Goedemorgen
Sinds gisteren heb ik ineens een andere startpagina.
Ik had altijd Google en ineens is dit websearches.com geworden.
Ik heb al een paar keer getracht google weer in te stellen als startpagina maar dat lukt me niet.
Ik gebruik als browser Mozilla firefox.
Bijgaand mijn logjes.
Rikje
Logfile of random's system information tool 1.10 (written by random/random)
Run by Erika at 2014-08-24 09:12:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 763 GB (81%) free of 941 GB
Total RAM: 6071 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:12:25, on 24-8-2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe
C:\Program Files (x86)\Sitecom\Common\RaUI.exe
C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
C:\Program Files\trend micro\Erika.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1408804271&from=ild&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1408804271&from=ild&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: TNS NIPO Clicks - {FB4D29C1-82DE-4b80-8BB0-A7CDDDCD2773} - C:\Users\Erika\AppData\Local\Wakoopa Shared\WakoopaBHO.dll
O4 - HKLM\..\Run: c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
O4 - HKLM\..\Run: C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe” -launchedbylogin
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
O4 - HKLM\..\Run: “C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe” –showwindow=false –onOSstartup=true
O4 - HKLM\..\Run: “C:\Program Files (x86)\AVG\AVG2014\avgui.exe” /TRAYONLY
O4 - HKLM\..\Run: “C:\Program Files (x86)\AVG Web TuneUp\vprot.exe”
O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
O4 - HKCU\..\Run: “C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe” -deviceID “CN19F411SS05QB:NW” -scfn “HP Photosmart 6510 series (NET)” -AutoStart 1
O4 - HKCU\..\Run: “C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe”
O4 - HKCU\..\Run: C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe
O4 - HKCU\..\Run: C:\Users\Erika\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=8da9f4b0987847d392c69128c064797a-b1ab53bf69ee3d56e0b68fecf6a63d5566bf3245 /CMPID=1213b
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18\..\Run: “C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe” (User ‘SYSTEM’)
O4 - HKUS\S-1-5-18\..\RunOnce: “C:\Windows\System32\SPReview\SPReview.exe” /sp:1 /errorfwlink:“http://go.microsoft.com/fwlink/?LinkID=122915” /build:7601 (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\Run: “C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe” (User ‘Default user’)
O4 - HKUS\.DEFAULT\..\RunOnce: “C:\Windows\System32\SPReview\SPReview.exe” /sp:1 /errorfwlink:“http://go.microsoft.com/fwlink/?LinkID=122915” /build:7601 (User ‘Default user’)
O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files (x86)\Sitecom\Common\RaUI.exe
O4 - Global Startup: Spyder3Utility.lnk = C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra ‘Tools’ menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.1.0\ViProtocol.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: CodecIconProgram.exe - Unknown owner - C:\Users\Erika\AppData\Local\CodecIconProgram\CodecIconProgram.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ExportRootSamba - Unknown owner - C:\Windows\SysWOW64\ExportRootSamba\ExportRootSamba.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater3.1.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.1.0\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 15481 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=24beb63a-c9f6-4e4d-a2d7-0a7a848b9777 /coreSdkOptions=4382 /logConfFile=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\c3e8f479-4b5f-4004-9a13-fa3e8994ee6f-1c4-oopp.tmp” /loggerName=AVG.RS.Core /binaryPath=“C:\Program Files (x86)\AVG\AVG2014\” /tempPath=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\temp\” /logPath=“C:\Windows\system32\config\systemprofile\AppData\Local\Avg2014\log\”
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
“C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe”
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 24015792
\??\C:\Windows\system32\conhost.exe "-474136387-132179017-3607686611300500933-1217948585315370371-1509336368-686969187
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
“taskhost.exe”
“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe”
“C:\Windows\system32\Dwm.exe”
C:\Windows\Explorer.EXE
“C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe”
“C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE”
“C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE”
C:\Windows\SysWOW64\svchost.exe -k netsvcs
“C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe” -servicelaunch=true
taskeng.exe {DB3721DD-98E8-4275-BDE8-AB2B653974AC}
“C:\Program Files\Software Informer\softinfo.exe” -service
“C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe”
“C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe”
“C:\Program Files (x86)\AVG\AVG2014\avgemca.exe”
“c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe”
“C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe”
taskeng.exe {5EEFB749-297E-48DF-B6D8-137B8EC60A07}
“c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe”
“C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe”
“C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe”
“C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe”
“C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe” /starttray
C:\Windows\system32\svchost.exe -k imgsvc
“C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.1.0\ToolbarUpdater.exe”
“C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe”
“C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.1.0\loggingserver.exe” 72648 “C:\ProgramData\AVG Secure Search\Logger\logger.properties”
\??\C:\Windows\system32\conhost.exe "2076819684-191725694977871055710072731161969649814728350843511251188-1525783807
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
“C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe”
C:\Windows\servicing\TrustedInstaller.exe
“C:\Windows\System32\WUDFHost.exe” -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3425076e-1da6-419b-82fa-155982813e0e -SystemEventPortName:HostProcess-d0f9fa6d-26d8-41ca-b618-2261d91734df -IoCancelEventPortName:HostProcess-4f2def46-94ff-4de2-94eb-358b5a2ec3e4 -NonStateChangingEventPortName:HostProcess-d4f0883b-5eb4-4899-9a22-be827a7b9209 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:54e21c39-076a-469a-9ea3-a49e62a890eb -DeviceGroupId:WpdFsGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
“C:\Program Files\Logitech\SetPointP\SetPoint.exe” /launchGaming
“C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe” -deviceID “CN19F411SS05QB:NW” -scfn “HP Photosmart 6510 series (NET)” -AutoStart 1
“C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe”
“C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe”
“C:\Program Files (x86)\Sitecom\Common\RaUI.exe” -s
“C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe”
“C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe”
“C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe”
“C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe” –showwindow=false –onOSstartup=true
“C:\Program Files (x86)\AVG\AVG2014\avgui.exe” /TRAYONLY
“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
KHALMNPR.EXE /API
“C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe” “-launchedbyvulcan”
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
“C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe”
“C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe” –type=renderer –no-sandbox –lang=en-US –lang=en-US –log-severity=disable –channel=“5696.0.941971595\2147114330” /prefetch:3
“C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe”
“C:\Program Files\Windows Media Player\wmpnetwk.exe”
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
“C:\Program Files (x86)\Mozilla Firefox\firefox.exe” http://istart.webssearches.com/?type=sc&ts=1408804271&from=ild&uid=WDCXWD10EADS-65M2B0_WD-WCAV5634178841788
C:\Windows\system32\wbem\wmiprvse.exe
“C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe” –channel=3972.19737240.224051275 “C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll” -greomni “C:\Program Files (x86)\Mozilla Firefox\omni.ja” -appomni “C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja” -appdir “C:\Program Files (x86)\Mozilla Firefox\browser” E7CF176E110C211B 3972 “\\.\pipe\gecko-crash-server-pipe.3972” plugin
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe” –proxy-stub-channel=Flash5312.594A0D80.12256 –host-broker-channel=Flash5312.594A0D80.3139 –host-pid=5312 –host-npapi-version=27 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll”
“C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe” –channel=1248.0038F8A0.1443440671 –proxy-stub-channel=Flash5312.594A0D80.12256 –plugin-path=“C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll” –host-npapi-version=27 –type=renderer
“C:\Users\Erika\Desktop\RSITx64.exe”
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default
prefs.js - “browser.search.useDBForOrder” - “false”
prefs.js - “browser.startup.homepage” - “https://www.google.nl/?gws_rd=ssl”
prefs.js - “extensions.enabledItems” - “{a55c4ab0-ac89-4352-a750-98552a6a9337}:1.0, avg@igeared:6.103.018.001, DeviceDetection@logitech.com:1.21.0.11, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17”
“Description”=Adobe® Flash® Player 14.0.0.179 Plugin
“Path”=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
“Description”=Adobe Shockwave Player
“Path”=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll
“Description”=
“Path”=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\3.1.0\\npsitesafety.dll
“Description”=Garmin GPS Control for Firefox
“Path”=C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
“Description”=Google Earth in your browser
“Path”=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
“Description”=Zylom Games Player 1.00
“Path”=C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
“Description”=Adobe® Flash® Player 14.0.0.179 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll
“Description”=Garmin GPS Control for Firefox
“Path”=C:\Program Files\Garmin GPS Plugin\npGarmin.dll
“Description”=
“Path”=disabled
“Description”=Ag Player Plugin
“Path”=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
“Description”=
“Path”=
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
“Description”=
“Path”=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
ILnsp110.log
ILnsp120.log
NPCltInst11.dll
NPCltInst121.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\extensions\
DeviceDetection@logitech.com
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}-trash
{6d0f26ba-45b8-4871-9c07-43ab341d5b73}
{ab91efd4-6975-4081-8552-1b3922ed79e2}
C:\Users\Erika\AppData\Roaming\Mozilla\Firefox\Profiles\pp5a1fpf.default\searchplugins\
avg-secure-search.xml
======Registry dump======
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
Java™ Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TNS NIPO Clicks - C:\Users\Erika\AppData\Local\Wakoopa Shared\WakoopaBHO.dll
“AdobeAAMUpdater-1.0”=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
“Logitech Download Assistant”=C:\Windows\System32\LogiLDA.dll
“EvtMgr6”=C:\Program Files\Logitech\SetPointP\SetPoint.exe
“NCPluginUpdater”=C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
“HP Photosmart 6510 series (NET)”=C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe
“GarminExpressTrayApp”=C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
“TNS NIPO Clicks”=C:\Users\Erika\AppData\Local\TNS NIPO Clicks\TNS NIPO Clicks.exe
“AVG-Secure-Search-Update_1213b”=C:\Users\Erika\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=8da9f4b0987847d392c69128c064797a-b1ab53bf69ee3d56e0b68fecf6a63d5566bf3245 /CMPID=1213b
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
“hpsysdrv”=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
“IAStorIcon”=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
“StartCCC”=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
“SwitchBoard”=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
“AdobeCS6ServiceManager”=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
“Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
“APSDaemon”=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
“QuickTime Task”=C:\Program Files (x86)\QuickTime\QTTask.exe
“Adobe Creative Cloud”=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
“AVG_UI”=C:\Program Files (x86)\AVG\AVG2014\avgui.exe
“vProt”=C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
“SunJavaUpdateSched”=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Sitecom Wireless Utility.lnk - C:\Program Files (x86)\Sitecom\Common\RaUI.exe
Spyder3Utility.lnk - C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
“{E54729E8-BB3D-4270-9D49-7389EA579090}”=C:\Windows\SysWow64\EZUPBH~1.DLL
“SecurityProviders”=credssp.dll
“ConsentPromptBehaviorAdmin”=5
“ConsentPromptBehaviorUser”=3
“EnableUIADesktopToggle”=0
“PromptOnSecureDesktop”=0
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“NoActiveDesktop”=1
“NoActiveDesktopChanges”=1
“ForceActiveDesktopOn”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“vidc.uyvy”=msyuv.dll
“vidc.yuy2”=msyuv.dll
“vidc.yvyu”=msyuv.dll
“vidc.iyuv”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“vidc.yvu9”=tsbyuv.dll
“msacm.l3acm”=C:\Windows\System32\l3codeca.acm
“wave1”=wdmaud.drv
“midi1”=wdmaud.drv
“mixer1”=wdmaud.drv
“aux1”=wdmaud.drv
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 1 month======
2014-08-24 09:12:18 —-D—- C:\rsit
2014-08-24 08:34:18 —-A—- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-08-24 08:34:01 —-A—- C:\Windows\system32\drivers\mwac.sys
2014-08-24 08:34:01 —-A—- C:\Windows\system32\drivers\mbamchameleon.sys
2014-08-24 08:34:01 —-A—- C:\Windows\system32\drivers\mbam.sys
2014-08-23 16:31:53 —-D—- C:\Program Files (x86)\SiteLookup
2014-08-23 16:30:19 —-D—- C:\Program Files (x86)\globalUpdate
2014-08-23 15:48:56 —-D—- C:\Users\Erika\AppData\Roaming\uTorrent
2014-08-14 21:53:53 —-A—- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-14 21:53:53 —-A—- C:\Windows\SYSWOW64\icardagt.exe
2014-08-14 21:53:53 —-A—- C:\Windows\system32\infocardapi.dll
2014-08-14 21:53:53 —-A—- C:\Windows\system32\icardagt.exe
2014-08-14 21:53:38 —-A—- C:\Windows\SYSWOW64\icardres.dll
2014-08-14 21:53:38 —-A—- C:\Windows\system32\icardres.dll
2014-08-14 21:52:00 —-A—- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-14 21:52:00 —-A—- C:\Windows\system32\TsWpfWrp.exe
2014-08-14 17:05:48 —-A—- C:\Windows\SYSWOW64\tzres.dll
2014-08-14 17:05:48 —-A—- C:\Windows\system32\tzres.dll
2014-08-14 17:05:34 —-A—- C:\Windows\system32\msi.dll
2014-08-14 17:05:33 —-A—- C:\Windows\SYSWOW64\msi.dll
2014-08-14 17:05:33 —-A—- C:\Windows\system32\authui.dll
2014-08-14 17:05:32 —-A—- C:\Windows\SYSWOW64\authui.dll
2014-08-14 17:05:32 —-A—- C:\Windows\system32\consent.exe
2014-08-14 17:05:31 —-A—- C:\Windows\SYSWOW64\msihnd.dll
2014-08-14 17:05:31 —-A—- C:\Windows\system32\msihnd.dll
2014-08-14 17:05:25 —-A—- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-14 17:05:24 —-A—- C:\Windows\system32\win32k.sys
2014-08-14 17:05:23 —-A—- C:\Windows\SYSWOW64\gdi32.dll
2014-08-14 17:05:23 —-A—- C:\Windows\system32\gdi32.dll
2014-08-14 17:05:02 —-A—- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-14 17:05:02 —-A—- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-14 17:05:01 —-A—- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-14 17:05:01 —-A—- C:\Windows\SYSWOW64\iernonce.dll
2014-08-14 17:05:00 —-A—- C:\Windows\SYSWOW64\urlmon.dll
2014-08-14 17:05:00 —-A—- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-14 17:04:59 —-A—- C:\Windows\system32\ieetwproxystub.dll
2014-08-14 17:04:58 —-A—- C:\Windows\SYSWOW64\mshtml.dll
2014-08-14 17:04:58 —-A—- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-14 17:04:58 —-A—- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-14 17:04:58 —-A—- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 17:04:56 —-A—- C:\Windows\SYSWOW64\iesetup.dll
2014-08-14 17:04:56 —-A—- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-14 17:04:56 —-A—- C:\Windows\system32\iernonce.dll
2014-08-14 17:04:56 —-A—- C:\Windows\system32\ie4uinit.exe
2014-08-14 17:04:55 —-A—- C:\Windows\SYSWOW64\iertutil.dll
2014-08-14 17:04:55 —-A—- C:\Windows\system32\urlmon.dll
2014-08-14 17:04:55 —-A—- C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 17:04:54 —-A—- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-14 17:04:54 —-A—- C:\Windows\system32\ieetwcollector.exe
2014-08-14 17:04:53 —-A—- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-14 17:04:53 —-A—- C:\Windows\system32\dxtmsft.dll
2014-08-14 17:04:52 —-A—- C:\Windows\SYSWOW64\ieui.dll
2014-08-14 17:04:52 —-A—- C:\Windows\SYSWOW64\ieframe.dll
2014-08-14 17:04:52 —-A—- C:\Windows\system32\msfeeds.dll
2014-08-14 17:04:51 —-A—- C:\Windows\system32\iesetup.dll
2014-08-14 17:04:51 —-A—- C:\Windows\system32\iedkcs32.dll
2014-08-14 17:04:49 —-A—- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-14 17:04:49 —-A—- C:\Windows\SYSWOW64\jscript9.dll
2014-08-14 17:04:49 —-A—- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-14 17:04:49 —-A—- C:\Windows\system32\iertutil.dll
2014-08-14 17:04:48 —-A—- C:\Windows\SYSWOW64\wininet.dll
2014-08-14 17:04:48 —-A—- C:\Windows\SYSWOW64\vbscript.dll
2014-08-14 17:04:48 —-A—- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-14 17:04:47 —-A—- C:\Windows\system32\jsproxy.dll
2014-08-14 17:04:46 —-A—- C:\Windows\SYSWOW64\msrating.dll
2014-08-14 17:04:46 —-A—- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-14 17:04:45 —-A—- C:\Windows\system32\dxtrans.dll
2014-08-14 17:04:44 —-A—- C:\Windows\system32\ieui.dll
2014-08-14 17:04:44 —-A—- C:\Windows\system32\ieframe.dll
2014-08-14 17:04:43 —-A—- C:\Windows\system32\mshtmlmedia.dll
2014-08-14 17:04:43 —-A—- C:\Windows\system32\mshtmled.dll
2014-08-14 17:04:43 —-A—- C:\Windows\system32\ieUnatt.exe
2014-08-14 17:04:42 —-A—- C:\Windows\system32\jscript9diag.dll
2014-08-14 17:04:42 —-A—- C:\Windows\system32\jscript9.dll
2014-08-14 17:04:41 —-A—- C:\Windows\system32\vbscript.dll
2014-08-14 17:04:41 —-A—- C:\Windows\system32\ieapfltr.dll
2014-08-14 17:04:40 —-A—- C:\Windows\system32\wininet.dll
2014-08-14 17:04:39 —-A—- C:\Windows\system32\msrating.dll
2014-08-14 17:04:39 —-A—- C:\Windows\system32\MshtmlDac.dll
2014-08-14 17:04:38 —-A—- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 17:04:38 —-A—- C:\Windows\system32\mshtml.dll
2014-08-14 17:04:06 —-A—- C:\Windows\system32\rpcrt4.dll
2014-08-14 17:04:05 —-A—- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-06 14:54:42 —-D—- C:\Program Files (x86)\Mozilla Firefox
2014-08-06 10:13:34 —-D—- C:\ProgramData\Oracle
2014-08-06 10:13:27 —-A—- C:\Windows\SYSWOW64\javaws.exe
2014-08-06 10:13:11 —-A—- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-08-06 10:13:10 —-A—- C:\Windows\SYSWOW64\javaw.exe
2014-08-06 10:13:10 —-A—- C:\Windows\SYSWOW64\java.exe
2014-08-04 14:11:22 —-A—- C:\Windows\system32\drivers\avgtpx64.sys
2014-08-04 14:10:48 —-D—- C:\ProgramData\AVG Secure Search
2014-08-04 13:31:33 —-D—- C:\ProgramData\AVG Security Toolbar
2014-08-04 13:30:51 —-D—- C:\ProgramData\AVG Web TuneUp
2014-08-04 13:30:50 —-D—- C:\Program Files (x86)\AVG Web TuneUp
2014-07-28 15:12:37 —-A—- C:\DelFix.txt
2014-07-28 08:59:09 —-A—- C:\Windows\SYSWOW64\sqlite3.dll
======List of files/folders modified in the last 1 month======
2014-08-24 09:12:23 —-D—- C:\Program Files\trend micro
2014-08-24 09:12:19 —-D—- C:\Windows\Temp
2014-08-24 09:01:57 —-D—- C:\Windows\system32\config
2014-08-24 08:58:06 —-HD—- C:\ProgramData
2014-08-24 08:58:04 —-D—- C:\Windows\Web
2014-08-24 08:58:04 —-D—- C:\Windows\system32\drivers
2014-08-24 08:56:57 —-RD—- C:\Program Files (x86)
2014-08-24 08:56:44 —-D—- C:\Windows\Tasks
2014-08-24 08:56:44 —-D—- C:\Windows\system32\Tasks
2014-08-24 08:34:04 —-D—- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-24 08:28:56 —-D—- C:\ProgramData\MFAData
2014-08-23 18:17:51 —-D—- C:\Windows\system32\wbem
2014-08-23 18:17:51 —-D—- C:\Windows
2014-08-23 18:15:26 —-D—- C:\Program Files\Common Files\Microsoft Shared
2014-08-23 18:15:03 —-D—- C:\Program Files\Internet Explorer
2014-08-23 18:15:03 —-D—- C:\Program Files (x86)\Internet Explorer
2014-08-23 18:14:29 —-D—- C:\Windows\AppCompat
2014-08-23 18:14:23 —-SHD—- C:\Windows\Installer
2014-08-23 18:14:23 —-D—- C:\Windows\system32\CodeIntegrity
2014-08-23 18:14:23 —-D—- C:\Windows\system32\catroot2
2014-08-23 18:14:23 —-D—- C:\Windows\System32
2014-08-23 18:14:23 —-D—- C:\Windows\servicing
2014-08-23 18:14:23 —-D—- C:\Windows\rescache
2014-08-23 18:14:23 —-D—- C:\Windows\PolicyDefinitions
2014-08-23 18:14:23 —-D—- C:\Windows\inf
2014-08-23 18:14:22 —-D—- C:\Windows\winsxs
2014-08-23 18:14:22 —-D—- C:\Windows\SYSWOW64\XPSViewer
2014-08-23 18:14:22 —-D—- C:\Windows\SYSWOW64\nl-NL
2014-08-23 18:14:22 —-D—- C:\Windows\SYSWOW64\MUI
2014-08-23 18:14:22 —-D—- C:\Windows\SYSWOW64\en-US
2014-08-23 18:14:22 —-D—- C:\Windows\SysWOW64
2014-08-23 18:14:22 —-D—- C:\Windows\system32\nl-NL
2014-08-23 18:14:22 —-D—- C:\Windows\system32\MUI
2014-08-23 18:14:22 —-D—- C:\Windows\system32\en-US
2014-08-23 18:14:22 —-D—- C:\Windows\system32\DriverStore
2014-08-23 18:13:34 —-D—- C:\Windows\registration
2014-08-23 18:05:19 —-SHD—- C:\System Volume Information
2014-08-23 16:46:13 —-D—- C:\ProgramData\Hewlett-Packard
2014-08-23 16:38:53 —-SHD—- C:\Config.Msi
2014-08-23 16:38:20 —-D—- C:\ProgramData\AVG2014
2014-08-23 16:30:09 —-D—- C:\Program Files (x86)\Garmin
2014-08-23 15:36:26 —-A—- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-08-23 15:36:25 —-D—- C:\Windows\Prefetch
2014-08-23 09:01:25 —-D—- C:\Users\Erika\AppData\Roaming\Dropbox
2014-08-23 08:46:09 —-D—- C:\Users\Erika\AppData\Roaming\Belastingdienst
2014-08-21 09:49:11 —-A—- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-08-17 15:26:31 —-A—- C:\Windows\system32\PerfStringBackup.INI
2014-08-15 08:57:39 —-D—- C:\Windows\Microsoft.NET
2014-08-15 08:56:49 —-RSD—- C:\Windows\assembly
2014-08-15 08:33:47 —-D—- C:\Windows\ehome
2014-08-14 22:47:15 —-D—- C:\ProgramData\Microsoft Help
2014-08-14 22:44:07 —-D—- C:\Windows\system32\catroot
2014-08-14 22:11:00 —-D—- C:\Windows\system32\MRT
2014-08-14 22:07:14 —-D—- C:\Windows\debug
2014-08-14 22:07:12 —-A—- C:\Windows\system32\MRT.exe
2014-08-14 11:08:41 —-D—- C:\ProgramData\Soulseek
2014-08-12 08:37:29 —-D—- C:\ProgramData\Package Cache
2014-08-12 08:36:32 —-D—- C:\ProgramData\Garmin
2014-08-07 09:53:53 —-D—- C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-04 14:01:58 —-D—- C:\Windows\system32\wfp
2014-08-04 13:56:33 —-SHD—- C:\$RECYCLE.BIN
2014-08-04 13:56:33 —-D—- C:\Program Files (x86)\Common Files
2014-07-28 08:49:41 —-D—- C:\Program Files\Microsoft Silverlight
2014-07-28 08:49:40 —-D—- C:\Program Files (x86)\Microsoft Silverlight
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys
R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys
R1 RapportCerberus_69875;RapportCerberus_69875; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_69875.sys
R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys
R2 acedrv11;acedrv11; \??\C:\Windows\system32\drivers\acedrv11.sys
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys
R3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\Windows\system32\drivers\serscan.sys
S1 RxFilter;RxFilter; C:\Windows\system32\DRIVERS\RxFilter.sys
S3 grmnusb;Garmin USB Driver; C:\Windows\system32\drivers\grmnusb.sys
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys
S3 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys
S3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey; C:\Windows\system32\DRIVERS\SNTUSB64.SYS
S3 Spyder3;Datacolor Spyder3; C:\Windows\system32\DRIVERS\Spyder3.sys
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
R2 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
R2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe
R2 Garmin Core Update Service;Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
R2 RoxWatch10;Roxio Hard Drive Watcher 10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
R2 vToolbarUpdater3.1.0;vToolbarUpdater3.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\3.1.0\ToolbarUpdater.exe
R3 RoxMediaDB10;RoxMediaDB10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 CodecIconProgram.exe;CodecIconProgram.exe; C:\Users\Erika\AppData\Local\CodecIconProgram\CodecIconProgram.exe
S2 ExportRootSamba;ExportRootSamba; C:\Windows\SysWOW64\ExportRootSamba\ExportRootSamba.exe
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S2 Roxio Upnp Server 10;Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
S2 RoxLiveShare10;LiveShare P2P Server 10; C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
—————–EOF—————–
de rest in volgende bericht