E-Peek v 1.0.5.5 © Emphyrio/Onsia Patrick 2013-2014 Downloaded @ [url=http://www.antimalwarehelp.be/EDev/Tools/E-Peek/EPeekDL.html]E Dev[/url] Run at do 6 nov 2014 16:15 . Windows 8 Professional (32 bits) C:\WINDOWS [NTFS - Fixed] Default Browser: Internet Explorer Boot mode: Normal boot User logged in: Geo . Java x86: n/a . AV : Windows Defender [Updated - Not Running] AS : Windows Defender [Updated - Not Running] AS : Spybot - Search and Destroy [Updated - Running] FW : Windows firewall . ==================== Files and Folders history ================================= Folders Created Last 7 days : 31/10/2014 ##### r-h-s-d+a- C:\rsit 31/10/2014 ##### r-h-s-d+a- C:\Program Files\trend micro 06/11/2014 ##### r-h-s-d+a- C:\Program Files\E Dev Files Modified Last 7 days : 05/11/2014 01792392 r-h-s-d-a+ C:\WINDOWS\system32\PerfStringBackup.INI 05/11/2014 00796920 r-h-s-d-a+ C:\WINDOWS\system32\perfh013.dat 05/11/2014 00710244 r-h-s-d-a+ C:\WINDOWS\system32\perfh009.dat 05/11/2014 00159176 r-h-s-d-a+ C:\WINDOWS\system32\perfc013.dat 05/11/2014 00132614 r-h-s-d-a+ C:\WINDOWS\system32\perfc009.dat 03/11/2014 00001999 r-h-s-d-a+ C:\WINDOWS\system32\ScanResults.xml 03/11/2014 00000464 r-h-s-d-a+ C:\WINDOWS\system32\ScannerSettings Files Created Last 7 days : ==================== RUNNING PROCESSES ========================================= [AllShareFrameworkDMS] -SYSTEM- C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe - (Samsung) [AllShareFrameworkManagerDMS] -SYSTEM- C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe - (Samsung) [AppleIEDAV] -Geo- C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe - (Apple Inc.) [ApplePhotoStreams] -Geo- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe - (Apple Inc.) [APSDaemon] -Geo- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe - (Apple Inc.) [AutoUpdate] -Geo- C:\WINDOWS\System32\AutoUpdate.exe - (Microsoft Corporation) [CCleaner] -Geo- C:\Program Files\CCleaner\CCleaner.exe - (Piriform Ltd) [conhost] -Geo- C:\WINDOWS\system32\conhost.exe - (Microsoft Corporation) [conhost] -SYSTEM- C:\WINDOWS\system32\conhost.exe - (Microsoft Corporation) [csrss] -SYSTEM- C:\WINDOWS\system32\csrss.exe - (Microsoft Corporation) [csrss] -SYSTEM- C:\WINDOWS\system32\csrss.exe - (Microsoft Corporation) [dasHost] -LOCAL SERVICE- C:\WINDOWS\system32\dashost.exe - (Microsoft Corporation) [dllhost] -SYSTEM- C:\WINDOWS\system32\dllhost.exe - (Microsoft Corporation) [dwm] -DWM-1- C:\WINDOWS\system32\dwm.exe - (Microsoft Corporation) [E-Peek 1.0.5] -Geo- C:\Program Files\E Dev\E-Peek\E-Peek 1.0.5.exe - (E Dev) [explorer] -Geo- C:\WINDOWS\Explorer.EXE - (Microsoft Corporation) [GoogleUpdate] -SYSTEM- C:\Program Files\Google\Update\GoogleUpdate.exe - (Google Inc.) [hpqbam08] -Geo- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe - (Hewlett-Packard Co.) [hpqgpc01] -Geo- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe - (Hewlett-Packard) [hpqste08] -Geo- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe - (Hewlett-Packard Co.) [hpqtra08] -Geo- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.) [hpwuschd2] -Geo- C:\Program Files\HP\HP Software Update\hpwuschd2.exe - (Hewlett-Packard) [iCloudServices] -Geo- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe - (Apple Inc.) [iexplore] -Geo- C:\Program Files\Internet Explorer\iexplore.exe - (Microsoft Corporation) [iexplore] -Geo- C:\Program Files\Internet Explorer\iexplore.exe - (Microsoft Corporation) [iexplore] -Geo- C:\Program Files\Internet Explorer\iexplore.exe - (Microsoft Corporation) [iexplore] -Geo- C:\Program Files\Internet Explorer\iexplore.exe - (Microsoft Corporation) [iexplore] -Geo- C:\Program Files\Internet Explorer\iexplore.exe - (Microsoft Corporation) [Kies] -Geo- C:\Program Files\Samsung\Kies\Kies.exe - (Samsung) [KiesTrayAgent] -Geo- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe - (Samsung Electronics Co., Ltd.) [LiveComm] -Geo- C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x86__8wekyb3d8bbwe\LiveComm.exe - (Microsoft Corporation) [lsass] -SYSTEM- C:\WINDOWS\system32\lsass.exe - (Microsoft Corporation) [mbam] -Geo- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe - (Malwarebytes Corporation) [mbamscheduler] -SYSTEM- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe - (Malwarebytes Corporation) [mbamservice] -SYSTEM- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe - (Malwarebytes Corporation) [mDNSResponder] -SYSTEM- C:\Program Files\Bonjour\mDNSResponder.exe - (Apple Inc.) [mighost] -Geo- C:\$Windows.~BT\Sources\mighost.exe - (Microsoft Corporation) [msdtc] -NETWORK SERVICE- C:\WINDOWS\System32\msdtc.exe - (Microsoft Corporation) [MsMpEng] -SYSTEM- C:\Program Files\Windows Defender\MsMpEng.exe - (Microsoft Corporation) [ONENOTEM] -Geo- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE - (Microsoft Corporation) [ReiGuard] -SYSTEM- C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe - (Reimage®) [RuntimeBroker] -Geo- C:\Windows\System32\RuntimeBroker.exe - (Microsoft Corporation) [Samsung Link Tray Agent] -Geo- C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe - (Copyright 2013 SAMSUNG) [Samsung Link] -SYSTEM- C:\Program Files\Samsung\Samsung Link\Samsung Link.exe - (Copyright 2013 SAMSUNG) [Samsung Link] -SYSTEM- C:\Program Files\Samsung\Samsung Link\Samsung Link.exe - (Copyright 2013 SAMSUNG) [SDFSSvc] -SYSTEM- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe - (Safer-Networking Ltd.) [SDTray] -Geo- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe - (Safer-Networking Ltd.) [SDUpdSvc] -SYSTEM- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe - (Safer-Networking Ltd.) [SDWSCSvc] -SYSTEM- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe - (Safer-Networking Ltd.) [SeaPort] -SYSTEM- C:\Program Files\Microsoft\BingBar\7.1.355.0\SeaPort.exe - (Microsoft Corporation.) [SearchFilterHost] -SYSTEM- C:\WINDOWS\system32\SearchFilterHost.exe - (Microsoft Corporation) [SearchIndexer] -SYSTEM- C:\WINDOWS\system32\SearchIndexer.exe - (Microsoft Corporation) [SearchProtocolHost] -SYSTEM- C:\WINDOWS\system32\SearchProtocolHost.exe - (Microsoft Corporation) [services] -SYSTEM- C:\WINDOWS\system32\services.exe - (Microsoft Corporation) [SetupHost] -Geo- C:\$Windows.~BT\Sources\SetupHost.Exe - (Microsoft Corporation) [smss] -SYSTEM- C:\WINDOWS\system32\smss.exe - (Microsoft Corporation) [spoolsv] -SYSTEM- C:\WINDOWS\System32\spoolsv.exe - (Microsoft Corporation) [SpotifyWebHelper] -Geo- C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe - (Spotify Ltd) [taskeng] -SYSTEM- C:\WINDOWS\system32\taskeng.exe - (Microsoft Corporation) [taskhost] -Geo- C:\WINDOWS\system32\taskhost.exe - (Microsoft Corporation) [taskhost] -LOCAL SERVICE- C:\WINDOWS\system32\taskhost.exe - (Microsoft Corporation) [taskhostex] -Geo- C:\WINDOWS\system32\taskhostex.exe - (Microsoft Corporation) [TeamViewer_Service] -SYSTEM- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe - (TeamViewer GmbH) [TomTomHOMERunner] -Geo- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe - (TomTom) [TomTomHOMEService] -SYSTEM- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe - (TomTom) [unsecapp] -Geo- C:\WINDOWS\system32\wbem\unsecapp.exe - (Microsoft Corporation) [wimserv] -Geo- C:\WINDOWS\system32\wimserv.exe - (Microsoft Corporation) [WindowsStoreSetupBox] -SYSTEM- C:\WINDOWS\SoftwareDistribution\Download\0fa20ec87b11f2348d77a29fb0b04300\WindowsStoreSetupBox.exe - (Microsoft Corporation) [wininit] -SYSTEM- C:\WINDOWS\system32\wininit.exe - (Microsoft Corporation) [winlogon] -SYSTEM- C:\WINDOWS\system32\winlogon.exe - (Microsoft Corporation) [WmiPrvSE] -NETWORK SERVICE- C:\WINDOWS\system32\wbem\wmiprvse.exe - (Microsoft Corporation) [wuauclt] -SYSTEM- C:\WINDOWS\system32\wuauclt.exe - (Microsoft Corporation) ==================== IE PAGES ================================================== IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://www.google.be/ IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\WINDOWS\system32\blank.htm IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE02 - HKCU\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEG&bmod=TSEG; IE04 - HKCU\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [Bing] @ URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE04 - HKCU\..\SearchScopes {401D16D1-B56D-42FD-BF77-1027943C9EF4} @ DisplayName: [Google] @ URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEG_nlBE356 IE05 - HKCU\..\URLSearchHooks @ {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = C:\Windows\System32\ieframe.dll IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Local Page = C:\Windows\System32\blank.htm IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEG&bmod=TSEG; IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE08 - HKLM\Software\Microsoft\Internet Explorer\Main @ Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 IE10 - HKLM\..\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ DisplayName: [@ieframe.dll,-12512] @ URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE10 - HKLM\..\SearchScopes {401D16D1-B56D-42FD-BF77-1027943C9EF4} @ DisplayName: [Google] @ URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEG; IE12 - HKLM\..\Toolbar{2318C2B1-4965-11d4-9B18-009027A5CD4F} @ Default = C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll IE12 - HKLM\..\Toolbar{8dcb7100-df86-4384-8842-8fa844297b3f} @ Default = "C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll" ==================== Auto Load ================================================= AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Userinit = C:\Windows\system32\userinit.exe, AL00 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon @ Shell = explorer.exe ==================== Windows Host File ========================================= ==================== BHO ======================================================= BHO - [Google Toolbar Helper] - {AA58ED58-01DD-4d91-8333-CF10577473F7} @ Default = C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll BHO - [Office Document Cache Handler] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} @ Default = C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL BHO - [Bing Bar Helper] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} @ Default = C:\Program Files\Microsoft\BingBar\7.1.355.0\BingExt.dll ==================== Auto Start Programs ======================================= ASP01 - HKLM\..\Run @ HP Software Update = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe ASP01 - HKLM\..\Run @ KiesTrayAgent = C:\Program Files\Samsung\Kies\KiesTrayAgent.exe ASP01 - HKLM\..\Run @ Samsung Link = "C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe" ASP01 - HKLM\..\Run @ SDTray = "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" ASP04 - HKCU\..\Run @ AppleIEDAV = C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe ASP04 - HKCU\..\Run @ ApplePhotoStreams = C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe ASP04 - HKCU\..\Run @ CCleaner Monitoring = "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR ASP04 - HKCU\..\Run @ iCloudServices = C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe ASP04 - HKCU\..\Run @ KiesPreload = C:\Program Files\Samsung\Kies\Kies.exe /preload ASP04 - HKCU\..\Run @ Spotify Web Helper = "C:\Users\Geo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" ASP04 - HKCU\..\Run @ TomTomHOME.exe = "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" ASP - Startup - C:\Users\Geo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ASP - Startup - C:\Users\Geo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk ASP - CommonStartup - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini ASP - CommonStartup - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ==================== Extra Items IE ============================================ EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCELERATED_GRAPHICS @ Text = Accelerated graphics EI03 - Adv Opt - HKLM\..\AdvancedOptions\ACCESSIBILITY @ Text = Accessibility EI03 - Adv Opt - HKLM\..\AdvancedOptions\BROWSE @ Text = Browsing EI03 - Adv Opt - HKLM\..\AdvancedOptions\CRYPTO @ Text = Security EI03 - Adv Opt - HKLM\..\AdvancedOptions\HTTP @ Text = HTTP 1.1 settings EI03 - Adv Opt - HKLM\..\AdvancedOptions\INTERNATIONAL @ Text = International EI03 - Adv Opt - HKLM\..\AdvancedOptions\MULTIMEDIA @ Text = Multimedia ==================== Internet Default Prefix =================================== IDP00 - Default - HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix @ Default = http:// IDP01 - WWW - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes @ WWW = http:// ==================== Default Settings IE - DSIE ================================ DSIE - ieuinit.inf: START_PAGE= "http://go.microsoft.com/fwlink/p/?LinkId DSIE - ieuinit.inf: SEARCH_PAGE_URL= "http://go.microsoft.com/fwlink/?LinkId ==================== Trusted Zones - TZ ======================================== ==================== Protocol Hijackers - PH =================================== PH01 - Filter:text/xml - {807573E5-5146-11D5-A672-00B0D022E945} @ = C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL <= Unknown ==================== ShellServiceObjectDelayLoad - SSODL ======================= SSODL - WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} @ = ==================== Extra items - EXT (Torpig/ConduitSearch) ================== EXT01 - HKCU\SOFTWARE\AppDataLow\Software\Microsoft EXT02 - HKCR\Directory\shellex\CopyHookHandlers\FileSystem @ {217FC9C0-3AEA-1069-A2DB-08002B30309D}= C:\WINDOWS\system32\shell32.dll EXT02 - HKCR\Directory\shellex\CopyHookHandlers\Sharing @ {40dd6e20-7c17-11ce-a804-00aa003ca9f6}= C:\WINDOWS\system32\ntshrui.dll ==================== DRIVERS and SERVICES ====================================== *** Win32OwnProcess *** SERV - R2 - [AllShare Framework DMS] - AllShare Framework DMS - c:\program files\samsung\allshare framework dms\1.3.23\allshareframeworkmanagerdms.exe SERV - R2 - [Bonjour Service] - Bonjour-service - c:\program files\bonjour\mdnsresponder.exe SERV - R2 - [MBAMScheduler] - MBAMScheduler - c:\program files\malwarebytes anti-malware\mbamscheduler.exe SERV - R2 - [MBAMService] - MBAMService - c:\program files\malwarebytes anti-malware\mbamservice.exe SERV - R2 - [ReimageRealTimeProtector] - Reimage Real Time Protector - c:\program files\reimage\reimage protector\reiguard.exe SERV - R2 - [Samsung Link Service] - Samsung Link Service - c:\program files\samsung\samsung link\samsung link.exe SERV - R2 - [SDScannerService] - Spybot-S&D 2 Scanner Service - c:\program files\spybot - search & destroy 2\sdfssvc.exe SERV - R2 - [SDUpdateService] - Spybot-S&D 2 Updating Service - c:\program files\spybot - search & destroy 2\sdupdsvc.exe SERV - R2 - [SDWSCService] - Spybot-S&D 2 Security Center Service - c:\program files\spybot - search & destroy 2\sdwscsvc.exe SERV - R2 - [TeamViewer8] - TeamViewer 8 - c:\program files\teamviewer\version8\teamviewer_service.exe SERV - R2 - [WinDefend] - Windows Defender Service - c:\program files\windows defender\msmpeng.exe SERV - R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe SERV - R3 - [BBUpdate] - BBUpdate - c:\program files\microsoft\bingbar\7.1.355.0\seaport.exe SERV - R3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe SERV - R3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe SERV - S2 - [BBSvc] - BingBar Service - c:\program files\microsoft\bingbar\7.1.355.0\bbsvc.exe SERV - S2 - [gupdate] - Google Update-service (gupdate) - c:\program files\google\update\googleupdate.exe SERV - S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe SERV - S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe SERV - S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe SERV - S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe SERV - S3 - [gupdatem] - Google Update-service (gupdatem) - c:\program files\google\update\googleupdate.exe SERV - S3 - [gusvc] - Google Software Updater - c:\program files\google\common\google updater\googleupdaterservice.exe SERV - S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe SERV - S3 - [ose] - Office Source Engine - c:\program files\common files\microsoft shared\source engine\ose.exe SERV - S3 - [osppsvc] - Office Software Protection Platform - c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe SERV - S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe SERV - S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe SERV - S3 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe SERV - S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe SERV - S3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe SERV - S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe SERV - S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe SERV - S3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe *** Win32ShareProcess *** SERV - R2 - [SamSs] - Security Accounts Manager - c:\windows\system32\lsass.exe SERV - S3 - [EFS] - Encrypting File System (EFS) - c:\windows\system32\lsass.exe SERV - S3 - [KeyIso] - CNG Key Isolation - c:\windows\system32\lsass.exe SERV - S3 - [Netlogon] - Netlogon - c:\windows\system32\lsass.exe SERV - S3 - [VaultSvc] - Credential Manager - c:\windows\system32\lsass.exe SERV - S4 - [NetTcpPortSharing] - Net.Tcp Port Sharing Service - c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe *** Others *** SERV - R2 - [Spooler] - Print Spooler - c:\windows\system32\spoolsv.exe SERV - R2 - [TomTomHOMEService] - TomTomHOMEService - c:\program files\tomtom home 2\tomtomhomeservice.exe SERV - S3 - [UI0Detect] - Interactive Services Detection - c:\windows\system32\ui0detect.exe *** File System Driver *** DRV - R0 - [FileInfo] - File Information FS MiniFilter - C:\WINDOWS\system32\Drivers\FileInfo.sys DRV - R0 - [FltMgr] - FltMgr - C:\WINDOWS\system32\Drivers\FltMgr.sys DRV - R0 - [Mup] - Mup - C:\WINDOWS\system32\Drivers\Mup.sys DRV - R0 - [WdFilter] - Windows Defender Mini-Filter Driver - C:\WINDOWS\system32\Drivers\WdFilter.sys DRV - R1 - [NetBIOS] - NetBIOS Interface - C:\WINDOWS\system32\Drivers\NetBIOS.sys DRV - R3 - [srv] - Server SMB 1.xxx Driver - C:\WINDOWS\system32\Drivers\srv.sys DRV - R3 - [srv2] - Server SMB 2.xxx Driver - C:\WINDOWS\system32\Drivers\srv2.sys *** Kernel Driver *** DRV - R0 - [ACPI] - Microsoft ACPI-stuurprogramma - C:\WINDOWS\system32\Drivers\ACPI.sys DRV - R0 - [acpiex] - Microsoft ACPIEx Driver - C:\WINDOWS\system32\Drivers\acpiex.sys DRV - R0 - [CLFS] - Common Log (CLFS) - C:\WINDOWS\system32\Drivers\CLFS.sys DRV - R0 - [CNG] - CNG - C:\WINDOWS\system32\Drivers\CNG.sys DRV - R0 - [disk] - Stuurprogramma voor schijfstations - C:\WINDOWS\system32\Drivers\disk.sys DRV - R0 - [EhStorClass] - Enhanced Storage Filter Driver - C:\WINDOWS\system32\Drivers\EhStorClass.sys DRV - R0 - [fvevol] - BitLocker Drive Encryption Filter Driver - C:\WINDOWS\system32\Drivers\fvevol.sys DRV - R0 - [KSecDD] - KSecDD - C:\WINDOWS\system32\Drivers\KSecDD.sys DRV - R0 - [KSecPkg] - KSecPkg - C:\WINDOWS\system32\Drivers\KSecPkg.sys DRV - R0 - [mountmgr] - Mount Point Manager - C:\WINDOWS\system32\Drivers\mountmgr.sys DRV - R0 - [msisadrv] - msisadrv - C:\WINDOWS\system32\Drivers\msisadrv.sys DRV - R0 - [NDIS] - NDIS System Driver - C:\WINDOWS\system32\Drivers\NDIS.sys DRV - R0 - [partmgr] - Partition Manager - C:\WINDOWS\system32\Drivers\partmgr.sys DRV - R0 - [pci] - PCI Bus-stuurprogramma - C:\WINDOWS\system32\Drivers\pci.sys DRV - R0 - [pcw] - Performance Counters for Windows Driver - C:\WINDOWS\system32\Drivers\pcw.sys DRV - R0 - [pdc] - pdc - C:\WINDOWS\system32\Drivers\pdc.sys DRV - R0 - [rdyboost] - ReadyBoost - C:\WINDOWS\system32\Drivers\rdyboost.sys DRV - R0 - [spaceport] - Stuurprogramma voor opslagruimten - C:\WINDOWS\system32\Drivers\spaceport.sys DRV - R0 - [storahci] - Microsoft Standaard SATA AHCI-stuurprogramma - C:\WINDOWS\system32\Drivers\storahci.sys DRV - R0 - [Tcpip] - Stuurprogramma voor TCP/IP-protocol - C:\WINDOWS\system32\Drivers\Tcpip.sys DRV - R0 - [TVALZ] - TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver - C:\WINDOWS\system32\Drivers\TVALZ.sys [x] DRV - R0 - [vdrvroot] - Microsoft Virtual Drive Enumerator - C:\WINDOWS\system32\Drivers\vdrvroot.sys DRV - R0 - [volmgr] - Stuurprogramma voor Volumebeheer - C:\WINDOWS\system32\Drivers\volmgr.sys DRV - R0 - [volmgrx] - Dynamic Volume Manager - C:\WINDOWS\system32\Drivers\volmgrx.sys DRV - R0 - [volsnap] - Opslagvolumes - C:\WINDOWS\system32\Drivers\volsnap.sys DRV - R0 - [Wdf01000] - Kernel Mode Driver Frameworks service - C:\WINDOWS\system32\Drivers\Wdf01000.sys DRV - R0 - [WFPLWFS] - Microsoft Windows-filterplatform - C:\WINDOWS\system32\Drivers\WFPLWFS.sys DRV - R1 - [AFD] - Ancillary Function Driver for Winsock - C:\WINDOWS\system32\Drivers\AFD.sys DRV - R1 - [Beep] - Beep - C:\WINDOWS\system32\Drivers\Beep.sys DRV - R1 - [tdx] - Stuurprogramma voor ondersteuning van NetIO Legacy TDI - C:\WINDOWS\system32\Drivers\tdx.sys DRV - R2 - [tcpipreg] - TCP/IP Registry Compatibility - C:\WINDOWS\system32\Drivers\tcpipreg.sys DRV - S0 - [hwpolicy] - Hardware Policy Driver - C:\WINDOWS\system32\Drivers\hwpolicy.sys DRV - S3 - [atapi] - IDE-kanaal - C:\WINDOWS\system32\Drivers\atapi.sys ==================== SvcHost - White Listed ==================================== HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@hpdevmgmt hpqcxs08 = ServiceDll = C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [0d0213498683414dde29b1686a4c08d5] hpqddsvc = ServiceDll = C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [ee281dd6843f3f697c1ad7933eeb1e9b] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@HPService HPSLPSVC = ServiceDll = C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [449fe0cc10851eb123f10688629d2698] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@HPZ12 Pml Driver HPZ12 = ServiceDll = C:\WINDOWS\system32\HPZipm12.dll [65bc271f337637731d3c71455ae1f476] Net Driver HPZ12 = ServiceDll = C:\WINDOWS\system32\HPZinw12.dll [a081cb6fb9a12668f233eb5414be3a0e] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@print PrintNotify = ServiceDll = C:\Windows\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll [de50965045161f015d16b52efe3aebd9] ==================== SigCheck x86 Fast ========================================= Fast Scan All ok ==================== Job tasks ================================================= There are no .job files found. ==================== End scanning at do 6 nov 2014 16:15 (0 Min 21 Sec ) =======