Logfile of random's system information tool 1.10 (written by random/random) Run by hennie at 2015-04-24 11:42:47 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 258 GB (80%) free of 323 GB Total RAM: 1015 MB (15% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:43:26, on 24-4-2015 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.19612) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\hkcmd.exe C:\Program Files\AVG\AVG2015\avgui.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Windows\system32\ctfmon.exe C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\Users\hennie\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\hennie\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\hennie\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\hennie\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\hennie\Documents\Downloads\RSIT (1).exe C:\Program Files\trend micro\hennie.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={961C1CFA-9A76-4D92-87A3-A228B2080F60}&mid=c58bc967d89247cdbc42d15426af2cdd-c3309647e0c8f106dc9ce2d3c900db9ee0fe34fc&lang=nl&ds=AVG&coid=avgtbavg&cmpid=0215pit&pr=fr&d=2015-04-19 16:03:35&v=4.1.0.411&pid=wtu&sg=&sap=hp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O3 - Toolbar: Mirar - {006C9380-D33C-40DF-9283-F4AACFAC5A02} - C:\Windows\system32\fb78.dll (file missing) O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [GroupsICT] C:\Users\hennie\AppData\Roaming\GroupsICT.exe O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart O4 - HKCU\..\Run: [Google Update] "C:\Users\hennie\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6.4; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; OfficeLivePatch.1.3; .NET CLR 3.0.30729; OfficeLiveConnector.1.4)" -"http://www.spele.nl/game/pacman/motor_banen.html" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O8 - Extra context menu item: Zoek op het web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Unknown owner - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (file missing) O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe -- End of file - 7614 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-916243623-521414899-487270652-1000Core.job - C:\Users\hennie\AppData\Local\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-916243623-521414899-487270652-1000UA.job - C:\Users\hennie\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {006C9380-D33C-40DF-9283-F4AACFAC5A02} - Mirar - C:\Windows\system32\fb78.dll [] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184] "toolbar_eula_launcher"=C:\Program Files\GoogleEULA\EULALauncher.exe [2007-02-09 16896] "Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424] "DivXMediaServer"=C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [] "AVG_UI"=C:\Program Files\AVG\AVG2015\avgui.exe [2015-04-15 3745232] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240] "uTorrent"=C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED [] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920] "GroupsICT"=C:\Users\hennie\AppData\Roaming\GroupsICT.exe [] "GoogleDriveSync"=C:\Program Files\Google\Drive\googledrivesync.exe /autostart [] "Google Update"=C:\Users\hennie\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-24 107912] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Shockwave Updater"=C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; GTB6.4; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; OfficeLivePatch.1.3; .NET CLR 3.0.30729; OfficeLiveConnector.1.4) -http://www.spele.nl/game/pacman/motor_banen.html [] C:\Users\hennie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2008-02-11 204800] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "MSVideo8"=VfWWDM32.dll "msacm.siren"=sirenacm.dll "VIDC.IV41"=IR41_32.AX "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "mixer1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2015-04-23 19:31:19 ----A---- C:\MBAM Scanlog.txt 2015-04-23 16:50:54 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys 2015-04-23 16:48:14 ----D---- C:\Program Files\Malwarebytes Anti-Malware 2015-04-23 16:48:14 ----A---- C:\Windows\system32\drivers\mwac.sys 2015-04-23 16:48:14 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys 2015-04-23 16:48:14 ----A---- C:\Windows\system32\drivers\mbam.sys 2015-04-21 15:15:17 ----D---- C:\AdwCleaner 2015-04-20 20:41:14 ----D---- C:\Program Files\trend micro 2015-04-20 20:41:12 ----D---- C:\rsit 2015-04-20 19:01:43 ----A---- C:\Windows\system32\msxml3.dll 2015-04-20 18:20:10 ----A---- C:\Windows\system32\gdi32.dll 2015-04-20 18:16:45 ----A---- C:\Windows\system32\clfsw32.dll 2015-04-20 18:16:45 ----A---- C:\Windows\system32\clfs.sys 2015-04-20 18:15:11 ----A---- C:\Windows\system32\ntkrnlpa.exe 2015-04-20 18:15:11 ----A---- C:\Windows\system32\ntdll.dll 2015-04-20 18:15:10 ----A---- C:\Windows\system32\ntoskrnl.exe 2015-04-20 17:36:46 ----A---- C:\Windows\system32\drivers\089B7368.sys 2015-04-19 17:59:09 ----A---- C:\Windows\system32\drivers\08993668.sys 2015-04-19 16:01:46 ----D---- C:\ProgramData\AVG Web TuneUp 2015-04-19 16:00:13 ----D---- C:\Program Files\AVG Web TuneUp 2015-04-19 14:48:43 ----D---- C:\Users\hennie\AppData\Roaming\AVG2015 2015-04-19 14:45:35 ----HD---- C:\$AVG 2015-04-19 14:45:34 ----D---- C:\ProgramData\AVG2015 2015-04-19 14:43:54 ----D---- C:\Program Files\AVG 2015-04-19 14:28:19 ----HD---- C:\ProgramData\Common Files 2015-04-19 14:28:18 ----D---- C:\ProgramData\MFAData 2015-04-19 14:18:43 ----A---- C:\Windows\system32\WindowsAccessBridge.dll 2015-04-19 14:18:43 ----A---- C:\Windows\system32\javaw.exe 2015-04-19 14:18:42 ----A---- C:\Windows\system32\javaws.exe 2015-04-19 14:18:42 ----A---- C:\Windows\system32\java.exe 2015-04-19 14:09:02 ----D---- C:\Program Files\Common Files\Java 2015-04-19 13:50:05 ----A---- C:\DelFix.txt 2015-04-15 17:06:42 ----A---- C:\Windows\system32\mshtml.dll 2015-04-15 17:06:40 ----A---- C:\Windows\system32\urlmon.dll 2015-04-15 17:06:40 ----A---- C:\Windows\system32\ieframe.dll 2015-04-15 17:06:39 ----A---- C:\Windows\system32\vbscript.dll 2015-04-15 17:06:39 ----A---- C:\Windows\system32\msfeeds.dll 2015-04-15 17:06:38 ----A---- C:\Windows\system32\wininet.dll 2015-04-15 17:06:38 ----A---- C:\Windows\system32\mstime.dll 2015-04-15 17:06:38 ----A---- C:\Windows\system32\iertutil.dll 2015-04-15 17:06:37 ----A---- C:\Windows\system32\iedkcs32.dll 2015-04-15 17:06:37 ----A---- C:\Windows\system32\dxtrans.dll 2015-04-15 17:06:36 ----A---- C:\Windows\system32\occache.dll 2015-04-15 17:06:36 ----A---- C:\Windows\system32\ieui.dll 2015-04-15 17:06:36 ----A---- C:\Windows\system32\dxtmsft.dll 2015-04-15 17:06:35 ----A---- C:\Windows\system32\url.dll 2015-04-15 17:06:35 ----A---- C:\Windows\system32\ieUnatt.exe 2015-04-15 17:06:35 ----A---- C:\Windows\system32\iesysprep.dll 2015-04-15 17:06:35 ----A---- C:\Windows\system32\iepeers.dll 2015-04-15 17:06:34 ----A---- C:\Windows\system32\mshtmled.dll 2015-04-15 17:06:34 ----A---- C:\Windows\system32\msfeedsbs.dll 2015-04-15 17:06:34 ----A---- C:\Windows\system32\licmgr10.dll 2015-04-15 17:06:34 ----A---- C:\Windows\system32\iesetup.dll 2015-04-15 17:06:34 ----A---- C:\Windows\system32\iernonce.dll 2015-04-15 17:06:33 ----A---- C:\Windows\system32\msfeedssync.exe 2015-04-15 17:06:33 ----A---- C:\Windows\system32\jsproxy.dll 2015-04-15 17:06:33 ----A---- C:\Windows\system32\ie4uinit.exe 2015-04-15 17:06:33 ----A---- C:\Windows\system32\corpol.dll 2015-04-15 13:05:06 ----A---- C:\Windows\system32\drivers\avgldx86.sys 2015-04-09 14:12:50 ----A---- C:\Windows\system32\drivers\avgidsdriverx.sys 2015-04-07 12:45:10 ----A---- C:\Windows\system32\drivers\avgtdix.sys 2015-04-03 09:37:24 ----A---- C:\Windows\system32\drivers\avgmfx86.sys ======List of files/folders modified in the last 1 month====== 2015-04-24 11:42:41 ----D---- C:\Windows\Temp 2015-04-24 11:21:55 ----SHD---- C:\System Volume Information 2015-04-23 16:53:16 ----D---- C:\Windows\system32\drivers 2015-04-23 16:48:14 ----RD---- C:\Program Files 2015-04-22 17:04:09 ----SHD---- C:\Windows\Installer 2015-04-22 17:04:06 ----D---- C:\Users\hennie\AppData\Roaming\Mozilla 2015-04-22 17:00:23 ----D---- C:\Windows\System32 2015-04-22 17:00:23 ----D---- C:\Windows\inf 2015-04-22 17:00:23 ----A---- C:\Windows\system32\PerfStringBackup.INI 2015-04-21 15:23:04 ----D---- C:\Program Files\Common Files 2015-04-21 15:23:02 ----HD---- C:\ProgramData 2015-04-20 19:22:12 ----D---- C:\Program Files\Internet Explorer 2015-04-20 19:22:11 ----D---- C:\Windows\system32\migration 2015-04-20 19:02:27 ----D---- C:\Windows\winsxs 2015-04-20 19:02:25 ----D---- C:\Windows\system32\catroot 2015-04-20 19:01:29 ----D---- C:\Windows\system32\MRT 2015-04-20 18:59:06 ----D---- C:\Windows\Microsoft.NET 2015-04-20 18:27:00 ----RSD---- C:\Windows\assembly 2015-04-20 18:21:24 ----A---- C:\Windows\system32\mrt.exe 2015-04-20 18:19:35 ----D---- C:\ProgramData\Microsoft Help 2015-04-20 18:01:45 ----D---- C:\Windows\system32\catroot2 2015-04-19 16:06:25 ----D---- C:\Windows\Tasks 2015-04-19 14:54:07 ----D---- C:\Windows\system32\Tasks 2015-04-19 14:47:21 ----D---- C:\Users\hennie\AppData\Roaming\TuneUp Software 2015-04-19 14:23:37 ----D---- C:\Program Files\Java 2015-04-19 14:04:13 ----D---- C:\ProgramData\Oracle 2015-04-19 12:54:44 ----D---- C:\ProgramData\Malwarebytes 2015-04-14 19:35:24 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2015-04-01 15:57:54 ----D---- C:\Windows\system32\LogFiles ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2015-03-11 166880] R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2015-03-11 269792] R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2015-04-03 110048] R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2015-03-20 35808] R1 Avgdiskx;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiskx.sys [2015-03-11 132576] R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2015-04-09 226784] R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-03-11 29664] R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2015-04-15 206816] R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2015-04-07 213984] R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688] R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller; C:\Windows\system32\DRIVERS\l260x86.sys [2008-10-16 29184] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600] R3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 23256] R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-04-24 114904] R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 51928] R3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136] R3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328] R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] R3 X10Hid;X10 Hid Device; C:\Windows\System32\Drivers\x10hid.sys [2006-11-17 13976] S1 NGS;Norman General Security Driver; \??\c:\program files\norman\ngs\bin\ngs.sys [] S3 3xHybrid;Philips SAA713x PCI Card; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-01-08 1136600] S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2; C:\Windows\system32\DRIVERS\aabed2.sys [2008-03-20 23040] S3 FETNDIS;VIA Rhine-Family Fast Ethernet Adapter Driver-service; C:\Windows\system32\DRIVERS\fetnd5.sys [2006-11-02 45568] S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272] S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976] S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [] S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032] S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [] S3 uxddrv;Dynamically loaded UxdDrv; \??\E:\DIAGNOSE\WSTENG32\2PART\uxddrv86.sys [] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088] R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [2015-04-15 3438032] R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [2015-04-15 311792] R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504] R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440] R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536] R2 WtuSystemSupport;WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [2015-04-19 620056] R2 x10nets;X10 Device Network Service; C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe [2001-11-12 20480] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-24 107912] S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14 268464] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-24 107912] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168] S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] -----------------EOF-----------------