Ga naar inhoud

Ronnyabl

Lid
  • Items

    30
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door Ronnyabl

  1. Ik moet even weg, dus kan wel enkele uren duren voordat ik terug kan reageren. ComboFix 11-04-30.05 - Ronny 01/05/2011 13:15:31.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.32.1043.18.4095.2750 [GMT 2:00] Gestart vanuit: c:\users\Ronny\Desktop\ComboFix.exe AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} FW: BitDefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Ronny\AppData\Roaming\inst.exe c:\users\Ronny\AppData\Roaming\pcouffin.sys . . (((((((((((((((((((( Bestanden Gemaakt van 2011-04-01 to 2011-05-01 )))))))))))))))))))))))))))))) . . 2011-05-01 11:20 . 2011-05-01 11:20 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-05-01 10:51 . 2011-05-01 10:51 -------- d-----w- C:\inetpub 2011-05-01 10:08 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-05-01 10:08 . 2011-05-01 10:08 -------- d-----w- c:\programdata\Malwarebytes 2011-05-01 10:08 . 2011-05-01 10:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-05-01 10:08 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-01 08:05 . 2011-05-01 08:05 -------- d-----w- c:\program files (x86)\Trend Micro 2011-04-29 18:14 . 2009-10-16 09:19 872448 ----a-w- c:\windows\SysWow64\rapture3d_oal.dll 2011-04-29 18:14 . 2009-07-13 17:04 839680 ----a-w- c:\windows\SysWow64\mkl_vml_p4.dll 2011-04-29 18:14 . 2009-07-13 17:04 532480 ----a-w- c:\windows\SysWow64\mkl_vml_p3.dll 2011-04-29 18:14 . 2009-07-13 17:04 512000 ----a-w- c:\windows\SysWow64\mkl_vml_def.dll 2011-04-29 18:14 . 2009-07-13 17:04 3485696 ----a-w- c:\windows\SysWow64\mkl_p4.dll 2011-04-29 18:14 . 2009-07-13 17:04 2793472 ----a-w- c:\windows\SysWow64\mkl_p3.dll 2011-04-29 18:14 . 2009-07-13 17:04 2441216 ----a-w- c:\windows\SysWow64\mkl_def.dll 2011-04-29 18:14 . 2009-07-13 17:04 2174976 ----a-w- c:\windows\SysWow64\mkl_lapack32.dll 2011-04-29 18:14 . 2009-07-13 17:04 2125824 ----a-w- c:\windows\SysWow64\mkl_lapack64.dll 2011-04-29 18:14 . 2009-07-13 17:04 184320 ----a-w- c:\windows\SysWow64\libguide40.dll 2011-04-29 18:14 . 2011-04-29 18:14 -------- d-----w- c:\program files (x86)\BRS 2011-04-29 18:13 . 2011-04-30 09:44 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2011-04-29 18:13 . 2011-04-29 18:13 -------- d-----w- c:\windows\SysWow64\xlive 2011-04-29 18:12 . 2009-10-15 10:44 809560 ----a-r- c:\windows\SysWow64\tmp31AF.tmp 2011-04-29 18:09 . 2009-10-15 10:44 809560 ----a-r- c:\windows\SysWow64\tmp31AE.tmp 2011-04-29 17:34 . 2011-04-29 17:34 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2011-04-29 16:39 . 2011-04-29 17:09 310728 ----a-w- c:\windows\system32\drivers\atksgt.sys 2011-04-29 16:39 . 2011-04-29 16:39 42696 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2011-04-29 15:58 . 2011-04-29 15:58 -------- d-----w- c:\programdata\Solidshield 2011-04-28 18:36 . 2011-04-28 18:36 -------- d-----w- c:\programdata\ATI 2011-04-28 18:36 . 2011-04-28 18:36 -------- d-----w- c:\program files (x86)\AMD APP 2011-04-28 18:36 . 2011-04-28 18:36 -------- d-----w- c:\program files\Common Files\ATI Technologies 2011-04-28 18:36 . 2011-04-28 18:36 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies 2011-04-28 18:35 . 2011-04-28 18:35 -------- d-----w- c:\program files (x86)\ATI Technologies 2011-04-28 18:34 . 2011-04-28 18:36 -------- d-----w- c:\program files\ATI Technologies 2011-04-28 18:27 . 2010-11-09 13:35 21992 ----a-w- c:\windows\system32\drivers\cpuz135_x64.sys 2011-04-28 18:14 . 2011-04-28 18:14 -------- d-----w- c:\program files (x86)\Common Files\Futuremark Shared 2011-04-28 17:42 . 2011-04-28 17:42 -------- d-----w- c:\program files (x86)\Seagate 2011-04-28 17:42 . 2011-04-29 17:34 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2011-04-28 17:33 . 2011-04-28 17:33 -------- d-----w- c:\program files\ATI 2011-04-28 14:09 . 2011-04-28 14:09 -------- d-----w- c:\program files (x86)\My Company Name 2011-04-28 14:08 . 2009-10-21 13:27 16896 ----a-w- c:\windows\system32\ATKOGL64.dll 2011-04-28 14:08 . 2009-10-20 14:38 1354240 ----a-w- c:\windows\system32\atklumdispx.dll 2011-04-28 14:08 . 2009-02-17 16:22 39424 ----a-w- c:\windows\system32\drivers\ATKDispLowFilter.sys 2011-04-28 14:08 . 2009-02-17 16:22 17792 ----a-w- c:\windows\system32\drivers\asusgsb.sys 2011-04-27 18:34 . 2011-04-27 18:34 -------- d-----w- c:\program files (x86)\oZone3D 2011-04-27 17:41 . 2011-04-27 17:41 -------- d-----w- c:\program files (x86)\Common Files\Steam 2011-04-27 17:41 . 2011-04-28 14:37 -------- d-----w- c:\program files (x86)\Steam 2011-04-26 17:33 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe 2011-04-26 17:33 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe 2011-04-26 17:33 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe 2011-04-26 17:33 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe 2011-04-26 16:33 . 2011-04-26 16:33 1409 ----a-w- c:\windows\QTFont.for 2011-04-25 07:29 . 2005-03-07 17:44 45056 ----a-w- c:\windows\SysWow64\PhDi2.sys 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2011-04-25 07:25 . 2011-04-25 18:15 131072 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2011-04-25 07:24 . 2011-04-25 07:24 -------- d-----w- c:\program files (x86)\Apple Software Update 2011-04-25 07:24 . 2011-04-25 07:25 -------- d-----w- c:\programdata\Apple Computer 2011-04-25 07:18 . 2005-06-01 02:10 495616 ----a-w- c:\windows\SysWow64\PICSDK2.dll 2011-04-25 07:18 . 2005-06-01 01:10 77824 ----a-w- c:\windows\SysWow64\PICEntry.dll 2011-04-25 07:18 . 2005-05-31 22:10 73728 ----a-w- c:\windows\SysWow64\PICSDK.dll 2011-04-25 07:18 . 2004-03-03 04:10 65536 ----a-w- c:\windows\SysWow64\EPPicMgr.dll 2011-04-25 07:18 . 2004-03-03 04:10 114688 ----a-w- c:\windows\SysWow64\EpPicPrt.dll 2011-04-25 07:17 . 2011-04-25 07:17 -------- d-----w- c:\program files (x86)\Panasonic 2011-04-24 17:51 . 2011-04-24 17:51 -------- d-----w- c:\program files (x86)\Nero 2011-04-24 17:49 . 2011-04-24 17:51 -------- d-----w- c:\programdata\Nero 2011-04-24 17:49 . 2011-04-24 17:50 -------- d-----w- c:\program files (x86)\Common Files\Nero 2011-04-24 17:48 . 2011-04-24 17:59 -------- d-----w- c:\programdata\LightScribe 2011-04-23 18:58 . 2011-04-23 18:58 -------- d-----w- c:\programdata\AMD 2011-04-23 18:58 . 2010-02-18 07:18 46136 ----a-w- c:\windows\system32\drivers\amdiox64.sys 2011-04-23 18:33 . 2009-09-04 15:44 517960 ----a-w- c:\windows\system32\XAudio2_5.dll 2011-04-23 11:11 . 2011-04-23 11:11 -------- d-----w- c:\program files\BitDefender 2011-04-23 11:04 . 2011-04-23 11:11 -------- d-----w- c:\program files\Common Files\BitDefender 2011-04-23 11:04 . 2011-05-01 11:14 132438 ----a-w- c:\programdata\bdinstall.bin 2011-04-23 09:56 . 2011-04-23 09:56 2048 ----a-w- c:\windows\SysWow64\winver.exe 2011-04-23 09:56 . 2011-04-23 09:56 833024 ----a-w- c:\windows\SysWow64\user32.dll 2011-04-23 09:56 . 2011-04-23 09:56 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll 2011-04-23 09:56 . 2011-04-23 09:56 1536 ----a-w- c:\windows\SysWow64\sppcomapi.dll 2011-04-23 09:56 . 2011-04-23 09:56 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs 2011-04-23 09:39 . 2011-04-23 09:39 -------- d-----w- c:\program files (x86)\MSECache 2011-04-23 09:34 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll 2011-04-23 09:34 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2011-04-23 09:34 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll 2011-04-23 09:34 . 2011-02-19 12:04 1544192 ----a-w- c:\windows\system32\DWrite.dll 2011-04-23 09:34 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll 2011-04-23 09:34 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll 2011-04-23 09:34 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll 2011-04-23 07:29 . 2011-04-23 07:29 -------- d-----w- c:\users\Public\CyberLink 2011-04-23 07:27 . 2011-04-23 07:29 -------- d-----w- c:\programdata\CyberLink 2011-04-23 07:27 . 2011-04-23 07:27 -------- d-----w- c:\program files (x86)\Cyberlink 2011-04-23 07:27 . 2011-04-23 07:27 -------- d-----w- c:\program files (x86)\Common Files\CyberLink 2011-04-23 07:25 . 2011-04-23 07:24 29480 ----a-w- c:\windows\SysWow64\msxml3a.dll 2011-04-23 07:20 . 2011-04-23 07:20 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys 2011-04-22 19:59 . 2011-04-22 19:59 -------- d-----w- c:\program files (x86)\Common Files\Java 2011-04-22 19:58 . 2011-04-22 19:58 -------- d-----w- c:\windows\Sun 2011-04-22 19:58 . 2011-04-22 19:58 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-04-22 19:58 . 2011-04-22 19:58 -------- d-----w- c:\program files (x86)\Java 2011-04-22 19:36 . 2011-04-22 19:36 521448 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-22 19:35 . 2011-04-22 19:36 -------- d-----w- c:\program files\Java 2011-04-22 19:05 . 2011-02-24 06:15 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-04-22 19:05 . 2011-02-24 05:38 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-04-22 18:41 . 2011-04-22 18:41 834544 ----a-w- c:\windows\system32\drivers\sptd.sys 2011-04-22 17:53 . 2011-04-23 01:02 -------- d-----w- c:\program files (x86)\Microsoft Works 2011-04-22 17:53 . 2011-04-23 09:45 -------- d-----w- c:\program files (x86)\Microsoft.NET 2011-04-22 17:22 . 2011-04-22 21:23 -------- d-----w- c:\programdata\NortonInstaller 2011-04-22 17:01 . 2011-04-22 17:01 -------- d-----w- c:\programdata\McAfee 2011-04-22 16:55 . 2011-04-22 16:55 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2011-04-22 16:55 . 2011-04-22 16:55 -------- d-----w- c:\program files\Google 2011-04-22 16:55 . 2011-04-29 18:15 -------- d-----w- c:\program files (x86)\Google 2011-04-22 16:38 . 2011-04-22 16:39 -------- d-----w- c:\program files (x86)\Windows Live 2011-04-22 16:38 . 2011-04-22 16:38 -------- d-----w- c:\program files\Windows Live 2011-04-22 16:37 . 2011-04-22 16:37 -------- d-----w- c:\windows\PCHEALTH 2011-04-22 16:36 . 2011-04-22 16:36 -------- d-----w- c:\program files (x86)\Common Files\Windows Live 2011-04-22 15:31 . 2011-04-22 15:31 -------- d-----w- c:\windows\system32\SPReview 2011-04-22 15:31 . 2011-04-22 15:31 -------- d-----w- c:\windows\system32\EventProviders 2011-04-22 15:30 . 2010-11-05 01:57 48976 ----a-w- c:\windows\system32\netfxperf.dll 2011-04-22 15:30 . 2010-11-05 01:57 1942856 ----a-w- c:\windows\system32\dfshim.dll 2011-04-22 15:30 . 2010-11-05 01:58 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll 2011-04-22 15:30 . 2010-11-20 13:33 5563776 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-04-22 15:30 . 2010-11-20 13:27 12288 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2011-04-22 15:30 . 2010-11-20 13:27 3715584 ----a-w- c:\windows\system32\mstscax.dll 2011-04-22 15:30 . 2010-11-20 11:07 59392 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2011-04-22 15:30 . 2010-11-20 13:26 1838080 ----a-w- c:\windows\system32\d3d10warp.dll . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-23 07:24 . 2009-05-21 18:21 505128 ----a-w- c:\windows\SysWow64\msvcp71.dll 2011-04-23 07:24 . 2009-05-21 16:57 353576 ----a-w- c:\windows\SysWow64\msvcr71.dll 2011-04-22 16:37 . 2010-06-24 09:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-04-22 15:35 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll 2011-04-22 15:35 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2011-03-21 17:56 . 2011-03-21 17:56 53760 ----a-w- c:\windows\system32\OpenCL.dll 2011-03-21 17:56 . 2011-03-21 17:56 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll 2011-03-04 06:19 . 2011-04-26 17:34 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2011-03-04 06:19 . 2011-04-26 17:34 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2010-07-08 07:37 . 2010-07-08 07:37 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe . . ------- Sigcheck ------- . [7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll [7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll [-] 2010-11-20 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll . [-] 2011-04-23 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll [7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll [7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay] @="{594D4122-1F87-41E2-96C7-825FB4796516}" [HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}] 2010-07-29 05:15 316416 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "ISPMonitor"="d:\\isp.exe" [2010-10-25 418304] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-05 336384] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R3 7ByteIo;7ByteIo;c:\program files (x86)\Ronny\Tools\Hot CPU Tester Pro 4 LE\SysInfoX64.sys [x] R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-04-05 365568] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] . . --- Andere Services/Drivers In Geheugen --- . *Deregistered* - Bdfndisf *Deregistered* - bdfwfpf . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc iissvcs REG_MULTI_SZ w3svc was apphost REG_MULTI_SZ apphostsvc . Inhoud van de 'Gedeelde Taken' map . 2011-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files (x86)\Apple Software Update\SoftwareUpdate.exe [2006-08-29 12:21] . 2011-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 16:55] . 2011-04-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-22 16:55] . 2011-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684313654-1291478289-3967929469-1000Core.job - c:\users\Ronny\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-22 15:07] . 2011-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684313654-1291478289-3967929469-1000UA.job - c:\users\Ronny\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-22 15:07] . 2011-04-26 c:\windows\Tasks\User_Feed_Synchronization-{7193B1C5-482D-4BC8-ADC0-4DB76FFFFE58}.job - c:\windows\system32\msfeedssync.exe [2011-04-22 12:17] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay] @="{594D4122-1F87-41E2-96C7-825FB4796516}" [HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}] 2010-07-29 05:15 378368 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2010-11-16 104008] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976] "Classic Start Menu"="c:\program files\Classic Shell\ClassicStartMenu.exe" [2010-07-29 98304] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "LinkInstaller"="c:\program files\Common Files\LinkInstaller.exe" [2010-07-08 101544] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Bijkomende Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.be/ mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html . - - - - ORPHANS VERWIJDERD - - - - . WebBrowser-{87775FDB-6972-41F9-AE51-8326E38CB206} - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) WebBrowser-{2D8D9ACC-F6D7-4362-8876-A275CA929591} - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}] "ImagePath"="\??\c:\program files (x86)\Ronny\Media Players\PowerDVD10Ultra\PowerDVD10\NavFilter\000.fcl" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\.Default\Software\SetId\Internal] @Denied: (A 2) (LocalSystem) "DATA2"="<settings accountStatus=\"3\" oldDevice=\"\" timeDiff=\"-12\" expireTime=\"1306148986\" productStatus=\"1\" obSize=\"0\" InstallIS=\"1289332796\" isSubsc=\"0\" authStat_is=\"0\" version=\"14.1\" keyType=\"195\" prodId=\"2\" moduleId1=\"8\" moduleId2=\"0\" relType=\"0\" />\0a" . [HKEY_USERS\S-1-5-21-3684313654-1291478289-3967929469-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3684313654-1291478289-3967929469-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Voltooingstijd: 2011-05-01 13:23:15 ComboFix-quarantined-files.txt 2011-05-01 11:23 . Pre-Run: 158.415.052.800 bytes beschikbaar Post-Run: 158.904.172.544 bytes beschikbaar . - - End Of File - - B25A11446ACAA9519CCBA009BCAEDCA7
  2. Hijack uitgevoerd zoals beschreben. Geen malware gevonden Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Databaseversie: 6483 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 1/05/2011 12:16:56 mbam-log-2011-05-01 (12-16-56).txt Scantype: Snelle scan Objecten gescand: 162919 Verstreken tijd: 3 minuut/minuten, 2 seconde(n) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 0 Registerwaarden geïnfecteerd: 0 Registerdata geïnfecteerd: 0 Mappen geïnfecteerd: 0 Bestanden geïnfecteerd: 0 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registersleutels geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerwaarden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerdata geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Mappen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Bestanden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Nieuwe Hijack Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:20:30, on 1/05/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v8.00 (8.00.7601.17514) Boot mode: Normal Running processes: C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe" O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [iSPMonitor] D:\\isp.exe O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: ISP Monitor (ISPMonitorSrv) - How2 Studios - C:\Program Files (x86)\ISP Monitor\ISPMonitorSrv.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\Windows\ O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe O23 - Service: BitDefender Desktop Update Service (Updatesrv) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10078 bytes
  3. Het is een zelf samengestelde pc, geschikt voor Win7 mobo : MSI K9N SLI Athlon 64 x2 6000+ 4GB DDR2 OCZ Na installatie zijn alle drivers geïnstalleerd en in apparaatbeheer geen gele uitroeptekens. Alvast bedankt voor de snelle reacties, hieronder Hijackthis logje Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:13:55, on 1/05/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v8.00 (8.00.7601.17514) Boot mode: Normal Running processes: C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {87775fdb-6972-41f9-ae51-8326e38cb206} - (no file) R3 - URLSearchHook: (no name) - {2d8d9acc-f6d7-4362-8876-a275ca929591} - (no file) O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe" O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [iSPMonitor] D:\\isp.exe O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: ISP Monitor (ISPMonitorSrv) - How2 Studios - C:\Program Files (x86)\ISP Monitor\ISPMonitorSrv.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\Windows\ O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe O23 - Service: BitDefender Desktop Update Service (Updatesrv) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10451 bytes
  4. Hallo, ik heb het volgend probleem: PC loopt willekeurig vast, soms na 10 min, soms na een uur of twee. Ik krijg geen foutmelding of blue screen, maakt ook niet uit met wat ik bezig ben. CTRL+ALT+DEL werkt ook niet. Wat heb ik al gedaan: * Scannen op virussen - geen resultaat * Volledig nieuwe installatie W7 64bit - geen resultaat, probleem blijft bestaan * Mijn graka Asus HD5770 vervangen door mijn oude IceQ HD 2600 XT - geen resultaat, zelfde probleem * Mijn voeding Antec 480W vervangen door een 450W voeding (jammer genoeg had ik geen zwaardere voeding ter beschikking) - geen resultaat, probleem blijft bestaan * Alle koelers schoon geblazen (daar kwam nogal wat uit) * Benchmarks en andere progs die het systeem belasten laten draaien - geen problemen gehad hiermee, alles ging vlot * Test programma voor harde schijf - alle HD's in orde * Memtest - geheugen in orde Dus na dit alles zou ik het niet meer weten. Het herstarten gaat ook niet altijd even vlot. Soms blijft hij gewoon hangen tijdens het opstarten, soms doet hij eerst een diskcheck. Het opstarten gaat ook wel trager dan normaal, zelfs na het opnieuw installeren van W7. Als er iemand nog ideeën heeft, ik hoor het graag.
  5. Hallo, kan er mij misschien iemand zeggen welke van onderstaande AGP kaarten de beste aankoop zou zijn. Geforce 7900GS XFX 512MB - 132€ ATI X1950pro 256MB - 139€ Radeon X850XT 256MB - 99€ ATI X1650 PRO 512MB - 75,9€ ATI HD2600 PRO 512MB - 87€ ATI RX2600 PRO 256MB - 99€ Alvast bedankt
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.