DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 11.0.9600.17496 Run by [removed] at 18:19:28 on 2015-02-08 Microsoft Windows 7 Professional 6.1.7601.1.1252.31.1043.18.4095.2408 [GMT 1:00] . AV: Bitdefender Antivirus *Enabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D} SP: Bitdefender Antispyware *Enabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Bitdefender\Bitdefender\vsserv.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Tablet\Wacom\WTabletServicePro.exe C:\Windows\system32\atieclxx.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\taskhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe C:\Program Files\Tablet\Wacom\WacomHost.exe C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE C:\Program Files\Bitdefender\Bitdefender\bdagent.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\spool\drivers\x64\3\E_IATI9SA.EXE C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe C:\Program Files (x86)\Datacolor\SpyderGallery Desktop\SpyderGallery Desktop.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\cmd.exe C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcrnmh.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = about:blank mWinlogon: Userinit = userinit.exe BHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [EPSON Stylus Photo R2400] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATI9SA.EXE /FU "C:\Windows\TEMP\E_SEE63.tmp" /EF "HKCU" uRun: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" uRun: [Bitdefender Agent Wallet-toepassing] "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" uRun: [Bitdefender Wallet] "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" dRun: [Bitdefender Wallet Agent] "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" dRun: [Bitdefender Wallet] "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard dRun: [Bitdefender Agent Wallet-toepassing] "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" StartupFolder: C:\Users\Mark\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Mark\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SPYDER~2.LNK - C:\Program Files (x86)\Datacolor\SpyderGallery Desktop\SpyderGallery Desktop.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SPYDER~1.LNK - C:\Program Files (x86)\Datacolor\Spyder4Elite\Utility\SpyderUtility.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 TCP: NameServer = 192.168.178.1 TCP: Interfaces\{0F4D2F9C-9052-4AE0-B3C5-FC5BF3E0E6FE} : DHCPNameServer = 192.168.178.1 TCP: Interfaces\{35B0CBF3-07FA-485F-A105-85C654826B56} : DHCPNameServer = 192.168.178.1 SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-mStart Page = about:blank x64-BHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Run: [Bdagent] "C:\Program Files\Bitdefender\Bitdefender\bdagent.exe" x64-SSODL: WebCheck - . ============= SERVICES / DRIVERS =============== . R0 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2014-4-3 893440] R0 gzflt;gzflt;C:\Windows\System32\drivers\gzflt.sys [2014-4-3 150256] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2014-4-3 103504] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-8-18 203264] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088] R2 UPDATESRV;Bitdefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [2014-4-3 67320] R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2014-1-25 671512] R3 avchv;avchv Function Driver;C:\Windows\System32\drivers\avchv.sys [2014-4-3 261056] R3 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2014-4-3 635392] R3 hidkmdf;KMDF Driver;C:\Windows\System32\drivers\hidkmdf.sys [2014-1-25 14136] R3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\drivers\wachidrouter.sys [2014-1-25 100664] R3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\drivers\wacomrouterfilter.sys [2014-1-25 15160] R3 yukonw7;NDIS6.2 Minipoortstuurprogramma voor Marvell Yukon Ethernet-controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120] S3 BDSandBox;BDSandBox;C:\Windows\System32\drivers\bdsandbox.sys [2014-4-3 82824] S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168] S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-12-13 114688] S3 Spyder4;Datacolor Spyder4;C:\Windows\System32\drivers\dccmtr.sys [2011-7-12 15360] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2013-3-18 54784] S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-1-19 1255736] . =============== File Associations =============== . FileExt: .txt: txtfile="C:\Windows\System32\NOTEPAD.EXE" %1 FileExt: .ini: inifile="C:\Windows\System32\NOTEPAD.EXE" %1 FileExt: .inf: inffile="C:\Windows\System32\NOTEPAD.EXE" %1 . =============== Created Last 30 ================ . 2015-01-17 17:59:40 -------- d-----w- C:\Users\Mark\AppData\Local\Popcorn Time 2015-01-17 09:10:45 141312 ----a-w- C:\Windows\System32\drivers\mrxdav.sys 2015-01-14 17:45:55 52736 ----a-w- C:\Windows\System32\TSWbPrxy.exe 2015-01-14 17:45:54 210432 ----a-w- C:\Windows\System32\profsvc.dll 2015-01-14 17:45:53 52224 ----a-w- C:\Windows\SysWow64\nlaapi.dll 2015-01-14 17:45:53 303616 ----a-w- C:\Windows\System32\nlasvc.dll 2015-01-14 17:45:53 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll 2015-01-14 17:45:47 5553592 ----a-w- C:\Windows\System32\ntoskrnl.exe 2015-01-14 17:45:47 3971512 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2015-01-14 17:45:47 3916728 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2015-01-14 17:45:46 503808 ----a-w- C:\Windows\System32\srcore.dll 2015-01-14 17:45:46 50176 ----a-w- C:\Windows\System32\srclient.dll 2015-01-14 17:45:46 43008 ----a-w- C:\Windows\SysWow64\srclient.dll 2015-01-14 17:45:46 296960 ----a-w- C:\Windows\System32\rstrui.exe . ==================== Find3M ==================== . 2015-01-28 17:54:40 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2015-01-28 17:54:40 701616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2014-12-22 20:42:54 2029336 ----a-w- C:\Windows\System32\WacomMT.dll 2014-12-22 20:42:54 1997592 ----a-w- C:\Windows\System32\Wacom_Tablet.dll 2014-12-22 20:42:54 1990936 ----a-w- C:\Windows\System32\Wacom_Touch_Tablet.dll 2014-12-22 20:42:54 1863960 ----a-w- C:\Windows\System32\Wintab32.dll 2014-12-22 20:42:51 1626392 ----a-w- C:\Windows\SysWow64\WacomMT.dll 2014-12-22 20:42:51 1618712 ----a-w- C:\Windows\SysWow64\Wacom_Tablet.dll 2014-12-22 20:42:51 1612056 ----a-w- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll 2014-12-22 20:42:51 1497368 ----a-w- C:\Windows\SysWow64\Wintab32.dll 2014-12-13 05:09:01 144384 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-12-13 03:33:44 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2014-12-04 02:50:55 413184 ----a-w- C:\Windows\System32\generaltel.dll 2014-12-04 02:50:45 741376 ----a-w- C:\Windows\System32\invagent.dll 2014-12-04 02:50:40 396800 ----a-w- C:\Windows\System32\devinv.dll 2014-12-04 02:50:38 830976 ----a-w- C:\Windows\System32\appraiser.dll 2014-12-04 02:50:37 227328 ----a-w- C:\Windows\System32\aepdu.dll 2014-12-04 02:50:37 192000 ----a-w- C:\Windows\System32\aepic.dll 2014-12-04 02:44:48 1083392 ----a-w- C:\Windows\System32\aeinv.dll 2014-12-01 23:28:44 1232040 ----a-w- C:\Windows\System32\aitstatic.exe 2014-11-22 03:06:23 2724864 ----a-w- C:\Windows\System32\mshtml.tlb 2014-11-22 03:06:11 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll 2014-11-22 02:50:39 66560 ----a-w- C:\Windows\System32\iesetup.dll 2014-11-22 02:50:10 580096 ----a-w- C:\Windows\System32\vbscript.dll 2014-11-22 02:49:54 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll 2014-11-22 02:48:20 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll 2014-11-22 02:35:29 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-11-22 02:34:51 814080 ----a-w- C:\Windows\System32\jscript9diag.dll 2014-11-22 02:34:07 6039552 ----a-w- C:\Windows\System32\jscript9.dll 2014-11-22 02:26:31 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-11-22 02:20:44 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2014-11-22 02:14:16 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-11-22 02:07:43 501248 ----a-w- C:\Windows\SysWow64\vbscript.dll 2014-11-22 02:07:17 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll 2014-11-22 02:06:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll 2014-11-22 02:05:02 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll 2014-11-22 01:54:30 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll 2014-11-22 01:47:10 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll 2014-11-22 01:46:58 2125312 ----a-w- C:\Windows\System32\inetcpl.cpl 2014-11-22 01:40:04 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll 2014-11-22 01:29:26 4299264 ----a-w- C:\Windows\SysWow64\jscript9.dll 2014-11-22 01:28:21 2358272 ----a-w- C:\Windows\System32\wininet.dll 2014-11-22 01:22:49 2052096 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2014-11-22 01:21:57 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll 2014-11-22 01:00:20 1888256 ----a-w- C:\Windows\SysWow64\wininet.dll 2014-11-11 03:09:06 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll 2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll 2014-11-11 03:08:48 728064 ----a-w- C:\Windows\System32\kerberos.dll 2014-11-11 02:44:45 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll 2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll 2014-11-11 01:46:26 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys . ============= FINISH: 18:20:04,99 ===============