Ga naar inhoud

Aanbevolen berichten

Dag beste leden.

Hier is het gevraagde log van RSIT.

Logfile of random's system information tool 1.10 (written by random/random)

Run by FM2A88 at 2014-08-15 09:35:20

Microsoft Windows 8.1

System drive C: has 267 GB (66%) free of 407 GB

Total RAM: 7602 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 9:35:23, on 15/08/2014

Platform: Unknown Windows (WinNT 6.02.1008)

MSIE: Internet Explorer v11.0 (11.00.9600.17239)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe

C:\Program Files (x86)\Dell AIO Printer 948\dldfmon.exe

C:\Program Files (x86)\Dell AIO Printer 948\memcard.exe

C:\Program Files (x86)\Kies\KiesTrayAgent.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files\trend micro\FM2A88.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1407522120&from=tugs&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN België: Hotmail, Skype, nieuws, entertainment, lifestyle en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)

O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll

O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll

O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll

O2 - BHO: TVersitybar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Users\FM2A88\AppData\LocalLow\TVersitybar\prxtbTVer.dll

O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll

O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll

O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)

O3 - Toolbar: TVersitybar Toolbar - {66bd2442-241b-44cd-8c7a-b51037053cdb} - C:\Users\FM2A88\AppData\LocalLow\TVersitybar\prxtbTVer.dll

O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [dldfmon.exe] "C:\Program Files (x86) (x86)\Dell AIO Printer 948\dldfmon.exe"

O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files (x86) (x86)\Dell AIO Printer 948\memcard.exe"

O4 - HKLM\..\Run: [Dell AIO Printer 948] "C:\Program Files (x86)\Dell AIO Printer 948\fm3032.exe" /s

O4 - HKLM\..\Run: [GoforFilesInstaller Starter] "C:\Users\FM2A88\AppData\Local\Temp\install13067082.exe" -startup

O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Kies\KiesTrayAgent.exe

O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AnyProtect Scanner] "C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe"

O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe

O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000

O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll

O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll

O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll

O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe

O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe

O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL

O20 - AppInit_DLLs:

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: dldfCATSCustConnectService - Unknown owner - C:\Windows\system32\spool\DRIVERS\x64\3\\dldfserv.exe

O23 - Service: dldf_device - - C:\Windows\SysWOW64\dldfcoms.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe

O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

O23 - Service: IePlugin Services (IePluginServices) - Unknown owner - C:\ProgramData\IePluginServices\PluginService.exe (file missing)

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Toolbar Service (TBSrv) - ClientConnect Ltd. - C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe

O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Update Dolphin Deals - Unknown owner - C:\Program Files (x86)\Dolphin Deals\updateDolphinDeals.exe (file missing)

O23 - Service: Update Greener Web - Unknown owner - C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe (file missing)

O23 - Service: Util Dolphin Deals - Unknown owner - C:\Program Files (x86)\Dolphin Deals\bin\utilDolphinDeals.exe (file missing)

O23 - Service: Util Greener Web - Unknown owner - C:\Program Files (x86)\Greener Web\bin\utilGreenerWeb.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 14703 bytes

======Listing Processes======

wininit.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService

"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"

"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"

"C:\Program Files\Bonjour\mDNSResponder.exe"

"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"

C:\Windows\system32\spool\DRIVERS\x64\3\\dldfserv.exe

dashost.exe {6a836c04-534e-4113-bab85b9af2e06a40}

C:\Windows\SysWOW64\dldfcoms.exe -service

"C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\diMaster.dll" /prefetch:1

C:\Windows\system32\svchost.exe -k imgsvc

"C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe"

"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"

"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"

C:\Windows\system32\SearchIndexer.exe /Embedding

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

"C:\Program Files (x86)\Dolphin Deals\bin\DolphinDeals.PurBrowse64.exe" /l false /s false /c "Dolphin Deals" /t "C:\Program Files (x86)\Dolphin Deals\bin\TEMP" /i "http://apisqeedolphinde-a.akamaihd.net/gsrs?is=amp1lmbe&bp=PBG&g=00000000-0000-0000-0000-000000000000" /d {f2dee4ac-05d0-4e54-80bc-2dc0ba61a2c7}Gw64 /p 544e3f8f-d18e-4af1-962a-a0eda799de32:chrome

\??\C:\Windows\system32\conhost.exe 0x4

C:\Windows\System32\WinLogon.exe -SpecialSession

-hiberboot

atieclxx

C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {9BA05972-F6A8-11CF-A442-00A0C90A8F39} -Embedding

taskhostex.exe

"C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe" /c /a /s UserSession

C:\Windows\Explorer.EXE

ClassicStartMenu.exe -startup

"C:\Program Files (x86)\Dell AIO Printer 948\dldfmon.exe"

"C:\Program Files (x86)\Dell AIO Printer 948\memcard.exe"

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow

"C:\Program Files (x86)\Kies\KiesTrayAgent.exe"

"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="7160.0.669748210\393865855" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x9996 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/GwsPrerenderNavSuggest/Default/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/RapporRollout/Enabled/SPDY/SpdyDisabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_29/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="7160.2.2105746227\599606322" /prefetch:673131151

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/GwsPrerenderNavSuggest/Default/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/RapporRollout/Enabled/SPDY/SpdyDisabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_29/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="7160.3.144152129\347433947" /prefetch:673131151

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/GwsPrerenderNavSuggest/Default/NetworkConnectivity/disable_network_stats/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/RapporRollout/Enabled/SPDY/SpdyDisabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_29/UMA-Uniformity-Trial-10-Percent/group_06/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="7160.22.2121963866\526330143" /prefetch:673131151

"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe46_ Global\UsGthrCtrlFltPipeMssGthrPipe46 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

taskeng.exe {D4E4C0F8-25BE-46C2-A5A6-CFDDB4C2F124}

"C:\Windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572

"C:\Users\FM2A88\Desktop\RSITx64.exe"

C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\AmiUpdXp.job - C:\Users\FM2A88\AppData\Local\20061\a2786.exe

C:\Windows\tasks\APSnotifierPP1.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier2 A

C:\Windows\tasks\APSnotifierPP2.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier 4

C:\Windows\tasks\APSnotifierPP3.job - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe --notifier 6

C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe

C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c

C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]

"Description"=iTunes Detector Plug-in

"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]

"Description"=

"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]

"Description"=Java™ Deployment Toolkit

"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]

"Description"=Oracle® Next Generation Java™ Plug-In

"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]

"Description"=Microsoft Lync Plug-in for Firefox

"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]

"Description"=Microsoft SharePoint Plug-in for Firefox

"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]

"Description"=WLPG Install MIME type

"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]

"Description"=globalUpdate Update

"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]

"Description"=globalUpdate Update

"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]

"Description"=Google Update

"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0]

"Description"=VLC Multimedia Plugin

"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]

"Description"=Ag Player Plugin

"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\

belgiumeid@eid.belgium.be

C:\Program Files (x86)\Mozilla Firefox\plugins\

npMeetingJoinPluginOC.dll

C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\extensions\

faststartff@gmail.com

jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack

{66bd2442-241b-44cd-8c7a-b51037053cdb}

{E9A1DEE0-C623-4439-8932-001E7D17607D}

C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\searchplugins\

Web Search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]

Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-07-27 218776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]

ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-20 774144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll [2014-06-26 917344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2014-07-27 2335960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]

ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2013-10-20 460288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]

Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-05-21 153248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]

ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-20 627712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll [2014-06-26 654688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66bd2442-241b-44cd-8c7a-b51037053cdb}]

TVersitybar Toolbar - C:\Users\FM2A88\AppData\LocalLow\TVersitybar\prxtbTVer.dll [2014-04-10 423744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]

Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL [2014-02-21 392344]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

Java Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]

Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-07-27 1730256]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-08 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]

ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2013-10-20 386048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2013-10-20 774144]

{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll [2014-06-26 917344]

{66BD2442-241B-44CD-8C7A-B51037053CDB} - TVersitybar Toolbar - C:\Users\FM2A88\AppData\LocalLow\TVersitybar\prxtbTVer.dll [2014-04-10 423744]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]

{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-10-20 627712]

{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll [2014-06-26 654688]

{3041d03e-fd4b-44e0-b742-2d9b88305f98}

{66bd2442-241b-44cd-8c7a-b51037053cdb} - TVersitybar Toolbar - C:\Users\FM2A88\AppData\LocalLow\TVersitybar\prxtbTVer.dll [2014-04-10 423744]

{ae07101b-46d4-4a98-af68-0333ea26e113}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"dldfmon.exe"=C:\Program Files (x86)\Dell AIO Printer 948\dldfmon.exe [2009-04-27 455336]

"MemoryCardManager"=C:\Program Files (x86)\Dell AIO Printer 948\memcard.exe [2009-04-27 410280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2014-02-08 1193352]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]

"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-03 43816]

"dldfmon.exe"=C:\Program Files (x86) (x86)\Dell AIO Printer 948\dldfmon.exe [2009-04-27 455336]

"MemoryCardManager"=C:\Program Files (x86) (x86)\Dell AIO Printer 948\memcard.exe [2009-04-27 410280]

"Dell AIO Printer 948"=C:\Program Files (x86)\Dell AIO Printer 948\fm3032.exe [2009-04-27 311976]

"GoforFilesInstaller Starter"=C:\Users\FM2A88\AppData\Local\Temp\install13067082.exe -startup []

"KiesTrayAgent"=C:\Program Files (x86)\Kies\KiesTrayAgent.exe [2014-05-28 310064]

"TrojanScanner"=C:\Program Files (x86)\Trojan Remover\Trjscan.exe [2014-07-08 1666432]

"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-07-08 152392]

"fst_be_68"= []

"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]

"AnyProtect Scanner"=C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CleanHlp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CleanHlp.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"msacm.l3acm"=C:\Windows\System32\l3codeca.acm

"vidc.yuy2"=msyuv.dll

"vidc.i420"=iyuv_32.dll

"msacm.msgsm610"=msgsm32.acm

"msacm.msg711"=msg711.acm

"vidc.yvyu"=msyuv.dll

"vidc.yvu9"=tsbyuv.dll

"wavemapper"=msacm32.drv

"midimapper"=midimap.dll

"vidc.uyvy"=msyuv.dll

"vidc.iyuv"=iyuv_32.dll

"vidc.mrle"=msrle32.dll

"msacm.imaadpcm"=imaadp32.acm

"msacm.msadpcm"=msadp32.acm

"vidc.msvc"=msvidc32.dll

"wave"=wdmaud.drv

"midi"=wdmaud.drv

"mixer"=wdmaud.drv

"aux"=wdmaud.drv

"wave1"=wdmaud.drv

"midi1"=wdmaud.drv

"mixer1"=wdmaud.drv

"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

.scr - open - C:\Windows\system32\notepad.exe "%1"

.scr - install -

.scr - config -

======List of files/folders created in the last 1 month======

2014-08-15 09:19:30 ----D---- C:\rsit

2014-08-15 09:19:30 ----D---- C:\Program Files\trend micro

2014-08-15 00:49:19 ----A---- C:\Windows\system32\drivers\{f2dee4ac-05d0-4e54-80bc-2dc0ba61a2c7}Gw64.sys

2014-08-14 23:47:32 ----D---- C:\Program Files (x86)\Dolphin Deals

2014-08-14 20:35:27 ----D---- C:\Users\FM2A88\AppData\Roaming\uTorrent

2014-08-13 17:46:40 ----A---- C:\Windows\SYSWOW64\dxgi.dll

2014-08-13 17:46:40 ----A---- C:\Windows\system32\dxgi.dll

2014-08-13 17:46:40 ----A---- C:\Windows\system32\dwmcore.dll

2014-08-13 17:46:40 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys

2014-08-13 17:46:34 ----A---- C:\Windows\SYSWOW64\urlmon.dll

2014-08-13 17:46:34 ----A---- C:\Windows\SYSWOW64\msfeeds.dll

2014-08-13 17:46:34 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll

2014-08-13 17:46:34 ----A---- C:\Windows\system32\urlmon.dll

2014-08-13 17:46:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll

2014-08-13 17:46:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll

2014-08-13 17:46:33 ----A---- C:\Windows\SYSWOW64\dxtrans.dll

2014-08-13 17:46:33 ----A---- C:\Windows\system32\msfeeds.dll

2014-08-13 17:46:33 ----A---- C:\Windows\system32\dxtmsft.dll

2014-08-13 17:46:32 ----A---- C:\Windows\system32\iertutil.dll

2014-08-13 17:46:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll

2014-08-13 17:46:31 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll

2014-08-13 17:46:31 ----A---- C:\Windows\system32\dxtrans.dll

2014-08-13 17:46:30 ----A---- C:\Windows\system32\mshtmled.dll

2014-08-13 17:46:30 ----A---- C:\Windows\system32\jscript9diag.dll

2014-08-13 17:46:30 ----A---- C:\Windows\system32\jscript9.dll

2014-08-13 17:46:30 ----A---- C:\Windows\system32\ieframe.dll

2014-08-13 17:46:29 ----A---- C:\Windows\system32\mshtml.dll

2014-08-13 17:46:29 ----A---- C:\Windows\system32\ieapfltr.dll

2014-08-13 17:46:28 ----A---- C:\Windows\SYSWOW64\mshtmled.dll

2014-08-13 17:46:28 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll

2014-08-13 17:46:27 ----A---- C:\Windows\SYSWOW64\mshtml.dll

2014-08-13 17:46:09 ----A---- C:\Windows\SYSWOW64\wininet.dll

2014-08-13 17:46:09 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll

2014-08-13 17:46:09 ----A---- C:\Windows\system32\wininet.dll

2014-08-13 17:46:09 ----A---- C:\Windows\system32\iedkcs32.dll

2014-08-13 17:46:08 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll

2014-08-13 17:46:08 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll

2014-08-13 17:46:08 ----A---- C:\Windows\system32\ie4uinit.exe

2014-08-13 17:46:07 ----A---- C:\Windows\SYSWOW64\vbscript.dll

2014-08-13 17:46:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll

2014-08-13 17:46:07 ----A---- C:\Windows\system32\vbscript.dll

2014-08-13 17:46:07 ----A---- C:\Windows\system32\MshtmlDac.dll

2014-08-13 17:45:06 ----A---- C:\Windows\system32\rpcrt4.dll

2014-08-13 17:45:05 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll

2014-08-13 17:44:56 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe

2014-08-13 17:44:56 ----A---- C:\Windows\system32\TsWpfWrp.exe

2014-08-13 17:41:32 ----A---- C:\Windows\SYSWOW64\authui.dll

2014-08-13 17:41:32 ----A---- C:\Windows\system32\msi.dll

2014-08-13 17:41:32 ----A---- C:\Windows\system32\authui.dll

2014-08-13 17:41:31 ----A---- C:\Windows\SYSWOW64\msihnd.dll

2014-08-13 17:41:31 ----A---- C:\Windows\SYSWOW64\msi.dll

2014-08-13 17:41:31 ----A---- C:\Windows\system32\msihnd.dll

2014-08-13 17:41:31 ----A---- C:\Windows\system32\consent.exe

2014-08-13 17:41:28 ----A---- C:\Windows\system32\aepdu.dll

2014-08-13 17:41:28 ----A---- C:\Windows\system32\aeinv.dll

2014-08-13 17:41:26 ----A---- C:\Windows\system32\MrmCoreR.dll

2014-08-13 17:41:24 ----A---- C:\Windows\SYSWOW64\Wpc.dll

2014-08-13 17:41:24 ----A---- C:\Windows\system32\WpcWebSync.dll

2014-08-13 17:41:24 ----A---- C:\Windows\system32\WpcMon.exe

2014-08-13 17:41:24 ----A---- C:\Windows\system32\Wpc.dll

2014-08-13 17:41:24 ----A---- C:\Windows\system32\win32k.sys

2014-08-13 17:41:23 ----A---- C:\Windows\SYSWOW64\gdi32.dll

2014-08-13 17:41:23 ----A---- C:\Windows\system32\MDMAgent.exe

2014-08-13 17:41:23 ----A---- C:\Windows\system32\gdi32.dll

2014-08-12 22:30:46 ----D---- C:\Program Files (x86)\Systweak Support Dock

2014-08-12 22:27:43 ----D---- C:\Program Files (x86)\Advanced System Protector

2014-08-12 22:27:07 ----D---- C:\Users\FM2A88\AppData\Roaming\Systweak

2014-08-12 22:26:44 ----D---- C:\Program Files (x86)\SupTab

2014-08-12 22:23:56 ----A---- C:\Windows\GPlrLanc.dat

2014-08-11 23:19:58 ----HD---- C:\Users\FM2A88\AppData\Roaming\GoldenGate

2014-08-11 22:42:25 ----D---- C:\Program Files\ADVANCED TOOLS

2014-08-11 22:38:15 ----D---- C:\Users\FM2A88\AppData\Roaming\Soldiers939

2014-08-11 22:38:11 ----D---- C:\Users\FM2A88\AppData\Roaming\GoodGameEmpire

2014-08-11 20:21:52 ----D---- C:\Users\FM2A88\AppData\Roaming\AVG

2014-08-11 20:20:43 ----D---- C:\ProgramData\AVG

2014-08-11 20:20:36 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}

2014-08-11 20:20:03 ----D---- C:\Program Files (x86)\Cheat Engine 6.4

2014-08-11 19:12:11 ----D---- C:\ProgramData\Real

2014-08-11 19:11:57 ----D---- C:\Users\FM2A88\AppData\Roaming\OpenCandy

2014-08-10 15:52:07 ----D---- C:\Users\FM2A88\AppData\Roaming\ap_logs

2014-08-10 15:39:52 ----D---- C:\Users\FM2A88\AppData\Roaming\DownloadManager

2014-08-10 14:10:52 ----D---- C:\Program Files (x86)\predm

2014-08-10 09:42:58 ----D---- C:\Users\FM2A88\AppData\Roaming\SimpleFiles

2014-08-10 07:51:45 ----A---- C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64.sys

2014-08-10 01:19:07 ----D---- C:\Users\FM2A88\AppData\Roaming\QuickScan

2014-08-10 01:17:47 ----D---- C:\Download Genius

2014-08-08 20:38:19 ----A---- C:\Windows\SYSWOW64\javaws.exe

2014-08-08 20:38:14 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll

2014-08-08 20:38:14 ----A---- C:\Windows\SYSWOW64\javaw.exe

2014-08-08 20:38:14 ----A---- C:\Windows\SYSWOW64\java.exe

2014-08-08 20:38:06 ----D---- C:\Program Files (x86)\Java

2014-08-08 20:24:54 ----D---- C:\ProgramData\IePluginServices

2014-08-08 20:24:31 ----D---- C:\ProgramData\WindowsMangerProtect

2014-08-08 20:23:39 ----D---- C:\ProgramData\374311380

2014-08-08 20:22:13 ----D---- C:\Program Files (x86)\globalUpdate

2014-08-08 20:21:15 ----D---- C:\Program Files (x86)\HaoZip

2014-07-24 13:05:17 ----A---- C:\Windows\system32\SyncEngine.dll

2014-07-24 13:05:17 ----A---- C:\Windows\system32\SkyDriveTelemetry.dll

2014-07-24 13:05:17 ----A---- C:\Windows\system32\SkyDrive.exe

======List of files/folders modified in the last 1 month======

2014-08-15 09:31:15 ----D---- C:\Windows\Prefetch

2014-08-15 09:19:30 ----RD---- C:\Program Files

2014-08-15 09:00:00 ----D---- C:\Windows\system32\sru

2014-08-15 08:59:07 ----D---- C:\Windows\AppReadiness

2014-08-15 08:58:39 ----D---- C:\Windows\system32\config

2014-08-15 08:34:23 ----D---- C:\Windows\Temp

2014-08-15 08:27:25 ----D---- C:\Windows\Microsoft.NET

2014-08-15 08:12:48 ----D---- C:\Users\FM2A88\AppData\Roaming\ClassicShell

2014-08-15 08:10:56 ----SHD---- C:\Windows\Installer

2014-08-15 08:08:58 ----D---- C:\Windows\system32\Tasks

2014-08-15 08:08:57 ----RD---- C:\Program Files (x86)

2014-08-15 08:08:57 ----D---- C:\Windows\Tasks

2014-08-15 00:49:19 ----D---- C:\Windows\system32\drivers

2014-08-14 21:05:28 ----SHD---- C:\System Volume Information

2014-08-14 20:16:55 ----RD---- C:\Windows\System32

2014-08-14 20:16:55 ----A---- C:\Windows\system32\PerfStringBackup.INI

2014-08-14 20:16:54 ----D---- C:\Windows\Inf

2014-08-14 20:10:58 ----D---- C:\Users\FM2A88\AppData\Roaming\Azureus

2014-08-14 20:10:58 ----D---- C:\Program Files (x86)\Vuze

2014-08-14 18:37:55 ----RSD---- C:\Windows\assembly

2014-08-14 18:25:30 ----HD---- C:\Program Files\WindowsApps

2014-08-14 08:20:09 ----D---- C:\Windows\WinSxS

2014-08-13 22:58:23 ----RD---- C:\Windows\ToastData

2014-08-13 22:58:23 ----D---- C:\Windows\SYSWOW64\nl-NL

2014-08-13 22:58:23 ----D---- C:\Windows\SysWOW64

2014-08-13 22:58:23 ----D---- C:\Windows\system32\nl-NL

2014-08-13 22:58:23 ----D---- C:\Windows\system32\migration

2014-08-13 22:58:23 ----D---- C:\Program Files\Internet Explorer

2014-08-13 22:58:23 ----D---- C:\Program Files (x86)\Internet Explorer

2014-08-13 22:58:22 ----D---- C:\Windows\PolicyDefinitions

2014-08-13 18:16:03 ----D---- C:\ProgramData\Microsoft Help

2014-08-13 18:15:29 ----D---- C:\Windows\CbsTemp

2014-08-13 18:14:17 ----D---- C:\Windows\system32\MRT

2014-08-13 18:10:51 ----A---- C:\Windows\system32\MRT.exe

2014-08-13 18:07:49 ----SD---- C:\Windows\system32\CompatTel

2014-08-13 18:06:15 ----A---- C:\Windows\win.ini

2014-08-13 18:05:13 ----D---- C:\Windows\system32\wbem

2014-08-13 17:40:50 ----A---- C:\Windows\SYSWOW64\msrating.dll

2014-08-13 17:40:48 ----A---- C:\Windows\SYSWOW64\jsproxy.dll

2014-08-13 17:40:29 ----A---- C:\Windows\system32\ieetwproxystub.dll

2014-08-13 17:40:29 ----A---- C:\Windows\system32\ieetwcollectorres.dll

2014-08-13 17:40:29 ----A---- C:\Windows\system32\ieetwcollector.exe

2014-08-13 17:40:28 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll

2014-08-13 17:40:27 ----A---- C:\Windows\system32\ieUnatt.exe

2014-08-13 17:40:26 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe

2014-08-13 17:40:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll

2014-08-13 17:40:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll

2014-08-13 17:40:23 ----A---- C:\Windows\system32\iesetup.dll

2014-08-13 17:40:23 ----A---- C:\Windows\system32\iernonce.dll

2014-08-13 17:40:17 ----A---- C:\Windows\system32\msrating.dll

2014-08-13 17:40:16 ----A---- C:\Windows\system32\jsproxy.dll

2014-08-13 17:36:51 ----D---- C:\Windows\system32\catroot2

2014-08-12 22:43:55 ----HD---- C:\ProgramData

2014-08-12 22:34:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information

2014-08-12 22:32:21 ----D---- C:\Windows

2014-08-12 22:23:52 ----SD---- C:\Windows\Downloaded Program Files

2014-08-12 22:22:49 ----SD---- C:\Users\FM2A88\AppData\Roaming\Microsoft

2014-08-10 13:43:02 ----D---- C:\Program Files (x86)\MyFree Codec

2014-08-10 01:16:50 ----D---- C:\Program Files (x86)\Common Files

2014-08-08 20:43:09 ----D---- C:\Program Files (x86)\WinRAR

2014-08-08 20:42:14 ----D---- C:\Program Files\WinRAR

2014-08-08 20:38:29 ----D---- C:\ProgramData\Oracle

2014-08-08 20:21:34 ----HD---- C:\Windows\system32\GroupPolicy

2014-08-08 20:21:34 ----D---- C:\Windows\SYSWOW64\GroupPolicy

2014-08-02 02:17:43 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

2014-07-31 21:17:03 ----D---- C:\Users\FM2A88\AppData\Roaming\vlc

2014-07-28 12:59:28 ----D---- C:\Windows\system32\DriverStore

2014-07-26 14:37:06 ----D---- C:\Users\FM2A88\AppData\Roaming\dvdcss

2014-07-25 16:37:54 ----D---- C:\Program Files\Microsoft Silverlight

2014-07-25 16:37:53 ----D---- C:\Program Files (x86)\Microsoft Silverlight

2014-07-25 16:37:52 ----HD---- C:\Windows\ELAMBKUP

2014-07-24 15:44:58 ----D---- C:\Windows\rescache

2014-07-24 12:55:56 ----D---- C:\Windows\system32\drivers\N360x64

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1504000.00D\SYMDS64.SYS [2013-10-30 493656]

R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [2014-03-04 1148120]

R1 A2DDA;A2 Direct Disk Access Support Driver; \??\C:\EEK\RUN\a2ddax64.sys [2014-06-21 26176]

R1 BHDrvx64;BHDrvx64; \??\C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\BASHDefs\20140801.001\BHDrvx64.sys [2014-05-10 1530160]

R1 ccSet_N360;N360 Settings Manager; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [2014-02-25 162392]

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2014-06-11 486192]

R1 IDSVia64;IDSVia64; \??\C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\IPSDefs\20140813.001\IDSvia64.sys [2014-06-20 525016]

R1 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [2014-02-13 875736]

R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [2013-10-30 36952]

R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [2013-10-30 264280]

R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [2014-02-18 593112]

R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]

R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-13 13207552]

R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-13 626176]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-06-11 142128]

R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]

R3 NAVENG;NAVENG; \??\C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\VirusDefs\20140814.008\ENG64.SYS [2014-08-09 126040]

R3 NAVEX15;NAVEX15; \??\C:\Program Files (x86)\Norton 360\NortonData\21.2.0.38\Definitions\VirusDefs\20140814.008\EX64.SYS [2014-08-09 2099288]

R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT-stuurprogramma; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]

R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2014-05-23 177752]

S0 SymELAM;Symantec ELAM Driver; C:\Windows\system32\drivers\N360x64\1504000.00D\SymELAM.sys [2013-10-30 23568]

S1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys []

S3 cleanhlp;cleanhlp; \??\C:\EEK\Run\cleanhlp64.sys [2014-06-21 57024]

S3 dg_ssudbus;@oem34.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-04-11 110336]

S3 ssadbus;@oem27.inf,%SAMSUNG.Service.Desc%;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\System32\drivers\ssadbus.sys [2014-04-11 169288]

S3 ssadmdfl;@oem29.inf,%Samsung.Filter.Name%;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2014-04-11 21320]

S3 ssadmdm;@oem29.inf,%Samsung.Service.Name%;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2014-04-11 188232]

S3 ssadserd;@oem31.inf,%Samsung.Service.Name%;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2014-04-11 158024]

S3 ssudmdm;@oem37.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-04-11 206080]

S3 USBAAPL64;@oem10.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2013-03-18 54784]

S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-13 239616]

R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]

R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2014-02-07 31192]

R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]

R2 dldf_device;dldf_device; C:\Windows\SysWOW64\dldfcoms.exe [2007-06-26 1052808]

R2 dldfCATSCustConnectService;dldfCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dldfserv.exe [2007-06-26 33416]

R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [2014-06-27 265040]

R2 TBSrv;Toolbar Service; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [2014-04-10 350528]

R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]

R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]

S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-14 68608]

S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-18 116648]

S2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe -service []

S2 Update Dolphin Deals;Update Dolphin Deals; C:\Program Files (x86)\Dolphin Deals\updateDolphinDeals.exe []

S2 Update Greener Web;Update Greener Web; C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe []

S2 Util Dolphin Deals;Util Dolphin Deals; C:\Program Files (x86)\Dolphin Deals\bin\utilDolphinDeals.exe []

S2 Util Greener Web;Util Greener Web; C:\Program Files (x86)\Greener Web\bin\utilGreenerWeb.exe []

S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-06-14 1357104]

S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-14 68608]

S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-18 116648]

S3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe [2014-07-08 641352]

S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-05-07 119408]

S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]

-----------------EOF-----------------

Link naar reactie
Delen op andere sites

  • Reacties 20
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Hoi bouge,

welkom op PC-Helpforum.be.

Je topic werd verplaatst naar Bestrijding malware & virussen, zo blijft het forum overzichtelijk.

Zodra één van de malware-experts online komt gebeurt de analyse van je logje en krijg je verdere persoonlijke begeleiding.

Link naar reactie
Delen op andere sites

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  {201f27d4-3704-41d6-89c1-aa35e39143ed};c
 {66bd2442-241b-44cd-8c7a-b51037053cdb};c
 C:\Users\FM2A88\AppData\LocalLow\TVersitybar;fs
 {3041d03e-fd4b-44e0-b742-2d9b88305f98};c
 {ae07101b-46d4-4a98-af68-0333ea26e113};c
 AnyProtect Scanner;s
 C:\Program Files (x86)\AnyProtectEx;fs
 globalUpdate;s
 globalUpdatem;s
 C:\Program Files (x86)\globalUpdate;fs
 IePluginServices;s
 C:\ProgramData\IePluginServices;fs
 TBSrv;s
 C:\Program Files (x86)\Tbccint;fs
 Update Dolphin Deals;s
 Update Greener Web;s
 Util Dolphin Deals;s
 Util Greener Web;s
 C:\Program Files (x86)\Dolphin Deals;fs
 C:\Program Files (x86)\Greener Web;fs
 C:\Windows\tasks\AmiUpdXp.job;f
 C:\Windows\tasks\APSnotifierPP1.job;f 
C:\Windows\tasks\APSnotifierPP2.job;f 
C:\Windows\tasks\APSnotifierPP3.job;f 
C:\Windows\tasks\AutoKMS.job;f
 C:\Windows\AutoKMS.exe;f
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job;f
 C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job;f
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10];r64
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4];r64
 C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\extensions\[email="faststartff@gmail.com"]faststartff@gmail.com[/email];fs
 C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\extensions\jid0-c1av474BVPIHcGJfBp3GkhlhAa4@jetpack;fs
 C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\extensions\{66bd2442-241b-44cd-8c7a-b51037053cdb};fs
 C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D};fs
 C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default\searchplugins\Web Search.xml;f
 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}];r64
 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66bd2442-241b-44cd-8c7a-b51037053cdb}];r64
 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run];r64
 "fst_be_68"=-;r64
 "AnyProtect Scanner"=-;r64
 C:\Program Files (x86)\Advanced System Protector;fs
C:\Users\FM2A88\AppData\Roaming\Systweak;fs
C:\Program Files (x86)\SupTab;fs
 C:\Users\FM2A88\AppData\Roaming\OpenCandy;fs
 C:\ProgramData\IePluginServices;fs
C:\ProgramData\WindowsMangerProtect;fs
C:\ProgramData\374311380;fs
C:\Program Files (x86)\HaoZip;fs
 C:\Program Files (x86)\MyFree Codec;fs
 emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Deep Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Beste,bedankt voor uw reactie maar eigenlijk ben ik op zoek naar een manier om die domme surveys te omzeilen.Na opzoekingen op het web ben ik op deze manier uitgekomen maar weet ik nog niet hoe het moet.Misschien kan iemand mij daarmee helpen.Alvast bedankt

Link naar reactie
Delen op andere sites

Je wil die domme surveys omzeilen ? Wat wil je daar mee bedoelen ? En wil je dat doen met een volledig geïnfecteerde computer ? Of wil je dat we die eerst eens even ontdoen van alle rotzooi die je binnengehaald hebt ? Want dat is behoorlijk veel.

Om dat te kunnen doen, zou je eerst best de suggesties uit bericht 3 uitvoeren. Dat is daarvoor al een goed begin ;-)

Link naar reactie
Delen op andere sites

Dubbelklik op Zoek.exe om de tool te starten.


  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

  C:\Windows\Sysnative\Tasks\Systweak-Support-Dock;fs
 C:\Windows\Sysnative\Tasks\Update Service SimpleFiles;fs
 C:\Users\FM2A88\AppData\Roaming\DownloadManager;fs
 C:\Users\FM2A88\AppData\Roaming\SimpleFiles;fs
 C:\Users\FM2A88\AppData\Local\globalUpdate;fs
 C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308};fs
 C:\Windows\SysNative\tasks\GoforFilesUpdate;fs
 C:\Windows\SysNative\tasks\Optimizer Pro Schedule;fs
 C:\Program Files (x86)\Systweak Support Dock;fs
 C:\Program Files (x86)\SimpleFilesUpdater;fs
 C:\Windows\SysNative\tasks\YourFile DownloaderUpdate;fs
 C:\Program Files (x86)\YourFileDownloader Updater;fs
 emptyfolderscheck;delete 
startupall; 
filesrcm;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Deep Scan

  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Dubbelklik op Zoek.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

iedefaults;

  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.

Zoek.exe logbestand plaatsen

  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.