Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 07-01-2015 Ran by Gebruiker (administrator) on GEBRUIK-W9RJQI2 on 12-01-2015 14:02:28 Running from E:\wvh\Downloads\ZOEK.exe\Farbar recovery scan Loaded Profile: Gebruiker (Available profiles: Gebruiker) Platform: Microsoft Windows 8.1 Pro met Media Center (X86) OS Language: Nederlands (Nederland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Kingsoft Corporation) C:\Program Files\cmcm\Clean Master\cmcore.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe (Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe (Copyright 2013 SAMSUNG) C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (F-Secure Corporation) C:\Program Files\Internetbeveiliging\fshoster32.exe (Microsoft) C:\Program Files\Heimdal\HeimdalSecureDNS\DNSService.exe (CSIS Security Group) C:\Program Files\Heimdal\Service\HeimdalAgentService.exe (IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\integratedoffice.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\GEARS Client\GearsAgentService.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\GEARS Client\GearsHelper.exe (Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe () C:\Program Files\CyberLink\Shared files\RichVideo.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Seagate Technology LLC) C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe (Seagate Technology LLC) C:\Program Files\Seagate\Seagate Dashboard 2.0\MobileService.exe (ReviverSoft) C:\Program Files\ReviverSoft\Start Menu Reviver\StartMenuReviverService.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\OnDemand\WAOnDemand.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (ReviverSoft) C:\Program Files\ReviverSoft\Start Menu Reviver\StartMenuReviver.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\OnDemand\ondemands\wd\waodwd.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\OnDemand\ondemands\bs\wabpmsn.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\OnDemand\ondemands\bs\wabpoes.exe (Kingsoft Corporation) C:\Program Files\cmcm\Clean Master\cmtray.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (F-Secure Corporation) C:\Program Files\Internetbeveiliging\fshoster32.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Seagate Technology LLC) C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe (OPSWAT, Inc.) C:\Program Files\OPSWAT\GEARS Client\Gears.exe (Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe (Cloudfogger GmbH) C:\Program Files\Cloudfogger\Cloudfogger.exe (Google) C:\Program Files\Google\Drive\googledrivesync.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Cloudfogger GmbH) C:\Program Files\Cloudfogger\Cloudfogger.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe () C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe (CSIS Security Group) C:\Program Files\Heimdal\Client\HeimdalAgent.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google) C:\Program Files\Google\Drive\googledrivesync.exe () C:\Program Files\OPSWAT\OnDemand\ondemands\oesis\wa_3rd_party_host_32.exe (IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe (Seagate Technology LLC) C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Seagate Technology LLC) C:\Program Files\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files\KeePass Password Safe 2\KeePass.exe [2109952 2014-10-07] (Dominik Reichl) HKLM\...\Run: [Toolwiz TimeFreeze] => F:\Backup schijf\Backup heusden\Downloads\Timefreeze\ToolwizTimeFreezeGUI.exe [1677912 2013-04-28] (Toolwiz) HKLM\...\Run: [AllShare Play] => C:\Program Files\Samsung\AllShare Play\utils\AllShare Play Launcher.exe [407384 2013-02-21] (Samsung Electronics) HKLM\...\Run: [F-Secure Hoster (45123)] => C:\Program Files\Internetbeveiliging\fshoster32.exe [183864 2012-11-26] (F-Secure Corporation) HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-07-12] (Realtek Semiconductor) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [150208 2014-04-20] (IvoSoft) HKLM\...\Run: [DBAgent] => C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1518664 2014-09-17] (Seagate Technology LLC) HKLM\...\Run: [cmsc] => c:\program files\cmcm\Clean Master\cmtray.exe [468328 2015-01-03] (Kingsoft Corporation) HKLM\...\Run: [GEARS] => C:\Program Files\OPSWAT\GEARS Client\GEARS.exe [1755456 2014-12-31] (OPSWAT, Inc.) HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [4997872 2014-12-31] (Emsisoft GmbH) Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [SkyDrive] => C:\Users\Gebruiker\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-10-09] (Microsoft Corporation) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [Toolwiz TimeFreeze] => C:\Program Files\Toolwiz TimeFreeze\TimeFreeze.exe [1545496 2013-01-08] (Toolwiz) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [HP Photosmart 6520 series (NET)] => C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [Cloudfogger] => C:\Program Files\Cloudfogger\Cloudfogger.exe [7173456 2013-02-25] (Cloudfogger GmbH) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [Uploader] => C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127080 2014-09-17] (Seagate Technology LLC) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [GoogleChromeAutoLaunch_5FEA36A39174F28C3634662B2D565CAA] => C:\Program Files\Google\Chrome\Application\chrome.exe [854344 2014-10-22] (Google Inc.) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [468192 2014-10-15] (Sony) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {24ea8251-74bd-11e4-b0c9-001e68a1d46c} - "H:\Startme.exe" HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {4d2c9e38-202b-11e2-af9d-001e68a1d46c} - "H:\LaunchU3.exe" -a HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {781f199f-244e-11e2-af9f-001e68a1d46c} - "H:\LaunchU3.exe" -a HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {918466ab-205c-11e2-af9e-001e68a1d46c} - "H:\LaunchU3.exe" -a HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {af2f1cc5-3b63-11e4-b073-001e68a1d46c} - "H:\Startme.exe" HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\MountPoints2: {e7477767-299f-11e2-af9f-001e68a1d46c} - "I:\LaunchU3.exe" -a Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Heimdal.lnk ShortcutTarget: Heimdal.lnk -> C:\Program Files\Heimdal\Client\HeimdalAgent.exe (CSIS Security Group) Startup: C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Gebruiker\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Inktwaarschuwingen controleren - HP Photosmart 6520 series (netwerk).lnk ShortcutTarget: Inktwaarschuwingen controleren - HP Photosmart 6520 series (netwerk).lnk -> C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) Startup: C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk ShortcutTarget: Verzenden naar OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation) ShellIconOverlayIdentifiers: [ 0Cloudfogger] -> {15EDBCBF-7231-4290-946E-5BB12C6AF342} => C:\Program Files\Cloudfogger\CfShellEx_1.4.2143.dll (Cloudfogger GmbH) ShellIconOverlayIdentifiers: [ 1Cloudfogger] -> {14A3EC74-D852-416A-9691-AC3096EE1953} => C:\Program Files\Cloudfogger\CfShellEx_1.4.2143.dll (Cloudfogger GmbH) ShellIconOverlayIdentifiers: [ 2Cloudfogger] -> {E9C2814C-12B8-4D74-9551-16DDEBFC8AE4} => C:\Program Files\Cloudfogger\CfShellEx_1.4.2143.dll (Cloudfogger GmbH) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-235396244-3051213757-2033591465-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49967;https=127.0.0.1:49967 HKU\S-1-5-21-235396244-3051213757-2033591465-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://nl.search.yahoo.com/?type=523482&fr=spigot-yhp-ie HKU\S-1-5-21-235396244-3051213757-2033591465-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKU\S-1-5-21-235396244-3051213757-2033591465-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKU\S-1-5-21-235396244-3051213757-2033591465-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://mail.google.com/mail/ca/u/0/#inbox https://dub114.mail.live.com/default.aspx?fid=fltrash StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-235396244-3051213757-2033591465-1000 -> DefaultScope {B16E565E-E617-439F-8089-C40001897012} URL = https://nl.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=523482&p={searchTerms} SearchScopes: HKU\S-1-5-21-235396244-3051213757-2033591465-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-235396244-3051213757-2033591465-1000 -> {B16E565E-E617-439F-8089-C40001897012} URL = https://nl.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=523482&p={searchTerms} BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit) BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation) BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 212.54.40.25 212.54.44.54 FireFox: ======== FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.15.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: samsung.com/AllSharePlayPCPlugin -> C:\Program Files\Samsung\AllShare Play\utils\npAllSharePlayPCPlugin.dll (Samsung) Chrome: ======= CHR HomePage: Default -> https://nl.search.yahoo.com/?type=523482&fr=yo-yhp-ch CHR StartupUrls: Default -> "https://duckduckgo.com/", "https://mail.google.com/mail/ca/u/0/#inbox", "https://dub114.mail.live.com/default.aspx?fid=fltrash" CHR DefaultSearchKeyword: Default -> duckduckgo.com CHR DefaultSearchURL: Default -> https://duckduckgo.com/?q={searchTerms} CHR DefaultSuggestURL: Default -> https://ac.duckduckgo.com/ac/?q={searchTerms}&type=list CHR Profile: C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (CookiesOK) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\afmkbjoakcacgljcdccofbffloabfbni [2015-01-06] CHR Extension: (Google Documenten) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-08] CHR Extension: (Google Drive) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-27] CHR Extension: (TV) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2014-07-08] CHR Extension: (WOT) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-01-06] CHR Extension: (YouTube) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-08] CHR Extension: (Google Cast) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2015-01-06] CHR Extension: (TVGiDS.tv) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocdjdnpjmkaaaangagmlnkcpfjkjfcn [2014-07-08] CHR Extension: (TV) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-07-08] CHR Extension: (Adblock Plus) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-06] CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2014-10-12] CHR Extension: (Symbaloo Bookmarker 0.4.2) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnjfgbikbkcmickdalamlmpmkhmbollm [2015-01-06] CHR Extension: (Save my Tabs) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\djadfifncobffjpicnkiegahdiobpaap [2015-01-06] CHR Extension: (MightyText - SMS Text Messaging ⟷ Computer) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkfhfaphfkopdgpbfkebjfcblcafcmpi [2014-07-08] CHR Extension: (Google+) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2014-07-08] CHR Extension: (Torrent Turbo Search App) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegbffmjdkflkcfncpfjjbggbdlnbdif [2014-07-08] CHR Extension: (Black Menu for Google™) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke [2015-01-06] CHR Extension: (Gmail Offline) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-07-08] CHR Extension: (Google Agenda) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-07-08] CHR Extension: (Box - 10GB of FREE storage) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnkaeblpdcamcioiiabclakabcbjmbl [2014-07-08] CHR Extension: (Metascan Online for Chrome) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjampemfhdfmangifafmianhokmpjbcj [2015-01-07] CHR Extension: (Mail Checker Plus for Google Mail™) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gffjhibehnempbkeheiccaincokdjbfe [2014-07-08] CHR Extension: (Vanilla Cookie Manager) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gieohaicffldbmiilohhggbidhephnjj [2015-01-06] CHR Extension: (AdBlock) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-06] CHR Extension: (Hola Beter Internet) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-01-08] CHR Extension: (Avast Online Security) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-25] CHR Extension: (LastPass: Free Password Manager) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-01-06] CHR Extension: (NOS Video) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggmbjghgeahcopdibklblgfkfendefg [2014-07-08] CHR Extension: (Dropbox) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-07-08] CHR Extension: (CouchPotato) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\jochingjncojldfclaicaomboafaiong [2015-01-06] CHR Extension: (Woordenboeken.nu) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\klmficblehaigahmmlhoomjbiigebnpk [2014-07-08] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-01-06] CHR Extension: (Google Maps) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-07-08] CHR Extension: (Google Mail Checker) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-07-08] CHR Extension: (Ghostery) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-01-06] CHR Extension: (OneDrive) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2014-07-08] CHR Extension: (Google Wallet) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-21] CHR Extension: (SABconnect++) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\okphadhbbjadcifjplhifajfacbkkbod [2015-01-06] CHR Extension: (Picasa) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-07-08] CHR Extension: (Gmail) - C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-08] CHR HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\GEBRUI~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-05-27] CHR HKU\S-1-5-21-235396244-3051213757-2033591465-1000\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4920104 2014-12-31] (Emsisoft GmbH) R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe [406648 2012-10-23] (Samsung) R2 AllShare Play Service; C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe [631368 2013-02-21] (Copyright 2013 SAMSUNG) R2 cmcore; c:\program files\cmcm\Clean Master\cmcore.exe [315240 2015-01-03] (Kingsoft Corporation) S3 FoxitCloudUpdateService; C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242912 2014-09-11] (Foxit Software Inc.) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-10-08] (Freemake) [File not signed] R2 fshoster; C:\Program Files\Internetbeveiliging\fshoster32.exe [183864 2012-11-26] (F-Secure Corporation) R2 HeimdalSecureDNS; C:\Program Files\Heimdal\HeimdalSecureDNS\DnsService.exe [93344 2014-12-11] (Microsoft) R2 HeimdalService; C:\Program Files\Heimdal\Service\HeimdalAgentService.exe [133280 2014-12-11] (CSIS Security Group) R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [696320 2011-08-18] (Hewlett-Packard Co.) [File not signed] S3 iumsvc; C:\Program Files\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2631456 2014-12-18] (IObit) R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX86\integratedoffice.exe [1281112 2012-11-23] (Microsoft Corporation) R2 OPSWATGEARSClient; C:\Program Files\OPSWAT\GEARS Client\GearsAgentService.exe [792384 2014-12-31] (OPSWAT, Inc.) R2 OPSWATGEARSHelper; C:\Program Files\OPSWAT\GEARS Client\GearsHelper.exe [179008 2014-12-31] (OPSWAT, Inc.) R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 RapportMgmtService; C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-12-15] (IBM Corp.) R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [601072 2014-05-15] (Paramount Software UK Ltd) R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [247152 2010-08-19] () R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation) R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 Seagate Dashboard Services; C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-09-17] (Seagate Technology LLC) R2 Seagate MobileBackup Service; C:\Program Files\Seagate\Seagate Dashboard 2.0\MobileService.exe [157776 2014-09-17] (Seagate Technology LLC) S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software) R2 StartMenuReviverService; C:\Program Files\ReviverSoft\Start Menu Reviver\StartMenuReviverService.exe [598648 2014-09-17] (ReviverSoft) R2 WAOnDemand; C:\Program Files\OPSWAT\OnDemand\WAOnDemand.exe [1669952 2014-12-30] (OPSWAT, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [288128 2014-09-22] (Microsoft Corporation) S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22192 2014-09-22] (Microsoft Corporation) S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1222144 2014-07-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [58200 2014-05-12] (Emsisoft GmbH) R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH) R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH) R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [18552 2014-05-12] (Emsisoft GmbH) R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-02-22] (Microsoft Corporation) R1 BTOWSFF; C:\WINDOWS\system32\Drivers\BTOWSFF.sys [26432 2013-01-08] (Toolwiz.com) R0 BTOWSVF; C:\WINDOWS\System32\Drivers\BTOWSVF.sys [49856 2013-01-08] (Toolwiz.com) R1 CBFilterFS; C:\WINDOWS\system32\drivers\cbfltfs.sys [115928 2013-01-07] (EldoS Corporation) R1 cbfs3; C:\WINDOWS\system32\drivers\cbfs3.sys [299528 2012-12-04] (EldoS Corporation) R3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-12-04] (Emsisoft GmbH) S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [137632 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [22432 2012-10-19] (Windows (R) Win 7 DDK provider) R3 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [243128 2014-12-14] (Disc Soft Ltd) R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [26328 2014-09-13] (Sony Mobile Communications) S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation) R3 ksapi; C:\WINDOWS\system32\drivers\ksapi.sys [81768 2015-01-03] (Kingsoft Corporation) R3 NETwNs32; C:\WINDOWS\system32\DRIVERS\NETwNs32.sys [7518208 2013-06-18] (Intel Corporation) S3 PSMounterEx; C:\WINDOWS\system32\drivers\psmounterex.sys [65144 2013-08-01] (Paramount Software UK Ltd) S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [15688 2013-09-30] () S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [10320 2013-09-30] () R1 RapportCerberus_80083; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_80083.sys [430296 2014-12-08] () R1 RapportEI; C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [251288 2014-12-15] (IBM Corp.) R0 RapportKELL; C:\WINDOWS\System32\Drivers\RapportKELL.sys [208888 2014-12-15] (IBM Corp.) R1 RapportPG; C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [332728 2014-12-15] (IBM Corp.) R1 RegHiveRecovery; C:\WINDOWS\system32\drivers\RegHiveRecovery.sys [41136 2014-02-20] (Microsoft Corporation) S3 ssudobex; C:\WINDOWS\system32\DRIVERS\ssudobex.sys [184192 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 USB28xxBGA; C:\WINDOWS\system32\DRIVERS\emBDA.sys [608128 2011-03-10] (eMPIA Technology, Inc.) S3 USB28xxOEM; C:\WINDOWS\system32\DRIVERS\emOEM.sys [1038080 2011-03-10] (eMPIA Technology, Inc.) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84800 2014-09-22] (Microsoft Corporation) S3 WIMMount; C:\Program Files\Windows Kits\8.1\Assessment and Deployment Kit\Deployment Tools\x86\DISM\wimmount.sys [36464 2013-08-21] (Microsoft Corporation) S3 winbondcir; C:\WINDOWS\system32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation) R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-03-13] (Microsoft Corporation) S3 WUDFSensorLP; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation) S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation) S1 iSafeKrnlMon; No ImagePath ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)