Ga naar inhoud

Aanbevolen berichten

Geplaatst:

Logbestand Combofix

ComboFix 11-02-18.05 - Patrick 19/02/2011 19:27:09.1.2 - x86

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.32.1043.18.3039.2016 [GMT 1:00]

Gestart vanuit: c:\users\Patrick\Desktop\ComboFix.exe

AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}

SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

ADS - Windows: deleted 24 bytes in 1 streams.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\users\Patrick\videos\FartGreeting.exe

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-01-19 to 2011-02-19 ))))))))))))))))))))))))))))))

.

2011-02-19 18:36 . 2011-02-19 18:37 -------- d-----w- c:\users\Patrick\AppData\Local\temp

2011-02-19 18:36 . 2011-02-19 18:36 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-02-18 18:18 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21388FE2-C7A4-4031-9CD0-AEFB0742E713}\mpengine.dll

2011-02-12 10:19 . 2011-02-12 10:19 -------- d-----w- c:\program files\Common Files\Skype

2011-02-10 18:22 . 2011-02-10 18:22 -------- d-----w- C:\ads

2011-02-10 17:12 . 2010-12-21 05:38 204288 ----a-w- c:\windows\system32\upnp.dll

2011-02-10 17:12 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll

2011-02-10 17:12 . 2010-12-21 05:38 51200 ----a-w- c:\windows\system32\wscapi.dll

2011-02-10 17:12 . 2010-12-21 05:38 981504 ----a-w- c:\windows\system32\wininet.dll

2011-02-10 17:12 . 2010-12-21 05:38 350720 ----a-w- c:\windows\system32\winhttp.dll

2011-02-10 17:12 . 2010-12-21 05:38 204800 ----a-w- c:\windows\system32\WebClnt.dll

2011-02-10 17:12 . 2010-12-21 05:36 1236992 ----a-w- c:\windows\system32\msxml3.dll

2011-02-10 17:12 . 2010-12-21 05:34 80384 ----a-w- c:\windows\system32\davclnt.dll

2011-02-10 17:12 . 2010-12-21 05:38 73728 ----a-w- c:\windows\system32\wscsvc.dll

2011-02-10 17:12 . 2010-12-21 05:38 14336 ----a-w- c:\windows\system32\slwga.dll

2011-02-10 17:12 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys

2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll

2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll

2011-01-26 19:01 . 2011-01-26 19:01 -------- d-----w- c:\users\Patrick\AppData\Roaming\Fighters

2011-01-24 23:11 . 2011-01-24 23:11 -------- d-----w- c:\programdata\Fighters

2011-01-24 23:10 . 2011-01-24 23:10 -------- d-----w- c:\program files\Fighters

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-02-02 20:40 . 2010-08-17 20:38 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-01-05 17:54 . 2011-01-05 17:55 717289 ----a-w- c:\windows\system32\unins000.exe

2010-12-20 17:09 . 2010-08-15 12:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-12-20 17:08 . 2010-08-15 12:11 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-12-20 16:07 . 2009-07-01 17:06 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys

2010-11-23 16:21 . 2009-07-01 17:06 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-09 39408]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]

"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 321080]

"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]

"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-09-01 499768]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-02 98304]

"HPCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]

"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-06-08 611712]

"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-03-23 495708]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\beid]

2010-02-05 11:29 2056192 ----a-w- c:\program files\Belgium Identity Card\beid35gui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]

2009-06-17 11:13 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]

2010-05-14 08:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]

2008-06-13 17:11 210216 ----a-w- c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]

2008-10-30 10:51 210216 ----a-w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]

2008-06-13 17:11 210216 ----a-w- c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]

2008-11-26 10:34 210216 ----a-w- c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 20992]

R2 gupdate1ca1929fc0a08b0;Google Updateservice (gupdate1ca1929fc0a08b0);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 133104]

R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usbxp.sys [2004-04-30 24832]

R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]

R3 rcmirror;rcmirror;c:\windows\system32\DRIVERS\rcmirror.sys [2008-10-08 3328]

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]

R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-06 1343400]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe [2009-03-02 81920]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-01 176128]

S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-02 135336]

S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2010-06-15 26168]

S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]

S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-12-17 365952]

S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2009-06-03 599344]

S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]

S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-28 59904]

S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-20 116136]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]

S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]

--- Andere Services/Drivers In Geheugen ---

*Deregistered* - PROCEXP141

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-06-17 11:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Inhoud van de 'Gedeelde Taken' map

2011-02-19 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-09 19:45]

2011-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 19:45]

2011-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 19:45]

2011-02-13 c:\windows\Tasks\SmartDefrag.job

- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-11-17 17:08]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.vkliedekerke.be/

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_be&c=91&bd=Pavilion&pf=cnnb

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki...

FF - ProfilePath - c:\users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\p4n5xhyw.default\

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS VERWIJDERD - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

HKLM-Run-NWEReboot - (no file)

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2011-02-19 19:42:42

ComboFix-quarantined-files.txt 2011-02-19 18:42

Pre-Run: 100.499.382.272 bytes beschikbaar

Post-Run: 101.938.913.280 bytes beschikbaar

- - End Of File - - 1A9A731666F72F5B279D94B1DE137EC4

  • Reacties 22
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Geplaatst:

Wanneer ik de laptop opstart blijft de cpu minuten lang, tot bijna een uur, op 100 % draaien. Ik kan geen mediabestanden afspelen. Deze zijn traag, met horten en stoten, het geluid is robotachtig, .... Pas wanneer de CPU stilvalt, gaat alles normaal, en snel. Het is gewoon heel triestig om een uur te moeten wachten tot de PC goed werkt. Bijvoorbeeld Skype werkt ook enkel goed als de CPU niet meer aan 100 % draait. Het zijn vooral meerdere "svchost.exe" bestanden die de processor belasten.

Geplaatst: (aangepast)

Sorry voor de laattijdige reactie.

Heb automatische updates uitgeschakeld, heropgestart, aangeschakeld en heropgestart.

Bij opstarten van de laptop heeft het 50 minuten geduurd voor de processor ophield met draaien. Pas na deze 50 minuten werkt de laptop snel en zonder haperingen.

aangepast door Pat Beemer
Geplaatst:
Ik zie dat je Windows 7 hebt en die is voorzien van een Knipprogramma dus gebruik die eens en sla vervolgens het bestand op in .jpeg formaat.

Het knipprogramma vind je terug bij je bureau-accessoires.

Klik op 'start' (windowssymbool links onderaan je bureaublad, ga dan naar 'alle programma's' en zoek in deze lijst 'bureau-accessoires'.

Klik nu op bureau-accessoires, dan vind je daar het knipprogramma terug, tenzij je een Windows 7 starter hebt.

Meer info hier : ( http://www.pc-helpforum.be/f204/vista-knipprogramma-30049/ ).

Geplaatst:

We zullen eens kijken welke services de oorzaak zijn.

Klik 1 x op die svchost en daarna klik je er met je rechtermuisknop op.

In de lijst die nu verschijnt selecteer je "Naar services gaan".

Nu zal het venster services openen met de service's die door die svchost worden gebruikt gemarkeerd.

Geef die eens door dan kunnen we eens zien of die al dan niet uit kunnen om te kijken of dit verbetering brengt.

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.