+ Plaats een Reactie
Pagina 1 van de 2 12 LaatsteLaatste
Resultaten 1 tot 15 van de 20

Onderwerp: IA store icon/foutmelding internet explorer & outlook/

  1. #1

    Ingeschreven
    Jan 2012
    Berichten
    11

    IA store icon/foutmelding internet explorer & outlook/

    OS: windows 7 (64)
    - reeds gescand met AVG (geen infecties gevonden)
    - malware: 3 infecties gevonden en verwijderd

    PS: in normale modus werkt outlook niet, kan er niets gedownload worden (executives functioneren niet), in veilige modus echter werkt outlook wel, alsook de meeste downloads.

    bij opstart windows, foutmelding: IA Stor icon has stopped working. Vervolgens bij opstart internet explorer: a computer program has corrupted your default search setting for internet explorer. Internet Explorer has reset this setting to your original search provider (http://www.bing.com) Internet Explorer will now open Search settings, where you can change this setting or install more search providers:


    Malwarebytes' Anti-Malware log:

    Malwarebytes Anti-Malware 1.60.0.1800
    www.malwarebytes.org

    Databaseversie: v2012.01.06.02

    Windows 7 Service Pack 1 x64 NTFS (Veilige modus/netwerkmogelijkheden)
    Internet Explorer 9.0.8112.16421
    Fluxys :: HOME874C87 [administrator]

    06/01/2012 18:55:32
    mbam-log-2012-01-06 (18-55-32).txt

    Scantype: Snelle scan
    Ingeschakelde scanopties: Geheugen | Opstarten | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scanopties: P2P
    Objecten gescand: 175762
    Verstreken tijd: 2 minuut/minuten,

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    (einde)


    HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 18:50:33, on 06/01/2012
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16421)
    Boot mode: Safe mode with network support

    Running processes:
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Users\Fluxys\AppData\Local\Temp\HouseCall32\housecall.bin
    C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
    C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
    O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
    O4 - HKLM\..\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CyberLink Product - 2010/11/05 21:10:50 (CLKMSVC10_C6F09094) - CyberLink - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 13231 bytes

  2. #2
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Download ComboFix van één van deze locaties:

    Link 1
    Link 2


    * BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op.

    >>Hier<< kunt u lezen hoe u Combofix dient te gebruiken.






    1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix.

    * (hier of hier staat een handleiding over hoe je deze kan uitschakelen: )

    2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.
    3. Dubbelklik op "Combofix.exe" om de tool te starten.
    4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

    * Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion." herstart dan de computer.

    5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  3. #3

    Ingeschreven
    Jan 2012
    Berichten
    11
    ComboFix 12-01-06.01 - Fluxys 06/01/2012 19:57:09.1.8 - x64 NETWORK
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.16343.14779 [GMT 1:00]
    Running from: c:\users\Fluxys\Desktop\ComboFix.exe
    AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Fluxys\AppData\Roaming\inst.exe
    c:\users\Fluxys\AppData\Roaming\vso_ts_preview.xml
    c:\users\Fluxys\GoToAssistDownloadHelper.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-06 19:01 . 2012-01-06 19:01 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-01-06 18:58 . 2012-01-06 18:58 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78A652E6-7C52-40D5-AFB7-AE6AD03EF040}\offreg.dll
    2012-01-06 17:36 . 2011-06-21 04:09 200976 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys
    2012-01-06 17:07 . 2012-01-06 17:07 -------- d--h--w- c:\programdata\Common Files
    2012-01-06 17:05 . 2012-01-06 17:05 13048 ----a-w- c:\windows\system32\avgrssta.dll
    2012-01-06 17:03 . 2012-01-06 17:03 388096 ----a-r- c:\users\Fluxys\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2012-01-06 17:03 . 2012-01-06 17:03 -------- d-----w- c:\program files (x86)\Trend Micro
    2012-01-06 16:52 . 2012-01-06 16:52 -------- d-----w- C:\$AVG
    2012-01-06 16:52 . 2012-01-06 17:05 56008 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
    2012-01-06 16:52 . 2012-01-06 17:05 317520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
    2012-01-06 16:52 . 2012-01-06 17:05 269904 ----a-w- c:\windows\system32\drivers\avgldx64.sys
    2012-01-06 16:52 . 2012-01-06 17:05 35664 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
    2012-01-06 16:52 . 2012-01-06 16:52 -------- d-----w- c:\windows\system32\drivers\Avg
    2012-01-06 16:51 . 2012-01-06 16:51 -------- d-----w- c:\programdata\avg9
    2012-01-06 16:51 . 2012-01-06 16:51 -------- d-----w- c:\program files (x86)\AVG
    2012-01-06 12:55 . 2012-01-06 12:55 -------- d-----w- c:\users\Fluxys\AppData\Roaming\Malwarebytes
    2012-01-06 12:55 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-01-05 23:51 . 2012-01-05 23:51 -------- d-----w- c:\program files (x86)\Common Files\Java
    2012-01-05 23:47 . 2012-01-05 23:47 -------- d-----w- c:\users\Fluxys\AppData\Roaming\F-Secure
    2012-01-05 19:19 . 2012-01-06 17:03 -------- d-----w- C:\temp
    2012-01-03 20:36 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78A652E6-7C52-40D5-AFB7-AE6AD03EF040}\mpengine.dll
    2012-01-02 14:08 . 2012-01-02 14:16 -------- d-----w- c:\programdata\iolo
    2012-01-02 10:46 . 2012-01-02 11:24 42672 ----a-w- c:\windows\SysWow64\drivers\fsbts.sys
    2012-01-02 10:45 . 2012-01-06 00:02 -------- d-----w- c:\program files (x86)\Telenet Security Pack
    2012-01-02 10:43 . 2012-01-02 10:45 -------- d-----w- c:\programdata\fssg
    2012-01-02 10:43 . 2012-01-06 00:01 -------- d-----w- c:\programdata\f-secure
    2012-01-02 10:37 . 2012-01-06 12:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\programdata\Malwarebytes
    2012-01-01 13:54 . 2012-01-06 16:26 -------- d-----w- c:\users\Fluxys\AppData\Local\ElevatedDiagnostics
    2012-01-01 13:23 . 2008-05-07 18:59 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
    2011-12-26 15:08 . 2011-12-26 15:08 -------- d-----w- c:\program files (x86)\VirtualDJ
    2011-12-26 14:31 . 2011-12-26 14:31 -------- d-----w- c:\program files\iPod
    2011-12-26 14:31 . 2011-12-26 14:32 -------- d-----w- c:\program files\iTunes
    2011-12-26 14:31 . 2011-12-26 14:32 -------- d-----w- c:\program files (x86)\iTunes
    2011-12-14 15:54 . 2011-12-14 15:54 -------- d-----w- c:\windows\SysWow64\siscardplugins
    2011-12-14 15:47 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
    2011-12-14 15:47 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
    2011-12-14 15:47 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
    2011-12-14 15:47 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-12-14 15:47 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-12-14 15:47 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-01-06 11:39 . 2011-05-17 16:36 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
    2012-01-05 18:52 . 2011-05-17 16:34 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
    2012-01-03 20:36 . 2011-05-17 16:34 704336 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
    2011-12-14 11:29 . 2011-05-19 15:27 704336 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2011-12-04 12:35 . 2011-12-04 12:35 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
    2011-12-04 12:35 . 2011-12-04 12:35 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
    2011-11-19 18:42 . 2011-11-19 18:42 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys
    2011-11-19 18:42 . 2011-11-19 18:42 82816 ----a-w- c:\users\Fluxys\AppData\Roaming\pcouffin.sys
    2011-11-15 13:29 . 2010-11-24 08:25 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-11-10 04:54 . 2011-04-26 16:57 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
    2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-09-28 1715768]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-12-04 296056]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
    "LaunchHPOSIAPP"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe" [2009-04-04 385024]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
    "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-04-25 305088]
    "beid"="c:\program files (x86)\Belgium Identity Card\beid35gui.exe" [2011-07-06 2068480]
    "BATINDICATOR"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe" [2009-05-08 2068992]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-06 2076512]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "HideFastUserSwitching"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "EnableShellExecuteHooks"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [x]
    R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [x]
    R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x]
    R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    R2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2012-01-06 308136]
    R2 CLKMSVC10_C6F09094;CyberLink Product - 2010/11/05 21:10;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-06-30 245232]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 136176]
    R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560]
    R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
    R3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys [x]
    R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
    R3 CXCIR;AVerMedia Consumer Infrared Receiver;c:\windows\system32\DRIVERS\AVer888RCIR_64.sys [x]
    R3 EMVSCARD;EMVSCARD;c:\windows\system32\Drivers\EMVSCARD.sys [x]
    R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
    R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 136176]
    R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [x]
    S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 19:20]
    .
    2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 19:20]
    .
    2012-01-05 c:\windows\Tasks\HPCeeScheduleForFluxys.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
    .
    2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{5FA94B92-692D-4F39-B72B-3E89CC89FB3F}.job
    - c:\windows\system32\msfeedssync.exe [2011-06-01 07:50]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-18 568888]
    "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x1
    "AppInit_DLLs"=c:\windows\System32\avgrssta.dll
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.be/
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://www.bing.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    TCP: DhcpNameServer = 192.168.0.1
    FF - ProfilePath - c:\users\Fluxys\AppData\Roaming\Mozilla\Firefox\Profiles\bq9wnmer.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.be
    .
    - - - - ORPHANS REMOVED - - - -
    .
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - c:\program files (x86)\InstallShield Installation Information\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\setup.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1983625899-2747462429-1117706802-1000_Classes\Wow6432Node\CLSID\{3d29161d-c71a-43cf-bc38-56e9cc43b8e7}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:000000a1
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,c3,4d,9e,47,61,a7,8f,c3,c6,d9,0d,66,8a,e8,c0,2b,79,a9,95,8c,a1,17,\
    .
    [HKEY_USERS\S-1-5-21-1983625899-2747462429-1117706802-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):04,46,00,37,9b,56,b5,26,24,b3,9e,2f,49,cb,3d,71,37,67,d2,fb,98,
    97,5b,e5,a0,a8,1f,6f,ca,e5,ac,44,87,ad,43,1c,4f,8a,20,cb,00,00,00,00,00,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-01-06 20:02:26
    ComboFix-quarantined-files.txt 2012-01-06 19:02
    .
    Pre-Run: 26.930.274.304 bytes free
    Post-Run: 26.872.594.432 bytes free
    .
    - - End Of File - - 47F7C32DF9B1E83A88EEEAA87C5CE24C

  4. #4
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Download TDSSKiller en plaats het op je bureaublad.
    • Pak de bestanden in tdsskiller.zip uit.
    • Open de map tdsskiller en dubbelklik op TDSSKiller.exe om de tool te starten.
    • Let op!!! Windows Vista & 7 gebruikers dienen TDSSkiller als administrator uit te voeren "Rechtermuisknop uitvoeren als",
    • Als er door TDSSkiller een update wordt gevonden klikt u op de knop "Load update"
    • Een nieuwe versie van TDSSkiller zal nu gedownload worden en sla deze op het bureaublad op.
    • Start nu TDSSkiller opnieuw.
    • Klik op "Change parameters" en zorg dat de onderstaande opties allemaal aangevinkt zijn.
    • Klik op de knop "Start Scan" en volg de instructies.
    • Wanneer de scan klaar is klik je op de knop "Report".
    • Selecteer de inhoud (log) en plaats deze in uw volgende bericht.

    Wanneer er een herstart nodig was, vind je de logfile in C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt



    De unsigned files skip je, TDSS File System laat je verwijderen of in quarantaine zetten, delete of copy to quarantine

    Rootkit.Boot.SST.b en anderen zoals Sinowal, ZeroAccess of Whistler laat je herstellen Cure.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  5. #5
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    plaats het in delen het zal te groot zijn.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  6. #6

    Ingeschreven
    Jan 2012
    Berichten
    11

    tdsskiller

    sorry, log was te groot om te posten, ik doe het in 2 delen. 2 unsigned errors gevonden, die ik geskipt heb.

    21:11:46.0988 3004 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
    21:11:47.0035 3004 ============================================================
    21:11:47.0035 3004 Current date / time: 2012/01/06 21:11:47.0035
    21:11:47.0035 3004 SystemInfo:
    21:11:47.0035 3004
    21:11:47.0035 3004 OS Version: 6.1.7601 ServicePack: 1.0
    21:11:47.0035 3004 Product type: Workstation
    21:11:47.0035 3004 ComputerName: HOME874C87
    21:11:47.0035 3004 UserName: Fluxys
    21:11:47.0035 3004 Windows directory: C:\Windows
    21:11:47.0035 3004 System windows directory: C:\Windows
    21:11:47.0035 3004 Running under WOW64
    21:11:47.0035 3004 Processor architecture: Intel x64
    21:11:47.0035 3004 Number of processors: 8
    21:11:47.0035 3004 Page size: 0x1000
    21:11:47.0035 3004 Boot type: Normal boot
    21:11:47.0035 3004 ============================================================
    21:11:47.0503 3004 Initialize success
    21:12:29.0997 5140 ============================================================
    21:12:29.0997 5140 Scan started
    21:12:29.0997 5140 Mode: Manual; SigCheck; TDLFS;
    21:12:29.0997 5140 ============================================================

    21:12:30.0200 5140 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
    21:12:30.0262 5140 1394ohci - ok
    21:12:30.0278 5140 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
    21:12:30.0293 5140 ACPI - ok
    21:12:30.0309 5140 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
    21:12:30.0356 5140 AcpiPmi - ok
    21:12:30.0496 5140 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    21:12:30.0496 5140 adp94xx - ok
    21:12:30.0543 5140 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    21:12:30.0543 5140 adpahci - ok
    21:12:30.0574 5140 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    21:12:30.0574 5140 adpu320 - ok
    21:12:30.0637 5140 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
    21:12:30.0683 5140 AFD - ok
    21:12:30.0746 5140 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
    21:12:30.0746 5140 agp440 - ok
    21:12:30.0777 5140 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
    21:12:30.0777 5140 aliide - ok
    21:12:30.0793 5140 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
    21:12:30.0793 5140 amdide - ok
    21:12:30.0824 5140 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    21:12:30.0871 5140 AmdK8 - ok
    21:12:30.0917 5140 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    21:12:30.0949 5140 AmdPPM - ok
    21:12:30.0995 5140 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
    21:12:31.0011 5140 amdsata - ok
    21:12:31.0058 5140 amdsbs (f67f933e79241ed32ff46a4f29b5120 C:\Windows\system32\DRIVERS\amdsbs.sys
    21:12:31.0073 5140 amdsbs - ok
    21:12:31.0089 5140 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
    21:12:31.0089 5140 amdxata - ok
    21:12:31.0136 5140 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
    21:12:31.0229 5140 AppID - ok
    21:12:31.0354 5140 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    21:12:31.0370 5140 arc - ok
    21:12:31.0385 5140 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    21:12:31.0385 5140 arcsas - ok
    21:12:31.0417 5140 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    21:12:31.0526 5140 AsyncMac - ok
    21:12:31.0619 5140 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
    21:12:31.0619 5140 atapi - ok
    21:12:31.0682 5140 AVer7231_x64 (eb1b01221c444a669f85136c43a40b74) C:\Windows\system32\DRIVERS\AVer7231_x64.sys
    21:12:31.0744 5140 AVer7231_x64 - ok
    21:12:31.0838 5140 AvgLdx64 (b447db072bf939db9e07bef2adf4ecbd) C:\Windows\System32\Drivers\avgldx64.sys
    21:12:31.0869 5140 AvgLdx64 - ok
    21:12:31.0916 5140 AvgMfx64 (0db5a749acd8e66091736f88c40207bd) C:\Windows\System32\Drivers\avgmfx64.sys
    21:12:31.0916 5140 AvgMfx64 - ok
    21:12:31.0947 5140 AvgRkx64 (5e7f0f9cbe0f7823371a4d51df29f7ff) C:\Windows\system32\Drivers\avgrkx64.sys
    21:12:31.0963 5140 AvgRkx64 - ok
    21:12:31.0978 5140 AvgTdiA (8aa68c0ba2b84fd7eb3e1f10bbfc825 C:\Windows\System32\Drivers\avgtdia.sys
    21:12:31.0994 5140 AvgTdiA - ok
    21:12:32.0087 5140 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    21:12:32.0134 5140 b06bdrv - ok
    21:12:32.0150 5140 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    21:12:32.0197 5140 b57nd60a - ok
    21:12:32.0259 5140 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    21:12:32.0275 5140 Beep - ok
    21:12:32.0337 5140 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    21:12:32.0353 5140 blbdrive - ok
    21:12:32.0431 5140 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
    21:12:32.0477 5140 bowser - ok
    21:12:32.0509 5140 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    21:12:32.0555 5140 BrFiltLo - ok
    21:12:32.0602 5140 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    21:12:32.0633 5140 BrFiltUp - ok
    21:12:32.0727 5140 BridgeMP (5c2f352a4e961d72518261257aae204 C:\Windows\system32\DRIVERS\bridge.sys
    21:12:32.0758 5140 BridgeMP - ok
    21:12:32.0805 5140 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    21:12:32.0836 5140 Brserid - ok
    21:12:32.0883 5140 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    21:12:32.0914 5140 BrSerWdm - ok
    21:12:32.0961 5140 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    21:12:32.0992 5140 BrUsbMdm - ok
    21:12:32.0992 5140 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    21:12:33.0008 5140 BrUsbSer - ok
    21:12:33.0055 5140 BthAvrcp (832b121e4532919cc49f2438f1dcaa21) C:\Windows\system32\DRIVERS\BthAvrcp.sys
    21:12:33.0086 5140 BthAvrcp - ok
    21:12:33.0179 5140 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
    21:12:33.0211 5140 BthEnum - ok
    21:12:33.0273 5140 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    21:12:33.0289 5140 BTHMODEM - ok
    21:12:33.0320 5140 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
    21:12:33.0335 5140 BthPan - ok
    21:12:33.0367 5140 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys
    21:12:33.0398 5140 BTHPORT - ok
    21:12:33.0476 5140 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys
    21:12:33.0491 5140 BTHUSB - ok
    21:12:33.0523 5140 catchme - ok
    21:12:33.0569 5140 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    21:12:33.0601 5140 cdfs - ok
    21:12:33.0647 5140 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
    21:12:33.0663 5140 cdrom - ok
    21:12:33.0741 5140 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    21:12:33.0757 5140 circlass - ok
    21:12:33.0803 5140 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    21:12:33.0803 5140 CLFS - ok
    21:12:33.0866 5140 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    21:12:33.0881 5140 CmBatt - ok
    21:12:33.0913 5140 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
    21:12:33.0928 5140 cmdide - ok
    21:12:33.0991 5140 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
    21:12:34.0022 5140 CNG - ok
    21:12:34.0053 5140 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    21:12:34.0069 5140 Compbatt - ok
    21:12:34.0115 5140 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
    21:12:34.0131 5140 CompositeBus - ok
    21:12:34.0209 5140 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    21:12:34.0209 5140 crcdisk - ok
    21:12:34.0271 5140 ctxusbm (ba8e5b2291c01ef71ca80e25f0c79d55) C:\Windows\system32\DRIVERS\ctxusbm.sys
    21:12:34.0287 5140 ctxusbm - ok
    21:12:34.0303 5140 CXCIR (7d8451566fe3d9332e79751e58ec2ee0) C:\Windows\system32\DRIVERS\AVer888RCIR_64.sys
    21:12:34.0334 5140 CXCIR - ok
    21:12:34.0381 5140 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
    21:12:34.0412 5140 DfsC - ok
    21:12:34.0474 5140 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    21:12:34.0505 5140 discache - ok
    21:12:34.0537 5140 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    21:12:34.0552 5140 Disk - ok
    21:12:34.0568 5140 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    21:12:34.0599 5140 drmkaud - ok
    21:12:34.0630 5140 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
    21:12:34.0646 5140 DXGKrnl - ok
    21:12:34.0755 5140 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    21:12:34.0802 5140 ebdrv - ok
    21:12:34.0880 5140 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    21:12:34.0895 5140 elxstor - ok
    21:12:34.0989 5140 EMVSCARD (647c55949dd6c4c9e7c74a22e64f84ff) C:\Windows\system32\Drivers\EMVSCARD.sys
    21:12:35.0005 5140 EMVSCARD - ok
    21:12:35.0051 5140 epmntdrv (9eafb3b3b60b8ad958985152a9309aca) C:\Windows\system32\epmntdrv.sys
    21:12:35.0067 5140 epmntdrv ( UnsignedFile.Multi.Generic ) - warning
    21:12:35.0067 5140 epmntdrv - detected UnsignedFile.Multi.Generic (1)
    21:12:35.0098 5140 ErrDev (34a3c54752046e79a126e15c51db409 C:\Windows\system32\drivers\errdev.sys
    21:12:35.0114 5140 ErrDev - ok
    21:12:35.0145 5140 EuGdiDrv (fb949ed2c93c878a189039f3d7730942) C:\Windows\system32\EuGdiDrv.sys
    21:12:35.0161 5140 EuGdiDrv ( UnsignedFile.Multi.Generic ) - warning
    21:12:35.0161 5140 EuGdiDrv - detected UnsignedFile.Multi.Generic (1)
    21:12:35.0254 5140 exfat (a510c654ec00c1e9bdd91eeb3a59823 C:\Windows\system32\drivers\exfat.sys
    21:12:35.0285 5140 exfat - ok
    21:12:35.0301 5140 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    21:12:35.0332 5140 fastfat - ok
    21:12:35.0395 5140 fdc (d765d19cd8ef61f650c384f62fac00a C:\Windows\system32\DRIVERS\fdc.sys
    21:12:35.0410 5140 fdc - ok
    21:12:35.0488 5140 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    21:12:35.0488 5140 FileInfo - ok
    21:12:35.0519 5140 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    21:12:35.0551 5140 Filetrace - ok
    21:12:35.0566 5140 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    21:12:35.0582 5140 flpydisk - ok
    21:12:35.0613 5140 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
    21:12:35.0629 5140 FltMgr - ok
    21:12:35.0707 5140 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    21:12:35.0707 5140 FsDepends - ok
    21:12:35.0738 5140 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    21:12:35.0753 5140 Fs_Rec - ok
    21:12:35.0800 5140 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
    21:12:35.0800 5140 fvevol - ok
    21:12:35.0816 5140 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    21:12:35.0831 5140 gagp30kx - ok
    21:12:35.0863 5140 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    21:12:35.0863 5140 GEARAspiWDM - ok
    21:12:35.0972 5140 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    21:12:36.0003 5140 hcw85cir - ok
    21:12:36.0034 5140 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
    21:12:36.0065 5140 HdAudAddService - ok
    21:12:36.0112 5140 HDAudBus (97bfed39b6b79eb12cddbfeed51f56b C:\Windows\system32\drivers\HDAudBus.sys
    21:12:36.0143 5140 HDAudBus - ok
    21:12:36.0221 5140 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
    21:12:36.0237 5140 HECIx64 - ok
    21:12:36.0253 5140 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    21:12:36.0268 5140 HidBatt - ok
    21:12:36.0299 5140 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    21:12:36.0315 5140 HidBth - ok
    21:12:36.0346 5140 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    21:12:36.0377 5140 HidIr - ok
    21:12:36.0471 5140 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
    21:12:36.0487 5140 HidUsb - ok
    21:12:36.0580 5140 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
    21:12:36.0580 5140 HpSAMD - ok
    21:12:36.0674 5140 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
    21:12:36.0721 5140 HTTP - ok
    21:12:36.0752 5140 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
    21:12:36.0752 5140 hwpolicy - ok
    21:12:36.0799 5140 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
    21:12:36.0814 5140 i8042prt - ok
    21:12:36.0908 5140 iaStor (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
    21:12:36.0908 5140 iaStor - ok
    21:12:36.0955 5140 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
    21:12:36.0955 5140 iaStorV - ok
    21:12:36.0986 5140 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    21:12:37.0001 5140 iirsp - ok
    21:12:37.0064 5140 IntcAzAudAddService (dab7318ccfa8081200d5b7b486793f74) C:\Windows\system32\drivers\RTKVHD64.sys
    21:12:37.0079 5140 IntcAzAudAddService - ok
    21:12:37.0173 5140 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
    21:12:37.0173 5140 intelide - ok
    21:12:37.0220 5140 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    21:12:37.0235 5140 intelppm - ok
    21:12:37.0282 5140 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:12:37.0298 5140 IpFilterDriver - ok
    21:12:37.0329 5140 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
    21:12:37.0345 5140 IPMIDRV - ok
    21:12:37.0423 5140 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    21:12:37.0454 5140 IPNAT - ok
    21:12:37.0501 5140 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    21:12:37.0516 5140 IRENUM - ok
    21:12:37.0563 5140 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
    21:12:37.0579 5140 isapnp - ok
    21:12:37.0641 5140 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
    21:12:37.0657 5140 iScsiPrt - ok
    21:12:37.0688 5140 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
    21:12:37.0688 5140 kbdclass - ok
    21:12:37.0719 5140 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
    21:12:37.0735 5140 kbdhid - ok
    21:12:37.0766 5140 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
    21:12:37.0781 5140 KSecDD - ok
    21:12:37.0797 5140 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
    21:12:37.0813 5140 KSecPkg - ok
    21:12:37.0891 5140 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    21:12:37.0922 5140 ksthunk - ok
    21:12:37.0984 5140 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    21:12:38.0015 5140 lltdio - ok
    21:12:38.0109 5140 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    21:12:38.0109 5140 LSI_FC - ok
    21:12:38.0125 5140 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    21:12:38.0140 5140 LSI_SAS - ok
    21:12:38.0156 5140 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    21:12:38.0156 5140 LSI_SAS2 - ok
    21:12:38.0171 5140 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    21:12:38.0171 5140 LSI_SCSI - ok
    21:12:38.0218 5140 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    21:12:38.0249 5140 luafv - ok
    21:12:38.0327 5140 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    21:12:38.0343 5140 megasas - ok
    21:12:38.0374 5140 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    21:12:38.0374 5140 MegaSR - ok
    21:12:38.0405 5140 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    21:12:38.0421 5140 Modem - ok
    21:12:38.0437 5140 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    21:12:38.0468 5140 monitor - ok
    21:12:38.0577 5140 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    21:12:38.0577 5140 mouclass - ok
    21:12:38.0608 5140 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    21:12:38.0624 5140 mouhid - ok
    21:12:38.0671 5140 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
    21:12:38.0671 5140 mountmgr - ok
    21:12:38.0702 5140 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
    21:12:38.0702 5140 mpio - ok
    21:12:38.0733 5140 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    21:12:38.0749 5140 mpsdrv - ok
    21:12:38.0842 5140 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
    21:12:38.0873 5140 MRxDAV - ok
    Laatst gewijzigd door BartQuanten; 06-01-12 om 21:35.

  7. #7

    Ingeschreven
    Jan 2012
    Berichten
    11

    TDSSKiller deel 2

    21:12:38.0889 5140 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:12:38.0920 5140 mrxsmb - ok
    21:12:38.0951 5140 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:12:38.0967 5140 mrxsmb10 - ok
    21:12:39.0014 5140 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:12:39.0029 5140 mrxsmb20 - ok
    21:12:39.0107 5140 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
    21:12:39.0107 5140 msahci - ok
    21:12:39.0139 5140 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
    21:12:39.0154 5140 msdsm - ok
    21:12:39.0185 5140 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    21:12:39.0217 5140 Msfs - ok
    21:12:39.0248 5140 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    21:12:39.0279 5140 mshidkmdf - ok
    21:12:39.0357 5140 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
    21:12:39.0373 5140 msisadrv - ok
    21:12:39.0388 5140 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    21:12:39.0419 5140 MSKSSRV - ok
    21:12:39.0451 5140 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    21:12:39.0482 5140 MSPCLOCK - ok
    21:12:39.0497 5140 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    21:12:39.0544 5140 MSPQM - ok
    21:12:39.0622 5140 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
    21:12:39.0622 5140 MsRPC - ok
    21:12:39.0653 5140 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
    21:12:39.0669 5140 mssmbios - ok
    21:12:39.0700 5140 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    21:12:39.0731 5140 MSTEE - ok
    21:12:39.0778 5140 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    21:12:39.0794 5140 MTConfig - ok
    21:12:39.0809 5140 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    21:12:39.0825 5140 Mup - ok
    21:12:39.0919 5140 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    21:12:39.0950 5140 NativeWifiP - ok
    21:12:39.0997 5140 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
    21:12:40.0012 5140 NDIS - ok
    21:12:40.0043 5140 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    21:12:40.0075 5140 NdisCap - ok
    21:12:40.0106 5140 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    21:12:40.0121 5140 NdisTapi - ok
    21:12:40.0199 5140 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
    21:12:40.0231 5140 Ndisuio - ok
    21:12:40.0262 5140 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
    21:12:40.0293 5140 NdisWan - ok
    21:12:40.0324 5140 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
    21:12:40.0355 5140 NDProxy - ok
    21:12:40.0387 5140 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    21:12:40.0418 5140 NetBIOS - ok
    21:12:40.0496 5140 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
    21:12:40.0543 5140 NetBT - ok
    21:12:40.0589 5140 netr28x (064ab63c9a588d2611306ae16d017e7e) C:\Windows\system32\DRIVERS\netr28x.sys
    21:12:40.0605 5140 netr28x - ok
    21:12:40.0652 5140 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    21:12:40.0652 5140 nfrd960 - ok
    21:12:40.0714 5140 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    21:12:40.0745 5140 Npfs - ok
    21:12:40.0761 5140 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    21:12:40.0792 5140 nsiproxy - ok
    21:12:40.0839 5140 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
    21:12:40.0870 5140 Ntfs - ok
    21:12:40.0886 5140 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    21:12:40.0917 5140 Null - ok
    21:12:41.0135 5140 nvlddmkm (2f34fc7ecb80fa0168fe8683ca1875b3) C:\Windows\system32\DRIVERS\nvlddmkm.sys
    21:12:41.0260 5140 nvlddmkm - ok
    21:12:41.0338 5140 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
    21:12:41.0354 5140 nvraid - ok
    21:12:41.0369 5140 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
    21:12:41.0369 5140 nvstor - ok
    21:12:41.0401 5140 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
    21:12:41.0416 5140 nv_agp - ok
    21:12:41.0447 5140 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
    21:12:41.0479 5140 ohci1394 - ok
    21:12:41.0619 5140 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    21:12:41.0635 5140 Parport - ok
    21:12:41.0650 5140 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
    21:12:41.0666 5140 partmgr - ok
    21:12:41.0681 5140 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
    21:12:41.0697 5140 pci - ok
    21:12:41.0713 5140 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
    21:12:41.0728 5140 pciide - ok
    21:12:41.0759 5140 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    21:12:41.0759 5140 pcmcia - ok
    21:12:41.0853 5140 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys
    21:12:41.0884 5140 pcouffin - ok
    21:12:41.0900 5140 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    21:12:41.0915 5140 pcw - ok
    21:12:41.0947 5140 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    21:12:41.0978 5140 PEAUTH - ok
    21:12:42.0103 5140 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
    21:12:42.0134 5140 PptpMiniport - ok
    21:12:42.0149 5140 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    21:12:42.0181 5140 Processor - ok
    21:12:42.0212 5140 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
    21:12:42.0243 5140 Psched - ok
    21:12:42.0290 5140 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    21:12:42.0321 5140 ql2300 - ok
    21:12:42.0399 5140 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    21:12:42.0399 5140 ql40xx - ok
    21:12:42.0430 5140 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    21:12:42.0446 5140 QWAVEdrv - ok
    21:12:42.0477 5140 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    21:12:42.0524 5140 RasAcd - ok
    21:12:42.0539 5140 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    21:12:42.0571 5140 RasAgileVpn - ok
    21:12:42.0664 5140 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:12:42.0695 5140 Rasl2tp - ok
    21:12:42.0727 5140 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    21:12:42.0758 5140 RasPppoe - ok
    21:12:42.0773 5140 RasSstp (e8b1e447b008d07ff47d016c2b0eeec C:\Windows\system32\DRIVERS\rassstp.sys
    21:12:42.0805 5140 RasSstp - ok
    21:12:42.0883 5140 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
    21:12:42.0914 5140 rdbss - ok
    21:12:42.0929 5140 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    21:12:42.0945 5140 rdpbus - ok
    21:12:42.0976 5140 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:12:43.0023 5140 RDPCDD - ok
    21:12:43.0039 5140 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    21:12:43.0054 5140 RDPENCDD - ok
    21:12:43.0085 5140 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    21:12:43.0101 5140 RDPREFMP - ok
    21:12:43.0179 5140 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
    21:12:43.0210 5140 RDPWD - ok
    21:12:43.0226 5140 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
    21:12:43.0241 5140 rdyboost - ok
    21:12:43.0288 5140 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
    21:12:43.0304 5140 RFCOMM - ok
    21:12:43.0382 5140 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    21:12:43.0413 5140 rspndr - ok
    21:12:43.0444 5140 RTL8167 (7ea8d2eb9bbfd2ab8a3117a1e96d3b3a) C:\Windows\system32\DRIVERS\Rt64win7.sys
    21:12:43.0460 5140 RTL8167 - ok
    21:12:43.0475 5140 sbp2port (ac03af3329579fffb455aa2daabbe22 C:\Windows\system32\drivers\sbp2port.sys
    21:12:43.0491 5140 sbp2port - ok
    21:12:43.0522 5140 scfilter (253f38d0d7074c02ff8deb9836c97d2 C:\Windows\system32\DRIVERS\scfilter.sys
    21:12:43.0553 5140 scfilter - ok
    21:12:43.0631 5140 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    21:12:43.0663 5140 secdrv - ok
    21:12:43.0709 5140 Serenum (cb624c0035412af0debec78c41f5ca1 C:\Windows\system32\DRIVERS\serenum.sys
    21:12:43.0725 5140 Serenum - ok
    21:12:43.0756 5140 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    21:12:43.0772 5140 Serial - ok
    21:12:43.0865 5140 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    21:12:43.0865 5140 sermouse - ok
    21:12:43.0897 5140 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
    21:12:43.0928 5140 sffdisk - ok
    21:12:43.0943 5140 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
    21:12:43.0959 5140 sffp_mmc - ok
    21:12:43.0975 5140 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
    21:12:43.0990 5140 sffp_sd - ok
    21:12:44.0068 5140 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    21:12:44.0099 5140 sfloppy - ok
    21:12:44.0131 5140 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    21:12:44.0131 5140 SiSRaid2 - ok
    21:12:44.0146 5140 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    21:12:44.0162 5140 SiSRaid4 - ok
    21:12:44.0193 5140 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    21:12:44.0224 5140 Smb - ok
    21:12:44.0318 5140 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    21:12:44.0318 5140 spldr - ok
    21:12:44.0349 5140 srv (441fba48bff01fdb9d5969ebc1838f0 C:\Windows\system32\DRIVERS\srv.sys
    21:12:44.0380 5140 srv - ok
    21:12:44.0411 5140 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
    21:12:44.0427 5140 srv2 - ok
    21:12:44.0521 5140 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
    21:12:44.0536 5140 srvnet - ok
    21:12:44.0567 5140 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    21:12:44.0583 5140 stexstor - ok
    21:12:44.0614 5140 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
    21:12:44.0614 5140 swenum - ok
    21:12:44.0661 5140 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
    21:12:44.0692 5140 Tcpip - ok
    21:12:44.0786 5140 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
    21:12:44.0801 5140 TCPIP6 - ok
    21:12:44.0833 5140 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
    21:12:44.0864 5140 tcpipreg - ok
    21:12:44.0895 5140 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    21:12:44.0926 5140 TDPIPE - ok
    21:12:44.0957 5140 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
    21:12:44.0973 5140 TDTCP - ok
    21:12:45.0004 5140 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
    21:12:45.0035 5140 tdx - ok
    21:12:45.0113 5140 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
    21:12:45.0129 5140 TermDD - ok
    21:12:45.0160 5140 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:12:45.0191 5140 tssecsrv - ok
    21:12:45.0254 5140 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
    21:12:45.0269 5140 TsUsbFlt - ok
    21:12:45.0347 5140 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
    21:12:45.0379 5140 tunnel - ok
    21:12:45.0394 5140 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    21:12:45.0410 5140 uagp35 - ok
    21:12:45.0441 5140 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
    21:12:45.0457 5140 udfs - ok
    21:12:45.0503 5140 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
    21:12:45.0503 5140 uliagpkx - ok
    21:12:45.0581 5140 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
    21:12:45.0613 5140 umbus - ok
    21:12:45.0644 5140 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    21:12:45.0659 5140 UmPass - ok
    21:12:45.0691 5140 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7e C:\Windows\system32\Drivers\usbaapl64.sys
    21:12:45.0722 5140 USBAAPL64 - ok
    21:12:45.0753 5140 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
    21:12:45.0769 5140 usbccgp - ok
    21:12:45.0847 5140 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    21:12:45.0878 5140 usbcir - ok
    21:12:45.0893 5140 usbehci (c025055fe7b87701eb042095df1a2d7 C:\Windows\system32\drivers\usbehci.sys
    21:12:45.0909 5140 usbehci - ok
    21:12:45.0940 5140 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
    21:12:45.0956 5140 usbhub - ok
    21:12:45.0987 5140 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
    21:12:46.0003 5140 usbohci - ok
    21:12:46.0096 5140 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    21:12:46.0112 5140 usbprint - ok
    21:12:46.0127 5140 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
    21:12:46.0159 5140 usbscan - ok
    21:12:46.0174 5140 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    21:12:46.0190 5140 USBSTOR - ok
    21:12:46.0221 5140 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
    21:12:46.0237 5140 usbuhci - ok
    21:12:46.0315 5140 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
    21:12:46.0330 5140 vdrvroot - ok
    21:12:46.0361 5140 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    21:12:46.0377 5140 vga - ok
    21:12:46.0393 5140 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    21:12:46.0424 5140 VgaSave - ok
    21:12:46.0439 5140 vhdmp (2ce2df28c83aeaf30084e1b1eb253cb C:\Windows\system32\drivers\vhdmp.sys
    21:12:46.0455 5140 vhdmp - ok
    21:12:46.0549 5140 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
    21:12:46.0549 5140 viaide - ok
    21:12:46.0564 5140 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
    21:12:46.0580 5140 volmgr - ok
    21:12:46.0611 5140 volmgrx (a255814907c89be58b79ef2f189b843 C:\Windows\system32\drivers\volmgrx.sys
    21:12:46.0611 5140 volmgrx - ok
    21:12:46.0642 5140 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
    21:12:46.0642 5140 volsnap - ok
    21:12:46.0673 5140 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    21:12:46.0689 5140 vsmraid - ok
    21:12:46.0751 5140 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
    21:12:46.0767 5140 vwifibus - ok
    21:12:46.0814 5140 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    21:12:46.0814 5140 vwififlt - ok
    21:12:46.0845 5140 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
    21:12:46.0861 5140 vwifimp - ok
    21:12:46.0876 5140 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    21:12:46.0892 5140 WacomPen - ok
    21:12:46.0970 5140 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    21:12:47.0017 5140 WANARP - ok
    21:12:47.0017 5140 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    21:12:47.0048 5140 Wanarpv6 - ok
    21:12:47.0110 5140 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    21:12:47.0110 5140 Wd - ok
    21:12:47.0141 5140 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    21:12:47.0157 5140 Wdf01000 - ok
    21:12:47.0188 5140 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    21:12:47.0219 5140 WfpLwf - ok
    21:12:47.0282 5140 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    21:12:47.0297 5140 WIMMount - ok
    21:12:47.0344 5140 WinUSB (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUSB.sys
    21:12:47.0360 5140 WinUSB - ok
    21:12:47.0391 5140 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
    21:12:47.0407 5140 WmiAcpi - ok
    21:12:47.0438 5140 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    21:12:47.0485 5140 ws2ifsl - ok
    21:12:47.0563 5140 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
    21:12:47.0594 5140 WudfPf - ok
    21:12:47.0609 5140 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:12:47.0656 5140 WUDFRd - ok
    21:12:47.0687 5140 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    21:12:47.0859 5140 \Device\Harddisk0\DR0 - ok
    21:12:47.0859 5140 MBR (0x1B8) (23b571400a29918f5392f6e85eeb756e) \Device\Harddisk1\DR7
    21:12:48.0046 5140 \Device\Harddisk1\DR7 - ok
    21:12:48.0046 5140 Boot (0x1200) (d9b58e7123b850ddde561b42fc4b90c7) \Device\Harddisk0\DR0\Partition0
    21:12:48.0046 5140 \Device\Harddisk0\DR0\Partition0 - ok
    21:12:48.0093 5140 Boot (0x1200) (085a248c8d6d9c5ba466ed3ba324b1da) \Device\Harddisk0\DR0\Partition1
    21:12:48.0093 5140 \Device\Harddisk0\DR0\Partition1 - ok
    21:12:48.0109 5140 Boot (0x1200) (777aea4bf8ad2329451cb4d502822f64) \Device\Harddisk0\DR0\Partition2
    21:12:48.0109 5140 \Device\Harddisk0\DR0\Partition2 - ok
    21:12:48.0140 5140 Boot (0x1200) (c9f03a1373e81110c39b311a47f18d0e) \Device\Harddisk0\DR0\Partition3
    21:12:48.0140 5140 \Device\Harddisk0\DR0\Partition3 - ok
    21:12:48.0155 5140 Boot (0x1200) (1eaa08d4db85e1149262ac8ac372cf69) \Device\Harddisk0\DR0\Partition4
    21:12:48.0155 5140 \Device\Harddisk0\DR0\Partition4 - ok
    21:12:48.0187 5140 Boot (0x1200) (f37c77b7e540ac8f00fad9ce45c40bc4) \Device\Harddisk0\DR0\Partition5
    21:12:48.0187 5140 \Device\Harddisk0\DR0\Partition5 - ok
    21:12:48.0187 5140 Boot (0x1200) (a8497fe72dc10f73147e846a654538ce) \Device\Harddisk1\DR7\Partition0
    21:12:48.0187 5140 \Device\Harddisk1\DR7\Partition0 - ok
    21:12:48.0187 5140 ============================================================
    21:12:48.0187 5140 Scan finished
    21:12:48.0187 5140 ============================================================
    21:12:48.0187 2016 Detected object count: 2
    21:12:48.0187 2016 Actual detected object count: 2
    21:14:05.0048 2016 epmntdrv ( UnsignedFile.Multi.Generic ) - skipped by user
    21:14:05.0048 2016 epmntdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:14:05.0048 2016 EuGdiDrv ( UnsignedFile.Multi.Generic ) - skipped by user
    21:14:05.0048 2016 EuGdiDrv ( UnsignedFile.Multi.Generic ) - User select action: Skip

  8. #8
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Hoe staat het met de problemen ?
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  9. #9

    Ingeschreven
    Jan 2012
    Berichten
    11
    Geen verandering
    nog altijd dezelfde problemen.

  10. #10
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Download de Emsisoft Emergency Kit naar het bureaublad en pak het ZIP bestand uit.
    • Open de map "EmsisoftEmergencyKit" en dubbelklik op "Start.exe"
    • Klik nu op "Emergency Kit Scanner" u krijg nu een melding dat het is aanbevolen om eerst te updaten sta dit toe door te klikken op "Ja"
    • Als de update gereed is en de melding "Update process is succesvol afgerond" verschijnt klikt u op "menu" en dan op "Scan PC"
    • Selecteer de optie "Diep" als deze niet standaard al zo is ingesteld.
    • Klik Nu op de knop "Scan" en doe verder niets op de computer tijdens het scannen, deze scan kan een geruime tijd in beslag nemen dus wacht dit geduldig af.
    • Het venster met de waarschuwing over een verhoogd risico kunt u sluiten als de scan gereed is.

      Opmerking:

      Als u deze melding ziet.

      C:\Documents and Settings\username\Bureaublad\ComboFix.exe/$0\List.bat Verwijderd Virus.Win32.HTML!IK

      Wanneer het bestand in het venster met scanresultaten staat kun je rechtsklikken op die detectie en kiezen voor "Versturen als vals alarm (False Positive)".

    • Zorg ervoor dat alle gevonden items zijn aangevinkt en druk dan op de knop "verwijder geselecteerde" u zal nu de volgende melding krijgen maar klik hier op "Ja"
    • Als het verwijderen gereed is klikt u op de knop "View report" en selecteert u het tekstbestand van deze scan met de naam zoals: a2scan_110730-111615.txt
    • Plaats de inhoud van dit LOG bestand straks in uw volgende bericht.
    • Herstart nu de computer.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  11. #11

    Ingeschreven
    Jan 2012
    Berichten
    11
    Emsisoft Emergency Kit - Version 1.0
    Last update: 1/7/2012 2:39:55 PM

    Scan settings:

    Scan type: Deep Scan
    Objects: Memory, Traces, Cookies, A:\, B:\, C:\, M:\, R:\
    Scan archives: On
    Heuristics: Off
    ADS Scan: On

    Scan start: 1/7/2012 2:40:26 PM

    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\178a06621982ba841d960227379a522c[1].js detected: Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\1a05f83fe7b8807168d30bff5ce36f3a[1].js detected: Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\1d054719c86f05ba4b01f1e8d766f257[1].js detected: Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U89R3IUS\3c3ecb71da4b216531f26f46695db96b[1].js detected: Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\142a0a83-1e1bff97/eval_c.class detected: Exploit.Java.CVE-2010!IK

    Scanned

    Files: 311845
    Traces: 403649
    Cookies: 89
    Processes: 24

    Found

    Files: 5
    Traces: 0
    Cookies: 0
    Processes: 0
    Registry keys: 0

    Scan end: 1/7/2012 4:48:31 PM
    Scan time: 2:08:05

    C:\Users\Fluxys\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\142a0a83-1e1bff97/eval_c.class Deleted Exploit.Java.CVE-2010!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\178a06621982ba841d960227379a522c[1].js Deleted Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\1a05f83fe7b8807168d30bff5ce36f3a[1].js Deleted Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\93PC0JZR\1d054719c86f05ba4b01f1e8d766f257[1].js Deleted Trojan.JS.IFrame!IK
    C:\Users\Fluxys\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U89R3IUS\3c3ecb71da4b216531f26f46695db96b[1].js Deleted Trojan.JS.IFrame!IK

    Deleted

    Files: 5
    Traces: 0
    Cookies: 0

  12. #12

    Ingeschreven
    Jan 2012
    Berichten
    11
    Nog steeds dezelfde problemen na opnieuw opstarten van de computer.

  13. #13
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Update Combofix en start het opnieuw, plaats die nieuwe uitslag.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



  14. #14

    Ingeschreven
    Jan 2012
    Berichten
    11
    ComboFix 12-01-06.03 - Fluxys 07/01/2012 19:19:49.2.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.16343.14289 [GMT 1:00]
    Running from: c:\users\Fluxys\Desktop\ComboFix.exe
    AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-12-07 to 2012-01-07 )))))))))))))))))))))))))))))))
    .
    .
    2012-01-07 18:23 . 2012-01-07 18:23 -------- d-----w- c:\users\Fluxys\AppData\Local\temp
    2012-01-07 18:23 . 2012-01-07 18:23 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-01-07 13:10 . 2012-01-07 13:10 -------- d-----w- c:\windows\SysWow64\drivers\avg
    2012-01-06 17:36 . 2011-06-21 04:09 200976 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys
    2012-01-06 17:07 . 2012-01-06 17:07 -------- d--h--w- c:\programdata\Common Files
    2012-01-06 17:05 . 2012-01-06 17:05 13048 ----a-w- c:\windows\system32\avgrssta.dll
    2012-01-06 17:03 . 2012-01-06 17:03 388096 ----a-r- c:\users\Fluxys\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2012-01-06 17:03 . 2012-01-06 17:03 -------- d-----w- c:\program files (x86)\Trend Micro
    2012-01-06 16:52 . 2012-01-06 16:52 -------- d-----w- C:\$AVG
    2012-01-06 16:52 . 2012-01-06 17:05 56008 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
    2012-01-06 16:52 . 2012-01-06 17:05 317520 ----a-w- c:\windows\system32\drivers\avgtdia.sys
    2012-01-06 16:52 . 2012-01-07 13:10 269904 ----a-w- c:\windows\system32\drivers\avgldx64.sys
    2012-01-06 16:52 . 2012-01-07 13:17 -------- d-----w- c:\windows\system32\drivers\Avg
    2012-01-06 16:52 . 2012-01-06 17:05 35664 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
    2012-01-06 16:51 . 2012-01-06 16:51 -------- d-----w- c:\programdata\avg9
    2012-01-06 16:51 . 2012-01-06 16:51 -------- d-----w- c:\program files (x86)\AVG
    2012-01-06 12:55 . 2012-01-06 12:55 -------- d-----w- c:\users\Fluxys\AppData\Roaming\Malwarebytes
    2012-01-06 12:55 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-01-05 23:51 . 2012-01-05 23:51 -------- d-----w- c:\program files (x86)\Common Files\Java
    2012-01-05 23:47 . 2012-01-05 23:47 -------- d-----w- c:\users\Fluxys\AppData\Roaming\F-Secure
    2012-01-05 19:19 . 2012-01-06 17:03 -------- d-----w- C:\temp
    2012-01-03 20:36 . 2011-11-30 01:21 8822856 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78A652E6-7C52-40D5-AFB7-AE6AD03EF040}\mpengine.dll
    2012-01-02 14:08 . 2012-01-02 14:16 -------- d-----w- c:\programdata\iolo
    2012-01-02 10:46 . 2012-01-02 11:24 42672 ----a-w- c:\windows\SysWow64\drivers\fsbts.sys
    2012-01-02 10:45 . 2012-01-06 00:02 -------- d-----w- c:\program files (x86)\Telenet Security Pack
    2012-01-02 10:43 . 2012-01-02 10:45 -------- d-----w- c:\programdata\fssg
    2012-01-02 10:43 . 2012-01-06 00:01 -------- d-----w- c:\programdata\f-secure
    2012-01-02 10:37 . 2012-01-06 12:55 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-01-02 10:37 . 2012-01-02 10:37 -------- d-----w- c:\programdata\Malwarebytes
    2012-01-01 13:54 . 2012-01-06 16:26 -------- d-----w- c:\users\Fluxys\AppData\Local\ElevatedDiagnostics
    2012-01-01 13:23 . 2008-05-07 18:59 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
    2011-12-26 15:08 . 2011-12-26 15:08 -------- d-----w- c:\program files (x86)\VirtualDJ
    2011-12-26 14:31 . 2011-12-26 14:31 -------- d-----w- c:\program files\iPod
    2011-12-26 14:31 . 2011-12-26 14:32 -------- d-----w- c:\program files\iTunes
    2011-12-26 14:31 . 2011-12-26 14:32 -------- d-----w- c:\program files (x86)\iTunes
    2011-12-14 15:54 . 2011-12-14 15:54 -------- d-----w- c:\windows\SysWow64\siscardplugins
    2011-12-14 15:47 . 2011-10-26 05:21 43520 ----a-w- c:\windows\system32\csrsrv.dll
    2011-12-14 15:47 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
    2011-12-14 15:47 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
    2011-12-14 15:47 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-12-14 15:47 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-12-14 15:47 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-01-07 15:57 . 2011-05-17 16:34 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
    2012-01-07 15:57 . 2011-05-19 15:27 704336 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2012-01-06 11:39 . 2011-05-17 16:36 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
    2012-01-03 20:36 . 2011-05-17 16:34 704336 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
    2011-12-04 12:35 . 2011-12-04 12:35 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
    2011-12-04 12:35 . 2011-12-04 12:35 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
    2011-11-19 18:42 . 2011-11-19 18:42 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys
    2011-11-19 18:42 . 2011-11-19 18:42 82816 ----a-w- c:\users\Fluxys\AppData\Roaming\pcouffin.sys
    2011-11-15 13:29 . 2010-11-24 08:25 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-11-10 04:54 . 2011-04-26 16:57 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
    2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-01-06_19.01.15 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-11-24 08:03 . 2012-01-07 18:07 64724 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2012-01-07 18:07 37044 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2010-12-06 12:05 . 2012-01-07 18:07 14016 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1983625899-2747462429-1117706802-1000_UserData.bin
    - 2010-11-06 04:01 . 2012-01-06 16:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-11-06 04:01 . 2012-01-06 19:09 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-11-06 04:01 . 2012-01-06 19:09 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2010-11-06 04:01 . 2012-01-06 16:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-07-14 04:54 . 2012-01-06 16:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:54 . 2012-01-06 19:09 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:46 . 2012-01-07 15:57 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    + 2012-01-07 18:05 . 2012-01-07 18:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2012-01-06 18:54 . 2012-01-06 18:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2012-01-07 18:05 . 2012-01-07 18:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2012-01-06 18:54 . 2012-01-06 18:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2009-07-14 02:36 . 2012-01-06 17:35 633972 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-01-07 18:10 633972 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-01-07 18:10 112694 c:\windows\system32\perfc009.dat
    - 2009-07-14 02:36 . 2012-01-06 17:35 112694 c:\windows\system32\perfc009.dat
    + 2009-07-14 05:12 . 2012-01-06 19:09 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    - 2009-07-14 05:12 . 2012-01-06 16:38 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    - 2009-07-14 05:01 . 2012-01-06 18:53 396348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2009-07-14 05:01 . 2012-01-07 15:59 396348 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2010-12-06 12:09 . 2012-01-07 13:30 958460 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1983625899-2747462429-1117706802-1000-8192.dat
    + 2011-06-01 20:22 . 2012-01-07 15:59 7844651 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1983625899-2747462429-1117706802-1000-4096.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-09-28 1715768]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
    "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-12-04 296056]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
    "LaunchHPOSIAPP"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe" [2009-04-04 385024]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-12-08 421736]
    "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2011-04-25 305088]
    "beid"="c:\program files (x86)\Belgium Identity Card\beid35gui.exe" [2011-07-06 2068480]
    "BATINDICATOR"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe" [2009-05-08 2068992]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-07 2078048]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "HideFastUserSwitching"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "EnableShellExecuteHooks"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R2 CLKMSVC10_C6F09094;CyberLink Product - 2010/11/05 21:10;c:\program files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe [2010-06-30 245232]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 136176]
    R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560]
    R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
    R3 CXCIR;AVerMedia Consumer Infrared Receiver;c:\windows\system32\DRIVERS\AVer888RCIR_64.sys [x]
    R3 EMVSCARD;EMVSCARD;c:\windows\system32\Drivers\EMVSCARD.sys [x]
    R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-07-15 16776]
    R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-07-15 9096]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 136176]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [x]
    S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [x]
    S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [x]
    S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [x]
    S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2012-01-06 308136]
    S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
    S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
    S3 AVer7231_x64;AVerMedia 7231 capture service;c:\windows\system32\DRIVERS\AVer7231_x64.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
    S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_C6F09094
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-01-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 19:20]
    .
    2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-11 19:20]
    .
    2012-01-05 c:\windows\Tasks\HPCeeScheduleForFluxys.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 10:53]
    .
    2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{5FA94B92-692D-4F39-B72B-3E89CC89FB3F}.job
    - c:\windows\system32\msfeedssync.exe [2011-06-01 07:50]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-18 568888]
    "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\windows\System32\avgrssta.dll
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.be/
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://www.bing.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    TCP: DhcpNameServer = 192.168.0.1
    FF - ProfilePath - c:\users\Fluxys\AppData\Roaming\Mozilla\Firefox\Profiles\bq9wnmer.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.be
    .
    - - - - ORPHANS REMOVED - - - -
    .
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1983625899-2747462429-1117706802-1000_Classes\Wow6432Node\CLSID\{3d29161d-c71a-43cf-bc38-56e9cc43b8e7}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:000000a1
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,c3,4d,9e,47,61,a7,8f,c3,c6,d9,0d,66,8a,e8,c0,2b,79,a9,95,8c,a1,17,\
    .
    [HKEY_USERS\S-1-5-21-1983625899-2747462429-1117706802-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):04,46,00,37,9b,56,b5,26,24,b3,9e,2f,49,cb,3d,71,37,67,d2,fb,98,
    97,5b,e5,a0,a8,1f,6f,ca,e5,ac,44,87,ad,43,1c,4f,8a,20,cb,00,00,00,00,00,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-01-07 19:24:39
    ComboFix-quarantined-files.txt 2012-01-07 18:24
    ComboFix2.txt 2012-01-06 19:02
    .
    Pre-Run: 26.226.270.208 bytes free
    Post-Run: 26.489.528.320 bytes free
    .
    - - End Of File - - FA6DCBB96173A4CDF1965F335F8D822A

  15. #15
    Hijack Mod Juisterr's Avatar
    Ingeschreven
    Aug 2006
    Locatie
    kotje aan de kust, Zuid-Holland
    Berichten
    15.602
    Ziet er toch goed uit zo.
    Goed geholpen hier:
    Een PB sturen heeft geen zin, daar word niet op gereageerd.! Alle berichten op het forum aub.
    miekiemoesblog
    speciale tips



+ Plaats een Reactie
Pagina 1 van de 2 12 LaatsteLaatste

Forum Rechten

  • Je mag geen nieuwe onderwerpen plaatsen
  • Je mag geen reacties plaatsen
  • Je mag geen bijlagen toevoegen
  • Je mag jouw berichten niet wijzigen

SEO by vBSEO 3.5.1