Hoi Ben
Ik heb de pc gescand met mbam en rsit. Hieronder zie je de logjes.
Ik heb op zich geen problemen met de pc maar mijn dochter heeft iets gedownload
via softonic. Dus voor de zekerheid even gescand. Ik hoor graag of er bijzonderheden zijn.
Groetjes Marianne
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 18-8-2014
Scan Time: 17:52:15
Logfile: mbam log.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.18.07
Rootkit Database: v2014.08.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Marianne
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 370534
Time Elapsed: 34 min, 43 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, Quarantined, ,
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, Quarantined, ,
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, Quarantined, ,
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, Quarantined, ,
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1574775380-1247856254-1461627734-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, ,
PUP.Optional.Softonic.A, HKU\S-1-5-21-1574775380-1247856254-1461627734-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, ,
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Logfile of random's system information tool 1.10 (written by random/random)
Run by Marianne at 2014-08-18 19:34:34
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 159 GB (67%) free of 238 GB
Total RAM: 4095 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:34:38, on 18-8-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Marianne\AppData\Roaming\Spotify\spotify.exe
C:\Users\Marianne\AppData\Local\DM\TinyDM.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Marianne.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: “C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe”
O4 - HKLM\..\Run: C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE /EPT “EPLTarget\P0000000000000000” /M “Epson Stylus Office BX535WD”
O4 - HKCU\..\Run: C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: “C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe”
O4 - HKCU\..\Run: “C:\Users\Marianne\AppData\Roaming\Spotify\Spotify.exe” /uri spotify:autostart
O4 - HKCU\..\Run: “C:\Users\Marianne\AppData\Local\DM\TinyDM.exe” /M
O4 - HKCU\..\Run: C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: “C:\Program Files (x86)\Skype\Phone\Skype.exe” /minimized /regrun
O4 - HKCU\..\Run: “C:\Users\Marianne\AppData\Roaming\uTorrent\uTorrent.exe” /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 12775 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
“C:\Windows\system32\nvvsvc.exe”
“C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe”
C:\Windows\system32\svchost.exe -k RPCSS
“c:\Program Files\Microsoft Security Client\MsMpEng.exe”
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
“C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe”
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
“taskhost.exe”
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {B119F4E6-E032-4379-8AB8-6481E4BC6AA0}
“C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe”
“C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe”
“C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe” /STARTUP
“C:\Program Files\Bonjour\mDNSResponder.exe”
“C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe” /service
“C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe” /service
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
“C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE”
WLIDSvcM.exe 2236
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
“C:\Windows\System32\WUDFHost.exe” -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fdb22ba6-7326-4815-80fd-73fe49d6399e -SystemEventPortName:HostProcess-9adf384e-5b56-431c-b1d2-fb7d4d47eebe -IoCancelEventPortName:HostProcess-09cc0b89-f486-412b-bf6f-27b8a1c1c7ec -NonStateChangingEventPortName:HostProcess-762c1ef7-5ba5-4201-8d76-41f98169c8d2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:77874aa7-64e6-445e-b5ff-a9adba91180e -DeviceGroupId:WpdFsGroup
“C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey
“C:\Program Files\Logitech\SetPointP\SetPoint.exe” /launchGaming
“C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe” -s
“C:\Program Files\Windows Sidebar\sidebar.exe” /autoRun
“C:/Program Files/NVIDIA Corporation/Display/nvtray.exe” -user_has_logged_in 1
“C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe” /c
“c:\Program Files\Microsoft Security Client\NisSrv.exe”
“C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE” /EPT “EPLTarget\P0000000000000000” /M “Epson Stylus Office BX535WD”
“C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe”
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe”
C:\Windows\system32\SearchIndexer.exe /Embedding
KHALMNPR.EXE /API
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
“C:\Users\Marianne\AppData\Roaming\Spotify\spotify.exe” /uri spotify:autostart
“C:\Users\Marianne\AppData\Local\DM\TinyDM.exe” /M
“C:\Program Files (x86)\Skype\Phone\Skype.exe” /minimized /regrun
“C:\Program Files (x86)\MagicDisc\MagicDisc.exe”
“C:\Program Files (x86)\CyberLink\Shared Files\brs.exe”
“C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe”
“C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe”
“C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe”
“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
ArcCon.ac 66482 0
“C:\Program Files (x86)\iTunes\iTunesHelper.exe”
“C:\Program Files\iPod\bin\iPodService.exe”
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
“C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe” -Embedding
“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe”
“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=gpu-process –channel=“5080.0.1433077966\1516935257” –supports-dual-gpus=false –gpu-driver-bug-workarounds=1,16,43 –gpu-vendor-id=0x10de –gpu-device-id=0x0611 –gpu-driver-vendor=NVIDIA –gpu-driver-version=9.18.13.1106 –ignored=“ –type=renderer ” /prefetch:822062411
“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=renderer –lang=nl –force-fieldtrials=“BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/” –extension-process –renderer-print-preview –enable-threaded-compositing –enable-delegated-renderer –channel=“5080.2.477991791\906536732” /prefetch:673131151
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe” –type=renderer –js-flags=–harmony-proxies –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“4092.0.1384815214\56469147” /prefetch:673131151
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe” –type=renderer –js-flags=–harmony-proxies –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“4092.1.2028471566\1430957398” /prefetch:673131151
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe” –type=renderer –js-flags=–harmony-proxies –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“4092.2.2108494295\380630050” /prefetch:673131151
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe” –type=renderer –js-flags=–harmony-proxies –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“4092.3.86481746\1397862807” /prefetch:673131151
“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=renderer –lang=nl –force-fieldtrials=“BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_64/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/” –renderer-print-preview –enable-threaded-compositing –enable-delegated-renderer –channel=“5080.5.241100899\1349919801” /prefetch:673131151
“C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyHelper.exe” –type=gpu-process –channel=“4092.4.716874855\2011885828” –no-sandbox –lang=en-US –log-severity=disable –supports-dual-gpus=false –gpu-driver-bug-workarounds=0,9,19,22 –gpu-vendor-id=0x10de –gpu-device-id=0x0611 –gpu-driver-vendor=NVIDIA –gpu-driver-version=9.18.13.1106 –lang=en-US –log-severity=disable /prefetch:822062411
“C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe” -auto
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
“C:\Windows\system32\SearchProtocolHost.exe” Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 “Software\Microsoft\Windows Search” “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)” “C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc” “DownLevelDaemon”
“C:\Windows\system32\SearchFilterHost.exe” 0 516 520 528 65536 524
“C:\Users\Marianne\Desktop\RSITx64.exe”
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
“MSC”=c:\Program Files\Microsoft Security Client\msseces.exe
“EvtMgr6”=C:\Program Files\Logitech\SetPointP\SetPoint.exe
“RTHDVCPL”=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
“Sidebar”=C:\Program Files\Windows Sidebar\sidebar.exe
“IncrediMail”=C:\Program Files (x86)\IncrediMail\bin\IncMail.exe
“EPLTarget\P0000000000000000”=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE
“AnyDVD”=C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
“Spotify Web Helper”=C:\Users\Marianne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
“Spotify”=C:\Users\Marianne\AppData\Roaming\Spotify\Spotify.exe
“Tiny download manager”=C:\Users\Marianne\AppData\Local\DM\TinyDM.exe
“”=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
“Skype”=C:\Program Files (x86)\Skype\Phone\Skype.exe
“uTorrent”=C:\Users\Marianne\AppData\Roaming\uTorrent\uTorrent.exe
“BDRegion”=C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
“GrooveMonitor”=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe
“EEventManager”=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
“ArcSoft Connection Service”=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
“KiesTrayAgent”=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
“SunJavaUpdateSched”=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
“APSDaemon”=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
“iTunesHelper”=C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\Marianne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
“{B5A7F190-DDA6-4420-B3BA-52453494E6CD}”=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=0
“ConsentPromptBehaviorUser”=3
“EnableLUA”=0
“EnableUIADesktopToggle”=0
“PromptOnSecureDesktop”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoDriveTypeAutoRun”=145
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“VIDC.UYVY”=msyuv.dll
“VIDC.YUY2”=msyuv.dll
“VIDC.YVYU”=msyuv.dll
“VIDC.IYUV”=iyuv_32.dll
“vidc.i420”=lvcod64.dll
“VIDC.YVU9”=tsbyuv.dll
“msacm.l3acm”=l3codecp.acm
“VIDC.LAGS”=lagarith.dll
“VIDC.FFDS”=ff_vfw.dll
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
“wave1”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer1”=wdmaud.drv
“aux1”=wdmaud.drv
“MSVideo”=vfwwdm32.dll
“MSVideo8”=VfWWDM32.dll
“wave2”=wdmaud.drv
“midi2”=wdmaud.drv
“mixer2”=wdmaud.drv
“aux2”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 3 months======
2014-08-18 19:34:34 —-D—- C:\rsit
2014-08-18 17:51:44 —-A—- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-08-18 17:51:11 —-A—- C:\Windows\system32\drivers\mwac.sys
2014-08-18 17:51:11 —-A—- C:\Windows\system32\drivers\mbamchameleon.sys
2014-08-18 17:51:11 —-A—- C:\Windows\system32\drivers\mbam.sys
2014-08-18 17:51:10 —-D—- C:\ProgramData\Malwarebytes
2014-08-18 17:51:10 —-D—- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-18 16:36:48 —-D—- C:\Program Files\Tropix 2 - Quest for the Golden Banana
2014-08-18 16:24:10 —-D—- C:\Program Files (x86)\Realore
2014-08-18 16:12:18 —-D—- C:\Program Files (x86)\ReflexiveArcade
2014-08-15 00:15:04 —-A—- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 00:15:04 —-A—- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 00:15:04 —-A—- C:\Windows\system32\infocardapi.dll
2014-08-15 00:15:04 —-A—- C:\Windows\system32\icardagt.exe
2014-08-15 00:15:01 —-A—- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 00:15:01 —-A—- C:\Windows\system32\icardres.dll
2014-08-15 00:14:41 —-A—- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 00:14:41 —-A—- C:\Windows\system32\TsWpfWrp.exe
2014-08-14 23:14:35 —-A—- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-14 23:14:34 —-A—- C:\Windows\SYSWOW64\urlmon.dll
2014-08-14 23:14:34 —-A—- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-14 23:14:34 —-A—- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-14 23:14:34 —-A—- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-14 23:14:34 —-A—- C:\Windows\SYSWOW64\iernonce.dll
2014-08-14 23:14:34 —-A—- C:\Windows\system32\ieetwproxystub.dll
2014-08-14 23:14:33 —-A—- C:\Windows\SYSWOW64\mshtml.dll
2014-08-14 23:14:33 —-A—- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-14 23:14:33 —-A—- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-14 23:14:33 —-A—- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 23:14:32 —-A—- C:\Windows\SYSWOW64\iesetup.dll
2014-08-14 23:14:32 —-A—- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-14 23:14:32 —-A—- C:\Windows\system32\iernonce.dll
2014-08-14 23:14:32 —-A—- C:\Windows\system32\ie4uinit.exe
2014-08-14 23:14:31 —-A—- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-14 23:14:31 —-A—- C:\Windows\SYSWOW64\iertutil.dll
2014-08-14 23:14:31 —-A—- C:\Windows\system32\urlmon.dll
2014-08-14 23:14:31 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 23:14:30 —-A—- C:\Windows\SYSWOW64\ieui.dll
2014-08-14 23:14:30 —-A—- C:\Windows\SYSWOW64\ieframe.dll
2014-08-14 23:14:30 —-A—- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-14 23:14:30 —-A—- C:\Windows\system32\msfeeds.dll
2014-08-14 23:14:30 —-A—- C:\Windows\system32\ieetwcollector.exe
2014-08-14 23:14:30 —-A—- C:\Windows\system32\dxtmsft.dll
2014-08-14 23:14:29 —-A—- C:\Windows\system32\iesetup.dll
2014-08-14 23:14:29 —-A—- C:\Windows\system32\iedkcs32.dll
2014-08-14 23:14:28 —-A—- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-14 23:14:28 —-A—- C:\Windows\system32\iertutil.dll
2014-08-14 23:14:27 —-A—- C:\Windows\SYSWOW64\vbscript.dll
2014-08-14 23:14:27 —-A—- C:\Windows\SYSWOW64\jscript9.dll
2014-08-14 23:14:27 —-A—- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-14 23:14:27 —-A—- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-14 23:14:26 —-A—- C:\Windows\SYSWOW64\wininet.dll
2014-08-14 23:14:26 —-A—- C:\Windows\system32\jsproxy.dll
2014-08-14 23:14:25 —-A—- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-14 23:14:24 —-A—- C:\Windows\SYSWOW64\msrating.dll
2014-08-14 23:14:22 —-A—- C:\Windows\system32\ieui.dll
2014-08-14 23:14:22 —-A—- C:\Windows\system32\ieframe.dll
2014-08-14 23:14:22 —-A—- C:\Windows\system32\dxtrans.dll
2014-08-14 23:14:21 —-A—- C:\Windows\system32\mshtmlmedia.dll
2014-08-14 23:14:21 —-A—- C:\Windows\system32\mshtmled.dll
2014-08-14 23:14:20 —-A—- C:\Windows\system32\vbscript.dll
2014-08-14 23:14:20 —-A—- C:\Windows\system32\jscript9diag.dll
2014-08-14 23:14:20 —-A—- C:\Windows\system32\jscript9.dll
2014-08-14 23:14:20 —-A—- C:\Windows\system32\ieUnatt.exe
2014-08-14 23:14:19 —-A—- C:\Windows\system32\wininet.dll
2014-08-14 23:14:19 —-A—- C:\Windows\system32\ieapfltr.dll
2014-08-14 23:14:18 —-A—- C:\Windows\system32\msrating.dll
2014-08-14 23:14:18 —-A—- C:\Windows\system32\MshtmlDac.dll
2014-08-14 23:14:17 —-A—- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 23:14:17 —-A—- C:\Windows\system32\mshtml.dll
2014-08-14 23:12:57 —-A—- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\system32\KBDYAK.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\system32\KBDTAT.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\system32\KBDRU1.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\system32\KBDRU.DLL
2014-08-14 23:12:57 —-A—- C:\Windows\system32\KBDBASH.DLL
2014-08-14 23:12:09 —-A—- C:\Windows\SYSWOW64\tzres.dll
2014-08-14 23:12:09 —-A—- C:\Windows\system32\tzres.dll
2014-08-14 23:11:26 —-A—- C:\Windows\system32\msi.dll
2014-08-14 23:11:24 —-A—- C:\Windows\SYSWOW64\msi.dll
2014-08-14 23:11:23 —-A—- C:\Windows\SYSWOW64\authui.dll
2014-08-14 23:11:23 —-A—- C:\Windows\system32\authui.dll
2014-08-14 23:11:22 —-A—- C:\Windows\SYSWOW64\msihnd.dll
2014-08-14 23:11:22 —-A—- C:\Windows\system32\msihnd.dll
2014-08-14 23:11:22 —-A—- C:\Windows\system32\consent.exe
2014-08-14 23:10:48 —-A—- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-14 23:10:47 —-A—- C:\Windows\system32\win32k.sys
2014-08-14 23:10:46 —-A—- C:\Windows\SYSWOW64\gdi32.dll
2014-08-14 23:10:46 —-A—- C:\Windows\system32\gdi32.dll
2014-08-14 23:10:43 —-A—- C:\Windows\system32\shell32.dll
2014-08-14 23:10:41 —-A—- C:\Windows\SYSWOW64\shell32.dll
2014-08-14 23:09:04 —-A—- C:\Windows\system32\rpcrt4.dll
2014-08-14 23:09:03 —-A—- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-14 23:08:34 —-A—- C:\Windows\system32\aepdu.dll
2014-08-14 23:08:30 —-A—- C:\Windows\system32\aeinv.dll
2014-08-03 14:51:01 —-A—- C:\Windows\system32\wups2.dll
2014-08-03 14:51:01 —-A—- C:\Windows\system32\wucltux.dll
2014-08-03 14:51:01 —-A—- C:\Windows\system32\wuaueng.dll
2014-08-03 14:51:01 —-A—- C:\Windows\system32\wuauclt.exe
2014-08-03 14:50:45 —-A—- C:\Windows\SYSWOW64\wups.dll
2014-08-03 14:50:45 —-A—- C:\Windows\SYSWOW64\wudriver.dll
2014-08-03 14:50:45 —-A—- C:\Windows\SYSWOW64\wuapi.dll
2014-08-03 14:50:45 —-A—- C:\Windows\system32\wups.dll
2014-08-03 14:50:45 —-A—- C:\Windows\system32\wudriver.dll
2014-08-03 14:50:45 —-A—- C:\Windows\system32\wuapi.dll
2014-08-03 14:49:49 —-A—- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-03 14:49:49 —-A—- C:\Windows\SYSWOW64\wuapp.exe
2014-08-03 14:49:48 —-A—- C:\Windows\system32\wuwebv.dll
2014-08-03 14:49:48 —-A—- C:\Windows\system32\wuapp.exe
2014-07-14 13:02:08 —-A—- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-07-14 12:20:18 —-A—- C:\Windows\SYSWOW64\osk.exe
2014-07-14 12:20:16 —-A—- C:\Windows\system32\osk.exe
2014-07-14 12:19:01 —-A—- C:\Windows\SYSWOW64\qedit.dll
2014-07-14 12:19:01 —-A—- C:\Windows\system32\qedit.dll
2014-07-14 12:18:56 —-A—- C:\Windows\system32\drivers\afd.sys
2014-07-14 12:18:30 —-A—- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-14 12:18:30 —-A—- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-14 12:18:30 —-A—- C:\Windows\SYSWOW64\credssp.dll
2014-07-14 12:18:28 —-A—- C:\Windows\SYSWOW64\wdigest.dll
2014-07-14 12:18:28 —-A—- C:\Windows\SYSWOW64\schannel.dll
2014-07-14 12:18:28 —-A—- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-14 12:18:28 —-A—- C:\Windows\SYSWOW64\kerberos.dll
2014-07-14 12:18:18 —-A—- C:\Windows\system32\wdigest.dll
2014-07-14 12:18:18 —-A—- C:\Windows\system32\schannel.dll
2014-07-14 12:18:18 —-A—- C:\Windows\system32\msv1_0.dll
2014-07-14 12:18:18 —-A—- C:\Windows\system32\kerberos.dll
2014-07-14 12:18:17 —-A—- C:\Windows\system32\TSpkg.dll
2014-07-14 12:18:17 —-A—- C:\Windows\system32\ncrypt.dll
2014-07-14 12:18:17 —-A—- C:\Windows\system32\credssp.dll
2014-07-14 12:16:53 —-A—- C:\Windows\SYSWOW64\sspicli.dll
2014-07-14 12:16:53 —-A—- C:\Windows\SYSWOW64\secur32.dll
2014-07-14 12:16:33 —-A—- C:\Windows\system32\lsasrv.dll
2014-07-14 10:30:13 —-D—- C:\Program Files (x86)\Photo Notifier and Animation Creator
2014-07-14 10:30:12 —-D—- C:\ProgramData\Photo Notifier and Animation Creator
2014-06-19 20:32:14 —-D—- C:\Users\Marianne\AppData\Roaming\dvdcss
2014-06-12 17:43:33 —-A—- C:\Windows\SYSWOW64\usp10.dll
2014-06-12 17:43:33 —-A—- C:\Windows\system32\usp10.dll
2014-06-12 17:43:33 —-A—- C:\Windows\system32\drivers\tcpip.sys
2014-06-12 17:43:32 —-A—- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 17:43:31 —-A—- C:\Windows\SYSWOW64\msxml6r.dll
2014-06-12 17:43:31 —-A—- C:\Windows\SYSWOW64\msxml6.dll
2014-06-12 17:43:31 —-A—- C:\Windows\SYSWOW64\msxml3r.dll
2014-06-12 17:43:31 —-A—- C:\Windows\SYSWOW64\msxml3.dll
2014-06-12 17:43:31 —-A—- C:\Windows\system32\msxml6r.dll
2014-06-12 17:43:31 —-A—- C:\Windows\system32\msxml6.dll
2014-06-12 17:43:31 —-A—- C:\Windows\system32\msxml3r.dll
2014-06-12 17:43:31 —-A—- C:\Windows\system32\msxml3.dll
2014-06-12 17:43:30 —-A—- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-12 17:43:30 —-A—- C:\Windows\system32\rdpcorets.dll
2014-06-12 17:43:27 —-A—- C:\Windows\SYSWOW64\urlmon(186).dll
2014-06-12 17:43:25 —-A—- C:\Windows\SYSWOW64\iertutil(183).dll
2014-06-12 17:43:25 —-A—- C:\Windows\system32\urlmon(178).dll
2014-06-12 17:43:21 —-A—- C:\Windows\system32\iertutil(166).dll
2014-06-12 17:43:20 —-A—- C:\Windows\SYSWOW64\wininet(187).dll
2014-06-12 17:43:17 —-A—- C:\Windows\system32\wininet(181).dll
2014-06-10 18:11:40 —-A—- C:\Windows\SYSWOW64\secman.dll
======List of files/folders modified in the last 3 months======
2014-08-18 19:34:38 —-D—- C:\Windows\Prefetch
2014-08-18 19:34:37 —-D—- C:\Program Files\trend micro
2014-08-18 19:34:11 —-D—- C:\Windows\Temp
2014-08-18 19:24:47 —-D—- C:\Windows\system32\config
2014-08-18 18:57:39 —-D—- C:\Users\Marianne\AppData\Roaming\Spotify
2014-08-18 18:56:41 —-D—- C:\Users\Marianne\AppData\Roaming\uTorrent
2014-08-18 18:53:27 —-D—- C:\ProgramData\NVIDIA
2014-08-18 18:48:13 —-D—- C:\Users\Marianne\AppData\Roaming\Vso
2014-08-18 18:03:12 —-SHD—- C:\System Volume Information
2014-08-18 17:51:44 —-D—- C:\Windows\system32\drivers
2014-08-18 17:51:10 —-RD—- C:\Program Files (x86)
2014-08-18 17:51:10 —-HD—- C:\ProgramData
2014-08-18 17:46:18 —-D—- C:\Windows\system32\FxsTmp
2014-08-18 16:38:11 —-D—- C:\Windows\SysWOW64
2014-08-18 16:36:48 —-RD—- C:\Program Files
2014-08-18 16:10:33 —-D—- C:\Windows\System32
2014-08-18 16:10:33 —-D—- C:\Windows\inf
2014-08-18 16:10:33 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-08-16 14:43:38 —-A—- C:\Windows\NeroDigital.ini
2014-08-15 21:51:40 —-D—- C:\Windows\rescache
2014-08-15 14:28:34 —-D—- C:\Windows\Microsoft.NET
2014-08-15 14:28:00 —-RSD—- C:\Windows\assembly
2014-08-15 14:12:14 —-D—- C:\Windows\Minidump
2014-08-15 14:11:52 —-D—- C:\Windows
2014-08-15 00:44:50 —-D—- C:\Windows\winsxs
2014-08-15 00:41:33 —-D—- C:\Windows\ehome
2014-08-15 00:41:32 —-RSD—- C:\Windows\Fonts
2014-08-15 00:41:18 —-D—- C:\Windows\SYSWOW64\nl-NL
2014-08-15 00:41:18 —-D—- C:\Windows\system32\nl-NL
2014-08-15 00:41:14 —-D—- C:\Program Files\Internet Explorer
2014-08-15 00:41:13 —-D—- C:\Windows\SYSWOW64\en-US
2014-08-15 00:41:12 —-D—- C:\Windows\PolicyDefinitions
2014-08-15 00:41:11 —-D—- C:\Windows\system32\en-US
2014-08-15 00:41:10 —-D—- C:\Program Files (x86)\Internet Explorer
2014-08-15 00:33:35 —-SHD—- C:\Windows\Installer
2014-08-15 00:33:34 —-D—- C:\ProgramData\Microsoft Help
2014-08-15 00:31:15 —-D—- C:\Windows\system32\catroot2
2014-08-15 00:31:15 —-D—- C:\Windows\system32\catroot
2014-08-15 00:27:03 —-D—- C:\Windows\system32\MRT
2014-08-15 00:20:15 —-A—- C:\Windows\system32\MRT.exe
2014-08-15 00:13:58 —-SD—- C:\Windows\system32\CompatTel
2014-07-31 23:50:20 —-D—- C:\Users\Marianne\AppData\Roaming\Skype
2014-07-29 18:03:33 —-D—- C:\Windows\system32\NDF
2014-07-27 12:47:11 —-D—- C:\ProgramData\Skype
2014-07-27 12:47:08 —-RD—- C:\Program Files (x86)\Skype
2014-07-27 12:47:08 —-D—- C:\Program Files (x86)\Common Files
2014-07-25 08:47:31 —-D—- C:\Program Files\Microsoft Silverlight
2014-07-25 08:47:29 —-D—- C:\Program Files (x86)\Microsoft Silverlight
2014-07-15 10:53:35 —-D—- C:\Program Files\Windows Journal
2014-07-15 10:53:34 —-D—- C:\Windows\SYSWOW64\Dism
2014-07-15 10:53:34 —-D—- C:\Windows\system32\Dism
2014-07-14 15:42:39 —-D—- C:\Users\Marianne\AppData\Roaming\Belastingdienst
2014-07-14 13:02:30 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-07-14 12:01:24 —-D—- C:\Windows\system32\wbem
2014-07-14 12:00:05 —-D—- C:\Windows\Tasks
2014-07-14 12:00:05 —-D—- C:\Windows\SYSWOW64\wbem
2014-07-14 12:00:05 —-D—- C:\Windows\system32\wfp
2014-07-14 12:00:05 —-D—- C:\Windows\system32\DriverStore
2014-07-14 12:00:04 —-D—- C:\Windows\ShellNew
2014-07-14 12:00:01 —-D—- C:\Windows\SYSWOW64\Macromed
2014-07-14 12:00:01 —-D—- C:\Windows\system32\Tasks
2014-07-14 12:00:00 —-D—- C:\Windows\system32\Macromed
2014-07-14 12:00:00 —-D—- C:\Windows\system32\CodeIntegrity
2014-07-14 12:00:00 —-D—- C:\Windows\AppCompat
2014-07-14 12:00:00 —-D—- C:\Windows\.jagex_cache_32
2014-07-14 11:59:58 —-D—- C:\Users\Marianne\AppData\Roaming\IObit
2014-07-14 11:59:58 —-D—- C:\Users\Marianne\AppData\Roaming\Arcsoft
2014-07-14 11:59:54 —-D—- C:\ProgramData\CyberLink
2014-07-14 11:59:53 —-D—- C:\Program Files\Common Files\Microsoft Shared
2014-07-14 11:59:31 —-D—- C:\Windows\registration
2014-07-14 11:57:53 —-D—- C:\Program Files (x86)\IncrediMail
2014-06-10 19:05:30 —-D—- C:\Windows\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x64.sys
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys
S3 CamDrL64;Logitech QuickCam Pro 3000(PID_08B0); C:\Windows\system32\DRIVERS\CamDrL64.sys
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys
S3 epmntdrv;epmntdrv; \??\C:\Windows\syswow64\epmntdrv.sys
S3 EuGdiDrv;EuGdiDrv; \??\C:\Windows\syswow64\EuGdiDrv.sys
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys
S3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys
S3 LVUSBS64;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBS64.sys
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys
S3 WinUsb;Sony sa0107 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe
S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
—————–EOF—————–