Ga naar inhoud

Rundll 32 werkt NIET :-(


 Delen

Aanbevolen berichten

Helaas krijg ik ook regelmatig de melding Rundll 32 werkt NIET.

Alvast bedankt ...zie hier de LOG:

Logfile of random's system information tool 1.10 (written by random/random)

Run by Denis at 2014-11-26 23:20:23

Microsoft Windows 7 Ultimate Service Pack 1

System drive C: has 16 GB (10%) free of 153 GB

Total RAM: 4095 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 23:20:27, on 26-11-2014

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.17420)

Boot mode: Normal

Running processes:

C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe

C:\Windows\Samsung\PanelMgr\SSMMgr.exe

C:\Program Files (x86)\AVG\AVG2015\avgui.exe

C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Windows\SysWOW64\ctfmon.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe

C:\Program Files (x86)\AVS4YOU\AVSVideoEditor\AVSVideoEditor.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Common Files\AVSMedia\ActiveX\AVSVideoConverterHost.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Windows\SysWOW64\WerFault.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files\trend micro\Denis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = msn

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = msn

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, enhanced for Bing and MSN

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O1 - Hosts: 208.77.98.29 smithsonmartin.com

O1 - Hosts: 208.77.98.29 smithsonmartin.com

O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll

O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun

O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY

O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe

O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"

O4 - HKLM\..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [se] "C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe" /minimized

O4 - HKCU\..\Run: [EPSON Stylus Photo R220 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIAIA.EXE /FU "C:\Windows\TEMP\E_S25D7.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: PokerStars.eu - {07BA1DA9-F501-4796-8728-74D1B91A6CD5} - C:\Program Files (x86)\PokerStars.EU\PokerStarsUpdate.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: http://www.samsungsetup.com

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe

O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files (x86)\Cepstral\bin\CepstralLicSrv.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe

O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O23 - Service: True Sword 5 Scheduler (TrueSwordSchedulerService) - Security Stronghold - C:\Program Files (x86)\True Sword 5\TrueSwordSchedule.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Update service - Company - C:\Program Files (x86)\Popcorn Time\Updater.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 12895 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe

c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot

C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-e93d-cc38b1aaa325 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

wininit.exe

%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

winlogon.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

"C:\Windows\system32\nvvsvc.exe"

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k NetworkService

"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"

C:\Windows\system32\nvvsvc.exe -session -first

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"

"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"

"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"

"C:\Program Files\Bonjour\mDNSResponder.exe"

"C:\Program Files (x86)\Cepstral\bin\CepstralLicSrv.exe"

"C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE"

"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\VideoCnv\Zet.dll",serv

"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\VideoCnv\Zet.dll",serv

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"

C:\Windows\system32\HPSIsvc.exe

"C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe"

"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"

"C:\Program Files (x86)\True Sword 5\TrueSwordSchedule.exe"

"C:\Program Files (x86)\Popcorn Time\Updater.exe"

"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"

"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"

"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2cc9dd96-c698-437a-ba9a-db973bca7c68 -SystemEventPortName:HostProcess-4bf66207-3494-4970-a394-47af349b2c85 -IoCancelEventPortName:HostProcess-22001b18-a32b-4d51-8b0f-1de27d90aff0 -NonStateChangingEventPortName:HostProcess-6b53f86f-1ada-4664-812f-d93f47080308 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4cf73660-dabe-4ccc-9d21-fd6a49e22974 -DeviceGroupId:WpdFsGroup

"C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe"

"C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe"

"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\Windows\system32\SearchIndexer.exe /Embedding

"taskhost.exe"

"C:\Windows\system32\Dwm.exe"

C:\Windows\Explorer.EXE

"C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe" /minimized

"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR

"C:\Windows\Samsung\PanelMgr\SSMMgr.exe" /autorun

"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY

"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

C:\Windows\Samsung\PanelMgr\caller64.exe Samsung PanelMgr

"C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot

"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"C:\Program Files (x86)\iTunes\iTunesHelper.exe"

"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1

ctfmon.exe

"C:\Program Files\iPod\bin\iPodService.exe"

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical

"C:\Program Files (x86)\AVS4YOU\AVSVideoEditor\AVSVideoEditor.exe"

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6704.0.1397281605\233131221" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38,46 --gpu-vendor-id=0x10de --gpu-device-id=0x0622 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1407 --ignored=" --type=renderer " /prefetch:822062411

"C:\Program Files (x86)\Common Files\AVSMedia\ActiveX\AVSVideoConverterHost.exe" -Embedding

rundll32.exe "c:\progra~2\videocnv\zet.dll",_init

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\SysWOW64\WerFault.exe -u -p 7132 -s 448

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/ControlForLargePopulation/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_89/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="6704.10.231543055\767827979" /prefetch:673131151

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6704.11.1716572045\1722914545" --ppapi-flash-args=enable_hw_video_decode=1 --lang=nl --ignored=" --type=renderer " /prefetch:-632637702

"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt

"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\log.txt

"C:\Users\Denis\Downloads\RSITx64 (1).exe"

C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default

prefs.js - "browser.startup.homepage" - "Web search"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]

"Description"=Adobe® Flash® Player 15.0.0.239 Plugin

"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]

"Description"=Adobe Shockwave Player

"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]

"Description"=iTunes Detector Plug-in

"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]

"Description"=

"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]

"Description"=DivX Plus Web Player

"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]

"Description"=DivX VOD Helper Plug-in

"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]

"Description"=Google Earth in your browser

"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]

"Description"=Java™ Deployment Toolkit

"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]

"Description"=Oracle® Next Generation Java™ Plug-In

"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]

"Description"=

"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]

"Description"=This plugin detects and launches Pando Media Booster

"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]

"Description"=RealPlayer LiveConnect-Enabled Plug-In

"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0]

"Description"=RealNetworks RealDownloader Chrome Background Extension Plug-In

"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0]

"Description"=RealNetworks RealDownloader HTML5VideoShim Plug-In

"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0]

"Description"=RealNetworks RealDownloader Peppe rFlash Video Shim Plug-In

"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]

"Description"=RealPlayer Download Plugin

"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]

"Description"=RealDownloader Plugin

"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]

"Description"=VLC Multimedia Plugin

"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]

"Description"=Handles PDFs in-place in Firefox

"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]

"Description"=Adobe® Flash® Player 15.0.0.239 Plugin

"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]

"Description"=DivX VOD Helper Plug-in

"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]

"Description"=

"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\

ffxtlbr@babylon.com

{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}

{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\extensions\

ffxtlbra@softonic.com

C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\searchplugins\

babylon.xml

BrowserDefender.xml

mixidj.xml

softonic.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]

RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29 539888]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]

DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"se"=C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe [2014-04-04 5679008]

"EPSON Stylus Photo R220 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIAIA.EXE [2006-12-25 211456]

"AdobeBridge"= []

"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-10-29 6501656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]

"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]

"Samsung PanelMgr"=C:\Windows\Samsung\PanelMgr\SSMMgr.exe [2010-06-07 618496]

"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2014-11-09 3653136]

"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2012-11-13 450560]

"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2012-11-30 1263512]

"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-10-11 60712]

"TkBellExe"=C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2013-02-13 295072]

""= []

"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-08-04 30264]

"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]

"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-10-15 157480]

"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-10-02 421888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]

Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2008-03-18 275360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=0

"ConsentPromptBehaviorUser"=0

"EnableLUA"=0

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoActiveDesktop"=1

"NoActiveDesktopChanges"=1

"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"vidc.mrle"=msrle32.dll

"vidc.msvc"=msvidc32.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msg711"=msg711.acm

"msacm.msgsm610"=msgsm32.acm

"msacm.msadpcm"=msadp32.acm

"midimapper"=midimap.dll

"wavemapper"=msacm32.drv

"vidc.uyvy"=msyuv.dll

"vidc.yuy2"=msyuv.dll

"vidc.yvyu"=msyuv.dll

"vidc.iyuv"=iyuv_32.dll

"vidc.i420"=iyuv_32.dll

"vidc.yvu9"=tsbyuv.dll

"msacm.l3acm"=C:\Windows\System32\l3codeca.acm

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

"aux"=wdmaud.drv

"wave2"=wdmaud.drv

"midi1"=wdmaud.drv

"mixer1"=wdmaud.drv

"aux1"=wdmaud.drv

"VIDC.FPS1"=frapsv64.dll

"wave3"=wdmaud.drv

"midi2"=wdmaud.drv

"mixer2"=wdmaud.drv

"aux2"=wdmaud.drv

"wave4"=wdmaud.drv

"midi3"=wdmaud.drv

"mixer3"=wdmaud.drv

"aux3"=wdmaud.drv

"wave5"=wdmaud.drv

"midi4"=wdmaud.drv

"mixer4"=wdmaud.drv

"aux4"=wdmaud.drv

"wave6"=wdmaud.drv

"midi5"=wdmaud.drv

"mixer5"=wdmaud.drv

"aux5"=wdmaud.drv

"wave7"=wdmaud.drv

"midi6"=wdmaud.drv

"mixer6"=wdmaud.drv

"aux6"=wdmaud.drv

"wave8"=wdmaud.drv

"mixer7"=wdmaud.drv

"wave9"=wdmaud.drv

"midi7"=wdmaud.drv

"mixer8"=wdmaud.drv

"aux7"=wdmaud.drv

"wave1"=wdmaud.drv

"midi8"=wdmaud.drv

"mixer9"=wdmaud.drv

"aux8"=wdmaud.drv

"midi9"=wdmaud.drv

"aux9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-26 23:07:33 ----D---- C:\Program Files\trend micro

2014-11-26 23:07:29 ----D---- C:\rsit

2014-11-26 19:28:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe

2014-11-18 22:19:30 ----D---- C:\ProgramData\RegistryReviver.exe

2014-11-18 22:19:17 ----D---- C:\ProgramData\ReviverSoft

2014-11-18 19:23:22 ----A---- C:\Windows\SYSWOW64\pku2u.dll

2014-11-18 19:23:22 ----A---- C:\Windows\system32\pku2u.dll

2014-11-18 19:23:22 ----A---- C:\Windows\system32\kerberos.dll

2014-11-18 19:23:21 ----A---- C:\Windows\SYSWOW64\kerberos.dll

2014-11-17 13:35:31 ----A---- C:\Windows\system32\FNTCACHE.DAT

2014-11-12 14:26:57 ----A---- C:\Windows\system32\termsrv.dll

2014-11-12 14:26:56 ----A---- C:\Windows\SYSWOW64\sspicli.dll

2014-11-12 14:26:56 ----A---- C:\Windows\SYSWOW64\secur32.dll

2014-11-12 14:26:56 ----A---- C:\Windows\SYSWOW64\msaudite.dll

2014-11-12 14:26:56 ----A---- C:\Windows\SYSWOW64\adtschema.dll

2014-11-12 14:26:56 ----A---- C:\Windows\system32\msaudite.dll

2014-11-12 14:26:56 ----A---- C:\Windows\system32\lsasrv.dll

2014-11-12 14:26:56 ----A---- C:\Windows\system32\drivers\ksecpkg.sys

2014-11-12 14:26:56 ----A---- C:\Windows\system32\adtschema.dll

2014-11-12 14:26:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll

2014-11-12 14:26:49 ----A---- C:\Windows\SYSWOW64\iernonce.dll

2014-11-12 14:26:49 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll

2014-11-12 14:26:49 ----A---- C:\Windows\system32\ieetwproxystub.dll

2014-11-12 14:26:49 ----A---- C:\Windows\system32\ieetwcollector.exe

2014-11-12 14:26:48 ----A---- C:\Windows\SYSWOW64\urlmon.dll

2014-11-12 14:26:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

2014-11-12 14:26:48 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll

2014-11-12 14:26:48 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll

2014-11-12 14:26:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll

2014-11-12 14:26:48 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll

2014-11-12 14:26:48 ----A---- C:\Windows\system32\iernonce.dll

2014-11-12 14:26:48 ----A---- C:\Windows\system32\ie4uinit.exe

2014-11-12 14:26:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll

2014-11-12 14:26:46 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll

2014-11-12 14:26:46 ----A---- C:\Windows\SYSWOW64\iesetup.dll

2014-11-12 14:26:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll

2014-11-12 14:26:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll

2014-11-12 14:26:46 ----A---- C:\Windows\system32\urlmon.dll

2014-11-12 14:26:46 ----A---- C:\Windows\system32\ieetwcollectorres.dll

2014-11-12 14:26:46 ----A---- C:\Windows\system32\iedkcs32.dll

2014-11-12 14:26:45 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

2014-11-12 14:26:45 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe

2014-11-12 14:26:45 ----A---- C:\Windows\SYSWOW64\ieui.dll

2014-11-12 14:26:45 ----A---- C:\Windows\SYSWOW64\ieframe.dll

2014-11-12 14:26:45 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll

2014-11-12 14:26:45 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe

2014-11-12 14:26:45 ----A---- C:\Windows\system32\msfeeds.dll

2014-11-12 14:26:45 ----A---- C:\Windows\system32\iesetup.dll

2014-11-12 14:26:45 ----A---- C:\Windows\system32\dxtrans.dll

2014-11-12 14:26:44 ----A---- C:\Windows\system32\iertutil.dll

2014-11-12 14:26:44 ----A---- C:\Windows\system32\ieapfltr.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\wininet.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\msrating.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll

2014-11-12 14:26:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll

2014-11-12 14:26:43 ----A---- C:\Windows\system32\jsproxy.dll

2014-11-12 14:26:43 ----A---- C:\Windows\system32\ieUnatt.exe

2014-11-12 14:26:42 ----A---- C:\Windows\system32\ieui.dll

2014-11-12 14:26:42 ----A---- C:\Windows\system32\ieframe.dll

2014-11-12 14:26:42 ----A---- C:\Windows\system32\dxtmsft.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\wininet.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\vbscript.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\mshtmlmedia.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\mshtmled.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\jscript9diag.dll

2014-11-12 14:26:41 ----A---- C:\Windows\system32\jscript9.dll

2014-11-12 14:26:40 ----A---- C:\Windows\system32\msrating.dll

2014-11-12 14:26:40 ----A---- C:\Windows\system32\MshtmlDac.dll

2014-11-12 14:26:40 ----A---- C:\Windows\system32\mshtml.dll

2014-11-12 14:26:30 ----A---- C:\Windows\system32\msxml3.dll

2014-11-12 14:26:29 ----A---- C:\Windows\SYSWOW64\msxml3r.dll

2014-11-12 14:26:29 ----A---- C:\Windows\SYSWOW64\msxml3.dll

2014-11-12 14:26:29 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL

2014-11-12 14:26:29 ----A---- C:\Windows\system32\msxml3r.dll

2014-11-12 14:26:29 ----A---- C:\Windows\system32\IMJP10K.DLL

2014-11-12 14:26:24 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll

2014-11-12 14:26:24 ----A---- C:\Windows\system32\EncDump.dll

2014-11-12 14:26:24 ----A---- C:\Windows\system32\audiosrv.dll

2014-11-12 14:26:24 ----A---- C:\Windows\system32\AUDIOKSE.dll

2014-11-12 14:26:24 ----A---- C:\Windows\system32\AudioEng.dll

2014-11-12 14:26:23 ----A---- C:\Windows\SYSWOW64\AudioSes.dll

2014-11-12 14:26:23 ----A---- C:\Windows\SYSWOW64\AudioEng.dll

2014-11-12 14:26:23 ----A---- C:\Windows\system32\AudioSes.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\wdigest.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\TSpkg.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\schannel.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\ncrypt.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\msv1_0.dll

2014-11-12 14:26:15 ----A---- C:\Windows\SYSWOW64\credssp.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\wdigest.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\TSpkg.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\schannel.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\ncrypt.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\msv1_0.dll

2014-11-12 14:26:15 ----A---- C:\Windows\system32\credssp.dll

2014-11-12 14:26:04 ----A---- C:\Windows\SYSWOW64\packager.dll

2014-11-12 14:26:04 ----A---- C:\Windows\system32\packager.dll

2014-11-12 14:26:02 ----A---- C:\Windows\system32\win32k.sys

2014-11-12 14:26:00 ----A---- C:\Windows\SYSWOW64\msi.dll

2014-11-12 14:26:00 ----A---- C:\Windows\system32\msi.dll

2014-11-12 14:25:53 ----A---- C:\Windows\SYSWOW64\oleaut32.dll

2014-11-12 14:25:53 ----A---- C:\Windows\system32\oleaut32.dll

2014-11-09 20:49:38 ----D---- C:\Program Files (x86)\True Sword 5

2014-11-09 20:49:38 ----A---- C:\Windows\eSellerateEngine.dll

2014-11-09 20:49:38 ----A---- C:\Windows\eSellerateControl350.dll

2014-11-03 13:38:26 ----D---- C:\Users\Denis\AppData\Roaming\DriverCure

2014-11-03 13:38:25 ----D---- C:\Users\Denis\AppData\Roaming\ParetoLogic

2014-11-03 13:38:03 ----D---- C:\ProgramData\ParetoLogic

2014-11-02 21:04:23 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7

2014-10-29 21:35:16 ----A---- C:\Windows\system32\drivers\avgidsdrivera.sys

2014-10-28 12:57:44 ----D---- C:\Program Files (x86)\VideoCnv

2014-10-27 20:11:32 ----D---- C:\Users\Denis\AppData\Roaming\GemistDownloader

2014-10-27 20:11:31 ----D---- C:\Program Files (x86)\GemistDownloader

2014-10-27 13:11:23 ----D---- C:\Program Files (x86)\QuickTime

2014-10-27 13:07:32 ----D---- C:\Program Files\iPod

2014-10-27 13:07:31 ----D---- C:\Program Files\iTunes

2014-10-27 13:07:31 ----D---- C:\Program Files (x86)\iTunes

======List of files/folders modified in the last 1 month======

2014-11-26 23:15:55 ----D---- C:\Windows\Prefetch

2014-11-26 23:15:21 ----D---- C:\Windows\temp

2014-11-26 23:07:33 ----D---- C:\Program Files

2014-11-26 22:19:33 ----D---- C:\ProgramData\MFAData

2014-11-26 19:28:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

2014-11-26 19:28:03 ----D---- C:\Windows\SysWOW64

2014-11-26 15:24:39 ----D---- C:\Windows\system32\config

2014-11-26 15:12:05 ----SHD---- C:\System Volume Information

2014-11-26 10:38:26 ----D---- C:\Windows\system32\Tasks

2014-11-25 14:20:07 ----SHD---- C:\Windows\Installer

2014-11-25 14:20:07 ----SHD---- C:\Config.Msi

2014-11-23 22:26:00 ----D---- C:\Windows\inf

2014-11-23 22:21:52 ----D---- C:\Windows\system32\catroot2

2014-11-22 00:41:26 ----D---- C:\Windows\System32

2014-11-22 00:41:26 ----A---- C:\Windows\system32\PerfStringBackup.INI

2014-11-19 17:40:56 ----D---- C:\ProgramData\NVIDIA

2014-11-19 15:33:54 ----D---- C:\Program Files (x86)\PokerStars.EU

2014-11-19 15:31:55 ----D---- C:\Program Files (x86)\Battle.net

2014-11-18 23:55:55 ----D---- C:\Windows\winsxs

2014-11-18 22:27:27 ----D---- C:\Windows

2014-11-18 22:19:30 ----HD---- C:\ProgramData

2014-11-18 22:18:20 ----D---- C:\Windows\Tasks

2014-11-18 19:19:48 ----D---- C:\Windows\system32\catroot

2014-11-17 14:29:05 ----D---- C:\Users\Denis\AppData\Roaming\Ustream Producer

2014-11-17 13:08:15 ----D---- C:\Windows\debug

2014-11-16 12:26:20 ----D---- C:\Users\Denis\AppData\Roaming\uTorrent

2014-11-14 14:00:28 ----D---- C:\Windows\system32\drivers

2014-11-14 13:55:27 ----RD---- C:\Program Files (x86)

2014-11-12 23:16:56 ----D---- C:\Windows\rescache

2014-11-12 22:48:47 ----D---- C:\Windows\Microsoft.NET

2014-11-12 22:48:02 ----RSD---- C:\Windows\assembly

2014-11-12 22:35:57 ----D---- C:\Windows\SYSWOW64\nl-NL

2014-11-12 22:35:57 ----D---- C:\Windows\SYSWOW64\en-US

2014-11-12 22:35:57 ----D---- C:\Windows\system32\nl-NL

2014-11-12 22:35:57 ----D---- C:\Windows\system32\en-US

2014-11-12 22:35:57 ----D---- C:\Program Files\Internet Explorer

2014-11-12 22:35:57 ----D---- C:\Program Files (x86)\Internet Explorer

2014-11-12 22:08:59 ----D---- C:\ProgramData\Microsoft Help

2014-11-12 22:03:47 ----D---- C:\Windows\system32\MRT

2014-11-12 21:55:59 ----A---- C:\Windows\system32\MRT.exe

2014-11-12 14:12:56 ----HD---- C:\$AVG

2014-11-12 00:07:09 ----D---- C:\Users\Denis\AppData\Roaming\Skype

2014-11-11 19:05:02 ----D---- C:\Program Files (x86)\Hearthstone

2014-11-10 11:49:50 ----D---- C:\Program Files (x86)\SamsungPrinterLiveUpdate

2014-11-09 20:34:12 ----D---- C:\Program Files (x86)\Common Files

2014-11-09 20:21:13 ----D---- C:\Program Files (x86)\MixMeister Fusion

2014-11-06 18:42:52 ----RSD---- C:\Windows\Fonts

2014-11-03 14:08:21 ----D---- C:\Windows\SYSWOW64\Traktor 2.0.1

2014-11-03 14:08:21 ----D---- C:\Program Files (x86)\Mozilla Firefox

2014-11-03 14:08:19 ----D---- C:\Windows\Panther

2014-11-03 14:08:16 ----D---- C:\Windows\Downloaded Program Files

2014-11-02 21:01:11 ----SHD---- C:\$RECYCLE.BIN

2014-11-02 21:01:06 ----RD---- C:\Users

2014-11-02 17:28:52 ----D---- C:\Program Files\CCleaner

2014-10-27 13:07:32 ----D---- C:\Program Files\Common Files\Apple

2014-10-27 13:07:21 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2014-06-18 190744]

R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2014-07-18 313624]

R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2014-10-05 124184]

R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-12-18 834544]

R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]

R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]

R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2014-10-29 263960]

R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]

R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2014-10-10 274200]

R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]

R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]

R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]

R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [2009-09-17 145448]

R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x64.sys [2009-10-13 61440]

R3 FETNDIS;Stuurprogrammaservice voor VIA Rhine-Family Fast Ethernet-adapter; C:\Windows\system32\DRIVERS\fet6x64.sys [2009-06-10 47872]

R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]

R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]

R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]

R3 vpcbus;Hostbusservice voor Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]

R3 vpcusb;Connectorservice voor USB-virtualisatie; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]

S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys []

S2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys []

S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]

S3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]

S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]

S3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]

S3 ivusb;Initio Driver for USB Default Controller; C:\Windows\system32\DRIVERS\ivusb.sys [2010-07-29 29720]

S3 kx1avs;Traktor Kontrol X1 Midi; C:\Windows\System32\Drivers\kx1avs.sys [2011-07-07 357968]

S3 kx1usb_svc;Traktor Kontrol X1; C:\Windows\System32\Drivers\kx1usb.sys [2011-07-07 70224]

S3 kz1avs;Traktor Kontrol Z1 WDM Audio; C:\Windows\System32\Drivers\kz1avs.sys [2013-05-17 359120]

S3 kz1usb_svc;Traktor Kontrol Z1; C:\Windows\System32\Drivers\kz1usb.sys [2013-05-17 83152]

S3 LoopBe30;nerds.de LoopBe30 - Internal Midi Port SvcDesc(WDM); C:\Windows\system32\drivers\loopbe30.sys [2011-02-26 16896]

S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-09-25 20480]

S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2013-07-25 23040]

S3 NMRKUSBA;Numark USB2 WDM; C:\Windows\system32\drivers\nmrkusba.sys [2010-04-22 50240]

S3 NMRKUSBU;Numark USB2 driver; C:\Windows\System32\Drivers\nmrkusbu.sys [2010-04-22 398912]

S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]

S3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]

S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]

S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]

S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []

S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]

S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []

S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-07-28 54784]

S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]

S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []

S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744]

R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-11-09 3488784]

R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-11-09 298080]

R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]

R2 Cepstral License Server;Cepstral License Server; C:\Program Files (x86)\Cepstral\bin\CepstralLicSrv.exe [2007-03-15 57344]

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]

R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [2007-01-11 126464]

R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-24 136704]

R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2011-05-11 126520]

R2 NIHardwareService;NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2014-03-24 11966768]

R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-02-10 877856]

R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]

R2 TrueSwordSchedulerService;True Sword 5 Scheduler; C:\Program Files (x86)\True Sword 5\TrueSwordSchedule.exe [2011-10-18 1023488]

R2 Update service;Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [2014-10-09 179200]

R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]

S2 fa6789c5;VideoCnv; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]

S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-21 116648]

S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-10 1266464]

S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26 267440]

S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-21 116648]

S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]

S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-06 114688]

S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]

S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-06 119408]

S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]

S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-04-23 572096]

S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-18 1255736]

S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]

S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites


Je Java software is verouderd.

Oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem.

Ga naar Java en download daar de correcte Java versie.

  • Klik op "Gratis Java-download".
  • Ga akkoord met de licentiebepalingen en klik op de button voor de gratis download.
  • Het bestand JavaSetup wordt aangeboden - kies hier voor "bestand opslaan".
  • Sluit alle programma's die eventueel open zijn - zeker je web browser!
  • Ga dan naar Start > Configuratiescherm > Software en verwijder alle oudere versies van Java uit de Softwarelijst.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE of JAVA) in de naam.
  • Klik dan op Verwijderen of op de Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart je pc.
  • Klik vervolgens op JavaSetup om de nieuwste versie van Java te installeren.
  • Vink de installatie van de Ask toolbar uit en ga dan verder met de installatie.

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

{08B0E5C0-4FCB-11CF-AAA5-00401C608501};c
 Update service;s
 C:\Program Files (x86)\Popcorn Time;fs
 c:\Program Files (x86)\VideoCnv;fs
 C:\Program Files (x86)\Mozilla Firefox\extensions\[email="ffxtlbr@babylon.com"]ffxtlbr@babylon.com[/email];fs
 C:\Program Files (x86)\Mozilla Firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f};fs
 C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\extensions\[email="ffxtlbra@softonic.com"]ffxtlbra@softonic.com[/email];fs
 C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\searchplugins\babylon.xml;f
 C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\searchplugins\BrowserDefender.xml;f
 C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\searchplugins\mixidj.xml;f
 C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default\searchplugins\softonic.xml;f
 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run];r64
 ""=-;r64
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows];r64
"AppInit_DLLs"=-;r64
 c:\Users\Denis\AppData\Roaming\ParetoLogic;fs
C:\ProgramData\ParetoLogic;fs
resethosts;
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7;fs
 C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69;fs
emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Deep Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites


Zoek.exe v5.0.0.0 Updated 27-11-2014

Tool run by Denis on vr 28-11-2014 at 19:22:35,59.

Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\Denis\Downloads\zoek.exe [scan all users] [script inserted] [Checkboxes used]

===== Runcheck 19:25:01,20 =====

--- Create Environment Variables 19:25:03,93

--- Create System Restore Point 19:26:00,61

--- Checking Input 19:26:29,31

--- Reset Hosts File 19:26:39,47

--- AU AppData Check 19:26:40,64

--- Remove From Windows Installer 19:26:55,09

--- Empty Folders Check 19:30:14,81

--- Registry HKLM Software Check 19:30:14,95

--- Quick Launch Shortcut Check 19:30:58,77

--- IE Startpage Check 19:31:15,01

--- Program Files DB Check 19:33:46,15

--- C:\Users\Bezoeker\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Default\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Default User\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Denis\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gast\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gebruiker\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\TEMP\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Denis DB Check 19:41:31,41

--- C:\PROGRA~3 DB Check 19:42:05,39

--- C:\Users\Bezoeker\AppData\Local DB Check 19:42:25,40

--- C:\Users\Default\AppData\Local DB Check 19:42:25,40

--- C:\Users\Default User\AppData\Local DB Check 19:42:25,40

--- C:\Users\Denis\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gast\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gebruiker\AppData\Local DB Check 19:42:25,40

--- C:\Users\TEMP\AppData\Local DB Check 19:42:25,40

--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 19:42:25,40

--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 19:42:25,40

--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 19:42:25,40

--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 19:42:25,40

--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 19:47:00,90

--- C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 19:47:17,51

--- Tasks DB Check 19:47:28,63

--- Downloads DB Check 19:47:35,92

--- C:\Users\Bezoeker\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Denis\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gast\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gebruiker\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\TEMP\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 19:47:46,14

--- Tasks2 DB Check 19:50:52,46

--- Documents DB Check 19:51:45,11

--- C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default DB Check 19:52:03,80

--- C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\0 DB Check 19:52:03,80

--- C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\7nnoef75.default DB Check 19:52:03,80

--- C:\Users\TEMP\AppData\Roaming\Mozilla\Firefox\Profiles\6au37e4l.default DB Check 19:52:03,80

--- C:\Users\Public\Desktop DB Check 19:52:22,80

--- C:\Users\Denis\Desktop DB Check 19:52:30,85

--- Services DB Check 19:52:51,64

--- FF prefs.js DB Check 19:54:32,23

--- Del by CLSID 20:00:58,70

--- Processes 20:04:13,90

--- Delete Services 20:04:15,02

--- Firefox Fix 20:04:46,38

- - - Updated - - -

Zoek.exe v5.0.0.0 Updated 27-11-2014

Tool run by Denis on vr 28-11-2014 at 19:22:35,59.

Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\Denis\Downloads\zoek.exe [scan all users] [script inserted] [Checkboxes used]

===== Runcheck 19:25:01,20 =====

--- Create Environment Variables 19:25:03,93

--- Create System Restore Point 19:26:00,61

--- Checking Input 19:26:29,31

--- Reset Hosts File 19:26:39,47

--- AU AppData Check 19:26:40,64

--- Remove From Windows Installer 19:26:55,09

--- Empty Folders Check 19:30:14,81

--- Registry HKLM Software Check 19:30:14,95

--- Quick Launch Shortcut Check 19:30:58,77

--- IE Startpage Check 19:31:15,01

--- Program Files DB Check 19:33:46,15

--- C:\Users\Bezoeker\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Default\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Default User\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Denis\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gast\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Gebruiker\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\TEMP\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 19:35:03,51

--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 19:35:03,51

--- C:\Users\Denis DB Check 19:41:31,41

--- C:\PROGRA~3 DB Check 19:42:05,39

--- C:\Users\Bezoeker\AppData\Local DB Check 19:42:25,40

--- C:\Users\Default\AppData\Local DB Check 19:42:25,40

--- C:\Users\Default User\AppData\Local DB Check 19:42:25,40

--- C:\Users\Denis\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gast\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\Local DB Check 19:42:25,40

--- C:\Users\Gebruiker\AppData\Local DB Check 19:42:25,40

--- C:\Users\TEMP\AppData\Local DB Check 19:42:25,40

--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 19:42:25,40

--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 19:42:25,40

--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 19:42:25,40

--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 19:42:25,40

--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 19:47:00,90

--- C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 19:47:17,51

--- Tasks DB Check 19:47:28,63

--- Downloads DB Check 19:47:35,92

--- C:\Users\Bezoeker\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Denis\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gast\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gast.GEBRUIK-EKAE5SA\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\Gebruiker\AppData\LocalLow DB Check 19:47:46,14

--- C:\Users\TEMP\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 19:47:46,14

--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 19:47:46,14

--- Tasks2 DB Check 19:50:52,46

--- Documents DB Check 19:51:45,11

--- C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\n3ttvxov.default DB Check 19:52:03,80

--- C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\0 DB Check 19:52:03,80

--- C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\7nnoef75.default DB Check 19:52:03,80

--- C:\Users\TEMP\AppData\Roaming\Mozilla\Firefox\Profiles\6au37e4l.default DB Check 19:52:03,80

--- C:\Users\Public\Desktop DB Check 19:52:22,80

--- C:\Users\Denis\Desktop DB Check 19:52:30,85

--- Services DB Check 19:52:51,64

--- FF prefs.js DB Check 19:54:32,23

--- Del by CLSID 20:00:58,70

--- Processes 20:04:13,90

--- Delete Services 20:04:15,02

--- Firefox Fix 20:04:46,38

Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

  • VANAF HIER SNAP IK NIET WAT ER STAAT :-(

Link naar reactie
Delen op andere sites

Het logje dat je geplaatst hebt is het "werklog" van zoek.exe. De resultaten van deze scan zitten in het bestand Zoek-results.log op de C-partitie. Het is dit logje dat we graag zouden zien om te beoordelen. Dat mag je dus als bijlage aan een volgend bericht hangen.

Link naar reactie
Delen op andere sites

 Delen

×
×
  • Nieuwe aanmaken...