Goedenmiddag
alle beste wensen allen
mijn desktop was overleden en draai nu op mijn laptop
merk alleen dat de cpu veel aan t werk is bij geen gebruik
kan de oog van de meester ff mijn logjes bekijken voor de zkerheid
gr Dennis,
Logfile of random's system information tool 1.09 (written by random/random)
Run by Dennis at 2014-01-03 13:08:00
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 144 GB (75%) free of 191 GB
Total RAM: 1014 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:08:17, on 3-1-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Dennis\Downloads\RSIT.exe
C:\Program Files\trend micro\Dennis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey
O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - .DEFAULT User Startup: RUN.CMD (User ‘Default user’)
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O11 - Options group: Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
–
End of file - 4131 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
======Registry dump======
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll
“Driver Genius”=
“MSC”=c:\Program Files\Microsoft Security Client\msseces.exe
“IgfxTray”=C:\Windows\system32\igfxtray.exe
“HotKeysCmds”=C:\Windows\system32\hkcmd.exe
“Persistence”=C:\Windows\system32\igfxpers.exe
“SynTPEnh”=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
“GrooveMonitor”=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\igfxdev.dll
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
“{B5A7F190-DDA6-4420-B3BA-52453494E6CD}”=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=0
“ConsentPromptBehaviorUser”=0
“EnableLUA”=0
“EnableUIADesktopToggle”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoDriveTypeAutoRun”=145
“NoResolveSearch”=1
“NoResolveTrack”=1
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“vidc.uyvy”=msyuv.dll
“vidc.yuy2”=msyuv.dll
“vidc.yvyu”=msyuv.dll
“vidc.iyuv”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“vidc.yvu9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“vidc.cvid”=iccvid.dll
“msacm.l3pacm”=l3codecp.acm
“msacm.aacacm”=AACACM.acm
“msacm.lameacm”=lameACM.acm
“msacm.ac3acm”=ac3acm.acm
“VIDC.LAGS”=lagarith.dll
“VIDC.FFDS”=ff_vfw.dll
“VIDC.X264”=x264vfw.dll
“msacm.ac3filter”=ac3filter.acm
“VIDC.MLCY”=mlc.dll
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-01-03 13:08:01 —-D—- C:\Program Files\trend micro
2014-01-03 13:08:00 —-D—- C:\rsit
2014-01-03 13:00:55 —-D—- C:\AdwCleaner
2013-12-18 19:59:27 —-A—- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-18 19:59:24 —-A—- C:\Windows\system32\drivers\terminpt.sys
2013-12-18 19:59:24 —-A—- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-12-18 19:59:22 —-A—- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-18 19:59:21 —-A—- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-18 19:59:19 —-A—- C:\Windows\system32\drivers\TsUsbGD.sys
2013-12-18 19:59:19 —-A—- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-12-18 19:59:15 —-A—- C:\Windows\system32\wksprtPS.dll
2013-12-18 19:59:15 —-A—- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-18 19:59:15 —-A—- C:\Windows\system32\tsgqec.dll
2013-12-18 19:59:15 —-A—- C:\Windows\system32\MsRdpWebAccess.dll
2013-12-18 19:59:14 —-A—- C:\Windows\system32\TSWbPrxy.exe
2013-12-18 19:59:14 —-A—- C:\Windows\system32\rdpudd.dll
2013-12-18 19:59:14 —-A—- C:\Windows\system32\aaclient.dll
2013-12-18 19:59:13 —-A—- C:\Windows\system32\wksprt.exe
2013-12-18 19:59:13 —-A—- C:\Windows\system32\rdpendp_winip.dll
2013-12-18 19:59:10 —-A—- C:\Windows\system32\mstsc.exe
2013-12-18 19:59:06 —-A—- C:\Windows\system32\rdpcorets.dll
2013-12-18 19:58:51 —-A—- C:\Windows\system32\mstscax.dll
2013-12-15 19:30:34 —-D—- C:\Users\Dennis\AppData\Roaming\Malwarebytes
2013-12-15 19:30:13 —-D—- C:\ProgramData\Malwarebytes
2013-12-15 19:30:10 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2013-12-15 19:30:10 —-A—- C:\Windows\system32\drivers\mbam.sys
2013-12-15 19:25:09 —-D—- C:\Program Files\CCleaner
2013-12-15 14:55:05 —-A—- C:\Windows\system32\msonpmon.dll
2013-12-15 14:52:50 —-D—- C:\Program Files\Microsoft Works
2013-12-15 14:52:07 —-D—- C:\Program Files\Microsoft Visual Studio
2013-12-15 14:52:07 —-D—- C:\Program Files\Common Files\DESIGNER
2013-12-15 14:50:52 —-D—- C:\Windows\PCHEALTH
2013-12-15 14:48:02 —-D—- C:\Program Files\Microsoft Visual Studio 8
2013-12-15 14:46:31 —-D—- C:\Program Files\Microsoft Office
2013-12-15 14:46:29 —-D—- C:\ProgramData\Microsoft Help
2013-12-15 14:44:02 —-RHD—- C:\MSOCache
2013-12-14 17:16:53 —-D—- C:\ProgramData\Spotnet
2013-12-14 17:16:53 —-D—- C:\Program Files\Spotnet
2013-12-14 16:45:06 —-D—- C:\Windows\Migration
2013-12-14 16:29:12 —-D—- C:\Program Files\InstallShield Installation Information
2013-12-14 15:53:03 —-A—- C:\Windows\system32\ie4uinit.exe
2013-12-14 15:53:01 —-A—- C:\Windows\system32\jsproxy.dll
2013-12-14 15:53:00 —-A—- C:\Windows\system32\ieui.dll
2013-12-14 15:53:00 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2013-12-14 15:52:59 —-A—- C:\Windows\system32\jscript9diag.dll
2013-12-14 15:52:59 —-A—- C:\Windows\system32\iesetup.dll
2013-12-14 15:52:59 —-A—- C:\Windows\system32\iernonce.dll
2013-12-14 15:52:59 —-A—- C:\Windows\system32\ieapfltr.dll
2013-12-14 15:52:58 —-A—- C:\Windows\system32\ieUnatt.exe
2013-12-14 15:52:58 —-A—- C:\Windows\system32\ieetwproxystub.dll
2013-12-14 15:52:57 —-A—- C:\Windows\system32\ieetwcollector.exe
2013-12-14 15:52:56 —-A—- C:\Windows\system32\wininet.dll
2013-12-14 15:52:55 —-A—- C:\Windows\system32\urlmon.dll
2013-12-14 15:52:55 —-A—- C:\Windows\system32\iertutil.dll
2013-12-14 15:52:53 —-A—- C:\Windows\system32\ieframe.dll
2013-12-14 15:52:51 —-A—- C:\Windows\system32\mshtml.dll
2013-12-14 15:52:50 —-A—- C:\Windows\system32\jscript9.dll
2013-12-14 14:53:40 —-HD—- C:\Windows\system32\CanonIJ Uninstaller Information
2013-12-14 14:53:22 —-HD—- C:\ProgramData\CanonBJ
2013-12-14 14:52:30 —-A—- C:\Windows\system32\CNMLMA4.DLL
2013-12-13 20:49:57 —-D—- C:\130a4f8439028997e2812adc
2013-12-13 20:48:48 —-A—- C:\Windows\system32\drivers\usbhub.sys
2013-12-13 20:48:48 —-A—- C:\Windows\system32\drivers\usbehci.sys
2013-12-13 20:48:48 —-A—- C:\Windows\system32\drivers\usbccgp.sys
2013-12-13 20:48:47 —-A—- C:\Windows\system32\drivers\usbuhci.sys
2013-12-13 20:48:47 —-A—- C:\Windows\system32\drivers\usbport.sys
2013-12-13 20:48:47 —-A—- C:\Windows\system32\drivers\usbohci.sys
2013-12-13 20:48:47 —-A—- C:\Windows\system32\drivers\usbd.sys
2013-12-13 20:07:58 —-A—- C:\Windows\system32\wmp.dll
2013-12-13 20:07:55 —-A—- C:\Windows\system32\wmploc.DLL
2013-12-13 20:02:41 —-A—- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-13 20:02:41 —-A—- C:\Windows\system32\elshyph.dll
2013-12-13 20:02:40 —-A—- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-13 20:02:40 —-A—- C:\Windows\system32\msrating.dll
2013-12-13 20:02:40 —-A—- C:\Windows\system32\msls31.dll
2013-12-13 20:02:40 —-A—- C:\Windows\system32\jsIntl.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\url.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\mshtmlmedia.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\iedkcs32.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\ieapfltr.dat
2013-12-13 20:02:39 —-A—- C:\Windows\system32\icardie.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\dxtrans.dll
2013-12-13 20:02:39 —-A—- C:\Windows\system32\dxtmsft.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\wextract.exe
2013-12-13 20:02:38 —-A—- C:\Windows\system32\webcheck.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\vbscript.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\mshtmled.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\msfeeds.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\licmgr10.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\inseng.dll
2013-12-13 20:02:38 —-A—- C:\Windows\system32\iexpress.exe
2013-12-13 20:02:37 —-A—- C:\Windows\system32\pngfilt.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\occache.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\MshtmlDac.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\mshta.exe
2013-12-13 20:02:37 —-A—- C:\Windows\system32\msfeedssync.exe
2013-12-13 20:02:37 —-A—- C:\Windows\system32\msfeedsbs.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\jscript.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\imgutil.dll
2013-12-13 20:02:37 —-A—- C:\Windows\system32\iepeers.dll
2013-12-13 20:02:36 —-A—- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-13 20:02:36 —-A—- C:\Windows\system32\mshtmler.dll
2013-12-13 20:02:36 —-A—- C:\Windows\system32\iesysprep.dll
2013-12-13 20:02:36 —-A—- C:\Windows\system32\IEAdvpack.dll
2013-12-13 20:01:34 —-A—- C:\Windows\system32\tdh.dll
2013-12-13 20:01:34 —-A—- C:\Windows\system32\ntoskrnl.exe
2013-12-13 20:01:34 —-A—- C:\Windows\system32\ntkrnlpa.exe
2013-12-13 20:01:34 —-A—- C:\Windows\system32\ntdll.dll
2013-12-13 20:01:34 —-A—- C:\Windows\system32\advapi32.dll
2013-12-13 20:01:22 —-A—- C:\Windows\system32\mswsock.dll
2013-12-13 20:01:22 —-A—- C:\Windows\system32\drivers\tcpip.sys
2013-12-13 20:01:22 —-A—- C:\Windows\system32\drivers\afd.sys
2013-12-13 17:26:55 —-A—- C:\Windows\system32\drivers\tssecsrv.sys
2013-12-13 16:38:03 —-A—- C:\Windows\system32\comctl32.dll
2013-12-13 16:38:01 —-A—- C:\Windows\system32\drivers\hidparse.sys
2013-12-13 16:38:01 —-A—- C:\Windows\system32\drivers\hidclass.sys
2013-12-13 16:37:56 —-A—- C:\Windows\system32\rpcrt4.dll
2013-12-13 16:37:49 —-A—- C:\Windows\system32\wintrust.dll
2013-12-13 16:36:50 —-A—- C:\Windows\system32\authui.dll
2013-12-13 16:36:49 —-A—- C:\Windows\system32\SmartcardCredentialProvider.dll
2013-12-13 16:36:49 —-A—- C:\Windows\system32\credui.dll
2013-12-13 16:35:26 —-A—- C:\Windows\system32\msieftp.dll
2013-12-13 16:35:24 —-A—- C:\Windows\system32\schannel.dll
2013-12-13 16:35:23 —-A—- C:\Windows\system32\sspicli.dll
2013-12-13 16:35:23 —-A—- C:\Windows\system32\ncrypt.dll
2013-12-13 16:35:23 —-A—- C:\Windows\system32\lsasrv.dll
2013-12-13 16:35:23 —-A—- C:\Windows\system32\drivers\ksecpkg.sys
2013-12-13 16:35:23 —-A—- C:\Windows\system32\drivers\ksecdd.sys
2013-12-13 16:35:23 —-A—- C:\Windows\system32\drivers\cng.sys
2013-12-13 16:35:22 —-A—- C:\Windows\system32\sspisrv.dll
2013-12-13 16:35:22 —-A—- C:\Windows\system32\secur32.dll
2013-12-13 16:35:22 —-A—- C:\Windows\system32\lsass.exe
2013-12-13 16:35:06 —-A—- C:\Windows\system32\imagehlp.dll
2013-12-13 16:35:04 —-A—- C:\Windows\system32\wscript.exe
2013-12-13 16:35:04 —-A—- C:\Windows\system32\scrrun.dll
2013-12-13 16:35:04 —-A—- C:\Windows\system32\cscript.exe
2013-12-13 16:35:02 —-A—- C:\Windows\system32\WMPhoto.dll
2013-12-13 16:34:56 —-A—- C:\Windows\system32\drivers\dxgkrnl.sys
2013-12-13 16:34:53 —-A—- C:\Windows\system32\tzres.dll
2013-12-13 16:34:38 —-A—- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-12-13 16:34:37 —-A—- C:\Windows\system32\dciman32.dll
2013-12-13 16:34:37 —-A—- C:\Windows\system32\atmfd.dll
2013-12-13 16:34:36 —-A—- C:\Windows\system32\lpk.dll
2013-12-13 16:34:36 —-A—- C:\Windows\system32\fontsub.dll
2013-12-13 16:34:36 —-A—- C:\Windows\system32\atmlib.dll
2013-12-13 16:34:32 —-A—- C:\Windows\system32\scavengeui.dll
2013-12-13 16:34:24 —-A—- C:\Windows\system32\win32k.sys
2013-12-13 16:34:12 —-A—- C:\Windows\system32\WMVDECOD.DLL
2013-12-13 16:34:09 —-A—- C:\Windows\system32\drivers\portcls.sys
2013-12-13 16:34:09 —-A—- C:\Windows\system32\drivers\drmk.sys
2013-12-13 16:34:01 —-A—- C:\Windows\system32\WebClnt.dll
2013-12-13 16:34:01 —-A—- C:\Windows\system32\drivers\mrxdav.sys
2013-12-13 16:34:01 —-A—- C:\Windows\system32\davclnt.dll
2013-12-13 16:34:00 —-A—- C:\Windows\system32\gdi32.dll
2013-12-13 16:33:49 —-A—- C:\Windows\system32\shell32.dll
2013-12-13 16:33:48 —-A—- C:\Windows\system32\shdocvw.dll
2013-12-13 16:33:40 —-A—- C:\Windows\system32\drivers\ataport.sys
2013-12-13 16:33:38 —-A—- C:\Windows\system32\IKEEXT.DLL
2013-12-13 16:33:38 —-A—- C:\Windows\system32\FWPUCLNT.DLL
2013-12-13 16:33:37 —-A—- C:\Windows\system32\nshwfp.dll
2013-12-13 16:33:29 —-A—- C:\Windows\system32\cryptsvc.dll
2013-12-13 16:33:29 —-A—- C:\Windows\system32\cryptnet.dll
2013-12-13 16:33:29 —-A—- C:\Windows\system32\crypt32.dll
2013-12-13 16:33:23 —-D—- C:\Program Files\Common Files\Java
2013-12-13 16:33:08 —-A—- C:\Windows\system32\javaws.exe
2013-12-13 16:33:05 —-A—- C:\Windows\system32\drivers\usbcir.sys
2013-12-13 16:33:03 —-A—- C:\Windows\system32\drivers\Wdf01000.sys
2013-12-13 16:32:59 —-A—- C:\Windows\system32\KernelBase.dll
2013-12-13 16:32:59 —-A—- C:\Windows\system32\kernel32.dll
2013-12-13 16:32:58 —-AH—- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-12-13 16:32:58 —-AH—- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-12-13 16:32:58 —-AH—- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-12-13 16:32:58 —-AH—- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-12-13 16:32:58 —-A—- C:\Windows\system32\winsrv.dll
2013-12-13 16:32:58 —-A—- C:\Windows\system32\conhost.exe
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-12-13 16:32:57 —-AH—- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-12-13 16:32:56 —-AH—- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-12-13 16:32:55 —-AH—- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-12-13 16:32:55 —-A—- C:\Windows\system32\WindowsAccessBridge.dll
2013-12-13 16:32:55 —-A—- C:\Windows\system32\javaw.exe
2013-12-13 16:32:55 —-A—- C:\Windows\system32\java.exe
2013-12-13 16:32:54 —-AH—- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-12-13 16:32:54 —-AH—- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
======List of files/folders modified in the last 1 month======
2014-01-03 13:08:13 —-D—- C:\Windows\Prefetch
2014-01-03 13:08:01 —-RD—- C:\Program Files
2014-01-03 13:07:18 —-D—- C:\Windows\Temp
2014-01-03 12:58:28 —-D—- C:\Windows\system32\config
2014-01-03 10:02:13 —-D—- C:\Windows\system32\drivers
2014-01-02 14:20:30 —-SD—- C:\Users\Dennis\AppData\Roaming\Microsoft
2014-01-02 11:10:25 —-SHD—- C:\System Volume Information
2014-01-02 09:33:35 —-D—- C:\Windows
2014-01-01 16:11:01 —-D—- C:\Program Files\ESET
2014-01-01 16:04:09 —-D—- C:\Windows\inf
2014-01-01 16:01:04 —-D—- C:\Windows\System32
2013-12-29 09:36:27 —-D—- C:\Windows\system32\catroot2
2013-12-23 23:35:35 —-A—- C:\Windows\system32\PerfStringBackup.INI
2013-12-19 12:15:15 —-SHD—- C:\Windows\Installer
2013-12-19 12:14:22 —-A—- C:\Windows\win.ini
2013-12-18 21:19:21 —-D—- C:\Windows\rescache
2013-12-18 20:05:29 —-D—- C:\Windows\winsxs
2013-12-18 20:03:29 —-D—- C:\Windows\system32\wbem
2013-12-18 20:03:29 —-D—- C:\Windows\system32\nl-NL
2013-12-18 20:03:29 —-D—- C:\Windows\system32\drivers\nl-NL
2013-12-18 20:03:29 —-D—- C:\Windows\PolicyDefinitions
2013-12-18 20:03:27 —-D—- C:\Windows\system32\DriverStore
2013-12-18 19:59:55 —-D—- C:\Windows\system32\catroot
2013-12-17 20:22:09 —-D—- C:\Windows\system32\Tasks
2013-12-16 14:15:43 —-RSD—- C:\Windows\assembly
2013-12-15 21:14:15 —-D—- C:\ProgramData\Adobe
2013-12-15 21:12:35 —-D—- C:\Users\Dennis\AppData\Roaming\Adobe
2013-12-15 19:56:41 —-RSD—- C:\Windows\Fonts
2013-12-15 19:55:51 —-D—- C:\Program Files\Common Files\microsoft shared
2013-12-15 19:30:13 —-HD—- C:\ProgramData
2013-12-15 19:28:03 —-D—- C:\Windows\Panther
2013-12-15 19:28:03 —-D—- C:\Windows\Logs
2013-12-15 19:28:03 —-D—- C:\Windows\debug
2013-12-15 14:52:36 —-D—- C:\Program Files\MSBuild
2013-12-15 14:52:07 —-D—- C:\Program Files\Common Files
2013-12-15 14:52:02 —-D—- C:\Windows\ShellNew
2013-12-15 14:50:52 —-SD—- C:\ProgramData\Microsoft
2013-12-15 14:50:52 —-D—- C:\Program Files\Microsoft.NET
2013-12-15 14:47:26 —-D—- C:\Program Files\Common Files\System
2013-12-15 00:34:50 —-D—- C:\Windows\system32\wdi
2013-12-14 17:13:21 —-D—- C:\Windows\Microsoft.NET
2013-12-14 16:46:05 —-D—- C:\Windows\system32\en-US
2013-12-14 15:56:26 —-D—- C:\Program Files\Internet Explorer
2013-12-13 20:41:47 —-D—- C:\Program Files\Microsoft Silverlight
2013-12-13 20:39:28 —-D—- C:\Program Files\Windows Media Player
2013-12-13 20:39:25 —-D—- C:\Windows\system32\migration
2013-12-13 20:28:54 —-D—- C:\Program Files\Microsoft Security Client
2013-12-13 20:18:23 —-D—- C:\Windows\system32\MRT
2013-12-13 17:54:07 —-A—- C:\Windows\system32\FlashPlayerApp.exe
2013-12-13 16:32:54 —-D—- C:\Program Files\Java
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys
S3 b06diag;Broadcom NetXtreme II Diag Driver; C:\Windows\system32\drivers\bxdiagx.sys
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys
S3 BFN7x86;Bigfoot Networks Killer Gaming Service; C:\Windows\system32\drivers\Xeno7x86.sys
S3 BFNVis32;Bigfoot Networks Killer Gaming Service; C:\Windows\system32\drivers\XenoVx86.sys
S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\drivers\BthEnum.sys
S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys
S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys
S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys
S3 bxfcoe;bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys
S3 bxois;bxois; C:\Windows\system32\drivers\bxois.sys
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys
S3 E1G60;Stuurprogramma voor Intel(R) PRO/1000 NDIS 6-adapter; C:\Windows\system32\DRIVERS\E1G60I32.sys
S3 IFCoEMP;IFCoEMP; C:\Windows\system32\drivers\ifM60x32.sys
S3 IFCoEVB;IFCoEVB; C:\Windows\system32\drivers\ifP60X32.sys
S3 ioatdma1;ioatdma1; C:\Windows\System32\Drivers\qd16032.sys
S3 ioatdma2;Intel(R) QuickData Technology device ver.2; C:\Windows\System32\Drivers\qd26032.sys
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys
S3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver; C:\Windows\system32\drivers\Synth3dVsc.sys
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys
S3 tsusbhub;Remote Deskotop USB Hub; C:\Windows\system32\drivers\tsusbhub.sys
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys
S3 ViaC7;Stuurprogramma voor VIA C7-processor; C:\Windows\system32\drivers\viac7.sys
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe
S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
—————–EOF—————–
# AdwCleaner v3.016 - Report created 03/01/2014 at 13:03:37
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Dennis - DENNIS-PC
# Running from : C:\Users\Dennis\Downloads\adwcleaner.exe
# Option : Clean
***** *****
***** *****
Folder Deleted : C:\Program Files\driver-soft
***** *****
***** *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FDBBC21-E399-4542-B4CE-86326E1F0727}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B878FD4-8F19-46DB-94B1-4CABFF80679C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8BA495EF-6CD5-413A-8AEF-483631B98C4F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C71E394-2E6F-452A-AB7D-C17E78307083}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BADB1512-759C-4792-A18A-DD6BDC4E1991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E54FBC83-9028-45AC-A5B9-D5DA828E59C2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{633AA60B-C339-46C3-951F-047F9822C473}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9156C8F9-B397-4DEF-8AC5-5966221A134A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A8E5842E-102B-4289-9D57-3B3F5B5E15D3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKLM\Software\Driver-Soft
***** *****
-\\ Internet Explorer v11.0.9600.16428
*************************
AdwCleaner.txt - -
AdwCleaner.txt - -
########## EOF - C:\AdwCleaner\AdwCleaner.txt - ##########
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Databaseversie: v2014.01.03.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16476
Dennis :: DENNIS-PC
3-1-2014 9:53:16
mbam-log-2014-01-03 (09-53-16).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 199990
Verstreken tijd: 8 minuut/minuten, 46 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)