Logfile of random's system information tool 1.10 (written by random/random) Run by Geo at 2014-10-31 14:04:32 Microsoft Windows 8 Pro System drive C: has 102 GB (67%) free of 153 GB Total RAM: 3037 MB (25% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:05:09, on 31/10/2014 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v10.0 (10.00.9200.17116) Boot mode: Normal Running processes: C:\WINDOWS\system32\taskhostex.exe C:\WINDOWS\system32\taskhost.exe C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\WINDOWS\Explorer.EXE C:\Windows\System32\RuntimeBroker.exe C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe C:\Program Files\Samsung\Kies\KiesTrayAgent.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files\Samsung\Kies\Kies.exe C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files\CCleaner\CCleaner.exe C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE C:\WINDOWS\system32\wbem\unsecapp.exe C:\Windows\System32\WWAHost.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\WINDOWS\WinStore\WSHost.exe C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe C:\WINDOWS\system32\DllHost.exe C:\WINDOWS\system32\backgroundTaskHost.exe C:\WINDOWS\system32\backgroundTaskHost.exe C:\WINDOWS\system32\backgroundTaskHost.exe C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe\LiveComm.exe C:\WINDOWS\system32\wwahost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Users\Geo\Downloads\RSIT.exe C:\Program Files\trend micro\Geo.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll" (file missing) O4 - HKLM\..\Run: [Samsung Link] "C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe" O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" O4 - HKCU\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKCU\..\Run: [AppleIEDAV] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [AppleIEDAV] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Spotify Web Helper] "C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [AVG-Secure-Search-Update_JUNE2013_TB] "C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe" /PROMPT /CMPID=JUNE2013_TB (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [AVG-Secure-Search-Update_JUNE2013_TB] "C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe" /PROMPT /CMPID=JUNE2013_TB (User '?') O4 - HKUS\S-1-5-21-3928279562-192512764-2294349407-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce: [DPAPIKeyMig] %SystemRoot%\system32\dpapimig.exe -quiet (User '?') O4 - S-1-5-21-3928279562-192512764-2294349407-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (User '?') O4 - Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: AllShare Framework DMS - Samsung - C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) - Reimage® - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe O23 - Service: Samsung Link Service - Copyright 2013 SAMSUNG - C:\Program Files\Samsung\Samsung Link\Samsung Link.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- End of file - 10340 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\APSnotifierPP1.job - C:\Program Files\AnyProtectEx\AnyProtect.exe --notifier2 A C:\WINDOWS\tasks\APSnotifierPP2.job - C:\Program Files\AnyProtectEx\AnyProtect.exe --notifier 4 C:\WINDOWS\tasks\APSnotifierPP3.job - C:\Program Files\AnyProtectEx\AnyProtect.exe --notifier 6 C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-16 194128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] Bing Bar Helper - C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25 1253144] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-16 194128] {8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25 1253144] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Samsung Link"=C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [2014-03-13 569696] "KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2014-02-14 311616] "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056] ""= [] "SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"=C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [2014-08-07 43816] "ApplePhotoStreams"=C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [2014-08-14 43816] "AppleIEDAV"=C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [2014-08-04 1080104] "Spotify Web Helper"=C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-10-08 1514040] "KiesPreload"=C:\Program Files\Samsung\Kies\Kies.exe [2014-02-14 1564992] "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2013-08-27 248208] "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-09-26 4811032] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Users\Geo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup OneNote 2010 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon] SDWinLogon.dll [] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access" "C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service" "C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater" "C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe] "Debugger="tasklist.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "VIDC.YUY2"=msyuv.dll "vidc.i420"=iyuv_32.dll "vidc.cvid"=iccvid.dll "VIDC.YVYU"=msyuv.dll "VIDC.YVU9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "VIDC.UYVY"=msyuv.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "VIDC.IYUV"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "MSVideo8"=VfWWDM32.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-10-31 14:04:33 ----D---- C:\Program Files\trend micro 2014-10-31 14:04:32 ----D---- C:\rsit 2014-10-29 14:28:49 ----D---- C:\WINDOWS\system32\AutoUpdateLicense 2014-10-29 14:13:30 ----A---- C:\WINDOWS\system32\WSShared.dll 2014-10-29 14:13:30 ----A---- C:\WINDOWS\system32\AutoUpdate.exe 2014-10-29 14:13:28 ----A---- C:\WINDOWS\system32\WinSetupUI.dll 2014-10-29 14:13:28 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-29 14:13:28 ----A---- C:\WINDOWS\system32\NotificationUI.exe 2014-10-29 14:04:06 ----D---- C:\WINDOWS\AppReadiness 2014-10-23 17:05:19 ----D---- C:\ProgramData\Reimage Protector 2014-10-23 17:04:59 ----D---- C:\Program Files\Reimage 2014-10-23 17:04:55 ----D---- C:\rei 2014-10-23 17:01:45 ----A---- C:\WINDOWS\Reimage.ini 2014-10-23 15:49:52 ----SHD---- C:\Users\Geo\AppData\Roaming\AnyProtectEx 2014-10-23 15:49:52 ----D---- C:\Program Files\AnyProtectEx 2014-10-23 15:46:41 ----A---- C:\WINDOWS\system32\drivers\webinstrNew.sys 2014-10-23 15:46:34 ----D---- C:\ProgramData\Systweak 2014-10-23 15:46:03 ----D---- C:\Users\Geo\AppData\Roaming\Systweak 2014-10-23 15:36:46 ----D---- C:\Users\Geo\AppData\Roaming\QuickScan 2014-10-23 15:33:41 ----D---- C:\Program Files\Microsoft Silverlight 2014-10-23 15:31:20 ----A---- C:\WINDOWS\system32\sdnclean.exe 2014-10-23 15:31:08 ----D---- C:\Program Files\Spybot - Search & Destroy 2 2014-10-23 14:47:23 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT 2014-10-20 17:47:02 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe 2014-10-17 13:35:23 ----A---- C:\WINDOWS\system32\ntdll.dll 2014-10-17 13:35:22 ----A---- C:\WINDOWS\system32\localspl.dll 2014-10-17 13:35:21 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL 2014-10-17 13:35:20 ----A---- C:\WINDOWS\system32\wcmsvc.dll 2014-10-17 13:35:20 ----A---- C:\WINDOWS\system32\schannel.dll 2014-10-17 13:35:17 ----A---- C:\WINDOWS\system32\dwmapi.dll 2014-10-17 13:35:17 ----A---- C:\WINDOWS\system32\d3d10warp.dll 2014-10-17 13:35:16 ----A---- C:\WINDOWS\system32\winload.exe 2014-10-17 13:35:16 ----A---- C:\WINDOWS\system32\storagewmi.dll 2014-10-17 13:35:15 ----A---- C:\WINDOWS\system32\wcmcsp.dll 2014-10-17 13:35:15 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys 2014-10-17 13:35:14 ----A---- C:\WINDOWS\system32\profsvc.dll 2014-10-17 13:35:13 ----A---- C:\WINDOWS\system32\win32spl.dll 2014-10-17 13:35:13 ----A---- C:\WINDOWS\system32\defragsvc.dll 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDYAK.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDTAT.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDRUM.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDRU1.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDRU.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\KBDBASH.DLL 2014-10-17 13:35:12 ----A---- C:\WINDOWS\system32\Defrag.exe 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\user32.dll 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\srvsvc.dll 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\drivers\srv2.sys 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys 2014-10-17 13:34:51 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys 2014-10-17 13:34:50 ----A---- C:\WINDOWS\system32\msdtctm.dll 2014-10-17 13:34:49 ----A---- C:\WINDOWS\system32\sscore.dll 2014-10-17 13:34:37 ----A---- C:\WINDOWS\system32\win32k.sys 2014-10-17 13:34:36 ----A---- C:\WINDOWS\system32\packager.dll 2014-10-17 13:34:26 ----A---- C:\WINDOWS\system32\mstscax.dll 2014-10-17 13:34:25 ----A---- C:\WINDOWS\system32\termsrv.dll 2014-10-17 13:34:25 ----A---- C:\WINDOWS\system32\rdpcorets.dll 2014-10-17 13:34:24 ----A---- C:\WINDOWS\system32\winsta.dll 2014-10-17 13:34:24 ----A---- C:\WINDOWS\system32\mstsc.exe 2014-10-17 13:34:24 ----A---- C:\WINDOWS\system32\aaclient.dll 2014-10-17 13:34:17 ----A---- C:\WINDOWS\system32\generaltel.dll 2014-10-17 13:34:16 ----A---- C:\WINDOWS\system32\aepdu.dll 2014-10-17 13:34:15 ----A---- C:\WINDOWS\system32\aeinv.dll 2014-10-17 13:34:14 ----A---- C:\WINDOWS\system32\rastls.dll 2014-10-17 13:34:08 ----A---- C:\WINDOWS\system32\authui.dll 2014-10-17 13:34:08 ----A---- C:\WINDOWS\system32\actxprxy.dll 2014-10-17 13:34:05 ----A---- C:\WINDOWS\system32\twinui.dll 2014-10-17 13:34:04 ----A---- C:\WINDOWS\system32\msi.dll 2014-10-17 13:33:49 ----A---- C:\WINDOWS\system32\mshtml.dll 2014-10-17 13:33:45 ----A---- C:\WINDOWS\system32\ieframe.dll 2014-10-17 13:33:44 ----A---- C:\WINDOWS\system32\iertutil.dll 2014-10-17 13:33:43 ----A---- C:\WINDOWS\system32\wininet.dll 2014-10-17 13:33:42 ----A---- C:\WINDOWS\system32\urlmon.dll 2014-10-17 13:33:40 ----A---- C:\WINDOWS\system32\uxtheme.dll 2014-10-17 13:33:40 ----A---- C:\WINDOWS\system32\jscript9.dll 2014-10-17 13:33:39 ----A---- C:\WINDOWS\system32\msrating.dll 2014-10-17 13:33:39 ----A---- C:\WINDOWS\system32\msfeeds.dll 2014-10-17 13:33:39 ----A---- C:\WINDOWS\system32\iesysprep.dll 2014-10-17 13:33:39 ----A---- C:\WINDOWS\system32\iedkcs32.dll 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\mshtmled.dll 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\jscript.dll 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\iernonce.dll 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\ie4uinit.exe 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\dxtrans.dll 2014-10-17 13:33:38 ----A---- C:\WINDOWS\system32\dxtmsft.dll 2014-10-17 13:33:37 ----A---- C:\WINDOWS\system32\UXInit.dll 2014-10-17 13:33:36 ----A---- C:\WINDOWS\system32\jsproxy.dll 2014-10-17 13:33:36 ----A---- C:\WINDOWS\system32\iesetup.dll ======List of files/folders modified in the last 1 month====== 2014-10-31 14:04:58 ----D---- C:\WINDOWS\Prefetch 2014-10-31 14:04:33 ----RD---- C:\Program Files 2014-10-31 14:00:04 ----D---- C:\WINDOWS\system32\sru 2014-10-31 13:56:53 ----RD---- C:\WINDOWS\System32 2014-10-31 13:01:21 ----D---- C:\WINDOWS\Temp 2014-10-31 12:59:15 ----D---- C:\WINDOWS\WinSxS 2014-10-30 14:59:51 ----D---- C:\WINDOWS\system32\config 2014-10-30 14:40:43 ----D---- C:\WINDOWS\Microsoft.NET 2014-10-29 18:13:50 ----D---- C:\WINDOWS\debug 2014-10-29 15:33:19 ----D---- C:\WINDOWS\system32\NDF 2014-10-29 15:31:59 ----D---- C:\WINDOWS\inf 2014-10-29 15:31:59 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2014-10-29 15:29:30 ----D---- C:\Windows 2014-10-29 14:29:46 ----D---- C:\WINDOWS\CbsTemp 2014-10-29 14:28:49 ----D---- C:\WINDOWS\WinStore 2014-10-28 18:20:52 ----D---- C:\WINDOWS\system32\wdi 2014-10-28 18:18:47 ----D---- C:\WINDOWS\SoftwareDistribution 2014-10-28 12:36:48 ----SHD---- C:\WINDOWS\Installer 2014-10-28 12:36:47 ----HD---- C:\Config.Msi 2014-10-28 12:35:09 ----SHD---- C:\System Volume Information 2014-10-28 12:04:43 ----D---- C:\Program Files\Malwarebytes Anti-Malware 2014-10-28 12:04:24 ----D---- C:\WINDOWS\system32\Drivers 2014-10-28 11:45:24 ----D---- C:\WINDOWS\AUInstallAgent 2014-10-28 11:37:22 ----HD---- C:\Program Files\WindowsApps 2014-10-23 17:24:45 ----D---- C:\WINDOWS\Tasks 2014-10-23 17:06:11 ----D---- C:\WINDOWS\system32\Tasks 2014-10-23 17:05:19 ----HD---- C:\ProgramData 2014-10-23 16:53:56 ----D---- C:\WINDOWS\Globalization 2014-10-23 16:12:43 ----A---- C:\WINDOWS\wininit.ini 2014-10-23 15:45:03 ----D---- C:\ProgramData\Spybot - Search & Destroy 2014-10-23 15:34:11 ----SD---- C:\ProgramData\Microsoft 2014-10-21 11:01:26 ----D---- C:\WINDOWS\system32\catroot2 2014-10-20 18:12:10 ----D---- C:\WINDOWS\rescache 2014-10-20 18:01:26 ----RSD---- C:\WINDOWS\assembly 2014-10-20 17:41:24 ----D---- C:\WINDOWS\system32\drivers\nl-NL 2014-10-20 17:41:16 ----D---- C:\WINDOWS\system32\wbem 2014-10-20 17:41:16 ----D---- C:\WINDOWS\system32\nl-NL 2014-10-20 17:41:16 ----D---- C:\WINDOWS\system32\Boot 2014-10-20 17:41:14 ----RSD---- C:\WINDOWS\Fonts 2014-10-20 17:41:08 ----SD---- C:\WINDOWS\system32\CompatTel 2014-10-20 17:41:05 ----RD---- C:\WINDOWS\ToastData 2014-10-20 17:40:54 ----D---- C:\Program Files\Internet Explorer 2014-10-20 17:40:52 ----D---- C:\WINDOWS\system32\DriverStore 2014-10-20 17:40:42 ----D---- C:\WINDOWS\system32\MRT 2014-10-20 17:37:26 ----A---- C:\WINDOWS\system32\MRT.exe 2014-10-20 17:20:32 ----D---- C:\Users\Geo\AppData\Roaming\Spotify 2014-10-17 14:05:32 ----D---- C:\ProgramData\Microsoft Help 2014-10-10 17:51:47 ----D---- C:\Program Files\CCleaner ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 TVALZ;@oem1.inf,%TVALZ.SvcDesc%;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\WINDOWS\System32\drivers\TVALZ_O.SYS [2007-11-09 23640] R1 avgtp;avgtp; \??\C:\WINDOWS\system32\drivers\avgtpx86.sys [2014-06-24 42784] R1 MpKsl01b33c00;MpKsl01b33c00; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0DE09546-3343-4F0A-B3A8-7380D42D3DBB}\MpKsl01b33c00.sys [2014-10-30 39464] R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2012-07-26 52224] R2 webinstrNew;webinstrNew; \??\C:\WINDOWS\system32\Drivers\webinstrNew.sys [2014-10-23 51336] R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2012-07-25 10071552] R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2012-06-29 290304] R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2014-10-01 23256] R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2014-10-31 114904] R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2014-10-01 51928] R3 NETwNs32;@netwns32.inf,___ %NIC_Service_DispName_WIN7%;___ Stuurprogramma voor Intel(R) Wireless WiFi Link 5000 Series-adapter voor 32-bits Windows 7; C:\WINDOWS\system32\DRIVERS\NETwNs32.sys [2012-06-02 7518208] R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT-stuurprogramma; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2012-07-25 495104] R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Stuurprogramma voor seriële digitale fotocamera; C:\WINDOWS\system32\DRIVERS\serscan.sys [2012-10-11 9216] R3 tosrfec;@oem4.inf,%busenum.SVCDESC%;Bluetooth ACPI; C:\WINDOWS\System32\drivers\tosrfec.sys [2013-11-01 22424] R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-07-09 175872] R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2012-07-26 13824] S3 dg_ssudbus;@oem13.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 88576] S3 dot4;@oem5.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-10-19 137632] S3 Dot4Print;@oem6.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-10-19 22432] S3 dot4usb;@oem5.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-10-19 42912] S3 ssudmdm;@oem11.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192] S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Stuurprogramma voor USB-scanner; C:\WINDOWS\System32\drivers\usbscan.sys [2013-07-01 36864] S3 WinUsb;@oem10.inf,%WinUSB_SvcDesc%;SAMSUNG Android USB Driver; C:\WINDOWS\system32\DRIVERS\WinUsb.sys [2012-07-26 46592] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AllShare Framework DMS;AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [2013-12-21 401800] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504] R2 hpqddsvc;HP CUE DeviceDiscovery-service; C:\WINDOWS\system32\svchost.exe [2012-09-20 23040] R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2012-09-20 23040] R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-10-01 1871160] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-10-01 968504] R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2012-09-20 23040] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2012-09-20 23040] R2 ReimageRealTimeProtector;Reimage Real Time Protector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2014-07-28 5857128] R2 Samsung Link Service;Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [2014-03-13 577376] R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168] R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408] R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928] R2 TeamViewer8;TeamViewer 8; C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe [2013-10-01 5087584] R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2013-08-27 93072] R3 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.355.0\SeaPort.exe [2012-01-25 240408] R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2012-09-20 23040] R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S2 BBSvc;BingBar Service; C:\Program Files\Microsoft\BingBar\7.1.355.0\BBSvc.exe [2012-01-25 192792] S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-19 116648] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2012-07-06 43616] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-19 116648] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-12-19 194032] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] -----------------EOF-----------------