Ga naar inhoud

Windows Update werkt niet meer


mswintie

Aanbevolen berichten

OK. De PC is niet moeten herstarten.

Het is wel een hele boterham geworden ;-)

Asjeblief:

ComboFix 12-08-08.01 - Michael 08/08/2012 20:47:09.1.8 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.8086.6281 [GMT 2:00]

Gestart vanuit: c:\users\Michael\Desktop\ComboFix.exe

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Nieuw herstelpunt werd aangemaakt

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\Roaming

c:\users\Michael\Internet Explorer.lnk

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-07-08 to 2012-08-08 ))))))))))))))))))))))))))))))

.

.

2012-08-08 07:01 . 2012-08-08 07:01 74703 ----a-w- c:\windows\SysWow64\mfc45.dll

2012-08-08 07:01 . 2012-08-08 07:02 -------- d-----w- c:\programdata\iolo

2012-08-08 07:01 . 2012-08-08 07:01 -------- d-----w- c:\program files (x86)\iolo

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\programdata\Malwarebytes

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-08-07 20:33 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-07 09:25 . 2012-08-07 09:25 388096 ----a-r- c:\users\Michael\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-08-07 09:25 . 2012-08-07 09:25 -------- d-----w- c:\program files (x86)\Trend Micro

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- c:\users\Michael\AppData\Roaming\InstallShield

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- C:\swsetup

2012-08-07 08:19 . 2012-08-07 08:19 -------- d-----w- C:\bb26a787cc3116d973cbb6db

2012-08-07 07:56 . 2012-06-22 05:38 177144 ----a-w- c:\windows\system32\mfevtps.exe

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Oracle

2012-08-07 07:53 . 2012-07-05 20:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-08-07 07:48 . 2012-08-07 07:49 -------- d-----w- c:\users\McAfee

2012-08-07 07:37 . 2012-08-07 07:37 -------- d-----w- c:\windows\SysWow64\wbem\Logs

2012-08-07 07:23 . 2012-08-07 07:23 -------- d-----w- c:\users\Michael\AppData\Roaming\SUPERAntiSpyware.com

2012-08-07 07:16 . 2012-08-07 07:16 -------- d-----w- c:\program files (x86)\Citrix

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\SpeedyPC Software

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\DriverCure

2012-08-02 14:46 . 2012-08-02 15:03 -------- d-----w- c:\programdata\SpeedyPC Software

2012-08-02 07:51 . 2012-08-07 07:56 -------- d-----w- c:\programdata\McAfee

2012-08-02 07:30 . 2012-08-02 07:30 -------- d-----w- c:\programdata\Citrix

2012-08-02 07:29 . 2012-08-02 09:40 -------- d-----w- c:\users\Michael\AppData\Local\Citrix

2012-08-02 06:52 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2012-08-02 06:27 . 2012-08-02 06:27 -------- d-----w- c:\users\Michael\AppData\Roaming\McAfee

2012-07-31 05:58 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78432234-2B54-4C1C-A764-F1DA14FA081C}\mpengine.dll

2012-07-28 11:30 . 2012-07-28 11:30 -------- d-----w- c:\users\Michael\AppData\Roaming\NVIDIA

2012-07-28 11:13 . 2012-07-28 11:14 -------- d--h--w- c:\windows\msdownld.tmp

2012-07-28 10:58 . 2012-07-28 10:58 -------- d-----w- c:\program files (x86)\Team JPN

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\users\Michael\AppData\Roaming\Anvsoft

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\program files (x86)\Funny Photo Maker

2012-07-21 15:14 . 2012-07-21 15:14 -------- d-----w- c:\program files (x86)\Elaborate Bytes

2012-07-21 15:14 . 2012-07-21 15:14 -------- d--h--w- c:\programdata\Common Files

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\Garmin

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\GARMIN_Corp

2012-07-11 21:02 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll

2012-07-11 21:02 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll

2012-07-11 21:02 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll

2012-07-11 21:02 . 2011-12-21 17:14 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm

2012-07-11 21:02 . 2012-07-11 18:00 79872 ----a-w- c:\windows\SysWow64\ff_vfw.dll

2012-07-11 20:58 . 2012-07-15 12:10 -------- d-----w- c:\users\Michael\AppData\Roaming\Realtek

2012-07-10 18:55 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-08-08 18:40 . 2012-02-12 18:27 29 ----a-w- c:\windows\SysWow64\TempWmicBatchFile.bat

2012-08-07 09:28 . 2012-04-14 07:37 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-08-07 09:28 . 2011-12-02 07:08 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-07-13 05:55 . 2011-12-09 14:45 59701280 ----a-w- c:\windows\system32\MRT.exe

2012-06-22 05:38 . 2012-06-22 05:38 335784 ----a-w- c:\windows\system32\drivers\mfewfpk.sys

2012-06-22 05:36 . 2012-06-22 05:36 752672 ----a-w- c:\windows\system32\drivers\mfehidk.sys

2012-06-09 17:21 . 2011-12-05 16:01 178688 ----a-w- c:\windows\SysWow64\unrar.dll

2012-06-02 22:19 . 2012-06-22 05:51 38424 ----a-w- c:\windows\system32\wups.dll

2012-06-02 22:19 . 2012-06-22 05:52 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-02 22:19 . 2012-06-22 05:52 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-02 22:19 . 2012-06-22 05:52 44056 ----a-w- c:\windows\system32\wups2.dll

2012-06-02 22:19 . 2012-06-22 05:51 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-06-02 22:15 . 2012-06-22 05:52 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-06-02 22:15 . 2012-06-22 05:51 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-06-02 13:19 . 2012-06-22 05:51 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-06-02 13:15 . 2012-06-22 05:51 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-05-31 10:25 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\atapi.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\asyncmac.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\kbdclass.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\ndis.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\ntfs.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\null.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\tcpip.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\tdx.sys

.

[7] 2012-05-04 . A37A39568C8EC9A17D1B7471445B81A8 . 3916656 . . [6.1.7601.21987] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21987_none_6e78bf732bb8d24e\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\erdnt\cache86\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\SysWOW64\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17835_none_6e2331b012747421\ntoskrnl.exe

[7] 2012-03-31 . 28F44480E411C3DDF04B63F6560E6EF4 . 3913072 . . [6.1.7601.17803] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17803_none_6e41a0e0125deda0\ntoskrnl.exe

[7] 2012-03-31 . 2E02A17E8965AD671E4987E503AD38B1 . 3916656 . . [6.1.7601.21955] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21955_none_6e972ea32ba24bcd\ntoskrnl.exe

[7] 2012-03-06 . 53B4BDEA12A032EEC71E60B6BFF42F37 . 3913072 . . [6.1.7601.17790] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17790_none_6ddd4ed012a99fed\ntoskrnl.exe

[7] 2012-03-06 . 57B7DE30C4E65AD19CA13AC3065EE60B . 3916656 . . [6.1.7601.21936] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21936_none_6eadcec52b912d42\ntoskrnl.exe

[7] 2011-12-02 . FB58ABD5E1F75A2CF713C9DFF0EC0804 . 3912576 . . [6.1.7601.17640] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntoskrnl.exe

[7] 2011-12-02 . 90EFDB506F6140EEA9DEE398D9449D86 . 3912576 . . [6.1.7601.21755] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntoskrnl.exe

[7] 2011-11-19 . F0F0E99A65F598A1A7720F5111C4DA8F . 3913584 . . [6.1.7601.17727] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17727_none_6e30004a126a8db7\ntoskrnl.exe

[7] 2011-11-19 . 00B12EA93ED392FBD09F07B63E926647 . 3916656 . . [6.1.7601.21863] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21863_none_6e8a5c3d2bac37e9\ntoskrnl.exe

[7] 2010-11-21 . 2088D9994332583EDB3C561DE31EA5AD . 3911040 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntoskrnl.exe

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\ntoskrnl.exe

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

.

R0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-06-22 335784]

R1 SASDIFSV;SASDIFSV;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]

R1 SAS***IL;SAS***IL;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SAS***IL64.SYS [x]

R1 uonluwye;uonluwye;c:\windows\system32\drivers\uonluwye.sys [x]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update-service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-06-22 177144]

R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]

R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [x]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 250056]

R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [x]

R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]

R3 gupdatem;Google Update-service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [x]

R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]

R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-09-16 340240]

R3 NETMD760;Net MD;c:\windows\system32\Drivers\NETMD760.sys [x]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]

R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [x]

R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-06 1255736]

R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]

R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-17 1999168]

R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-16 380224]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/12/05 17:08];c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]

S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-15 1166848]

S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]

S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]

S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]

S2 CronService;Cron Service for Prey;c:\program files\Prey\platform\windows\cronsvc.exe [2011-02-15 19968]

S2 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2008-12-17 410976]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480]

S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-11-23 2118976]

S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]

S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtuele adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [x]

S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [x]

S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x]

S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]

S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]

S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [x]

S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]

S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]

S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]

S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]

S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]

S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*Deregistered* - da2c1cad348cf36f

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2012-08-08 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 09:28]

.

2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002Core.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-08-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002UA.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-07-25 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

2012-08-08 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x1

"AppInit_DLLs"=c:\windows\System32\nvinitx.dll

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.be/

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 195.130.131.3 195.130.130.131

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

Toolbar-Locked - (no file)

WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)

AddRemove-McAfee Virtual Technician - c:\program files (x86)\McAfee\Supportability\MVT\MVTInstaller.exe

AddRemove-eType - c:\users\Michael\AppData\Roaming\eType\eTypeUninstall.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]

"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\da2c1cad348cf36f]

"ImagePath"="\SystemRoot\System32\Drivers\da2c1cad348cf36f.sys"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2012-08-08 20:54:01

ComboFix-quarantined-files.txt 2012-08-08 18:54

.

Pre-Run: 460.566.319.104 bytes beschikbaar

Post-Run: 460.614.385.664 bytes beschikbaar

.

- - End Of File - - 8021F94DF42AC0FB746C2C4AE412338A

Link naar reactie
Delen op andere sites

  • Reacties 23
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Open een nieuw kladblokbestand.

Maak een scriptje

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

C:\bb26a787cc3116d973cbb6db

File::

c:\windows\system32\drivers\uonluwye.sys

Driver::

uonluwye

Registry::

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\da2c1cad348cf36f]

Sla dit bestand op je bureaublad op als CFScript

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht

Link naar reactie
Delen op andere sites

Ziehier het volgende log-bestandje:

ComboFix 12-08-09.01 - Michael 10/08/2012 7:50.2.8 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.8086.6463 [GMT 2:00]

Gestart vanuit: c:\users\Michael\Desktop\ComboFix.exe

gebruikte Opdracht switches :: c:\users\Michael\Desktop\CFScript.txt

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\windows\system32\drivers\uonluwye.sys"

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\bb26a787cc3116d973cbb6db

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_uonluwye

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-07-10 to 2012-08-10 ))))))))))))))))))))))))))))))

.

.

2012-08-10 05:54 . 2012-08-10 05:54 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2012-08-10 05:54 . 2012-08-10 05:54 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-08-08 07:01 . 2012-08-08 07:01 74703 ----a-w- c:\windows\SysWow64\mfc45.dll

2012-08-08 07:01 . 2012-08-08 07:02 -------- d-----w- c:\programdata\iolo

2012-08-08 07:01 . 2012-08-08 07:01 -------- d-----w- c:\program files (x86)\iolo

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\programdata\Malwarebytes

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-08-07 20:33 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-07 09:25 . 2012-08-07 09:25 388096 ----a-r- c:\users\Michael\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-08-07 09:25 . 2012-08-07 09:25 -------- d-----w- c:\program files (x86)\Trend Micro

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- c:\users\Michael\AppData\Roaming\InstallShield

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- C:\swsetup

2012-08-07 07:57 . 2012-06-22 05:34 169320 ----a-w- c:\windows\system32\drivers\mfeapfk.sys

2012-08-07 07:56 . 2012-06-22 05:38 177144 ----a-w- c:\windows\system32\mfevtps.exe

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Oracle

2012-08-07 07:53 . 2012-07-05 20:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-08-07 07:48 . 2012-08-07 07:49 -------- d-----w- c:\users\McAfee

2012-08-07 07:37 . 2012-08-07 07:37 -------- d-----w- c:\windows\SysWow64\wbem\Logs

2012-08-07 07:23 . 2012-08-07 07:23 -------- d-----w- c:\users\Michael\AppData\Roaming\SUPERAntiSpyware.com

2012-08-07 07:16 . 2012-08-07 07:16 -------- d-----w- c:\program files (x86)\Citrix

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\SpeedyPC Software

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\DriverCure

2012-08-02 14:46 . 2012-08-02 15:03 -------- d-----w- c:\programdata\SpeedyPC Software

2012-08-02 07:51 . 2012-08-07 07:56 -------- d-----w- c:\programdata\McAfee

2012-08-02 07:30 . 2012-08-02 07:30 -------- d-----w- c:\programdata\Citrix

2012-08-02 07:29 . 2012-08-02 09:40 -------- d-----w- c:\users\Michael\AppData\Local\Citrix

2012-08-02 06:52 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2012-08-02 06:27 . 2012-08-02 06:27 -------- d-----w- c:\users\Michael\AppData\Roaming\McAfee

2012-07-31 05:58 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78432234-2B54-4C1C-A764-F1DA14FA081C}\mpengine.dll

2012-07-28 11:30 . 2012-07-28 11:30 -------- d-----w- c:\users\Michael\AppData\Roaming\NVIDIA

2012-07-28 11:13 . 2012-07-28 11:14 -------- d--h--w- c:\windows\msdownld.tmp

2012-07-28 10:58 . 2012-07-28 10:58 -------- d-----w- c:\program files (x86)\Team JPN

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\users\Michael\AppData\Roaming\Anvsoft

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\program files (x86)\Funny Photo Maker

2012-07-21 15:14 . 2012-07-21 15:14 -------- d-----w- c:\program files (x86)\Elaborate Bytes

2012-07-21 15:14 . 2012-07-21 15:14 -------- d--h--w- c:\programdata\Common Files

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\Garmin

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\GARMIN_Corp

2012-07-13 05:58 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys

2012-07-11 21:02 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll

2012-07-11 21:02 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll

2012-07-11 21:02 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll

2012-07-11 21:02 . 2011-12-21 17:14 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm

2012-07-11 21:02 . 2012-07-11 18:00 79872 ----a-w- c:\windows\SysWow64\ff_vfw.dll

2012-07-11 20:58 . 2012-07-15 12:10 -------- d-----w- c:\users\Michael\AppData\Roaming\Realtek

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-08-10 05:56 . 2012-02-12 18:27 29 ----a-w- c:\windows\SysWow64\TempWmicBatchFile.bat

2012-08-07 09:28 . 2012-04-14 07:37 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-08-07 09:28 . 2011-12-02 07:08 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-07-13 05:55 . 2011-12-09 14:45 59701280 ----a-w- c:\windows\system32\MRT.exe

2012-06-22 05:38 . 2012-06-22 05:38 335784 ----a-w- c:\windows\system32\drivers\mfewfpk.sys

2012-06-22 05:36 . 2012-06-22 05:36 752672 ----a-w- c:\windows\system32\drivers\mfehidk.sys

2012-06-09 17:21 . 2011-12-05 16:01 178688 ----a-w- c:\windows\SysWow64\unrar.dll

2012-06-02 22:19 . 2012-06-22 05:51 38424 ----a-w- c:\windows\system32\wups.dll

2012-06-02 22:19 . 2012-06-22 05:52 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-02 22:19 . 2012-06-22 05:52 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-02 22:19 . 2012-06-22 05:52 44056 ----a-w- c:\windows\system32\wups2.dll

2012-06-02 22:19 . 2012-06-22 05:51 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-06-02 22:15 . 2012-06-22 05:52 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-06-02 22:15 . 2012-06-22 05:51 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-06-02 13:19 . 2012-06-22 05:51 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-06-02 13:15 . 2012-06-22 05:51 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-05-31 10:25 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\atapi.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\asyncmac.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\kbdclass.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\ndis.sys

.

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\null.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\tcpip.sys

.

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\drivers\tdx.sys

.

[7] 2012-05-04 . A37A39568C8EC9A17D1B7471445B81A8 . 3916656 . . [6.1.7601.21987] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21987_none_6e78bf732bb8d24e\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\erdnt\cache86\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\SysWOW64\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17835_none_6e2331b012747421\ntoskrnl.exe

[7] 2012-03-31 . 28F44480E411C3DDF04B63F6560E6EF4 . 3913072 . . [6.1.7601.17803] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17803_none_6e41a0e0125deda0\ntoskrnl.exe

[7] 2012-03-31 . 2E02A17E8965AD671E4987E503AD38B1 . 3916656 . . [6.1.7601.21955] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21955_none_6e972ea32ba24bcd\ntoskrnl.exe

[7] 2012-03-06 . 53B4BDEA12A032EEC71E60B6BFF42F37 . 3913072 . . [6.1.7601.17790] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17790_none_6ddd4ed012a99fed\ntoskrnl.exe

[7] 2012-03-06 . 57B7DE30C4E65AD19CA13AC3065EE60B . 3916656 . . [6.1.7601.21936] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21936_none_6eadcec52b912d42\ntoskrnl.exe

[7] 2011-12-02 . FB58ABD5E1F75A2CF713C9DFF0EC0804 . 3912576 . . [6.1.7601.17640] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntoskrnl.exe

[7] 2011-12-02 . 90EFDB506F6140EEA9DEE398D9449D86 . 3912576 . . [6.1.7601.21755] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntoskrnl.exe

[7] 2011-11-19 . F0F0E99A65F598A1A7720F5111C4DA8F . 3913584 . . [6.1.7601.17727] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17727_none_6e30004a126a8db7\ntoskrnl.exe

[7] 2011-11-19 . 00B12EA93ED392FBD09F07B63E926647 . 3916656 . . [6.1.7601.21863] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21863_none_6e8a5c3d2bac37e9\ntoskrnl.exe

[7] 2010-11-21 . 2088D9994332583EDB3C561DE31EA5AD . 3911040 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntoskrnl.exe

[-] 1601-01-01 00:00 . !HASH: COULD NOT OPEN FILE !!!!! . 0 . . [------] .. c:\windows\system32\ntoskrnl.exe

.

((((((((((((((((((((((((((((( SnapShot@2012-08-08_18.52.21 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-08-10 05:47 74228 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-08-10 05:47 44970 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2011-12-05 14:53 . 2012-08-10 05:47 19682 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4175197894-823669262-2136076139-1002_UserData.bin

+ 2009-07-13 23:38 . 2009-07-13 23:38 15360 c:\windows\system32\vga.dll

+ 2009-07-14 00:16 . 2009-07-14 00:16 17408 c:\windows\system32\tsddd.dll

+ 2009-07-14 00:16 . 2009-07-14 01:32 32256 c:\windows\system32\RDPREFDD.dll

+ 2009-07-13 23:19 . 2009-07-14 01:45 57424 c:\windows\system32\PSHED.DLL

+ 2009-07-13 23:19 . 2009-07-14 01:41 36864 c:\windows\system32\pcwum.dll

+ 2009-07-13 23:22 . 2009-07-14 01:48 32832 c:\windows\system32\mcupdate_AuthenticAMD.dll

+ 2011-12-02 08:49 . 2011-12-02 08:49 20352 c:\windows\system32\kdusb.dll

+ 2011-12-02 08:49 . 2011-12-02 08:49 17792 c:\windows\system32\kdcom.dll

+ 2011-12-02 08:49 . 2011-12-02 08:49 19328 c:\windows\system32\kd1394.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 10240 c:\windows\system32\kbdnecat.dll

+ 2009-07-13 23:37 . 2009-07-14 01:41 12288 c:\windows\system32\KBDKOR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:41 12800 c:\windows\system32\KBDJPN.DLL

+ 2009-07-13 23:38 . 2009-07-13 23:38 14848 c:\windows\system32\framebuf.dll

+ 2009-07-13 23:37 . 2009-07-14 01:27 34816 c:\windows\system32\f3ahvoas.dll

+ 2009-07-14 00:39 . 2009-07-14 00:39 23040 c:\windows\system32\drivers\WSDPrint.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 21504 c:\windows\system32\drivers\ws2ifsl.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 16464 c:\windows\system32\drivers\wmilib.sys

+ 2009-07-13 23:31 . 2009-07-13 23:31 14336 c:\windows\system32\drivers\wmiacpi.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 41984 c:\windows\system32\drivers\winusb.sys

+ 2009-07-13 23:29 . 2009-07-14 01:45 22096 c:\windows\system32\drivers\wimmount.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 12800 c:\windows\system32\drivers\wfplwf.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 42064 c:\windows\system32\drivers\WdfLdr.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 21056 c:\windows\system32\drivers\wd.sys

+ 2009-07-13 23:37 . 2009-07-13 23:37 42496 c:\windows\system32\drivers\watchdog.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 88576 c:\windows\system32\drivers\wanarp.sys

+ 2009-07-14 00:02 . 2009-07-14 00:02 27776 c:\windows\system32\drivers\wacompen.sys

+ 2009-07-14 00:07 . 2009-07-14 00:07 17920 c:\windows\system32\drivers\vwifimp.sys

+ 2009-07-14 00:07 . 2009-07-14 00:07 59904 c:\windows\system32\drivers\vwififlt.sys

+ 2009-07-14 00:07 . 2009-07-14 00:07 24576 c:\windows\system32\drivers\vwifibus.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 71552 c:\windows\system32\drivers\volmgr.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 17488 c:\windows\system32\drivers\viaide.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 29184 c:\windows\system32\drivers\vgapnp.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 29184 c:\windows\system32\drivers\vga.sys

+ 2009-07-14 00:01 . 2009-07-14 01:45 36432 c:\windows\system32\drivers\vdrvroot.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 30720 c:\windows\system32\drivers\usbuhci.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 91648 c:\windows\system32\drivers\USBSTOR.SYS

+ 2010-11-21 03:24 . 2010-11-21 03:24 31744 c:\windows\system32\drivers\usbrpm.sys

+ 2009-07-14 00:38 . 2009-07-14 00:38 25088 c:\windows\system32\drivers\usbprint.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 25600 c:\windows\system32\drivers\usbohci.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 52736 c:\windows\system32\drivers\usbehci.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 99328 c:\windows\system32\drivers\usbccgp.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 32896 c:\windows\system32\drivers\USBCAMD2.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 19968 c:\windows\system32\drivers\usb8023.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 48640 c:\windows\system32\drivers\umbus.sys

+ 2009-07-13 23:38 . 2009-07-14 01:45 64592 c:\windows\system32\drivers\ULIAGPKX.SYS

+ 2009-07-13 23:38 . 2009-07-14 01:45 64080 c:\windows\system32\drivers\UAGP35.SYS

+ 2010-11-29 21:00 . 2010-11-29 21:00 16120 c:\windows\system32\drivers\TurboB.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 31232 c:\windows\system32\drivers\TsUsbGD.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 59392 c:\windows\system32\drivers\TsUsbFlt.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 39424 c:\windows\system32\drivers\tssecsrv.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 63360 c:\windows\system32\drivers\termdd.sys

+ 2012-03-14 03:31 . 2012-02-17 04:57 23552 c:\windows\system32\drivers\tdtcp.sys

+ 2009-07-14 00:16 . 2009-07-14 00:16 15872 c:\windows\system32\drivers\tdpipe.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 26624 c:\windows\system32\drivers\tdi.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 45056 c:\windows\system32\drivers\tcpipreg.sys

+ 2009-07-14 00:01 . 2009-07-14 00:01 29184 c:\windows\system32\drivers\tape.sys

+ 2009-07-14 00:00 . 2009-07-14 01:45 12496 c:\windows\system32\drivers\swenum.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 68864 c:\windows\system32\drivers\stream.sys

+ 2009-07-13 21:59 . 2009-07-14 01:45 24656 c:\windows\system32\drivers\stexstor.sys

+ 2011-12-01 23:58 . 2010-08-20 10:05 21616 c:\windows\system32\drivers\stdcfltn.sys

+ 2009-07-13 20:27 . 2009-07-14 01:45 19008 c:\windows\system32\drivers\spldr.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 20992 c:\windows\system32\drivers\smclib.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 93184 c:\windows\system32\drivers\smb.sys

+ 2009-07-13 21:59 . 2009-07-14 01:45 80464 c:\windows\system32\drivers\sisraid4.sys

+ 2009-06-10 20:37 . 2009-07-14 01:45 43584 c:\windows\system32\drivers\sisraid2.sys

+ 2009-07-14 00:01 . 2009-07-14 00:01 16896 c:\windows\system32\drivers\sfloppy.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 14336 c:\windows\system32\drivers\sffp_sd.sys

+ 2009-07-14 00:01 . 2009-07-14 00:01 13824 c:\windows\system32\drivers\sffp_mmc.sys

+ 2009-07-14 00:01 . 2009-07-14 00:01 14336 c:\windows\system32\drivers\sffdisk.sys

+ 2009-07-14 00:35 . 2009-07-14 00:35 12288 c:\windows\system32\drivers\serscan.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 26624 c:\windows\system32\drivers\sermouse.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 94208 c:\windows\system32\drivers\serial.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 23552 c:\windows\system32\drivers\serenum.sys

+ 2009-07-14 02:36 . 2009-06-10 20:37 23040 c:\windows\system32\drivers\secdrv.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 29696 c:\windows\system32\drivers\scfilter.sys

+ 2009-07-14 00:08 . 2009-07-14 00:08 76800 c:\windows\system32\drivers\rspndr.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 11264 c:\windows\system32\drivers\rootmdm.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 41472 c:\windows\system32\drivers\RNDISMP.sys

+ 2009-07-14 00:17 . 2009-07-14 00:17 24064 c:\windows\system32\drivers\rdpbus.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 83968 c:\windows\system32\drivers\rassstp.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 92672 c:\windows\system32\drivers\raspppoe.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 14848 c:\windows\system32\drivers\rasacd.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 46592 c:\windows\system32\drivers\qwavedrv.sys

+ 2011-12-02 08:29 . 2010-07-13 02:38 29288 c:\windows\system32\drivers\qicflt.sys

+ 2011-12-02 08:03 . 2010-03-19 09:00 55856 c:\windows\system32\drivers\PxHlpa64.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 60416 c:\windows\system32\drivers\processr.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 50768 c:\windows\system32\drivers\pcw.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 48720 c:\windows\system32\drivers\pciidex.sys

+ 2009-07-13 23:19 . 2009-07-14 01:45 12352 c:\windows\system32\drivers\pciide.sys

+ 2012-05-11 05:47 . 2012-03-17 07:58 75120 c:\windows\system32\drivers\partmgr.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 97280 c:\windows\system32\drivers\parport.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 72832 c:\windows\system32\drivers\ohci1394.sys

+ 2011-12-02 08:28 . 2011-10-17 21:01 27712 c:\windows\system32\drivers\nvpciflt.sys

+ 2011-09-13 21:14 . 2011-09-13 21:14 95744 c:\windows\system32\drivers\nusb3hub.sys

+ 2009-07-13 23:21 . 2009-07-13 23:21 24576 c:\windows\system32\drivers\nsiproxy.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 44032 c:\windows\system32\drivers\npfs.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 51264 c:\windows\system32\drivers\nfrd960.sys

+ 2012-03-26 17:44 . 2010-05-27 11:36 19456 c:\windows\system32\drivers\NETMD760.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 44544 c:\windows\system32\drivers\netbios.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 57856 c:\windows\system32\drivers\ndproxy.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 56832 c:\windows\system32\drivers\ndisuio.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 24064 c:\windows\system32\drivers\ndistapi.sys

+ 2009-07-14 00:08 . 2009-07-14 00:08 35328 c:\windows\system32\drivers\ndiscap.sys

+ 2009-07-13 23:23 . 2009-07-14 01:48 60496 c:\windows\system32\drivers\mup.sys

+ 2009-07-14 00:02 . 2009-07-14 00:02 15360 c:\windows\system32\drivers\MTConfig.sys

+ 2009-07-13 23:31 . 2009-07-14 01:48 32320 c:\windows\system32\drivers\mssmbios.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 11136 c:\windows\system32\drivers\mskssrv.sys

+ 2009-07-13 23:19 . 2009-07-14 01:48 15424 c:\windows\system32\drivers\msisadrv.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 26112 c:\windows\system32\drivers\msfs.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 31104 c:\windows\system32\drivers\msahci.sys

+ 2009-07-14 00:08 . 2009-07-14 00:08 77312 c:\windows\system32\drivers\mpsdrv.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 94592 c:\windows\system32\drivers\mountmgr.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 31232 c:\windows\system32\drivers\mouhid.sys

+ 2009-07-13 23:19 . 2009-07-14 01:48 49216 c:\windows\system32\drivers\mouclass.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 30208 c:\windows\system32\drivers\monitor.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 40448 c:\windows\system32\drivers\modem.sys

+ 2011-03-13 17:20 . 2012-02-22 11:29 75936 c:\windows\system32\drivers\mfenlfk.sys

+ 2011-12-02 08:06 . 2012-02-22 11:29 10248 c:\windows\system32\drivers\mfeclnk.sys

+ 2009-06-10 20:37 . 2009-07-14 01:48 35392 c:\windows\system32\drivers\megasas.sys

+ 2009-07-14 00:01 . 2009-07-14 00:01 22016 c:\windows\system32\drivers\mcd.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 65600 c:\windows\system32\drivers\lsi_sas2.sys

+ 2009-07-14 00:08 . 2009-07-14 00:08 60928 c:\windows\system32\drivers\lltdio.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 20992 c:\windows\system32\drivers\ksthunk.sys

+ 2012-07-12 05:58 . 2012-06-02 05:48 95600 c:\windows\system32\drivers\ksecdd.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 33280 c:\windows\system32\drivers\kbdhid.sys

+ 2011-05-17 15:27 . 2011-05-17 15:27 25496 c:\windows\system32\drivers\iwdbus.sys

+ 2009-07-13 23:31 . 2009-07-14 01:48 20544 c:\windows\system32\drivers\isapnp.sys

+ 2009-07-14 00:08 . 2009-07-14 00:08 17920 c:\windows\system32\drivers\irenum.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 78848 c:\windows\system32\drivers\IPMIDrv.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 82944 c:\windows\system32\drivers\ipfltdrv.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 62464 c:\windows\system32\drivers\intelppm.sys

+ 2009-07-13 23:19 . 2009-07-14 01:48 16960 c:\windows\system32\drivers\intelide.sys

+ 2011-05-17 15:27 . 2011-05-17 15:27 34200 c:\windows\system32\drivers\intelaud.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 44112 c:\windows\system32\drivers\iirsp.sys

+ 2011-10-11 19:08 . 2011-10-11 19:08 59904 c:\windows\system32\drivers\iBtFltCoex.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 14720 c:\windows\system32\drivers\hwpolicy.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 78720 c:\windows\system32\drivers\HpSAMD.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 30208 c:\windows\system32\drivers\hidusb.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 32896 c:\windows\system32\drivers\hidparse.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 46592 c:\windows\system32\drivers\hidir.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 76800 c:\windows\system32\drivers\hidclass.sys

+ 2009-07-13 23:31 . 2009-07-13 23:31 26624 c:\windows\system32\drivers\hidbatt.sys

+ 2012-06-24 12:25 . 2011-09-22 08:49 56600 c:\windows\system32\drivers\HECIx64.sys

+ 2009-07-13 22:53 . 2009-06-10 20:31 31232 c:\windows\system32\drivers\hcw85cir.sys

+ 2009-05-08 09:08 . 2009-05-08 09:08 20520 c:\windows\system32\drivers\grmnusb.sys

+ 2009-05-12 13:28 . 2009-05-12 13:28 31784 c:\windows\system32\drivers\grmngen.sys

+ 2012-03-20 19:16 . 2009-05-18 12:17 34152 c:\windows\system32\drivers\GEARAspiWDM.sys

+ 2009-07-13 23:38 . 2009-07-14 01:47 65088 c:\windows\system32\drivers\GAGP30KX.SYS

+ 2009-07-13 23:26 . 2009-07-14 01:47 55376 c:\windows\system32\drivers\fsdepends.sys

+ 2012-04-11 16:51 . 2012-03-01 06:46 23408 c:\windows\system32\drivers\fs_rec.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 24576 c:\windows\system32\drivers\flpydisk.sys

+ 2009-07-13 23:25 . 2009-07-13 23:25 34304 c:\windows\system32\drivers\filetrace.sys

+ 2009-07-13 23:34 . 2009-07-14 01:47 70224 c:\windows\system32\drivers\fileinfo.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 29696 c:\windows\system32\drivers\fdc.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 98816 c:\windows\system32\drivers\dxg.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 16896 c:\windows\system32\drivers\dxapi.sys

+ 2009-07-13 23:21 . 2009-07-14 01:43 55128 c:\windows\system32\drivers\dumpfve.sys

+ 2009-07-13 23:19 . 2009-07-14 01:47 28736 c:\windows\system32\drivers\Dumpata.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 27520 c:\windows\system32\drivers\Diskdump.sys

+ 2009-07-13 23:19 . 2009-07-14 01:47 73280 c:\windows\system32\drivers\disk.sys

+ 2009-07-13 23:37 . 2009-07-13 23:37 40448 c:\windows\system32\drivers\discache.sys

+ 2009-07-14 00:01 . 2009-07-14 01:47 24144 c:\windows\system32\drivers\crcdisk.sys

+ 2009-07-14 00:01 . 2009-07-14 01:47 39504 c:\windows\system32\drivers\crashdmp.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 38912 c:\windows\system32\drivers\CompositeBus.sys

+ 2009-07-13 23:31 . 2009-07-14 01:52 21584 c:\windows\system32\drivers\compbatt.sys

+ 2009-07-13 23:19 . 2009-07-14 01:52 17488 c:\windows\system32\drivers\cmdide.sys

+ 2009-07-13 23:31 . 2009-07-13 23:31 17664 c:\windows\system32\drivers\CmBatt.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 45568 c:\windows\system32\drivers\circlass.sys

+ 2011-03-13 17:20 . 2012-02-22 11:29 65264 c:\windows\system32\drivers\cfwids.sys

+ 2011-12-02 08:03 . 2009-10-20 09:00 10224 c:\windows\system32\drivers\cdralw2k.sys

+ 2011-12-02 08:03 . 2009-10-20 09:00 10224 c:\windows\system32\drivers\cdr4_xp.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 92160 c:\windows\system32\drivers\cdfs.sys

+ 2011-08-29 22:32 . 2011-08-29 22:32 53760 c:\windows\system32\drivers\btmaux.sys

+ 2011-05-19 07:17 . 2011-05-19 07:17 51712 c:\windows\system32\drivers\btmaud.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 80384 c:\windows\system32\drivers\BTHUSB.SYS

+ 2009-07-14 00:06 . 2009-07-14 00:06 72192 c:\windows\system32\drivers\bthmodem.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 41984 c:\windows\system32\drivers\bthenum.sys

+ 2009-07-14 01:20 . 2009-06-10 20:41 14720 c:\windows\system32\drivers\BrUsbSer.sys

+ 2009-07-14 01:20 . 2009-06-10 20:41 14976 c:\windows\system32\drivers\BrUsbMdm.sys

+ 2009-07-14 01:20 . 2009-06-10 20:41 47104 c:\windows\system32\drivers\BrSerWdm.sys

+ 2009-07-14 01:05 . 2009-07-14 01:01 95232 c:\windows\system32\drivers\bridge.sys

+ 2009-07-14 01:19 . 2009-06-10 20:41 18432 c:\windows\system32\drivers\BrFiltLo.sys

+ 2011-12-06 16:31 . 2011-02-23 04:55 90624 c:\windows\system32\drivers\bowser.sys

+ 2009-07-13 23:35 . 2009-07-13 23:35 45056 c:\windows\system32\drivers\blbdrive.sys

+ 2009-07-13 23:31 . 2009-07-14 01:52 28240 c:\windows\system32\drivers\battc.sys

+ 2009-07-13 21:59 . 2009-07-14 01:52 97856 c:\windows\system32\drivers\arcsas.sys

+ 2009-07-13 21:59 . 2009-07-14 01:52 87632 c:\windows\system32\drivers\arc.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 61440 c:\windows\system32\drivers\appid.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 27008 c:\windows\system32\drivers\amdxata.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 60928 c:\windows\system32\drivers\amdppm.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 64512 c:\windows\system32\drivers\amdk8.sys

+ 2009-07-13 23:19 . 2009-07-14 01:52 15440 c:\windows\system32\drivers\amdide.sys

+ 2009-07-13 23:19 . 2009-07-14 01:52 15440 c:\windows\system32\drivers\aliide.sys

+ 2009-07-13 23:38 . 2009-07-14 01:52 61008 c:\windows\system32\drivers\AGP440.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 60416 c:\windows\system32\drivers\agilevpn.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 12800 c:\windows\system32\drivers\acpipmi.sys

+ 2011-12-02 08:29 . 2010-12-13 17:34 27760 c:\windows\system32\drivers\Accelern.sys

+ 2012-03-11 19:11 . 2012-03-11 19:11 44672 c:\windows\system32\drivers\a38usb.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 68096 c:\windows\system32\drivers\1394bus.sys

+ 2011-12-15 17:40 . 2011-10-26 05:21 43520 c:\windows\system32\csrsrv.dll

+ 2009-07-13 23:19 . 2009-07-14 01:52 23120 c:\windows\system32\BOOTVID.DLL

+ 2012-07-14 12:36 . 2012-08-09 09:47 1952 c:\windows\system32\wdi\ERCQueuedResolutions.dat

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDYCL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDYCC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDYBA.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDYAK.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDWOL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDVNTC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUZB.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDUSX.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUSR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUSL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUSA.DLL

+ 2010-11-21 03:23 . 2010-11-21 03:23 7168 c:\windows\system32\KBDUS.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDURDU.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUR1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDUR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDUKX.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUK.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDUGHR1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDUGHR.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDTURME.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 8192 c:\windows\system32\KBDTUQ.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 8192 c:\windows\system32\KBDTUF.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDTIPRC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDTH3.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDTH2.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDTH1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDTH0.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDTAT.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDTAJIK.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDSYR2.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDSYR1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDSW09.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDSW.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDSP.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDSORST.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDSORS1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDSOREX.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDSN1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDSMSNO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDSMSFI.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDSL1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDSL.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 8192 c:\windows\system32\KBDSG.DLL

+ 2010-11-21 03:23 . 2010-11-21 03:23 7680 c:\windows\system32\KBDSF.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDRU1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDRU.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDROST.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDROPR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDRO.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7680 c:\windows\system32\KBDPO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDPL1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDPL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDPASH.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDNSO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDNO1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDNO.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7680 c:\windows\system32\KBDNEPR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\kbdnecnt.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\kbdnec95.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\kbdnec.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDNE.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDMONMO.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDMON.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDMLT48.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDMLT47.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDMAORI.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDMACST.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDMAC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDLV1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDLV.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDLT2.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDLT1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDLT.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 8192 c:\windows\system32\kbdlk41a.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDLAO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDLA.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDKYR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDKHMR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDKAZ.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDIULAT.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDIT142.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDIT.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDIR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDINUK2.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINTEL.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7680 c:\windows\system32\KBDINTAM.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINPUN.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINORI.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINMAR.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7680 c:\windows\system32\KBDINMAL.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINKAN.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINHIN.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINGUJ.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINEN.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7680 c:\windows\system32\KBDINDEV.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7680 c:\windows\system32\KBDINBEN.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINBE2.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINBE1.DLL

+ 2011-12-02 08:48 . 2011-12-02 08:48 7168 c:\windows\system32\KBDINASA.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDIC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDIBO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\kbdibm02.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDHU1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDHU.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 9728 c:\windows\system32\KBDHEPT.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDHELA3.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDHELA2.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDHEB.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDHE319.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDHE220.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDHE.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDHAU.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDGRLND.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7680 c:\windows\system32\KBDGR1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDGR.DLL

+ 2010-11-21 03:23 . 2010-11-21 03:23 8192 c:\windows\system32\KBDGKL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\kbdgeoqw.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\kbdgeoer.dll

+ 2010-11-21 03:24 . 2010-11-21 03:24 6656 c:\windows\system32\KBDGEO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDGAE.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDFR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDFO.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDFI1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDFI.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDFC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDFA.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDEST.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDES.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDDV.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDDIV2.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDDIV1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDDA.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDCZ2.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 8192 c:\windows\system32\KBDCZ1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDCZ.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\KBDCR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8704 c:\windows\system32\KBDCAN.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDCA.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDBULG.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBU.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBR.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDBLR.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBHC.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBGPH1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBGPH.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDBENE.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDBE.DLL

+ 2010-11-21 03:24 . 2010-11-21 03:24 7168 c:\windows\system32\KBDBASH.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDAZEL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDAZE.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\kbdax2.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDARMW.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDARME.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\KBDAL.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDA3.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 6656 c:\windows\system32\KBDA2.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\KBDA1.DLL

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\kbd106n.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 8192 c:\windows\system32\kbd106.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\kbd103.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\kbd101c.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\kbd101b.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7168 c:\windows\system32\kbd101a.dll

+ 2009-07-13 23:37 . 2009-07-14 01:28 7680 c:\windows\system32\kbd101.dll

+ 2011-12-02 08:49 . 2011-12-02 08:49 7936 c:\windows\system32\drivers\usbd.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 9728 c:\windows\system32\drivers\umpass.sys

+ 2009-07-14 00:16 . 2009-07-14 00:16 8192 c:\windows\system32\drivers\RDPREFMP.sys

+ 2009-07-14 00:16 . 2009-07-14 00:16 7680 c:\windows\system32\drivers\RDPENCDD.sys

+ 2009-07-14 00:16 . 2009-07-14 00:16 7680 c:\windows\system32\drivers\RDPCDD.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 8064 c:\windows\system32\drivers\mstee.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 6784 c:\windows\system32\drivers\mspqm.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 7168 c:\windows\system32\drivers\mspclock.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 8192 c:\windows\system32\drivers\mshidkmdf.sys

+ 2009-07-13 23:31 . 2009-07-13 23:31 9728 c:\windows\system32\drivers\errdev.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 5632 c:\windows\system32\drivers\drmkaud.sys

+ 2009-07-14 01:20 . 2009-06-10 20:41 8704 c:\windows\system32\drivers\BrFiltUp.sys

+ 2009-07-14 00:00 . 2009-07-14 00:00 6656 c:\windows\system32\drivers\beep.sys

- 2011-12-02 00:02 . 2012-08-08 12:59 1733 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat

+ 2011-12-02 00:02 . 2012-08-10 05:55 1733 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat

+ 2012-08-10 05:55 . 2012-08-10 05:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2012-08-08 18:40 . 2012-08-08 18:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-08-10 05:55 . 2012-08-10 05:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-08-08 18:40 . 2012-08-08 18:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-12-02 08:49 . 2011-12-02 08:49 605552 c:\windows\system32\winload.exe

+ 2010-11-21 03:24 . 2010-11-21 03:24 147456 c:\windows\system32\RDPENCDD.dll

+ 2010-11-21 03:24 . 2010-11-21 03:24 274944 c:\windows\system32\rdpdd.dll

+ 2010-11-21 16:48 . 2012-08-10 05:48 743342 c:\windows\system32\perfh013.dat

- 2010-11-21 16:48 . 2012-08-08 18:45 743342 c:\windows\system32\perfh013.dat

- 2009-07-14 02:36 . 2012-08-08 18:45 652148 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2012-08-10 05:48 652148 c:\windows\system32\perfh009.dat

- 2010-11-21 16:48 . 2012-08-08 18:45 152426 c:\windows\system32\perfc013.dat

+ 2010-11-21 16:48 . 2012-08-10 05:48 152426 c:\windows\system32\perfc013.dat

- 2009-07-14 02:36 . 2012-08-08 18:45 121080 c:\windows\system32\perfc009.dat

+ 2009-07-14 02:36 . 2012-08-10 05:48 121080 c:\windows\system32\perfc009.dat

+ 2010-11-21 03:24 . 2010-11-21 03:24 299392 c:\windows\system32\mcupdate_GenuineIntel.dll

+ 2010-11-21 03:24 . 2010-11-21 03:24 263040 c:\windows\system32\hal.dll

+ 2010-11-21 03:23 . 2010-11-21 03:23 172544 c:\windows\system32\drivers\WUDFRd.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 112128 c:\windows\system32\drivers\WUDFPf.sys

+ 2011-12-02 07:43 . 2006-11-01 18:51 151656 c:\windows\system32\drivers\WimFltr.sys

+ 2009-07-13 23:22 . 2009-07-14 01:45 654928 c:\windows\system32\drivers\Wdf01000.sys

+ 2009-06-10 20:37 . 2009-07-14 01:45 161872 c:\windows\system32\drivers\vsmraid.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 295808 c:\windows\system32\drivers\volsnap.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 363392 c:\windows\system32\drivers\volmgrx.sys

+ 2009-07-13 23:38 . 2009-07-13 23:38 129024 c:\windows\system32\drivers\videoprt.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 215936 c:\windows\system32\drivers\vhdmp.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 184960 c:\windows\system32\drivers\usbvideo.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 325120 c:\windows\system32\drivers\usbport.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 343040 c:\windows\system32\drivers\usbhub.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 100352 c:\windows\system32\drivers\usbcir.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 328192 c:\windows\system32\drivers\udfs.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 125440 c:\windows\system32\drivers\tunnel.sys

+ 2011-12-02 08:29 . 2011-08-26 05:09 390704 c:\windows\system32\drivers\SynTP.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 189824 c:\windows\system32\drivers\storport.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 168448 c:\windows\system32\drivers\srvnet.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 410112 c:\windows\system32\drivers\srv2.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 467456 c:\windows\system32\drivers\srv.sys

+ 2009-06-10 20:48 . 2009-06-10 20:48 426496 c:\windows\system32\drivers\spsys.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 109056 c:\windows\system32\drivers\sdbus.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 171392 c:\windows\system32\drivers\scsiport.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 103808 c:\windows\system32\drivers\sbp2port.sys

+ 2012-06-24 12:26 . 2011-09-08 15:40 508520 c:\windows\system32\drivers\Rtlh64.sys

+ 2011-12-02 08:29 . 2011-08-24 05:57 565352 c:\windows\system32\drivers\Rt64win7.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 146432 c:\windows\system32\drivers\rmcast.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 158720 c:\windows\system32\drivers\rfcomm.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 213888 c:\windows\system32\drivers\rdyboost.sys

+ 2012-06-13 05:44 . 2012-04-28 03:55 210944 c:\windows\system32\drivers\rdpwd.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 309248 c:\windows\system32\drivers\rdbss.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 111104 c:\windows\system32\drivers\raspptp.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 129536 c:\windows\system32\drivers\rasl2tp.sys

+ 2009-07-13 21:59 . 2009-07-14 01:45 128592 c:\windows\system32\drivers\ql40xx.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 230400 c:\windows\system32\drivers\portcls.sys

+ 2009-07-13 23:51 . 2009-07-14 01:01 651264 c:\windows\system32\drivers\PEAuth.sys

+ 2009-07-13 23:31 . 2009-07-14 01:45 220752 c:\windows\system32\drivers\pcmcia.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 184704 c:\windows\system32\drivers\pci.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 131584 c:\windows\system32\drivers\pacer.sys

+ 2009-07-14 00:07 . 2009-07-14 00:07 318976 c:\windows\system32\drivers\nwifi.sys

+ 2011-12-02 08:28 . 2011-06-13 00:44 122472 c:\windows\system32\drivers\nvstusb.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 166272 c:\windows\system32\drivers\nvstor.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 148352 c:\windows\system32\drivers\nvraid.sys

+ 2011-12-02 08:28 . 2011-07-08 12:51 174184 c:\windows\system32\drivers\nvhda64v.sys

+ 2009-07-13 23:38 . 2009-07-14 01:48 122960 c:\windows\system32\drivers\NV_AGP.SYS

+ 2011-09-13 21:14 . 2011-09-13 21:14 212992 c:\windows\system32\drivers\nusb3xhc.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 376192 c:\windows\system32\drivers\netio.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 261632 c:\windows\system32\drivers\netbt.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 164352 c:\windows\system32\drivers\ndiswan.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 366976 c:\windows\system32\drivers\msrpc.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 273792 c:\windows\system32\drivers\msiscsi.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 140672 c:\windows\system32\drivers\msdsm.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 128000 c:\windows\system32\drivers\mrxsmb20.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 288768 c:\windows\system32\drivers\mrxsmb10.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 158208 c:\windows\system32\drivers\mrxsmb.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 140800 c:\windows\system32\drivers\mrxdav.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 155008 c:\windows\system32\drivers\mpio.sys

+ 2011-03-13 17:20 . 2012-02-22 11:29 100912 c:\windows\system32\drivers\mferkdet.sys

+ 2011-03-13 17:20 . 2012-02-22 11:29 487296 c:\windows\system32\drivers\mfefirek.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 284736 c:\windows\system32\drivers\MegaSR.sys

+ 2009-07-13 23:26 . 2009-07-13 23:26 113152 c:\windows\system32\drivers\luafv.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 115776 c:\windows\system32\drivers\lsi_scsi.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 106560 c:\windows\system32\drivers\lsi_sas.sys

+ 2009-07-13 21:59 . 2009-07-14 01:48 114752 c:\windows\system32\drivers\lsi_fc.sys

+ 2012-07-12 05:58 . 2012-06-02 05:48 151920 c:\windows\system32\drivers\ksecpkg.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 243712 c:\windows\system32\drivers\ks.sys

+ 2011-12-02 08:29 . 2011-08-25 18:21 173656 c:\windows\system32\drivers\jmcr.sys

+ 2009-07-14 00:09 . 2009-07-14 00:09 120320 c:\windows\system32\drivers\irda.sys

+ 2009-07-14 00:10 . 2009-07-14 00:10 116224 c:\windows\system32\drivers\ipnat.sys

+ 2012-06-24 12:25 . 2011-08-23 13:12 317440 c:\windows\system32\drivers\IntcDAud.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 410496 c:\windows\system32\drivers\iaStorV.sys

+ 2012-06-24 12:26 . 2011-05-20 08:53 557848 c:\windows\system32\drivers\iaStor.sys

+ 2009-07-13 23:19 . 2009-07-13 23:19 105472 c:\windows\system32\drivers\i8042prt.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 753664 c:\windows\system32\drivers\http.sys

+ 2009-07-14 00:06 . 2009-07-14 00:06 100864 c:\windows\system32\drivers\hidbth.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 122368 c:\windows\system32\drivers\hdaudbus.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 288640 c:\windows\system32\drivers\FWPKCLNT.SYS

+ 2010-11-21 03:24 . 2010-11-21 03:24 223248 c:\windows\system32\drivers\fvevol.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 289664 c:\windows\system32\drivers\fltMgr.sys

+ 2009-07-13 23:23 . 2009-07-13 23:23 204800 c:\windows\system32\drivers\fastfat.sys

+ 2009-07-13 23:23 . 2009-07-13 23:23 195072 c:\windows\system32\drivers\exfat.sys

+ 2009-06-10 20:36 . 2009-07-14 01:47 530496 c:\windows\system32\drivers\elxstor.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 258048 c:\windows\system32\drivers\dxgmms1.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 982912 c:\windows\system32\drivers\dxgkrnl.sys

+ 2012-04-07 11:23 . 2012-04-07 11:23 283200 c:\windows\system32\drivers\dtsoftbus01.sys

+ 2009-07-14 00:06 . 2009-07-14 01:01 116224 c:\windows\system32\drivers\drmk.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 102400 c:\windows\system32\drivers\dfsc.sys

+ 2011-12-05 15:40 . 2011-06-16 13:40 176000 c:\windows\system32\drivers\CtClsFlt.sys

+ 2011-12-05 15:40 . 2009-05-28 09:49 224768 c:\windows\system32\drivers\CtAudDrv.sys

+ 2012-07-12 05:58 . 2012-06-02 05:50 458704 c:\windows\system32\drivers\cng.sys

+ 2010-11-21 03:24 . 2010-11-21 03:24 179072 c:\windows\system32\drivers\Classpnp.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 147456 c:\windows\system32\drivers\cdrom.sys

+ 2009-06-10 20:34 . 2009-06-10 20:34 468480 c:\windows\system32\drivers\bxvbda.sys

+ 2011-10-10 22:43 . 2011-10-10 22:43 288768 c:\windows\system32\drivers\btmhsf.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 552960 c:\windows\system32\drivers\bthport.sys

+ 2009-07-14 00:07 . 2009-07-14 00:07 118784 c:\windows\system32\drivers\bthpan.sys

+ 2009-07-14 01:19 . 2009-07-14 01:19 286720 c:\windows\system32\drivers\BrSerId.sys

+ 2009-06-10 20:34 . 2009-06-10 20:34 270848 c:\windows\system32\drivers\b57nd60a.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 155520 c:\windows\system32\drivers\ataport.sys

+ 2011-09-15 15:48 . 2011-09-15 15:48 299008 c:\windows\system32\drivers\AmpPal.sys

+ 2009-06-10 20:37 . 2009-07-14 01:52 194128 c:\windows\system32\drivers\amdsbs.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 107904 c:\windows\system32\drivers\amdsata.sys

+ 2012-02-15 16:13 . 2011-12-28 03:59 498688 c:\windows\system32\drivers\afd.sys

+ 2009-07-13 21:59 . 2009-07-14 01:52 182864 c:\windows\system32\drivers\adpu320.sys

+ 2009-07-13 21:59 . 2009-07-14 01:52 339536 c:\windows\system32\drivers\adpahci.sys

+ 2009-06-10 20:36 . 2009-07-14 01:52 491088 c:\windows\system32\drivers\adp94xx.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 334208 c:\windows\system32\drivers\acpi.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 229888 c:\windows\system32\drivers\1394ohci.sys

+ 2009-07-13 23:19 . 2009-07-14 01:52 367696 c:\windows\system32\clfs.sys

+ 2010-11-21 03:23 . 2010-11-21 03:23 780008 c:\windows\system32\ci.dll

+ 2010-11-21 03:24 . 2010-11-21 03:24 144384 c:\windows\system32\cdd.dll

+ 2011-12-02 08:49 . 2011-12-02 08:49 367616 c:\windows\system32\atmfd.dll

- 2009-07-14 05:01 . 2012-08-08 12:59 430204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2009-07-14 05:01 . 2012-08-10 05:55 430204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-06-24 12:24 . 2011-10-18 18:53 2957544 c:\windows\system32\drivers\RTKVHD64.sys

+ 2009-06-10 20:37 . 2009-07-14 01:45 1524816 c:\windows\system32\drivers\ql2300.sys

+ 2011-12-02 08:49 . 2011-12-02 08:49 1659776 c:\windows\system32\drivers\ntfs.sys

+ 2011-12-02 08:30 . 2011-09-18 10:26 8604672 c:\windows\system32\drivers\NETwNs64.sys

+ 2009-06-10 20:34 . 2009-06-10 20:34 3286016 c:\windows\system32\drivers\evbda.sys

+ 2011-12-02 07:41 . 2012-08-09 21:13 1954848 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

- 2011-12-02 07:41 . 2012-08-07 20:38 1954848 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2011-12-05 14:50 . 2012-08-09 10:48 2793836 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-12288.dat

- 2011-12-05 14:50 . 2012-08-07 09:02 2793836 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-12288.dat

+ 2011-12-02 08:28 . 2011-10-17 21:01 13093312 c:\windows\system32\drivers\nvlddmkm.sys

+ 2011-12-02 08:28 . 2011-07-19 22:39 12287456 c:\windows\system32\drivers\igdkmd64.sys

+ 2011-12-05 14:50 . 2012-08-10 05:55 11006440 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-8192.dat

- 2011-12-05 14:50 . 2012-08-08 12:59 11006440 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-8192.dat

- 2011-12-05 16:20 . 2012-08-07 20:38 18357936 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-4096.dat

+ 2011-12-05 16:20 . 2012-08-09 21:13 18357936 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-4096.dat

.

-- Snapshot teruggezet naar huidige datum --

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

.

R0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-06-22 335784]

R1 SASDIFSV;SASDIFSV;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]

R1 SAS***IL;SAS***IL;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SAS***IL64.SYS [x]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update-service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-06-22 177144]

R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]

R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [x]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 250056]

R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [x]

R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]

R3 gupdatem;Google Update-service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [x]

R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-09-16 340240]

R3 NETMD760;Net MD;c:\windows\system32\Drivers\NETMD760.sys [x]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]

R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [x]

R3 PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0;PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\dell support center\pcdsrvc_x64.pkms [2012-04-10 25072]

R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x]

R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-06 1255736]

R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/12/05 17:08];c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [x]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]

S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-15 1166848]

S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]

S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]

S2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]

S2 CronService;Cron Service for Prey;c:\program files\Prey\platform\windows\cronsvc.exe [2011-02-15 19968]

S2 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2008-12-17 410976]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-17 1999168]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-16 380224]

S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-11-23 2118976]

S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]

S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtuele adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [x]

S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [x]

S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [x]

S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]

S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]

S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]

S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [x]

S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]

S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]

S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]

S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]

S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]

S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*Deregistered* - da2c1cad348cf36f

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2012-08-09 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 09:28]

.

2012-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002Core.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002UA.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-07-25 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

2012-08-10 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"combofix"="c:\combofix\CF11481.3XE" [2010-11-21 345088]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\windows\System32\nvinitx.dll

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.be/

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 195.130.131.3 195.130.130.131

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0]

"ImagePath"="\??\c:\progra~1\dell support center\pcdsrvc_x64.pkms"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]

"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\da2c1cad348cf36f]

"ImagePath"="\SystemRoot\System32\Drivers\da2c1cad348cf36f.sys"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\programdata\TVersity\Media Server\MediaServer.exe

c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

.

**************************************************************************

.

Voltooingstijd: 2012-08-10 08:00:18 - machine werd herstart

ComboFix-quarantined-files.txt 2012-08-10 06:00

ComboFix2.txt 2012-08-08 18:54

.

Pre-Run: 468.512.202.752 bytes beschikbaar

Post-Run: 468.183.076.864 bytes beschikbaar

.

- - End Of File - - FFD82DBBEF5C4C7F1A8EDCED2E914F8D

Link naar reactie
Delen op andere sites

Bijna goed. Er is een zaak neit gefixt.

Open het script bestandje en laat enkel deze lijnen staan.

Registry::

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\da2c1cad348cf36f]

Sluit het bestand en sla de wijzigingen op.

Herstart de pc in veilige modus met netwerk en voer dan combofix uit door het scriptje op combofix te slepen.

Plaats dan het nieuwe logje in een volgend bericht.

Link naar reactie
Delen op andere sites

Ziezo, deze werd in veilige modus uitgevoerd, zoals gevraagd ;-)

ComboFix 12-08-09.01 - Michael 10/08/2012 19:55:49.3.8 - x64 NETWORK

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.8086.6664 [GMT 2:00]

Gestart vanuit: c:\users\Michael\Desktop\ComboFix.exe

gebruikte Opdracht switches :: c:\users\Michael\Desktop\CFscript.txt

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Nieuw herstelpunt werd aangemaakt

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-07-10 to 2012-08-10 ))))))))))))))))))))))))))))))

.

.

2012-08-10 18:01 . 2012-08-10 18:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2012-08-10 18:01 . 2012-08-10 18:01 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-08-08 07:01 . 2012-08-08 07:01 74703 ----a-w- c:\windows\SysWow64\mfc45.dll

2012-08-08 07:01 . 2012-08-10 15:50 -------- d-----w- c:\programdata\iolo

2012-08-08 07:01 . 2012-08-08 07:01 -------- d-----w- c:\program files (x86)\iolo

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\programdata\Malwarebytes

2012-08-07 20:33 . 2012-08-07 20:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-08-07 20:33 . 2012-07-03 11:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-08-07 09:25 . 2012-08-07 09:25 388096 ----a-r- c:\users\Michael\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-08-07 09:25 . 2012-08-07 09:25 -------- d-----w- c:\program files (x86)\Trend Micro

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- c:\users\Michael\AppData\Roaming\InstallShield

2012-08-07 08:29 . 2012-08-07 08:29 -------- d-----w- C:\swsetup

2012-08-07 07:57 . 2012-06-22 05:34 169320 ----a-w- c:\windows\system32\drivers\mfeapfk.sys

2012-08-07 07:56 . 2012-06-22 05:38 177144 ----a-w- c:\windows\system32\mfevtps.exe

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Common Files\Java

2012-08-07 07:53 . 2012-08-07 07:53 -------- d-----w- c:\program files (x86)\Oracle

2012-08-07 07:53 . 2012-07-05 20:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-08-07 07:48 . 2012-08-07 07:49 -------- d-----w- c:\users\McAfee

2012-08-07 07:37 . 2012-08-07 07:37 -------- d-----w- c:\windows\SysWow64\wbem\Logs

2012-08-07 07:23 . 2012-08-07 07:23 -------- d-----w- c:\users\Michael\AppData\Roaming\SUPERAntiSpyware.com

2012-08-07 07:16 . 2012-08-07 07:16 -------- d-----w- c:\program files (x86)\Citrix

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\SpeedyPC Software

2012-08-02 14:46 . 2012-08-02 14:46 -------- d-----w- c:\users\Michael\AppData\Roaming\DriverCure

2012-08-02 14:46 . 2012-08-02 15:03 -------- d-----w- c:\programdata\SpeedyPC Software

2012-08-02 07:51 . 2012-08-07 07:56 -------- d-----w- c:\programdata\McAfee

2012-08-02 07:30 . 2012-08-02 07:30 -------- d-----w- c:\programdata\Citrix

2012-08-02 07:29 . 2012-08-02 09:40 -------- d-----w- c:\users\Michael\AppData\Local\Citrix

2012-08-02 06:52 . 2012-06-05 07:37 256904 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys

2012-08-02 06:27 . 2012-08-02 06:27 -------- d-----w- c:\users\Michael\AppData\Roaming\McAfee

2012-07-31 18:01 . 2012-07-31 18:01 83400 ----a-w- c:\windows\system32\drivers\da2c1cad348cf36f.sys

2012-07-31 05:58 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78432234-2B54-4C1C-A764-F1DA14FA081C}\mpengine.dll

2012-07-28 11:30 . 2012-07-28 11:30 -------- d-----w- c:\users\Michael\AppData\Roaming\NVIDIA

2012-07-28 11:13 . 2012-07-28 11:14 -------- d--h--w- c:\windows\msdownld.tmp

2012-07-28 10:58 . 2012-07-28 10:58 -------- d-----w- c:\program files (x86)\Team JPN

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\users\Michael\AppData\Roaming\Anvsoft

2012-07-23 18:02 . 2012-07-23 18:02 -------- d-----w- c:\program files (x86)\Funny Photo Maker

2012-07-21 15:14 . 2012-07-21 15:14 -------- d-----w- c:\program files (x86)\Elaborate Bytes

2012-07-21 15:14 . 2012-07-21 15:14 -------- d--h--w- c:\programdata\Common Files

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\Garmin

2012-07-21 10:15 . 2012-07-21 10:15 -------- d-----w- c:\users\Michael\AppData\Local\GARMIN_Corp

2012-07-13 05:58 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys

2012-07-11 21:02 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll

2012-07-11 21:02 . 2011-06-24 14:44 243200 ----a-w- c:\windows\SysWow64\xvidvfw.dll

2012-07-11 21:02 . 2011-06-24 14:28 650752 ----a-w- c:\windows\SysWow64\xvidcore.dll

2012-07-11 21:02 . 2011-12-21 17:14 151552 ----a-w- c:\windows\SysWow64\ac3acm.acm

2012-07-11 21:02 . 2012-07-11 18:00 79872 ----a-w- c:\windows\SysWow64\ff_vfw.dll

2012-07-11 20:58 . 2012-07-15 12:10 -------- d-----w- c:\users\Michael\AppData\Roaming\Realtek

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-08-10 17:51 . 2012-02-12 18:27 29 ----a-w- c:\windows\SysWow64\TempWmicBatchFile.bat

2012-08-07 09:28 . 2012-04-14 07:37 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-08-07 09:28 . 2011-12-02 07:08 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-07-13 05:55 . 2011-12-09 14:45 59701280 ----a-w- c:\windows\system32\MRT.exe

2012-06-22 05:38 . 2012-06-22 05:38 335784 ----a-w- c:\windows\system32\drivers\mfewfpk.sys

2012-06-22 05:36 . 2012-06-22 05:36 752672 ----a-w- c:\windows\system32\drivers\mfehidk.sys

2012-06-09 17:21 . 2011-12-05 16:01 178688 ----a-w- c:\windows\SysWow64\unrar.dll

2012-06-02 22:19 . 2012-06-22 05:51 38424 ----a-w- c:\windows\system32\wups.dll

2012-06-02 22:19 . 2012-06-22 05:52 2428952 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-02 22:19 . 2012-06-22 05:52 57880 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-02 22:19 . 2012-06-22 05:52 44056 ----a-w- c:\windows\system32\wups2.dll

2012-06-02 22:19 . 2012-06-22 05:51 701976 ----a-w- c:\windows\system32\wuapi.dll

2012-06-02 22:15 . 2012-06-22 05:52 2622464 ----a-w- c:\windows\system32\wucltux.dll

2012-06-02 22:15 . 2012-06-22 05:51 99840 ----a-w- c:\windows\system32\wudriver.dll

2012-06-02 13:19 . 2012-06-22 05:51 186752 ----a-w- c:\windows\system32\wuwebv.dll

2012-06-02 13:15 . 2012-06-22 05:51 36864 ----a-w- c:\windows\system32\wuapp.exe

2012-05-31 10:25 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2009-07-14 01:52 . !HASH: COULD NOT OPEN FILE !!!!! . 24128 . . [------] .. c:\windows\system32\drivers\atapi.sys

.

[-] 2009-07-14 00:10 . !HASH: COULD NOT OPEN FILE !!!!! . 23040 . . [------] .. c:\windows\system32\drivers\asyncmac.sys

.

[-] 2009-07-14 01:48 . !HASH: COULD NOT OPEN FILE !!!!! . 50768 . . [------] .. c:\windows\system32\drivers\kbdclass.sys

.

[-] 2011-12-02 08:48 . !HASH: COULD NOT OPEN FILE !!!!! . 951680 . . [------] .. c:\windows\system32\drivers\ndis.sys

.

[-] 2011-12-02 08:49 . !HASH: COULD NOT OPEN FILE !!!!! . 1659776 . . [------] .. c:\windows\system32\drivers\ntfs.sys

.

[-] 2009-07-13 23:19 . !HASH: COULD NOT OPEN FILE !!!!! . 6144 . . [------] .. c:\windows\system32\drivers\null.sys

.

[-] 2012-03-30 11:35 . !HASH: COULD NOT OPEN FILE !!!!! . 1918320 . . [------] .. c:\windows\system32\drivers\tcpip.sys

.

[-] 2010-11-21 03:24 . !HASH: COULD NOT OPEN FILE !!!!! . 119296 . . [------] .. c:\windows\system32\drivers\tdx.sys

.

[7] 2012-05-04 . A37A39568C8EC9A17D1B7471445B81A8 . 3916656 . . [6.1.7601.21987] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21987_none_6e78bf732bb8d24e\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\erdnt\cache86\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\SysWOW64\ntoskrnl.exe

[7] 2012-05-04 . 53483A0B2DE3617E832F1DBAF9620F39 . 3913072 . . [6.1.7601.17835] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17835_none_6e2331b012747421\ntoskrnl.exe

[7] 2012-03-31 . 28F44480E411C3DDF04B63F6560E6EF4 . 3913072 . . [6.1.7601.17803] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17803_none_6e41a0e0125deda0\ntoskrnl.exe

[7] 2012-03-31 . 2E02A17E8965AD671E4987E503AD38B1 . 3916656 . . [6.1.7601.21955] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21955_none_6e972ea32ba24bcd\ntoskrnl.exe

[7] 2012-03-06 . 53B4BDEA12A032EEC71E60B6BFF42F37 . 3913072 . . [6.1.7601.17790] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17790_none_6ddd4ed012a99fed\ntoskrnl.exe

[7] 2012-03-06 . 57B7DE30C4E65AD19CA13AC3065EE60B . 3916656 . . [6.1.7601.21936] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21936_none_6eadcec52b912d42\ntoskrnl.exe

[7] 2011-12-02 . FB58ABD5E1F75A2CF713C9DFF0EC0804 . 3912576 . . [6.1.7601.17640] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17640_none_6e135c8612811711\ntoskrnl.exe

[7] 2011-12-02 . 90EFDB506F6140EEA9DEE398D9449D86 . 3912576 . . [6.1.7601.21755] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21755_none_6e972ad72ba2517f\ntoskrnl.exe

[7] 2011-11-19 . F0F0E99A65F598A1A7720F5111C4DA8F . 3913584 . . [6.1.7601.17727] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17727_none_6e30004a126a8db7\ntoskrnl.exe

[7] 2011-11-19 . 00B12EA93ED392FBD09F07B63E926647 . 3916656 . . [6.1.7601.21863] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.21863_none_6e8a5c3d2bac37e9\ntoskrnl.exe

[7] 2010-11-21 . 2088D9994332583EDB3C561DE31EA5AD . 3911040 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.1.7601.17514_none_6e37cb8c12652b73\ntoskrnl.exe

[-] 2012-05-04 11:06 . !HASH: COULD NOT OPEN FILE !!!!! . 5559664 . . [------] .. c:\windows\system32\ntoskrnl.exe

.

((((((((((((((((((((((((((((( SnapShot_2012-08-10_05.56.33 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-11-21 03:09 . 2012-08-10 17:52 74920 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

- 2009-07-14 05:10 . 2012-08-10 05:47 44970 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-08-10 17:52 44970 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2011-12-05 14:53 . 2012-08-10 17:52 19978 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4175197894-823669262-2136076139-1002_UserData.bin

- 2011-12-02 00:02 . 2012-08-10 05:55 1733 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat

+ 2011-12-02 00:02 . 2012-08-10 17:52 1733 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Bluetooth\bthservsdp.dat

- 2012-08-10 05:55 . 2012-08-10 05:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-08-10 17:53 . 2012-08-10 17:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-08-10 17:53 . 2012-08-10 17:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-08-10 05:55 . 2012-08-10 05:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2010-11-21 16:48 . 2012-08-10 05:48 743342 c:\windows\system32\perfh013.dat

+ 2010-11-21 16:48 . 2012-08-10 15:41 743342 c:\windows\system32\perfh013.dat

+ 2009-07-14 02:36 . 2012-08-10 17:49 647686 c:\windows\system32\perfh009.dat

+ 2010-11-21 16:48 . 2012-08-10 15:41 152426 c:\windows\system32\perfc013.dat

- 2010-11-21 16:48 . 2012-08-10 05:48 152426 c:\windows\system32\perfc013.dat

+ 2009-07-14 02:36 . 2012-08-10 17:49 116810 c:\windows\system32\perfc009.dat

+ 2009-07-14 05:01 . 2012-08-10 17:52 430204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-08-10 05:55 430204 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2011-12-05 14:50 . 2012-08-10 05:55 11006440 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-8192.dat

+ 2011-12-05 14:50 . 2012-08-10 17:52 11006440 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-8192.dat

+ 2011-12-05 16:20 . 2012-08-10 13:01 18357936 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-4096.dat

- 2011-12-05 16:20 . 2012-08-09 21:13 18357936 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4175197894-823669262-2136076139-1002-4096.dat

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveTrack"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

.

R0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-06-22 335784]

R1 SASDIFSV;SASDIFSV;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]

R1 SAS***IL;SAS***IL;c:\users\Michael\AppData\Local\Temp\SAS_SelfExtract\SAS***IL64.SYS [x]

R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/12/05 17:08];c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-03-13 11:58 146928]

R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

R2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]

R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-15 1166848]

R2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]

R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]

R2 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 CronService;Cron Service for Prey;c:\program files\Prey\platform\windows\cronsvc.exe [2011-02-15 19968]

R2 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2008-12-17 410976]

R2 gupdate;Google Update-service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-06-22 177144]

R2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]

R2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-17 1999168]

R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

R2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-16 380224]

R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-11-23 2118976]

R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]

R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]

R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [2012-03-11 44672]

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 250056]

R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtuele adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-09-15 299008]

R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-09-15 299008]

R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]

R3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712]

R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-08-29 53760]

R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-10-10 288768]

R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-06-16 176000]

R3 gupdatem;Google Update-service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 136176]

R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-10-11 59904]

R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]

R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-08-23 317440]

R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2011-08-25 173656]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-09-16 340240]

R3 NETMD760;Net MD;c:\windows\system32\Drivers\NETMD760.sys [2010-05-27 19456]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]

R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys [2011-06-13 122472]

R3 PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0;PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\dell support center\pcdsrvc_x64.pkms [2012-04-10 25072]

R3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-13 29288]

R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]

R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-11-09 11856]

R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-06 1255736]

R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2011-10-17 27712]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]

S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-04-07 283200]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]

S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]

S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]

S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2011-09-22 56600]

S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-09-18 8604672]

S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-13 95744]

S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-13 212992]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*Deregistered* - da2c1cad348cf36f

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2012-08-10 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-07 09:28]

.

2012-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-11 11:15]

.

2012-08-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002Core.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4175197894-823669262-2136076139-1002UA.job

- c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-05 15:06]

.

2012-07-25 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

2012-08-10 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\Dell Support Center\uaclauncher.exe [2012-04-13 06:11]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\windows\System32\nvinitx.dll

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.be/

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 195.130.131.3 195.130.130.131

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{DF44B31B-FD8C5AD0-06020101}_0]

"ImagePath"="\??\c:\progra~1\dell support center\pcdsrvc_x64.pkms"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]

"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\000.fcl"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\da2c1cad348cf36f]

"ImagePath"="\SystemRoot\System32\Drivers\da2c1cad348cf36f.sys"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2012-08-10 20:03:32

ComboFix-quarantined-files.txt 2012-08-10 18:03

ComboFix2.txt 2012-08-10 06:00

ComboFix3.txt 2012-08-08 18:54

.

Pre-Run: 468.656.664.576 bytes beschikbaar

Post-Run: 468.466.401.280 bytes beschikbaar

.

- - End Of File - - 369E89F2EB28A57DC55F7B71118C5AA3

Link naar reactie
Delen op andere sites

We zijn nu zeker dat het probleem niet wordt veroorzaakt door een virus of malware besmetting.

Verwijder Combofix: Start -> Uitvoeren en typ: ComboFix /Uninstall (met spatie voor de /)

Dit zal Combofix verwijderen + gerelateerde mappen en bestanden, herstelt de klokinstellingen opnieuw, verbergt de bestandsextensies, gaat verborgen bestanden en systeembestanden terug verbergen en maakt een nieuw herstelpunt.

Indien aanwezig mag je de map C:\Qoobox manueel verwijderen.

Wat heb je al gedaan om het probleem van de updates op te lossen?

Kan je desgevallend ook vermelden welke tools / programma's je reeds hebt gebruikt om dit op te lossen?

Kwestie van geen tips te geven die je al hebt uitgevoerd.

Link naar reactie
Delen op andere sites

Zo, ComboFix is verwijderd zoals gevraagd.

Om op je vraag te antwoorden: ik heb via de microsoft alle mogelijke Fixit-programma's laten runnen doch deze konden het probleem niet oplossen. De enige échte foutmelding die ik krijg is 0x80070424 (heb hierop ook gegoogled naar Microsoft en het Fixit progje geprobeerd, zonder resultaat).

Verder kan ik géén enkele virusscanner realtime laten beschermen, raar maar waar. Mcafee kan ik zelfs niet installeren omdat er een essentieel windows onderdeel zou ontbreken?

Volgende Microsoft hulpprogramma's heb ik al geprobeerd:

MicrosoftFixit.wu.LB.32267927146221498.3.1.Run

MicrosoftFixit.wu.RNP.31267936403288208.6.1.Run

MicrosoftFixit.wu.Run

MicrosoftFixit50687

MicrosoftFixit50884

Windows6.1-KB947821-v22-x64

WindowsUpdateAgent30-x64

Groetjes

Link naar reactie
Delen op andere sites

Ga naar start - alle programma's - bureauaccesoires.

Zoek het icoon van het opdrachtprompt en klik er op met de rechter muisknop en kies dan in het lijstje voor uitvoeren als administrator om het opdrachtprompt te openen.

Typ nu regsvr32 wuaueng.dll en druk enter

Typ nu regsvr32 wups.dll en druk enter

Typ exit en druk enter om het opdrachtprompt te sluiten.

Ga naar start, typ services.msc in het zoekveld en open de services.

Controleer of onderstaande services opgestart zijn en start ze handmatig op indien nodig.

Background Intelligent Transfer Service

Windows Update

Workstation

Sluit het service venter en kijk of de updates nu wel willen installeren.

Link naar reactie
Delen op andere sites

post-36776-1417705046,9232_thumb.jpgIk krijg een foutmelding bij het uitvoeren van regsvr32 wuaueng.dll (zie foto)

regsvr32 wups.dl kan ik wel uitvoeren.

Als ik naar services ga vind ik géén "Background Intelligent Transfer Service" en geen "Windows Update".

"Workstation" vind ik wel en deze is opgestart

Vriendelijke groet

Link naar reactie
Delen op andere sites


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.