hoi virus helpers
Ik werk met een toshiba laptop met win 7 en avast als virusscanner.
telkens na de opstart komt na enkele min. avast met een melding van een virus in:
C:\user\……\OppData\local\mediaget LLC\Mediaget2\update.exe
mediaget-atm-proxy.exe is geinfecteerd met Win 32: pup-gen (pup)
C:\user\…..\OppData\local\Temp\half-open-check.exe
Na het doen van een opstartscan komt de melding opnieuw.
zelfs na enkele malen opnieuw scannen.
Of het er mee te maken heeft weet ik niet maar ook heb ik veel last van pop up schermpjes in zowel firefox als Grome.
Het betreffen advertentie pop ups
Ook al een paar maand last van een melding bij het opstarten van: Runtime error 2 at 00004AD4
dit kwam bij elke opstart. Alleen de laatste 2 dagen wordt deze melding minder en start de pc vaker op zonder deze melding dan met.
Maar dit worden, denk ik, te veel meldingen in één topic
dus svp liever eerst de avast melding en de pop ups
(bij mijn hoofd PC met vista en avast heeft zich dit probleem ook voor gedaan maar was na een mbam scan en een opstartscan verholpen)
hier de gevraagde logjes
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Databaseversie: v2014.02.13.02
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
hov :: LAPPIE
15-2-2014 18:16:23
mbam-log-2014-02-15 (18-16-23).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 293138
Verstreken tijd: 8 minuut/minuten, 49 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
Logfile of random's system information tool 1.09 (written by random/random)
Run by hov at 2014-02-15 18:27:00
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 67 GB (57%) free of 119 GB
Total RAM: 2812 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:27:06, on 15-2-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16736)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lexmark 9300 Series\lxcqmon.exe
C:\Program Files (x86)\Lexmark 9300 Series\ezprint.exe
C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
C:\Users\hov\AppData\Local\MediaGet2\mediaget.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\IVT Corporation\BlueSoleil\BtTray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
C:\Program Files\trend micro\hov.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: “C:\Program Files (x86)\Lexmark 9300 Series\fm3032.exe” /s
O4 - HKLM\..\Run: “C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe” autorun
O4 - HKLM\..\Run: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
O4 - HKLM\..\Run: “c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe” /WinStart
O4 - HKLM\..\Run: “C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\IVT Corporation\BlueSoleil\BtTray.exe”
O4 - HKLM\..\Run: C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
O4 - HKLM\..\Run: “C:\Program Files\Alwil Software\Avast5\AvastUI.exe” /nogui
O4 - HKCU\..\Run: C:\Users\hov\AppData\Local\MediaGet2\mediaget.exe –minimized
O4 - HKCU\..\Run: “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=service
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18\..\Run: C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User ‘Default user’)
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User ‘Default user’)
O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Update-agent.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~2\sk-enh~1\psupport.dll c:\progra~3\webtect\webtect.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BecHelperService - Unknown owner - C:\Program Files (x86)\KPN\Mobiel Internet Software\BecHelperService.exe
O23 - Service: BlueSoleilCS - Unknown owner - C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
O23 - Service: BsHelpCS - Unknown owner - C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxcq_device - - C:\Windows\system32\lxcqcoms.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 12790 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
“C:\Program Files\Alwil Software\Avast5\AvastSvc.exe”
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
“taskhost.exe”
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
taskeng.exe {BB7F7A05-66F7-4DDD-AAD6-767A13440C16}
“C:\Program Files (x86)\Google\Update\GoogleUpdate.exe” /c
“C:\Program Files (x86)\Lexmark 9300 Series\lxcqmon.exe”
“C:\Program Files (x86)\Lexmark 9300 Series\ezprint.exe”
“C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe”
“C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe”
“C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe” -s
“C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe” /FORPCEE3
“C:\Users\hov\AppData\Local\MediaGet2\mediaget.exe” –minimized
“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=service
C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
“C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe” autorun
“C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe” /WinStart
“C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE” /tsr
“C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM”
“C:\Program Files (x86)\IVT Corporation\BlueSoleil\BtTray.exe”
taskeng.exe {2DFCC268-3979-4328-9325-0486F536AEBA}
“C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe”
“C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe” 0
“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”
“C:\Program Files (x86)\KPN\Mobiel Internet Software\BecHelperService.exe”
“C:\Program Files (x86)\KPN\Mobiel Internet Software\LoggerServer.exe” -background 3220
“C:\Program Files (x86)\IVT Corporation\BlueSoleil\BlueSoleilCS.exe”
\??\C:\Windows\system32\conhost.exe "1512017962-870224217213549271-196367386191467618448286364-1067760340781265896
C:\Windows\system32\lxcqcoms.exe -service
“c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe”
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
“C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe”
“C:\Program Files\TOSHIBA\TECO\TecoService.exe”
“C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE”
“C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe”
WLIDSvcM.exe 3816
“C:\Program Files (x86)\IVT Corporation\BlueSoleil\BsHelpCS.exe”
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
“C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe”
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
“C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe”
“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
“C:\Program Files\Alwil Software\Avast5\AvastUI.exe” /nogui
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
“C:\Program Files (x86)\Mozilla Firefox\firefox.exe”
“C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe”
“C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe”
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
“C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe” –channel=2496.1173ae00.1722163142 “C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll” -greomni “C:\Program Files (x86)\Mozilla Firefox\omni.ja” -appomni “C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja” -appdir “C:\Program Files (x86)\Mozilla Firefox\browser” E7CF176E110C211B 2496 “\\.\pipe\gecko-crash-server-pipe.2496” plugin
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe” –proxy-stub-channel=Flash1752.5FF8C768.26828 –host-broker-channel=Flash1752.5FF8C768.12210 –host-pid=1752 –host-npapi-version=27 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll”
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe” –channel=1868.003BF710.1993294198 –proxy-stub-channel=Flash1752.5FF8C768.26828 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll” –host-npapi-version=27 –type=renderer
“C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe”
“C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe”
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
“C:\Windows\notepad.exe” “C:\Users\hov\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2014-02-15 (18-16-23).txt”
“C:\Windows\system32\SearchProtocolHost.exe” Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 “Software\Microsoft\Windows Search” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)” “C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc” “DownLevelDaemon”
“C:\Windows\system32\SearchFilterHost.exe” 0 520 524 532 65536 528
“C:\Users\hov\Downloads\RSITx64(3).exe”
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Sk-Enhancer-S-5902107913.job
=========Mozilla firefox=========
ProfilePath - C:\Users\hov\AppData\Roaming\Mozilla\Firefox\Profiles\zf4wi6bs.default
prefs.js - “browser.search.useDBForOrder” - true
prefs.js - “browser.startup.homepage” - “startpagina.nl”
prefs.js - “keyword.URL” - “”
“Description”=Adobe® Flash® Player 12.0.0.44 Plugin
“Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll
“Description”=Google Earth in your browser
“Path”=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
“Description”=Picasa3 plugin
“Path”=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
“Description”=Office Live Update v1.5
“Path”=C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
“Description”=Adobe® Flash® Player 12.0.0.43 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\hov\AppData\Roaming\Mozilla\Firefox\Profiles\zf4wi6bs.default\extensions\
gkg_y@vjdjyeuo.co.uk
sbgi@aqrdhx.net
C:\Users\hov\AppData\Roaming\Mozilla\Firefox\Profiles\zf4wi6bs.default\searchplugins\
bing.xml
utorrentbarnl-customized-web-search.xml
======Registry dump======
avast! Online Security - C:\Pr
Happy2Savveu - C:\Pr
DisCouuniTExttensi - C:\Pr
Java™ Plug-In SSV Helper - C:\Pr
avast! Online Security - C:\Pr
Java™ Plug-In 2 SSV Helper - C:\Pr
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Pr
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Pr
“lxcqmon.exe”=C:\Pr
“EzPrint”=C:\Pr
“WrtMon.exe”=C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe
“LXCQCATS”=rundll32 C:\Windows\system32\spool\DRIVERS\x64\3\LXCQtime.dll,RunDLLEntry
“TPwrMain”=C:\Pr
“TosWaitSrv”=C:\Pr
“TosSENotify”=C:\Pr
“TosNC”=C:\Pr
“Toshiba TEMPRO”=C:\Pr
“SmoothView”=C:\Pr
“RtHDVCpl”=C:\Pr
“RtHDVBg”=C:\Pr
“HSON”=C:\Pr
“00TCrdMain”=C:\Pr
“TosVolRegulator”=C:\Pr
“Teco”=C:\Pr
“TosReelTimeMonitor”=C:\Pr
“MediaGet2”=C:\Users\hov\AppData\Local\MediaGet2\mediaget.exe
“EC5A6BA57C4FDADF8A595B3E69A8FDC4E5E23109._service_run”=C:\Pr
C:\Pr
C:\Pr
C:\Pr
C:\Pr
C:\Pr
C:\Pr
“Lexmark 9300 Series”=C:\Pr
“TWebCamera”=C:\Pr
“StartCCC”=C:\Pr
“NBAgent”=c:\Pr
“GrooveMonitor”=C:\Pr
“BtTray”=C:\Pr
“KeNotify”=C:\Pr
“Adobe ARM”=C:\Pr
“SunJavaUpdateSched”=C:\Pr
“AvastUI.exe”=C:\Pr
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Update-agent.lnk - C:\Program Files (x86)\KPN\Mobiel Internet Software\AutoUpdateSrv.exe
C:\Users\hov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
“AppInit_DLLs”=“ C:\PROGRA~3\FASTAN~1\FASTAN~2.DLL C:\PROGRA~3\WebTect\WEBTEC~1.DLL C:\PROGRA~3\INTELE~1\INTELE~2.DLL”
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
“{B5A7F190-DDA6-4420-B3BA-52453494E6CD}”=C:\Pr
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=5
“ConsentPromptBehaviorUser”=3
“EnableUIADesktopToggle”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“EnableLinkedConnections”=1
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“VIDC.UYVY”=msyuv.dll
“VIDC.YUY2”=msyuv.dll
“VIDC.YVYU”=msyuv.dll
“VIDC.IYUV”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“VIDC.YVU9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“MSVideo8”=VfWWDM32.dll
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
“wave1”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer1”=wdmaud.drv
“aux1”=wdmaud.drv
“wave2”=wdmaud.drv
“midi2”=wdmaud.drv
“mixer2”=wdmaud.drv
“aux2”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-02-15 15:03:23 —-D—- C:\Program Files (x86)\Mozilla Firefox
2014-01-21 18:03:51 —-A—- C:\Windows\SYSWOW64\javaws.exe
2014-01-21 18:03:44 —-A—- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-01-21 18:03:44 —-A—- C:\Windows\SYSWOW64\javaw.exe
2014-01-21 18:03:44 —-A—- C:\Windows\SYSWOW64\java.exe
2014-01-18 12:50:29 —-D—- C:\Program Files (x86)\McAfee Security Scan
======List of files/folders modified in the last 1 month======
2014-02-15 18:27:06 —-D—- C:\Windows\Prefetch
2014-02-15 18:27:04 —-D—- C:\Windows\Temp
2014-02-15 18:27:04 —-D—- C:\Program Files\trend micro
2014-02-15 18:10:40 —-A—- C:\Windows\SYSWOW64\LOCALSERVICE.INI
2014-02-15 18:10:39 —-A—- C:\Windows\SYSWOW64\bscs.ini
2014-02-15 18:08:57 —-D—- C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-15 17:27:59 —-RD—- C:\Program Files (x86)
2014-02-13 14:17:13 —-D—- C:\Windows\inf
2014-02-13 14:16:58 —-D—- C:\Windows\system32\catroot2
2014-02-13 14:15:23 —-D—- C:\Windows
2014-02-13 10:17:06 —-D—- C:\Users\hov\AppData\Roaming\uTorrent
2014-02-13 10:15:40 —-D—- C:\Windows\Panther
2014-02-13 10:15:40 —-D—- C:\Windows\Logs
2014-02-13 10:15:40 —-D—- C:\Windows\debug
2014-02-12 23:59:32 —-D—- C:\Program Files\Lx_cats
2014-02-12 22:43:53 —-D—- C:\Windows\system32\config
2014-02-12 22:31:23 —-SHD—- C:\System Volume Information
2014-02-11 11:07:49 —-D—- C:\Program Files (x86)\Sk-Enhancer
2014-02-05 16:55:09 —-D—- C:\Windows\SysWOW64
2014-02-05 16:55:07 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-01-28 10:06:26 —-HD—- C:\ProgramData
2014-01-28 10:01:36 —-RD—- C:\Program Files
2014-01-28 09:52:51 —-D—- C:\ProgramData\WebTect
2014-01-28 09:52:51 —-D—- C:\ProgramData\Intelewin filter
2014-01-28 09:51:26 —-D—- C:\ProgramData\Fast And Safe
2014-01-24 16:18:47 —-D—- C:\Windows\system32\Tasks
2014-01-24 16:18:38 —-A—- C:\Windows\system32\aswBoot.exe
2014-01-24 09:47:16 —-D—- C:\Windows\System32
2014-01-24 09:47:16 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-01-24 09:47:10 —-A—- C:\Windows\SYSWOW64\REMOTEDEVICE.INI
2014-01-24 09:43:47 —-A—- C:\Windows\SYSWOW64\LOCALDEVICE.INI
2014-01-21 18:04:20 —-D—- C:\ProgramData\Oracle
2014-01-21 18:03:56 —-SHD—- C:\Windows\Installer
2014-01-21 18:03:56 —-SHD—- C:\Config.Msi
2014-01-21 18:03:44 —-D—- C:\Program Files (x86)\Java
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys
R0 BTHidEnum;Bluetooth HID Enumerator; C:\Windows\System32\Drivers\vbtenum.sys
R0 BTHidMgr;Bluetooth HID Manager Service; C:\Windows\System32\Drivers\BTHidMgr.sys
R0 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys
R3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys
R3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys
R3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\Windows\System32\Drivers\btcusb.sys
S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\drivers\BthEnum.sys
S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys
S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys
S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys
S3 massfilter;MBB Mass Storage Filter Driver; C:\Windows\system32\DRIVERS\massfilter.sys
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys
S3 RTL8187Se;Realtek RTL8187SE PCIE-netwerkadapter voor draadloos LAN; C:\Windows\system32\DRIVERS\RTL8187Se.sys
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys
S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
S3 ZTEusbnet;ZTE USB-NDIS miniport; C:\Windows\system32\DRIVERS\ZTEusbnet.sys
S3 ZTEusbnmea;ZTE NMEA Port; C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Pr
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe
R2 avast! Antivirus;avast! Antivirus; C:\Pr
R2 BecHelperService;BecHelperService; C:\Pr
R2 BlueSoleilCS;BlueSoleilCS; C:\Pr
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Pr
R2 ConfigFree Service;ConfigFree Service; C:\Pr
R2 lxcq_device;lxcq_device; C:\Windows\system32\lxcqcoms.exe
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; c:\Pr
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe
R2 TosCoSrv;TOSHIBA Power Saver; C:\Pr
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Pr
R2 VMCService;Vodafone Mobile Connect Service; C:\Pr
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Pr
R3 BsHelpCS;BsHelpCS; C:\Pr
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Pr
S2 25e4f9bf;WebTect; C:\Windows\syswow64\rundll32.exe
S2 64af91bf;Fast And Safe; C:\Windows\syswow64\rundll32.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Updateservice (gupdate); C:\Pr
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 fsssvc;Windows Live Family Safety Service; C:\Pr
S3 gupdatem;Google Update-service (gupdatem); C:\Pr
S3 gusvc;Google Updater Service; C:\Pr
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Pr
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Pr
S3 odserv;Microsoft Office Diagnostics Service; C:\Pr
S3 ose;Office Source Engine; C:\Pr
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Pr
S3 TMachInfo;TMachInfo; C:\Pr
S3 TPCHSrv;TPCH Service; C:\Pr
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe
—————–EOF—————–