Hallo,
Sinds enige tijd heb ik een nogal irritante browser hijack. Mijn systeem is voorzien van Windows 10. En de highjack vind plaats op Microsoft Edge. Spontane opstart van Edge en maar sites blijven openen.
Hopelijk kunnen jullie mij helpen om hier van af te komen.
Logs:
Malwarebytes
-Logboekdetails-
Scandatum: 01-06-17
Scantijd: 18:42
Logbestand: Malware.txt
Beheerder: Ja
-Software-informatie-
Versie: 3.1.2.1733
Versie componenten: 1.0.122
Update pakketversie: 1.0.2066
Licentie: Proef
-Systeeminformatie-
Besturingssysteem: Windows 10
Processor: x86
Bestandssysteem: NTFS
Gebruiker: FERRY-PC\Ferry
-Scansamenvatting-
Scantype: Aangepaste scan
Resultaat: Voltooid
Objecten gescand: 234092
Dreigingen herkend: 2
Dreigingen in quarantaine: 0
(Geen kwaadaardige items gedetecteerd)
Verstreken tijd: 27 min, 21 sec
-Scanopties-
Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Ingeschakeld
Heuristiek: Ingeschakeld
POP: Ingeschakeld
POA: Ingeschakeld
-Scandetails-
Proces: 0
(Geen kwaadaardige items gedetecteerd)
Module: 0
(Geen kwaadaardige items gedetecteerd)
Registersleutel: 1
PUP.Optional.OtherSearch, HKLM\SOFTWARE\OTHERSEARCH, Geen actie door gebruiker, [570], [305744],1.0.2066
Registerwaarde: 1
PUP.Optional.OtherSearch, HKLM\SOFTWARE\OTHERSEARCH|AFFID, Geen actie door gebruiker, [570], [305744],1.0.2066
Registerdata: 0
(Geen kwaadaardige items gedetecteerd)
Gegevensstroom: 0
(Geen kwaadaardige items gedetecteerd)
Map: 0
(Geen kwaadaardige items gedetecteerd)
Bestand: 0
(Geen kwaadaardige items gedetecteerd)
Fysieke sector: 0
(Geen kwaadaardige items gedetecteerd)
(end)
# AdwCleaner v6.047 - Logbestand aangemaakt 31/05/2017 op 21:55:59
# Bijgewerkt op 19/05/2017 door Malwarebytes
# Database : 2017-05-31.2 [Server]
# Besturingssysteem : Windows 10 Pro (X86)
# Gebruikersnaam : Ferry - FERRY-PC
# Gestart vanuit : C:\Users\Ferry\Desktop\adwcleaner_6.047.exe
# Mode: Verwijderen
# Ondersteuning : https://www.malwarebytes.com/support
***** [ Services ] *****
[-] Service verwijderd: 78080d72ebecfb1ef52e642e894a2a85
***** [ Mappen ] *****
[-] Map verwijderd: C:\ProgramData\d61181ac
[-] Map verwijderd: C:\Users\Ferry\AppData\Local\DriverToolkit
[-] Map verwijderd: C:\Program Files\DriverToolkit
[-] Map verwijderd: C:\WINDOWS\system32\SSL
[-] Map verwijderd: C:\WINDOWS\system32\sstmp
***** [ Bestanden ] *****
[-] Bestand verwijderd: C:\END
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Snelkoppelingen ] *****
***** [ Geplande Taken ] *****
***** [ Register ] *****
[-] Sleutel verwijderd: HKU\S-1-5-21-3829025451-3821063052-892049231-1000\Software\DriverToolkit
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\DriverToolkit
[-] Sleutel verwijderd: HKLM\SOFTWARE\OtherSearch
[-] Sleutel verwijderd: HKLM\SOFTWARE\HDWallpaper
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchy
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{24F5E422-6A70-4FAA-8CAD-E23D5DC1DAE6}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD0688A5-FC8B-4E93-A485-CBF606A56D49}
***** [ Browsers ] *****
*************************
:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [1844 bytes] - [31/05/2017 21:55:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [2090 bytes] - [31/05/2017 21:54:36]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1990 bytes] ##########
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.14393.953 BrowserJavaVersion: 11.131.2
Run by Ferry at 19:41:29 on 2017-06-01
Microsoft Windows 10 Pro 10.0.14393.0.1252.31.1043.18.2795.1406 [GMT 2:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\WINDOWS\system32\dwm.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\LPlatSvc.exe
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\system32\DbxSvc.exe
C:\Windows\system32\IProsetMonitor.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\PDF Architect 5\creator-ws.exe
C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\LPlatSvc.exe
C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\igfxHK.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x86__kzf8qxf38zg5c\SkypeHost.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\WINDOWS\system32\backgroundTaskHost.exe
C:\Windows\System32\smartscreen.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Users\Ferry\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Users\Ferry\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\anh0swlnxgf\CIOO9.exe
C:\Users\Ferry\AppData\Roaming\fm3opukxynd\puaa42sy5x1.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Users\Ferry\AppData\Roaming\n2m4q5rpn0v\lj1cbu1fph2.exe
C:\Users\Ferry\AppData\Roaming\33bmswoton4\3vaaspwaidr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\conhost.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.nl/?gws_rd=ssl#spf=1
BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft office\office15\OCHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_131\bin\ssv.dll
BHO: PDF Architect 5 Helper: {AEA429F3-D2D4-4BD7-A03E-5357DA017733} - c:\program files\pdf architect 5\creator-ie-helper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_131\bin\jp2ssv.dll
TB: PDF Architect 5 Toolbar: {84F23192-A475-4038-B5C0-8584777F2DF4} - c:\program files\pdf architect 5\creator-ie-plugin.dll
uRun: [Spotify Web Helper] "c:\users\ferry\appdata\roaming\spotify\SpotifyWebHelper.exe"
uRun: [Spotify] "c:\users\ferry\appdata\roaming\spotify\Spotify.exe" -autostart -minimized
uRun: [OneDrive] "c:\users\ferry\appdata\local\microsoft\onedrive\OneDrive.exe" /background
uRun: [8EE24K5NBNZO3HE] "c:\program files\anh0swlnxgf\CIOO9.exe"
uRun: [bevu12jntao] "c:\users\ferry\appdata\roaming\fm3opukxynd\puaa42sy5x1.exe"
uRun: [0mtodjqiczj] "c:\users\ferry\appdata\roaming\n2m4q5rpn0v\lj1cbu1fph2.exe"
uRun: [im3zen13k3j] "c:\users\ferry\appdata\roaming\33bmswoton4\3vaaspwaidr.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [NvBackend] "c:\program files\nvidia corporation\update core\NvBackend.exe"
mRun: [WindowsDefender] "c:\program files\windows defender\MSASCuiL.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Dropbox] "c:\program files\dropbox\client\Dropbox.exe" /systemstartup
mRun: [Malwarebytes TrayApp] c:\program files\malwarebytes\anti-malware\mbamtray.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~1\office15\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft office\office15\OCHelper.dll
TCP: NameServer = 8.8.8.8
TCP: NameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{17950864-ab99-40c9-b4bc-0a87ce715196} : NameServer = 8.8.8.8
TCP: Interfaces\{1db48f5d-0bf7-483d-b541-50ca7008a005} : NameServer = 8.8.8.8
TCP: Interfaces\{3092c383-4821-4602-8425-b9972eb0f733} : NameServer = 8.8.8.8
TCP: Interfaces\{3092c383-4821-4602-8425-b9972eb0f733} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{6b39583d-7e5b-45b8-95ab-d8839ce64e90} : NameServer = 8.8.8.8
TCP: Interfaces\{6b39583d-7e5b-45b8-95ab-d8839ce64e90} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1} : NameServer = 8.8.8.8
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1} : DHCPNameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1}\A5967676F673931353 : DHCPNameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{9fc70b0f-5430-4ab4-bc95-0dbf04c67c86} : NameServer = 8.8.8.8
TCP: Interfaces\{9fc70b0f-5430-4ab4-bc95-0dbf04c67c86} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{bc315126-0b65-11e7-9e6d-806e6f6e6963} : NameServer = 8.8.8.8
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - c:\program files\microsoft office\office15\MSOSB.DLL
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
AppInit_DLLs= c:\windows\system32\nvinit.dll
SSODL: WebCheck - <orphaned>
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\58.0.3029.110\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - c:\windows\system32\windows.storage.dll
.
============= SERVICES / DRIVERS ===============
.
R?2 dbupdate;Dropbox-update-service (dbupdate);c:\program files\dropbox\update\DropboxUpdate.exe [2017-5-20 143144]
R0 intelpep;Stuurprogramma voor Intel(R) Power Engine-invoegtoepassing ;c:\windows\system32\drivers\intelpep.sys [2016-7-16 42520]
R0 iorate;iorate;c:\windows\system32\drivers\iorate.sys [2017-3-18 42336]
R0 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2017-5-31 220088]
R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2016-9-12 53296]
R0 volume;Volumestuurprogramma;c:\windows\system32\drivers\volume.sys [2016-7-16 14176]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;c:\windows\system32\drivers\WindowsTrustedRT.sys [2016-7-16 86040]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;c:\windows\system32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 15384]
R0 Wof;Windows Overlay File System Filter Driver;c:\windows\system32\drivers\wof.sys [2017-3-18 173408]
R1 ahcache;Application Compatibility Cache;c:\windows\system32\drivers\ahcache.sys [2017-3-18 188928]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\windows\system32\drivers\mbae.sys [2017-5-31 59904]
R1 FileCrypt;FileCrypt;c:\windows\system32\drivers\filecrypt.sys [2016-7-16 77312]
R1 GpuEnergyDrv;GPU Energy Driver;c:\windows\system32\drivers\gpuenergydrv.sys [2016-7-16 7680]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2017-1-31 143776]
R2 BcmBtRSupport;Bluetooth Driver Management Service;c:\windows\system32\BtwRSupportService.exe [2015-3-27 1677016]
R2 CDPSvc;Service Platform voor verbonden apparaten;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
R2 CDPUserSvc_35d4f;CDPUserSvc_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 clreg;Virtual Registry for Containers;c:\windows\system32\drivers\registry.sys [2016-7-16 58368]
R2 CoreMessagingRegistrar;CoreMessaging;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 38792]
R2 DbxSvc;DbxSvc;c:\windows\system32\DbxSvc.exe [2017-5-30 42288]
R2 DiagTrack;Connected User Experiences and Telemetry;c:\windows\system32\svchost.exe -k utcsvc [2016-7-16 38792]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe [2016-5-4 292832]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2017-2-10 401984]
R2 LPlatSvc;Lenovo Platform Service;c:\windows\system32\LPlatSvc.exe [2016-11-1 694360]
R2 MBAMChameleon;MBAMChameleon;c:\windows\system32\drivers\MBAMChameleon.sys [2017-5-31 161720]
R2 MBAMService;Malwarebytes Service;c:\program files\malwarebytes\anti-malware\MBAMService.exe [2017-5-31 3398608]
R2 MessagingService_35d4f;MessagingService_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\nvidia corporation\display.nvcontainer\NVDisplay.Container.exe [2017-3-17 421944]
R2 OneSyncSvc_35d4f;Host synchroniseren_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 PDF Architect 5 Creator;PDF Architect 5 Creator;c:\program files\pdf architect 5\creator-ws.exe [2017-2-10 778640]
R2 PDF Architect 5 Manager;PDF Architect 5 Manager;c:\programdata\pdfforge\pdf architect 5 manager\pdf architect 5\Architect Manager.exe [2017-2-28 985904]
R2 SmsRouter;Microsoft Windows SMS Router-service.;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R2 storqosflt;Storage QoS Filter Driver;c:\windows\system32\drivers\storqosflt.sys [2016-7-16 62976]
R2 SynTPEnhService;SynTPEnh Caller Service;c:\program files\synaptics\syntp\SynTPEnhService.exe [2016-1-8 228960]
R2 tiledatamodelsvc;Tile Data model server;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R2 UserManager;User Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R2 wcifs;Windows Container Isolation;c:\windows\system32\drivers\wcifs.sys [2017-3-18 95072]
R2 wcnfs;Windows Container Name Virtualization;c:\windows\system32\drivers\wcnfs.sys [2016-7-16 52736]
R2 WpnService;Systeemservice voor Windows Push Notifications;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R3 AppXSvc;AppX Deployment Service (AppXSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2015-3-27 177280]
R3 BthLEEnum;Bluetooth Low Energy-stuurprogramma;c:\windows\system32\drivers\BthLEEnum.sys [2017-5-9 203776]
R3 ClipSVC;Client License Service (ClipSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
R3 iwdbus;IWD Bus Enumerator;c:\windows\system32\drivers\iwdbus.sys [2015-12-1 35320]
R3 LenovoRd;LenovoRd;c:\windows\system32\drivers\LenovoRd.sys [2012-12-6 96768]
R3 LicenseManager;Service voor Windows-licentiebeheer ;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
R3 MBAMFarflt;MBAMFarflt;c:\windows\system32\drivers\farflt.sys [2017-5-31 97208]
R3 MBAMProtection;MBAMProtection;c:\windows\system32\drivers\mbam.sys [2017-5-31 39360]
R3 MBAMWebProtection;MBAMWebProtection;c:\windows\system32\drivers\mwac.sys [2017-5-31 74680]
R3 MbmUsbSerial;MBM USB Generic Serial Driver svc;c:\windows\system32\drivers\MbmUsbSerial.sys [2015-6-30 70128]
R3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2012-7-17 55104]
R3 MkBusFilter;MbmFilter Service;c:\windows\system32\drivers\MbmDeviceFilter.sys [2015-6-30 38072]
R3 NcbService;Network Connection Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;c:\windows\system32\drivers\NdisVirtualBus.sys [2016-7-16 15872]
R3 NETwNe32;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 32 Bit;c:\windows\system32\drivers\NETwen01.sys [2016-7-16 2670592]
R3 NgcCtnrSvc;Microsoft Passport Container;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
R3 NgcSvc;Microsoft Passport;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R3 PimIndexMaintenanceSvc_35d4f;Contact Data_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 RCUVCAVS;Ricoh UVC AVStream driver;c:\windows\system32\drivers\RCUVCAVS.sys [2013-7-2 97280]
R3 risdxc;risdxc;c:\windows\system32\drivers\risdxc86.sys [2013-9-8 79360]
R3 StateRepository;State Repository Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R3 TimeBrokerSvc;Time Broker;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
R3 UnistoreSvc_35d4f;User Data Storage_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 UserDataSvc_35d4f;User Data Access_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 UsoSvc;Update Orchestrator Service for Windows Update;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R3 WdNisDrv;Windows Defender Network Inspection System Driver;c:\windows\system32\drivers\WdNisDrv.sys [2016-7-16 100192]
R3 WdNisSvc;Windows Defender Network Inspection Service;c:\program files\windows defender\NisSrv.exe [2017-5-9 271488]
R3 wmbclass;Stuurprogramma voor USB-versie van mobiele breedbandadapter;c:\windows\system32\drivers\wmbclass.sys [2017-5-9 254464]
S2 dmwappushservice;dmwappushsvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S2 DoSvc;Delivery Optimization;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S2 MapsBroker;Downloaded Maps Manager;c:\windows\system32\svchost.exe -k NetworkService [2016-7-16 38792]
S3 AcpiDev;Stuurprogramma voor ACPI-apparaten;c:\windows\system32\drivers\AcpiDev.sys [2016-7-16 12800]
S3 ADP80XX;ADP80XX;c:\windows\system32\drivers\adp80xx.sys [2016-7-16 1038176]
S3 AJRouter;AllJoyn Router Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 applockerfltr;Smartlocker Filter Driver;c:\windows\system32\drivers\applockerfltr.sys [2016-7-16 12288]
S3 AppReadiness;App Readiness;c:\windows\system32\svchost.exe -k AppReadiness [2016-7-16 38792]
S3 AppvStrm;AppvStrm;c:\windows\system32\drivers\AppVStrm.sys [2017-3-18 94560]
S3 AppvVemgr;AppvVemgr;c:\windows\system32\drivers\AppvVemgr.sys [2016-7-16 118112]
S3 AppvVfs;AppvVfs;c:\windows\system32\drivers\AppvVfs.sys [2016-7-16 111456]
S3 bcmfn;bcmfn Service;c:\windows\system32\drivers\bcmfn.sys [2016-7-16 8192]
S3 bcmfn2;bcmfn2 Service;c:\windows\system32\drivers\bcmfn2.sys [2016-7-16 8192]
S3 BthHFSrv;Bluetooth Handsfree Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 38792]
S3 btwampfl;btwampfl;c:\windows\system32\drivers\btwampfl.sys [2015-3-27 162560]
S3 buttonconverter;Service voor Portable Device Control-apparaten;c:\windows\system32\drivers\buttonconverter.sys [2016-7-16 27648]
S3 CapImg;HID-stuurprogramma voor CapImg-touchscreen;c:\windows\system32\drivers\capimg.sys [2017-3-18 97792]
S3 dbupdatem;Dropbox-update-service (dbupdatem);c:\program files\dropbox\update\DropboxUpdate.exe [2017-5-20 143144]
S3 DcpSvc;DataCollectionPublishingService;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DevQueryBroker;DevQuery Background Discovery Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 diagnosticshub.standardcollector.service;Microsoft(R) Diagnostics Hub Standard Collector-service;c:\windows\system32\diagsvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 69632]
S3 DmEnrollmentSvc;Registratieservice voor Apparaatbeheer;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DsSvc;Data Sharing Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 embeddedmode;Ingesloten modus;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 EntAppSvc;Enterprise App Management Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 FrameServer;Windows Camera Frame Server;c:\windows\system32\svchost.exe -k Camera [2016-7-16 38792]
S3 genericusbfn;Algemene USB-functieklasse;c:\windows\system32\drivers\genericusbfn.sys [2016-7-16 17920]
S3 GPIO;Stuurprogramma voor Intel SoC GPIO-controller;c:\windows\system32\drivers\iaiogpio.sys [2016-7-16 22016]
S3 hidinterrupt;Algemeen stuurprogramma voor HID-knoppen waarvoor interrupts zijn geïmplementeerd;c:\windows\system32\drivers\hidinterrupt.sys [2016-7-16 38240]
S3 iagpio;Intel Serial IO GPIO Controller Driver;c:\windows\system32\drivers\iagpio.sys [2016-7-16 25600]
S3 iai2c;Intel(R) Serial IO I2C-hostcontroller;c:\windows\system32\drivers\iai2c.sys [2016-7-16 66560]
S3 iaioi2c;I2C-controllerservice voor Intel(R) Atom(TM)-processor;c:\windows\system32\drivers\iaioi2c.sys [2016-7-16 61936]
S3 iaStorAV;Intel(R) SATA RAID-controller Windows;c:\windows\system32\drivers\iaStorAV.sys [2016-7-16 524640]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files\intel\intel(r) integrated clock controller service\ICCProxy.exe [2017-3-17 169752]
S3 icssvc;Windows Mobile Hotspot Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2017-3-17 103936]
S3 IndirectKmd;Indirecte weergave kernelmodusstuurprogramma;c:\windows\system32\drivers\IndirectKmd.sys [2016-7-16 30208]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2015-12-1 44016]
S3 lfsvc;Geolocation Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 LSI_SAS2i;LSI_SAS2i;c:\windows\system32\drivers\lsi_sas2i.sys [2016-7-16 89952]
S3 LSI_SAS3i;LSI_SAS3i;c:\windows\system32\drivers\lsi_sas3i.sys [2016-7-16 85856]
S3 megasas2i;megasas2i;c:\windows\system32\drivers\MegaSas2i.sys [2017-3-18 56672]
S3 MsSecFlt;Minifilter voor Microsoft Security Events Component;c:\windows\system32\drivers\mssecflt.sys [2016-7-16 159584]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;c:\windows\system32\drivers\NetAdapterCx.sys [2016-7-16 62976]
S3 NetSetupSvc;Network Setup Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 PDF Architect 5 CrashHandler;PDF Architect 5 CrashHandler;c:\program files\pdf architect 5\crash-handler-ws.exe [2017-2-10 979848]
S3 PDF Architect 5;PDF Architect 5;c:\program files\pdf architect 5\ws.exe [2017-2-10 2468240]
S3 percsas2i;percsas2i;c:\windows\system32\drivers\percsas2i.sys [2016-7-16 51552]
S3 percsas3i;percsas3i;c:\windows\system32\drivers\percsas3i.sys [2016-7-16 54624]
S3 PhoneSvc;Phone Service;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 RetailDemo;Retaildemoservice;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 Sense;Windows Defender Advanced Threat Protection Service;c:\program files\windows defender advanced threat protection\MsSense.exe [2017-3-18 1887272]
S3 SensorDataService;Sensor Data Service;c:\windows\system32\SensorDataService.exe [2017-3-18 894976]
S3 SensorService;Sensor Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 SerCx2;Serial UART Support Library;c:\windows\system32\drivers\SerCx2.sys [2016-7-16 117600]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\drivers\Smb_driver_Intel.sys [2017-3-17 35504]
S3 smphost;Microsoft Storage Spaces SMP;c:\windows\system32\svchost.exe -k smphost [2016-7-16 38792]
S3 stornvme;Microsoft Standard NVM Express Driver;c:\windows\system32\drivers\stornvme.sys [2016-7-16 66912]
S3 storufs;Microsoft Universal Flash Storage (UFS)-stuurprogramma;c:\windows\system32\drivers\storufs.sys [2016-7-16 26976]
S3 TieringEngineService;Storage Tiers Management;c:\windows\system32\TieringEngineService.exe [2016-7-16 253440]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;c:\windows\system32\drivers\UcmCx.sys [2016-7-16 68608]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;c:\windows\system32\drivers\UcmTcpciCx.sys [2016-7-16 76800]
S3 UcmUcsi;UCSI-client van USB-connectorbeheer;c:\windows\system32\drivers\UcmUcsi.sys [2016-7-16 35840]
S3 UdeCx;USB Device Emulation Support Library;c:\windows\system32\drivers\Udecx.sys [2016-7-16 33280]
S3 UEFI;Microsoft UEFI-stuurprogramma;c:\windows\system32\drivers\uefi.sys [2016-7-16 23392]
S3 Ufx01000;USB Function Class Extension;c:\windows\system32\drivers\ufx01000.sys [2016-7-16 205152]
S3 UfxChipidea;Chipidea USB-controller;c:\windows\system32\drivers\UfxChipidea.sys [2016-7-16 75616]
S3 ufxsynopsys;Synopsys USB-controller;c:\windows\system32\drivers\ufxsynopsys.sys [2016-7-16 107360]
S3 UrsChipidea;Stuurprogramma voor Chipidea USB Role-Switch;c:\windows\system32\drivers\urschipidea.sys [2016-7-16 22880]
S3 UrsCx01000;USB Role-Switch Support Library;c:\windows\system32\drivers\urscx01000.sys [2016-7-16 42336]
S3 UrsSynopsys;Stuurprogramma voor Synopsys USB Role-Switch;c:\windows\system32\drivers\urssynopsys.sys [2016-7-16 21856]
S3 vhf;Virtual HID Framework (VHF)-stuurprogramma;c:\windows\system32\drivers\vhf.sys [2016-7-16 24064]
S3 vmgid;Microsoft Hyper-V-stuurprogramma voor de gastinfrastructuur;c:\windows\system32\drivers\vmgid.sys [2016-7-16 8704]
S3 vmicguestinterface;Hyper-V Guest Service Interface;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 w3logsvc;W3C-logboekregistratieservice;c:\windows\system32\svchost.exe -k apphost [2016-7-16 38792]
S3 WalletService;WalletService;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 wdiwifi;WDI Driver Framework;c:\windows\system32\drivers\WdiWiFi.sys [2017-3-18 518656]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;c:\windows\system32\svchost.exe -k WepHostSvcGroup [2016-7-16 38792]
S3 wisvc;Windows Insider Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 workfolderssvc;Work Folders;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 WpnUserService_35d4f;Windows Push Notification-gebruikersservice_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 XblAuthManager;Xbox Live-verificatiebeheer;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 XblGameSave;Games opslaan op Xbox Live;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xboxgip;Xbox Game Input Protocol Driver;c:\windows\system32\drivers\xboxgip.sys [2017-3-18 216576]
S3 XboxNetApiSvc;XboxNetApiSvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xinputhid;XINPUT HID Filter Driver;c:\windows\system32\drivers\xinputhid.sys [2017-3-18 34304]
S4 AppVClient;Microsoft App-V Client;c:\windows\system32\AppVClient.exe [2017-3-18 615264]
S4 shpamsvc;Shared PC Account Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S4 tzautoupdate;Updater van automatische tijdzone;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S4 UevAgentDriver;UevAgentDriver;c:\windows\system32\drivers\UevAgentDriver.sys [2016-7-16 36192]
S4 UevAgentService;User Experience Virtualization Service;c:\windows\system32\AgentService.exe [2016-7-16 858624]
.
=============== File Associations ===============
.
ShellExec: PDF Architect 5.exe: edit="c:\program files\pdf architect 5\architect.exe" --file "%1"
ShellExec: PDF Architect 5.exe: open="c:\program files\pdf architect 5\architect.exe" --file "%1"
.
=============== Created Last 30 ================
.
2017-06-01 17:11:55 39168 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0aa4287-52a8-43a7-947f-ae7b9cbe847c}\MpKsl7e909f48.sys
2017-06-01 17:11:06 -------- d-----w- c:\users\ferry\appdata\local\UNP
2017-05-31 20:45:34 10555024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0aa4287-52a8-43a7-947f-ae7b9cbe847c}\mpengine.dll
2017-05-31 19:55:59 -------- d---a-w- c:\program files\UNP
2017-05-31 19:55:59 -------- d-----w- c:\windows\system32\UNP
2017-05-31 19:55:27 10555024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2017-05-31 19:53:32 -------- d-----w- C:\AdwCleaner
2017-05-31 15:57:48 -------- d-----w- c:\users\ferry\appdata\roaming\SUPERAntiSpyware.com
2017-05-31 15:57:19 -------- d---a-w- c:\program files\SUPERAntiSpyware
2017-05-31 15:57:19 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2017-05-31 15:55:14 915640 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{83f515db-bc2c-4505-9c87-9af6eddb13c0}\gapaengine.dll
2017-05-31 15:43:07 161720 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys
2017-05-31 15:42:57 97208 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-05-31 15:42:56 74680 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-05-31 15:42:50 39360 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-05-31 15:42:46 220088 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-05-31 15:42:39 59904 ----a-w- c:\windows\system32\drivers\mbae.sys
2017-05-31 15:42:28 -------- d-----w- c:\programdata\Malwarebytes
2017-05-31 15:42:28 -------- d-----w- c:\program files\Malwarebytes
2017-05-31 15:11:58 -------- d-----w- c:\program files\UJKDFNJY2M
2017-05-31 15:11:57 -------- d-----w- c:\program files\P65IN4CPT1
2017-05-31 15:11:56 -------- d-----w- c:\users\ferry\appdata\roaming\33bmswoton4
2017-05-31 15:11:53 -------- d-----w- c:\users\ferry\appdata\roaming\Chugophwabory
2017-05-31 15:11:53 -------- d-----w- c:\program files\Nogisphaniing Log
2017-05-31 15:11:52 -------- d-----w- c:\users\ferry\appdata\local\Nekale
2017-05-31 15:11:52 -------- d-----w- c:\program files\Vojesereaveing
2017-05-31 15:11:45 -------- d-----w- c:\users\ferry\appdata\roaming\n2m4q5rpn0v
2017-05-31 15:11:36 -------- d-----w- c:\program files\MVMX3L7M1O
2017-05-31 15:11:35 -------- d-----w- c:\users\ferry\appdata\roaming\fm3opukxynd
2017-05-30 17:46:41 -------- d-----w- c:\program files\YIOG7FY9I0
2017-05-30 17:46:40 -------- d-----w- c:\program files\AF422116UY
2017-05-30 17:46:39 -------- d-----w- c:\users\ferry\appdata\roaming\pq03vc4342c
2017-05-30 17:46:29 -------- d-----w- c:\users\ferry\appdata\roaming\fu1kl0a5fu4
2017-05-30 17:27:58 -------- d-----w- c:\program files\Z6W1MKB42K
2017-05-30 17:27:57 -------- d-----w- c:\program files\5HUU9A5K92
2017-05-30 17:27:54 -------- d-----w- c:\users\ferry\appdata\roaming\Profiles
2017-05-30 17:27:54 -------- d-----w- c:\users\ferry\appdata\roaming\j5le3fofm30
2017-05-30 17:27:44 -------- d-----w- c:\users\ferry\appdata\roaming\tga1ar51tip
2017-05-30 17:27:39 -------- d-----w- c:\users\ferry\appdata\roaming\fsusoz2mw2i
2017-05-30 17:27:39 -------- d-----w- c:\program files\0SUOUNDA2Y
2017-05-30 17:27:36 -------- d-----w- c:\program files\anh0swlnxgf
2017-05-30 17:27:32 -------- d-----w- c:\users\ferry\appdata\roaming\ayxqc2hc1be
2017-05-30 17:26:37 -------- d-----w- c:\program files\ixY5WSQZn7
2017-05-30 17:24:04 -------- d-----w- c:\program files\78080d72ebecfb1ef52e642e894a2a85
2017-05-30 17:18:42 -------- d-----w- c:\users\ferry\.fontconfig
2017-05-30 17:18:30 -------- d-----w- c:\users\ferry\appdata\roaming\NVIDIA
2017-05-30 17:18:28 -------- d-----w- c:\users\ferry\appdata\local\Movavi
2017-05-30 17:18:28 -------- d-----w- c:\users\ferry\appdata\local\converter
2017-05-30 17:17:49 -------- d-----w- c:\programdata\Movavi
2017-05-30 17:17:28 -------- d-----w- c:\programdata\Movavi Video Converter 17
2017-05-30 10:22:14 42288 ----a-w- c:\windows\system32\DbxSvc.exe
2017-05-20 18:03:48 -------- d-----r- c:\users\ferry\Dropbox
2017-05-20 18:01:57 -------- d-----w- c:\users\ferry\appdata\roaming\Dropbox
2017-05-20 18:01:16 -------- d-----w- c:\program files\Dropbox
2017-05-20 18:00:53 -------- d-----w- c:\users\ferry\appdata\local\Dropbox
2017-05-20 18:00:53 -------- d-----w- c:\programdata\Dropbox
2017-05-20 12:35:05 -------- d-----w- c:\program files\NSIS
2017-05-09 20:19:59 783360 ----a-w- c:\windows\system32\TSWorkspace.dll
.
==================== Find3M ====================
.
2017-05-31 15:55:00 456360 ------w- c:\windows\system32\MpSigStub.exe
2017-04-29 00:59:38 177656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-04-29 00:59:37 835576 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-04-28 01:33:50 448864 ----a-w- c:\windows\system32\ContentDeliveryManager.Utilities.dll
2017-04-28 01:32:09 685440 ----a-w- c:\windows\system32\Windows.Internal.Shell.Broker.dll
2017-04-28 01:32:08 402272 ----a-w- c:\windows\system32\AppVCatalog.dll
2017-04-28 01:32:04 551264 ----a-w- c:\windows\system32\AppVOrchestration.dll
2017-04-28 01:32:03 498016 ----a-w- c:\windows\system32\AppVEntVirtualization.dll
2017-04-28 01:28:15 965472 ----a-w- c:\windows\system32\ReAgent.dll
2017-04-28 01:01:53 784064 ----a-w- c:\windows\system32\winresume.exe
2017-04-28 01:00:14 1725136 ----a-w- c:\windows\system32\KernelBase.dll
2017-04-28 01:00:07 5996896 ----a-w- c:\windows\system32\ntoskrnl.exe
2017-04-28 00:59:55 601712 ----a-w- c:\windows\system32\oleaut32.dll
2017-04-28 00:58:41 1956704 ----a-w- c:\windows\system32\drivers\ntfs.sys
2017-04-28 00:56:56 2048488 ----a-w- c:\windows\system32\CoreUIComponents.dll
2017-04-28 00:55:11 583128 ----a-w- c:\windows\system32\CoreMessaging.dll
2017-04-28 00:51:41 277856 ----a-w- c:\windows\system32\WinSetupUI.dll
2017-04-28 00:49:54 53080 ----a-w- c:\windows\system32\drivers\fsdepends.sys
2017-04-28 00:48:25 263472 ----a-w- c:\windows\system32\Windows.Storage.ApplicationData.dll
2017-04-28 00:46:29 1896288 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2017-04-28 00:46:17 342880 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2017-04-28 00:46:09 1504056 ----a-w- c:\windows\system32\WindowsCodecs.dll
2017-04-28 00:46:06 1431232 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.dll
2017-04-28 00:46:03 5722320 ----a-w- c:\windows\system32\windows.storage.dll
2017-04-28 00:45:54 781144 ----a-w- c:\windows\system32\WWAHost.exe
2017-04-28 00:45:44 493920 ----a-w- c:\windows\system32\SettingSyncHost.exe
2017-04-28 00:45:44 116576 ----a-w- c:\windows\system32\CloudExperienceHostCommon.dll
2017-04-28 00:45:33 861024 ----a-w- c:\windows\system32\LicenseManager.dll
2017-04-28 00:45:29 975744 ----a-w- c:\windows\system32\twinapi.appcore.dll
2017-04-28 00:45:29 25440 ----a-w- c:\windows\system32\browser_broker.exe
2017-04-28 00:45:00 545120 ----a-w- c:\windows\system32\drivers\vhdmp.sys
2017-04-28 00:43:59 1980768 ----a-w- c:\windows\system32\msxml6.dll
2017-04-28 00:43:55 458592 ----a-w- c:\windows\system32\drivers\spaceport.sys
2017-04-28 00:43:48 1557224 ----a-w- c:\windows\system32\crypt32.dll
2017-04-28 00:43:27 355168 ----a-w- c:\windows\system32\drivers\rdbss.sys
2017-04-28 00:43:10 846560 ----a-w- c:\windows\system32\WinTypes.dll
2017-04-28 00:43:09 2168288 ----a-w- c:\windows\system32\combase.dll
2017-04-28 00:42:58 601952 ----a-w- c:\windows\system32\NetSetupEngine.dll
2017-04-28 00:41:08 361104 ----a-w- c:\windows\system32\tsmf.dll
2017-04-28 00:41:07 80224 ----a-w- c:\windows\system32\rdpudd.dll
2017-04-28 00:40:30 6665952 ----a-w- c:\windows\system32\Windows.Media.Protection.PlayReady.dll
2017-04-28 00:40:19 4023008 ----a-w- c:\windows\system32\mfcore.dll
2017-04-28 00:40:17 1277856 ----a-w- c:\windows\system32\mfasfsrcsnk.dll
2017-04-28 00:40:15 1851696 ----a-w- c:\windows\system32\mfmp4srcsnk.dll
2017-04-28 00:40:15 1360456 ----a-w- c:\windows\system32\mfnetsrc.dll
2017-04-28 00:40:13 981888 ----a-w- c:\windows\system32\mfnetcore.dll
2017-04-28 00:40:10 352760 ----a-w- c:\windows\system32\MMDevAPI.dll
2017-04-28 00:40:09 1202936 ----a-w- c:\windows\system32\mfmpeg2srcsnk.dll
2017-04-28 00:39:48 962760 ----a-w- c:\windows\system32\ole32.dll
2017-04-28 00:39:22 4312248 ----a-w- c:\windows\explorer.exe
2017-04-28 00:38:56 1384704 ----a-w- c:\windows\system32\sppobjs.dll
2017-04-28 00:35:23 1411616 ----a-w- c:\windows\system32\gdi32full.dll
2017-04-28 00:33:18 380184 ----a-w- c:\windows\system32\services.exe
2017-04-28 00:29:28 5685760 ----a-w- c:\windows\system32\Windows.Data.Pdf.dll
2017-04-28 00:26:56 281088 ----a-w- c:\windows\system32\RDXTaskFactory.dll
2017-04-28 00:23:19 95232 ----a-w- c:\windows\system32\UserDataTimeUtil.dll
2017-04-28 00:23:10 1631232 ----a-w- c:\windows\system32\Windows.UI.Xaml.Resources.dll
2017-04-28 00:22:46 26112 ----a-w- c:\windows\system32\odbcconf.dll
2017-04-28 00:22:16 165376 ----a-w- c:\windows\system32\ReInfo.dll
2017-04-28 00:22:08 69120 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2017-04-28 00:21:41 27648 ----a-w- c:\windows\system32\BthTelemetry.dll
2017-04-28 00:21:26 73728 ----a-w- c:\windows\system32\tdc.ocx
2017-04-28 00:21:14 224256 ----a-w- c:\windows\system32\ExSMime.dll
2017-04-28 00:20:50 44032 ----a-w- c:\windows\system32\virtdisk.dll
2017-04-28 00:20:47 141824 ----a-w- c:\windows\system32\Windows.Devices.Radios.dll
2017-04-28 00:20:27 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2017-04-28 00:20:23 30720 ----a-w- c:\windows\system32\drivers\vwifimp.sys
2017-04-28 00:20:00 203776 ----a-w- c:\windows\system32\drivers\BthLEEnum.sys
2017-04-28 00:19:33 119296 ----a-w- c:\windows\system32\Family.Client.dll
2017-04-28 00:19:26 584192 ----a-w- c:\windows\system32\UIRibbonRes.dll
2017-04-28 00:19:24 98304 ----a-w- c:\windows\system32\appidsvc.dll
2017-04-28 00:19:15 156672 ----a-w- c:\windows\system32\UserDeviceRegistration.dll
2017-04-28 00:19:07 94208 ----a-w- c:\windows\system32\drivers\bridge.sys
2017-04-28 00:19:05 138240 ----a-w- c:\windows\system32\DisplayManager.dll
2017-04-28 00:18:43 450560 ----a-w- c:\windows\system32\rastls.dll
2017-04-28 00:18:37 255488 ----a-w- c:\windows\system32\unimdm.tsp
2017-04-28 00:18:35 285184 ----a-w- c:\windows\system32\Windows.UI.BlockedShutdown.dll
2017-04-28 00:18:31 254464 ----a-w- c:\windows\system32\drivers\wmbclass.sys
2017-04-28 00:17:57 136192 ----a-w- c:\windows\system32\WinRtTracing.dll
2017-04-28 00:17:50 94208 ----a-w- c:\windows\system32\Windows.StateRepositoryClient.dll
2017-04-28 00:17:39 330752 ----a-w- c:\windows\system32\aadcloudap.dll
2017-04-28 00:17:36 95232 ----a-w- c:\windows\system32\BluetoothApis.dll
2017-04-28 00:17:02 186880 ----a-w- c:\windows\system32\Family.SyncEngine.dll
2017-04-28 00:17:01 142336 ----a-w- c:\windows\system32\Windows.Devices.WiFi.dll
2017-04-28 00:15:44 334848 ----a-w- c:\windows\system32\rastlsext.dll
2017-04-28 00:15:41 216576 ----a-w- c:\windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-28 00:15:38 237568 ----a-w- c:\windows\system32\SyncSettings.dll
2017-04-28 00:15:35 206336 ----a-w- c:\windows\system32\bthprops.cpl
2017-04-28 00:15:29 404992 ----a-w- c:\windows\system32\dsreg.dll
2017-04-28 00:15:14 822784 ----a-w- c:\windows\system32\Chakradiag.dll
2017-04-28 00:15:12 102400 ----a-w- c:\windows\system32\ConsentUX.dll
2017-04-28 00:15:11 557568 ----a-w- c:\windows\system32\StoreAgent.dll
2017-04-28 00:15:09 774144 ----a-w- c:\windows\system32\SystemSettings.Handlers.dll
2017-04-28 00:14:11 670208 ----a-w- c:\windows\system32\Windows.Devices.PointOfService.dll
2017-04-28 00:14:06 223232 ----a-w- c:\windows\system32\InstallAgentUserBroker.exe
2017-04-28 00:14:01 483840 ----a-w- c:\windows\system32\Windows.Devices.AllJoyn.dll
2017-04-28 00:14:00 445952 ----a-w- c:\windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-04-28 00:14:00 306688 ----a-w- c:\windows\system32\ieproxy.dll
2017-04-28 00:12:58 284672 ----a-w- c:\windows\system32\apprepsync.dll
2017-04-28 00:12:52 273920 ----a-w- c:\windows\system32\PrintDialogs3D.dll
.
============= FINISH: 19:41:54,61 ===============
zie deel 2/2 voor DDS attach log en GMER logfile
grtz,
Bintang
Sinds enige tijd heb ik een nogal irritante browser hijack. Mijn systeem is voorzien van Windows 10. En de highjack vind plaats op Microsoft Edge. Spontane opstart van Edge en maar sites blijven openen.
Hopelijk kunnen jullie mij helpen om hier van af te komen.
Logs:
Malwarebytes
-Logboekdetails-
Scandatum: 01-06-17
Scantijd: 18:42
Logbestand: Malware.txt
Beheerder: Ja
-Software-informatie-
Versie: 3.1.2.1733
Versie componenten: 1.0.122
Update pakketversie: 1.0.2066
Licentie: Proef
-Systeeminformatie-
Besturingssysteem: Windows 10
Processor: x86
Bestandssysteem: NTFS
Gebruiker: FERRY-PC\Ferry
-Scansamenvatting-
Scantype: Aangepaste scan
Resultaat: Voltooid
Objecten gescand: 234092
Dreigingen herkend: 2
Dreigingen in quarantaine: 0
(Geen kwaadaardige items gedetecteerd)
Verstreken tijd: 27 min, 21 sec
-Scanopties-
Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Ingeschakeld
Heuristiek: Ingeschakeld
POP: Ingeschakeld
POA: Ingeschakeld
-Scandetails-
Proces: 0
(Geen kwaadaardige items gedetecteerd)
Module: 0
(Geen kwaadaardige items gedetecteerd)
Registersleutel: 1
PUP.Optional.OtherSearch, HKLM\SOFTWARE\OTHERSEARCH, Geen actie door gebruiker, [570], [305744],1.0.2066
Registerwaarde: 1
PUP.Optional.OtherSearch, HKLM\SOFTWARE\OTHERSEARCH|AFFID, Geen actie door gebruiker, [570], [305744],1.0.2066
Registerdata: 0
(Geen kwaadaardige items gedetecteerd)
Gegevensstroom: 0
(Geen kwaadaardige items gedetecteerd)
Map: 0
(Geen kwaadaardige items gedetecteerd)
Bestand: 0
(Geen kwaadaardige items gedetecteerd)
Fysieke sector: 0
(Geen kwaadaardige items gedetecteerd)
(end)
# AdwCleaner v6.047 - Logbestand aangemaakt 31/05/2017 op 21:55:59
# Bijgewerkt op 19/05/2017 door Malwarebytes
# Database : 2017-05-31.2 [Server]
# Besturingssysteem : Windows 10 Pro (X86)
# Gebruikersnaam : Ferry - FERRY-PC
# Gestart vanuit : C:\Users\Ferry\Desktop\adwcleaner_6.047.exe
# Mode: Verwijderen
# Ondersteuning : https://www.malwarebytes.com/support
***** [ Services ] *****
[-] Service verwijderd: 78080d72ebecfb1ef52e642e894a2a85
***** [ Mappen ] *****
[-] Map verwijderd: C:\ProgramData\d61181ac
[-] Map verwijderd: C:\Users\Ferry\AppData\Local\DriverToolkit
[-] Map verwijderd: C:\Program Files\DriverToolkit
[-] Map verwijderd: C:\WINDOWS\system32\SSL
[-] Map verwijderd: C:\WINDOWS\system32\sstmp
***** [ Bestanden ] *****
[-] Bestand verwijderd: C:\END
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Snelkoppelingen ] *****
***** [ Geplande Taken ] *****
***** [ Register ] *****
[-] Sleutel verwijderd: HKU\S-1-5-21-3829025451-3821063052-892049231-1000\Software\DriverToolkit
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\DriverToolkit
[-] Sleutel verwijderd: HKLM\SOFTWARE\OtherSearch
[-] Sleutel verwijderd: HKLM\SOFTWARE\HDWallpaper
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchy
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{24F5E422-6A70-4FAA-8CAD-E23D5DC1DAE6}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD0688A5-FC8B-4E93-A485-CBF606A56D49}
***** [ Browsers ] *****
*************************
:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [1844 bytes] - [31/05/2017 21:55:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [2090 bytes] - [31/05/2017 21:54:36]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1990 bytes] ##########
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.14393.953 BrowserJavaVersion: 11.131.2
Run by Ferry at 19:41:29 on 2017-06-01
Microsoft Windows 10 Pro 10.0.14393.0.1252.31.1043.18.2795.1406 [GMT 2:00]
.
AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\WINDOWS\system32\dwm.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\LPlatSvc.exe
C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
C:\WINDOWS\system32\nvvsvc.exe
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\system32\DbxSvc.exe
C:\Windows\system32\IProsetMonitor.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\PDF Architect 5\creator-ws.exe
C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\LPlatSvc.exe
C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\igfxHK.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x86__kzf8qxf38zg5c\SkypeHost.exe
C:\WINDOWS\system32\AUDIODG.EXE
C:\WINDOWS\system32\backgroundTaskHost.exe
C:\Windows\System32\smartscreen.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\Windows Defender\MSASCuiL.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Users\Ferry\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Users\Ferry\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\anh0swlnxgf\CIOO9.exe
C:\Users\Ferry\AppData\Roaming\fm3opukxynd\puaa42sy5x1.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\Users\Ferry\AppData\Roaming\n2m4q5rpn0v\lj1cbu1fph2.exe
C:\Users\Ferry\AppData\Roaming\33bmswoton4\3vaaspwaidr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\conhost.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\Program Files\Dropbox\Update\DropboxUpdate.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.nl/?gws_rd=ssl#spf=1
BHO: Skype for Business Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft office\office15\OCHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_131\bin\ssv.dll
BHO: PDF Architect 5 Helper: {AEA429F3-D2D4-4BD7-A03E-5357DA017733} - c:\program files\pdf architect 5\creator-ie-helper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_131\bin\jp2ssv.dll
TB: PDF Architect 5 Toolbar: {84F23192-A475-4038-B5C0-8584777F2DF4} - c:\program files\pdf architect 5\creator-ie-plugin.dll
uRun: [Spotify Web Helper] "c:\users\ferry\appdata\roaming\spotify\SpotifyWebHelper.exe"
uRun: [Spotify] "c:\users\ferry\appdata\roaming\spotify\Spotify.exe" -autostart -minimized
uRun: [OneDrive] "c:\users\ferry\appdata\local\microsoft\onedrive\OneDrive.exe" /background
uRun: [8EE24K5NBNZO3HE] "c:\program files\anh0swlnxgf\CIOO9.exe"
uRun: [bevu12jntao] "c:\users\ferry\appdata\roaming\fm3opukxynd\puaa42sy5x1.exe"
uRun: [0mtodjqiczj] "c:\users\ferry\appdata\roaming\n2m4q5rpn0v\lj1cbu1fph2.exe"
uRun: [im3zen13k3j] "c:\users\ferry\appdata\roaming\33bmswoton4\3vaaspwaidr.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [NvBackend] "c:\program files\nvidia corporation\update core\NvBackend.exe"
mRun: [WindowsDefender] "c:\program files\windows defender\MSASCuiL.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Dropbox] "c:\program files\dropbox\client\Dropbox.exe" /systemstartup
mRun: [Malwarebytes TrayApp] c:\program files\malwarebytes\anti-malware\mbamtray.exe
mPolicies-System: DSCAutomationHostEnabled = dword:2
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~1\office15\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft office\office15\OCHelper.dll
TCP: NameServer = 8.8.8.8
TCP: NameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{17950864-ab99-40c9-b4bc-0a87ce715196} : NameServer = 8.8.8.8
TCP: Interfaces\{1db48f5d-0bf7-483d-b541-50ca7008a005} : NameServer = 8.8.8.8
TCP: Interfaces\{3092c383-4821-4602-8425-b9972eb0f733} : NameServer = 8.8.8.8
TCP: Interfaces\{3092c383-4821-4602-8425-b9972eb0f733} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{6b39583d-7e5b-45b8-95ab-d8839ce64e90} : NameServer = 8.8.8.8
TCP: Interfaces\{6b39583d-7e5b-45b8-95ab-d8839ce64e90} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1} : NameServer = 8.8.8.8
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1} : DHCPNameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{7af84d91-a6e0-4b8a-9d1a-4ae8dc9541e1}\A5967676F673931353 : DHCPNameServer = 89.101.251.228 89.101.251.229
TCP: Interfaces\{9fc70b0f-5430-4ab4-bc95-0dbf04c67c86} : NameServer = 8.8.8.8
TCP: Interfaces\{9fc70b0f-5430-4ab4-bc95-0dbf04c67c86} : DHCPNameServer = 8.8.8.8
TCP: Interfaces\{bc315126-0b65-11e7-9e6d-806e6f6e6963} : NameServer = 8.8.8.8
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - c:\program files\microsoft office\office15\MSOSB.DLL
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - c:\windows\system32\tbauth.dll
AppInit_DLLs= c:\windows\system32\nvinit.dll
SSODL: WebCheck - <orphaned>
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\58.0.3029.110\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - c:\windows\system32\windows.storage.dll
.
============= SERVICES / DRIVERS ===============
.
R?2 dbupdate;Dropbox-update-service (dbupdate);c:\program files\dropbox\update\DropboxUpdate.exe [2017-5-20 143144]
R0 intelpep;Stuurprogramma voor Intel(R) Power Engine-invoegtoepassing ;c:\windows\system32\drivers\intelpep.sys [2016-7-16 42520]
R0 iorate;iorate;c:\windows\system32\drivers\iorate.sys [2017-3-18 42336]
R0 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2017-5-31 220088]
R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2016-9-12 53296]
R0 volume;Volumestuurprogramma;c:\windows\system32\drivers\volume.sys [2016-7-16 14176]
R0 WindowsTrustedRT;Windows Trusted Execution Environment Class Extension;c:\windows\system32\drivers\WindowsTrustedRT.sys [2016-7-16 86040]
R0 WindowsTrustedRTProxy;Microsoft Windows Trusted Runtime Secure Service;c:\windows\system32\drivers\WindowsTrustedRTProxy.sys [2016-7-16 15384]
R0 Wof;Windows Overlay File System Filter Driver;c:\windows\system32\drivers\wof.sys [2017-3-18 173408]
R1 ahcache;Application Compatibility Cache;c:\windows\system32\drivers\ahcache.sys [2017-3-18 188928]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit;c:\windows\system32\drivers\mbae.sys [2017-5-31 59904]
R1 FileCrypt;FileCrypt;c:\windows\system32\drivers\filecrypt.sys [2016-7-16 77312]
R1 GpuEnergyDrv;GPU Energy Driver;c:\windows\system32\drivers\gpuenergydrv.sys [2016-7-16 7680]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2017-1-31 143776]
R2 BcmBtRSupport;Bluetooth Driver Management Service;c:\windows\system32\BtwRSupportService.exe [2015-3-27 1677016]
R2 CDPSvc;Service Platform voor verbonden apparaten;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
R2 CDPUserSvc_35d4f;CDPUserSvc_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 clreg;Virtual Registry for Containers;c:\windows\system32\drivers\registry.sys [2016-7-16 58368]
R2 CoreMessagingRegistrar;CoreMessaging;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [2016-7-16 38792]
R2 DbxSvc;DbxSvc;c:\windows\system32\DbxSvc.exe [2017-5-30 42288]
R2 DiagTrack;Connected User Experiences and Telemetry;c:\windows\system32\svchost.exe -k utcsvc [2016-7-16 38792]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe [2016-5-4 292832]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2017-2-10 401984]
R2 LPlatSvc;Lenovo Platform Service;c:\windows\system32\LPlatSvc.exe [2016-11-1 694360]
R2 MBAMChameleon;MBAMChameleon;c:\windows\system32\drivers\MBAMChameleon.sys [2017-5-31 161720]
R2 MBAMService;Malwarebytes Service;c:\program files\malwarebytes\anti-malware\MBAMService.exe [2017-5-31 3398608]
R2 MessagingService_35d4f;MessagingService_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\nvidia corporation\display.nvcontainer\NVDisplay.Container.exe [2017-3-17 421944]
R2 OneSyncSvc_35d4f;Host synchroniseren_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R2 PDF Architect 5 Creator;PDF Architect 5 Creator;c:\program files\pdf architect 5\creator-ws.exe [2017-2-10 778640]
R2 PDF Architect 5 Manager;PDF Architect 5 Manager;c:\programdata\pdfforge\pdf architect 5 manager\pdf architect 5\Architect Manager.exe [2017-2-28 985904]
R2 SmsRouter;Microsoft Windows SMS Router-service.;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R2 storqosflt;Storage QoS Filter Driver;c:\windows\system32\drivers\storqosflt.sys [2016-7-16 62976]
R2 SynTPEnhService;SynTPEnh Caller Service;c:\program files\synaptics\syntp\SynTPEnhService.exe [2016-1-8 228960]
R2 tiledatamodelsvc;Tile Data model server;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R2 UserManager;User Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R2 wcifs;Windows Container Isolation;c:\windows\system32\drivers\wcifs.sys [2017-3-18 95072]
R2 wcnfs;Windows Container Name Virtualization;c:\windows\system32\drivers\wcnfs.sys [2016-7-16 52736]
R2 WpnService;Systeemservice voor Windows Push Notifications;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R3 AppXSvc;AppX Deployment Service (AppXSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2015-3-27 177280]
R3 BthLEEnum;Bluetooth Low Energy-stuurprogramma;c:\windows\system32\drivers\BthLEEnum.sys [2017-5-9 203776]
R3 ClipSVC;Client License Service (ClipSVC);c:\windows\system32\svchost.exe -k wsappx [2016-7-16 38792]
R3 iwdbus;IWD Bus Enumerator;c:\windows\system32\drivers\iwdbus.sys [2015-12-1 35320]
R3 LenovoRd;LenovoRd;c:\windows\system32\drivers\LenovoRd.sys [2012-12-6 96768]
R3 LicenseManager;Service voor Windows-licentiebeheer ;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
R3 MBAMFarflt;MBAMFarflt;c:\windows\system32\drivers\farflt.sys [2017-5-31 97208]
R3 MBAMProtection;MBAMProtection;c:\windows\system32\drivers\mbam.sys [2017-5-31 39360]
R3 MBAMWebProtection;MBAMWebProtection;c:\windows\system32\drivers\mwac.sys [2017-5-31 74680]
R3 MbmUsbSerial;MBM USB Generic Serial Driver svc;c:\windows\system32\drivers\MbmUsbSerial.sys [2015-6-30 70128]
R3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\drivers\HECI.sys [2012-7-17 55104]
R3 MkBusFilter;MbmFilter Service;c:\windows\system32\drivers\MbmDeviceFilter.sys [2015-6-30 38072]
R3 NcbService;Network Connection Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R3 NdisVirtualBus;Microsoft Virtual Network Adapter Enumerator;c:\windows\system32\drivers\NdisVirtualBus.sys [2016-7-16 15872]
R3 NETwNe32;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 32 Bit;c:\windows\system32\drivers\NETwen01.sys [2016-7-16 2670592]
R3 NgcCtnrSvc;Microsoft Passport Container;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
R3 NgcSvc;Microsoft Passport;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
R3 PimIndexMaintenanceSvc_35d4f;Contact Data_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 RCUVCAVS;Ricoh UVC AVStream driver;c:\windows\system32\drivers\RCUVCAVS.sys [2013-7-2 97280]
R3 risdxc;risdxc;c:\windows\system32\drivers\risdxc86.sys [2013-9-8 79360]
R3 StateRepository;State Repository Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
R3 TimeBrokerSvc;Time Broker;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
R3 UnistoreSvc_35d4f;User Data Storage_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 UserDataSvc_35d4f;User Data Access_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
R3 UsoSvc;Update Orchestrator Service for Windows Update;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
R3 WdNisDrv;Windows Defender Network Inspection System Driver;c:\windows\system32\drivers\WdNisDrv.sys [2016-7-16 100192]
R3 WdNisSvc;Windows Defender Network Inspection Service;c:\program files\windows defender\NisSrv.exe [2017-5-9 271488]
R3 wmbclass;Stuurprogramma voor USB-versie van mobiele breedbandadapter;c:\windows\system32\drivers\wmbclass.sys [2017-5-9 254464]
S2 dmwappushservice;dmwappushsvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S2 DoSvc;Delivery Optimization;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S2 MapsBroker;Downloaded Maps Manager;c:\windows\system32\svchost.exe -k NetworkService [2016-7-16 38792]
S3 AcpiDev;Stuurprogramma voor ACPI-apparaten;c:\windows\system32\drivers\AcpiDev.sys [2016-7-16 12800]
S3 ADP80XX;ADP80XX;c:\windows\system32\drivers\adp80xx.sys [2016-7-16 1038176]
S3 AJRouter;AllJoyn Router Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 applockerfltr;Smartlocker Filter Driver;c:\windows\system32\drivers\applockerfltr.sys [2016-7-16 12288]
S3 AppReadiness;App Readiness;c:\windows\system32\svchost.exe -k AppReadiness [2016-7-16 38792]
S3 AppvStrm;AppvStrm;c:\windows\system32\drivers\AppVStrm.sys [2017-3-18 94560]
S3 AppvVemgr;AppvVemgr;c:\windows\system32\drivers\AppvVemgr.sys [2016-7-16 118112]
S3 AppvVfs;AppvVfs;c:\windows\system32\drivers\AppvVfs.sys [2016-7-16 111456]
S3 bcmfn;bcmfn Service;c:\windows\system32\drivers\bcmfn.sys [2016-7-16 8192]
S3 bcmfn2;bcmfn2 Service;c:\windows\system32\drivers\bcmfn2.sys [2016-7-16 8192]
S3 BthHFSrv;Bluetooth Handsfree Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2016-7-16 38792]
S3 btwampfl;btwampfl;c:\windows\system32\drivers\btwampfl.sys [2015-3-27 162560]
S3 buttonconverter;Service voor Portable Device Control-apparaten;c:\windows\system32\drivers\buttonconverter.sys [2016-7-16 27648]
S3 CapImg;HID-stuurprogramma voor CapImg-touchscreen;c:\windows\system32\drivers\capimg.sys [2017-3-18 97792]
S3 dbupdatem;Dropbox-update-service (dbupdatem);c:\program files\dropbox\update\DropboxUpdate.exe [2017-5-20 143144]
S3 DcpSvc;DataCollectionPublishingService;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DevQueryBroker;DevQuery Background Discovery Broker;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 diagnosticshub.standardcollector.service;Microsoft(R) Diagnostics Hub Standard Collector-service;c:\windows\system32\diagsvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-7-16 69632]
S3 DmEnrollmentSvc;Registratieservice voor Apparaatbeheer;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 DsSvc;Data Sharing Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 embeddedmode;Ingesloten modus;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 EntAppSvc;Enterprise App Management Service;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 FrameServer;Windows Camera Frame Server;c:\windows\system32\svchost.exe -k Camera [2016-7-16 38792]
S3 genericusbfn;Algemene USB-functieklasse;c:\windows\system32\drivers\genericusbfn.sys [2016-7-16 17920]
S3 GPIO;Stuurprogramma voor Intel SoC GPIO-controller;c:\windows\system32\drivers\iaiogpio.sys [2016-7-16 22016]
S3 hidinterrupt;Algemeen stuurprogramma voor HID-knoppen waarvoor interrupts zijn geïmplementeerd;c:\windows\system32\drivers\hidinterrupt.sys [2016-7-16 38240]
S3 iagpio;Intel Serial IO GPIO Controller Driver;c:\windows\system32\drivers\iagpio.sys [2016-7-16 25600]
S3 iai2c;Intel(R) Serial IO I2C-hostcontroller;c:\windows\system32\drivers\iai2c.sys [2016-7-16 66560]
S3 iaioi2c;I2C-controllerservice voor Intel(R) Atom(TM)-processor;c:\windows\system32\drivers\iaioi2c.sys [2016-7-16 61936]
S3 iaStorAV;Intel(R) SATA RAID-controller Windows;c:\windows\system32\drivers\iaStorAV.sys [2016-7-16 524640]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files\intel\intel(r) integrated clock controller service\ICCProxy.exe [2017-3-17 169752]
S3 icssvc;Windows Mobile Hotspot Service;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [2016-7-16 38792]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2017-3-17 103936]
S3 IndirectKmd;Indirecte weergave kernelmodusstuurprogramma;c:\windows\system32\drivers\IndirectKmd.sys [2016-7-16 30208]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2015-12-1 44016]
S3 lfsvc;Geolocation Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 LSI_SAS2i;LSI_SAS2i;c:\windows\system32\drivers\lsi_sas2i.sys [2016-7-16 89952]
S3 LSI_SAS3i;LSI_SAS3i;c:\windows\system32\drivers\lsi_sas3i.sys [2016-7-16 85856]
S3 megasas2i;megasas2i;c:\windows\system32\drivers\MegaSas2i.sys [2017-3-18 56672]
S3 MsSecFlt;Minifilter voor Microsoft Security Events Component;c:\windows\system32\drivers\mssecflt.sys [2016-7-16 159584]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library;c:\windows\system32\drivers\NetAdapterCx.sys [2016-7-16 62976]
S3 NetSetupSvc;Network Setup Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 PDF Architect 5 CrashHandler;PDF Architect 5 CrashHandler;c:\program files\pdf architect 5\crash-handler-ws.exe [2017-2-10 979848]
S3 PDF Architect 5;PDF Architect 5;c:\program files\pdf architect 5\ws.exe [2017-2-10 2468240]
S3 percsas2i;percsas2i;c:\windows\system32\drivers\percsas2i.sys [2016-7-16 51552]
S3 percsas3i;percsas3i;c:\windows\system32\drivers\percsas3i.sys [2016-7-16 54624]
S3 PhoneSvc;Phone Service;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 RetailDemo;Retaildemoservice;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 ScDeviceEnum;Smart Card Device Enumeration Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 Sense;Windows Defender Advanced Threat Protection Service;c:\program files\windows defender advanced threat protection\MsSense.exe [2017-3-18 1887272]
S3 SensorDataService;Sensor Data Service;c:\windows\system32\SensorDataService.exe [2017-3-18 894976]
S3 SensorService;Sensor Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 SerCx2;Serial UART Support Library;c:\windows\system32\drivers\SerCx2.sys [2016-7-16 117600]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\drivers\Smb_driver_Intel.sys [2017-3-17 35504]
S3 smphost;Microsoft Storage Spaces SMP;c:\windows\system32\svchost.exe -k smphost [2016-7-16 38792]
S3 stornvme;Microsoft Standard NVM Express Driver;c:\windows\system32\drivers\stornvme.sys [2016-7-16 66912]
S3 storufs;Microsoft Universal Flash Storage (UFS)-stuurprogramma;c:\windows\system32\drivers\storufs.sys [2016-7-16 26976]
S3 TieringEngineService;Storage Tiers Management;c:\windows\system32\TieringEngineService.exe [2016-7-16 253440]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension;c:\windows\system32\drivers\UcmCx.sys [2016-7-16 68608]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension;c:\windows\system32\drivers\UcmTcpciCx.sys [2016-7-16 76800]
S3 UcmUcsi;UCSI-client van USB-connectorbeheer;c:\windows\system32\drivers\UcmUcsi.sys [2016-7-16 35840]
S3 UdeCx;USB Device Emulation Support Library;c:\windows\system32\drivers\Udecx.sys [2016-7-16 33280]
S3 UEFI;Microsoft UEFI-stuurprogramma;c:\windows\system32\drivers\uefi.sys [2016-7-16 23392]
S3 Ufx01000;USB Function Class Extension;c:\windows\system32\drivers\ufx01000.sys [2016-7-16 205152]
S3 UfxChipidea;Chipidea USB-controller;c:\windows\system32\drivers\UfxChipidea.sys [2016-7-16 75616]
S3 ufxsynopsys;Synopsys USB-controller;c:\windows\system32\drivers\ufxsynopsys.sys [2016-7-16 107360]
S3 UrsChipidea;Stuurprogramma voor Chipidea USB Role-Switch;c:\windows\system32\drivers\urschipidea.sys [2016-7-16 22880]
S3 UrsCx01000;USB Role-Switch Support Library;c:\windows\system32\drivers\urscx01000.sys [2016-7-16 42336]
S3 UrsSynopsys;Stuurprogramma voor Synopsys USB Role-Switch;c:\windows\system32\drivers\urssynopsys.sys [2016-7-16 21856]
S3 vhf;Virtual HID Framework (VHF)-stuurprogramma;c:\windows\system32\drivers\vhf.sys [2016-7-16 24064]
S3 vmgid;Microsoft Hyper-V-stuurprogramma voor de gastinfrastructuur;c:\windows\system32\drivers\vmgid.sys [2016-7-16 8704]
S3 vmicguestinterface;Hyper-V Guest Service Interface;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 vmicvmsession;Hyper-V PowerShell Direct Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2016-7-16 38792]
S3 w3logsvc;W3C-logboekregistratieservice;c:\windows\system32\svchost.exe -k apphost [2016-7-16 38792]
S3 WalletService;WalletService;c:\windows\system32\svchost.exe -k appmodel [2016-7-16 38792]
S3 wdiwifi;WDI Driver Framework;c:\windows\system32\drivers\WdiWiFi.sys [2017-3-18 518656]
S3 WEPHOSTSVC;Windows Encryption Provider Host Service;c:\windows\system32\svchost.exe -k WepHostSvcGroup [2016-7-16 38792]
S3 wisvc;Windows Insider Service;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 workfolderssvc;Work Folders;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S3 WpnUserService_35d4f;Windows Push Notification-gebruikersservice_35d4f;c:\windows\system32\svchost.exe -k UnistackSvcGroup [2016-7-16 38792]
S3 XblAuthManager;Xbox Live-verificatiebeheer;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 XblGameSave;Games opslaan op Xbox Live;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xboxgip;Xbox Game Input Protocol Driver;c:\windows\system32\drivers\xboxgip.sys [2017-3-18 216576]
S3 XboxNetApiSvc;XboxNetApiSvc;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S3 xinputhid;XINPUT HID Filter Driver;c:\windows\system32\drivers\xinputhid.sys [2017-3-18 34304]
S4 AppVClient;Microsoft App-V Client;c:\windows\system32\AppVClient.exe [2017-3-18 615264]
S4 shpamsvc;Shared PC Account Manager;c:\windows\system32\svchost.exe -k netsvcs [2016-7-16 38792]
S4 tzautoupdate;Updater van automatische tijdzone;c:\windows\system32\svchost.exe -k LocalService [2016-7-16 38792]
S4 UevAgentDriver;UevAgentDriver;c:\windows\system32\drivers\UevAgentDriver.sys [2016-7-16 36192]
S4 UevAgentService;User Experience Virtualization Service;c:\windows\system32\AgentService.exe [2016-7-16 858624]
.
=============== File Associations ===============
.
ShellExec: PDF Architect 5.exe: edit="c:\program files\pdf architect 5\architect.exe" --file "%1"
ShellExec: PDF Architect 5.exe: open="c:\program files\pdf architect 5\architect.exe" --file "%1"
.
=============== Created Last 30 ================
.
2017-06-01 17:11:55 39168 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0aa4287-52a8-43a7-947f-ae7b9cbe847c}\MpKsl7e909f48.sys
2017-06-01 17:11:06 -------- d-----w- c:\users\ferry\appdata\local\UNP
2017-05-31 20:45:34 10555024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{b0aa4287-52a8-43a7-947f-ae7b9cbe847c}\mpengine.dll
2017-05-31 19:55:59 -------- d---a-w- c:\program files\UNP
2017-05-31 19:55:59 -------- d-----w- c:\windows\system32\UNP
2017-05-31 19:55:27 10555024 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2017-05-31 19:53:32 -------- d-----w- C:\AdwCleaner
2017-05-31 15:57:48 -------- d-----w- c:\users\ferry\appdata\roaming\SUPERAntiSpyware.com
2017-05-31 15:57:19 -------- d---a-w- c:\program files\SUPERAntiSpyware
2017-05-31 15:57:19 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2017-05-31 15:55:14 915640 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{83f515db-bc2c-4505-9c87-9af6eddb13c0}\gapaengine.dll
2017-05-31 15:43:07 161720 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys
2017-05-31 15:42:57 97208 ----a-w- c:\windows\system32\drivers\farflt.sys
2017-05-31 15:42:56 74680 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-05-31 15:42:50 39360 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-05-31 15:42:46 220088 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-05-31 15:42:39 59904 ----a-w- c:\windows\system32\drivers\mbae.sys
2017-05-31 15:42:28 -------- d-----w- c:\programdata\Malwarebytes
2017-05-31 15:42:28 -------- d-----w- c:\program files\Malwarebytes
2017-05-31 15:11:58 -------- d-----w- c:\program files\UJKDFNJY2M
2017-05-31 15:11:57 -------- d-----w- c:\program files\P65IN4CPT1
2017-05-31 15:11:56 -------- d-----w- c:\users\ferry\appdata\roaming\33bmswoton4
2017-05-31 15:11:53 -------- d-----w- c:\users\ferry\appdata\roaming\Chugophwabory
2017-05-31 15:11:53 -------- d-----w- c:\program files\Nogisphaniing Log
2017-05-31 15:11:52 -------- d-----w- c:\users\ferry\appdata\local\Nekale
2017-05-31 15:11:52 -------- d-----w- c:\program files\Vojesereaveing
2017-05-31 15:11:45 -------- d-----w- c:\users\ferry\appdata\roaming\n2m4q5rpn0v
2017-05-31 15:11:36 -------- d-----w- c:\program files\MVMX3L7M1O
2017-05-31 15:11:35 -------- d-----w- c:\users\ferry\appdata\roaming\fm3opukxynd
2017-05-30 17:46:41 -------- d-----w- c:\program files\YIOG7FY9I0
2017-05-30 17:46:40 -------- d-----w- c:\program files\AF422116UY
2017-05-30 17:46:39 -------- d-----w- c:\users\ferry\appdata\roaming\pq03vc4342c
2017-05-30 17:46:29 -------- d-----w- c:\users\ferry\appdata\roaming\fu1kl0a5fu4
2017-05-30 17:27:58 -------- d-----w- c:\program files\Z6W1MKB42K
2017-05-30 17:27:57 -------- d-----w- c:\program files\5HUU9A5K92
2017-05-30 17:27:54 -------- d-----w- c:\users\ferry\appdata\roaming\Profiles
2017-05-30 17:27:54 -------- d-----w- c:\users\ferry\appdata\roaming\j5le3fofm30
2017-05-30 17:27:44 -------- d-----w- c:\users\ferry\appdata\roaming\tga1ar51tip
2017-05-30 17:27:39 -------- d-----w- c:\users\ferry\appdata\roaming\fsusoz2mw2i
2017-05-30 17:27:39 -------- d-----w- c:\program files\0SUOUNDA2Y
2017-05-30 17:27:36 -------- d-----w- c:\program files\anh0swlnxgf
2017-05-30 17:27:32 -------- d-----w- c:\users\ferry\appdata\roaming\ayxqc2hc1be
2017-05-30 17:26:37 -------- d-----w- c:\program files\ixY5WSQZn7
2017-05-30 17:24:04 -------- d-----w- c:\program files\78080d72ebecfb1ef52e642e894a2a85
2017-05-30 17:18:42 -------- d-----w- c:\users\ferry\.fontconfig
2017-05-30 17:18:30 -------- d-----w- c:\users\ferry\appdata\roaming\NVIDIA
2017-05-30 17:18:28 -------- d-----w- c:\users\ferry\appdata\local\Movavi
2017-05-30 17:18:28 -------- d-----w- c:\users\ferry\appdata\local\converter
2017-05-30 17:17:49 -------- d-----w- c:\programdata\Movavi
2017-05-30 17:17:28 -------- d-----w- c:\programdata\Movavi Video Converter 17
2017-05-30 10:22:14 42288 ----a-w- c:\windows\system32\DbxSvc.exe
2017-05-20 18:03:48 -------- d-----r- c:\users\ferry\Dropbox
2017-05-20 18:01:57 -------- d-----w- c:\users\ferry\appdata\roaming\Dropbox
2017-05-20 18:01:16 -------- d-----w- c:\program files\Dropbox
2017-05-20 18:00:53 -------- d-----w- c:\users\ferry\appdata\local\Dropbox
2017-05-20 18:00:53 -------- d-----w- c:\programdata\Dropbox
2017-05-20 12:35:05 -------- d-----w- c:\program files\NSIS
2017-05-09 20:19:59 783360 ----a-w- c:\windows\system32\TSWorkspace.dll
.
==================== Find3M ====================
.
2017-05-31 15:55:00 456360 ------w- c:\windows\system32\MpSigStub.exe
2017-04-29 00:59:38 177656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-04-29 00:59:37 835576 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-04-28 01:33:50 448864 ----a-w- c:\windows\system32\ContentDeliveryManager.Utilities.dll
2017-04-28 01:32:09 685440 ----a-w- c:\windows\system32\Windows.Internal.Shell.Broker.dll
2017-04-28 01:32:08 402272 ----a-w- c:\windows\system32\AppVCatalog.dll
2017-04-28 01:32:04 551264 ----a-w- c:\windows\system32\AppVOrchestration.dll
2017-04-28 01:32:03 498016 ----a-w- c:\windows\system32\AppVEntVirtualization.dll
2017-04-28 01:28:15 965472 ----a-w- c:\windows\system32\ReAgent.dll
2017-04-28 01:01:53 784064 ----a-w- c:\windows\system32\winresume.exe
2017-04-28 01:00:14 1725136 ----a-w- c:\windows\system32\KernelBase.dll
2017-04-28 01:00:07 5996896 ----a-w- c:\windows\system32\ntoskrnl.exe
2017-04-28 00:59:55 601712 ----a-w- c:\windows\system32\oleaut32.dll
2017-04-28 00:58:41 1956704 ----a-w- c:\windows\system32\drivers\ntfs.sys
2017-04-28 00:56:56 2048488 ----a-w- c:\windows\system32\CoreUIComponents.dll
2017-04-28 00:55:11 583128 ----a-w- c:\windows\system32\CoreMessaging.dll
2017-04-28 00:51:41 277856 ----a-w- c:\windows\system32\WinSetupUI.dll
2017-04-28 00:49:54 53080 ----a-w- c:\windows\system32\drivers\fsdepends.sys
2017-04-28 00:48:25 263472 ----a-w- c:\windows\system32\Windows.Storage.ApplicationData.dll
2017-04-28 00:46:29 1896288 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2017-04-28 00:46:17 342880 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2017-04-28 00:46:09 1504056 ----a-w- c:\windows\system32\WindowsCodecs.dll
2017-04-28 00:46:06 1431232 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.dll
2017-04-28 00:46:03 5722320 ----a-w- c:\windows\system32\windows.storage.dll
2017-04-28 00:45:54 781144 ----a-w- c:\windows\system32\WWAHost.exe
2017-04-28 00:45:44 493920 ----a-w- c:\windows\system32\SettingSyncHost.exe
2017-04-28 00:45:44 116576 ----a-w- c:\windows\system32\CloudExperienceHostCommon.dll
2017-04-28 00:45:33 861024 ----a-w- c:\windows\system32\LicenseManager.dll
2017-04-28 00:45:29 975744 ----a-w- c:\windows\system32\twinapi.appcore.dll
2017-04-28 00:45:29 25440 ----a-w- c:\windows\system32\browser_broker.exe
2017-04-28 00:45:00 545120 ----a-w- c:\windows\system32\drivers\vhdmp.sys
2017-04-28 00:43:59 1980768 ----a-w- c:\windows\system32\msxml6.dll
2017-04-28 00:43:55 458592 ----a-w- c:\windows\system32\drivers\spaceport.sys
2017-04-28 00:43:48 1557224 ----a-w- c:\windows\system32\crypt32.dll
2017-04-28 00:43:27 355168 ----a-w- c:\windows\system32\drivers\rdbss.sys
2017-04-28 00:43:10 846560 ----a-w- c:\windows\system32\WinTypes.dll
2017-04-28 00:43:09 2168288 ----a-w- c:\windows\system32\combase.dll
2017-04-28 00:42:58 601952 ----a-w- c:\windows\system32\NetSetupEngine.dll
2017-04-28 00:41:08 361104 ----a-w- c:\windows\system32\tsmf.dll
2017-04-28 00:41:07 80224 ----a-w- c:\windows\system32\rdpudd.dll
2017-04-28 00:40:30 6665952 ----a-w- c:\windows\system32\Windows.Media.Protection.PlayReady.dll
2017-04-28 00:40:19 4023008 ----a-w- c:\windows\system32\mfcore.dll
2017-04-28 00:40:17 1277856 ----a-w- c:\windows\system32\mfasfsrcsnk.dll
2017-04-28 00:40:15 1851696 ----a-w- c:\windows\system32\mfmp4srcsnk.dll
2017-04-28 00:40:15 1360456 ----a-w- c:\windows\system32\mfnetsrc.dll
2017-04-28 00:40:13 981888 ----a-w- c:\windows\system32\mfnetcore.dll
2017-04-28 00:40:10 352760 ----a-w- c:\windows\system32\MMDevAPI.dll
2017-04-28 00:40:09 1202936 ----a-w- c:\windows\system32\mfmpeg2srcsnk.dll
2017-04-28 00:39:48 962760 ----a-w- c:\windows\system32\ole32.dll
2017-04-28 00:39:22 4312248 ----a-w- c:\windows\explorer.exe
2017-04-28 00:38:56 1384704 ----a-w- c:\windows\system32\sppobjs.dll
2017-04-28 00:35:23 1411616 ----a-w- c:\windows\system32\gdi32full.dll
2017-04-28 00:33:18 380184 ----a-w- c:\windows\system32\services.exe
2017-04-28 00:29:28 5685760 ----a-w- c:\windows\system32\Windows.Data.Pdf.dll
2017-04-28 00:26:56 281088 ----a-w- c:\windows\system32\RDXTaskFactory.dll
2017-04-28 00:23:19 95232 ----a-w- c:\windows\system32\UserDataTimeUtil.dll
2017-04-28 00:23:10 1631232 ----a-w- c:\windows\system32\Windows.UI.Xaml.Resources.dll
2017-04-28 00:22:46 26112 ----a-w- c:\windows\system32\odbcconf.dll
2017-04-28 00:22:16 165376 ----a-w- c:\windows\system32\ReInfo.dll
2017-04-28 00:22:08 69120 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2017-04-28 00:21:41 27648 ----a-w- c:\windows\system32\BthTelemetry.dll
2017-04-28 00:21:26 73728 ----a-w- c:\windows\system32\tdc.ocx
2017-04-28 00:21:14 224256 ----a-w- c:\windows\system32\ExSMime.dll
2017-04-28 00:20:50 44032 ----a-w- c:\windows\system32\virtdisk.dll
2017-04-28 00:20:47 141824 ----a-w- c:\windows\system32\Windows.Devices.Radios.dll
2017-04-28 00:20:27 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2017-04-28 00:20:23 30720 ----a-w- c:\windows\system32\drivers\vwifimp.sys
2017-04-28 00:20:00 203776 ----a-w- c:\windows\system32\drivers\BthLEEnum.sys
2017-04-28 00:19:33 119296 ----a-w- c:\windows\system32\Family.Client.dll
2017-04-28 00:19:26 584192 ----a-w- c:\windows\system32\UIRibbonRes.dll
2017-04-28 00:19:24 98304 ----a-w- c:\windows\system32\appidsvc.dll
2017-04-28 00:19:15 156672 ----a-w- c:\windows\system32\UserDeviceRegistration.dll
2017-04-28 00:19:07 94208 ----a-w- c:\windows\system32\drivers\bridge.sys
2017-04-28 00:19:05 138240 ----a-w- c:\windows\system32\DisplayManager.dll
2017-04-28 00:18:43 450560 ----a-w- c:\windows\system32\rastls.dll
2017-04-28 00:18:37 255488 ----a-w- c:\windows\system32\unimdm.tsp
2017-04-28 00:18:35 285184 ----a-w- c:\windows\system32\Windows.UI.BlockedShutdown.dll
2017-04-28 00:18:31 254464 ----a-w- c:\windows\system32\drivers\wmbclass.sys
2017-04-28 00:17:57 136192 ----a-w- c:\windows\system32\WinRtTracing.dll
2017-04-28 00:17:50 94208 ----a-w- c:\windows\system32\Windows.StateRepositoryClient.dll
2017-04-28 00:17:39 330752 ----a-w- c:\windows\system32\aadcloudap.dll
2017-04-28 00:17:36 95232 ----a-w- c:\windows\system32\BluetoothApis.dll
2017-04-28 00:17:02 186880 ----a-w- c:\windows\system32\Family.SyncEngine.dll
2017-04-28 00:17:01 142336 ----a-w- c:\windows\system32\Windows.Devices.WiFi.dll
2017-04-28 00:15:44 334848 ----a-w- c:\windows\system32\rastlsext.dll
2017-04-28 00:15:41 216576 ----a-w- c:\windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-28 00:15:38 237568 ----a-w- c:\windows\system32\SyncSettings.dll
2017-04-28 00:15:35 206336 ----a-w- c:\windows\system32\bthprops.cpl
2017-04-28 00:15:29 404992 ----a-w- c:\windows\system32\dsreg.dll
2017-04-28 00:15:14 822784 ----a-w- c:\windows\system32\Chakradiag.dll
2017-04-28 00:15:12 102400 ----a-w- c:\windows\system32\ConsentUX.dll
2017-04-28 00:15:11 557568 ----a-w- c:\windows\system32\StoreAgent.dll
2017-04-28 00:15:09 774144 ----a-w- c:\windows\system32\SystemSettings.Handlers.dll
2017-04-28 00:14:11 670208 ----a-w- c:\windows\system32\Windows.Devices.PointOfService.dll
2017-04-28 00:14:06 223232 ----a-w- c:\windows\system32\InstallAgentUserBroker.exe
2017-04-28 00:14:01 483840 ----a-w- c:\windows\system32\Windows.Devices.AllJoyn.dll
2017-04-28 00:14:00 445952 ----a-w- c:\windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-04-28 00:14:00 306688 ----a-w- c:\windows\system32\ieproxy.dll
2017-04-28 00:12:58 284672 ----a-w- c:\windows\system32\apprepsync.dll
2017-04-28 00:12:52 273920 ----a-w- c:\windows\system32\PrintDialogs3D.dll
.
============= FINISH: 19:41:54,61 ===============
zie deel 2/2 voor DDS attach log en GMER logfile
grtz,
Bintang
Comment