Ga naar inhoud

Opm65

Lid
  • Items

    23
  • Registratiedatum

  • Laatst bezocht

Opm65's prestaties

  1. Uiteindelijk heb ik het probleem op kunnen lossen door de slaapstand volledig uit te schakelen (via de energie-instellingen van Windows 10) na de installatie van de Anniversary Update.
  2. Hoi, Hierbij een probleem met de Anniversary Update van Windows 10. Ik heb deze update inmiddels vier keer geïnstalleerd, en iedere keer liep Windows na het opnieuw opstarten vast, zodat ik terug moest gaan naar de vorige versie van Windows 10 (versie 1511). Ik kom bij dat vastlopen wel bij het gewone opstartscherm van Windows, maar kan niets aanklikken, de taakbalk en de iconen op het bureaublad zijn allemaal geblokkeerd. Ik heb een aantal oplossingen, gevonden op het internet, uitgeprobeerd maar niets helpt. Het gaat dan om de volgende oplossingen: 1. het uitschakelen van Snel Opstarten (bij energie-instellingen) 2. de opslaglocatie van apps veranderen van schijf D: naar schijf C: 3. na het installeren van de Anniversary Update, nog voor het opnieuw opstarten, de "Aan de Slag" app ("Get Started") verwijderen en het wsreset commando draaien, zodat de cache van de Windows Store geschoond wordt. Het idee is dat die "Get Started" app de freeze veroorzaakt 4. de Anniversary Update installeren onder een ander Microsoft account (met administrator rechten). Weet iemand nog een andere oplossing? De fix die Microsoft zelf in de update van 31/8/2016 (van de Anniversary Update) heeft geplaatst werkt bij mij in ieder geval niet, aangezien ik het vandaag nog geprobeerd heb (met oplossing 4 hierboven). Alvast mijn dank.
  3. Hoi falstring, Bedankt voor je reactie. Ik heb je advies opgevolgd, maar dat lost het probleem niet op. Ik heb de USB-poorten overigens één voor één opnieuw geïnstalleerd, omdat ik anders geen muis en toetsenbord meer heb om de PC opnieuw op te starten. Het vreemde blijft, dat Windows 10 op mijn PC als driver UASPSTOR.SYS laadt, terwijl op de laptop waarop de externe schijf wel gewoon werkt (met windows 10) USBSTOR.SYS geladen wordt. Dan ga je toch denken dat het aan een specifieke chipset ligt (in mijn geval Intel 5 Series/3400 Series).
  4. Hoi, Sinds de update naar Windows 10 werkt mijn externe harde schijf (Seagate Desktop Expansion 4TB) niet meer. Moederbord: Gigabyte GA-P55M-UD2. Onder Apparaatbeheer vond ik het volgende: Opslagcontrollers - Via USB aangesloten SCSI (UAS)-apparaat voor massaopslag: Dit apparaat start niet. (Code 10) {Bewerking mislukt} De aangevraagde bewerking is niet gelukt. Device USB\VID_0BC2&PID_3320\MSFT30NA4MB4F4 could not be migrated. Last Device Instance Id: USB\VID_0BC2&PID_3320\NA4MB4F4 Class Guid: {36FC9E60-C465-11CF-8056-444553540000} Location Path: PCIROOT(0)#PCI(1A07)#USBROOT(0)#USB(4) Migration Rank: 0xF0000000C0000103 Present: true Status: 0xC0000719 19-9-2015 13:15:37 Apparaat niet gemigreerd (= not migrated) 19-9-2015 13:15:37 Apparaat geconfigureerd (uaspstor.inf) 19-9-2015 13:15:58 Apparaat niet gestart (UASPStor) Op een andere PC met windows 10 (een ASUS laptop) werkt de externe schijf wel. Windows 10 laadt als driver UASPSTOR.SYS op mijn PC, maar dit zou USBSTOR.SYS moeten zijn, zoals op de genoemde laptop. De Seagate externe schijf kan USB 3 aan, maar zit op een USB 2 poort (mijn moederbord heeft geen USB3 poorten). Ligt dit aan het GIGABYTE moederbord (drivers, BIOS)? Weet iemand een oplossing voor dit probleem? Zowel Seagate als Gigabyte kon mij niet helpen. Volgens Gigabyte had Intel geen nieuwe drivers voor de P55 chipset voor windows 10.
  5. Bedankt voor je reactie. Omdat de opstartproblemen zelf nog niet opgelost bleken te zijn, heb ik windows 7 opnieuw geïnstalleerd. Ik had voor de inbouw van een Samsung SSD het besturingssysteem overgezet naar de SSD, maar hier was blijkbaar toch iets niet helemaal goed gegaan. Vandaar een nieuwe installatie van windows.
  6. Hoi. Ik heb een probleem met msconfig.exe. Om opstartproblemen op te lossen (na de inbouw van een nieuwe videokaart en een SSD) heb ik msconfig.exe gebruikt om op te starten in de opstartmethode 'Selectief Opstarten'. De problemen lijken opgelost te zijn (na het gebruik van een systeemherstelschijf), en ik wil nu weer gewoon opstarten. Maar ik kan msconfig.exe nu niet in de opstartmethode 'Normaal Opstarten' krijgen. Indien ik 'Normaal Opstarten' aanvink en op Toepassen druk, springt msconfig.exe weer automatisch op 'Selectief Opstarten'. De pc blijft nu voortdurend in een beperkte staat opstarten. Weet ieman een oplossing hiervoor? Alvast mijn dank.
  7. Heel erg bedankt voor de hulp, alles is weer netjes opgeruimd!
  8. Log van AdwCleaner: # AdwCleaner v3.017 - Report created 17/01/2014 at 13:38:29 # Updated 12/01/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Gebruiker - GEBRUIKER-PC # Running from : C:\Users\Gebruiker\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\Gebruiker\AppData\LocalLow\ZoneAlarm_Security ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\BandooCore.EXE Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.BandooCore.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.ResourcesMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.SettingsMngr.1 Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr Key Deleted : HKLM\SOFTWARE\Classes\BandooCore.StatisticMngr.1 Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASUS_N_Series_Screensaver Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2645238 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FEB40468-2C9A-4868-A0A2-A5318974F879} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFC6B931-37B8-45EA-8185-F99F93C07DD9} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9776B328-1795-4B10-8673-4FBBACC20704} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080} Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\ZoneAlarm_Security Key Deleted : HKLM\Software\Bandoo Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DeviceVM Key Deleted : HKLM\Software\ZoneAlarm_Security Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm_Security Toolbar Key Deleted : [x64] HKLM\SOFTWARE\DeviceVM ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16428 ************************* AdwCleaner[R0].txt - [5417 octets] - [17/01/2014 13:36:50] AdwCleaner[s0].txt - [5359 octets] - [17/01/2014 13:38:29] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [5419 octets] ########## De rommel van Conduite/Rockfuel is zo te zien nu ook verwijderd uit het register. Hitman Pro vindt nu ook niets meer.
  9. Bedankt voor je reactie. Maar is het niet veiliger om dat verwijderen via een tool zoals AdwCleaner? Of zou deze die items in het register van Windows niet aanpakken?
  10. Hitman Pro geeft nog twee meldingen: Rocketfuel in HKLM\SOFTWARE\Classes\Wow6432Node\SLSID en Rocketfuel in HKLM\SOFTWARE\Wow6432Node. Maar aangezien we geen licentie hebben voor Hitman Pro, kunnen we dit hiermee niet verwijderen.
  11. De log van zoek.exe: Zoek.exe v5.0.0.0 Updated 15-Januari-2014 Tool run by Gebruiker on do 16-01-2014 at 17:19:41,30. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Desktop\zoek.exe [scan all users] [script inserted] [Checkboxes used] ==== System Restore Info ====================== 16-1-2014 17:24:29 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\Panda Security deleted successfully C:\Program Files\CheckPoint deleted successfully C:\Program Files\Fighters deleted successfully C:\Program Files\Symantec deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{91da5e8a-3318-4f8c-b67e-5964de3ab546} deleted successfully ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] ==== Deleting Files \ Folders ====================== C:\PROGRA~2\ZoneAlarm_Security deleted C:\PROGRA~2\zonealarm_security_suite deleted C:\PROGRA~2\Conduit deleted C:\Users\Gebruiker\AppData\Local\Conduit deleted C:\Users\Gebruiker\AppData\LocalLow\Conduit deleted C:\Windows\Syswow64\tmp31C9.tmp deleted C:\Windows\Syswow64\tmp31DA.tmp deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.htm" deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.html" deleted "C:\Users\Gebruiker\AppData\Roaming\temp\ICON.rtf" deleted "C:\Users\Gebruiker\AppData\Roaming\temp" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== 2014-01-16 15:06:01 8629990396B6FA011E27B46ED6AC4BDB 808224 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\nvStInst.exe 2014-01-16 12:54:23 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-01-16 15:05:15 28AC0BD3E6712C07B663A48F2E5CE3AC 32544 ----a-w- C:\Windows\SysWOW64\nvaudcap32v.dll 2014-01-16 15:05:12 BDC32E3B7E5297EC0B4E0AEA2E2E55E0 9657464 ----a-w- C:\Windows\SysWOW64\nvopencl.dll 2014-01-16 15:05:11 D18F9D53B844B5E6FE614FEE8FBF186F 852768 ----a-w- C:\Windows\SysWOW64\NvIFR.dll 2014-01-16 15:05:11 C1E3CC280E6CB4F3C1BA9F9EC50683E2 2747680 ----a-w- C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-16 15:05:11 A403088619D575D43AA0C46AD56BB203 22960416 ----a-w- C:\Windows\SysWOW64\nvoglv32.dll 2014-01-16 15:05:11 9C1FBE3D3CBFCF88DCDFCB21D38307A3 2947872 ----a-w- C:\Windows\SysWOW64\nvcuvid.dll 2014-01-16 15:05:11 5F0E3FBF97F9AABBC6B7227B77F7E958 15230352 ----a-w- C:\Windows\SysWOW64\nvd3dum.dll 2014-01-16 15:05:11 5B9DF8156153C839A0E6449294030519 847648 ----a-w- C:\Windows\SysWOW64\NvFBC.dll 2014-01-16 15:05:11 39BD6D4EF0FDBC92D0B1CD86A4D0BFF0 9700224 ----a-w- C:\Windows\SysWOW64\nvcuda.dll 2014-01-16 15:05:10 5F67586FFD23EBEF5C074296AA1E0F76 17560352 ----a-w- C:\Windows\SysWOW64\nvcompiler.dll 2014-01-16 14:15:24 AD27563BC16AB1EAACAE3033E99C2F78 194048 ----a-w- C:\Windows\SysWOW64\elshyph.dll 2014-01-16 14:15:05 FB0D1CC2911A0645DDA6C0608473EB55 34816 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-16 14:15:05 F705F52FC41577641E82B9934728B02C 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-01-16 14:15:05 D9F12F54E3B5A092F1D5F191F5286E53 337408 ----a-w- C:\Windows\SysWOW64\html.iec 2014-01-16 14:15:05 C1A6E565B2782C09BC40AD749B46D9ED 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-16 14:15:05 B68750104FBA545C633B7E9AEA660208 2166272 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-01-16 14:15:05 B5EB5BD3066959611E1F7A80FD6CC172 1818112 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-01-16 14:15:05 9E170B0AF156B478BD2B1FD6A2250C9E 62464 ----a-w- C:\Windows\SysWOW64\tdc.ocx 2014-01-16 14:15:05 9B8701A380CEE1B05D651B4ED4048C8F 645120 ----a-w- C:\Windows\SysWOW64\jsIntl.dll 2014-01-16 14:15:05 4A7956EE34BE56D20C54CF6A47693C25 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-01-16 14:15:05 44D5C650C971910827EA65B4D989ED94 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-01-16 14:15:05 2EE1E467D73642AFDDB03019F58C252B 1156608 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-01-16 14:15:05 298FDE634538B62CEEEC266D8773B21A 182272 ----a-w- C:\Windows\SysWOW64\msls31.dll 2014-01-16 14:15:05 22868FAAF9C851BFA924B8D7EDB6CBC1 11220992 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-01-16 14:15:05 08B56CF57B7CE44315034247CC76D0F1 244736 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-01-16 14:15:04 F862CD08F1AD4EE39BD506853F3C6103 16284 ----a-w- C:\Windows\SysWOW64\ieuinit.inf 2014-01-16 14:15:04 EC7038154490E50ACD405A022F51B204 83456 ----a-w- C:\Windows\SysWOW64\inseng.dll 2014-01-16 14:15:04 CFCE4EFF1D6D909EE2EA3AFCB8F1E677 233472 ----a-w- C:\Windows\SysWOW64\url.dll 2014-01-16 14:15:04 C3B0DBD04CC18574B0706CA119902474 367104 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-01-16 14:15:04 C17139EAF939964142C7A1AEEE02DC81 616104 ----a-w- C:\Windows\SysWOW64\ieapfltr.dat 2014-01-16 14:15:04 BE8B10D84DDD8F43A32EE013B54F5287 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-01-16 14:15:04 AB3B2CA52AFB695AFCDD2620A21E5B21 24576 ----a-w- C:\Windows\SysWOW64\licmgr10.dll 2014-01-16 14:15:04 9A33FDDD687A836A1FD478B43C5A95FD 151552 ----a-w- C:\Windows\SysWOW64\iexpress.exe 2014-01-16 14:15:04 81A605B0F3A29A117AB83A08D40F772F 1926656 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-01-16 14:15:04 71144A47CD02FDDC77DDF5EB5315767F 523776 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-01-16 14:15:04 6A92CEC8532056791C6832B2725D170D 139264 ----a-w- C:\Windows\SysWOW64\wextract.exe 2014-01-16 14:15:04 6A794439B6612E43FEDE0217C919B652 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-01-16 14:15:04 6922D7ED84AE102504174922D5D42F49 238288 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-01-16 14:15:04 64831CAD496A073398853A34A5813675 69632 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-01-16 14:15:04 5DFE55E0221F0C5FA4D6CECFA72B1D78 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-01-16 14:15:04 4F032F1FDEFEA5EC8EEA3562643B5EE8 69120 ----a-w- C:\Windows\SysWOW64\icardie.dll 2014-01-16 14:15:04 433161597584186EF806EFC8EA530433 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-01-16 14:15:04 2AF48780D879AFC43733159CB29CD8BD 1051136 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-16 14:15:04 03B3541AE6986602CF9CB5B3AD169C33 208384 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2014-01-16 14:15:03 F9F114B2A6F876C92D317A755494F233 17142784 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-01-16 14:15:03 F8DE2F74CD4323BABBDACAADD9A39254 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-01-16 14:15:03 F7B6E341F4B1947BEC0E14EEBE3C627E 111616 ----a-w- C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-16 14:15:03 BC2C13A3B664B686DA52D558FE5502FC 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-01-16 14:15:03 AE6A2C5ECD3E96556E22F12816842F60 48640 ----a-w- C:\Windows\SysWOW64\mshtmler.dll 2014-01-16 14:15:03 AE254DBF16E3E3D7C35ED017B4B55EC6 4240384 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-01-16 14:15:03 ABDFC692D9FE43E2BA8FE6CB5A8CB95A 13312 ----a-w- C:\Windows\SysWOW64\mshta.exe 2014-01-16 14:15:03 887055A3C8DD6C87D200D11EAFDBD45B 74240 ----a-w- C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-16 14:15:03 809804D8AED97AEA96B3D4B66A4C5C70 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-01-16 14:15:03 779E142FE2159935E78C0FA2E190FF1E 610304 ----a-w- C:\Windows\SysWOW64\jscript.dll 2014-01-16 14:15:03 6EB0B7301E00F717BD68A742D1391FAF 36352 ----a-w- C:\Windows\SysWOW64\imgutil.dll 2014-01-16 14:15:03 5EC13202430A3EB68DFF44CF1FEEA2BE 61952 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-16 14:15:03 55969AADF0210A614700F89B48976F68 43008 ----a-w- C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-16 14:15:03 53FC62C51CB18C9100A7DFAF2D2A6C47 12800 ----a-w- C:\Windows\SysWOW64\msfeedssync.exe 2014-01-16 14:15:03 4D4726D1AD5ED1590A62685F92900594 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-16 14:15:03 4BCC7EB5F20840DA67943BD86AE95735 56832 ----a-w- C:\Windows\SysWOW64\pngfilt.dll 2014-01-16 14:15:03 1AFBAA54BDF637F69B8E02A5578286B0 116736 ----a-w- C:\Windows\SysWOW64\iepeers.dll 2014-01-16 14:15:03 1200D9C7DB0ADC1B8143A0A9921BF7DA 127488 ----a-w- C:\Windows\SysWOW64\occache.dll 2014-01-16 14:15:02 83F49FD1BC0A999B006D564C540C7258 86016 ----a-w- C:\Windows\SysWOW64\iesysprep.dll 2014-01-16 11:37:12 02DF0628BE8B64B84D50FBE53549AA3B 12625408 ----a-w- C:\Windows\SysWOW64\wmploc.DLL 2014-01-16 11:37:11 6C4B2E1A25841077084EB9F76FF6FFA7 11410432 ----a-w- C:\Windows\SysWOW64\wmp.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-01-16 15:05:13 DF2393DCDA345251F6CC0F59D5AE6DBF 31520 ----a-w- C:\Windows\Sysnative\nvhdap64.dll 2014-01-16 15:05:13 B99F55FC24FC321036BAD3F025DE5EB1 1515296 ----a-w- C:\Windows\Sysnative\nvhdagenco6420103.dll 2014-01-16 15:05:13 1675579489A3CC59B0A2ED3C1514E883 74016 ----a-w- C:\Windows\Sysnative\nvapo64v.dll 2014-01-16 15:05:11 D22521804E3CB0DFB4FCB11A0E2A0CFF 879392 ----a-w- C:\Windows\Sysnative\NvFBC64.dll 2014-01-16 15:05:11 CBF3BF5CFA0AB6D77AB59272605F625B 1884448 ----a-w- C:\Windows\Sysnative\nvdispco6433221.dll 2014-01-16 15:05:11 96E23AC6B6E6007CC2B42C9FE2BD4E69 3132704 ----a-w- C:\Windows\Sysnative\nvcuvid.dll 2014-01-16 15:05:11 8C0E8871D4E2FFAB20319FB4162FDA00 11554264 ----a-w- C:\Windows\Sysnative\nvopencl.dll 2014-01-16 15:05:11 55DFCF0031E7257E3DE83E219DC49E8B 882464 ----a-w- C:\Windows\Sysnative\NvIFR64.dll 2014-01-16 15:05:11 334ECC4245D7E8A648D338E325E11C57 3125024 ----a-w- C:\Windows\Sysnative\nvcuvenc.dll 2014-01-16 15:05:11 328D7B3C63E21B9B0D557484F99C177F 1511712 ----a-w- C:\Windows\Sysnative\nvdispgenco6433221.dll 2014-01-16 15:05:11 006A27B58271126AD1D58302666F1471 30372640 ----a-w- C:\Windows\Sysnative\nvoglv64.dll 2014-01-16 15:05:10 CD4EC143C035E069B40775197336DD1A 25257248 ----a-w- C:\Windows\Sysnative\nvcompiler.dll 2014-01-16 15:05:10 10A5FF3ACDBA9289381772C5535CB55C 11605752 ----a-w- C:\Windows\Sysnative\nvcuda.dll 2014-01-16 14:15:24 344DA9D196C0D98A738289BB09CE4CF6 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-01-16 14:15:05 8F7FBD0177F79727CF945ABDA657A0AC 235008 ----a-w- C:\Windows\Sysnative\elshyph.dll 2014-01-16 14:15:02 E6CB36B85BE59095337427E853A5B65A 2332160 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-01-16 14:15:02 E4A6577D74B2439974C8018AB5F1BFEA 13312 ----a-w- C:\Windows\Sysnative\msfeedssync.exe 2014-01-16 14:15:02 D31AE751B6DACAFD0D7CC99EAE9606C2 131072 ----a-w- C:\Windows\Sysnative\IEAdvpack.dll 2014-01-16 14:15:02 6F1AF8E1206E92256459E3012C20472A 942592 ----a-w- C:\Windows\Sysnative\jsIntl.dll 2014-01-16 14:15:02 5BECC17076F1806F60BB259B654FAC5C 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-01-16 14:15:02 43D9CE875F8FC8370C6BA2F74D50D01C 1394176 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-01-16 14:15:02 4399857346DD183683332921500046B1 86016 ----a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe 2014-01-16 14:15:02 3168FA85740503BAE77DB821CB3EE4FB 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-01-16 14:15:02 2EBD0C5B090125AECF017C57344C45AB 247808 ----a-w- C:\Windows\Sysnative\msls31.dll 2014-01-16 14:15:02 092F3E7D054FDF779054E29A0A0D4267 2764288 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-01-16 14:15:02 038ABC9BCC86DFF9E181D44E43E2CEBA 52224 ----a-w- C:\Windows\Sysnative\msfeedsbs.dll 2014-01-16 14:15:01 FB9459892AF2AD60BDA98F820C1A28C3 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-01-16 14:15:01 F862CD08F1AD4EE39BD506853F3C6103 16284 ----a-w- C:\Windows\Sysnative\ieuinit.inf 2014-01-16 14:15:01 E36FDC470352C8F351F31959619CADD8 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-01-16 14:15:01 D6C88A6094D1FDAC56A186BBD7F06357 40448 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-01-16 14:15:01 D36A88D22B843C3812B501434E5A67A0 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-01-16 14:15:01 CE8831D2DCB5803A4CBC8EDCCBBC2A05 77312 ----a-w- C:\Windows\Sysnative\tdc.ocx 2014-01-16 14:15:01 C92173481A58935BE15172079CF122B8 235520 ----a-w- C:\Windows\Sysnative\url.dll 2014-01-16 14:15:01 C70F72684CDCF9BB142F50F98BB1DD9C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-01-16 14:15:01 C6ECA2F7A1B189025171E6A29F2605AA 453120 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-01-16 14:15:01 C17139EAF939964142C7A1AEEE02DC81 616104 ----a-w- C:\Windows\Sysnative\ieapfltr.dat 2014-01-16 14:15:01 B99C7CC6ED6917E3035A12171F40D240 5765120 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-01-16 14:15:01 95951E6A277F78FA13A85F2F408F4C0B 12995584 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-01-16 14:15:01 5FAC15F872026BBC31C11D3A32B84624 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-01-16 14:15:01 5141B67F14E2B6CBB6ADF851ABE364A5 90112 ----a-w- C:\Windows\Sysnative\SetIEInstalledDate.exe 2014-01-16 14:15:01 3A4FD19F13F8809BA08E9F76C0E38832 413696 ----a-w- C:\Windows\Sysnative\html.iec 2014-01-16 14:15:01 2405D24AA28CCC4CC7E0CC0AE008746F 48640 ----a-w- C:\Windows\Sysnative\mshtmler.dll 2014-01-16 14:15:01 0FBEBD36FEFFEE5AF25FDAEE5E35EE99 105984 ----a-w- C:\Windows\Sysnative\iesysprep.dll 2014-01-16 14:15:01 0A9D5716CB1F3AFA73703F39647BB8C2 81408 ----a-w- C:\Windows\Sysnative\icardie.dll 2014-01-16 14:15:01 05018A4E76F1636EFBB7DCB76900872A 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-01-16 14:15:01 0134898497B6C6CD50F7FC5DE85712A6 296960 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-01-16 14:15:00 FD61D51199F3FC9EB0023FBF405EAAD0 147968 ----a-w- C:\Windows\Sysnative\occache.dll 2014-01-16 14:15:00 F00AE7B953ABEF1B53FBBA187DFC8238 243200 ----a-w- C:\Windows\Sysnative\webcheck.dll 2014-01-16 14:15:00 EE10AB99A480875E012CA339EC48F02B 1228800 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2014-01-16 14:15:00 E949B344680691F255C0E662D4B5BFF1 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-01-16 14:15:00 D233E1A32CE6AF918C9DE1BC44AFEB2A 23212032 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-01-16 14:15:00 CC84F4E36AA96810AD766C88DD657ADB 626176 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-01-16 14:15:00 A8C830CABD7640EE8E6F0F1019F91E83 548352 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-01-16 14:15:00 9675B272086CF5D22B83B541FAA8D4EA 30208 ----a-w- C:\Windows\Sysnative\licmgr10.dll 2014-01-16 14:15:00 77FBE2E014EFB93FD037FA33AB8C7D6E 263376 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-01-16 14:15:00 68899208A26E4522D25DBA87FF2E98D1 84992 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-01-16 14:15:00 612DC699EBF0AA1AAA065898D33B553A 1993728 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-01-16 14:15:00 5BBDBE5EBB49EA7C76A2EE7490A45D68 101376 ----a-w- C:\Windows\Sysnative\inseng.dll 2014-01-16 14:15:00 5A54ED24D5D42102A64904809215E0DC 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-01-16 14:15:00 46FD16F9B1924A2EA8CD5C6716CC654F 167424 ----a-w- C:\Windows\Sysnative\iexpress.exe 2014-01-16 14:15:00 1EA6500C25A80E8BDB65099C509AF993 143872 ----a-w- C:\Windows\Sysnative\wextract.exe 2014-01-16 14:14:59 F34C20D099CF94A606A2B5B0C668B570 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-01-16 14:14:59 E70D4270C43CE6C46841B684315B9EFF 62464 ----a-w- C:\Windows\Sysnative\pngfilt.dll 2014-01-16 14:14:59 BB6DEAFAC5F0AAEC37FEAF3F3AA48347 774144 ----a-w- C:\Windows\Sysnative\jscript.dll 2014-01-16 14:14:59 ADA5C3D49A12CED9F07913DC00E547A8 48128 ----a-w- C:\Windows\Sysnative\imgutil.dll 2014-01-16 14:14:59 9870EC900829595D191BB03C6C48B479 83968 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-01-16 14:14:59 95828D670CFD3B16EE188168E083C3C5 13824 ----a-w- C:\Windows\Sysnative\mshta.exe 2014-01-16 14:14:59 45152BA21450811F4619C9C1790E7353 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-01-16 14:14:59 3AFA03119583647136C49B80DAD38F19 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-01-16 14:14:59 1FCBE949A67939ADEAE7279E423AA684 135680 ----a-w- C:\Windows\Sysnative\iepeers.dll 2014-01-16 12:03:16 F2BF71FCEAB8FB8A691408C478E2FF4C 3156480 ----a-w- C:\Windows\Sysnative\win32k.sys 2014-01-16 11:37:12 AB272BBFB05A8585C3405EFA9F605774 12625920 ----a-w- C:\Windows\Sysnative\wmploc.DLL 2014-01-16 11:37:10 8CBBB27369F9F07BC5E874E750EAF9D0 14631424 ----a-w- C:\Windows\Sysnative\wmp.dll ====== C:\Windows\Sysnative\drivers ===== 2014-01-16 15:05:16 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\Windows\Sysnative\drivers\nvvad64v.sys 2014-01-16 15:05:13 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\Windows\Sysnative\drivers\nvhda64v.sys 2014-01-16 15:05:11 0218E1CE8F7B5D404980192B9112D03A 12645664 ----a-w- C:\Windows\Sysnative\drivers\nvlddmkm.sys 2014-01-16 12:31:33 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2014-01-16 12:03:20 DCA68B0943D6FA415F0C56C92158A83A 99840 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-01-16 12:03:20 18A85013A3E0F7E1755365D287443965 53248 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-01-16 12:03:19 FFA06EF43987ED0DD42AD59B260C0C78 7808 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-01-16 12:03:19 DD253AFC3BC6CBA412342DE60C3647F3 30720 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-01-16 12:03:19 8D1196CFBB223621F2C67D45710F25BA 343040 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-01-16 12:03:19 765A92D428A8DB88B960DA5A8D6089DC 25600 ----a-w- C:\Windows\Sysnative\drivers\usbohci.sys 2014-01-16 12:03:19 12FEB33791920678F8433701C822BCFD 325120 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-01-16 12:01:29 3555BA97171CD153118F73FDCCC8BFDE 376768 ----a-w- C:\Windows\Sysnative\drivers\netio.sys ====== C:\Windows\Tasks ====== 2014-01-16 12:51:10 415F9C52A56AE58DBA1EB206FE3F1D00 3186 ----a-w- C:\Windows\Sysnative\Tasks\P4GIntlCtrl ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-01-16 13:41:40 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-01-16 12:06:16 -------- d-----w- C:\PROGRA~2\Microsoft XNA ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2014-01-16 12:31:13 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Programs ====== C:\Users\Gebruiker ====== 2014-01-16 13:40:51 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Gebruiker\Desktop\RSITx64.exe ====== C: exe-files == 2014-01-16 16:16:44 B96D9ACD9D4AAC1F231D66AB8D02AB17 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1453884697-2928237095-1140060775-1001\$IFODT42.exe 2014-01-16 15:48:56 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\$Recycle.Bin\S-1-5-21-1453884697-2928237095-1140060775-1001\$RFODT42.exe 2014-01-16 15:11:34 900B47792F30734A2805395EBEBB705E 1194784 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvxdsync.exe 2014-01-16 15:11:34 1E00A0A539E7C30DD418E774428BA35B 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\setup.exe 2014-01-16 15:11:32 B7973C405247C5A44BA46B12A4B7AEEA 922912 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvvsvc.exe 2014-01-16 15:11:31 556A74975E52F0853FCE02C05F83F9FF 2448160 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\NvTray.exe 2014-01-16 15:11:30 8E3B16C9BADBEAC35F92F4553E38B171 63264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvSmartMaxapp64.exe 2014-01-16 15:11:30 3C7224A0D1F629EB9B2BC2A79D86CAAE 63264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvSmartMaxapp.exe 2014-01-16 15:11:23 0FCBAB692485A4B867AC5EF896A2ED55 6866208 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{ACCFD5AB-89BD-46FC-9694-02126086715B}\nvcplui.exe 2014-01-16 15:10:28 1E00A0A539E7C30DD418E774428BA35B 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{CBB17961-0EDC-40A1-91E0-396188DE45EC}\setup.exe 2014-01-16 15:08:36 AB3ADA6637B288371093B16BFBC9651A 266633424 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\332.21-notebook-win8-win7-64bit-international-whql-g.exe 2014-01-16 15:08:35 A2974CA40BC4457255E1B60F06BCC50C 30502520 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\GeForce_Experience_Update_v1.8.1.0.exe 2014-01-16 15:06:01 8629990396B6FA011E27B46ED6AC4BDB 808224 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\nvStInst.exe 2014-01-16 15:05:40 B942824E4901D50834EEB441BE98AB9A 1785120 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\nvspcaps64.exe 2014-01-16 15:05:40 94397226B4D18C9E62DC943A9CF6A487 1475360 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\nvspcaps.exe 2014-01-16 15:05:40 041DADF180B8175D06CBB6C442F4D960 540448 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShadowPlay.{FD5CF741-FCEF-4B03-9BA5-90869B9B4C85}\DXSETUP.exe 2014-01-16 15:05:36 336DF94267FC40D147FC3AC8798DFA73 87328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.LEDVisualizer.{72BD2562-2CB9-4A92-8CA6-4D507C7F5581}\NvLedServiceHost.exe 2014-01-16 15:05:35 4A8B43D324521AEFCA813434B8AED3C2 127264 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.LEDVisualizer.{72BD2562-2CB9-4A92-8CA6-4D507C7F5581}\NvLedVisualizer.exe 2014-01-16 15:05:25 62FE81A76C39AE1E37B9B1369B0B22CB 1015584 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{1240D026-2977-4C4F-A856-C5892C156182}\GFExperience.exe 2014-01-16 15:05:23 031A21DE7D208C6A2BAF75BE1B51426C 596768 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{1240D026-2977-4C4F-A856-C5892C156182}\7z.exe 2014-01-16 15:05:22 6AA2CC058B79B3C73ECB0C008F867DB0 636232 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\SteamLauncher\NVIDIA.SteamLauncher.exe 2014-01-16 15:05:20 3C447C228DEAC197E5D245474C404DB3 3063072 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\x86\server\nvstreamer.exe 2014-01-16 15:05:20 0F4FE8097C56739DA9A8BD71DF868981 14658848 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\x86\server\nvstreamsvc.exe 2014-01-16 15:05:18 68DE8D996D8FF628AB6B3D422035F862 15129376 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\amd64\server\nvstreamsvc.exe 2014-01-16 15:05:18 0CD3924E6EA85D62E4883796275C21FB 3960096 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\GFExperience.NvStreamSrv.{8BDBBF74-C368-4759-8A5C-4241E3A28133}\amd64\server\nvstreamer.exe 2014-01-16 15:05:17 A0012C1D9B8648C20C00202418B9D02F 2279712 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Update.Core.{B90EFFB4-C24B-4690-A30B-8A8278521F1C}\NvBackend.exe 2014-01-16 15:05:17 1F899DC290F02F7F0482F610C2873D61 194888 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Update.Core.{B90EFFB4-C24B-4690-A30B-8A8278521F1C}\WLMerger.exe 2014-01-16 15:05:13 903A40C958D471F9D30D29FA6D2800A4 1494304 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Network.Service.{745F2990-9A2B-4D3C-891B-90FE26E294C5}\NVNetworkService.exe 2014-01-16 15:05:13 82397849C695A1D86DE86AEE488BC9DA 23639304 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.3DVision.{415321A8-A5C4-4C61-9319-30E4AA9C6157}\3DVision_332.21.exe 2014-01-16 15:05:10 1ED211177754B06F6A1B923B52516FA6 74267360 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{EBD3978D-5FEE-47C9-8811-6C05A4B86E33}\NvCplSetupInt.exe 2014-01-16 15:05:09 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{EBD3978D-5FEE-47C9-8811-6C05A4B86E33}\dbInstaller.exe 2014-01-16 15:05:09 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe 2014-01-16 15:03:15 7495C8A57D0494D4371CD06A496B54CD 412960 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{8B89A600-61C6-4FE2-BFF7-B13663A2D22B}\setup.exe 2014-01-16 14:22:35 CC6CC1E54EE9EE46ACD124BC715B4D9A 486176 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nvTaskBar.exe 2014-01-16 14:22:35 8883E5C1820810403F610BE9A5962828 2747680 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nwiz.exe 2014-01-16 14:22:35 7495C8A57D0494D4371CD06A496B54CD 412960 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\setup.exe 2014-01-16 14:22:35 68DE8D996D8FF628AB6B3D422035F862 15129376 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\nvstreamsvc.exe 2014-01-16 14:22:35 3C447C228DEAC197E5D245474C404DB3 3063072 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\nvstreamer.exe 2014-01-16 14:22:35 1F899DC290F02F7F0482F610C2873D61 194888 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Update.Core\WLMerger.exe 2014-01-16 14:22:35 0F4FE8097C56739DA9A8BD71DF868981 14658848 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\x86\server\nvstreamsvc.exe 2014-01-16 14:22:35 0CD3924E6EA85D62E4883796275C21FB 3960096 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\amd64\server\nvstreamer.exe 2014-01-16 14:22:34 B942824E4901D50834EEB441BE98AB9A 1785120 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\nvspcaps64.exe 2014-01-16 14:22:34 94397226B4D18C9E62DC943A9CF6A487 1475360 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\nvspcaps.exe 2014-01-16 14:22:34 903A40C958D471F9D30D29FA6D2800A4 1494304 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Network.Service\NVNetworkService.exe 2014-01-16 14:22:34 6AA2CC058B79B3C73ECB0C008F867DB0 636232 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience.NvStreamSrv\SteamLauncher\NVIDIA.SteamLauncher.exe 2014-01-16 14:22:34 4A8B43D324521AEFCA813434B8AED3C2 127264 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\LEDVisualizer\NvLedVisualizer.exe 2014-01-16 14:22:34 336DF94267FC40D147FC3AC8798DFA73 87328 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\LEDVisualizer\NvLedServiceHost.exe 2014-01-16 14:22:26 1ED211177754B06F6A1B923B52516FA6 74267360 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.Driver\NvCplSetupInt.exe 2014-01-16 14:22:25 E84A135B0CB2CACA91097BE598B2A937 802080 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.NView\nvAppBar.exe 2014-01-16 14:22:25 AA24F8E20A16B9D9DFFC44A8158A2D6A 250144 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Display.Driver\dbInstaller.exe 2014-01-16 14:22:25 A0012C1D9B8648C20C00202418B9D02F 2279712 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\Update.Core\NvBackend.exe 2014-01-16 14:22:25 62FE81A76C39AE1E37B9B1369B0B22CB 1015584 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience\GFExperience.exe 2014-01-16 14:22:25 53406E9988306CBD4537677C5336ABA4 889416 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\MS.NET\dotNetFx40_Full_setup.exe 2014-01-16 14:22:25 041DADF180B8175D06CBB6C442F4D960 540448 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\ShadowPlay\DXSETUP.exe 2014-01-16 14:22:25 031A21DE7D208C6A2BAF75BE1B51426C 596768 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\GFExperience\7z.exe 2014-01-16 14:22:23 82397849C695A1D86DE86AEE488BC9DA 23639304 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVision\3DVision_332.21.exe 2014-01-16 14:15:05 ED45D1C3FDA215374FBCFC161A57AA80 467456 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-01-16 14:15:05 CC02FE4520CA886508069245D9A6962F 222720 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-01-16 14:15:05 C8A8321292A459B0A17FB39A782A5C74 806096 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-01-16 14:15:03 7F7F391491C315A4A72EFCAC0D34FA93 25600 ----a-w- C:\Program Files (x86)\Internet Explorer\ExtExport.exe 2014-01-16 14:15:02 0685765C0CBE095BA0C6C8790BAE21EF 804560 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-01-16 14:15:01 D68007F924B9F387AA7C76F48D0A260A 223232 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-01-16 14:15:01 70D721CC971A9EFFCF7845CEFBB02704 480256 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-01-16 14:15:01 41F922D6A794C0F8425C8436D7077C84 359632 ----a-w- C:\Program Files\Internet Explorer\iediagcmd.exe 2014-01-16 13:41:41 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruiker.exe 2014-01-16 12:54:23 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Temp\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe 2014-01-16 12:52:45 9911EF198C1A01F11D8D6F777F9A9261 1070088 ----a-w- C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXYKSRKM\install_flashplayer12x32axau_gtba_chra_dy_aaa_aih.exe 2014-01-16 12:30:53 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXYKSRKM\mbam-setup-1.75.0.1300.exe 2014-01-16 11:37:13 D21DD7BFC81C8623DE48EBB17133D59C 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2014-01-16 11:37:13 9AED8E824CF5FAAB67957EDBC5512060 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2014-01-16 11:30:11 CA29059459C98937578B0F6B45E56E0F 3110568 ----a-w- C:\Users\Gebruiker\AppData\Local\NVIDIA\NvBackend\Packages\000056e3\dao.17646152.exe === C: other files == 2014-01-16 15:05:16 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{B497EE22-DE60-4ADA-A83D-DF18077CBF6F}\nvvad64v.sys 2014-01-16 15:05:15 DAC9726D9C90631D6A1C0ECAA0226021 34080 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{B497EE22-DE60-4ADA-A83D-DF18077CBF6F}\nvvad32v.sys 2014-01-16 15:05:13 F4992A26D629288ADBBDC3A715629FA1 163104 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda64.sys 2014-01-16 15:05:13 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda64v.sys 2014-01-16 15:05:13 9F8EE4948B7ADD9D12F778F61A2758A4 162592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda32v.sys 2014-01-16 15:05:13 47FEB587AAE06F6717FCABF8BCF184FD 129312 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{381A26B8-1FF8-4E2C-8309-A805F4DF8F20}\nvhda32.sys 2014-01-16 14:23:05 F4992A26D629288ADBBDC3A715629FA1 163104 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda64.sys 2014-01-16 14:23:05 E366A5681C50785D4ED04FCFD65C3415 197408 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda64v.sys 2014-01-16 14:23:05 DAC9726D9C90631D6A1C0ECAA0226021 34080 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NvVAD\nvvad32v.sys 2014-01-16 14:23:05 C7C75E4D199802EFCE0BEC2F6F823E31 451872 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb64.sys 2014-01-16 14:23:05 9F8EE4948B7ADD9D12F778F61A2758A4 162592 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda32v.sys 2014-01-16 14:23:05 47FEB587AAE06F6717FCABF8BCF184FD 129312 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\HDAudio\nvhda32.sys 2014-01-16 14:23:05 09216A70CC364D0974F606F6F2109210 39200 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NvVAD\nvvad64v.sys 2014-01-16 14:23:05 0819597CF50E316819493C7A832EDAEC 435232 ----a-w- C:\NVIDIA\DisplayDriver\332.21\Win8_WinVista_Win7_64\International\NV3DVisionUSB.Driver\nvstusb32.sys 2014-01-16 12:53:10 AB51E1F08C8E789D6C9E8B94D15BE9A9 340432 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_59849.sys 2014-01-16 12:53:10 000D82CC258E2D341605A6F350C4D1E6 606672 ----a-w- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1453884697-2928237095-1140060775-1001\Software\Microsoft\Windows\CurrentVersion\Run] "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Steam"="D:\Program Files\Steam\Steam.exe -silent" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "EA Core"="C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HControlUser"="C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe" "ATKOSD2"="C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" "ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "MDS_Menu"="C:\Program Files (x86)\Cyberlink\MediaShowEspresso\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\MediaShowEspresso UpdateWithCreateOnce Software\CyberLink\MediaShow Espresso\5.0" "PDVD9LanguageShortcut"="C:\Program Files (x86)\Cyberlink\PowerDVD9\Language\Language.exe" "RemoteControl9"="C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5" "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0" "UpdatePDRShortCut"="C:\Program Files (x86)\Cyberlink\PowerDirector\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\PowerDirector UpdateWithCreateOnce Software\CyberLink\PowerDirector\7.0" "UpdatePSTShortCut"="C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Cyberlink\DVD Suite UpdateWithCreateOnce Software\CyberLink\PowerStarter" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "WinampAgent"="C:\Program Files (x86)\Winamp\winampa.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Spotify"="C:\Users\Gebruiker\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\Gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Steam"="D:\Program Files\Steam\Steam.exe -silent" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "EA Core"="C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "EeeStorageBackup"="C:\Program Files (x86)\ASUS\Asus WebStorage\BackupService.exe" "AmIcoSinglun64"="C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" "ETDWare"="C:\Program Files\Elantech\ETDCtrl.exe" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" "hkey"="HKLM" "item"="Adobe Reader Speed Launcher" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ADSMTray] "command"="C:\\Program Files (x86)\\ASUS\\ASUS Data Security Manager\\ADSMTray.exe" "hkey"="HKLM" "item"="ADSMTray" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUS Screen Saver Protector] "command"="C:\\Windows\\AsScrPro.exe" "hkey"="HKLM" "item"="ASUS Screen Saver Protector" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer] "command"="\"C:\\Program Files (x86)\\CyberLink\\Power2Go\\CLMLSvc.exe\"" "hkey"="HKLM" "item"="CLMLServer" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISW] "command"="C:\\Program Files\\CheckPoint\\ZAForceField\\ForceField.exe /icon=\"hidden\"" "hkey"="HKLM" "item"="ISW" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s" "hkey"="HKLM" "item"="RtHDVCpl" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14-12-2013 00:52] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\ACMON" [C:\Program Files (x86)\ASUS\Splendid\ACMON.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\ASPG" [C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe] "C:\Windows\SysNative\tasks\ASUS Live Update" [C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe] "C:\Windows\SysNative\tasks\ASUS P4G" [C:\Program Files\P4G\BatteryLife.exe] "C:\Windows\SysNative\tasks\ASUS SmartLogon Console Sensor" [C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe] "C:\Windows\SysNative\tasks\ASUSControlDeck" [C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe"] "C:\Windows\SysNative\tasks\P4G Sidebar" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\P4GIntlCtrl" [C:\Program Files\P4G\IntlCtrl.exe] "C:\Windows\SysNative\tasks\WC3" [C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe] "C:\Windows\SysNative\tasks\{07ECAF20-A744-435A-AE62-C44D731143C3}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\{5325319D-9CFC-442D-B104-BE3D74AD6ACD}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\{677916E2-546F-46A6-92EE-615BB0FC3AF8}" [C:\Program Files (x86)\THQ\Company of Heroes\RelicCOH.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF" [25-11-2013 15:28] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx[28-11-2013 14:56] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="Google" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=42 folders=17 7508763 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\Gebruiker\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on do 16-01-2014 at 18:08:29,47 ======================
  12. Dit is het log bestand: Logfile of random's system information tool 1.09 (written by random/random) Run by Gebruiker at 2014-01-16 14:41:40 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 18 GB (15%) free of 119 GB Total RAM: 4095 MB (49% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:42:27, on 16-1-2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16750) Boot mode: Normal Running processes: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files\trend micro\Gebruiker.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: ZoneAlarm Security - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - (no file) O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: AutorunsDisabled O4 - Global Startup: AutorunsDisabled O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Mystery%20P.I.%20-%20The%20Curious%20Case%20of%20Counterfeit%20Cove/Images/stg_drm.ocx O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files%20(x86)/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing) O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) - Unknown owner - C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 11841 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch "C:\Windows\system32\nvvsvc.exe" "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup "C:\Program Files\HitmanPro\hmpsched.exe" C:\Windows\system32\svchost.exe -k NetworkService "C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe" "C:\Program Files\ATKGFNEX\GFNEXSrv.exe" C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" "C:\Program Files\Bonjour\mDNSResponder.exe" C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe" "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\diMaster.dll" /prefetch:1 "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" "C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe" "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL mmsys.cpl "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" WLIDSvcM.exe 2560 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe /Embedding "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\Windows\system32\nvvsvc.exe -session -first "taskhost.exe" "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray "C:\Windows\system32\Dwm.exe" C:\Windows\Explorer.EXE "C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe" "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp "C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe" /c /a /s UserSession2 \??\C:\Windows\system32\conhost.exe "-1483280548-198802752316634342191495978215-155972201320284151012048640709-145506585 taskeng.exe {4FC7BF28-F9D3-4EAA-9CC6-52EB63A109E1} "C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe" "C:\Program Files\P4G\BatteryLife.exe" "C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe" "C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe" "C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" "C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe" "C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe" "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1 ATKOSD.exe KBFiltr.exe WDC.exe "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe" "C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe" "C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" "C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe" "C:\Program Files\Internet Explorer\iexplore.exe" https://get3.adobe.com/nl/flashplayer/update/activex "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4624 CREDAT:267521 /prefetch:2 C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe -Embedding C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true C:\Windows\system32\svchost.exe -k SDRSVC "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4624 CREDAT:988458 /prefetch:2 C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe "C:\Users\Gebruiker\Desktop\RSITx64.exe" ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll [2013-05-31 509776] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL [2013-04-09 387040] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-22 463272] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Aanmeldhulp voor Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] ZoneAlarm Security Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-22 171944] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {91da5e8a-3318-4f8c-b67e-5964de3ab546} - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll [2013-05-31 509776] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [2013-07-27 1028896] "NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2013-11-29 2273056] "ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2013-11-29 1096480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [2009-12-08 3058304] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe /icon=hidden [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-29 8123936] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "HControlUser"=C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [2009-06-19 105016] "ATKOSD2"=C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [2009-10-09 6937216] "ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [2009-08-20 170624] "NPSStartup"= [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro35Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-01-16 14:41:40 ----D---- C:\rsit 2014-01-16 14:41:40 ----D---- C:\Program Files\trend micro 2014-01-16 13:32:00 ----D---- C:\Users\Gebruiker\AppData\Roaming\Malwarebytes 2014-01-16 13:31:34 ----D---- C:\ProgramData\Malwarebytes 2014-01-16 13:31:33 ----A---- C:\Windows\system32\drivers\mbam.sys 2014-01-16 13:31:32 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-16 13:06:16 ----D---- C:\Program Files (x86)\Microsoft XNA 2014-01-16 13:03:41 ----D---- C:\Program Files\CCleaner 2014-01-16 12:37:12 ----A---- C:\Windows\SYSWOW64\wmploc.DLL 2014-01-16 12:37:12 ----A---- C:\Windows\system32\wmploc.DLL 2014-01-16 12:37:11 ----A---- C:\Windows\SYSWOW64\wmp.dll 2014-01-16 12:37:10 ----A---- C:\Windows\system32\wmp.dll 2014-01-16 12:34:19 ----A---- C:\Windows\SYSWOW64\ieui.dll 2014-01-16 12:34:19 ----A---- C:\Windows\system32\ieui.dll 2014-01-16 12:34:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iesysprep.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2014-01-16 12:34:17 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iesysprep.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iesetup.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\iernonce.dll 2014-01-16 12:34:17 ----A---- C:\Windows\system32\ie4uinit.exe 2014-01-16 12:34:16 ----A---- C:\Windows\system32\iertutil.dll 2014-01-16 12:34:15 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2014-01-16 12:34:15 ----A---- C:\Windows\SYSWOW64\jscript.dll 2014-01-16 12:34:15 ----A---- C:\Windows\system32\msfeeds.dll 2014-01-16 12:34:15 ----A---- C:\Windows\system32\jscript.dll 2014-01-16 12:34:14 ----A---- C:\Windows\system32\jscript9.dll 2014-01-16 12:34:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2014-01-16 12:34:13 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2014-01-16 12:34:13 ----A---- C:\Windows\system32\urlmon.dll 2014-01-16 12:34:11 ----A---- C:\Windows\SYSWOW64\wininet.dll 2014-01-16 12:34:11 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2014-01-16 12:34:11 ----A---- C:\Windows\system32\jsproxy.dll 2014-01-16 12:34:10 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2014-01-16 12:34:10 ----A---- C:\Windows\system32\wininet.dll 2014-01-16 12:34:08 ----A---- C:\Windows\system32\ieframe.dll 2014-01-16 12:34:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-01-16 12:34:05 ----A---- C:\Windows\system32\mshtml.dll ======List of files/folders modified in the last 1 month====== 2014-01-16 14:41:40 ----RD---- C:\Program Files 2014-01-16 14:41:26 ----D---- C:\Windows\Temp 2014-01-16 14:07:30 ----D---- C:\Windows\system32\config 2014-01-16 13:55:11 ----D---- C:\Windows\System32 2014-01-16 13:55:11 ----D---- C:\Windows\inf 2014-01-16 13:55:11 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-01-16 13:53:23 ----SHD---- C:\Windows\Installer 2014-01-16 13:51:16 ----SHD---- C:\System Volume Information 2014-01-16 13:51:10 ----D---- C:\Windows\system32\Tasks 2014-01-16 13:49:07 ----D---- C:\Windows\winsxs 2014-01-16 13:48:00 ----D---- C:\Windows\Panther 2014-01-16 13:47:26 ----D---- C:\Windows 2014-01-16 13:47:14 ----D---- C:\ProgramData\NVIDIA 2014-01-16 13:42:00 ----D---- C:\Windows\SysWOW64 2014-01-16 13:42:00 ----D---- C:\Program Files\Windows Media Player 2014-01-16 13:42:00 ----D---- C:\Program Files (x86)\Windows Media Player 2014-01-16 13:41:59 ----D---- C:\Program Files (x86)\Internet Explorer 2014-01-16 13:41:57 ----D---- C:\Program Files\Internet Explorer 2014-01-16 13:41:56 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-01-16 13:41:56 ----D---- C:\Windows\system32\nl-NL 2014-01-16 13:41:47 ----D---- C:\Windows\system32\DriverStore 2014-01-16 13:41:46 ----D---- C:\Windows\system32\drivers 2014-01-16 13:31:34 ----HD---- C:\ProgramData 2014-01-16 13:31:32 ----RD---- C:\Program Files (x86) 2014-01-16 13:25:15 ----SD---- C:\Users\Gebruiker\AppData\Roaming\Microsoft 2014-01-16 13:16:10 ----D---- C:\Users\Gebruiker\AppData\Roaming\Winamp 2014-01-16 13:16:07 ----D---- C:\Windows\Minidump 2014-01-16 13:16:07 ----D---- C:\Windows\Logs 2014-01-16 13:16:07 ----D---- C:\Windows\debug 2014-01-16 13:06:50 ----RSD---- C:\Windows\assembly 2014-01-16 13:02:56 ----D---- C:\Windows\system32\catroot 2014-01-16 13:02:52 ----D---- C:\Windows\system32\catroot2 2014-01-16 12:36:36 ----D---- C:\ProgramData\Microsoft Help ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2009-12-08 35384] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-06 408600] R0 ***laby;***laby; C:\Windows\system32\DRIVERS\***laby.sys [2009-06-18 15928] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 RapportKE64;RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [2013-10-25 317808] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888] R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [2013-05-21 493656] R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [2013-05-23 1139800] R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20140110.001\BHDrvx64.sys [2014-01-10 1526488] R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [2013-04-16 169048] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-11-25 484952] R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20140115.001\IDSvia64.sys [2014-01-15 521944] R1 RapportCerberus_59849;RapportCerberus_59849; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [2014-01-16 606672] R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-10-25 284176] R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-10-25 399312] R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [2013-03-05 36952] R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [2013-03-05 224416] R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [2013-04-25 433752] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-11-25 137648] R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-09 140800] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-09-29 2005024] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-11-13 67072] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928] R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928] R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140115.032\ENG64.SYS [2014-01-16 126040] R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140115.032\EX64.SYS [2014-01-16 2099288] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-14 196384] R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-10-30 39200] R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400] R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [2013-05-16 796760] R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-07-21 177312] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] R4 RapportCerberus_56758;RapportCerberus_56758; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_56758.sys [2013-08-25 589872] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-22 48488] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832] S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-02-15 52736] S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008] R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536] R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2013-11-25 109352] R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [2013-05-21 144368] R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-11-29 1370912] R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-11-29 15128352] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-11-11 922912] R2 OberonGameConsoleService;Oberon Media Game Console service; C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe [2009-09-15 44312] R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-10-25 1444120] R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-11-11 414496] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096] S2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 359552] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-02-07 161384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-14 257416] S3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280] S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2013-05-31 641352] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152] S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-07 569768] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-06 1255736] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] -----------------EOF-----------------
  13. Op een notebook die wij hebben (windows 7 64 bit) staat nogal wat spyware zoals Conduite en Rocketfuel. Kunnen jullie helpen om dat te verwijderen? Bij voorbaat onze dank.
  14. Heel erg bedankt voor de hulp. De pc start weer een stuk vlugger op dan eerst.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.