Ga naar inhoud

Aanbevolen berichten

Geplaatst:
Logfile of random's system information tool 1.10 (written by random/random)
Run by hermonneke at 2015-10-28 11:31:00
Microsoft Windows 10 Home
System drive C: has 351 GB (78%) free of 449 GB
Total RAM: 4044 MB (48% free)
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:31:02, on 28-10-2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
 
Running processes:
C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files\trend micro\hermonneke.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bing.com/search?FORM=IE8SRC&q=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: TSBHO Class - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKCU\..\Run: [Gadwin PrintScreen (64-bit)] "C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe" /nosplash
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
O4 - HKCU\..\Run: [OneDrive] "C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\RunOnce: [uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
O4 - HKCU\..\RunOnce: [uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
O4 - HKCU\..\RunOnce: [uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64"
O4 - HKCU\..\RunOnce: [uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - HP - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel® Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Online Games Manager (ogmservice) - RealNetworks, Inc. - C:\Program Files (x86)\Online Games Manager\ogmservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: SimpleSlideShowServer - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
 
--
End of file - 13649 bytes
 
======Listing Processes======
 
 
 
 
 
 
 
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
dashost.exe {c5ca8b6d-a1ae-4edf-8a5dd333880a9f9f}
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
 
"C:\Program Files (x86)\Online Games Manager\ogmservice.exe" --service-run
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
 

"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
"C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
 
winlogon.exe
"dwm.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe" /nosplash
"C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.13821.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe" -ServerName:App.AppXqagq4n4gvy0tjw576pgh6xr601s1h1mv.mca
"C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6228.10041.0_x64__8wekyb3d8bbwe\onenoteim.exe" -ServerName:microsoft.onenoteim.AppXxqb9ypsz6cs1w07e1pmjy4ww4dy9tpqr.mca
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 20FC4A33-539A-B1A1-5788-376674801FEA -Reinvoke
"C:\Program Files (x86)\Windows Live\Mail\wlmail.exe"
"C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe" -Embedding
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca
C:\WINDOWS\system32\browser_broker.exe -Embedding
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe" SCODEF:8048 CREDAT:140545 EDGEHOST  /prefetch:6
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\rsit\log.txt
"fontdrvhost.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding
 
"C:\Users\hermonneke\Downloads\RSITx64.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe36_ Global\UsGthrCtrlFltPipeMssGthrPipe36 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 624 628 636 8192 632
 
======Scheduled tasks folder======
 
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler
C:\WINDOWS\tasks\SlimDrivers Startup.job - C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe  -boot
C:\WINDOWS\tasks\User_Feed_Synchronization-{CFFA2738-98EF-4EE5-B5A4-519659D71B27}.job - C:\Windows\system32\msfeedssync.exe  sync
 
=========Mozilla firefox=========
 
ProfilePath - C:\Users\hermonneke\AppData\Roaming\Mozilla\Firefox\Profiles\gvp0nt3e.default-1424006294058
 
prefs.js - "browser.search.useDBForOrder" -  true
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
 

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll
 
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
 

======Registry dump======
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04 219304]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}]
TrueSuite Website Log On - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-08-19 1761096]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11 2340472]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-08-04 153768]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}]
TrueSuite Website Log On - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-08-19 1610056]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-09-12 1733240]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2015-06-01 183216]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2015-06-01 411056]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2015-06-01 453552]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-07-17 3944136]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2000-01-01 1703424]
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen (64-bit)"=C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe [2014-10-15 14439584]
"CCleaner"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"OneDrive"=C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-10-27 548552]
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"=C:\WINDOWS\system32\cmd.exe [2015-07-10 232448]
"Uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"=C:\WINDOWS\system32\cmd.exe [2015-07-10 232448]
"Uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64"=C:\WINDOWS\system32\cmd.exe [2015-07-10 232448]
"Uninstall C:\Users\hermonneke\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"=C:\WINDOWS\system32\cmd.exe [2015-07-10 232448]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2015-06-01 451584]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"aux1"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
 
======File associations======
 
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
 
======List of files/folders created in the last 1 month======
 
2015-10-28 10:40:29 ----D---- C:\Program Files\trend micro
2015-10-28 10:40:28 ----D---- C:\rsit
2015-10-26 19:48:19 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-26 19:48:13 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-26 15:05:45 ----D---- C:\Program Files (x86)\Detective Quest - Het Glazen Muiltje
2015-10-24 21:34:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-10-24 21:34:18 ----A---- C:\WINDOWS\system32\edgehtml.dll
2015-10-24 21:34:16 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-10-24 21:34:12 ----A---- C:\WINDOWS\system32\shell32.dll
2015-10-24 21:34:11 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-24 21:34:09 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-10-24 21:34:07 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2015-10-24 21:34:06 ----A---- C:\WINDOWS\system32\BingMaps.dll
2015-10-24 21:34:05 ----A---- C:\WINDOWS\system32\windows.storage.dll
2015-10-24 21:34:04 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-10-24 21:34:02 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-10-24 21:34:01 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-10-24 21:34:00 ----A---- C:\WINDOWS\system32\mos.dll
2015-10-24 21:33:58 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2015-10-24 21:33:57 ----A---- C:\WINDOWS\system32\Chakra.dll
2015-10-24 21:33:56 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-10-24 21:33:54 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2015-10-24 21:33:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2015-10-24 21:33:51 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-24 21:33:51 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-24 21:33:48 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2015-10-24 21:33:47 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2015-10-24 21:33:47 ----A---- C:\WINDOWS\system32\mfcore.dll
2015-10-24 21:33:46 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-10-24 21:33:45 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-24 21:33:45 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-24 21:33:44 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2015-10-24 21:33:44 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-24 21:33:43 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2015-10-24 21:33:42 ----A---- C:\WINDOWS\system32\wininet.dll
2015-10-24 21:33:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2015-10-24 21:33:41 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-10-24 21:33:38 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-10-24 21:33:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2015-10-24 21:33:34 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2015-10-24 21:33:33 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-10-24 21:33:33 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-10-24 21:33:33 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2015-10-24 21:33:32 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2015-10-24 21:33:32 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2015-10-24 21:33:31 ----A---- C:\WINDOWS\system32\wlansvc.dll
2015-10-24 21:33:30 ----A---- C:\WINDOWS\system32\winmde.dll
2015-10-24 21:33:30 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-10-24 21:33:29 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2015-10-24 21:33:29 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-24 21:33:29 ----A---- C:\WINDOWS\system32\UserDataService.dll
2015-10-24 21:33:29 ----A---- C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-24 21:33:28 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-10-24 21:33:28 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2015-10-24 21:33:28 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-24 21:33:27 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-24 21:33:27 ----A---- C:\WINDOWS\system32\Unistore.dll
2015-10-24 21:33:27 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-24 21:33:25 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2015-10-24 21:33:25 ----A---- C:\WINDOWS\system32\wwansvc.dll
2015-10-24 21:33:25 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-24 21:33:25 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\SYSWOW64\RemoteNaturalLanguage.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2015-10-24 21:33:24 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-10-24 21:33:23 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-10-24 21:33:23 ----A---- C:\WINDOWS\system32\mfsvr.dll
2015-10-24 21:33:23 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-24 21:33:22 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2015-10-24 21:33:22 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2015-10-24 21:33:22 ----A---- C:\WINDOWS\system32\RDXService.dll
2015-10-24 21:33:22 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2015-10-24 21:33:22 ----A---- C:\WINDOWS\system32\esent.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\system32\wpx.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\system32\ContactApis.dll
2015-10-24 21:33:21 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-24 21:33:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2015-10-24 21:33:20 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2015-10-24 21:33:20 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-10-24 21:33:20 ----A---- C:\WINDOWS\system32\jscript.dll
2015-10-24 21:33:20 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2015-10-24 21:33:19 ----A---- C:\WINDOWS\system32\mfds.dll
2015-10-24 21:33:18 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2015-10-24 21:33:18 ----A---- C:\WINDOWS\system32\winload.exe
2015-10-24 21:33:18 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2015-10-24 21:33:17 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2015-10-24 21:33:17 ----A---- C:\WINDOWS\system32\bisrv.dll
2015-10-24 21:33:16 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2015-10-24 21:33:16 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2015-10-24 21:33:16 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2015-10-24 21:33:16 ----A---- C:\WINDOWS\system32\drivers\Wdf01000.sys
2015-10-24 21:33:15 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2015-10-24 21:33:15 ----A---- C:\WINDOWS\system32\directmanipulation.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\system32\NotificationController.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2015-10-24 21:33:14 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-24 21:33:13 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2015-10-24 21:33:13 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2015-10-24 21:33:13 ----A---- C:\WINDOWS\SYSWOW64\directmanipulation.dll
2015-10-24 21:33:13 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-24 21:33:13 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-24 21:33:12 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2015-10-24 21:33:12 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-10-24 21:33:12 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-24 21:33:12 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-10-24 21:33:12 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2015-10-24 21:33:11 ----A---- C:\WINDOWS\system32\ChatApis.dll
2015-10-24 21:33:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-24 21:33:10 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2015-10-24 21:33:10 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-10-24 21:33:10 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-10-24 21:33:10 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2015-10-24 21:33:10 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-10-24 21:33:09 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2015-10-24 21:33:09 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2015-10-24 21:33:09 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2015-10-24 21:33:09 ----A---- C:\WINDOWS\system32\winresume.exe
2015-10-24 21:33:09 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-10-24 21:33:09 ----A---- C:\WINDOWS\system32\LockAppBroker.dll
2015-10-24 21:33:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-10-24 21:33:08 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2015-10-24 21:33:08 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-24 21:33:08 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-24 21:33:08 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2015-10-24 21:33:08 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-24 21:33:07 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2015-10-24 21:33:07 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2015-10-24 21:33:07 ----A---- C:\WINDOWS\system32\winlogon.exe
2015-10-24 21:33:06 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\ncsi.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\drivers\fastfat.sys
2015-10-24 21:33:06 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2015-10-24 21:33:05 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\mf.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\EmailApis.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2015-10-24 21:33:05 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-24 21:33:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-24 21:33:04 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2015-10-24 21:33:04 ----A---- C:\WINDOWS\system32\provengine.dll
2015-10-24 21:33:04 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\wwanconn.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\wuuhext.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\WUDFx02000.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\psmsrv.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\ngccredprov.dll
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2015-10-24 21:33:03 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\pnidui.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\MapsStore.dll
2015-10-24 21:33:02 ----A---- C:\WINDOWS\system32\cloudAP.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\omadmclient.exe
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\ncryptprov.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\mfps.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2015-10-24 21:33:01 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\SYSWOW64\ncryptprov.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\wwanmm.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-10-24 21:33:00 ----A---- C:\WINDOWS\system32\drivers\buttonconverter.sys
2015-10-24 21:32:59 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\SYSWOW64\PhoneCallHistoryApis.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\omadmapi.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\ngckeyenum.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-24 21:32:59 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-10-24 21:32:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Speech.Pal.dll
2015-10-24 21:32:58 ----A---- C:\WINDOWS\system32\syncutil.dll
2015-10-24 21:32:58 ----A---- C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-24 21:32:58 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2015-10-24 21:32:57 ----A---- C:\WINDOWS\system32\wwancfg.dll
2015-10-24 21:32:57 ----A---- C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-24 21:32:57 ----A---- C:\WINDOWS\system32\LocationGeofences.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\wpnapps.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\netcenter.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-24 21:32:56 ----A---- C:\WINDOWS\system32\AudioEng.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\SYSWOW64\CallHistoryClient.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\system32\LocationPeIP.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-24 21:32:55 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2015-10-24 21:32:54 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2015-10-24 21:32:54 ----A---- C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-24 21:32:54 ----A---- C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-24 21:32:54 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2015-10-24 21:32:54 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2015-10-24 21:32:53 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2015-10-24 21:32:53 ----A---- C:\WINDOWS\SYSWOW64\netcenter.dll
2015-10-24 21:32:53 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2015-10-24 21:32:53 ----A---- C:\WINDOWS\system32\provops.dll
2015-10-24 21:32:53 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-24 21:32:52 ----A---- C:\WINDOWS\system32\nlasvc.dll
2015-10-24 21:32:52 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\LocationPeCell.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\dmcsps.dll
2015-10-24 21:32:50 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2015-10-24 21:32:49 ----A---- C:\WINDOWS\system32\syncmlhook.dll
2015-10-24 21:32:49 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2015-10-24 21:32:49 ----A---- C:\WINDOWS\system32\configmanager2.dll
2015-10-24 21:07:38 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-24 19:06:04 ----D---- C:\WINDOWS\PCHEALTH
2015-10-09 15:53:00 ----D---- C:\Program Files (x86)\Enchanted Cavern 2
2015-10-08 14:09:18 ----D---- C:\$SysReset
2015-10-07 21:56:42 ----D---- C:\Program Files (x86)\The Rise of Atlantis
2015-10-07 12:35:32 ----D---- C:\Program Files (x86)\ESET
 
======List of files/folders modified in the last 1 month======
 
2015-10-28 11:27:41 ----D---- C:\WINDOWS\Prefetch
2015-10-28 11:22:35 ----D---- C:\WINDOWS\Temp
2015-10-28 11:08:01 ----D---- C:\WINDOWS\system32\sru
2015-10-28 11:07:10 ----D---- C:\Program Files (x86)\Google
2015-10-28 10:40:29 ----RD---- C:\Program Files
2015-10-28 10:35:00 ----D---- C:\WINDOWS\Microsoft.NET
2015-10-28 10:26:57 ----D---- C:\WINDOWS\system32\config
2015-10-28 10:24:56 ----D---- C:\WINDOWS\System32
2015-10-27 20:55:59 ----HD---- C:\OneDriveTemp
2015-10-27 20:45:37 ----D---- C:\WINDOWS\AppReadiness
2015-10-27 18:57:37 ----SHD---- C:\WINDOWS\Installer
2015-10-27 18:55:59 ----D---- C:\WINDOWS\SysWOW64
2015-10-27 18:55:56 ----D---- C:\WINDOWS\system32\Tasks
2015-10-27 18:50:20 ----HD---- C:\Program Files\WindowsApps
2015-10-26 19:48:19 ----RD---- C:\Program Files (x86)
2015-10-26 19:44:55 ----HD---- C:\ProgramData
2015-10-26 19:21:08 ----D---- C:\WINDOWS\INF
2015-10-26 19:21:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-26 15:34:20 ----AD---- C:\ProgramData\Temp
2015-10-26 15:00:33 ----D---- C:\BigFishCache
2015-10-24 22:49:08 ----D---- C:\Users\hermonneke\AppData\Roaming\vlc
2015-10-24 22:03:46 ----D---- C:\WINDOWS\WinSxS
2015-10-24 22:02:05 ----D---- C:\WINDOWS\system32\drivers
2015-10-24 21:59:50 ----SD---- C:\WINDOWS\SYSWOW64\F12
2015-10-24 21:59:50 ----D---- C:\WINDOWS\SYSWOW64\migration
2015-10-24 21:59:43 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2015-10-24 21:59:43 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2015-10-24 21:59:42 ----SD---- C:\WINDOWS\system32\F12
2015-10-24 21:59:42 ----D---- C:\WINDOWS\system32\migration
2015-10-24 21:59:42 ----D---- C:\WINDOWS\system32\Boot
2015-10-24 21:59:42 ----D---- C:\WINDOWS\system32\appraiser
2015-10-24 21:59:34 ----RD---- C:\WINDOWS\PurchaseDialog
2015-10-24 21:59:34 ----D---- C:\WINDOWS\Provisioning
2015-10-24 21:59:31 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-10-24 21:59:31 ----D---- C:\WINDOWS\L2Schemas
2015-10-24 21:59:31 ----D---- C:\WINDOWS\AppPatch
2015-10-24 21:59:29 ----D---- C:\WINDOWS\system32\DriverStore
2015-10-24 21:57:39 ----D---- C:\ProgramData\Microsoft Help
2015-10-24 21:57:18 ----D---- C:\WINDOWS\CbsTemp
2015-10-24 21:53:40 ----D---- C:\WINDOWS\system32\MRT
2015-10-24 21:45:40 ----A---- C:\WINDOWS\system32\MRT.exe
2015-10-24 21:27:23 ----D---- C:\WINDOWS\system32\catroot2
2015-10-24 21:05:59 ----D---- C:\WINDOWS\system32\wbem
2015-10-24 21:05:14 ----D---- C:\Program Files\Windows Defender
2015-10-24 21:04:51 ----D---- C:\Windows
2015-10-24 21:01:50 ----D---- C:\WINDOWS\Tasks
2015-10-24 21:01:39 ----D---- C:\WINDOWS\SYSWOW64\WinMetadata
2015-10-24 21:01:39 ----D---- C:\WINDOWS\SYSWOW64\wbem
2015-10-24 21:01:35 ----SD---- C:\WINDOWS\system32\Nui
2015-10-24 21:01:35 ----D---- C:\WINDOWS\system32\WinMetadata
2015-10-24 21:01:35 ----D---- C:\WINDOWS\system32\oobe
2015-10-24 21:01:35 ----D---- C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-24 21:01:34 ----RSD---- C:\WINDOWS\Media
2015-10-24 21:01:26 ----D---- C:\WINDOWS\IME
2015-10-24 21:01:15 ----D---- C:\Zylom Games
2015-10-24 21:01:15 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-24 21:00:33 ----D---- C:\WINDOWS\system32\Sysprep
2015-10-24 21:00:33 ----D---- C:\WINDOWS\System
2015-10-24 21:00:28 ----D---- C:\WINDOWS\rescache
2015-10-24 21:00:28 ----D---- C:\WINDOWS\nl
2015-10-24 20:57:59 ----D---- C:\ProgramData\panda_url_filtering
2015-10-24 20:57:43 ----D---- C:\ProgramData\Hewlett-Packard
2015-10-24 20:57:07 ----D---- C:\Program Files\Windows Live
2015-10-24 20:57:07 ----D---- C:\Program Files\Common Files\microsoft shared
2015-10-24 20:57:00 ----D---- C:\Program Files (x86)\Windows Live
2015-10-24 20:56:56 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-24 20:56:56 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-24 20:56:56 ----D---- C:\Program Files (x86)\Jewel Quest - The Sleepless Star
2015-10-24 20:56:54 ----D---- C:\Program Files (x86)\Hawaiian Explorer - Lost Island
2015-10-24 20:56:53 ----D---- C:\Program Files (x86)\Fierce Tales - Een Hondenleven
2015-10-24 20:56:53 ----D---- C:\Program Files (x86)\Dreamsdwell Stories
2015-10-24 20:56:52 ----D---- C:\Program Files (x86)\Denda Games
2015-10-24 20:56:51 ----D---- C:\Program Files (x86)\Big City Adventure - New York
2015-10-24 20:56:51 ----D---- C:\Program Files (x86)\Akhra - The Treasures
2015-10-24 20:32:17 ----D---- C:\WINDOWS\registration
2015-10-24 20:24:49 ----D---- C:\WINDOWS\ServiceProfiles
2015-10-24 20:18:49 ----RSD---- C:\WINDOWS\assembly
2015-10-24 19:59:47 ----D---- C:\ProgramData\Panda Security
2015-10-24 19:55:41 ----D---- C:\Program Files (x86)\Panda Security
2015-10-24 19:53:05 ----RHD---- C:\MSOCache
2015-10-24 19:46:45 ----SHD---- C:\System Volume Information
2015-10-22 13:59:30 ----D---- C:\WINDOWS\Logs
2015-10-22 13:01:48 ----D---- C:\WINDOWS\system32\LogFiles
2015-10-21 15:40:26 ----D---- C:\WINDOWS\SoftwareDistribution
2015-10-21 15:32:35 ----D---- C:\WINDOWS\debug
2015-10-19 22:45:13 ----D---- C:\WINDOWS\ModemLogs
2015-10-19 20:04:46 ----D---- C:\Users\hermonneke\AppData\Roaming\dvdcss
2015-10-19 19:50:22 ----D---- C:\WINDOWS\system32\log
2015-10-19 19:33:21 ----D---- C:\AdwCleaner
2015-10-16 04:10:46 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
 
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
 
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-11-08 632168]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R1 NNSNAHSL;@oem1.inf,%NNSNAHSL_Desc%;Network Activity Hook Server LightWeight Filter Driver; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [2014-12-31 48400]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 clwvd;@oem0.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-06-01 5384176]
R3 IntcDAud;@oem15.inf,%IntcDAud.SvcDesc%;Intel® Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2011-12-21 317440]
R3 MEIx64;@oem19.inf,%TEE_SvcDesc%;Intel® Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-10-10 129312]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-07-29 175104]
R3 netr28x;@oem35.inf,%Generic.Service.DispName%;Ralink 802.11n Extensible Wireless Driver; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2015-06-12 2554528]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-07-10 587264]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2015-07-17 42696]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10305; C:\WINDOWS\system32\DRIVERS\stwrt64.sys [2000-01-01 550912]
R3 SynTP;@oem32.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-07-17 614088]
S0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-09-17 36352]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-07-10 116736]
S3 DrvAgent64;DrvAgent64; \??\C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS [2014-11-24 20872]
S3 fcvsc;fcvsc; C:\WINDOWS\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-07-29 934752]
S3 RSPCIESTOR;@oem42.inf,%Rts5208%;Realtek PCIE CardReader Driver; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys [2015-07-29 374016]
S3 SWDUMon;SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [2015-09-28 16152]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-07-29 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
 
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
 
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-09-14 82128]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-09-11 2774104]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2015-09-06 349728]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-08 15720]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2014-10-10 409376]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-07-29 26112]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
R2 ogmservice;Online Games Manager; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [2014-03-27 581568]
R2 OneSyncSvc_Session10;Host synchroniseren_Session10; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2000-01-01 333824]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-07-17 246472]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-06-17 43696]
R3 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2015-05-19 99128]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 PimIndexMaintenanceSvc_Session10;Contact Data_Session10; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 UnistoreSvc_Session10;User Data Storage_Session10; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-07-10 135848]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc_Session15;Host synchroniseren_Session15; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc_Session16;Host synchroniseren_Session16; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-19 268976]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-07-10 50352]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 cphs;Intel® Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-06-01 290224]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 FPLService;TrueSuiteService; C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-08-19 260424]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2015-09-06 209952]
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 HPAuto;HP Auto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-16 682040]
S3 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
S3 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S3 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-07-11 26680]
S3 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-09-01 2425960]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2006-11-10 99936]
S3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-05-13 887256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-15 147624]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\lsass.exe [2015-07-10 56344]
S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-07 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-07-07 5132888]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session15;Contact Data_Session15; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 PimIndexMaintenanceSvc_Session16;Contact Data_Session16; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 SamsungAllShareV2.0;Samsung AllShare PC; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [2012-03-02 25504]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-07-29 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [2012-03-02 27584]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session15;User Data Storage_Session15; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc_Session16;User Data Storage_Session16; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
 
-----------------EOF-----------------

Clarkie ik gebruik 64bit versie en windows firewall + windows defender de bestand grote van skisprong 2.90 MB

Geplaatst:

Schakel eerst de Antivirussoftware uit voordat je zoek.exe download of uitvoert.

Schakel je antivirus- en antispywareprogramma's tijdelijk uit, deze kunnen namelijk de werking van Zoek.exe nadelig beïnvloeden.

(hier en hier) kan je lezen hoe je dat doet.

Download 51a612a8b27e2-Zoek.pngZoek.exe naar het bureaublad (klik hier voor meer informatie over hoe zoek.exe te gebruiken)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kan je dat negeren, het is namelijk een onterechte waarschuwing.
  • Dubbelklik vervolgens op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze Computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.

    emptyfolderscheck;delete
    firefoxlook; 
    Chromelook; 
    CHRdefaults;
    autoclean; 
    iedefaults; 
    
    
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.
Geplaatst:

Download AdwCleaner by Xplode naar het bureaublad (verwijder eerst eventuele aanwezige oudere versies van deze tool op je PC, zodat je nu de meest recente database van AdwCleaner kan gebruiken).

Als de link naar AdwCleaner niet werkt, probeer dan deze link.

De download start automatisch na enkele seconden.

  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner om hem te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren,
  • Door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik op Scan (Engelse versie) of Scannen (Nederlandstalige versie)
  • Mocht u gevonden items willen behouden, verwijder deze dan nu uit het lijstje.
  • Klik vervolgens op Clean (Engelse versie) of Verwijderen (Nederlandstalige versie)
  • Klik bij popup-scherm "AdwCleaner Herstart" op OK


Nadat de PC opnieuw is opgestart, opent meestal onmiddellijk een logfile van AdwCleaner.
Anders is het logfile hier terug te vinden C:\AdwCleaner\AdwCleaner[s0].txt.

Logbestand plaatsen

  • Voeg het logbestand met de naam C:\AdwCleaner\AdwCleaner[s0].txt als bijlage toe aan het volgende bericht.
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.


Meer informatie vind je in de handleiding.

Geplaatst:

juisterr ik denk dat ik me gaan ophangen want er is niks veranderd ik heb naar twee personen gemaild in Bcc en ze ontvingen het 7 maal ja het is wel geen 20 keer meer maar ik weet niet of dat verschil maakt. en als ik in aan verstuur is alles normaal. Sorry groetjes mon


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.