Ga naar inhoud

Michiels123

Lid
  • Items

    22
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door Michiels123

  1. 16:24:22.0921 1228 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48

    16:24:23.0000 1228 ============================================================

    16:24:23.0000 1228 Current date / time: 2012/08/30 16:24:23.0000

    16:24:23.0000 1228 SystemInfo:

    16:24:23.0000 1228

    16:24:23.0000 1228 OS Version: 5.1.2600 ServicePack: 3.0

    16:24:23.0000 1228 Product type: Workstation

    16:24:23.0000 1228 ComputerName: USER-84E810BCC9

    16:24:23.0000 1228 UserName: Gebruiker

    16:24:23.0000 1228 Windows directory: C:\WINDOWS

    16:24:23.0000 1228 System windows directory: C:\WINDOWS

    16:24:23.0000 1228 Processor architecture: Intel x86

    16:24:23.0000 1228 Number of processors: 4

    16:24:23.0000 1228 Page size: 0x1000

    16:24:23.0000 1228 Boot type: Normal boot

    16:24:23.0000 1228 ============================================================

    16:24:24.0656 1228 Drive \Device\Harddisk0\DR0 - Size: 0x9962B8000 (38.35 Gb), SectorSize: 0x200, Cylinders: 0x138D, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054

    16:24:24.0671 1228 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058

    16:24:24.0671 1228 ============================================================

    16:24:24.0671 1228 \Device\Harddisk0\DR0:

    16:24:24.0671 1228 MBR partitions:

    16:24:24.0671 1228 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4CAA44D

    16:24:24.0671 1228 \Device\Harddisk1\DR1:

    16:24:24.0687 1228 MBR partitions:

    16:24:24.0687 1228 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1

    16:24:24.0687 1228 ============================================================

    16:24:24.0718 1228 C: <-> \Device\Harddisk1\DR1\Partition1

    16:24:24.0750 1228 E: <-> \Device\Harddisk0\DR0\Partition1

    16:24:24.0750 1228 ============================================================

    16:24:24.0750 1228 Initialize success

    16:24:24.0750 1228 ============================================================

    16:25:10.0968 2396 ============================================================

    16:25:10.0968 2396 Scan started

    16:25:10.0968 2396 Mode: Manual;

    16:25:10.0968 2396 ============================================================

    16:25:13.0000 2396 ================ Scan system memory ========================

    16:25:13.0000 2396 System memory - ok

    16:25:13.0000 2396 ================ Scan services =============================

    16:25:13.0062 2396 Abiosdsk - ok

    16:25:13.0062 2396 abp480n5 - ok

    16:25:13.0125 2396 [ 02273A448BA21A7D447DAEB47810D40C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys

    16:25:13.0125 2396 ACPI - ok

    16:25:13.0156 2396 [ 63F517B1A87DABF3F5ACB8A7952FC1D1 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys

    16:25:13.0171 2396 ACPIEC - ok

    16:25:13.0203 2396 [ 5F92E1E98EC2F4E6FE13D19AA3E24AD7 ] ACSSCR C:\WINDOWS\system32\DRIVERS\a38usb.sys

    16:25:13.0250 2396 ACSSCR - ok

    16:25:13.0265 2396 adpu160m - ok

    16:25:13.0281 2396 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys

    16:25:13.0312 2396 aec - ok

    16:25:13.0343 2396 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys

    16:25:13.0562 2396 AFD - ok

    16:25:13.0562 2396 Aha154x - ok

    16:25:13.0562 2396 aic78u2 - ok

    16:25:13.0578 2396 aic78xx - ok

    16:25:13.0625 2396 [ 8BED67D13DCB55B3E9FF6DAC4C6D3B49 ] Alerter C:\WINDOWS\system32\alrsvc.dll

    16:25:13.0640 2396 Alerter - ok

    16:25:13.0656 2396 [ DAB2A89FDE5CF791161200D90C1BCB12 ] ALG C:\WINDOWS\System32\alg.exe

    16:25:13.0656 2396 ALG - ok

    16:25:13.0671 2396 AliIde - ok

    16:25:13.0718 2396 [ F6AF59D6EEE5E1C304F7F73706AD11D8 ] Ambfilt C:\WINDOWS\system32\drivers\Ambfilt.sys

    16:25:13.0796 2396 Ambfilt - ok

    16:25:13.0796 2396 AmdPPM - ok

    16:25:13.0796 2396 amsint - ok

    16:25:13.0812 2396 AppMgmt - ok

    16:25:13.0828 2396 asc - ok

    16:25:13.0843 2396 asc3350p - ok

    16:25:13.0859 2396 asc3550 - ok

    16:25:14.0000 2396 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

    16:25:14.0031 2396 aspnet_state - ok

    16:25:14.0046 2396 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys

    16:25:14.0046 2396 AsyncMac - ok

    16:25:14.0093 2396 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys

    16:25:14.0093 2396 atapi - ok

    16:25:14.0093 2396 Atdisk - ok

    16:25:14.0125 2396 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys

    16:25:14.0125 2396 Atmarpc - ok

    16:25:14.0156 2396 [ F10745ED3195360E69AA4A6E7768C0E0 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll

    16:25:14.0171 2396 AudioSrv - ok

    16:25:14.0203 2396 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys

    16:25:14.0218 2396 audstub - ok

    16:25:14.0390 2396 [ D67719BCFDE5798F5C30D14EFED3BCAF ] AVGIDSAgent C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    16:25:14.0531 2396 AVGIDSAgent - ok

    16:25:14.0578 2396 [ 1074F787080068C71303B61FAE7E7CA4 ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys

    16:25:14.0609 2396 AVGIDSDriver - ok

    16:25:14.0625 2396 [ 61A7E0B02F82CFF3DB2445BBE50B3589 ] AVGIDSFilter C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys

    16:25:14.0640 2396 AVGIDSFilter - ok

    16:25:14.0687 2396 [ D63D83659EEDF60B3A3E620281A888E5 ] AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys

    16:25:14.0687 2396 AVGIDSHX - ok

    16:25:14.0718 2396 [ BAF975B72062F53D327788E99D64197E ] AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys

    16:25:14.0718 2396 AVGIDSShim - ok

    16:25:14.0750 2396 [ DDA6A2A18841E4C9172BB85958B8D948 ] Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys

    16:25:14.0750 2396 Avgldx86 - ok

    16:25:14.0750 2396 [ CCDD61545AAEA265977E4B1EFDC74E8C ] Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys

    16:25:14.0750 2396 Avgmfx86 - ok

    16:25:14.0781 2396 [ 1FD90B28D2C3100BF4500199C8AD6358 ] Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys

    16:25:14.0781 2396 Avgrkx86 - ok

    16:25:14.0812 2396 [ 1263F2554ACE925C237A40B4C568D815 ] Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys

    16:25:14.0812 2396 Avgtdix - ok

    16:25:14.0843 2396 [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    16:25:14.0843 2396 avgwd - ok

    16:25:14.0875 2396 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys

    16:25:14.0890 2396 Beep - ok

    16:25:14.0906 2396 [ 5C0073A51C4873430FA8B262E92183FF ] BITS C:\WINDOWS\system32\qmgr.dll

    16:25:14.0984 2396 BITS - ok

    16:25:15.0015 2396 [ 139102D1865D3C1F152A25ABD16242DB ] Browser C:\WINDOWS\System32\browser.dll

    16:25:15.0062 2396 Browser - ok

    16:25:15.0109 2396 [ B279426E3C0C344893ED78A613A73BDE ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys

    16:25:15.0140 2396 BthEnum - ok

    16:25:15.0156 2396 [ FCA6F069597B62D42495191ACE3FC6C1 ] BTHMODEM C:\WINDOWS\system32\DRIVERS\bthmodem.sys

    16:25:15.0156 2396 BTHMODEM - ok

    16:25:15.0203 2396 [ 80602B8746D3738F5886CE3D67EF06B6 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys

    16:25:15.0218 2396 BthPan - ok

    16:25:15.0234 2396 [ 29FF6A865782D0F5B8E7FA1FFAB4182B ] BTHPORT C:\WINDOWS\system32\Drivers\BTHport.sys

    16:25:15.0265 2396 BTHPORT - ok

    16:25:15.0296 2396 [ 530494EF38B7EEA798FAC9B87ECD5284 ] BthServ C:\WINDOWS\System32\bthserv.dll

    16:25:15.0312 2396 BthServ - ok

    16:25:15.0343 2396 [ 61364CD71EF63B0F038B7E9DF00F1EFA ] BTHUSB C:\WINDOWS\system32\Drivers\BTHUSB.sys

    16:25:15.0343 2396 BTHUSB - ok

    16:25:15.0375 2396 catchme - ok

    16:25:15.0406 2396 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys

    16:25:15.0421 2396 cbidf2k - ok

    16:25:15.0453 2396 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

    16:25:15.0468 2396 CCDECODE - ok

    16:25:15.0468 2396 cd20xrnt - ok

    16:25:15.0500 2396 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys

    16:25:15.0515 2396 Cdaudio - ok

    16:25:15.0531 2396 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys

    16:25:15.0531 2396 Cdfs - ok

    16:25:15.0562 2396 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys

    16:25:15.0562 2396 Cdrom - ok

    16:25:15.0593 2396 Changer - ok

    16:25:15.0609 2396 [ BD85400700B80FBE3D4A3412BCE74861 ] CiSvc C:\WINDOWS\system32\cisvc.exe

    16:25:15.0640 2396 CiSvc - ok

    16:25:15.0640 2396 [ 4FB6108130829666C8FE96B442FEAD94 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe

    16:25:15.0656 2396 ClipSrv - ok

    16:25:15.0671 2396 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

    16:25:15.0765 2396 clr_optimization_v2.0.50727_32 - ok

    16:25:15.0765 2396 CmdIde - ok

    16:25:15.0781 2396 COMSysApp - ok

    16:25:15.0796 2396 Cpqarray - ok

    16:25:15.0828 2396 [ 0A9CF5D3CF63A8699F28C814EF821C7E ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll

    16:25:15.0843 2396 CryptSvc - ok

    16:25:15.0843 2396 dac2w2k - ok

    16:25:15.0843 2396 dac960nt - ok

    16:25:15.0906 2396 [ D9883335CC1C17AFC3A09C8AC3E4DBE4 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll

    16:25:15.0906 2396 DcomLaunch - ok

    16:25:15.0937 2396 [ 146AB038F5DBB366122D28444999AB2C ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll

    16:25:15.0968 2396 Dhcp - ok

    16:25:15.0984 2396 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys

    16:25:15.0984 2396 Disk - ok

    16:25:15.0984 2396 dmadmin - ok

    16:25:16.0046 2396 [ DEC123E0C75971D0CC7A6C6A75E28429 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys

    16:25:16.0078 2396 dmboot - ok

    16:25:16.0109 2396 [ 7268E66259722F6228C730685B201092 ] dmio C:\WINDOWS\system32\drivers\dmio.sys

    16:25:16.0125 2396 dmio - ok

    16:25:16.0156 2396 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys

    16:25:16.0156 2396 dmload - ok

    16:25:16.0156 2396 [ 127DB74184E2D3D31655DA525A5EFDE1 ] dmserver C:\WINDOWS\System32\dmserver.dll

    16:25:16.0171 2396 dmserver - ok

    16:25:16.0203 2396 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys

    16:25:16.0218 2396 DMusic - ok

    16:25:16.0250 2396 [ DE6CDB6CBC5C27B9085CFA6DFE8E5025 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll

    16:25:16.0265 2396 Dnscache - ok

    16:25:16.0281 2396 [ 90EE765E1A598B578852901F74F914F1 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll

    16:25:16.0296 2396 Dot3svc - ok

    16:25:16.0296 2396 dpti2o - ok

    16:25:16.0328 2396 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys

    16:25:16.0343 2396 drmkaud - ok

    16:25:16.0359 2396 [ E6BBDEBF7081899D161C773E8D84D015 ] EapHost C:\WINDOWS\System32\eapsvc.dll

    16:25:16.0375 2396 EapHost - ok

    16:25:16.0390 2396 [ 2F5C7F650B7AF178988946EE4B0D9C01 ] ERSvc C:\WINDOWS\System32\ersvc.dll

    16:25:16.0406 2396 ERSvc - ok

    16:25:16.0437 2396 [ 657B69389B893F440B07590C9E963F23 ] Eventlog C:\WINDOWS\system32\services.exe

    16:25:16.0453 2396 Eventlog - ok

    16:25:16.0484 2396 [ 97912DC0679D2DA60CCE589BBC196D72 ] EventSystem C:\WINDOWS\system32\es.dll

    16:25:16.0562 2396 EventSystem - ok

    16:25:16.0593 2396 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys

    16:25:16.0609 2396 Fastfat - ok

    16:25:16.0640 2396 [ 2D5D4156292150FE571872C1B88E9299 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll

    16:25:16.0718 2396 FastUserSwitchingCompatibility - ok

    16:25:16.0734 2396 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys

    16:25:16.0796 2396 Fdc - ok

    16:25:16.0828 2396 [ A75DDC492D2D1D6558AD8003A4ADB73A ] FilterService C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys

    16:25:16.0828 2396 FilterService - ok

    16:25:16.0843 2396 [ 8BFFFB5AC954E19DFDB96D56512AA518 ] Fips C:\WINDOWS\system32\drivers\Fips.sys

    16:25:16.0843 2396 Fips - ok

    16:25:16.0859 2396 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys

    16:25:16.0875 2396 Flpydisk - ok

    16:25:16.0906 2396 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys

    16:25:16.0906 2396 FltMgr - ok

    16:25:16.0968 2396 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

    16:25:16.0968 2396 FontCache3.0.0.0 - ok

    16:25:17.0000 2396 [ 790A4CA68F44BE35967B3DF61F3E4675 ] FsUsbExDisk C:\WINDOWS\system32\FsUsbExDisk.SYS

    16:25:17.0203 2396 FsUsbExDisk - ok

    16:25:17.0218 2396 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys

    16:25:17.0218 2396 Fs_Rec - ok

    16:25:17.0250 2396 [ FA8CA22E70245C81FF29C36AF56292FC ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys

    16:25:17.0250 2396 Ftdisk - ok

    16:25:17.0296 2396 [ 72FE2BEA6863D4EB93442A1C4FB5CA48 ] GcKernel C:\WINDOWS\system32\DRIVERS\GcKernel.sys

    16:25:17.0312 2396 GcKernel - ok

    16:25:17.0343 2396 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys

    16:25:17.0343 2396 Gpc - ok

    16:25:17.0453 2396 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe

    16:25:17.0453 2396 gupdate - ok

    16:25:17.0453 2396 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe

    16:25:17.0453 2396 gupdatem - ok

    16:25:17.0500 2396 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    16:25:17.0531 2396 gusvc - ok

    16:25:17.0578 2396 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\WINDOWS\system32\DRIVERS\hamachi.sys

    16:25:17.0609 2396 hamachi - ok

    16:25:17.0640 2396 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

    16:25:17.0640 2396 HDAudBus - ok

    16:25:17.0703 2396 [ 5327BAD9B35C33D2A64B64E4CF282ECD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll

    16:25:17.0734 2396 helpsvc - ok

    16:25:17.0750 2396 [ 10003105AAB8D5A7DB51A9CB3D9F55A3 ] HidServ C:\WINDOWS\System32\hidserv.dll

    16:25:17.0750 2396 HidServ - ok

    16:25:17.0765 2396 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys

    16:25:17.0781 2396 hidusb - ok

    16:25:17.0796 2396 [ 1FF903FFA2DA1704E5A5443D37D8E49E ] hkmsvc C:\WINDOWS\System32\kmsvc.dll

    16:25:17.0812 2396 hkmsvc - ok

    16:25:17.0812 2396 hpn - ok

    16:25:17.0843 2396 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys

    16:25:17.0843 2396 HTTP - ok

    16:25:17.0875 2396 [ 2529C7BA05242BEED0027F554D0513BB ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll

    16:25:17.0890 2396 HTTPFilter - ok

    16:25:17.0890 2396 i2omgmt - ok

    16:25:17.0906 2396 i2omp - ok

    16:25:17.0921 2396 [ C43372D0682F8E32E4EC21117E089EC0 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys

    16:25:17.0937 2396 i8042prt - ok

    16:25:18.0078 2396 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

    16:25:18.0140 2396 idsvc - ok

    16:25:18.0218 2396 [ 78DF31CDD3A380E7F9CFCC8B4E24813C ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    16:25:18.0218 2396 IJPLMSVC - ok

    16:25:18.0250 2396 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys

    16:25:18.0265 2396 Imapi - ok

    16:25:18.0281 2396 [ A117772F94C854DE5D1BBC1F1962B192 ] ImapiService C:\WINDOWS\system32\imapi.exe

    16:25:18.0281 2396 ImapiService - ok

    16:25:18.0296 2396 ini910u - ok

    16:25:18.0421 2396 [ 0CACDCBBC8E6F11E2865C47BFC509848 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys

    16:25:18.0500 2396 IntcAzAudAddService - ok

    16:25:18.0500 2396 IntelIde - ok

    16:25:18.0531 2396 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

    16:25:18.0546 2396 Ip6Fw - ok

    16:25:18.0578 2396 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

    16:25:18.0578 2396 IpFilterDriver - ok

    16:25:18.0593 2396 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys

    16:25:18.0625 2396 IpInIp - ok

    16:25:18.0640 2396 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys

    16:25:18.0640 2396 IpNat - ok

    16:25:18.0671 2396 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys

    16:25:18.0687 2396 IPSec - ok

    16:25:18.0703 2396 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys

    16:25:18.0734 2396 IRENUM - ok

    16:25:18.0750 2396 [ 0B78E1A31340E1FB1E389D5633F7C3A0 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys

    16:25:18.0750 2396 isapnp - ok

    16:25:18.0921 2396 [ 0A5709543986843D37A92290B7838340 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe

    16:25:18.0968 2396 JavaQuickStarterService - ok

    16:25:19.0000 2396 [ 380397621E94B32C744E7B2CC1330390 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys

    16:25:19.0015 2396 Kbdclass - ok

    16:25:19.0015 2396 [ B833B70FE639F01FB36CEDABE57EF031 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys

    16:25:19.0031 2396 kbdhid - ok

    16:25:19.0062 2396 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys

    16:25:19.0062 2396 kmixer - ok

    16:25:19.0109 2396 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys

    16:25:19.0125 2396 KSecDD - ok

    16:25:19.0140 2396 [ C7955E7EDAEA462D04F1C4BE1D340372 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll

    16:25:19.0171 2396 LanmanServer - ok

    16:25:19.0218 2396 [ A936A575EAF6DCE8DC08BC0C53972ADD ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll

    16:25:19.0218 2396 lanmanworkstation - ok

    16:25:19.0218 2396 lbrtfdc - ok

    16:25:19.0265 2396 [ 91AE20C5C2776C511994AA1308C05283 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll

    16:25:19.0312 2396 LmHosts - ok

    16:25:19.0390 2396 [ 6C42815DD57E397F0CD988304B5EB4B3 ] LVUVC C:\WINDOWS\system32\DRIVERS\lvuvc.sys

    16:25:19.0468 2396 LVUVC - ok

    16:25:19.0500 2396 [ C56A45A03DCA11712DE9FDF98224230B ] Messenger C:\WINDOWS\System32\msgsvc.dll

    16:25:19.0515 2396 Messenger - ok

    16:25:19.0531 2396 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys

    16:25:19.0531 2396 mnmdd - ok

    16:25:19.0562 2396 [ 5B1D994DCF1895AFA27600E46A2F0FEA ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe

    16:25:19.0578 2396 mnmsrvc - ok

    16:25:19.0593 2396 [ 8114EEAC353F549331AB73E9AF4219ED ] Modem C:\WINDOWS\system32\drivers\Modem.sys

    16:25:19.0609 2396 Modem - ok

    16:25:19.0656 2396 [ 9FA7207D1B1ADEAD88AE8EED9CDBBAA5 ] Monfilt C:\WINDOWS\system32\drivers\Monfilt.sys

    16:25:19.0734 2396 Monfilt - ok

    16:25:19.0750 2396 [ 1A4E2214DD63E4A876463D3427EE8261 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys

    16:25:19.0765 2396 Mouclass - ok

    16:25:19.0781 2396 [ 18017899254E01371E1A39754D6BF98C ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys

    16:25:19.0781 2396 mouhid - ok

    16:25:19.0812 2396 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys

    16:25:19.0812 2396 MountMgr - ok

    16:25:19.0843 2396 [ C0F8E0C2C3C0437CF37C6781896DC3EC ] MPE C:\WINDOWS\system32\DRIVERS\MPE.sys

    16:25:19.0859 2396 MPE - ok

    16:25:19.0859 2396 mraid35x - ok

    16:25:19.0890 2396 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys

    16:25:19.0890 2396 MRxDAV - ok

    16:25:19.0921 2396 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

    16:25:19.0921 2396 MRxSmb - ok

    16:25:19.0937 2396 [ 21EA21984D7D1AD50DB2E627020AB14C ] MSDTC C:\WINDOWS\system32\msdtc.exe

    16:25:19.0953 2396 MSDTC - ok

    16:25:20.0000 2396 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys

    16:25:20.0000 2396 Msfs - ok

    16:25:20.0000 2396 MSIServer - ok

    16:25:20.0031 2396 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys

    16:25:20.0046 2396 MSKSSRV - ok

    16:25:20.0062 2396 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys

    16:25:20.0062 2396 MSPCLOCK - ok

    16:25:20.0078 2396 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys

    16:25:20.0078 2396 MSPQM - ok

    16:25:20.0093 2396 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys

    16:25:20.0093 2396 mssmbios - ok

    16:25:20.0109 2396 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys

    16:25:20.0140 2396 MSTEE - ok

    16:25:20.0140 2396 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINDOWS\system32\DRIVERS\ASACPI.sys

    16:25:20.0218 2396 MTsensor - ok

    16:25:20.0250 2396 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys

    16:25:20.0250 2396 Mup - ok

    16:25:20.0281 2396 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

    16:25:20.0296 2396 NABTSFEC - ok

    16:25:20.0328 2396 [ 87E394C810794D3C70CF22E8316CB23E ] napagent C:\WINDOWS\System32\qagentrt.dll

    16:25:20.0359 2396 napagent - ok

    16:25:20.0390 2396 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys

    16:25:20.0390 2396 NDIS - ok

    16:25:20.0421 2396 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys

    16:25:20.0421 2396 NdisIP - ok

    16:25:20.0437 2396 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys

    16:25:20.0671 2396 NdisTapi - ok

    16:25:20.0703 2396 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys

    16:25:20.0718 2396 Ndisuio - ok

    16:25:20.0734 2396 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys

    16:25:20.0734 2396 NdisWan - ok

    16:25:20.0750 2396 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys

    16:25:20.0781 2396 NDProxy - ok

    16:25:20.0812 2396 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys

    16:25:20.0828 2396 NetBIOS - ok

    16:25:20.0843 2396 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys

    16:25:20.0843 2396 NetBT - ok

    16:25:20.0859 2396 [ DC6BAE085E9B3C2F3A963ED46791FEAB ] NetDDE C:\WINDOWS\system32\netdde.exe

    16:25:20.0859 2396 NetDDE - ok

    16:25:20.0859 2396 [ DC6BAE085E9B3C2F3A963ED46791FEAB ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe

    16:25:20.0859 2396 NetDDEdsdm - ok

    16:25:20.0890 2396 [ 8754210A3399D19610CE2D71E0C3E5D9 ] Netlogon C:\WINDOWS\system32\lsass.exe

    16:25:20.0890 2396 Netlogon - ok

    16:25:20.0906 2396 [ 5431FB616ECAE0D587C5B97D0B86CBD8 ] Netman C:\WINDOWS\System32\netman.dll

    16:25:20.0937 2396 Netman - ok

    16:25:21.0000 2396 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

    16:25:21.0000 2396 NetTcpPortSharing - ok

    16:25:21.0031 2396 [ 4522CBE00A9E9EEE36AA82ED4B319148 ] Nla C:\WINDOWS\System32\mswsock.dll

    16:25:21.0031 2396 Nla - ok

    16:25:21.0078 2396 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys

    16:25:21.0078 2396 Npfs - ok

    16:25:21.0125 2396 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys

    16:25:21.0140 2396 Ntfs - ok

    16:25:21.0156 2396 [ 8754210A3399D19610CE2D71E0C3E5D9 ] NtLmSsp C:\WINDOWS\system32\lsass.exe

    16:25:21.0156 2396 NtLmSsp - ok

    16:25:21.0187 2396 [ AC1A78237B53044735693633F8235468 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll

    16:25:21.0187 2396 NtmsSvc - ok

    16:25:21.0218 2396 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys

    16:25:21.0218 2396 Null - ok

    16:25:21.0781 2396 [ 7B5A17BD54BB9142843DBE99A1CAAED8 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

    16:25:22.0296 2396 nv - ok

    16:25:22.0343 2396 [ 7D275ECDA4628318912F6C945D5CF963 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys

    16:25:22.0359 2396 NVENETFD - ok

    16:25:22.0375 2396 [ 75E2E77C5497F34E60491D27BF03F1CB ] nvgts C:\WINDOWS\system32\DRIVERS\nvgts.sys

    16:25:22.0375 2396 nvgts - ok

    16:25:22.0406 2396 [ B64AACEFAD2BE5BFF5353FE681253C67 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys

    16:25:22.0406 2396 nvnetbus - ok

    16:25:22.0453 2396 [ 5150B108EA88831E1C599603D8B89621 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe

    16:25:22.0453 2396 NVSvc - ok

    16:25:22.0515 2396 [ 83E8AB7BB3C8956C53FEC071C94F0BBB ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    16:25:22.0562 2396 nvUpdatusService - ok

    16:25:22.0578 2396 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

    16:25:22.0578 2396 NwlnkFlt - ok

    16:25:22.0578 2396 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

    16:25:22.0593 2396 NwlnkFwd - ok

    16:25:22.0609 2396 [ E3934CCC20A4D24F1924E13D36D2A5BD ] Parport C:\WINDOWS\system32\drivers\Parport.sys

    16:25:22.0609 2396 Parport - ok

    16:25:22.0625 2396 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys

    16:25:22.0640 2396 PartMgr - ok

    16:25:22.0687 2396 [ 1EADE28746A64C21E0A808BB12A63326 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys

    16:25:22.0687 2396 ParVdm - ok

    16:25:22.0687 2396 [ 3B166F9F753C21AEDAA9A6BD76B49655 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys

    16:25:22.0687 2396 PCI - ok

    16:25:22.0687 2396 PCIDump - ok

    16:25:22.0718 2396 [ B31EDEBA4DA28283F6B8DC4756FB9585 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys

    16:25:22.0718 2396 PCIIde - ok

    16:25:22.0734 2396 [ 2137FFD65F8E609A3A5ACD487C56CCE0 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys

    16:25:22.0734 2396 Pcmcia - ok

    16:25:22.0734 2396 PDCOMP - ok

    16:25:22.0750 2396 PDFRAME - ok

    16:25:22.0765 2396 PDRELI - ok

    16:25:22.0781 2396 PDRFRAME - ok

    16:25:22.0796 2396 perc2 - ok

    16:25:22.0812 2396 perc2hib - ok

    16:25:22.0875 2396 [ 657B69389B893F440B07590C9E963F23 ] PlugPlay C:\WINDOWS\system32\services.exe

    16:25:22.0890 2396 PlugPlay - ok

    16:25:22.0890 2396 [ 8754210A3399D19610CE2D71E0C3E5D9 ] PolicyAgent C:\WINDOWS\system32\lsass.exe

    16:25:22.0890 2396 PolicyAgent - ok

    16:25:22.0921 2396 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys

    16:25:22.0921 2396 PptpMiniport - ok

    16:25:22.0921 2396 [ 82A17ECA34D801590A67C0A2244965ED ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys

    16:25:22.0937 2396 Processor - ok

    16:25:22.0937 2396 [ 8754210A3399D19610CE2D71E0C3E5D9 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe

    16:25:22.0937 2396 ProtectedStorage - ok

    16:25:22.0953 2396 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys

    16:25:22.0953 2396 PSched - ok

    16:25:22.0968 2396 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys

    16:25:22.0984 2396 Ptilink - ok

    16:25:22.0984 2396 ql1080 - ok

    16:25:23.0000 2396 Ql10wnt - ok

    16:25:23.0015 2396 ql12160 - ok

    16:25:23.0031 2396 ql1240 - ok

    16:25:23.0046 2396 ql1280 - ok

    16:25:23.0062 2396 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys

    16:25:23.0062 2396 RasAcd - ok

    16:25:23.0078 2396 [ 0575D034B1292CA3A9BB9F67A8EE289C ] RasAuto C:\WINDOWS\System32\rasauto.dll

    16:25:23.0078 2396 RasAuto - ok

    16:25:23.0093 2396 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

    16:25:23.0093 2396 Rasl2tp - ok

    16:25:23.0125 2396 [ 9E7E2DF6971A5F00102BE3F901CC3BDC ] RasMan C:\WINDOWS\System32\rasmans.dll

    16:25:23.0125 2396 RasMan - ok

    16:25:23.0140 2396 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys

    16:25:23.0156 2396 RasPppoe - ok

    16:25:23.0171 2396 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys

    16:25:23.0171 2396 Raspti - ok

    16:25:23.0203 2396 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys

    16:25:23.0218 2396 Rdbss - ok

    16:25:23.0234 2396 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

    16:25:23.0234 2396 RDPCDD - ok

    16:25:23.0265 2396 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys

    16:25:23.0281 2396 RDPWD - ok

    16:25:23.0312 2396 [ EA9FDF71D696B532BDC44C8BFF03A737 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe

    16:25:23.0328 2396 RDSessMgr - ok

    16:25:23.0359 2396 [ 4173BC66E485FD77A03C4819F60BD0DA ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys

    16:25:23.0359 2396 redbook - ok

    16:25:23.0359 2396 [ 4007ABF5D9BF0E55451D775443D1F985 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll

    16:25:23.0375 2396 RemoteAccess - ok

    16:25:23.0421 2396 [ 851C30DF2807FCFA21E4C681A7D6440E ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys

    16:25:23.0421 2396 RFCOMM - ok

    16:25:23.0468 2396 [ D1F1D0EE50F8C070A612796676971699 ] RichVideo C:\Program Files\CyberLink\Shared files\RichVideo.exe

    16:25:23.0500 2396 RichVideo - ok

    16:25:23.0515 2396 [ BE078F8F7EC2491EFDD79A53353A060F ] RpcLocator C:\WINDOWS\system32\locator.exe

    16:25:23.0531 2396 RpcLocator - ok

    16:25:23.0562 2396 [ D9883335CC1C17AFC3A09C8AC3E4DBE4 ] RpcSs C:\WINDOWS\System32\rpcss.dll

    16:25:23.0562 2396 RpcSs - ok

    16:25:23.0593 2396 [ AD1B5F1B99FFF08C99F443D784711A81 ] RSVP C:\WINDOWS\system32\rsvp.exe

    16:25:23.0609 2396 RSVP - ok

    16:25:23.0625 2396 [ 8754210A3399D19610CE2D71E0C3E5D9 ] SamSs C:\WINDOWS\system32\lsass.exe

    16:25:23.0625 2396 SamSs - ok

    16:25:23.0640 2396 [ 1B4CD62174E907C7EF8EC5D4D0A2A616 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe

    16:25:23.0671 2396 SCardSvr - ok

    16:25:23.0703 2396 [ 7C288AE0F75CB18CFF1DF6179A67AD8F ] Schedule C:\WINDOWS\system32\schedsvc.dll

    16:25:23.0703 2396 Schedule - ok

    16:25:23.0718 2396 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys

    16:25:23.0734 2396 Secdrv - ok

    16:25:23.0765 2396 [ 6983665BEA867125B1DA5757CD8B2F9D ] seclogon C:\WINDOWS\System32\seclogon.dll

    16:25:23.0765 2396 seclogon - ok

    16:25:23.0781 2396 [ F6EC8F1E50E40237BDDEE1CB7FE20B42 ] SENS C:\WINDOWS\system32\sens.dll

    16:25:23.0796 2396 SENS - ok

    16:25:23.0796 2396 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys

    16:25:23.0812 2396 serenum - ok

    16:25:23.0812 2396 [ 92C21762653BB2CE51147EB8A9AA654F ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys

    16:25:23.0812 2396 Serial - ok

    16:25:23.0859 2396 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys

    16:25:23.0859 2396 Sfloppy - ok

    16:25:23.0890 2396 [ 7579C4BE909D47F10F3D8D801CB13ED9 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll

    16:25:23.0890 2396 SharedAccess - ok

    16:25:23.0921 2396 [ 2D5D4156292150FE571872C1B88E9299 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll

    16:25:23.0921 2396 ShellHWDetection - ok

    16:25:23.0921 2396 Simbad - ok

    16:25:23.0953 2396 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys

    16:25:23.0968 2396 SLIP - ok

    16:25:23.0968 2396 Sparrow - ok

    16:25:24.0015 2396 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys

    16:25:24.0031 2396 splitter - ok

    16:25:24.0062 2396 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe

    16:25:24.0078 2396 Spooler - ok

    16:25:24.0109 2396 [ 64D2A7640E0767ECD3BCB38D3200E7CE ] sr C:\WINDOWS\system32\DRIVERS\sr.sys

    16:25:24.0109 2396 sr - ok

    16:25:24.0140 2396 [ 81CBF363C414620CAA61BD6843D8FDB9 ] srservice C:\WINDOWS\system32\srsvc.dll

    16:25:24.0187 2396 srservice - ok

    16:25:24.0312 2396 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys

    16:25:24.0453 2396 Srv - ok

    16:25:24.0531 2396 [ 5B9D0DE64BE96A806819516440FD211C ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll

    16:25:24.0546 2396 SSDPSRV - ok

    16:25:24.0625 2396 [ 5A1D0CA8A5F1E7B4EC50B9D76C001F0E ] ss_bus C:\WINDOWS\system32\DRIVERS\ss_bus.sys

    16:25:24.0703 2396 ss_bus - ok

    16:25:24.0781 2396 [ F0A85580E36A3A85059037D39A9CF079 ] ss_mdfl C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys

    16:25:24.0781 2396 ss_mdfl - ok

    16:25:24.0843 2396 [ 84C3DBFD1BFA4ADC0A950B3D5506CB00 ] ss_mdm C:\WINDOWS\system32\DRIVERS\ss_mdm.sys

    16:25:24.0843 2396 ss_mdm - ok

    16:25:24.0953 2396 [ 5AE996186D2DC694FEF88F14A3FC9242 ] stisvc C:\WINDOWS\system32\wiaservc.dll

    16:25:25.0062 2396 stisvc - ok

    16:25:25.0093 2396 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys

    16:25:25.0140 2396 streamip - ok

    16:25:25.0156 2396 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys

    16:25:25.0171 2396 swenum - ok

    16:25:25.0234 2396 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys

    16:25:25.0250 2396 swmidi - ok

    16:25:25.0265 2396 SwPrv - ok

    16:25:25.0265 2396 symc810 - ok

    16:25:25.0281 2396 symc8xx - ok

    16:25:25.0296 2396 sym_hi - ok

    16:25:25.0312 2396 sym_u3 - ok

    16:25:25.0343 2396 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys

    16:25:25.0406 2396 sysaudio - ok

    16:25:25.0437 2396 [ 251EAE7C56C6AB9490311A3C9757E18D ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe

    16:25:25.0468 2396 SysmonLog - ok

    16:25:25.0500 2396 [ 2BC9FB448F0C2394FF53C83A7BB04731 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll

    16:25:25.0515 2396 TapiSrv - ok

    16:25:25.0578 2396 [ D9F19E78F98834CB411D6AD3C68D181A ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys

    16:25:26.0031 2396 Tcpip - ok

    16:25:26.0046 2396 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys

    16:25:26.0062 2396 TDPIPE - ok

    16:25:26.0078 2396 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys

    16:25:26.0078 2396 TDTCP - ok

    16:25:26.0078 2396 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys

    16:25:26.0093 2396 TermDD - ok

    16:25:26.0125 2396 [ E0AEF86A594C9990D6321C5CA239C5B7 ] TermService C:\WINDOWS\System32\termsrv.dll

    16:25:26.0125 2396 TermService - ok

    16:25:26.0140 2396 [ 2D5D4156292150FE571872C1B88E9299 ] Themes C:\WINDOWS\System32\shsvcs.dll

    16:25:26.0140 2396 Themes - ok

    16:25:26.0156 2396 TosIde - ok

    16:25:26.0171 2396 [ 20655E8CA1C78BC7088B18E93806D21B ] TrkWks C:\WINDOWS\system32\trkwks.dll

    16:25:26.0187 2396 TrkWks - ok

    16:25:26.0203 2396 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys

    16:25:26.0218 2396 Udfs - ok

    16:25:26.0218 2396 ultra - ok

    16:25:26.0343 2396 [ 8B802B483CBDE06F62DBC04DC7AFAF8E ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    16:25:26.0359 2396 UMVPFSrv - ok

    16:25:26.0390 2396 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys

    16:25:26.0406 2396 Update - ok

    16:25:26.0421 2396 [ 01653D6C9604F1FB31A76EC94E08954F ] upnphost C:\WINDOWS\System32\upnphost.dll

    16:25:26.0437 2396 upnphost - ok

    16:25:26.0453 2396 [ A89796DD0DE24CF03B3A39407E1F46A3 ] UPS C:\WINDOWS\System32\ups.exe

    16:25:26.0453 2396 UPS - ok

    16:25:26.0515 2396 [ 68A00F7BD18BC3AF2D98A75142E1C74E ] USB28xxBGA C:\WINDOWS\system32\DRIVERS\emBDA.sys

    16:25:26.0546 2396 USB28xxBGA - ok

    16:25:26.0562 2396 [ D52F4FC7788D670A78B2C253717B5330 ] USB28xxOEM C:\WINDOWS\system32\DRIVERS\emOEM.sys

    16:25:26.0562 2396 USB28xxOEM - ok

    16:25:26.0625 2396 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys

    16:25:26.0625 2396 usbaudio - ok

    16:25:26.0671 2396 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys

    16:25:26.0671 2396 usbccgp - ok

    16:25:26.0718 2396 [ 2825E0E294686A26506690059E1F437A ] USBCCID C:\WINDOWS\system32\DRIVERS\usbccid.sys

    16:25:26.0718 2396 USBCCID - ok

    16:25:26.0734 2396 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys

    16:25:26.0750 2396 usbehci - ok

    16:25:26.0750 2396 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys

    16:25:26.0765 2396 usbhub - ok

    16:25:26.0796 2396 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys

    16:25:26.0796 2396 usbohci - ok

    16:25:26.0812 2396 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys

    16:25:26.0812 2396 usbprint - ok

    16:25:26.0843 2396 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys

    16:25:26.0859 2396 usbscan - ok

    16:25:26.0890 2396 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    16:25:26.0890 2396 USBSTOR - ok

    16:25:26.0937 2396 [ 63BBFCA7F390F4C49ED4B96BFB1633E0 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys

    16:25:26.0937 2396 usbvideo - ok

    16:25:26.0968 2396 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys

    16:25:26.0968 2396 VgaSave - ok

    16:25:26.0968 2396 ViaIde - ok

    16:25:27.0000 2396 [ 8AB662B3C4691E6DDF61C96BB5B7D103 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys

    16:25:27.0000 2396 VolSnap - ok

    16:25:27.0031 2396 [ A585EDD6965B301DE8A45C6768C7C215 ] VSS C:\WINDOWS\System32\vssvc.exe

    16:25:27.0062 2396 VSS - ok

    16:25:27.0265 2396 [ 8ED347BAD8D1FB7C40B593BFB01786D2 ] vToolbarUpdater11.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    16:25:27.0296 2396 vToolbarUpdater11.2.0 - ok

    16:25:27.0328 2396 [ 390D8E65F362327AD510B08971478301 ] W32Time C:\WINDOWS\system32\w32time.dll

    16:25:27.0328 2396 W32Time - ok

    16:25:27.0343 2396 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys

    16:25:27.0343 2396 Wanarp - ok

    16:25:27.0343 2396 WDICA - ok

    16:25:27.0375 2396 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys

    16:25:27.0375 2396 wdmaud - ok

    16:25:27.0390 2396 [ 33D8E2812054D97A0AEC9B8F04277927 ] WebClient C:\WINDOWS\System32\webclnt.dll

    16:25:27.0406 2396 WebClient - ok

    16:25:27.0468 2396 [ F9E105F369C18E4001E0C05AAF600D73 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll

    16:25:27.0484 2396 winmgmt - ok

    16:25:27.0515 2396 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll

    16:25:27.0531 2396 WmdmPmSN - ok

    16:25:27.0546 2396 [ 87F11D161207C7063EDABAC0AADC33C3 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe

    16:25:27.0562 2396 WmiApSrv - ok

    16:25:27.0593 2396 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys

    16:25:27.0593 2396 WS2IFSL - ok

    16:25:27.0625 2396 [ 843F7FA8EA38E6A4262976DCC994C81A ] wscsvc C:\WINDOWS\system32\wscsvc.dll

    16:25:27.0625 2396 wscsvc - ok

    16:25:27.0656 2396 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

    16:25:27.0656 2396 WSTCODEC - ok

    16:25:27.0687 2396 [ 1E8FDDDEF3FE260BADAB06DAE10D753A ] wuauserv C:\WINDOWS\system32\wuauserv.dll

    16:25:27.0703 2396 wuauserv - ok

    16:25:27.0750 2396 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys

    16:25:27.0765 2396 WudfPf - ok

    16:25:27.0781 2396 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys

    16:25:27.0828 2396 WudfRd - ok

    16:25:27.0859 2396 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll

    16:25:27.0859 2396 WudfSvc - ok

    16:25:27.0906 2396 [ E99782DBB8FFA2AEE72B31DAC8D8D887 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll

    16:25:27.0937 2396 WZCSVC - ok

    16:25:27.0968 2396 [ FD3C38635808920F8235BF2FED642F54 ] xmlprov C:\WINDOWS\System32\xmlprov.dll

    16:25:27.0968 2396 xmlprov - ok

    16:25:28.0000 2396 ================ Scan global ===============================

    16:25:28.0031 2396 [ 953AD498333B03F7CE547151F96EF241 ] C:\WINDOWS\system32\basesrv.dll

    16:25:28.0046 2396 [ C7CC71181F7FD61C49EFF278003827A5 ] C:\WINDOWS\system32\winsrv.dll

    16:25:28.0359 2396 [ C7CC71181F7FD61C49EFF278003827A5 ] C:\WINDOWS\system32\winsrv.dll

    16:25:28.0375 2396 [ 657B69389B893F440B07590C9E963F23 ] C:\WINDOWS\system32\services.exe

    16:25:28.0375 2396 [Global] - ok

    16:25:28.0375 2396 ================ Scan MBR ==================================

    16:25:28.0421 2396 [ C99C3199CFAA4CBDCD91493F6D113A50 ] \Device\Harddisk0\DR0

    16:25:28.0640 2396 \Device\Harddisk0\DR0 - ok

    16:25:28.0656 2396 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1

    16:25:28.0890 2396 \Device\Harddisk1\DR1 - ok

    16:25:28.0890 2396 ================ Scan VBR ==================================

    16:25:28.0937 2396 [ 249B50C54991EB21FEDF29563EFCA7AA ] \Device\Harddisk0\DR0\Partition1

    16:25:28.0937 2396 \Device\Harddisk0\DR0\Partition1 - ok

    16:25:28.0937 2396 [ BADBE69CE05D329C85B554B34E6CEA69 ] \Device\Harddisk1\DR1\Partition1

    16:25:28.0937 2396 \Device\Harddisk1\DR1\Partition1 - ok

    16:25:28.0937 2396 ============================================================

    16:25:28.0937 2396 Scan finished

    16:25:28.0937 2396 ============================================================

    16:25:28.0953 2220 Detected object count: 0

    16:25:28.0953 2220 Actual detected object count: 0

  2. Emsisoft Emergency Kit - Versie 2.0

    Laatste Update: 30/08/2012 13:48:31

    Scaninstellingen:

    Scantype: Diepe scan

    Objecten: Rootkits, Geheugen, Sporen, C:\, E:\

    Scan archieven: Aan

    ADS Scan: Aan

    Scan gestart: 30/08/2012 13:49:31

    Key: hkey_classes_root\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} Ontdekt: Trace.Registry.funwebproducts!E1

    Value: hkey_current_user\software\mywebsearch\bar --> menuextlabel Ontdekt: Trace.Registry.mywebsearch toolbar!E1

    Key: hkey_classes_root\interface\{07b18eac-a523-4961-b6bb-170de4475cca} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{120927bf-1700-43bc-810f-fab92549b390} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{1f52a5fa-a705-4415-b975-88503b291728} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{3e720453-b472-4954-b7aa-33069eb53906} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{90449521-d834-4703-bb4e-d3aa44042ff8} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{991aac62-b100-47ce-8b75-253965244f69} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Value: hkey_current_user\software\microsoft\internet explorer\urlsearchhooks --> {00a6faf6-072e-44cf-8957-5838f569a31d} Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_current_user\software\mywebsearch Ontdekt: Trace.Registry.mywebsearchtoobar!E1

    Value: hkey_local_machine\software\reflexive entertainment\big kahuna reef 2 --> installpath Ontdekt: Trace.Registry.gamefiesta big kahuna reef 2!E1

    Key: hkey_local_machine\software\trymedia systems Ontdekt: Trace.Registry.trymedia!E1

    Key: hkey_local_machine\software\trymedia systems\activemark software Ontdekt: Trace.Registry.trymedia!E1

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388680.DLL Ontdekt: Adware.Win32.MyWebSearch!E1

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388699.DLL Ontdekt: Trojan-Dropper.Softomat!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388702.DLL Ontdekt: Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388704.DLL Ontdekt: Packed.Win32.Krap!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388710.scr Ontdekt: Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388712.exe Ontdekt: Riskware.Win32.Somoto.AMN!E1

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388716.SCR Ontdekt: Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388718.DLL Ontdekt: Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388719.EXE Ontdekt: Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388735.DLL Ontdekt: Trojan.Trash!E2

    C:\Program Files\Windows Live\Messenger\riched20.dll Ontdekt: Adware.Win32.MyWebSearch!E1

    C:\Program Files\Trend Micro\HiJackThis\backups\backup-20120829-112723-960.dll Ontdekt: Adware.Win32.MyWebSearch!E1

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\de_smurfen_op_vakantie_Full_Download (1).exe -> $INSTDIR\torrent.exe Ontdekt: AdWare.Intellidownload!E2

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\de_smurfen_op_vakantie_Full_Download.exe -> $INSTDIR\torrent.exe Ontdekt: AdWare.Intellidownload!E2

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\SoftonicDownloader_voor_minecraft.exe Ontdekt: Riskware.Win32.SoftonicDownloader.AMN!E1

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\SoftonicDownloader_voor_minecraft-server.exe Ontdekt: Riskware.Win32.SoftonicDownloader.AMN!E1

    Gescand 640930

    Gevonden 37

    Scan geëindigd: 30/08/2012 14:47:35

    Scantijd: 0:58:04

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\SoftonicDownloader_voor_minecraft.exe Verwijderd Riskware.Win32.SoftonicDownloader.AMN!E1

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\SoftonicDownloader_voor_minecraft-server.exe Verwijderd Riskware.Win32.SoftonicDownloader.AMN!E1

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\de_smurfen_op_vakantie_Full_Download (1).exe -> $INSTDIR\torrent.exe Verwijderd AdWare.Intellidownload!E2

    C:\Documents and Settings\Gebruiker\Mijn documenten\Downloads\de_smurfen_op_vakantie_Full_Download.exe -> $INSTDIR\torrent.exe Verwijderd AdWare.Intellidownload!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388712.exe Verwijderd Riskware.Win32.Somoto.AMN!E1

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388704.DLL Verwijderd Packed.Win32.Krap!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388702.DLL Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388710.scr Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388716.SCR Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388718.DLL Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388719.EXE Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388735.DLL Verwijderd Trojan.Trash!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388699.DLL Verwijderd Trojan-Dropper.Softomat!E2

    C:\System Volume Information\_restore{51EE6CF6-91EE-4CCD-98B5-8E25715E183A}\RP956\A0388680.DLL Verwijderd Adware.Win32.MyWebSearch!E1

    C:\Program Files\Windows Live\Messenger\riched20.dll Verwijderd Adware.Win32.MyWebSearch!E1

    C:\Program Files\Trend Micro\HiJackThis\backups\backup-20120829-112723-960.dll Verwijderd Adware.Win32.MyWebSearch!E1

    Key: hkey_local_machine\software\trymedia systems Verwijderd Trace.Registry.trymedia!E1

    Key: hkey_local_machine\software\trymedia systems\activemark software Verwijderd Trace.Registry.trymedia!E1

    Value: hkey_local_machine\software\reflexive entertainment\big kahuna reef 2 --> installpath Verwijderd Trace.Registry.gamefiesta big kahuna reef 2!E1

    Key: hkey_classes_root\interface\{07b18eac-a523-4961-b6bb-170de4475cca} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{120927bf-1700-43bc-810f-fab92549b390} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{1f52a5fa-a705-4415-b975-88503b291728} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{3e720453-b472-4954-b7aa-33069eb53906} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{90449521-d834-4703-bb4e-d3aa44042ff8} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{991aac62-b100-47ce-8b75-253965244f69} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_classes_root\interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Value: hkey_current_user\software\microsoft\internet explorer\urlsearchhooks --> {00a6faf6-072e-44cf-8957-5838f569a31d} Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Key: hkey_current_user\software\mywebsearch Verwijderd Trace.Registry.mywebsearchtoobar!E1

    Value: hkey_current_user\software\mywebsearch\bar --> menuextlabel Verwijderd Trace.Registry.mywebsearch toolbar!E1

    Key: hkey_classes_root\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} Verwijderd Trace.Registry.funwebproducts!E1

    Verwijderd 37

  3. ComboFix 12-08-28.03 - Gebruiker 29/08/2012 20:56:29.4.4 - x86Microsoft Windows XP Home Edition 5.1.2600.3.1252.32.1043.18.2047.1456 [GMT 2:00]

    Gestart vanuit: c:\documents and settings\Gebruiker\Mijn documenten\Downloads\ComboFix.exe

    gebruikte Opdracht switches :: c:\documents and settings\Gebruiker\Bureaublad\CFScript.txt

    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}

    FW: AVG Internet Security 2012 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    .

    FILE ::

    "c:\windows\system32\XDva386.sys"

    "c:\windows\system32\XDva388.sys"

    "c:\windows\system32\XDva391.sys"

    "c:\windows\system32\XDva397.sys"

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    -------\Legacy_XDVA386

    -------\Legacy_XDVA388

    -------\Legacy_XDVA391

    -------\Legacy_XDVA397

    -------\Service_XDva386

    -------\Service_XDva388

    -------\Service_XDva391

    -------\Service_XDva397

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-07-28 to 2012-08-29 ))))))))))))))))))))))))))))))

    .

    .

    2012-08-29 09:35 . 2012-08-29 09:35 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\Malwarebytes

    2012-08-29 09:34 . 2012-08-29 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

    2012-08-28 15:42 . 2012-08-28 15:42 -------- d-----w- c:\program files\Trend Micro

    2012-08-28 09:32 . 2012-08-28 09:32 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\InstallShield

    2012-08-26 12:42 . 2012-08-26 12:42 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers

    2012-08-26 12:42 . 2012-08-24 13:58 405152 ----a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll

    2012-08-17 12:33 . 2012-08-17 12:33 -------- d-----w- C:\AMD

    2012-08-17 09:18 . 2012-08-17 09:18 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\AVG

    2012-08-16 12:14 . 2012-08-16 12:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PIXELA

    2012-07-30 21:52 . 2012-07-30 21:52 103904 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-07-06 13:58 . 2008-04-15 12:00 78336 ----a-w- c:\windows\system32\browser.dll

    2012-07-04 14:05 . 2010-03-18 14:46 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys

    2012-07-03 18:23 . 2008-04-15 12:00 1866240 ----a-w- c:\windows\system32\win32k.sys

    2012-07-02 17:38 . 2008-04-15 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

    2012-07-02 17:38 . 2008-04-15 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

    2012-07-02 17:38 . 2008-04-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

    2012-07-02 12:05 . 2008-04-15 12:00 385024 ------w- c:\windows\system32\html.iec

    2012-06-05 15:49 . 2008-04-15 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll

    2012-06-05 15:49 . 2008-04-15 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll

    2012-06-04 15:35 . 2010-03-20 15:53 222448 ----a-w- c:\windows\system32\muweb.dll

    2012-06-04 04:32 . 2008-04-15 12:00 152576 ----a-w- c:\windows\system32\schannel.dll

    2012-06-02 13:19 . 2009-08-06 18:24 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui

    2012-06-02 13:19 . 2010-03-18 14:48 329240 ----a-w- c:\windows\system32\wucltui.dll

    2012-06-02 13:19 . 2010-03-18 14:48 210968 ----a-w- c:\windows\system32\wuweb.dll

    2012-06-02 13:19 . 2010-03-18 14:48 219160 ----a-w- c:\windows\system32\wuaucpl.cpl

    2012-06-02 13:19 . 2010-03-18 14:48 53784 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-02 13:19 . 2010-03-18 14:48 35864 ----a-w- c:\windows\system32\wups.dll

    2012-06-02 13:19 . 2009-08-06 18:24 45080 ----a-w- c:\windows\system32\wups2.dll

    2012-06-02 13:19 . 2008-04-15 12:00 97304 ----a-w- c:\windows\system32\cdm.dll

    2012-06-02 13:19 . 2009-08-06 18:24 15896 ----a-w- c:\windows\system32\wuapi.dll.mui

    2012-06-02 13:19 . 2010-03-18 14:48 577048 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-02 13:19 . 2009-08-06 18:23 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

    2012-06-02 13:19 . 2010-03-18 14:48 1933848 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-02 13:19 . 2009-08-06 18:23 24088 ----a-w- c:\windows\system32\wucltui.dll.mui

    2012-06-02 13:19 . 2010-03-20 15:53 18160 ----a-w- c:\windows\system32\mucltui.dll.mui

    2012-06-02 13:18 . 2010-03-20 15:53 275696 ----a-w- c:\windows\system32\mucltui.dll

    .

    .

    ------- Sigcheck -------

    Note: Unsigned files aren't necessarily malware.

    .

    [7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys

    [7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

    [7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys

    [-] 2008-06-20 . D9F19E78F98834CB411D6AD3C68D181A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

    .

    [-] 2009-10-15 . 497BEF5C5FAD126CA16437C1682F64EA . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

    .

    ((((((((((((((((((((((((((((( SnapShot@2012-08-29_14.48.48 )))))))))))))))))))))))))))))))))))))))))

    .

    + 2012-08-29 19:03 . 2012-08-29 19:03 16384 c:\windows\Temp\Perflib_Perfdata_4dc.dat

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    2012-07-09 19:53 2074208 ----a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-07-09 2074208]

    .

    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-27 39408]

    "Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]

    "GoogleChromeAutoLaunch_8AD85EDB4020A1F877E10A98EC8362E1"="c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012-08-17 1229848]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "RTHDCPL"="RTHDCPL.EXE" [2009-05-22 17881600]

    "emMON"="emMON.exe" [2006-05-30 61440]

    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-15 110592]

    "LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-01 190808]

    "beid"="c:\program files\Belgium Identity Card\beid35gui.exe" [2011-07-06 2068480]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]

    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]

    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

    "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-07-09 1107552]

    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]

    "NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]

    "nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]

    .

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

    .

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "_nltide_3"="advpack.dll" [2009-03-08 128512]

    "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe" [2011-03-14 234656]

    .

    c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\

    Logitech . Productregistratie.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]

    .

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

    .

    [HKLM\~\startupfolder\C:^Documents and Settings^Gebruiker^Menu Start^Programma's^Opstarten^Logitech . Productregistratie.lnk]

    path=c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\Logitech . Productregistratie.lnk

    backup=c:\windows\pss\Logitech . Productregistratie.lnkStartup

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "%windir%\\system32\\sessmgr.exe"=

    "c:\\Program Files\\LimeWire\\LimeWire.exe"=

    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    "c:\\Program Files\\Farming Simulator 2011\\FarmingSimulator2011.exe"=

    "c:\\Program Files\\Farming Simulator 2011\\game.exe"=

    "c:\\Documents and Settings\\Gebruiker\\Mijn documenten\\Downloads\\crossfire_downloader.exe"=

    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

    "c:\\Documents and Settings\\Gebruiker\\Mijn documenten\\Downloads\\crossfire_downloader (1).exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=

    "c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=

    "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=

    "c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

    "443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443

    "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443

    "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674

    "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674

    "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675

    .

    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19/04/2012 4:50 24896]

    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 7:30 31952]

    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/10/2011 7:23 235216]

    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 2:14 301248]

    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [4/07/2012 17:25 5160568]

    R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/08/2011 7:09 193288]

    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [7/07/2012 15:53 1262400]

    R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [1/04/2011 7:11 428640]

    R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [9/07/2012 21:53 935008]

    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23/12/2011 13:32 139856]

    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [23/12/2011 13:32 24144]

    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23/12/2011 13:32 17232]

    S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2010 15:19 136176]

    S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [19/03/2010 10:26 37632]

    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [18/03/2010 18:40 1684736]

    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [28/03/2010 17:38 36608]

    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2010 15:19 136176]

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 13:18]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 13:18]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-1960408961-682003330-1003Core.job

    - c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-10 08:19]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-1960408961-682003330-1003UA.job

    - c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-10 08:19]

    .

    .

    ------- Bijkomende Scan -------

    .

    uStart Page = hxxp://www.google.be/

    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

    IE: Free YouTube to MP3 Converter - c:\documents and settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    TCP: DhcpNameServer = 195.130.130.1 195.130.131.1

    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

    Rootkit scan 2012-08-29 21:04

    Windows 5.1.2600 Service Pack 3 NTFS

    .

    scannen van verborgen processen ...

    .

    scannen van verborgen autostart items ...

    .

    scannen van verborgen bestanden ...

    .

    Scan succesvol afgerond

    verborgen bestanden: 0

    .

    **************************************************************************

    .

    --------------------- DLLs Geladen Onder Lopende Processen ---------------------

    .

    - - - - - - - > 'explorer.exe'(2732)

    c:\windows\system32\webcheck.dll

    c:\windows\system32\WPDShServiceObj.dll

    c:\windows\system32\PortableDeviceTypes.dll

    c:\windows\system32\PortableDeviceApi.dll

    .

    ------------------------ Andere Aktieve Processen ------------------------

    .

    c:\windows\System32\SCardSvr.exe

    c:\windows\RTHDCPL.EXE

    c:\windows\emMON.exe

    c:\windows\system32\rundll32.exe

    c:\windows\system32\RunDLL32.exe

    c:\program files\Canon\IJPLM\IJPLMSVC.EXE

    c:\program files\Java\jre6\bin\jqs.exe

    c:\windows\system32\nvsvc32.exe

    c:\program files\AVG\AVG2012\avgnsx.exe

    c:\program files\AVG\AVG2012\avgemcx.exe

    c:\program files\AVG\AVG2012\avgrsx.exe

    c:\program files\CyberLink\Shared files\RichVideo.exe

    c:\program files\AVG\AVG2012\avgcsrvx.exe

    c:\windows\system32\wscntfy.exe

    .

    **************************************************************************

    .

    Voltooingstijd: 2012-08-29 21:07:45 - machine werd herstart

    ComboFix-quarantined-files.txt 2012-08-29 19:07

    ComboFix2.txt 2012-08-29 14:53

    .

    Pre-Run: 116.342.480.896 bytes beschikbaar

    Post-Run: 116.341.288.960 bytes beschikbaar

    .

    - - End Of File - - 52922E4F434E60F760EF02C21EF39EB7

  4. ComboFix 12-08-28.03 - Gebruiker 29/08/2012 16:33:09.3.4 - x86

    Microsoft Windows XP Home Edition 5.1.2600.3.1252.32.1043.18.2047.1408 [GMT 2:00]

    Gestart vanuit: c:\documents and settings\Gebruiker\Mijn documenten\Downloads\ComboFix.exe

    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}

    FW: AVG Internet Security 2012 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    -------\Legacy_MYWEBSEARCHSERVICE

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-07-28 to 2012-08-29 ))))))))))))))))))))))))))))))

    .

    .

    2012-08-29 09:35 . 2012-08-29 09:35 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\Malwarebytes

    2012-08-29 09:34 . 2012-08-29 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

    2012-08-28 15:42 . 2012-08-28 15:42 -------- d-----w- c:\program files\Trend Micro

    2012-08-28 09:32 . 2012-08-28 09:32 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\InstallShield

    2012-08-26 12:42 . 2012-08-26 12:42 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers

    2012-08-26 12:42 . 2012-08-24 13:58 405152 ----a-w- c:\windows\system32\Newtonsoft.Json.Net20.dll

    2012-08-17 12:33 . 2012-08-17 12:33 -------- d-----w- C:\AMD

    2012-08-17 09:18 . 2012-08-17 09:18 -------- d-----w- c:\documents and settings\Gebruiker\Application Data\AVG

    2012-08-16 12:14 . 2012-08-16 12:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PIXELA

    2012-07-30 21:52 . 2012-07-30 21:52 103904 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-07-06 13:58 . 2008-04-15 12:00 78336 ----a-w- c:\windows\system32\browser.dll

    2012-07-04 14:05 . 2010-03-18 14:46 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys

    2012-07-03 18:23 . 2008-04-15 12:00 1866240 ----a-w- c:\windows\system32\win32k.sys

    2012-07-02 17:38 . 2008-04-15 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

    2012-07-02 17:38 . 2008-04-15 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

    2012-07-02 17:38 . 2008-04-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

    2012-07-02 12:05 . 2008-04-15 12:00 385024 ------w- c:\windows\system32\html.iec

    2012-06-05 15:49 . 2008-04-15 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll

    2012-06-05 15:49 . 2008-04-15 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll

    2012-06-04 15:35 . 2010-03-20 15:53 222448 ----a-w- c:\windows\system32\muweb.dll

    2012-06-04 04:32 . 2008-04-15 12:00 152576 ----a-w- c:\windows\system32\schannel.dll

    2012-06-02 13:19 . 2009-08-06 18:24 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui

    2012-06-02 13:19 . 2010-03-18 14:48 329240 ----a-w- c:\windows\system32\wucltui.dll

    2012-06-02 13:19 . 2010-03-18 14:48 210968 ----a-w- c:\windows\system32\wuweb.dll

    2012-06-02 13:19 . 2010-03-18 14:48 219160 ----a-w- c:\windows\system32\wuaucpl.cpl

    2012-06-02 13:19 . 2010-03-18 14:48 53784 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-02 13:19 . 2010-03-18 14:48 35864 ----a-w- c:\windows\system32\wups.dll

    2012-06-02 13:19 . 2009-08-06 18:24 45080 ----a-w- c:\windows\system32\wups2.dll

    2012-06-02 13:19 . 2008-04-15 12:00 97304 ----a-w- c:\windows\system32\cdm.dll

    2012-06-02 13:19 . 2009-08-06 18:24 15896 ----a-w- c:\windows\system32\wuapi.dll.mui

    2012-06-02 13:19 . 2010-03-18 14:48 577048 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-02 13:19 . 2009-08-06 18:23 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

    2012-06-02 13:19 . 2010-03-18 14:48 1933848 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-02 13:19 . 2009-08-06 18:23 24088 ----a-w- c:\windows\system32\wucltui.dll.mui

    2012-06-02 13:19 . 2010-03-20 15:53 18160 ----a-w- c:\windows\system32\mucltui.dll.mui

    2012-06-02 13:18 . 2010-03-20 15:53 275696 ----a-w- c:\windows\system32\mucltui.dll

    .

    .

    ------- Sigcheck -------

    Note: Unsigned files aren't necessarily malware.

    .

    [7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys

    [7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

    [7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys

    [-] 2008-06-20 . D9F19E78F98834CB411D6AD3C68D181A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

    .

    [-] 2009-10-15 . 497BEF5C5FAD126CA16437C1682F64EA . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87775fdb-6972-41f9-ae51-8326e38cb206}]

    2011-05-09 09:49 176936 ----a-w- c:\program files\uTorrentBar_NL\prxtbuTo0.dll

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    2012-07-09 19:53 2074208 ----a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-07-09 2074208]

    .

    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

    .

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

    "{87775FDB-6972-41F9-AE51-8326E38CB206}"= "c:\program files\uTorrentBar_NL\prxtbuTo0.dll" [2011-05-09 176936]

    .

    [HKEY_CLASSES_ROOT\clsid\{87775fdb-6972-41f9-ae51-8326e38cb206}]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-27 39408]

    "Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]

    "GoogleChromeAutoLaunch_8AD85EDB4020A1F877E10A98EC8362E1"="c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012-08-17 1229848]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "RTHDCPL"="RTHDCPL.EXE" [2009-05-22 17881600]

    "emMON"="emMON.exe" [2006-05-30 61440]

    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-15 110592]

    "LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-01 190808]

    "beid"="c:\program files\Belgium Identity Card\beid35gui.exe" [2011-07-06 2068480]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]

    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]

    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

    "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-07-09 1107552]

    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]

    "NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]

    "nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]

    .

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

    .

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "_nltide_3"="advpack.dll" [2009-03-08 128512]

    "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe" [2011-03-14 234656]

    .

    c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\

    Logitech . Productregistratie.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]

    .

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

    .

    [HKLM\~\startupfolder\C:^Documents and Settings^Gebruiker^Menu Start^Programma's^Opstarten^Logitech . Productregistratie.lnk]

    path=c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\Logitech . Productregistratie.lnk

    backup=c:\windows\pss\Logitech . Productregistratie.lnkStartup

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "%windir%\\system32\\sessmgr.exe"=

    "c:\\Program Files\\LimeWire\\LimeWire.exe"=

    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

    "c:\\Program Files\\Farming Simulator 2011\\FarmingSimulator2011.exe"=

    "c:\\Program Files\\Farming Simulator 2011\\game.exe"=

    "c:\\Documents and Settings\\Gebruiker\\Mijn documenten\\Downloads\\crossfire_downloader.exe"=

    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

    "c:\\Documents and Settings\\Gebruiker\\Mijn documenten\\Downloads\\crossfire_downloader (1).exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=

    "c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=

    "c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=

    "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=

    "c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

    "443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443

    "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443

    "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674

    "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674

    "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675

    .

    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [19/04/2012 4:50 24896]

    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 7:30 31952]

    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/10/2011 7:23 235216]

    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 2:14 301248]

    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [4/07/2012 17:25 5160568]

    R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/08/2011 7:09 193288]

    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [7/07/2012 15:53 1262400]

    R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [1/04/2011 7:11 428640]

    R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [9/07/2012 21:53 935008]

    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [23/12/2011 13:32 139856]

    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [23/12/2011 13:32 24144]

    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [23/12/2011 13:32 17232]

    S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2010 15:19 136176]

    S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [19/03/2010 10:26 37632]

    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [18/03/2010 18:40 1684736]

    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [28/03/2010 17:38 36608]

    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27/10/2010 15:19 136176]

    S3 XDva386;XDva386;\??\c:\windows\system32\XDva386.sys --> c:\windows\system32\XDva386.sys [?]

    S3 XDva388;XDva388;\??\c:\windows\system32\XDva388.sys --> c:\windows\system32\XDva388.sys [?]

    S3 XDva391;XDva391;\??\c:\windows\system32\XDva391.sys --> c:\windows\system32\XDva391.sys [?]

    S3 XDva397;XDva397;\??\c:\windows\system32\XDva397.sys --> c:\windows\system32\XDva397.sys [?]

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 13:18]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 13:18]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-1960408961-682003330-1003Core.job

    - c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-10 08:19]

    .

    2012-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-1960408961-682003330-1003UA.job

    - c:\documents and settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-10 08:19]

    .

    .

    ------- Bijkomende Scan -------

    .

    uStart Page = hxxp://www.google.be/

    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

    IE: Free YouTube to MP3 Converter - c:\documents and settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    TCP: DhcpNameServer = 195.130.130.1 195.130.131.1

    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)

    MSConfigStartUp-AutoStartNPSAgent - c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe

    MSConfigStartUp-Logitech Vid - c:\program files\Logitech\Logitech Vid\vid.exe

    MSConfigStartUp-LogitechQuickCamRibbon - c:\program files\Logitech\Logitech WebCam Software\LWS.exe

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

    Rootkit scan 2012-08-29 16:49

    Windows 5.1.2600 Service Pack 3 NTFS

    .

    scannen van verborgen processen ...

    .

    scannen van verborgen autostart items ...

    .

    scannen van verborgen bestanden ...

    .

    Scan succesvol afgerond

    verborgen bestanden: 0

    .

    **************************************************************************

    .

    --------------------- DLLs Geladen Onder Lopende Processen ---------------------

    .

    - - - - - - - > 'explorer.exe'(524)

    c:\windows\system32\webcheck.dll

    c:\windows\system32\WPDShServiceObj.dll

    c:\windows\system32\PortableDeviceTypes.dll

    c:\windows\system32\PortableDeviceApi.dll

    .

    ------------------------ Andere Aktieve Processen ------------------------

    .

    c:\windows\System32\SCardSvr.exe

    c:\windows\RTHDCPL.EXE

    c:\windows\emMON.exe

    c:\windows\system32\rundll32.exe

    c:\program files\Canon\IJPLM\IJPLMSVC.EXE

    c:\program files\Java\jre6\bin\jqs.exe

    c:\windows\system32\RunDLL32.exe

    c:\windows\system32\nvsvc32.exe

    c:\program files\CyberLink\Shared files\RichVideo.exe

    c:\program files\AVG\AVG2012\avgnsx.exe

    c:\program files\AVG\AVG2012\avgemcx.exe

    c:\program files\AVG\AVG2012\avgrsx.exe

    c:\program files\AVG\AVG2012\avgcsrvx.exe

    c:\windows\system32\wscntfy.exe

    .

    **************************************************************************

    .

    Voltooingstijd: 2012-08-29 16:53:08 - machine werd herstart

    ComboFix-quarantined-files.txt 2012-08-29 14:53

    .

    Pre-Run: 116.036.919.296 bytes beschikbaar

    Post-Run: 115.974.955.008 bytes beschikbaar

    .

    - - End Of File - - 96B14CCE65C5127A1FD83579A96164CA

  5. Malwarebytes heeft een berg rotzooi van je PC gehaald. Doe nu even de volgende stap :

    Download ComboFix van één van deze locaties:

    Link 1

    Link 2

    * BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

    1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

    Klik hier

    Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap.

    2. Dubbelklik op ComboFix.exe en volg de meldingen op het scherm.

    3. ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.

    **Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware.

    4. Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.

    cf-rc-auto.jpg

    Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:

    rc-auto-done.jpg

    Klik op Ja om verder te gaan met het scannen naar malware.

    5. Wanneer ComboFix klaar is, zal het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

    Wat doet dit programma precies? Ben er niet gerust in, want men bureaublad verwijderd zich dan gewoon helemaal :hmpf:

  6. HijackThis:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 12:08:14, on 29/08/2012

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Unable to get Internet Explorer version!

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files\AVG\AVG2012\avgnsx.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\Program Files\AVG\AVG2012\avgemcx.exe

    C:\Program Files\CyberLink\Shared files\RichVideo.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    C:\Program Files\AVG\AVG2012\avgrsx.exe

    C:\Program Files\AVG\AVG2012\avgcsrvx.exe

    C:\WINDOWS\RTHDCPL.EXE

    C:\WINDOWS\emMON.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe

    C:\Program Files\Belgium Identity Card\beid35gui.exe

    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

    C:\Program Files\AVG\AVG2012\avgtray.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\WINDOWS\system32\RunDLL32.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Logitech\Vid HD\Vid.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: uTorrentBar_NL - {87775fdb-6972-41f9-ae51-8326e38cb206} - C:\Program Files\uTorrentBar_NL\prxtbuTo0.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

    O4 - HKLM\..\Run: [emMON] emMON.exe

    O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide

    O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login

    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet

    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode

    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8AD85EDB4020A1F877E10A98EC8362E1] "C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --no-startup-window

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

    O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Lokale service')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

    O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Netwerkservice')

    O4 - HKUS\S-1-5-21-1614895754-1960408961-682003330-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')

    O4 - HKUS\S-1-5-21-1614895754-1960408961-682003330-1005\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'UpdatusUser')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

    O4 - Startup: Logitech . Productregistratie.lnk = C:\Program Files\Logitech\Ereg\eReg.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/nl/uno1/GAME_UNO1.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1341837150484

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    --

    End of file - 12332 bytes

    Malwarebytes Anti-Malware:

    Malwarebytes Anti-Malware (-evaluatieversie-) 1.62.0.1300

    Malwarebytes : Free anti-malware download

    Databaseversie: v2012.08.29.03

    Windows XP Service Pack 3 x86 NTFS

    Internet Explorer 8.0.6001.18702

    Gebruiker :: USER-84E810BCC9 [administrator]

    Realtime bescherming: Ingeschakeld

    29/08/2012 11:36:23

    mbam-log-2012-08-29 (11-36-23).txt

    Scantype: Snelle scan

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 236513

    Verstreken tijd: 16 minuut/minuten, 52 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 2

    C:\Program Files\Windows Live\Messenger\msimg32.dll (PUP.FunWebProducts) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (PUP.FunWebProducts) -> Zal worden verwijderd tijdens het herstarten.

    Registersleutels gedetecteerd: 142

    HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.FunWebProducts) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.FunWebProducts) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearchToolBar.SettingsPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearchToolBar.SettingsPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.IECookiesManager.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.IECookiesManager (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.DataControl.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.DataControl (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HTMLMenu.2 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HTMLMenu (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.HTMLPanel.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.HTMLPanel (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearchToolBar.ToolbarPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearchToolBar.ToolbarPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.PopSwatterSettingsControl.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.PopSwatterSettingsControl (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.PseudoTransparentPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.PseudoTransparentPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.PopSwatterBarButton.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.PopSwatterBarButton (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HTMLMenu.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\ScreenSaverControl.ScreenSaverInstaller.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\ScreenSaverControl.ScreenSaverInstaller (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.OutlookAddin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.KillerObjManager.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.KillerObjManager (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HistoryKillerScheduler.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HistoryKillerScheduler (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HistorySwatterControlBar.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\FunWebProducts.HistorySwatterControlBar (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{4FD77ADE-791D-EB2F-78D8-BB69276AE8B7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{E79DFBC0-5697-4fbd-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.ChatSessionPlugin.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.ChatSessionPlugin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\bho_project.bho_object (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\bho_project.bho_object.1 (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.MultipleButton (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.MultipleButton.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.ThirdPartyInstaller (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.ThirdPartyInstaller.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.UrlAlertButton (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\MyWebSearch.UrlAlertButton.1 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\FocusInteractive (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FLIPOPIA (Adware.GabPath) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{67FA02C4-AB30-4e77-A640-78EE8EC8673B} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCR\CLSID\{3EEDDAB6-D529-0A42-82CC-1A4A3446B9C5} (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerwaarden gedetecteerd: 6

    HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Data: ©Ž±#¥aI¶»

    äG\Ê -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd.

    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources|f3PopularScreensavers (PUP.MyWebSearch) -> Data: C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform|FunWebProducts (PUP.MyWebSearch) -> Data: -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flipopia|UninstallString (Adware.GabPath) -> Data: explorer http://clients.flipopia.com/data/flipopia/uninstaller/FPUninstaller.exe -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 21

    C:\Documents and Settings\Gebruiker\Application Data\Flipopia (Adware.GabPath) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\ScreenSaver (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\ScreenSaver\Images (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch (PUP.MyWebSearch) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar (PUP.MyWebSearch) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar\1.bin (PUP.MyWebSearch) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar\1.bin\chrome (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Avatar (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Game (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\History (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Overlay (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Settings (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\setups (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    Bestanden gedetecteerd: 133

    C:\Program Files\Windows Live\Messenger\msimg32.dll (PUP.FunWebProducts) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (PUP.FunWebProducts) -> Zal worden verwijderd tijdens het herstarten.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3FFTBPR.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\WINDOWS\system32\f3PSSavr.scr (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Documents and Settings\Gebruiker\Application Data\Flipopia\config.cfg (Adware.GabPath) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Documents and Settings\Gebruiker\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\ScreenSaver\Images\00877118.urr (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\00DE5C12.dat (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn-new.html (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\CHROME.MANIFEST (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\INSTALL.RDF (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3PATCH.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3TPINST.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\M3UNPAT.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSMLBTN.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\MWSUABTN.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\0002C087 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDEDD7 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDF123 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDF2C9.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDF48E.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDF4DC.bmp (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\00DDF569.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\014D508D.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\014D5177.bmp (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\014D52BF.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\014D533C.bin (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\019A5E33.exe (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Cache\files.ini (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\History\search3 (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\CM.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\WB.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\8_step1.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkez.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkgr.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkgs.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bklf.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkrg.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkwebfet.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzc.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzl.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzn.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzq.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzr.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzu.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzv.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzw.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\bkzwinky.jpg (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\blubtn2d.png (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\blubtn2r.png (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\blubtn3d.png (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\blubtn3r.png (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\rebut4.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\rebut4b.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\rebut4c.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\shield.png (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Overlay\COMMON.F3S (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (PUP.MyWebSearch) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)

  7. Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:01:45, on 28/08/2012

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Unable to get Internet Explorer version!

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\RTHDCPL.EXE

    C:\WINDOWS\emMON.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

    C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe

    C:\Program Files\Belgium Identity Card\beid35gui.exe

    C:\Program Files\AVG\AVG2012\avgtray.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\WINDOWS\system32\RunDLL32.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Logitech\Vid HD\Vid.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\Program Files\AVG\AVG2012\avgnsx.exe

    C:\Program Files\AVG\AVG2012\avgemcx.exe

    C:\Program Files\CyberLink\Shared files\RichVideo.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    C:\Program Files\AVG\AVG2012\avgrsx.exe

    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    C:\Program Files\AVG\AVG2012\avgcsrvx.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL

    R3 - URLSearchHook: uTorrentBar_NL Toolbar - {87775fdb-6972-41f9-ae51-8326e38cb206} - C:\Program Files\uTorrentBar_NL\prxtbuTo0.dll

    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL

    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: uTorrentBar_NL - {87775fdb-6972-41f9-ae51-8326e38cb206} - C:\Program Files\uTorrentBar_NL\prxtbuTo0.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL

    O3 - Toolbar: uTorrentBar_NL Toolbar - {87775fdb-6972-41f9-ae51-8326e38cb206} - C:\Program Files\uTorrentBar_NL\prxtbuTo0.dll

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

    O4 - HKLM\..\Run: [emMON] emMON.exe

    O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

    O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide

    O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login

    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

    O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode

    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8AD85EDB4020A1F877E10A98EC8362E1] "C:\Documents and Settings\Gebruiker\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" --no-startup-window

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

    O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Lokale service')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

    O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Netwerkservice')

    O4 - HKUS\S-1-5-21-1614895754-1960408961-682003330-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')

    O4 - HKUS\S-1-5-21-1614895754-1960408961-682003330-1005\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'UpdatusUser')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

    O4 - Startup: Logitech . Productregistratie.lnk = C:\Program Files\Logitech\Ereg\eReg.exe

    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?s=100000334&p=ZCYYYYYYYYBE&a=nIKI5JND2bzt8xmiKg2Yqg&n=2011032606

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Gebruiker\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/nl/uno1/GAME_UNO1.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1341837150484

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

    O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    O24 - Desktop Component 0: (no name) - http://upload.wikimedia.org/wikipedia/commons/0/0c/Fleygletur_a_01.png

    --

    End of file - 13559 bytes

  8. Hallo, mijn windows xp, (Andere pc) blokkeert zeer vaak bij het gebruik van de pc. Heb er al zo'n beetje oplossingen voor gezocht op 't internet maar vind gewoon niet hoe ik het moet kunnen oplossen. Als je er niets aan doet (de pc) gaat hij gewoon snel. Maar speel je erop, ga je op internet, speel je er een spelletje op, maakt niet uit wat. Hij blokkeert altijd.. Maar het vreemdste vind ik ook, als het uiteindelijk begint te blokkeren veranderd het scherm ook van kwaliteit enzovoort.. De lettertype veranderd dan, en het scherm word onduidelijker. Toe help iemand, ik wil dat dit stopt.. Het is zo irritant! Bijvoorbeeld bij deze spelletjes: Farming Simulator 2011, minecraft, runescape, Euro truck simulator, Need for speed world.. Deze gingen vroeger altijd perfect! Zonder te blokkeren, of zelfs te laggen! Maar dat veranderde gewoon een aantal weken terug.

    Pleas help me.. :dong:

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.