Logfile of random's system information tool 1.10 (written by random/random) Run by Mirjam at 2015-07-03 21:29:42 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 328 GB (72%) free of 456 GB Total RAM: 4044 MB (47% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:29:56, on 3-7-2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17840) Boot mode: Normal Running processes: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\MiuiTab\cmdshell.exe C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe C:\Program Files (x86)\IObit\Smart Defrag 4\SmartDefrag.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe C:\Program Files (x86)\MiuiTab\HPNotify.exe C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebApp.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files\trend micro\Mirjam.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1435829777&z=5b731d3e1c113d1a850eb4cg0zdc3w1beo8t2m8m0t&from=cmi&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1435829777&z=5b731d3e1c113d1a850eb4cg0zdc3w1beo8t2m8m0t&from=cmi&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1435829777&z=5b731d3e1c113d1a850eb4cg0zdc3w1beo8t2m8m0t&from=cmi&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519&q={searchTerms} R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1435829777&z=5b731d3e1c113d1a850eb4cg0zdc3w1beo8t2m8m0t&from=cmi&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519&q={searchTerms} R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1435829777&z=5b731d3e1c113d1a850eb4cg0zdc3w1beo8t2m8m0t&from=cmi&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\MiuiTab\SupTab.dll O2 - BHO: TSBHO Class - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Ads Removal - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart O4 - HKLM\..\Run: [SmartWeb] C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex (User 'Default user') O4 - Startup: SmartWeb.lnk = C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe O4 - Startup: StormWatch.lnk = C:\Program Files (x86)\StormWatch\StormWatch.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: TrueSuiteService (FPLService) - HP - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe O23 - Service: globalUpdate Update Service (globalUpdate1d0b4ab5ae6cdb2) (globalUpdate1d0b4ab5ae6cdb2) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe (file missing) O23 - Service: globalUpdate Update Service (globalUpdatem1d0b4ab5b0ce3b7) (globalUpdatem1d0b4ab5b0ce3b7) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\MiuiTab\ProtectService.exe O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: StormWatch Update Service - Unknown owner - C:\Program Files (x86)\StormWatch\StormWatchSrv.exe O23 - Service: SWUpdaterSvc (SWUpdater) - Weather Protector LLC - C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: Encyclopaedia Enter (vicoqudu) - Unknown owner - C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\hnswC8AD.tmp O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: WikiBrowserUpdateService - Unknown owner - C:\Users\Mirjam\AppData\Local\WikiUpdate.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Recharge Advertisement (xyvypiqy) - Unknown owner - C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\knsgB1C1.tmp O23 - Service: Typewriter High Resolution (zejytose) - Unknown owner - C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\jnsbB2DA.tmp -- End of file - 14486 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe" C:\Windows\system32\svchost.exe -k RPCSS "c:\Program Files\Microsoft Security Client\MsMpEng.exe" C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs "C:\Program Files\IDT\WDM\STacSV64.exe" C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k NetworkService "C:\Windows\system32\Dwm.exe" C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe" "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" C:\Windows\System32\svchost.exe -k utcsvc C:\Windows\SysWOW64\ezSharedSvcHost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe" "C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe" "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe" "C:\Windows\System32\hkcmd.exe" "C:\Windows\System32\igfxpers.exe" "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "C:\Program Files\IDT\WDM\sttray64.exe" "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey "C:\Program Files (x86)\MiuiTab\ProtectService.exe" "C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe" "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe" "C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe" "C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe" "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "C:\Program Files (x86)\MiuiTab\cmdshell.exe" "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" "C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe" "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" "C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true "taskhost.exe" C:\Windows\system32\svchost.exe -k imgsvc C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\hnswC8AD.tmp C:\Users\Mirjam\AppData\Local\WikiUpdate.exe "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" WLIDSvcM.exe 3320 C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\jnsbB2DA.tmp "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan" "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart "C:\Windows\system32\GWX\GWX.exe" taskeng.exe {37A939D0-484B-4DF0-837E-4B722082DB61} "C:\Program Files (x86)\IObit\Smart Defrag 4\SmartDefrag.exe" /startup "C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe" /Task taskeng.exe {3FE9E6D8-61B8-430F-8B2D-CB4C9A8204A3} "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe" C:\Windows\system32\wbem\wmiprvse.exe "c:\Program Files\Microsoft Security Client\NisSrv.exe" "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe" C:\Windows\system32\SearchIndexer.exe /Embedding C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted "C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-697b5464-c2b9-4366-b4ee-040a433201ba -SystemEventPortName:HostProcess-12647538-ebe3-4ad4-abaa-64bb9a91c90c -IoCancelEventPortName:HostProcess-407a0e86-ff42-40e4-9cc6-d29edefd4d2d -NonStateChangingEventPortName:HostProcess-b1b9a6c3-9cdf-4c01-9c45-9bb85085b17c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a5fe07e4-6e96-4a43-a12c-d80c1cc00efc -DeviceGroupId:WpdFsGroup "C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE" "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe" C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/1.9.1.474" --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --channel="1244.0.1873167460\1696539519" /prefetch:673131151 "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" "C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe" HPNotify.exe -run "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" C:\Windows\system32\wbem\wmiprvse.exe "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe" /starttips "C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe" SmartWebApp.exe C:\Windows\system32\wbem\unsecapp.exe -Embedding "C:\Program Files (x86)\StormWatch\StormWatchSrv.exe" "C:\Program Files (x86)\StormWatch\StormWatchApp.exe" /S /distid=122486 /distid=122486 /S /tpchannelid=channel5 /distid=122486 /install=1 "C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe" "C:\Program Files (x86)\StormWatch\StormWatch.exe" /installer 122486 channel5 "taskhost.exe" C:\Windows\system32\AUDIODG.EXE 0x498 C:\Windows\system32\sppsvc.exe "C:\Program Files (x86)\Windows Live\Mail\wlmail.exe" "C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding taskeng.exe {06664166-F28F-4288-97FC-E1D87865E62B} C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\knsgB1C1.tmp "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://track.pc-helpforum.be/track/click/30483147/www.pc-helpforum.be?p=eyJzIjoieVJlSHBuN0d4OTQxSVg4aU1pOU9aQnFMWlhJIiwidiI6MSwicCI6IntcInVcIjozMDQ4MzE0NyxcInZcIjoxLFwidXJsXCI6XCJodHRwOlxcXC9cXFwvd3d3LnBjLWhlbHBmb3J1bS5iZVxcXC90b3BpY1xcXC81ODg2NC1tYWx3YXJlLW5hLWRvd25sb2FkXFxcLz92aWV3PWdldG5ld3Bvc3RcIixcImlkXCI6XCJhM2I5ZjI4YjZkYzU0ZjJiYmMzNWU3N2E1OWYyYjM5OFwiLFwidXJsX2lkc1wiOltcImE4NzBjYWE1NTY2NmJhNjAzNWQ4NjJmNjk5NTE4ZWFjYzk3OWFkZTNcIl19In0" "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8920.0.1446422329\1401368704" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,9,21,44 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0116 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2372 --ignored=" --type=renderer " /prefetch:822062411 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowIdleFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledConnectionRacing/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=8920 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --disable-accelerated-video-decode --channel="8920.1.1764479854\1675533633" /prefetch:673131151 "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Unused_4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledConnectionRacing/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=8920 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --disable-accelerated-video-decode --channel="8920.2.360872348\445600861" /prefetch:673131151 "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528 "C:\Users\Mirjam\Downloads\RSITx64.exe" taskhost.exe $(Arg0) ======Scheduled tasks folder====== C:\Windows\tasks\APSnotifierPP1.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier 3A C:\Windows\tasks\APSnotifierPP2.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier 4 C:\Windows\tasks\APSnotifierPP3.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier 6 C:\Windows\tasks\Crossbrowse.job - C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe /rawdata='joMRltcRmn/z3fMM4NqUlhJUMDhpihSOvlFEWRqpj8DkXmmgkyUErhKjJ/lEAkzZSoiPkqcYMY2nCqh0i5EA2X+ClNbRwHIWgFTM4Icxzh65vbPGYOTNTTL95v2EHKm5Ors4aD0fHeLBFq+wIjnQs6IIExIgsqdK6iCrIYVY5PaOJlJxzHbdN1UU2NWRmwAzni18LVv9vNx3M33KPDR3bJ9s0bUgp7DjbkLiI1oWbWs6zlH/ELysBsNS7A8JypQJ76JsqicGDL5u4irVc5im61BdW3dRu1F7Py+VuhyThYBiwaRN3jYRN8duk5A4u5kzpDnoyUynMN3uDpT+kgH1Uw==' C:\Windows\tasks\FWRMDCIVECTHWPVS.job - C:\ProgramData\Service1291\Service1291.exe C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler C:\Windows\tasks\HPCeeScheduleForMIRJAM-HP$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForMIRJAM-HP$ (null) C:\Windows\tasks\HPCeeScheduleForMirjam.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForMirjam (null) C:\Windows\tasks\jjIV957BFlWVKXJ.job - C:\Users\Mirjam\AppData\Roaming\jjIV957BFlWVKXJ.exe --c=I0bcgEhGEoCoHCcknEi4iER6yvCaePALrmfH8WxUB91DXHbn5b0PdnTQ9xb3SuY3LDLCKeFtLib2kEsIOWD7c3HYZXtO861x6qYVxHHSJuI08BgKjOWf22A0pjHpuxhV1FrFKVJKSRu5XKBd+vCs1X1XvzGu+QHr2+VqMxoZ4bxOYARhYQ8NHK8h8D+obT+46uCqqd4eppBTMpsa4KJ3fhAFrgVCWm6dNigC5qbvGbW2FuPhhGB2Equtg2+ze0vEgX24hq3ZXRzYoTxKUWw+jEdPjC+Bbyn3UA77Ul8gWCH/aYJwSdkW77TTFuuK6nwRQ/R/RNKyoaVOdhXMB2oW2A== C:\Windows\tasks\m7BvemfPnDqtu.job - C:\Users\Mirjam\AppData\Roaming\m7BvemfPnDqtu.exe --c=Shp63WZmeENzFdYKpIm/dw4gKtI8JN8b1rSFpG28hp6vzuBIi+2qkVAD/b7qCJb0c9dJQ2YA3xfgXIPC/Oxkum0QNCPuGGaQAvalJ0DriI9TPt/a6n+Mh8MiO953iRU8Rw78zEq7y0LjKYEiTzb29yH6n5GnD4rqMLIhbnVOWMB+baec62MpO80oq4/3iG7vMAHmmdy4uYFW4L0jPcINMDGgS6/wjpFLqzO2wCCVwbxBf+sW07ihZ3uIS1J1Q4CbMUs/1wTVk1hmHEuDBHNHMZVr08S3KlYj1NZTP8JQB3SasIGEnyyq5rLcBcxXDMQCmxmAOJVmMuPN8p48BlaP1g== C:\Windows\tasks\m7BvemfPnDqtugK.job - C:\Users\Mirjam\AppData\Roaming\m7BvemfPnDqtugK.exe --c=ObCdkc+cvtllxd11oe2dzkYs02I6HuGhy47Jw35jcK8LVNmkmua1pNlizfC3057FDrrr6FWJn6OxDWon2too6zOLaUxQU4K01Q40g4kfbt8Q5jSdg18vnIqawCiDBVmC8saDOzrLSh1CY65yd38l33xezTndEDJwZAGOteTUGk2Onj5sxJxUjy1r20X4O39wfnLHls+YHWo3AC4YPdtFjqV6O18R7MhC1Qks0dknf9aCwl+iwBW+LtDx6QGykpMfoxsnwkwSmVR3cFjO8u1Kx2DUt3c/X9bpzoWMgp8xtoqO3EDxAg0KdqDvvaxnpnY7XOXiAFr8rYRYkTMV8LBzFQ== C:\Windows\tasks\OKCNUPSY1.job - C:\ProgramData\FlashBeat\FlashBeat.exe C:\Windows\tasks\TxCzqQ7kD4.job - C:\Users\Mirjam\AppData\Roaming\TxCzqQ7kD4.exe --c=JSbARVEhiwbm+NmVhJDGSz+3X3kPYB6Gho5FRHjStykCHfHmqf3jk4OfjJU3Pk2pKaqKpC/gR0OpD6r3/4LA49nJNt9gzkP6vJJpaWuHvjb/Gpr4WtFwiso0asrA17aT+FTCN8JKYZXIiBpRriVKEL3LmgNYxijwNa0as8IzlVRmH7bMI2W7lt+GdbYBZYgnMHcov8H5F+8OOLDBXsxa68VauoWtHyTlPOS123vhYaJNMlW1MDFMwty+++Rea5XYHttbvoqSkU/I16Da3LYLSx9L1VizlH612EO3J5CrwzpjxYOvXK/td1A/AzNoiWpWI2Dm5uV6Ey4j3FT5WFUsFg== =========Mozilla firefox========= ProfilePath - C:\Users\Mirjam\AppData\Roaming\Mozilla\Firefox\Profiles\rcfluzsp.default prefs.js - "browser.startup.homepage" - "http://www.oursurfing.com/?type=hp&ts=1435828859&z=865c4c192d86fb62e5d7e32g4z0c9w1b1o2bcb7qee&from=amt&uid=SAMSUNGXHN-M500MBB_S2SVJ9ABA08519" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331] "Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10] "Description"=globalUpdate Update "Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4] "Description"=globalUpdate Update "Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64] "Description"= "Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll C:\Users\Mirjam\AppData\Roaming\Mozilla\Firefox\Profiles\rcfluzsp.default\extensions\ searchffv2@gmail.com sweetsearch@gmail.com ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}] ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-04-16 2471744] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}] TrueSuite Website Log On - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-05-05 1746760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}] LuckyTab Class - C:\Program Files (x86)\MiuiTab\SupTab.dll [2015-06-24 544952] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}] TrueSuite Website Log On - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-05-05 1598280] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Aanmeldhulp voor Microsoft-account - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}] Ads Removal - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11 464720] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}] Advanced SystemCare Surfing Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2014-10-17 669984] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-05-10 168216] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-05-10 392472] "Persistence"=C:\Windows\system32\igfxpers.exe [2011-05-10 416024] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-14 2837288] "SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-06-08 1128448] "SetDefault"=C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [2011-06-27 42808] "MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000] "AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-02-03 557768] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper] c:\users\mirjam\appdata\roaming\spotify\data\spotifywebhelper.exe [] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-04-30 284440] ""= [] "HPQuickWebProxy"=C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-06-28 168504] "Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-04-30 40336] "HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056] "HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-03-05 578944] "HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960] "Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2015-02-15 2694320] "IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2015-04-02 5844800] "SmartWeb"=C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17 270368] C:\Users\Mirjam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup SmartWeb.lnk - C:\Users\Mirjam\AppData\Local\SmartWeb\SmartWebHelper.exe StormWatch.lnk - C:\Program Files (x86)\StormWatch\StormWatch.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2011-05-10 385024] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "EnableShellExecuteHooks"=1 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "MSVideo8"=VfWWDM32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 ======List of files/folders created in the last 1 month====== 2015-07-03 21:29:42 ----D---- C:\rsit 2015-07-03 21:29:42 ----D---- C:\Program Files\trend micro 2015-07-03 19:14:10 ----D---- C:\Program Files (x86)\AnyProtectEx 2015-07-03 15:39:47 ----D---- C:\Program Files (x86)\gmsd_nl_005010020 2015-07-03 15:39:43 ----D---- C:\Program Files (x86)\StormWatch 2015-07-02 13:10:03 ----D---- C:\Program Files (x86)\predm 2015-07-02 12:38:45 ----A---- C:\Windows\SYSWOW64\IObitSmartDefragExtension.dll 2015-07-02 12:12:56 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll 2015-07-02 12:12:14 ----A---- C:\Windows\system32\crypt32.dll 2015-07-02 12:12:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll 2015-07-02 12:12:13 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll 2015-07-02 12:12:13 ----A---- C:\Windows\SYSWOW64\cryptnet.dll 2015-07-02 12:12:13 ----A---- C:\Windows\SYSWOW64\crypt32.dll 2015-07-02 12:12:13 ----A---- C:\Windows\system32\wintrust.dll 2015-07-02 12:12:13 ----A---- C:\Windows\system32\cryptsvc.dll 2015-07-02 12:12:13 ----A---- C:\Windows\system32\cryptnet.dll 2015-07-02 12:11:01 ----A---- C:\Windows\SYSWOW64\wups.dll 2015-07-02 12:11:01 ----A---- C:\Windows\SYSWOW64\wudriver.dll 2015-07-02 12:11:01 ----A---- C:\Windows\SYSWOW64\wuapi.dll 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wups2.dll 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wups.dll 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wudriver.dll 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wuaueng.dll 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wuauclt.exe 2015-07-02 12:11:01 ----A---- C:\Windows\system32\wu.upgrade.ps.dll 2015-07-02 12:11:00 ----A---- C:\Windows\SYSWOW64\wuwebv.dll 2015-07-02 12:11:00 ----A---- C:\Windows\SYSWOW64\wuapp.exe 2015-07-02 12:11:00 ----A---- C:\Windows\system32\wuwebv.dll 2015-07-02 12:11:00 ----A---- C:\Windows\system32\wucltux.dll 2015-07-02 12:11:00 ----A---- C:\Windows\system32\wuapp.exe 2015-07-02 12:11:00 ----A---- C:\Windows\system32\wuapi.dll 2015-07-02 12:11:00 ----A---- C:\Windows\system32\WinSetupUI.dll 2015-07-02 11:42:24 ----D---- C:\Windows\SYSWOW64\Flash 2015-07-02 11:42:03 ----D---- C:\Program Files (x86)\globalUpdate 2015-07-02 11:41:41 ----SHD---- C:\Users\Mirjam\AppData\Roaming\AnyProtectEx 2015-07-02 11:40:22 ----D---- C:\Program Files (x86)\Crossbrowse 2015-07-02 11:38:28 ----D---- C:\ProgramData\Service1291 2015-07-02 11:38:27 ----D---- C:\ProgramData\28341ff220e0446c9fff27c4493d622e 2015-07-02 11:33:18 ----SHD---- C:\Config.Msi 2015-07-02 11:24:32 ----D---- C:\Program Files (x86)\CinemaP-1.9cV02.07 2015-07-02 11:24:10 ----D---- C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA 2015-07-02 11:23:15 ----D---- C:\ProgramData\EpicScale 2015-07-02 11:23:02 ----D---- C:\Program Files (x86)\mbot_nl_014010019 2015-07-02 11:22:41 ----D---- C:\ProgramData\IHProtectUpDate 2015-07-02 11:21:55 ----D---- C:\Program Files (x86)\MiuiTab 2015-07-02 11:21:39 ----D---- C:\ProgramData\WindowsMangerProtect 2015-07-02 11:21:33 ----A---- C:\Windows\prleth.sys 2015-07-02 11:21:33 ----A---- C:\Windows\hgfs.sys 2015-06-10 15:33:12 ----A---- C:\Windows\system32\wmp.dll 2015-06-10 15:33:10 ----A---- C:\Windows\SYSWOW64\wmp.dll 2015-06-10 15:33:07 ----A---- C:\Windows\system32\spwmp.dll 2015-06-10 15:33:06 ----A---- C:\Windows\SYSWOW64\spwmp.dll 2015-06-10 15:33:06 ----A---- C:\Windows\SYSWOW64\dxmasf.dll 2015-06-10 15:33:06 ----A---- C:\Windows\system32\dxmasf.dll 2015-06-10 15:33:05 ----A---- C:\Windows\SYSWOW64\wmploc.DLL 2015-06-10 15:33:04 ----A---- C:\Windows\system32\wmploc.DLL 2015-06-10 15:33:00 ----A---- C:\Windows\system32\generaltel.dll 2015-06-10 15:33:00 ----A---- C:\Windows\system32\appraiser.dll 2015-06-10 15:32:59 ----A---- C:\Windows\system32\invagent.dll 2015-06-10 15:32:59 ----A---- C:\Windows\system32\devinv.dll 2015-06-10 15:32:59 ----A---- C:\Windows\system32\aepic.dll 2015-06-10 15:32:59 ----A---- C:\Windows\system32\aeinv.dll 2015-06-10 15:32:58 ----A---- C:\Windows\system32\aepdu.dll 2015-06-10 15:32:58 ----A---- C:\Windows\system32\acmigration.dll 2015-06-10 15:32:49 ----A---- C:\Windows\system32\kerberos.dll 2015-06-10 15:32:49 ----A---- C:\Windows\system32\diagtrack.dll 2015-06-10 15:32:48 ----A---- C:\Windows\SYSWOW64\kerberos.dll 2015-06-10 15:32:48 ----A---- C:\Windows\system32\KernelBase.dll 2015-06-10 15:32:47 ----A---- C:\Windows\system32\lsasrv.dll 2015-06-10 15:32:47 ----A---- C:\Windows\system32\kernel32.dll 2015-06-10 15:32:45 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe 2015-06-10 15:32:45 ----A---- C:\Windows\SYSWOW64\advapi32.dll 2015-06-10 15:32:45 ----A---- C:\Windows\system32\advapi32.dll 2015-06-10 15:32:44 ----A---- C:\Windows\system32\ntoskrnl.exe 2015-06-10 15:32:43 ----A---- C:\Windows\system32\ntdll.dll 2015-06-10 15:32:42 ----A---- C:\Windows\system32\wow64.dll 2015-06-10 15:32:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys 2015-06-10 15:32:42 ----A---- C:\Windows\system32\conhost.exe 2015-06-10 15:32:41 ----A---- C:\Windows\SYSWOW64\tracerpt.exe 2015-06-10 15:32:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe 2015-06-10 15:32:41 ----A---- C:\Windows\system32\winsrv.dll 2015-06-10 15:32:41 ----A---- C:\Windows\system32\tracerpt.exe 2015-06-10 15:32:41 ----A---- C:\Windows\system32\srcore.dll 2015-06-10 15:32:41 ----A---- C:\Windows\system32\rstrui.exe 2015-06-10 15:32:40 ----A---- C:\Windows\SYSWOW64\schannel.dll 2015-06-10 15:32:40 ----A---- C:\Windows\SYSWOW64\ntdll.dll 2015-06-10 15:32:40 ----A---- C:\Windows\SYSWOW64\msv1_0.dll 2015-06-10 15:32:40 ----A---- C:\Windows\system32\schannel.dll 2015-06-10 15:32:40 ----A---- C:\Windows\system32\msv1_0.dll 2015-06-10 15:32:40 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2015-06-10 15:32:39 ----A---- C:\Windows\SYSWOW64\logman.exe 2015-06-10 15:32:39 ----A---- C:\Windows\system32\wdigest.dll 2015-06-10 15:32:39 ----A---- C:\Windows\system32\tdh.dll 2015-06-10 15:32:39 ----A---- C:\Windows\system32\sechost.dll 2015-06-10 15:32:39 ----A---- C:\Windows\system32\ncrypt.dll 2015-06-10 15:32:39 ----A---- C:\Windows\system32\logman.exe 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\wdigest.dll 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\TSpkg.dll 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\tdh.dll 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\setup16.exe 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\sechost.dll 2015-06-10 15:32:38 ----A---- C:\Windows\SYSWOW64\ncrypt.dll 2015-06-10 15:32:38 ----A---- C:\Windows\system32\TSpkg.dll 2015-06-10 15:32:38 ----A---- C:\Windows\system32\sspicli.dll 2015-06-10 15:32:38 ----A---- C:\Windows\system32\smss.exe 2015-06-10 15:32:38 ----A---- C:\Windows\system32\lsass.exe 2015-06-10 15:32:37 ----A---- C:\Windows\SYSWOW64\typeperf.exe 2015-06-10 15:32:37 ----A---- C:\Windows\SYSWOW64\relog.exe 2015-06-10 15:32:37 ----A---- C:\Windows\SYSWOW64\auditpol.exe 2015-06-10 15:32:37 ----A---- C:\Windows\system32\typeperf.exe 2015-06-10 15:32:37 ----A---- C:\Windows\system32\srclient.dll 2015-06-10 15:32:37 ----A---- C:\Windows\system32\relog.exe 2015-06-10 15:32:37 ----A---- C:\Windows\system32\auditpol.exe 2015-06-10 15:32:36 ----A---- C:\Windows\SYSWOW64\srclient.dll 2015-06-10 15:32:36 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll 2015-06-10 15:32:36 ----A---- C:\Windows\SYSWOW64\diskperf.exe 2015-06-10 15:32:36 ----A---- C:\Windows\system32\sspisrv.dll 2015-06-10 15:32:36 ----A---- C:\Windows\system32\ntvdm64.dll 2015-06-10 15:32:36 ----A---- C:\Windows\system32\diskperf.exe 2015-06-10 15:32:36 ----A---- C:\Windows\system32\csrsrv.dll 2015-06-10 15:32:36 ----A---- C:\Windows\system32\credssp.dll 2015-06-10 15:32:35 ----A---- C:\Windows\SYSWOW64\sspicli.dll 2015-06-10 15:32:35 ----A---- C:\Windows\SYSWOW64\secur32.dll 2015-06-10 15:32:35 ----A---- C:\Windows\SYSWOW64\KernelBase.dll 2015-06-10 15:32:35 ----A---- C:\Windows\SYSWOW64\kernel32.dll 2015-06-10 15:32:35 ----A---- C:\Windows\SYSWOW64\credssp.dll 2015-06-10 15:32:35 ----A---- C:\Windows\system32\wow64win.dll 2015-06-10 15:32:35 ----A---- C:\Windows\system32\wow64cpu.dll 2015-06-10 15:32:35 ----A---- C:\Windows\system32\secur32.dll 2015-06-10 15:32:34 ----A---- C:\Windows\SYSWOW64\wow32.dll 2015-06-10 15:32:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:32:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:32:33 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:32:33 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-06-10 15:32:32 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-06-10 15:32:31 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-06-10 15:32:31 ----A---- C:\Windows\SYSWOW64\instnm.exe 2015-06-10 15:32:31 ----A---- C:\Windows\SYSWOW64\apisetschema.dll 2015-06-10 15:32:31 ----A---- C:\Windows\system32\apisetschema.dll 2015-06-10 15:32:30 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-06-10 15:32:30 ----A---- C:\Windows\SYSWOW64\user.exe 2015-06-10 15:32:30 ----A---- C:\Windows\SYSWOW64\adtschema.dll 2015-06-10 15:32:30 ----A---- C:\Windows\system32\adtschema.dll 2015-06-10 15:32:29 ----A---- C:\Windows\SYSWOW64\msobjs.dll 2015-06-10 15:32:29 ----A---- C:\Windows\SYSWOW64\msaudite.dll 2015-06-10 15:32:29 ----A---- C:\Windows\system32\UtcResources.dll 2015-06-10 15:32:29 ----A---- C:\Windows\system32\msobjs.dll 2015-06-10 15:32:29 ----A---- C:\Windows\system32\msaudite.dll 2015-06-10 15:31:42 ----A---- C:\Windows\system32\comctl32.dll 2015-06-10 15:31:41 ----A---- C:\Windows\SYSWOW64\comctl32.dll 2015-06-10 15:31:40 ----A---- C:\Windows\system32\win32k.sys 2015-06-10 15:31:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll 2015-06-10 15:31:27 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll 2015-06-10 15:31:26 ----A---- C:\Windows\SYSWOW64\mshtmled.dll 2015-06-10 15:31:26 ----A---- C:\Windows\system32\ieetwproxystub.dll 2015-06-10 15:31:26 ----A---- C:\Windows\system32\ieetwcollector.exe 2015-06-10 15:31:25 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll 2015-06-10 15:31:24 ----A---- C:\Windows\SYSWOW64\urlmon.dll 2015-06-10 15:31:24 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll 2015-06-10 15:31:24 ----A---- C:\Windows\system32\iernonce.dll 2015-06-10 15:31:24 ----A---- C:\Windows\system32\ie4uinit.exe 2015-06-10 15:31:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll 2015-06-10 15:31:23 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll 2015-06-10 15:31:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll 2015-06-10 15:31:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll 2015-06-10 15:31:22 ----A---- C:\Windows\SYSWOW64\dxtrans.dll 2015-06-10 15:31:22 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-06-10 15:31:19 ----A---- C:\Windows\SYSWOW64\iesetup.dll 2015-06-10 15:31:19 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll 2015-06-10 15:31:19 ----A---- C:\Windows\system32\iedkcs32.dll 2015-06-10 15:31:18 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll 2015-06-10 15:31:18 ----A---- C:\Windows\SYSWOW64\jscript.dll 2015-06-10 15:31:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll 2015-06-10 15:31:18 ----A---- C:\Windows\system32\urlmon.dll 2015-06-10 15:31:18 ----A---- C:\Windows\system32\ieetwcollectorres.dll 2015-06-10 15:31:17 ----A---- C:\Windows\SYSWOW64\jsproxy.dll 2015-06-10 15:31:17 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe 2015-06-10 15:31:17 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe 2015-06-10 15:31:16 ----A---- C:\Windows\SYSWOW64\ieui.dll 2015-06-10 15:31:16 ----A---- C:\Windows\SYSWOW64\ieframe.dll 2015-06-10 15:31:16 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll 2015-06-10 15:31:16 ----A---- C:\Windows\system32\msfeeds.dll 2015-06-10 15:31:16 ----A---- C:\Windows\system32\dxtrans.dll 2015-06-10 15:31:14 ----A---- C:\Windows\system32\iesetup.dll 2015-06-10 15:31:14 ----A---- C:\Windows\system32\ieapfltr.dll 2015-06-10 15:31:12 ----A---- C:\Windows\system32\iertutil.dll 2015-06-10 15:31:11 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll 2015-06-10 15:31:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll 2015-06-10 15:31:11 ----A---- C:\Windows\system32\vbscript.dll 2015-06-10 15:31:10 ----A---- C:\Windows\SYSWOW64\wininet.dll 2015-06-10 15:31:09 ----A---- C:\Windows\SYSWOW64\msrating.dll 2015-06-10 15:31:09 ----A---- C:\Windows\system32\jsproxy.dll 2015-06-10 15:31:09 ----A---- C:\Windows\system32\ieUnatt.exe 2015-06-10 15:31:07 ----A---- C:\Windows\system32\ieui.dll 2015-06-10 15:31:07 ----A---- C:\Windows\system32\dxtmsft.dll 2015-06-10 15:31:06 ----A---- C:\Windows\system32\ieframe.dll 2015-06-10 15:31:05 ----A---- C:\Windows\system32\mshtmled.dll 2015-06-10 15:31:04 ----A---- C:\Windows\system32\mshtmlmedia.dll 2015-06-10 15:31:04 ----A---- C:\Windows\system32\jscript.dll 2015-06-10 15:31:03 ----A---- C:\Windows\system32\jscript9diag.dll 2015-06-10 15:31:03 ----A---- C:\Windows\system32\jscript9.dll 2015-06-10 15:31:02 ----A---- C:\Windows\system32\wininet.dll 2015-06-10 15:31:00 ----A---- C:\Windows\system32\msrating.dll 2015-06-10 15:31:00 ----A---- C:\Windows\system32\MshtmlDac.dll 2015-06-10 15:30:59 ----A---- C:\Windows\system32\mshtml.dll ======List of files/folders modified in the last 1 month====== 2015-07-03 21:29:42 ----RD---- C:\Program Files 2015-07-03 21:29:21 ----D---- C:\Windows\temp 2015-07-03 19:15:08 ----D---- C:\Windows\Tasks 2015-07-03 19:14:10 ----D---- C:\Program Files (x86) 2015-07-03 19:13:35 ----D---- C:\Windows\SysWOW64 2015-07-03 15:38:41 ----D---- C:\Windows\system32\Tasks 2015-07-03 15:20:14 ----D---- C:\Windows\system32\config 2015-07-03 15:11:11 ----A---- C:\Windows\SYSWOW64\log.txt 2015-07-03 11:08:14 ----D---- C:\Windows\System32 2015-07-02 12:35:50 ----D---- C:\Program Files (x86)\IObit 2015-07-02 12:23:07 ----D---- C:\ProgramData 2015-07-02 12:17:20 ----D---- C:\Windows\winsxs 2015-07-02 12:16:12 ----D---- C:\Windows 2015-07-02 12:15:12 ----D---- C:\boot 2015-07-02 12:14:08 ----D---- C:\Windows\SYSWOW64\nl-NL 2015-07-02 12:14:08 ----D---- C:\Windows\system32\nl-NL 2015-07-02 12:14:08 ----D---- C:\Windows\PolicyDefinitions 2015-07-02 12:10:57 ----D---- C:\Windows\system32\catroot2 2015-07-02 12:09:59 ----SHD---- C:\System Volume Information 2015-07-02 12:09:10 ----D---- C:\Windows\inf 2015-07-02 11:51:37 ----D---- C:\Users\Mirjam\AppData\Roaming\uTorrent 2015-07-02 11:42:09 ----SHD---- C:\Windows\Installer 2015-07-02 11:37:26 ----D---- C:\Program Files (x86)\BuyNsave 2015-07-02 11:24:34 ----D---- C:\Windows\system32\drivers\etc 2015-07-02 11:24:32 ----D---- C:\Users\Mirjam\AppData\Roaming\Spotify 2015-07-02 10:55:46 ----D---- C:\ProgramData\ProductData 2015-06-20 21:43:17 ----D---- C:\Windows\Prefetch 2015-06-18 18:52:23 ----A---- C:\Windows\system32\PerfStringBackup.INI 2015-06-17 12:32:41 ----D---- C:\Users\Mirjam\AppData\Roaming\Synthesia 2015-06-17 12:09:04 ----D---- C:\Program Files (x86)\Synthesia 2015-06-16 14:09:00 ----D---- C:\Windows\SoftwareDistribution 2015-06-16 14:00:05 ----D---- C:\Windows\debug 2015-06-14 16:53:00 ----D---- C:\Users\Mirjam\AppData\Roaming\vlc 2015-06-14 11:36:58 ----D---- C:\Program Files (x86)\Windows Media Player 2015-06-14 11:36:57 ----SD---- C:\Windows\system32\CompatTel 2015-06-14 11:36:57 ----D---- C:\Windows\system32\appraiser 2015-06-14 11:36:57 ----D---- C:\Program Files\Windows Media Player 2015-06-14 11:36:56 ----D---- C:\Windows\AppPatch 2015-06-14 11:36:50 ----D---- C:\Windows\system32\drivers 2015-06-14 11:36:47 ----D---- C:\Program Files\Internet Explorer 2015-06-14 11:36:46 ----D---- C:\Windows\SYSWOW64\en-US 2015-06-14 11:36:45 ----D---- C:\Windows\system32\en-US 2015-06-14 11:36:42 ----D---- C:\Program Files (x86)\Internet Explorer 2015-06-13 22:29:14 ----D---- C:\ProgramData\Microsoft Help 2015-06-13 22:26:07 ----D---- C:\Windows\system32\MRT 2015-06-13 22:16:36 ----A---- C:\Windows\system32\MRT.exe ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848] R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888] R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2014-06-04 21184] R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2015-04-16 26528] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568] R3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088] R3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2015-03-25 23048] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-05-10 12228128] R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-05-10 317440] R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2012-12-06 2350176] R3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2015-03-25 34848] R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2014-07-27 339048] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-07-27 565352] R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10305; C:\Windows\system32\DRIVERS\stwrt64.sys [2011-06-08 528384] R3 StillCam;Stuurprogramma voor seriële digitale fotocamera; C:\Windows\system32\drivers\serscan.sys [2009-07-14 12288] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-10-14 396848] R3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2015-03-25 23016] S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232] S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232] S3 catchme;catchme; \??\C:\ComboFix\catchme.sys [] S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456] S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056] S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-06-12 82112] R2 AdvancedSystemCareService8;Advanced SystemCare Service 8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [2014-11-04 815392] R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136] R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232] R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2015-05-19 99128] R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624] R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-04-30 13592] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2014-07-27 2425960] R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\MiuiTab\ProtectService.exe [2015-06-24 125112] R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2015-04-02 878912] R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944] R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816] R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-06-08 301568] R2 StormWatch Update Service;StormWatch Update Service; C:\Program Files (x86)\StormWatch\StormWatchSrv.exe [2015-04-10 586264] R2 SWUpdater;SWUpdaterSvc; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [2014-11-22 17584] R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] R2 vicoqudu;Encyclopaedia Enter; C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\hnswC8AD.tmp [2015-07-02 165376] R2 WikiBrowserUpdateService;WikiBrowserUpdateService; C:\Users\Mirjam\AppData\Local\WikiUpdate.exe [2015-06-30 364032] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480] R2 xyvypiqy;Recharge Advertisement; C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\knsgB1C1.tmp [2015-07-03 141824] R2 zejytose;Typewriter High Resolution; C:\Users\Mirjam\AppData\Roaming\31444335-1435829050-3532-3438-441EA1E49ADA\jnsbB2DA.tmp [2015-07-02 199168] R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760] R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088] S2 FPLService;TrueSuiteService; C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-05-05 263496] S2 globalUpdate1d0b4ab5ae6cdb2;globalUpdate Update Service (globalUpdate1d0b4ab5ae6cdb2); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc [] S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-26 116648] S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2015-04-02 2585408] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496] S3 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808] S3 globalUpdatem1d0b4ab5b0ce3b7;globalUpdate Update Service (globalUpdatem1d0b4ab5b0ce3b7); C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc [] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-26 116648] S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-22 114688] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-16 148080] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-07-27 1255736] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] -----------------EOF-----------------