Ga naar inhoud

rossi925

Lid
  • Items

    144
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door rossi925

  1. # AdwCleaner v3.008 - Report created 18/10/2013 at 16:47:44

    # Updated 17/10/2013 by Xplode

    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Username : Rossi925 - ROSSI925-PC

    # Running from : C:\Users\Rossi925\Desktop\adwcleaner.exe

    # Option : Scan

    ***** [ Services ] *****

    ***** [ Files / Folders ] *****

    File Found : C:\Windows\System32\roboot64.exe

    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****

    Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}

    Key Found : HKCU\Software\AppDataLow\Software\lyricspal

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}

    Key Found : HKCU\Software\Softonic

    Key Found : HKCU\Software\SpeedyPC Software

    Key Found : HKCU\Software\Webplayer

    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}

    Key Found : [x64] HKCU\Software\Softonic

    Key Found : [x64] HKCU\Software\SpeedyPC Software

    Key Found : [x64] HKCU\Software\Webplayer

    Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}

    Key Found : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}

    Key Found : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}

    Key Found : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}

    Key Found : HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}

    Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}

    Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho

    Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS

    Key Found : HKLM\Software\SpeedyPC Software

    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}

    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}

    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}

    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}

    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}

    Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [AppsHat]

    Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [discountfinder@moneymillionaire.com]

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16720

    Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=WDCXWD7500BPKT-80PK4T0_WD-WX91A71W5075W5075&ts=1370813861

    Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=WDCXWD7500BPKT-80PK4T0_WD-WX91A71W5075W5075&ts=1370813861

    -\\ Mozilla Firefox v

    [ File : C:\Users\Rossi925\AppData\Roaming\Mozilla\Firefox\Profiles\[ofr2][opt]rs0\prefs.js ]

    -\\ Google Chrome v30.0.1599.69

    [ File : C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Found : homepage

    Found : urls_to_restore_on_startup

    Found : homepage

    Found : urls_to_restore_on_startup

    Found : homepage

    Found : urls_to_restore_on_startup

    *************************

    AdwCleaner[R0].txt - [7200 octets] - [20/08/2013 17:54:42]

    AdwCleaner[R1].txt - [3334 octets] - [18/10/2013 16:47:44]

    AdwCleaner[s0].txt - [6632 octets] - [20/08/2013 17:55:10]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [3454 octets] ##########

  2. Malwarebytes Anti-Malware 1.75.0.1300

    www.malwarebytes.org

    Databaseversie: v2013.10.18.07

    Windows 7 Service Pack 1 x64 NTFS

    Internet Explorer 10.0.9200.16721

    Rossi925 :: ROSSI925-PC [administrator]

    18/10/2013 16:31:15

    mbam-log-2013-10-18 (16-31-15).txt

    Scan type: Snelle scan

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 252637

    Verstreken tijd: 11 minuut/minuten, 7 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 3

    HKCR\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB} (PUP.Optional.MiniBar.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerwaarden gedetecteerd: 1

    HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {E9F44F0F-B06C-48DD-90FD-DBC3D2BE70A3} -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 6

    C:\Users\Rossi925\AppData\Local\Temp\uttE264.tmp.exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Rossi925\Downloads\4shared_Desktop_4.0.3.1.exe (PUP.Optional.4Shared) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Rossi925\Downloads\Adlock10_downloader_by_Adlock10.exe (PUP.Optional.Somoto) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Rossi925\Downloads\SoftonicDownloader_voor_easy-graphic-converter.exe (PUP.Optional.Softonic) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Rossi925\Local Settings\Temporary Internet Files\Content.IE5\OS63TGKH\spstub[1].exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Rossi925\Local Settings\Temporary Internet Files\Content.IE5\UW67F8SF\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)

  3. Logfile of random's system information tool 1.09 (written by random/random)

    Run by Rossi925 at 2013-10-18 13:16:02

    Microsoft Windows 7 Home Premium Service Pack 1

    System drive C: has 89 GB (31%) free of 286 GB

    Total RAM: 12265 MB (72% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 13:16:05, on 18/10/2013

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v10.0 (10.00.9200.16720)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe

    C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe

    C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    C:\Program Files (x86)\Steam\Steam.exe

    C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

    C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe

    C:\Program Files (x86)\Polar\WebSync\WebSync.exe

    C:\Windows\AsScrPro.exe

    C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe

    C:\ExpressGateUtil\VAWinAgent.exe

    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

    C:\Program Files (x86)\Gaming Mouse\Tray.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe

    C:\Program Files (x86)\AVG\AVG2013\avgui.exe

    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\trend micro\Rossi925.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: WsSVRIEHelper - {54F73992-6549-4369-9A0D-84FD310A464A} - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll

    O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL

    O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"

    O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

    O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S

    O4 - HKLM\..\Run: [Gaming Mouse Hid] "C:\Program Files (x86)\Gaming Mouse\hid.exe"

    O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe

    O4 - HKLM\..\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r

    O4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXE

    O4 - HKLM\..\Run: [CPMonitor] "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"

    O4 - HKLM\..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe

    O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"

    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

    O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    O4 - HKLM\..\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"

    O4 - HKLM\..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    O4 - HKLM\..\Run: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe

    O4 - HKLM\..\Run: [browserPlugInHelper] C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY

    O4 - HKLM\..\RunOnce: [spUninstallCleanUp] REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f

    O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent

    O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    O4 - HKCU\..\Run: [AppsHat] C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe

    O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Rossi925\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

    O4 - HKCU\..\Run: [Apps Hat] C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-21-209168772-1577477127-873989120-1004\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')

    O4 - HKUS\S-1-5-21-209168772-1577477127-873989120-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')

    O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe

    O4 - Global Startup: Polar WebSync.lnk = C:\Program Files (x86)\Polar\WebSync\WebSync.exe

    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll

    O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll

    O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB

    O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    O23 - Service: Asus process privilege adjust service (AsusUacSvc) - Unknown owner - C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe

    O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

    O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe

    O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe

    O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe

    O23 - Service: DiscountfinderService - Unknown owner - C:\ProgramData\Kortingzoeker\DFService.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

    O23 - Service: Polar Daemon - Unknown owner - C:\Program Files (x86)\Polar\Daemon\polard.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Samsung AllShare PC Service (SamsungAllShare) - Unknown owner - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\WiselinkPro.exe

    O23 - Service: SimpleSlideShowServer - Samsung Electronics - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    O23 - Service: Intel® Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: VideAceWindowsService - Unknown owner - C:\ExpressGateUtil\VAWinService.exe

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 17181 bytes

    ======Listing Processes======

    \SystemRoot\System32\smss.exe

    C:\PROGRA~2\AVG\AVG2013\avgrsa.exe /boot

    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe /pipeName=00f90d45-6f4a-4d67-b099-c54751fafd26 /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\43125f47-9c02-4918-a804-b21b61744310-208-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2013\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2013" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\"

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    wininit.exe

    %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

    C:\Windows\system32\services.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    winlogon.exe

    "C:\Windows\system32\nvvsvc.exe"

    "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k NetworkService

    "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"

    "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"

    "C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"

    C:\Windows\system32\nvvsvc.exe -session -first

    C:\Windows\System32\spoolsv.exe

    taskeng.exe {712C212C-D324-4DA2-A5BB-2224C575EEEC}

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

    "C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe"

    "C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"

    "C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"

    "C:\Program Files (x86)\AVG\AVG2013\avgfws.exe"

    "C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe"

    "C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe"

    "C:\ProgramData\Kortingzoeker\DFService.exe"

    "taskhost.exe"

    "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"

    taskeng.exe {72C634CE-20F4-4282-A29D-9BC919EC952A}

    "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"

    "C:\Windows\system32\Dwm.exe"

    C:\Windows\Explorer.EXE

    taskeng.exe {B30497E9-021A-4284-B967-06147E9087A4}

    C:\Windows\SysWOW64\PnkBstrA.exe

    "C:\Program Files\ASUS\P4G\BatteryLife.exe"

    "C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"

    "C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"

    "C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"

    C:\Windows\SysWOW64\PnkBstrB.exe

    "C:\Program Files (x86)\Polar\Daemon\polard.exe"

    "C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe"

    "C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe"

    "C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\WiselinkPro.exe"

    "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s

    "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

    "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

    "C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe"

    "C:\Program Files (x86)\Steam\Steam.exe" -silent

    "C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe"

    "C:\Program Files (x86)\AVG\AVG2013\avgemca.exe"

    "C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    "C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

    "C:\Program Files (x86)\Polar\WebSync\WebSync.exe" -normal

    "C:\Program Files (x86)\Gaming Mouse\hid.exe"

    "C:\Windows\AsScrPro.exe"

    "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"

    "C:\ExpressGateUtil\VAWinAgent.exe"

    "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

    "C:\Program Files (x86)\Gaming Mouse\Tray.exe"

    "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"

    "C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"

    "C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"

    "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"

    "C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe"

    "C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe"

    "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY

    "C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe"

    \??\C:\Windows\system32\conhost.exe "1206285342485890938753188900-112338274473439928-16623895832468390171489410774

    C:\Windows\system32\svchost.exe -k imgsvc

    "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1

    C:\ExpressGateUtil\VAWinService.exe

    "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"

    WLIDSvcM.exe 5964

    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    ATKOSD.exe

    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe /pipeName=e7be0c3e-fdcc-461b-b579-e7197699102b /coreSdkOptions=4114 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\d5ae0a67-3e48-4070-8faa-e12f7d5a251d-a6c-oopp.tmp" /loggerName=AVG.NS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2013\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2013" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\"

    KBFiltr.exe

    WDC.exe

    C:\Windows\system32\SearchIndexer.exe /Embedding

    C:\Windows\system32\svchost.exe -k bthsvcs

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    "C:\Program Files\Windows Media Player\wmpnetwk.exe"

    C:\Windows\System32\svchost.exe -k LocalServicePeerNet

    "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService

    C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}

    "C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe"

    "C:\Program Files (x86)\Nero\Update\NASvc.exe"

    "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe"

    "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding

    C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE

    "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe" -scan -tt_on

    "C:\Program Files\Internet Explorer\iexplore.exe"

    "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:8080 CREDAT:267521 /prefetch:2

    "C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe"

    C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe -Embedding

    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

    "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-209168772-1577477127-873989120-100111_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-209168772-1577477127-873989120-100111 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"

    "C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544

    "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:8080 CREDAT:4134195 /prefetch:2

    "C:\Users\Rossi925\Desktop\RSITx64.exe"

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

    ======Scheduled tasks folder======

    C:\Windows\tasks\Adobe Flash Player Updater.job

    C:\Windows\tasks\AutoKMS.job

    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-209168772-1577477127-873989120-1001Core.job

    C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-209168772-1577477127-873989120-1001UA.job

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]

    Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-07-10 205472]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

    Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-10-09 256080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

    Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL [2013-09-13 878296]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

    Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2013-09-13 2328264]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54F73992-6549-4369-9A0D-84FD310A464A}]

    Aimersoft Video Converter Ultimate - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll [2013-05-08 275744]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]

    CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-03-13 60576]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

    Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

    Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-09 194640]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

    Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2013-09-13 705240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

    Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2013-09-13 1724616]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-10-09 256080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-09 194640]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

    "RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-31 12446824]

    "AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-03-13 617120]

    "AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-03-13 379552]

    "IntelTBRunOnce"=wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs []

    "Setwallpaper"=c:\programdata\SetWallpaper.cmd []

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "ANT Agent"=C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe [2013-02-15 14731776]

    "Steam"=C:\Program Files (x86)\Steam\steam.exe [2013-10-09 1813928]

    "Spotify Web Helper"=C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2013-10-11 1140736]

    "AppsHat"=C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752]

    "Facebook Update"=C:\Users\Rossi925\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-22 138096]

    "Apps Hat"=C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752]

    "swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-04-13 39408]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mio Share]

    C:\Users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mio\Mio Share.appref-ms [2013-09-03 342]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

    C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-03 19604072]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]

    C:\Users\Rossi925\AppData\Roaming\Spotify\Spotify.exe [2013-10-11 4752384]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]

    C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2013-10-11 1140736]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

    "Nuance PDF Reader-reminder"=C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [2008-11-03 328992]

    "ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-04-13 2018032]

    "ASUSWebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [2011-02-23 731472]

    "Gaming Mouse Hid"=C:\Program Files (x86)\Gaming Mouse\hid.exe [2010-01-19 428544]

    "ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2013-04-04 3058304]

    "THX TruStudio NB Settings"=C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [2011-03-17 909312]

    "UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]

    "CPMonitor"=C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe [2011-04-01 84464]

    "VAWinAgent"=C:\ExpressGateUtil\VAWinAgent.exe [2011-04-08 45448]

    "UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

    "CLMLServer"=C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]

    "UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]

    "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

    "ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-22 318080]

    "ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2011-10-24 174720]

    "HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]

    "Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-02-02 2321072]

    "FLxHCIm64"=C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [2012-07-19 48128]

    "AllShareAgent"=C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [2011-02-18 250768]

    "Aimersoft Helper Compact.exe"=C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2013-05-29 1734144]

    "BrowserPlugInHelper"=C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe [2013-05-08 1960448]

    "beid"=C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup []

    "AVG_UI"=C:\Program Files (x86)\AVG\AVG2013\avgui.exe [2013-08-15 4411440]

    [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]

    "SpUninstallCleanUp"=REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f []

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

    AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe

    Polar WebSync.lnk - C:\Program Files (x86)\Polar\WebSync\WebSync.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

    WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

    "SecurityProviders"=credssp.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

    "ConsentPromptBehaviorAdmin"=5

    "ConsentPromptBehaviorUser"=3

    "EnableUIADesktopToggle"=0

    "dontdisplaylastusername"=0

    "legalnoticecaption"=

    "legalnoticetext"=

    "shutdownwithoutlogon"=1

    "undockwithoutlogon"=1

    "EnableLinkedConnections"=1

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

    "NoActiveDesktop"=1

    "NoActiveDesktopChanges"=1

    "ForceActiveDesktopOn"=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

    "vidc.mrle"=msrle32.dll

    "vidc.msvc"=msvidc32.dll

    "msacm.imaadpcm"=imaadp32.acm

    "msacm.msg711"=msg711.acm

    "msacm.msgsm610"=msgsm32.acm

    "msacm.msadpcm"=msadp32.acm

    "midimapper"=midimap.dll

    "wavemapper"=msacm32.drv

    "VIDC.UYVY"=msyuv.dll

    "VIDC.YUY2"=msyuv.dll

    "VIDC.YVYU"=msyuv.dll

    "VIDC.IYUV"=iyuv_32.dll

    "vidc.i420"=iyuv_32.dll

    "VIDC.YVU9"=tsbyuv.dll

    "msacm.l3acm"=C:\Windows\System32\l3codeca.acm

    "MSVideo8"=VfWWDM32.dll

    "wave1"=wdmaud.drv

    "midi1"=wdmaud.drv

    "mixer1"=wdmaud.drv

    "wave2"=wdmaud.drv

    "midi2"=wdmaud.drv

    "mixer2"=wdmaud.drv

    "wave3"=wdmaud.drv

    "midi3"=wdmaud.drv

    "mixer3"=wdmaud.drv

    "wave4"=wdmaud.drv

    "midi4"=wdmaud.drv

    "mixer4"=wdmaud.drv

    "wave5"=wdmaud.drv

    "mixer5"=wdmaud.drv

    "midi5"=wdmaud.drv

    "wave"=wdmaud.drv

    "midi"=wdmaud.drv

    "mixer"=wdmaud.drv

    "aux"=wdmaud.drv

    "aux1"=wdmaud.drv

    "aux2"=wdmaud.drv

    "wave9"=wdmaud.drv

    "midi9"=wdmaud.drv

    "mixer9"=wdmaud.drv

    "wave6"=wdmaud.drv

    "midi6"=wdmaud.drv

    "mixer6"=wdmaud.drv

    "wave8"=wdmaud.drv

    "midi8"=wdmaud.drv

    "mixer8"=wdmaud.drv

    "wave7"=wdmaud.drv

    "midi7"=wdmaud.drv

    "mixer7"=wdmaud.drv

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    .js - open - C:\Windows\System32\WScript.exe "%1" %*

    ======List of files/folders created in the last 1 month======

    2013-10-18 13:05:01 ----A---- C:\Windows\system32\drivers\EsgScanner.sys

    2013-10-18 13:04:57 ----D---- C:\sh4ldr

    2013-10-18 13:04:03 ----D---- C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP

    2013-10-13 16:20:59 ----D---- C:\Program Files\Microsoft.NET

    2013-10-09 19:58:09 ----A---- C:\Windows\SYSWOW64\ieui.dll

    2013-10-09 19:58:09 ----A---- C:\Windows\system32\ieui.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe

    2013-10-09 19:58:08 ----A---- C:\Windows\SYSWOW64\iesysprep.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\SYSWOW64\iesetup.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\SYSWOW64\iertutil.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\SYSWOW64\iernonce.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe

    2013-10-09 19:58:08 ----A---- C:\Windows\system32\iesysprep.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\system32\iesetup.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\system32\iernonce.dll

    2013-10-09 19:58:08 ----A---- C:\Windows\system32\ie4uinit.exe

    2013-10-09 19:58:07 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

    2013-10-09 19:58:07 ----A---- C:\Windows\SYSWOW64\jscript.dll

    2013-10-09 19:58:07 ----A---- C:\Windows\system32\msfeeds.dll

    2013-10-09 19:58:07 ----A---- C:\Windows\system32\jscript.dll

    2013-10-09 19:58:07 ----A---- C:\Windows\system32\iertutil.dll

    2013-10-09 19:58:06 ----A---- C:\Windows\SYSWOW64\jscript9.dll

    2013-10-09 19:58:06 ----A---- C:\Windows\system32\jscript9.dll

    2013-10-09 19:58:05 ----A---- C:\Windows\SYSWOW64\urlmon.dll

    2013-10-09 19:58:05 ----A---- C:\Windows\system32\urlmon.dll

    2013-10-09 19:58:04 ----A---- C:\Windows\SYSWOW64\wininet.dll

    2013-10-09 19:58:04 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

    2013-10-09 19:58:04 ----A---- C:\Windows\system32\wininet.dll

    2013-10-09 19:58:04 ----A---- C:\Windows\system32\jsproxy.dll

    2013-10-09 19:58:03 ----A---- C:\Windows\SYSWOW64\ieframe.dll

    2013-10-09 19:58:02 ----A---- C:\Windows\system32\ieframe.dll

    2013-10-09 19:58:01 ----A---- C:\Windows\system32\mshtml.dll

    2013-10-09 19:57:59 ----A---- C:\Windows\SYSWOW64\mshtml.dll

    2013-10-09 10:18:16 ----A---- C:\Windows\SYSWOW64\comctl32.dll

    2013-10-09 10:18:16 ----A---- C:\Windows\system32\comctl32.dll

    2013-10-09 10:18:14 ----A---- C:\Windows\SYSWOW64\atmfd.dll

    2013-10-09 10:18:14 ----A---- C:\Windows\system32\lpk.dll

    2013-10-09 10:18:14 ----A---- C:\Windows\system32\dciman32.dll

    2013-10-09 10:18:14 ----A---- C:\Windows\system32\atmfd.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\WebClnt.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\lpk.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\fontsub.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\dciman32.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\davclnt.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\SYSWOW64\atmlib.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\WebClnt.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\fontsub.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\Wdf01000.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\usbvideo.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\usbcir.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\mrxdav.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\hidparse.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\drivers\hidclass.sys

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\davclnt.dll

    2013-10-09 10:18:13 ----A---- C:\Windows\system32\atmlib.dll

    2013-10-09 10:18:12 ----A---- C:\Windows\system32\mswsock.dll

    2013-10-09 10:18:12 ----A---- C:\Windows\system32\drivers\tcpip.sys

    2013-10-09 10:18:12 ----A---- C:\Windows\system32\drivers\afd.sys

    2013-10-09 10:18:11 ----A---- C:\Windows\SYSWOW64\mswsock.dll

    2013-10-09 10:18:11 ----A---- C:\Windows\system32\win32k.sys

    2013-10-09 10:18:10 ----A---- C:\Windows\system32\ntoskrnl.exe

    2013-10-09 10:18:09 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe

    2013-10-09 10:18:09 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe

    2013-10-09 10:18:09 ----A---- C:\Windows\system32\tdh.dll

    2013-10-09 10:18:09 ----A---- C:\Windows\system32\advapi32.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\wow32.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\user.exe

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\tdh.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\setup16.exe

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\instnm.exe

    2013-10-09 10:18:08 ----A---- C:\Windows\SYSWOW64\advapi32.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\system32\wow64.dll

    2013-10-09 10:18:08 ----A---- C:\Windows\system32\ntdll.dll

    2013-10-09 10:18:05 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll

    2013-10-09 10:18:05 ----A---- C:\Windows\system32\scavengeui.dll

    2013-10-09 10:18:05 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll

    2013-10-09 10:18:05 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbuhci.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbport.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbohci.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbhub.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbehci.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbd.sys

    2013-10-09 10:18:03 ----A---- C:\Windows\system32\drivers\usbccgp.sys

    2013-10-05 23:18:48 ----D---- C:\Program Files\Common Files\DESIGNER

    2013-10-05 23:18:28 ----D---- C:\Program Files (x86)\Microsoft SQL Server

    2013-10-05 23:18:10 ----D---- C:\ProgramData\regid.1991-06.com.microsoft

    2013-10-05 23:17:41 ----D---- C:\Program Files\Microsoft SQL Server

    2013-10-05 23:14:48 ----D---- C:\Program Files\Microsoft Analysis Services

    2013-10-05 23:14:48 ----D---- C:\Program Files (x86)\Microsoft Analysis Services

    2013-10-05 23:14:40 ----D---- C:\Program Files (x86)\Microsoft Office

    2013-10-05 23:14:39 ----D---- C:\Program Files\Microsoft Office

    2013-10-05 23:14:18 ----RHD---- C:\MSOCache

    2013-10-04 16:17:54 ----D---- C:\Program Files (x86)\Ubisoft

    2013-10-03 17:12:49 ----A---- C:\Windows\SYSWOW64\steam_api.dll

    2013-10-02 16:56:33 ----A---- C:\Windows\SYSWOW64\binkw32.dll

    2013-10-02 16:56:18 ----D---- C:\ProgramData\Logs

    2013-10-02 16:56:18 ----A---- C:\Windows\system32\roboot64.exe

    2013-10-01 13:48:35 ----D---- C:\Program Files (x86)\AGEIA Technologies

    2013-10-01 13:46:08 ----A---- C:\Windows\system32\drivers\nvvad64v.sys

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvopencl.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\NvIFR.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\NvFBC.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvcuda.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\SYSWOW64\nvapi.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvopencl.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvoglv64.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\NvIFR64.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvhdap64.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\NvFBC64.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvdispgenco6432723.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvdispco6432723.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvd3dumx.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvcuvid.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvcuvenc.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvcuda.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvcompiler.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\nvaudcap64v.dll

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys

    2013-10-01 13:46:07 ----A---- C:\Windows\system32\drivers\nvhda64v.sys

    2013-10-01 13:44:51 ----D---- C:\NVIDIA

    2013-10-01 13:35:44 ----D---- C:\ProgramData\Orbit

    2013-09-19 14:05:10 ----D---- C:\ProgramData\Spotnet

    2013-09-19 14:05:10 ----D---- C:\Program Files (x86)\Spotnet

    2013-09-19 06:06:52 ----D---- C:\Users\Rossi925\AppData\Roaming\Need for Speed World

    ======List of files/folders modified in the last 1 month======

    2013-10-18 13:16:04 ----D---- C:\Windows\Temp

    2013-10-18 13:16:04 ----D---- C:\Program Files\trend micro

    2013-10-18 13:05:07 ----D---- C:\Windows\system32\drivers

    2013-10-18 13:05:04 ----SHD---- C:\Windows\Installer

    2013-10-18 13:05:04 ----D---- C:\Windows\Prefetch

    2013-10-18 13:05:01 ----D---- C:\Windows\system32\Tasks

    2013-10-18 13:04:42 ----SHD---- C:\System Volume Information

    2013-10-18 13:04:03 ----D---- C:\Windows

    2013-10-18 12:56:35 ----D---- C:\ProgramData\MFAData

    2013-10-18 12:54:12 ----RD---- C:\Program Files (x86)

    2013-10-18 12:52:45 ----A---- C:\Windows\SYSWOW64\log.txt

    2013-10-18 12:50:59 ----D---- C:\Program Files (x86)\Steam

    2013-10-18 12:50:12 ----D---- C:\ProgramData\NVIDIA

    2013-10-18 11:06:42 ----D---- C:\Windows\system32\config

    2013-10-18 11:05:57 ----D---- C:\Users\Rossi925\AppData\Roaming\Spotify

    2013-10-18 06:38:13 ----D---- C:\Users\Rossi925\AppData\Roaming\vlc

    2013-10-18 06:35:50 ----D---- C:\Users\Rossi925\AppData\Roaming\uTorrent

    2013-10-18 06:07:38 ----D---- C:\Users\Rossi925\AppData\Roaming\GrabIt

    2013-10-18 05:52:00 ----D---- C:\Users\Rossi925\AppData\Roaming\Polar WebSync

    2013-10-17 14:30:15 ----D---- C:\Windows\System32

    2013-10-17 14:30:15 ----A---- C:\Windows\system32\PerfStringBackup.INI

    2013-10-14 16:44:38 ----D---- C:\Windows\system32\NDF

    2013-10-14 10:15:10 ----D---- C:\Windows\system32\catroot2

    2013-10-13 16:21:20 ----RSD---- C:\Windows\assembly

    2013-10-13 16:20:59 ----RD---- C:\Program Files

    2013-10-13 16:20:59 ----D---- C:\Program Files (x86)\Microsoft.NET

    2013-10-13 16:18:51 ----D---- C:\ProgramData\Microsoft Help

    2013-10-11 23:21:35 ----D---- C:\Users\Rossi925\AppData\Roaming\dvdcss

    2013-10-11 16:35:28 ----D---- C:\Windows\SysWOW64

    2013-10-10 20:57:57 ----D---- C:\Windows\rescache

    2013-10-10 12:09:24 ----D---- C:\Windows\Microsoft.NET

    2013-10-09 20:55:36 ----D---- C:\Windows\winsxs

    2013-10-09 20:52:18 ----D---- C:\Program Files (x86)\Internet Explorer

    2013-10-09 20:52:16 ----D---- C:\Windows\SYSWOW64\drivers

    2013-10-09 20:52:16 ----D---- C:\Program Files\Internet Explorer

    2013-10-09 20:52:11 ----D---- C:\Windows\AppPatch

    2013-10-09 20:52:10 ----D---- C:\Windows\system32\nl-NL

    2013-10-09 20:52:07 ----D---- C:\Windows\system32\DriverStore

    2013-10-09 20:51:20 ----D---- C:\Program Files\Microsoft Silverlight

    2013-10-09 20:51:19 ----D---- C:\Program Files (x86)\Microsoft Silverlight

    2013-10-09 19:58:24 ----D---- C:\Windows\system32\catroot

    2013-10-09 19:52:56 ----D---- C:\Windows\system32\MRT

    2013-10-09 19:51:25 ----A---- C:\Windows\system32\MRT.exe

    2013-10-09 12:50:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

    2013-10-06 16:48:05 ----D---- C:\Windows\Tasks

    2013-10-06 08:06:25 ----D---- C:\Windows\inf

    2013-10-06 00:49:19 ----A---- C:\Windows\win.ini

    2013-10-05 23:32:27 ----SD---- C:\Users\Rossi925\AppData\Roaming\Microsoft

    2013-10-05 23:21:13 ----D---- C:\Program Files (x86)\Mozilla Firefox

    2013-10-05 23:18:58 ----RSD---- C:\Windows\Fonts

    2013-10-05 23:18:51 ----D---- C:\Windows\ShellNew

    2013-10-05 23:18:50 ----D---- C:\Program Files\Common Files\Microsoft Shared

    2013-10-05 23:18:48 ----D---- C:\Program Files\Common Files

    2013-10-05 23:18:10 ----HD---- C:\ProgramData

    2013-10-05 23:17:41 ----SD---- C:\ProgramData\Microsoft

    2013-10-05 23:15:16 ----D---- C:\Program Files\Common Files\System

    2013-10-04 16:09:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

    2013-10-01 13:48:35 ----D---- C:\Program Files (x86)\NVIDIA Corporation

    2013-10-01 13:47:45 ----RD---- C:\Users

    2013-10-01 13:47:44 ----D---- C:\Program Files\NVIDIA Corporation

    2013-10-01 06:16:39 ----D---- C:\Windows\Logs

    2013-09-21 17:17:38 ----D---- C:\Windows\system32\wdi

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2013-07-20 71480]

    R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2013-07-20 311608]

    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2013-07-01 116536]

    R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2013-09-05 45880]

    R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-05 438808]

    R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]

    R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]

    R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]

    R1 ATKWMIACPIIO_;ATKWMIACPI Driver_; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]

    R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2012-09-04 50296]

    R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2013-07-20 246072]

    R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2013-07-20 206648]

    R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2013-03-21 240952]

    R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]

    R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

    R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]

    R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35344]

    R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2010-11-30 16120]

    R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2011-02-26 16768]

    R3 AsusgmsFltr;Gaming Mouse; C:\Windows\system32\drivers\Asusgms.sys [2010-01-12 11520]

    R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-07 2770944]

    R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-03-13 28832]

    R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver; C:\Windows\system32\DRIVERS\FLxHCIc.sys [2012-07-19 246568]

    R3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver; C:\Windows\system32\DRIVERS\FLxHCIh.sys [2012-07-19 76584]

    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-02-06 4740456]

    R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]

    R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]

    R3 MEIx64;Intel® Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-09-21 56344]

    R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-06-16 196384]

    R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-08-20 39200]

    R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]

    R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-04-21 471144]

    S3 ACSSCR;ACR38 Smart Card Reader; C:\Windows\system32\DRIVERS\a38usb.sys [2013-06-18 44672]

    S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-03-13 36000]

    S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-03-13 298656]

    S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-03-13 201376]

    S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-03-13 55456]

    S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-03-13 154272]

    S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-03-13 280224]

    S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]

    S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]

    S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]

    S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]

    S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files (x86)\MediaCoder\SysInfoX64.sys []

    S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2012-06-22 22704]

    S3 fspad_win764;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_win764; C:\Windows\system32\DRIVERS\fspad_win764.sys [2011-06-19 53760]

    S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]

    S3 grmnusb;grmnusb; C:\Windows\system32\drivers\grmnusb.sys [2012-04-18 19304]

    S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-06-10 57344]

    S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RTSUVSTOR.sys [2010-08-03 290920]

    S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]

    S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

    S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]

    S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]

    S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]

    R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]

    R2 AsusUacSvc;Asus process privilege adjust service; C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe [2010-07-27 113840]

    R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]

    R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]

    R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]

    R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2013-09-04 1432080]

    R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2013-07-04 4939312]

    R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-07-23 283136]

    R2 DiscountfinderService;DiscountfinderService; C:\ProgramData\Kortingzoeker\DFService.exe [2013-01-04 141824]

    R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2010-10-06 325656]

    R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432]

    R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-09-12 920864]

    R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-08-27 2155296]

    R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-08-01 66872]

    R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2013-08-01 107832]

    R2 Polar Daemon;Polar Daemon; C:\Program Files (x86)\Polar\Daemon\polard.exe [2012-12-12 419536]

    R2 SamsungAllShare;Samsung AllShare PC Service; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\WiselinkPro.exe [2011-02-18 7233952]

    R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2013-07-17 1025408]

    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-09-12 414496]

    R2 UNS;Intel® Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]

    R2 VideAceWindowsService;VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [2011-03-26 91464]

    R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]

    R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-10-09 565672]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-18 116648]

    S2 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2011-02-18 22464]

    S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-06-03 162408]

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09 257416]

    S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]

    S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2013-04-04 79360]

    S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-04-04 79360]

    S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]

    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-18 116648]

    S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-07-06 194032]

    S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-10-01 178824]

    S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]

    S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]

    S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-04-03 1255736]

    S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

    S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

    S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

    -----------------EOF-----------------

  4. Zoek.exe Version 4.0.0.4 Updated 19-08-2013

    Tool run by Rossi925 on di 20/08/2013 at 17:44:45,97.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Rossi925\Desktop\zoek.exe [script inserted]

    ==== Deleting Files \ Folders ======================

    "C:\Users\Rossi925\Downloads\Babylon10_setup.exe" deleted

    "C:\users\Rossi925\AppData\Locallow\Minibar" deleted

    "C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP" deleted

    ==== Folders Found In C:\users\Rossi925\AppData\Local\76561197972651619 ======================

    2013-07-31 12:47:13 d-----w- C:\users\Rossi925\AppData\Local\76561197972651619\28020

    2013-07-31 12:47:13 d-----w- C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache

    2013-07-31 12:47:13 d-----w- C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache\persistent

    2013-07-31 12:47:13 d-----w- C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache\temp

    ==== Files Found In C:\users\Rossi925\AppData\Local\76561197972651619 ======================

    2013-07-31 12:57:05 731 ----a-w- 8154092BD3C1D64CE1A0746782832138 C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache\persistent\D9FA8096F855C00D13E9CDB97AD0ED0EFBB32DA0

    2013-07-31 12:57:05 782 ----a-w- 04C79E86EE04A3FBD2BA041D60653C9D C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache\persistent\6018B115E4F8FEFEFFB9E05CF59BF82310D1CD8A

    2013-07-31 12:57:06 719 ----a-w- 4D72CF78B160F999648323228D667DCE C:\users\Rossi925\AppData\Local\76561197972651619\28020\cache\persistent\50F446BADC59250D5222F7A59CF478888CDB6946

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3Z4282X0 will be deleted at reboot

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0TMRYFAB will be deleted at reboot

    ==== Empty FireFox Cache ======================

    No FireFox Cache found

    ==== Empty Chrome Cache ======================

    C:\users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    No Java Cache Found

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Rossi925\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3Z4282X0" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0TMRYFAB" not found

    ==== EOF on di 20/08/2013 at 17:47:23,59 ======================

    Ik heb dan dus adwcleaner opgestart,scan gedaan,clean gedaan en nadien is pc opgestart en krreg volgend log file :

    # AdwCleaner v3.000 - Report created 20/08/2013 at 17:55:10

    # Updated 20/08/2013 by Xplode

    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Username : Rossi925 - ROSSI925-PC

    # Running from : C:\Users\Rossi925\Desktop\adwcleaner.exe

    # Option : Clean

    ***** [ Services ] *****

    ***** [ Files / Folders ] *****

    File Deleted : C:\Users\Rossi925\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js

    File Deleted : C:\Users\Rossi925\AppData\Roaming\Mozilla\Firefox\Profiles\[ofr2][opt]rs0\user.js

    File Deleted : C:\Users\Rossi925\AppData\Roaming\Mozilla\Firefox\Profiles\[opt]rs0\user.js

    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****

    Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{9309FA47-1B48-4768-AFA4-9E0556F5DC81}]

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL

    Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap

    Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard

    Key Deleted : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1

    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api

    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1

    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers

    Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

    Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS

    Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc

    Key Deleted : HKCU\Software\5308bdbb234ef12

    Key Deleted : HKLM\SOFTWARE\5308bdbb234ef12

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{377E5D4D-77E5-476A-8716-7E70A9272DA0}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}

    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}

    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}

    Key Deleted : HKCU\Software\1ClickDownload

    Key Deleted : HKCU\Software\APN DTX

    Key Deleted : HKCU\Software\BabSolution

    Key Deleted : HKCU\Software\BI

    Key Deleted : HKCU\Software\DataMngr

    [#] Key Deleted : HKCU\Software\DataMngr_Toolbar

    Key Deleted : HKCU\Software\IM

    Key Deleted : HKCU\Software\ImInstaller

    Key Deleted : HKCU\Software\Softonic

    Key Deleted : HKLM\Software\Babylon

    Key Deleted : HKLM\Software\DataMngr

    Key Deleted : HKLM\Software\Delta

    Key Deleted : HKLM\Software\Desksvc

    Key Deleted : HKLM\Software\eSafeSecControl

    Key Deleted : HKLM\Software\iLividSRTB

    Key Deleted : HKLM\Software\Minibar

    Key Deleted : HKLM\Software\qvo6Software

    Key Deleted : HKLM\Software\V9

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eSafeSecControl

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lrcspal@lyricspal.co

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar

    Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer

    Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\browse~1\261546~1.206\{c16c1~1\browse~1.dll

    Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\wincert\win32c~1.dll

    Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN64C~1.DLL

    Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll

    ***** [ Browsers ] *****

    -\\ Internet Explorer v10.0.9200.16660

    -\\ Mozilla Firefox v

    [ File : C:\Users\Rossi925\AppData\Roaming\Mozilla\Firefox\Profiles\[ofr2][opt]rs0\prefs.js ]

    -\\ Google Chrome v28.0.1500.95

    [ File : C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Deleted : homepage

    Deleted : urls_to_restore_on_startup

    *************************

    AdwCleaner[R0].txt - [7200 octets] - [20/08/2013 17:54:42]

    AdwCleaner[s0].txt - [6472 octets] - [20/08/2013 17:55:10]

    ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [6532 octets] ##########

  5. Ik had na de scan een lijn over het hoofd gezien dat verwijderd moest worden.Ik heb de procedure dus opnieuw gedaan vanaf de zoek functies.Het resultaat van deze log vindt je hieronder :

    Zoek.exe Version 4.0.0.4 Updated 19-08-2013

    Tool run by Rossi925 on di 20/08/2013 at 10:58:44,80.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Rossi925\Desktop\zoek.exe [script inserted]

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Services ======================

    ==== Deleting Files \ Folders ======================

    "C:\Program Files (x86)\Minibar" not found

    "C:\Users\Rossi925\AppData\Roaming\Yontoo" not found

    "C:\PROGRA~2\SEARCH~1\Datamngr" not found

    "C:\ProgramData\BrowserDefender" not found

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    ====== C:\Users\Rossi925\AppData\Local\Temp ====

    ====== C:\Windows\SysWOW64 =====

    2013-08-14 08:20:06 C9BFFA62DFBF0317AECE707B39C4BF25 391168 ----a-w- C:\Windows\SysWOW64\ieui.dll

    2013-08-14 08:20:06 AF6A6C16ACAD816B48714AE7A4082D89 61440 ----a-w- C:\Windows\SysWOW64\iesetup.dll

    2013-08-14 08:20:06 A484F9DB744849C0B32DD1CE73A94F62 2706432 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

    2013-08-14 08:20:05 D0E0086BA353C379DCFE8624E8B8F17A 2048512 ----a-w- C:\Windows\SysWOW64\iertutil.dll

    2013-08-14 08:20:05 BC90EED56A5C77168A8D6F0C4221D7CB 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2013-08-14 08:20:05 8A5BD908D421BEE82941EF8ABD8B4F09 33280 ----a-w- C:\Windows\SysWOW64\iernonce.dll

    2013-08-14 08:20:05 37730C04B543536D971B3F157415EFF5 109056 ----a-w- C:\Windows\SysWOW64\iesysprep.dll

    2013-08-14 08:20:04 45C118A1E03182365CB568F99B81A473 493056 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

    2013-08-14 08:20:04 1C83426A51AD83B5E788B6CF143B48D8 690688 ----a-w- C:\Windows\SysWOW64\jscript.dll

    2013-08-14 08:20:03 AC8C3591D536D1CCB62EDCBEA88140B3 2877440 ----a-w- C:\Windows\SysWOW64\jscript9.dll

    2013-08-14 08:20:03 059FC59F97A6220C46A612A9470A00B3 1141248 ----a-w- C:\Windows\SysWOW64\urlmon.dll

    2013-08-14 08:20:02 DAA3903F06116AE9EE7AC1D1B93684A4 1767936 ----a-w- C:\Windows\SysWOW64\wininet.dll

    2013-08-14 08:20:02 49EB7DE3A1CCCE9D0873DE9114810113 39936 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

    2013-08-14 08:20:01 E9BCB6728DD04412BF87F03DB00DE1CF 13761024 ----a-w- C:\Windows\SysWOW64\ieframe.dll

    2013-08-14 08:19:58 E631B408882F8320739F6E0CAF444397 14329344 ----a-w- C:\Windows\SysWOW64\mshtml.dll

    2013-08-14 07:52:19 AE8EB083B050E17A7D6EB5E28AECDDD6 1166848 ----a-w- C:\Windows\SysWOW64\crypt32.dll

    2013-08-14 07:52:19 7CA1BECEA5DE2643ADDAD32670E7A4C9 140288 ----a-w- C:\Windows\SysWOW64\cryptsvc.dll

    2013-08-14 07:52:19 7B851A8018B1EA00A69707A390004884 103936 ----a-w- C:\Windows\SysWOW64\cryptnet.dll

    2013-08-14 07:52:19 68EAAEDF0365168B804E8728368FA946 175104 ----a-w- C:\Windows\SysWOW64\wintrust.dll

    2013-08-14 07:52:12 0805487A6036A9F9C4E7AF7FEF835529 1620992 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL

    2013-08-14 07:52:09 D5E18BA95F9E7D787D25EF07AC68603E 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll

    2013-08-14 07:52:01 4DC999CED9429939D75682EBD7D48901 663552 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll

    2013-08-14 07:51:45 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

    2013-08-14 07:51:44 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

    2013-08-14 07:51:43 77F5D2CB80697EB96C45E79A869A6FAC 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll

    2013-08-14 07:51:43 528D298F9914C558EA7A9809BE598E65 1292192 ----a-w- C:\Windows\SysWOW64\ntdll.dll

    2013-08-14 07:51:42 4E77948A7BD16BA5724EC79C60176B03 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll

    2013-08-14 07:51:41 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

    2013-08-14 07:51:41 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

    2013-08-14 07:51:41 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

    ====== C:\Windows\SysWOW64\drivers =====

    ====== C:\Windows\Sysnative =====

    2013-08-14 08:20:07 3A2FD42F11CD325A4ACAFE7FB0EEA83A 2706432 ----a-w- C:\Windows\Sysnative\mshtml.tlb

    2013-08-14 08:20:06 69F5E016A98CE1908DB08382F2ACF882 526336 ----a-w- C:\Windows\Sysnative\ieui.dll

    2013-08-14 08:20:05 D8CC9A20C517A54678363C4C77B930A4 136704 ----a-w- C:\Windows\Sysnative\iesysprep.dll

    2013-08-14 08:20:05 963B29E0EFB20D66436214DB7C43D7F7 67072 ----a-w- C:\Windows\Sysnative\iesetup.dll

    2013-08-14 08:20:05 6C8BDC9F16943D626DFE8A987BCCFD20 51712 ----a-w- C:\Windows\Sysnative\ie4uinit.exe

    2013-08-14 08:20:05 65546D87F7A78AB31841A536456CB94D 2647040 ----a-w- C:\Windows\Sysnative\iertutil.dll

    2013-08-14 08:20:05 622C7C8D39609FCEACE3508715D48C7F 39936 ----a-w- C:\Windows\Sysnative\iernonce.dll

    2013-08-14 08:20:05 28C2F8C7DBE11AA3DA041D35F4E59481 89600 ----a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe

    2013-08-14 08:20:04 8C12653BEA781902AA60E4A855A55D5C 603136 ----a-w- C:\Windows\Sysnative\msfeeds.dll

    2013-08-14 08:20:04 5A7FA01EEC393A3E0D0F3EBAA1FD959E 3958784 ----a-w- C:\Windows\Sysnative\jscript9.dll

    2013-08-14 08:20:04 16FE878530FDFC9AB08B7FFC32335958 855552 ----a-w- C:\Windows\Sysnative\jscript.dll

    2013-08-14 08:20:03 289C5E0A386E7B6CA9539D66D15E22CC 1365504 ----a-w- C:\Windows\Sysnative\urlmon.dll

    2013-08-14 08:20:02 AC155DD9BD1E6D3B740826A4D1C68AAE 2241024 ----a-w- C:\Windows\Sysnative\wininet.dll

    2013-08-14 08:20:02 04DE09B1E287F6DC5C7FD655B6E84AB9 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll

    2013-08-14 08:20:00 677A1C1B0F254EC918D84A7FE29274CA 15405056 ----a-w- C:\Windows\Sysnative\ieframe.dll

    2013-08-14 08:19:59 396889142BD839DB8A055A0BE0AD2F79 19239424 ----a-w- C:\Windows\Sysnative\mshtml.dll

    2013-08-14 07:52:20 287998A9BA0140ABB59792CDEB2F8483 1472512 ----a-w- C:\Windows\Sysnative\crypt32.dll

    2013-08-14 07:52:19 A6B726DCA228F7878E38368A1BDC68BE 139776 ----a-w- C:\Windows\Sysnative\cryptnet.dll

    2013-08-14 07:52:19 959041D7014C97133D859B45BCA0FC58 224256 ----a-w- C:\Windows\Sysnative\wintrust.dll

    2013-08-14 07:52:19 6B400F211BEE880A37A1ED0368776BF4 184320 ----a-w- C:\Windows\Sysnative\cryptsvc.dll

    2013-08-14 07:52:13 D29200AB0B37B7293C6942EAF755295E 1888768 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL

    2013-08-14 07:52:09 B3CA3253009D26666F5BCB16E77D2618 2048 ----a-w- C:\Windows\Sysnative\tzres.dll

    2013-08-14 07:52:02 26036E228D2467DE6975AD819C22C043 1217024 ----a-w- C:\Windows\Sysnative\rpcrt4.dll

    2013-08-14 07:51:44 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe

    2013-08-14 07:51:43 D6180FBBADA79BC28E5FD8187EBE7F64 243712 ----a-w- C:\Windows\Sysnative\wow64.dll

    2013-08-14 07:51:43 8E45DD84F8F786B2DB94AD95225B9246 1732032 ----a-w- C:\Windows\Sysnative\ntdll.dll

    ====== C:\Windows\Sysnative\drivers =====

    2013-08-14 07:52:22 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\Sysnative\drivers\tssecsrv.sys

    2013-08-14 07:52:20 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys

    ====== C:\Windows\Tasks ======

    2013-08-19 21:01:43 68E9FB5D83585CFEA1558EA318169AA0 2946 ----a-w- C:\Windows\Sysnative\Tasks\{DE3FEA7E-DB3C-4DE7-8361-0BCE81EF39DD}

    2013-07-28 07:50:19 5005FB322BD30A8BD2BEC2FF12DB68C4 3352 ----a-w- C:\Windows\Sysnative\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-209168772-1577477127-873989120-1001

    2013-07-25 18:00:03 9317211978B29D24DE556E4B8C32972D 3440 ----a-w- C:\Windows\Sysnative\Tasks\{E350AF91-6716-4282-8934-0C23462AE054}

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    ======= C:\Program Files (x86) =====

    2013-08-19 20:20:20 -------- d-----w- C:\Program Files (x86)\Trend Micro

    2013-08-19 17:06:04 -------- d-----w- C:\Program Files (x86)\Garmin GPS Plugin

    2013-07-31 12:47:04 -------- d-----w- C:\Program Files (x86)\OpenAL

    2013-07-28 07:49:41 -------- d-----w- C:\Program Files (x86)\Real

    2013-07-26 11:57:16 -------- d-----w- C:\Program Files (x86)\Common Files\Nero

    2013-07-26 11:57:11 -------- d-----w- C:\Program Files (x86)\Nero

    2013-07-25 11:12:04 -------- d-----w- C:\Program Files (x86)\MSXML 4.0

    ======= C: =====

    ====== C:\Users\Rossi925\AppData\Roaming ======

    2013-08-19 21:22:41 -------- d-----w- C:\users\Rossi925\AppData\Local\Temp

    2013-08-19 18:59:18 -------- d-----w- C:\users\Rossi925\AppData\Locallow\Minibar

    2013-08-19 18:58:19 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat

    2013-08-19 18:58:19 -------- d-----w- C:\users\Rossi925\AppData\Local\WebPlayer

    2013-08-19 18:58:17 -------- d-----w- C:\users\Rossi925\AppData\Local\avgchrome

    2013-08-09 15:36:50 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin

    2013-08-07 20:49:45 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games

    2013-08-04 14:54:58 97680694BE2FCA4AC22D6C39BB51CAA5 3584 ----a-w- C:\users\Rossi925\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    2013-08-03 11:32:35 -------- d-----w- C:\users\Rossi925\AppData\Locallow\Temp

    2013-07-31 12:47:13 -------- d-----w- C:\users\Rossi925\AppData\Local\76561197972651619

    2013-07-28 07:49:27 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Real

    2013-07-25 17:48:37 -------- d-----w- C:\users\Rossi925\AppData\Roaming\CyberLink

    2013-07-24 21:23:25 -------- d-----w- C:\users\Rossi925\AppData\Local\Nero_AG

    2013-07-24 15:52:14 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Nero

    ====== C:\Users\Rossi925 ======

    2013-08-19 19:36:08 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Rossi925\Downloads\SpyHunter-Installer.exe

    2013-08-19 19:09:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

    2013-08-19 18:57:04 DA0373643B12CF8DB4098A6A273032C3 166656 ----a-w- C:\Users\Rossi925\Downloads\Adlock10_downloader_by_Adlock10.exe

    2013-08-19 18:56:43 D37870ECD5BB93FE99758C48AC64794E 725584 ----a-w- C:\Users\Rossi925\Downloads\Babylon10_setup.exe

    2013-08-19 17:04:46 C3EDCCA1FD54009D7C56EEC837148DC8 18854112 ----a-w- C:\Users\Rossi925\Downloads\CommunicatorPlugin_404.exe

    2013-08-01 13:53:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA

    2013-07-31 12:47:15 -------- d-----w- C:\ProgramData\Creative Labs

    2013-07-31 07:08:32 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

    2013-07-28 07:48:54 -------- d-----w- C:\ProgramData\Real

    2013-07-26 11:57:11 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero

    2013-07-25 17:48:37 -------- d-----w- C:\Users\Public\CyberLink

    2013-07-24 15:39:38 -------- d-----w- C:\ProgramData\Nero

    ====== C: exe-files ==

    2013-08-19 20:28:55 25D473D7805261C752DA738B13E35816 185271 ----a-w- C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla31.exe

    2013-08-19 19:48:35 22D3D73B2FA74C01D8D1CBA813D574B8 190411 ----a-w- C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla37.exe

    2013-08-19 19:36:08 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Rossi925\Downloads\SpyHunter-Installer.exe

    2013-08-19 19:09:01 4A3B3C915C3FC187689EC0EB116C2616 33792864 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\28.0.1500.95\28.0.1500.95_chrome_installer.exe

    2013-08-19 19:08:48 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\inst...app_4fe91ede9f9bdca3_0001.0003_fc100576141c6894\GoogleUpdateSetup.exe

    2013-08-19 19:08:48 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\clic...exe_4fe91ede9f9bdca3_0001.0003_none_81523f7b64d98436\GoogleUpdateSetup.exe

    2013-08-19 19:08:48 2D479A35439E0DFBDBF2FDB6DEE8D49B 10120 ------w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\inst...app_4fe91ede9f9bdca3_0001.0003_fc100576141c6894\clickonce_bootstrap.exe

    2013-08-19 18:58:19 D8BA5F4E6A1594D0E07C886DAC0F5F8C 64142 ----a-w- C:\Users\Rossi925\AppData\Local\WebPlayer\Uninstall.exe

    2013-08-19 18:57:04 DA0373643B12CF8DB4098A6A273032C3 166656 ----a-w- C:\Users\Rossi925\Downloads\Adlock10_downloader_by_Adlock10.exe

    2013-08-19 18:56:43 D37870ECD5BB93FE99758C48AC64794E 725584 ----a-w- C:\Users\Rossi925\Downloads\Babylon10_setup.exe

    2013-08-19 17:04:46 C3EDCCA1FD54009D7C56EEC837148DC8 18854112 ----a-w- C:\Users\Rossi925\Downloads\CommunicatorPlugin_404.exe

    2013-08-15 20:51:05 A8A497E0AD525A819DF7188D2A79007D 1096192 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Mapupload\MAPUPLOAD.EXE

    2013-08-14 08:20:05 BC90EED56A5C77168A8D6F0C4221D7CB 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2013-08-14 08:20:05 7BA1862B8A5698DC5FCFDFF3BC359DE9 770648 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe

    2013-08-14 08:20:05 6C8BDC9F16943D626DFE8A987BCCFD20 51712 ----a-w- C:\Windows\System32\ie4uinit.exe

    2013-08-14 08:20:05 28C2F8C7DBE11AA3DA041D35F4E59481 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2013-08-14 08:20:04 133CEF30905806A35606652D409EEEBA 775256 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe

    2013-08-14 07:51:45 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

    2013-08-14 07:51:44 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

    2013-08-14 07:51:44 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe

    2013-08-14 07:51:41 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

    2013-08-14 07:51:41 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

    2013-08-14 07:51:41 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

    2013-08-13 21:23:30 9E970EB020EC22032DBBD0BD8C2C659F 525656 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\Redist\DirectX\DXSETUP.exe

    2013-08-13 21:23:30 6DD89ADFE3A4FFF3738F5BE2566AE7FA 3501720 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe

    2013-08-13 21:23:30 5C82BE7AD1775B67916EE19C15B99331 2723264 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\Redist\vcredist_x86.exe

    === C: other files ==

    2013-08-20 08:58:19 D4D1265CF12D8AFC6FA1EB115AF20625 220854 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\a0e76fb3-3f8f-47d3-8bd3-a5662e640e01.zip

    2013-08-20 08:42:27 DB7084B294760E9766E327C6A9F8B524 87521 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\ca1f6805-3f76-47d3-8bd3-a5662e640e01.zip

    2013-08-17 13:34:57 F3DCE782F7BB35B79DB98DE2FFF3847B 184588 ----a-w- C:\Users\Rossi925\Desktop\Nieuwe map\moonshl2\extlink\nes.nesterds.source.zip

    2013-08-17 13:34:56 B5CFA9D6C8FEBD618F91AC2843D50A1C 4194304 ----a-w- C:\Users\Rossi925\Desktop\Nieuwe map\SYSTEM.SYS

    2013-08-15 20:50:53 85B8E7C5B5383EC5BFA0B7E3E7B69F10 677 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAM_1395\uninstall.bat

    2013-08-15 20:50:53 7503E7718E6F1B11F48BDAE12A00B341 1427 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAM_1395\install.bat

    2013-08-15 20:50:41 D3BAD0E54A8B6A3DD8BDC209163E85F2 678 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAMILY_2215\uninstall.bat

    2013-08-15 20:50:41 5AFE8933C5DDFA0BA3248F3329FB6B83 1257 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAMILY_2215\install.bat

    2013-08-14 07:52:22 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys

    2013-08-14 07:52:20 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys

    ==== Startup Registry Enabled ======================

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Windows\CurrentVersion\Run]

    "ANT Agent"="C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe"

    "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"

    "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    "Spotify Web Helper"="C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    "AppsHat"="C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1003\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Nuance PDF Reader-reminder"="C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe -r C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"

    "ASUSPRP"="C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

    "ASUSWebStorage"="C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S"

    "Gaming Mouse Hid"="C:\Program Files (x86)\Gaming Mouse\hid.exe"

    "ASUS Screen Saver Protector"="C:\Windows\AsScrPro.exe"

    "THX TruStudio NB Settings"="C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe /r"

    "UpdReg"="C:\Windows\UpdReg.EXE"

    "CPMonitor"="C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"

    "VAWinAgent"="C:\ExpressGateUtil\VAWinAgent.exe"

    "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5"

    "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

    "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "ATKOSD2"="C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"

    "ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"

    "HControlUser"="C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"

    "Wireless Console 3"="C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"

    "FLxHCIm64"="C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"

    "AllShareAgent"="C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe"

    "Aimersoft Helper Compact.exe"="C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe"

    "BrowserPlugInHelper"="C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe"

    "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup"

    "AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "ANT Agent"="C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe"

    "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"

    "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    "Spotify Web Helper"="C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    "AppsHat"="C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

    ==== Startup Registry Enabled x64 ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"

    "AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

    "AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

    "IntelTBRunOnce"="wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"

    "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"

    ==== Startup Registry Disabled x64 ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Mio Share]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Mio Share"

    "hkey"="HKCU"

    "command"="C:\\Users\\Rossi925\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Mio\\Mio Share.appref-ms"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Skype"

    "hkey"="HKCU"

    "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Spotify"

    "hkey"="HKCU"

    "command"="\"C:\\Users\\Rossi925\\AppData\\Roaming\\Spotify\\Spotify.exe\" /uri spotify:autostart"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Spotify Web Helper"

    "hkey"="HKCU"

    "command"="\"C:\\Users\\Rossi925\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\""

    ==== Startup Folders ======================

    2011-04-13 02:49:43 2062 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk

    2013-07-13 09:59:53 2071 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Polar WebSync.lnk

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12/06/2013 13:50]

    C:\Windows\tasks\AutoKMS.job --a------ C:\Windows\AutoKMS\AutoKMS.exe []

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [18/04/2013 13:32]

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [undetermined Task]

    ==== Firefox Extensions ======================

    AppDir: C:\Program Files (x86)\Mozilla Firefox

    - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be

    ==== Firefox Plugins ======================

    ==== Chrome Look ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    mapcejffhcbidcjmomhalabpcbaeimcb - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRChromePlugin.crx[08/05/2013 15:13]

    Windows Media Player Extension for HTML5 - Rossi925 - Default\Extensions\hokdglbhghcebcopdbanieangmcamaak

    Aimersoft Video Converter Ultimate - Rossi925 - Default\Extensions\mapcejffhcbidcjmomhalabpcbaeimcb

    ==== Set IE to Default ======================

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag"

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QEVGQ3XZ will be deleted at reboot

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8X2RFMY will be deleted at reboot

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Z2Y6SR4Y will be deleted at reboot

    ==== Empty FireFox Cache ======================

    No FireFox Cache found

    ==== Empty Chrome Cache ======================

    C:\users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    No Java Cache Found

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Rossi925\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QEVGQ3XZ" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8X2RFMY" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JKVUXSL5" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QEVGQ3XZ" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8X2RFMY" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Z2Y6SR4Y" not found

    ==== EOF on di 20/08/2013 at 11:10:37,48 ======================

  6. Zoek.exe Version 4.0.0.4 Updated 19-08-2013

    Tool run by Rossi925 on ma 19/08/2013 at 23:03:22,57.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Rossi925\Desktop\zoek.exe [script inserted]

    ==== Deleting CLSID Registry Keys ======================

    HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5} deleted successfully

    HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Services ======================

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BrowserDefendert deleted successfully

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BrowserDefendert deleted successfully

    ==== Registry Fix Code ======================

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "bProtector Start Page"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

    "bProtectorDefaultScope"=-

    ==== Deleting Files \ Folders ======================

    "C:\Users\Rossi925\AppData\Roaming\Yontoo" not found

    "C:\Users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk" deleted

    "C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data" deleted

    "C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences" deleted

    "C:\windows\SysNative\tasks\Desk 365 RunAsStdUser" deleted

    "C:\windows\SysNative\Tasks\BrowserDefendert" deleted

    "C:\windows\SysNative\tasks\Lyrics-Pal Update" deleted

    "C:\Windows\tasks\Lyrics-Pal Update.job" deleted

    "C:\Program Files (x86)\LyricsPal\128.dll" deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" not deleted

    "C:\Program Files (x86)\Minibar" deleted

    "C:\PROGRA~2\SEARCH~1\DATAMNGR" deleted

    "C:\ProgramData\BrowserDefender" not deleted

    "C:\Program Files (x86)\Minibar" deleted

    "C:\Program Files (x86)\LyricsPal" not deleted

    "C:\Users\Rossi925\AppData\Roaming\DriverCure" deleted

    "C:\Users\Rossi925\AppData\Roaming\Babylon" deleted

    "C:\ProgramData\BrowserDefender" not deleted

    "C:\ProgramData\WINCERT" deleted

    "C:\ProgramData\Babylon" deleted

    "C:\Users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LSHunter.TV" deleted

    "C:\Users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender" deleted

    "C:\Users\Rossi925\AppData\Local\iLivid" deleted

    "C:\Users\Rossi925\AppData\Local\Minibar" deleted

    "C:\Users\Rossi925\AppData\Local\Bundled software uninstaller" deleted

    "C:\Users\Rossi925\AppData\LocalLow\Delta" deleted

    "C:\Windows\SysWow64\searchplugins" deleted

    "C:\Windows\SysWow64\Extensions" deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}" not deleted

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings" not deleted

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    ====== C:\Users\Rossi925\AppData\Local\Temp ====

    2013-08-19 19:49:17 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\ESGScanner.sys

    2013-08-19 19:36:21 B575AB32F77C20EB24D2EB4822B0EFBA 46646352 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\SHSetup.exe

    2013-08-19 19:00:35 DB521C3DC7B679226322033B09719ECA 339440 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\uninst1.exe

    2013-08-19 18:57:33 B3FDF6E7B0AECD48CA7E4921773FB606 1110476 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\7z920.exe

    2013-08-19 18:57:32 2F5252E50745E47DB355B005725DAE05 327880 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\appshat-distribution.exe

    2013-08-19 18:57:28 06561D1CE80C12575F9A8920E2734393 787440 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\DeltaTB.exe

    2013-08-19 18:57:20 8F4B9ED66402EFDE8BCA5274A0BA21A5 4620384 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\OptimizerPro.exe

    2013-08-19 18:57:18 9E50AAF44D446AB37F32EBECE3589102 607107 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\LyricsPal_1060-8101_v122.exe

    ====== C:\Windows\SysWOW64 =====

    2013-08-14 08:20:06 C9BFFA62DFBF0317AECE707B39C4BF25 391168 ----a-w- C:\Windows\SysWOW64\ieui.dll

    2013-08-14 08:20:06 AF6A6C16ACAD816B48714AE7A4082D89 61440 ----a-w- C:\Windows\SysWOW64\iesetup.dll

    2013-08-14 08:20:06 A484F9DB744849C0B32DD1CE73A94F62 2706432 ----a-w- C:\Windows\SysWOW64\mshtml.tlb

    2013-08-14 08:20:05 D0E0086BA353C379DCFE8624E8B8F17A 2048512 ----a-w- C:\Windows\SysWOW64\iertutil.dll

    2013-08-14 08:20:05 BC90EED56A5C77168A8D6F0C4221D7CB 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2013-08-14 08:20:05 8A5BD908D421BEE82941EF8ABD8B4F09 33280 ----a-w- C:\Windows\SysWOW64\iernonce.dll

    2013-08-14 08:20:05 37730C04B543536D971B3F157415EFF5 109056 ----a-w- C:\Windows\SysWOW64\iesysprep.dll

    2013-08-14 08:20:04 45C118A1E03182365CB568F99B81A473 493056 ----a-w- C:\Windows\SysWOW64\msfeeds.dll

    2013-08-14 08:20:04 1C83426A51AD83B5E788B6CF143B48D8 690688 ----a-w- C:\Windows\SysWOW64\jscript.dll

    2013-08-14 08:20:03 AC8C3591D536D1CCB62EDCBEA88140B3 2877440 ----a-w- C:\Windows\SysWOW64\jscript9.dll

    2013-08-14 08:20:03 059FC59F97A6220C46A612A9470A00B3 1141248 ----a-w- C:\Windows\SysWOW64\urlmon.dll

    2013-08-14 08:20:02 DAA3903F06116AE9EE7AC1D1B93684A4 1767936 ----a-w- C:\Windows\SysWOW64\wininet.dll

    2013-08-14 08:20:02 49EB7DE3A1CCCE9D0873DE9114810113 39936 ----a-w- C:\Windows\SysWOW64\jsproxy.dll

    2013-08-14 08:20:01 E9BCB6728DD04412BF87F03DB00DE1CF 13761024 ----a-w- C:\Windows\SysWOW64\ieframe.dll

    2013-08-14 08:19:58 E631B408882F8320739F6E0CAF444397 14329344 ----a-w- C:\Windows\SysWOW64\mshtml.dll

    2013-08-14 07:52:19 AE8EB083B050E17A7D6EB5E28AECDDD6 1166848 ----a-w- C:\Windows\SysWOW64\crypt32.dll

    2013-08-14 07:52:19 7CA1BECEA5DE2643ADDAD32670E7A4C9 140288 ----a-w- C:\Windows\SysWOW64\cryptsvc.dll

    2013-08-14 07:52:19 7B851A8018B1EA00A69707A390004884 103936 ----a-w- C:\Windows\SysWOW64\cryptnet.dll

    2013-08-14 07:52:19 68EAAEDF0365168B804E8728368FA946 175104 ----a-w- C:\Windows\SysWOW64\wintrust.dll

    2013-08-14 07:52:12 0805487A6036A9F9C4E7AF7FEF835529 1620992 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL

    2013-08-14 07:52:09 D5E18BA95F9E7D787D25EF07AC68603E 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll

    2013-08-14 07:52:01 4DC999CED9429939D75682EBD7D48901 663552 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll

    2013-08-14 07:51:45 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

    2013-08-14 07:51:44 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

    2013-08-14 07:51:43 77F5D2CB80697EB96C45E79A869A6FAC 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll

    2013-08-14 07:51:43 528D298F9914C558EA7A9809BE598E65 1292192 ----a-w- C:\Windows\SysWOW64\ntdll.dll

    2013-08-14 07:51:42 4E77948A7BD16BA5724EC79C60176B03 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll

    2013-08-14 07:51:41 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

    2013-08-14 07:51:41 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

    2013-08-14 07:51:41 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

    ====== C:\Windows\SysWOW64\drivers =====

    ====== C:\Windows\Sysnative =====

    2013-08-14 08:20:07 3A2FD42F11CD325A4ACAFE7FB0EEA83A 2706432 ----a-w- C:\Windows\Sysnative\mshtml.tlb

    2013-08-14 08:20:06 69F5E016A98CE1908DB08382F2ACF882 526336 ----a-w- C:\Windows\Sysnative\ieui.dll

    2013-08-14 08:20:05 D8CC9A20C517A54678363C4C77B930A4 136704 ----a-w- C:\Windows\Sysnative\iesysprep.dll

    2013-08-14 08:20:05 963B29E0EFB20D66436214DB7C43D7F7 67072 ----a-w- C:\Windows\Sysnative\iesetup.dll

    2013-08-14 08:20:05 6C8BDC9F16943D626DFE8A987BCCFD20 51712 ----a-w- C:\Windows\Sysnative\ie4uinit.exe

    2013-08-14 08:20:05 65546D87F7A78AB31841A536456CB94D 2647040 ----a-w- C:\Windows\Sysnative\iertutil.dll

    2013-08-14 08:20:05 622C7C8D39609FCEACE3508715D48C7F 39936 ----a-w- C:\Windows\Sysnative\iernonce.dll

    2013-08-14 08:20:05 28C2F8C7DBE11AA3DA041D35F4E59481 89600 ----a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe

    2013-08-14 08:20:04 8C12653BEA781902AA60E4A855A55D5C 603136 ----a-w- C:\Windows\Sysnative\msfeeds.dll

    2013-08-14 08:20:04 5A7FA01EEC393A3E0D0F3EBAA1FD959E 3958784 ----a-w- C:\Windows\Sysnative\jscript9.dll

    2013-08-14 08:20:04 16FE878530FDFC9AB08B7FFC32335958 855552 ----a-w- C:\Windows\Sysnative\jscript.dll

    2013-08-14 08:20:03 289C5E0A386E7B6CA9539D66D15E22CC 1365504 ----a-w- C:\Windows\Sysnative\urlmon.dll

    2013-08-14 08:20:02 AC155DD9BD1E6D3B740826A4D1C68AAE 2241024 ----a-w- C:\Windows\Sysnative\wininet.dll

    2013-08-14 08:20:02 04DE09B1E287F6DC5C7FD655B6E84AB9 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll

    2013-08-14 08:20:00 677A1C1B0F254EC918D84A7FE29274CA 15405056 ----a-w- C:\Windows\Sysnative\ieframe.dll

    2013-08-14 08:19:59 396889142BD839DB8A055A0BE0AD2F79 19239424 ----a-w- C:\Windows\Sysnative\mshtml.dll

    2013-08-14 07:52:20 287998A9BA0140ABB59792CDEB2F8483 1472512 ----a-w- C:\Windows\Sysnative\crypt32.dll

    2013-08-14 07:52:19 A6B726DCA228F7878E38368A1BDC68BE 139776 ----a-w- C:\Windows\Sysnative\cryptnet.dll

    2013-08-14 07:52:19 959041D7014C97133D859B45BCA0FC58 224256 ----a-w- C:\Windows\Sysnative\wintrust.dll

    2013-08-14 07:52:19 6B400F211BEE880A37A1ED0368776BF4 184320 ----a-w- C:\Windows\Sysnative\cryptsvc.dll

    2013-08-14 07:52:13 D29200AB0B37B7293C6942EAF755295E 1888768 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL

    2013-08-14 07:52:09 B3CA3253009D26666F5BCB16E77D2618 2048 ----a-w- C:\Windows\Sysnative\tzres.dll

    2013-08-14 07:52:02 26036E228D2467DE6975AD819C22C043 1217024 ----a-w- C:\Windows\Sysnative\rpcrt4.dll

    2013-08-14 07:51:44 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe

    2013-08-14 07:51:43 D6180FBBADA79BC28E5FD8187EBE7F64 243712 ----a-w- C:\Windows\Sysnative\wow64.dll

    2013-08-14 07:51:43 8E45DD84F8F786B2DB94AD95225B9246 1732032 ----a-w- C:\Windows\Sysnative\ntdll.dll

    ====== C:\Windows\Sysnative\drivers =====

    2013-08-14 07:52:22 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\Sysnative\drivers\tssecsrv.sys

    2013-08-14 07:52:20 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys

    ====== C:\Windows\Tasks ======

    2013-08-19 21:01:43 68E9FB5D83585CFEA1558EA318169AA0 2946 ----a-w- C:\Windows\Sysnative\Tasks\{DE3FEA7E-DB3C-4DE7-8361-0BCE81EF39DD}

    2013-07-28 07:50:19 5005FB322BD30A8BD2BEC2FF12DB68C4 3352 ----a-w- C:\Windows\Sysnative\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-209168772-1577477127-873989120-1001

    2013-07-25 18:00:03 9317211978B29D24DE556E4B8C32972D 3440 ----a-w- C:\Windows\Sysnative\Tasks\{E350AF91-6716-4282-8934-0C23462AE054}

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    ======= C:\Program Files (x86) =====

    2013-08-19 20:20:20 -------- d-----w- C:\Program Files (x86)\Trend Micro

    2013-08-19 18:57:37 -------- d-----w- C:\Program Files (x86)\LyricsPal

    2013-08-19 17:06:04 -------- d-----w- C:\Program Files (x86)\Garmin GPS Plugin

    2013-07-31 12:47:04 -------- d-----w- C:\Program Files (x86)\OpenAL

    2013-07-28 07:49:41 -------- d-----w- C:\Program Files (x86)\Real

    2013-07-26 11:57:16 -------- d-----w- C:\Program Files (x86)\Common Files\Nero

    2013-07-26 11:57:11 -------- d-----w- C:\Program Files (x86)\Nero

    2013-07-25 11:12:04 -------- d-----w- C:\Program Files (x86)\MSXML 4.0

    ======= C: =====

    ====== C:\Users\Rossi925\AppData\Roaming ======

    2013-08-19 18:59:18 -------- d-----w- C:\users\Rossi925\AppData\Locallow\Minibar

    2013-08-19 18:58:19 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat

    2013-08-19 18:58:19 -------- d-----w- C:\users\Rossi925\AppData\Local\WebPlayer

    2013-08-19 18:58:17 -------- d-----w- C:\users\Rossi925\AppData\Local\avgchrome

    2013-08-09 15:36:50 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin

    2013-08-07 20:49:45 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games

    2013-08-04 14:54:58 97680694BE2FCA4AC22D6C39BB51CAA5 3584 ----a-w- C:\users\Rossi925\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

    2013-08-03 11:32:35 -------- d-----w- C:\users\Rossi925\AppData\Locallow\Temp

    2013-07-31 12:47:13 -------- d-----w- C:\users\Rossi925\AppData\Local\76561197972651619

    2013-07-28 07:49:27 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Real

    2013-07-25 17:48:37 -------- d-----w- C:\users\Rossi925\AppData\Roaming\CyberLink

    2013-07-24 21:23:25 -------- d-----w- C:\users\Rossi925\AppData\Local\Nero_AG

    2013-07-24 15:52:14 -------- d-----w- C:\users\Rossi925\AppData\Roaming\Nero

    ====== C:\Users\Rossi925 ======

    2013-08-19 19:36:08 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Rossi925\Downloads\SpyHunter-Installer.exe

    2013-08-19 19:09:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

    2013-08-19 18:57:57 -------- d-----w- C:\ProgramData\BrowserDefender

    2013-08-19 18:57:04 DA0373643B12CF8DB4098A6A273032C3 166656 ----a-w- C:\Users\Rossi925\Downloads\Adlock10_downloader_by_Adlock10.exe

    2013-08-19 18:56:43 D37870ECD5BB93FE99758C48AC64794E 725584 ----a-w- C:\Users\Rossi925\Downloads\Babylon10_setup.exe

    2013-08-19 17:04:46 C3EDCCA1FD54009D7C56EEC837148DC8 18854112 ----a-w- C:\Users\Rossi925\Downloads\CommunicatorPlugin_404.exe

    2013-08-01 13:53:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA

    2013-07-31 12:47:15 -------- d-----w- C:\ProgramData\Creative Labs

    2013-07-31 07:08:32 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

    2013-07-28 07:48:54 -------- d-----w- C:\ProgramData\Real

    2013-07-26 11:57:11 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero

    2013-07-25 17:48:37 -------- d-----w- C:\Users\Public\CyberLink

    2013-07-24 15:39:38 -------- d-----w- C:\ProgramData\Nero

    ====== C: exe-files ==

    2013-08-19 20:28:55 25D473D7805261C752DA738B13E35816 185271 ----a-w- C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla31.exe

    2013-08-19 19:48:35 22D3D73B2FA74C01D8D1CBA813D574B8 190411 ----a-w- C:\Windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla37.exe

    2013-08-19 19:36:21 B575AB32F77C20EB24D2EB4822B0EFBA 46646352 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\SHSetup.exe

    2013-08-19 19:36:08 29702C25639B549AC5221E546545D56B 728960 ----a-w- C:\Users\Rossi925\Downloads\SpyHunter-Installer.exe

    2013-08-19 19:09:02 4A3B3C915C3FC187689EC0EB116C2616 33792864 ----a-w- C:\Program Files (x86)\Google\Update\Install\{D0867559-4F3B-423D-9C46-03E66A109A79}\28.0.1500.95_chrome_installer.exe

    2013-08-19 19:09:01 4A3B3C915C3FC187689EC0EB116C2616 33792864 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\28.0.1500.95\28.0.1500.95_chrome_installer.exe

    2013-08-19 19:08:48 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\inst...app_4fe91ede9f9bdca3_0001.0003_fc100576141c6894\GoogleUpdateSetup.exe

    2013-08-19 19:08:48 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\clic...exe_4fe91ede9f9bdca3_0001.0003_none_81523f7b64d98436\GoogleUpdateSetup.exe

    2013-08-19 19:08:48 2D479A35439E0DFBDBF2FDB6DEE8D49B 10120 ------w- C:\Users\Rossi925\AppData\Local\Apps\2.0\R8PCELKB.RDB\MNDJ0MQ5.CK6\inst...app_4fe91ede9f9bdca3_0001.0003_fc100576141c6894\clickonce_bootstrap.exe

    2013-08-19 19:00:35 DB521C3DC7B679226322033B09719ECA 339440 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\uninst1.exe

    2013-08-19 18:58:19 D8BA5F4E6A1594D0E07C886DAC0F5F8C 64142 ----a-w- C:\Users\Rossi925\AppData\Local\WebPlayer\Uninstall.exe

    2013-08-19 18:57:59 6A08ED5BB65B3874928F147504685ECD 2838992 ----a-w- C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe

    2013-08-19 18:57:59 6A08ED5BB65B3874928F147504685ECD 2838992 ----a-w- C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe

    2013-08-19 18:57:33 B3FDF6E7B0AECD48CA7E4921773FB606 1110476 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\7z920.exe

    2013-08-19 18:57:32 2F5252E50745E47DB355B005725DAE05 327880 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\appshat-distribution.exe

    2013-08-19 18:57:28 06561D1CE80C12575F9A8920E2734393 787440 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\DeltaTB.exe

    2013-08-19 18:57:20 8F4B9ED66402EFDE8BCA5274A0BA21A5 4620384 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\OptimizerPro.exe

    2013-08-19 18:57:18 9E50AAF44D446AB37F32EBECE3589102 607107 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\LyricsPal_1060-8101_v122.exe

    2013-08-19 18:57:04 DA0373643B12CF8DB4098A6A273032C3 166656 ----a-w- C:\Users\Rossi925\Downloads\Adlock10_downloader_by_Adlock10.exe

    2013-08-19 18:56:43 D37870ECD5BB93FE99758C48AC64794E 725584 ----a-w- C:\Users\Rossi925\Downloads\Babylon10_setup.exe

    2013-08-19 17:04:46 C3EDCCA1FD54009D7C56EEC837148DC8 18854112 ----a-w- C:\Users\Rossi925\Downloads\CommunicatorPlugin_404.exe

    2013-08-15 20:51:05 A8A497E0AD525A819DF7188D2A79007D 1096192 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Mapupload\MAPUPLOAD.EXE

    2013-08-15 12:59:46 0075F4CF39B928A63D7E2C325A8A14E1 1903336 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\83EF0D0E-BAB0-7891-907A-A1D5F391AE23\Latest\MyDeltaTB.exe

    2013-08-14 08:20:05 BC90EED56A5C77168A8D6F0C4221D7CB 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2013-08-14 08:20:05 7BA1862B8A5698DC5FCFDFF3BC359DE9 770648 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe

    2013-08-14 08:20:05 6C8BDC9F16943D626DFE8A987BCCFD20 51712 ----a-w- C:\Windows\System32\ie4uinit.exe

    2013-08-14 08:20:05 28C2F8C7DBE11AA3DA041D35F4E59481 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2013-08-14 08:20:04 133CEF30905806A35606652D409EEEBA 775256 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe

    2013-08-14 07:51:45 9FA7BF625122CCAC90FCD307174D8CF3 3913664 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe

    2013-08-14 07:51:44 DD5F17D44E9966E7EA447AE8C4D12D6C 3968960 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe

    2013-08-14 07:51:44 C19DCA1024135D5485E25AB1047F77BC 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe

    2013-08-14 07:51:41 D313AE69128A75367AA36E15522931F6 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe

    2013-08-14 07:51:41 CFEEF3185342ADEAE1E77A017052565B 2048 ----a-w- C:\Windows\SysWOW64\user.exe

    2013-08-14 07:51:41 3EED15C223E139C3A28B458800E52BF3 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe

    2013-08-13 21:23:30 9E970EB020EC22032DBBD0BD8C2C659F 525656 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\Redist\DirectX\DXSETUP.exe

    2013-08-13 21:23:30 6DD89ADFE3A4FFF3738F5BE2566AE7FA 3501720 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe

    2013-08-13 21:23:30 5C82BE7AD1775B67916EE19C15B99331 2723264 ----a-w- C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\Redist\vcredist_x86.exe

    2013-08-13 07:09:56 16E5360B03577B0B8775FFAFC403A5E3 243976 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\83EF0D0E-BAB0-7891-907A-A1D5F391AE23\Latest\ccp.exe

    === C: other files ==

    2013-08-19 19:49:17 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Users\Rossi925\AppData\Local\Temp\ESGScanner.sys

    2013-08-17 13:34:57 F3DCE782F7BB35B79DB98DE2FFF3847B 184588 ----a-w- C:\Users\Rossi925\Desktop\Nieuwe map\moonshl2\extlink\nes.nesterds.source.zip

    2013-08-17 13:34:56 B5CFA9D6C8FEBD618F91AC2843D50A1C 4194304 ----a-w- C:\Users\Rossi925\Desktop\Nieuwe map\SYSTEM.SYS

    2013-08-15 20:50:53 85B8E7C5B5383EC5BFA0B7E3E7B69F10 677 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAM_1395\uninstall.bat

    2013-08-15 20:50:53 7503E7718E6F1B11F48BDAE12A00B341 1427 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAM_1395\install.bat

    2013-08-15 20:50:41 D3BAD0E54A8B6A3DD8BDC209163E85F2 678 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAMILY_2215\uninstall.bat

    2013-08-15 20:50:41 5AFE8933C5DDFA0BA3248F3329FB6B83 1257 ----a-w- C:\Users\Rossi925\Downloads\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor Gps Garmin (oudoor) en MapSource\Kaarten voor MapSource\FAMILY_2215\install.bat

    2013-08-14 07:52:22 4CE278FC9671BA81A138D70823FCAA09 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys

    2013-08-14 07:52:20 DB74544B75566C974815E79A62433F29 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys

    ==== Startup Registry Enabled ======================

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Windows\CurrentVersion\Run]

    "ANT Agent"="C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe"

    "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"

    "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    "Spotify Web Helper"="C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    "AppsHat"="C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1003\Software\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

    [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "mctadmin"="C:\Windows\System32\mctadmin.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Nuance PDF Reader-reminder"="C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe -r C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"

    "ASUSPRP"="C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

    "ASUSWebStorage"="C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S"

    "Gaming Mouse Hid"="C:\Program Files (x86)\Gaming Mouse\hid.exe"

    "ASUS Screen Saver Protector"="C:\Windows\AsScrPro.exe"

    "THX TruStudio NB Settings"="C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe /r"

    "UpdReg"="C:\Windows\UpdReg.EXE"

    "CPMonitor"="C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"

    "VAWinAgent"="C:\ExpressGateUtil\VAWinAgent.exe"

    "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5"

    "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

    "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0"

    "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "ATKOSD2"="C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"

    "ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"

    "HControlUser"="C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"

    "Wireless Console 3"="C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"

    "FLxHCIm64"="C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"

    "AllShareAgent"="C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe"

    "Aimersoft Helper Compact.exe"="C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe"

    "BrowserPlugInHelper"="C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe"

    "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup"

    "AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

    "ANT Agent"="C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe"

    "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"

    "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    "Spotify Web Helper"="C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    "AppsHat"="C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"

    ==== Startup Registry Enabled x64 ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"

    "AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

    "AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"

    "IntelTBRunOnce"="wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"

    "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"

    ==== Startup Registry Disabled x64 ======================

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Mio Share]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Mio Share"

    "hkey"="HKCU"

    "command"="C:\\Users\\Rossi925\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Mio\\Mio Share.appref-ms"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Skype"

    "hkey"="HKCU"

    "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Spotify"

    "hkey"="HKCU"

    "command"="\"C:\\Users\\Rossi925\\AppData\\Roaming\\Spotify\\Spotify.exe\" /uri spotify:autostart"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper]

    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

    "item"="Spotify Web Helper"

    "hkey"="HKCU"

    "command"="\"C:\\Users\\Rossi925\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\""

    ==== Startup Folders ======================

    2011-04-13 02:49:43 2062 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk

    2013-07-13 09:59:53 2071 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Polar WebSync.lnk

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12/06/2013 13:50]

    C:\Windows\tasks\AutoKMS.job --a------ C:\Windows\AutoKMS\AutoKMS.exe []

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [18/04/2013 13:32]

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [undetermined Task]

    ==== Firefox Extensions ======================

    AppDir: C:\Program Files (x86)\Mozilla Firefox

    - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be

    ==== Firefox Plugins ======================

    ==== Chrome Look ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    mapcejffhcbidcjmomhalabpcbaeimcb - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRChromePlugin.crx[08/05/2013 15:13]

    pnbbffeddnekkhjmokkhdebbfbibbflc - C:\Program Files (x86)\LyricsPal\128.crx[]

    Windows Media Player Extension for HTML5 - Rossi925 - Default\Extensions\hokdglbhghcebcopdbanieangmcamaak

    Aimersoft Video Converter Ultimate - Rossi925 - Default\Extensions\mapcejffhcbidcjmomhalabpcbaeimcb

    ==== Chrome Fix ======================

    C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hitman-blood-money.nl.softonic.com_0.localstorage deleted successfully

    C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hitman-blood-money.nl.softonic.com_0.localstorage-journal deleted successfully

    C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www1.delta-search.com_0.localstorage deleted successfully

    C:\Users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www1.delta-search.com_0.localstorage-journal deleted successfully

    ==== Set IE to Default ======================

    Old Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag"

    New Values:

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

    "Start Page"="HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found"

    {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} Unknown Url="Not_Found"

    {33BB0A4E-99AF-4226-BDF6-49120163DE86} Unknown Url="Not_Found"

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

    {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Unknown Url="Not_Found"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F7EB7A06-B2C0-4440-BB2A-79B7EABE50B4} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F7EB7A06-B2C0-4440-BB2A-79B7EABE50B4} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f7eb7a06-b2c0-4440-bb2a-79b7eabe50b4} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully

    HKEY_USERS\S-1-5-21-209168772-1577477127-873989120-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully

    HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{F7EB7A06-B2C0-4440-BB2A-79B7EABE50B4} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F7EB7A06-B2C0-4440-BB2A-79B7EABE50B4} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Registry Keys ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pnbbffeddnekkhjmokkhdebbfbibbflc deleted successfully

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OTA2A8N4 will be deleted at reboot

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0IAM6MFY will be deleted at reboot

    C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NSYC885N will be deleted at reboot

    ==== Empty FireFox Cache ======================

    No FireFox Cache found

    ==== Empty Chrome Cache ======================

    C:\users\Rossi925\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    No Java Cache Found

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Rossi925\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22" not found

    "C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23" not found

    "C:\ProgramData\BrowserDefender" not found

    "C:\Program Files (x86)\LyricsPal" not found

    "C:\ProgramData\BrowserDefender" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OTA2A8N4" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0IAM6MFY" not found

    "C:\Users\Rossi925\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NSYC885N" not found

    ==== EOF on ma 19/08/2013 at 23:29:01,53 ======================

  7. Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:25:27, on 19/08/2013

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v10.0 (10.00.9200.16660)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    C:\Program Files (x86)\Steam\Steam.exe

    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

    C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe

    C:\Program Files (x86)\Polar\WebSync\WebSync.exe

    C:\Windows\AsScrPro.exe

    C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe

    C:\ExpressGateUtil\VAWinAgent.exe

    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe

    C:\Program Files (x86)\AVG\AVG2013\avgui.exe

    C:\Program Files (x86)\Gaming Mouse\Tray.exe

    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    C:\Windows\SysWOW64\DllHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN.be, Nieuws, sport en showbizz, 24/24, 7/7, meer dan 350 nieuwsupdates per dag

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: UsProvider Class - {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files (x86)\Minibar\Minibar.dll

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: WsSVRIEHelper - {54F73992-6549-4369-9A0D-84FD310A464A} - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll

    O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: MinibarBHO - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Minibar.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O2 - BHO: Lyrics-Pal - {f7eb7a06-b2c0-4440-bb2a-79b7eabe50b4} - C:\Program Files (x86)\LyricsPal\128.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"

    O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

    O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S

    O4 - HKLM\..\Run: [Gaming Mouse Hid] "C:\Program Files (x86)\Gaming Mouse\hid.exe"

    O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe

    O4 - HKLM\..\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r

    O4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXE

    O4 - HKLM\..\Run: [CPMonitor] "C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe"

    O4 - HKLM\..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe

    O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"

    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

    O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~2.EXE

    O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    O4 - HKLM\..\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"

    O4 - HKLM\..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    O4 - HKLM\..\Run: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe

    O4 - HKLM\..\Run: [browserPlugInHelper] C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY

    O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Rossi925\AppData\Roaming\Yontoo\YontooDesktop.exe"

    O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\Rossi925\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"

    O4 - HKCU\..\Run: [AppsHat] C:\Users\Rossi925\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe

    O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe

    O4 - Global Startup: Polar WebSync.lnk = C:\Program Files (x86)\Polar\WebSync\WebSync.exe

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll

    O9 - Extra button: Visit AppsHat.com - {AAA38851-3CFF-475F-B5E0-720D3645E4A5} - C:\Program Files (x86)\Minibar\Minibar.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O20 - AppInit_DLLs: c:\progra~3\browse~1\261546~1.206\{c16c1~1\browse~1.dll c:\progra~3\wincert\win32c~1.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    O23 - Service: Asus process privilege adjust service (AsusUacSvc) - Unknown owner - C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe

    O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

    O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe

    O23 - Service: BrowserDefendert - Unknown owner - C:\ProgramData\BrowserDefender\2.6.1546.206\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe

    O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe

    O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe

    O23 - Service: DiscountfinderService - Unknown owner - C:\ProgramData\Kortingzoeker\DFService.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

    O23 - Service: Polar Daemon - Unknown owner - C:\Program Files (x86)\Polar\Daemon\polard.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Samsung AllShare PC Service (SamsungAllShare) - Unknown owner - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\WiselinkPro.exe

    O23 - Service: SimpleSlideShowServer - Samsung Electronics - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    O23 - Service: Intel® Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: VideAceWindowsService - Unknown owner - C:\ExpressGateUtil\VAWinService.exe

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 15731 bytes

  8. ----------------- FindyKill V4.005 ------------------

    * User : Mario - GEBRUIK-ZTI84EP

    * Emplacement : C:\Program Files\FindyKill

    * Outils Mis a jours le 17/10/08 par Chiquitine29

    * Recherche effectuée à 10:50:57 le za 21/08/2010

    * Windows_NT - Internet Explorer 8.0.7600.16385

    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

    --------------- [ Processus actifs ] ----------------

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe

    C:\Windows\SysWOW64\svchost.exe

    C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe

    C:\Windows\SysWOW64\PnkBstrA.exe

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\Steam\steam.exe

    C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    C:\Program Files (x86)\Skype\Phone\Skype.exe

    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe

    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe

    C:\Windows\V0330Mon.exe

    C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    --------------- [ Fichiers/Dossiers infectieux ] ----------------

    »»»» Presence des fichiers dans C:

    »»»» Presence des fichiers dans C:\Windows

    »»»» Presence des fichiers dans C:\Windows\Prefetch

    Present ! - C:\Windows\prefetch\MDELK.EXE-F8530D61.pf

    »»»» Presence des fichiers dans C:\Windows\system32

    »»»» Presence des fichiers dans C:\Windows\system32\drivers

    »»»» Presence des fichiers dans C:\Users\Mario\AppData\Roaming

    »»»» Presence des fichiers dans C:\Users\Mario\AppData\Local\Temp

    --------------- [ Registre / Startup ] ----------------

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    IAAnotif REG_SZ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe

    MSSE REG_SZ "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey

    Launch LgDevAgt REG_SZ "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"

    Launch LCDMon REG_SZ "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"

    Launch LGDCore REG_SZ "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE

    Windows Mobile Device Center REG_EXPAND_SZ %windir%\WindowsMobile\wmdc.exe

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    msnmsgr REG_SZ "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

    Steam REG_SZ "c:\program files (x86)\steam\steam.exe" -silent

    swg REG_SZ "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    ANT Agent REG_SZ C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    Skype REG_SZ "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

    --------------- [ Registre / Clés infectieuses ] ----------------

    --------------- [ Etat / Services ] ----------------

    +- Services : [ Auto=2 Demande=3 Désactivé=4 ]

    Ndisuio - Type de démarrage = 3

    EapHost - Type de démarrage = 3

    Wlansvc - Type de démarrage = 3

    /!\ SharedAccess - Type de démarrage = 4

    wuauserv - Type de démarrage = 2

    wscsvc - Type de démarrage = 2

    --------------- [ Recherche dans supports amovibles] ----------------

    +- Informations :

    C: - vast station

    D: - vast station

    E: - cd-rom-station

    F: - cd-rom-station

    G: - vast station

    +- Contenu de l'autorun : E:\autorun.inf

    [AutoRun]

    OPEN=autorun.exe

    ICON=Conviction.ico

    +- Contenu de l'autorun : F:\autorun.inf

    [autorun]

    open=Autorun.exe

    Icon=Autorun.ico

    Name=Battlefield Bad Company 2

    [special]

    Disk=1

    ProductGuiID={3AC8457C-0385-4BEA-A959-E095F05D6D67}

    +- presence des fichiers :

    Présent ! - E:\autorun.inf

    Présent ! - F:\autorun.inf

    --------------- [ Registre / Moutpoint2 ] ----------------

    -> Recherche négative.

    ------------------- ! Fin du rapport ! --------------------

  9. KASPERSKY ONLINE SCANNER 7.0: scan report

    Friday, August 20, 2010

    Operating system: Microsoft (build 7600)

    Kaspersky Online Scanner version: 7.0.26.13

    Last database update: Friday, August 20, 2010 07:29:41

    Records in database: 4131583

    --------------------------------------------------------------------------------

    Scan settings:

    scan using the following database: extended

    Scan archives: yes

    Scan e-mail databases: yes

    Scan area - My Computer:

    A:\

    C:\

    D:\

    E:\

    F:\

    G:\

    Scan statistics:

    Objects scanned: 177904

    Threats found: 9

    Infected objects found: 12

    Suspicious objects found: 0

    Scan duration: 03:58:27

    File name / Threat / Threats count

    C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{72A9B818-5480-229D-F3A5-A52B7763FBB9}-Mwozya.exe Infected: Packed.Win32.Katusha.n 1

    C:\Users\All Users\Microsoft\Microsoft Antimalware\LocalCopy\{72A9B818-5480-229D-F3A5-A52B7763FBB9}-Mwozya.exe Infected: Packed.Win32.Katusha.n 1

    C:\Users\Mario\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\155b0e55-368bb4f7 Infected: Trojan-Downloader.Java.Agent.ft 1

    C:\Users\Mario\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\155b0e55-368bb4f7 Infected: Trojan-Downloader.Java.Agent.fu 1

    C:\Users\Mario\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\155b0e55-368bb4f7 Infected: Trojan-Downloader.Java.Agent.fv 1

    C:\Users\Mario\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\7adbb65d-46735d99 Infected: Exploit.Java.Agent.f 1

    D:\daemon406-x86.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1

    D:\mario\Zuma Deluxe(Full) crack keygen.zip Infected: Trojan.Win32.VB.ujs 2

    D:\p2p\SweetImSetup.exe Infected: not-a-virus:AdWare.Win32.Mostofate.aa 1

    G:\GAMES\Installed games\FIFA10\FIFA10.exe Infected: Trojan-Dropper.Win32.VB.mwg 1

    G:\GAMES\Volledige Games\FIFA10\FIFA10.iso Infected: Trojan-Dropper.Win32.VB.mwg 1

    Selected area has been scanned.

  10. Ik heb ondertussen last van vervelende popups ook vandaar deze nieuwe log,oa lpbe.zengo.com en ook opnieuw adserving cpxinteractive .com,http://fr.allods.gpotato.eu/,http://fiesta.outspark.com/

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 0:02:55, on 20/08/2010

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.16385)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Steam\steam.exe

    C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe

    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe

    C:\Windows\V0330Mon.exe

    C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe

    C:\Program Files (x86)\Piolet\Piolet.exe

    C:\Program Files (x86)\Piolet\BGCheck.exe

    C:\Program Files (x86)\Vuze\Azureus.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O3 - Toolbar: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - (no file)

    O4 - HKLM\..\Run: [bCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"

    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\SysWOW64\NeroCheck.exe

    O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [steam] "c:\program files (x86)\steam\steam.exe" -silent

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

    O15 - Trusted IP range: http://127.0.0.1

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB

    O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updateservice (gupdate1caea43b39e40fe) (gupdate1caea43b39e40fe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 12288 bytes

  11. Malwarebytes' Anti-Malware 1.46

    www.malwarebytes.org

    Databaseversie: 4391

    Windows 6.1.7600

    Internet Explorer 8.0.7600.16385

    19/08/2010 22:46:56

    mbam-log-2010-08-19 (22-46-56).txt

    Scantype: Snelle scan

    Objecten gescand: 139453

    Verstreken tijd: 3 minuut/minuten, 5 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 1

    Registerwaarden geïnfecteerd: 0

    Registerdata geïnfecteerd: 0

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 0

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    ogfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:48:20, on 19/08/2010

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.16385)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\Steam\steam.exe

    C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe

    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe

    C:\Windows\V0330Mon.exe

    C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O3 - Toolbar: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - (no file)

    O4 - HKLM\..\Run: [bCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"

    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\SysWOW64\NeroCheck.exe

    O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [steam] "c:\program files (x86)\steam\steam.exe" -silent

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

    O15 - Trusted IP range: http://127.0.0.1

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB

    O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updateservice (gupdate1caea43b39e40fe) (gupdate1caea43b39e40fe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 12224 bytes

  12. Ik doe langs deze weg nog eens een beroep op jullie,de vorige keer was het in feite opgelost maar heb nu met dezelfde kenmerken te maken alléén ontbreken er nu een paar logs in vergelijking met de eerste keer.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 0:22:58, on 19/08/2010

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.16385)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Steam\steam.exe

    C:\Program Files (x86)\GamesBar\SearchEngineProtection.exe

    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe

    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe

    C:\Windows\V0330Mon.exe

    C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\FrostWire\FrostWire.exe

    C:\Program Files (x86)\FrostWire\FrostWire.exe

    C:\Program Files (x86)\Windows Media Player\wmplayer.exe

    C:\Program Files (x86)\Piolet\Piolet.exe

    C:\Program Files (x86)\Piolet\BGCheck.exe

    C:\Program Files (x86)\Vuze\Azureus.exe

    C:\Users\Mario\AppData\Local\Temp\Mvx.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

    R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: RadioBar Toolbar - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll

    O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O3 - Toolbar: RadioBar Toolbar - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll

    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    O4 - HKLM\..\Run: [bCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"

    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\SysWOW64\NeroCheck.exe

    O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [steam] "c:\program files (x86)\steam\steam.exe" -silent

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe

    O4 - HKCU\..\Run: [searchEngineProtection] C:\Program Files (x86)\Gamesbar\SearchEngineProtection.exe

    O4 - HKCU\..\Run: [ZE18MW23GY] C:\Users\Mario\AppData\Local\Temp\Mvx.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll

    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

    O15 - Trusted IP range: http://127.0.0.1

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB

    O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Protocol: toolbarchrome - {718733BC-AD64-4E5F-AC18-A85FBD75D54D} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updateservice (gupdate1caea43b39e40fe) (gupdate1caea43b39e40fe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 13385 bytes

  13. Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 1:36:17, on 5/08/2010

    Platform: Windows 7 (WinNT 6.00.3504)

    MSIE: Internet Explorer v8.00 (8.00.7600.16385)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files (x86)\Steam\steam.exe

    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe

    C:\PROGRA~2\Raptr\raptr.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe

    C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe

    C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe

    C:\Windows\V0330Mon.exe

    C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\Vuze\Azureus.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\FrostWire\FrostWire.exe

    C:\Program Files (x86)\Windows Live\Mail\wlmail.exe

    C:\Program Files (x86)\Piolet\Piolet.exe

    C:\Program Files (x86)\Piolet\BGCheck.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Internet Explorer\iexplore.exe

    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = HLN home

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll

    R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll

    R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    F2 - REG:system.ini: UserInit=userinit.exe

    O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files (x86)\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll

    O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files (x86)\GamesBar\2.0.1.55\oberontb.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll

    O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files (x86)\GamesBar\2.0.1.55\oberontb.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

    O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll

    O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files (x86)\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll

    O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

    O4 - HKLM\..\Run: [bCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"

    O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\SysWOW64\NeroCheck.exe

    O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe

    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent

    O4 - HKCU\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKLM\..\Policies\Explorer\Run: [ctfmon] C:\Windows\system32\sndvol32.exe

    O4 - HKCU\..\Policies\Explorer\Run: [ctfmon] C:\Windows\system32\sndvol32.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files (x86)\GamesBar\2.0.1.55\oberontb.dll

    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files (x86)\GamesBar\2.0.1.55\oberontb.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

    O15 - Trusted IP range: http://127.0.0.1

    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB

    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab

    O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://iplay.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

    O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe

    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe

    O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updateservice (gupdate1caea43b39e40fe) (gupdate1caea43b39e40fe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --

    End of file - 14465 bytes

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.