Ga naar inhoud

romijo

Lid
  • Items

    584
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door romijo

  1. [ATTACH]37569[/ATTACH] - - - Updated - - - sorry ik had eerder niet goed gekeken dank voor uw hulp vr.gr. Romijo logje18nov.txt
  2. sorry lukt niet om in te pakken wegens wel/niet internet # AdwCleaner v4.101 - Rapport aangemaakt 17/11/2014 op 19:11:43 # Laatste Update 09/11/2014 door Xplode # Database : 2014-11-16.1 [Live] # Besturingssysteem : Windows 8.1 (64 bits) # Gebruikersnaam : M. Robbescheuten - ROBBESCHEUTEN # Gestart vanuit : C:\Users\M. Robbescheuten\Desktop\adwcleaner_4.101.exe # Optie : Verwijderen ***** [ Services ] ***** ***** [ Bestanden / Mappen ] ***** Map Verwijderd : C:\Users\M. Robbescheuten\AppData\Local\CheckCode Map Verwijderd : C:\Users\M. Robbescheuten\AppData\LocalLow\sitefinder Bestand Verwijderd : C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk ***** [ Taken ] ***** Taak Verwijderd : LaunchSignup ***** [ Snelkoppelingen ] ***** ***** [ Register ] ***** Sleutel Verwijderd : HKLM\SOFTWARE\Classes\jZip.file Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPath\jZip.exe Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73} Sleutel Verwijderd : HKCU\Software\jZip Sleutel Verwijderd : HKLM\SOFTWARE\jZip Sleutel Verwijderd : HKLM\SOFTWARE\Upt Sleutel Verwijderd : HKLM\SOFTWARE\WinUpd Sleutel Verwijderd : HKLM\SOFTWARE\SI-App Sleutel Verwijderd : HKLM\SOFTWARE\RST Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZip Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Upt Sleutel Verwijderd : [x64] HKLM\SOFTWARE\WinUpd Sleutel Verwijderd : [x64] HKLM\SOFTWARE\SI-App Sleutel Verwijderd : [x64] HKLM\SOFTWARE\RST Gegevens Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - Robbescheuten\AppData\Local\Smartbar\Application\Resources\crdlil64.dll Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\acoustica-cd-dvd-label-maker.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ccleaner.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cdcovercreator.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dvd-shrink.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\infrarecorder.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystart.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\omiga-plus.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\samsung-kies.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\spider-player.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweetfunnycool.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweetfunnycoool.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\windows-essentials-2012.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\windows-live-mail.nl.softonic.com Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\MyStart Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\SWEETFUNNYCOOOL Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\SWEETFUNNYCOOOL ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [19368 octets] - [17/09/2014 21:14:51] AdwCleaner[R1].txt - [8083 octets] - [17/09/2014 21:22:44] AdwCleaner[R2].txt - [5410 octets] - [17/09/2014 21:24:16] AdwCleaner[R3].txt - [4321 octets] - [17/11/2014 19:10:45] AdwCleaner[s0].txt - [16510 octets] - [17/09/2014 21:17:14] AdwCleaner[s1].txt - [6862 octets] - [17/09/2014 21:26:03] AdwCleaner[s2].txt - [4254 octets] - [17/11/2014 19:11:43] ########## EOF - C:\AdwCleaner\AdwCleaner[s2].txt - [4314 octets] ##########
  3. bijna geen internet zo nu en dan even hoop dat 't lukt 't is echt hopeloos - - - Updated - - - lukt niet zal hem nog eens even opnieuw opstarten
  4. hoi ik hoef niet tot morgen te wachten het is wel wat beter als voorheen maar nog steeds af en toe wat langere tijd nodig om een website te zoeken en de filmpjes b.v. op YouTube onderbreken opnieuw door te trage verbinding de tablets doen het nu wel vr.gr. Romijo
  5. dank je juisterr, het lijkt te hebben gewerkt, maar even afwachten nog ik laat hem tot morgenavond even lopen dan laat ik hier berichtje achter
  6. Het gaat zeer slecht alles geeft aan dat 't correct zou moeten werken maar dan is het er weer even en dan weer niet, erg lastig
  7. Zoek.exe v5.0.0.0 Updated 15-November-2014 Tool run by M. Robbescheuten on za 15-11-2014 at 20:56:22,50. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\M. Robbescheuten\Desktop\zoek.exe [scan all users] [script inserted] ==== Older Logs ====================== C:\zoek-results2014-09-18-205113.log 53137 bytes C:\zoek-results2014-09-19-082834.log 63579 bytes C:\zoek-results2014-09-19-201405.log 48318 bytes C:\zoek-results2014-09-20-192658.log 36064 bytes C:\zoek-results2014-11-15-182216.log 877 bytes ==== Empty Folders Check ====================== C:\PROGRA~2\Imagenomic C:\PROGRA~2\Nend Software C:\PROGRA~3\CanonEPP C:\PROGRA~3\CanonIJEPPEX2 C:\Users\M. Robbescheuten\AppData\Local\CheckCode C:\Users\M. Robbescheuten\AppData\Local\MediaShow C:\Users\M815E~1.ROB\AppData\Local\CheckCode C:\Users\M815E~1.ROB\AppData\Local\MediaShow ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wajam Internet Enhancer Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsMangerProtect deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IePluginServices deleted successfully ==== Deleting Files \ Folders ====================== C:\Users\M. Robbescheuten\AppData\Local\FolderImportPrivacy deleted C:\WINDOWS\Syswow64\SDKTaskWin32 deleted C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\jZip.lnk deleted C:\Users\M. Robbescheuten\AppData\Roaming\MAGIX deleted C:\PROGRA~3\MAGIX deleted C:\PROGRA~3\Package Cache deleted C:\Users\M. Robbescheuten\AppData\Local\jZip deleted C:\Users\M. Robbescheuten\AppData\Local\CrashRpt deleted C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\ICSharpCode.net deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X6 deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X7 deleted C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jZip.lnk deleted C:\windows\SysNative\Tasks\LaunchSignup deleted C:\Users\M. Robbescheuten\Documents\Add-in Express deleted "C:\PROGRA~2\jZip\jZipShell.dll" deleted "C:\PROGRA~2\jZip" not deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\M815E~1.ROB\AppData\Local\Temp ==== 2014-11-10 21:27:14 271355AF84F8C3921C3736490D655C7A 149606400 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\sketchup_install\SketchUp2015-x64.msi 2014-11-10 21:27:14 271355AF84F8C3921C3736490D655C7A 149606400 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\sketchup_install\SketchUp2015-x64.msi 2014-11-10 21:27:14 23E447B572442516319D09F292EE300B 703816 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\sketchup_install\setup.exe 2014-11-10 21:27:14 23E447B572442516319D09F292EE300B 703816 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\sketchup_install\setup.exe 2014-11-09 20:33:22 E3A25C80E2375B2D42C3D4729769BDF3 10240 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\SDIAG_c54c6df1-8160-41fc-8b9a-bdef19e29a0d\NetworkDiagnosticSnapIn.dll 2014-11-09 20:33:22 E3A25C80E2375B2D42C3D4729769BDF3 10240 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\SDIAG_c54c6df1-8160-41fc-8b9a-bdef19e29a0d\NetworkDiagnosticSnapIn.dll ====== Java Cache ===== 2014-11-11 21:17:17 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-7c2bebf9 2014-11-11 21:17:11 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-643d9ad4 2014-11-11 21:17:11 40222AF0EEB5E27B4390394D74135CC5 424 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2014-11-11 21:17:11 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-3a8eae16 2014-11-13 23:02:41 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\48820925-7d5fbc4d 2014-11-11 21:17:12 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-60c8c1fb 2014-11-13 23:03:25 8C7A7AAF771522D7925D73F13C5767C3 64366 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\7e60542d-3b815cdb-temp 2014-11-13 23:03:24 67911F367EC150BDC8F2CB46397F0925 845 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-364c9a5c 2014-11-13 23:03:24 1A338EC33B756B2F65A17D06A1911B8D 37 ----a-w- C:\Users\M. Robbescheuten\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-e2e4c8970372d2fb4193a7ef29d16f6c3f08527947fcb9208b3a0e48820369fd-6.0.lap 2014-11-11 21:17:17 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-7c2bebf9 2014-11-11 21:17:11 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-643d9ad4 2014-11-11 21:17:11 40222AF0EEB5E27B4390394D74135CC5 424 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2014-11-11 21:17:11 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-3a8eae16 2014-11-13 23:02:41 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\48820925-7d5fbc4d 2014-11-11 21:17:12 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-60c8c1fb 2014-11-13 23:03:25 8C7A7AAF771522D7925D73F13C5767C3 64366 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\7e60542d-3b815cdb-temp 2014-11-13 23:03:24 67911F367EC150BDC8F2CB46397F0925 845 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-364c9a5c 2014-11-13 23:03:24 1A338EC33B756B2F65A17D06A1911B8D 37 ----a-w- C:\Users\M815E~1.ROB\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\2bbaaf87-e2e4c8970372d2fb4193a7ef29d16f6c3f08527947fcb9208b3a0e48820369fd-6.0.lap ====== C:\WINDOWS\SysWOW64 ===== 2014-11-12 23:22:02 07330241FD9D9A03811DDBDC4F9FD18F 19781632 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-11-12 23:21:32 154532E0EC2317E6924A9D27F894FF2F 12819456 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2014-11-12 23:21:26 3CA90FDAB95FB2B0D91249BEDE3DE0D9 4298240 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2014-11-12 23:21:25 03D7DF4711B851EF286562F97429211D 1892864 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2014-11-12 23:21:24 F169B03C4B9996708DB20FF0C875B4FF 880128 ----a-w- C:\WINDOWS\SysWOW64\inetcomm.dll 2014-11-12 23:21:24 98D83B6B4FBA32C39585D1E07121BEA0 2277376 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2014-11-12 23:21:24 8A88AD059EDC1014D5D6A472A6D1D66C 661504 ----a-w- C:\WINDOWS\SysWOW64\jscript.dll 2014-11-12 23:21:24 027A2CF002AD94399B51C07E855E3B2B 1310208 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2014-11-12 23:21:23 EF7A48E5955736BEECF0B0ABB478E90E 478208 ----a-w- C:\WINDOWS\SysWOW64\ieui.dll 2014-11-12 23:21:23 E855B15E1BE0B58F84843D31F4CC4795 501248 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2014-11-12 23:21:23 A6145F4F8C69C3B46653B1C5E75A7BD6 688640 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-11-12 23:21:23 8FC2FB51EB90E6AA582BDBA39C1935FD 620032 ----a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-11-12 23:21:23 7BCC24D058205664BD700D272B169AEC 418304 ----a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-11-12 23:21:23 7B0D22C64F9B6A8CD79EFADD29700693 285696 ----a-w- C:\WINDOWS\SysWOW64\dxtrans.dll 2014-11-12 23:21:23 1BE74145FDF58734CFE968063533FBEC 708096 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-11-12 23:21:23 108D84EE2359C595CCEA32820A2D5405 2051072 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-11-12 23:21:22 FCAF49AE2E10EF3823262D10E7F2D0DE 60416 ----a-w- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 23:21:22 FC51834D5057B9D7847666AE88BC981C 130048 ----a-w- C:\WINDOWS\SysWOW64\occache.dll 2014-11-12 23:21:22 F1313045CDCBBC4C90C34AEF67CEE088 112128 ----a-w- C:\WINDOWS\SysWOW64\IEAdvpack.dll 2014-11-12 23:21:22 ED5A4451A1A2777C6C5DB4238FD09078 115712 ----a-w- C:\WINDOWS\SysWOW64\ieUnatt.exe 2014-11-12 23:21:22 DCFF6E5356CFF5B50BBA0FAAE01A0412 90624 ----a-w- C:\WINDOWS\SysWOW64\iesysprep.dll 2014-11-12 23:21:22 BE5EDCACB9E83C3695F650094367740C 99328 ----a-w- C:\WINDOWS\SysWOW64\hlink.dll 2014-11-12 23:21:22 9F6204775EB03156B430FD095E3D0B5C 325632 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-11-12 23:21:22 971D57DFB6F3FBC98EB74D1AF8E3C13B 76288 ----a-w- C:\WINDOWS\SysWOW64\mshtmled.dll 2014-11-12 23:21:22 8DFBD587DBEBBC8EB50AD169DE88C449 340992 ----a-w- C:\WINDOWS\SysWOW64\html.iec 2014-11-12 23:21:22 8D1E12756ED6F1FDB026AD3CF264F90C 40448 ----a-w- C:\WINDOWS\SysWOW64\imgutil.dll 2014-11-12 23:21:22 8A109878FA68DD1A4C91D8D499797E22 128000 ----a-w- C:\WINDOWS\SysWOW64\iepeers.dll 2014-11-12 23:21:22 615D259116D1B331911CE28C8CD1CCF3 73216 ----a-w- C:\WINDOWS\SysWOW64\tdc.ocx 2014-11-12 23:21:22 45CDC0E37774D30BEE8C5F62CE30D599 1042944 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2014-11-12 23:21:22 236AD481F1632F4CE7E9835FFD4AF41D 168960 ----a-w- C:\WINDOWS\SysWOW64\msrating.dll 2014-11-12 23:21:22 1D391C687102569FD1EA154F0C1A4CE8 91136 ----a-w- C:\WINDOWS\SysWOW64\inseng.dll 2014-11-12 23:21:22 159199095C9959BE75E61C0FF947708F 152064 ----a-w- C:\WINDOWS\SysWOW64\iexpress.exe 2014-11-12 23:21:22 151E64E5D34DFB95D57B5B97C50DE64D 230400 ----a-w- C:\WINDOWS\SysWOW64\webcheck.dll 2014-11-12 23:21:22 0FEEFF4B96CA5972121F59525142A14E 52736 ----a-w- C:\WINDOWS\SysWOW64\msfeedsbs.dll 2014-11-12 23:21:22 02FF387F6228169EDDCB41F5E4B1A4E4 47104 ----a-w- C:\WINDOWS\SysWOW64\jsproxy.dll 2014-11-12 23:21:21 EF7B7299A1D6604AD3CA2CE1BEF8C8F3 30720 ----a-w- C:\WINDOWS\SysWOW64\iernonce.dll 2014-11-12 23:21:21 A66A88FFE53BBB9DDAACE0110A8232EC 137728 ----a-w- C:\WINDOWS\SysWOW64\wextract.exe 2014-11-12 23:21:21 59607FB7C6B84860CE2D1C5F7C57E052 47616 ----a-w- C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-11-12 23:21:21 53E15B8DBD615567CA8895D65746C8D3 64000 ----a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2014-11-12 23:21:21 3C544C566EE7091AC52D4D9156C62687 235520 ----a-w- C:\WINDOWS\SysWOW64\url.dll 2014-11-12 23:21:21 316280CC22CBB15271A91D83CDFB73C3 27136 ----a-w- C:\WINDOWS\SysWOW64\licmgr10.dll 2014-11-12 23:21:21 26F4BDB6EA83011885E217A51A4A3E68 62464 ----a-w- C:\WINDOWS\SysWOW64\iesetup.dll 2014-11-12 23:21:21 0812A503FF349D1DCEEB820B2E4FEE15 57344 ----a-w- C:\WINDOWS\SysWOW64\pngfilt.dll 2014-11-12 23:21:20 3FA76B67F25D84B3C2A4E8A8C0919E6E 12800 ----a-w- C:\WINDOWS\SysWOW64\mshta.exe 2014-11-12 23:21:20 1BD4CD20A25B4A3A5F7BAAC25E9D9202 11264 ----a-w- C:\WINDOWS\SysWOW64\msfeedssync.exe 2014-11-12 22:53:48 5F333FDBF392850373C89BDA31EBEC1B 1346048 ----a-w- C:\WINDOWS\SysWOW64\user32.dll 2014-11-12 22:53:48 3B45EA6108E48406828D4E015FF41DD0 12800 ----a-w- C:\WINDOWS\SysWOW64\winshfhc.dll 2014-11-12 22:53:11 B09332CC976AC43EFF595B6F01AA275C 2459136 ----a-w- C:\WINDOWS\SysWOW64\authui.dll 2014-11-12 22:53:11 46FBD043A1688EFD6AC1395EE886AD33 3607040 ----a-w- C:\WINDOWS\SysWOW64\msi.dll 2014-11-12 22:53:10 48C20EB77757F22840FF4CED98D8DEB1 325120 ----a-w- C:\WINDOWS\SysWOW64\msihnd.dll 2014-11-12 22:52:39 BC426A818B7F3DB5F509BC1B62FF1501 357376 ----a-w- C:\WINDOWS\SysWOW64\schannel.dll 2014-11-12 22:52:39 B2AC9E081A847ACBD5B62BE25AF39DA1 88800 ----a-w- C:\WINDOWS\SysWOW64\ncryptsslp.dll 2014-11-12 22:51:32 DDAAC7C966436938526D4CF4C6042A5C 154112 ----a-w- C:\WINDOWS\SysWOW64\msaudite.dll 2014-11-12 22:51:32 A22688490DCC2DA19441CA09EF7299BF 736768 ----a-w- C:\WINDOWS\SysWOW64\adtschema.dll 2014-11-12 22:51:32 791BDC9FD3C95F92C7DB2162132C8645 324096 ----a-w- C:\WINDOWS\SysWOW64\certcli.dll 2014-11-12 22:46:47 CA23E168518460519DC8D49EC6AD9550 18723112 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2014-11-12 22:46:45 1FB4389CA807D59B105B0827FCC8F768 11820544 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2014-11-12 22:46:44 0EEE3F2278E447498B2CDBDF34C63C91 670384 ----a-w- C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2014-11-12 22:46:43 1793FC07D568C930C04F9FF40FFF9A69 799744 ----a-w- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-11-12 22:46:41 C1AD30D5E28B4291D4A16BC6944ABC0C 2030592 ----a-w- C:\WINDOWS\SysWOW64\WsmSvc.dll 2014-11-12 22:46:41 A208DEE0CD61E24817C26D5A05503DA7 334336 ----a-w- C:\WINDOWS\SysWOW64\puiobj.dll 2014-11-12 22:46:40 46C1902654FF54C835E4C4E8C14B7F2A 239104 ----a-w- C:\WINDOWS\SysWOW64\FXSAPI.dll 2014-11-12 22:46:40 17FC09725FEE2546B96A938288509719 485376 ----a-w- C:\WINDOWS\SysWOW64\untfs.dll 2014-11-12 22:20:12 FACBA112943A89FBB8AC25085521924F 344536 ----a-w- C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2014-11-12 22:20:12 22B2920A0857BDD61B1331C30AD76F30 424544 ----a-w- C:\WINDOWS\SysWOW64\AudioEng.dll 2014-11-12 22:20:12 0CBA301F325F922FAFB3B83AD3337BB2 370424 ----a-w- C:\WINDOWS\SysWOW64\AudioSes.dll 2014-11-12 18:14:07 F344D6066EA270AABABA83E2A6B6428F 723968 ----a-w- C:\WINDOWS\SysWOW64\wuapi.dll 2014-11-12 18:14:07 DC523277A7EC2336A654960E08EB5BDC 81920 ----a-w- C:\WINDOWS\SysWOW64\wudriver.dll 2014-11-12 18:14:07 C17F3F1EE09758CF9D234B22B80A1006 25600 ----a-w- C:\WINDOWS\SysWOW64\wups.dll 2014-11-12 18:14:07 529122F3ADC548F0CCBB6164D86FA116 124928 ----a-w- C:\WINDOWS\SysWOW64\wuwebv.dll 2014-11-12 18:14:07 514AEA6CF4B70FAA30A2BC4B4CC10A39 29696 ----a-w- C:\WINDOWS\SysWOW64\wuapp.exe 2014-11-12 18:10:32 75D0FAD0165770819770628239BF57DB 602768 ----a-w- C:\WINDOWS\SysWOW64\oleaut32.dll 2014-11-12 18:04:26 3BF6BEBD0A5666BDB426A734A4578D9B 1346048 ----a-w- C:\WINDOWS\SysWOW64\msxml3.dll 2014-11-12 18:04:03 D1A07DE4DC408E5AA5CFBAE261919BDC 72192 ----a-w- C:\WINDOWS\SysWOW64\packager.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-11-12 23:22:02 6432F143CDC9D73BD2BF832CAB2EDC01 25110016 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-11-12 23:21:36 BED4D30B7FF094E368333CE2D1CE3195 14390272 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2014-11-12 23:21:28 079FEE6FC11A74E4309B6A10931C1CB2 6040064 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2014-11-12 23:21:25 BF1FC65A307B31939ADF7F976FDE033C 2365440 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2014-11-12 23:21:25 559E084EEBE44864493B2903433F19B3 1550336 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2014-11-12 23:21:24 DE58DE2C6C8439B7174D6D3568AA4A80 814080 ----a-w- C:\WINDOWS\Sysnative\jscript9diag.dll 2014-11-12 23:21:24 62D54F4673A6208C8CC147758122B3C3 2865152 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2014-11-12 23:21:24 46B5DD7C4B1851F59E48302185E076DF 1032704 ----a-w- C:\WINDOWS\Sysnative\inetcomm.dll 2014-11-12 23:21:24 22CBDB8810CBED0B4F5E4BE69D7E2AE8 2884096 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2014-11-12 23:21:23 F7522B00C823794F86ABD5BE1F3D6B09 316928 ----a-w- C:\WINDOWS\Sysnative\dxtrans.dll 2014-11-12 23:21:23 BC3B7CCE855F9A8E7BC96F7062229A02 799232 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2014-11-12 23:21:23 62E2FCF45F349DE6CAFB3AA7E1D81DA4 2124288 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2014-11-12 23:21:23 587DEBB59F5F14C9610966FB14A33607 633856 ----a-w- C:\WINDOWS\Sysnative\ieui.dll 2014-11-12 23:21:23 258C3082AD82C1AAD335DA3FE2D3EB25 580096 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2014-11-12 23:21:23 200CEA827BDC503F00C0AED0EA227D49 800768 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2014-11-12 23:21:23 175C139D51F99099D1BDA17794B02191 490496 ----a-w- C:\WINDOWS\Sysnative\dxtmsft.dll 2014-11-12 23:21:23 0D03DAD6BB183156C70F863D0F2FA55A 812544 ----a-w- C:\WINDOWS\Sysnative\jscript.dll 2014-11-12 23:21:22 FD7C8FAC461BED1FEEB808E477D884D4 716800 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2014-11-12 23:21:22 F79E5258AF040A8AD83C7C1273A071C3 54784 ----a-w- C:\WINDOWS\Sysnative\jsproxy.dll 2014-11-12 23:21:22 F0A53129AE95A895EC8C4DC36E1797A2 108544 ----a-w- C:\WINDOWS\Sysnative\hlink.dll 2014-11-12 23:21:22 E40D3696BE4852956669C285038B37A6 114688 ----a-w- C:\WINDOWS\Sysnative\ieetwcollector.exe 2014-11-12 23:21:22 DD8FD33C108F14681A410067AB21DDF3 152064 ----a-w- C:\WINDOWS\Sysnative\occache.dll 2014-11-12 23:21:22 C9AB2198141844D3DF96B4552CE9D5AB 77824 ----a-w- C:\WINDOWS\Sysnative\JavaScriptCollectionAgent.dll 2014-11-12 23:21:22 AF28C90094C4C50F083599C10D2DC072 145408 ----a-w- C:\WINDOWS\Sysnative\iepeers.dll 2014-11-12 23:21:22 A7F53772ECAE2F44B455D14F71179940 48640 ----a-w- C:\WINDOWS\Sysnative\ieetwproxystub.dll 2014-11-12 23:21:22 A348DEFC16B6FBC88B7D61C3B861BCB1 107520 ----a-w- C:\WINDOWS\Sysnative\inseng.dll 2014-11-12 23:21:22 9CD8D475F462F82E6FD8BFCA7186ACD4 372736 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2014-11-12 23:21:22 8AE1AC97407CD82D8389390C21430579 111616 ----a-w- C:\WINDOWS\Sysnative\iesysprep.dll 2014-11-12 23:21:22 85E97591864F3125C5B08FB44E0E8078 60416 ----a-w- C:\WINDOWS\Sysnative\msfeedsbs.dll 2014-11-12 23:21:22 853BB696932E4C48EE7034BFF1209A5A 262144 ----a-w- C:\WINDOWS\Sysnative\webcheck.dll 2014-11-12 23:21:22 70576D76A11DD5AE54E719297A315F90 88064 ----a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll 2014-11-12 23:21:22 3721721151DB49457B0FD35E0C04594C 199680 ----a-w- C:\WINDOWS\Sysnative\msrating.dll 2014-11-12 23:21:22 2E475D2FCE0125FA0C486DB9D59E739B 417280 ----a-w- C:\WINDOWS\Sysnative\html.iec 2014-11-12 23:21:22 2CEACC509889A095828F27115257408D 92160 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2014-11-12 23:21:22 1C3C54FA2D620DF3093F356A56EC5957 144384 ----a-w- C:\WINDOWS\Sysnative\ieUnatt.exe 2014-11-12 23:21:22 00FB2FB8C27C834CF575BC415B80F995 87552 ----a-w- C:\WINDOWS\Sysnative\tdc.ocx 2014-11-12 23:21:21 F54E1190251EB245183BF16D6C315613 237568 ----a-w- C:\WINDOWS\Sysnative\url.dll 2014-11-12 23:21:21 E99E2E88BFE584184AE92B1F8995CE93 66560 ----a-w- C:\WINDOWS\Sysnative\iesetup.dll 2014-11-12 23:21:21 D66D11191B48007179B0A77DC0717267 33280 ----a-w- C:\WINDOWS\Sysnative\licmgr10.dll 2014-11-12 23:21:21 CDC8A85EB301A8CBE55A81A1D55AF5E5 132096 ----a-w- C:\WINDOWS\Sysnative\IEAdvpack.dll 2014-11-12 23:21:21 6A7F8D139610E5F3F158182778EF9275 34304 ----a-w- C:\WINDOWS\Sysnative\iernonce.dll 2014-11-12 23:21:21 6096209CB47D61499C3608B9C25B073C 64512 ----a-w- C:\WINDOWS\Sysnative\pngfilt.dll 2014-11-12 23:21:21 4B9C652BD0FD95A9E6123913C35519D6 143872 ----a-w- C:\WINDOWS\Sysnative\wextract.exe 2014-11-12 23:21:21 161BC2E883A8D8759A4DCF2A85AF9128 51200 ----a-w- C:\WINDOWS\Sysnative\imgutil.dll 2014-11-12 23:21:20 CA2F3153EF3BCB0BD3A8984C933DF604 167424 ----a-w- C:\WINDOWS\Sysnative\iexpress.exe 2014-11-12 23:21:20 A3871DED5ED88F59C0D1396761708F81 13824 ----a-w- C:\WINDOWS\Sysnative\mshta.exe 2014-11-12 23:21:20 66585D645C4E23A0FD5124BD714AE020 12800 ----a-w- C:\WINDOWS\Sysnative\msfeedssync.exe 2014-11-12 22:53:49 F0A117D19873FCDF801F082F33BFBB6C 1519488 ----a-w- C:\WINDOWS\Sysnative\user32.dll 2014-11-12 22:53:48 668417ED63F9FBE7DD8D7A54B04279DA 14336 ----a-w- C:\WINDOWS\Sysnative\winshfhc.dll 2014-11-12 22:53:11 EF745B98D81B8C462DB99FC8B5C4322A 3320320 ----a-w- C:\WINDOWS\Sysnative\msi.dll 2014-11-12 22:53:11 D5B41A0C38408814A3E9BAC8C82B2E5B 2773504 ----a-w- C:\WINDOWS\Sysnative\authui.dll 2014-11-12 22:53:10 D1A2E993DB1867C79177CCC9DB6337D0 116032 ----a-w- C:\WINDOWS\Sysnative\consent.exe 2014-11-12 22:53:10 D0C15BC83B3D0AF4F9B1D70216D91794 428032 ----a-w- C:\WINDOWS\Sysnative\msihnd.dll 2014-11-12 22:53:10 034ED41F13D9C1845C1E081F05B640DB 110080 ----a-w- C:\WINDOWS\Sysnative\appinfo.dll 2014-11-12 22:52:39 F0CE4A653EEBA09509EAF93AE2226FA9 426496 ----a-w- C:\WINDOWS\Sysnative\schannel.dll 2014-11-12 22:52:39 6DE50D5592C6EE18C87B0C2EEEDC1621 185856 ----a-w- C:\WINDOWS\Sysnative\dpapisrv.dll 2014-11-12 22:52:39 622928F5A8045F8122F10561D6C35ED0 104336 ----a-w- C:\WINDOWS\Sysnative\ncryptsslp.dll 2014-11-12 22:51:32 D7B23B3154508256C9F434EF9B65B91D 131584 ----a-w- C:\WINDOWS\Sysnative\rdpudd.dll 2014-11-12 22:51:32 A8484FB640E044858BA19FB4F13DD4CE 154112 ----a-w- C:\WINDOWS\Sysnative\msaudite.dll 2014-11-12 22:51:32 949E590B76018E4523FC71CE510ED9ED 1441792 ----a-w- C:\WINDOWS\Sysnative\lsasrv.dll 2014-11-12 22:51:32 91E59FCB3B32DD84E5DCDA2EA1583807 736768 ----a-w- C:\WINDOWS\Sysnative\adtschema.dll 2014-11-12 22:51:32 488CEA4F1B4D2446FFB7A94E3CB385FE 445440 ----a-w- C:\WINDOWS\Sysnative\certcli.dll 2014-11-12 22:51:32 3D2D2EA099D98FE6B94C7D8C7992C08C 40448 ----a-w- C:\WINDOWS\Sysnative\rfxvmt.dll 2014-11-12 22:51:32 1D25CC0A9C480C5D56A5A6CF2B5DEB99 3547648 ----a-w- C:\WINDOWS\Sysnative\rdpcorets.dll 2014-11-12 22:46:48 1D303CE5BCBD5B80BBA08321F28A3F86 21197152 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2014-11-12 22:46:47 BCE66E78D388875B87286CA091E7075F 7484224 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2014-11-12 22:46:46 C4306ADC38939CAC60EA38AAD9F170C0 13424128 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2014-11-12 22:46:46 1907823D5ACFD75D1D8C0D4318299726 2714112 ----a-w- C:\WINDOWS\Sysnative\SettingsHandlers.dll 2014-11-12 22:46:45 CA729FCE295895515A09BD6FF7903DC8 836176 ----a-w- C:\WINDOWS\Sysnative\mfmp4srcsnk.dll 2014-11-12 22:46:45 C88B63FE96DB4BCED65DD442BC8E77F5 1053184 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2014-11-12 22:46:45 A208498C5CD750A1743C1AC8162A810F 941568 ----a-w- C:\WINDOWS\Sysnative\MFMediaEngine.dll 2014-11-12 22:46:42 50E96089F9BE352621997143A56C8E76 822272 ----a-w- C:\WINDOWS\Sysnative\win32spl.dll 2014-11-12 22:46:41 9CE162EB9057CF079736F4DD00FC0D6C 2480128 ----a-w- C:\WINDOWS\Sysnative\WsmSvc.dll 2014-11-12 22:46:41 5416C603B6C85CF0698E8A2A1D28BAA2 448512 ----a-w- C:\WINDOWS\Sysnative\puiobj.dll 2014-11-12 22:46:40 9C55CE9707B3CA29A6505BCDCC546390 275968 ----a-w- C:\WINDOWS\Sysnative\FXSAPI.dll 2014-11-12 22:46:40 8758F5DEBD2B950B2D56ED11F9E0B38F 545792 ----a-w- C:\WINDOWS\Sysnative\untfs.dll 2014-11-12 22:46:40 6C118AEDD15FDBEAECC0E85C64B5B86B 615424 ----a-w- C:\WINDOWS\Sysnative\FXSCOMEX.dll 2014-11-12 22:46:39 A92EF73B02686B7E6F070B486512DB88 389176 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2014-11-12 22:24:38 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2014-11-12 22:20:12 DFDFDE2EA4B5CD0606BA6E56ECEE502D 272248 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2014-11-12 22:20:12 C0484CA5C7F87E38909746B63C7FC868 911360 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2014-11-12 22:20:12 BB93DAAAE9006598935192B9CB65E475 108432 ----a-w- C:\WINDOWS\Sysnative\EncDump.dll 2014-11-12 22:20:12 9F87516BF76C40B41D831F7D729A6044 482872 ----a-w- C:\WINDOWS\Sysnative\AudioEng.dll 2014-11-12 22:20:12 9C88C9397B44B76E5C9A44B8E2CE53A1 500016 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2014-11-12 22:20:12 8085F95BB18A171E7221D2831BC08BC2 394120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2014-11-12 22:20:12 7F70B1044272982AAEA7C16E83424770 226304 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2014-11-12 18:14:08 DCD090318EC800CF6275C6835900B0C6 3557376 ----a-w- C:\WINDOWS\Sysnative\wuaueng.dll 2014-11-12 18:14:07 EA2DF5520D3623F353F43809A2F88086 55776 ----a-w- C:\WINDOWS\Sysnative\wuauclt.exe 2014-11-12 18:14:07 E67B019D23320AA0C5F1E6DE5D30546A 407552 ----a-w- C:\WINDOWS\Sysnative\WUSettingsProvider.dll 2014-11-12 18:14:07 CCE7F88AD038494253B485EC1B144EB3 60416 ----a-w- C:\WINDOWS\Sysnative\wups.dll 2014-11-12 18:14:07 BCC10D47920E83EAC8F2E7E2D414692E 894976 ----a-w- C:\WINDOWS\Sysnative\wuapi.dll 2014-11-12 18:14:07 70AC0FA699C9420CB282CCF72993C2E1 51712 ----a-w- C:\WINDOWS\Sysnative\wups2.dll 2014-11-12 18:14:07 5D67074419BBFDCA587C2E2A93743E8A 140288 ----a-w- C:\WINDOWS\Sysnative\wuwebv.dll 2014-11-12 18:14:07 4D94560FD4982BB52C1FE64AE38E1A9F 35840 ----a-w- C:\WINDOWS\Sysnative\wuapp.exe 2014-11-12 18:14:07 4A112AD7D9C7289FE9945D05E97019D0 17408 ----a-w- C:\WINDOWS\Sysnative\wuaext.dll 2014-11-12 18:14:07 2E66E7D4F1E39F7048A231AA60FD2532 95744 ----a-w- C:\WINDOWS\Sysnative\wudriver.dll 2014-11-12 18:14:07 2585412FC573F298FCBFD6759F8C4C0F 1714176 ----a-w- C:\WINDOWS\Sysnative\wucltux.dll 2014-11-12 18:10:32 9A108C0A3092110F4651B3AFB9CC7B3D 789184 ----a-w- C:\WINDOWS\Sysnative\oleaut32.dll 2014-11-12 18:04:26 93645AEBE163230A2ED5050C14AE6603 2149376 ----a-w- C:\WINDOWS\Sysnative\msxml3.dll 2014-11-12 18:04:03 84549E8C8BF76B293A7E625A98D4BCF9 81408 ----a-w- C:\WINDOWS\Sysnative\packager.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2014-11-12 22:53:48 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\WINDOWS\Sysnative\drivers\WdFilter.sys 2014-11-12 22:53:48 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\WINDOWS\Sysnative\drivers\WdNisDrv.sys 2014-11-12 22:53:48 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\WINDOWS\Sysnative\drivers\WdBoot.sys 2014-11-12 22:51:32 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\WINDOWS\Sysnative\drivers\rdpvideominiport.sys 2014-11-12 22:51:32 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys 2014-11-12 22:51:32 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2014-11-12 22:46:46 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-11-12 22:46:41 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\WINDOWS\Sysnative\drivers\netio.sys 2014-11-12 22:46:41 66732C13628BDB1AB0D6FD46027327C2 148800 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBSTOR.SYS 2014-11-12 22:46:40 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-11-10 21:28:57 -------- d-----w- C:\Program Files\SketchUp 2014-10-25 21:47:53 -------- d-----w- C:\Program Files\Common Files\Topaz Labs 2014-10-25 21:39:36 -------- d-----w- C:\Program Files\7-Zip ======= C:\PROGRA~2 ===== 2014-11-15 12:12:47 -------- d-----w- C:\PROGRA~2\trend micro 2014-11-14 21:30:23 -------- d-----w- C:\PROGRA~2\Portrait Professional Max 6 2014-11-11 21:17:01 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-11-07 22:18:13 -------- d-----w- C:\PROGRA~2\Movavi Screen Capture Studio 5 2014-11-07 20:52:19 -------- d-----w- C:\PROGRA~2\MOJOSOFT 2014-11-04 22:04:27 -------- d-----w- C:\PROGRA~2\Photo to Sketch Converter 2014-10-31 10:34:57 -------- d-----w- C:\PROGRA~2\Imagenomic 2014-10-30 22:09:46 -------- d-----w- C:\PROGRA~2\COMMON~1\ArcSoft 2014-10-30 22:09:07 -------- d-----w- C:\PROGRA~2\ArcSoft 2014-10-28 22:26:55 -------- d-----w- C:\PROGRA~2\Microsoft Synchronization Services 2014-10-28 22:26:45 -------- d-----w- C:\PROGRA~2\COMMON~1\Nova Development 2014-10-28 22:26:44 -------- d-----w- C:\PROGRA~2\Creative Home 2014-10-25 21:47:52 -------- d-----w- C:\PROGRA~2\COMMON~1\Topaz Labs 2014-10-24 13:20:29 -------- d-----w- C:\PROGRA~2\jZip ======= C: ===== ====== C:\Users\M. Robbescheuten\AppData\Roaming ====== 2014-11-14 21:30:25 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\Anthropics 2014-11-14 21:30:25 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\Anthropics 2014-11-12 23:37:11 -------- d-sh--w- C:\Users\M815E~1.ROB\AppData\Local\EmieBrowserModeList 2014-11-12 23:37:11 -------- d-sh--w- C:\Users\M. Robbescheuten\AppData\Local\EmieBrowserModeList 2014-11-12 23:36:55 -------- d-sh--w- C:\Users\M815E~1.ROB\AppData\Locallow\EmieBrowserModeList 2014-11-12 23:36:55 -------- d-sh--w- C:\Users\M. Robbescheuten\AppData\Locallow\EmieBrowserModeList 2014-11-11 21:16:59 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Locallow\Oracle 2014-11-11 21:16:59 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Locallow\Oracle 2014-11-10 21:31:36 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\SketchUp 2014-11-10 21:31:36 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\SketchUp 2014-11-07 22:04:35 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BusinessCards MX 2014-11-07 22:04:35 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BusinessCards MX 2014-11-07 21:25:49 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo Frame Studio 2014-11-07 21:25:49 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo Frame Studio 2014-11-07 20:52:30 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo Calendar Studio 2014-11-07 20:52:30 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo Calendar Studio 2014-11-07 20:52:19 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\mojosoft 2014-11-07 20:52:19 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\mojosoft 2014-10-30 22:10:30 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\ArcSoft 2014-10-30 22:10:30 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\ArcSoft 2014-10-30 22:09:46 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Local\ArcSoft 2014-10-30 22:09:46 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Local\ArcSoft 2014-10-28 22:57:05 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Local\HCSShell 2014-10-28 22:57:05 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Local\HCSShell 2014-10-28 22:28:01 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Local\Creative Home 2014-10-28 22:28:01 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Local\Creative Home 2014-10-23 21:20:22 -------- d-----w- C:\Users\M815E~1.ROB\AppData\Roaming\NeatImage SL 64 2014-10-23 21:20:22 -------- d-----w- C:\Users\M. Robbescheuten\AppData\Roaming\NeatImage SL 64 ====== C:\Users\M. Robbescheuten ====== 2014-11-15 12:11:07 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\M815E~1.ROB\Desktop\RSIT.exe 2014-11-15 12:11:07 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\M. Robbescheuten\Desktop\RSIT.exe 2014-11-14 21:30:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Portrait Professional Max 6 2014-11-11 21:15:45 -------- d-----w- C:\ProgramData\Oracle 2014-11-10 21:31:36 -------- d---a-w- C:\ProgramData\Reprise 2014-11-10 21:29:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2015 2014-11-10 21:28:57 -------- d-----w- C:\ProgramData\SketchUp 2014-11-07 22:18:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Screen Capture Studio 5 2014-11-04 22:04:29 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo to Sketch Converter 2014-10-31 10:48:04 -------- d-----w- C:\Users\Public\Foxit Software 2014-10-31 10:47:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 2014-10-30 22:09:46 -------- d-----w- C:\ProgramData\ArcSoft 2014-10-30 22:09:10 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft 2014-10-28 22:49:45 -------- d-----w- C:\ProgramData\Creative Home 2014-10-28 22:26:48 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hallmark ====== C: exe-files == 2014-11-15 12:12:47 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files (x86)\trend micro\M. Robbescheuten.exe 2014-11-14 21:30:23 DA85258990D4FADA198692A353464573 1708544 ----a-w- C:\Program Files (x86)\Portrait Professional Max 6\PortraitProfessional.exe 2014-11-14 21:30:23 6D827AA554FC2F03BE3000C5F3EFC1B6 691481 ----a-w- C:\Program Files (x86)\Portrait Professional Max 6\unins000.exe 2014-11-13 21:58:25 E9252383496C120FA55CE9A03D31E94C 426056 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\000067be\CoProc update.19053990.exe 2014-11-12 23:21:22 5F1B1148C830C0F149A476A58CE0D09D 815248 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-11-12 23:21:22 5AC6DB399DE418E3955F0CA4567BDD37 813712 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-11-12 23:21:21 CFB15ED916904B30D32DFDE29B67CDCC 25600 ----a-w- C:\Program Files (x86)\Internet Explorer\ExtExport.exe 2014-11-12 23:21:21 CC5C5634FA72689449B4BF7960AC1AD5 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-11-12 23:21:21 8D7C6EE90630126F79275BAC5FE16E51 468992 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-11-12 23:21:21 8CFC152DF5D4FCFD621EF3E231999D03 484352 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-11-12 23:21:21 6A16741182E4C1E83636053C81CE344E 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-11-12 22:56:54 F0B6EDC16656EC9518BE9023862C17F9 182960 ------w- C:\Users\M. Robbescheuten\AppData\Local\Apps\2.0\93WO1TB9.WZC\WA43B7OW.A33\scan..tion_4fda2c49e3177181_0001.0019_29ccecc5088b0f82\ScanCircle.exe 2014-11-11 21:15:51 AA3520FB0133A56BEE1DB34D74DBEF64 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2014-11-11 21:15:51 75D477E868CA51EC1B09D730570F322B 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2014-11-11 21:15:51 691D49FB44EDE9788288CABE4F7E0DAF 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2014-11-11 21:15:48 E3E6B18458FFB07CB24D7A0BA77C9FDF 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\pack200.exe 2014-11-11 21:15:48 DC197DCE6325CBAC905DE0D0E3BA3E8E 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmid.exe 2014-11-11 21:15:48 B719E0F43166037DF46B5CFBE60A5118 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jjs.exe 2014-11-11 21:15:48 A458E2535E46151690E53E2A03FAA711 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\keytool.exe 2014-11-11 21:15:48 9BFAEF308D50779F6B255CB7BA7DCA5A 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\kinit.exe 2014-11-11 21:15:48 7AB1F1B3FB6C3DACA34EA2F988CDF5AC 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\orbd.exe 2014-11-11 21:15:48 75EE99C7F0038C746D82C76221ECA4EF 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\policytool.exe 2014-11-11 21:15:48 67F763B09F4BC8689E6FA9761E068D74 159656 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\unpack200.exe 2014-11-11 21:15:48 57E1F756FAA787623DFCD2C1B2AACC68 51112 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssvagent.exe 2014-11-11 21:15:48 4367C05B0CF5553E71B34F51003D0615 76200 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2launcher.exe 2014-11-11 21:15:48 4109C4DB4BD48F5BF8115C7523A6B6F8 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\klist.exe 2014-11-11 21:15:48 33D2AF53E209DA3E2BA939EB89801DC0 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmiregistry.exe 2014-11-11 21:15:48 29E65AC6AFD8A0A9CAA361FF6F7B4886 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\servertool.exe 2014-11-11 21:15:48 28FC00F89631B0F6E1E9CA386FADD566 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\tnameserv.exe 2014-11-11 21:15:48 26C7F32186B1F0364CD06EA69227A79D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\ktab.exe 2014-11-11 21:15:47 BB8C890E3E6372F2720709262BD42BF4 30632 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jabswitch.exe 2014-11-11 21:15:47 AA3520FB0133A56BEE1DB34D74DBEF64 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\java.exe 2014-11-11 21:15:47 75D477E868CA51EC1B09D730570F322B 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaw.exe 2014-11-11 21:15:47 74713E9C1B01B152DDD3A1A3519A3647 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\java-rmi.exe 2014-11-11 21:15:47 70E67429D2C011FD0419AF899A8D0D70 68520 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe 2014-11-11 21:15:47 691D49FB44EDE9788288CABE4F7E0DAF 272296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe 2014-11-10 21:53:59 D145BB932810734F294E0B03989AB47C 168856 ----a-w- C:\ProgramData\ashampoo\YourDeals.exe 2014-11-10 21:53:59 89A746B5E7D518E9AD2960AE02085576 1331528 ----a-w- C:\ProgramData\ashampoo\unins000.exe 2014-11-10 21:53:58 8F53C79162E1B8A8159A61B763323326 3496296 ----a-w- C:\Program Files (x86)\Ashampoo\Ashampoo Photo Card 2\ASHCARD.exe 2014-11-10 21:53:58 507A2FCCE549788A649E0D433290C867 1260392 ----a-w- C:\Program Files (x86)\Ashampoo\Ashampoo Photo Card 2\CrashSender1402.exe 2014-11-10 21:53:36 DD7FA3590E074B94EC7E00980DFB2E31 104760 ----a-w- C:\Program Files (x86)\Ashampoo\Ashampoo Photo Card 2\updateMediator.exe 2014-11-10 21:53:35 5DABD697256E000FDE03E0F7C631D140 1277424 ----a-w- C:\Program Files (x86)\Ashampoo\Ashampoo Photo Card 2\unins000.exe 2014-11-10 21:51:47 8A9237333F7A386B63CCCDABA615B7DF 427152 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\00006785\CoProc update.19044373.exe === C: other files == 2014-11-12 22:53:48 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\System32\drivers\WdFilter.sys 2014-11-12 22:53:48 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\System32\drivers\WdNisDrv.sys 2014-11-12 22:53:48 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\System32\drivers\WdBoot.sys 2014-11-12 22:51:32 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys 2014-11-12 22:51:32 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2014-11-12 22:51:32 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\System32\drivers\cng.sys 2014-11-12 22:46:46 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2014-11-12 22:46:41 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\System32\drivers\netio.sys 2014-11-12 22:46:41 66732C13628BDB1AB0D6FD46027327C2 148800 -c--a-w- C:\Windows\System32\drivers\USBSTOR.SYS 2014-11-12 22:46:40 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2014-11-12 22:24:38 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\Windows\System32\win32k.sys 2014-11-11 21:15:48 CE44A9D4918DCDC7CCCF5503BF4D7A3D 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-2617873385-1771127311-2925833956-1002\Software\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe" [HKEY_USERS\S-1-5-21-2617873385-1771127311-2925833956-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WAB Migrate"="%ProgramFiles%\Windows Mail\wab.exe /Upgrade" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "PowerDVD12DMREngine"="C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe" "PowerDVD12Agent"="C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe" "APSDaemon"="c:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "QuickTime Task"="c:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe" "AddressBookReminderApp"="C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\ReminderApp.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Users\\M. Robbescheuten\\AppData\\Local\\Smartbar\\Application\\Resources\\crdlil64.dll" ==== Startup Folders ====================== 2014-10-06 21:58:50 1154 ----a-w- C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk 2014-10-06 21:58:50 1154 ----a-w- C:\Users\M815E~1.ROB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk 2014-10-28 22:26:48 2309 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Planner Reminder.lnk ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\ALU" [C:\Program Files (x86)\Acer\Live Updater\updater.exe] "C:\WINDOWS\SysNative\tasks\ALUAgent" [C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\EgisUpdate" ["C:\Program Files\EgisTec IPS\EgisUpdate.exe"] "C:\WINDOWS\SysNative\tasks\Hotkey Utility" ["C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe"] "C:\WINDOWS\SysNative\tasks\PMMUpdate" ["C:\Program Files\EgisTec IPS\PMMUpdate.exe"] "C:\WINDOWS\SysNative\tasks\Power Management" ["C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [14-03-2014 00:34] ==== Chromium Look ====================== Google Docs - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Facebook for Chrome - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalhedleemkkdjddjgfjmcnbpejpapp Solitaire - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep Google Wallet - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Docs - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Facebook for Chrome - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalhedleemkkdjddjgfjmcnbpejpapp Solitaire - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep Google Wallet - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" "Default_Page_URL"="Google" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="Google" "Default_Page_URL"="Google" "Start Page"="Google" "Search Page"="Google" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="Google" "Default_Page_URL"="Google" "Start Page"="Google" "Search Page"="Google" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="msn" "Start Page"="https://www.google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="Bing" "Search Page"="Bing" "Default_Page_URL"="msn" "Start Page"="msn" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="Bing" "Search Page"="Bing" "Default_Page_URL"="msn" "Start Page"="msn" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{9DD089FE-3DBF-407D-97C1-B219EA7CE64C}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="{searchTerms - Google Search}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing" {9DD089FE-3DBF-407D-97C1-B219EA7CE64C} Bing Url="{searchTerms} - Bing" ==== Reset Google Chrome ====================== C:\Users\M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully C:\Users\M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully C:\Users\M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyServer"="http=127.0.0.1:39589" "ProxyOverride"="*origin.com;*ea.com;*akamaihd.net;<local>" "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1 deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\363FB0CBBA367FF4E81FEAD0F717B142 deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\M. Robbescheuten\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\M. Robbescheuten\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\M. Robbescheuten\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\M. Robbescheuten\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\M. Robbescheuten\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2581 folders=324 469362916 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\M. Robbescheuten\AppData\Local\Temp will be emptied at reboot C:\Users\M815E~1~ROB\AppData\Local\Temp emptied successfully C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Users\M815E~1.ROB\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\M815E~1.ROB\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\jZip" not found ==== EOF on za 15-11-2014 at 21:13:23,87 ======================
  8. Logfile of random's system information tool 1.10 (written by random/random) Run by M. Robbescheuten at 2014-11-15 13:12:46 Microsoft Windows 8.1 System drive C: has 251 GB (54%) free of 468 GB Total RAM: 6095 MB (75% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:13:19, on 15-11-2014 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.17416) Boot mode: Normal Running processes: C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\Planner\PLNRnote.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Users\M. Robbescheuten\Desktop\RSIT.exe C:\Program Files (x86)\trend micro\M. Robbescheuten.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.nl/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:39589 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *origin.com;*ea.com;*akamaihd.net;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [PowerDVD12DMREngine] "C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe" O4 - HKLM\..\Run: [PowerDVD12Agent] "C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe" O4 - HKLM\..\Run: [APSDaemon] "c:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [QuickTime Task] "c:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [AddressBookReminderApp] C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\ReminderApp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe O4 - HKUS\S-1-5-21-2617873385-1771127311-2925833956-1001\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'UpdatusUser') O4 - Startup: StormWatchApp.lnk = C:\Users\M. Robbescheuten\AppData\Local\StormWatch\StormWatchApp.exe O4 - Global Startup: Event Planner Reminder.lnk = C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\Planner\PLNRnote.exe O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Site Finder - {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - (no file) O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~2\mcafee\sitead~1\mcieplg.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~2\mcafee\sitead~1\mcieplg.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: ArcSoft Exchange Service (ADExchange) - ArcSoft, Inc. - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe O23 - Service: CLHNServiceForPowerDVD12 - CyberLink Corp. - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe O23 - Service: FolderImportPrivacy.exe - Unknown owner - C:\Users\M. Robbescheuten\AppData\Local\FolderImportPrivacy\FolderImportPrivacy.exe (file missing) O23 - Service: Foxit Cloud Safe Update Service (FoxitCloudUpdateService) - Foxit Software Inc. - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: IePlugin Services (IePluginServices) - Unknown owner - C:\ProgramData\IePluginServices\PluginService.exe (file missing) O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee OOBE Service (McOobeSv) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\windows\system32\mfevtps.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: Wajam Internet Enhancer Service - Unknown owner - C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Unknown owner - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 13650 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-11 460712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-11 172968] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2012-06-22 1527896] "PowerDVD12DMREngine"=C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe [2012-07-25 505872] "PowerDVD12Agent"=C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe [2012-07-25 374560] "APSDaemon"=c:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720] "QuickTime Task"=c:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888] "HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2013-05-30 96056] ""= [] "AddressBookReminderApp"=C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\ReminderApp.exe [] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Event Planner Reminder.lnk - C:\Program Files (x86)\Creative Home\Hallmark Card Studio 2015 Deluxe\Planner\PLNRnote.exe C:\Users\M. Robbescheuten\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup StormWatchApp.lnk - C:\Users\M. Robbescheuten\AppData\Local\StormWatch\StormWatchApp.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CleanHlp] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CleanHlp.sys] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "msacm.msgsm610"=msgsm32.acm "msacm.msg711"=msg711.acm "msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm "vidc.yuy2"=msyuv.dll "vidc.i420"=lvcodec2.dll "vidc.cvid"=iccvid.dll "vidc.yvyu"=msyuv.dll "vidc.yvu9"=tsbyuv.dll "wavemapper"=msacm32.drv "midimapper"=midimap.dll "vidc.uyvy"=msyuv.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msadpcm"=msadp32.acm "vidc.iyuv"=iyuv_32.dll "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "msacm.l3codecp"=l3codecp.acm "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "aux1"=wdmaud.drv "msacm.siren"=sirenacm.dll "vidc.dvsd"=pdvcodec.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-11-15 13:12:47 ----D---- C:\Program Files (x86)\trend micro 2014-11-15 09:48:25 ----ASH---- C:\swapfile.sys 2014-11-15 09:48:25 ----ASH---- C:\pagefile.sys 2014-11-14 22:30:25 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\Anthropics 2014-11-14 22:30:23 ----D---- C:\Program Files (x86)\Portrait Professional Max 6 2014-11-13 00:22:02 ----A---- C:\WINDOWS\SysWOW64\mshtml.dll 2014-11-13 00:21:32 ----A---- C:\WINDOWS\SysWOW64\ieframe.dll 2014-11-13 00:21:26 ----A---- C:\WINDOWS\SysWOW64\jscript9.dll 2014-11-13 00:21:25 ----A---- C:\WINDOWS\SysWOW64\wininet.dll 2014-11-13 00:21:24 ----A---- C:\WINDOWS\SysWOW64\urlmon.dll 2014-11-13 00:21:24 ----A---- C:\WINDOWS\SysWOW64\jscript.dll 2014-11-13 00:21:24 ----A---- C:\WINDOWS\SysWOW64\inetcomm.dll 2014-11-13 00:21:24 ----A---- C:\WINDOWS\SysWOW64\iertutil.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\vbscript.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\ieui.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\dxtrans.dll 2014-11-13 00:21:23 ----A---- C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\webcheck.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\occache.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\msrating.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\mshtmled.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\msfeedsbs.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\jsproxy.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\inseng.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\imgutil.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\iexpress.exe 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\ieUnatt.exe 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\iesysprep.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\iepeers.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\IEAdvpack.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\hlink.dll 2014-11-13 00:21:22 ----A---- C:\WINDOWS\SysWOW64\actxprxy.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\wextract.exe 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\url.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\pngfilt.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\licmgr10.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\iesetup.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\iernonce.dll 2014-11-13 00:21:21 ----A---- C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-11-13 00:21:20 ----A---- C:\WINDOWS\SysWOW64\mshta.exe 2014-11-13 00:21:20 ----A---- C:\WINDOWS\SysWOW64\msfeedssync.exe 2014-11-12 23:53:48 ----A---- C:\WINDOWS\SysWOW64\winshfhc.dll 2014-11-12 23:53:48 ----A---- C:\WINDOWS\SysWOW64\user32.dll 2014-11-12 23:53:11 ----A---- C:\WINDOWS\SysWOW64\msi.dll 2014-11-12 23:53:11 ----A---- C:\WINDOWS\SysWOW64\authui.dll 2014-11-12 23:53:10 ----A---- C:\WINDOWS\SysWOW64\msihnd.dll 2014-11-12 23:52:39 ----A---- C:\WINDOWS\SysWOW64\schannel.dll 2014-11-12 23:52:39 ----A---- C:\WINDOWS\SysWOW64\ncryptsslp.dll 2014-11-12 23:51:32 ----A---- C:\WINDOWS\SysWOW64\msaudite.dll 2014-11-12 23:51:32 ----A---- C:\WINDOWS\SysWOW64\certcli.dll 2014-11-12 23:51:32 ----A---- C:\WINDOWS\SysWOW64\adtschema.dll 2014-11-12 23:46:47 ----A---- C:\WINDOWS\SysWOW64\shell32.dll 2014-11-12 23:46:45 ----A---- C:\WINDOWS\SysWOW64\twinui.dll 2014-11-12 23:46:44 ----A---- C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2014-11-12 23:46:43 ----A---- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-11-12 23:46:41 ----A---- C:\WINDOWS\SysWOW64\WsmSvc.dll 2014-11-12 23:46:41 ----A---- C:\WINDOWS\SysWOW64\puiobj.dll 2014-11-12 23:46:40 ----A---- C:\WINDOWS\SysWOW64\untfs.dll 2014-11-12 23:46:40 ----A---- C:\WINDOWS\SysWOW64\FXSAPI.dll 2014-11-12 23:20:12 ----A---- C:\WINDOWS\SysWOW64\AudioSes.dll 2014-11-12 23:20:12 ----A---- C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2014-11-12 23:20:12 ----A---- C:\WINDOWS\SysWOW64\AudioEng.dll 2014-11-12 19:14:07 ----A---- C:\WINDOWS\SysWOW64\wuwebv.dll 2014-11-12 19:14:07 ----A---- C:\WINDOWS\SysWOW64\wups.dll 2014-11-12 19:14:07 ----A---- C:\WINDOWS\SysWOW64\wudriver.dll 2014-11-12 19:14:07 ----A---- C:\WINDOWS\SysWOW64\wuapp.exe 2014-11-12 19:14:07 ----A---- C:\WINDOWS\SysWOW64\wuapi.dll 2014-11-12 19:10:32 ----A---- C:\WINDOWS\SysWOW64\oleaut32.dll 2014-11-12 19:04:26 ----A---- C:\WINDOWS\SysWOW64\msxml3.dll 2014-11-12 19:04:03 ----A---- C:\WINDOWS\SysWOW64\packager.dll 2014-11-11 22:17:01 ----D---- C:\Program Files (x86)\Common Files\Java 2014-11-11 22:15:45 ----D---- C:\ProgramData\Oracle 2014-11-10 22:31:36 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\SketchUp 2014-11-10 22:31:36 ----AD---- C:\ProgramData\Reprise 2014-11-10 22:28:57 ----D---- C:\ProgramData\SketchUp 2014-11-07 23:18:13 ----D---- C:\Program Files (x86)\Movavi Screen Capture Studio 5 2014-11-07 21:52:19 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\mojosoft 2014-11-07 21:52:19 ----D---- C:\Program Files (x86)\MOJOSOFT 2014-11-04 23:04:27 ----D---- C:\Program Files (x86)\Photo to Sketch Converter 2014-10-31 11:34:57 ----D---- C:\Program Files (x86)\Imagenomic 2014-10-30 23:10:30 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\ArcSoft 2014-10-30 23:09:46 ----D---- C:\ProgramData\ArcSoft 2014-10-30 23:09:46 ----D---- C:\Program Files (x86)\Common Files\ArcSoft 2014-10-30 23:09:07 ----D---- C:\Program Files (x86)\ArcSoft 2014-10-28 23:49:45 ----D---- C:\ProgramData\Creative Home 2014-10-28 23:26:55 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services 2014-10-28 23:26:45 ----D---- C:\Program Files (x86)\Common Files\Nova Development 2014-10-28 23:26:44 ----D---- C:\Program Files (x86)\Creative Home 2014-10-28 22:35:25 ----SHD---- C:\$RECYCLE.BIN 2014-10-25 22:47:52 ----D---- C:\Program Files (x86)\Common Files\Topaz Labs 2014-10-24 14:20:29 ----D---- C:\Program Files (x86)\jZip 2014-10-23 22:20:22 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\NeatImage SL 64 2014-10-16 13:08:59 ----A---- C:\WINDOWS\SysWOW64\MrmCoreR.dll 2014-10-16 13:06:03 ----A---- C:\WINDOWS\SysWOW64\rastls.dll 2014-10-16 13:05:55 ----A---- C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2014-10-16 13:05:55 ----A---- C:\WINDOWS\SysWOW64\mstscax.dll 2014-10-16 13:05:54 ----A---- C:\WINDOWS\SysWOW64\ntdll.dll 2014-10-16 13:05:51 ----A---- C:\WINDOWS\SysWOW64\WSShared.dll 2014-10-16 13:05:51 ----A---- C:\WINDOWS\SysWOW64\Wldap32.dll 2014-10-16 13:05:51 ----A---- C:\WINDOWS\SysWOW64\SearchFolder.dll 2014-10-16 13:05:51 ----A---- C:\WINDOWS\SysWOW64\propsys.dll 2014-10-16 13:05:51 ----A---- C:\WINDOWS\SysWOW64\KernelBase.dll 2014-10-16 13:05:50 ----A---- C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-10-16 13:05:50 ----A---- C:\WINDOWS\SysWOW64\SkyDriveShell.dll ======List of files/folders modified in the last 1 month====== 2014-11-15 13:12:47 ----D---- C:\Program Files (x86) 2014-11-15 13:12:29 ----D---- C:\WINDOWS\Temp 2014-11-15 13:02:18 ----D---- C:\WINDOWS\Prefetch 2014-11-15 10:06:22 ----D---- C:\WINDOWS\Microsoft.NET 2014-11-15 09:52:39 ----D---- C:\WINDOWS\System32 2014-11-15 09:52:39 ----D---- C:\WINDOWS\Inf 2014-11-15 09:50:39 ----A---- C:\WINDOWS\SysWOW64\log.txt 2014-11-15 09:48:16 ----D---- C:\ProgramData\NVIDIA 2014-11-14 17:49:12 ----D---- C:\Users\M. Robbescheuten\AppData\Roaming\vlc 2014-11-14 00:08:22 ----HD---- C:\ProgramData 2014-11-14 00:08:22 ----D---- C:\Program Files (x86)\Common Files 2014-11-13 00:30:26 ----D---- C:\WINDOWS\WinSxS 2014-11-13 00:28:01 ----D---- C:\WINDOWS\SysWOW64 2014-11-13 00:28:01 ----D---- C:\Program Files (x86)\Windows Defender 2014-11-13 00:27:58 ----D---- C:\WINDOWS\SysWOW64\nl-NL 2014-11-13 00:27:58 ----D---- C:\WINDOWS\SysWOW64\migration 2014-11-13 00:27:58 ----D---- C:\Program Files (x86)\Internet Explorer 2014-11-13 00:27:57 ----RD---- C:\WINDOWS\ToastData 2014-11-13 00:27:57 ----RD---- C:\WINDOWS\ImmersiveControlPanel 2014-11-13 00:27:57 ----D---- C:\WINDOWS\apppatch 2014-11-13 00:25:58 ----SHD---- C:\WINDOWS\Installer 2014-11-13 00:25:58 ----HD---- C:\Config.Msi 2014-11-13 00:23:44 ----D---- C:\WINDOWS\CbsTemp 2014-11-13 00:10:06 ----RSD---- C:\WINDOWS\assembly 2014-11-13 00:04:29 ----D---- C:\Windows 2014-11-13 00:04:01 ----D---- C:\WINDOWS\SoftwareDistribution 2014-11-12 19:28:53 ----D---- C:\ProgramData\Microsoft Help 2014-11-12 19:28:25 ----RSD---- C:\WINDOWS\Fonts 2014-11-11 22:15:48 ----A---- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2014-11-11 22:15:43 ----D---- C:\Program Files (x86)\Java 2014-11-10 22:53:59 ----D---- C:\ProgramData\ashampoo 2014-11-10 22:53:35 ----D---- C:\Program Files (x86)\Ashampoo 2014-11-10 22:28:57 ----RD---- C:\Program Files 2014-11-10 22:27:53 ----SHD---- C:\System Volume Information 2014-10-30 01:55:02 ----A---- C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-10-28 23:26:55 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-10-24 13:41:57 ----D---- C:\WINDOWS\AppReadiness 2014-10-18 20:56:11 ----D---- C:\WINDOWS\rescache 2014-10-17 00:15:30 ----D---- C:\WINDOWS\MediaViewer 2014-10-17 00:15:30 ----D---- C:\WINDOWS\FileManager 2014-10-17 00:15:30 ----D---- C:\WINDOWS\Camera 2014-10-17 00:15:27 ----D---- C:\WINDOWS\WinStore ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [] R0 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [] R0 mfewfpk;McAfee Inc. mfewfpk; C:\WINDOWS\system32\drivers\mfewfpk.sys [] R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [] R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [] R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [] R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [] R1 mwlPSDFilter;mwlPSDFilter; C:\WINDOWS\system32\DRIVERS\mwlPSDFilter.sys [] R1 mwlPSDNServ;mwlPSDNServ; C:\WINDOWS\system32\DRIVERS\mwlPSDNServ.sys [] R1 mwlPSDVDisk;mwlPSDVDisk; C:\WINDOWS\system32\DRIVERS\mwlPSDVDisk.sys [] R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [] R2 ntk_PowerDVD12;ntk_PowerDVD12; \??\C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [2012-06-20 83704] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [] R3 LVRS64;@oem38.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs64.sys [] R3 LVUVC64;@oem39.inf,%PID_0805_DD%(UVC);Logitech Webcam 300(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc64.sys [] R3 MEIx64;@oem9.inf,%HECI_SvcDesc%;Intel® Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [] R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [] R3 mfefirek;McAfee Inc. mfefirek; C:\WINDOWS\system32\drivers\mfefirek.sys [] R3 NVHDA;@oem7.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [] R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [] R3 RSUSBVSTOR;@oem4.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [] R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT-stuurprogramma; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [] R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Stuurprogramma voor USB-audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [] R3 usbscan;@sti.inf,%usbscan.SvcDesc%;Stuurprogramma voor USB-scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys [] R3 WDC_SAM;@oem34.inf,%WDC_SAM_ServiceName%;WD SCSI Pass Thru driver; C:\WINDOWS\System32\drivers\wdcsam64.sys [] S0 mfeelamk;McAfee Inc. mfeelamk; C:\WINDOWS\system32\drivers\mfeelamk.sys [] S3 cfwids;McAfee Inc. cfwids; C:\WINDOWS\system32\drivers\cfwids.sys [] S3 dg_ssudbus;@oem8.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [] S3 HipShieldK;McAfee Inc. HipShieldK; C:\WINDOWS\system32\drivers\HipShieldK.sys [] S3 mfeapfk;McAfee Inc. mfeapfk; C:\WINDOWS\system32\drivers\mfeapfk.sys [] S3 mferkdet;McAfee Inc. mferkdet; C:\WINDOWS\system32\drivers\mferkdet.sys [] S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [] S3 ssudmdm;@oem48.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [] S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB-videoapparaat (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ADExchange;ArcSoft Exchange Service; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-03-19 43072] R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2012-10-09 2449552] R2 CLHNServiceForPowerDVD12;CLHNServiceForPowerDVD12; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [2012-07-25 90640] R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2012-07-25 78352] R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2012-07-25 295440] R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752] R2 Fabs;FABS - Helping agent for MAGIX media database; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376] R2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service; C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [2014-09-11 242912] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2012-07-13 2451456] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2012-07-19 166720] R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2012-07-19 277824] R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-06-22 218320] R2 mfevtp;McAfee Validation Trust Protection Service; C:\windows\system32\mfevtps.exe [] R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [] R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-07-31 1258856] R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2013-09-13 337776] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-07-31 382312] R2 UNS;Intel® Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-07-19 365376] R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2012-08-23 658576] R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] S2 FolderImportPrivacy.exe;FolderImportPrivacy.exe; C:\Users\M. Robbescheuten\AppData\Local\FolderImportPrivacy\FolderImportPrivacy.exe [] S2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe -service [] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 mcmscsvc;McAfee Services; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McNASvc;McAfee Network Agent; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 McShield;McAfee McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [2012-06-22 237920] S2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-05-11 200728] S2 Wajam Internet Enhancer Service;Wajam Internet Enhancer Service; C:\Program Files (x86)\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe [] S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2012-07-12 174160] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800] S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-09-27 43696] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144] S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440] -----------------EOF----------------- - - - Updated - - - netwerk adaptor werkt correct word gezegd
  9. Internet zeer traag dan wel dan geen verbinding HELP a.u.b. vr.gr. Romijo
  10. Hoi, Gelukkig dat de topic nog niet is gesloten bedankt, De Pc is erg traag op internet morgen is het 1 week geleden dat we de nieuwe Wifi router x6 N900 in gebruik namen het is alleen op de pc de tablets werken uitstekend Wat zou ik kunnen doen? b.v.d. vriendelijke groeten Romijo
  11. Hoi, het probleem is verdwenen wat 't is geweest ik weet 't niet maar stel even voor als het mogelijk is deze topic even nog open te laten b.v. een weekje stel dat 't weer terugkomt b.v.d. vr.gr. Romijo
  12. Hoi Falstring, momenteel doet de mijne weer normaal ik zal morgenavond eens even testen op allen kan wel zeggen de tablets doen beiden normaal wacht even af tot morgen en dan laat ik nog even een berichtje achter of het probleem zich nog voordoet alvast bedankt maar ga nu naar bedje morgenvroeg weer vroeg op vr.gr. Romijo
  13. Hoi we hebben j.l. vrijdag 7-11 door onsbrabantnet een nieuwe router geplaatst gekregen door een monteur het ging allemaal perfect al onze pc's, laptops, tablets en telefoons werkte perfect toen de monteur de deur uitliep maar nu 2 dagen later zo'n trage verbinding soms wel soms helemaal geen verbinding sinds vandaag. vandaag ook een ongevraagde zogenaamde vriend op Facebook had zichzelf genesteld tussen mijn vrienden ik had daar geen goedkeuring voor gegeven en hem handmatig verwijderd alles ging raar doen op mijn pc na de verwijdering dacht ik 't gaat wel weer, maar na een tijdje begon de ellende weer wat kan ik doen om alles weer goed en snel functioneel te krijgen ik zal maar geen notities van router hier plaatsen. ik hoop dat jullie me kunnen helpen b.v.d. vriendelijke groeten Romijo
  14. Hallo, Ik kreeg vanavond ongevraagd 3x een bestand op mijn pc o.a. : pub1DFB.tmp pubCB7F.tmp pubED4B.tmp ik kan ze niet verwijderen en revo-uninstaller ziet ze niet. kunnen jullie mij a.u.b. hierbij helpen? b.v.d. vr. gr. Romijo - - - Updated - - - sorry beetje dom van mij was van Publisher daar ben ik vanavond mee bezig geweest het heeft zich dus al opgelost ik zal het markeren als opgelost
  15. Maxstar hartelijk dank voor uw hulp alles werkt weer perfect !! ik zal deze topic als opgelost markeren.
  16. Hallo Maxstar, jeetje zeg avond nacht en dag bezig geweest hierbij de volgende scan waar ik zeker van weet dat 't geen bedreiging geeft heb ik uitgevinkt vriendelijke groetjes Romijo a2scan_140922-223819.txt
  17. Hallo Maxstar, dank voor uw hulp internet explorer doet 't weer Heb opnieuw logje adw. AdwCleaner[S0].txt
  18. Hallo, 't loopt hier grandioos fout heb de pc terug gezet naar een paar dagen terug google chrome had ik er af gegooid en internet explorer weer aangezet maar die deed niets meer hopelijk komt 't nog goed want internet explorer zegt steeds er is een fout opgetreden en valt weg gr. en bedankt weer zoek-results.txt zoek-results.txt
  19. [ATTACH]35794[/ATTACH]opnieuw gedaan sorry voor 't ongemak gr. Romijo zoek-results.txt
  20. Hoi Maxstar, ik hoop dat 't nu wel compleet is zal het als bijlage erbij zetten dank voor uw moeite gr. Romijo log.txt
  21. Zoek.exe v5.0.0.0 Updated 14-September-2014 Tool run by M. Robbescheuten on do 18-09-2014 at 22:43:22,33. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\M. Robbescheuten\Downloads\zoek.exe [scan all users] [script inserted] ==== System Restore Info ====================== 18-9-2014 22:45:34 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2617873385-1771127311-2925833956-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} deleted successfully HKEY_USERS\S-1-5-21-2617873385-1771127311-2925833956-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Explorer Bars\{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} deleted successfully ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Users\M. Robbescheuten\AppData\Local\Smartbar not found C:\Program Files (x86)\SiteFinder deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-09-13 08:00:37 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\M815E~1.ROB\AppData\Local\Temp ==== 2014-09-13 23:19:03 FB5621842FDABF9F8359775573498FBC 605064 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\npGoogleUpdate3.dll 2014-09-13 23:19:03 FB5621842FDABF9F8359775573498FBC 605064 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\npGoogleUpdate3.dll 2014-09-13 23:19:03 C95CDDF65F9F8C9433AFF8F0A811375A 189320 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psmachine_64.dll 2014-09-13 23:19:03 C95CDDF65F9F8C9433AFF8F0A811375A 189320 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psmachine_64.dll 2014-09-13 23:19:03 84180917AAB55EE4392C54E0E0BD4022 166792 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psmachine.dll 2014-09-13 23:19:03 84180917AAB55EE4392C54E0E0BD4022 166792 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psmachine.dll 2014-09-13 23:19:03 715CCB3F5EDA626198CCADC7AB8CE9A2 189320 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psuser_64.dll 2014-09-13 23:19:03 715CCB3F5EDA626198CCADC7AB8CE9A2 189320 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psuser_64.dll 2014-09-13 23:19:03 3D58798BD1D1F96381C0B47CA859739D 166792 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psuser.dll 2014-09-13 23:19:03 3D58798BD1D1F96381C0B47CA859739D 166792 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\psuser.dll 2014-09-13 23:19:01 DEC1A40D0210FAD3BB67028B97F155A4 26112 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateHelper.msi 2014-09-13 23:19:01 DEC1A40D0210FAD3BB67028B97F155A4 26112 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateHelper.msi 2014-09-13 23:19:01 AC6998D92A311E7CF0B4DAEC3566F444 51080 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateBroker.exe 2014-09-13 23:19:01 AC6998D92A311E7CF0B4DAEC3566F444 51080 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateBroker.exe 2014-09-13 23:19:01 AA0E4F73727BFC8BA404884B1C1DB719 285064 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleCrashHandler64.exe 2014-09-13 23:19:01 AA0E4F73727BFC8BA404884B1C1DB719 285064 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleCrashHandler64.exe 2014-09-13 23:19:01 956672375AF066D958E4D07F5ABAFC1A 51080 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateOnDemand.exe 2014-09-13 23:19:01 956672375AF066D958E4D07F5ABAFC1A 51080 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateOnDemand.exe 2014-09-13 23:19:01 901AC7A94B75648F4084A37640473271 895120 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateSetup.exe 2014-09-13 23:19:01 901AC7A94B75648F4084A37640473271 895120 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateSetup.exe 2014-09-13 23:19:01 80E350E0AA963B2125896B13E60A4D68 114568 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateComRegisterShell64.exe 2014-09-13 23:19:01 80E350E0AA963B2125896B13E60A4D68 114568 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdateComRegisterShell64.exe 2014-09-13 23:19:01 77E585EDD4C7EB7AB2ACC36BC1DC32A5 1696648 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\goopdate.dll 2014-09-13 23:19:01 77E585EDD4C7EB7AB2ACC36BC1DC32A5 1696648 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\goopdate.dll 2014-09-13 23:19:01 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdate.exe 2014-09-13 23:19:01 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleUpdate.exe 2014-09-13 23:19:01 397D14958D6C9C2B365469A857B2AC4E 230792 ----atw- C:\Users\M815E~1.ROB\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleCrashHandler.exe 2014-09-13 23:19:01 397D14958D6C9C2B365469A857B2AC4E 230792 ----atw- C:\Users\M. Robbescheuten\AppData\Local\Temp\{A0019A05-38BF-4CB1-8C77-3037DBF89F9B}\GoogleCrashHandler.exe 2014-09-13 18:48:08 B25E32C0C64B236F23F0B716ED1627B2 4226843 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\n1837\OptimizerPro(2).exe 2014-09-13 18:48:08 B25E32C0C64B236F23F0B716ED1627B2 4226843 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\n1837\OptimizerPro(2).exe 2014-09-13 18:48:04 F1D54C928FDBA74E906AB153FBBDC25C 4205799 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\n1837\OptimizerPro(1).exe 2014-09-13 18:48:04 F1D54C928FDBA74E906AB153FBBDC25C 4205799 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\n1837\OptimizerPro(1).exe 2014-09-13 18:47:58 1AC42FF41023CE239929989FC4CFB96B 2270880 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\n1837\WIE_2.14.1.82.exe 2014-09-13 18:47:58 1AC42FF41023CE239929989FC4CFB96B 2270880 ----a-w- C:\Users\M. Robbescheuten\AppData\Local\Temp\n1837\WIE_2.14.1.82.exe 2014-09-13 18:47:57 837B83703D9846451B7202F7B0246B82 4213099 ----a-w- C:\Users\M815E~1.ROB\AppData\Local\Temp\n1837\OptimizerPro.exe
  22. dank voor uw hulp log: [ATTACH]35756[/ATTACH] log.txt
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.