Logfile of random's system information tool 1.10 (written by random/random) Run by WoutSr at 2014-06-22 11:13:52 Microsoft Windows 8.1 System drive C: has 765 GB (86%) free of 891 GB Total RAM: 4040 MB (56% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:14:10, on 22-6-2014 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.17126) Boot mode: Normal Running processes: C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe C:\Program Files (x86)\Webshots\Wallpaper\WallScreen.exe C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Users\WoutSr\Desktop\Tor Browser\Browser\firefox.exe C:\Users\WoutSr\Desktop\Tor Browser\Tor\tor.exe C:\Windows\syswow64\wwahost.exe C:\Program Files\trend micro\WoutSr.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [Allmyapps Update] "C:\Users\WoutSr\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup O4 - Startup: Inktwaarschuwingen controleren - HP Deskjet 3070 B611 series.lnk = ? O4 - Startup: Webshots Wallpaper & Screensaver.lnk = C:\Program Files (x86)\Webshots\Wallpaper\WallScreen.exe O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: Marktplaats.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - adfarm.mediaplex.com/ad/ck/5026-153897-5908-1?mpre=http%3A%2F%2Fwww.marktplaats.nl (file missing) (HKCU) O9 - Extra 'Tools' menuitem: Marktplaats.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - adfarm.mediaplex.com/ad/ck/5026-153897-5908-1?mpre=http%3A%2F%2Fwww.marktplaats.nl (file missing) (HKCU) O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink PowerDVD 10 MS Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe O23 - Service: CyberLink PowerDVD 10 MS Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies Ltd. - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: ZoneAlarm Privacy Service (ZAPrivacyService) - Check Point Software Technologies, Ltd. - C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe -- End of file - 9769 bytes ======Listing Processes====== wininit.exe winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS "dwm.exe" "C:\Windows\system32\nvvsvc.exe" "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" "C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe" C:\Windows\system32\nvvsvc.exe -session -first C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k NetworkService "C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe" -service C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" "C:\Program Files\Bonjour\mDNSResponder.exe" "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service "C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe" "C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe" "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" "C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe" "C:\Program Files\CyberLink\Shared files\RichVideo64.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL mmsys.cpl "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b9a4d6cd-4845-49b0-9f4c-412d2493fbf1 -SystemEventPortName:HostProcess-bc5dd2cf-2419-42f2-996b-dcc544a260d4 -IoCancelEventPortName:HostProcess-75806b9a-3873-4be4-863b-22f143daa470 -NonStateChangingEventPortName:HostProcess-7143cc9f-e0e1-4124-a00e-b3b3e6c7eff0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5bb08062-e8c2-417e-9693-0364347596e3 -DeviceGroupId:WpdFsGroup "C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp \??\C:\Windows\system32\conhost.exe 0x4 taskhostex.exe C:\Windows\Explorer.EXE "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Windows\system32\RunDll32.exe" "C:\Program Files\HP\HP Deskjet 3070 B611 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN1AN4717L05MQ;CONNECTION=USB;MONITOR=1; "C:\Program Files (x86)\Webshots\Wallpaper\WallScreen.exe" "C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1 C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\System32\skydrive.exe -Embedding "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe" "C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe" C:\Windows\System32\RuntimeBroker.exe -Embedding taskeng.exe {14AA870C-EB07-4A0A-A8B4-5855B35BEFEA} "C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe" "C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE" C:\Windows\system32\svchost.exe -k HPService "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files\Internet Explorer\iexplore.exe" http://www.pc-helpforum.be/f389/programma-start-niet-meer-70951-new/ "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3796 CREDAT:267521 /prefetch:2 "C:\Windows\System32\SettingSyncHost.exe" -Embedding "C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding Browser\firefox.exe -no-remote -profile .\Data\Browser\profile.default\ "C:\Users\WoutSr\Desktop\Tor Browser\Tor\tor.exe" --defaults-torrc "C:\Users\WoutSr\Desktop\Tor Browser\Data\Tor\torrc-defaults" -f "C:\Users\WoutSr\Desktop\Tor Browser\Data\Tor\torrc" DataDirectory "C:\Users\WoutSr\Desktop\Tor Browser\Data\Tor" GeoIPFile "C:\Users\WoutSr\Desktop\Tor Browser\Data\Tor\geoip" GeoIPv6File "C:\Users\WoutSr\Desktop\Tor Browser\Data\Tor\geoip6" HashedControlPassword 16:23e0b8069567d9df60eef422a12cd039327ed6a1190357ea367be89531 __OwningControllerProcess 3752 "C:\Windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572 "C:\Windows\syswow64\wwahost.exe" -ServerName:App.wwa wmiadap.exe /F /T /R C:\Windows\system32\wbem\wmiprvse.exe "C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey DB5DF958-AD2C-22DC-CF51-C53CE89C2818 -Reinvoke C:\Windows\system32\wbem\wmiprvse.exe "C:\Users\WoutSr\Documents\Downloads\RSITx64.exe" C:\Windows\System32\svchost.exe -k WerSvcGroup =========Mozilla firefox========= ProfilePath - C:\Users\WoutSr\AppData\Roaming\Mozilla\Firefox\Profiles\4hlq8qdq.default prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT3321897&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP868BD56C-7B88-4054-9D6E-318BA0397526&SSPV=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 14.0.0.125 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0] "Description"=DivX Web Player "Path"=C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0] "Description"=Microsoft Lync Plug-in for Firefox "Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision] "Description"=NVIDIA stereo images plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming] "Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51] "Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In "Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3] "Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In "Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3] "Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In "Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3] "Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In "Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51] "Description"=RealPlayer Download Plugin "Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@realnetworks.com/npdlplugin;version=1] "Description"=RealDownloader Plugin "Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 14.0.0.125 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] "Description"=DivX VOD Helper Plug-in "Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll C:\Program Files (x86)\Mozilla Firefox\plugins\ nppdf32.dll C:\Users\WoutSr\AppData\Roaming\Mozilla\Firefox\Profiles\4hlq8qdq.default\searchplugins\ zonealarm.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-06-16 218784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-06-16 2335960] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}] RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14 542376] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}] Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2014-06-16 153248] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}] Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-06-16 1730264] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Allmyapps Update"=C:\Users\WoutSr\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe [2013-12-09 317304] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "ZoneAlarm"=C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [2014-04-25 137352] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904] "HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2011-10-28 49208] ""= [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Secunia PSI Tray.lnk - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe C:\Users\WoutSr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Inktwaarschuwingen controleren - HP Deskjet 3070 B611 series.lnk - C:\Windows\system32\RunDll32.exe Webshots Wallpaper & Screensaver.lnk - C:\Program Files (x86)\Webshots\Wallpaper\WallScreen.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2013-08-26 622080] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "ConfirmFileDelete"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "VIDC.YUY2"=msyuv.dll "vidc.i420"=lvcod64.dll "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "VIDC.YVYU"=msyuv.dll "VIDC.YVU9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "VIDC.UYVY"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.mrle"=msrle32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.msvc"=msvidc32.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux"=wdmaud.drv "MSVideo8"=VfWWDM32.dll "MSVideo"=vfwwdm32.dll "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux1"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-06-22 11:13:52 ----D---- C:\rsit 2014-06-22 11:13:52 ----D---- C:\Program Files\trend micro 2014-06-22 11:04:11 ----A---- C:\Windows\system32\SyncEngine.dll 2014-06-22 11:04:11 ----A---- C:\Windows\system32\lsasrv.dll 2014-06-22 11:04:10 ----A---- C:\Windows\system32\win32k.sys 2014-06-22 11:04:10 ----A---- C:\Windows\system32\SkyDrive.exe 2014-06-22 11:04:10 ----A---- C:\Windows\system32\mfcore.dll 2014-06-22 11:04:10 ----A---- C:\Windows\system32\d3d9.dll 2014-06-22 11:04:09 ----A---- C:\Windows\SYSWOW64\mfcore.dll 2014-06-22 11:04:09 ----A---- C:\Windows\SYSWOW64\d3d9.dll 2014-06-22 11:04:09 ----A---- C:\Windows\system32\wuaueng.dll 2014-06-22 11:04:09 ----A---- C:\Windows\system32\SkyDriveTelemetry.dll 2014-06-22 11:04:09 ----A---- C:\Windows\system32\localspl.dll 2014-06-22 11:04:08 ----A---- C:\Windows\SYSWOW64\SkyDriveShell.dll 2014-06-22 11:04:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\vpnike.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\SkyDriveShell.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\ntdll.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\framedynos.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\drivers\usbport.sys 2014-06-22 11:04:08 ----A---- C:\Windows\system32\drivers\usbhub.sys 2014-06-22 11:04:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys 2014-06-22 11:04:08 ----A---- C:\Windows\system32\dhcpcore.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\authui.dll 2014-06-22 11:04:08 ----A---- C:\Windows\system32\actxprxy.dll 2014-06-22 11:04:07 ----A---- C:\Windows\SYSWOW64\framedynos.dll 2014-06-22 11:04:07 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll 2014-06-22 11:04:07 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll 2014-06-22 11:04:07 ----A---- C:\Windows\SYSWOW64\authui.dll 2014-06-22 11:04:07 ----A---- C:\Windows\SYSWOW64\adtschema.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\winbici.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\ncobjapi.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\fveapi.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\framedyn.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\drivers\usbuhci.sys 2014-06-22 11:04:07 ----A---- C:\Windows\system32\drivers\usbehci.sys 2014-06-22 11:04:07 ----A---- C:\Windows\system32\drivers\usbd.sys 2014-06-22 11:04:07 ----A---- C:\Windows\system32\drivers\agilevpn.sys 2014-06-22 11:04:07 ----A---- C:\Windows\system32\dhcpcore6.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\BFE.DLL 2014-06-22 11:04:07 ----A---- C:\Windows\system32\bdesvc.dll 2014-06-22 11:04:07 ----A---- C:\Windows\system32\adtschema.dll 2014-06-22 11:04:06 ----A---- C:\Windows\SYSWOW64\WebClnt.dll 2014-06-22 11:04:06 ----A---- C:\Windows\SYSWOW64\Robocopy.exe 2014-06-22 11:04:06 ----A---- C:\Windows\SYSWOW64\ncobjapi.dll 2014-06-22 11:04:06 ----A---- C:\Windows\system32\wuauclt.exe 2014-06-22 11:04:06 ----A---- C:\Windows\system32\WebClnt.dll 2014-06-22 11:04:06 ----A---- C:\Windows\system32\Robocopy.exe 2014-06-22 11:04:06 ----A---- C:\Windows\system32\IKEEXT.DLL 2014-06-22 11:04:06 ----A---- C:\Windows\system32\drivers\vwifimp.sys 2014-06-22 11:04:06 ----A---- C:\Windows\system32\dhcpcsvc6.dll 2014-06-22 11:04:06 ----A---- C:\Windows\system32\dhcpcsvc.dll 2014-06-22 11:04:05 ----A---- C:\Windows\SYSWOW64\framedyn.dll 2014-06-22 11:04:05 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll 2014-06-22 11:04:05 ----A---- C:\Windows\SYSWOW64\dhcpcsvc.dll 2014-06-22 11:04:05 ----A---- C:\Windows\SYSWOW64\actxprxy.dll 2014-06-22 11:04:05 ----A---- C:\Windows\system32\drivers\vwififlt.sys 2014-06-22 11:04:05 ----A---- C:\Windows\system32\BulkOperationHost.exe 2014-06-22 11:04:04 ----A---- C:\Windows\SYSWOW64\d3d8thk.dll 2014-06-22 11:04:04 ----A---- C:\Windows\system32\srms.dat 2014-06-22 11:04:04 ----A---- C:\Windows\system32\reseteng.dll 2014-06-22 11:04:00 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2014-06-21 11:28:12 ----D---- C:\Program Files (x86)\Mozilla Firefox 2014-06-17 13:28:08 ----D---- C:\ProgramData\Visan 2014-06-17 13:27:59 ----N---- C:\Windows\system32\HPDiscoPMa211.dll 2014-06-17 13:27:51 ----D---- C:\Program Files\HP 2014-06-17 13:08:28 ----D---- C:\MATS 2014-06-12 21:28:55 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2014-06-12 21:28:35 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-12 21:28:35 ----A---- C:\Windows\system32\drivers\mwac.sys 2014-06-12 21:28:35 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2014-06-12 19:07:32 ----A---- C:\Windows\system32\rdpcorets.dll 2014-06-12 19:07:30 ----A---- C:\Windows\system32\msxml3.dll 2014-06-12 19:07:29 ----A---- C:\Windows\SYSWOW64\msxml3.dll 2014-06-12 19:07:27 ----A---- C:\Windows\SYSWOW64\gdi32.dll 2014-06-12 19:07:27 ----A---- C:\Windows\system32\gdi32.dll 2014-06-12 19:07:24 ----A---- C:\Windows\SYSWOW64\dxtrans.dll 2014-06-12 19:07:24 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll 2014-06-12 19:07:24 ----A---- C:\Windows\system32\dxtrans.dll 2014-06-12 19:07:24 ----A---- C:\Windows\system32\dxtmsft.dll 2014-06-12 19:07:23 ----A---- C:\Windows\system32\mshtmled.dll 2014-06-12 19:07:08 ----A---- C:\Windows\system32\mshtml.dll 2014-06-12 19:07:07 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2014-06-12 19:07:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2014-06-12 19:06:58 ----A---- C:\Windows\system32\jscript9.dll 2014-06-12 19:06:55 ----A---- C:\Windows\system32\ieframe.dll 2014-06-12 19:06:52 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2014-06-12 19:06:50 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2014-06-12 19:06:49 ----A---- C:\Windows\system32\wininet.dll 2014-06-12 19:06:47 ----A---- C:\Windows\SYSWOW64\wininet.dll 2014-06-12 19:06:47 ----A---- C:\Windows\system32\iertutil.dll 2014-06-12 19:06:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2014-06-12 19:06:46 ----A---- C:\Windows\system32\urlmon.dll 2014-06-12 19:06:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2014-06-12 19:06:44 ----A---- C:\Windows\system32\jscript9diag.dll 2014-06-12 19:06:44 ----A---- C:\Windows\system32\ieapfltr.dll 2014-06-12 19:06:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2014-06-12 19:06:43 ----A---- C:\Windows\system32\ie4uinit.exe 2014-06-12 19:06:42 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2014-06-12 19:06:42 ----A---- C:\Windows\system32\msfeeds.dll 2014-06-12 19:06:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2014-06-12 19:06:39 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2014-06-12 19:06:39 ----A---- C:\Windows\system32\jsproxy.dll 2014-06-12 19:06:33 ----A---- C:\Windows\system32\drivers\tcpip.sys 2014-06-12 19:06:32 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS 2014-06-12 19:06:31 ----A---- C:\Windows\system32\drivers\ks.sys 2014-06-12 19:06:28 ----A---- C:\Windows\SYSWOW64\WSShared.dll 2014-06-12 19:06:28 ----A---- C:\Windows\system32\WSShared.dll 2014-06-12 19:06:27 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-12 19:06:27 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-12 19:06:26 ----A---- C:\Windows\system32\WSReset.exe 2014-06-12 19:06:07 ----A---- C:\Windows\system32\shell32.dll 2014-06-12 19:06:06 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll 2014-06-12 19:06:05 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll 2014-06-12 19:06:04 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll 2014-06-12 19:06:04 ----A---- C:\Windows\system32\Windows.UI.Search.dll 2014-06-12 19:06:03 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll 2014-06-12 19:06:01 ----A---- C:\Windows\SYSWOW64\shell32.dll 2014-06-12 19:05:59 ----A---- C:\Windows\system32\twinui.dll 2014-06-12 19:05:59 ----A---- C:\Windows\system32\gpsvc.dll 2014-06-12 19:05:57 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll 2014-06-12 19:05:57 ----A---- C:\Windows\SYSWOW64\twinui.dll 2014-06-12 19:05:57 ----A---- C:\Windows\system32\SettingsHandlers.dll 2014-06-12 19:05:57 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll 2014-06-12 19:05:56 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll 2014-06-12 19:05:56 ----A---- C:\Windows\system32\mstscax.dll 2014-06-12 19:05:55 ----A---- C:\Windows\system32\workfolderssvc.dll 2014-06-12 19:05:55 ----A---- C:\Windows\system32\wmpmde.dll 2014-06-12 19:05:55 ----A---- C:\Windows\system32\winmde.dll 2014-06-12 19:05:54 ----A---- C:\Windows\SYSWOW64\mstscax.dll 2014-06-12 19:05:54 ----A---- C:\Windows\system32\services.exe 2014-06-12 19:05:54 ----A---- C:\Windows\system32\drivers\afd.sys 2014-06-12 19:05:53 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll 2014-06-12 19:05:53 ----A---- C:\Windows\system32\SearchFolder.dll 2014-06-12 19:05:53 ----A---- C:\Windows\system32\AUDIOKSE.dll 2014-06-12 19:05:52 ----A---- C:\Windows\system32\srvsvc.dll 2014-06-12 19:05:52 ----A---- C:\Windows\system32\MFMediaEngine.dll 2014-06-12 19:05:52 ----A---- C:\Windows\system32\drivers\srv2.sys 2014-06-12 19:05:51 ----A---- C:\Windows\SYSWOW64\winmde.dll 2014-06-12 19:05:51 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll 2014-06-12 19:05:51 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll 2014-06-12 19:05:51 ----A---- C:\Windows\system32\Windows.Media.dll 2014-06-12 19:05:51 ----A---- C:\Windows\system32\mfsvr.dll 2014-06-12 19:05:51 ----A---- C:\Windows\system32\drivers\volsnap.sys 2014-06-12 19:05:50 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll 2014-06-12 19:05:45 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll 2014-06-12 19:05:45 ----A---- C:\Windows\system32\XpsGdiConverter.dll 2014-06-12 19:05:44 ----A---- C:\Windows\system32\win32spl.dll 2014-06-12 19:05:44 ----A---- C:\Windows\system32\ntoskrnl.exe 2014-06-12 19:05:44 ----A---- C:\Windows\system32\defragsvc.dll 2014-06-12 19:05:44 ----A---- C:\Windows\system32\audiosrv.dll 2014-06-12 19:05:43 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll 2014-06-12 19:05:43 ----A---- C:\Windows\SYSWOW64\mfsvr.dll 2014-06-12 19:05:43 ----A---- C:\Windows\SYSWOW64\dwmapi.dll 2014-06-12 19:05:43 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe 2014-06-12 19:05:43 ----A---- C:\Windows\system32\GeofenceMonitorService.dll 2014-06-12 19:05:43 ----A---- C:\Windows\system32\dwmapi.dll 2014-06-12 19:05:43 ----A---- C:\Windows\system32\drivers\nwifi.sys 2014-06-12 19:05:43 ----A---- C:\Windows\system32\drivers\hdaudbus.sys 2014-06-12 19:05:42 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll 2014-06-12 19:05:42 ----A---- C:\Windows\system32\resutils.dll 2014-06-12 19:05:42 ----A---- C:\Windows\system32\ploptin.dll 2014-06-12 19:05:42 ----A---- C:\Windows\system32\MFCaptureEngine.dll 2014-06-12 19:05:42 ----A---- C:\Windows\system32\MDEServer.exe 2014-06-12 19:05:42 ----A---- C:\Windows\system32\drivers\fvevol.sys 2014-06-12 19:05:42 ----A---- C:\Windows\system32\drivers\Classpnp.sys 2014-06-12 19:05:41 ----A---- C:\Windows\SYSWOW64\MFCaptureEngine.dll 2014-06-12 19:05:41 ----A---- C:\Windows\SYSWOW64\GeofenceMonitorService.dll 2014-06-12 19:05:41 ----A---- C:\Windows\system32\swprv.dll 2014-06-12 19:05:41 ----A---- C:\Windows\system32\MSVideoDSP.dll 2014-06-12 19:05:41 ----A---- C:\Windows\system32\gpapi.dll 2014-06-12 19:05:41 ----A---- C:\Windows\system32\drivers\srvnet.sys 2014-06-12 19:05:41 ----A---- C:\Windows\system32\drivers\msiscsi.sys 2014-06-12 19:05:40 ----A---- C:\Windows\SYSWOW64\gpapi.dll 2014-06-12 19:05:40 ----A---- C:\Windows\system32\wscsvc.dll 2014-06-12 19:05:40 ----A---- C:\Windows\system32\VSSVC.exe 2014-06-12 19:05:40 ----A---- C:\Windows\system32\rpchttp.dll 2014-06-12 19:05:40 ----A---- C:\Windows\system32\rdpencom.dll 2014-06-12 19:05:40 ----A---- C:\Windows\system32\drivers\storport.sys 2014-06-12 19:05:39 ----A---- C:\Windows\SYSWOW64\rpchttp.dll 2014-06-12 19:05:39 ----A---- C:\Windows\SYSWOW64\rdpencom.dll 2014-06-12 19:05:39 ----A---- C:\Windows\SYSWOW64\propsys.dll 2014-06-12 19:05:39 ----A---- C:\Windows\SYSWOW64\MSVideoDSP.dll 2014-06-12 19:05:39 ----A---- C:\Windows\SYSWOW64\mf.dll 2014-06-12 19:05:39 ----A---- C:\Windows\system32\propsys.dll 2014-06-12 19:05:39 ----A---- C:\Windows\system32\mf.dll 2014-06-12 19:05:39 ----A---- C:\Windows\system32\drivers\spaceport.sys 2014-06-12 19:05:39 ----A---- C:\Windows\system32\drivers\fltMgr.sys 2014-06-12 19:05:38 ----A---- C:\Windows\SYSWOW64\wintrust.dll 2014-06-12 19:05:38 ----A---- C:\Windows\SYSWOW64\mfplat.dll 2014-06-12 19:05:38 ----A---- C:\Windows\SYSWOW64\AudioSes.dll 2014-06-12 19:05:38 ----A---- C:\Windows\SYSWOW64\AudioEng.dll 2014-06-12 19:05:38 ----A---- C:\Windows\system32\energyprov.dll 2014-06-12 19:05:38 ----A---- C:\Windows\system32\AudioSes.dll 2014-06-12 19:05:38 ----A---- C:\Windows\system32\AudioEng.dll 2014-06-12 19:05:37 ----A---- C:\Windows\SYSWOW64\clusapi.dll 2014-06-12 19:05:37 ----A---- C:\Windows\system32\wintrust.dll 2014-06-12 19:05:37 ----A---- C:\Windows\system32\srcore.dll 2014-06-12 19:05:37 ----A---- C:\Windows\system32\mfpmp.exe 2014-06-12 19:05:37 ----A---- C:\Windows\system32\mfplat.dll 2014-06-12 19:05:37 ----A---- C:\Windows\system32\clusapi.dll 2014-06-12 19:05:37 ----A---- C:\Windows\system32\audiodg.exe 2014-06-12 19:05:36 ----A---- C:\Windows\SYSWOW64\resutils.dll 2014-06-12 19:05:36 ----A---- C:\Windows\system32\WorkFoldersShell.dll 2014-06-12 19:05:36 ----A---- C:\Windows\system32\tlscsp.dll 2014-06-12 19:05:35 ----A---- C:\Windows\SYSWOW64\tlscsp.dll 2014-06-12 19:05:35 ----A---- C:\Windows\system32\WorkfoldersControl.dll 2014-06-12 19:05:35 ----A---- C:\Windows\system32\mispace.dll 2014-06-12 19:05:35 ----A---- C:\Windows\system32\BootMenuUX.dll 2014-06-12 19:05:34 ----A---- C:\Windows\SYSWOW64\mispace.dll 2014-06-12 19:05:34 ----A---- C:\Windows\system32\wlansvc.dll 2014-06-12 19:05:34 ----A---- C:\Windows\system32\wlansec.dll 2014-06-12 19:05:34 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll 2014-06-12 19:05:34 ----A---- C:\Windows\system32\rdvidcrl.dll 2014-06-12 19:05:34 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll 2014-06-12 19:05:33 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll 2014-06-12 19:05:33 ----A---- C:\Windows\system32\wlanmsm.dll 2014-06-12 19:05:33 ----A---- C:\Windows\system32\wlanapi.dll 2014-06-12 19:05:32 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll 2014-06-12 19:05:32 ----A---- C:\Windows\SYSWOW64\wlanhlp.dll 2014-06-12 19:05:32 ----A---- C:\Windows\SYSWOW64\wlanapi.dll 2014-06-12 19:05:32 ----A---- C:\Windows\SYSWOW64\srclient.dll 2014-06-12 19:05:32 ----A---- C:\Windows\system32\wlanhlp.dll 2014-06-12 19:05:32 ----A---- C:\Windows\system32\tsgqec.dll 2014-06-12 19:05:32 ----A---- C:\Windows\system32\srclient.dll 2014-06-12 19:05:32 ----A---- C:\Windows\system32\rstrui.exe 2014-06-12 19:02:23 ----A---- C:\Windows\SYSWOW64\drvinst.exe 2014-06-12 19:02:23 ----A---- C:\Windows\system32\drvinst.exe 2014-06-12 19:02:23 ----A---- C:\Windows\system32\drvcfg.exe 2014-06-12 19:02:22 ----A---- C:\Windows\system32\FntCache.dll 2014-06-12 19:02:22 ----A---- C:\Windows\system32\DWrite.dll 2014-06-12 19:02:21 ----A---- C:\Windows\SYSWOW64\DWrite.dll 2014-06-12 19:02:10 ----A---- C:\Windows\system32\WpcMon.exe 2014-06-12 19:02:10 ----A---- C:\Windows\system32\Wpc.dll 2014-06-12 19:02:09 ----A---- C:\Windows\system32\WpcWebSync.dll 2014-06-12 19:02:08 ----A---- C:\Windows\SYSWOW64\Wpc.dll 2014-06-12 19:02:07 ----A---- C:\Windows\system32\wpccpl.dll 2014-06-12 19:02:06 ----A---- C:\Windows\system32\drivers\wpcfltr.sys 2014-06-06 13:51:25 ----D---- C:\Program Files (x86)\Soft4Boost 2014-06-03 10:06:57 ----D---- C:\ProgramData\PDVD 2014-06-03 10:06:54 ----D---- C:\Program Files (x86)\NSIS Uninstall Information 2014-06-03 10:04:20 ----D---- C:\ProgramData\SUPPORTDIR 2014-06-03 09:59:55 ----D---- C:\Users\WoutSr\AppData\Roaming\Allmyapps 2014-05-26 20:02:06 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\nvopencl.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\nvinit.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll 2014-05-26 19:57:56 ----A---- C:\Windows\SYSWOW64\NvIFR.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\nvopencl.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\nvoglv64.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\nvoglshim64.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\nvinitx.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\NvIFROpenGL.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\NvIFR64.dll 2014-05-26 19:57:56 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\NvFBC.dll 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\nvcuda.dll 2014-05-26 19:57:55 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\NvFBC64.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvEncodeAPI64.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvdispgenco6433788.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvdispco6433788.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvd3dumx.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvcuvid.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvcuvenc.dll 2014-05-26 19:57:55 ----A---- C:\Windows\system32\nvcuda.dll 2014-05-26 19:57:54 ----A---- C:\Windows\system32\nvcompiler.dll 2014-05-25 13:36:17 ----D---- C:\Users\WoutSr\AppData\Roaming\DriverCure 2014-05-23 13:57:28 ----D---- C:\Program Files (x86)\HP ======List of files/folders modified in the last 1 month====== 2014-06-22 11:13:57 ----D---- C:\Windows\Prefetch 2014-06-22 11:13:52 ----RD---- C:\Program Files 2014-06-22 11:12:56 ----D---- C:\Windows\Temp 2014-06-22 11:10:00 ----D---- C:\Windows\system32\config 2014-06-22 11:09:46 ----D---- C:\Windows\system32\Tasks 2014-06-22 11:08:40 ----D---- C:\Windows\WinSxS 2014-06-22 11:08:00 ----D---- C:\ProgramData\NVIDIA 2014-06-22 11:07:57 ----D---- C:\Windows\Inf 2014-06-22 11:05:53 ----D---- C:\Windows\system32\drivers 2014-06-22 11:05:51 ----RD---- C:\Windows\System32 2014-06-22 11:05:51 ----D---- C:\Windows\SYSWOW64\wbem 2014-06-22 11:05:51 ----D---- C:\Windows\SYSWOW64\nl-NL 2014-06-22 11:05:51 ----D---- C:\Windows\SYSWOW64\migration 2014-06-22 11:05:51 ----D---- C:\Windows\SysWOW64 2014-06-22 11:05:51 ----D---- C:\Windows\system32\wbem 2014-06-22 11:05:51 ----D---- C:\Windows\system32\nl-NL 2014-06-22 11:05:51 ----D---- C:\Windows\system32\en-US 2014-06-22 11:05:51 ----D---- C:\Windows\MediaViewer 2014-06-22 11:05:51 ----D---- C:\Windows\FileManager 2014-06-22 11:05:51 ----D---- C:\Windows\Camera 2014-06-22 11:05:50 ----D---- C:\Windows\system32\DriverStore 2014-06-22 11:05:03 ----D---- C:\Windows\CbsTemp 2014-06-22 11:04:42 ----SHD---- C:\System Volume Information 2014-06-22 11:03:37 ----D---- C:\Windows\system32\catroot2 2014-06-22 11:01:54 ----A---- C:\Windows\system32\PerfStringBackup.INI 2014-06-22 11:00:04 ----D---- C:\Windows\system32\sru 2014-06-22 10:55:25 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-22 10:03:26 ----RD---- C:\Program Files (x86) 2014-06-22 09:49:23 ----D---- C:\Windows\AppReadiness 2014-06-22 09:48:53 ----HD---- C:\Program Files\WindowsApps 2014-06-20 15:38:36 ----HD---- C:\ProgramData 2014-06-17 13:42:55 ----D---- C:\Windows\system32\catroot 2014-06-17 13:31:08 ----SHD---- C:\Windows\Installer 2014-06-17 13:31:06 ----SHD---- C:\Config.Msi 2014-06-17 13:31:06 ----SD---- C:\ProgramData\Microsoft 2014-06-17 13:31:06 ----D---- C:\Program Files (x86)\Microsoft 2014-06-17 13:28:03 ----D---- C:\Users\WoutSr\AppData\Roaming\HpUpdate 2014-06-17 13:27:53 ----D---- C:\ProgramData\HP 2014-06-17 13:27:52 ----D---- C:\Windows\twain_32 2014-06-17 09:50:57 ----D---- C:\ProgramData\regid.1991-06.com.microsoft 2014-06-17 09:50:50 ----D---- C:\Windows\Microsoft.NET 2014-06-17 09:50:35 ----RSD---- C:\Windows\assembly 2014-06-17 09:49:16 ----D---- C:\Program Files\Microsoft Office 15 2014-06-14 12:21:42 ----D---- C:\Program Files\Internet Explorer 2014-06-14 12:21:42 ----D---- C:\Program Files (x86)\Internet Explorer 2014-06-14 12:21:37 ----D---- C:\Windows\WinStore 2014-06-14 12:21:36 ----RD---- C:\Windows\ToastData 2014-06-14 12:21:32 ----RD---- C:\Windows\ImmersiveControlPanel 2014-06-14 12:21:32 ----D---- C:\Windows\system32\oobe 2014-06-14 12:21:32 ----D---- C:\Windows\system32\drivers\nl-NL 2014-06-14 11:03:44 ----D---- C:\Windows\system32\MRT 2014-06-14 11:03:42 ----A---- C:\Windows\system32\MRT.exe 2014-06-14 11:02:58 ----D---- C:\Windows\system32\migration 2014-06-12 21:28:35 ----D---- C:\ProgramData\Malwarebytes 2014-06-12 21:28:35 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-06-08 11:27:55 ----D---- C:\Windows 2014-06-08 11:25:26 ----D---- C:\Windows\debug 2014-06-06 13:51:28 ----RSD---- C:\Windows\Fonts 2014-06-06 13:51:25 ----D---- C:\Program Files (x86)\Common Files 2014-06-04 09:59:06 ----D---- C:\Windows\Tasks 2014-06-03 20:42:08 ----D---- C:\Windows\SoftwareDistribution 2014-06-03 10:08:05 ----D---- C:\ProgramData\CyberLink 2014-06-03 10:06:54 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2014-06-03 10:06:20 ----D---- C:\ProgramData\Temp 2014-06-03 10:04:49 ----D---- C:\Program Files (x86)\CyberLink 2014-06-03 10:04:20 ----D---- C:\ProgramData\install_clap 2014-05-31 07:13:24 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe 2014-05-26 20:02:23 ----D---- C:\Program Files (x86)\NVIDIA Corporation 2014-05-23 15:01:55 ----D---- C:\Program Files\CCleaner ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-08-07 644968] R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-03-13 157016] R1 CLVirtualDrive;CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [2013-03-05 91712] R1 Vsdatant;@oem10.inf,%Vsdatant_Desc%;Zone Alarm Firewall Driver; C:\Windows\System32\drivers\vsdatant.sys [2014-04-24 450968] R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680] R3 CompFilter64;UVCCompositeFilter; C:\Windows\System32\drivers\lvbflt64.sys [2012-10-26 26784] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-08-27 3613528] R3 LVRS64;@oem18.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520] R3 LVUVC64;@oem17.inf,%PID_0826_DD%(UVC);Logitech HD Webcam C525(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176] R3 MEIx64;@oem6.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-04 99288] R3 NVHDA;@oem26.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-05-20 12688328] R3 nvvad_WaveExtensible;@oem24.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2013-12-05 39200] R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-21 816344] R3 RtlWlanu;@netrtwlanu.inf,%RtlWlanu.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtwlanu.sys [2013-07-31 1975000] R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Stuurprogramma voor USB-audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088] R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-30 38912] S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-08-26 4166656] S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [] S3 IntcDAud;@oem11.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2013-08-26 449528] S3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [] S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544] S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB-videoapparaat (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432] R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184] R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-05-21 2279608] R2 CyberLink PowerDVD 10 MS Monitor Service;CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [2013-03-11 74712] R2 CyberLink PowerDVD 10 MS Service;CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [2013-03-11 316376] R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2013-08-22 37768] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720] R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304] R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 15129376] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-05-20 927520] R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-08-14 39056] R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2010-08-19 386344] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-05-20 413128] R2 vsmon;TrueVector Internet Monitor; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2014-04-25 3592120] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-22 43696] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-21 119408] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600] -----------------EOF-----------------