Modified: 01/03/2014 2:54
Company: Creative Technology Ltd.
----------
----------
Key: ctprxy2k
ImagePath: system32\drivers\ctprxy2k.sys
C:\Windows\System32\drivers\ctprxy2k.sys
18200 bytes
Created: 01/03/2014 2:55
Modified: 01/03/2014 2:55
Company: Creative Technology Ltd
----------
----------
Key: ctsfm2k
ImagePath: system32\drivers\ctsfm2k.sys
C:\Windows\System32\drivers\ctsfm2k.sys
215320 bytes
Created: 01/03/2014 2:55
Modified: 01/03/2014 2:55
Company: Creative Technology Ltd
----------
----------
Key: emupia
ImagePath: system32\drivers\emupia2k.sys
C:\Windows\System32\drivers\emupia2k.sys
120600 bytes
Created: 01/03/2014 2:56
Modified: 01/03/2014 2:56
Company: Creative Technology Ltd
----------
----------
Key: etdrv
ImagePath: \?\C:\Windows\etdrv.sys
C:\Windows\etdrv.sys
25640 bytes
Created: 31/03/2013 22:14
Modified: 20/04/2013 17:50
Company: Windows (R) Server 2003 DDK provider
----------
----------
Key: FLEXnet Licensing Service
ImagePath: "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (verified signer: [Flexera Software, Inc. ])
1044816 bytes
Created: 31/05/2013 22:48
Modified: 31/05/2013 22:48
Company: Flexera Software, Inc.
----------
----------
Key: gdrv
ImagePath: \?\C:\Windows\gdrv.sys
C:\Windows\gdrv.sys
25640 bytes
Created: 27/03/2013 23:12
Modified: 22/09/2013 8:41
Company: Windows (R) Server 2003 DDK provider
----------
----------
Key: GfExperienceService
ImagePath: "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (verified signer: [NVIDIA Corporation])
1148744 bytes
Created: 21/09/2014 11:44
Modified: 16/01/2015 7:42
Company: NVIDIA Corporation
----------
----------
Key: GVTDrv64
ImagePath: \?\C:\Windows\GVTDrv64.sys
C:\Windows\GVTDrv64.sys
30528 bytes
Created: 27/03/2013 23:12
Modified: 22/09/2013 8:41
Company: [no info]
----------
----------
Key: ha20x2k
ImagePath: system32\drivers\ha20x2k.sys
C:\Windows\System32\drivers\ha20x2k.sys
1564440 bytes
Created: 01/03/2014 2:56
Modified: 01/03/2014 2:56
Company: Creative Technology Ltd
----------
----------
Key: HauppaugeTVServer
ImagePath: C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
442368 bytes
Created: 02/04/2013 17:01
Modified: 26/02/2009 15:15
Company: Hauppauge Computer Works
----------
----------
Key: HiSuiteOuc64.exe
ImagePath: "C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe" -/service
C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe (verified signer: [Huawei Technologies Co.,Ltd.])
138272 bytes
Created: 29/11/2014 12:20
Modified: 05/09/2014 8:40
Company:
----------
----------
Key: HPSupportSolutionsFrameworkService
ImagePath: "C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe"
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe (verified signer: [Hewlett-Packard Company])
89864 bytes
Created: 11/12/2014 11:36
Modified: 11/12/2014 11:36
Company: Hewlett-Packard Company
----------
----------
Key: HuaweiHiSuiteService64.exe
ImagePath: "C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service
C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe (verified signer: [Huawei Technologies Co.,Ltd.])
219680 bytes
Created: 29/11/2014 12:20
Modified: 05/09/2014 8:40
Company:
----------
----------
Key: IAStorDataMgrSvc
ImagePath: "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (verified signer: [Intel Corporation])
13592 bytes
Created: 27/03/2013 23:05
Modified: 01/02/2012 16:29
Company: Intel Corporation
----------
----------
Key: ICCS
ImagePath: "C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
160256 bytes
Created: 27/03/2013 23:08
Modified: 30/08/2011 15:55
Company: Intel Corporation
----------
----------
Key: Intel(R) Capability Licensing Service Interface
ImagePath: "C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Program Files\Intel\iCLS Client\HeciServer.exe (verified signer: [Intel® Upgrade Service])
634632 bytes
Created: 19/06/2012 19:10
Modified: 19/06/2012 19:10
Company: Intel(R) Corporation
----------
----------
Key: Intel(R) ME Service
ImagePath: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (verified signer: [Intel Corporation])
129856 bytes
Created: 27/03/2013 23:02
Modified: 05/07/2012 13:23
Company: Intel Corporation
----------
----------
Key: iumsvc
ImagePath: "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe"
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe (verified signer: [Intel® Services Manager])
174368 bytes
Created: 28/02/2014 10:32
Modified: 28/02/2014 10:32
Company: [no info]
----------
----------
Key: jhi_service
ImagePath: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (verified signer: [Intel Corporation])
166720 bytes
Created: 27/03/2013 23:01
Modified: 05/07/2012 13:23
Company: Intel Corporation
----------
----------
Key: LBTServ
ImagePath: C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe (verified signer: [Logitech])
357144 bytes
Created: 24/03/2014 23:50
Modified: 24/03/2014 23:50
Company: Logitech, Inc.
----------
----------
Key: LMS
ImagePath: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (verified signer: [Intel Corporation])
277824 bytes
Created: 27/03/2013 23:01
Modified: 19/07/2012 9:53
Company: Intel Corporation
----------
----------
Key: MBAMProtector
ImagePath: \?\C:\Windows\system32\drivers\mbam.sys
C:\Windows\System32\drivers\mbam.sys
25816 bytes
Created: 10/11/2013 9:40
Modified: 21/11/2014 6:14
Company: Malwarebytes Corporation
----------
----------
Key: MBAMScheduler
ImagePath: "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (verified signer: [Malwarebytes Corporation])
1871160 bytes
Created: 24/09/2014 16:26
Modified: 21/11/2014 6:12
Company: Malwarebytes Corporation
----------
----------
Key: MBAMService
ImagePath: "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (verified signer: [Malwarebytes Corporation])
969016 bytes
Created: 24/09/2014 16:26
Modified: 21/11/2014 6:12
Company: Malwarebytes Corporation
----------
----------
Key: MBAMWebAccessControl
ImagePath: \?\C:\Windows\system32\drivers\mwac.sys
C:\Windows\System32\drivers\mwac.sys
63704 bytes
Created: 24/09/2014 16:26
Modified: 21/11/2014 6:14
Company: Malwarebytes Corporation
----------
----------
Key: NvNetworkService
ImagePath: "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (verified signer: [NVIDIA Corporation])
1706312 bytes
Created: 02/12/2013 22:03
Modified: 16/01/2015 7:42
Company: NVIDIA Corporation
----------
----------
Key: NvStreamKms
ImagePath: \?\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
19784 bytes
Created: 01/06/2014 19:37
Modified: 16/01/2015 7:42
Company: NVIDIA Corporation
----------
----------
Key: NvStreamSvc
ImagePath: "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (verified signer: [NVIDIA Corporation])
21833544 bytes
Created: 01/11/2013 19:59
Modified: 16/01/2015 7:42
Company: NVIDIA Corporation
----------
----------
Key: ossrv
ImagePath: system32\drivers\ctoss2k.sys
C:\Windows\System32\drivers\ctoss2k.sys
181528 bytes
Created: 01/03/2014 2:55
Modified: 01/03/2014 2:55
Company: Creative Technology Ltd.
----------
----------
Key: PnkBstrA
ImagePath: C:\Windows\system32\PnkBstrA.exe
C:\Windows\System32\PnkBstrA.exe (verified signer: [Even Balance, Inc.])
76152 bytes
Created: 04/07/2014 18:36
Modified: 04/07/2014 18:36
Company: [no info]
----------
----------
Key: pwdrvio
ImagePath: system32\pwdrvio.sys
C:\Windows\System32\pwdrvio.sys
19152 bytes
Created: 24/01/2015 13:30
Modified: 30/09/2013 16:26
Company: [no info]
----------
----------
Key: pwdspio
ImagePath: \?\C:\Windows\system32\pwdspio.sys
C:\Windows\System32\pwdspio.sys
12504 bytes
Created: 24/01/2015 13:30
Modified: 30/09/2013 16:26
Company: [no info]
----------
----------
Key: StarWindServiceAE
ImagePath: C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
370688 bytes
Created: 23/12/2009 22:34
Modified: 23/12/2009 22:34
Company: StarWind Software
----------
----------
Key: Steam Client Service
ImagePath: "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Program Files (x86)\Common Files\Steam\SteamService.exe (verified signer: [Valve])
834752 bytes
Created: 31/03/2013 19:24
Modified: 19/01/2015 19:49
Company: Valve Corporation
----------
----------
Key: UNS
ImagePath: "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (verified signer: [Intel Corporation])
365376 bytes
Created: 27/03/2013 23:01
Modified: 19/07/2012 9:53
Company: Intel Corporation
----------
----------
Key: VGPU
ImagePath: System32\drivers\rdvgkmd.sys
C:\Windows\System32\drivers\rdvgkmd.sys - [file not found to scan]
----------
************************************************************
21:10:43: Scanning -----VXD ENTRIES-----
************************************************************
21:10:43: Scanning ----- ContextMenuHandlers -----
Key: 7-Zip
CLSID: {23170F69-40C1-278A-1000-000100020000}
Path: C:\Program Files\7-Zip\7-zip32.dll
C:\Program Files\7-Zip\7-zip32.dll
56320 bytes
Created: 18/04/2011 23:34
Modified: 18/04/2011 23:34
Company: Igor Pavlov
----------
Key: AIMP
CLSID: {1F77B17B-F531-44DB-ACA4-76ABB5010A28}
Path: C:\Program Files (x86)\AIMP3\Modules\aimp_menu32.dll
C:\Program Files (x86)\AIMP3\Modules\aimp_menu32.dll
286720 bytes
Created: 07/03/2014 19:58
Modified: 07/03/2014 19:58
Company: AIMP DevTeam
----------
************************************************************
21:10:43: Scanning ----- Folder\ColumnHandlers -----
Key: {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
File: "C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
401920 bytes
Created: 19/05/2010 14:37
Modified: 19/05/2010 14:37
Company: OpenOffice.org
----------
************************************************************
21:10:44: Scanning ----- 64-Bit ContextMenuHandlers -----
Key: AIMP
CLSID: {1F77B17B-F531-44DB-ACA4-76ABB5010A28}
Path: C:\Program Files (x86)\AIMP3\Modules\aimp_menu64.dll
C:\Program Files (x86)\AIMP3\Modules\aimp_menu64.dll
590848 bytes
Created: 07/03/2014 19:58
Modified: 07/03/2014 19:58
Company: AIMP DevTeam
----------
Key: EPP
CLSID: {09A47860-11B0-4DA5-AFA5-26D86198A780}
Path: C:\PROGRA~1\MICROS~3\shellext.dll
C:\PROGRA~1\MICROS~3\shellext.dll (verified signer: [Microsoft Corporation])
349336 bytes
Created: 30/01/2015 2:24
Modified: 30/01/2015 2:24
Company: Microsoft Corporation
----------
Key: PowerISO
CLSID: {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
Path: C:\Program Files (x86)\PowerISO\PWRISOSH.DLL
C:\Program Files (x86)\PowerISO\PWRISOSH.DLL (verified signer: [Power Software Ltd])
233496 bytes
Created: 23/10/2013 15:11
Modified: 23/10/2013 15:11
Company: Power Software Ltd
----------
************************************************************
21:10:44: Scanning ----- 64-Bit Folder\ColumnHandlers -----
Key: {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
File: "C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl_x64.dll"
C:\Program Files (x86)\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl_x64.dll
830464 bytes
Created: 19/05/2010 14:41
Modified: 19/05/2010 14:41
Company: OpenOffice.org
----------
************************************************************
21:10:45: Scanning ----- Browser Helper Objects -----
Key: {0347C33E-8762-4905-BF09-768834316C61}
BHO: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (verified signer: [Hewlett-Packard Company])
328248 bytes
Created: 20/09/2009 11:15
Modified: 20/09/2009 11:15
Company: Hewlett-Packard Co.
----------
Key: {9030D464-4C02-4ABF-8ECC-5164760863C6}
BHO: c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (verified signer: [Microsoft Corporation])
403840 bytes
Created: 18/08/2009 10:32
Modified: 18/08/2009 10:32
Company: Microsoft Corporation
----------
Key: {AF949550-9094-4807-95EC-D1C317803333}
BHO: C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (verified signer: [Logitech])
364824 bytes
Created: 19/05/2014 21:35
Modified: 19/05/2014 21:35
Company: Logitech, Inc.
----------
Key: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}
BHO: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (verified signer: [Hewlett-Packard Company])
509496 bytes
Created: 20/09/2009 11:15
Modified: 20/09/2009 11:15
Company: Hewlett-Packard Co.
----------
************************************************************
21:10:45: Scanning ----- 64-Bit Browser Helper Objects -----
Key: {AF949550-9094-4807-95EC-D1C317803333}
BHO: C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (verified signer: [Logitech])
433944 bytes
Created: 19/05/2014 21:35
Modified: 19/05/2014 21:35
Company: Logitech, Inc.
----------
************************************************************
21:10:46: Scanning ----- ShellServiceObjectDelayLoad Entries -----
************************************************************
21:10:46: Scanning ----- 64-Bit ShellServiceObjectDelayLoad Entries -----
************************************************************
21:10:46: Scanning ----- ShellServiceObjects -----
************************************************************
21:10:47: Scanning ----- 64-Bit ShellServiceObjects -----
************************************************************
21:10:48: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
No SharedTaskScheduler entries found to scan
************************************************************
21:10:48: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
************************************************************
21:10:48: Scanning ----- APPINIT_DLLS -----
No AppInit_DLLs value found to check
************************************************************
21:10:48: Scanning ----- 64-Bit APPINIT_DLLS -----
No 64-Bit AppInit_DLLs value found to check
************************************************************
21:10:49: Scanning ----- SECURITY PROVIDER DLLS -----
************************************************************
21:10:49: Scanning ----- CREDENTIAL PROVIDERS -----
************************************************************
21:10:51: Scanning ------ COMMON STARTUP GROUP ------
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 14/07/2009 5:54
Modified: 14/07/2009 5:54
Company: [no info]
--------------------
************************************************************
21:10:51: Scanning ----- USER STARTUP GROUPS -----
Checking Startup Group for: PAINKILLER
[C:\Users\PAINKILLER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
C:\Users\PAINKILLER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 27/03/2013 22:18
Modified: 18/08/2014 14:28
Company: [no info]
----------
--------------------
Checking Startup Group for: SANDRA
[C:\Users\SANDRA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
C:\Users\SANDRA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 28/03/2013 11:31
Modified: 20/08/2014 17:41
Company: [no info]
----------
OpenOffice.org 3.2.lnk - links to [C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE]
C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE
1195008 bytes
Created: 20/05/2010 11:14
Modified: 20/05/2010 11:14
Company: [no info]
----------
--------------------
************************************************************
21:10:52: Scanning ----- SCHEDULED TASKS -----
Taskname: Adobe Acrobat Update Task
File: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (verified signer: [Adobe Systems, Incorporated])
1022152 bytes
Created: 19/12/2014 8:48
Modified: 19/12/2014 8:48
Company: Adobe Systems Incorporated
Schedule: At logon
Next Run Time:
Status: Queued
Creator: Adobe Systems Incorporated
Comments: This task keeps your Adobe Reader and Acrobat applications up to date with the latest enhancements and security fixes
----------
Taskname: Adobe Flash Player Updater
File: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (verified signer: [Adobe Systems Incorporated])
267440 bytes
Created: 11/04/2013 18:33
Modified: 04/02/2015 23:24
Company: Adobe Systems Incorporated
Schedule: At 1:24:00 every day
Next Run Time: 19/02/2015 21:24:00
Status: Ready
Creator: Adobe Systems Incorporated
Comments: Esta tarea mantiene actualizada la instalación de Adobe Flash Player con las últimas mejoras y soluciones de seguridad. Si desactiva o elimina la tarea, Adobe Flash Player no podrá proteger automáticamente su equipo con las últimas soluciones de seguridad.
----------
Taskname: CCleanerSkipUAC
File: C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\CCleaner\CCleaner.exe (verified signer: [Piriform Ltd])
4529944 bytes
Created: 20/05/2014 14:29
Modified: 20/05/2014 14:29
Company: Piriform Ltd
Parameters: $(Arg0)
Schedule: Task not scheduled
Next Run Time:
Status: Ready
Creator: Piriform Ltd
Comments:
----------
Taskname: GoogleUpdateTaskMachineCore
File: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (verified signer: [Google Inc])
107912 bytes
Created: 27/03/2013 22:56
Modified: 21/10/2014 2:47
Company: Google Inc.
Parameters: /c
Schedule: Multiple schedule times
Next Run Time: 20/02/2015 3:52:00
Status: Running
Creator: SYSTEM
Comments: Mantiene actualizado el software de Google. Si esta tarea se inhabilita o se detiene, el software de Google no se mantendrá actualizado, lo que significa que las vulnerabilidades de seguridad que puedan surgir no se podrán solucionar y es posible que el rendimiento del producto se vea afectado. Esta tarea se desinstala por sí sola cuando no la está utilizando ningún software de Google.
----------
Taskname: GoogleUpdateTaskMachineUA
File: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (verified signer: [Google Inc])
107912 bytes
Created: 27/03/2013 22:56
Modified: 21/10/2014 2:47
Company: Google Inc.
Parameters: /ua /installsource scheduler
Schedule: At 3:52:00 every day
Next Run Time: 19/02/2015 21:52:00
Status: Ready
Creator: SYSTEM
Comments: Mantiene actualizado el software de Google. Si esta tarea se inhabilita o se detiene, el software de Google no se mantendrá actualizado, lo que significa que las vulnerabilidades de seguridad que puedan surgir no se podrán solucionar y es posible que el rendimiento del producto se vea afectado. Esta tarea se desinstala por sí sola cuando no la está utilizando ningún software de Google.
----------
Taskname: IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
File: C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe (verified signer: [Intel® Services Manager])
174368 bytes
Created: 28/02/2014 10:32
Modified: 28/02/2014 10:32
Company: [no info]
Parameters: --automatic
Schedule: At 13:53:42 every day
Next Run Time: 20/02/2015 13:53:42
Status: Ready
Creator: SYSTEM
Comments: Intel(R) Update Manager helps you keep your system up-to-date. Keep this task running to be notified automatically when new updates become available.
----------
Taskname: IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon
File: C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe (verified signer: [Intel® Services Manager])
174368 bytes
Created: 28/02/2014 10:32
Modified: 28/02/2014 10:32
Company: [no info]
Parameters: --automatic
Schedule: At logon
Next Run Time:
Status: Ready
Creator: SYSTEM
Comments: Intel(R) Update Manager helps you keep your system up-to-date. Keep this task running to be notified automatically when new updates become available.
----------
************************************************************
21:10:54: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----
************************************************************
21:10:54: Scanning ----- DEVICE DRIVER ENTRIES -----
Value: vidc.i420
File: lvcodec2.dll
C:\Windows\SysWoW64\lvcodec2.dll (verified signer: [Microsoft Windows Hardware Compatibility Publisher])
416280 bytes
Created: 26/07/2008 15:23
Modified: 26/07/2008 15:23
Company: Logitech Inc.
----------
Value: msacm.l3acm
File: C:\Windows\SysWOW64\l3codeca.acm
C:\Windows\SysWOW64\l3codeca.acm
64000 bytes
Created: 14/07/2009 1:07
Modified: 14/07/2009 2:14
Company: Fraunhofer Institut Integrierte Schaltungen IIS
----------
Value: msacm.vorbis
File: vorbis.acm
C:\Windows\SysWoW64\vorbis.acm
1554944 bytes
Created: 13/04/2013 21:12
Modified: 15/09/2009 10:14
Company: HMS
http://hp.vector.co.jp/authors/VA012897/
----------
Value: VIDC.FMVC
File: fmcodec.dll
C:\Windows\SysWoW64\fmcodec.dll
77824 bytes
Created: 19/08/2008 1:18
Modified: 19/08/2008 1:18
Company: Fox Magic Software
----------
Value: VIDC.FPS1
File: frapsvid.dll
C:\Windows\SysWoW64\frapsvid.dll
65536 bytes
Created: 26/02/2013 7:31
Modified: 26/02/2013 7:31
Company: Beepa P/L
----------
Value: vidc.VP60
File: C:\Windows\system32\vp6vfw.dll
C:\Windows\SysWoW64\vp6vfw.dll (verified signer: [Electronic Arts])
-R- 447752 bytes
Created: 04/09/2008 19:17
Modified: 04/09/2008 19:17
Company: On2.com
----------
************************************************************
21:10:55: ----- ADDITIONAL CHECKS -----
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Checking autorun.inf in E:\
E:\autorun.inf
182 bytes
Created: 18/07/2014 6:54
Modified: 23/02/2012 10:07
Company: [no info]
E:\autorun.inf open entry: [Setup.exe]
E:\Setup.exe (verified signer: [Seagate Technology LLC])
156312 bytes
Created: 18/07/2014 6:54
Modified: 16/01/2009 8:14
Company: Seagate Technology LLC
----------
--------------------
Desktop Wallpaper: C:\Users\PAINKILLER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
C:\Users\PAINKILLER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
206743 bytes
Created: 01/06/2014 15:41
Modified: 28/09/2014 0:03
Company: [no info]
----------
Web Desktop Wallpaper entry is blank
----------
Checks for rogue DNS NameServers completed
----------
Checks for Backdoor.ZeroAccess completed
----------
Safe Mode checks completed
Additional checks completed
************************************************************
21:10:56: Scanning ----- RUNNING PROCESSES -----
C:\Windows\System32\smss.exe
112640 bytes
Created: 28/04/2014 4:24
Modified: 28/04/2014 4:24
Company: Microsoft Corporation
--------------------
C:\Windows\System32\csrss.exe
7680 bytes
Created: 14/07/2009 0:19
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Windows\System32\wininit.exe
129024 bytes
Created: 14/07/2009 0:52
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Windows\System32\services.exe
328704 bytes
Created: 14/07/2009 0:19
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Windows\System32\lsass.exe
31232 bytes
Created: 10/02/2015 22:02
Modified: 15/01/2015 9:09
Company: Microsoft Corporation
--------------------
C:\Windows\System32\lsm.exe
343040 bytes
Created: 21/11/2010 4:23
Modified: 21/11/2010 4:23
Company: Microsoft Corporation
--------------------
C:\Windows\System32\winlogon.exe
455168 bytes
Created: 17/10/2014 0:00
Modified: 17/07/2014 3:07
Company: Microsoft Corporation
--------------------
C:\Windows\System32\svchost.exe
27136 bytes
Created: 14/07/2009 0:31
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Program Files\Microsoft Security Client\MsMpEng.exe
23784 bytes
Created: 30/01/2015 3:15
Modified: 30/01/2015 3:15
Company: Microsoft Corporation
--------------------
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1249424 bytes
Created: 01/06/2014 14:12
Modified: 05/02/2015 20:07
Company: NVIDIA Corporation
--------------------
C:\Windows\System32\spoolsv.exe
559104 bytes
Created: 28/04/2014 3:46
Modified: 28/04/2014 3:46
Company: Microsoft Corporation
--------------------
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2291568 bytes
Created: 18/08/2009 11:48
Modified: 18/08/2009 11:48
Company: Microsoft Corporation
--------------------
C:\Windows\System32\SearchIndexer.exe
591872 bytes
Created: 28/04/2014 3:39
Modified: 28/04/2014 3:39
Company: Microsoft Corporation
--------------------
C:\Program Files\Microsoft Security Client\NisSrv.exe
366512 bytes
Created: 30/01/2015 3:15
Modified: 30/01/2015 3:15
Company: Microsoft Corporation
--------------------
C:\Windows\System32\conhost.exe
338432 bytes
Created: 28/04/2014 4:24
Modified: 28/04/2014 4:24
Company: Microsoft Corporation
--------------------
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
221040 bytes
Created: 18/08/2009 11:48
Modified: 18/08/2009 11:48
Company: Microsoft Corporation
--------------------
C:\Windows\System32\taskhost.exe
68608 bytes
Created: 28/04/2014 4:04
Modified: 28/04/2014 4:04
Company: Microsoft Corporation
--------------------
C:\Windows\System32\taskeng.exe
464384 bytes
Created: 21/11/2010 4:24
Modified: 21/11/2010 4:24
Company: Microsoft Corporation
--------------------
C:\Windows\System32\dwm.exe
120320 bytes
Created: 14/07/2009 0:37
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Windows\System32\schtasks.exe
285696 bytes
Created: 21/11/2010 4:24
Modified: 21/11/2010 4:24
Company: Microsoft Corporation
--------------------
C:\Program Files\Common Files\logishrd\KHAL3\KHALMNPR.exe
230680 bytes
Created: 13/06/2013 20:31
Modified: 13/06/2013 20:31
Company: Logitech, Inc.
--------------------
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
2448016 bytes
Created: 01/06/2014 14:12
Modified: 05/02/2015 20:07
Company: NVIDIA Corporation
--------------------
C:\Program Files\Windows Media Player\wmpnetwk.exe
1525248 bytes
Created: 21/11/2010 4:25
Modified: 21/11/2010 4:25
Company: Microsoft Corporation
--------------------
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
284440 bytes
Created: 27/03/2013 23:05
Modified: 01/02/2012 16:29
Company: Intel Corporation
--------------------
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
1844544 bytes
Created: 27/03/2013 23:01
Modified: 19/07/2012 9:53
Company: Intel Corporation
--------------------
C:\Program Files (x86)\HP\Common\HpDeviceDetection3.exe
217864 bytes
Created: 11/12/2014 11:34
Modified: 11/12/2014 11:34
Company: Hewlett-Packard Company
--------------------
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
856904 bytes
Created: 18/11/2014 21:56
Modified: 14/11/2014 22:15
Company: Google Inc.
--------------------
C:\Windows\System32\notepad.exe
193536 bytes
Created: 14/07/2009 0:56
Modified: 14/07/2009 2:39
Company: Microsoft Corporation
--------------------
C:\Program Files (x86)\Trojan Remover\Rmvtrjan.exe
FileSize: 5484896
[This is a Trojan Remover component]
--------------------
--------------------
C:\Windows\System32\SearchProtocolHost.exe
249856 bytes
Created: 28/04/2014 3:39
Modified: 28/04/2014 3:39
Company: Microsoft Corporation
--------------------
C:\Windows\System32\SearchFilterHost.exe
113664 bytes
Created: 28/04/2014 3:39
Modified: 28/04/2014 3:39
Company: Microsoft Corporation
--------------------
************************************************************
21:11:03: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
21:11:03: Checking ----- ROGUE BROWSER MODIFICATIONS -----
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\Windows\SysWOW64\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\Windows\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://www.google.com
************************************************************
=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
Scan completed at: 21:11:04 19 feb 2015
Total Scan time: 00:00:50
************************************************************