Ga naar inhoud

malware DLL-bestand MSVCR110.DLL


 Delen

Aanbevolen berichten

Beste,

Logfile of random's system information tool 1.10 (written by random/random)

Run by Steven at 2014-11-21 11:23:28

Microsoft Windows 7 Professional Service Pack 1

System drive C: has 103 GB (23%) free of 453 GB

Total RAM: 4028 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 11:23:41, on 21/11/2014

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.17420)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe

C:\Program Files (x86)\SupTab\HpUI.exe

C:\Program Files (x86)\SupTab\Loader32.exe

C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

C:\Program Files (x86)\Origin\Origin.exe

C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe

C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe

C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe

C:\windows\SysWOW64\RunDll32.exe

C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe

C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe

C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe

C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\windows\SysWOW64\cmd.exe

C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe

C:\Users\Steven\AppData\Local\Akamai\netsession_win.exe

C:\Users\Steven\AppData\Local\Akamai\netsession_win.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe

C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe

C:\Program Files\trend micro\Steven.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = istartsurf

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/search?q={searchTerms}

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = istartsurf

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = istartsurf

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1410285768&from=amt&uid=TOSHIBAXMK5061GSYN_Y2TQC452TXXY2TQC452T&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1410285768&from=amt&uid=TOSHIBAXMK5061GSYN_Y2TQC452TXXY2TQC452T&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = istartsurf

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.bing.com/search?q={searchTerms}

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/search?q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll

O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll

O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: ArcPluginIEBHO - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll

O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll

O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll

O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60

O4 - HKLM\..\Run: [ADSK DLMSession] C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe

O4 - HKLM\..\Run: [uSB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [iMSS] "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"

O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun

O4 - HKLM\..\Run: [brStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN

O4 - HKLM\..\Run: [File Sanitizer] c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start

O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup

O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true

O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Steven\AppData\Local\Akamai\netsession_win.exe"

O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Steven\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKCU\..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe -AutoStart

O4 - HKCU\..\Run: [AccelerometerSysTrayApplet] "C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.Exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Startup: CurseClientStartup.ccip

O4 - Global Startup: Bluetooth.lnk = ?

O4 - Global Startup: CodeMeter Control Center.lnk = C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe

O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm

O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll

O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)

O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Arc Service (ArcService) - Perfect World Entertainment Inc - C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe

O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Security Service (BTHSSecurityMgr) - Intel® Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe

O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)

O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe

O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe

O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe

O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe

O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe

O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe

O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)

O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe

O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe

O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe

O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe

O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe

O23 - Service: Intel® ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)

O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe

O23 - Service: mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit (mi-raysat_3dsmax2013_64) - Unknown owner - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)

O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)

O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe

O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe

O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

O23 - Service: Roxio Burn Launcher (RoxioBurnLauncher) - Unknown owner - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe

O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)

O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)

O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)

O23 - Service: Mobile Broadband Service (WMCoreService) - Ericsson AB - C:\Program Files (x86)\Ericsson\Mobile Broadband Drivers\WMCore\mini_WMCore.exe

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

O23 - Service: Intel® PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--

End of file - 23164 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

wininit.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

winlogon.exe

C:\windows\system32\services.exe

C:\windows\system32\lsass.exe

C:\windows\system32\lsm.exe

C:\windows\system32\svchost.exe -k DcomLaunch

C:\windows\system32\svchost.exe -k RPCSS

"c:\Program Files\Microsoft Security Client\MsMpEng.exe"

"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"

C:\windows\system32\atiesrxx.exe

C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\windows\system32\svchost.exe -k LocalService

C:\windows\system32\svchost.exe -k netsvcs

"C:\Program Files\IDT\WDM\STacSV64.exe"

C:\windows\system32\svchost.exe -k GPSvcGroup

C:\windows\system32\Hpservice.exe

C:\windows\system32\vcsFPService.exe

C:\windows\system32\svchost.exe -k NetworkService

atieclxx

C:\windows\system32\WLANExt.exe 31407744

\??\C:\windows\system32\conhost.exe "-947099526164341363-2012008884-12057240021700367419-1145704867-1917257184-1589608012

"C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"

C:\windows\Explorer.EXE

"C:\windows\system32\Dwm.exe"

C:\windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\ProgramData\IePluginServices\PluginService.exe -service

"C:\Program Files (x86)\SupTab\HpUI.exe" -run

C:\windows\System32\spoolsv.exe

C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"

"taskhost.exe"

"C:\Program Files\Bonjour\mDNSResponder.exe"

"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"

"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"

"C:\Program Files (x86)\SupTab\Loader64.exe"

"C:\Program Files (x86)\SupTab\Loader32.exe"

"c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"

"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe"

"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe"

"C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"

"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe"

"C:\Program Files\Intel\iCLS Client\HeciServer.exe"

"C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe"

"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"

"C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe"

"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe"

C:\windows\SysWOW64\PnkBstrA.exe

"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"

"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"

C:\windows\system32\svchost.exe -k imgsvc

C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe

"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"

WLIDSvcM.exe 3688

"C:\Program Files (x86)\Ericsson\Mobile Broadband Drivers\WMCore\mini_WMCore.exe" servicemode

"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"

"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"

"C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe"

"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"

C:\windows\system32\wbem\unsecapp.exe -Embedding

C:\windows\system32\wbem\wmiprvse.exe

"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"

"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"

C:\windows\system32\SearchIndexer.exe /Embedding

"c:\Program Files\Microsoft Security Client\NisSrv.exe"

"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ff010f8c-03ad-44a2-b5b2-91e2da21bffe -SystemEventPortName:HostProcess-dd7ef78f-aadf-4038-aaca-e8edec48f585 -IoCancelEventPortName:HostProcess-5c9886d4-4cdd-4bb9-ae8d-eccb803c2a4a -NonStateChangingEventPortName:HostProcess-36a00303-0b73-493f-a629-481721e1ef14 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a90dbf9d-b2af-47a0-b0ef-76709c64fac6 -DeviceGroupId:

C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\windows\servicing\TrustedInstaller.exe

"C:\Program Files\IDT\WDM\sttray64.exe"

"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"

"C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"

"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"

"C:\Program Files (x86)\Origin\Origin.exe" -AutoStart

"C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\accelerometerST.exe"

C:\windows\System32\svchost.exe -k LocalServicePeerNet

"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"

"C:\Program Files\Windows Media Player\wmpnetwk.exe"

"C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe"

"C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe"

"C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN

-BootProc

"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"

"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook

"C:\Program Files (x86)\Browny02\BrYNSvc.exe"

"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe"

"C:\Users\Steven\AppData\Local\Apps\2.0\YMB3B8MV.6DN\0J5PRTO9.H6Y\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b62a0ea0a2ec\CurseClient.exe"

"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe" /start

"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true

"C:\Program Files (x86)\iTunes\iTunesHelper.exe"

"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"C:\Program Files\iPod\bin\iPodService.exe"

-BootProc

C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}

"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"

"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"

"C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe"

C:\windows\system32\wbem\unsecapp.exe -Embedding

C:\windows\system32\cmd.exe /c ""C:/Users/Steven/AppData/Local/Akamai/installer_no_upload_silent.exe" & "C:/Users/Steven/AppData/Local/Akamai/netsession_win.exe""

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow

"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --lang=en-US --lang=en-US --log-severity=disable --channel="6036.0.712564315\1973965650" /prefetch:3

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0

"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"

"C:/Users/Steven/AppData/Local/Akamai/netsession_win.exe"

"C:/Users/Steven/AppData/Local/Akamai/netsession_win.exe" --client

"C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe" -startup

"C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe"

"C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe"

"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"

-Minimized

"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"

"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"

"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"

"C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe"

"C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe"

"C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"

"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" Google

"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=8276.ed6f820.665672025 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 8276 "\\.\pipe\gecko-crash-server-pipe.8276" plugin

"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe" --proxy-stub-channel=Flash9172.103BE980.24156 --host-broker-channel=Flash9172.103BE980.16379 --host-pid=9172 --host-npapi-version=27 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll"

"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe" --channel=6736.003EF548.1004016432 --proxy-stub-channel=Flash9172.103BE980.24156 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll" --host-npapi-version=27 --type=renderer

taskeng.exe {30D1A96F-65C8-4A83-87EC-52C79F420D28}

"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis

C:\windows\system32\wbem\wmiprvse.exe

C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

C:\windows\system32\vssvc.exe

C:\windows\System32\svchost.exe -k swprv

"C:\Users\Steven\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3828895511-1117663807-856057220-1002Core.job - C:\Users\Steven\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver

C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3828895511-1117663807-856057220-1002UA.job - C:\Users\Steven\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler

C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c

C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

C:\windows\tasks\HPCeeScheduleForSteven.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForSteven (null)

=========Mozilla firefox=========

ProfilePath - C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\0zvl38dm.default

prefs.js - "browser.search.useDBForOrder" - true

prefs.js - "browser.startup.homepage" - "about:home"

prefs.js - "keyword.URL" - "http://www.google.com/search?rls=org.mozilla:en-US:official&client=firefox-a&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]

"Description"=Adobe® Flash® Player 15.0.0.223 Plugin

"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]

"Description"=Adobe Shockwave Player

"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]

"Description"=iTunes Detector Plug-in

"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]

"Description"=

"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.3]

"Description"=

"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]

"Description"=

"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]

"Description"=Google Earth in your browser

"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66]

"Description"=Intel IPT WebApi plugin

"Path"=C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]

"Description"=This plugin updates Intel WebAPI component

"Path"=C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.71.2]

"Description"=Java™ Deployment Toolkit

"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2]

"Description"=Oracle® Next Generation Java™ Plug-In

"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]

"Description"=

"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]

"Description"=Office Authorization plug-in for NPAPI browsers

"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]

"Description"=Microsoft SharePoint Plug-in for Firefox

"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]

"Description"=WLPG Install MIME type

"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]

"Description"=This plugin detects and launches Pando Media Booster

"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@perfectworld.com/npArcPlayNowPlugin]

"Description"=Arc PlayNow plugin for Mozilla browsers

"Path"=C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]

"Description"=Handles PDFs in-place in Firefox

"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]

"Description"=

"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]

"Description"=Adobe® Flash® Player 15.0.0.223 Plugin

"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]

"Description"=

"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.11.2]

"Description"=Java™ Deployment Toolkit

"Path"=C:\windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2]

"Description"=Oracle® Next Generation Java™ Plug-In

"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]

"Description"=

"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]

"Description"=Office Authorization plug-in for NPAPI browsers

"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]

"Description"=

"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\

belgiumeid@eid.belgium.be

C:\Users\Steven\AppData\Roaming\Mozilla\Firefox\Profiles\0zvl38dm.default\searchplugins\

Google.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-28 551840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-28 209824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]

HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]

DVDVideoSoft WebPageAdjuster Class - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2013-01-30 342176]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]

MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]

File Sanitizer for HP ProtectTools - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2012-03-22 122456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]

IETabPage Class - C:\Program Files (x86)\SupTab\SupTab.dll [2014-09-09 515464]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-26 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}]

ArcPluginIEBHO Class - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll [2014-01-21 117072]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-26 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]

HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]

DVDVideoSoft WebPageAdjuster Class - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2013-01-30 281760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]

"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2013-03-05 1664000]

"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]

"MfeEpePcMonitor"=C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe []

"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]

"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-07-04 2816240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"NCPluginUpdater"=c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe [2014-10-21 21720]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"Akamai NetSession Interface"=C:\Users\Steven\AppData\Local\Akamai\netsession_win.exe [2012-10-09 4441920]

"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-03-11 3093624]

"AdobeBridge"= []

"Facebook Update"=C:\Users\Steven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-31 138096]

"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2014-11-20 3618648]

"AccelerometerSysTrayApplet"=C:\Program Files\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.Exe [2013-06-11 75584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]

"IAStorIcon"=C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe [2013-02-09 56128]

"ADSK DLMSession"=C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [2012-07-23 1632216]

"USB3MON"=C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-08-08 292088]

"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]

"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-03 43816]

"IMSS"=C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [2013-10-25 134616]

"ControlCenter4"=C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [2012-09-06 143360]

"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2012-06-06 3076096]

"File Sanitizer"=c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2012-03-22 12310616]

"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-09-11 766208]

"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [2014-02-10 336672]

"beid"=C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup []

"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-03-21 2691480]

"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2014-04-09 185144]

""= []

"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-07-08 152392]

"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

CodeMeter Control Center.lnk - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe

C:\Users\Steven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

CurseClientStartup.ccip

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]

wlnotify.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]

"notification packages"=DPPassFilter

scecli

C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoActiveDesktop"=1

"NoActiveDesktopChanges"=1

"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"vidc.mrle"=msrle32.dll

"vidc.msvc"=msvidc32.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msg711"=msg711.acm

"msacm.msgsm610"=msgsm32.acm

"msacm.msadpcm"=msadp32.acm

"midimapper"=midimap.dll

"wavemapper"=msacm32.drv

"VIDC.UYVY"=msyuv.dll

"VIDC.YUY2"=msyuv.dll

"VIDC.YVYU"=msyuv.dll

"VIDC.IYUV"=iyuv_32.dll

"vidc.i420"=iyuv_32.dll

"VIDC.YVU9"=tsbyuv.dll

"msacm.l3acm"=C:\Windows\System32\l3codeca.acm

"MSVideo8"=VfWWDM32.dll

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

"wave1"=wdmaud.drv

"midi1"=wdmaud.drv

"mixer1"=wdmaud.drv

"aux"=wdmaud.drv

"wave2"=wdmaud.drv

"midi2"=wdmaud.drv

"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2014-11-20 23:43:06 ----D---- C:\rsit

2014-11-20 23:43:06 ----D---- C:\Program Files\trend micro

2014-11-20 23:29:57 ----A---- C:\windows\SYSWOW64\sho45A.tmp

2014-11-20 16:06:16 ----A---- C:\windows\SYSWOW64\shoDC5A.tmp

2014-11-20 14:12:47 ----A---- C:\windows\SYSWOW64\pku2u.dll

2014-11-20 14:12:47 ----A---- C:\windows\SYSWOW64\kerberos.dll

2014-11-20 14:12:47 ----A---- C:\windows\system32\pku2u.dll

2014-11-20 14:12:47 ----A---- C:\windows\system32\kerberos.dll

2014-11-12 23:12:03 ----A---- C:\windows\SYSWOW64\oleaut32.dll

2014-11-12 23:12:03 ----A---- C:\windows\system32\oleaut32.dll

2014-11-12 15:25:44 ----A---- C:\windows\system32\generaltel.dll

2014-11-12 15:25:44 ----A---- C:\windows\system32\aepdu.dll

2014-11-12 15:25:42 ----A---- C:\windows\system32\aeinv.dll

2014-11-12 15:25:41 ----A---- C:\windows\SYSWOW64\mshtmled.dll

2014-11-12 15:25:41 ----A---- C:\windows\SYSWOW64\iernonce.dll

2014-11-12 15:25:41 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll

2014-11-12 15:25:41 ----A---- C:\windows\system32\ieetwproxystub.dll

2014-11-12 15:25:41 ----A---- C:\windows\system32\ieetwcollector.exe

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\urlmon.dll

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\mshtml.dll

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\msfeeds.dll

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\iedkcs32.dll

2014-11-12 15:25:40 ----A---- C:\windows\SYSWOW64\dxtrans.dll

2014-11-12 15:25:40 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll

2014-11-12 15:25:40 ----A---- C:\windows\system32\iernonce.dll

2014-11-12 15:25:40 ----A---- C:\windows\system32\ie4uinit.exe

2014-11-12 15:25:39 ----A---- C:\windows\SYSWOW64\iesetup.dll

2014-11-12 15:25:39 ----A---- C:\windows\SYSWOW64\ieapfltr.dll

2014-11-12 15:25:38 ----A---- C:\windows\SYSWOW64\iertutil.dll

2014-11-12 15:25:38 ----A---- C:\windows\system32\urlmon.dll

2014-11-12 15:25:38 ----A---- C:\windows\system32\iedkcs32.dll

2014-11-12 15:25:37 ----A---- C:\windows\SYSWOW64\jsproxy.dll

2014-11-12 15:25:37 ----A---- C:\windows\SYSWOW64\jscript9diag.dll

2014-11-12 15:25:37 ----A---- C:\windows\system32\ieetwcollectorres.dll

2014-11-12 15:25:36 ----A---- C:\windows\SYSWOW64\ieUnatt.exe

2014-11-12 15:25:36 ----A---- C:\windows\SYSWOW64\ieui.dll

2014-11-12 15:25:36 ----A---- C:\windows\SYSWOW64\ieframe.dll

2014-11-12 15:25:36 ----A---- C:\windows\SYSWOW64\dxtmsft.dll

2014-11-12 15:25:36 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe

2014-11-12 15:25:36 ----A---- C:\windows\system32\msfeeds.dll

2014-11-12 15:25:36 ----A---- C:\windows\system32\dxtrans.dll

2014-11-12 15:25:35 ----A---- C:\windows\system32\iesetup.dll

2014-11-12 15:25:35 ----A---- C:\windows\system32\ieapfltr.dll

2014-11-12 15:25:34 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll

2014-11-12 15:25:34 ----A---- C:\windows\SYSWOW64\jscript9.dll

2014-11-12 15:25:34 ----A---- C:\windows\system32\iertutil.dll

2014-11-12 15:25:33 ----A---- C:\windows\SYSWOW64\wininet.dll

2014-11-12 15:25:33 ----A---- C:\windows\SYSWOW64\vbscript.dll

2014-11-12 15:25:33 ----A---- C:\windows\SYSWOW64\msrating.dll

2014-11-12 15:25:33 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll

2014-11-12 15:25:33 ----A---- C:\windows\system32\jsproxy.dll

2014-11-12 15:25:33 ----A---- C:\windows\system32\ieUnatt.exe

2014-11-12 15:25:33 ----A---- C:\windows\system32\dxtmsft.dll

2014-11-12 15:25:32 ----A---- C:\windows\system32\mshtmled.dll

2014-11-12 15:25:32 ----A---- C:\windows\system32\ieui.dll

2014-11-12 15:25:32 ----A---- C:\windows\system32\ieframe.dll

2014-11-12 15:25:31 ----A---- C:\windows\system32\vbscript.dll

2014-11-12 15:25:31 ----A---- C:\windows\system32\mshtmlmedia.dll

2014-11-12 15:25:31 ----A---- C:\windows\system32\jscript9diag.dll

2014-11-12 15:25:31 ----A---- C:\windows\system32\jscript9.dll

2014-11-12 15:25:30 ----A---- C:\windows\system32\wininet.dll

2014-11-12 15:25:29 ----A---- C:\windows\system32\msrating.dll

2014-11-12 15:25:29 ----A---- C:\windows\system32\MshtmlDac.dll

2014-11-12 15:25:27 ----A---- C:\windows\system32\mshtml.dll

2014-11-12 15:25:19 ----A---- C:\windows\system32\msxml3.dll

2014-11-12 15:25:18 ----A---- C:\windows\SYSWOW64\msxml3r.dll

2014-11-12 15:25:18 ----A---- C:\windows\SYSWOW64\msxml3.dll

2014-11-12 15:25:18 ----A---- C:\windows\system32\msxml3r.dll

2014-11-12 15:25:16 ----A---- C:\windows\SYSWOW64\adtschema.dll

2014-11-12 15:25:16 ----A---- C:\windows\system32\termsrv.dll

2014-11-12 15:25:16 ----A---- C:\windows\system32\lsasrv.dll

2014-11-12 15:25:16 ----A---- C:\windows\system32\drivers\ksecpkg.sys

2014-11-12 15:25:16 ----A---- C:\windows\system32\adtschema.dll

2014-11-12 15:25:15 ----A---- C:\windows\SYSWOW64\sspicli.dll

2014-11-12 15:25:15 ----A---- C:\windows\SYSWOW64\secur32.dll

2014-11-12 15:25:15 ----A---- C:\windows\SYSWOW64\msaudite.dll

2014-11-12 15:25:15 ----A---- C:\windows\system32\msaudite.dll

2014-11-12 15:25:09 ----A---- C:\windows\SYSWOW64\IMJP10K.DLL

2014-11-12 15:25:09 ----A---- C:\windows\system32\IMJP10K.DLL

2014-11-12 15:25:07 ----A---- C:\windows\SYSWOW64\AUDIOKSE.dll

2014-11-12 15:25:07 ----A---- C:\windows\system32\AUDIOKSE.dll

2014-11-12 15:25:06 ----A---- C:\windows\system32\EncDump.dll

2014-11-12 15:25:06 ----A---- C:\windows\system32\audiosrv.dll

2014-11-12 15:25:06 ----A---- C:\windows\system32\AudioSes.dll

2014-11-12 15:25:06 ----A---- C:\windows\system32\AudioEng.dll

2014-11-12 15:25:05 ----A---- C:\windows\SYSWOW64\AudioSes.dll

2014-11-12 15:25:05 ----A---- C:\windows\SYSWOW64\AudioEng.dll

2014-11-12 15:25:02 ----A---- C:\windows\system32\schannel.dll

2014-11-12 15:25:01 ----A---- C:\windows\SYSWOW64\schannel.dll

2014-11-12 15:25:01 ----A---- C:\windows\SYSWOW64\ncrypt.dll

2014-11-12 15:25:01 ----A---- C:\windows\system32\ncrypt.dll

2014-11-12 15:24:59 ----A---- C:\windows\SYSWOW64\wdigest.dll

2014-11-12 15:24:59 ----A---- C:\windows\SYSWOW64\msv1_0.dll

2014-11-12 15:24:59 ----A---- C:\windows\system32\wdigest.dll

2014-11-12 15:24:59 ----A---- C:\windows\system32\TSpkg.dll

2014-11-12 15:24:59 ----A---- C:\windows\system32\msv1_0.dll

2014-11-12 15:24:58 ----A---- C:\windows\SYSWOW64\TSpkg.dll

2014-11-12 15:24:58 ----A---- C:\windows\SYSWOW64\credssp.dll

2014-11-12 15:24:58 ----A---- C:\windows\system32\credssp.dll

2014-11-12 15:24:51 ----A---- C:\windows\system32\packager.dll

2014-11-12 15:24:50 ----A---- C:\windows\SYSWOW64\packager.dll

2014-11-12 15:24:49 ----A---- C:\windows\system32\win32k.sys

2014-11-12 15:24:47 ----A---- C:\windows\SYSWOW64\msi.dll

2014-11-12 15:24:47 ----A---- C:\windows\system32\msi.dll

2014-11-12 11:38:10 ----D---- C:\Program Files (x86)\Mozilla Firefox

2014-11-10 00:54:27 ----A---- C:\windows\system32\NicInstC.dll

2014-11-10 00:54:27 ----A---- C:\windows\system32\e1cmsg.dll

2014-11-10 00:54:27 ----A---- C:\windows\system32\drivers\e1c62x64.sys

2014-11-05 16:40:15 ----A---- C:\windows\SYSWOW64\javaws.exe

2014-11-05 16:40:05 ----A---- C:\windows\SYSWOW64\WindowsAccessBridge-32.dll

2014-11-05 16:40:05 ----A---- C:\windows\SYSWOW64\javaw.exe

2014-11-05 16:40:05 ----A---- C:\windows\SYSWOW64\java.exe

2014-10-22 23:49:19 ----A---- C:\windows\SYSWOW64\sho2DFC.tmp

2014-10-16 09:44:52 ----A---- C:\windows\SYSWOW64\sho6744.tmp

2014-10-15 17:12:42 ----A---- C:\windows\SYSWOW64\mscorier.dll

2014-10-15 17:12:42 ----A---- C:\windows\SYSWOW64\dfshim.dll

2014-10-15 17:12:42 ----A---- C:\windows\system32\mscorier.dll

2014-10-15 17:12:42 ----A---- C:\windows\system32\dfshim.dll

2014-10-15 17:12:41 ----A---- C:\windows\SYSWOW64\mscories.dll

2014-10-15 17:12:41 ----A---- C:\windows\system32\mscories.dll

2014-10-15 17:12:32 ----A---- C:\windows\SYSWOW64\blackbox.dll

2014-10-15 17:12:32 ----A---- C:\windows\system32\drmv2clt.dll

2014-10-15 17:12:32 ----A---- C:\windows\system32\blackbox.dll

2014-10-15 17:12:31 ----A---- C:\windows\SYSWOW64\drmv2clt.dll

2014-10-15 17:12:30 ----A---- C:\windows\system32\wmp.dll

2014-10-15 17:12:27 ----A---- C:\windows\system32\mf.dll

2014-10-15 17:12:26 ----A---- C:\windows\SYSWOW64\wmp.dll

2014-10-15 17:12:26 ----A---- C:\windows\SYSWOW64\wmdrmsdk.dll

2014-10-15 17:12:26 ----A---- C:\windows\system32\wmdrmsdk.dll

2014-10-15 17:12:25 ----A---- C:\windows\SYSWOW64\mf.dll

2014-10-15 17:12:25 ----A---- C:\windows\SYSWOW64\drmmgrtn.dll

2014-10-15 17:12:25 ----A---- C:\windows\system32\drmmgrtn.dll

2014-10-15 17:12:24 ----A---- C:\windows\system32\drivers\PEAuth.sys

2014-10-15 17:12:24 ----A---- C:\windows\system32\ci.dll

2014-10-15 17:12:23 ----A---- C:\windows\system32\wintrust.dll

2014-10-15 17:12:23 ----A---- C:\windows\system32\winresume.exe

2014-10-15 17:12:23 ----A---- C:\windows\system32\winload.exe

2014-10-15 17:12:23 ----A---- C:\windows\system32\quartz.dll

2014-10-15 17:12:23 ----A---- C:\windows\system32\ntoskrnl.exe

2014-10-15 17:12:23 ----A---- C:\windows\system32\cryptsvc.dll

2014-10-15 17:12:22 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe

2014-10-15 17:12:22 ----A---- C:\windows\SYSWOW64\cryptsvc.dll

2014-10-15 17:12:22 ----A---- C:\windows\system32\evr.dll

2014-10-15 17:12:22 ----A---- C:\windows\system32\crypt32.dll

2014-10-15 17:12:21 ----A---- C:\windows\SYSWOW64\wintrust.dll

2014-10-15 17:12:21 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe

2014-10-15 17:12:21 ----A---- C:\windows\SYSWOW64\evr.dll

2014-10-15 17:12:21 ----A---- C:\windows\system32\mfplat.dll

2014-10-15 17:12:21 ----A---- C:\windows\system32\cryptui.dll

2014-10-15 17:12:20 ----A---- C:\windows\SYSWOW64\quartz.dll

2014-10-15 17:12:20 ----A---- C:\windows\SYSWOW64\mfplat.dll

2014-10-15 17:12:20 ----A---- C:\windows\SYSWOW64\cryptui.dll

2014-10-15 17:12:20 ----A---- C:\windows\SYSWOW64\crypt32.dll

2014-10-15 17:12:20 ----A---- C:\windows\system32\srcore.dll

2014-10-15 17:12:20 ----A---- C:\windows\system32\pcasvc.dll

2014-10-15 17:12:19 ----A---- C:\windows\SYSWOW64\cryptsp.dll

2014-10-15 17:12:19 ----A---- C:\windows\system32\msscp.dll

2014-10-15 17:12:19 ----A---- C:\windows\system32\cryptsp.dll

2014-10-15 17:12:18 ----A---- C:\windows\system32\rstrui.exe

2014-10-15 17:12:18 ----A---- C:\windows\system32\msnetobj.dll

2014-10-15 17:12:18 ----A---- C:\windows\system32\appidsvc.dll

2014-10-15 17:12:17 ----A---- C:\windows\SYSWOW64\msscp.dll

2014-10-15 17:12:15 ----A---- C:\windows\system32\appidapi.dll

2014-10-15 17:12:11 ----A---- C:\windows\SYSWOW64\rrinstaller.exe

2014-10-15 17:12:11 ----A---- C:\windows\SYSWOW64\msnetobj.dll

2014-10-15 17:12:11 ----A---- C:\windows\system32\rrinstaller.exe

2014-10-15 17:12:11 ----A---- C:\windows\system32\drivers\appid.sys

2014-10-15 17:12:10 ----A---- C:\windows\SYSWOW64\mfps.dll

2014-10-15 17:12:10 ----A---- C:\windows\SYSWOW64\appidapi.dll

2014-10-15 17:12:10 ----A---- C:\windows\system32\mfps.dll

2014-10-15 17:12:10 ----A---- C:\windows\system32\appidpolicyconverter.exe

2014-10-15 17:12:09 ----A---- C:\windows\SYSWOW64\srclient.dll

2014-10-15 17:12:09 ----A---- C:\windows\SYSWOW64\mfpmp.exe

2014-10-15 17:12:09 ----A---- C:\windows\system32\srclient.dll

2014-10-15 17:12:09 ----A---- C:\windows\system32\setbcdlocale.dll

2014-10-15 17:12:09 ----A---- C:\windows\system32\mfpmp.exe

2014-10-15 17:12:09 ----A---- C:\windows\system32\appidcertstorecheck.exe

2014-10-15 17:12:08 ----A---- C:\windows\SYSWOW64\wmploc.DLL

2014-10-15 17:12:08 ----A---- C:\windows\SYSWOW64\spwmp.dll

2014-10-15 17:12:08 ----A---- C:\windows\SYSWOW64\mferror.dll

2014-10-15 17:12:08 ----A---- C:\windows\SYSWOW64\dxmasf.dll

2014-10-15 17:12:08 ----A---- C:\windows\system32\wmploc.DLL

2014-10-15 17:12:08 ----A---- C:\windows\system32\spwmp.dll

2014-10-15 17:12:08 ----A---- C:\windows\system32\mferror.dll

2014-10-15 17:12:08 ----A---- C:\windows\system32\dxmasf.dll

2014-10-15 17:11:02 ----A---- C:\windows\system32\rdpcorets.dll

2014-10-15 17:10:58 ----A---- C:\windows\SYSWOW64\rastls.dll

2014-10-15 17:10:58 ----A---- C:\windows\system32\rastls.dll

2014-10-15 17:10:51 ----A---- C:\windows\SYSWOW64\winsta.dll

2014-10-15 17:10:51 ----A---- C:\windows\system32\winsta.dll

2014-10-15 17:10:50 ----A---- C:\windows\system32\winlogon.exe

2014-10-15 17:10:50 ----A---- C:\windows\system32\rdpcorekmts.dll

2014-10-15 17:10:50 ----A---- C:\windows\system32\drivers\tssecsrv.sys

2014-10-15 17:10:50 ----A---- C:\windows\system32\drivers\rdpwd.sys

2014-10-15 17:10:42 ----A---- C:\windows\system32\mstscax.dll

2014-10-15 17:10:41 ----A---- C:\windows\SYSWOW64\mstscax.dll

2014-10-12 10:33:52 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll

2014-10-11 20:15:12 ----A---- C:\windows\system32\drivers\rdpvideominiport.sys

2014-10-11 20:15:05 ----A---- C:\windows\SYSWOW64\rdpendp_winip.dll

2014-10-11 20:15:03 ----A---- C:\windows\system32\rdpudd.dll

2014-10-11 20:15:03 ----A---- C:\windows\system32\rdpendp_winip.dll

2014-10-10 08:16:59 ----D---- C:\windows\system32\drivers\en-US

2014-10-10 08:13:09 ----A---- C:\windows\system32\TsUsbGDCoInstaller.dll

2014-10-10 08:13:07 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll

2014-10-10 08:13:07 ----A---- C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe

2014-10-10 08:13:07 ----A---- C:\windows\system32\drivers\TsUsbFlt.sys

2014-10-10 08:13:06 ----A---- C:\windows\SYSWOW64\wksprtPS.dll

2014-10-10 08:13:06 ----A---- C:\windows\SYSWOW64\tsgqec.dll

2014-10-10 08:13:06 ----A---- C:\windows\SYSWOW64\mstsc.exe

2014-10-10 08:13:06 ----A---- C:\windows\SYSWOW64\MsRdpWebAccess.dll

2014-10-10 08:13:06 ----A---- C:\windows\system32\wksprtPS.dll

2014-10-10 08:13:06 ----A---- C:\windows\system32\wksprt.exe

2014-10-10 08:13:06 ----A---- C:\windows\system32\TSWbPrxy.exe

2014-10-10 08:13:06 ----A---- C:\windows\system32\tsgqec.dll

2014-10-10 08:13:06 ----A---- C:\windows\system32\mstsc.exe

2014-10-10 08:13:06 ----A---- C:\windows\system32\MsRdpWebAccess.dll

2014-10-10 08:13:05 ----A---- C:\windows\SYSWOW64\rdvidcrl.dll

2014-10-10 08:13:05 ----A---- C:\windows\system32\rdvidcrl.dll

2014-10-01 11:36:57 ----A---- C:\windows\SYSWOW64\qdvd.dll

2014-10-01 11:36:57 ----A---- C:\windows\system32\qdvd.dll

2014-09-30 17:22:34 ----A---- C:\windows\SYSWOW64\shoC905.tmp

2014-09-28 11:24:13 ----A---- C:\windows\SYSWOW64\tzres.dll

2014-09-28 11:24:13 ----A---- C:\windows\system32\tzres.dll

2014-09-12 15:40:32 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

2014-09-11 20:25:43 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll

2014-09-11 20:25:43 ----A---- C:\windows\system32\msmpeg2vdec.dll

2014-09-11 11:46:03 ----A---- C:\windows\system32\TSWorkspace.dll

2014-09-11 11:46:02 ----A---- C:\windows\SYSWOW64\TSWorkspace.dll

2014-09-11 11:45:51 ----A---- C:\windows\SYSWOW64\d3d10warp.dll

2014-09-11 11:45:51 ----A---- C:\windows\system32\d3d10warp.dll

2014-09-09 19:07:26 ----A---- C:\awhA42E.tmp

2014-09-09 19:04:14 ----D---- C:\s

2014-09-09 19:03:21 ----D---- C:\ProgramData\IePluginServices

2014-09-09 19:03:18 ----D---- C:\ProgramData\WindowsMangerProtect

2014-09-09 19:03:16 ----D---- C:\Program Files (x86)\SupTab

2014-09-09 15:39:34 ----A---- C:\windows\SYSWOW64\installd.exe

2014-08-29 23:58:25 ----A---- C:\windows\SYSWOW64\sho334F.tmp

2014-08-28 14:43:11 ----A---- C:\windows\SYSWOW64\gdi32.dll

2014-08-28 14:43:11 ----A---- C:\windows\system32\gdi32.dll

======List of files/folders modified in the last 3 months======

2014-11-21 11:23:27 ----D---- C:\windows\Temp

2014-11-21 11:22:16 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt

2014-11-21 11:16:28 ----D---- C:\windows\System32

2014-11-21 11:16:28 ----D---- C:\windows\inf

2014-11-21 11:16:28 ----A---- C:\windows\system32\PerfStringBackup.INI

2014-11-21 11:13:52 ----A---- C:\windows\SYSWOW64\log.txt

2014-11-21 11:13:17 ----SHD---- C:\windows\Installer

2014-11-21 11:13:17 ----SHD---- C:\Config.Msi

2014-11-21 11:11:48 ----D---- C:\Program Files (x86)\Origin

2014-11-21 11:11:06 ----D---- C:\windows\tracing

2014-11-21 11:10:05 ----D---- C:\windows\Minidump

2014-11-21 11:09:59 ----D---- C:\Windows

2014-11-21 11:06:08 ----D---- C:\ProgramData\Origin

2014-11-21 11:04:30 ----D---- C:\windows\system32\config

2014-11-21 11:03:51 ----HD---- C:\ProgramData

2014-11-21 00:34:22 ----SHD---- C:\System Volume Information

2014-11-21 00:33:25 ----RSD---- C:\windows\assembly

2014-11-21 00:31:48 ----D---- C:\windows\Logs

2014-11-21 00:02:22 ----D---- C:\windows\SysWOW64

2014-11-20 23:59:36 ----D---- C:\Users\Steven\AppData\Roaming\BitTorrent

2014-11-20 23:59:19 ----D---- C:\windows\debug

2014-11-20 23:43:06 ----RD---- C:\Program Files

2014-11-20 17:02:02 ----D---- C:\Users\Steven\AppData\Roaming\Origin

2014-11-20 16:57:35 ----D---- C:\Program Files (x86)\Battlelog Web Plugins

2014-11-20 15:34:44 ----A---- C:\windows\SYSWOW64\PnkBstrA.exe

2014-11-20 15:34:31 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe

2014-11-20 15:19:59 ----D---- C:\windows\winsxs

2014-11-20 15:15:44 ----D---- C:\Program Files (x86)\Hearthstone

2014-11-20 15:15:33 ----D---- C:\Program Files (x86)\Battle.net

2014-11-20 14:59:37 ----D---- C:\swsetup

2014-11-20 14:29:52 ----D---- C:\windows\Prefetch

2014-11-20 14:10:26 ----D---- C:\windows\system32\catroot2

2014-11-17 01:10:18 ----D---- C:\Users\Steven\AppData\Roaming\Skype

2014-11-14 12:59:36 ----D---- C:\windows\rescache

2014-11-13 23:26:56 ----RD---- C:\Program Files (x86)

2014-11-13 23:26:49 ----D---- C:\windows\Tasks

2014-11-13 22:10:09 ----D---- C:\windows\Microsoft.NET

2014-11-12 19:26:33 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe

2014-11-12 18:00:08 ----SD---- C:\windows\system32\CompatTel

2014-11-12 18:00:07 ----D---- C:\windows\SYSWOW64\nl-NL

2014-11-12 18:00:07 ----D---- C:\windows\system32\nl-NL

2014-11-12 18:00:06 ----D---- C:\windows\system32\drivers

2014-11-12 18:00:06 ----D---- C:\Program Files\Internet Explorer

2014-11-12 18:00:05 ----D---- C:\windows\SYSWOW64\en-US

2014-11-12 18:00:04 ----D---- C:\windows\system32\en-US

2014-11-12 18:00:03 ----D---- C:\Program Files (x86)\Internet Explorer

2014-11-12 15:49:21 ----D---- C:\ProgramData\Microsoft Help

2014-11-12 15:46:35 ----RSD---- C:\windows\Fonts

2014-11-12 15:45:05 ----D---- C:\windows\system32\MRT

2014-11-12 15:38:13 ----A---- C:\windows\system32\MRT.exe

2014-11-10 00:54:52 ----D---- C:\windows\system32\DriverStore

2014-11-05 16:40:36 ----D---- C:\ProgramData\Oracle

2014-11-05 16:40:21 ----D---- C:\Program Files (x86)\Common Files

2014-11-05 16:40:05 ----D---- C:\Program Files (x86)\Java

2014-10-30 12:25:26 ----N---- C:\windows\system32\MpSigStub.exe

2014-10-28 22:03:51 ----D---- C:\ProgramData\Package Cache

2014-10-28 21:37:02 ----D---- C:\Program Files (x86)\Origin Games

2014-10-16 09:43:51 ----D---- C:\windows\SYSWOW64\Dism

2014-10-16 09:43:51 ----D---- C:\windows\system32\Dism

2014-10-16 09:43:51 ----D---- C:\Program Files\Windows Media Player

2014-10-16 09:43:51 ----D---- C:\Program Files (x86)\Windows Media Player

2014-10-16 09:43:50 ----D---- C:\windows\system32\CodeIntegrity

2014-10-16 09:43:50 ----D---- C:\windows\system32\Boot

2014-10-15 17:10:39 ----D---- C:\windows\system32\catroot

2014-10-11 20:16:27 ----D---- C:\windows\system32\drivers\nl-NL

2014-10-11 20:16:27 ----D---- C:\windows\PolicyDefinitions

2014-10-10 08:30:51 ----D---- C:\windows\system32\Tasks

2014-10-10 08:16:59 ----D---- C:\windows\SYSWOW64\wbem

2014-10-10 08:16:59 ----D---- C:\windows\system32\wbem

2014-10-10 08:12:56 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI

2014-09-11 20:44:35 ----D---- C:\Program Files\Microsoft Security Client

2014-09-11 20:44:34 ----D---- C:\Program Files (x86)\Microsoft Security Client

2014-09-09 19:18:26 ----D---- C:\windows\AppPatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2012-09-07 31040]

R0 iaStor;Intel AHCI Controller; C:\windows\system32\drivers\iaStor.sys [2013-02-09 568640]

R0 iusb3hcs;Intel® USB 3.0 hostcontrollerswitch-stuurprogramma; C:\windows\system32\DRIVERS\iusb3hcs.sys [2014-08-08 20464]

R0 MfeEpeOpal;MfeEpeOpal; C:\windows\system32\drivers\MfeEpeOpal.sys [2013-03-27 91432]

R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2013-03-27 158760]

R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]

R0 PxHlpa64;PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys [2012-03-08 58000]

R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]

R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]

R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2010-01-26 44576]

R2 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]

R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2012-09-07 43328]

R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2014-01-24 12760576]

R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2014-01-24 619008]

R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtuele adapter; C:\windows\system32\DRIVERS\AMPPAL.sys [2013-07-29 164832]

R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2012-02-03 42816]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2014-01-24 94208]

R3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C; C:\windows\system32\DRIVERS\e1c62x64.sys [2014-05-02 495376]

R3 ecnssndis; Mobile Broadband Driver; C:\windows\System32\Drivers\wwuss64.sys [2011-10-05 26664]

R3 ecnssndisfltr; Mobile Broadband Driver Filter; C:\windows\System32\Drivers\wwussf64.sys [2011-10-05 29736]

R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]

R3 h36wgps;HP Mobile Broadband Module NMEA; C:\windows\system32\DRIVERS\h36wgps64.sys [2012-03-02 103184]

R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2013-11-04 26936]

R3 iusb3hub;Intel® USB 3.0 hub-stuurprogramma; C:\windows\system32\DRIVERS\iusb3hub.sys [2014-08-08 358896]

R3 iusb3xhc;Intel® USB 3.0 uitbreidbare hostcontroller-stuurprogramma; C:\windows\system32\DRIVERS\iusb3xhc.sys [2014-08-08 795632]

R3 Mbm3CBus;HP hs2350 HSPA+ Mobile Broadband Module USB Device (WDM); C:\windows\system32\DRIVERS\Mbm3CBus.sys [2013-04-22 443648]

R3 Mbm3DevMt;HP Mobile Broadband Module Device Management Driver (WDM); C:\windows\system32\DRIVERS\Mbm3DevMt.sys [2013-04-22 455936]

R3 Mbm3mdfl;HP Mobile Broadband Module Modem Filter; C:\windows\system32\DRIVERS\Mbm3mdfl.sys [2013-04-22 22272]

R3 Mbm3Mdm;HP Mobile Broadband Module Modem Driver; C:\windows\system32\DRIVERS\Mbm3Mdm.sys [2013-04-22 508160]

R3 MEIx64;Intel® Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2013-10-25 62784]

R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit; C:\windows\system32\DRIVERS\Netwsw00.sys [2013-08-22 11520512]

R3 Sftfs;Sftfs; C:\windows\system32\DRIVERS\Sftfslh.sys [2013-06-26 767144]

R3 Sftplay;Sftplay; C:\windows\system32\DRIVERS\Sftplaylh.sys [2013-06-26 273576]

R3 Sftredir;Sftredir; C:\windows\system32\DRIVERS\Sftredirlh.sys [2013-06-26 28840]

R3 Sftvol;Sftvol; C:\windows\system32\DRIVERS\Sftvollh.sys [2013-06-26 23208]

R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2012-11-28 1866080]

R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10305; C:\windows\system32\DRIVERS\stwrt64.sys [2013-03-05 543744]

R3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]

R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2014-07-04 555760]

R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]

S1 MpKsl5decc2f0;MpKsl5decc2f0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CA6DBD1B-2300-470D-ACDE-B6CC15A51A95}\MpKsl5decc2f0.sys []

S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]

S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol; C:\windows\system32\DRIVERS\amppal.sys [2013-07-29 164832]

S3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\windows\system32\drivers\bcbtums.sys [2014-07-04 172760]

S3 BthEnum;Bluetooth-stuurprogramma voor aanvraagblok; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]

S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]

S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]

S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\windows\System32\Drivers\BTHUSB.sys [2012-05-17 80384]

S3 btwampfl;btwampfl Bluetooth filter driver; \??\C:\windows\system32\drivers\btwampfl.sys [2014-07-04 598808]

S3 btwaudio;Bluetooth-audioapparaat; C:\windows\system32\drivers\btwaudio.sys [2014-07-04 184144]

S3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\drivers\btwavdt.sys [2014-07-04 210984]

S3 BTWDPAN;Bluetooth Personal Area Network; C:\windows\system32\DRIVERS\btwdpan.sys [2012-02-02 89640]

S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2014-07-04 39976]

S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2014-07-04 21544]

S3 cxbu0x64;OMNIKEY 3x21; C:\windows\system32\DRIVERS\cxbu0x64.sys [2014-04-05 191224]

S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2012-01-31 64312]

S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]

S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]

S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2013-11-01 176880]

S3 johci;JMicron 1394 Filter Driver; C:\windows\system32\DRIVERS\johci.sys [2013-05-31 26208]

S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]

S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]

S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]

S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]

S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]

S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]

S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]

S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]

S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]

S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]

S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]

S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

S3 USBAAPL64;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]

R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2014-01-24 239616]

R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-07-29 772064]

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]

R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]

R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]

R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2014-03-06 1008344]

R2 CodeMeter.exe;CodeMeter Runtime Server; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2012-11-21 2571704]

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]

R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2013-04-22 822504]

R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2012-07-20 494456]

R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-10-11 631024]

R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2012-03-14 152992]

R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]

R2 HPAuto;HP Auto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]

R2 HPFSService;File Sanitizer for HP ProtectTools; c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2012-03-22 372824]

R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [2014-02-10 683296]

R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2012-09-07 33600]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-02-09 13632]

R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-09-09 715656]

R2 IFXSpMgtSrv;Security Platform Management Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2012-01-27 1127800]

R2 IFXTCS;Trusted Platform Core Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2012-01-27 984440]

R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]

R2 Intel® ME Service;Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2013-10-25 131032]

R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2013-10-25 165336]

R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2013-10-25 279000]

R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2013-03-27 1327104]

R2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit; C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe [2011-09-15 86016]

R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]

R2 PersonalSecureDriveService;Personal Secure Drive Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2012-01-27 212344]

R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2014-11-20 76152]

R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-10-11 154864]

R2 RoxioBurnLauncher;Roxio Burn Launcher; C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [2012-03-21 536848]

R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-06-26 523944]

R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2013-03-05 327680]

R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2012-02-03 498352]

R2 UNS;Intel® Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2013-10-25 366040]

R3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-06-05 266240]

R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2014-04-09 1448248]

R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]

R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2014-07-08 641352]

R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]

R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-06-26 207528]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]

S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-19 116648]

S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-12 267440]

S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]

S3 ArcService;Arc Service; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [2014-01-21 88400]

S3 aspnet_state;ASP.NET-statusservice; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]

S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2012-01-31 477056]

S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-16 1432400]

S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-09-20 1044816]

S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-19 116648]

S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-11-06 114688]

S3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]

S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]

S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-11-12 114288]

S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-10-11 284912]

S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-11-20 1900400]

S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]

S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]

S3 RoxMediaDB12OEM;RoxMediaDB12OEM; C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2012-03-07 1118480]

S3 stllssvr;stllssvr; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2011-12-08 76416]

S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]

S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]

S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2012-03-09 117552]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites


Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

C:\Program Files (x86)\SupTab;fs
C:\Program Files\McAfee Security Scan;fs
C:\ProgramData\IePluginServices;fs
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk,f
C:\awhA42E.tmp;f
{0E8A89AD-95D7-40EB-8D9D-083EF7066A01};c
{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C};c
{EE932B49-D5C0-4D19-A3DA-CE0849258DE6};c
{ae07101b-46d4-4a98-af68-0333ea26e113};c
IePluginServices;s
McComponentHostService;s
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}];r
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}];r
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}];r64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}];r64
emptyclsid;
chromelook; 
firefoxlook; 
emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Deep Scan

  • Installed Programs

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites


Je Java software is verouderd.

Oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem.

Ga naar Java en download daar de correcte Java versie.

  • Klik op "Gratis Java-download".
  • Ga akkoord met de licentiebepalingen en klik op de button voor de gratis download.
  • Het bestand JavaSetup wordt aangeboden - kies hier voor "bestand opslaan".
  • Sluit alle programma's die eventueel open zijn - zeker je web browser!
  • Ga dan naar Start > Configuratiescherm > Software en verwijder alle oudere versies van Java uit de Softwarelijst.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE of JAVA) in de naam.
  • Klik dan op Verwijderen of op de Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart je pc.
  • Klik vervolgens op JavaSetup om de nieuwste versie van Java te installeren.
  • Vink de installatie van de Ask toolbar uit en ga dan verder met de installatie.

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Start 51a612a8b27e2-Zoek.pngZoek.exe nogmaals met het onderstaande script.

  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
     
    McAfee Security Scan Plus;u
    C:\Program Files (x86)\SupTab;fs
    C:\Program Files\McAfee Security Scan;fs
    C:\ProgramData\IePluginServices;fs
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk,f
    C:\awhA42E.tmp;f
    C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi;f
    {0E8A89AD-95D7-40EB-8D9D-083EF7066A01};c
    {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C};c
    {EE932B49-D5C0-4D19-A3DA-CE0849258DE6};c
    {ae07101b-46d4-4a98-af68-0333ea26e113};c
    {e4f94d1e-2f53-401e-8885-681602c0ddd8};c
    IePluginServices;s
    McComponentHostService;s
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}];r
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}];r
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}];r64
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}];r64
    emptyclsid;
    chromelook; 
    firefoxlook; 
    emptyfolderscheck;delete 
    startupall; 
    filesrcm;
    installedprogs;
    autoclean;
    


  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Download Malwarebytes Anti-Malware 2.0 bij voorkeur naar het bureaublad.

  • Dubbelklik op mbam-setup-2.0.exe om de installatie van Malwarebytes Anti-Malware te starten.
  • Volg de verdere aanwijzingen, de volledige installatieprocedure kunt u nalezen op de volgende link - Malwarebytes Anti-Malware installeren.
  • Start MBAM.
  • Klik bovenin het scherm op Scan.
  • Kies vervolgens de Aangepaste scan en klik op Scan nu.
  • Plaats vervolgens een vinkje bij de optie "Scannen naar rootkits".
  • Controleer of zowel bij "Potentieel Ongewenst Programma (POP)" als bij "Ongewenste Wijzigingen (PUM)" de optie "Behandel detecties als Malware" staat ingesteld. Is dat niet het geval, pas dit dan aan.
  • Selecteer in het rechter venster alle aanwezige harde schijven en partities.
  • Klik vervolgens op de knop Start scan om de Aangepaste scan uit te voeren.
  • Vóór het scannen wordt er automatisch gecontroleerd of er updates van de virusdefinities beschikbaar zijn. Indien er een update beschikbaar is, moet je deze eerst installeren via "Nu bijwerken".
  • De scan wordt nu automatisch gestart,wanneer de scan gereed is en er bedreigingen zijn gedetecteerd krijg je hier een overzicht van. Selecteer deze en plaats ze allemaal in Quarantaine.
  • Indien gevraagd wordt om de computer opnieuw op te starten, klik je op JA.
  • Na herstarten van de PC open je MBAM opnieuw.
  • Klik bovenaan in het menu op Historie.
  • Kies vervolgens voor de optie "programmalogboeken" en selecteer het Scanlogboek dat je wil exporteren. Kies voor de meest recente scan die je hebt uitgevoerd (zie datum en uur).
  • Vink het Scanlogboek aan en klik op de knop Bekijk.
  • In een nieuw venster zal je de resultaten van deze scan zien.
  • Nu kan je kiezen voor het exporteren van deze gegevens of voor het opslaan op je klembord.
  • Ofwel kies je onderaan voor "Exporteer" om het gedetailleerde logboek te exporteren als tekstbestand. Geef het tekstbestand een naam, bvb. "MBAM Scanlog", kies de optie tekstbestand (*.txt) en sla dit bestand op een door jou gekozen locatie op. Doe je dit niet dan wordt dit bestand standaard op je bureaublad opgeslagen.

532aab157609a-MBAM-Scan.png

  • Ofwel kan je het bestand selecteren via "Kopieer naar Klembord", zodat de inhoud van het log beschikbaar is op je klembord en je het in een volgende post kan plakken.

Malwarebytes' Anti-Malware logbestand plaatsen

  • Voeg het logbestand wat je zojuist hebt opgeslagen als bijlage toe aan het volgende bericht. (Dit logbestand kan je tevens terugvinden in Malwarebytes Anti-Malware bij Historie > Programmalogboeken)
    of
  • Plak de inhoud van dit logbestand in het volgende bericht.

Link naar reactie
Delen op andere sites


Mooie opruiming.

Volgende stap.

Download adwcleaner.pngAdwCleaner by Xplode naar het bureaublad (verwijder eerst eventuele aanwezige oudere versies van deze tool op je PC, zodat je nu de meest recente database van AdwCleaner kan gebruiken).

  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner om hem te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren,
  • Door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik op Scan.
  • Klik vervolgens op Clean (Engelse versie)of Verwijderen (Nederlandse versie).
  • Klik bij Herstarten Noodzakelijk op OK

Nadat de PC opnieuw is opgestart, opent meestal een logfile.

Anders is het hier terug te vinden C:\\AdwCleaner\\AdwCleaner[s0].txt.

Logbestand plaatsen

  • Voeg het logbestand met de naam C:\\AdwCleaner\\AdwCleaner[s0].txt als bijlage toe aan het volgende bericht.
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

 Delen

×
×
  • Nieuwe aanmaken...