logjes kijken aub

  • asteri

    Goede avond,

    Wil iemand aub naar mijn logjes kijken??Mijn pc + installatie is nog geen maand oud, alles gedaan door gerenomeerd epc boer, maar ik krijg ineens de melding dat mijn Windows 7 een niet legitiem exemplaar is. Tot op vandaag geen enkel probleem gehad.

    Misschien heb ik toch het beruchte Politie virus opgelopen?? Of is er inderdaad iets met meijn Windows 7 mis??

    scan van Norton : geen threads gevonden

    Eset scan: geen threads gevonden

    RSIT log en de nader logjes:

    Logfile of random's system information tool 1.09 (written by random/random)

    Run by A. Sotirakis at 2013-09-29 18:40:34

    Microsoft Windows 7 Home Premium Service Pack 1

    System drive C: has 419 GB (90%) free of 467 GB

    Total RAM: 3781 MB (54% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:40:40, on 29-9-2013

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v10.0 (10.00.9200.16686)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\ccSvcHst.exe

    C:\Program Files (x86)\Logitech\Vid HD\Vid.exe

    C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe

    C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files\trend micro\A. Sotirakis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe

    O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll

    O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\coIEPlg.dll

    O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\IPS\IPSBHO.DLL

    O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\coIEPlg.dll

    O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide

    O4 - HKLM\..\Run: C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon

    O4 - HKLM\..\RunOnce: C:\Program Files (x86)\SMINST\Launcher.exe

    O4 - HKCU\..\Run: “C:\Program Files (x86)\Logitech\Vid HD\Vid.exe” -bootmode

    O4 - HKCU\..\Run: “C:\Users\A. Sotirakis\AppData\Local\Facebook\Update\FacebookUpdate.exe” /c /nocrashserver

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)

    O4 - Startup: Logitech . Productregistratie.lnk = C:\Program Files (x86)\Logitech\Ereg\eReg.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\Microsoft Office\Office10\EXCEL.EXE/3000

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: Accelerated graphics

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe

    O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\ccSvcHst.exe

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    End of file - 8883 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    winlogon.exe

    wininit.exe

    C:\Windows\system32\services.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\svchost.exe -k netsvcs

    “C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe”

    C:\Windows\system32\svchost.exe -k GPSvcGroup

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    “taskhost.exe”

    “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    “C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE”

    “C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe”

    “C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe”

    “C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\ccSvcHst.exe” /s “N360” /m “C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\diMaster.dll” /prefetch:1

    “C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe” /starttray

    C:\Windows\system32\svchost.exe -k imgsvc

    “C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE”

    “C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\ccSvcHst.exe” /c /a /s UserSession2

    WLIDSvcM.exe 1964

    C:\Windows\system32\sppsvc.exe

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    “C:\Windows\system32\Dwm.exe”

    C:\Windows\Explorer.EXE

    “C:\Windows\System32\igfxtray.exe”

    “C:\Windows\System32\hkcmd.exe”

    “C:\Windows\System32\igfxpers.exe”

    “C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe” -s

    “C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe”

    “C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE” /logon

    “C:\Program Files (x86)\Logitech\Vid HD\Vid.exe” -bootmode

    “C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe” -hide

    “C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE” /logon

    C:\Windows\splwow64.exe 8192

    C:\Windows\system32\SearchIndexer.exe /Embedding

    “C:\Program Files\Windows Media Player\wmpnetwk.exe”

    “C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe”

    “C:\Program Files (x86)\Mozilla Firefox\firefox.exe”

    “C:\Windows\system32\SearchProtocolHost.exe” Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 “Software\Microsoft\Windows Search” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)” “C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc” “DownLevelDaemon”

    “C:\Windows\system32\SearchFilterHost.exe” 0 516 520 528 65536 524

    “C:\Users\A. Sotirakis\Desktop\RSITx64.exe”

    C:\Windows\system32\wbem\wmiprvse.exe

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job

    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1205618074-3359576139-1583540805-1000Core.job

    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1205618074-3359576139-1583540805-1000UA.job

    =========Mozilla firefox=========

    ProfilePath - C:\Users\A. Sotirakis\AppData\Roaming\Mozilla\Firefox\Profiles\nvefy7jb.default

    “Description”=Adobe® Flash® Player 11.8.800.168 Plugin

    “Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll

    “Description”=Canon Easy-PhotoPrint EX

    “Path”=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

    “Description”=

    “Path”=disabled

    “Description”=Ag Player Plugin

    “Path”=c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll

    “Description”=WLPG Install MIME type

    “Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    “Description”=Handles PDFs in-place in Firefox

    “Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

    “Description”=

    “Path”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll

    “Description”=Adobe® Flash® Player 11.8.800.168 Plugin

    “Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll

    “Description”=

    “Path”=disabled

    “Description”=Ag Player Plugin

    “Path”=c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll

    “Description”=

    “Path”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll

    C:\Users\A. Sotirakis\AppData\Roaming\Mozilla\Firefox\Profiles\nvefy7jb.default\extensions\

    en-US@dictionaries.addons.mozilla.org

    ======Registry dump======

    Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll

    Norton Identity Protection - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\coIEPlg.dll

    Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\IPS\IPSBHO.DLL

    Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\coIEPlg.dll

    {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll

    “IgfxTray”=C:\Windows\system32\igfxtray.exe

    “HotKeysCmds”=C:\Windows\system32\hkcmd.exe

    “Persistence”=C:\Windows\system32\igfxpers.exe

    “RTHDVCPL”=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

    “AdobeAAMUpdater-1.0”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe

    “CanonMyPrinter”=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe

    “Logitech Vid”=C:\Program Files (x86)\Logitech\Vid HD\Vid.exe

    “Facebook Update”=C:\Users\A. Sotirakis\AppData\Local\Facebook\Update\FacebookUpdate.exe

    “Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    “LWS”=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe

    “CanonSolutionMenuEx”=C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

    “Launcher”=C:\Program Files (x86)\SMINST\Launcher.exe

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

    Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE

    C:\Users\A. Sotirakis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

    Logitech . Productregistratie.lnk - C:\Program Files (x86)\Logitech\Ereg\eReg.exe

    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

    “SecurityProviders”=credssp.dll

    “ConsentPromptBehaviorAdmin”=5

    “ConsentPromptBehaviorUser”=3

    “EnableUIADesktopToggle”=0

    “dontdisplaylastusername”=0

    “legalnoticecaption”=

    “legalnoticetext”=

    “shutdownwithoutlogon”=1

    “undockwithoutlogon”=1

    “NoActiveDesktop”=1

    “NoActiveDesktopChanges”=1

    “ForceActiveDesktopOn”=0

    “vidc.mrle”=msrle32.dll

    “vidc.msvc”=msvidc32.dll

    “msacm.imaadpcm”=imaadp32.acm

    “msacm.msg711”=msg711.acm

    “msacm.msgsm610”=msgsm32.acm

    “msacm.msadpcm”=msadp32.acm

    “midimapper”=midimap.dll

    “wavemapper”=msacm32.drv

    “VIDC.UYVY”=msyuv.dll

    “VIDC.YUY2”=msyuv.dll

    “VIDC.YVYU”=msyuv.dll

    “VIDC.IYUV”=iyuv_32.dll

    “vidc.i420”=lvcod64.dll

    “VIDC.YVU9”=tsbyuv.dll

    “msacm.l3acm”=C:\Windows\System32\l3codeca.acm

    “wave1”=wdmaud.drv

    “midi1”=wdmaud.drv

    “mixer1”=wdmaud.drv

    “aux1”=wdmaud.drv

    “wave”=wdmaud.drv

    “midi”=wdmaud.drv

    “mixer”=wdmaud.drv

    “aux”=wdmaud.drv

    “MSVideo8”=VfWWDM32.dll

    “MSVideo”=vfwwdm32.dll

    “wave2”=wdmaud.drv

    “midi2”=wdmaud.drv

    “mixer2”=wdmaud.drv

    “aux2”=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    .js - open - C:\Windows\System32\WScript.exe “%1” %*

    ======List of files/folders created in the last 1 month======

    2013-09-29 18:40:34 —-D—- C:\rsit

    2013-09-29 18:40:34 —-D—- C:\Program Files\trend micro

    2013-09-29 18:13:23 —-D—- C:\Program Files (x86)\ESET

    2013-09-29 18:06:24 —-D—- C:\AdwCleaner

    2013-09-21 11:17:58 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Malwarebytes

    2013-09-21 11:17:50 —-D—- C:\ProgramData\Malwarebytes

    2013-09-21 11:17:49 —-D—- C:\Program Files (x86)\Malwarebytes' Anti-Malware

    2013-09-21 11:17:49 —-A—- C:\Windows\system32\drivers\mbam.sys

    2013-09-13 10:35:08 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Windows Live Writer

    2013-09-12 20:33:34 —-A—- C:\Users\A. Sotirakis\AppData\Roaming\GDIPFONTCACHEV1.DAT

    2013-09-12 20:33:03 —-D—- C:\Program Files (x86)\MSECache

    2013-09-12 19:29:55 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Skype

    2013-09-11 22:14:34 —-A—- C:\Windows\SYSWOW64\ieui.dll

    2013-09-11 22:14:34 —-A—- C:\Windows\system32\ieui.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe

    2013-09-11 22:14:33 —-A—- C:\Windows\SYSWOW64\iesysprep.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\SYSWOW64\iesetup.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\SYSWOW64\iertutil.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\SYSWOW64\iernonce.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\RegisterIEPKEYs.exe

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\iesysprep.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\iesetup.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\iertutil.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\iernonce.dll

    2013-09-11 22:14:33 —-A—- C:\Windows\system32\ie4uinit.exe

    2013-09-11 22:14:32 —-A—- C:\Windows\SYSWOW64\msfeeds.dll

    2013-09-11 22:14:32 —-A—- C:\Windows\SYSWOW64\jscript.dll

    2013-09-11 22:14:32 —-A—- C:\Windows\system32\msfeeds.dll

    2013-09-11 22:14:32 —-A—- C:\Windows\system32\jscript9.dll

    2013-09-11 22:14:32 —-A—- C:\Windows\system32\jscript.dll

    2013-09-11 22:14:31 —-A—- C:\Windows\SYSWOW64\urlmon.dll

    2013-09-11 22:14:31 —-A—- C:\Windows\SYSWOW64\jscript9.dll

    2013-09-11 22:14:31 —-A—- C:\Windows\system32\urlmon.dll

    2013-09-11 22:14:30 —-A—- C:\Windows\SYSWOW64\wininet.dll

    2013-09-11 22:14:30 —-A—- C:\Windows\SYSWOW64\jsproxy.dll

    2013-09-11 22:14:30 —-A—- C:\Windows\system32\wininet.dll

    2013-09-11 22:14:30 —-A—- C:\Windows\system32\jsproxy.dll

    2013-09-11 22:14:29 —-A—- C:\Windows\SYSWOW64\ieframe.dll

    2013-09-11 22:14:29 —-A—- C:\Windows\system32\ieframe.dll

    2013-09-11 22:14:28 —-A—- C:\Windows\system32\mshtml.dll

    2013-09-11 22:14:26 —-A—- C:\Windows\SYSWOW64\mshtml.dll

    2013-09-11 21:22:16 —-A—- C:\Windows\system32\drivers\ataport.sys

    2013-09-11 21:22:15 —-A—- C:\Windows\SYSWOW64\ntoskrnl.exe

    2013-09-11 21:22:15 —-A—- C:\Windows\SYSWOW64\ntkrnlpa.exe

    2013-09-11 21:22:15 —-A—- C:\Windows\SYSWOW64\ntdll.dll

    2013-09-11 21:22:15 —-A—- C:\Windows\system32\ntoskrnl.exe

    2013-09-11 21:22:15 —-A—- C:\Windows\system32\ntdll.dll

    2013-09-11 21:22:15 —-A—- C:\Windows\system32\KernelBase.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll

    2013-09-11 21:22:14 —-AH—- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\wow32.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\user.exe

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\setup16.exe

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\ntvdm64.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\KernelBase.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\kernel32.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\instnm.exe

    2013-09-11 21:22:14 —-A—- C:\Windows\SYSWOW64\apisetschema.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\wow64win.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\wow64cpu.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\wow64.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\winsrv.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\smss.exe

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\ntvdm64.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\kernel32.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\csrsrv.dll

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\conhost.exe

    2013-09-11 21:22:14 —-A—- C:\Windows\system32\apisetschema.dll

    2013-09-11 21:22:13 —-A—- C:\Windows\system32\win32k.sys

    2013-09-11 21:22:13 —-A—- C:\Windows\system32\shell32.dll

    2013-09-11 21:22:12 —-A—- C:\Windows\SYSWOW64\shell32.dll

    2013-09-11 21:22:12 —-A—- C:\Windows\SYSWOW64\shdocvw.dll

    2013-09-11 21:22:12 —-A—- C:\Windows\system32\shdocvw.dll

    2013-09-10 20:54:25 —-D—- C:\Program Files\CCleaner

    2013-09-09 17:17:45 —-D—- C:\ProgramData\Licenses

    2013-09-09 17:17:45 —-AD—- C:\ProgramData\TEMP

    2013-09-09 17:17:42 —-D—- C:\Program Files (x86)\SpywareBlaster

    2013-09-04 20:12:05 —-A—- C:\Windows\ODBC.INI

    2013-09-04 20:11:27 —-D—- C:\Windows\Msagent

    2013-09-04 20:11:26 —-D—- C:\Program Files (x86)\Microsoft Office

    2013-09-04 19:56:15 —-HD—- C:\ProgramData\CanonIJScan

    2013-09-04 19:55:28 —-D—- C:\ProgramData\CanonIJ

    2013-09-04 19:52:36 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Canon

    2013-09-04 19:46:42 —-HD—- C:\ProgramData\CanonIJEPPEX

    2013-09-04 19:41:05 —-HD—- C:\ProgramData\CanonIJSolutionMenuEX

    2013-09-04 19:41:04 —-HD—- C:\ProgramData\CanonIJMyPrinter

    2013-09-04 19:41:04 —-HD—- C:\ProgramData\CanonIJEPPEX2

    2013-09-04 19:41:04 —-HD—- C:\ProgramData\CanonEPP

    2013-09-04 19:40:26 —-D—- C:\ProgramData\CanonIJPLM

    2013-09-04 19:39:24 —-A—- C:\Windows\system32\CNMLMAA.DLL

    2013-09-04 19:39:20 —-A—- C:\Windows\SYSWOW64\CNHMCA.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\SYSWOW64\CNC280U.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\SYSWOW64\CNC280L.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\system32\CNHMCA6.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\system32\CNC280L.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\system32\CNC280I.dll

    2013-09-04 19:39:20 —-A—- C:\Windows\system32\CNC280C.dll

    2013-09-04 19:37:49 —-D—- C:\ProgramData\CanonIJMSetup

    2013-09-04 19:36:54 —-D—- C:\Program Files\Common Files\CANON

    2013-09-04 19:36:46 —-D—- C:\ProgramData\CanonIJWSpt

    2013-09-04 19:35:52 —-D—- C:\Program Files\Canon

    2013-09-04 19:35:22 —-HD—- C:\ProgramData\CanonBJ

    2013-09-04 19:35:19 —-HD—- C:\Windows\system32\CanonIJ Uninstaller Information

    2013-09-04 19:35:03 —-A—- C:\Windows\system32\CNMIUAA.DLL

    2013-09-04 19:34:57 —-HD—- C:\Program Files\CanonBJ

    2013-09-04 19:32:59 —-D—- C:\Program Files (x86)\Canon

    2013-09-03 22:15:14 —-D—- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2

    2013-09-03 18:55:38 —-D—- C:\ProgramData\VirtualizedApplications

    2013-09-03 18:13:46 —-D—- C:\ProgramData\McAfee

    2013-09-03 16:45:13 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\SoftGrid Client

    2013-09-03 15:41:37 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Skype old

    2013-09-03 15:41:32 —-RD—- C:\Program Files (x86)\Skype

    2013-09-03 15:41:31 —-D—- C:\ProgramData\Skype

    2013-09-03 14:31:09 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Mozilla

    2013-09-03 14:31:01 —-D—- C:\ProgramData\Mozilla

    2013-09-03 14:31:01 —-D—- C:\Program Files (x86)\Mozilla Maintenance Service

    2013-09-03 14:31:00 —-D—- C:\Program Files (x86)\Mozilla Firefox

    2013-09-03 13:51:13 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe

    2013-09-03 13:51:11 —-D—- C:\Windows\system32\Macromed

    2013-09-02 17:36:06 —-A—- C:\Windows\SYSWOW64\rpcrt4.dll

    2013-09-02 17:36:06 —-A—- C:\Windows\system32\rpcrt4.dll

    2013-09-02 17:36:05 —-A—- C:\Windows\SYSWOW64\tzres.dll

    2013-09-02 17:36:05 —-A—- C:\Windows\system32\tzres.dll

    2013-09-02 17:36:03 —-A—- C:\Windows\system32\drivers\tcpip.sys

    2013-09-02 17:36:02 —-A—- C:\Windows\SYSWOW64\wintrust.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\SYSWOW64\cryptsvc.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\SYSWOW64\cryptnet.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\SYSWOW64\crypt32.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\system32\wintrust.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\system32\cryptsvc.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\system32\cryptnet.dll

    2013-09-02 17:36:02 —-A—- C:\Windows\system32\crypt32.dll

    2013-09-02 17:36:00 —-A—- C:\Windows\SYSWOW64\WMVDECOD.DLL

    2013-09-02 17:36:00 —-A—- C:\Windows\system32\WMVDECOD.DLL

    2013-09-02 17:35:59 —-A—- C:\Windows\system32\drivers\tssecsrv.sys

    2013-09-02 17:34:54 —-D—- C:\ProgramData\regid.1986-12.com.adobe

    2013-09-02 17:21:37 —-D—- C:\Program Files\Common Files\Adobe

    2013-09-02 17:21:24 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Macromedia

    2013-09-02 17:21:17 —-D—- C:\Windows\SYSWOW64\Macromed

    2013-09-02 17:17:18 —-N—- C:\Windows\system32\drivers\PxHlpa64.sys

    2013-09-02 17:17:18 —-N—- C:\Windows\system32\drivers\cdralw2k.sys

    2013-09-02 17:17:18 —-N—- C:\Windows\system32\drivers\cdr4_xp.sys

    2013-09-02 17:06:45 —-D—- C:\Program Files\Common Files\Symantec Shared

    2013-09-02 17:06:45 —-A—- C:\Windows\system32\drivers\SYMEVENT64x86.SYS

    2013-09-02 17:05:58 —-D—- C:\Windows\system32\drivers\N360x64

    2013-09-02 17:05:57 —-D—- C:\Program Files (x86)\Norton 360 Premier Edition

    2013-09-02 15:27:12 —-D—- C:\ProgramData\Norton

    2013-09-02 15:21:19 —-D—- C:\ProgramData\NortonInstaller

    2013-09-02 15:21:19 —-D—- C:\Program Files (x86)\NortonInstaller

    2013-09-02 15:21:12 —-D—- C:\ProgramData\LogiShrd

    2013-09-02 15:17:37 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Leadertech

    2013-09-02 15:17:04 —-D—- C:\Program Files\Common Files\Logishrd

    2013-09-02 15:16:57 —-D—- C:\ProgramData\Logitech

    2013-09-02 15:16:25 —-D—- C:\Program Files (x86)\Logitech

    2013-09-02 15:12:24 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Adobe

    2013-09-02 15:12:15 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Identities

    2013-09-02 15:12:08 —-SD—- C:\Users\A. Sotirakis\AppData\Roaming\Microsoft

    2013-09-02 15:12:08 —-D—- C:\Users\A. Sotirakis\AppData\Roaming\Media Center Programs

    2013-09-02 15:11:53 —-SHD—- C:\ProgramData\Sjablonen

    2013-09-02 15:11:53 —-SHD—- C:\ProgramData\Menu Start

    2013-09-02 15:11:53 —-SHD—- C:\ProgramData\Favorieten

    2013-09-02 15:11:53 —-SHD—- C:\ProgramData\Documenten

    2013-09-02 15:11:53 —-SHD—- C:\ProgramData\Bureaublad

    2013-08-30 13:54:08 —-D—- C:\Windows\I386

    2013-08-30 13:54:08 —-A—- C:\Windows\system32\drivers\HECIx64.sys

    2013-08-30 13:53:22 —-A—- C:\Windows\SYSWOW64\IntelOpenCL32.dll

    2013-08-30 13:53:22 —-A—- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe

    2013-08-30 13:53:22 —-A—- C:\Windows\SYSWOW64\Intel_OpenCL_ICD32.dll

    2013-08-30 13:53:22 —-A—- C:\Windows\system32\IntelOpenCL64.dll

    2013-08-30 13:53:22 —-A—- C:\Windows\system32\Intel_OpenCL_ICD64.dll

    2013-08-30 13:53:22 —-A—- C:\Windows\system32\igfxCoIn_v2932.dll

    2013-08-30 13:53:21 —-A—- C:\Windows\system32\iglhsip64.dll

    2013-08-30 13:53:20 —-A—- C:\Windows\SYSWOW64\iglhsip32.dll

    2013-08-30 13:53:20 —-A—- C:\Windows\SYSWOW64\iglhcp32.dll

    2013-08-30 13:53:20 —-A—- C:\Windows\system32\iglhcp64.dll

    2013-08-30 13:53:20 —-A—- C:\Windows\system32\igfxtray.exe

    2013-08-30 13:53:20 —-A—- C:\Windows\system32\igfxTMM.dll

    2013-08-30 13:53:20 —-A—- C:\Windows\system32\igfxsrvc.exe

    2013-08-30 13:53:20 —-A—- C:\Windows\system32\igfxsrvc.dll

    2013-08-30 13:53:16 —-A—- C:\Windows\system32\igfxress.dll

    2013-08-30 13:53:14 —-A—- C:\Windows\SYSWOW64\igfxexps32.dll

    2013-08-30 13:53:14 —-A—- C:\Windows\SYSWOW64\igfxdv32.dll

    2013-08-30 13:53:14 —-A—- C:\Windows\system32\igfxpph.dll

    2013-08-30 13:53:14 —-A—- C:\Windows\system32\igfxpers.exe

    2013-08-30 13:53:14 —-A—- C:\Windows\system32\igfxext.exe

    2013-08-30 13:53:14 —-A—- C:\Windows\system32\igfxexps.dll

    2013-08-30 13:53:14 —-A—- C:\Windows\system32\igfxdo.dll

    2013-08-30 13:53:13 —-A—- C:\Windows\SYSWOW64\igfxcmrt32.dll

    2013-08-30 13:53:13 —-A—- C:\Windows\system32\IGFXDEVLib.dll

    2013-08-30 13:53:13 —-A—- C:\Windows\system32\igfxdev.dll

    2013-08-30 13:53:13 —-A—- C:\Windows\system32\igfxcmrt64.dll

    2013-08-30 13:53:12 —-A—- C:\Windows\system32\igfxcmjit64.dll

    2013-08-30 13:53:11 —-A—- C:\Windows\SYSWOW64\igfxcmjit32.dll

    2013-08-30 13:53:11 —-A—- C:\Windows\SYSWOW64\igfx11cmrt32.dll

    2013-08-30 13:53:11 —-A—- C:\Windows\system32\igfx11cmrt64.dll

    2013-08-30 13:53:07 —-A—- C:\Windows\system32\igdumd64.dll

    2013-08-30 13:53:04 —-A—- C:\Windows\SYSWOW64\igdumd32.dll

    2013-08-30 13:52:58 —-A—- C:\Windows\system32\igdrcl64.dll

    2013-08-30 13:52:52 —-A—- C:\Windows\SYSWOW64\igdrcl32.dll

    2013-08-30 13:52:51 —-A—- C:\Windows\system32\drivers\igdkmd64.sys

    2013-08-30 13:52:46 —-A—- C:\Windows\system32\igdfcl64.dll

    2013-08-30 13:52:39 —-A—- C:\Windows\SYSWOW64\igdfcl32.dll

    2013-08-30 13:52:39 —-A—- C:\Windows\SYSWOW64\igdde32.dll

    2013-08-30 13:52:39 —-A—- C:\Windows\system32\igdde64.dll

    2013-08-30 13:52:38 —-A—- C:\Windows\system32\igdbcl64.dll

    2013-08-30 13:52:37 —-A—- C:\Windows\SYSWOW64\igdbcl32.dll

    2013-08-30 13:52:35 —-A—- C:\Windows\system32\igd10umd64.dll

    2013-08-30 13:52:33 —-A—- C:\Windows\SYSWOW64\igd10umd32.dll

    2013-08-30 13:52:30 —-A—- C:\Windows\system32\ig7icd64.dll

    2013-08-30 13:52:28 —-A—- C:\Windows\SYSWOW64\ig7icd32.dll

    2013-08-30 13:52:20 —-A—- C:\Windows\system32\IccLibDll_x64.dll

    2013-08-30 13:52:20 —-A—- C:\Windows\system32\hkcmd.exe

    2013-08-30 13:52:20 —-A—- C:\Windows\system32\hccutils.dll

    2013-08-30 13:52:18 —-A—- C:\Windows\system32\GfxUI.exe

    2013-08-30 13:52:18 —-A—- C:\Windows\system32\gfxSrvc.dll

    2013-08-30 13:52:16 —-A—- C:\Windows\system32\difx64.exe

    2013-08-30 13:52:15 —-A—- C:\Windows\system32\IntcDAuC.dll

    2013-08-30 13:52:15 —-A—- C:\Windows\system32\drivers\IntcDAud.sys

    2013-08-30 13:52:09 —-A—- C:\Windows\system32\drivers\iaStorF.sys

    2013-08-30 13:52:08 —-A—- C:\Windows\system32\drivers\iaStorA.sys

    2013-08-30 13:49:35 —-A—- C:\Windows\csup.txt

    2013-08-30 13:02:34 —-D—- C:\Windows\SYSWOW64\SYSPREP

    2013-08-30 12:20:14 —-SHD—- C:\$RECYCLE.BIN

    2013-08-30 12:20:07 —-A—- C:\Windows\SYSWOW64\SkinMagic.txt

    2013-08-30 12:19:23 —-D—- C:\Program Files\Realtek

    2013-08-30 12:19:22 —-D—- C:\Windows\SYSWOW64\RTCOM

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\WavesGUILib64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tossaeapo64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\toseaeapo64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tosasfapo64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tosade.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tepeqapo64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tadefxapo264.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\tadefxapo.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\SRSWOW64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\SRSTSX64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\SRSTSH64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\SRSHP64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\sltech64.dll

    2013-08-30 12:18:45 —-A—- C:\Windows\system32\slprp64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\SYSWOW64\SFCOM.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\slcnt64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\sl3apo64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\SFSS_APO.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\SFNHK64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\SFCOM64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\SFAPO64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\RtPgEx64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\RtlCPAPI64.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\RTKSMSettingsIPC.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\RTKSMlfx.dll

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\drivers\rtvienna.dat

    2013-08-30 12:18:44 —-A—- C:\Windows\system32\drivers\RTKVHD64.sys

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RtkCoLDR64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RtkCfg64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RtkAPO64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RtkApi64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RTEEP64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RTEEL64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RTEEG64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RTEED64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RtDataProc64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RTCOM64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RP3DHT64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RP3DAA64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RCoRes64.dat

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\RCoInstII64.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\R4EEP64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\R4EEL64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\R4EEG64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\R4EED64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\R4EEA64A.dll

    2013-08-30 12:18:43 —-A—- C:\Windows\system32\drivers\RTAIODAT.DAT

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MISS_APO.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxVolumeSDAPO.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioVnA64.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioRealtek64.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioRealtek264.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioEQ64.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioAPOShell64.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioAPO5064.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioAPO4064.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioAPO30.dll

    2013-08-30 12:18:42 —-A—- C:\Windows\system32\MaxxAudioAPO20.dll

    2013-08-30 12:18:41 —-HD—- C:\Program Files (x86)\Temp

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\KAAPORT64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\FMAPO64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSVoiceClarityDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSU2PREC64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSU2PLFX64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSU2PGFX64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSSymmetryDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSS2SpeakerDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSS2HeadphoneDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSNeoPCDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSLimiterDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSLFXAPO64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSGFXAPONS64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSGFXAPO64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSGainCompensatorDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSBoostDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\DTSBassEnhancementDLL64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\CONEQMSAPOGUILibrary.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\AERTAR64.dll

    2013-08-30 12:18:41 —-A—- C:\Windows\system32\AERTAC64.dll

    2013-08-30 12:18:40 —-A—- C:\Windows\RtlExUpd.dll

    2013-08-30 12:14:51 —-D—- C:\ProgramData\Intel

    2013-08-30 12:14:20 —-D—- C:\Program Files (x86)\Intel

    2013-08-30 12:14:04 —-A—- C:\Windows\system32\OpenCL.DLL

    2013-08-30 12:14:03 —-A—- C:\Windows\SYSWOW64\OpenCL.DLL

    2013-08-30 12:12:48 —-D—- C:\Intel

    2013-08-30 12:12:44 —-D—- C:\Windows\SoftwareDistribution

    2013-08-30 12:12:23 —-D—- C:\Windows\FltMgr

    2013-08-30 12:11:44 —-A—- C:\Windows\system32\RTNUninst64.dll

    2013-08-30 12:11:44 —-A—- C:\Windows\system32\RtNicProp64.dll

    2013-08-30 12:11:44 —-A—- C:\Windows\system32\drivers\Rt64win7.sys

    2013-08-30 12:11:40 —-D—- C:\Program Files (x86)\Realtek

    2013-08-30 12:10:24 —-D—- C:\Program Files (x86)\Panda Security

    2013-08-30 12:09:43 —-D—- C:\ProgramData\Adobe

    2013-08-30 12:09:43 —-D—- C:\Program Files (x86)\Adobe

    2013-08-30 12:09:16 —-D—- C:\Program Files (x86)\ASM104xUSB3

    2013-08-30 12:09:05 —-HD—- C:\Program Files (x86)\InstallShield Installation Information

    2013-08-30 12:09:05 —-D—- C:\Program Files (x86)\SMINST

    2013-08-30 12:04:53 —-SHD—- C:\System Volume Information

    2013-08-30 12:04:53 —-ASH—- C:\hiberfil.sys

    2013-08-30 12:04:52 —-ASH—- C:\pagefile.sys

    ======List of files/folders modified in the last 1 month======

    2013-09-29 18:40:34 —-RD—- C:\Program Files

    2013-09-29 18:40:21 —-D—- C:\Windows\Temp

    2013-09-29 18:13:23 —-RD—- C:\Program Files (x86)

    2013-09-29 18:13:12 —-D—- C:\Windows\System32

    2013-09-29 18:13:12 —-A—- C:\Windows\system32\PerfStringBackup.INI

    2013-09-29 18:13:11 —-D—- C:\Windows\inf

    2013-09-29 18:00:37 —-D—- C:\Windows\system32\config

    2013-09-29 17:59:06 —-D—- C:\Windows\Prefetch

    2013-09-25 17:26:03 —-D—- C:\Windows

    2013-09-23 22:04:07 —-D—- C:\Windows\system32\catroot2

    2013-09-21 11:17:50 —-HD—- C:\ProgramData

    2013-09-21 11:17:49 —-D—- C:\Windows\system32\drivers

    2013-09-20 20:26:14 —-D—- C:\Windows\SysWOW64

    2013-09-18 22:18:58 —-SHD—- C:\Windows\Installer

    2013-09-16 19:43:44 —-D—- C:\Windows\rescache

    2013-09-13 21:51:55 —-D—- C:\Windows\Panther

    2013-09-13 21:51:54 —-D—- C:\Windows\debug

    2013-09-12 18:25:10 —-D—- C:\Windows\Microsoft.NET

    2013-09-12 18:24:51 —-RSD—- C:\Windows\assembly

    2013-09-12 17:53:26 —-D—- C:\Windows\winsxs

    2013-09-12 17:52:13 —-D—- C:\Program Files (x86)\Internet Explorer

    2013-09-12 17:52:12 —-D—- C:\Program Files\Internet Explorer

    2013-09-12 17:52:11 —-D—- C:\Windows\AppPatch

    2013-09-12 17:52:10 —-D—- C:\Windows\SYSWOW64\nl-NL

    2013-09-12 17:52:10 —-D—- C:\Windows\system32\nl-NL

    2013-09-12 17:52:09 —-D—- C:\Windows\system32\DriverStore

    2013-09-11 22:16:04 —-D—- C:\Windows\system32\catroot

    2013-09-11 22:12:47 —-D—- C:\Windows\system32\MRT

    2013-09-11 22:12:43 —-A—- C:\Windows\system32\MRT.exe

    2013-09-10 20:55:13 —-D—- C:\Windows\Logs

    2013-09-10 20:54:27 —-D—- C:\Windows\system32\Tasks

    2013-09-04 20:13:16 —-RSD—- C:\Windows\Fonts

    2013-09-04 20:11:42 —-D—- C:\Windows\ShellNew

    2013-09-04 20:11:40 —-D—- C:\Program Files (x86)\Common Files

    2013-09-04 20:11:27 —-D—- C:\Windows\Help

    2013-09-04 20:11:26 —-SD—- C:\ProgramData\Microsoft

    2013-09-04 20:07:11 —-D—- C:\Windows\system

    2013-09-04 20:05:54 —-D—- C:\Program Files\Common Files\Microsoft Shared

    2013-09-04 20:03:22 —-D—- C:\Windows\system32\FxsTmp

    2013-09-04 19:39:23 —-RSD—- C:\Windows\Media

    2013-09-04 19:39:22 —-D—- C:\Windows\twain_32

    2013-09-04 19:36:54 —-D—- C:\Program Files\Common Files

    2013-09-03 15:19:44 —-D—- C:\Windows\Tasks

    2013-09-02 17:02:00 —-D—- C:\Windows\system32\wdi

    2013-09-02 15:39:21 —-D—- C:\Windows\system32\LogFiles

    2013-09-02 15:12:02 —-RD—- C:\Users

    2013-09-02 15:11:53 —-D—- C:\Program Files\Windows NT

    2013-08-30 13:02:46 —-D—- C:\Windows\options

    2013-08-30 13:02:42 —-D—- C:\Windows\system32\sysprep

    2013-08-30 13:02:34 —-D—- C:\Windows\SYSWOW64\oobe

    2013-08-30 12:12:27 —-A—- C:\Windows\win.ini

    2013-08-30 12:08:43 —-D—- C:\Windows\system32\restore

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 iaStorA;iaStorA; C:\Windows\system32\drivers\iaStorA.sys

    R0 iaStorF;iaStorF; C:\Windows\system32\drivers\iaStorF.sys

    R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys

    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys

    R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1404000.028\SYMDS64.SYS

    R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1404000.028\SYMEFA64.SYS

    R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130924.001\BHDrvx64.sys

    R1 ccSet_N360;Norton 360 Settings Manager; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys

    R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys

    R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130927.002\IDSvia64.sys

    R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS

    R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS

    R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS

    R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys

    R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys

    R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

    R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys

    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys

    R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys

    R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys

    R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys

    R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130928.006\ENG64.SYS

    R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130928.006\EX64.SYS

    R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys

    R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS

    R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS

    S3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys

    S3 LVUVC64;Logitech HD Webcam C310(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys

    S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys

    S3 Prot6Flt;Prot6Flt; C:\Windows\system32\DRIVERS\Prot6Flt.sys

    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys

    S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys

    S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys

    S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys

    S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe

    R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE

    R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    R2 N360;Norton 360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.4.0.40\ccSvcHst.exe

    R2 UMVPFSrv;UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

    S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe

    S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe

    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

    —————–EOF—————–

    # AdwCleaner v3.005 - Report created 29/09/2013 at 18:08:06

    # Updated 22/09/2013 by Xplode

    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Username : A. Sotirakis - ASOTIRAKIS-PC

    # Running from : C:\Users\A. Sotirakis\Desktop\adwcleaner.exe

    # Option : Clean

    ***** *****

    ***** *****

    ***** *****

    ***** *****

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

    ***** *****

    -\\ Internet Explorer v10.0.9200.16686

    -\\ Mozilla Firefox v23.0.1 (nl)

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner\AdwCleaner.txt - ##########

    # AdwCleaner v3.005 - Report created 29/09/2013 at 18:06:35

    # Updated 22/09/2013 by Xplode

    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Username : A. Sotirakis - ASOTIRAKIS-PC

    # Running from : C:\Users\A. Sotirakis\Desktop\adwcleaner.exe

    # Option : Scan

    ***** *****

    ***** *****

    ***** *****

    ***** *****

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}

    ***** *****

    -\\ Internet Explorer v10.0.9200.16686

    -\\ Mozilla Firefox v23.0.1 (nl)

    *************************

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner\AdwCleaner.txt - ##########

    Malwarebytes Anti-Malware (-evaluatieversie-) 1.75.0.1300

    www.malwarebytes.org

    Databaseversie: v2013.09.29.04

    Windows 7 Service Pack 1 x64 NTFS

    Internet Explorer 10.0.9200.16686

    A. Sotirakis :: ASOTIRAKIS-PC

    Bescherming: Ingeschakeld

    29-9-2013 18:10:45

    mbam-log-2013-09-29 (18-10-45).txt

    Scan type: Snelle scan

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 193985

    Verstreken tijd: 1 minuut/minuten, 18 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

  • fazantje

    Hoi Asteri,

    Ik heb een feestje gehad, dus niet verantwoord om logjes na te kijken.

    Ik hoorde net dat Ben toevallig ook een feestje had, dus ook niet instaat.

    Hopelijk kun je tot morgenvroeg wachten.

    Heb je melding gehad via Windows updates, het z.g.n. WGA (Windows Genuine Advantage)

    Als je de melding non-genuine krijgt, dan weet je zeker dat het illegaal is, maar daar ga ik niet van uit.

    Welke virusscanner gebruik je nu?

    Zag er meerdere toen ik door jou logjes ging.

    Maar zo asl ik al zei, ik heb nu te veel op om verantwoord te beoordelen.:)-D

    Heb je de pc nu 30 dagen?

    Wel je windows geactiveerd?

    Groetjes Huib;)

  • asteri

    Hoi,

    Was het een leuk feestje??

    Ik heb de Norton virusscanner, ik heb alleen volgens het schema van de viruspagina de andere ook gebruikt, zoals de online etc. om de logjes te plaatsen.

    De winkel heeft mij gezegd dat de PC gebruikersklaar was, niets gezegd om iets te activeren!!!

    Ik kreeg de melding plotseling, spontaan.

    Later toen ik van d eschrik bekomen was, ben ik gaan zoeken, en bij de updates geprobeerd maar dat zegt ook dat ik een niet legitieme versie heb.

    Mijn eerste schrik was Politie virus, maar nu denk ik dat ze gewoon vergeten zijn te activeren.

    Ik hoor graag toch morgen als je koppijn weg is (:P) of er misschien iets geks tussen staat en of ik de ADW cleaner, de Esets scanner en de RSIT weer kan verwijderen van de PC ??

    tot horens

  • asteri

    Overigens krijg ik ook steeds de melding dat de Malwarebytes anti malware is verlopen, heb ik de proefversie misschien in plaats van de gratis ??

  • Ben

    Hallo,

    Zit er geen sticker van Windows op je pc?

    Mbam heb je de 30 dagen proef versie (de pro) die gaat daarna over in free.

    Gr.Ben

  • fazantje

    Hoi Asteri,

    Ja, het was een mooi feestje:D

    Jou computer:

    Ik zie geen afwijkende zaken in jou computer, dus doe het volgende eens en anders terug naar die gerenommeerde winkel;)

    Als die winkel moeilijk gaat doen, dan even melden dat jij contact gaat opnemen met Microsoft Nederland over de verkooppraktijken van hun.

    Contact gegevens:

    Microsoft B.V.

    Evert van de Beekstraat 354

    1118 CZ Schiphol

    Tel: +31 20 5001500

    Je moet Windows binnen 30 dagen na installatie activeren en om dit te controleren/doen, doe je het volgende:

    Open Windows activeren door op de knop Start te klikken, met de rechtermuisknop op Computer te klikken, Eigenschappen te kiezen en vervolgens op Windows nu activeren te klikken.‌

    Als er door Windows een internetverbinding is gevonden, klikt je op Windows nu online activeren.

    Als u om het beheerderswachtwoord of een bevestiging wordt gevraagd, typt je het wachtwoord of een bevestiging.

    Typ jou Windows 7-productcode in wanneer daarom wordt gevraagd, klik op volgende en volg de instructies.

    Succes,

    Huib;)

  • asteri

    Hoi Fazantje,

    Je bent je gewicht in goud waard, als we jou niet hadden……….

    Heb Windows opnieuw geactiveerd, en de melding is nu verdwenen, suf hoor, van zo'n “ gerenommeerde”" ( :D:P ) winkel !!!

    Rest mij de volgende vraag, hoe verwijder ik nu de ADW cleaner en de RSIT?? Ik zie ze niet in de rij software van het configuratie scherm staan.

    Als ik naar de mijn computer, C schijf ga zie ik ze daar wel staan, is het voldoende als ik ze daar verwijder of blijven er dan resten over???

  • fazantje

    Hoi Asteri,

    Doe dan maar een kilootje of 80(:D:D

    ADW cleaner met rechtermuisknop starten en kies dan voor uninstal.

    Rsit als volgt:

    Download Delfix by Xplode naar het bureaublad.

    Dubbelklik op Delfix.exe om de tool te starten.

    Zet nu vinkjes voor de volgende items:

    Activate UAC

    Remove disinfection tools

    Create registry backup

    Purge System Restore

    Reset system settings

    Klik nu op "Run" en wacht geduldig tot de tool gereed is.

    Wanneer de tool gereed is wordt er een logbestand aangemaakt.

    Dit hoeft je echter niet te plaatsen.

    Mochten er nog tools overgebleven zijn dan kan je die zelf verwijderen.

    Succes,

    Huib;)

  • asteri

    Met dank,

    dit kan worden afgesloten!!

    asteri

  • fazantje

    Omdat dit topic is opgelost word het gesloten.

    Wilt U Uw topic als nog weer openen, stuur dan een privé bericht naar Ben of Huib (fazantje).

    Zij zullen dan het “slotje” er van af halen en het topic is weer open.

    Het AV team.

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.