Ga naar inhoud

Probleen Avast GrimeFighter


Aanbevolen berichten

Logfile of random's system information tool 1.10 (written by random/random)
Run by Gebruiker at 2015-08-18 09:36:45
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 363 GB (76%) free of 477 GB
Total RAM: 3488 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:36:59, on 18-8-2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\Samsung\Kies\Kies.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Gebruiker\Downloads\RSIT(4).exe
C:\Program Files\trend micro\Gebruiker.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ipernity.com/home/294067
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Emsisoft Protection Service (a2AntiMalware) - Emsisoft Ltd - C:\Program Files\Emsisoft Anti-Malware\a2service.exe
O23 - Service: Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: HitmanPro 3.7 Crusader (HitmanPro37Crusader) - SurfRight B.V. - C:\Program Files\HitmanPro\HitmanPro.exe
O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe
O23 - Service: HitmanPro.Alert Service (hmpalertsvc) - SurfRight B.V. - C:\Program Files\HitmanPro.Alert\hmpalert.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe

--
End of file - 5641 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe  

=========Mozilla firefox=========

ProfilePath - C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\om83l57t.default-1432806240564

prefs.js - "browser.startup.homepage" -  "http://www.ipernity.com/home/294067"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1217157.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-12 559624]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-06-11 10996368]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-08-12 6109776]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2015-04-28 311616]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"=C:\Program Files\Samsung\Kies\Kies.exe [2015-04-28 1566016]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-04-23 6278424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 330752]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2015-08-17 10:28:22 ----A---- C:\Windows\File Renamer - Basic Uninstaller.exe
2015-08-17 10:28:21 ----D---- C:\Program Files\File Renamer
2015-08-14 19:32:47 ----D---- C:\Program Files\Common Files\Wondershare
2015-08-14 19:32:42 ----D---- C:\Program Files\Wondershare
2015-08-14 10:05:50 ----D---- C:\Program Files\Mozilla Firefox
2015-08-13 17:28:07 ----D---- C:\Users\Gebruiker\AppData\Roaming\PersBackup5
2015-08-12 15:17:37 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\invagent.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\generaltel.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\devinv.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-12 10:09:04 ----A---- C:\Windows\system32\appraiser.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\aepdu.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\aeinv.dll
2015-08-12 10:09:04 ----A---- C:\Windows\system32\acmigration.dll
2015-08-12 10:09:03 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-12 10:09:03 ----A---- C:\Windows\system32\wucltux.dll
2015-08-12 10:09:03 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-12 10:09:03 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-12 10:09:03 ----A---- C:\Windows\system32\wuapi.dll
2015-08-12 10:09:02 ----A---- C:\Windows\system32\wups2.dll
2015-08-12 10:09:02 ----A---- C:\Windows\system32\wups.dll
2015-08-12 10:09:02 ----A---- C:\Windows\system32\wudriver.dll
2015-08-12 10:09:02 ----A---- C:\Windows\system32\wuapp.exe
2015-08-12 10:09:02 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-12 10:09:02 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-12 10:08:56 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-12 10:08:56 ----A---- C:\Windows\system32\davclnt.dll
2015-08-12 10:08:55 ----A---- C:\Windows\system32\notepad.exe
2015-08-12 10:08:55 ----A---- C:\Windows\notepad.exe
2015-08-12 10:08:50 ----A---- C:\Windows\system32\mstscax.dll
2015-08-12 10:08:48 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-12 10:08:48 ----A---- C:\Windows\system32\aaclient.dll
2015-08-12 10:08:44 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-12 10:08:43 ----A---- C:\Windows\system32\sysmain.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\srcore.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\smss.exe
2015-08-12 10:08:43 ----A---- C:\Windows\system32\schannel.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\rstrui.exe
2015-08-12 10:08:43 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\ntkrnlpa.exe
2015-08-12 10:08:43 ----A---- C:\Windows\system32\ntdll.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\kerberos.dll
2015-08-12 10:08:43 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-12 10:08:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-12 10:08:43 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\wdigest.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\sspicli.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\srclient.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\secur32.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\msobjs.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\msaudite.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\lsass.exe
2015-08-12 10:08:42 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-12 10:08:42 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-12 10:08:42 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-12 10:08:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-12 10:08:42 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\credssp.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\auditpol.exe
2015-08-12 10:08:42 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-12 10:08:42 ----A---- C:\Windows\system32\adtschema.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\win32k.sys
2015-08-12 10:08:23 ----A---- C:\Windows\system32\lpk.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\fontsub.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\FntCache.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\DWrite.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\dciman32.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\atmlib.dll
2015-08-12 10:08:23 ----A---- C:\Windows\system32\atmfd.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\urlmon.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 10:08:19 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\iernonce.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-12 10:08:19 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-12 10:08:19 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-12 10:08:18 ----A---- C:\Windows\system32\vbscript.dll
2015-08-12 10:08:18 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-12 10:08:18 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-12 10:08:18 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-12 10:08:18 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-12 10:08:18 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-12 10:08:18 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-12 10:08:17 ----A---- C:\Windows\system32\wininet.dll
2015-08-12 10:08:17 ----A---- C:\Windows\system32\msrating.dll
2015-08-12 10:08:17 ----A---- C:\Windows\system32\jscript.dll
2015-08-12 10:08:17 ----A---- C:\Windows\system32\iesetup.dll
2015-08-12 10:08:17 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 10:08:16 ----A---- C:\Windows\system32\ieui.dll
2015-08-12 10:08:16 ----A---- C:\Windows\system32\ieframe.dll
2015-08-12 10:08:16 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-12 10:08:14 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-12 10:08:14 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-12 10:08:14 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-12 10:08:13 ----A---- C:\Windows\system32\mshtml.dll
2015-08-12 10:08:13 ----A---- C:\Windows\system32\jscript9.dll
2015-08-12 10:08:12 ----A---- C:\Windows\system32\iertutil.dll
2015-08-12 10:07:57 ----A---- C:\Windows\system32\shell32.dll
2015-08-12 10:07:51 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-12 10:07:38 ----A---- C:\Windows\system32\basesrv.dll
2015-08-12 10:06:28 ----A---- C:\Windows\system32\msxml3.dll
2015-08-12 10:06:27 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-12 10:06:27 ----A---- C:\Windows\system32\msxml6.dll
2015-08-12 10:06:27 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-12 10:04:38 ----D---- C:\Program Files\BookWright
2015-08-12 09:37:32 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2015-08-12 09:37:22 ----A---- C:\Windows\system32\aswBoot.exe
2015-08-12 09:37:15 ----A---- C:\Windows\avastSS.scr
2015-08-12 09:36:35 ----A---- C:\Windows\system32\drivers\aswNdisFlt.sys
2015-08-11 08:18:25 ----A---- C:\Windows\system32\drivers\41794517.sys
2015-08-09 17:03:59 ----D---- C:\Users\Gebruiker\AppData\Roaming\Windows Live Writer
2015-08-09 08:47:16 ----A---- C:\Windows\system32\drivers\20DD3EE8.sys
2015-07-29 09:28:13 ----A---- C:\Windows\system32\drivers\35A902C9.sys
2015-07-28 14:09:12 ----A---- C:\Windows\system32\drivers\73D80BB5.sys
2015-07-27 14:13:14 ----D---- C:\Program Files\MyFree Codec
2015-07-26 13:42:41 ----A---- C:\Windows\system32\drivers\ngvss.sys
2015-07-20 11:08:15 ----A---- C:\Windows\system32\FlashPlayerApp.exe

======List of files/folders modified in the last 1 month======

2015-08-18 09:36:55 ----D---- C:\Windows\CryptoGuard
2015-08-18 09:36:48 ----D---- C:\Program Files\Trend Micro
2015-08-18 09:36:09 ----D---- C:\Windows\Temp
2015-08-18 09:32:31 ----D---- C:\Program Files\Emsisoft Anti-Malware
2015-08-18 09:22:19 ----SHD---- C:\System Volume Information
2015-08-18 09:09:20 ----A---- C:\Windows\system32\log.txt
2015-08-18 09:08:43 ----D---- C:\Windows\system32\drivers
2015-08-18 09:06:53 ----D---- C:\Windows\system32\config
2015-08-17 16:30:47 ----D---- C:\Windows\inf
2015-08-17 16:30:12 ----D---- C:\Windows
2015-08-17 13:33:03 ----D---- C:\Windows\Minidump
2015-08-17 13:33:03 ----D---- C:\Windows\Logs
2015-08-17 13:33:03 ----D---- C:\Windows\debug
2015-08-17 13:32:56 ----D---- C:\Windows\system32\Tasks
2015-08-17 11:23:58 ----D---- C:\rsit
2015-08-17 10:29:06 ----SHD---- C:\Windows\Installer
2015-08-17 10:28:21 ----D---- C:\Program Files
2015-08-16 09:31:47 ----D---- C:\Windows\System32
2015-08-14 19:38:00 ----D---- C:\ProgramData
2015-08-14 19:32:47 ----D---- C:\Program Files\Common Files
2015-08-14 18:35:29 ----D---- C:\Windows\rescache
2015-08-14 16:37:36 ----D---- C:\Program Files\Mozilla Maintenance Service
2015-08-13 12:33:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-13 10:20:55 ----D---- C:\Windows\Microsoft.NET
2015-08-13 10:19:45 ----RSD---- C:\Windows\assembly
2015-08-13 09:51:15 ----D---- C:\Program Files\Common Files\Adobe AIR
2015-08-13 09:49:26 ----D---- C:\Windows\Tasks
2015-08-12 16:25:46 ----D---- C:\Windows\winsxs
2015-08-12 16:22:22 ----SD---- C:\Windows\system32\CompatTel
2015-08-12 16:22:19 ----D---- C:\Windows\system32\appraiser
2015-08-12 16:22:18 ----D---- C:\Windows\AppPatch
2015-08-12 16:22:16 ----D---- C:\Windows\system32\nl-NL
2015-08-12 16:22:02 ----D---- C:\Windows\system32\drivers\nl-NL
2015-08-12 16:21:50 ----D---- C:\Windows\system32\en-US
2015-08-12 16:21:36 ----D---- C:\Program Files\Internet Explorer
2015-08-12 15:26:39 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-12 15:24:20 ----D---- C:\Windows\system32\MRT
2015-08-12 15:21:23 ----A---- C:\Windows\system32\MRT.exe
2015-08-12 10:06:04 ----D---- C:\Windows\system32\catroot2
2015-08-12 09:38:47 ----D---- C:\Windows\system32\DriverStore
2015-08-09 17:11:20 ----D---- C:\Windows\Prefetch
2015-08-05 16:46:32 ----SHD---- C:\$RECYCLE.BIN
2015-07-30 16:40:19 ----D---- C:\Recovery
2015-07-30 14:17:16 ----D---- C:\zoek_backup
2015-07-30 14:14:50 ----D---- C:\Users\Gebruiker\AppData\Roaming\ZHP
2015-07-30 14:11:44 ----D---- C:\Qoobox
2015-07-30 14:10:29 ----D---- C:\Program Files\ZHPDiag
2015-07-30 14:10:29 ----D---- C:\Program Files\Windows XP Mode
2015-07-30 14:10:13 ----D---- C:\AdwCleaner
2015-07-30 14:09:59 ----D---- C:\ProgramData\Mozilla
2015-07-28 09:44:50 ----D---- C:\Windows\SoftwareDistribution
2015-07-27 11:09:44 ----D---- C:\Windows\system32\vbox
2015-07-25 09:42:37 ----SD---- C:\Windows\system32\GWX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2015-08-12 275856]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-08-12 49776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-08-12 208664]
R0 ngvss;ngvss; C:\Windows\system32\drivers\ngvss.sys [2015-08-12 95112]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2012-08-10 46096]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2015-08-12 26096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-08-12 81728]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-08-12 788784]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-08-12 433264]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 epp32;epp32; C:\Windows\system32\DRIVERS\epp32.sys [2015-03-24 111368]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 295936]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-08-12 24016]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-08-12 76000]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-08-12 113592]
R2 hmpalert;HitmanPro.Alert Support Driver; \??\C:\Windows\system32\drivers\hmpalert.sys [2014-04-09 75640]
R2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-07-26 220752]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2013-11-07 3768320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-06-19 3240400]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x86.sys [2011-08-11 88176]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 23256]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-08-18 98520]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 51928]
R3 MEI;Intel® Management Engine Interface; C:\Windows\system32\drivers\HECI.sys [2010-10-19 41088]
R3 vpcbus;Hostbusservice voor Virtual PC; C:\Windows\system32\drivers\vpchbus.sys [2009-09-23 165376]
R3 vpcusb;Connectorservice voor USB-virtualisatie; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 78336]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\C:\Users\GEBRUI~1\AppData\Local\Temp\catchme.sys []
S3 cpuz135;cpuz135; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x32.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-06-16 89856]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 39272]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-06-16 184192]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136]
S3 usbscan;Stuurprogramma voor USB-scanner; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Stuurprogramma voor VIA C7-processor; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 a2AntiMalware;Emsisoft Protection Service; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2015-05-26 5155576]
R2 AdobeActiveFileMonitor11.0;Adobe Active File Monitor V11; C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [2012-09-23 171600]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-08-12 146600]
R2 avast! Firewall;Avast Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2015-08-12 109008]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2015-07-01 106248]
R2 hmpalertsvc;HitmanPro.Alert Service; C:\Program Files\HitmanPro.Alert\hmpalert.exe [2014-04-09 1876816]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [2015-03-28 89840]
R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-06-18 1871160]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 UNS;Intel® Management and Security Application User Notification Service; C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-07-26 3218624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 cphs;Intel® Content Protection HECI Service; C:\Windows\system32\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 HitmanPro37Crusader;HitmanPro 3.7 Crusader; C:\Program Files\HitmanPro\HitmanPro.exe [2015-07-01 10113976]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-14 149160]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-10-02 1343400]
S4 aspnet_state;ASP.NET-statusservice; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------
 

Link naar reactie
Delen op andere sites

Hoe nu verder. Ik weet niet zo goed wat en waar ik moet plaatsen ??

 

Een overzicht:

- De oorspronkelijke vraag van deze discussie (Avast GrimeFighter)  is een paar dagen geleden automatisch opgelost na het beschikbaar komen van de opvolger Avast Cleanup.

- Ik heb nog steeds vastlopers bij het openen van sites met video's en/of geluid. Lijkt mij een 'onoplosbaar' probleem tussen Firefox en Flash

- Collectieve bestandsnaam wijziging is opgelost met het antwoord van '' Passer

- Staat nog open m'n vraag over 'Naam van een opslagmap wijzigen'

"Door schade en schande (CTB locker virus) wijs geworden ben ik bezig back-up's van mijn fotoboeken te maken op een externe harde schijf.

 

Na het back-uppen van een eerste boek wilde ik kijken of eea goed was gegaan een probeerde het betreffende boek te openen en kreeg een pop-up venster met de vraag met welk programma ik dat wilde doen. Ik koos toen voor Acrobat Reader, wat niets opleverde.

 

Maar alle andere boeken waarvan ik ook een back-up maakte worden automatisch in een Acrobat Reader Map opgeslagen.

 

Kan ik dat wijzigen en ook dat 'automatisme' stoppen ???"

 
Link naar reactie
Delen op andere sites

Die back-ups van alle voor jou belangrijke data, die zou je eigenlijk sowieso al "van in den beginne" moeten gehad hebben en dat liefst op minimum twee verschillende geheugendragers.

 

Als ik de historiek van de problemen op deze PC bekijk (je vorige topics) en de looptijd van dit topic, dan kan ik maar één ding besluiten: het is hoog tijd voor een nieuwe en frisse start met volledige herinstallatie van je Windows 7.

 

Maak na de herinstallatie en het installeren van de updates een volledige kopie (image) van je PC ... altijd een voordeel als je zo'n ultieme noodrem met bijhorend opstartmedium in de buurt hebt ... image nummer twee kan je maken nadat alle software geïnstalleerd is en je alle persoonlijke bestanden en instellingen hebt teruggeplaatst / aangepast.

 

Wil je het veilig houden, stockeer dan deze images ook dubbel, dus op twee verschillende externe harde schijven.

Link naar reactie
Delen op andere sites

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.