
guntheru
Lid-
Items
19 -
Registratiedatum
-
Laatst bezocht
Inhoudstype
Profielen
Forums
Store
Alles dat geplaatst werd door guntheru
-
Trage laptop en reclame zoveel ik wil
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Bestandje bijgevoegd dat na heropstart is verschenen. Bedankt alvast! zoek-results.txt -
Trage laptop en reclame zoveel ik wil
guntheru plaatste een topic in Archief Bestrijding malware & virussen
Hallo, heb een probleem op de laptop, hij werkt traag en er verschijnt voortdurend reclame. Kan iemand me helpen? heb alvast het rsit-logje alvast bedankt! log.txt -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Alles lijk in orde terug! Super bedankt! -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Oke is gebeurd -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
hier is het malwarebytes.txt -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Hier is het. Pc is al merkelijk beter nu:-) AdwCleaner[S0].txt -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Snap niet wat ik misdoe, maar er gebeurt terug niet veel hoor. <br><br>Zoek.exe v5.0.0.0 Updated 14-September-2014<br>Tool run by cedric on ma 15/09/2014 at 20:45:03,91.<br>Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64<br>Running in: Normal Mode Internet Access Detected<br>Launched: C:\Users\cedric\Downloads\zoek.exe [scan all users] [script inserted] <br><br>===== Runcheck 20:47:04,43 =====<br><br>--- Create Environment Variables 20:47:09,53 <br>--- Checking Input 20:47:41,05 <br>--- Emptyclsid 20:49:35,90 <br>--- Del by CLSID 20:49:50,10 <br><br> Dit is na 2 uur -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Dat duurt al bijna drie uur nu. Is dat normaal? groeten -
Pc vol reclame en onderstreepte woorden
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Hier is het Zoek.exe v5.0.0.0 Updated 14-September-2014 Tool run by cedric on ma 15/09/2014 at 12:45:02,35. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\cedric\Downloads\zoek.exe [scan all users] [script inserted] ===== Runcheck 12:46:10,10 ===== --- Create Environment Variables 12:46:14,25 --- Create System Restore Point 12:46:36,14 --- Checking Input 12:47:18,29 --- AU AppData Check 12:47:37,74 --- Remove From Windows Installer 12:47:50,88 --- IE Startpage Check 12:53:40,58 --- Program Files DB Check 12:55:45,40 --- C:\Users\cedric\AppData\Roaming DB Check 12:57:24,76 --- C:\Users\Default\AppData\Roaming DB Check 12:57:24,76 --- C:\Users\Default User\AppData\Roaming DB Check 12:57:24,76 --- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 12:57:24,76 --- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 12:57:24,76 --- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 12:57:24,76 --- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 12:57:24,76 --- C:\Users\cedric DB Check 13:01:46,68 --- C:\PROGRA~3 DB Check 13:02:26,02 --- C:\Users\Administrator\AppData\Local DB Check 13:02:30,23 --- C:\Users\cedric\AppData\Local DB Check 13:02:30,23 --- C:\Users\Default\AppData\Local DB Check 13:02:30,23 --- C:\Users\Default User\AppData\Local DB Check 13:02:30,23 --- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 13:02:30,23 --- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 13:02:30,23 --- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 13:02:30,23 --- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 13:02:30,23 --- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 13:05:54,81 --- C:\Users\cedric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 13:06:13,69 --- Tasks DB Check 13:06:24,79 --- Downloads DB Check 13:06:32,51 --- C:\Users\cedric\AppData\LocalLow DB Check 13:06:42,71 --- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 13:06:42,71 --- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 13:06:42,71 --- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 13:06:42,71 --- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 13:06:42,71 --- Tasks2 DB Check 13:08:40,36 --- Documents DB Check 13:09:32,53 --- C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709 DB Check 13:09:45,39 --- C:\Users\Public\Desktop DB Check 13:09:50,95 --- C:\Users\cedric\Desktop DB Check 13:09:58,20 --- Services DB Check 13:10:16,25 --- FF prefs.js DB Check 13:11:31,15 --- Emptyclsid 13:12:54,63 --- Del by CLSID 13:13:07,37 -
Pc vol reclame en onderstreepte woorden
guntheru plaatste een topic in Archief Bestrijding malware & virussen
Kan iemand me even helpen? Heb alvast een rsit gemaakt alvast bedankt! - - - Updated - - - Hier is het log bestand info.txt log.txt -
Laptop traag en irritant veel pop ups
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
oke, alles gelukt! super bedankt, kan ik terug stressvrij op de laptop -
Laptop traag en irritant veel pop ups
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Alles lijkt opgelost denk ik bedankt voor de hulp! -
Laptop traag en irritant veel pop ups
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
# AdwCleaner v3.022 - Report created 14/03/2014 at 06:26:53 # Updated 13/03/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : cedric - GUNTHERAGNETHA # Running from : C:\Users\cedric\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\cedric\AppData\LocalLow\ShopperReports3 File Deleted : C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\Classes\Applications\lollipop.exe Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClickPotatoLiteSA_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClickPotatoLiteSA_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\DefaultTab Key Deleted : HKCU\Software\lollipop Key Deleted : HKCU\Software\ParetoLogic Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\systweak Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3 Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DefaultTab Key Deleted : HKLM\Software\SearchProtect Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\Software\Uniblue ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16518 Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [start Page] -\\ Mozilla Firefox v27.0.1 (nl) [ File : C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\prefs.js ] -\\ Google Chrome v33.0.1750.146 [ File : C:\Users\cedric\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [3957 octets] - [14/03/2014 06:25:02] AdwCleaner[s0].txt - [3541 octets] - [14/03/2014 06:26:53] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [3601 octets] ########## -
Laptop traag en irritant veel pop ups
guntheru reageerde op guntheru's topic in Archief Bestrijding malware & virussen
Zoek.exe v5.0.0.0 Updated 07-March-2014 Tool run by cedric on do 13/03/2014 at 17:37:33,55. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\cedric\Downloads\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== System Restore Info ====================== 13/03/2014 17:43:03 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Lavasoft deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\SimilarSites deleted successfully C:\PROGRA~2\WinZip Registry Optimizer deleted successfully C:\Program Files\log deleted successfully C:\Program Files\office.tmp deleted successfully C:\PROGRA~3\boost_interprocess deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\cedric\AppData\Roaming\BitTorrent deleted successfully C:\Users\cedric\AppData\Roaming\Nico Mak Computing deleted successfully C:\Users\cedric\AppData\Roaming\SimilarSites deleted successfully C:\Users\cedric\AppData\Roaming\Sony Corporation deleted successfully C:\Users\cedric\AppData\Roaming\TP deleted successfully C:\Users\cedric\AppData\Local\cache deleted successfully C:\Users\cedric\AppData\Local\genienext deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1022104969-3133531358-4227153473-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-1022104969-3133531358-4227153473-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6A6E4B66-F3E2-4B55-8BC5-4A9D176AC983} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709 ---- Lines conduit removed from prefs.js ---- user_pref("browser.newtab.url", "http://search.conduit.com/?ctid=CT3320133&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SPDCB5A9EC- user_pref("browser.search.defaultenginename", "Conduit Search"); user_pref("browser.search.selectedEngine", "Conduit Search"); user_pref("browser.startup.homepage", "http://search.conduit.com/?ctid=CT3320133&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPDCB5A9EC-ED88-4 ---- FireFox user.js and prefs.js backups ---- user_20141303_1813_.backup prefs_20141303_1813_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon] ==== Deleting Files \ Folders ====================== C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\8ef36653-7dcd-4c5f-81f5-7870fda4b7b7...394107f67c.com not found C:\Program Files (x86)\SimilarSites not found C:\Users\cedric\AppData\Roaming\SimilarSites not found C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\sitefinder@sitefinder.com deleted C:\Windows\syswow64\appdata deleted C:\Users\cedric\daemonprocess.txt deleted C:\Users\cedric\.android deleted C:\PROGRA~2\GreenTree Applications deleted C:\Users\cedric\AppData\Roaming\Systweak deleted C:\PROGRA~3\ParetoLogic deleted C:\PROGRA~3\ProductData deleted C:\PROGRA~3\YTD Video Downloader deleted C:\Users\cedric\AppData\Local\APN deleted C:\Users\cedric\AppData\Local\SearchProtect deleted C:\Users\cedric\AppData\Local\Mobogenie deleted C:\Users\cedric\AppData\Local\SwvUpdater deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader deleted C:\Users\cedric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\cedric\Downloads\SoftonicDownloader_voor_advanced-systemcare.exe deleted C:\Users\cedric\AppData\LocalLow\ADSRemoval deleted C:\Users\cedric\AppData\LocalLow\boost_interprocess deleted C:\windows\SysNative\tasks\DTReg deleted C:\Windows\Syswow64\FAP13B3.tmp deleted C:\Windows\Syswow64\FAP268A.tmp deleted C:\Windows\Syswow64\FAP3C3D.tmp deleted C:\Windows\Syswow64\FAP53D5.tmp deleted C:\Windows\Syswow64\FAPD0C2.tmp deleted C:\Windows\Syswow64\FAPD3FF.tmp deleted C:\Windows\Syswow64\FAPDF86.tmp deleted C:\Windows\Syswow64\FAPE072.tmp deleted C:\Windows\Syswow64\FAPFFAC.tmp deleted C:\Windows\Syswow64\SearchProtect deleted C:\Users\cedric\Documents\Optimizer Pro deleted C:\Users\cedric\Documents\Mobogenie deleted C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\searchplugins\conduit-search.xml deleted C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\Invalidprefs.js deleted C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\8ef36653-7dcd-4c5f-81f5-7870fda4b7b7@67e486b0-922d-4a2d-9e3f-77394107f67c.com deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-02-23 23:33:12 4E189CEBB9122D0DE29B99D68F7E0019 1442 ----a-w- C:\Windows\chgt-c.ini ====== C:\Users\cedric\AppData\Local\Temp ==== 2014-03-08 10:59:10 C76B8E74F900E083712ADC5B597A05C3 339264 ----a-w- C:\Users\cedric\AppData\Local\Temp\3180\taskmgr.dll 2014-03-08 10:59:10 5C74AD321FDD45D4562F6F67D9A75C84 1145120 ----a-w- C:\Users\cedric\AppData\Local\Temp\3180\ProjectOnUninstall.exe 2014-03-08 10:48:52 2F28FCA1AECCCA9C06A5043B0702FBBE 1753920 ----a-w- C:\Users\cedric\AppData\Local\Temp\ASCDownloader\IMF_ActionCenterDownloader.exe 2014-03-08 10:47:54 C76B8E74F900E083712ADC5B597A05C3 339264 ----a-w- C:\Users\cedric\AppData\Local\Temp\4635\taskmgr.dll 2014-03-08 10:47:54 5C74AD321FDD45D4562F6F67D9A75C84 1145120 ----a-w- C:\Users\cedric\AppData\Local\Temp\4635\ProjectOnUninstall.exe 2014-03-07 10:51:46 67A4F993EBC17246AD2C00052AD0FE11 18926080 ----a-w- C:\Users\cedric\AppData\Local\Temp\BeidMW64.msi 2014-03-07 10:51:45 64E50696521D7FC6CE0EC230D1EA6601 17185280 ----a-w- C:\Users\cedric\AppData\Local\Temp\BeidMW.msi 2014-03-07 10:27:19 0B88C2FFEA162EDB43DFDB3619513723 272664 ----a-w- C:\Users\cedric\AppData\Local\Temp\Step2.exe 2014-03-07 10:22:47 DE2594D67FE8B09756FC62024CFD7C79 12136960 ----a-w- C:\Users\cedric\AppData\Local\Temp\Step1.msi ====== Java Cache ===== 2014-03-10 08:50:43 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-2f8dde56 2014-03-10 08:50:29 B3D163E07CBABE802563E61E8291ED55 99 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-6.0.lap 2014-03-10 08:50:29 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-6f035100 2014-03-10 08:50:27 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-4d45b09f 2014-03-10 08:52:03 4FF89A65EF2C1BAA8666DE0614D0A627 469 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\4de63de6-107df52a 2014-03-10 08:52:01 58FAC43F18D460DEBCF6BEC9B57FAF20 137 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\3fe5812a-6.0.lap 2014-03-10 08:50:30 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-158444e7 2014-03-10 08:52:02 1B5ED17F7C2215073A3A12910D54A34C 35335 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\497e8c48-1b21ef79 ====== C:\Windows\SysWOW64 ===== 2014-03-10 08:46:49 95E15A2DE75AB48728AB8E1911C3EDB1 264616 ----a-w- C:\Windows\SysWOW64\javaws.exe 2014-03-10 08:46:20 CB3638541DCAC86EE17FA8258202E20E 175016 ----a-w- C:\Windows\SysWOW64\javaw.exe 2014-03-10 08:46:20 A7871E39687EC6EE9712209DAE248B3A 96168 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-03-10 08:46:20 9395BBE294045909A025C9F3DC3D9025 174504 ----a-w- C:\Windows\SysWOW64\java.exe 2014-03-07 13:42:08 8999F18D38D55E34D356796507FFD639 192000 ----a-w- C:\Windows\SysWOW64\rdpendp_winip.dll 2014-03-07 13:42:07 E6446AB7A7E602CAFF51ACA3C68C1526 269312 ----a-w- C:\Windows\SysWOW64\aaclient.dll 2014-03-07 13:42:07 40FF6C636380A87DE3A99F4E348BFDCB 1048064 ----a-w- C:\Windows\SysWOW64\mstsc.exe 2014-03-07 13:42:06 EF1689081813A60D4610FF429530BA36 4916224 ----a-w- C:\Windows\SysWOW64\mstscax.dll 2014-03-07 13:42:06 A9D4140B8B843D5719F7C3EED8C0F9FD 37376 ----a-w- C:\Windows\SysWOW64\tsgqec.dll 2014-03-07 13:42:04 D3F64318307CEC05CBDE533D99976532 16896 ----a-w- C:\Windows\SysWOW64\wksprtPS.dll 2014-03-07 13:42:03 3F853160DEE5B71B9AD2F1BAF2B1E55B 46592 ----a-w- C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-03-07 13:37:13 33B26FA5DBEB69FFAB703EDCB4E6DE4A 514560 ----a-w- C:\Windows\SysWOW64\qdvd.dll 2014-03-06 21:04:59 99DE7F0838685CE9F4C39E58FEE6F48B 790272 ----a-w- C:\Windows\SysWOW64\MaxxAudioAPOShell.dll 2014-03-06 21:00:27 626E882211093EA7C632FC3A6C91578D 147456 ----a-w- C:\Windows\SysWOW64\iglhcp32.dll 2014-03-06 21:00:27 053CDD6CC8D53D96030A66ADCF2CAFFA 208896 ----a-w- C:\Windows\SysWOW64\iglhsip32.dll 2014-03-06 21:00:24 93C9F5E09337213A4A3DE7E13A724D2E 228864 ----a-w- C:\Windows\SysWOW64\igfxdv32.dll 2014-03-06 21:00:24 0263DD370C8CC5B66B76C1B6A426F121 23552 ----a-w- C:\Windows\SysWOW64\igfxexps32.dll 2014-03-06 21:00:22 FC766773A207255FF0E48CC5EF7203CC 4338688 ----a-w- C:\Windows\SysWOW64\igd10umd32.dll 2014-03-06 21:00:22 6485368ADC59D2FAC03D8C29B4104FC8 571904 ----a-w- C:\Windows\SysWOW64\igdumdx32.dll 2014-03-06 21:00:22 21DF57EE5AEDA5CB7CB4D43FCD97251E 4896768 ----a-w- C:\Windows\SysWOW64\igdumd32.dll 2014-03-06 21:00:20 BFAC249F12855ECA75F48F52764A6811 11405824 ----a-w- C:\Windows\SysWOW64\ig4icd32.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-03-07 13:42:09 E9A0777DCA9148157E0EF9B71D7DE353 15360 ----a-w- C:\Windows\Sysnative\RdpGroupPolicyExtension.dll 2014-03-07 13:42:09 AD4D0AEDB5993EDA31EB80A54EDBC344 243200 ----a-w- C:\Windows\Sysnative\rdpudd.dll 2014-03-07 13:42:09 8F69EE5E0EB0779DC3E90DFD8D8E8683 3174912 ----a-w- C:\Windows\Sysnative\rdpcorets.dll 2014-03-07 13:42:08 D346E07D62E3D4BEAB040939744EC31B 228864 ----a-w- C:\Windows\Sysnative\rdpendp_winip.dll 2014-03-07 13:42:08 AE8535663AA64318D174CD7CA44ED947 62976 ----a-w- C:\Windows\Sysnative\TSWbPrxy.exe 2014-03-07 13:42:07 F059D17612BF074443C01FCCC8D5C905 54272 ----a-w- C:\Windows\Sysnative\MsRdpWebAccess.dll 2014-03-07 13:42:07 98C04A60A10777D99B569636C55FE91C 1123840 ----a-w- C:\Windows\Sysnative\mstsc.exe 2014-03-07 13:42:06 7B619C36F84720CB6AB77031B6F4FA60 13312 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyExtension.dll 2014-03-07 13:42:06 0E894692EB8579703FB1EC8AB6908571 13312 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyControl.exe 2014-03-07 13:42:05 9EB297848DAACF111C36B6048EFF5AEA 43520 ----a-w- C:\Windows\Sysnative\TsUsbGDCoInstaller.dll 2014-03-07 13:42:05 87E8244DCB33A7A0836C66389B8874B6 322560 ----a-w- C:\Windows\Sysnative\aaclient.dll 2014-03-07 13:42:05 6846ECABF7034DD97EE1DE38F1DA16B4 384000 ----a-w- C:\Windows\Sysnative\wksprt.exe 2014-03-07 13:42:04 FF16B21E5C0C46A70B2CD4F65B87D9F1 5773824 ----a-w- C:\Windows\Sysnative\mstscax.dll 2014-03-07 13:42:04 E98E2152251EB2576714B2CCE01555DC 44032 ----a-w- C:\Windows\Sysnative\tsgqec.dll 2014-03-07 13:42:03 09112DADA82F4700F833C2E40DFB59FC 18432 ----a-w- C:\Windows\Sysnative\wksprtPS.dll 2014-03-07 13:37:13 973131EB99BE1E19DAC502CB724E72A5 366592 ----a-w- C:\Windows\Sysnative\qdvd.dll 2014-03-07 13:35:21 DAD88CD4525202FE432A3F2876B11480 27456 ----a-w- C:\Windows\Sysnative\RegistryDefragBootTime.exe 2014-03-06 21:09:02 0D2106264D437A031DD64A9DA514357F 73800 ----a-w- C:\Windows\Sysnative\RtNicProp64.dll 2014-03-06 21:06:02 771536F10F1A419622787FB5D27A8E6B 871856 ----a-w- C:\Windows\Sysnative\tossaeapo64.dll 2014-03-06 21:06:02 3D30D3B2776C1A24F6498F569466E8D7 162224 ----a-w- C:\Windows\Sysnative\toseaeapo64.dll 2014-03-06 21:06:02 0C089E47D8BD3996742F0939DE7E2D48 2103040 ----a-w- C:\Windows\Sysnative\WavesGUILib64.dll 2014-03-06 21:06:01 C082B23A77E89D5AA0329777FF34A0DE 65944 ----a-w- C:\Windows\Sysnative\tepeqapo64.dll 2014-03-06 21:06:01 A58E46E776CFAD5DCBC8C2D9A920E7B4 582056 ----a-w- C:\Windows\Sysnative\tosasfapo64.dll 2014-03-06 21:06:01 7380AE45CFA24369A7305520897142B8 1361336 ----a-w- C:\Windows\Sysnative\tosade.dll 2014-03-06 21:06:00 95F25E2D41AACCB8956F8E3C6740E377 148416 ----a-w- C:\Windows\Sysnative\tadefxapo.dll 2014-03-06 21:06:00 1A3586235C5DEF0C05F2F0C711E94376 836544 ----a-w- C:\Windows\Sysnative\tadefxapo264.dll 2014-03-06 21:05:58 928A1E0360023226799F08F07108C07B 244480 ----a-w- C:\Windows\Sysnative\slprp64.dll 2014-03-06 21:05:58 0F94B0EB0F9691C56E2C2F392F5BD53B 723200 ----a-w- C:\Windows\Sysnative\sltech64.dll 2014-03-06 21:05:56 35C6A24D95DC70A73D2DABD04FA7EB2D 1044224 ----a-w- C:\Windows\Sysnative\slcnt64.dll 2014-03-06 21:05:55 B4D7A07098508A3BCC3C57612F890F98 947760 ----a-w- C:\Windows\Sysnative\SFSS_APO.dll 2014-03-06 21:05:55 5AE160D9D229409D975D71AA1D38F5D9 898816 ----a-w- C:\Windows\Sysnative\sl3apo64.dll 2014-03-06 21:05:54 7B3E9344FB43D799C6462227A0E65877 221024 ----a-w- C:\Windows\Sysnative\SFNHK64.dll 2014-03-06 21:05:54 2C25AF115BDDC05D9A84D26227A08E63 81248 ----a-w- C:\Windows\Sysnative\SFCOM64.dll 2014-03-06 21:05:54 17ABCAD44A75C635583A238ED6333357 78688 ----a-w- C:\Windows\Sysnative\SFAPO64.dll 2014-03-06 21:05:52 F0D94C5786977B4C44A914683DEBAA9A 1958616 ----a-w- C:\Windows\Sysnative\RTSnMg64.cpl 2014-03-06 21:05:51 0E2C5B7C842024F50B1795A980C4D0FF 2810072 ----a-w- C:\Windows\Sysnative\RtPgEx64.dll 2014-03-06 21:05:48 CA1D7D09854D305A64B100DC1400BA21 331880 ----a-w- C:\Windows\Sysnative\RtlCPAPI64.dll 2014-03-06 21:05:43 8814A281406553A2640D6A04702C63BD 14952 ----a-w- C:\Windows\Sysnative\RtkCoLDR64.dll 2014-03-06 21:05:43 0805289E121F3E3C458C970B08314EB2 149608 ----a-w- C:\Windows\Sysnative\RtkCfg64.dll 2014-03-06 21:05:40 C08DE9FE49B8DE126EE7A42C7C80450E 1021656 ----a-w- C:\Windows\Sysnative\RtkApi64.dll 2014-03-06 21:05:40 6DB093B854351CD7F36A4E8EA7082E7A 2782936 ----a-w- C:\Windows\Sysnative\RtkAPO64.dll 2014-03-06 21:05:39 ECAEC5FBBBEF8612AF0A866AFA5F7EF2 101208 ----a-w- C:\Windows\Sysnative\RTEEL64A.dll 2014-03-06 21:05:39 D0D0D82B7366E691275E433CD34F89B2 375128 ----a-w- C:\Windows\Sysnative\RTEEP64A.dll 2014-03-06 21:05:39 6F4CD493196100EEF349D7132CECAFD9 78680 ----a-w- C:\Windows\Sysnative\RTEEG64A.dll 2014-03-06 21:05:38 A6286A6C7A1BBFCBA17AA54384A21D1C 204120 ----a-w- C:\Windows\Sysnative\RTEED64A.dll 2014-03-06 21:05:38 2A7224C314131592497D02A57D867218 618200 ----a-w- C:\Windows\Sysnative\RtDataProc64.dll 2014-03-06 21:05:36 22CAB76AF907B82664FEDE6A653ABA2A 1286872 ----a-w- C:\Windows\Sysnative\RTCOM64.dll 2014-03-06 21:05:35 E9D4A333DF15D06C68AC4BFB9B6581CB 310104 ----a-w- C:\Windows\Sysnative\RP3DAA64.dll 2014-03-06 21:05:35 B6FE01558CC03F3866C9AD0ED19261D8 310104 ----a-w- C:\Windows\Sysnative\RP3DHT64.dll 2014-03-06 21:05:33 6FE243C4544916588BE5DEC48F541714 154840 ----a-w- C:\Windows\Sysnative\RCoInstII64.dll 2014-03-06 21:05:33 038364E2CA0621AD0436DC72C46EF8C0 43720192 ----a-w- C:\Windows\Sysnative\RCoRes64.dat 2014-03-06 21:05:26 D0EB28022A91A5C084E8A7DEBB08D8D2 141584 ----a-w- C:\Windows\Sysnative\R4EEL64A.dll 2014-03-06 21:05:26 8882AD10853E45402CABD3BAF48A7EFC 124176 ----a-w- C:\Windows\Sysnative\R4EEA64A.dll 2014-03-06 21:05:26 0B5EF50E26CFD1E7BF01E32E053532B2 434960 ----a-w- C:\Windows\Sysnative\R4EED64A.dll 2014-03-06 21:05:26 03625A179B27362D3A90E3331AEBE95E 7164176 ----a-w- C:\Windows\Sysnative\R4EEP64A.dll 2014-03-06 21:05:26 01096663377134C41D618AF0E53A953E 75024 ----a-w- C:\Windows\Sysnative\R4EEG64A.dll 2014-03-06 21:05:24 32D0421AE8550172EEFC6301685FED1C 912184 ----a-w- C:\Windows\Sysnative\NAHIMICAPOSettingsIPC.dll 2014-03-06 21:05:22 B6DBCBB878A3BE0B48E8F5045CB9CA9D 906800 ----a-w- C:\Windows\Sysnative\MISS_APO.dll 2014-03-06 21:05:22 34775CBB1FAA0693C61994082B4C55D9 5753112 ----a-w- C:\Windows\Sysnative\NAHIMICAPOlfx.dll 2014-03-06 21:05:18 587A8CF457604D84266FF858CEB60223 662784 ----a-w- C:\Windows\Sysnative\MaxxVolumeSDAPO.dll 2014-03-06 21:05:17 8C3D0711219078FB6601C39387EB7B30 1286400 ----a-w- C:\Windows\Sysnative\MaxxSpeechAPO64.dll 2014-03-06 21:05:17 32E91908A319CF4FDDE18C6F5699E0E0 907008 ----a-w- C:\Windows\Sysnative\MaxxVoiceAPO2064.dll 2014-03-06 21:05:16 0B8F799CDEFF2A5C4ADFA86CC22323FA 3899648 ----a-w- C:\Windows\Sysnative\MaxxAudioVnN64.dll 2014-03-06 21:05:09 1B89185D5D7AB3A10B4309E16C62CC30 27644160 ----a-w- C:\Windows\Sysnative\MaxxAudioVnA64.dll 2014-03-06 21:05:06 61D45CFD4C0694D318D8160857CF4DDA 14153984 ----a-w- C:\Windows\Sysnative\MaxxAudioRealtek64.dll 2014-03-06 21:05:04 DD8A18C147ACD7799D84FD4A4E1C4064 1922304 ----a-w- C:\Windows\Sysnative\MaxxAudioRealtek264.dll 2014-03-06 21:05:02 1A6C91215105B6B6C48B0F531E1CD8FA 2036992 ----a-w- C:\Windows\Sysnative\MaxxAudioEQ64.dll 2014-03-06 21:05:00 D956C3D6ECE65A10A1018A72E08C4973 1013504 ----a-w- C:\Windows\Sysnative\MaxxAudioAPOShell64.dll 2014-03-06 21:04:58 E15522E4A9CF2F48395F5548167E8895 1345280 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO5064.dll 2014-03-06 21:04:58 315AEF22E309E724AD0575C75E7EF5F3 1084160 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO4064.dll 2014-03-06 21:04:58 06080807E61471A18AD99F3E6FF3C9B5 663296 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO30.dll 2014-03-06 21:04:57 75616F8DB5C092A8A50AFEC273859DD7 318808 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO20.dll 2014-03-06 21:04:56 6F7D1601DA55BBE5C7A79E01E236D7B9 603984 ----a-w- C:\Windows\Sysnative\KAAPORT64.dll 2014-03-06 21:04:47 922CDA544EB5C5A57795B38ED5871B69 2743328 ----a-w- C:\Windows\Sysnative\FMAPO64.dll 2014-03-06 21:04:46 DE32448E6B40141C80DAABFF6FBE1744 693352 ----a-w- C:\Windows\Sysnative\DTSVoiceClarityDLL64.dll 2014-03-06 21:04:46 A9B98F96FBE514ADEABD20B2BD132172 415680 ----a-w- C:\Windows\Sysnative\DTSU2PREC64.dll 2014-03-06 21:04:45 8AE860D92752CFA136979B1FF797FFDC 501184 ----a-w- C:\Windows\Sysnative\DTSU2PLFX64.dll 2014-03-06 21:04:45 37B8A8089ECED77F6CEAF74917C5D12B 487360 ----a-w- C:\Windows\Sysnative\DTSU2PGFX64.dll 2014-03-06 21:04:44 F132C08BD8C58579B400DFAA71F34CFB 1756264 ----a-w- C:\Windows\Sysnative\DTSS2SpeakerDLL64.dll 2014-03-06 21:04:44 9948969B2C1987B1D64789EFEB284A84 712296 ----a-w- C:\Windows\Sysnative\DTSSymmetryDLL64.dll 2014-03-06 21:04:43 F7C357462077156DC211AC2112FC8C53 1568360 ----a-w- C:\Windows\Sysnative\DTSS2HeadphoneDLL64.dll 2014-03-06 21:04:43 2EF5442E8E7ED20F7634EEFB09640C8F 491112 ----a-w- C:\Windows\Sysnative\DTSNeoPCDLL64.dll 2014-03-06 21:04:42 BC0474E5476E5EA0D0E1AA5AC41E2061 242792 ----a-w- C:\Windows\Sysnative\DTSGFXAPO64.dll 2014-03-06 21:04:42 B3977C8BA77559F4F8752AE8EB724C87 242792 ----a-w- C:\Windows\Sysnative\DTSLFXAPO64.dll 2014-03-06 21:04:42 3B8FB5376F5431C0101747D5138BCB9B 241768 ----a-w- C:\Windows\Sysnative\DTSGFXAPONS64.dll 2014-03-06 21:04:42 192A03A21636D3775CEE4C049C3BEB2A 432744 ----a-w- C:\Windows\Sysnative\DTSLimiterDLL64.dll 2014-03-06 21:04:41 FF31A2F57AAAB58DB78FCC961A58B206 428648 ----a-w- C:\Windows\Sysnative\DTSGainCompensatorDLL64.dll 2014-03-06 21:04:40 21B38D4D86A87909491F690883AE6D1E 1486952 ----a-w- C:\Windows\Sysnative\DTSBoostDLL64.dll 2014-03-06 21:04:39 8B5A737AD11EF45D9B1AEB4ED6884968 728680 ----a-w- C:\Windows\Sysnative\DTSBassEnhancementDLL64.dll 2014-03-06 21:04:38 B827E0AE582ACD641F0B2B052773A5CA 6217904 ----a-w- C:\Windows\Sysnative\DDPP64A.dll 2014-03-06 21:04:37 A1C8F811777EFA1B6BD82B226016CF2D 313520 ----a-w- C:\Windows\Sysnative\DDPO64A.dll 2014-03-06 21:04:36 FAC24F4CC63235D9533DD6605E5EE6F0 1938608 ----a-w- C:\Windows\Sysnative\DDPD64A.dll 2014-03-06 21:04:36 82DF29C6D5571BFA69429563F0AED677 260272 ----a-w- C:\Windows\Sysnative\DDPA64.dll 2014-03-06 21:04:32 6E14F444A2506049EEC25CB5EDFE0905 113576 ----a-w- C:\Windows\Sysnative\CONEQMSAPOGUILibrary.dll 2014-03-06 21:04:28 2D0895BED270D1A8CADD981A5BFC0AE5 605496 ----a-w- C:\Windows\Sysnative\audioLibVc.dll 2014-03-06 21:04:27 F2CF417EF502555B139EDCD9FEBF9CD3 109848 ----a-w- C:\Windows\Sysnative\AcpiServiceVnA64.dll 2014-03-06 21:04:27 B3E9EA31E37EDCC1D54CE20504549ABE 108640 ----a-w- C:\Windows\Sysnative\AERTAR64.dll 2014-03-06 21:04:27 2CBDC11690656A1A2D03EC65AE2BCE68 209096 ----a-w- C:\Windows\Sysnative\AERTAC64.dll 2014-03-06 21:00:28 EE4F3EE7BEF22FD35EA5249A78D3AB79 90112 ----a-w- C:\Windows\Sysnative\igfxCoIn_v2869.dll 2014-03-06 21:00:28 5D463B6AB51B49D666F5965AA9464D87 5448 ----a-w- C:\Windows\Sysnative\iglhxs64.vp 2014-03-06 21:00:27 8FF8BB604620836A0B0CE7E99D56440A 511032 ----a-w- C:\Windows\Sysnative\igfxsrvc.exe 2014-03-06 21:00:27 8C71C669747887B4054D056C7A6F79F8 188416 ----a-w- C:\Windows\Sysnative\iglhcp64.dll 2014-03-06 21:00:27 73D292020B4911315686596EBBC5640F 380416 ----a-w- C:\Windows\Sysnative\igfxTMM.dll 2014-03-06 21:00:27 3CD0E54D977C28CA50FBE3E40C6F7D0F 163384 ----a-w- C:\Windows\Sysnative\igfxtray.exe 2014-03-06 21:00:27 233064139949FF4349A1E17C20F39A1A 206336 ----a-w- C:\Windows\Sysnative\iglhsip64.dll 2014-03-06 21:00:26 FE9DD2A78C919CAFD30C895B4AB8C3C1 87552 ----a-w- C:\Windows\Sysnative\igfxrfin.lrc 2014-03-06 21:00:26 F679EF4C684268FB0055A3074E2A7566 87040 ----a-w- C:\Windows\Sysnative\igfxrdan.lrc 2014-03-06 21:00:26 EDDF165A5814EE5867AE3C1F2C5FC556 87552 ----a-w- C:\Windows\Sysnative\igfxrslv.lrc 2014-03-06 21:00:26 E578FDE93CE0B29696E8B04CB7218CD9 87552 ----a-w- C:\Windows\Sysnative\igfxrnor.lrc 2014-03-06 21:00:26 C877ADB543F67912A5592A2A146E6837 87552 ----a-w- C:\Windows\Sysnative\igfxrtrk.lrc 2014-03-06 21:00:26 BF43C2CA2973A6482C3766F2C011B257 86528 ----a-w- C:\Windows\Sysnative\igfxrheb.lrc 2014-03-06 21:00:26 BDD3B304F100C16879EA77BFDF7801B6 87552 ----a-w- C:\Windows\Sysnative\igfxrptb.lrc 2014-03-06 21:00:26 B9FE5A0ADB2A6E92B782BBD748442CB1 84992 ----a-w- C:\Windows\Sysnative\igfxrjpn.lrc 2014-03-06 21:00:26 B97118477D60610D7EE14F253CC69398 88576 ----a-w- C:\Windows\Sysnative\igfxresn.lrc 2014-03-06 21:00:26 B80052C021433859818EE3E55390F592 88064 ----a-w- C:\Windows\Sysnative\igfxrsky.lrc 2014-03-06 21:00:26 B2D5AC8C8955384314BA8C6567DDEC79 87552 ----a-w- C:\Windows\Sysnative\igfxrsve.lrc 2014-03-06 21:00:26 A71EFF1FAD6374D4984F6E020A1224FA 84992 ----a-w- C:\Windows\Sysnative\igfxrkor.lrc 2014-03-06 21:00:26 93F8B79AC238ECF79A4233CCA8F682B0 87552 ----a-w- C:\Windows\Sysnative\igfxrhun.lrc 2014-03-06 21:00:26 8B7B506C19FB073F9ECDC67F6053AF5C 88576 ----a-w- C:\Windows\Sysnative\igfxrfra.lrc 2014-03-06 21:00:26 6D3BC2A0270207F31DC0B3B34DFEEDEC 88064 ----a-w- C:\Windows\Sysnative\igfxrptg.lrc 2014-03-06 21:00:26 58ACF6E6C6A59819D27D6CE624D2EF47 88064 ----a-w- C:\Windows\Sysnative\igfxrita.lrc 2014-03-06 21:00:26 4E34EF2E9B236F809CD7C4F8FE73BC95 87552 ----a-w- C:\Windows\Sysnative\igfxrenu.lrc 2014-03-06 21:00:26 290F868B7964BC82BBB545AC38378B8E 88064 ----a-w- C:\Windows\Sysnative\igfxrplk.lrc 2014-03-06 21:00:26 26286D4D81AC51D38B4B2DF66B95AE89 87040 ----a-w- C:\Windows\Sysnative\igfxrtha.lrc 2014-03-06 21:00:26 22652661A8C57BDBAB0E3D908C707245 88064 ----a-w- C:\Windows\Sysnative\igfxrrus.lrc 2014-03-06 21:00:26 1DB9AF476448524A214C8878E775EB67 88064 ----a-w- C:\Windows\Sysnative\igfxrdeu.lrc 2014-03-06 21:00:26 19174B0EC0D7335487882305C96547E9 88064 ----a-w- C:\Windows\Sysnative\igfxrnld.lrc 2014-03-06 21:00:26 04114241F83C27BA56CBFAFA4619848E 88576 ----a-w- C:\Windows\Sysnative\igfxrell.lrc 2014-03-06 21:00:25 DCFFF6EE3EA7606DC9B5D0DDB480F727 83968 ----a-w- C:\Windows\Sysnative\igfxrcht.lrc 2014-03-06 21:00:25 A961369E7D52C9569BD374D8243D94F3 83968 ----a-w- C:\Windows\Sysnative\igfxrchs.lrc 2014-03-06 21:00:25 9DF9255689C480D3FE219752C9D09C55 244224 ----a-w- C:\Windows\Sysnative\igfxpph.dll 2014-03-06 21:00:25 28935157633349C0E74DE61FC89C9167 87552 ----a-w- C:\Windows\Sysnative\igfxrcsy.lrc 2014-03-06 21:00:25 194FBB48D50F5357905FAA019EA2B231 86528 ----a-w- C:\Windows\Sysnative\igfxrara.lrc 2014-03-06 21:00:24 93349A60604AAAEC54DA4458FD04DC47 224824 ----a-w- C:\Windows\Sysnative\igfxext.exe 2014-03-06 21:00:24 4E592C92850A9A2C0E3BF702A60C0908 418360 ----a-w- C:\Windows\Sysnative\igfxpers.exe 2014-03-06 21:00:23 8D190B001736DB115F49021741267B51 142336 ----a-w- C:\Windows\Sysnative\igfxdo.dll 2014-03-06 21:00:23 3F57403B74E5A6C7B5A527F21CE97F10 4096 ----a-w- C:\Windows\Sysnative\IGFXDEVLib.dll 2014-03-06 21:00:22 E8E14873F4FE2AA36F9E1BEDB88C0158 6549504 ----a-w- C:\Windows\Sysnative\igdumd64.dll 2014-03-06 21:00:22 09487A4A161615176ACE18DE834793CE 122368 ----a-w- C:\Windows\Sysnative\igfxcpl.cpl 2014-03-06 21:00:21 E02A08D4450647244F14C00DB3C0D639 15546880 ----a-w- C:\Windows\Sysnative\ig4icd64.dll 2014-03-06 21:00:19 E703154B70055754D28239B1A07998F1 259 ----a-w- C:\Windows\Sysnative\GfxUI.exe.config 2014-03-06 21:00:19 4E2B2F3B7FD17CA06C74F5B54AD476A2 387640 ----a-w- C:\Windows\Sysnative\hkcmd.exe 2014-03-06 21:00:17 9D497C3C093D4E65B8EAAA95133831C8 3158584 ----a-w- C:\Windows\Sysnative\GfxUI.exe 2014-03-06 21:00:16 F537983F65DD5BA0C17F6D95DA4B9696 119360 ----a-w- C:\Windows\Sysnative\Gfxres.sv-SE.resources 2014-03-06 21:00:16 AB20AF03DA5AC78FD9DEFBA318A435A8 189552 ----a-w- C:\Windows\Sysnative\Gfxres.th-TH.resources 2014-03-06 21:00:16 7DCB8B4BD50DEB37C4671C961367B079 121173 ----a-w- C:\Windows\Sysnative\Gfxres.tr-TR.resources 2014-03-06 21:00:16 77AB19E1907F311863B23094BB517019 104044 ----a-w- C:\Windows\Sysnative\Gfxres.zh-TW.resources 2014-03-06 21:00:16 405C4693BB5C5E37C9C0D69988082621 102883 ----a-w- C:\Windows\Sysnative\Gfxres.zh-CN.resources 2014-03-06 21:00:16 3C321E8DC259CF496CBCC6695490C662 118058 ----a-w- C:\Windows\Sysnative\Gfxres.sk-SK.resources 2014-03-06 21:00:16 2410905B04FBDC450E15C7ABD34C567D 119808 ----a-w- C:\Windows\Sysnative\gfxSrvc.dll 2014-03-06 21:00:16 1592AB29C1B53C993939C2C74C3A8C81 114372 ----a-w- C:\Windows\Sysnative\Gfxres.sl-SI.resources 2014-03-06 21:00:16 0FA6CF9ACD2AAB5B35FCBDBA4BC6ECCD 165395 ----a-w- C:\Windows\Sysnative\Gfxres.ru-RU.resources 2014-03-06 21:00:14 FB3AC60EC591A93790885D4BDE8906C4 118409 ----a-w- C:\Windows\Sysnative\Gfxres.pl-PL.resources 2014-03-06 21:00:14 F93C2A04C6963E0D43AC31EB26175092 136401 ----a-w- C:\Windows\Sysnative\Gfxres.ja-JP.resources 2014-03-06 21:00:14 E6D6609F49E7D807542827B8EF48D838 133746 ----a-w- C:\Windows\Sysnative\Gfxres.he-IL.resources 2014-03-06 21:00:14 C2A75C0341015889ED74F853BA5F21D7 123230 ----a-w- C:\Windows\Sysnative\Gfxres.ko-KR.resources 2014-03-06 21:00:14 C219E058EC655352BDE407DC496E1E87 119616 ----a-w- C:\Windows\Sysnative\Gfxres.hu-HU.resources 2014-03-06 21:00:14 B6F3F46234300C5A701F84D30915E81F 120800 ----a-w- C:\Windows\Sysnative\Gfxres.fr-FR.resources 2014-03-06 21:00:14 9E66009E269C8113FC2DB51210232FD9 118697 ----a-w- C:\Windows\Sysnative\Gfxres.fi-FI.resources 2014-03-06 21:00:14 86B1912B5ED6EEA59F91E9454DFBB06D 125558 ----a-w- C:\Windows\Sysnative\Gfxres.it-IT.resources 2014-03-06 21:00:14 630EDA1F8C6F46DB01C56869DF46FBC7 119067 ----a-w- C:\Windows\Sysnative\Gfxres.pt-PT.resources 2014-03-06 21:00:14 5525BB54E5B6D471E3FE83AFB69A993C 114852 ----a-w- C:\Windows\Sysnative\Gfxres.nb-NO.resources 2014-03-06 21:00:14 13B80E7A4C0BA1FCBC53B289B52DD58D 120366 ----a-w- C:\Windows\Sysnative\Gfxres.pt-BR.resources 2014-03-06 21:00:14 12FA5616DABD2DBB2EFC83FCD7F5FEAB 119586 ----a-w- C:\Windows\Sysnative\Gfxres.nl-NL.resources 2014-03-06 21:00:13 ECCC5744385342272C25DDEBCB3DC9E9 122927 ----a-w- C:\Windows\Sysnative\Gfxres.es-ES.resources 2014-03-06 21:00:13 D3B47A7DB8683DB7DBB9BD809D05A7AE 154680 ----a-w- C:\Windows\Sysnative\difx64.exe 2014-03-06 21:00:13 A1D56C6514D3BCCED1118B1A24F25D91 110211 ----a-w- C:\Windows\Sysnative\Gfxres.en-US.resources 2014-03-06 21:00:13 794173FEB0C0275BE9E2F4750A9F6C7B 118745 ----a-w- C:\Windows\Sysnative\Gfxres.cs-CZ.resources 2014-03-06 21:00:13 653B94C71B5AAE750898AB7D305F2203 114261 ----a-w- C:\Windows\Sysnative\Gfxres.da-DK.resources 2014-03-06 21:00:13 63E8B7570D3CFD513F453B6B1F6080A2 122709 ----a-w- C:\Windows\Sysnative\Gfxres.de-DE.resources 2014-03-06 21:00:13 5DC5D4517F868EAC180C77D6F21B201F 139909 ----a-w- C:\Windows\Sysnative\Gfxres.ar-SA.resources 2014-03-06 21:00:13 36D6DE4918F97ACB23E606C51A7108FE 178407 ----a-w- C:\Windows\Sysnative\Gfxres.el-GR.resources 2014-03-06 20:56:04 4D5D8058F17C873B4F0792678BAA6534 34080 ----a-w- C:\Windows\Sysnative\SmartDefragBootTime.exe 2014-03-06 20:55:47 6A6E91C06ACDBE1D85A4EC469BBB8EBB 121856 ----a-w- C:\Windows\Sysnative\IObitSmartDefragExtension.dll ====== C:\Windows\Sysnative\drivers ===== 2014-03-07 13:42:08 313F68E1A3E6345A4F47A36B07062F34 19456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys 2014-03-07 13:42:05 17C6B51CBCCDED95B3CC14E22791F85E 57856 ----a-w- C:\Windows\Sysnative\drivers\TsUsbFlt.sys 2014-03-07 10:31:02 9A8F69CEEC2062FCD156F53B867BDCEA 316312 ----a-w- C:\Windows\Sysnative\drivers\RapportKE64.sys 2014-03-07 10:18:43 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf 2014-03-06 21:09:50 ECDE3F85CBFE6C6CF89BC6E48BA2E056 2988760 ----a-w- C:\Windows\Sysnative\drivers\rtwlane.sys 2014-03-06 21:09:02 D787F86566F6EA23053D9C5F401E33B7 888536 ----a-w- C:\Windows\Sysnative\drivers\Rt64win7.sys 2014-03-06 21:05:52 072413353DBD94C37F23CD85E0F2DF05 5804772 ----a-w- C:\Windows\Sysnative\drivers\rtvienna.dat 2014-03-06 21:05:46 C651A99B25AF42423FF80A88A58CD00B 3791320 ----a-w- C:\Windows\Sysnative\drivers\RTKVHD64.sys 2014-03-06 21:05:36 867F8909D2DC751A2C986DA044ED271F 704269 ----a-w- C:\Windows\Sysnative\drivers\RTAIODAT.DAT 2014-03-06 21:00:22 8814F0B9A09C647D3D7BE735450E7B4C 10629408 ----a-w- C:\Windows\Sysnative\drivers\igdkmd64.sys ====== C:\Windows\Tasks ====== 2014-03-06 20:46:09 C6A0B29D4F83B98B2E37BDC5A0538C41 2888 ----a-w- C:\Windows\Sysnative\Tasks\Uninstaller_SkipUac_Administrator ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-03-13 15:01:58 -------- d-----w- C:\Program Files\trend micro 2014-03-07 10:55:23 -------- d-----w- C:\Program Files\DIFX 2014-02-23 23:33:03 -------- d-----w- C:\Program Files\PhotoZoom Pro 4 ======= C:\PROGRA~2 ===== 2014-03-10 08:47:11 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-03-10 08:39:24 -------- d-----w- C:\PROGRA~2\COMMON~1\Adobe 2014-03-08 10:18:51 -------- d-----w- C:\PROGRA~2\COMMON~1\Isabel CSP 2014-03-08 10:18:51 -------- d-----w- C:\PROGRA~2\COMMON~1\Isabel 2014-03-07 10:52:33 -------- d-----w- C:\PROGRA~2\Belgium Identity Card 2014-03-07 10:29:29 -------- d-----w- C:\PROGRA~2\Trusteer 2014-03-06 20:44:36 -------- d-----w- C:\PROGRA~2\IObit 2014-03-05 20:18:22 -------- d-----w- C:\PROGRA~2\AVG 2014-03-05 04:23:45 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype ======= C: ===== 2014-03-07 15:51:14 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\asc_rdflag ====== C:\Users\cedric\AppData\Roaming ====== 2014-03-10 08:52:11 -------- d-----w- C:\Users\cedric\AppData\Roaming\beid-cache 2014-03-08 09:52:47 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Trusteer 2014-03-07 10:30:01 -------- d-----w- C:\Users\cedric\AppData\Local\Trusteer 2014-03-06 21:29:22 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\IObit 2014-03-06 20:46:04 -------- d-----w- C:\Users\cedric\AppData\Locallow\IObit 2014-03-06 20:43:49 -------- d-----w- C:\Users\cedric\AppData\Roaming\IObit 2014-03-05 20:20:52 -------- d-----w- C:\Users\cedric\AppData\Roaming\AVG2014 2014-03-05 20:20:37 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\AVG2014 2014-03-05 20:20:14 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Avg2014 2014-03-05 20:20:12 -------- d-----w- C:\Users\cedric\AppData\Roaming\TuneUp Software 2014-03-05 20:18:23 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\Avg2014 2014-03-05 20:16:47 -------- d-----w- C:\Users\cedric\AppData\Local\Avg2014 2014-03-05 20:02:30 -------- d-----w- C:\Users\cedric\AppData\Roaming\LavasoftStatistics 2014-02-26 21:53:59 -------- d-----w- C:\Users\cedric\AppData\Local\SpeedBalance 2014-02-25 22:23:45 -------- d-----w- C:\Users\cedric\AppData\Local\webkit 2014-02-25 22:20:27 3A5DA0850690839A59D7906FB4C866BB 1469 ----a-w- C:\Users\cedric\AppData\Local\recently-used.xbel 2014-02-25 22:17:31 -------- d-----w- C:\Users\cedric\AppData\Local\gtk-2.0 2014-02-25 22:14:53 -------- d-----w- C:\Users\cedric\AppData\Local\fontconfig 2014-02-25 22:14:51 -------- d-----w- C:\Users\cedric\AppData\Local\gegl-0.2 2014-02-23 23:33:07 -------- d-----w- C:\Users\cedric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoZoom Pro 4 ====== C:\Users\cedric ====== 2014-03-13 15:01:22 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\cedric\Downloads\RSITx64.exe 2014-03-13 14:59:38 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\cedric\Downloads\RSIT.exe 2014-03-12 12:09:06 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG zelfstandigLinkScanner 2014-03-10 08:46:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-03-10 08:28:11 D6A3D61864E8F9565550548865D7522C 921000 ----a-w- C:\Users\cedric\Downloads\jxpiinstall(1).exe 2014-03-10 08:26:58 D6A3D61864E8F9565550548865D7522C 921000 ----a-w- C:\Users\cedric\Downloads\jxpiinstall.exe 2014-03-08 10:18:51 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KBC-Online for Business 2014-03-07 13:58:11 CB869DAEA55A8D78687F91FE467CA3E7 46222840 ----a-w- C:\Users\cedric\Downloads\eID-QuickInstaller-build-7416-signed_tcm227-236875(1).exe 2014-03-07 10:55:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID 2014-03-07 10:50:11 CB869DAEA55A8D78687F91FE467CA3E7 46222840 ----a-w- C:\Users\cedric\Downloads\eID-QuickInstaller-build-7416-signed_tcm227-236875.exe 2014-03-07 10:29:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Eindpuntbeveiliging 2014-03-07 10:27:25 -------- d-----w- C:\ProgramData\Trusteer 2014-03-07 10:23:04 -------- d-----w- C:\ProgramData\Isabel Services 2014-03-07 10:22:16 3CAA77307A96AE7325DB5EDEAF1BDD02 135968 ----a-w- C:\Users\cedric\Downloads\O4BT.Installer.Kbc.exe 2014-03-06 21:08:29 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\ProgramData\DP45977C.lfl 2014-03-06 20:46:04 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller 2014-03-06 20:45:18 -------- d-----w- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} 2014-03-06 20:45:15 -------- d-----w- C:\ProgramData\IObit 2014-03-06 20:43:20 D72352C40ABFC97336923A22403C7729 41807400 ----a-w- C:\Users\cedric\Desktop\advanced-systemcare-setup.exe 2014-03-06 20:40:30 7FFE531FC3065DE780E683F4197B5F67 4892480 ----a-w- C:\Users\cedric\Downloads\wzmp_8.exe 2014-03-05 20:19:27 -------- d-----w- C:\ProgramData\AVG2014 2014-03-05 20:16:47 -------- d--h--w- C:\ProgramData\Common Files 2014-03-05 19:45:20 -------- d-----w- C:\ProgramData\Lavasoft 2014-03-05 19:43:58 33917156051EE3EBE0CD70F226CF1FB1 455640 ----a-w- C:\Users\cedric\Downloads\ad-aware-windows-downloader.exe 2014-03-05 19:08:55 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Users\cedric\Downloads\mbam-setup-1.75.0.1300(2).exe 2014-03-05 19:05:29 C8F069A68D57DA55102D58CFE24C0D72 4765152 ----a-w- C:\Users\cedric\Downloads\ccsetup411.exe 2014-03-05 04:23:45 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-02-25 22:17:08 -------- d-----w- C:\Users\cedric\.thumbnails 2014-02-25 22:14:51 -------- d-----w- C:\Users\cedric\.gimp-2.8 2014-02-16 20:01:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 ====== C: exe-files == 2014-03-13 15:01:59 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\cedric.exe 2014-03-13 15:01:22 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\cedric\Downloads\RSITx64.exe 2014-03-13 14:59:38 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\cedric\Downloads\RSIT.exe 2014-03-10 08:45:49 C422AF851B98378A39B51D99FE707E64 146344 ----a-w- C:\Program Files (x86)\Java\jre7\bin\unpack200.exe 2014-03-10 08:45:49 0E37C7C174521E16CEA0A6BC46F03BCD 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\tnameserv.exe 2014-03-10 08:45:47 F4BA3A5D5FDE0A321CD7C4A74749CE5B 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\pack200.exe 2014-03-10 08:45:47 EBAB810C999D8C31F0D5D8B28B3EEDD1 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\servertool.exe 2014-03-10 08:45:47 ACA236A716C2291E40ED069F2CBB3D35 49064 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ssvagent.exe 2014-03-10 08:45:47 6E2BECF6E17FF8DC850C058A38A50C4F 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmiregistry.exe 2014-03-10 08:45:47 6E1B0EEBF3D1CC7ECF4104E1473900FF 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmid.exe 2014-03-10 08:45:47 397A6EA17BB97800939DE44D7BFEEC04 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\policytool.exe 2014-03-10 08:45:47 18BC25C50200C3DD4E67611D2467DAA2 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\orbd.exe 2014-03-10 08:45:46 ED1F5F1906F8D963612A4831CDB331D6 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ktab.exe 2014-03-10 08:45:46 B9436A665A8621073A12338B16D7BFD4 182696 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jqs.exe 2014-03-10 08:45:46 762E372DCFDAE32FAE52C1A50A0029C2 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\klist.exe 2014-03-10 08:45:46 6EEAD2C8A5CAC1F0F2066ABD77BA9092 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\keytool.exe 2014-03-10 08:45:46 49A5F3169A23C00F9F2023DFE04D7AF6 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\kinit.exe 2014-03-10 08:45:45 A8F2A6D5782AA0166D8367FF674DDF77 52648 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe 2014-03-10 08:45:44 E9BFEA5B2F3F7598DA990F9728768790 66984 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javacpl.exe 2014-03-10 08:45:44 CB3638541DCAC86EE17FA8258202E20E 175016 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaw.exe 2014-03-10 08:45:44 95E15A2DE75AB48728AB8E1911C3EDB1 264616 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaws.exe 2014-03-10 08:45:43 FBC27FD8E76C53E6E8066944BBE2BF73 48040 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jabswitch.exe 2014-03-10 08:45:43 9395BBE294045909A025C9F3DC3D9025 174504 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java.exe 2014-03-10 08:45:43 5877E6618DA03EE8E7A869F57EE6ACE5 15784 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java-rmi.exe 2014-03-10 08:43:58 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Users\cedric\AppData\LocalLow\Sun\Java\jre1.7.0_51\lzma.exe 2014-03-10 08:28:11 D6A3D61864E8F9565550548865D7522C 921000 ----a-w- C:\Users\cedric\Downloads\jxpiinstall(1).exe 2014-03-10 08:26:58 D6A3D61864E8F9565550548865D7522C 921000 ----a-w- C:\Users\cedric\Downloads\jxpiinstall.exe 2014-03-08 10:59:10 5C74AD321FDD45D4562F6F67D9A75C84 1145120 ----a-w- C:\Users\cedric\AppData\Local\Temp\3180\ProjectOnUninstall.exe 2014-03-08 10:48:55 26AE0B3EBF24F13292372CAC53E461BE 39694640 ----a-w- C:\ProgramData\IObit\ASCDownloader\Advanced SystemCare.exe 2014-03-08 10:48:52 2F28FCA1AECCCA9C06A5043B0702FBBE 1753920 ----a-w- C:\Users\cedric\AppData\Local\Temp\ASCDownloader\IMF_ActionCenterDownloader.exe 2014-03-08 10:47:54 5C74AD321FDD45D4562F6F67D9A75C84 1145120 ----a-w- C:\Users\cedric\AppData\Local\Temp\4635\ProjectOnUninstall.exe 2014-03-07 20:48:19 CB869DAEA55A8D78687F91FE467CA3E7 46222840 ----a-w- C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6E96L6H1\eID-QuickInstaller-build-7416-signed_tcm227-236875.exe 2014-03-07 13:58:11 CB869DAEA55A8D78687F91FE467CA3E7 46222840 ----a-w- C:\Users\cedric\Downloads\eID-QuickInstaller-build-7416-signed_tcm227-236875(1).exe 2014-03-07 10:50:11 CB869DAEA55A8D78687F91FE467CA3E7 46222840 ----a-w- C:\Users\cedric\Downloads\eID-QuickInstaller-build-7416-signed_tcm227-236875.exe 2014-03-07 10:27:19 0B88C2FFEA162EDB43DFDB3619513723 272664 ----a-w- C:\Users\cedric\AppData\Local\Temp\Step2.exe 2014-03-07 10:22:16 3CAA77307A96AE7325DB5EDEAF1BDD02 135968 ----a-w- C:\Users\cedric\Downloads\O4BT.Installer.Kbc.exe 2014-03-06 21:06:04 2FF3426DE6BB81F20849755381B47B52 287488 ----a-w- C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe 2014-03-06 21:06:03 ACA3B1A550ED553028F5FDBFA0398A22 101120 ----a-w- C:\Program Files\Realtek\Audio\HDA\WavesSvc.exe 2014-03-06 21:06:02 2A21E75EF80242E0646E7567993E977D 562792 ----a-w- C:\Program Files\Realtek\Audio\HDA\vncutil64.exe 2014-03-06 21:05:48 72C58C9DE23EE6B9B15E9D3A33E5B59E 1719512 ----a-w- C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe 2014-03-06 21:05:44 B291D7BE1D602860F764270CF02079B7 7506136 ----a-w- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe 2014-03-06 21:05:42 57E2E6BF2D8B3EDA2077A3A5502F2333 290520 ----a-w- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe 2014-03-06 21:05:39 54BF6A01D8E2C804612703F878E2BCDC 978648 ----a-w- C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe 2014-03-06 21:05:28 3749C2382FFEFBB2C5C42AB5D09C10BC 13662936 ----a-w- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe 2014-03-06 21:05:27 F31CDC26F3624750C2AE2DEFF1E598DA 1368792 ----a-w- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe 2014-03-06 21:05:00 736E5D35E9AA5F847CC84A0DA6BF2B18 3670272 ----a-w- C:\Program Files\Realtek\Audio\HDA\MaxxAudioControl64.exe 2014-03-06 21:04:48 0C57BAD785EEAD029ABF6CBCF43E9A39 51776 ----a-w- C:\Program Files\Realtek\Audio\HDA\FMAPP.exe 2014-03-06 21:04:45 6688B6F74C360CBC366B7AF948D9084D 240576 ----a-w- C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe 2014-03-06 21:04:39 44BB65B1D3827043978FC8E11CA7C0B4 210024 ----a-w- C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe 2014-03-06 21:04:32 F9EDCA74B8CB3744159DEF02352F7BD6 58880 ----a-w- C:\Program Files\Realtek\Audio\HDA\CreateRtkToastLnk.exe 2014-03-06 20:56:29 EBBA40A5961A12540E3B024548296BA1 4213072 ----a-w- C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.exe 2014-03-06 20:56:21 ECA745AE9DDECCE3B4C55BE0B657B0DB 3730704 ----a-w- C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremovalsetup02251.exe 2014-03-06 20:54:55 13BECDBFC9F055C1D07479F38C4A2123 7267616 ----a-w- C:\ProgramData\IObit\ASCDownloader\Smart Defrag 3.exe 2014-03-06 20:54:45 D9365C61C616D0F8369D9D4B23A16912 13933264 ----a-w- C:\ProgramData\IObit\ASCDownloader\Driver Booster.exe 2014-03-06 20:54:32 EFC5AF1AF298781D459C80A3C75E5873 23688584 ----a-w- C:\ProgramData\IObit\ASCDownloader\IObit Malware Fighter 2.exe 2014-03-06 20:46:03 A9E39A061CF55238D9BBD8113EDA929D 7560992 ----a-w- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe 2014-03-06 20:46:00 5D4ACF36CF6B3E2453C2E39216BD173B 629568 ----a-w- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallDisplay.exe 2014-03-06 20:45:59 C098B4EA64D8C957486ACD736031435C 588608 ----a-w- C:\Program Files (x86)\IObit\IObit Uninstaller\Install_PintoStartMenu.exe 2014-03-06 20:45:57 78148DC7BA8C46551929FF7E47FA4133 1114944 ----a-w- C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe 2014-03-06 20:45:48 935E2093CEED8198C820B7F60BB63167 2151200 ----a-w- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe 2014-03-06 20:45:47 1B39F4B8BA2EA0063C054ABD9C8C5F14 2129728 ----a-w- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallPromote.exe 2014-03-06 20:43:20 D72352C40ABFC97336923A22403C7729 41807400 ----a-w- C:\Users\cedric\Desktop\advanced-systemcare-setup.exe 2014-03-06 20:40:30 7FFE531FC3065DE780E683F4197B5F67 4892480 ----a-w- C:\Users\cedric\Downloads\wzmp_8.exe === C: other files == 2014-03-13 05:36:17 DB9C19AF00AF59299146FAE53285022E 128676 ----a-w- C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\adblockpopups@jessehakanen.net.xpi 2014-03-10 09:09:09 6C702001B52B46BC97434B4CEFDAF55E 20959 ----a-w- C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\belgiumeid@eid.belgium.be.xpi 2014-03-10 08:45:50 863EB6802B1C3B7630290871599BE0BD 18636 ----a-w- C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip 2014-03-10 08:43:12 5596EE15F5694BB23A69DBDA96CE2BB6 921512 ----a-w- C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N05SQ5HM\JavaSetup7u51.com 2014-03-10 08:25:35 5596EE15F5694BB23A69DBDA96CE2BB6 921512 ----a-w- C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NOST8A3I\JavaSetup7u51.com 2014-03-10 08:20:29 5596EE15F5694BB23A69DBDA96CE2BB6 921512 ----a-w- C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D3U0OI87\JavaSetup7u51.com 2014-03-10 08:11:36 5596EE15F5694BB23A69DBDA96CE2BB6 921512 ----a-w- C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6E96L6H1\JavaSetup7u51.com 2014-03-07 13:42:08 313F68E1A3E6345A4F47A36B07062F34 19456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys 2014-03-07 13:42:05 17C6B51CBCCDED95B3CC14E22791F85E 57856 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys 2014-03-07 10:51:45 C1F1650DA495D8957E83608F8BE613A5 61312 ----a-w- C:\drivers\SPR3322K.sys 2014-03-07 10:51:45 2825E0E294686A26506690059E1F437A 29184 ----a-w- C:\drivers\usbccid.sys 2014-03-07 10:51:44 B871A8F6396ECC620766F20E3A120857 57984 ----a-w- C:\drivers\SCR3XX2K.sys 2014-03-07 10:51:44 B2FB0404BFA484BFA5D9A2BE7C0C809C 172544 ----a-w- C:\drivers\cxbu0x64.sys 2014-03-07 10:51:44 258D95A50AC8EF725E114C92FA3A38AA 71680 ----a-w- C:\drivers\S332x64.sys 2014-03-07 10:51:44 1BAACB69DC6C99FA6B249EF27D4642ED 68608 ----a-w- C:\drivers\S3XXx64.sys 2014-03-07 10:51:44 0284C94FC495D8D08DF24C18994C1662 114304 ----a-w- C:\drivers\cxbu0wdm.sys 2014-03-07 10:51:43 888DFE4137F626CEA9CCE3BD47941B64 44672 ----a-w- C:\drivers\a38usbx64.sys 2014-03-07 10:51:43 8378A77DFAF832A7ACBE90F59066FF9A 14080 ----a-w- C:\drivers\acr38svr.sys 2014-03-07 10:51:43 5F92E1E98EC2F4E6FE13D19AA3E24AD7 37632 ----a-w- C:\drivers\a38usb.sys 2014-03-07 10:51:43 0FA03F53C0A635513F34B3D85BA1D361 17674 ----a-w- C:\drivers\a38usb98.sys 2014-03-07 10:31:16 83E7AA6B7A0BD16E5D19A725F50D7901 233336 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso64.sys 2014-03-07 10:31:15 48B7B7BD033DC916748ADA22CE1D72A1 63320 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys 2014-03-07 10:31:11 AB51E1F08C8E789D6C9E8B94D15BE9A9 340432 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys 2014-03-07 10:31:11 000D82CC258E2D341605A6F350C4D1E6 606672 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys 2014-03-07 10:31:02 9A8F69CEEC2062FCD156F53B867BDCEA 316312 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys 2014-03-06 21:09:50 ECDE3F85CBFE6C6CF89BC6E48BA2E056 2988760 ----a-w- C:\Windows\System32\drivers\rtwlane.sys 2014-03-06 21:09:02 D787F86566F6EA23053D9C5F401E33B7 888536 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys 2014-03-06 21:05:46 C651A99B25AF42423FF80A88A58CD00B 3791320 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys 2014-03-06 21:00:22 8814F0B9A09C647D3D7BE735450E7B4C 10629408 ----a-w- C:\Windows\System32\drivers\igdkmd64.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-1022104969-3133531358-4227153473-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"="C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SVPWUTIL"="C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL" "KeNotify"="C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe LPCM" "DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "IsaKbcCertUpdate"="C:\Program Files (x86)\Common Files\Isabel\isa_kbc_certupdate.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "TWebCamera"=""C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"="C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 " "TosVolRegulator"="C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3" "TPwrMain"="%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE" "SmoothView"="%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe " "00TCrdMain"="%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe " "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " "SmartFaceVWatcher"="%ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe " "TosSENotify"="C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" "hkey"="HKLM" "item"="Adobe Reader Speed Launcher" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DivX Download Manager] "command"="\"C:\\Program Files (x86)\\DivX\\DivX Plus Web Player\\DDmService.exe\" start" "hkey"="HKLM" "item"="DivX Download Manager" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EEventManager] "command"="\"C:\\Program Files (x86)\\Epson Software\\Event Manager\\EEventManager.exe\"" "hkey"="HKLM" "item"="EEventManager" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HWSetup] "command"="C:\\Program Files\\TOSHIBA\\Utilities\\HWSetup.exe hwSetUP" "hkey"="HKLM" "item"="HWSetup" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IObit Malware Fighter] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="IObit Malware Fighter" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\IObit\\IObit Malware Fighter\\IMF.exe\" /autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent] "command"="\"c:\\Program Files (x86)\\Nero\\Nero BackItUp & Burn\\Nero BackItUp\\NBAgent.exe\" /WinStart" "hkey"="HKLM" "item"="NBAgent" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba Registration] "command"="C:\\Program Files\\Toshiba\\Registration\\ToshibaReminder.exe" "hkey"="HKLM" "item"="Toshiba Registration" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPRO] "command"="C:\\Program Files (x86)\\Toshiba TEMPRO\\TemproTray.exe" "hkey"="HKLM" "item"="Toshiba TEMPRO" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosNC] "command"="C:\\Program Files\\Toshiba\\BulletinBoard\\TosNcCore.exe" "hkey"="HKLM" "item"="TosNC" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosReelTimeMonitor] "command"="C:\\Program Files\\TOSHIBA\\ReelTime\\TosReelTimeMonitor.exe" "hkey"="HKLM" "item"="TosReelTimeMonitor" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [13/03/2014 15:54] C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0e0f4a8bbd6e.job --a------ C:6C:\ProgramC:FilesC:x86\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:6C:\ProgramC:FilesC:x86\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\ConfigFree Startup Programs" [C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore1ce0e0f4a8bbd6e" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Administrator" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709 - Adblock Plus Pop-up Addon - %ProfilePath%\extensions\adblockpopups@jessehakanen.net.xpi - Belgium eID - %ProfilePath%\extensions\belgiumeid@eid.belgium.be.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709 95812430959AE88CDD0301AB3A71913B - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash D775FA6F1E88B3B99E69E8A0D6C3A819 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll - Shockwave Flash 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions fnjbmmemklcjgepojigaapkoodmkgbae - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx[08/12/2010 22:15] kdidombaedgpfiiedeimiebkmbilgmlc - No path found[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[03/01/2014 01:32] nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx[08/12/2010 22:15] Advanced SystemCare Surfing Protection - cedric\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd DivX HiQ - cedric\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae DivX Plus Web Player HTML5 \u003Cvideo\u003E - cedric\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.trovigo.com/?gd=&ctid=CT3322168&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPB04C9218-20B1-420B-A132-C1B6716BC8FF&SSPV=" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" "Default_Search_URL"="http://www.google.com/ie" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="http://www.google.com/ie" "Default_Search_URL"="http://www.google.com/ie" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.trovigo.com/?gd=&ctid=CT3322168&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPB04C9218-20B1-420B-A132-C1B6716BC8FF&SSPV=" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {2BF1907A-156C-4923-BE7F-17713D97E1F8} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" {3A93E9D2-EE23-44D2-AF74-8A87AD53413A} Unknown Url="Not_Found" {4FD52280-AE04-4DFE-86D6-FC593968E122} Unknown Url="Not_Found" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1022104969-3133531358-4227153473-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3A93E9D2-EE23-44D2-AF74-8A87AD53413A} deleted successfully HKEY_USERS\S-1-5-21-1022104969-3133531358-4227153473-1001\Software\Microsoft\Internet Explorer\SearchScopes\{4FD52280-AE04-4DFE-86D6-FC593968E122} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\cedric\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\cedric\AppData\Local\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\cedric\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1583 folders=175 127583770 bytes) ==== Empty Temp Folders ====================== C:\Users\cedric\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\cedric\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on do 13/03/2014 at 20:24:02,88 ====================== -
Laptop traag en irritant veel pop ups
guntheru plaatste een topic in Archief Bestrijding malware & virussen
Hallo, mijn laptop is tegenwoordig extreem traag en krijg constant popup meldingen. Kan iemand mij hierbij helpen? Heb al een rsit gedaan. alvast bedankt! Logfile of random's system information tool 1.09 (written by random/random) Run by cedric at 2014-03-13 16:01:56 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 89 GB (58%) free of 153 GB Total RAM: 2937 MB (29% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 16:23:55, on 13/03/2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.16518) Boot mode: Normal Running processes: C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe C:\Program Files (x86)\Common Files\Isabel\isa_kbc_certupdate.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe C:\Program Files\trend micro\cedric.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Zoeken R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll O4 - HKLM\..\Run: [sVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL O4 - HKLM\..\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [isaKbcCertUpdate] C:\Program Files (x86)\Common Files\Isabel\isa_kbc_certupdate.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file) O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file) O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file) O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://cbc-pdf.cbc.be O15 - Trusted Zone: http://static.cbc.be O15 - Trusted Zone: http://www.cbccorporate.be O15 - Trusted Zone: ?SOB - Úvodní stránka O15 - Trusted Zone: http://www.csob.sk O15 - Trusted Zone: http://www.isabel.be O15 - Trusted Zone: http://www.beta.isabel.be O15 - Trusted Zone: http://www.isabel.eu O15 - Trusted Zone: http://www.beta.isabel.eu O15 - Trusted Zone: http://kbc-pdf.kbc.be O15 - Trusted Zone: http://static.kbc.be O15 - Trusted Zone: KBC Asset Management O15 - Trusted Zone: http://www.kbcam.com O15 - Trusted Zone: http://wp-a.kbcbankingforbusiness.com O15 - Trusted Zone: http://www.kbcbankingforbusiness.com O15 - Trusted Zone: http://www.kbccorporates.com O15 - Trusted Zone: http://www.kbcfi.com O15 - Trusted Zone: http://wp-a.kbcmerchantbanking.com O15 - Trusted Zone: http://www.kbcmerchantbanking.com O15 - Trusted Zone: http://www.kh.hu O15 - Trusted Zone: http://cbc-pdf.cbc.be (HKLM) O15 - Trusted Zone: http://static.cbc.be (HKLM) O15 - Trusted Zone: http://www.cbccorporate.be (HKLM) O15 - Trusted Zone: ?SOB - Úvodní stránka (HKLM) O15 - Trusted Zone: http://www.csob.sk (HKLM) O15 - Trusted Zone: http://www.isabel.be (HKLM) O15 - Trusted Zone: http://www.beta.isabel.be (HKLM) O15 - Trusted Zone: http://www.isabel.eu (HKLM) O15 - Trusted Zone: http://www.beta.isabel.eu (HKLM) O15 - Trusted Zone: http://kbc-pdf.kbc.be (HKLM) O15 - Trusted Zone: http://static.kbc.be (HKLM) O15 - Trusted Zone: KBC Asset Management (HKLM) O15 - Trusted Zone: http://www.kbcam.com (HKLM) O15 - Trusted Zone: http://wp-a.kbcbankingforbusiness.com (HKLM) O15 - Trusted Zone: http://www.kbcbankingforbusiness.com (HKLM) O15 - Trusted Zone: http://www.kbccorporates.com (HKLM) O15 - Trusted Zone: http://www.kbcfi.com (HKLM) O15 - Trusted Zone: http://wp-a.kbcmerchantbanking.com (HKLM) O15 - Trusted Zone: http://www.kbcmerchantbanking.com (HKLM) O15 - Trusted Zone: http://www.kh.hu (HKLM) O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing) O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 15791 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS "C:\Program Files\Microsoft Security Client\MsMpEng.exe" "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService "C:\Windows\system32\Dwm.exe" C:\Windows\System32\spoolsv.exe "taskhost.exe" C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service "C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE" "C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE" "C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe" "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s "c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe" "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3 "C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe" "C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe" "C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe" "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey "C:\Windows\System32\igfxtray.exe" "C:\Windows\System32\hkcmd.exe" "C:\Windows\System32\igfxpers.exe" C:\Windows\system32\igfxsrvc.exe -Embedding "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe" C:\Windows\system32\igfxext.exe -Embedding C:\Windows\system32\TODDSrv.exe "C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe" "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW "C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe" "C:\Program Files (x86)\Common Files\Isabel\isa_kbc_certupdate.exe" WLIDSvcM.exe 3992 "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE" C:\Windows\system32\SearchIndexer.exe /Embedding "C:\Program Files\Microsoft Security Client\NisSrv.exe" "C:\Program Files\Synaptics\SynTP\SynTPHelper.exe" "C:\Program Files\Windows Media Player\wmpnetwk.exe" C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} "C:\Windows\system32\wuauclt.exe" "C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe" "C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" "C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe" "C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe" "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe" "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY /updatefinished "C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe" "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4116.123b0300.1651001137 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4116 "\\.\pipe\gecko-crash-server-pipe.4116" plugin "C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe" --proxy-stub-channel=Flash5292.6BD5C768.14792 --host-broker-channel=Flash5292.6BD5C768.14503 --host-pid=5292 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll" "C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe" --channel=7052.006BF6EC.1619131190 --proxy-stub-channel=Flash5292.6BD5C768.14792 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll" --host-npapi-version=27 --type=renderer "C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe" "C:\Users\cedric\AppData\Local\Temp\K9 Natural price list.pdf" "C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe" --channel=4584.1.611308889 --type=renderer "C:\Users\cedric\AppData\Local\Temp\K9 Natural price list.pdf" "C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4116.32702900.1547742137 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4116 "\\.\pipe\gecko-crash-server-pipe.4116" plugin "C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe" --proxy-stub-channel=Flash944.6BD5C768.13364 --host-broker-channel=Flash944.6BD5C768.31374 --host-pid=944 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll" "C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe" --channel=452.0070F3D8.823400318 --proxy-stub-channel=Flash944.6BD5C768.13364 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll" --host-npapi-version=27 --type=renderer C:\Windows\system32\wbem\wmiprvse.exe "C:\Users\cedric\Downloads\RSITx64.exe" ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0e0f4a8bbd6e.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job =========Mozilla firefox========= ProfilePath - C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709 prefs.js - "browser.search.useDBForOrder" - "false" prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT3320133&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPDCB5A9EC-ED88-4753-841C-A8DCF4CF8C1B&SSPV=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 12.0.0.77 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0] "Description"=DivX Plus Web Player "Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0] "Description"=DivX OVS Helper Plug-in "Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0] "Description"=Picasa3 plugin "Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.51.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 12.0.0.77 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll C:\Program Files (x86)\Mozilla Firefox\extensions\ belgiumeid@eid.belgium.be C:\Program Files (x86)\Mozilla Firefox\components\ nsIQTScriptablePlugin.xpt C:\Program Files (x86)\Mozilla Firefox\plugins\ NPOFF12.DLL nppdf32.dll npqtplugin.dll npqtplugin2.dll npqtplugin3.dll npqtplugin4.dll npqtplugin5.dll npqtplugin6.dll npqtplugin7.dll QuickTimePlugin.class C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\extensions\ 8ef36653-7dcd-4c5f-81f5-7870fda4b7b7@67e486b0-922d-4a2d-9e3f-77394107f67c.com sitefinder@sitefinder.com C:\Users\cedric\AppData\Roaming\Mozilla\Firefox\Profiles\m1r89vlm.default-1376402822709\searchplugins\ conduit-search.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2014-03-06 2471744] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-02-16 218784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}] Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-11-20 6270336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2014-02-16 880344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-02-16 2331336] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}] DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}] DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-03-10 462760] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20 4502400] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2014-02-16 707288] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-03-10 171944] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}] TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-03-06 13662936] "RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-03-06 1368792] "TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2010-05-25 505768] "SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680] "00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-05-10 915320] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392] "SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080] "TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976] "TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376] "MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2013-10-23 1266912] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-03-06 163384] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-03-06 387640] "Persistence"=C:\Windows\system32\igfxpers.exe [2014-03-06 418360] "RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-03-06 1368792] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_70_Plugin.exe -update plugin [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager] C:\Program Files (x86)\DivX\DivX Plus Web Player\DDmService.exe [2010-12-08 63360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2009-12-03 976320] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2010-03-04 423936] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent] c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [2010-03-09 1086760] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2010-04-19 136136] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-05-11 1050072] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-04-23 595816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-07-09 38304] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "SVPWUTIL"=C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [2010-02-22 352256] "KeNotify"=C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [2010-08-15 34160] "TWebCamera"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-05-01 2454840] "DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-01-11 1230704] "GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040] "QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888] "AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-01-22 4962320] "IsaKbcCertUpdate"=C:\Program Files (x86)\Common Files\Isabel\isa_kbc_certupdate.exe [2013-10-22 1085976] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-12-21 959904] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2014-03-06 272384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll, schannel.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableLinkedConnections"=1 "DisableTaskMgr"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 "NoRun"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-03-13 16:01:58 ----D---- C:\Program Files\trend micro 2014-03-13 16:01:56 ----D---- C:\rsit 2014-03-10 09:52:11 ----D---- C:\Users\cedric\AppData\Roaming\beid-cache 2014-03-10 09:50:13 ----D---- C:\ProgramData\Oracle 2014-03-10 09:46:49 ----A---- C:\Windows\SYSWOW64\javaws.exe 2014-03-10 09:46:20 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll 2014-03-10 09:46:20 ----A---- C:\Windows\SYSWOW64\javaw.exe 2014-03-10 09:46:20 ----A---- C:\Windows\SYSWOW64\java.exe 2014-03-07 14:42:09 ----A---- C:\Windows\system32\rdpudd.dll 2014-03-07 14:42:09 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-03-07 14:42:09 ----A---- C:\Windows\system32\rdpcorets.dll 2014-03-07 14:42:08 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll 2014-03-07 14:42:08 ----A---- C:\Windows\system32\TSWbPrxy.exe 2014-03-07 14:42:08 ----A---- C:\Windows\system32\rdpendp_winip.dll 2014-03-07 14:42:08 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys 2014-03-07 14:42:07 ----A---- C:\Windows\SYSWOW64\mstsc.exe 2014-03-07 14:42:07 ----A---- C:\Windows\SYSWOW64\aaclient.dll 2014-03-07 14:42:07 ----A---- C:\Windows\system32\mstsc.exe 2014-03-07 14:42:07 ----A---- C:\Windows\system32\MsRdpWebAccess.dll 2014-03-07 14:42:06 ----A---- C:\Windows\SYSWOW64\tsgqec.dll 2014-03-07 14:42:06 ----A---- C:\Windows\SYSWOW64\mstscax.dll 2014-03-07 14:42:06 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-03-07 14:42:06 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-03-07 14:42:05 ----A---- C:\Windows\system32\wksprt.exe 2014-03-07 14:42:05 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-03-07 14:42:05 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys 2014-03-07 14:42:05 ----A---- C:\Windows\system32\aaclient.dll 2014-03-07 14:42:04 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll 2014-03-07 14:42:04 ----A---- C:\Windows\system32\tsgqec.dll 2014-03-07 14:42:04 ----A---- C:\Windows\system32\mstscax.dll 2014-03-07 14:42:03 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll 2014-03-07 14:42:03 ----A---- C:\Windows\system32\wksprtPS.dll 2014-03-07 14:37:13 ----A---- C:\Windows\SYSWOW64\qdvd.dll 2014-03-07 14:37:13 ----A---- C:\Windows\system32\qdvd.dll 2014-03-07 14:35:21 ----A---- C:\Windows\system32\RegistryDefragBootTime.exe 2014-03-07 11:55:23 ----D---- C:\Program Files\DIFX 2014-03-07 11:52:51 ----D---- C:\Windows\SYSWOW64\beidpp 2014-03-07 11:52:48 ----D---- C:\Windows\SYSWOW64\siscardplugins 2014-03-07 11:52:33 ----D---- C:\Program Files\log 2014-03-07 11:52:33 ----D---- C:\Program Files (x86)\Belgium Identity Card 2014-03-07 11:51:42 ----D---- C:\drivers 2014-03-07 11:31:02 ----A---- C:\Windows\system32\drivers\RapportKE64.sys 2014-03-07 11:29:29 ----D---- C:\Program Files (x86)\Trusteer 2014-03-07 11:27:25 ----D---- C:\ProgramData\Trusteer 2014-03-07 11:23:04 ----D---- C:\ProgramData\Isabel Services 2014-03-06 22:09:50 ----A---- C:\Windows\system32\drivers\rtwlane.sys 2014-03-06 22:09:02 ----A---- C:\Windows\system32\RtNicProp64.dll 2014-03-06 22:09:02 ----A---- C:\Windows\system32\drivers\Rt64win7.sys 2014-03-06 22:06:02 ----A---- C:\Windows\system32\WavesGUILib64.dll 2014-03-06 22:06:02 ----A---- C:\Windows\system32\tossaeapo64.dll 2014-03-06 22:06:02 ----A---- C:\Windows\system32\toseaeapo64.dll 2014-03-06 22:06:01 ----A---- C:\Windows\system32\tosasfapo64.dll 2014-03-06 22:06:01 ----A---- C:\Windows\system32\tosade.dll 2014-03-06 22:06:01 ----A---- C:\Windows\system32\tepeqapo64.dll 2014-03-06 22:06:00 ----A---- C:\Windows\system32\tadefxapo264.dll 2014-03-06 22:06:00 ----A---- C:\Windows\system32\tadefxapo.dll 2014-03-06 22:05:58 ----A---- C:\Windows\system32\sltech64.dll 2014-03-06 22:05:58 ----A---- C:\Windows\system32\slprp64.dll 2014-03-06 22:05:56 ----A---- C:\Windows\system32\slcnt64.dll 2014-03-06 22:05:55 ----A---- C:\Windows\system32\sl3apo64.dll 2014-03-06 22:05:55 ----A---- C:\Windows\system32\SFSS_APO.dll 2014-03-06 22:05:54 ----A---- C:\Windows\system32\SFNHK64.dll 2014-03-06 22:05:54 ----A---- C:\Windows\system32\SFCOM64.dll 2014-03-06 22:05:54 ----A---- C:\Windows\system32\SFAPO64.dll 2014-03-06 22:05:52 ----A---- C:\Windows\system32\drivers\rtvienna.dat 2014-03-06 22:05:51 ----A---- C:\Windows\system32\RtPgEx64.dll 2014-03-06 22:05:48 ----A---- C:\Windows\system32\RtlCPAPI64.dll 2014-03-06 22:05:46 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys 2014-03-06 22:05:43 ----A---- C:\Windows\system32\RtkCoLDR64.dll 2014-03-06 22:05:43 ----A---- C:\Windows\system32\RtkCfg64.dll 2014-03-06 22:05:40 ----A---- C:\Windows\system32\RtkAPO64.dll 2014-03-06 22:05:40 ----A---- C:\Windows\system32\RtkApi64.dll 2014-03-06 22:05:39 ----A---- C:\Windows\system32\RTEEP64A.dll 2014-03-06 22:05:39 ----A---- C:\Windows\system32\RTEEL64A.dll 2014-03-06 22:05:39 ----A---- C:\Windows\system32\RTEEG64A.dll 2014-03-06 22:05:38 ----A---- C:\Windows\system32\RTEED64A.dll 2014-03-06 22:05:38 ----A---- C:\Windows\system32\RtDataProc64.dll 2014-03-06 22:05:36 ----A---- C:\Windows\system32\RTCOM64.dll 2014-03-06 22:05:36 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT 2014-03-06 22:05:35 ----A---- C:\Windows\system32\RP3DHT64.dll 2014-03-06 22:05:35 ----A---- C:\Windows\system32\RP3DAA64.dll 2014-03-06 22:05:33 ----A---- C:\Windows\system32\RCoRes64.dat 2014-03-06 22:05:33 ----A---- C:\Windows\system32\RCoInstII64.dll 2014-03-06 22:05:26 ----A---- C:\Windows\system32\R4EEP64A.dll 2014-03-06 22:05:26 ----A---- C:\Windows\system32\R4EEL64A.dll 2014-03-06 22:05:26 ----A---- C:\Windows\system32\R4EEG64A.dll 2014-03-06 22:05:26 ----A---- C:\Windows\system32\R4EED64A.dll 2014-03-06 22:05:26 ----A---- C:\Windows\system32\R4EEA64A.dll 2014-03-06 22:05:24 ----A---- C:\Windows\system32\NAHIMICAPOSettingsIPC.dll 2014-03-06 22:05:22 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll 2014-03-06 22:05:22 ----A---- C:\Windows\system32\MISS_APO.dll 2014-03-06 22:05:18 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll 2014-03-06 22:05:17 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll 2014-03-06 22:05:17 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll 2014-03-06 22:05:16 ----A---- C:\Windows\system32\MaxxAudioVnN64.dll 2014-03-06 22:05:09 ----A---- C:\Windows\system32\MaxxAudioVnA64.dll 2014-03-06 22:05:06 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll 2014-03-06 22:05:04 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll 2014-03-06 22:05:02 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll 2014-03-06 22:05:00 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll 2014-03-06 22:04:59 ----A---- C:\Windows\SYSWOW64\MaxxAudioAPOShell.dll 2014-03-06 22:04:58 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll 2014-03-06 22:04:58 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll 2014-03-06 22:04:58 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll 2014-03-06 22:04:57 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll 2014-03-06 22:04:56 ----A---- C:\Windows\system32\KAAPORT64.dll 2014-03-06 22:04:47 ----A---- C:\Windows\system32\FMAPO64.dll 2014-03-06 22:04:46 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll 2014-03-06 22:04:46 ----A---- C:\Windows\system32\DTSU2PREC64.dll 2014-03-06 22:04:45 ----A---- C:\Windows\system32\DTSU2PLFX64.dll 2014-03-06 22:04:45 ----A---- C:\Windows\system32\DTSU2PGFX64.dll 2014-03-06 22:04:44 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll 2014-03-06 22:04:44 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll 2014-03-06 22:04:43 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2014-03-06 22:04:43 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll 2014-03-06 22:04:42 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll 2014-03-06 22:04:42 ----A---- C:\Windows\system32\DTSLFXAPO64.dll 2014-03-06 22:04:42 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll 2014-03-06 22:04:42 ----A---- C:\Windows\system32\DTSGFXAPO64.dll 2014-03-06 22:04:41 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll 2014-03-06 22:04:40 ----A---- C:\Windows\system32\DTSBoostDLL64.dll 2014-03-06 22:04:39 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll 2014-03-06 22:04:38 ----A---- C:\Windows\system32\DDPP64A.dll 2014-03-06 22:04:37 ----A---- C:\Windows\system32\DDPO64A.dll 2014-03-06 22:04:36 ----A---- C:\Windows\system32\DDPD64A.dll 2014-03-06 22:04:36 ----A---- C:\Windows\system32\DDPA64.dll 2014-03-06 22:04:32 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-03-06 22:04:28 ----A---- C:\Windows\system32\audioLibVc.dll 2014-03-06 22:04:27 ----A---- C:\Windows\system32\AERTAR64.dll 2014-03-06 22:04:27 ----A---- C:\Windows\system32\AERTAC64.dll 2014-03-06 22:04:27 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll 2014-03-06 22:00:28 ----A---- C:\Windows\system32\igfxCoIn_v2869.dll 2014-03-06 22:00:27 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll 2014-03-06 22:00:27 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll 2014-03-06 22:00:27 ----A---- C:\Windows\system32\iglhsip64.dll 2014-03-06 22:00:27 ----A---- C:\Windows\system32\iglhcp64.dll 2014-03-06 22:00:27 ----A---- C:\Windows\system32\igfxtray.exe 2014-03-06 22:00:27 ----A---- C:\Windows\system32\igfxTMM.dll 2014-03-06 22:00:27 ----A---- C:\Windows\system32\igfxsrvc.exe 2014-03-06 22:00:25 ----A---- C:\Windows\system32\igfxpph.dll 2014-03-06 22:00:24 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll 2014-03-06 22:00:24 ----A---- C:\Windows\SYSWOW64\igfxdv32.dll 2014-03-06 22:00:24 ----A---- C:\Windows\system32\igfxpers.exe 2014-03-06 22:00:24 ----A---- C:\Windows\system32\igfxext.exe 2014-03-06 22:00:23 ----A---- C:\Windows\system32\igfxdo.dll 2014-03-06 22:00:23 ----A---- C:\Windows\system32\IGFXDEVLib.dll 2014-03-06 22:00:22 ----A---- C:\Windows\SYSWOW64\igdumdx32.dll 2014-03-06 22:00:22 ----A---- C:\Windows\SYSWOW64\igdumd32.dll 2014-03-06 22:00:22 ----A---- C:\Windows\SYSWOW64\igd10umd32.dll 2014-03-06 22:00:22 ----A---- C:\Windows\system32\igdumd64.dll 2014-03-06 22:00:22 ----A---- C:\Windows\system32\drivers\igdkmd64.sys 2014-03-06 22:00:21 ----A---- C:\Windows\system32\ig4icd64.dll 2014-03-06 22:00:20 ----A---- C:\Windows\SYSWOW64\ig4icd32.dll 2014-03-06 22:00:19 ----A---- C:\Windows\system32\hkcmd.exe 2014-03-06 22:00:17 ----A---- C:\Windows\system32\GfxUI.exe 2014-03-06 22:00:16 ----A---- C:\Windows\system32\gfxSrvc.dll 2014-03-06 22:00:13 ----A---- C:\Windows\system32\difx64.exe 2014-03-06 22:00:07 ----A---- C:\log.txt 2014-03-06 21:56:04 ----A---- C:\Windows\system32\SmartDefragBootTime.exe 2014-03-06 21:55:47 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll 2014-03-06 21:46:00 ----D---- C:\ProgramData\ProductData 2014-03-06 21:45:18 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} 2014-03-06 21:45:15 ----D---- C:\ProgramData\IObit 2014-03-06 21:44:36 ----D---- C:\Program Files (x86)\IObit 2014-03-06 21:43:49 ----D---- C:\Users\cedric\AppData\Roaming\IObit 2014-03-05 21:20:52 ----D---- C:\Users\cedric\AppData\Roaming\AVG2014 2014-03-05 21:20:12 ----D---- C:\Users\cedric\AppData\Roaming\TuneUp Software 2014-03-05 21:19:27 ----HD---- C:\$AVG 2014-03-05 21:19:27 ----D---- C:\ProgramData\AVG2014 2014-03-05 21:18:22 ----D---- C:\Program Files (x86)\AVG 2014-03-05 21:16:47 ----HD---- C:\ProgramData\Common Files 2014-03-05 21:16:47 ----D---- C:\ProgramData\MFAData 2014-03-05 21:02:30 ----D---- C:\Users\cedric\AppData\Roaming\LavasoftStatistics 2014-03-05 20:48:27 ----D---- C:\Program Files (x86)\Lavasoft 2014-03-05 20:45:20 ----D---- C:\ProgramData\Lavasoft 2014-03-05 20:08:57 ----A---- C:\Windows\SYSWOW64\FAP53D5.tmp 2014-03-05 20:08:51 ----A---- C:\Windows\SYSWOW64\FAP3C3D.tmp 2014-03-05 20:08:46 ----A---- C:\Windows\SYSWOW64\FAP268A.tmp 2014-03-05 20:08:41 ----A---- C:\Windows\SYSWOW64\FAP13B3.tmp 2014-03-05 20:08:28 ----A---- C:\Windows\SYSWOW64\FAPE072.tmp 2014-03-05 20:08:28 ----A---- C:\Windows\SYSWOW64\FAPDF86.tmp 2014-03-05 20:08:25 ----A---- C:\Windows\SYSWOW64\FAPD3FF.tmp 2014-03-05 20:08:24 ----A---- C:\Windows\SYSWOW64\FAPD0C2.tmp 2014-03-05 20:07:30 ----A---- C:\Windows\SYSWOW64\FAPFFAC.tmp 2014-02-28 09:18:36 ----D---- C:\Windows\Migration 2014-02-24 00:33:12 ----A---- C:\Windows\chgt-c.ini 2014-02-24 00:33:03 ----D---- C:\Program Files\PhotoZoom Pro 4 2014-02-21 14:23:51 ----D---- C:\Program Files (x86)\SimilarSites 2014-02-21 14:23:34 ----D---- C:\Users\cedric\AppData\Roaming\SimilarSites 2014-02-21 14:21:33 ----D---- C:\Program Files\office.tmp 2014-02-16 22:41:38 ----A---- C:\Windows\SYSWOW64\vbscript.dll 2014-02-16 22:41:38 ----A---- C:\Windows\system32\vbscript.dll 2014-02-16 21:45:52 ----A---- C:\Windows\SYSWOW64\vbar332.dll 2014-02-16 21:45:04 ----D---- C:\LogoSmartz Trial 2014-02-16 13:26:21 ----D---- C:\Program Files (x86)\Mozilla Firefox ======List of files/folders modified in the last 1 month====== 2014-03-13 16:01:58 ----RD---- C:\Program Files 2014-03-13 16:01:10 ----D---- C:\Windows\Temp 2014-03-13 15:54:26 ----D---- C:\Windows\SysWOW64 2014-03-13 15:54:13 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe 2014-03-13 15:47:27 ----D---- C:\Windows\system32\config 2014-03-13 15:27:00 ----D---- C:\ProgramData\Adobe 2014-03-12 21:13:22 ----D---- C:\Windows\system32\catroot2 2014-03-12 21:13:22 ----D---- C:\Windows\system32\catroot 2014-03-12 21:13:20 ----D---- C:\Windows\winsxs 2014-03-12 20:47:10 ----SHD---- C:\Windows\Installer 2014-03-11 11:58:12 ----SHD---- C:\System Volume Information 2014-03-10 12:58:33 ----D---- C:\Windows\system32\drivers 2014-03-10 10:14:34 ----D---- C:\Users\cedric\AppData\Roaming\Adobe 2014-03-10 09:50:13 ----HD---- C:\ProgramData 2014-03-10 09:47:11 ----D---- C:\Program Files (x86)\Common Files 2014-03-10 09:45:36 ----D---- C:\Program Files (x86)\Java 2014-03-10 09:39:24 ----D---- C:\Program Files (x86)\Adobe 2014-03-09 22:42:44 ----D---- C:\Windows\System32 2014-03-09 22:42:44 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-03-09 22:42:40 ----D---- C:\Windows\inf 2014-03-08 11:59:21 ----D---- C:\Windows\system32\Tasks 2014-03-08 11:58:22 ----RD---- C:\Program Files (x86) 2014-03-08 11:57:28 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2014-03-08 11:57:27 ----D---- C:\Program Files (x86)\TOSHIBA 2014-03-08 11:50:21 ----D---- C:\Windows\Tasks 2014-03-08 11:28:47 ----D---- C:\Users\cedric\AppData\Roaming\SoftGrid Client 2014-03-07 22:07:28 ----SD---- C:\Users\cedric\AppData\Roaming\Microsoft 2014-03-07 21:49:41 ----D---- C:\Windows 2014-03-07 15:03:47 ----D---- C:\Windows\SYSWOW64\wbem 2014-03-07 15:03:47 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-03-07 15:03:46 ----D---- C:\Windows\system32\wbem 2014-03-07 15:03:46 ----D---- C:\Windows\system32\nl-NL 2014-03-07 15:03:46 ----D---- C:\Windows\system32\drivers\nl-NL 2014-03-07 15:03:46 ----D---- C:\Windows\PolicyDefinitions 2014-03-07 15:03:44 ----D---- C:\Windows\system32\DriverStore 2014-03-07 11:18:38 ----D---- C:\Windows\system32\drivers\UMDF 2014-03-07 09:46:26 ----D---- C:\Windows\Microsoft.NET 2014-03-06 22:31:12 ----D---- C:\Windows\SoftwareDistribution 2014-03-06 22:29:20 ----D---- C:\Windows\debug 2014-03-06 22:09:02 ----A---- C:\Windows\system32\RTNUninst64.dll 2014-03-06 22:07:33 ----D---- C:\Windows\SYSWOW64\RTCOM 2014-03-06 22:00:27 ----A---- C:\Windows\system32\igfxsrvc.dll 2014-03-06 22:00:26 ----A---- C:\Windows\system32\igfxress.dll 2014-03-06 22:00:24 ----A---- C:\Windows\system32\igfxexps.dll 2014-03-06 22:00:23 ----A---- C:\Windows\system32\igfxdev.dll 2014-03-06 22:00:22 ----A---- C:\Windows\system32\igd10umd64.dll 2014-03-06 22:00:19 ----A---- C:\Windows\system32\hccutils.dll 2014-03-06 21:53:30 ----D---- C:\Windows\Panther 2014-03-06 21:46:18 ----D---- C:\Users\cedric\AppData\Roaming\Apple Computer 2014-03-05 21:14:06 ----D---- C:\Program Files\Common Files 2014-03-05 20:06:07 ----D---- C:\Program Files\CCleaner 2014-03-05 18:41:24 ----D---- C:\Windows\Prefetch 2014-03-05 05:23:45 ----RD---- C:\Program Files (x86)\Skype 2014-03-05 05:23:42 ----D---- C:\ProgramData\Skype 2014-03-02 19:43:59 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI 2014-03-01 21:47:17 ----D---- C:\Windows\system32\NDF 2014-02-28 09:25:42 ----RSD---- C:\Windows\assembly 2014-02-28 09:19:07 ----D---- C:\Windows\SYSWOW64\en-US 2014-02-28 09:19:07 ----D---- C:\Windows\system32\en-US 2014-02-28 09:18:36 ----SD---- C:\ProgramData\Microsoft 2014-02-21 14:21:01 ----D---- C:\Program Files (x86)\MSECache 2014-02-17 11:29:21 ----D---- C:\Program Files\Internet Explorer 2014-02-17 11:29:21 ----D---- C:\Program Files (x86)\Internet Explorer 2014-02-17 11:29:15 ----RSD---- C:\Windows\Fonts 2014-02-17 11:23:04 ----D---- C:\Windows\system32\MRT 2014-02-17 11:19:32 ----A---- C:\Windows\system32\MRT.exe 2014-02-16 21:57:21 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-16 21:12:56 ----D---- C:\ProgramData\Microsoft Help 2014-02-16 21:00:18 ----D---- C:\Program Files\Microsoft Office 15 ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2013-11-25 196376] R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2013-10-31 294712] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 408600] R0 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys [2010-03-22 46192] R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-09-27 248240] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2014-02-10 316312] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888] R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840] R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2013-08-01 251192] R1 RapportCerberus_59849;RapportCerberus_59849; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [2014-03-07 606672] R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2014-02-10 282712] R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2014-02-10 397848] R1 SbFw;SbFw; C:\Windows\system32\drivers\SbFw.sys [2012-09-20 258848] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 134944] R3 CeKbFilter;CeKbFilter; C:\Windows\system32\DRIVERS\CeKbFilter.sys [2010-10-04 20592] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-03-06 10629408] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-03-06 3791320] R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-03-06 888536] R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2014-03-06 2988760] R3 SBFWIMCLMP;GFI Software Firewall NDIS IM Filter Miniport; C:\Windows\system32\DRIVERS\SBFWIM.sys [2012-09-12 120064] R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2013-06-26 767144] R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2013-06-26 273576] R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2013-06-26 28840] R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2013-06-26 23208] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464] R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2011-05-13 36328] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-03-07 19456] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-01-07 232992] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\Windows\system32\DRIVERS\rtl8192Ce.sys [2010-04-28 932384] S3 SBFWIMCL;GFI Software Firewall NDIS IM Filter Service; C:\Windows\system32\DRIVERS\sbfwim.sys [2012-09-12 120064] S3 sbhips;sbhips; C:\Windows\system32\drivers\sbhips.sys [2012-09-20 61216] S3 sbwtis;sbwtis; C:\Windows\system32\DRIVERS\sbwtis.sys [2012-09-20 86816] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872] S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640] S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2014-03-07 57856] S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432] R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-09-24 348008] R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-01-03 1363616] R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-01-03 1748640] R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200] R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448] R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2013-04-22 822504] R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2009-09-14 166400] R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2009-09-14 128512] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-27 1811456] R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-10-23 23808] R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2010-01-15 935208] R2 OfficeSvc;Microsoft Office-service; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-10-31 1907896] R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2014-02-10 1444120] R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-06-26 523944] R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368] R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632] R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2010-05-25 489384] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976] R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376] R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-06-26 207528] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088] S2 gupdate;Google Updateservice (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-30 135664] S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13 257928] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-30 135664] S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616] S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-02-16 118896] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-10-03 150600] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-10-03 5132888] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-13 1255736] S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] -----------------EOF----------------- -
oke, bedankt he! pc lijkt weer als nieuw
-
pc start veel sneller op, en de internet explorer lijkt niet vast te lopen ook, dus ziet er goed uit! bedankt!
-
Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Databaseversie: 7031 Windows 6.1.7600 Internet Explorer 9.0.8112.16421 6/07/2011 9:47:41 mbam-log-2011-07-06 (09-47-41).txt Scantype: Snelle scan Objecten gescand: 170292 Verstreken tijd: 5 minuut/minuten, 38 seconde(n) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 3 Registerwaarden geïnfecteerd: 0 Registerdata geïnfecteerd: 0 Mappen geïnfecteerd: 2 Bestanden geïnfecteerd: 3 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registersleutels geïnfecteerd: HKEY_CURRENT_USER\Software\z2010MegawildAdverpopper (Adware.PlayMP3z.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\z2010MegawildAdverpopper (Adware.PlayMP3z.Gen) -> Quarantined and deleted successfully. Registerwaarden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerdata geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Mappen geïnfecteerd: c:\program files\z2010megawildadverpopper (Adware.PlayMP3z.Gen) -> Quarantined and deleted successfully. c:\Users\gunther\AppData\Roaming\microsoft\Windows\start menu\Programs\PlayMP3z (Adware.PLayMP3z) -> Quarantined and deleted successfully. Bestanden geïnfecteerd: c:\program files\z2010megawildadverpopper\uninstall.exe (Adware.PlayMP3z.Gen) -> Quarantined and deleted successfully. c:\program files\z2010megawildadverpopper\z2010megawildadverpopper.dll (Adware.PlayMP3z.Gen) -> Quarantined and deleted successfully. c:\Users\gunther\AppData\Roaming\microsoft\Windows\start menu\Programs\PlayMP3z\run playmp3z.pif (Adware.PLayMP3z) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:54:53, on 6/07/2011 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\wuauclt.exe C:\hijack this\HijackThis.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.telenet.be R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.telenet.be R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.telenet.be R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [samsung.PCSync] "C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [samsung.PCSync] "C:\Program Files\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {B60CEFE7-2DD0-4B78-951A-509D951DB1F0} (ExtraFilm Uploader Control) - http://www.extrafilm.be/ExtraFilmUploader6.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ASWLSVC - Unknown owner - C:\Windows\System32\ASWLSVC.exe (file missing) O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- End of file - 5608 bytes bedankt alvast!
-
hallo, heb de laatste tijd nogal problemen met een trage opstartende pc, alsook men internet explorer die regelmatig vastloopt en dan ineens weer werkt ofwel wegvalt. Heb ondertussen al een hijacklog maar wat mag er weg en wat niet? Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\wuauclt.exe C:\hijack this\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.telenet.be R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.telenet.be R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.telenet.be R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKLM\..\Policies\Explorer\Run: [Rcib] C:\Windows\system32\KBDHEPTS.exe O4 - HKLM\..\Policies\Explorer\Run: [JFOHQUWHFZ] C:\Windows\system32\unimdmat4.exe O4 - HKLM\..\Policies\Explorer\Run: [crcibxn] C:\Windows\system32\PSHEDU.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [KUGHGZXAKT] C:\Windows\TEMP\Okl.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [KUGHGZXAKT] C:\Windows\TEMP\Okl.exe (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {B60CEFE7-2DD0-4B78-951A-509D951DB1F0} (ExtraFilm Uploader Control) - http://www.extrafilm.be/ExtraFilmUploader6.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ASWLSVC - Unknown owner - C:\Windows\System32\ASWLSVC.exe (file missing) O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- End of file - 5974 bytes alvast bedankt!!

OVER ONS
PC Helpforum helpt GRATIS computergebruikers sinds juli 2006. Ons team geeft via het forum professioneel antwoord op uw vragen en probeert uw pc problemen zo snel mogelijk op te lossen. Word lid vandaag, plaats je vraag online en het PC Helpforum-team helpt u graag verder!