Ik heb ondertussen malwarebytes gebruikt, maar dat ging niet goed omdat de instellingen op de pc opeens veranderden en ik daarna geen internet meer had.
Wel heb ik de pc in de veilige modus laten scannen en opnieuw hijackthis gebruikt en een scan gemaakt en alles opgeschoont met CC-cleaner.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Subst at 2014-04-15 21:51:49
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 230 GB (48%) free of 477 GB
Total RAM: 7919 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:51:52, on 15-4-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Subst\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
C:\Program Files\trend micro\Subst.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://127.0.0.1:9880
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: (no name) - {FB4D29C1-82DE-4b80-8BB0-A7CDDDCD2773} - (no file)
O4 - HKLM\..\Run: “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKCU\..\Run: C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe
O4 - HKCU\..\Run: “C:\Program Files (x86)\Google\Drive\googledrivesync.exe” /autostart
O4 - HKCU\..\Run: “C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe”
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: Accelerated graphics
O16 - DPF: {9E858349-A287-4D37-8C27-034330E160F9} (MijnAlbum Album Upload Software Control Control) - http://www.mijnalbum.nl/v3/skinsrc_redesign/core/system/aus8.0.14/ImageUploader8.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 7700 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
“C:\Program Files\Microsoft Security Client\MsMpEng.exe”
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
“taskhost.exe”
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”
C:\Windows\system32\AEADISRV.EXE
“C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe”
“C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey
“C:\Program Files (x86)\Google\Drive\googledrivesync.exe” /autostart
“C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe”
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
“C:\Program Files (x86)\iTunes\iTunesHelper.exe”
C:\Windows\system32\svchost.exe -k imgsvc
“C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe”
“C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe”
“C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE”
WLIDSvcM.exe 1200
“C:\Program Files (x86)\Google\Drive\googledrivesync.exe” /autostart
“C:\Program Files\iPod\bin\iPodService.exe”
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
C:\Windows\system32\svchost.exe -k SDRSVC
“C:\Windows\System32\WUDFHost.exe” -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9e06911f-9de9-4f43-bcd7-f3edb163aaca -SystemEventPortName:HostProcess-f2c3f3e0-0ee8-411f-87fc-4570a51f8653 -IoCancelEventPortName:HostProcess-6e176438-f789-4262-9b53-94f994186963 -NonStateChangingEventPortName:HostProcess-6ebd9266-3c57-48d6-aa4b-811279ad693e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d25068b2-f72c-42e6-b50a-83eb4161e496 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
“C:\Program Files\Microsoft Security Client\NisSrv.exe”
“C:\Users\Subst\AppData\Roaming\uTorrent\uTorrent.exe” /RELOCATED
“C:\Program Files (x86)\Mozilla Firefox\firefox.exe”
“C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe” –channel=840.c87f590.558761742 “C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll” -greomni “C:\Program Files (x86)\Mozilla Firefox\omni.ja” -appomni “C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja” -appdir “C:\Program Files (x86)\Mozilla Firefox\browser” E7CF176E110C211B 840 “\\.\pipe\gecko-crash-server-pipe.840” plugin
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe” –proxy-stub-channel=Flash1272.657F7F48.20471 –host-broker-channel=Flash1272.657F7F48.31686 –host-pid=1272 –host-npapi-version=27 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll”
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe” –channel=3660.0039F658.742435888 –proxy-stub-channel=Flash1272.657F7F48.20471 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll” –host-npapi-version=27 –type=renderer
“C:\Windows\system32\SearchProtocolHost.exe” Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 “Software\Microsoft\Windows Search” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)” “C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc” “DownLevelDaemon”
“C:\Windows\system32\SearchFilterHost.exe” 0 516 520 528 65536 524
“C:\Users\Subst\Downloads\RSITx64.exe”
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Subst\AppData\Roaming\Mozilla\Firefox\Profiles\pvljp0fc.default
prefs.js - “browser.search.useDBForOrder” - “false”
prefs.js - “browser.startup.homepage” - “http://nl.msn.com/”
“Description”=Adobe® Flash® Player 13.0.0.182 Plugin
“Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll
“Description”=
“Path”=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Windows\SysWOW64\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
“Description”=Ag Player Plugin
“Path”=C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll
“Description”=WLPG Install MIME type
“Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
“Description”=
“Path”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
“Description”=Adobe® Flash® Player 13.0.0.182 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll
“Description”=
“Path”=C:\Windows\system32\npDeployJava1.dll
“Description”=Ag Player Plugin
“Path”=C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
“Description”=
“Path”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
ffxtlbr@babylon.com
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Subst\AppData\Roaming\Mozilla\Firefox\Profiles\pvljp0fc.default\extensions\
{87775fdb-6972-41f9-ae51-8326e38cb206}
C:\Users\Subst\AppData\Roaming\Mozilla\Firefox\Profiles\pvljp0fc.default\searchplugins\
google-instant.xml
======Registry dump======
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
“MSC”=C:\Program Files\Microsoft Security Client\msseces.exe
“AdobeAAMUpdater-1.0”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
“CAHeadless”=C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe
“GoogleDriveSync”=C:\Program Files (x86)\Google\Drive\googledrivesync.exe
“TomTomHOME.exe”=C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
“iTunesHelper”=C:\Program Files (x86)\iTunes\iTunesHelper.exe
“Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=0
“ConsentPromptBehaviorUser”=3
“EnableLUA”=0
“EnableUIADesktopToggle”=0
“PromptOnSecureDesktop”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoDriveTypeAutoRun”=145
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“c:\windows\mdm.exe”=“c:\windows\mdm.exe:*:Enabled:Microsoft Firevall Engine”
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“vidc.uyvy”=msyuv.dll
“vidc.yuy2”=msyuv.dll
“vidc.yvyu”=msyuv.dll
“vidc.iyuv”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“vidc.yvu9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-04-15 21:51:49 —-D—- C:\rsit
2014-04-15 21:51:49 —-D—- C:\Program Files\trend micro
2014-04-13 22:53:24 —-A—- C:\malware.txt
2014-04-13 22:21:31 —-A—- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-04-13 22:21:08 —-D—- C:\ProgramData\Malwarebytes
2014-04-09 20:32:41 —-D—- C:\Program Files\HitmanPro
2014-04-09 20:29:47 —-D—- C:\ProgramData\Systweak
2014-04-09 20:29:40 —-A—- C:\Windows\system32\sasnative64.exe
2014-04-09 20:29:12 —-D—- C:\ProgramData\HitmanPro
2014-04-09 20:29:11 —-D—- C:\Users\Subst\AppData\Roaming\systweak
2014-04-09 02:01:52 —-A—- C:\Windows\system32\mshtml.dll
2014-04-09 02:01:51 —-A—- C:\Windows\SYSWOW64\mshtml.dll
2014-04-09 02:01:47 —-A—- C:\Windows\SYSWOW64\iologmsg.dll
2014-04-09 02:01:47 —-A—- C:\Windows\system32\iologmsg.dll
2014-04-09 02:01:47 —-A—- C:\Windows\system32\drivers\storport.sys
2014-04-09 02:01:47 —-A—- C:\Windows\system32\drivers\msiscsi.sys
2014-04-09 02:01:47 —-A—- C:\Windows\system32\drivers\Diskdump.sys
2014-04-09 02:01:44 —-A—- C:\Windows\system32\kernel32.dll
2014-04-09 02:01:43 —-A—- C:\Windows\SYSWOW64\setup16.exe
2014-04-09 02:01:43 —-A—- C:\Windows\SYSWOW64\ntvdm64.dll
2014-04-09 02:01:43 —-A—- C:\Windows\SYSWOW64\kernel32.dll
2014-04-09 02:01:43 —-A—- C:\Windows\system32\wow64win.dll
2014-04-09 02:01:43 —-A—- C:\Windows\system32\wow64cpu.dll
2014-04-09 02:01:43 —-A—- C:\Windows\system32\wow64.dll
2014-04-09 02:01:43 —-A—- C:\Windows\system32\ntvdm64.dll
2014-04-09 02:01:42 —-A—- C:\Windows\SYSWOW64\wow32.dll
2014-04-09 02:01:42 —-A—- C:\Windows\SYSWOW64\user.exe
2014-04-09 02:01:42 —-A—- C:\Windows\SYSWOW64\instnm.exe
2014-04-09 02:01:40 —-A—- C:\Windows\system32\drivers\ntfs.sys
2014-04-04 10:32:38 —-A—- C:\Windows\SYSWOW64\mstscax.dll
2014-04-04 10:32:38 —-A—- C:\Windows\system32\mstscax.dll
2014-04-03 12:15:39 —-A—- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-04-03 12:15:36 —-A—- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-04-03 12:15:36 —-A—- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-04-03 12:15:35 —-A—- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-04-03 12:15:33 —-A—- C:\Windows\SYSWOW64\wksprtPS.dll
2014-04-03 12:15:33 —-A—- C:\Windows\SYSWOW64\tsgqec.dll
2014-04-03 12:15:33 —-A—- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2014-04-03 12:15:33 —-A—- C:\Windows\system32\wksprtPS.dll
2014-04-03 12:15:33 —-A—- C:\Windows\system32\tsgqec.dll
2014-04-03 12:15:33 —-A—- C:\Windows\system32\MsRdpWebAccess.dll
2014-04-03 12:15:32 —-A—- C:\Windows\SYSWOW64\mstsc.exe
2014-04-03 12:15:32 —-A—- C:\Windows\system32\wksprt.exe
2014-04-03 12:15:32 —-A—- C:\Windows\system32\TSWbPrxy.exe
2014-04-03 12:15:32 —-A—- C:\Windows\system32\mstsc.exe
2014-04-03 12:15:31 —-A—- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-04-03 12:15:31 —-A—- C:\Windows\system32\rdvidcrl.dll
2014-04-03 12:14:31 —-A—- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-04-03 12:14:31 —-A—- C:\Windows\system32\TSWorkspace.dll
2014-03-29 12:28:31 —-D—- C:\Program Files (x86)\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2014-04-15 21:51:52 —-D—- C:\Windows\Prefetch
2014-04-15 21:51:49 —-RD—- C:\Program Files
2014-04-15 21:49:46 —-D—- C:\Users\Subst\AppData\Roaming\uTorrent
2014-04-15 20:03:26 —-AD—- C:\Windows\Temp
2014-04-15 20:03:14 —-D—- C:\Windows\system32\config
2014-04-15 20:03:10 —-D—- C:\Windows\winsxs
2014-04-15 19:56:42 —-D—- C:\Windows\system32\LogFiles
2014-04-15 19:56:41 —-D—- C:\Windows\System32
2014-04-15 19:56:41 —-D—- C:\Windows\inf
2014-04-15 19:56:40 —-AD—- C:\Windows
2014-04-15 19:55:08 —-D—- C:\Windows\system32\Tasks
2014-04-15 19:53:09 —-SHD—- C:\Windows\Installer
2014-04-15 19:53:08 —-SHD—- C:\Config.Msi
2014-04-15 19:52:43 —-SHD—- C:\System Volume Information
2014-04-15 18:45:10 —-D—- C:\ProgramData\Skype
2014-04-15 18:45:09 —-RD—- C:\Program Files (x86)
2014-04-15 18:45:09 —-D—- C:\Program Files (x86)\Common Files
2014-04-15 18:44:59 —-D—- C:\Users\Subst\AppData\Roaming\Skype
2014-04-15 05:37:26 —-D—- C:\Windows\SoftwareDistribution
2014-04-13 23:03:52 —-D—- C:\Windows\system32\drivers
2014-04-13 22:53:34 —-D—- C:\ProgramData\Windows
2014-04-13 22:21:08 —-HD—- C:\ProgramData
2014-04-13 08:50:45 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-04-12 05:54:51 —-D—- C:\Windows\system32\catroot2
2014-04-11 23:03:06 —-D—- C:\Windows\debug
2014-04-09 20:51:07 —-D—- C:\Windows\Tasks
2014-04-09 20:45:57 —-D—- C:\Windows\system32\drivers\etc
2014-04-09 04:00:47 —-D—- C:\Windows\rescache
2014-04-09 03:21:00 —-D—- C:\Windows\SYSWOW64\nl-NL
2014-04-09 03:21:00 —-D—- C:\Windows\SYSWOW64\en-US
2014-04-09 03:21:00 —-D—- C:\Windows\SysWOW64
2014-04-09 03:21:00 —-D—- C:\Windows\system32\nl-NL
2014-04-09 03:21:00 —-D—- C:\Windows\system32\en-US
2014-04-09 03:20:59 —-D—- C:\Windows\system32\DriverStore
2014-04-09 03:20:59 —-D—- C:\Windows\AppPatch
2014-04-09 03:05:45 —-D—- C:\ProgramData\Microsoft Help
2014-04-09 03:04:38 —-D—- C:\Windows\system32\MRT
2014-04-09 03:02:12 —-A—- C:\Windows\system32\MRT.exe
2014-04-09 02:01:09 —-D—- C:\Windows\system32\catroot
2014-04-04 10:28:04 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-04-03 22:08:55 —-SD—- C:\Users\Subst\AppData\Roaming\Microsoft
2014-04-03 22:06:51 —-D—- C:\ProgramData\EPSON
2014-04-03 22:06:50 —-D—- C:\Users\Subst\AppData\Roaming\Epson
2014-04-03 12:24:22 —-D—- C:\Program Files\CCleaner
2014-04-03 12:17:05 —-D—- C:\Windows\SYSWOW64\wbem
2014-04-03 12:17:05 —-D—- C:\Windows\system32\wbem
2014-04-03 12:17:05 —-D—- C:\Windows\system32\drivers\en-US
2014-04-03 01:29:24 —-D—- C:\Program Files\Microsoft Security Client
2014-04-03 01:29:24 —-D—- C:\Program Files (x86)\Microsoft Security Client
2014-03-19 22:40:07 —-D—- C:\Users\Subst\AppData\Roaming\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys
S3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrxusb.sys
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys
S3 WSDPrintDevice;WSD Print Support via UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys
S3 WSDScan;WSD Scan Support via UMB; C:\Windows\system32\drivers\WSDScan.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe
S4 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S4 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe
S4 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\nlssrv32.exe
S4 SamsungAllShareV2.0;Samsung AllShare PC; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
S4 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
S4 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
—————–EOF—————–
Groet André.