Ga naar inhoud

vtveen

Lid
  • Items

    165
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door vtveen

  1. Removal Tool levert weer allerlei problemen op met 'Avast'; nu het bestand ComboFix verwijderd. Qoobox ??
  2. Veilige modus: Qoobox zelf en BackEnv kan ik niet verwijderen (nog steeds dat Administrators verhaal ..). Een aantal andere '(sub)mappen' wel - zowel in veilige modus als normaal (zoals: Quarantine, Program Files, E, C, Windows , System32, Drivers en Registry Back up) Combofix /Uninstall: blijft alleen het icoon van het Bureaublad verwijderen. Het bestand in mijn Downloads blijft gewoon bestaan.
  3. Neen. (ik heb nog wel op m'n oude harde schijf, die in m'n nieuwe computer is ingebouwd twee programma's staan: Canon ScanGear Toobox FAU en Canon ScanGear Toolbox Cs; is daar nog iets mee te doen ??)
  4. "Qoobox zou je dan moeten kunnen verwijderen in "veilige modus"." Is voor experts waarschijnlijk eenvoudig, maar niet voor mij (helaas). Wat te doen ?? Combofix: Combofix /Uninstall gevonden en verwijderd, maar dat laat alleen het icoon van het bureaublad verdwijnen. Ik heb daarna nog steeds Combofix in mijn downloads staan.
  5. Qoobox verwijderen lukt niet; krijg melding "U moet administrator machtigingen opgeven om door te gaan" ?? Combofix: ComboFix/Uninstall kan ik niet vinden. Ik heb wel onder mijn downloads ComboFix staan, die ik wel zou kunnen verwijderen. Is dat hetzelfde ??
  6. Wat ik heb gedaan (zo goed mogelijk beschreven): - zoals in bericht #6 Canoscan D660.exe gedownload - bij pop-up venster gekozen voor C\users\gebruiker\desktop - vind dan inderdaad een icoontje Canoscan op het bureaublad (als bestandsmap) - rechtermuisklik en via Eigenschappen > Compatibiliteit - gekozen voor modus 'Vista" (is dat juist ???) - krijg dan nog een pop-up venster "wilt u het programma van een onbekende uitgever toestaan veranderingen aan te brengen" - "ja" > venster "C:\Windows\system32" - OK en daarna gebeurt er niets meer ... (ik krijg ook nergens de keuze het apparaat weer aan te sluiten)
  7. Ook deze beide 'modificaties' aangebracht. Volgens mij loopt alles weer goed; ik zal nog een paar dagen scherp op 'vreemde' problemen letten en dan hopelijk mijn vraag als opgelost markeren. In ieder geval zeer veel dank zover !!
  8. ComboFix 12-10-09.01 - Gebruiker 10-10-2012 11:09:46.1.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.31.1043.18.3488.2512 [GMT 2:00] Gestart vanuit: c:\users\Gebruiker\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\BrowserCompanion c:\program files\BrowserCompanion\jsLOader.dll c:\program files\BrowserCompanion\logo.ico c:\program files\BrowserCompanion\tdATaprotocol.dll c:\program files\BrowserCompanion\toolbar.dll c:\program files\BrowserCompanion\uninstall.exe c:\program files\BrowserCompanion\updatebhoWin32.dll c:\program files\BrowserCompanion\updater.ini c:\program files\BrowserCompanion\widgetserv.exe c:\windows\system32\drivers\hwinterface.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_hwinterface -------\Service_hwinterface . . (((((((((((((((((((( Bestanden Gemaakt van 2012-09-10 to 2012-10-10 )))))))))))))))))))))))))))))) . . 2012-10-10 09:13 . 2012-10-10 09:13 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-10-10 08:56 . 2012-10-10 08:56 -------- d-----w- c:\program files\Trend Micro 2012-10-10 07:39 . 2012-09-18 22:59 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE0AC286-D407-4D67-8CE5-5228CBE63C02}\mpengine.dll 2012-10-09 11:21 . 2012-10-10 07:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-10-09 11:21 . 2012-10-09 11:21 -------- d-----w- c:\programdata\Malwarebytes 2012-10-09 11:17 . 2012-10-10 07:34 -------- d-----w- c:\program files\Conduit 2012-10-09 11:16 . 2012-10-10 07:34 -------- d-----w- c:\program files\FileConverter_1.4 2012-10-07 08:20 . 2012-10-07 08:33 -------- d-----w- c:\program files\CCleaner 2012-10-06 17:26 . 2012-10-06 17:26 -------- d-----w- c:\program files\HitmanPro 2012-10-06 17:25 . 2012-10-06 17:26 -------- d-----w- c:\programdata\HitmanPro 2012-10-04 13:08 . 2012-10-04 13:08 -------- d-----w- c:\programdata\Canneverbe Limited 2012-10-03 15:53 . 2012-10-06 15:02 -------- d-----w- c:\program files\BookSmart 2012-10-02 14:18 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll 2012-10-02 09:01 . 2012-10-02 09:01 -------- d-----w- c:\windows\system32\Wat 2012-10-02 08:25 . 2012-05-31 10:25 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-10-02 08:23 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe 2012-10-02 08:23 . 2012-02-11 05:43 492032 ----a-w- c:\windows\system32\win32spl.dll 2012-10-02 08:23 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe 2012-10-02 08:23 . 2012-08-21 20:12 245760 ----a-w- c:\windows\system32\OxpsConverter.exe 2012-10-02 08:20 . 2012-05-14 04:33 769024 ----a-w- c:\windows\system32\localspl.dll 2012-10-02 08:20 . 2011-02-03 05:54 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2012-10-02 08:15 . 2003-06-18 23:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll 2012-10-02 08:15 . 2003-06-18 23:31 17920 ----a-w- c:\windows\system32\mdimon.dll 2012-10-02 08:14 . 2012-10-02 14:06 -------- d-----w- c:\program files\Microsoft.NET 2012-10-02 08:14 . 2012-08-21 09:13 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-02 08:14 . 2012-08-21 09:13 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-02 08:14 . 2012-08-21 09:13 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-10-02 08:13 . 2012-08-21 09:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-02 08:13 . 2012-08-21 09:13 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-02 08:13 . 2012-08-21 09:13 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-02 08:13 . 2012-08-21 09:12 41224 ----a-w- c:\windows\avastSS.scr 2012-10-02 08:13 . 2012-08-21 09:12 227648 ----a-w- c:\windows\system32\aswBoot.exe 2012-10-02 08:13 . 2012-10-02 08:13 -------- d-----w- c:\programdata\AVAST Software 2012-10-02 08:13 . 2012-10-02 08:13 -------- d-----w- c:\program files\AVAST Software 2012-10-02 08:13 . 2012-10-02 08:13 -------- d-----w- c:\program files\CDBurnerXP 2012-10-02 08:11 . 2012-10-02 08:11 -------- d-----r- C:\MSOCache 2012-10-02 08:10 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe 2012-10-02 08:10 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll 2012-10-02 08:10 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll 2012-10-02 08:10 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll 2012-10-02 08:10 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll 2012-10-02 08:10 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll 2012-10-02 08:10 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll 2012-10-02 08:10 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll 2012-10-02 08:10 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe 2012-09-11 10:50 . 2012-09-12 12:03 -------- d-----w- c:\windows\Panther 2012-09-11 10:50 . 2012-09-11 10:50 -------- d-----w- C:\Boot 2012-09-11 10:50 . 2012-09-11 10:50 -------- d-----w- c:\windows\system32\OEM 2012-09-11 10:50 . 2012-09-11 10:50 -------- d-----w- c:\program files\Wortmann_AG 2012-09-11 10:49 . 2012-09-11 10:49 -------- d-----w- c:\windows\ConfigSetRoot 2012-09-11 10:45 . 2009-12-31 06:48 1003008 ----a-w- C:\VMWindow.exe 2012-09-11 10:42 . 2012-09-11 10:42 -------- d-----w- c:\windows\nl 2012-09-11 10:41 . 2012-09-11 10:41 -------- dc----w- c:\windows\system32\DRVSTORE 2012-09-11 10:41 . 2011-05-13 13:27 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys 2012-09-11 10:41 . 2012-09-11 10:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2012-09-11 10:40 . 2012-09-11 10:40 -------- d-----w- c:\windows\PCHEALTH 2012-09-11 10:40 . 2012-09-11 10:42 -------- d-----w- c:\program files\Windows Live 2012-09-11 10:39 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2012-09-11 10:39 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2012-09-11 10:39 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2012-09-11 10:38 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2012-09-11 10:37 . 2012-09-11 10:37 -------- d-----w- c:\program files\Microsoft Silverlight 2012-09-11 10:37 . 2012-09-11 10:37 -------- d-----w- c:\program files\Common Files\Windows Live 2012-09-11 10:33 . 2009-12-31 09:22 295936 ----a-w- c:\windows\system32\drivers\vpcvmm.sys 2012-09-11 10:33 . 2009-12-31 09:05 2171392 ----a-w- c:\windows\system32\VPCWizard.exe 2012-09-11 10:33 . 2009-12-31 09:05 3330560 ----a-w- c:\windows\system32\vpc.exe 2012-09-11 10:33 . 2009-12-31 06:48 1003008 ----a-w- c:\windows\system32\VMWindow.exe 2012-09-11 10:33 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\system32\msxml6.dll 2012-09-11 10:33 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\system32\msxml3.dll 2012-09-11 10:33 . 2010-06-26 03:24 2048 ----a-w- c:\windows\system32\msxml3r.dll 2012-09-11 10:32 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll 2012-09-11 10:31 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll 2012-09-11 10:31 . 2012-06-06 05:05 143360 ----a-w- c:\program files\Common Files\System\ado\msjro.dll 2012-09-11 10:31 . 2012-06-06 05:05 372736 ----a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-09-11 10:31 . 2012-06-06 05:05 57344 ----a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-09-11 10:31 . 2012-06-06 05:05 352256 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-09-11 10:31 . 2012-06-06 05:05 212992 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-09-11 10:31 . 2012-06-06 05:05 1019904 ----a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-09-11 10:31 . 2012-06-06 05:03 805376 ----a-w- c:\windows\system32\cdosys.dll 2012-09-11 10:29 . 2012-03-17 07:27 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys 2012-09-11 10:28 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-09-11 10:27 . 2012-04-24 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2012-09-11 10:27 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\system32\crypt32.dll 2012-09-11 10:27 . 2012-04-24 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll 2012-09-11 10:27 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-09-11 10:27 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-09-11 10:27 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll 2012-09-11 10:27 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll 2012-09-11 10:27 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe 2012-09-11 10:26 . 2011-12-30 05:27 478720 ----a-w- c:\windows\system32\timedate.cpl 2012-09-11 10:25 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\system32\DWrite.dll 2012-09-11 10:23 . 2012-06-02 04:45 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2012-09-11 10:23 . 2012-06-02 04:45 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-09-11 10:23 . 2012-06-02 04:40 369336 ----a-w- c:\windows\system32\drivers\cng.sys 2012-09-11 10:23 . 2012-06-02 04:40 225280 ----a-w- c:\windows\system32\schannel.dll 2012-09-11 10:23 . 2012-06-02 04:39 219136 ----a-w- c:\windows\system32\ncrypt.dll 2012-09-11 10:22 . 2011-12-16 07:52 690688 ----a-w- c:\windows\system32\msvcrt.dll 2012-09-11 10:22 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2012-09-11 10:22 . 2012-03-01 05:37 172544 ----a-w- c:\windows\system32\wintrust.dll 2012-09-11 10:22 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll 2012-09-11 10:22 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll 2012-09-11 10:21 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll 2012-09-11 10:20 . 2012-01-04 08:58 442880 ----a-w- c:\windows\system32\ntshrui.dll 2012-09-11 10:19 . 2011-11-05 04:26 2048 ----a-w- c:\windows\system32\tzres.dll 2012-09-11 10:19 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll 2012-09-11 10:19 . 2012-10-08 16:54 -------- d-----w- C:\Driver 2012-09-11 10:18 . 2012-02-17 05:34 826880 ----a-w- c:\windows\system32\rdpcore.dll 2012-09-11 10:18 . 2012-02-17 04:13 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys 2012-09-11 10:18 . 2011-10-26 04:28 38912 ----a-w- c:\windows\system32\csrsrv.dll 2012-09-11 10:18 . 2011-10-15 05:38 534528 ----a-w- c:\windows\system32\EncDec.dll 2012-09-11 10:14 . 2012-10-02 08:08 -------- d-----w- C:\Inst 2012-09-11 10:14 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll 2012-09-11 10:14 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll 2012-09-11 10:14 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll 2012-09-11 10:14 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll 2012-09-11 10:14 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll 2012-09-11 10:14 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe 2012-09-11 10:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll 2012-09-11 10:14 . 2011-08-17 04:24 465408 ----a-w- c:\windows\system32\psisdecd.dll 2012-09-11 10:14 . 2011-08-17 04:19 75776 ----a-w- c:\windows\system32\psisrndr.ax 2012-09-11 10:12 . 2011-06-15 08:55 86016 ----a-w- c:\windows\system32\odbccu32.dll 2012-09-11 10:12 . 2011-06-15 08:55 81920 ----a-w- c:\windows\system32\odbccr32.dll 2012-09-11 10:12 . 2011-06-15 08:55 319488 ----a-w- c:\windows\system32\odbcjt32.dll 2012-09-11 10:12 . 2011-06-15 08:55 163840 ----a-w- c:\windows\system32\odbctrac.dll 2012-09-11 10:12 . 2011-06-15 08:55 122880 ----a-w- c:\windows\system32\odbccp32.dll . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-02 08:18 . 2011-03-28 16:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-07-27 11:21 . 2012-08-06 08:48 276288 ----a-w- c:\windows\system32\IntelCpHeciSvc.exe 2012-07-27 11:20 . 2012-08-06 08:48 144704 ----a-w- c:\windows\system32\igfxtray.exe 2012-07-27 11:20 . 2012-08-06 08:48 269120 ----a-w- c:\windows\system32\igfxsrvc.exe 2012-07-27 11:20 . 2012-08-06 08:48 188224 ----a-w- c:\windows\system32\igfxpers.exe 2012-07-27 11:20 . 2012-08-06 08:48 196416 ----a-w- c:\windows\system32\igfxext.exe 2012-07-27 11:20 . 2012-08-06 08:48 180544 ----a-w- c:\windows\system32\hkcmd.exe 2012-07-27 11:20 . 2012-08-06 08:48 6225216 ----a-w- c:\windows\system32\GfxUI.exe 2012-07-25 10:08 . 2012-08-06 08:48 519680 ----a-w- c:\windows\system32\iglhsip32.dll 2012-07-25 10:08 . 2012-08-06 08:48 286208 ----a-w- c:\windows\system32\igfxTMM.dll 2012-07-25 10:08 . 2012-08-06 08:48 180224 ----a-w- c:\windows\system32\iglhcp32.dll 2012-07-25 10:08 . 2012-08-06 08:48 102400 ----a-w- c:\windows\system32\igfxCoIn_v2817.dll 2012-07-25 10:08 . 2012-08-06 08:48 58880 ----a-w- c:\windows\system32\igfxsrvc.dll 2012-07-25 10:08 . 2012-08-06 08:48 437248 ----a-w- c:\windows\system32\igfxrrus.lrc 2012-07-25 10:08 . 2012-08-06 08:48 437248 ----a-w- c:\windows\system32\igfxrrom.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrsky.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrptg.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435712 ----a-w- c:\windows\system32\igfxrtrk.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435712 ----a-w- c:\windows\system32\igfxrsve.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435712 ----a-w- c:\windows\system32\igfxrslv.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435712 ----a-w- c:\windows\system32\igfxrptb.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435200 ----a-w- c:\windows\system32\igfxrtha.lrc 2012-07-25 10:08 . 2012-08-06 08:48 9023488 ----a-w- c:\windows\system32\igfxress.dll 2012-07-25 10:08 . 2012-08-06 08:48 437760 ----a-w- c:\windows\system32\igfxrfra.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrplk.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrnld.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrita.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrhrv.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436224 ----a-w- c:\windows\system32\igfxrhun.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436224 ----a-w- c:\windows\system32\igfxrfin.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435712 ----a-w- c:\windows\system32\igfxrnor.lrc 2012-07-25 10:08 . 2012-08-06 08:48 433664 ----a-w- c:\windows\system32\igfxrheb.lrc 2012-07-25 10:08 . 2012-08-06 08:48 430080 ----a-w- c:\windows\system32\igfxrjpn.lrc 2012-07-25 10:08 . 2012-08-06 08:48 429056 ----a-w- c:\windows\system32\igfxrkor.lrc 2012-07-25 10:08 . 2012-08-06 08:48 9216 ----a-w- c:\windows\system32\IGFXDEVLib.dll 2012-07-25 10:08 . 2012-08-06 08:48 438272 ----a-w- c:\windows\system32\igfxrell.lrc 2012-07-25 10:08 . 2012-08-06 08:48 437760 ----a-w- c:\windows\system32\igfxresn.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436736 ----a-w- c:\windows\system32\igfxrdeu.lrc 2012-07-25 10:08 . 2012-08-06 08:48 436224 ----a-w- c:\windows\system32\igfxrcsy.lrc 2012-07-25 10:08 . 2012-08-06 08:48 435200 ----a-w- c:\windows\system32\igfxrdan.lrc 2012-07-25 10:08 . 2012-08-06 08:48 433664 ----a-w- c:\windows\system32\igfxrara.lrc 2012-07-25 10:08 . 2012-08-06 08:48 427008 ----a-w- c:\windows\system32\igfxrcht.lrc 2012-07-25 10:08 . 2012-08-06 08:48 426496 ----a-w- c:\windows\system32\igfxrchs.lrc 2012-07-25 10:08 . 2012-08-06 08:48 328192 ----a-w- c:\windows\system32\igfxdev.dll 2012-07-25 10:08 . 2012-08-06 08:48 316416 ----a-w- c:\windows\system32\igfxpph.dll 2012-07-25 10:08 . 2012-08-06 08:48 284160 ----a-w- c:\windows\system32\igfxrenu.lrc 2012-07-25 10:08 . 2012-08-06 08:48 25088 ----a-w- c:\windows\system32\igfxexps.dll 2012-07-25 10:08 . 2012-08-06 08:48 130048 ----a-w- c:\windows\system32\igfxdo.dll 2012-07-25 10:08 . 2012-08-06 08:48 604160 ----a-w- c:\windows\system32\igfxcmrt32.dll 2012-07-25 10:08 . 2012-08-06 08:48 448512 ----a-w- c:\windows\system32\igfx11cmrt32.dll 2012-07-25 10:08 . 2012-08-06 08:48 3776512 ----a-w- c:\windows\system32\igfxcmjit32.dll 2012-07-25 10:08 . 2012-08-06 08:48 120320 ----a-w- c:\windows\system32\igfxcpl.cpl 2012-07-25 10:08 . 2012-08-06 08:48 6718976 ----a-w- c:\windows\system32\igdumd32.dll 2012-07-25 10:07 . 2012-08-06 08:48 7397376 ----a-w- c:\windows\system32\drivers\igdkmd32.sys 2012-07-25 10:07 . 2012-08-06 08:48 64512 ----a-w- c:\windows\system32\igdde32.dll 2012-07-25 10:07 . 2012-08-06 08:48 6831616 ----a-w- c:\windows\system32\igd10umd32.dll 2012-07-25 10:07 . 2012-08-06 08:48 10673152 ----a-w- c:\windows\system32\ig4icd32.dll 2012-07-25 10:07 . 2012-08-06 08:48 94208 ----a-w- c:\windows\system32\IccLibDll.dll 2012-07-25 10:07 . 2012-08-06 08:48 96256 ----a-w- c:\windows\system32\hccutils.dll 2012-07-25 10:07 . 2012-08-06 08:48 173056 ----a-w- c:\windows\system32\gfxSrvc.dll 2012-07-25 10:07 . 2012-08-06 08:48 452440 ----a-w- c:\windows\system32\d3dx10_40.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2012-06-11 10996368] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-07-27 144704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-07-27 180544] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-07-27 188224] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys] @="" . R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\Intel\Intel® Management Engine Components\UNS\UNS.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 cphs;Intel® Content Protection HECI Service;c:\windows\system32\IntelCpHeciSvc.exe [x] R3 cpuz135;cpuz135;c:\users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x32.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [x] S3 MEI;Intel® Management Engine Interface;c:\windows\system32\drivers\HECI.sys [x] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - WS2IFSL . Inhoud van de 'Gedeelde Taken' map . 2012-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-02 08:12] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://members.virtualtourist.com/m/7c27b/ IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.138 . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-Locked - (no file) . . . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Andere Aktieve Processen ------------------------ . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\taskhost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\conhost.exe c:\program files\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\windows\system32\sppsvc.exe . ************************************************************************** . Voltooingstijd: 2012-10-10 11:16:16 - machine werd herstart ComboFix-quarantined-files.txt 2012-10-10 09:16 ComboFix2.txt 2012-10-10 08:42 ComboFix3.txt 2012-10-10 08:10 . Pre-Run: 408.351.100.928 bytes beschikbaar Post-Run: 407.835.889.664 bytes beschikbaar . - - End Of File - - BCB823FEA46B4BE6C14CA03460327A2E Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 19:58:16, on 10-10-2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16450) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\BookSmart\BookSmart.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = "Travelling is a way of life" vtveen's Profile R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU) O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- End of file - 5048 bytes
  9. Hartelijk dank voor alle aanwijzingen. Helaas 'snap' ik er niet genoeg van om de boel aan de praat te krijgen cq de in structies tot een goed einde te brengen.
  10. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:06:30, on 10-10-2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16450) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\taskeng.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = "Travelling is a way of life" vtveen's Profile R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: script helper for ie - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Update Timer - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- End of file - 6464 bytes Het lukt me niet het logbestand van ComboFix terug te vinden. Ik heb wel geconstateerd dat er twee zaken zijn verwijderd: - Bestand BrowserCompanion - c:\windows\system32\drivers\hwinterface.sys
  11. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:13:44, on 9-10-2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16450) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\system32\taskhost.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Users\Gebruiker\AppData\Roaming\BrowserCompanion\tcbhn.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZUTZNOMO\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = "Travelling is a way of life" vtveen's Profile R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: FileConverter 1.4 Toolbar - {296aa17d-c89e-4242-a5a4-44bfe76914a2} - C:\Program Files\FileConverter_1.4\prxtbFile.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: FileConverter 1.4 - {296aa17d-c89e-4242-a5a4-44bfe76914a2} - C:\Program Files\FileConverter_1.4\prxtbFile.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O3 - Toolbar: FileConverter 1.4 Toolbar - {296aa17d-c89e-4242-a5a4-44bfe76914a2} - C:\Program Files\FileConverter_1.4\prxtbFile.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O4 - Startup: tcbhn.lnk = C:\Users\Gebruiker\AppData\Roaming\BrowserCompanion\tcbhn.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- End of file - 6500 bytes
  12. Al een paar dagen vreemde zaken op mijn (nieuwe) PC: - na het openenen van een zoekresultaat vanuit het hoofdmenu van Google heel traag 'pagina terug' - voor één van mijn websites kon ik niet meer inloggen Inmiddels Malwarebutes gedraaid; deze detecteerde 43 Pup.blabbers. Deze zijn verwijderd en daarna waren de problemen over. Ik las op internet dat ik evt. nog meer zou moeten doen om de PC helemaal schoon te krijgen, maar ik 'vertrouw' die websites niet. Is het inderdaad zo dat na het verwijderen van de PUP.blabbers er nog meer moet gebeuren ???
  13. Die heb ik teruggevonden in Downloads. En dan .... ??
  14. Malwarebytes gedraaid en het probleem lijkt nu over.
  15. Sinds één week heb ik een nieuwe PC met daarop Windows 7. De laatste dagen heb ik een 'probleem' wanneer ik via Google aan het zoeken ben. Als ik vanuit een zoekresultaat naar een andere website ga en daarna via "Pagina terug" naar de hoofdpagina van Google probeer te gaan, krijg ik gedurende een aantal seconden een compleet leeg scherm. Daarna kom ik wel weer op het hoodfdscherm. Buitengewoon vervelend en irritant. Wie heeft een oplossing ??
  16. Dat begrijp ik allemaal, maar waar sla ik het gedownloade 'bestand' op ??
  17. Kun je mij misschien in 'gewoon' Nederlands uitleggen wat ik nu moet doen ?? Bvd Jaap
  18. Ik heb sinds een week een nieuwe PC met daarop Windows 7. Alles loopt naar behoren, behalve mijn 'oude' scanner - CanoScan D660U - die wordt niet herkend. Is hier een simpele oplossing voor, of betekent dat kopen van een nieuwe scanner ??
  19. Vandaag nog even de wekelijkse AVG-scan afgewacht. En wat blijkt: deze geeft GEEN infecties meer aan !! Hartelijk dank voor alle moeite.
  20. En nu ?? Resultaten van AVG-scan vergeten en maar als opgelost markeren ??
  21. Gevonden: 11:32:49.0109 3108 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24 11:32:49.0515 3108 ============================================================ 11:32:49.0515 3108 Current date / time: 2012/09/20 11:32:49.0515 11:32:49.0515 3108 SystemInfo: 11:32:49.0515 3108 11:32:49.0515 3108 OS Version: 5.1.2600 ServicePack: 3.0 11:32:49.0515 3108 Product type: Workstation 11:32:49.0515 3108 ComputerName: J-5672B928EDC84 11:32:49.0515 3108 UserName: J. van 't Veen 11:32:49.0515 3108 Windows directory: C:\WINDOWS 11:32:49.0515 3108 System windows directory: C:\WINDOWS 11:32:49.0515 3108 Processor architecture: Intel x86 11:32:49.0515 3108 Number of processors: 1 11:32:49.0515 3108 Page size: 0x1000 11:32:49.0515 3108 Boot type: Normal boot 11:32:49.0515 3108 ============================================================ 11:32:50.0500 3108 Drive \Device\Harddisk0\DR0 - Size: 0x2658AE0000 (153.39 Gb), SectorSize: 0x200, Cylinders: 0x4E37, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 11:32:50.0515 3108 ============================================================ 11:32:50.0515 3108 \Device\Harddisk0\DR0: 11:32:50.0515 3108 MBR partitions: 11:32:50.0515 3108 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x132C0A77 11:32:50.0515 3108 ============================================================ 11:32:50.0531 3108 C: <-> \Device\Harddisk0\DR0\Partition1 11:32:50.0531 3108 ============================================================ 11:32:50.0531 3108 Initialize success 11:32:50.0531 3108 ============================================================ 11:32:55.0390 1780 ============================================================ 11:32:55.0390 1780 Scan started 11:32:55.0390 1780 Mode: Manual; 11:32:55.0390 1780 ============================================================ 11:32:56.0828 1780 ================ Scan system memory ======================== 11:32:56.0843 1780 System memory - ok 11:32:56.0843 1780 ================ Scan services ============================= 11:32:56.0953 1780 [ 0352A73CD6B1782EA3ED7A03A8268F55 ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys 11:32:56.0953 1780 Aavmker4 - ok 11:32:56.0968 1780 Abiosdsk - ok 11:32:56.0968 1780 abp480n5 - ok 11:32:57.0000 1780 [ 02273A448BA21A7D447DAEB47810D40C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 11:32:57.0000 1780 ACPI - ok 11:32:57.0062 1780 [ 63F517B1A87DABF3F5ACB8A7952FC1D1 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 11:32:57.0062 1780 ACPIEC - ok 11:32:57.0250 1780 [ E8FE4FCE23D2809BD88BCC1D0F8408CE ] AdobeActiveFileMonitor6.0 C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe 11:32:57.0250 1780 AdobeActiveFileMonitor6.0 - ok 11:32:57.0343 1780 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 11:32:57.0406 1780 AdobeFlashPlayerUpdateSvc - ok 11:32:57.0406 1780 adpu160m - ok 11:32:57.0453 1780 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 11:32:57.0453 1780 aec - ok 11:32:57.0484 1780 [ A7B8A3A79D35215D798A300DF49ED23F ] Afc C:\WINDOWS\system32\drivers\Afc.sys 11:32:57.0484 1780 Afc - ok 11:32:57.0515 1780 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 11:32:57.0515 1780 AFD - ok 11:32:57.0531 1780 Aha154x - ok 11:32:57.0531 1780 aic78u2 - ok 11:32:57.0546 1780 aic78xx - ok 11:32:57.0656 1780 [ 35045A23957A71BA649740741E69408C ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS 11:32:57.0687 1780 ALCXWDM - ok 11:32:57.0734 1780 [ 8BED67D13DCB55B3E9FF6DAC4C6D3B49 ] Alerter C:\WINDOWS\system32\alrsvc.dll 11:32:57.0734 1780 Alerter - ok 11:32:57.0750 1780 [ DAB2A89FDE5CF791161200D90C1BCB12 ] ALG C:\WINDOWS\System32\alg.exe 11:32:57.0781 1780 ALG - ok 11:32:57.0796 1780 AliIde - ok 11:32:57.0796 1780 amsint - ok 11:32:57.0812 1780 AppMgmt - ok 11:32:57.0812 1780 asc - ok 11:32:57.0828 1780 asc3350p - ok 11:32:57.0828 1780 asc3550 - ok 11:32:57.0953 1780 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 11:32:58.0031 1780 aspnet_state - ok 11:32:58.0062 1780 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys 11:32:58.0062 1780 aswFsBlk - ok 11:32:58.0093 1780 [ 2B9B1DF809E965EF63402CBBA6DB50AE ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys 11:32:58.0093 1780 aswMon2 - ok 11:32:58.0140 1780 [ B7D5E4486BA658ED08624D8084ABB830 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys 11:32:58.0140 1780 AswRdr - ok 11:32:58.0187 1780 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 11:32:58.0203 1780 aswSnx - ok 11:32:58.0234 1780 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 11:32:58.0234 1780 aswSP - ok 11:32:58.0250 1780 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys 11:32:58.0250 1780 aswTdi - ok 11:32:58.0281 1780 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 11:32:58.0281 1780 AsyncMac - ok 11:32:58.0296 1780 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 11:32:58.0296 1780 atapi - ok 11:32:58.0312 1780 Atdisk - ok 11:32:58.0343 1780 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 11:32:58.0359 1780 Atmarpc - ok 11:32:58.0390 1780 [ F10745ED3195360E69AA4A6E7768C0E0 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 11:32:58.0390 1780 AudioSrv - ok 11:32:58.0437 1780 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 11:32:58.0437 1780 audstub - ok 11:32:58.0531 1780 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 11:32:58.0531 1780 avast! Antivirus - ok 11:32:59.0375 1780 [ 1D7D0D5D33D8B1507EC5FBFE332E5657 ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe 11:33:00.0062 1780 AVGIDSAgent - ok 11:33:00.0140 1780 [ 9E42E8B6BB7FD68F840003A9FC8F24C8 ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys 11:33:00.0156 1780 AVGIDSDriver - ok 11:33:00.0187 1780 [ 2667A345903A2EA0C1D827F86853E417 ] AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys 11:33:00.0203 1780 AVGIDSHX - ok 11:33:00.0218 1780 [ 240F106B07CD9B522E2CD9E621618367 ] AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys 11:33:00.0218 1780 AVGIDSShim - ok 11:33:00.0234 1780 [ F0D3E3192F3B05E3A19C87DFDC320B50 ] Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 11:33:00.0250 1780 Avgldx86 - ok 11:33:00.0281 1780 [ 87E88A36279C8E5869270CC87F5BB7CD ] Avglogx C:\WINDOWS\system32\DRIVERS\avglogx.sys 11:33:00.0281 1780 Avglogx - ok 11:33:00.0312 1780 [ 3CDFD206BFE274A304D6373CD9E38F44 ] Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 11:33:00.0312 1780 Avgmfx86 - ok 11:33:00.0328 1780 [ B8392B63D795A3DE866793220D3559EF ] Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 11:33:00.0343 1780 Avgrkx86 - ok 11:33:00.0406 1780 [ B303F5E756C42DB96EA416FD0D2FF519 ] Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys 11:33:00.0421 1780 Avgtdix - ok 11:33:00.0453 1780 [ 3001E24F340D400BFF85935E5777FC5B ] avgtp C:\WINDOWS\system32\drivers\avgtpx86.sys 11:33:00.0453 1780 avgtp - ok 11:33:00.0515 1780 [ 42F11F37CC06D9AB6528AF2E215B8799 ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe 11:33:00.0515 1780 avgwd - ok 11:33:00.0562 1780 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 11:33:00.0562 1780 Beep - ok 11:33:00.0625 1780 [ 5C0073A51C4873430FA8B262E92183FF ] BITS C:\WINDOWS\system32\qmgr.dll 11:33:01.0312 1780 BITS - ok 11:33:01.0343 1780 [ 139102D1865D3C1F152A25ABD16242DB ] Browser C:\WINDOWS\System32\browser.dll 11:33:01.0343 1780 Browser - ok 11:33:01.0390 1780 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 11:33:01.0390 1780 cbidf2k - ok 11:33:01.0390 1780 cd20xrnt - ok 11:33:01.0421 1780 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 11:33:01.0421 1780 Cdaudio - ok 11:33:01.0468 1780 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 11:33:01.0515 1780 Cdfs - ok 11:33:01.0515 1780 [ 351735695E9EAD93DE6AF85D8BEB1CA8 ] cdrbsdrv C:\WINDOWS\system32\drivers\cdrbsdrv.sys 11:33:01.0515 1780 cdrbsdrv - ok 11:33:01.0531 1780 cdrbsvsd - ok 11:33:01.0578 1780 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 11:33:01.0578 1780 Cdrom - ok 11:33:01.0578 1780 Changer - ok 11:33:01.0609 1780 [ BD85400700B80FBE3D4A3412BCE74861 ] CiSvc C:\WINDOWS\system32\cisvc.exe 11:33:01.0640 1780 CiSvc - ok 11:33:01.0671 1780 [ 4FB6108130829666C8FE96B442FEAD94 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 11:33:01.0687 1780 ClipSrv - ok 11:33:01.0734 1780 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 11:33:01.0968 1780 clr_optimization_v2.0.50727_32 - ok 11:33:02.0015 1780 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 11:33:02.0031 1780 clr_optimization_v4.0.30319_32 - ok 11:33:02.0031 1780 CmdIde - ok 11:33:02.0046 1780 COMSysApp - ok 11:33:02.0062 1780 Cpqarray - ok 11:33:02.0109 1780 [ 0A9CF5D3CF63A8699F28C814EF821C7E ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 11:33:02.0109 1780 CryptSvc - ok 11:33:02.0125 1780 ctredr15.sys - ok 11:33:02.0125 1780 dac2w2k - ok 11:33:02.0140 1780 dac960nt - ok 11:33:02.0203 1780 [ D9883335CC1C17AFC3A09C8AC3E4DBE4 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 11:33:02.0234 1780 DcomLaunch - ok 11:33:02.0281 1780 [ 146AB038F5DBB366122D28444999AB2C ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 11:33:02.0281 1780 Dhcp - ok 11:33:02.0312 1780 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 11:33:02.0312 1780 Disk - ok 11:33:02.0328 1780 dmadmin - ok 11:33:02.0375 1780 [ DEC123E0C75971D0CC7A6C6A75E28429 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 11:33:02.0390 1780 dmboot - ok 11:33:02.0453 1780 [ 7268E66259722F6228C730685B201092 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 11:33:02.0453 1780 dmio - ok 11:33:02.0500 1780 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 11:33:02.0500 1780 dmload - ok 11:33:02.0531 1780 [ 127DB74184E2D3D31655DA525A5EFDE1 ] dmserver C:\WINDOWS\System32\dmserver.dll 11:33:02.0546 1780 dmserver - ok 11:33:02.0593 1780 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 11:33:02.0609 1780 DMusic - ok 11:33:02.0640 1780 [ DE6CDB6CBC5C27B9085CFA6DFE8E5025 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 11:33:02.0656 1780 Dnscache - ok 11:33:02.0703 1780 [ 90EE765E1A598B578852901F74F914F1 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 11:33:02.0734 1780 Dot3svc - ok 11:33:02.0750 1780 dpti2o - ok 11:33:02.0781 1780 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 11:33:02.0781 1780 drmkaud - ok 11:33:02.0796 1780 [ 6C5ABE3C6D8ADC67A988A0C3F68FAC24 ] DwProt C:\WINDOWS\system32\drivers\dwprot.sys 11:33:02.0812 1780 DwProt - ok 11:33:02.0843 1780 [ E6BBDEBF7081899D161C773E8D84D015 ] EapHost C:\WINDOWS\System32\eapsvc.dll 11:33:02.0859 1780 EapHost - ok 11:33:02.0890 1780 [ 2F5C7F650B7AF178988946EE4B0D9C01 ] ERSvc C:\WINDOWS\System32\ersvc.dll 11:33:02.0906 1780 ERSvc - ok 11:33:02.0937 1780 [ 657B69389B893F440B07590C9E963F23 ] Eventlog C:\WINDOWS\system32\services.exe 11:33:02.0953 1780 Eventlog - ok 11:33:03.0031 1780 [ 97912DC0679D2DA60CCE589BBC196D72 ] EventSystem C:\WINDOWS\system32\es.dll 11:33:03.0046 1780 EventSystem - ok 11:33:03.0093 1780 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 11:33:03.0093 1780 Fastfat - ok 11:33:03.0140 1780 [ 2D5D4156292150FE571872C1B88E9299 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 11:33:03.0171 1780 FastUserSwitchingCompatibility - ok 11:33:03.0203 1780 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 11:33:03.0218 1780 Fdc - ok 11:33:03.0250 1780 [ 8BFFFB5AC954E19DFDB96D56512AA518 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 11:33:03.0265 1780 Fips - ok 11:33:03.0343 1780 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 11:33:03.0796 1780 FLEXnet Licensing Service - ok 11:33:03.0828 1780 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 11:33:03.0828 1780 Flpydisk - ok 11:33:03.0875 1780 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 11:33:03.0875 1780 FltMgr - ok 11:33:03.0921 1780 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 11:33:03.0953 1780 FontCache3.0.0.0 - ok 11:33:03.0984 1780 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 11:33:03.0984 1780 Fs_Rec - ok 11:33:04.0000 1780 [ FA8CA22E70245C81FF29C36AF56292FC ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 11:33:04.0000 1780 Ftdisk - ok 11:33:04.0031 1780 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys 11:33:04.0031 1780 gameenum - ok 11:33:04.0062 1780 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 11:33:04.0062 1780 Gpc - ok 11:33:04.0125 1780 [ 408DDD80EEDE47175F6844817B90213E ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 11:33:04.0140 1780 gusvc - ok 11:33:04.0218 1780 [ 5327BAD9B35C33D2A64B64E4CF282ECD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 11:33:04.0218 1780 helpsvc - ok 11:33:04.0265 1780 [ 10003105AAB8D5A7DB51A9CB3D9F55A3 ] HidServ C:\WINDOWS\System32\hidserv.dll 11:33:04.0265 1780 HidServ - ok 11:33:04.0296 1780 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 11:33:04.0312 1780 HidUsb - ok 11:33:04.0375 1780 [ 54D9E71DD3F6DF476B99543F88650EDF ] HitmanProScheduler C:\Program Files\HitmanPro\hmpsched.exe 11:33:04.0375 1780 HitmanProScheduler - ok 11:33:04.0468 1780 [ 1FF903FFA2DA1704E5A5443D37D8E49E ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 11:33:04.0484 1780 hkmsvc - ok 11:33:04.0500 1780 hpn - ok 11:33:04.0546 1780 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 11:33:04.0562 1780 HTTP - ok 11:33:04.0578 1780 [ 2529C7BA05242BEED0027F554D0513BB ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 11:33:04.0828 1780 HTTPFilter - ok 11:33:04.0828 1780 i2omgmt - ok 11:33:04.0843 1780 i2omp - ok 11:33:04.0859 1780 [ C43372D0682F8E32E4EC21117E089EC0 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 11:33:04.0859 1780 i8042prt - ok 11:33:04.0921 1780 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe 11:33:05.0406 1780 IDriverT - ok 11:33:05.0484 1780 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 11:33:05.0515 1780 idsvc - ok 11:33:05.0546 1780 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 11:33:05.0546 1780 Imapi - ok 11:33:05.0625 1780 [ A117772F94C854DE5D1BBC1F1962B192 ] ImapiService C:\WINDOWS\system32\imapi.exe 11:33:05.0625 1780 ImapiService - ok 11:33:05.0640 1780 ini910u - ok 11:33:05.0640 1780 IntelIde - ok 11:33:05.0671 1780 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 11:33:05.0687 1780 Ip6Fw - ok 11:33:05.0703 1780 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 11:33:05.0703 1780 IpFilterDriver - ok 11:33:05.0734 1780 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 11:33:05.0734 1780 IpInIp - ok 11:33:05.0765 1780 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 11:33:05.0765 1780 IpNat - ok 11:33:05.0781 1780 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 11:33:05.0781 1780 IPSec - ok 11:33:05.0812 1780 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 11:33:05.0812 1780 IRENUM - ok 11:33:05.0843 1780 [ 0B78E1A31340E1FB1E389D5633F7C3A0 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 11:33:05.0859 1780 isapnp - ok 11:33:05.0859 1780 [ 380397621E94B32C744E7B2CC1330390 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 11:33:05.0875 1780 Kbdclass - ok 11:33:05.0906 1780 [ B833B70FE639F01FB36CEDABE57EF031 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 11:33:05.0906 1780 kbdhid - ok 11:33:05.0937 1780 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 11:33:05.0937 1780 kmixer - ok 11:33:05.0984 1780 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 11:33:05.0984 1780 KSecDD - ok 11:33:06.0031 1780 [ C7955E7EDAEA462D04F1C4BE1D340372 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 11:33:06.0046 1780 lanmanserver - ok 11:33:06.0078 1780 [ A936A575EAF6DCE8DC08BC0C53972ADD ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 11:33:06.0093 1780 lanmanworkstation - ok 11:33:06.0109 1780 lbrtfdc - ok 11:33:06.0156 1780 [ 91AE20C5C2776C511994AA1308C05283 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 11:33:06.0156 1780 LmHosts - ok 11:33:06.0218 1780 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 11:33:06.0218 1780 MDM - ok 11:33:06.0250 1780 [ C56A45A03DCA11712DE9FDF98224230B ] Messenger C:\WINDOWS\System32\msgsvc.dll 11:33:06.0500 1780 Messenger - ok 11:33:06.0531 1780 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 11:33:06.0531 1780 mnmdd - ok 11:33:06.0562 1780 [ 5B1D994DCF1895AFA27600E46A2F0FEA ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 11:33:06.0593 1780 mnmsrvc - ok 11:33:06.0640 1780 [ 8114EEAC353F549331AB73E9AF4219ED ] Modem C:\WINDOWS\system32\drivers\Modem.sys 11:33:06.0640 1780 Modem - ok 11:33:06.0671 1780 [ 1A4E2214DD63E4A876463D3427EE8261 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 11:33:06.0671 1780 Mouclass - ok 11:33:06.0718 1780 [ 18017899254E01371E1A39754D6BF98C ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 11:33:06.0718 1780 mouhid - ok 11:33:06.0734 1780 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 11:33:06.0734 1780 MountMgr - ok 11:33:06.0796 1780 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 11:33:07.0343 1780 MozillaMaintenance - ok 11:33:07.0359 1780 mraid35x - ok 11:33:07.0406 1780 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 11:33:07.0406 1780 MRxDAV - ok 11:33:07.0500 1780 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 11:33:07.0531 1780 MRxSmb - ok 11:33:07.0562 1780 [ 21EA21984D7D1AD50DB2E627020AB14C ] MSDTC C:\WINDOWS\system32\msdtc.exe 11:33:07.0765 1780 MSDTC - ok 11:33:07.0796 1780 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 11:33:07.0796 1780 Msfs - ok 11:33:07.0812 1780 MSIServer - ok 11:33:07.0843 1780 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 11:33:07.0843 1780 MSKSSRV - ok 11:33:07.0859 1780 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 11:33:07.0859 1780 MSPCLOCK - ok 11:33:07.0875 1780 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 11:33:07.0875 1780 MSPQM - ok 11:33:07.0921 1780 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 11:33:07.0921 1780 mssmbios - ok 11:33:07.0968 1780 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys 11:33:07.0968 1780 ms_mpu401 - ok 11:33:08.0000 1780 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys 11:33:08.0000 1780 MTsensor - ok 11:33:08.0031 1780 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 11:33:08.0031 1780 Mup - ok 11:33:08.0078 1780 [ 87E394C810794D3C70CF22E8316CB23E ] napagent C:\WINDOWS\System32\qagentrt.dll 11:33:08.0265 1780 napagent - ok 11:33:08.0328 1780 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 11:33:08.0328 1780 NDIS - ok 11:33:08.0375 1780 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 11:33:08.0375 1780 NdisTapi - ok 11:33:08.0406 1780 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 11:33:08.0421 1780 Ndisuio - ok 11:33:08.0453 1780 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 11:33:08.0468 1780 NdisWan - ok 11:33:08.0515 1780 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 11:33:08.0515 1780 NDProxy - ok 11:33:08.0546 1780 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 11:33:08.0562 1780 NetBIOS - ok 11:33:08.0609 1780 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 11:33:08.0625 1780 NetBT - ok 11:33:08.0671 1780 [ DC6BAE085E9B3C2F3A963ED46791FEAB ] NetDDE C:\WINDOWS\system32\netdde.exe 11:33:08.0843 1780 NetDDE - ok 11:33:08.0859 1780 [ DC6BAE085E9B3C2F3A963ED46791FEAB ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 11:33:08.0859 1780 NetDDEdsdm - ok 11:33:08.0890 1780 [ 8754210A3399D19610CE2D71E0C3E5D9 ] Netlogon C:\WINDOWS\system32\lsass.exe 11:33:08.0890 1780 Netlogon - ok 11:33:08.0937 1780 [ 5431FB616ECAE0D587C5B97D0B86CBD8 ] Netman C:\WINDOWS\System32\netman.dll 11:33:08.0953 1780 Netman - ok 11:33:08.0984 1780 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 11:33:08.0984 1780 NetTcpPortSharing - ok 11:33:09.0031 1780 [ 4522CBE00A9E9EEE36AA82ED4B319148 ] Nla C:\WINDOWS\System32\mswsock.dll 11:33:09.0046 1780 Nla - ok 11:33:09.0062 1780 [ A1B2D7F26D3E4B82C77E3DA51583DDB6 ] nlsX86cc C:\WINDOWS\system32\nlssrv32.exe 11:33:09.0078 1780 nlsX86cc - ok 11:33:09.0109 1780 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 11:33:09.0109 1780 Npfs - ok 11:33:09.0140 1780 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 11:33:09.0156 1780 Ntfs - ok 11:33:09.0171 1780 [ 8754210A3399D19610CE2D71E0C3E5D9 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 11:33:09.0171 1780 NtLmSsp - ok 11:33:09.0218 1780 [ AC1A78237B53044735693633F8235468 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 11:33:09.0437 1780 NtmsSvc - ok 11:33:09.0468 1780 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 11:33:09.0468 1780 Null - ok 11:33:09.0640 1780 [ BA1B732C1A70CFEA0C1B64F2850BF44F ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 11:33:09.0796 1780 nv - ok 11:33:09.0828 1780 [ DCE353985C988BFB7E84FD942068151F ] nvata C:\WINDOWS\system32\DRIVERS\nvata.sys 11:33:09.0843 1780 nvata - ok 11:33:09.0843 1780 [ 720CC533EECB65553BD86B139CA04433 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 11:33:09.0859 1780 NVENETFD - ok 11:33:09.0875 1780 [ 5F9F545CC5904DD8765F84EE1D056406 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 11:33:09.0875 1780 nvnetbus - ok 11:33:09.0921 1780 [ 0FEBE37DB6650FAA5965C00545009D1D ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 11:33:09.0953 1780 NVSvc - ok 11:33:09.0984 1780 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 11:33:09.0984 1780 NwlnkFlt - ok 11:33:10.0000 1780 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 11:33:10.0000 1780 NwlnkFwd - ok 11:33:10.0031 1780 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 11:33:10.0078 1780 ose - ok 11:33:10.0109 1780 [ E3934CCC20A4D24F1924E13D36D2A5BD ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 11:33:10.0125 1780 Parport - ok 11:33:10.0125 1780 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 11:33:10.0125 1780 PartMgr - ok 11:33:10.0171 1780 [ 1EADE28746A64C21E0A808BB12A63326 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 11:33:10.0171 1780 ParVdm - ok 11:33:10.0203 1780 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 11:33:10.0203 1780 pccsmcfd - ok 11:33:10.0234 1780 [ 3B166F9F753C21AEDAA9A6BD76B49655 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 11:33:10.0234 1780 PCI - ok 11:33:10.0234 1780 PCIDump - ok 11:33:10.0281 1780 [ B31EDEBA4DA28283F6B8DC4756FB9585 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 11:33:10.0281 1780 PCIIde - ok 11:33:10.0312 1780 [ 2137FFD65F8E609A3A5ACD487C56CCE0 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 11:33:10.0328 1780 Pcmcia - ok 11:33:10.0328 1780 PDCOMP - ok 11:33:10.0343 1780 PDFRAME - ok 11:33:10.0343 1780 PDRELI - ok 11:33:10.0359 1780 PDRFRAME - ok 11:33:10.0359 1780 perc2 - ok 11:33:10.0375 1780 perc2hib - ok 11:33:10.0421 1780 [ 657B69389B893F440B07590C9E963F23 ] PlugPlay C:\WINDOWS\system32\services.exe 11:33:10.0421 1780 PlugPlay - ok 11:33:10.0437 1780 [ 8754210A3399D19610CE2D71E0C3E5D9 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 11:33:10.0453 1780 PolicyAgent - ok 11:33:10.0484 1780 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 11:33:10.0484 1780 PptpMiniport - ok 11:33:10.0500 1780 [ 82A17ECA34D801590A67C0A2244965ED ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys 11:33:10.0515 1780 Processor - ok 11:33:10.0515 1780 [ 8754210A3399D19610CE2D71E0C3E5D9 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 11:33:10.0515 1780 ProtectedStorage - ok 11:33:10.0531 1780 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 11:33:10.0531 1780 PSched - ok 11:33:10.0562 1780 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 11:33:10.0562 1780 Ptilink - ok 11:33:10.0609 1780 [ 49452BFCEC22F36A7A9B9C2181BC3042 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 11:33:10.0640 1780 PxHelp20 - ok 11:33:10.0640 1780 ql1080 - ok 11:33:10.0656 1780 Ql10wnt - ok 11:33:10.0671 1780 ql12160 - ok 11:33:10.0671 1780 ql1240 - ok 11:33:10.0687 1780 ql1280 - ok 11:33:10.0718 1780 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 11:33:10.0718 1780 RasAcd - ok 11:33:10.0750 1780 [ 0575D034B1292CA3A9BB9F67A8EE289C ] RasAuto C:\WINDOWS\System32\rasauto.dll 11:33:11.0000 1780 RasAuto - ok 11:33:11.0046 1780 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 11:33:11.0046 1780 Rasl2tp - ok 11:33:11.0078 1780 [ 9E7E2DF6971A5F00102BE3F901CC3BDC ] RasMan C:\WINDOWS\System32\rasmans.dll 11:33:11.0093 1780 RasMan - ok 11:33:11.0109 1780 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 11:33:11.0109 1780 RasPppoe - ok 11:33:11.0109 1780 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 11:33:11.0125 1780 Raspti - ok 11:33:11.0140 1780 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 11:33:11.0140 1780 Rdbss - ok 11:33:11.0156 1780 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 11:33:11.0156 1780 RDPCDD - ok 11:33:11.0203 1780 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 11:33:11.0218 1780 RDPWD - ok 11:33:11.0281 1780 [ EA9FDF71D696B532BDC44C8BFF03A737 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 11:33:11.0718 1780 RDSessMgr - ok 11:33:11.0750 1780 [ 4173BC66E485FD77A03C4819F60BD0DA ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 11:33:11.0750 1780 redbook - ok 11:33:11.0781 1780 [ 4007ABF5D9BF0E55451D775443D1F985 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 11:33:11.0796 1780 RemoteAccess - ok 11:33:11.0843 1780 [ BE078F8F7EC2491EFDD79A53353A060F ] RpcLocator C:\WINDOWS\system32\locator.exe 11:33:11.0875 1780 RpcLocator - ok 11:33:11.0984 1780 [ D9883335CC1C17AFC3A09C8AC3E4DBE4 ] RpcSs C:\WINDOWS\system32\rpcss.dll 11:33:11.0984 1780 RpcSs - ok 11:33:12.0031 1780 [ AD1B5F1B99FFF08C99F443D784711A81 ] RSVP C:\WINDOWS\system32\rsvp.exe 11:33:12.0359 1780 RSVP - ok 11:33:12.0406 1780 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 11:33:12.0406 1780 rtl8139 - ok 11:33:12.0453 1780 [ 8754210A3399D19610CE2D71E0C3E5D9 ] SamSs C:\WINDOWS\system32\lsass.exe 11:33:12.0453 1780 SamSs - ok 11:33:12.0500 1780 [ 1B4CD62174E907C7EF8EC5D4D0A2A616 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 11:33:12.0734 1780 SCardSvr - ok 11:33:12.0765 1780 [ 7C288AE0F75CB18CFF1DF6179A67AD8F ] Schedule C:\WINDOWS\system32\schedsvc.dll 11:33:12.0781 1780 Schedule - ok 11:33:12.0812 1780 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 11:33:12.0812 1780 Secdrv - ok 11:33:12.0828 1780 [ 6983665BEA867125B1DA5757CD8B2F9D ] seclogon C:\WINDOWS\System32\seclogon.dll 11:33:12.0843 1780 seclogon - ok 11:33:12.0843 1780 [ F6EC8F1E50E40237BDDEE1CB7FE20B42 ] SENS C:\WINDOWS\system32\sens.dll 11:33:12.0859 1780 SENS - ok 11:33:12.0890 1780 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 11:33:12.0906 1780 serenum - ok 11:33:12.0921 1780 [ 92C21762653BB2CE51147EB8A9AA654F ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 11:33:12.0921 1780 Serial - ok 11:33:13.0000 1780 [ 7D3903AF48E6C1DC2704EAFCB608D031 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 11:33:13.0015 1780 ServiceLayer - ok 11:33:13.0046 1780 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 11:33:13.0046 1780 Sfloppy - ok 11:33:13.0109 1780 [ 7579C4BE909D47F10F3D8D801CB13ED9 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 11:33:13.0109 1780 SharedAccess - ok 11:33:13.0140 1780 [ 2D5D4156292150FE571872C1B88E9299 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 11:33:13.0140 1780 ShellHWDetection - ok 11:33:13.0156 1780 Simbad - ok 11:33:13.0203 1780 [ A1ECEEAA5C5E74B2499EB51D38185B84 ] SONYPVU1 C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 11:33:13.0312 1780 SONYPVU1 - ok 11:33:13.0312 1780 Sparrow - ok 11:33:13.0343 1780 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 11:33:13.0343 1780 splitter - ok 11:33:13.0390 1780 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 11:33:13.0390 1780 Spooler - ok 11:33:13.0421 1780 [ 64D2A7640E0767ECD3BCB38D3200E7CE ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 11:33:13.0421 1780 sr - ok 11:33:13.0468 1780 [ 81CBF363C414620CAA61BD6843D8FDB9 ] srservice C:\WINDOWS\system32\srsvc.dll 11:33:13.0484 1780 srservice - ok 11:33:13.0515 1780 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 11:33:13.0531 1780 Srv - ok 11:33:13.0578 1780 [ 5B9D0DE64BE96A806819516440FD211C ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 11:33:13.0578 1780 SSDPSRV - ok 11:33:13.0625 1780 [ E4C3B3A14FB2ABF5CE1FF05418BA73C1 ] SSFS0509 C:\WINDOWS\system32\Drivers\SSFS0509.SYS 11:33:13.0640 1780 SSFS0509 - ok 11:33:13.0640 1780 [ 251141FD898C0EF76976F51D39EA881D ] SSHRMD C:\WINDOWS\system32\Drivers\SSHRMD.SYS 11:33:13.0640 1780 SSHRMD - ok 11:33:13.0656 1780 [ 339E268E1F0DF8868045977CCCA6391F ] SSIDRV C:\WINDOWS\system32\Drivers\SSIDRV.SYS 11:33:13.0671 1780 SSIDRV - ok 11:33:13.0687 1780 [ CA85B64BC98ABABDD858143933B6FD4E ] SSKBFD C:\WINDOWS\system32\Drivers\sskbfd.sys 11:33:13.0687 1780 SSKBFD - ok 11:33:13.0734 1780 [ 5AE996186D2DC694FEF88F14A3FC9242 ] stisvc C:\WINDOWS\system32\wiaservc.dll 11:33:13.0750 1780 stisvc - ok 11:33:13.0796 1780 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 11:33:13.0796 1780 swenum - ok 11:33:13.0812 1780 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 11:33:13.0812 1780 swmidi - ok 11:33:13.0828 1780 SwPrv - ok 11:33:13.0828 1780 symc810 - ok 11:33:13.0843 1780 symc8xx - ok 11:33:13.0859 1780 sym_hi - ok 11:33:13.0859 1780 sym_u3 - ok 11:33:13.0875 1780 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 11:33:13.0875 1780 sysaudio - ok 11:33:13.0906 1780 [ 251EAE7C56C6AB9490311A3C9757E18D ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 11:33:14.0031 1780 SysmonLog - ok 11:33:14.0078 1780 [ 2BC9FB448F0C2394FF53C83A7BB04731 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 11:33:14.0093 1780 TapiSrv - ok 11:33:14.0109 1780 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 11:33:14.0125 1780 Tcpip - ok 11:33:14.0156 1780 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 11:33:14.0156 1780 TDPIPE - ok 11:33:14.0187 1780 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 11:33:14.0203 1780 TDTCP - ok 11:33:14.0218 1780 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 11:33:14.0234 1780 TermDD - ok 11:33:14.0281 1780 [ E0AEF86A594C9990D6321C5CA239C5B7 ] TermService C:\WINDOWS\System32\termsrv.dll 11:33:14.0296 1780 TermService - ok 11:33:14.0312 1780 [ 2D5D4156292150FE571872C1B88E9299 ] Themes C:\WINDOWS\System32\shsvcs.dll 11:33:14.0328 1780 Themes - ok 11:33:14.0343 1780 TosIde - ok 11:33:14.0375 1780 [ 20655E8CA1C78BC7088B18E93806D21B ] TrkWks C:\WINDOWS\system32\trkwks.dll 11:33:14.0390 1780 TrkWks - ok 11:33:14.0421 1780 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 11:33:14.0421 1780 Udfs - ok 11:33:14.0437 1780 ultra - ok 11:33:14.0484 1780 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 11:33:14.0500 1780 Update - ok 11:33:14.0546 1780 [ 01653D6C9604F1FB31A76EC94E08954F ] upnphost C:\WINDOWS\System32\upnphost.dll 11:33:14.0656 1780 upnphost - ok 11:33:14.0671 1780 [ A89796DD0DE24CF03B3A39407E1F46A3 ] UPS C:\WINDOWS\System32\ups.exe 11:33:14.0859 1780 UPS - ok 11:33:14.0937 1780 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 11:33:14.0937 1780 usbccgp - ok 11:33:14.0984 1780 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 11:33:15.0000 1780 usbehci - ok 11:33:15.0046 1780 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 11:33:15.0046 1780 usbhub - ok 11:33:15.0062 1780 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys 11:33:15.0062 1780 usbohci - ok 11:33:15.0078 1780 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 11:33:15.0078 1780 usbprint - ok 11:33:15.0093 1780 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 11:33:15.0093 1780 usbscan - ok 11:33:15.0109 1780 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 11:33:15.0109 1780 USBSTOR - ok 11:33:15.0109 1780 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 11:33:15.0125 1780 VgaSave - ok 11:33:15.0125 1780 ViaIde - ok 11:33:15.0140 1780 [ 8AB662B3C4691E6DDF61C96BB5B7D103 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 11:33:15.0156 1780 VolSnap - ok 11:33:15.0187 1780 [ A585EDD6965B301DE8A45C6768C7C215 ] VSS C:\WINDOWS\System32\vssvc.exe 11:33:15.0406 1780 VSS - ok 11:33:15.0500 1780 [ 40DBA03782BCC10685A8C200C5EBDCD0 ] vToolbarUpdater12.2.6 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe 11:33:15.0515 1780 vToolbarUpdater12.2.6 - ok 11:33:15.0546 1780 [ 390D8E65F362327AD510B08971478301 ] W32Time C:\WINDOWS\system32\w32time.dll 11:33:15.0562 1780 W32Time - ok 11:33:15.0625 1780 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 11:33:15.0703 1780 Wanarp - ok 11:33:15.0703 1780 WDICA - ok 11:33:15.0734 1780 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 11:33:15.0875 1780 wdmaud - ok 11:33:15.0890 1780 [ 33D8E2812054D97A0AEC9B8F04277927 ] WebClient C:\WINDOWS\System32\webclnt.dll 11:33:16.0015 1780 WebClient - ok 11:33:16.0234 1780 [ 5DF61C66BFE46350DDDF931B3B1DFEB2 ] WebrootSpySweeperService C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe 11:33:16.0734 1780 WebrootSpySweeperService - ok 11:33:16.0828 1780 [ F45DD1E1365D857DD08BC23563370D0E ] WinDefend C:\Program Files\Windows Defender\MsMpEng.exe 11:33:16.0828 1780 WinDefend - ok 11:33:17.0078 1780 [ F9E105F369C18E4001E0C05AAF600D73 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 11:33:17.0109 1780 winmgmt - ok 11:33:17.0375 1780 [ 250F8D15406269CB3A690B4A4859D92D ] WinRM C:\WINDOWS\system32\WsmSvc.dll 11:33:19.0015 1780 WinRM - ok 11:33:19.0062 1780 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 11:33:19.0265 1780 WmdmPmSN - ok 11:33:19.0328 1780 [ 87F11D161207C7063EDABAC0AADC33C3 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 11:33:19.0406 1780 WmiApSrv - ok 11:33:19.0484 1780 [ 79A01ACD485687EE602411A06B63A9A5 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 11:33:19.0703 1780 WMPNetworkSvc - ok 11:33:19.0781 1780 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 11:33:19.0875 1780 WPFFontCache_v0400 - ok 11:33:19.0906 1780 [ 843F7FA8EA38E6A4262976DCC994C81A ] wscsvc C:\WINDOWS\system32\wscsvc.dll 11:33:19.0968 1780 wscsvc - ok 11:33:19.0984 1780 WSearch - ok 11:33:20.0015 1780 [ 1E8FDDDEF3FE260BADAB06DAE10D753A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 11:33:20.0125 1780 wuauserv - ok 11:33:20.0156 1780 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 11:33:20.0187 1780 WudfPf - ok 11:33:20.0234 1780 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 11:33:20.0281 1780 WudfRd - ok 11:33:20.0312 1780 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 11:33:20.0875 1780 WudfSvc - ok 11:33:20.0937 1780 [ E99782DBB8FFA2AEE72B31DAC8D8D887 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 11:33:21.0046 1780 WZCSVC - ok 11:33:21.0062 1780 [ FD3C38635808920F8235BF2FED642F54 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 11:33:21.0359 1780 xmlprov - ok 11:33:21.0375 1780 ================ Scan global =============================== 11:33:21.0406 1780 [ 953AD498333B03F7CE547151F96EF241 ] C:\WINDOWS\system32\basesrv.dll 11:33:21.0500 1780 [ C7CC71181F7FD61C49EFF278003827A5 ] C:\WINDOWS\system32\winsrv.dll 11:33:21.0656 1780 [ C7CC71181F7FD61C49EFF278003827A5 ] C:\WINDOWS\system32\winsrv.dll 11:33:21.0843 1780 [ 657B69389B893F440B07590C9E963F23 ] C:\WINDOWS\system32\services.exe 11:33:22.0031 1780 [Global] - ok 11:33:22.0031 1780 ================ Scan MBR ================================== 11:33:22.0062 1780 [ 3051207086651214E435112E51817DC5 ] \Device\Harddisk0\DR0 11:33:22.0171 1780 \Device\Harddisk0\DR0 - ok 11:33:22.0187 1780 ================ Scan VBR ================================== 11:33:22.0187 1780 [ A689BB2B7A84A25121BE20D24F5D2C00 ] \Device\Harddisk0\DR0\Partition1 11:33:22.0187 1780 \Device\Harddisk0\DR0\Partition1 - ok 11:33:22.0203 1780 ============================================================ 11:33:22.0203 1780 Scan finished 11:33:22.0203 1780 ============================================================ 11:33:22.0218 1292 Detected object count: 0 11:33:22.0218 1292 Actual detected object count: 0 11:41:42.0593 3692 Deinitialize success
  22. Scan uitgevoerd en ook Report geopend. Kan dat rapport niet kopieren ?? ps: wat me opvalt is dat TDSSKiller 'maar' 314 objecten scant.
  23. Vanmorgen - reguliere AVG scan - 6 rootkits gedetecteerd. Daarvan was er één hetzelfde als een paar dagen geleden en waren er vijf nieuwe. Probleem onoplosbaar ??
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.