ComboFix 15-10-09.01 - Pj_Dc 14/10/2015 17:46:54.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.8100.5358 [GMT 2:00] Gestart vanuit: c:\users\Pj_Dc\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289} SP: ESET NOD32 Antivirus 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\1350122211.bdinstall.bin c:\programdata\1353344163.bdinstall.bin D:\install.exe . . (((((((((((((((((((( Bestanden Gemaakt van 2015-09-14 to 2015-10-14 )))))))))))))))))))))))))))))) . . 2015-10-11 17:42 . 2015-09-18 19:19 503808 ----a-w- c:\windows\system32\devinv.dll 2015-10-11 17:42 . 2015-09-18 19:19 1291264 ----a-w- c:\windows\system32\appraiser.dll 2015-10-11 17:42 . 2015-09-18 19:22 25432 ----a-w- c:\windows\system32\CompatTelRunner.exe 2015-10-11 17:42 . 2015-09-18 19:19 700416 ----a-w- c:\windows\system32\invagent.dll 2015-10-11 17:42 . 2015-09-18 19:19 766464 ----a-w- c:\windows\system32\generaltel.dll 2015-10-11 17:42 . 2015-09-18 19:19 73216 ----a-w- c:\windows\system32\acmigration.dll 2015-10-11 17:42 . 2015-09-18 19:09 1163776 ----a-w- c:\windows\system32\aeinv.dll 2015-10-04 11:52 . 2015-10-04 11:52 -------- d-----w- c:\program files (x86)\ESET 2015-10-02 14:41 . 2015-10-02 14:41 -------- d-----w- c:\users\Pj_Dc\AppData\Local\Blizzard 2015-10-01 18:23 . 2015-10-01 18:26 -------- d-----w- C:\AdwCleaner 2015-09-30 13:38 . 2015-10-14 15:39 -------- d-----w- c:\programdata\clear.fi 2015-09-30 13:26 . 2015-10-14 16:01 -------- d-----w- c:\users\Pj_Dc\AppData\Local\Temp 2015-09-30 12:52 . 2015-10-01 14:23 -------- d-----w- C:\zoek_backup 2015-09-27 11:28 . 2015-09-27 11:28 1715040 ----a-w- c:\programdata\Microsoft\WDExpress\14.0\1033\ResourceCache.dll 2015-09-27 11:24 . 2015-09-27 11:24 -------- d-----w- c:\program files\Application Verifier 2015-09-27 11:24 . 2015-09-27 11:24 -------- d-----w- c:\program files (x86)\Application Verifier 2015-09-27 11:24 . 2015-09-27 11:24 -------- d-----w- c:\programdata\Windows App Certification Kit 2015-09-27 11:20 . 2015-09-27 11:20 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 12.0 2015-09-27 11:18 . 2015-09-27 11:18 -------- d-----w- c:\programdata\NuGet 2015-09-27 11:03 . 2015-09-27 11:18 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 14.0 2015-09-27 10:56 . 2015-10-05 06:56 -------- d-----w- c:\programdata\VsTelemetry 2015-09-27 08:08 . 2015-09-27 08:08 -------- d-----w- c:\program files\trend micro 2015-09-27 08:08 . 2015-09-27 08:09 -------- d-----w- C:\rsit 2015-09-26 14:20 . 2015-09-26 14:20 -------- d-----w- c:\users\Pj_Dc\AppData\Roaming\NVIDIA 2015-09-23 16:58 . 2015-09-13 21:50 574072 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2015-09-23 16:58 . 2015-09-13 22:09 937776 ----a-w- c:\windows\system32\nvvsvc.exe 2015-09-23 16:58 . 2015-09-13 22:09 62584 ----a-w- c:\windows\system32\nvshext.dll 2015-09-23 16:58 . 2015-09-13 22:09 385144 ----a-w- c:\windows\system32\nvmctray.dll 2015-09-23 16:58 . 2015-09-13 22:09 2558584 ----a-w- c:\windows\system32\nvsvcr.dll 2015-09-23 16:58 . 2015-09-13 22:09 6884984 ----a-w- c:\windows\system32\nvcpl.dll 2015-09-23 16:58 . 2015-09-13 22:09 3496056 ----a-w- c:\windows\system32\nvsvc64.dll 2015-09-23 16:58 . 2015-09-11 12:17 5231082 ----a-w- c:\windows\system32\nvcoproc.bin 2015-09-23 16:57 . 2015-09-14 00:29 112760 ----a-w- c:\windows\system32\OpenCL.dll 2015-09-23 16:57 . 2015-09-14 00:29 105080 ----a-w- c:\windows\SysWow64\OpenCL.dll 2015-09-17 15:02 . 2015-09-17 15:02 -------- d-----w- C:\$Windows.~BT 2015-09-17 14:43 . 2015-09-17 14:43 -------- d-----w- c:\program files (x86)\Common Files\Skype . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-10-14 16:00 . 2014-09-26 15:10 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-09-22 15:01 . 2012-07-18 09:16 780488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-09-22 15:01 . 2011-08-30 05:36 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-09-03 18:09 . 2015-09-03 18:09 1731840 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2015-09-03 17:12 . 2015-09-03 17:12 201424 ----a-w- c:\windows\system32\drivers\rzudd.sys 2015-09-02 03:04 . 2015-09-09 12:30 41984 ----a-w- c:\windows\system32\lpk.dll 2015-09-02 03:04 . 2015-09-09 12:30 100864 ----a-w- c:\windows\system32\fontsub.dll 2015-09-02 03:04 . 2015-09-09 12:30 14336 ----a-w- c:\windows\system32\dciman32.dll 2015-09-02 03:04 . 2015-09-09 12:30 46080 ----a-w- c:\windows\system32\atmlib.dll 2015-09-02 02:48 . 2015-09-09 12:30 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2015-09-02 02:48 . 2015-09-09 12:30 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2015-09-02 02:48 . 2015-09-09 12:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2015-09-02 02:47 . 2015-09-09 12:30 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2015-09-02 01:51 . 2015-09-09 12:30 3209216 ----a-w- c:\windows\system32\win32k.sys 2015-09-02 01:47 . 2015-09-09 12:30 372736 ----a-w- c:\windows\system32\atmfd.dll 2015-09-02 01:33 . 2015-09-09 12:30 299520 ----a-w- c:\windows\SysWow64\atmfd.dll 2015-08-27 18:18 . 2015-09-09 12:30 2004480 ----a-w- c:\windows\system32\msxml6.dll 2015-08-27 18:18 . 2015-09-09 12:30 1887232 ----a-w- c:\windows\system32\msxml3.dll 2015-08-27 18:13 . 2015-09-09 12:30 2048 ----a-w- c:\windows\system32\msxml6r.dll 2015-08-27 18:13 . 2015-09-09 12:30 2048 ----a-w- c:\windows\system32\msxml3r.dll 2015-08-27 17:58 . 2015-09-09 12:30 1391104 ----a-w- c:\windows\SysWow64\msxml6.dll 2015-08-27 17:58 . 2015-09-09 12:30 1241088 ----a-w- c:\windows\SysWow64\msxml3.dll 2015-08-27 17:51 . 2015-09-09 12:30 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll 2015-08-27 17:51 . 2015-09-09 12:30 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2015-08-27 00:37 . 2014-06-24 18:49 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll 2015-08-27 00:37 . 2013-11-25 09:20 1423120 ----a-w- c:\windows\SysWow64\nvspcap.dll 2015-08-27 00:36 . 2014-06-24 18:49 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll 2015-08-27 00:36 . 2013-11-25 09:20 1710568 ----a-w- c:\windows\system32\nvspcap64.dll 2015-08-26 18:07 . 2015-09-09 12:29 98304 ----a-w- c:\windows\system32\wudriver.dll 2015-08-26 18:07 . 2015-09-09 12:29 37888 ----a-w- c:\windows\system32\wups2.dll 2015-08-26 18:07 . 2015-09-09 12:29 36864 ----a-w- c:\windows\system32\wups.dll 2015-08-26 18:07 . 2015-09-09 12:29 3165696 ----a-w- c:\windows\system32\wucltux.dll 2015-08-26 18:07 . 2015-09-09 12:29 2606080 ----a-w- c:\windows\system32\wuaueng.dll 2015-08-26 18:07 . 2015-09-09 12:29 192000 ----a-w- c:\windows\system32\wuwebv.dll 2015-08-26 18:07 . 2015-09-09 12:29 696320 ----a-w- c:\windows\system32\wuapi.dll 2015-08-26 18:06 . 2015-09-09 12:29 91136 ----a-w- c:\windows\system32\WinSetupUI.dll 2015-08-26 18:06 . 2015-09-09 12:29 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2015-08-26 18:06 . 2015-09-09 12:29 37376 ----a-w- c:\windows\system32\wuapp.exe 2015-08-26 18:06 . 2015-09-09 12:29 139776 ----a-w- c:\windows\system32\wuauclt.exe 2015-08-26 17:56 . 2015-09-09 12:29 93184 ----a-w- c:\windows\SysWow64\wudriver.dll 2015-08-26 17:56 . 2015-09-09 12:29 30208 ----a-w- c:\windows\SysWow64\wups.dll 2015-08-26 17:56 . 2015-09-09 12:29 173056 ----a-w- c:\windows\SysWow64\wuwebv.dll 2015-08-26 17:56 . 2015-09-09 12:29 566784 ----a-w- c:\windows\SysWow64\wuapi.dll 2015-08-26 17:55 . 2015-09-09 12:29 34816 ----a-w- c:\windows\SysWow64\wuapp.exe 2015-08-26 16:37 . 2012-07-14 19:37 134753440 ----a-w- c:\windows\system32\MRT.exe 2015-08-18 01:42 . 2015-09-09 12:30 393304 ----a-w- c:\windows\system32\iedkcs32.dll 2015-08-15 06:48 . 2015-09-09 12:30 25190400 ----a-w- c:\windows\system32\mshtml.dll 2015-08-15 06:34 . 2015-09-09 12:30 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2015-08-15 06:33 . 2015-09-09 12:30 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2015-08-15 06:18 . 2015-09-09 12:30 66560 ----a-w- c:\windows\system32\iesetup.dll 2015-08-15 06:18 . 2015-09-09 12:30 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2015-08-15 06:17 . 2015-09-09 12:30 417792 ----a-w- c:\windows\system32\html.iec 2015-08-15 06:17 . 2015-09-09 12:30 585216 ----a-w- c:\windows\system32\vbscript.dll 2015-08-15 06:17 . 2015-09-09 12:30 2886144 ----a-w- c:\windows\system32\iertutil.dll 2015-08-15 06:17 . 2015-09-09 12:30 88064 ----a-w- c:\windows\system32\MshtmlDac.dll 2015-08-15 06:10 . 2015-09-09 12:30 54784 ----a-w- c:\windows\system32\jsproxy.dll 2015-08-15 06:09 . 2015-09-09 12:30 34304 ----a-w- c:\windows\system32\iernonce.dll 2015-08-15 06:06 . 2015-09-09 12:30 615936 ----a-w- c:\windows\system32\ieui.dll 2015-08-15 06:04 . 2015-09-09 12:30 114688 ----a-w- c:\windows\system32\ieetwcollector.exe 2015-08-15 06:04 . 2015-09-09 12:30 144384 ----a-w- c:\windows\system32\ieUnatt.exe 2015-08-15 06:04 . 2015-09-09 12:30 817664 ----a-w- c:\windows\system32\jscript.dll 2015-08-15 06:04 . 2015-09-09 12:30 814080 ----a-w- c:\windows\system32\jscript9diag.dll 2015-08-15 06:00 . 2015-09-09 12:30 5923328 ----a-w- c:\windows\system32\jscript9.dll 2015-08-15 05:57 . 2015-09-09 12:30 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2015-08-15 05:53 . 2015-09-09 12:30 490496 ----a-w- c:\windows\system32\dxtmsft.dll 2015-08-15 05:53 . 2015-09-09 12:30 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2015-08-15 05:46 . 2015-09-09 12:30 77824 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2015-08-15 05:42 . 2015-09-09 12:30 199680 ----a-w- c:\windows\system32\msrating.dll 2015-08-15 05:41 . 2015-09-09 12:30 92160 ----a-w- c:\windows\system32\mshtmled.dll 2015-08-15 05:40 . 2015-09-09 12:30 504832 ----a-w- c:\windows\SysWow64\vbscript.dll 2015-08-15 05:40 . 2015-09-09 12:30 62464 ----a-w- c:\windows\SysWow64\iesetup.dll 2015-08-15 05:39 . 2015-09-09 12:30 47616 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2015-08-15 05:39 . 2015-09-09 12:30 341504 ----a-w- c:\windows\SysWow64\html.iec 2015-08-15 05:39 . 2015-09-09 12:30 316928 ----a-w- c:\windows\system32\dxtrans.dll 2015-08-15 05:38 . 2015-09-09 12:30 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2015-08-15 05:29 . 2015-09-09 12:30 115712 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2015-08-15 05:29 . 2015-09-09 12:30 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2015-08-15 05:24 . 2015-09-09 12:30 720384 ----a-w- c:\windows\system32\ie4uinit.exe 2015-08-15 05:23 . 2015-09-09 12:30 801280 ----a-w- c:\windows\system32\msfeeds.dll 2015-08-15 05:22 . 2015-09-09 12:30 1359360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2015-08-15 05:22 . 2015-09-09 12:30 2126336 ----a-w- c:\windows\system32\inetcpl.cpl 2015-08-15 05:16 . 2015-09-09 12:30 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2015-08-15 05:16 . 2015-09-09 12:30 14451712 ----a-w- c:\windows\system32\ieframe.dll 2015-08-15 05:10 . 2015-09-09 12:30 4520448 ----a-w- c:\windows\SysWow64\jscript9.dll 2015-08-15 05:07 . 2015-09-09 12:30 2427392 ----a-w- c:\windows\system32\wininet.dll 2015-08-15 05:01 . 2015-09-09 12:30 2052608 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2015-08-15 05:01 . 2015-09-09 12:30 1155072 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2015-08-15 04:55 . 2015-09-09 12:30 1545728 ----a-w- c:\windows\system32\urlmon.dll 2015-08-15 04:43 . 2015-09-09 12:30 800768 ----a-w- c:\windows\system32\ieapfltr.dll 2015-08-15 04:43 . 2015-09-09 12:30 1951232 ----a-w- c:\windows\SysWow64\wininet.dll 2015-08-13 15:19 . 2015-08-13 15:19 50904 ----a-w- c:\windows\system32\drivers\rzp1endpt.sys 2015-08-13 15:19 . 2015-08-13 15:19 42712 ----a-w- c:\windows\system32\drivers\rzvmouse.sys 2015-08-11 11:08 . 2015-08-11 11:08 90112 ----a-w- c:\windows\SysWow64\rzdevinfo.dll 2015-08-11 11:08 . 2015-08-11 11:08 155648 ----a-w- c:\windows\SysWow64\rztouchdll.dll 2015-08-11 11:08 . 2015-08-11 11:08 117248 ----a-w- c:\windows\SysWow64\rzdisplaydll.dll 2015-08-11 11:08 . 2015-08-11 11:08 1197568 ----a-w- c:\windows\SysWow64\rzdevicedll.dll 2015-08-11 11:08 . 2015-08-11 11:08 421888 ----a-w- c:\windows\SysWow64\rzaudiodll.dll 2015-08-11 04:52 . 2015-08-23 20:06 69416 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2015-08-11 04:52 . 2015-08-23 20:06 50472 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2015-08-11 04:52 . 2013-09-14 09:31 72504 ----a-w- c:\windows\system32\nvaudcap64v.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2015-04-06 17:18 223432 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2015-04-06 17:18 223432 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2015-04-06 17:18 223432 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 2015-07-14 11:03 1729752 ----a-w- c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 2015-07-14 11:03 1729752 ----a-w- c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 2015-07-14 11:03 1729752 ----a-w- c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GoogleChromeAutoLaunch_837A1F6DACFC786CA650E488878C5696"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2015-09-24 815944] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-06-21 341360] "ArcadeMovieService"="c:\program files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe" [2011-08-31 185640] "Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2015-08-31 593216] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "IsMyWinLockerReboot"="msiexec.exe" [2015-06-15 73216] . c:\users\Pj_Dc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2015-8-13 36710768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "midi5"=KORGUM64.DRV . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] R2 CLKMSVC10_34E30CCC;CyberLink Product - 2012/02/24 19:16;c:\program files (x86)\Acer\clear.fi\Movie\NavFilter\kmsvc.exe;c:\program files (x86)\Acer\clear.fi\Movie\NavFilter\kmsvc.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\wcmvcam64.sys;c:\windows\SYSNATIVE\DRIVERS\wcmvcam64.sys [x] R3 ArcService;Arc Service;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe;c:\program files (x86)\Perfect World Entertainment\Arc\ArcService.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x] R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\Drivers\KORGUM64.SYS;c:\windows\SYSNATIVE\Drivers\KORGUM64.SYS [x] R3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys;c:\windows\SYSNATIVE\DRIVERS\lv302a64.sys [x] R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x] R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x] R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys;c:\program files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x] R3 xhunter1;xhunter1;c:\windows\xhunter1.sys;c:\windows\xhunter1.sys [x] S0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys;c:\windows\SYSNATIVE\drivers\ahcix64s.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 AGSService;Adobe Genuine Software Integrity Service;c:\program files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe;c:\program files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x] S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x] S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x] S2 Razer Game Scanner Service;Razer Game Scanner;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe;c:\program files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [x] S2 RzKLService;RzKLService;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe [x] S2 rzpmgrk;rzpmgrk;c:\windows\system32\drivers\rzpmgrk.sys;c:\windows\SYSNATIVE\drivers\rzpmgrk.sys [x] S2 rzpnk;rzpnk;c:\windows\system32\drivers\rzpnk.sys;c:\windows\SYSNATIVE\drivers\rzpnk.sys [x] S2 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 e2eVAWdm;e2eSoft VAudio;c:\windows\system32\DRIVERS\VAud_WDM.sys;c:\windows\SYSNATIVE\DRIVERS\VAud_WDM.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys;c:\windows\SYSNATIVE\drivers\LVUSBS64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 rzp1endpt;Razer platform 1 end point;c:\windows\system32\DRIVERS\rzp1endpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzp1endpt.sys [x] S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x] S3 rzvmouse;Razer Virtual Mouse;c:\windows\system32\DRIVERS\rzvmouse.sys;c:\windows\SYSNATIVE\DRIVERS\rzvmouse.sys [x] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - WS2IFSL *Deregistered* - CLKMDRV10_34E30CCC . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-09-30 13:42 997704 ----a-w- c:\program files (x86)\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe . Inhoud van de 'Gedeelde Taken' map . 2015-10-13 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-4253350116-951323700-1799462684-1000UA1d0c1763291c48f.job - c:\users\Pj_Dc\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-19 07:18] . 2015-10-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4253350116-951323700-1799462684-1000UA.job - c:\users\Pj_Dc\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-25 15:08] . 2015-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0f21f684f3a4f.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-07 07:36] . 2015-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cf8e4e1cec15b4.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-07 07:36] . 2015-10-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4253350116-951323700-1799462684-1000Core1cf4d94b586617c.job - c:\users\Pj_Dc\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-09 10:05] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2014-01-31 15:45 643952 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2014-01-31 15:45 643952 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2014-01-31 15:45 643952 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2015-04-06 17:18 262344 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2015-04-06 17:18 262344 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2015-04-06 17:18 262344 ----a-w- c:\users\Pj_Dc\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)] @="{8BA85C75-763B-4103-94EB-9470F12FE0F7}" [HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}] 2015-07-14 10:59 2335960 ----a-w- d:\plus20~1\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)] @="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" [HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}] 2015-07-14 10:59 2335960 ----a-w- d:\plus20~1\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)] @="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" [HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}] 2015-07-14 10:59 2335960 ----a-w- d:\plus20~1\Office15\GROOVEEX.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2015-10-01 23:08 232712 ----a-w- c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WheelMouse"="c:\program files\Mouse\Amoumain.exe" [2000-01-01 196608] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2000-01-01 13662936] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2015-01-28 5595848] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-08-27 2634872] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-08-27 1710568] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-08-05 508240] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Drivers32] "midi5"=KORGUM64.DRV . ------- Bijkomende Scan ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - d:\plus20~1\Office15\EXCEL.EXE/3000 IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: Se&nd to OneNote - d:\plus20~1\Office15\ONBttnIE.dll/105 TCP: DhcpNameServer = 195.130.130.2 195.130.131.2 Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-Nvtmru - c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe AddRemove-BattlEye for A2 - d:\steamlibrary\steamapps\common\Arma 2BattlEye\UnInstallBE.exe AddRemove-Free YouTube to MP3 Converter_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe AddRemove-GamersFirst LIVE! - c:\program files (x86)\GamersFirst\LIVE!\uninstall.exe AddRemove-Minecraft1.7.9 - c:\users\Pj_Dc\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe AddRemove-Native Instruments Controller Editor - c:\programdata\{51B0C2F8-BB02-4FF9-83E6-6BBD135AD344}\Controller Editor Setup PC.exe AddRemove-Native Instruments Service Center - c:\programdata\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}\Service Center Setup PC.exe AddRemove-Native Instruments Traktor 2 - c:\programdata\{C79644E3-0443-4647-AF82-C8A62EB1B82A}\Traktor 2 Setup PC.exe AddRemove-Sleeping Dogs_is1 - c:\games\Sleeping Dogs\unins000.exe AddRemove-The Sims 4 Deluxe Edition_is1 - d:\games\The Sims 4 Deluxe Edition\Uninstall\unins000.exe AddRemove-{0886900B-B2F3-452C-B580-60F1253F7F80} - c:\programdata\{51B0C2F8-BB02-4FF9-83E6-6BBD135AD344}\Controller Editor Setup PC.exe AddRemove-{0B8565BA-BAD5-4732-B122-5FD78EFC50A9} - c:\programdata\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}\Service Center Setup PC.exe AddRemove-{29da3a37-6a61-4767-bb98-86d0515cd0b1} - c:\programdata\Package Cache\{29da3a37-6a61-4767-bb98-86d0515cd0b1}\VS11-KB3002339.exe AddRemove-{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - c:\programdata\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe AddRemove-{56ef8912-352f-4fab-9c73-6f1c92a7127f} - c:\programdata\Package Cache\{56ef8912-352f-4fab-9c73-6f1c92a7127f}\patch_KB2781514.exe AddRemove-{74d0e5db-b326-4dae-a6b2-445b9de1836e} - c:\programdata\Package Cache\{74d0e5db-b326-4dae-a6b2-445b9de1836e}\VC_redist.x86.exe AddRemove-{7f51bdb9-ee21-49ee-94d6-90afc321780e} - c:\programdata\Package Cache\{7f51bdb9-ee21-49ee-94d6-90afc321780e}\vcredist_x64.exe AddRemove-{A8EC0CC0-AD8D-4244-B080-424EDF7A7634} - c:\programdata\{C79644E3-0443-4647-AF82-C8A62EB1B82A}\Traktor 2 Setup PC.exe AddRemove-{C1C6816E-CBB3-A748-85F9-A8B47B68985B} - c:\programdata\continuetosave\uninstall.exe AddRemove-{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} - c:\programdata\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe AddRemove-{ce085a78-074e-4823-8dc1-8a721b94b76d} - c:\programdata\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe AddRemove-{cf9e81f7-4c03-403e-92b1-93d18aa8c3a4} - c:\programdata\Package Cache\{cf9e81f7-4c03-403e-92b1-93d18aa8c3a4}\wdexpress_full.exe AddRemove-{e0efdce9-a486-4676-8aa5-65bb08cbf34c} - c:\programdata\Package Cache\{e0efdce9-a486-4676-8aa5-65bb08cbf34c}\wdexpress_full.exe AddRemove-{e46eca4f-393b-40df-9f49-076faf788d83} - c:\programdata\Package Cache\{e46eca4f-393b-40df-9f49-076faf788d83}\VC_redist.x64.exe AddRemove-{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4} - c:\programdata\Package Cache\{e7a0c8b6-b0e9-41e2-8a0a-a6784f88d1d4}\sdksetup.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-4253350116-951323700-1799462684-1000\Software\SecuROM\License information*] @Allowed: (Read) (RestrictedCode) "datasecu"=hex:84,fe,a9,60,77,78,0e,dd,c6,d3,23,80,67,f3,20,c1,7e,af,a5,0c,02, fa,a9,66,18,62,7d,09,a2,c7,3f,3c,64,39,e2,f4,37,cf,0e,a2,62,ae,35,07,72,6f,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_185_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_185_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.19" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Andere Aktieve Processen ------------------------ . c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Advantage 9.10\Server\ADS.EXE c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe c:\program files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe c:\program files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe c:\program files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe c:\users\Pj_Dc\AppData\Roaming\Dropbox\bin\Dropbox.exe c:\program files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLMSService.exe c:\programdata\Razer\Synapse\RzStats\RzStats.Manager.exe c:\program files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe c:\users\Pj_Dc\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe . ************************************************************************** . Voltooingstijd: 2015-10-14 18:07:33 - machine werd herstart ComboFix-quarantined-files.txt 2015-10-14 16:07 . Pre-Run: 431.051.517.952 bytes beschikbaar Post-Run: 430.601.162.752 bytes beschikbaar . - - End Of File - - BA1E08E962B09DF5C1216802B20BF2DC