Mededeling

Collapse
No announcement yet.

Ernstige besmetting

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Ernstige besmetting

    Ingesloten een 2-tal log reports: Malwarebytes en Combofix.
    Deze zijn gemaakt nadat er handmatig een zeer groot aantal besmettingen is verwijderd.
    Wat mij betreft: de categorie ernstige besmettingen.
    Dat aantal was in de orde van ca. 53000 besmettingen.

    Deze aantallen zijn opgespoord door Microsoft Securiy Essentials, liep daarbij vast;
    Deze aantalen zijn op opgespoord door MalwareBytes, liep daarbij vast;
    Combofix deed het bij deze aantallen ook niet lekker. Het programma kwam tot een regulier einde.

    Vervolgens heb ik de mappen Quarantaine van Malware Bytes opgezocht en deze handmatig leeggemaakt (ca. 53.000 items instappen van maximaal 5.000 items) en Qoobex van Combofix opgezocht en deze handmatig leeggemaakt (eveneens ca. 53.000 items).
    Daarna het systeem opnieuw opgestart en in deze volgorde gedraaid:
    Combofix en vervolgens Malwarebytes (volledige scan);

    De logfiles tonen nog enkele problemen,

    Logfile Malwarebytes:
    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Databaseversie: v2013.07.10.02

    Windows Vista Service Pack 1 x86 NTFS
    Internet Explorer 7.0.6001.18000
    Melanie :: PC_VAN_MELANIE [administrator]

    10-7-2013 20:15:13
    mbam-log-2013-07-10 (20-15-13).txt

    Scan type: Snelle scan
    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scan opties: P2P
    Objecten gescand: 215966
    Verstreken tijd: 7 minuut/minuten, 40 seconde(n)

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 9
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) -> Geen actie ondernomen.
    HKCR\AppID\{80EF304A-B1C4-425C-8535-95AB6F1EEFB8} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCR\Typelib\{E0F01490-DCF3-4357-95AA-169A8C2B2190} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCR\Interface\{17E44256-51E0-4D46-A0C8-44E80AB4BA5B} (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} (Backdoor.Bot) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCR\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCU\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCU\SOFTWARE\Microsoft\fias4051 (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.
    HKCU\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 7
    C:\Users\Melanie\Desktop\installer_itunes_8_1_1_10_(32_bits)_Nederlands_Dutch.exe (PUP.SmsPay.pns) -> Geen actie ondernomen.
    C:\ProgramData\wigimogo\wigimogo.exe (Trojan.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd.
    C:\ProgramData\yofolufe\yofolufe.exe (Trojan.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd.
    C:\ProgramData\yujodiju\yujodiju.exe (Trojan.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd.
    C:\ProgramData\pegojehe\pegojehe.exe (Trojan.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd.
    C:\ProgramData\Microsoft\Media Index\svchos.exe (Trojan.FakeAlert) -> Succesvol in quarantaine geplaatst en verwijderd.
    C:\ProgramData\Microsoft\Media Index\t.id (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)

    Logfile Combofix

    ComboFix 13-07-13.01 - Melanie 13-07-2013 18:26:58.4.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.3070.1434 [GMT 2:00]
    Gestart vanuit: c:\users\Melanie\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
    SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    Besmet exemplaar van c:\windows\system32\userinit.exe werd aangetroffen en gedesinfecteerd
    Hersteld exemplaar van - c:\windows\erdnt\cache\userinit.exe
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2013-06-13 to 2013-07-13 ))))))))))))))))))))))))))))))
    .
    .
    2013-07-13 16:36 . 2013-07-13 16:36 60872 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1F73C8F-B953-4A27-9C6B-4126B2FC0270}\offreg.dll
    2013-07-13 16:35 . 2013-07-13 16:35 -------- d-----w- c:\users\Default\AppData\Local\temp
    2013-07-13 07:05 . 2013-06-17 00:10 7068072 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1F73C8F-B953-4A27-9C6B-4126B2FC0270}\mpengine.dll
    2013-07-11 07:49 . 2013-06-19 03:02 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2013-07-11 07:49 . 2013-06-19 03:02 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F244DAB5-ECEC-4823-B772-094A29C99612}\gapaengine.dll
    2013-07-11 07:47 . 2013-06-17 00:10 7068072 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2013-07-11 07:06 . 2013-07-11 07:07 -------- d-----w- c:\program files\Microsoft Security Client
    2013-07-10 18:41 . 2013-07-10 18:41 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-07-10 18:33 . 2013-07-10 18:33 -------- d-----w- c:\program files\CCleaner
    2013-07-10 07:35 . 2013-07-10 07:35 -------- d-----w- c:\users\Melanie\AppData\Roaming\Malwarebytes
    2013-07-10 07:35 . 2013-07-10 07:35 -------- d-----w- c:\programdata\Malwarebytes
    2013-07-10 07:35 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2013-07-10 07:35 . 2013-07-10 07:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2013-06-20 11:29 . 2013-06-20 11:29 -------- d-----w- C:\found.001
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-07-10 18:41 . 2011-06-07 12:04 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-06-12 04:18 . 2013-07-10 22:54 7068072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CC001500-7A41-4989-9017-81754FCCBB55}\mpengine.dll
    2013-05-09 08:58 . 2011-07-17 21:17 229648 ----a-w- c:\windows\system32\aswBoot.exe
    2013-05-02 15:28 . 2009-10-02 19:56 238872 ------w- c:\windows\system32\MpSigStub.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-06-24 247144]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-04-19 18678376]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
    "Skytel"="Skytel.exe" [2008-06-25 1826816]
    "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400]
    "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768]
    "HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416]
    "LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
    "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2007-09-07 86016]
    "UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
    "OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\SEARCH~1\Datamngr\datamngr.dll c:\progra~1\SEARCH~1\Datamngr\IEBHO.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
    2005-06-06 21:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
    2007-10-03 13:44 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
    2007-10-11 17:01 46368 ----a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2011-06-07 15:51 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
    2011-06-24 13:54 941968 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
    2011-06-24 13:54 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
    2011-06-24 13:54 3373968 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
    2001-06-08 13:29 147456 ------w- c:\windows\System32\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
    2007-10-11 17:03 29984 ----a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
    2007-07-05 10:35 94208 ----a-w- c:\windows\PLFSetL.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
    2007-08-31 07:01 328992 ----a-w- c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
    2011-06-15 06:19 307200 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
    2006-10-25 07:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2009-01-14 15:20 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\toolbar_eula_launcher]
    2007-02-09 13:54 16896 ----a-w- c:\program files\GoogleEULA\EULALauncher.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-06-22 15:34 1165776 ----a-w- c:\program files\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2013-07-13 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-10 18:41]
    .
    2013-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 18:12]
    .
    2013-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 18:12]
    .
    .
    ------- Bijkomende Scan -------
    .
    uStart Page = hxxp://www.google.nl/
    uInternet Settings,ProxyOverride = *.local
    IE: Add to Video Converter... - c:\program files\Media Player Utilities 5.22\AVIConverter\grab.html
    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    TCP: DhcpNameServer = 192.168.2.254
    DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://foto.hema.nl/ips-opdata/layout/hema/objects/jordan.cab
    .
    - - - - ORPHANS VERWIJDERD - - - -
    .
    MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe
    .
    .
    .
    **************************************************************************
    scannen van verborgen processen ...
    .
    scannen van verborgen autostart items ...
    .
    scannen van verborgen bestanden ...
    .
    Scan succesvol afgerond
    verborgen bestanden:
    .
    **************************************************************************
    .
    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    --------------------- DLLs Geladen Onder Lopende Processen ---------------------
    .
    - - - - - - - > 'Explorer.exe'(2464)
    c:\program files\Softex\OmniPass\SCUREDLL.dll
    .
    ------------------------ Andere Aktieve Processen ------------------------
    .
    c:\windows\system32\nvvsvc.exe
    c:\program files\Softex\OmniPass\OmniServ.exe
    c:\program files\Microsoft Security Client\MsMpEng.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    c:\program files\CyberLink\Shared Files\RichVideo.exe
    c:\program files\TomTom HOME 2\TomTomHOMEService.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Microsoft Security Client\NisSrv.exe
    c:\windows\system32\conime.exe
    c:\windows\RtHDVCpl.exe
    c:\program files\Softex\OmniPass\opvapp.exe
    c:\windows\ehome\ehmsas.exe
    c:\program files\Launch Manager\WisLMSvc.exe
    .
    **************************************************************************
    .
    Voltooingstijd: 2013-07-13 18:42:54 - machine werd herstart
    ComboFix-quarantined-files.txt 2013-07-13 16:42
    .
    Pre-Run: 136.881.315.840 bytes beschikbaar
    Post-Run: 137.052.528.640 bytes beschikbaar
    .
    - - End Of File - - F67717DFB9D592B6576B817B08A88ADF
    5C616939100B85E558DA92B899A0FC36

    Graag jullie deskundige reactie

    groetjes
    Gerard Roelands

  • #2
    Volg even deze instructies: http://www.nucia.eu/forum/threads/12...ericht-plaatst!
    MBAM was trouwens niet geupdate.

    Comment


    • #3
      Marckie,

      Excuus voor mijn onzorgvuldigheid. Ik had natuurlijk eerst de laatste instructies moeten lezen.

      Ingesloten de gevraagde logfiles:
      Stap 1 - Uitschakelen emulatiesoftware.
      defogger_disable by jpshortstuff (23.02.10.1)
      Log created at 21:35 on 13/07/2013 (Melanie)

      Checking for autostart values...
      HKCU\~\Run values retrieved.
      HKLM\~\Run values retrieved.

      Checking for services/drivers...


      -=E.O.F=-

      Stap 2 - Malwarebytes
      Malwarebytes Anti-Malware 1.75.0.1300
      www.malwarebytes.org

      Databaseversie: v2013.07.13.06

      Windows Vista Service Pack 1 x86 NTFS
      Internet Explorer 7.0.6001.18000
      Melanie :: PC_VAN_MELANIE [administrator]

      13-7-2013 21:51:23
      mbam-log-2013-07-13 (21-51-23).txt

      Scan type: Snelle scan
      Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
      Uitgeschakelde scan opties: P2P
      Objecten gescand: 215310
      Verstreken tijd: 3 minuut/minuten, 53 seconde(n)

      Geheugenprocessen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Geheugenmodulen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registersleutels gedetecteerd: 1
      HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) -> Succesvol in quarantaine geplaatst en verwijderd.

      Registerwaarden gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registerdata gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Mappen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Bestanden gedetecteerd: 1
      C:\Users\Melanie\Desktop\installer_itunes_8_1_1_10_(32_bits)_Nederlands_Dutch.exe (PUP.SmsPay.pns) -> Succesvol in quarantaine geplaatst en verwijderd.

      (einde)

      Stap 3 - DDS
      DDS.txt
      DDS (Ver_2012-11-20.01) - NTFS_x86
      Internet Explorer: 7.0.6001.18639
      Run by Melanie at 22:27:26 on 2013-07-13
      Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.3070.1661 [GMT 2:00]
      .
      AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
      SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
      .
      ============== Running Processes ================
      .
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\nvvsvc.exe
      C:\Program Files\Softex\OmniPass\OmniServ.exe
      c:\Program Files\Microsoft Security Client\MsMpEng.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\rundll32.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\WUDFHost.exe
      c:\Program Files\Microsoft Security Client\NisSrv.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Program Files\Launch Manager\LaunchAp.exe
      C:\Program Files\Launch Manager\HotkeyApp.exe
      C:\Program Files\Launch Manager\OSD.exe
      C:\Program Files\Softex\OmniPass\opvapp.exe
      C:\Program Files\Launch Manager\WButton.exe
      C:\Program Files\Softex\OmniPass\scureapp.exe
      C:\Program Files\Launch Manager\WisLMSvc.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Microsoft Security Client\msseces.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
      C:\Windows\servicing\TrustedInstaller.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\svchost.exe -k DcomLaunch
      C:\Windows\system32\svchost.exe -k rpcss
      C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
      C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
      C:\Windows\system32\svchost.exe -k netsvcs
      C:\Windows\system32\svchost.exe -k LocalService
      C:\Windows\system32\svchost.exe -k NetworkService
      C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
      C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
      C:\Windows\system32\svchost.exe -k imgsvc
      C:\Windows\System32\svchost.exe -k WerSvcGroup
      .
      ============== Pseudo HJT Report ===============
      .
      uStart Page = hxxp://www.google.nl/
      BHO: Adobe PDF Reader Help bij koppelingen: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
      BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
      BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - <orphaned>
      BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
      BHO: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
      BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll
      BHO: ChromeFrame BHO: {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - c:\program files\google\chrome frame\application\28.0.1500.71\npchrome_frame.dll
      TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
      TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
      uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
      uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
      uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
      uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
      uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
      mRun: [RtHDVCpl] RtHDVCpl.exe
      mRun: [Skytel] Skytel.exe
      mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
      mRun: [LaunchAp] "c:\program files\launch manager\LaunchAp.exe"
      mRun: [HotkeyApp] "c:\program files\launch manager\HotkeyApp.exe"
      mRun: [LMgrOSD] "c:\program files\launch manager\OSD.exe"
      mRun: [Wbutton] "c:\program files\launch manager\Wbutton.exe"
      mRun: [UCam_Menu] "c:\program files\homecinema\youcam\muitransfer\muistartmenu.exe" "c:\program files\homecinema\youcam" update "software\cyberlink\youcam\1.0"
      mRun: [OmniPass] c:\program files\softex\omnipass\scureapp.exe
      mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
      mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
      mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
      uPolicies-Explorer: NoDrives = dword:0
      mPolicies-Explorer: NoDrives = dword:0
      mPolicies-System: EnableUIADesktopToggle = dword:0
      IE: Add to Video Converter... - c:\program files\media player utilities 5.22\aviconverter\grab.html
      IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
      IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
      IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
      IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
      DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://foto.hema.nl/ips-opdata/layout/hema/objects/jordan.cab
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
      DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
      TCP: NameServer = 192.168.2.254
      TCP: Interfaces\{57EB6FD0-BC39-474A-9970-7BA1448E80E8} : DHCPNameServer = 192.168.2.254
      TCP: Interfaces\{6B4AC2FB-5E0C-4145-9A1A-E0AD425B7A81} : DHCPNameServer = 192.168.2.254
      Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\28.0.1500.71\npchrome_frame.dll
      Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
      Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
      AppInit_DLLs= c:\progra~1\search~1\datamngr\datamngr.dll c:\progra~1\search~1\datamngr\IEBHO.dll
      LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
      mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\28.0.1500.72\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
      .
      ============= SERVICES / DRIVERS ===============
      .
      R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
      R0 Si3531;SiI-3531 SATA Controller;c:\windows\system32\drivers\Si3531.sys [2007-6-1 210736]
      R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-1-20 100328]
      R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-6-24 92008]
      R3 NeroCd2k;NeroCd2k;c:\windows\system32\drivers\NeroCD2k.sys [2001-4-16 44227]
      R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]
      R3 WisLMSvc;WisLMSvc;c:\program files\launch manager\WisLMSvc.exe [2008-7-17 118784]
      S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
      S2 gupdate1c9ca885e58df8b;Google Updateservice (gupdate1c9ca885e58df8b);c:\program files\google\update\GoogleUpdate.exe [2009-5-1 133104]
      S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384]
      S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-7-25 30312]
      S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2011-7-25 36608]
      S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-7-25 96488]
      S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-7-25 12776]
      S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-7-25 121576]
      S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2011-7-25 98152]
      S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
      .
      =============== Created Last 30 ================
      .
      2013-07-13 20:21:49 60872 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b1f73c8f-b953-4a27-9c6b-4126b2fc0270}\offreg.dll
      2013-07-13 16:36:55 -------- d-----w- C:\$RECYCLE.BIN
      2013-07-13 16:25:49 -------- d-----w- C:\ComboFix
      2013-07-13 07:05:44 7068072 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b1f73c8f-b953-4a27-9c6b-4126b2fc0270}\mpengine.dll
      2013-07-11 07:49:54 724464 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
      2013-07-11 07:49:54 724464 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f244dab5-ecec-4823-b772-094a29c99612}\gapaengine.dll
      2013-07-11 07:47:24 7068072 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
      2013-07-11 07:06:30 -------- d-----w- c:\program files\Microsoft Security Client
      2013-07-10 22:54:27 7068072 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{cc001500-7a41-4989-9017-81754fccbb55}\mpengine.dll
      2013-07-10 18:41:01 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
      2013-07-10 18:33:38 -------- d-----w- c:\program files\CCleaner
      2013-07-10 10:30:30 98816 ----a-w- c:\windows\sed.exe
      2013-07-10 10:30:30 256000 ----a-w- c:\windows\PEV.exe
      2013-07-10 10:30:30 208896 ----a-w- c:\windows\MBR.exe
      2013-07-10 07:35:44 -------- d-----w- c:\users\melanie\appdata\roaming\Malwarebytes
      2013-07-10 07:35:36 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
      2013-07-10 07:35:36 -------- d-----w- c:\programdata\Malwarebytes
      2013-07-10 07:35:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
      2013-06-20 11:29:13 -------- d-----w- C:\found.001
      .
      ==================== Find3M ====================
      .
      2013-07-10 18:41:01 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
      2013-05-02 15:28:50 238872 ------w- c:\windows\system32\MpSigStub.exe
      .
      ============= FINISH: 22:28:07,58 ===============

      ATTACH.txt
      .
      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT
      .
      DDS (Ver_2012-11-20.01)
      .
      Microsoft® Windows Vista™ Home Premium
      Boot Device: \Device\HarddiskVolume1
      Install Date: 12-9-2008 22:05:14
      System Uptime: 13-7-2013 22:21:15 (0 hours ago)
      .
      Motherboard: MEDION | | WIM2220
      Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz | U2E1 | 1667/mhz
      .
      ==== Disk Partitions =========================
      .
      C: is FIXED (NTFS) - 278 GiB total, 127,3 GiB free.
      D: is FIXED (FAT32) - 20 GiB total, 10,984 GiB free.
      E: is CDROM ()
      G: is Removable
      .
      ==== Disabled Device Manager Items =============
      .
      ==== System Restore Points ===================
      .
      .
      ==== Installed Programs ======================
      .
      Update for Microsoft Office 2007 (KB2508958)
      "Nero SoundTrax Help
      Activation Assistant for the 2007 Microsoft Office suites
      Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
      Adobe Flash Player 11 ActiveX
      Adobe Reader 8.1.2 - Nederlands
      Adobe Reader 8.1.2 Security Update 1 (KB403742)
      Adobe Shockwave Player 11
      Adobe® Photoshop® Album Starter Edition 3.0
      Advertising Center
      Albelli Fotoboeken
      Apple Application Support
      Apple Mobile Device Support
      Apple Software Update
      AuthenTec Fingerprint Sensor Minimum Install
      Barbie(TM) als Zeemeermin
      Barbie(TM) in het Zwanenmeer
      Bonjour
      CCleaner
      Compatibiliteitspakket voor het 2007 Microsoft Office system
      CyberLink PowerDirector
      CyberLink PowerProducer
      CyberLink YouCam
      DolbyFiles
      Google Chrome
      Google Chrome Frame
      Google Earth
      Google Toolbar for Internet Explorer
      Google Update Helper
      Hema Album Software Advanced
      HEMA Fotoservice
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
      iLivid
      ImagXpress
      Inst5657
      Intel(R) Matrix Storage Manager
      iTunes
      Java(TM) 6 Update 7
      Kruidvat fotoservice
      Launch Manager V1.4.9
      MakeDisc
      Malwarebytes Anti-Malware versie 1.75.0.1300
      Media Player Utilities 5.22
      MediaShow
      Menu Templates - Starter Kit
      Microsoft .NET Framework 3.5 Language Pack SP1 - nld
      Microsoft .NET Framework 3.5 SP1
      Microsoft .NET Framework 4 Client Profile
      Microsoft .NET Framework 4 Client Profile NLD Language Pack
      Microsoft Office 2007 Service Pack 3 (SP3)
      Microsoft Office Access MUI (Dutch) 2007
      Microsoft Office Excel MUI (Dutch) 2007
      Microsoft Office File Validation Add-In
      Microsoft Office InfoPath MUI (Dutch) 2007
      Microsoft Office Outlook MUI (Dutch) 2007
      Microsoft Office PowerPoint MUI (Dutch) 2007
      Microsoft Office Professional Plus 2007
      Microsoft Office Proof (Dutch) 2007
      Microsoft Office Proof (English) 2007
      Microsoft Office Proof (French) 2007
      Microsoft Office Proof (German) 2007
      Microsoft Office Proofing (Dutch) 2007
      Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
      Microsoft Office Publisher MUI (Dutch) 2007
      Microsoft Office Shared MUI (Dutch) 2007
      Microsoft Office Word MUI (Dutch) 2007
      Microsoft Security Client
      Microsoft Security Essentials
      Microsoft Silverlight
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
      Movie Templates - Starter Kit
      MSXML 4.0 SP2 (KB936181)
      MSXML 4.0 SP2 (KB941833)
      MSXML 4.0 SP2 (KB954430)
      MSXML 4.0 SP2 (KB973688)
      MyFreeCodec
      Nero - Burning Rom
      Nero 9
      Nero BurningROM
      Nero BurnRights
      Nero ControlCenter
      Nero CoverDesigner
      Nero CoverDesigner Help
      Nero Disc Copy Gadget
      Nero Disc Copy Gadget Help
      Nero DiscSpeed
      Nero DriveSpeed
      Nero Express
      Nero InfoTool
      Nero Installer
      Nero Live
      Nero Live Help
      Nero PhotoSnap
      Nero PhotoSnap Help
      Nero Recode
      Nero Recode Help
      Nero Rescue Agent
      Nero RescueAgent Help
      Nero ShowTime
      Nero StartSmart
      Nero StartSmart Help
      Nero Vision
      Nero WaveEditor
      Nero WaveEditor Help
      NeroBurningROM
      NeroExpress
      neroxml
      NVIDIA Drivers
      OmniPass 5.00.91
      PaperPort Image Printer
      PhotoNow!
      PowerDVD
      PowerISO
      QuickTime
      Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
      Realtek High Definition Audio Driver
      Realtek USB 2.0 Card Reader
      Samsung Kies
      SAMSUNG USB Driver for Mobile Phones
      ScanSoft PaperPort 11
      Search-Results Toolbar
      Security Update for CAPICOM (KB931906)
      Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
      Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
      Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
      Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
      Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
      Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
      Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
      Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
      Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
      Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)
      Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)
      Skype Toolbars
      Skype™ 6.3
      SoundTrax
      Synaptics Pointing Device Driver
      Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL
      Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD
      TomTom HOME 2.7.5.2014
      TomTom HOME Visual Studio Merge Modules
      Ulead PhotoImpact 12
      Update for 2007 Microsoft Office System (KB967642)
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
      Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
      Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
      Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
      Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition
      Update voor Microsoft Office Excel 2007 Help (KB963678)
      Update voor Microsoft Office Powerpoint 2007 Help (KB963669)
      Update voor Microsoft Office Word 2007 Help (KB963665)
      VCRedistSetup
      Windows Live Messenger
      WinRAR archiver
      WoordenSTART Thuis Thema 2
      .
      ==== End Of File ===========================

      Stap 4 - GMER
      GMER 2.1.19163 - http://www.gmer.net
      Rootkit scan 2013-07-13 22:57:06
      Windows 6.0.6001 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD32 rev.11.0 298,09GB
      Running: 3x979tdt.exe; Driver: C:\Users\Melanie\AppData\Local\Temp\pwdcyuow.sys


      ---- Kernel code sections - GMER 2.1 ----

      ? System32\drivers\uilpt.sys Het systeem kan het opgegeven pad niet vinden. !
      .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8F407340, 0x3ECA97, 0xE8000020]
      ? C:\Users\Melanie\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven bestand niet vinden. !

      ---- User code sections - GMER 2.1 ----

      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!DialogBoxIndirectParamW 75EEBD25 5 Bytes JMP 6CC50F0D C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!DialogBoxParamW 75F01FD5 5 Bytes JMP 6CC50E97 C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!DialogBoxParamA 75F280B2 5 Bytes JMP 6CC50ED2 C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!DialogBoxIndirectParamA 75F283DD 5 Bytes JMP 6CC50F48 C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!MessageBoxIndirectA 75F3D471 5 Bytes JMP 6CC50E53 C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!MessageBoxIndirectW 75F3D56B 5 Bytes JMP 6CC50E0F C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!MessageBoxExA 75F3D5D1 1 Byte [E9]
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!MessageBoxExA 75F3D5D1 5 Bytes JMP 6CC50DD5 C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] USER32.dll!MessageBoxExW 75F3D5F5 5 Bytes JMP 6CC50D9B C:\Windows\system32\IEFRAME.dll
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHRestricted + DFD 762D8390 4 Bytes [99, 0B, 0E, 6D] {CDQ ; OR ECX, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHRestricted + E05 762D8398 8 Bytes [A7, 0A, 0E, 6D, A4, 32, 0D, ...]
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHRestricted + FB1 762D8544 4 Bytes [99, 0B, 0E, 6D] {CDQ ; OR ECX, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHRestricted + FB9 762D854C 4 Bytes [A7, 0A, 0E, 6D] {CMPSD ; OR CL, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!ILFree + 5F3 762D9AFC 4 Bytes [99, 0B, 0E, 6D] {CDQ ; OR ECX, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!ILFree + 5FB 762D9B04 4 Bytes [A7, 0A, 0E, 6D] {CMPSD ; OR CL, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHBindToObject + 693 762DA9B8 4 Bytes [99, 0B, 0E, 6D] {CDQ ; OR ECX, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] SHELL32.dll!SHBindToObject + 69B 762DA9C0 4 Bytes [A7, 0A, 0E, 6D] {CMPSD ; OR CL, [ESI]; INS DWORD [ES:EDI], DX}
      .text C:\Program Files\Internet Explorer\iexplore.exe[3392] ole32.dll!OleLoadFromStream 77159794 5 Bytes JMP 6CC51123 C:\Windows\system32\IEFRAME.dll

      ---- User IAT/EAT - GMER 2.1 ----

      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [741E8864] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74229855] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [741EB984] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [741DFB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [741E7A29] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [741DEA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7421B12D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [741EBC4A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [741E0756] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [741E06BD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [741D71B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7426D9E0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74207329] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [741DE109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [741D697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [741D69A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll
      IAT C:\Windows\Explorer.EXE[2912] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [741E2475] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18551_none_9e7a1850c9c1b3d c\gdiplus.dll

      ---- Devices - GMER 2.1 ----

      AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
      AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
      AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys

      ---- Processes - GMER 2.1 ----

      Process (*** hidden *** ) [4] 84D41D58

      ---- Registry - GMER 2.1 ----

      Reg HKLM\SOFTWARE\Classes\CLSID\{B6A930A0-A4F5-43A5-9B4E-6189A6C2B9E8}@{!s!\30!r!{!`!t!c!i!\24!t!j!s!y!s!\24! 19583823

      ---- EOF - GMER 2.1 ----

      Comment


      • #4
        Downloadt TDSSKiller en plaats het op je bureaublad.
        Dubbelklik op TDSSKiller.exe om de tool te starten.
        Klik op "Change parameters" en vink aan:
        - Services and drivers
        - Boot sectors
        - Verify drivers digital signatures
        Klik op "OK"
        Klik op de knop "Start Scan" en volg de instructies.
        Wanneer de scan klaar is klik je op de knop "Report".
        Er opent een kladblokbestand. Post de inhoud van dit bestand.
        Geeft TDSSKiller aan om een bestand te genezen (Cure),dan sta je dit toe. In dit geval wordt gevraagd om de computer te herstarten. Doe dit onmiddellijk.
        De unsigned files skip je.
        Rootkit.Boot.SST.b en anderen zoals Sinowal, ZeroAccess of Whistler laat je herstellen Cure.
        Na reboot vind je de log op c:\ met de naam TDSSKiller.versie_datum_uur_log.txt.
        Post dat logje.

        Comment


        • #5
          Oorspronkelijk geplaatst door Marckie Bekijk Berichten
          Downloadt TDSSKiller en plaats het op je bureaublad.
          Dubbelklik op TDSSKiller.exe om de tool te starten.
          Klik op "Change parameters" en vink aan:
          - Services and drivers
          - Boot sectors
          - Verify drivers digital signatures
          Klik op "OK"
          Klik op de knop "Start Scan" en volg de instructies.
          Wanneer de scan klaar is klik je op de knop "Report".
          Er opent een kladblokbestand. Post de inhoud van dit bestand.
          Geeft TDSSKiller aan om een bestand te genezen (Cure),dan sta je dit toe. In dit geval wordt gevraagd om de computer te herstarten. Doe dit onmiddellijk.
          De unsigned files skip je.
          Rootkit.Boot.SST.b en anderen zoals Sinowal, ZeroAccess of Whistler laat je herstellen Cure.
          Na reboot vind je de log op c:\ met de naam TDSSKiller.versie_datum_uur_log.txt.
          Post dat logje.
          Wanneer de scan klaar is klik je op de knop "Report".
          Er komt geen knop "Report".
          Er zijn bij de scan 6 threats gevonden en ik moet nu een action kiezen en kan dan vervolgens op een knop "Continue" klikken.
          De te maken keuzes zijn: "Skip", "Copy to quarantaine", "Delete".
          Met welke actie moet worden vervolgd?
          Alle gevonden threats hebben status "Unsigned file". Ik ga nu verder met "Skip".
          Last edited by groelands; 14-07-13, 09:58.

          Comment


          • #6
            Dat hangt af van wat er gedetecteerd werd, zie mijn instructies.

            Comment


            • #7
              Fout bij de indiening

              Marckie,

              Bij de indiening van de logfile TDSkiller doet zich een fout voor.
              De melding is als volgt:

              "De ingevoerde tekst is te lang (62034 tekens). Verkort de tekst tot maximaal 50000 tekens."

              Een volgende pagina? Hoe te maken?

              Gerard

              Comment


              • #8
                Je mag het logje gewoon over 2 posts verspreiden hoor.

                Comment


                • #9
                  Dank je, dat wist ik niet.

                  Hier is deel 1 van het TDSkiller log:
                  11:24:20.0108 5380 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
                  11:24:20.0358 5380 ============================================================
                  11:24:20.0358 5380 Current date / time: 2013/07/14 11:24:20.0358
                  11:24:20.0358 5380 SystemInfo:
                  11:24:20.0358 5380
                  11:24:20.0358 5380 OS Version: 6.0.6001 ServicePack: 1.0
                  11:24:20.0358 5380 Product type: Workstation
                  11:24:20.0358 5380 ComputerName: PC_VAN_MELANIE
                  11:24:20.0358 5380 UserName: Melanie
                  11:24:20.0358 5380 Windows directory: C:\Windows
                  11:24:20.0358 5380 System windows directory: C:\Windows
                  11:24:20.0358 5380 Processor architecture: Intel x86
                  11:24:20.0358 5380 Number of processors: 2
                  11:24:20.0358 5380 Page size: 0x1000
                  11:24:20.0358 5380 Boot type: Normal boot
                  11:24:20.0358 5380 ============================================================
                  11:24:21.0294 5380 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
                  11:24:21.0325 5380 ============================================================
                  11:24:21.0325 5380 \Device\Harddisk0\DR0:
                  11:24:21.0325 5380 MBR partitions:
                  11:24:21.0325 5380 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x22C2A800
                  11:24:21.0356 5380 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x22C2B800, BlocksNum 0x2802800
                  11:24:21.0356 5380 ============================================================
                  11:24:21.0481 5380 C: <-> \Device\Harddisk0\DR0\Partition1
                  11:24:21.0497 5380 D: <-> \Device\Harddisk0\DR0\Partition2
                  11:24:21.0497 5380 ============================================================
                  11:24:21.0497 5380 Initialize success
                  11:24:21.0497 5380 ============================================================
                  11:24:37.0892 0636 ============================================================
                  11:24:37.0892 0636 Scan started
                  11:24:37.0892 0636 Mode: Manual; SigCheck;
                  11:24:37.0892 0636 ============================================================
                  11:24:38.0126 0636 ================ Scan system memory ========================
                  11:24:38.0126 0636 System memory - ok
                  11:24:38.0126 0636 ================ Scan services =============================
                  11:24:38.0516 0636 [ FCB8C7210F0135E24C6580F7F649C73C ] ACPI C:\Windows\system32\drivers\acpi.sys
                  11:24:38.0610 0636 ACPI - ok
                  11:24:38.0781 0636 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
                  11:24:38.0797 0636 AdobeFlashPlayerUpdateSvc - ok
                  11:24:38.0828 0636 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
                  11:24:38.0859 0636 adp94xx - ok
                  11:24:39.0015 0636 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
                  11:24:39.0031 0636 adpahci - ok
                  11:24:39.0078 0636 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
                  11:24:39.0093 0636 adpu160m - ok
                  11:24:39.0203 0636 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
                  11:24:39.0218 0636 adpu320 - ok
                  11:24:39.0296 0636 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
                  11:24:39.0327 0636 AeLookupSvc - ok
                  11:24:39.0452 0636 [ 48EB99503533C27AC6135648E5474457 ] AFD C:\Windows\system32\drivers\afd.sys
                  11:24:39.0499 0636 AFD - ok
                  11:24:39.0593 0636 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
                  11:24:39.0593 0636 agp440 - ok
                  11:24:39.0655 0636 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
                  11:24:39.0671 0636 aic78xx - ok
                  11:24:39.0749 0636 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
                  11:24:39.0780 0636 ALG - ok
                  11:24:39.0811 0636 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
                  11:24:39.0827 0636 aliide - ok
                  11:24:39.0889 0636 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
                  11:24:39.0905 0636 amdagp - ok
                  11:24:39.0920 0636 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
                  11:24:39.0936 0636 amdide - ok
                  11:24:39.0998 0636 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
                  11:24:40.0014 0636 AmdK7 - ok
                  11:24:40.0061 0636 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
                  11:24:40.0076 0636 AmdK8 - ok
                  11:24:40.0170 0636 [ DD8D9C597AF7CD2F6B70A3D6A4A1ACEA ] androidusb C:\Windows\system32\Drivers\ssadadb.sys
                  11:24:40.0217 0636 androidusb - ok
                  11:24:40.0326 0636 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
                  11:24:40.0341 0636 Appinfo - ok
                  11:24:40.0544 0636 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                  11:24:40.0544 0636 Apple Mobile Device - ok
                  11:24:40.0607 0636 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
                  11:24:40.0622 0636 arc - ok
                  11:24:40.0700 0636 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
                  11:24:40.0716 0636 arcsas - ok
                  11:24:40.0747 0636 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
                  11:24:40.0794 0636 AsyncMac - ok
                  11:24:40.0825 0636 [ 0D83C87A801A3DFCD1BF73893FE7518C ] atapi C:\Windows\system32\drivers\atapi.sys
                  11:24:40.0841 0636 atapi - ok
                  11:24:40.0919 0636 [ 69E65A2CE11619F0C868967CA9540B80 ] ATSWPDRV C:\Windows\system32\DRIVERS\ATSwpDrv.sys
                  11:24:40.0919 0636 ATSWPDRV - ok
                  11:24:40.0997 0636 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
                  11:24:41.0028 0636 AudioEndpointBuilder - ok
                  11:24:41.0075 0636 [ 42076E29AAFA0830A2C5D4E310F58DD1 ] Audiosrv C:\Windows\System32\Audiosrv.dll
                  11:24:41.0106 0636 Audiosrv - ok
                  11:24:41.0153 0636 bcgummuh - ok
                  11:24:41.0199 0636 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
                  11:24:41.0231 0636 Beep - ok
                  11:24:41.0355 0636 [ D3E6D78285529962349A7F1617035938 ] BFE C:\Windows\System32\bfe.dll
                  11:24:41.0371 0636 BFE - ok
                  11:24:41.0496 0636 [ 02ED7B4DBC2A3232A389106DA7515C3D ] BITS C:\Windows\system32\qmgr.dll
                  11:24:41.0527 0636 BITS - ok
                  11:24:41.0636 0636 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
                  11:24:41.0667 0636 blbdrive - ok
                  11:24:41.0839 0636 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
                  11:24:41.0855 0636 Bonjour Service - ok
                  11:24:41.0933 0636 [ 8153396D5551276227FA146900F734E6 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
                  11:24:41.0948 0636 bowser - ok
                  11:24:42.0011 0636 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
                  11:24:42.0042 0636 BrFiltLo - ok
                  11:24:42.0120 0636 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
                  11:24:42.0151 0636 BrFiltUp - ok
                  11:24:42.0291 0636 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
                  11:24:42.0323 0636 Browser - ok
                  11:24:42.0369 0636 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
                  11:24:42.0416 0636 Brserid - ok
                  11:24:42.0432 0636 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
                  11:24:42.0479 0636 BrSerWdm - ok
                  11:24:42.0510 0636 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
                  11:24:42.0541 0636 BrUsbMdm - ok
                  11:24:42.0572 0636 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
                  11:24:42.0619 0636 BrUsbSer - ok
                  11:24:42.0681 0636 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
                  11:24:42.0728 0636 BTHMODEM - ok
                  11:24:42.0791 0636 catchme - ok
                  11:24:42.0806 0636 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
                  11:24:42.0837 0636 cdfs - ok
                  11:24:42.0900 0636 [ 1EC25CEA0DE6AC4718BF89F9E1778B57 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
                  11:24:42.0931 0636 cdrom - ok
                  11:24:43.0025 0636 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] CertPropSvc C:\Windows\System32\certprop.dll
                  11:24:43.0071 0636 CertPropSvc - ok
                  11:24:43.0103 0636 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
                  11:24:43.0134 0636 circlass - ok
                  11:24:43.0149 0636 [ 465745561C832B29F7C48B488AAB3842 ] CLFS C:\Windows\system32\CLFS.sys
                  11:24:43.0165 0636 CLFS - ok
                  11:24:43.0352 0636 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
                  11:24:43.0368 0636 clr_optimization_v2.0.50727_32 - ok
                  11:24:43.0539 0636 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
                  11:24:43.0555 0636 clr_optimization_v4.0.30319_32 - ok
                  11:24:43.0617 0636 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
                  11:24:43.0664 0636 CmBatt - ok
                  11:24:43.0773 0636 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
                  11:24:43.0789 0636 cmdide - ok
                  11:24:43.0820 0636 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
                  11:24:43.0836 0636 Compbatt - ok
                  11:24:43.0836 0636 COMSysApp - ok
                  11:24:43.0945 0636 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
                  11:24:43.0961 0636 crcdisk - ok
                  11:24:43.0992 0636 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
                  11:24:44.0039 0636 Crusoe - ok
                  11:24:44.0132 0636 [ 6DE363F9F99334514C46AEC02D3E3678 ] CryptSvc C:\Windows\system32\cryptsvc.dll
                  11:24:44.0179 0636 CryptSvc - ok
                  11:24:44.0241 0636 [ 301AE00E12408650BADDC04DBC832830 ] DcomLaunch C:\Windows\system32\rpcss.dll
                  11:24:44.0319 0636 DcomLaunch - ok
                  11:24:44.0382 0636 [ A3E9FA213F443AC77C7746119D13FEEC ] DfsC C:\Windows\system32\Drivers\dfsc.sys
                  11:24:44.0397 0636 DfsC - ok
                  11:24:44.0663 0636 [ FA3463F25F9CC9C3BCF1E7912FEFF099 ] DFSR C:\Windows\system32\DFSR.exe
                  11:24:44.0772 0636 DFSR - ok
                  11:24:44.0881 0636 [ 43A988A9C10333476CB5FB667CBD629D ] Dhcp C:\Windows\System32\dhcpcsvc.dll
                  11:24:44.0928 0636 Dhcp - ok
                  11:24:44.0975 0636 [ 64109E623ABD6955C8FB110B592E68B7 ] disk C:\Windows\system32\drivers\disk.sys
                  11:24:44.0990 0636 disk - ok
                  11:24:45.0037 0636 dkmtdile - ok
                  11:24:45.0084 0636 [ 4805D9A6D281C7A7DEFD9094DEC6AF7D ] Dnscache C:\Windows\System32\dnsrslvr.dll
                  11:24:45.0115 0636 Dnscache - ok
                  11:24:45.0177 0636 [ 5AF620A08C614E24206B79E8153CF1A8 ] dot3svc C:\Windows\System32\dot3svc.dll
                  11:24:45.0224 0636 dot3svc - ok
                  11:24:45.0271 0636 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
                  11:24:45.0318 0636 DPS - ok
                  11:24:45.0427 0636 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
                  11:24:45.0474 0636 drmkaud - ok
                  11:24:45.0536 0636 [ 85F33880B8CFB554BD3D9CCDB486845A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
                  11:24:45.0599 0636 DXGKrnl - ok
                  11:24:45.0645 0636 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
                  11:24:45.0692 0636 E1G60 - ok
                  11:24:45.0755 0636 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
                  11:24:45.0801 0636 EapHost - ok
                  11:24:45.0879 0636 [ DD2CD259D83D8B72C02C5F2331FF9D68 ] Ecache C:\Windows\system32\drivers\ecache.sys
                  11:24:45.0895 0636 Ecache - ok
                  11:24:45.0957 0636 ehkbarwa - ok
                  11:24:46.0020 0636 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
                  11:24:46.0035 0636 ehRecvr - ok
                  11:24:46.0145 0636 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
                  11:24:46.0160 0636 ehSched - ok
                  11:24:46.0191 0636 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
                  11:24:46.0207 0636 ehstart - ok
                  11:24:46.0254 0636 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
                  11:24:46.0285 0636 elxstor - ok
                  11:24:46.0425 0636 [ 70B1A86DF0C8EAD17D2BC332EDAE2C7C ] EMDMgmt C:\Windows\system32\emdmgmt.dll
                  11:24:46.0457 0636 EMDMgmt - ok
                  11:24:46.0488 0636 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
                  11:24:46.0535 0636 ErrDev - ok
                  11:24:46.0659 0636 [ 3CB3343D720168B575133A0A20DC2465 ] EventSystem C:\Windows\system32\es.dll
                  11:24:46.0691 0636 EventSystem - ok
                  11:24:46.0737 0636 [ 0D858EB20589A34EFB25695ACAA6AA2D ] exfat C:\Windows\system32\drivers\exfat.sys
                  11:24:46.0769 0636 exfat - ok
                  11:24:46.0893 0636 [ 3C489390C2E2064563727752AF8EAB9E ] fastfat C:\Windows\system32\drivers\fastfat.sys
                  11:24:46.0925 0636 fastfat - ok
                  11:24:46.0956 0636 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
                  11:24:46.0987 0636 fdc - ok
                  11:24:47.0018 0636 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
                  11:24:47.0034 0636 fdPHost - ok
                  11:24:47.0143 0636 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
                  11:24:47.0190 0636 FDResPub - ok
                  11:24:47.0237 0636 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
                  11:24:47.0252 0636 FileInfo - ok
                  11:24:47.0268 0636 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
                  11:24:47.0299 0636 Filetrace - ok
                  11:24:47.0377 0636 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
                  11:24:47.0408 0636 flpydisk - ok
                  11:24:47.0439 0636 [ 05EA53AFE985443011E36DAB07343B46 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
                  11:24:47.0455 0636 FltMgr - ok
                  11:24:47.0595 0636 [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                  11:24:47.0611 0636 FontCache3.0.0.0 - ok
                  11:24:47.0673 0636 [ CBE5F69A5E5B918225F420BA748F3742 ] FsUsbExDisk C:\Windows\system32\FsUsbExDisk.SYS
                  11:24:47.0673 0636 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
                  11:24:47.0673 0636 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
                  11:24:47.0767 0636 [ 65EA8B77B5851854F0C55C43FA51A198 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
                  11:24:47.0798 0636 Fs_Rec - ok
                  11:24:47.0814 0636 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
                  11:24:47.0829 0636 gagp30kx - ok
                  11:24:47.0954 0636 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
                  11:24:47.0954 0636 GEARAspiWDM - ok
                  11:24:47.0970 0636 gjeadksf - ok
                  11:24:48.0126 0636 [ D9F1113D9401185245573350712F92FC ] gpsvc C:\Windows\System32\gpsvc.dll
                  11:24:48.0173 0636 gpsvc - ok
                  11:24:48.0360 0636 [ 626A24ED1228580B9518C01930936DF9 ] gupdate1c9ca885e58df8b C:\Program Files\Google\Update\GoogleUpdate.exe
                  11:24:48.0375 0636 gupdate1c9ca885e58df8b - ok
                  11:24:48.0422 0636 [ 626A24ED1228580B9518C01930936DF9 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
                  11:24:48.0438 0636 gupdatem - ok
                  11:24:48.0609 0636 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  11:24:48.0625 0636 gusvc - ok
                  11:24:48.0703 0636 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
                  11:24:48.0781 0636 HdAudAddService - ok
                  11:24:48.0859 0636 [ C87B1EE051C0464491C1A7B03FA0BC99 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
                  11:24:48.0906 0636 HDAudBus - ok
                  11:24:48.0999 0636 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
                  11:24:49.0093 0636 HidBth - ok
                  11:24:49.0187 0636 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
                  11:24:49.0233 0636 HidIr - ok
                  11:24:49.0265 0636 [ 8FA640195279ACE21BEA91396A0054FC ] hidserv C:\Windows\System32\hidserv.dll
                  11:24:49.0311 0636 hidserv - ok
                  11:24:49.0358 0636 [ 854CA287AB7FAF949617A788306D967E ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
                  11:24:49.0374 0636 HidUsb - ok
                  11:24:49.0421 0636 hitmanpro3 - ok
                  11:24:49.0452 0636 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
                  11:24:49.0483 0636 hkmsvc - ok
                  11:24:49.0608 0636 [ 8B566EA71D5B76157A9CDB78F25A5731 ] Hotkey C:\Windows\system32\drivers\Hotkey.sys
                  11:24:49.0639 0636 Hotkey ( UnsignedFile.Multi.Generic ) - warning
                  11:24:49.0639 0636 Hotkey - detected UnsignedFile.Multi.Generic (1)
                  11:24:49.0686 0636 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
                  11:24:49.0686 0636 HpCISSs - ok
                  11:24:49.0811 0636 [ 96E241624C71211A79C84F50A8E71CAB ] HTTP C:\Windows\system32\drivers\HTTP.sys
                  11:24:49.0842 0636 HTTP - ok
                  11:24:49.0904 0636 hwpgfwdu - ok

                  Comment


                  • #10
                    Deel 2 TDSkiller log:

                    11:24:49.0935 0636 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
                    11:24:49.0935 0636 i2omp - ok
                    11:24:49.0998 0636 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
                    11:24:50.0013 0636 i8042prt - ok
                    11:24:50.0154 0636 [ 72B53E9C8924949DEC8F3799BCBA2251 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                    11:24:50.0169 0636 IAANTMON - ok
                    11:24:50.0232 0636 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
                    11:24:50.0247 0636 iaStor - ok
                    11:24:50.0310 0636 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
                    11:24:50.0325 0636 iaStorV - ok
                    11:24:50.0497 0636 [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                    11:24:50.0591 0636 idsvc - ok
                    11:24:50.0622 0636 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
                    11:24:50.0637 0636 iirsp - ok
                    11:24:50.0731 0636 [ 68E8C415E102E5D79FD7E4A765B8CBA4 ] IKEEXT C:\Windows\System32\ikeext.dll
                    11:24:50.0762 0636 IKEEXT - ok
                    11:24:50.0981 0636 [ 5D26CCB06E1F3B5C26E863DF3F4F2611 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
                    11:24:51.0074 0636 IntcAzAudAddService - ok
                    11:24:51.0121 0636 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
                    11:24:51.0137 0636 intelide - ok
                    11:24:51.0215 0636 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
                    11:24:51.0261 0636 intelppm - ok
                    11:24:51.0324 0636 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
                    11:24:51.0355 0636 IPBusEnum - ok
                    11:24:51.0371 0636 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
                    11:24:51.0417 0636 IpFilterDriver - ok
                    11:24:51.0480 0636 [ 6A35D233693EDC29A12742049BC5E37F ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
                    11:24:51.0495 0636 iphlpsvc - ok
                    11:24:51.0495 0636 IpInIp - ok
                    11:24:51.0527 0636 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
                    11:24:51.0573 0636 IPMIDRV - ok
                    11:24:51.0605 0636 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
                    11:24:51.0636 0636 IPNAT - ok
                    11:24:51.0729 0636 [ B84A28B3984185EDA8867541AF14CDDB ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
                    11:24:51.0792 0636 iPod Service - ok
                    11:24:51.0807 0636 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
                    11:24:51.0854 0636 IRENUM - ok
                    11:24:51.0885 0636 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
                    11:24:51.0901 0636 isapnp - ok
                    11:24:51.0995 0636 [ F247EEC28317F6C739C16DE420097301 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
                    11:24:52.0010 0636 iScsiPrt - ok
                    11:24:52.0088 0636 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
                    11:24:52.0088 0636 iteatapi - ok
                    11:24:52.0135 0636 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
                    11:24:52.0135 0636 iteraid - ok
                    11:24:52.0166 0636 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
                    11:24:52.0166 0636 kbdclass - ok
                    11:24:52.0229 0636 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
                    11:24:52.0260 0636 kbdhid - ok
                    11:24:52.0416 0636 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] KeyIso C:\Windows\system32\lsass.exe
                    11:24:52.0431 0636 KeyIso - ok
                    11:24:52.0556 0636 [ 7A0CF7908B6824D6A2A1D313E5AE3DCA ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
                    11:24:52.0587 0636 KSecDD - ok
                    11:24:52.0681 0636 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
                    11:24:52.0712 0636 KtmRm - ok
                    11:24:52.0728 0636 kuoihunc - ok
                    11:24:52.0790 0636 [ 1925E63C91CF1610AE41BFD539062079 ] LanmanServer C:\Windows\System32\srvsvc.dll
                    11:24:52.0806 0636 LanmanServer - ok
                    11:24:52.0899 0636 [ 2AE2E1628C5D3F1C0A46A67C9FA1DF15 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
                    11:24:52.0915 0636 LanmanWorkstation - ok
                    11:24:53.0055 0636 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
                    11:24:53.0102 0636 lltdio - ok
                    11:24:53.0227 0636 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
                    11:24:53.0274 0636 lltdsvc - ok
                    11:24:53.0321 0636 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
                    11:24:53.0399 0636 lmhosts - ok
                    11:24:53.0461 0636 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
                    11:24:53.0477 0636 LSI_FC - ok
                    11:24:53.0570 0636 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
                    11:24:53.0586 0636 LSI_SAS - ok
                    11:24:53.0648 0636 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
                    11:24:53.0664 0636 LSI_SCSI - ok
                    11:24:53.0773 0636 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
                    11:24:53.0820 0636 luafv - ok
                    11:24:53.0929 0636 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
                    11:24:53.0945 0636 Mcx2Svc - ok
                    11:24:53.0991 0636 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
                    11:24:54.0023 0636 megasas - ok
                    11:24:54.0101 0636 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
                    11:24:54.0147 0636 MegaSR - ok
                    11:24:54.0179 0636 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
                    11:24:54.0225 0636 MMCSS - ok
                    11:24:54.0257 0636 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
                    11:24:54.0288 0636 Modem - ok
                    11:24:54.0366 0636 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
                    11:24:54.0381 0636 monitor - ok
                    11:24:54.0522 0636 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
                    11:24:54.0522 0636 mouclass - ok
                    11:24:54.0569 0636 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
                    11:24:54.0584 0636 mouhid - ok
                    11:24:54.0615 0636 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
                    11:24:54.0631 0636 MountMgr - ok
                    11:24:54.0787 0636 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
                    11:24:54.0803 0636 MpFilter - ok
                    11:24:54.0927 0636 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
                    11:24:54.0927 0636 mpio - ok
                    11:24:55.0177 0636 [ A69630D039C38018689190234F866D77 ] MpKsl0124c912 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{16F3C3DB-FA83-47D3-8C90-4DA947D7269A}\MpKsl0124c912.sys
                    11:24:55.0177 0636 MpKsl0124c912 - ok
                    11:24:55.0286 0636 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
                    11:24:55.0317 0636 mpsdrv - ok
                    11:24:55.0442 0636 [ D1639BA315B0D79DEC49A4B0E1FB929B ] MpsSvc C:\Windows\system32\mpssvc.dll
                    11:24:55.0489 0636 MpsSvc - ok
                    11:24:55.0614 0636 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
                    11:24:55.0614 0636 Mraid35x - ok
                    11:24:55.0661 0636 [ AE3DE84536B6799D2267443CEC8EDBB9 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
                    11:24:55.0676 0636 MRxDAV - ok
                    11:24:55.0754 0636 [ 5734A0F2BE7E495F7D3ED6EFD4B9F5A1 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
                    11:24:55.0785 0636 mrxsmb - ok
                    11:24:55.0863 0636 [ 6B5FA5ADFACAC9DBBE0991F4566D7D55 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
                    11:24:55.0863 0636 mrxsmb10 - ok
                    11:24:55.0988 0636 [ 5C80D8159181C7ABF1B14BA703B01E0B ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
                    11:24:56.0004 0636 mrxsmb20 - ok
                    11:24:56.0113 0636 [ F70590424EEFBF5C27A40C67AFDB8383 ] msahci C:\Windows\system32\drivers\msahci.sys
                    11:24:56.0113 0636 msahci - ok
                    11:24:56.0238 0636 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
                    11:24:56.0238 0636 msdsm - ok
                    11:24:56.0316 0636 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
                    11:24:56.0331 0636 MSDTC - ok
                    11:24:56.0441 0636 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
                    11:24:56.0472 0636 Msfs - ok
                    11:24:56.0565 0636 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
                    11:24:56.0581 0636 msisadrv - ok
                    11:24:56.0721 0636 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
                    11:24:56.0753 0636 MSiSCSI - ok
                    11:24:56.0815 0636 msiserver - ok
                    11:24:56.0831 0636 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
                    11:24:56.0862 0636 MSKSSRV - ok
                    11:24:56.0971 0636 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
                    11:24:56.0987 0636 MsMpSvc - ok
                    11:24:57.0018 0636 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
                    11:24:57.0049 0636 MSPCLOCK - ok
                    11:24:57.0111 0636 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
                    11:24:57.0127 0636 MSPQM - ok
                    11:24:57.0205 0636 [ B5614AECB05A9340AA0FB55BF561CC63 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
                    11:24:57.0221 0636 MsRPC - ok
                    11:24:57.0314 0636 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
                    11:24:57.0330 0636 mssmbios - ok
                    11:24:57.0361 0636 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
                    11:24:57.0392 0636 MSTEE - ok
                    11:24:57.0423 0636 [ 6DFD1D322DE55B0B7DB7D21B90BEC49C ] Mup C:\Windows\system32\Drivers\mup.sys
                    11:24:57.0439 0636 Mup - ok
                    11:24:57.0486 0636 [ C43B25863FBD65B6D2A142AF3AE320CA ] napagent C:\Windows\system32\qagentRT.dll
                    11:24:57.0533 0636 napagent - ok
                    11:24:57.0626 0636 [ 3C21CE48FF529BB73DADB98770B54025 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
                    11:24:57.0642 0636 NativeWifiP - ok
                    11:24:57.0829 0636 [ 9BDC71790FA08F0A0B5F10462B1BD0B1 ] NDIS C:\Windows\system32\drivers\ndis.sys
                    11:24:57.0860 0636 NDIS - ok
                    11:24:57.0891 0636 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
                    11:24:57.0907 0636 NdisTapi - ok
                    11:24:58.0001 0636 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
                    11:24:58.0016 0636 Ndisuio - ok
                    11:24:58.0110 0636 [ 3D14C3B3496F88890D431E8AA022A411 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
                    11:24:58.0141 0636 NdisWan - ok
                    11:24:58.0203 0636 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
                    11:24:58.0235 0636 NDProxy - ok
                    11:24:58.0562 0636 [ C7F5C284B6F46FCAF6910EA4E644700B ] Nero BackItUp Scheduler 4.0 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                    11:24:58.0625 0636 Nero BackItUp Scheduler 4.0 - ok
                    11:24:58.0671 0636 [ 58B29812B8D23501D15D85DD72EACB34 ] NeroCd2k C:\Windows\system32\drivers\NeroCd2k.sys
                    11:24:58.0718 0636 NeroCd2k ( UnsignedFile.Multi.Generic ) - warning
                    11:24:58.0718 0636 NeroCd2k - detected UnsignedFile.Multi.Generic (1)
                    11:24:58.0749 0636 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
                    11:24:58.0781 0636 NetBIOS - ok
                    11:24:58.0890 0636 [ 7C5FEE5B1C5728507CD96FB4A13E7A02 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
                    11:24:58.0921 0636 netbt - ok
                    11:24:59.0030 0636 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] Netlogon C:\Windows\system32\lsass.exe
                    11:24:59.0061 0636 Netlogon - ok
                    11:24:59.0295 0636 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
                    11:24:59.0358 0636 Netman - ok
                    11:24:59.0389 0636 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
                    11:24:59.0451 0636 netprofm - ok
                    11:24:59.0514 0636 [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
                    11:24:59.0529 0636 NetTcpPortSharing - ok
                    11:24:59.0779 0636 [ 4547B8AEDD8119FCC127FDC7F282E983 ] NETw4v32 C:\Windows\system32\DRIVERS\NETw4v32.sys
                    11:24:59.0919 0636 NETw4v32 - ok
                    11:25:00.0044 0636 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
                    11:25:00.0060 0636 nfrd960 - ok
                    11:25:00.0216 0636 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
                    11:25:00.0231 0636 NisDrv - ok
                    11:25:00.0450 0636 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
                    11:25:00.0465 0636 NisSrv - ok
                    11:25:00.0512 0636 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
                    11:25:00.0575 0636 NlaSvc - ok
                    11:25:00.0653 0636 [ ECB5003F484F9ED6C608D6D6C7886CBB ] Npfs C:\Windows\system32\drivers\Npfs.sys
                    11:25:00.0699 0636 Npfs - ok
                    11:25:00.0793 0636 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
                    11:25:00.0840 0636 nsi - ok
                    11:25:00.0933 0636 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
                    11:25:00.0980 0636 nsiproxy - ok
                    11:25:00.0980 0636 ntcuxfbn - ok
                    11:25:01.0152 0636 [ B4EFFE29EB4F15538FD8A9681108492D ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
                    11:25:01.0277 0636 Ntfs - ok
                    11:25:01.0339 0636 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
                    11:25:01.0417 0636 ntrigdigi - ok
                    11:25:01.0433 0636 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
                    11:25:01.0479 0636 Null - ok
                    11:25:02.0197 0636 [ B0CC8B78A9F0C6D9C8909B9BF874A4DE ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
                    11:25:02.0509 0636 nvlddmkm - ok
                    11:25:02.0587 0636 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
                    11:25:02.0603 0636 nvraid - ok
                    11:25:02.0665 0636 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
                    11:25:02.0681 0636 nvstor - ok
                    11:25:02.0837 0636 [ 1F3671DC1060477E6262E41F9EFD46F6 ] nvsvc C:\Windows\system32\nvvsvc.exe
                    11:25:02.0868 0636 nvsvc - ok
                    11:25:03.0008 0636 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
                    11:25:03.0024 0636 nv_agp - ok
                    11:25:03.0024 0636 NwlnkFlt - ok
                    11:25:03.0039 0636 NwlnkFwd - ok
                    11:25:03.0258 0636 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
                    11:25:03.0289 0636 odserv - ok
                    11:25:03.0351 0636 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
                    11:25:03.0429 0636 ohci1394 - ok
                    11:25:03.0601 0636 [ 27915BDFF44CA08E85DA3D1DDB7B6ECD ] omniserv C:\Program Files\Softex\OmniPass\OmniServ.exe
                    11:25:03.0617 0636 omniserv ( UnsignedFile.Multi.Generic ) - warning
                    11:25:03.0617 0636 omniserv - detected UnsignedFile.Multi.Generic (1)
                    11:25:03.0695 0636 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
                    11:25:03.0710 0636 ose - ok
                    11:25:03.0882 0636 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2pimsvc C:\Windows\system32\p2psvc.dll
                    11:25:03.0913 0636 p2pimsvc - ok
                    11:25:04.0053 0636 [ 5DE1A3972FD3112C75EB17BDCF454169 ] p2psvc C:\Windows\system32\p2psvc.dll
                    11:25:04.0085 0636 p2psvc - ok
                    11:25:04.0131 0636 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
                    11:25:04.0178 0636 Parport - ok
                    11:25:04.0241 0636 [ 3B38467E7C3DAED009DFE359E17F139F ] partmgr C:\Windows\system32\drivers\partmgr.sys
                    11:25:04.0256 0636 partmgr - ok
                    11:25:04.0334 0636 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
                    11:25:04.0381 0636 Parvdm - ok
                    11:25:04.0475 0636 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
                    11:25:04.0490 0636 PcaSvc - ok
                    11:25:04.0631 0636 [ 01B94418DEB235DFF777CC80076354B4 ] pci C:\Windows\system32\drivers\pci.sys
                    11:25:04.0646 0636 pci - ok
                    11:25:04.0677 0636 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
                    11:25:04.0693 0636 pciide - ok
                    11:25:04.0787 0636 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
                    11:25:04.0787 0636 pcmcia - ok
                    11:25:04.0865 0636 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
                    11:25:04.0974 0636 PEAUTH - ok
                    11:25:05.0208 0636 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
                    11:25:05.0333 0636 pla - ok
                    11:25:05.0411 0636 [ 78F975CB6D18265BE6F492EDB2D7BC7B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
                    11:25:05.0442 0636 PlugPlay - ok
                    11:25:05.0598 0636 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
                    11:25:05.0691 0636 PNRPAutoReg - ok
                    11:25:05.0754 0636 [ 5DE1A3972FD3112C75EB17BDCF454169 ] PNRPsvc C:\Windows\system32\p2psvc.dll
                    11:25:05.0785 0636 PNRPsvc - ok
                    11:25:05.0941 0636 [ 47B8F37AA18B74D8C2E1BC1A7A2C8F8A ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
                    11:25:05.0972 0636 PolicyAgent - ok
                    11:25:06.0128 0636 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
                    11:25:06.0159 0636 PptpMiniport - ok
                    11:25:06.0269 0636 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
                    11:25:06.0300 0636 Processor - ok
                    11:25:06.0393 0636 [ B627E4FC8585E8843C5905D4D3587A90 ] ProfSvc C:\Windows\system32\profsvc.dll
                    11:25:06.0425 0636 ProfSvc - ok
                    11:25:06.0503 0636 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] ProtectedStorage C:\Windows\system32\lsass.exe
                    11:25:06.0518 0636 ProtectedStorage - ok
                    11:25:06.0643 0636 [ BFEF604508A0ED1EAE2A73E872555FFB ] PSched C:\Windows\system32\DRIVERS\pacer.sys
                    11:25:06.0674 0636 PSched - ok
                    11:25:06.0815 0636 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
                    11:25:06.0893 0636 ql2300 - ok
                    11:25:06.0986 0636 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
                    11:25:07.0002 0636 ql40xx - ok
                    11:25:07.0080 0636 qmsmgxub - ok
                    11:25:07.0158 0636 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
                    11:25:07.0173 0636 QWAVE - ok
                    11:25:07.0189 0636 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
                    11:25:07.0205 0636 QWAVEdrv - ok
                    11:25:07.0329 0636 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
                    11:25:07.0345 0636 RasAcd - ok
                    11:25:07.0376 0636 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
                    11:25:07.0407 0636 RasAuto - ok
                    11:25:07.0470 0636 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
                    11:25:07.0501 0636 Rasl2tp - ok
                    11:25:07.0610 0636 [ 6E7C284FC5C4EC07AD164D93810385A6 ] RasMan C:\Windows\System32\rasmans.dll
                    11:25:07.0641 0636 RasMan - ok
                    11:25:07.0735 0636 [ 3E9D9B048107B40D87B97DF2E48E0744 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
                    11:25:07.0766 0636 RasPppoe - ok
                    11:25:07.0766 0636 [ A7D141684E9500AC928A772ED8E6B671 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
                    11:25:07.0797 0636 RasSstp - ok
                    11:25:07.0875 0636 [ 6E1C5D0457622F9EE35F683110E93D14 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
                    11:25:07.0907 0636 rdbss - ok
                    11:25:07.0907 0636 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
                    11:25:07.0938 0636 RDPCDD - ok
                    11:25:07.0985 0636 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
                    11:25:08.0016 0636 rdpdr - ok
                    11:25:08.0016 0636 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
                    11:25:08.0047 0636 RDPENCDD - ok
                    11:25:08.0141 0636 [ E1C18F4097A5ABCEC941DC4B2F99DB7E ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
                    11:25:08.0172 0636 RDPWD - ok
                    11:25:08.0265 0636 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
                    11:25:08.0297 0636 RemoteAccess - ok
                    11:25:08.0406 0636 [ CC4E32400F3C7253400CF8F3F3A0B676 ] RemoteRegistry C:\Windows\system32\regsvc.dll
                    11:25:08.0453 0636 RemoteRegistry - ok
                    11:25:08.0640 0636 [ 17E0BEF5CA5C9CE52CC8082AC6EBC449 ] RichVideo C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    11:25:08.0655 0636 RichVideo - ok
                    11:25:08.0733 0636 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
                    11:25:08.0749 0636 RpcLocator - ok
                    11:25:08.0796 0636 [ 301AE00E12408650BADDC04DBC832830 ] RpcSs C:\Windows\system32\rpcss.dll
                    11:25:08.0827 0636 RpcSs - ok
                    11:25:08.0983 0636 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
                    11:25:09.0030 0636 rspndr - ok
                    11:25:09.0123 0636 [ B7E1C523E2F7787D700766FC78E01F77 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
                    11:25:09.0155 0636 RTL8169 - ok
                    11:25:09.0248 0636 [ 0D1C1B0DE2819FE1EA25098183130B64 ] RTSTOR C:\Windows\system32\drivers\RTSTOR.SYS
                    11:25:09.0264 0636 RTSTOR - ok
                    11:25:09.0295 0636 [ A911ECAC81F94ADEAFBE8E3F7873EDB0 ] SamSs C:\Windows\system32\lsass.exe
                    11:25:09.0326 0636 SamSs - ok
                    11:25:09.0357 0636 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
                    11:25:09.0389 0636 sbp2port - ok
                    11:25:09.0513 0636 [ 11387E32642269C7E62E8B52C060B3C6 ] SCardSvr C:\Windows\System32\SCardSvr.dll
                    11:25:09.0529 0636 SCardSvr - ok
                    11:25:09.0685 0636 [ 9FEB2026A460916D1A1198B460632630 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
                    11:25:09.0747 0636 SCDEmu ( UnsignedFile.Multi.Generic ) - warning
                    11:25:09.0747 0636 SCDEmu - detected UnsignedFile.Multi.Generic (1)
                    11:25:09.0857 0636 [ 7B587B8A6D4A99F79D2902D0385F29BD ] Schedule C:\Windows\system32\schedsvc.dll
                    11:25:09.0872 0636 Schedule - ok
                    11:25:09.0935 0636 [ 87C2D0377B23E2D8A41093C2F5FB1A5B ] SCPolicySvc C:\Windows\System32\certprop.dll
                    11:25:09.0950 0636 SCPolicySvc - ok
                    11:25:10.0044 0636 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
                    11:25:10.0059 0636 SDRSVC - ok
                    11:25:10.0200 0636 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
                    11:25:10.0247 0636 secdrv - ok
                    11:25:10.0325 0636 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
                    11:25:10.0356 0636 seclogon - ok
                    11:25:10.0449 0636 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
                    11:25:10.0481 0636 SENS - ok
                    11:25:10.0590 0636 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
                    11:25:10.0652 0636 Serenum - ok
                    11:25:10.0730 0636 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
                    11:25:10.0793 0636 Serial - ok
                    11:25:10.0871 0636 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
                    11:25:10.0902 0636 sermouse - ok
                    11:25:10.0995 0636 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
                    11:25:11.0042 0636 SessionEnv - ok
                    11:25:11.0136 0636 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
                    11:25:11.0183 0636 sffdisk - ok
                    11:25:11.0276 0636 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
                    11:25:11.0323 0636 sffp_mmc - ok
                    11:25:11.0385 0636 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
                    11:25:11.0432 0636 sffp_sd - ok
                    11:25:11.0510 0636 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
                    11:25:11.0604 0636 sfloppy - ok
                    11:25:11.0666 0636 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
                    11:25:11.0713 0636 SharedAccess - ok
                    11:25:11.0791 0636 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
                    11:25:11.0822 0636 ShellHWDetection - ok
                    11:25:11.0900 0636 [ 4346D5BBDDE7756D8614A3F193D60984 ] Si3531 C:\Windows\system32\DRIVERS\Si3531.sys
                    11:25:11.0916 0636 Si3531 - ok
                    11:25:12.0025 0636 [ E853C341BBF4AC0007A8DB0858DBB09D ] SiFilter C:\Windows\system32\DRIVERS\SiWinAcc.sys
                    11:25:12.0025 0636 SiFilter - ok
                    11:25:12.0072 0636 [ D80E6F142EB4963E82A8537DD745F51B ] SiRemFil C:\Windows\system32\DRIVERS\SiRemFil.sys
                    11:25:12.0072 0636 SiRemFil - ok
                    11:25:12.0181 0636 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
                    11:25:12.0197 0636 sisagp - ok
                    11:25:12.0275 0636 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
                    11:25:12.0290 0636 SiSRaid2 - ok
                    11:25:12.0399 0636 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
                    11:25:12.0431 0636 SiSRaid4 - ok
                    11:25:12.0633 0636 [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
                    11:25:12.0649 0636 SkypeUpdate - ok
                    11:25:12.0945 0636 [ 0BA91E1358AD25236863039BB2609A2E ] slsvc C:\Windows\system32\SLsvc.exe
                    11:25:13.0148 0636 slsvc - ok
                    11:25:13.0242 0636 [ 7C6DC44CA0BFA6291629AB764200D1D4 ] SLUINotify C:\Windows\system32\SLUINotify.dll
                    11:25:13.0289 0636 SLUINotify - ok
                    11:25:13.0320 0636 [ 031E6BCD53C9B2B9ACE111EAFEC347B6 ] Smb C:\Windows\system32\DRIVERS\smb.sys
                    11:25:13.0367 0636 Smb - ok
                    11:25:13.0429 0636 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
                    11:25:13.0460 0636 SNMPTRAP - ok
                    11:25:13.0679 0636 [ 279C771ED7D5D6132D7FE08EFC781FA4 ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
                    11:25:13.0803 0636 SNP2UVC - ok
                    11:25:13.0881 0636 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
                    11:25:13.0913 0636 spldr - ok
                    11:25:13.0991 0636 [ 3665F79026A3F91FBCA63F2C65A09B19 ] Spooler C:\Windows\System32\spoolsv.exe
                    11:25:14.0022 0636 Spooler - ok
                    11:25:14.0193 0636 [ 2252AEF839B1093D16761189F45AF885 ] srv C:\Windows\system32\DRIVERS\srv.sys
                    11:25:14.0225 0636 srv - ok
                    11:25:14.0334 0636 [ B7FF59408034119476B00A81BB53D5D1 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
                    11:25:14.0365 0636 srv2 - ok
                    11:25:14.0443 0636 [ 2ACCC9B12AF02030F531E6CCA6F8B76E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
                    11:25:14.0474 0636 srvnet - ok
                    11:25:14.0568 0636 [ 406776FE3C2B66796BAC1A7AFB9AC8A1 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
                    11:25:14.0583 0636 ssadbus - ok
                    11:25:14.0630 0636 [ B19532D015A5D295E2AA34BB521202CF ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
                    11:25:14.0646 0636 ssadmdfl - ok
                    11:25:14.0771 0636 [ 2AEBF9108E6F435458B9499C27394DA4 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
                    11:25:14.0802 0636 ssadmdm - ok
                    11:25:14.0849 0636 [ 28F893C9B4E98DEE5AE3C24DB56B1B11 ] ssadserd C:\Windows\system32\DRIVERS\ssadserd.sys
                    11:25:14.0880 0636 ssadserd - ok
                    11:25:14.0942 0636 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
                    11:25:14.0989 0636 SSDPSRV - ok
                    11:25:15.0067 0636 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
                    11:25:15.0083 0636 SstpSvc - ok
                    11:25:15.0192 0636 [ 7DD08A597BC56051F320DA0BAF69E389 ] stisvc C:\Windows\System32\wiaservc.dll
                    11:25:15.0223 0636 stisvc - ok
                    11:25:15.0301 0636 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
                    11:25:15.0317 0636 swenum - ok
                    11:25:15.0348 0636 [ B36C7CDB86F7F7A8E884479219766950 ] swprv C:\Windows\System32\swprv.dll
                    11:25:15.0410 0636 swprv - ok
                    11:25:15.0457 0636 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
                    11:25:15.0473 0636 Symc8xx - ok
                    11:25:15.0582 0636 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
                    11:25:15.0597 0636 Sym_hi - ok
                    11:25:15.0629 0636 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
                    11:25:15.0644 0636 Sym_u3 - ok
                    11:25:15.0753 0636 [ 4C6DE67EBB6C487F7690A373FCFDE279 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
                    11:25:15.0769 0636 SynTP - ok
                    11:25:15.0831 0636 [ 8710A92D0024B03B5FB9540DF1F71F1D ] SysMain C:\Windows\system32\sysmain.dll
                    11:25:15.0909 0636 SysMain - ok
                    11:25:15.0972 0636 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
                    11:25:16.0003 0636 TabletInputService - ok
                    11:25:16.0112 0636 [ 680916BB09EE0F3A6ACA7C274B0D633F ] TapiSrv C:\Windows\System32\tapisrv.dll
                    11:25:16.0175 0636 TapiSrv - ok
                    11:25:16.0237 0636 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
                    11:25:16.0284 0636 TBS - ok
                    11:25:16.0502 0636 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
                    11:25:16.0565 0636 Tcpip - ok
                    11:25:16.0643 0636 [ 6216A954ED7045B62880A92D6C9B9FC7 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
                    11:25:16.0721 0636 Tcpip6 - ok
                    11:25:16.0845 0636 [ D4A2E4A4B011F3A883AF77315A5AE76B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
                    11:25:16.0892 0636 tcpipreg - ok
                    11:25:16.0986 0636 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
                    11:25:17.0033 0636 TDPIPE - ok
                    11:25:17.0157 0636 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
                    11:25:17.0204 0636 TDTCP - ok
                    11:25:17.0282 0636 [ D09276B1FAB033CE1D40DCBDF303D10F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
                    11:25:17.0329 0636 tdx - ok
                    11:25:17.0423 0636 [ A048056F5E1A96A9BF3071B91741A5AA ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
                    11:25:17.0438 0636 TermDD - ok
                    11:25:17.0579 0636 [ D605031E225AACCBCEB5B76A4F1603A6 ] TermService C:\Windows\System32\termsrv.dll
                    11:25:17.0641 0636 TermService - ok
                    11:25:17.0766 0636 [ 1E3FDB80E40A3CE645F229DFBDFB7694 ] Themes C:\Windows\system32\shsvcs.dll
                    11:25:17.0797 0636 Themes - ok
                    11:25:17.0891 0636 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
                    11:25:17.0953 0636 THREADORDER - ok
                    11:25:18.0109 0636 [ F32E7CD2339C66760AA5178924B21E6B ] TomTomHOMEService C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                    11:25:18.0125 0636 TomTomHOMEService - ok
                    11:25:18.0249 0636 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
                    11:25:18.0296 0636 TrkWks - ok
                    11:25:18.0515 0636 [ 16613A1BAD034D4ECF957AF18B7C2FF5 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
                    11:25:18.0561 0636 TrustedInstaller - ok
                    11:25:18.0593 0636 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
                    11:25:18.0639 0636 tssecsrv - ok
                    11:25:18.0671 0636 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
                    11:25:18.0686 0636 tunmp - ok
                    11:25:18.0717 0636 [ 6042505FF6FA9AC1EF7684D0E03B6940 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
                    11:25:18.0749 0636 tunnel - ok
                    11:25:18.0795 0636 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
                    11:25:18.0811 0636 uagp35 - ok
                    11:25:18.0889 0636 [ 8B5088058FA1D1CD897A2113CCFF6C58 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
                    11:25:18.0936 0636 udfs - ok
                    11:25:19.0029 0636 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
                    11:25:19.0076 0636 UI0Detect - ok
                    11:25:19.0123 0636 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
                    11:25:19.0139 0636 uliagpkx - ok
                    11:25:19.0170 0636 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
                    11:25:19.0185 0636 uliahci - ok
                    11:25:19.0217 0636 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
                    11:25:19.0232 0636 UlSata - ok
                    11:25:19.0263 0636 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
                    11:25:19.0279 0636 ulsata2 - ok
                    11:25:19.0357 0636 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
                    11:25:19.0388 0636 umbus - ok
                    11:25:19.0497 0636 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
                    11:25:19.0529 0636 upnphost - ok
                    11:25:19.0622 0636 [ 83CAFCB53201BBAC04D822F32438E244 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
                    11:25:19.0638 0636 USBAAPL - ok
                    11:25:19.0685 0636 [ B902EBDC7B36B0CE29B70AF8E0A27AFF ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
                    11:25:19.0700 0636 usbccgp - ok
                    11:25:19.0809 0636 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
                    11:25:19.0856 0636 usbcir - ok
                    11:25:19.0934 0636 [ 9AF290F63974796782606521C4CB2E20 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
                    11:25:19.0950 0636 usbehci - ok
                    11:25:20.0090 0636 [ BF40C876B38B719822A96CF3261434FA ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
                    11:25:20.0106 0636 usbhub - ok
                    11:25:20.0137 0636 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
                    11:25:20.0199 0636 usbohci - ok
                    11:25:20.0246 0636 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
                    11:25:20.0277 0636 usbprint - ok
                    11:25:20.0371 0636 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
                    11:25:20.0387 0636 usbscan - ok
                    11:25:20.0433 0636 [ 87BA6B83C5D19B69160968D07D6E2982 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
                    11:25:20.0465 0636 USBSTOR - ok
                    11:25:20.0558 0636 [ 0E4C7F6266B2CC444C3239D60569410E ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
                    11:25:20.0574 0636 usbuhci - ok
                    11:25:20.0652 0636 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
                    11:25:20.0683 0636 usbvideo - ok
                    11:25:20.0777 0636 [ 032A0ACC3909AE7215D524E29D536797 ] UxSms C:\Windows\System32\uxsms.dll
                    11:25:20.0808 0636 UxSms - ok
                    11:25:20.0917 0636 [ B13BC395B9D6116628F5AF47E0802AC4 ] vds C:\Windows\System32\vds.exe
                    11:25:20.0948 0636 vds - ok
                    11:25:21.0011 0636 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
                    11:25:21.0042 0636 vga - ok
                    11:25:21.0057 0636 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
                    11:25:21.0089 0636 VgaSave - ok
                    11:25:21.0120 0636 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
                    11:25:21.0135 0636 viaagp - ok
                    11:25:21.0167 0636 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
                    11:25:21.0198 0636 ViaC7 - ok
                    11:25:21.0245 0636 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
                    11:25:21.0260 0636 viaide - ok
                    11:25:21.0276 0636 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
                    11:25:21.0291 0636 volmgr - ok
                    11:25:21.0385 0636 [ 98F5FFE6316BD74E9E2C97206C190196 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
                    11:25:21.0416 0636 volmgrx - ok
                    11:25:21.0510 0636 [ D8B4A53DD2769F226B3EB374374987C9 ] volsnap C:\Windows\system32\drivers\volsnap.sys
                    11:25:21.0525 0636 volsnap - ok
                    11:25:21.0619 0636 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
                    11:25:21.0635 0636 vsmraid - ok
                    11:25:21.0775 0636 [ D5FB73D19C46ADE183F968E13F186B23 ] VSS C:\Windows\system32\vssvc.exe
                    11:25:21.0900 0636 VSS - ok
                    11:25:21.0962 0636 [ 1CF9206966A8458CDA9A8B20DF8AB7D3 ] W32Time C:\Windows\system32\w32time.dll
                    11:25:22.0009 0636 W32Time - ok
                    11:25:22.0056 0636 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
                    11:25:22.0134 0636 WacomPen - ok
                    11:25:22.0165 0636 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
                    11:25:22.0212 0636 Wanarp - ok
                    11:25:22.0212 0636 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
                    11:25:22.0259 0636 Wanarpv6 - ok
                    11:25:22.0383 0636 [ F3A5C2E1A6533192B070D06ECF6BE796 ] wcncsvc C:\Windows\System32\wcncsvc.dll
                    11:25:22.0446 0636 wcncsvc - ok
                    11:25:22.0477 0636 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
                    11:25:22.0508 0636 WcsPlugInService - ok
                    11:25:22.0571 0636 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
                    11:25:22.0586 0636 Wd - ok
                    11:25:22.0758 0636 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
                    11:25:22.0789 0636 Wdf01000 - ok
                    11:25:22.0836 0636 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
                    11:25:22.0883 0636 WdiServiceHost - ok
                    11:25:22.0883 0636 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
                    11:25:22.0945 0636 WdiSystemHost - ok
                    11:25:23.0023 0636 [ CF9A5F41789B642DB967021DE06A2713 ] WebClient C:\Windows\System32\webclnt.dll
                    11:25:23.0054 0636 WebClient - ok
                    11:25:23.0163 0636 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
                    11:25:23.0195 0636 Wecsvc - ok
                    11:25:23.0241 0636 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
                    11:25:23.0288 0636 wercplsupport - ok
                    11:25:23.0335 0636 [ FD1965AAA112C6818A30AB02742D0461 ] WerSvc C:\Windows\System32\WerSvc.dll
                    11:25:23.0351 0636 WerSvc - ok
                    11:25:23.0429 0636 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
                    11:25:23.0460 0636 WinDefend - ok
                    11:25:23.0460 0636 WinHttpAutoProxySvc - ok
                    11:25:23.0569 0636 [ 00B79A7C984678F24CF052E5BEB3A2F5 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
                    11:25:23.0616 0636 Winmgmt - ok
                    11:25:23.0772 0636 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
                    11:25:23.0850 0636 WinRM - ok
                    11:25:23.0959 0636 [ F0FE933E27F1E2A83FF322A0693A4724 ] WisLMSvc C:\Program Files\Launch Manager\WisLMSvc.exe
                    11:25:23.0975 0636 WisLMSvc ( UnsignedFile.Multi.Generic ) - warning
                    11:25:23.0975 0636 WisLMSvc - detected UnsignedFile.Multi.Generic (1)
                    11:25:24.0099 0636 [ 275F4346E569DF56CFB95243BD6F6FF0 ] Wlansvc C:\Windows\System32\wlansvc.dll
                    11:25:24.0131 0636 Wlansvc - ok
                    11:25:24.0193 0636 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
                    11:25:24.0209 0636 WmiAcpi - ok
                    11:25:24.0240 0636 [ ABA4CF9F856D9A3A25F4DDD7690A6E9D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
                    11:25:24.0271 0636 wmiApSrv - ok
                    11:25:24.0489 0636 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
                    11:25:24.0583 0636 WMPNetworkSvc - ok
                    11:25:24.0692 0636 [ 5D94CD167751294962BA238D82DD1BB8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
                    11:25:24.0708 0636 WPCSvc - ok
                    11:25:24.0801 0636 [ 396D406292B0CD26E3504FFE82784702 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
                    11:25:24.0817 0636 WPDBusEnum - ok
                    11:25:24.0864 0636 [ 0CEC23084B51B8288099EB710224E955 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
                    11:25:24.0879 0636 WpdUsb - ok
                    11:25:25.0176 0636 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
                    11:25:25.0207 0636 WPFFontCache_v0400 - ok
                    11:25:25.0238 0636 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
                    11:25:25.0285 0636 ws2ifsl - ok
                    11:25:25.0332 0636 [ 683DD16B590372F2C9661D277F35E49C ] wscsvc C:\Windows\system32\wscsvc.dll
                    11:25:25.0347 0636 wscsvc - ok
                    11:25:25.0363 0636 WSearch - ok
                    11:25:25.0457 0636 [ 6298277B73C77FA99106B271A7525163 ] wuauserv C:\Windows\system32\wuaueng.dll
                    11:25:25.0550 0636 wuauserv - ok
                    11:25:25.0613 0636 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
                    11:25:25.0628 0636 WUDFRd - ok
                    11:25:25.0675 0636 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
                    11:25:25.0691 0636 wudfsvc - ok
                    11:25:25.0706 0636 ================ Scan global ===============================
                    11:25:25.0800 0636 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
                    11:25:25.0956 0636 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
                    11:25:25.0971 0636 [ F42F8855CB5C22E203C6672B124F17FD ] C:\Windows\system32\winsrv.dll
                    11:25:26.0034 0636 [ 2B336AB6286D6C81FA02CBAB914E3C6C ] C:\Windows\system32\services.exe
                    11:25:26.0049 0636 [Global] - ok
                    11:25:26.0049 0636 ================ Scan MBR ==================================
                    11:25:26.0112 0636 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
                    11:25:26.0658 0636 \Device\Harddisk0\DR0 - ok
                    11:25:26.0673 0636 ================ Scan VBR ==================================
                    11:25:26.0673 0636 [ 22B4AEC73C1A001F461ABFAD90E39F9E ] \Device\Harddisk0\DR0\Partition1
                    11:25:26.0673 0636 \Device\Harddisk0\DR0\Partition1 - ok
                    11:25:26.0705 0636 [ 71264E19CAB91066C6A8A61B77BEB4E0 ] \Device\Harddisk0\DR0\Partition2
                    11:25:26.0705 0636 \Device\Harddisk0\DR0\Partition2 - ok
                    11:25:26.0720 0636 ============================================================
                    11:25:26.0720 0636 Scan finished
                    11:25:26.0720 0636 ============================================================
                    11:25:26.0736 3832 Detected object count: 6
                    11:25:26.0736 3832 Actual detected object count: 6
                    11:26:05.0651 3832 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0651 3832 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:26:05.0651 3832 Hotkey ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0651 3832 Hotkey ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:26:05.0651 3832 NeroCd2k ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0651 3832 NeroCd2k ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:26:05.0651 3832 omniserv ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0651 3832 omniserv ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:26:05.0651 3832 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0651 3832 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:26:05.0666 3832 WisLMSvc ( UnsignedFile.Multi.Generic ) - skipped by user
                    11:26:05.0666 3832 WisLMSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
                    11:37:23.0227 3060 Deinitialize success

                    Comment


                    • #11
                      Hallo Gerard,

                      We gaan nu weer even aan de slag met ComboFix.

                      Open een kladblokbestand.
                      Kopieer de onderstaande code, en plak deze in het kladblokbestand.
                      Sla het kladblokbestand op als CFScript.txt
                      Code:
                      REGISTRY::
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                      "AppInit_DLLs"=""
                      Sleep nu het bestand CFScript.txt in het bestand ComboFix.exe

                      ComboFix zal opnieuw starten.
                      Wanneer ComboFix klaar is, dit kan na een herstart zijn, opent er een logfile.
                      Post de inhoud van de logfile.

                      Comment


                      • #12
                        Logile ComboFix:

                        ComboFix 13-07-13.01 - Melanie 14-07-2013 12:29:33.5.2 - x86
                        Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.3070.1867 [GMT 2:00]
                        Gestart vanuit: c:\users\Melanie\Desktop\ComboFix.exe
                        gebruikte Opdracht switches :: c:\users\Melanie\Desktop\CFScript.txt
                        AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
                        SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
                        SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                        .
                        .
                        (((((((((((((((((((( Bestanden Gemaakt van 2013-06-14 to 2013-07-14 ))))))))))))))))))))))))))))))
                        .
                        .
                        2013-07-14 10:38 . 2013-07-14 10:38 -------- d-----w- c:\users\Default\AppData\Local\temp
                        2013-07-14 09:24 . 2013-07-14 09:24 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{16F3C3DB-FA83-47D3-8C90-4DA947D7269A}\MpKsl0124c912.sys
                        2013-07-14 08:49 . 2013-06-17 00:10 7068072 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{16F3C3DB-FA83-47D3-8C90-4DA947D7269A}\mpengine.dll
                        2013-07-13 07:05 . 2013-06-17 00:10 7068072 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
                        2013-07-11 07:49 . 2013-06-19 03:02 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
                        2013-07-11 07:49 . 2013-06-19 03:02 724464 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F244DAB5-ECEC-4823-B772-094A29C99612}\gapaengine.dll
                        2013-07-11 07:06 . 2013-07-11 07:07 -------- d-----w- c:\program files\Microsoft Security Client
                        2013-07-10 22:54 . 2013-06-12 04:18 7068072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CC001500-7A41-4989-9017-81754FCCBB55}\mpengine.dll
                        2013-07-10 18:41 . 2013-07-10 18:41 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
                        2013-07-10 18:33 . 2013-07-10 18:33 -------- d-----w- c:\program files\CCleaner
                        2013-07-10 07:35 . 2013-07-10 07:35 -------- d-----w- c:\users\Melanie\AppData\Roaming\Malwarebytes
                        2013-07-10 07:35 . 2013-07-10 07:35 -------- d-----w- c:\programdata\Malwarebytes
                        2013-07-10 07:35 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
                        2013-07-10 07:35 . 2013-07-13 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                        2013-06-20 11:29 . 2013-06-20 11:29 -------- d-----w- C:\found.001
                        .
                        .
                        .
                        ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2013-07-10 18:41 . 2011-06-07 12:04 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
                        2013-05-09 08:58 . 2011-07-17 21:17 229648 ----a-w- c:\windows\system32\aswBoot.exe
                        2013-05-02 15:28 . 2009-10-02 19:56 238872 ------w- c:\windows\system32\MpSigStub.exe
                        .
                        .
                        ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
                        REGEDIT4
                        .
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                        "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-06-24 247144]
                        "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                        "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-04-19 18678376]
                        "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
                        "Skytel"="Skytel.exe" [2008-06-25 1826816]
                        "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400]
                        "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768]
                        "HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416]
                        "LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
                        "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2007-09-07 86016]
                        "UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
                        "OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096]
                        "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-11 13543968]
                        "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-11 92704]
                        "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "EnableUIADesktopToggle"= 0 (0x0)
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                        "aux1"=wdmaud.drv
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
                        @="Service"
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
                        2005-06-06 21:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
                        2007-10-03 13:44 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
                        2007-10-11 17:01 46368 ----a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                        2011-06-07 15:51 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
                        2011-06-24 13:54 941968 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
                        2011-06-24 13:54 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
                        2011-06-24 13:54 3373968 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
                        2001-06-08 13:29 147456 ------w- c:\windows\System32\NeroCheck.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
                        2007-10-11 17:03 29984 ----a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
                        2007-07-05 10:35 94208 ----a-w- c:\windows\PLFSetL.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
                        2007-08-31 07:01 328992 ----a-w- c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
                        2011-06-15 06:19 307200 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                        2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
                        2006-10-25 07:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
                        2009-01-14 15:20 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\toolbar_eula_launcher]
                        2007-02-09 13:54 16896 ----a-w- c:\program files\GoogleEULA\EULALauncher.exe
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
                        2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
                        .
                        --- Andere Services/Drivers In Geheugen ---
                        .
                        *NewlyCreated* - 03202814
                        *NewlyCreated* - 46808701
                        *NewlyCreated* - 99680061
                        *NewlyCreated* - MPKSL0124C912
                        *Deregistered* - 03202814
                        *Deregistered* - 46808701
                        *Deregistered* - 99680061
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
                        2013-07-13 17:54 1173456 ----a-w- c:\program files\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe
                        .
                        Inhoud van de 'Gedeelde Taken' map
                        .
                        2013-07-14 c:\windows\Tasks\Adobe Flash Player Updater.job
                        - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-10 18:41]
                        .
                        2013-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                        - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 18:12]
                        .
                        2013-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                        - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 18:12]
                        .
                        .
                        ------- Bijkomende Scan -------
                        .
                        uStart Page = hxxp://www.google.nl/
                        uInternet Settings,ProxyOverride = *.local
                        IE: Add to Video Converter... - c:\program files\Media Player Utilities 5.22\AVIConverter\grab.html
                        IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                        TCP: DhcpNameServer = 192.168.2.254
                        DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://foto.hema.nl/ips-opdata/layout/hema/objects/jordan.cab
                        .
                        .
                        **************************************************************************
                        .
                        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2013-07-14 12:38
                        Windows 6.0.6001 Service Pack 1 NTFS
                        .
                        scannen van verborgen processen ...
                        .
                        scannen van verborgen autostart items ...
                        .
                        scannen van verborgen bestanden ...
                        .
                        Scan succesvol afgerond
                        verborgen bestanden: 0
                        .
                        **************************************************************************
                        .
                        --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                        @Denied: (A) (Users)
                        @Denied: (A) (Everyone)
                        @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                        "BlindDial"=dword:00000000
                        .
                        --------------------- DLLs Geladen Onder Lopende Processen ---------------------
                        .
                        - - - - - - - > 'Explorer.exe'(3780)
                        c:\program files\Softex\OmniPass\SCUREDLL.dll
                        .
                        Voltooingstijd: 2013-07-14 12:45:48
                        ComboFix-quarantined-files.txt 2013-07-14 10:45
                        .
                        Pre-Run: 135.942.569.984 bytes beschikbaar
                        Post-Run: 135.910.223.872 bytes beschikbaar
                        .
                        - - End Of File - - 9826F33708C22383E8BD244F50FCAE2A
                        5C616939100B85E558DA92B899A0FC36

                        Comment


                        • #13
                          Prima zo.
                          Zijn er nog problemen?

                          Comment


                          • #14
                            Marckie, zeer bedankt voor de deskundige en vlotte ondersteuning (het was echt nodig).

                            Op dit moment zijn er geen problemen.
                            De laptop start zonder foutmeldingen, alles toepassingen starten lekker lot.
                            Tot zover OK.


                            Is dit het moment om het bureaublad weer schoon te maken?

                            Gerard

                            Comment


                            • #15
                              Graag gedaan hoor Gerard en leuk te horen dat de computer weer helemaal goed loopt.

                              Tijd om af te sluiten.
                              Deïnstalleer ComboFix. Ga naar "Start" - "Uitvoeren" en tik in: Combofix /Uninstall
                              (Let op de spatie tussen Combofix en /Uninstall)
                              Druk daarna op Enter.
                              Dit zal Combofix en ook alle gerelateerde mappen en bestanden verwijderen.

                              Voer de instructies uit die hier gegeven worden: De computer is malware-vrij, wat nu te doen?

                              Meer info over hoe je een nieuwe infectie kan voorkomen vind je hier.
                              Lees ook dit artikel even door: Niets voor niets.

                              De status van deze thread zet ik op opgelost.
                              Indien er niet meer gereageerd wordt, zal binnen een 3-tal dagen deze thread automatisch verplaatst worden naar de sectie Opgeloste hijackthislogs en is een reactie niet meer mogelijk. Dit om het forum netjes en overzichtelijk te houden.
                              Blijkt dat er toch nog problemen zijn, en je wil weer reageren in dit topic, dan stuur je me een privé bericht met verzoek om heropening.

                              Happy surfing again.

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X