Logfile of random's system information tool 1.10 (written by random/random) Run by Gebruiker at 2016-07-23 15:08:13 Microsoft Windows 10 Home System drive C: has 208 GB (44%) free of 476 GB Total RAM: 3036 MB (54% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:08:15, on 23-7-2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.10586.0494) Boot mode: Normal Running processes: C:\WINDOWS\system32\sihost.exe C:\WINDOWS\system32\taskhostw.exe C:\WINDOWS\Explorer.EXE C:\Windows\System32\RuntimeBroker.exe C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE C:\Program Files\Adobe\Acrobat DC\Acrobat\acrotray.exe C:\Program Files\Telenet Security Pack\fshoster32.exe C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Common\FSM32.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Program Files\CCleaner\CCleaner.exe C:\Program Files\Nikon\NkView6\NkvMon.exe C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ApplicationFrameHost.exe C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe C:\Program Files\Windows Live\Mail\wlmail.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Users\Gebruiker\Desktop\RSIT.exe C:\Program Files\trend micro\Gebruiker.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {b287e6b2-868b-4ac1-acce-c69eb5fd29d1} - C:\Program Files\InternetSpeedTracker_9t\bar\1.bin\9tSrcAs.dll (file missing) O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (file missing) O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files\Telenet Security Pack\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (file missing) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll O2 - BHO: (no name) - {9e28b297-11d4-4293-aa6f-558658ee66ae} - (no file) O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL O2 - BHO: (no name) - {cc28794a-99d4-4b1b-bccf-b065ce5f9feb} - (no file) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (file missing) O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [F-Secure Hoster (44163)] "C:\Program Files\Telenet Security Pack\fshoster32.exe" -app -hosterid:1 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" O4 - HKCU\..\Run: [OneDrive] "C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: &Webpagina converteren naar Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll/AcroIECapture.html O8 - Extra context menu item: Doel van &koppeling toevoegen aan bestaande PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Doel van koppeling converteren naar Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\Program Files\Microsoft Office\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Webpagina toevoegen aan bestaande PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll/AcroIEAppend.html O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8832b12e-a2f5-478b-9842-f6848d539ba6}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CS1\Services\Tcpip\..\{8832b12e-a2f5-478b-9842-f6848d539ba6}: NameServer = 82.163.143.171 82.163.142.173 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.143.171 82.163.142.173 O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Unknown owner - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (file missing) O23 - Service: F-Secure Dll Hoster (fshoster) - F-Secure Corporation - C:\Program Files\Telenet Security Pack\fshoster32.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Common\FSMA32.EXE O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Telenet Security Pack\apps\CCF_Reputation\fsorsp.exe O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files\Garmin\Device Interaction Service\GarminService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- End of file - 11026 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}] Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45BBE08D-81C5-4A67-AF20-B2A077C67747}] Browsing Protection by F-Secure - C:\Program Files\Telenet Security Pack\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2016-07-18 824288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-07-22 473152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9e28b297-11d4-4293-aa6f-558658ee66ae}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}] Adobe Acrobat Create PDF Helper - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30 141496] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 562904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cc28794a-99d4-4b1b-bccf-b065ce5f9feb}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-22 186944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}] Adobe Acrobat Create PDF from Selection - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30 141496] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [] {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30 141496] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648] "PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2004-03-09 57393] "IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2004-03-09 40960] "IgfxTray"=C:\Windows\system32\igfxtray.exe [] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [] "Persistence"=C:\Windows\system32\igfxpers.exe [] "SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2012-05-29 115032] "Windows Mobile-based device management"=C:\WINDOWS\WindowsMobile\wmdcBase.exe [] "CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2013-04-02 1282632] "AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-01-07 508128] "Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2016-06-30 1867448] ""= [] "F-Secure Hoster (44163)"=C:\Program Files\Telenet Security Pack\fshoster32.exe [2015-08-17 193064] "F-Secure Manager"=C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Common\FSM32.EXE [2015-10-07 306216] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-06-22 598552] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2015-07-13 248176] "OneDrive"=C:\Users\Gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-12 382144] "CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-12-08 6602152] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup NkvMon.exe.lnk - C:\Program Files\Nikon\NkView6\NkvMon.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] wlnotify.dll [] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DSCAutomationHostEnabled"=2 "SoftwareSASGeneration"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midimapper"=midimap.dll "msacm.imaadpcm"=imaadp32.acm "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "msacm.msadpcm"=msadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "vidc.cvid"=iccvid.dll "vidc.i420"=iyuv_32.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "vidc.yvyu"=msyuv.dll "wavemapper"=msacm32.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "msacm.siren"=sirenacm.dll "VIDC.SP54"=SP5X_32.DLL "VIDC.SP55"=SP5X_32.DLL "VIDC.SP56"=SP5X_32.DLL "VIDC.SP57"=SP5X_32.DLL "VIDC.SP58"=SP5X_32.DLL ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2016-07-23 14:56:42 ----D---- C:\rsit 2016-07-23 14:56:42 ----D---- C:\Program Files\trend micro 2016-07-22 15:08:02 ----D---- C:\Program Files\Common Files\Java 2016-07-13 18:37:59 ----A---- C:\WINDOWS\system32\olepro32.dll 2016-07-13 18:37:59 ----A---- C:\WINDOWS\system32\MosHostClient.dll 2016-07-13 18:37:59 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll 2016-07-13 18:37:59 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll 2016-07-13 18:37:59 ----A---- C:\WINDOWS\system32\MapConfiguration.dll 2016-07-13 18:37:58 ----A---- C:\WINDOWS\system32\MosStorage.dll 2016-07-13 18:37:58 ----A---- C:\WINDOWS\system32\moshost.dll 2016-07-13 18:37:58 ----A---- C:\WINDOWS\system32\MapsStore.dll 2016-07-13 18:37:58 ----A---- C:\WINDOWS\system32\MapsCSP.dll 2016-07-13 18:37:58 ----A---- C:\WINDOWS\system32\JpMapControl.dll 2016-07-13 18:37:57 ----A---- C:\WINDOWS\system32\urlmon.dll 2016-07-13 18:37:57 ----A---- C:\WINDOWS\system32\ole32.dll 2016-07-13 18:37:57 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-07-13 18:37:56 ----A---- C:\WINDOWS\system32\wininet.dll 2016-07-13 18:37:56 ----A---- C:\WINDOWS\system32\NMAA.dll 2016-07-13 18:37:56 ----A---- C:\WINDOWS\system32\moshostcore.dll 2016-07-13 18:37:55 ----A---- C:\WINDOWS\system32\MapControlCore.dll 2016-07-13 18:37:55 ----A---- C:\WINDOWS\system32\BingMaps.dll 2016-07-13 18:37:54 ----A---- C:\WINDOWS\system32\iertutil.dll 2016-07-13 18:37:53 ----A---- C:\WINDOWS\system32\WWAHost.exe 2016-07-13 18:37:53 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2016-07-13 18:37:52 ----A---- C:\WINDOWS\system32\mos.dll 2016-07-13 18:37:51 ----A---- C:\WINDOWS\system32\d2d1.dll 2016-07-13 18:37:50 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-07-13 18:37:49 ----A---- C:\WINDOWS\system32\win32kbase.sys 2016-07-13 18:37:49 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys 2016-07-13 18:37:49 ----A---- C:\WINDOWS\system32\cdd.dll 2016-07-13 18:37:48 ----A---- C:\WINDOWS\system32\win32kfull.sys 2016-07-13 18:37:48 ----A---- C:\WINDOWS\system32\drivers\pci.sys 2016-07-13 18:37:48 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys 2016-07-13 18:37:47 ----A---- C:\WINDOWS\system32\ntoskrnl.exe 2016-07-13 18:37:46 ----A---- C:\WINDOWS\system32\sppsvc.exe 2016-07-13 18:37:44 ----A---- C:\WINDOWS\system32\dxgi.dll 2016-07-13 18:37:43 ----A---- C:\WINDOWS\system32\d3d11.dll 2016-07-13 18:37:42 ----A---- C:\WINDOWS\system32\sppobjs.dll 2016-07-13 18:37:42 ----A---- C:\WINDOWS\system32\drivers\cng.sys 2016-07-13 18:37:41 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys 2016-07-13 18:37:40 ----A---- C:\WINDOWS\system32\msftedit.dll 2016-07-13 18:37:40 ----A---- C:\WINDOWS\system32\CertEnroll.dll 2016-07-13 18:37:39 ----A---- C:\WINDOWS\system32\dwmcore.dll 2016-07-13 18:37:38 ----A---- C:\WINDOWS\system32\WpcMon.exe 2016-07-13 18:37:38 ----A---- C:\WINDOWS\system32\crypt32.dll 2016-07-13 18:37:37 ----A---- C:\WINDOWS\system32\Wpc.dll 2016-07-13 18:37:37 ----A---- C:\WINDOWS\system32\dcomp.dll 2016-07-13 18:37:36 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll 2016-07-13 18:37:36 ----A---- C:\WINDOWS\system32\MusNotification.exe 2016-07-13 18:37:35 ----A---- C:\WINDOWS\system32\UIRibbon.dll 2016-07-13 18:37:35 ----A---- C:\WINDOWS\system32\samsrv.dll 2016-07-13 18:37:35 ----A---- C:\WINDOWS\system32\d3d9.dll 2016-07-13 18:37:34 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll 2016-07-13 18:37:34 ----A---- C:\WINDOWS\system32\sppwinob.dll 2016-07-13 18:37:33 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll 2016-07-13 18:37:33 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys 2016-07-13 18:37:32 ----A---- C:\WINDOWS\system32\wmpmde.dll 2016-07-13 18:37:32 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll 2016-07-13 18:37:32 ----A---- C:\WINDOWS\system32\aadtb.dll 2016-07-13 18:37:31 ----A---- C:\WINDOWS\system32\SimCfg.dll 2016-07-13 18:37:31 ----A---- C:\WINDOWS\system32\pnidui.dll 2016-07-13 18:37:31 ----A---- C:\WINDOWS\system32\DWrite.dll 2016-07-13 18:37:30 ----A---- C:\WINDOWS\system32\werconcpl.dll 2016-07-13 18:37:30 ----A---- C:\WINDOWS\system32\GdiPlus.dll 2016-07-13 18:37:30 ----A---- C:\WINDOWS\system32\dui70.dll 2016-07-13 18:37:29 ----A---- C:\WINDOWS\system32\WpcWebSync.dll 2016-07-13 18:37:29 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe 2016-07-13 18:37:28 ----A---- C:\WINDOWS\system32\TokenBroker.dll 2016-07-13 18:37:28 ----A---- C:\WINDOWS\system32\netshell.dll 2016-07-13 18:37:27 ----A---- C:\WINDOWS\system32\wwanconn.dll 2016-07-13 18:37:27 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll 2016-07-13 18:37:27 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll 2016-07-13 18:37:27 ----A---- C:\WINDOWS\system32\ClipUp.exe 2016-07-13 18:37:26 ----A---- C:\WINDOWS\system32\rpcrt4.dll 2016-07-13 18:37:26 ----A---- C:\WINDOWS\system32\qdvd.dll 2016-07-13 18:37:26 ----A---- C:\WINDOWS\system32\eappcfg.dll 2016-07-13 18:37:26 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys 2016-07-13 18:37:25 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2016-07-13 18:37:25 ----A---- C:\WINDOWS\system32\SimAuth.dll 2016-07-13 18:37:25 ----A---- C:\WINDOWS\system32\modernexecserver.dll 2016-07-13 18:37:25 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll 2016-07-13 18:37:24 ----A---- C:\WINDOWS\system32\WindowsCodecsExt.dll 2016-07-13 18:37:24 ----A---- C:\WINDOWS\system32\ProximityCommon.dll 2016-07-13 18:37:24 ----A---- C:\WINDOWS\system32\duser.dll 2016-07-13 18:37:23 ----A---- C:\WINDOWS\system32\StikyNot.exe 2016-07-13 18:37:23 ----A---- C:\WINDOWS\system32\cdpsvc.dll 2016-07-13 18:37:23 ----A---- C:\WINDOWS\system32\audiosrv.dll 2016-07-13 18:37:22 ----A---- C:\WINDOWS\system32\wwanmm.dll 2016-07-13 18:37:22 ----A---- C:\WINDOWS\system32\apprepapi.dll 2016-07-13 18:37:21 ----A---- C:\WINDOWS\system32\wcnwiz.dll 2016-07-13 18:37:21 ----A---- C:\WINDOWS\system32\tzautoupdate.dll 2016-07-13 18:37:21 ----A---- C:\WINDOWS\system32\rasgcw.dll 2016-07-13 18:37:20 ----A---- C:\WINDOWS\system32\WlanMediaManager.dll 2016-07-13 18:37:20 ----A---- C:\WINDOWS\system32\eappprxy.dll 2016-07-13 18:37:20 ----A---- C:\WINDOWS\system32\certcli.dll 2016-07-13 18:37:19 ----A---- C:\WINDOWS\system32\WLanConn.dll 2016-07-13 18:37:19 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2016-07-13 18:37:19 ----A---- C:\WINDOWS\system32\msra.exe 2016-07-13 18:37:18 ----A---- C:\WINDOWS\system32\WmpDui.dll 2016-07-13 18:37:18 ----A---- C:\WINDOWS\system32\eapphost.dll 2016-07-13 18:37:18 ----A---- C:\WINDOWS\system32\eapp3hst.dll 2016-07-13 18:37:18 ----A---- C:\WINDOWS\system32\aadcloudap.dll 2016-07-13 18:37:17 ----A---- C:\WINDOWS\system32\winsrv.dll 2016-07-13 18:37:17 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2016-07-13 18:37:17 ----A---- C:\WINDOWS\system32\GlobCollationHost.dll 2016-07-13 18:37:17 ----A---- C:\WINDOWS\system32\eappgnui.dll 2016-07-13 18:37:17 ----A---- C:\WINDOWS\system32\dot3ui.dll 2016-07-13 18:37:16 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll 2016-07-13 18:37:16 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll 2016-07-13 18:37:16 ----A---- C:\WINDOWS\system32\apprepsync.dll 2016-07-13 18:37:15 ----A---- C:\WINDOWS\system32\cdpreference.exe 2016-07-13 18:37:13 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-07-13 18:37:11 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-07-13 18:37:11 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-07-13 18:37:10 ----A---- C:\WINDOWS\system32\twinui.dll 2016-07-13 18:37:07 ----A---- C:\WINDOWS\system32\wmp.dll 2016-07-13 18:37:06 ----A---- C:\WINDOWS\explorer.exe 2016-07-13 18:37:00 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-07-13 18:37:00 ----A---- C:\WINDOWS\system32\SharedStartModel.dll 2016-07-13 18:37:00 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll 2016-07-13 18:37:00 ----A---- C:\WINDOWS\system32\RDXService.dll 2016-07-13 18:36:58 ----A---- C:\WINDOWS\system32\wuauclt.exe 2016-07-13 18:36:58 ----A---- C:\WINDOWS\system32\windows.storage.dll 2016-07-13 18:36:57 ----A---- C:\WINDOWS\system32\wuaueng.dll 2016-07-13 18:36:56 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2016-07-13 18:36:56 ----A---- C:\WINDOWS\system32\AppCapture.dll 2016-07-13 18:36:55 ----A---- C:\WINDOWS\system32\bcastdvr.exe 2016-07-13 18:36:54 ----A---- C:\WINDOWS\system32\shell32.dll 2016-07-13 18:36:50 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-07-13 18:36:50 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-07-13 18:36:47 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll 2016-07-13 18:36:44 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll 2016-07-13 18:36:43 ----A---- C:\WINDOWS\system32\localspl.dll 2016-07-13 18:36:43 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll 2016-07-13 18:36:42 ----A---- C:\WINDOWS\system32\usocore.dll 2016-07-13 18:36:42 ----A---- C:\WINDOWS\system32\authui.dll 2016-07-13 18:36:41 ----A---- C:\WINDOWS\system32\dosvc.dll 2016-07-13 18:36:40 ----A---- C:\WINDOWS\system32\PlayToManager.dll 2016-07-13 18:36:39 ----A---- C:\WINDOWS\system32\win32spl.dll 2016-07-13 18:36:38 ----A---- C:\WINDOWS\system32\winmde.dll 2016-07-13 18:36:38 ----A---- C:\WINDOWS\system32\propsys.dll 2016-07-13 18:36:37 ----A---- C:\WINDOWS\system32\SpeechPal.dll 2016-07-13 18:36:37 ----A---- C:\WINDOWS\system32\LogonController.dll 2016-07-13 18:36:36 ----A---- C:\WINDOWS\system32\updatehandlers.dll 2016-07-13 18:36:36 ----A---- C:\WINDOWS\system32\twinapi.dll 2016-07-13 18:36:35 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll 2016-07-13 18:36:35 ----A---- C:\WINDOWS\system32\LockAppBroker.dll 2016-07-13 18:36:34 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-07-13 18:36:33 ----A---- C:\WINDOWS\system32\SettingsHandlers_Maps.dll 2016-07-13 18:36:33 ----A---- C:\WINDOWS\system32\gameux.dll 2016-07-13 18:36:33 ----A---- C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 2016-07-13 18:36:32 ----A---- C:\WINDOWS\system32\WSShared.dll 2016-07-13 18:36:32 ----A---- C:\WINDOWS\system32\winipcsecproc.dll 2016-07-13 18:36:32 ----A---- C:\WINDOWS\system32\shutdownux.dll 2016-07-13 18:36:32 ----A---- C:\WINDOWS\system32\SHCore.dll 2016-07-13 18:36:31 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2016-07-13 18:36:31 ----A---- C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2016-07-13 18:36:31 ----A---- C:\WINDOWS\system32\SearchFolder.dll 2016-07-13 18:36:30 ----A---- C:\WINDOWS\system32\WSService.dll 2016-07-13 18:36:30 ----A---- C:\WINDOWS\system32\ntshrui.dll 2016-07-13 18:36:30 ----A---- C:\WINDOWS\system32\ClipSVC.dll 2016-07-13 18:36:30 ----A---- C:\WINDOWS\system32\Clipc.dll 2016-07-13 18:36:29 ----A---- C:\WINDOWS\system32\wiaaut.dll 2016-07-13 18:36:29 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll 2016-07-13 18:36:28 ----A---- C:\WINDOWS\system32\msxml3.dll 2016-07-13 18:36:28 ----A---- C:\WINDOWS\system32\hgcpl.dll 2016-07-13 18:36:28 ----A---- C:\WINDOWS\system32\ApplicationFrame.dll 2016-07-13 18:36:27 ----A---- C:\WINDOWS\system32\WMPhoto.dll 2016-07-13 18:36:27 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2016-07-13 18:36:27 ----A---- C:\WINDOWS\system32\inetpp.dll 2016-07-13 18:36:26 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll 2016-07-13 18:36:26 ----A---- C:\WINDOWS\system32\themecpl.dll 2016-07-13 18:36:25 ----A---- C:\WINDOWS\system32\winipcfile.dll 2016-07-13 18:36:25 ----A---- C:\WINDOWS\system32\sbe.dll 2016-07-13 18:36:25 ----A---- C:\WINDOWS\system32\licensingdiag.exe 2016-07-13 18:36:25 ----A---- C:\WINDOWS\HelpPane.exe 2016-07-13 18:36:24 ----A---- C:\WINDOWS\system32\WSSync.dll 2016-07-13 18:36:24 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2016-07-13 18:36:24 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2016-07-13 18:36:24 ----A---- C:\WINDOWS\system32\ntprint.dll 2016-07-13 18:36:24 ----A---- C:\WINDOWS\system32\IdCtrls.dll 2016-07-13 18:36:23 ----A---- C:\WINDOWS\system32\Windows.Speech.Pal.dll 2016-07-13 18:36:23 ----A---- C:\WINDOWS\system32\oemlicense.dll 2016-07-13 18:36:23 ----A---- C:\WINDOWS\system32\msieftp.dll 2016-07-13 18:36:22 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll 2016-07-13 18:36:21 ----A---- C:\WINDOWS\system32\WSClient.dll 2016-07-13 18:36:21 ----A---- C:\WINDOWS\system32\DevicePairing.dll 2016-07-13 18:36:20 ----A---- C:\WINDOWS\system32\winmsipc.dll 2016-07-13 18:36:20 ----A---- C:\WINDOWS\system32\mspaint.exe 2016-07-13 18:36:20 ----A---- C:\WINDOWS\system32\ieui.dll 2016-07-13 18:36:19 ----A---- C:\WINDOWS\system32\GamePanel.exe 2016-07-13 18:36:18 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-07-13 18:36:17 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-07-13 18:36:13 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-07-13 18:36:12 ----A---- C:\WINDOWS\system32\ieframe.dll 2016-07-13 18:36:10 ----A---- C:\WINDOWS\system32\edgehtml.dll 2016-07-13 18:36:04 ----A---- C:\WINDOWS\system32\mshtml.dll 2016-07-13 18:36:01 ----A---- C:\WINDOWS\system32\vbscript.dll 2016-07-13 18:36:01 ----A---- C:\WINDOWS\system32\Chakra.dll 2016-07-13 18:36:00 ----A---- C:\WINDOWS\system32\jscript9.dll 2016-07-13 18:35:59 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll 2016-07-13 18:35:59 ----A---- C:\WINDOWS\system32\devinv.dll 2016-07-13 18:35:59 ----A---- C:\WINDOWS\system32\appraiser.dll 2016-07-13 18:35:59 ----A---- C:\WINDOWS\system32\acmigration.dll 2016-07-13 18:35:58 ----A---- C:\WINDOWS\system32\mfplat.dll 2016-07-13 18:35:58 ----A---- C:\WINDOWS\system32\invagent.dll 2016-07-13 18:35:58 ----A---- C:\WINDOWS\system32\aeinv.dll 2016-07-13 18:35:57 ----A---- C:\WINDOWS\system32\Windows.Media.dll 2016-07-13 18:35:57 ----A---- C:\WINDOWS\system32\twinui.appcore.dll 2016-07-13 18:35:56 ----A---- C:\WINDOWS\system32\msfeeds.dll 2016-07-13 18:35:56 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys 2016-07-13 18:35:54 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-07-13 18:35:54 ----A---- C:\WINDOWS\system32\provhandlers.dll 2016-07-13 18:35:54 ----A---- C:\WINDOWS\system32\provengine.dll 2016-07-13 18:35:54 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-07-13 18:35:53 ----A---- C:\WINDOWS\system32\mfsvr.dll 2016-07-13 18:35:53 ----A---- C:\WINDOWS\system32\mfnetsrc.dll 2016-07-13 18:35:53 ----A---- C:\WINDOWS\system32\generaltel.dll 2016-07-13 18:35:52 ----A---- C:\WINDOWS\system32\tquery.dll 2016-07-13 18:35:52 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll 2016-07-13 18:35:52 ----A---- C:\WINDOWS\system32\DeviceCensus.exe 2016-07-13 18:35:52 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe 2016-07-13 18:35:51 ----A---- C:\WINDOWS\system32\SettingSync.dll 2016-07-13 18:35:51 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2016-07-13 18:35:51 ----A---- C:\WINDOWS\system32\aepic.dll 2016-07-13 18:35:50 ----A---- C:\WINDOWS\system32\mssrch.dll 2016-07-13 18:35:50 ----A---- C:\WINDOWS\system32\mf.dll 2016-07-13 18:35:50 ----A---- C:\WINDOWS\system32\dbgeng.dll 2016-07-13 18:35:49 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2016-07-13 18:35:48 ----A---- C:\WINDOWS\system32\xpsrchvw.exe 2016-07-13 18:35:48 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll 2016-07-13 18:35:48 ----A---- C:\WINDOWS\system32\Taskmgr.exe 2016-07-13 18:35:48 ----A---- C:\WINDOWS\system32\provops.dll 2016-07-13 18:35:47 ----A---- C:\WINDOWS\system32\ShareHost.dll 2016-07-13 18:35:47 ----A---- C:\WINDOWS\system32\SearchIndexer.exe 2016-07-13 18:35:47 ----A---- C:\WINDOWS\system32\KernelBase.dll 2016-07-13 18:35:46 ----A---- C:\WINDOWS\system32\WindowsCodecsRaw.dll 2016-07-13 18:35:46 ----A---- C:\WINDOWS\system32\reseteng.dll 2016-07-13 18:35:44 ----A---- C:\WINDOWS\system32\wpncore.dll 2016-07-13 18:35:44 ----A---- C:\WINDOWS\system32\DMRServer.dll 2016-07-13 18:35:43 ----A---- C:\WINDOWS\system32\wldp.dll 2016-07-13 18:35:43 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe 2016-07-13 18:35:43 ----A---- C:\WINDOWS\system32\NotificationController.dll 2016-07-13 18:35:42 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll 2016-07-13 18:35:42 ----A---- C:\WINDOWS\system32\TpmTasks.dll 2016-07-13 18:35:42 ----A---- C:\WINDOWS\system32\systemreset.exe 2016-07-13 18:35:42 ----A---- C:\WINDOWS\system32\mfpmp.exe 2016-07-13 18:35:41 ----A---- C:\WINDOWS\system32\workfolderssvc.dll 2016-07-13 18:35:41 ----A---- C:\WINDOWS\system32\mssphtb.dll 2016-07-13 18:35:41 ----A---- C:\WINDOWS\system32\dxtrans.dll 2016-07-13 18:35:40 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll 2016-07-13 18:35:40 ----A---- C:\WINDOWS\system32\webio.dll 2016-07-13 18:35:40 ----A---- C:\WINDOWS\system32\mssph.dll 2016-07-13 18:35:40 ----A---- C:\WINDOWS\system32\ieapfltr.dll 2016-07-13 18:35:39 ----A---- C:\WINDOWS\system32\WebcamUi.dll 2016-07-13 18:35:39 ----A---- C:\WINDOWS\system32\usercpl.dll 2016-07-13 18:35:39 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-07-13 18:35:38 ----A---- C:\WINDOWS\system32\wpdshext.dll 2016-07-13 18:35:38 ----A---- C:\WINDOWS\system32\Windows.Cortana.OneCore.dll 2016-07-13 18:35:38 ----A---- C:\WINDOWS\system32\mbsmsapi.dll 2016-07-13 18:35:38 ----A---- C:\WINDOWS\system32\fhsettingsprovider.dll 2016-07-13 18:35:37 ----A---- C:\WINDOWS\system32\webcheck.dll 2016-07-13 18:35:37 ----A---- C:\WINDOWS\system32\fhengine.dll 2016-07-13 18:35:37 ----A---- C:\WINDOWS\system32\fhcfg.dll 2016-07-13 18:35:36 ----A---- C:\WINDOWS\system32\WPDShServiceObj.dll 2016-07-13 18:35:36 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe 2016-07-13 18:35:36 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2016-07-13 18:35:36 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll 2016-07-13 18:35:35 ----A---- C:\WINDOWS\system32\msscntrs.dll 2016-07-13 18:35:35 ----A---- C:\WINDOWS\system32\IKEEXT.DLL 2016-07-13 18:35:35 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2016-07-13 18:35:31 ----A---- C:\WINDOWS\system32\mstscax.dll 2016-07-13 18:35:31 ----A---- C:\WINDOWS\system32\enterprisecsps.dll 2016-07-13 18:35:30 ----A---- C:\WINDOWS\system32\WMPDMC.exe 2016-07-13 18:35:30 ----A---- C:\WINDOWS\system32\schedsvc.dll 2016-07-13 18:35:30 ----A---- C:\WINDOWS\system32\browserbroker.dll 2016-07-13 18:35:29 ----A---- C:\WINDOWS\system32\wuuhext.dll 2016-07-13 18:35:29 ----A---- C:\WINDOWS\system32\rdpcorets.dll 2016-07-13 18:35:28 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys 2016-07-13 18:35:28 ----A---- C:\WINDOWS\system32\dmcsps.dll 2016-07-13 18:35:27 ----A---- C:\WINDOWS\system32\wmicmiplugin.dll 2016-07-13 18:35:27 ----A---- C:\WINDOWS\system32\taskeng.exe 2016-07-13 18:35:26 ----A---- C:\WINDOWS\system32\winresume.exe 2016-07-13 18:35:26 ----A---- C:\WINDOWS\system32\winload.exe 2016-07-13 18:35:25 ----A---- C:\WINDOWS\system32\Windows.Storage.Search.dll 2016-07-13 18:35:25 ----A---- C:\WINDOWS\system32\schtasks.exe 2016-07-13 18:35:24 ----A---- C:\WINDOWS\system32\rdpudd.dll 2016-07-13 18:35:24 ----A---- C:\WINDOWS\system32\dlnashext.dll 2016-07-13 18:35:23 ----A---- C:\WINDOWS\system32\WUDFPlatform.dll 2016-07-13 18:35:23 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll 2016-07-13 18:35:23 ----A---- C:\WINDOWS\system32\LegacyNetUXHost.exe 2016-07-13 18:35:23 ----A---- C:\WINDOWS\system32\LegacyNetUX.dll 2016-07-08 10:52:18 ----D---- C:\ProgramData\Kaspersky Lab Setup Files 2016-06-24 15:20:13 ----A---- C:\WINDOWS\system32\drivers\fsbts.sys 2016-06-24 15:19:44 ----A---- C:\WINDOWS\prodsett_copy.ini ======List of files/folders modified in the last 1 month====== 2016-07-23 15:07:53 ----D---- C:\WINDOWS\Prefetch 2016-07-23 14:56:42 ----RD---- C:\Program Files 2016-07-23 14:44:10 ----D---- C:\WINDOWS\Temp 2016-07-23 13:45:00 ----D---- C:\WINDOWS\system32\sru 2016-07-23 10:28:34 ----D---- C:\WINDOWS\Microsoft.NET 2016-07-23 10:27:07 ----D---- C:\WINDOWS\debug 2016-07-23 08:37:35 ----D---- C:\WINDOWS\SoftwareDistribution 2016-07-23 08:37:35 ----D---- C:\WINDOWS\INF 2016-07-23 08:37:35 ----D---- C:\Windows 2016-07-23 06:45:20 ----D---- C:\WINDOWS\AppReadiness 2016-07-23 06:45:19 ----HD---- C:\Program Files\WindowsApps 2016-07-22 15:09:20 ----D---- C:\ProgramData\Oracle 2016-07-22 15:09:14 ----SHD---- C:\WINDOWS\Installer 2016-07-22 15:09:07 ----SHD---- C:\Config.Msi 2016-07-22 15:09:02 ----D---- C:\Program Files\Java 2016-07-22 15:08:41 ----D---- C:\WINDOWS\System32 2016-07-22 15:08:02 ----D---- C:\Program Files\Common Files 2016-07-22 15:06:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll 2016-07-21 07:01:14 ----SHD---- C:\System Volume Information 2016-07-20 13:17:59 ----D---- C:\WINDOWS\system32\config 2016-07-17 15:18:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2016-07-16 07:04:21 ----D---- C:\WINDOWS\rescache 2016-07-14 18:03:36 ----D---- C:\WINDOWS\WinSxS 2016-07-14 17:58:51 ----D---- C:\WINDOWS\system32\catroot2 2016-07-14 17:58:43 ----D---- C:\WINDOWS\system32\CatRoot 2016-07-14 17:34:49 ----RD---- C:\WINDOWS\assembly 2016-07-14 17:15:26 ----D---- C:\ProgramData\Microsoft Help 2016-07-14 15:55:02 ----D---- C:\WINDOWS\system32\DriverStore 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\wbem 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\oobe 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\nl-NL 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\migration 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\en-US 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\drivers\nl-NL 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\drivers 2016-07-14 06:26:34 ----D---- C:\WINDOWS\system32\appraiser 2016-07-14 06:26:25 ----RD---- C:\WINDOWS\PrintDialog 2016-07-14 06:26:25 ----RD---- C:\WINDOWS\ImmersiveControlPanel 2016-07-14 06:26:25 ----RD---- C:\WINDOWS\DevicesFlow 2016-07-14 06:26:25 ----D---- C:\WINDOWS\Provisioning 2016-07-14 06:26:25 ----D---- C:\WINDOWS\PolicyDefinitions 2016-07-14 06:26:25 ----D---- C:\WINDOWS\bcastdvr 2016-07-14 06:26:25 ----D---- C:\WINDOWS\apppatch 2016-07-14 06:26:25 ----D---- C:\Program Files\Windows Photo Viewer 2016-07-14 06:26:25 ----D---- C:\Program Files\Windows Mail 2016-07-14 06:26:25 ----D---- C:\Program Files\Windows Journal 2016-07-14 06:26:25 ----D---- C:\Program Files\Windows Defender 2016-07-14 06:26:24 ----D---- C:\WINDOWS\system32\Boot 2016-07-14 06:26:24 ----D---- C:\Program Files\Internet Explorer 2016-07-13 19:21:28 ----D---- C:\WINDOWS\CbsTemp 2016-07-13 18:44:36 ----D---- C:\WINDOWS\system32\MRT 2016-07-13 18:40:37 ----A---- C:\WINDOWS\system32\MRT.exe 2016-07-13 05:11:16 ----D---- C:\WINDOWS\system32\Tasks 2016-07-11 16:41:29 ----RD---- C:\Users 2016-07-08 10:52:18 ----HD---- C:\ProgramData 2016-07-07 02:39:33 ----N---- C:\WINDOWS\system32\MpSigStub.exe 2016-07-03 09:19:15 ----D---- C:\ProgramData\CanonIJPLM 2016-07-02 06:37:58 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe 2016-06-24 15:19:42 ----D---- C:\ProgramData\f-secure 2016-06-24 15:16:23 ----AD---- C:\Program Files\Telenet Security Pack 2016-06-24 15:07:39 ----D---- C:\ProgramData\AVAST Software 2016-06-24 15:07:30 ----AD---- C:\Program Files\Microsoft Silverlight ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 fsbts;fsbts; C:\WINDOWS\system32\Drivers\fsbts.sys [2016-07-06 62160] R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-04-23 76288] R1 F-Secure HIPS;F-Secure HIPS Driver; \??\C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\HIPS\drivers\fshs.sys [2016-07-05 104648] R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 7680] R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 36864] R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 62464] R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [2016-07-05 170184] R3 fsni;fsni; \??\C:\Program Files\Telenet Security Pack\apps\CCF_Scanning\bin\fsni32.sys [2016-07-18 89792] R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd32.sys [2012-03-23 9036288] R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-12-12 130560] R3 rt640x86;@rt640x86.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x86.sys [2015-10-30 494080] S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 88928] S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 83288] S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 51040] S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 51552] S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 27992] S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 8192] S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 26624] S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-12 96768] S3 dg_ssudbus;@oem5.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2016-04-25 108032] S3 fssfltr;fssfltr; C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2012-03-08 39272] S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 17408] S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2015-10-30 22016] S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 38240] S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 66048] S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2015-10-30 61936] S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 23040] S3 RSUSBCCID;@oem37.inf,%USBCCID.DeviceDesc%;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\RtsUCcid.sys [2009-08-10 44032] S3 RSUSBSTOR;@oem65.inf,%RSUSBSTOR.SvcDesc%;RtsUStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUStor.sys [2009-08-19 173056] S3 ssudmdm;@oem4.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2016-04-25 199936] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128] R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-04-05 2021592] R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R2 fshoster;F-Secure Dll Hoster; C:\Program Files\Telenet Security Pack\fshoster32.exe [2015-08-17 193064] R2 FSORSPClient;F-Secure ORSP Client; C:\Program Files\Telenet Security Pack\apps\CCF_Reputation\fsorsp.exe [2016-06-24 60456] R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-05-14 140936] R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-12-12 25088] R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] R2 OneSyncSvc_7368fff;Host synchroniseren_7368fff; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136] R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2015-07-13 93040] R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R3 FSMA;F-Secure Management Agent; C:\Program Files\Telenet Security Pack\apps\ComputerSecurity\Common\FSMA32.EXE [2015-10-07 216104] R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [2015-04-08 708616] S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200] S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_10c5527;Host synchroniseren_10c5527; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_11932de3;Host synchroniseren_11932de3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_11b19e4;Host synchroniseren_11b19e4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_17f9dff4;Host synchroniseren_17f9dff4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1d0f3f5;Host synchroniseren_1d0f3f5; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1d6b7;Host synchroniseren_1d6b7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1e546f6;Host synchroniseren_1e546f6; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_21e49e;Host synchroniseren_21e49e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_26505;Host synchroniseren_26505; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_2655a68;Host synchroniseren_2655a68; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_267d1;Host synchroniseren_267d1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_26a0b;Host synchroniseren_26a0b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_357aae3;Host synchroniseren_357aae3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_3912399;Host synchroniseren_3912399; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_41f5e39;Host synchroniseren_41f5e39; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_54de02;Host synchroniseren_54de02; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_779c93c;Host synchroniseren_779c93c; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09 269504] S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [] S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 26112] S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-29 144200] S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_10c5527;MessagingService_10c5527; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_11932de3;MessagingService_11932de3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_11b19e4;MessagingService_11b19e4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_17f9dff4;MessagingService_17f9dff4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1d0f3f5;MessagingService_1d0f3f5; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1d6b7;MessagingService_1d6b7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1e546f6;MessagingService_1e546f6; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_21e49e;MessagingService_21e49e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_26505;MessagingService_26505; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_2655a68;MessagingService_2655a68; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_267d1;MessagingService_267d1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_26a0b;MessagingService_26a0b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_357aae3;MessagingService_357aae3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_3912399;MessagingService_3912399; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_41f5e39;MessagingService_41f5e39; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_54de02;MessagingService_54de02; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_7368fff;MessagingService_7368fff; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_779c93c;MessagingService_779c93c; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_10c5527;Contact Data_10c5527; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_11932de3;Contact Data_11932de3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_11b19e4;Contact Data_11b19e4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_17f9dff4;Contact Data_17f9dff4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1d0f3f5;Contact Data_1d0f3f5; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1d6b7;Contact Data_1d6b7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1e546f6;Contact Data_1e546f6; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_21e49e;Contact Data_21e49e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_26505;Contact Data_26505; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_2655a68;Contact Data_2655a68; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_267d1;Contact Data_267d1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_26a0b;Contact Data_26a0b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_357aae3;Contact Data_357aae3; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_3912399;Contact Data_3912399; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_41f5e39;Contact Data_41f5e39; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_54de02;Contact Data_54de02; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_7368fff;Contact Data_7368fff; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_779c93c;Contact Data_779c93c; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 900096] S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 256512] S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-10-30 45752] S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] -----------------EOF-----------------