Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 29-04-2014
Scan Time: 18:22:07
Logfile: 1.txt
Administrator: No
Version: 2.00.1.1004
Malware Database: v2014.04.29.04
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Benjamin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 348209
Time Elapsed: 59 min, 51 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, Quarantined, [8f8934fcfa813ef84539fba443c0df21],
Registry Values: 3
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{7473B6BD-4691-4744-A82B-7854EB3D70B6}, Quarantined, [26f27fb1d2a956e07f85a07c6e943ec2],
PUP.Optional.UTorrentControl.A, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{7473B6BD-4691-4744-A82B-7854EB3D70B6}, ½¶stâ??FDG¨+xTë=p¶, Quarantined, [26f27fb1d2a956e07f85a07c6e943ec2]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 11111111, Quarantined, [8f8934fcfa813ef84539fba443c0df21]
Registry Data: 5
PUP.Optional.Snapdo, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page,
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013, Good: (
http://www.google.com), Bad: (
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013),Replaced,[7c9c5cd49fdc5ed8356746eda262d52b]
PUP.Optional.Snapdo, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar,
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013, Good: (
http://www.google.com), Bad: (
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013),Replaced,[d7419f91d9a2af87e5b693a0ec181de3]
PUP.Optional.Snapdo, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL,
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013, Good: (
http://www.google.com), Bad: (
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013),Replaced,[997f9f912b50b87eccd2979c47bd19e7]
PUP.Optional.Snapdo, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant,
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013, Good: (
http://www.google.com), Bad: (
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013),Replaced,[22f62b050f6c76c0435cc172857f29d7]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1428500662-700679857-515325075-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default,
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013, Good: (
www.google.com), Bad: (
http://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DK&userid=e7f1fe5a-0eed-4a5a-b505-a8ad3a72ff42&searchtype=ds&q={searchTerms}&installDate=13/04/2013),Replaced,[72a6111fc7b4a5916bca1a10d62e7b85]
Folders: 10
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\components, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\defaults, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\defaults\preferences, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
Files: 87
PUP.Adware.Agent, C:\Users\Benjamin\Downloads\PowerDirector_11_Ultimate_Suite.exe, Quarantined, [67b1f937186380b6d2cca80d6a96916f],
PUP.Optional.Softonic.A, C:\Users\Benjamin\Downloads\SoftonicDownloader_for_hamachi.exe, Quarantined, [8296af812f4c22149c0333e9986928d8],
PUP.Optional.Softonic, C:\Users\Benjamin\Downloads\SoftonicDownloader_for_latency-optimizer.exe, Quarantined, [3edaba7689f287afd7698f72ac55b64a],
PUP.Optional.Softonic.A, C:\Users\Benjamin\Downloads\SoftonicDownloader_for_painttool-sai.exe, Quarantined, [22f61c143b40a096732c021aba47ef11],
PUP.Optional.Softonic, C:\Users\Benjamin\Downloads\SoftonicDownloader_for_process-tamer.exe, Quarantined, [be5a37f9384302344cf4ee138c752ad6],
PUP.Optional.Topmedia, C:\Users\Benjamin\Downloads\Ratatouille.iso_secure.exe, Quarantined, [2deb1f11631861d5f13d44baa45faf51],
PUP.Optional.Freemium.A, C:\Users\Benjamin\Downloads\CR_Downloader_for_baldur's-gate---dark-alliance.exe, Quarantined, [928609276318c274dd8070b3fc05639d],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIA50A.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [ca4ec36d27548caa1dfa0529817f43bd],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1328711180.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1329394333.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1340650008.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1347099202.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1348169355.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1348848054.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1349551314.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1350635134.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\1351188536.reg, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\ExcludeList.rcp, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\proupdate.tmp, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\rcpupdate.ini, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\TempHLList.rcp, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000002.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000002.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000003.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000003.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000004.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000004.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000005.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000005.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000006.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000006.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000007.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000007.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000008.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000008.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000009.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000009.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000010.rmx, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.RegCleanerPro.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000010.rxb, Quarantined, [d54387a92d4eec4a238b481dab57748c],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\chrome.manifest, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\install.rdf, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\babylon.css, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\babylon.xul, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\mtstart.js, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\server.js, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\tmplt.js, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\home.gif, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
PUP.Optional.Babylon.A, C:\Users\Benjamin Vinterberg\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js, Quarantined, [0f090c24c5b6ec4ac71985e5d82ac13f],
Physical Sectors: 0
(No malicious items detected)
(end)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:00:22, on 29-04-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)
Boot mode: Normal
Running processes:
C:\Users\Benjamin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Benjamin\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
C:\Users\Benjamin\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Update\29.0.0.6292\TorchUpdate.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\AppData\Local\Torch\Application\torch.exe
C:\Users\Benjamin\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [D-Link D-Link Wireless N Dual Band DWA-160 ] C:\Program Files (x86)\D-Link\DWA-160\AirNCFG.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Pando Media Booster] "C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Benjamin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [LOLReplay Recorder] "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize
O4 - HKCU\..\Run: [Dargon] C:\Program Files (x86)\Dargon\DargonD.exe
O4 - HKCU\..\Run: [AVG-Secure-Search-Update_0214b] "C:\Program Files (x86)\AVG SafeGuard toolbar\AVG-Secure-Search-Update_0214b.exe" /PROMPT /CMPID=0214b
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Benjamin\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETVÆRKSTJENESTE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
http://*.hola.orgO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O20 - AppInit_DLLs: c:\progra~2\citrix\icacli~1\rshook.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: D-Link Wireless N Dual Band DWA-160 _WPS Service (D-Link Wireless N Dual Band DWA-160 _WPS) - Unknown owner - C:\Program Files (x86)\D-Link\DWA-160\ANIWConnService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Tjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Torch Crash Handler (TorchCrashHandler) - TorchMedia Inc. - C:\Users\Benjamin\AppData\Local\Torch\Update\TorchCrashHandler.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.0.5 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Consumer Service (WTabletServiceCon) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
--
End of file - 13702 bytes