Logfile of random's system information tool 1.10 (written by random/random) Run by gebruiker at 2016-10-17 13:42:30 Microsoft Windows 10 Home System drive C: has 51 GB (69%) free of 74 GB Total RAM: 2040 MB (33% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:42:42, on 17-10-2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.10586.0589) Boot mode: Normal Running processes: C:\WINDOWS\system32\sihost.exe C:\WINDOWS\system32\taskhostw.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\taskhostw.exe C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe C:\Windows\System32\RuntimeBroker.exe C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe C:\WINDOWS\system32\SettingSyncHost.exe C:\Program Files\360\Total Security\safemon\QHSafeTray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Users\gebruiker\AppData\Local\FluxSoftware\Flux\flux.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\gebruiker\Desktop\Downloads\RSIT.exe C:\Program Files\trend micro\gebruiker.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll O4 - HKLM\..\Run: [QHSafeTray] "C:\Program Files\360\Total Security\safemon\360Tray.exe" /start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [f.lux] "C:\Users\gebruiker\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow O4 - HKCU\..\Run: [OneDrive] "C:\Users\gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: 360 Total Security (QHActiveDefense) - QIHU 360 SOFTWARE CO. LIMITED - C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe -- End of file - 4467 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-10-16 473152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-10-16 186944] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "QHSafeTray"=C:\Program Files\360\Total Security\safemon\360Tray.exe [2016-09-28 345000] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-06-22 598552] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "f.lux"=C:\Users\gebruiker\AppData\Local\FluxSoftware\Flux\flux.exe [2013-10-24 1017224] "OneDrive"=C:\Users\gebruiker\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-25 551112] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DSCAutomationHostEnabled"=2 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midimapper"=midimap.dll "msacm.imaadpcm"=imaadp32.acm "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "msacm.msadpcm"=msadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "vidc.cvid"=iccvid.dll "vidc.i420"=iyuv_32.dll "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "vidc.yvyu"=msyuv.dll "wavemapper"=msacm32.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2016-10-17 13:42:30 ----D---- C:\rsit 2016-10-17 13:42:30 ----D---- C:\Program Files\trend micro 2016-10-16 19:47:53 ----SHD---- C:\Config.Msi 2016-10-16 19:47:27 ----D---- C:\Program Files\Common Files\Java 2016-10-16 19:47:20 ----D---- C:\Users\gebruiker\AppData\Roaming\Sun 2016-10-16 19:28:19 ----A---- C:\ipconfig.txt 2016-10-16 19:18:28 ----A---- C:\WINDOWS\system32\ipconfig.txt ======List of files/folders modified in the last 1 month====== 2016-10-17 13:42:30 ----RD---- C:\Program Files 2016-10-17 13:42:25 ----D---- C:\WINDOWS\Prefetch 2016-10-17 13:40:00 ----D---- C:\WINDOWS\Temp 2016-10-17 13:25:00 ----D---- C:\WINDOWS\system32\sru 2016-10-17 13:15:09 ----D---- C:\WINDOWS\Microsoft.NET 2016-10-16 23:15:29 ----SHD---- C:\WINDOWS\Installer 2016-10-16 19:48:40 ----D---- C:\WINDOWS\System32 2016-10-16 19:48:40 ----D---- C:\ProgramData\Oracle 2016-10-16 19:47:27 ----D---- C:\Program Files\Common Files 2016-10-16 19:46:58 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll 2016-10-16 19:46:39 ----D---- C:\Program Files\Java 2016-10-16 18:57:48 ----D---- C:\WINDOWS\system32\NDF 2016-10-16 17:32:58 ----D---- C:\WINDOWS\AppReadiness 2016-10-14 11:28:42 ----HD---- C:\Program Files\WindowsApps 2016-10-13 13:03:27 ----D---- C:\WINDOWS\system32\config 2016-10-12 18:09:07 ----D---- C:\WINDOWS\CbsTemp 2016-10-12 18:09:06 ----D---- C:\WINDOWS\WinSxS 2016-10-12 18:05:49 ----D---- C:\ProgramData\Microsoft Help 2016-10-12 18:03:09 ----AD---- C:\Program Files\Microsoft Silverlight 2016-10-12 18:02:52 ----D---- C:\WINDOWS\system32\MRT 2016-10-12 17:53:52 ----AC---- C:\WINDOWS\system32\MRT.exe 2016-10-12 14:02:16 ----D---- C:\WINDOWS\system32\catroot2 2016-10-03 16:20:18 ----D---- C:\WINDOWS\system32\drivers 2016-10-01 02:23:20 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe 2016-09-28 19:27:00 ----HD---- C:\$WINDOWS.~BT 2016-09-28 19:19:11 ----DC---- C:\WINDOWS\Panther 2016-09-28 17:35:07 ----D---- C:\WINDOWS\Logs 2016-09-26 09:53:50 ----D---- C:\WINDOWS\system32\DriverStore 2016-09-19 17:27:43 ----D---- C:\WINDOWS\rescache 2016-09-19 08:25:16 ----RSHD---- C:\360SANDBOX 2016-09-18 18:19:06 ----D---- C:\WINDOWS\INF 2016-09-18 13:11:20 ----D---- C:\WINDOWS\system32\wbem 2016-09-18 13:11:20 ----D---- C:\WINDOWS\system32\oobe 2016-09-18 13:11:20 ----D---- C:\WINDOWS\system32\nl-NL 2016-09-18 13:11:20 ----D---- C:\WINDOWS\system32\migwiz 2016-09-18 13:11:20 ----D---- C:\WINDOWS\system32\migration 2016-09-18 13:11:19 ----SD---- C:\WINDOWS\system32\F12 2016-09-18 13:11:19 ----D---- C:\WINDOWS\system32\Boot 2016-09-18 13:11:19 ----D---- C:\WINDOWS\system32\AdvancedInstallers 2016-09-18 13:11:11 ----RD---- C:\WINDOWS\PrintDialog 2016-09-18 13:11:11 ----RD---- C:\WINDOWS\ImmersiveControlPanel 2016-09-18 13:11:11 ----RD---- C:\WINDOWS\DevicesFlow 2016-09-18 13:11:11 ----D---- C:\WINDOWS\apppatch 2016-09-18 13:11:11 ----D---- C:\Windows 2016-09-18 13:11:11 ----D---- C:\Program Files\Windows Photo Viewer 2016-09-18 13:11:11 ----D---- C:\Program Files\Windows Media Player 2016-09-18 13:11:11 ----D---- C:\Program Files\Windows Mail 2016-09-18 13:11:10 ----D---- C:\Program Files\Windows Defender 2016-09-18 13:11:10 ----D---- C:\Program Files\Internet Explorer 2016-09-18 11:16:14 ----D---- C:\WINDOWS\system32\appraiser 2016-09-18 11:15:45 ----D---- C:\WINDOWS\ShellNew ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 HookPort;HookPort; C:\WINDOWS\System32\Drivers\Hookport.sys [2016-08-08 78208] R1 360AntiHacker;360Safe Anti Hacker Service; C:\WINDOWS\System32\Drivers\360AntiHacker.sys [2016-08-08 144384] R1 360Box;360Box mini-filter driver; C:\WINDOWS\system32\DRIVERS\360Box.sys [2016-09-28 221696] R1 360SelfProtection;360SelfProtection; C:\WINDOWS\system32\drivers\360SelfProtection.sys [2016-08-08 195712] R1 BAPIDRV;BAPIDRV; C:\WINDOWS\system32\DRIVERS\BAPIDRV.sys [2016-09-09 195584] R1 EfiMon;EfiSystemMon; C:\WINDOWS\System32\Drivers\Efimon.sys [2015-12-11 23248] R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-04-23 76288] R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 7680] R1 qutmdserv;Quantum DeepScanner Servers; C:\WINDOWS\system32\DRIVERS\qutmdrv.sys [2016-08-08 322688] R1 qutmipc;qutmipc; \??\C:\WINDOWS\system32\drivers\qutmipc.sys [2016-08-08 74496] R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 36864] R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 62464] R3 360AvFlt;360AvFlt mini-filter driver; C:\WINDOWS\system32\DRIVERS\360AvFlt.sys [2016-09-28 83456] R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd32.sys [2012-03-23 4815872] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHDA.sys [2015-06-24 3529472] R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-12-25 130560] R3 rt640x86;@rt640x86.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x86.sys [2015-10-30 494080] S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 88928] S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 83288] S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 51040] S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 51552] S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 27992] S3 360Camera;360Safe Camera Filter Service; C:\WINDOWS\System32\Drivers\360Camera.sys [2016-08-08 52224] S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 8192] S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 26624] S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-25 96768] S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 17408] S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2015-10-30 22016] S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 38240] S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 66048] S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2015-10-30 61936] S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 23040] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-12-25 25088] R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] R2 OneSyncSvc_4f767d8a;Host synchroniseren_4f767d8a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R2 QHActiveDefense;360 Total Security; C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe [2016-09-28 926632] R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] R3 PimIndexMaintenanceSvc_4f767d8a;Contact Data_4f767d8a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-10-30 135848] S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_120daa9;Host synchroniseren_120daa9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_13d1a63;Host synchroniseren_13d1a63; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1776eb;Host synchroniseren_1776eb; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1a47f7;Host synchroniseren_1a47f7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_1bc5529;Host synchroniseren_1bc5529; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_20a16a;Host synchroniseren_20a16a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_2958b;Host synchroniseren_2958b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_29be0a8;Host synchroniseren_29be0a8; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_2cc0d;Host synchroniseren_2cc0d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_2e1f4;Host synchroniseren_2e1f4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_311181;Host synchroniseren_311181; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_3212b4;Host synchroniseren_3212b4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_45415f;Host synchroniseren_45415f; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_49ef6e;Host synchroniseren_49ef6e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_4a71022;Host synchroniseren_4a71022; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_4b187b;Host synchroniseren_4b187b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_51f42a;Host synchroniseren_51f42a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_61aca9;Host synchroniseren_61aca9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_712627;Host synchroniseren_712627; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_7a5d30d;Host synchroniseren_7a5d30d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S2 OneSyncSvc_7c8d96;Host synchroniseren_7c8d96; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15 268976] S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 26112] S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696] S3 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-09-16 153752] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-09-16 153752] S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_120daa9;MessagingService_120daa9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_13d1a63;MessagingService_13d1a63; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1776eb;MessagingService_1776eb; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1a47f7;MessagingService_1a47f7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_1bc5529;MessagingService_1bc5529; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_20a16a;MessagingService_20a16a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_2958b;MessagingService_2958b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_29be0a8;MessagingService_29be0a8; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_2cc0d;MessagingService_2cc0d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_2e1f4;MessagingService_2e1f4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_311181;MessagingService_311181; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_3212b4;MessagingService_3212b4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_45415f;MessagingService_45415f; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_49ef6e;MessagingService_49ef6e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_4a71022;MessagingService_4a71022; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_4b187b;MessagingService_4b187b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_4f767d8a;MessagingService_4f767d8a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_51f42a;MessagingService_51f42a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_61aca9;MessagingService_61aca9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_712627;MessagingService_712627; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_7a5d30d;MessagingService_7a5d30d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 MessagingService_7c8d96;MessagingService_7c8d96; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040] S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_120daa9;Contact Data_120daa9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_13d1a63;Contact Data_13d1a63; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1776eb;Contact Data_1776eb; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1a47f7;Contact Data_1a47f7; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_1bc5529;Contact Data_1bc5529; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_20a16a;Contact Data_20a16a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_2958b;Contact Data_2958b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_29be0a8;Contact Data_29be0a8; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_2cc0d;Contact Data_2cc0d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_2e1f4;Contact Data_2e1f4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_311181;Contact Data_311181; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_3212b4;Contact Data_3212b4; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_45415f;Contact Data_45415f; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_49ef6e;Contact Data_49ef6e; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_4a71022;Contact Data_4a71022; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_4b187b;Contact Data_4b187b; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_51f42a;Contact Data_51f42a; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_61aca9;Contact Data_61aca9; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_712627;Contact Data_712627; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_7a5d30d;Contact Data_7a5d30d; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 PimIndexMaintenanceSvc_7c8d96;Contact Data_7c8d96; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 37256] S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2016-09-07 900096] S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-10-30 45752] S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 37256] -----------------EOF-----------------