Ga naar inhoud

Trojan horse Patched_c.LYT in system32\services.exe


Aanbevolen berichten

Een goedemiddag,

Sinds enkele dagen geeft AVG aan dat er een trojan horse is gevonden in genoemde map. Ik heb van AVG de rescue CD op USB gezet en het bestand zowel geheald als gerenamed. Hierna kreeg ik mijn computer niet meer opgestart en heeft systeemherstel het vervolgens weer "goed" gezet. Melding AVG blijft. De resident Shield alert begint met file system32/services.exe als Trojan horse Patched_c.LYT met result object is white-listed (critical/system file..). Hierna komen er een hoop meldingen uit system32\config\systemprofile.. met als infection virus found HTML/framer. Deze meldingen krijg ik wel verwijderd. Bijgaand de log van hijackthis:

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 17:23:18, on 3-5-2013

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16447)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Toshiba\ConfigFree\NDSTray.exe

C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe

C:\Program Files\Toshiba\Power Saver\TPwrMain.exe

C:\Program Files\Toshiba\SmoothView\SmoothView.exe

C:\Program Files\Toshiba\FlashCards\TCrdMain.exe

C:\Program Files\Apoint2K\ApMsgFwd.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Windows\WindowsMobile\wmdSync.exe

C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

C:\Program Files\DivX\DivX Update\DivXUpdate.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Max Spyware Detector\MaxSDTray.exe

C:\Program Files\Max Spyware Detector\MaxUSBProc.exe

C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe

C:\Program Files\OpenOffice.org 3\program\soffice.exe

C:\Program Files\Apoint2K\HidFind.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe

C:\Program Files\OpenOffice.org 3\program\soffice.bin

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe

C:\Program Files\Windows Mail\WinMail.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Users\Toshiba\Downloads\HijackThis.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - (no file)

O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll

O2 - BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Toshiba\AppData\Roaming\Complitly\Complitly.dll

O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [iTSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START

O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto

O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start

O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

O4 - HKLM\..\Run: [smoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe

O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe

O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe

O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [sDActiveMonitor] "C:\Program Files\Max Spyware Detector\MaxSDTray.exe" -AUTO

O4 - HKLM\..\Run: [MaxUSBProc] "C:\Program Files\Max Spyware Detector\MaxUSBProc.exe"

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

O4 - Global Startup: Bluetooth Manager.lnk = ?

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe

O4 - Global Startup: Update-agent.lnk = ?

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - eBay, de wereldwijde online handelsplaats (file missing)

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - Amazon.co.uk: Low Prices in Electronics, Books, Sports Equipment & more (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: BecHelperService - Unknown owner - C:\Program Files\KPN\Mobiel Internet Software\BecHelperService.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: MaxMerger - Max Secure Software - C:\Program Files\Max Spyware Detector\MaxMerger.exe

O23 - Service: MaxWatchDogService - Max Secure Software - C:\Program Files\Max Spyware Detector\MaxWatchDogService.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe

O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Toshiba\AppData\Local\TVersity\Media Server\MediaServer.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--

End of file - 13142 bytes

Ik hoop dat iemand mij wilt helpen! Alvast hartelijk dank,

Link naar reactie
Delen op andere sites

  • Reacties 31
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Ga naar Start - Alle programma's - Bureauaccesoires.

Zoek het icoon van het opdrachtprompt en klik er op met de rechter muisknop en kies dan in het lijstje voor “uitvoeren als administrator” om het opdrachtprompt te openen.

Tik in: sc stop MaxWatchDogService en druk op Enter.

Tik in: sc delete MaxWatchDogService en druk op Enter.

Tik in: sc stop MaxMerger en druk op Enter.

Tik in: sc delete MaxMerger en druk op Enter.

Tik in exit en druk Enter.

Als je op een van deze instructies een foutmelding krijgt, ga dan gewoon door met de volgende instructie.

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {3bbd3c14-4c16-4989-8366-95bc9179779d} - (no file)

O2 - BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Toshiba\AppData\Roaming\Complitly\Complitly.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)

O4 - HKLM\..\Run: [sDActiveMonitor] "C:\Program Files\Max Spyware Detector\MaxSDTray.exe" –AUTO

O4 - HKLM\..\Run: [MaxUSBProc] "C:\Program Files\Max Spyware Detector\MaxUSBProc.exe"

O4 - Global Startup: Update-agent.lnk = ?

O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - eBay, de wereldwijde online handelsplaats (file missing)

O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - Amazon.co.uk: Low Prices in Electronics, Books, Sports Equipment & more (file missing)

Klik op 'Fix checked' om de items te verwijderen.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\\Program Files\\Trend Micro\\HiJackThis of C:\\Program Files (x86)\\Trend Micro\\HiJackThis.

Download MBAM (Malwarebytes Anti-Malware)

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.

MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.

Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw logje van HijackThis.

Link naar reactie
Delen op andere sites

Beste Kape,

Hartelijk dank voor je snelle en uitgebreide reactie! Ik heb de stappen uitgevoerd en als laatste vroeg Malware inderdaad om mijn laptop opnieuw op te starten. Ik heb hem na het opnieuw opstarten handmatig weer moeten openen, hij gaf hierin geen bijzonderheden (beginscherm weer met snelle scan etc.) ik kreeg van AVG weer direct meldingen.

Log Malwarebytes:

Malwarebytes Anti-Malware 1.75.0.1300

Malwarebytes : Free anti-malware download

Databaseversie: v2013.05.03.07

Windows Vista Service Pack 2 x86 NTFS

Internet Explorer 9.0.8112.16421

Toshiba :: PC_VAN_TOSHIBA [administrator]

3-5-2013 18:47:51

mbam-log-2013-05-03 (18-47-51).txt

Scan type: Snelle scan

Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scan opties: P2P

Objecten gescand: 213433

Verstreken tijd: 11 minuut/minuten, 34 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 1

HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> Succesvol in quarantaine geplaatst en verwijderd.

Registerwaarden gedetecteerd: 1

HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Data: C:\Users\Toshiba\AppData\Local\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\n. -> Succesvol in quarantaine geplaatst en verwijderd.

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 8

C:\Users\Toshiba\AppData\Local\Temp\wpbt0.dll (Trojan.Downloader.bh) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\Toshiba\AppData\Local\Temp\0.6998512951766863.exe (Trojan.Downloader.bh) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\Toshiba\AppData\Local\Temp\msimg32.dll (Rootkit.0Access) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\Toshiba\Downloads\PDFReaderSetup.exe (Adware.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Users\Toshiba\Downloads\installer_media_player_Dutch.exe (Adware.Downware) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Windows\Installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\n (Trojan.Sirefef) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Windows\Installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\80000000.@ (Rootkit.0Access) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Windows\Installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\800000cb.@ (Rootkit.0Access) -> Succesvol in quarantaine geplaatst en verwijderd.

(einde)

Nieuwe log hijackthis:

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 19:15:46, on 3-5-2013

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16447)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Toshiba\ConfigFree\NDSTray.exe

C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe

C:\Program Files\Toshiba\Power Saver\TPwrMain.exe

C:\Program Files\Toshiba\SmoothView\SmoothView.exe

C:\Program Files\Toshiba\FlashCards\TCrdMain.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Windows\WindowsMobile\wmdSync.exe

C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

C:\Program Files\DivX\DivX Update\DivXUpdate.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Apoint2K\ApMsgFwd.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\Program Files\Apoint2K\HidFind.exe

C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe

C:\Program Files\OpenOffice.org 3\program\soffice.exe

C:\Program Files\OpenOffice.org 3\program\soffice.bin

C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\Program Files\Windows Mail\WinMail.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Common Files\Java\Java Update\jucheck.exe

C:\Users\Toshiba\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll

O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [iTSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START

O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto

O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start

O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

O4 - HKLM\..\Run: [smoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe

O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe

O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe

O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

O4 - Global Startup: Bluetooth Manager.lnk = ?

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: BecHelperService - Unknown owner - C:\Program Files\KPN\Mobiel Internet Software\BecHelperService.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe

O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Toshiba\AppData\Local\TVersity\Media Server\MediaServer.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--

End of file - 11562 bytes

Alvast weer mijn dank,

Link naar reactie
Delen op andere sites

Download TDSSKiller en plaats het op je bureaublad.

Pak de bestanden in tdsskiller.zip uit.

Open de map tdsskiller en dubbelklik op TDSSKiller.exe om de tool te starten.

Windows 7 en Windows Vista gebruikers:

Rechtsklik op TDSSKiller.exe -> Uitvoeren als Administrator om de tool te starten.

Als TDSSKiller bericht geeft van een beschikbare update, dan voer je deze eerst uit.

Klik op de knop "Start Scan" en volg de instructies.

Wanneer de scan klaar is klik je op de knop "Report".

Er opent een kladblokbestand. Post de inhoud van dit bestand.

Herstart de pc als TDSSKiller die optie geeft. (Reboot now)

Wanneer er een herstart nodig was, vind je de logfile in C:\\TDSSKiller.[Version]_[Date]_[Time]_log.txt

Link naar reactie
Delen op andere sites

Beste Kape,

Ik de scan laten draaien, hij vond één treath. Ik heb hierbij de optie "cure" aangeklikt. Na het rebooten kreeg ik van AVG een andere melding van een trojan horse, deze kreeg AVG zelf verwijderd. Uiteraard ben ik zo stom geweest om de details niet op te schrijven.

Hij heeft een map TDSSKiller_Quarantine aangemaakt, hierin staan alleen configuratieinstellingen en DTA-bestanden. Ik heb hem wel nog een keer laten scannen, hier kwamen geen bijzonderheden uit. AVG is ook al enige tijd stil.

De log:

11:45:05.0846 4988 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

11:45:07.0884 4988 ============================================================

11:45:07.0884 4988 Current date / time: 2013/05/04 11:45:07.0884

11:45:07.0884 4988 SystemInfo:

11:45:07.0884 4988

11:45:07.0884 4988 OS Version: 6.0.6002 ServicePack: 2.0

11:45:07.0884 4988 Product type: Workstation

11:45:07.0884 4988 ComputerName: PC_VAN_TOSHIBA

11:45:07.0884 4988 UserName: Toshiba

11:45:07.0884 4988 Windows directory: C:\Windows

11:45:07.0884 4988 System windows directory: C:\Windows

11:45:07.0884 4988 Processor architecture: Intel x86

11:45:07.0884 4988 Number of processors: 2

11:45:07.0884 4988 Page size: 0x1000

11:45:07.0884 4988 Boot type: Normal boot

11:45:07.0884 4988 ============================================================

11:45:08.0321 4988 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050

11:45:08.0321 4988 ============================================================

11:45:08.0321 4988 \Device\Harddisk0\DR0:

11:45:08.0321 4988 MBR partitions:

11:45:08.0321 4988 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x95EB000

11:45:08.0321 4988 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x98D9800, BlocksNum 0x9140000

11:45:08.0321 4988 ============================================================

11:45:08.0352 4988 C: <-> \Device\Harddisk0\DR0\Partition1

11:45:08.0399 4988 D: <-> \Device\Harddisk0\DR0\Partition2

11:45:08.0399 4988 ============================================================

11:45:08.0399 4988 Initialize success

11:45:08.0399 4988 ============================================================

11:45:49.0284 4840 ============================================================

11:45:49.0284 4840 Scan started

11:45:49.0284 4840 Mode: Manual;

11:45:49.0284 4840 ============================================================

11:45:50.0345 4840 ================ Scan system memory ========================

11:45:50.0345 4840 System memory - ok

11:45:50.0361 4840 ================ Scan services =============================

11:45:50.0595 4840 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys

11:45:50.0595 4840 ACPI - ok

11:45:50.0673 4840 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys

11:45:50.0688 4840 adp94xx - ok

11:45:50.0720 4840 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys

11:45:50.0735 4840 adpahci - ok

11:45:50.0751 4840 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys

11:45:50.0766 4840 adpu160m - ok

11:45:50.0798 4840 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys

11:45:50.0798 4840 adpu320 - ok

11:45:50.0860 4840 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll

11:45:50.0860 4840 AeLookupSvc - ok

11:45:50.0954 4840 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys

11:45:50.0969 4840 AFD - ok

11:45:51.0016 4840 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys

11:45:51.0032 4840 agp440 - ok

11:45:51.0047 4840 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys

11:45:51.0063 4840 aic78xx - ok

11:45:51.0125 4840 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe

11:45:51.0141 4840 ALG - ok

11:45:51.0141 4840 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys

11:45:51.0156 4840 aliide - ok

11:45:51.0172 4840 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys

11:45:51.0188 4840 amdagp - ok

11:45:51.0203 4840 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys

11:45:51.0219 4840 amdide - ok

11:45:51.0234 4840 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys

11:45:51.0234 4840 AmdK7 - ok

11:45:51.0281 4840 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys

11:45:51.0297 4840 AmdK8 - ok

11:45:51.0390 4840 [ 45F47F79AD3F587A334345FD2969354B ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys

11:45:51.0390 4840 ApfiltrService - ok

11:45:51.0453 4840 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll

11:45:51.0453 4840 Appinfo - ok

11:45:51.0593 4840 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

11:45:51.0593 4840 Apple Mobile Device - ok

11:45:51.0671 4840 [ 0FE769CAE5855B53C90E23F85E7E89FF ] AppMgmt C:\Windows\System32\appmgmts.dll

11:45:51.0687 4840 AppMgmt - ok

11:45:51.0718 4840 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys

11:45:51.0734 4840 arc - ok

11:45:51.0765 4840 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys

11:45:51.0780 4840 arcsas - ok

11:45:51.0843 4840 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys

11:45:51.0843 4840 AsyncMac - ok

11:45:51.0874 4840 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys

11:45:51.0874 4840 atapi - ok

11:45:51.0921 4840 [ 6046A55F79DE9C581B8D5E9C1366CC81 ] athr C:\Windows\system32\DRIVERS\athr.sys

11:45:51.0936 4840 athr - ok

11:45:51.0983 4840 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

11:45:51.0983 4840 AudioEndpointBuilder - ok

11:45:51.0999 4840 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll

11:45:51.0999 4840 Audiosrv - ok

11:45:52.0108 4840 [ DB338A6BD3976904EB0F8343F51E64EB ] avg8wd C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

11:45:52.0108 4840 avg8wd - ok

11:45:52.0155 4840 [ BC12F2404BB6F2B6B2FF3C4C246CB752 ] AvgLdx86 C:\Windows\System32\Drivers\avgldx86.sys

11:45:52.0186 4840 AvgLdx86 - ok

11:45:52.0217 4840 [ 5903D729D4F0C5BCA74123C96A1B29E0 ] AvgMfx86 C:\Windows\System32\Drivers\avgmfx86.sys

11:45:52.0233 4840 AvgMfx86 - ok

11:45:52.0389 4840 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe

11:45:52.0389 4840 BBSvc - ok

11:45:52.0420 4840 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe

11:45:52.0420 4840 BBUpdate - ok

11:45:52.0560 4840 [ D2D165DE63B8398BF74483207FB16CA1 ] BecHelperService C:\Program Files\KPN\Mobiel Internet Software\BecHelperService.exe

11:45:52.0592 4840 BecHelperService - ok

11:45:52.0638 4840 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys

11:45:52.0638 4840 Beep - ok

11:45:52.0654 4840 blbdrive - ok

11:45:52.0748 4840 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe

11:45:52.0748 4840 Bonjour Service - ok

11:45:52.0779 4840 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys

11:45:52.0779 4840 bowser - ok

11:45:52.0826 4840 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys

11:45:52.0826 4840 BrFiltLo - ok

11:45:52.0841 4840 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys

11:45:52.0857 4840 BrFiltUp - ok

11:45:52.0888 4840 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll

11:45:52.0888 4840 Browser - ok

11:45:52.0919 4840 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys

11:45:52.0919 4840 Brserid - ok

11:45:52.0935 4840 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys

11:45:52.0950 4840 BrSerWdm - ok

11:45:52.0966 4840 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys

11:45:52.0966 4840 BrUsbMdm - ok

11:45:52.0997 4840 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys

11:45:52.0997 4840 BrUsbSer - ok

11:45:53.0028 4840 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys

11:45:53.0028 4840 BTHMODEM - ok

11:45:53.0106 4840 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys

11:45:53.0106 4840 cdfs - ok

11:45:53.0169 4840 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys

11:45:53.0169 4840 cdrom - ok

11:45:53.0231 4840 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll

11:45:53.0231 4840 CertPropSvc - ok

11:45:53.0262 4840 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys

11:45:53.0278 4840 circlass - ok

11:45:53.0325 4840 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys

11:45:53.0325 4840 CLFS - ok

11:45:53.0403 4840 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

11:45:53.0418 4840 clr_optimization_v2.0.50727_32 - ok

11:45:53.0512 4840 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

11:45:53.0512 4840 clr_optimization_v4.0.30319_32 - ok

11:45:53.0574 4840 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys

11:45:53.0574 4840 CmBatt - ok

11:45:53.0606 4840 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys

11:45:53.0621 4840 cmdide - ok

11:45:53.0652 4840 [ 76FFD950394C45196D09239EDC9B006B ] CnxtHdAudAddService C:\Windows\system32\drivers\CHDART.sys

11:45:53.0668 4840 CnxtHdAudAddService - ok

11:45:53.0699 4840 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys

11:45:53.0699 4840 Compbatt - ok

11:45:53.0715 4840 COMSysApp - ok

11:45:53.0762 4840 [ 596E452B5152EC9AFE8153D296459D2B ] ConfigFree Service C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

11:45:53.0762 4840 ConfigFree Service - ok

11:45:53.0777 4840 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys

11:45:53.0777 4840 crcdisk - ok

11:45:53.0793 4840 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys

11:45:53.0808 4840 Crusoe - ok

11:45:53.0855 4840 [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc C:\Windows\system32\cryptsvc.dll

11:45:53.0855 4840 CryptSvc - ok

11:45:53.0918 4840 [ 9BDB2E89BE8D0EF37B1F25C3D3FC192C ] CSC C:\Windows\system32\drivers\csc.sys

11:45:53.0933 4840 CSC - ok

11:45:53.0980 4840 [ 0A2095F92F6AE4FE6484D911B0C21E95 ] CscService C:\Windows\System32\cscsvc.dll

11:45:53.0980 4840 CscService - ok

11:45:54.0042 4840 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll

11:45:54.0042 4840 DcomLaunch - ok

11:45:54.0120 4840 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys

11:45:54.0120 4840 DfsC - ok

11:45:54.0214 4840 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe

11:45:54.0276 4840 DFSR - ok

11:45:54.0339 4840 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll

11:45:54.0339 4840 Dhcp - ok

11:45:54.0370 4840 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys

11:45:54.0370 4840 disk - ok

11:45:54.0401 4840 [ C8247DCE26E233A33CD6FC5D8F829880 ] DJUSB C:\Windows\system32\Drivers\DM2.sys

11:45:54.0417 4840 DJUSB - ok

11:45:54.0464 4840 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll

11:45:54.0464 4840 Dnscache - ok

11:45:54.0526 4840 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll

11:45:54.0542 4840 dot3svc - ok

11:45:54.0588 4840 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll

11:45:54.0588 4840 DPS - ok

11:45:54.0604 4840 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys

11:45:54.0604 4840 drmkaud - ok

11:45:54.0666 4840 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys

11:45:54.0666 4840 DXGKrnl - ok

11:45:54.0713 4840 [ 5D41BFB57FE676FB513F84D23E40E939 ] e.dentifier2 C:\Windows\system32\DRIVERS\aabed2.sys

11:45:54.0729 4840 e.dentifier2 - ok

11:45:54.0776 4840 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys

11:45:54.0791 4840 E1G60 - ok

11:45:54.0822 4840 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll

11:45:54.0838 4840 EapHost - ok

11:45:54.0885 4840 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys

11:45:54.0885 4840 Ecache - ok

11:45:54.0916 4840 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys

11:45:54.0932 4840 elxstor - ok

11:45:54.0994 4840 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll

11:45:54.0994 4840 EMDMgmt - ok

11:45:55.0056 4840 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll

11:45:55.0056 4840 EventSystem - ok

11:45:55.0119 4840 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys

11:45:55.0119 4840 exfat - ok

11:45:55.0166 4840 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys

11:45:55.0181 4840 fastfat - ok

11:45:55.0228 4840 [ DFBA0F60FA301E5B1BFB1403A93EE23E ] Fax C:\Windows\system32\fxssvc.exe

11:45:55.0228 4840 Fax - ok

11:45:55.0275 4840 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys

11:45:55.0290 4840 fdc - ok

11:45:55.0322 4840 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll

11:45:55.0322 4840 fdPHost - ok

11:45:55.0353 4840 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll

11:45:55.0353 4840 FDResPub - ok

11:45:55.0384 4840 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys

11:45:55.0384 4840 FileInfo - ok

11:45:55.0415 4840 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys

11:45:55.0431 4840 Filetrace - ok

11:45:55.0446 4840 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys

11:45:55.0446 4840 flpydisk - ok

11:45:55.0509 4840 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys

11:45:55.0509 4840 FltMgr - ok

11:45:55.0571 4840 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll

11:45:55.0587 4840 FontCache - ok

11:45:55.0665 4840 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

11:45:55.0665 4840 FontCache3.0.0.0 - ok

11:45:55.0696 4840 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys

11:45:55.0712 4840 Fs_Rec - ok

11:45:55.0727 4840 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys

11:45:55.0743 4840 gagp30kx - ok

11:45:55.0774 4840 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys

11:45:55.0790 4840 GEARAspiWDM - ok

11:45:55.0852 4840 [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys

11:45:55.0852 4840 ggflt - ok

11:45:55.0868 4840 [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys

11:45:55.0883 4840 ggsemc - ok

11:45:55.0930 4840 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll

11:45:55.0930 4840 gpsvc - ok

11:45:55.0992 4840 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe

11:45:55.0992 4840 gupdate - ok

11:45:56.0024 4840 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe

11:45:56.0024 4840 gupdatem - ok

11:45:56.0070 4840 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

11:45:56.0102 4840 gusvc - ok

11:45:56.0133 4840 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys

11:45:56.0148 4840 HdAudAddService - ok

11:45:56.0211 4840 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys

11:45:56.0211 4840 HDAudBus - ok

11:45:56.0242 4840 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys

11:45:56.0258 4840 HidBth - ok

11:45:56.0304 4840 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys

11:45:56.0320 4840 HidIr - ok

11:45:56.0351 4840 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll

11:45:56.0351 4840 hidserv - ok

11:45:56.0398 4840 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys

11:45:56.0398 4840 HidUsb - ok

11:45:56.0460 4840 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll

11:45:56.0460 4840 hkmsvc - ok

11:45:56.0476 4840 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys

11:45:56.0476 4840 HpCISSs - ok

11:45:56.0523 4840 [ CC267848CB3508E72762BE65734E764D ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys

11:45:56.0554 4840 HSF_DPV - ok

11:45:56.0585 4840 [ A2882945CC4B6E3E4E9E825590438888 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys

11:45:56.0585 4840 HSXHWAZL - ok

11:45:56.0632 4840 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys

11:45:56.0648 4840 HTTP - ok

11:45:56.0648 4840 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys

11:45:56.0663 4840 i2omp - ok

11:45:56.0726 4840 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys

11:45:56.0741 4840 i8042prt - ok

11:45:56.0788 4840 [ E5A0034847537EAEE3C00349D5C34C5F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys

11:45:56.0788 4840 iaStor - ok

11:45:56.0819 4840 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys

11:45:56.0835 4840 iaStorV - ok

11:45:56.0897 4840 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

11:45:56.0913 4840 IDriverT - ok

11:45:57.0006 4840 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe

11:45:57.0038 4840 idsvc - ok

11:45:57.0116 4840 [ 038815297078D236D8CC064C295A74C6 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys

11:45:57.0147 4840 igfx - ok

11:45:57.0194 4840 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys

11:45:57.0194 4840 iirsp - ok

11:45:57.0256 4840 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll

11:45:57.0256 4840 IKEEXT - ok

11:45:57.0287 4840 [ 98D303CCB3415E9202E82043B37D66DC ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys

11:45:57.0287 4840 IntcHdmiAddService - ok

11:45:57.0334 4840 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys

11:45:57.0334 4840 intelide - ok

11:45:57.0350 4840 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys

11:45:57.0350 4840 intelppm - ok

11:45:57.0396 4840 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll

11:45:57.0396 4840 IPBusEnum - ok

11:45:57.0443 4840 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys

11:45:57.0443 4840 IpFilterDriver - ok

11:45:57.0459 4840 IpInIp - ok

11:45:57.0474 4840 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys

11:45:57.0490 4840 IPMIDRV - ok

11:45:57.0521 4840 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys

11:45:57.0537 4840 IPNAT - ok

11:45:57.0630 4840 [ E46B17060D3962A384AE484094614788 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe

11:45:57.0630 4840 iPod Service - ok

11:45:57.0662 4840 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys

11:45:57.0677 4840 IRENUM - ok

11:45:57.0708 4840 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys

11:45:57.0724 4840 isapnp - ok

11:45:57.0771 4840 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys

11:45:57.0771 4840 iScsiPrt - ok

11:45:57.0786 4840 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys

11:45:57.0786 4840 iteatapi - ok

11:45:57.0802 4840 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys

11:45:57.0818 4840 iteraid - ok

11:45:57.0849 4840 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys

11:45:57.0864 4840 kbdclass - ok

11:45:57.0864 4840 [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys

11:45:57.0880 4840 kbdhid - ok

11:45:57.0911 4840 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe

11:45:57.0927 4840 KeyIso - ok

11:45:57.0974 4840 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys

11:45:57.0974 4840 KSecDD - ok

11:45:58.0036 4840 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll

11:45:58.0036 4840 KtmRm - ok

11:45:58.0083 4840 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll

11:45:58.0083 4840 LanmanServer - ok

11:45:58.0145 4840 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll

11:45:58.0145 4840 LanmanWorkstation - ok

11:45:58.0192 4840 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys

11:45:58.0192 4840 lltdio - ok

11:45:58.0239 4840 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll

11:45:58.0254 4840 lltdsvc - ok

11:45:58.0317 4840 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll

11:45:58.0317 4840 lmhosts - ok

11:45:58.0348 4840 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys

11:45:58.0348 4840 LSI_FC - ok

11:45:58.0364 4840 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys

11:45:58.0379 4840 LSI_SAS - ok

11:45:58.0395 4840 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys

11:45:58.0410 4840 LSI_SCSI - ok

11:45:58.0457 4840 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys

11:45:58.0457 4840 luafv - ok

11:45:58.0488 4840 [ D1A79F9CF0A0960DF4DAB08BEF847F43 ] massfilter C:\Windows\system32\DRIVERS\massfilter.sys

11:45:58.0504 4840 massfilter - ok

11:45:58.0566 4840 [ B78A412BDE0E567631698EE265FD4EB2 ] MaxMgr C:\Windows\system32\drivers\MaxMgr.sys

11:45:58.0566 4840 MaxMgr - ok

11:45:58.0613 4840 [ 9BA26B2E39DC793B3032B0C0D1C6FC82 ] MaxProtector32 C:\Windows\system32\drivers\MaxProtector32.sys

11:45:58.0613 4840 MaxProtector32 - ok

11:45:58.0676 4840 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe

11:45:58.0691 4840 McComponentHostService - ok

11:45:58.0722 4840 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys

11:45:58.0722 4840 mdmxsdk - ok

11:45:58.0754 4840 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys

11:45:58.0754 4840 megasas - ok

11:45:58.0800 4840 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll

11:45:58.0800 4840 MMCSS - ok

11:45:58.0847 4840 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys

11:45:58.0847 4840 Modem - ok

11:45:58.0910 4840 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys

11:45:58.0910 4840 monitor - ok

11:45:58.0941 4840 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys

11:45:58.0956 4840 mouclass - ok

11:45:58.0956 4840 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys

11:45:58.0972 4840 mouhid - ok

11:45:59.0019 4840 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys

11:45:59.0019 4840 MountMgr - ok

11:45:59.0066 4840 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys

11:45:59.0066 4840 mpio - ok

11:45:59.0112 4840 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys

11:45:59.0112 4840 mpsdrv - ok

11:45:59.0159 4840 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys

11:45:59.0159 4840 Mraid35x - ok

11:45:59.0206 4840 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys

11:45:59.0206 4840 MRxDAV - ok

11:45:59.0253 4840 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys

11:45:59.0253 4840 mrxsmb - ok

11:45:59.0268 4840 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys

11:45:59.0268 4840 mrxsmb10 - ok

11:45:59.0300 4840 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys

11:45:59.0300 4840 mrxsmb20 - ok

11:45:59.0331 4840 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys

11:45:59.0331 4840 msahci - ok

11:45:59.0378 4840 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys

11:45:59.0378 4840 msdsm - ok

11:45:59.0424 4840 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe

11:45:59.0440 4840 MSDTC - ok

11:45:59.0456 4840 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys

11:45:59.0471 4840 Msfs - ok

11:45:59.0487 4840 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys

11:45:59.0487 4840 msisadrv - ok

11:45:59.0518 4840 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll

11:45:59.0534 4840 MSiSCSI - ok

11:45:59.0549 4840 msiserver - ok

11:45:59.0580 4840 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys

11:45:59.0580 4840 MSKSSRV - ok

11:45:59.0627 4840 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys

11:45:59.0643 4840 MSPCLOCK - ok

11:45:59.0658 4840 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys

11:45:59.0658 4840 MSPQM - ok

11:45:59.0690 4840 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys

11:45:59.0690 4840 MsRPC - ok

11:45:59.0705 4840 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys

11:45:59.0705 4840 mssmbios - ok

11:45:59.0736 4840 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys

11:45:59.0736 4840 MSTEE - ok

11:45:59.0752 4840 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys

11:45:59.0752 4840 Mup - ok

11:45:59.0799 4840 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll

11:45:59.0799 4840 napagent - ok

11:45:59.0830 4840 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys

11:45:59.0830 4840 NativeWifiP - ok

11:45:59.0892 4840 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys

11:45:59.0892 4840 NDIS - ok

11:45:59.0939 4840 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys

11:45:59.0939 4840 NdisTapi - ok

11:45:59.0986 4840 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys

11:45:59.0986 4840 Ndisuio - ok

11:46:00.0017 4840 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys

11:46:00.0033 4840 NdisWan - ok

11:46:00.0064 4840 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys

11:46:00.0080 4840 NDProxy - ok

11:46:00.0095 4840 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys

11:46:00.0095 4840 NetBIOS - ok

11:46:00.0142 4840 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys

11:46:00.0158 4840 netbt - ok

11:46:00.0173 4840 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe

11:46:00.0173 4840 Netlogon - ok

11:46:00.0221 4840 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll

11:46:00.0237 4840 Netman - ok

11:46:00.0268 4840 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll

11:46:00.0268 4840 netprofm - ok

11:46:00.0315 4840 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe

11:46:00.0330 4840 NetTcpPortSharing - ok

11:46:00.0439 4840 [ 6522DD40A5F67CED020BD81B856613FB ] NETw4v32 C:\Windows\system32\DRIVERS\NETw4v32.sys

11:46:00.0486 4840 NETw4v32 - ok

11:46:00.0533 4840 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys

11:46:00.0533 4840 nfrd960 - ok

11:46:00.0580 4840 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll

11:46:00.0580 4840 NlaSvc - ok

11:46:00.0611 4840 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys

11:46:00.0627 4840 Npfs - ok

11:46:00.0658 4840 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll

11:46:00.0658 4840 nsi - ok

11:46:00.0689 4840 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys

11:46:00.0705 4840 nsiproxy - ok

11:46:00.0767 4840 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys

11:46:00.0783 4840 Ntfs - ok

11:46:00.0814 4840 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys

11:46:00.0829 4840 ntrigdigi - ok

11:46:00.0907 4840 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys

11:46:00.0923 4840 Null - ok

11:46:00.0939 4840 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys

11:46:00.0954 4840 nvraid - ok

11:46:00.0970 4840 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys

11:46:00.0985 4840 nvstor - ok

11:46:01.0001 4840 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys

11:46:01.0017 4840 nv_agp - ok

11:46:01.0017 4840 NwlnkFlt - ok

11:46:01.0017 4840 NwlnkFwd - ok

11:46:01.0079 4840 [ D955D5DE998DB2476BF0892BE3A96C26 ] o2flash C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe

11:46:01.0079 4840 o2flash - ok

11:46:01.0095 4840 [ D51942F12090FC947CA8AA01736DADE2 ] O2MDRDR C:\Windows\system32\DRIVERS\o2media.sys

11:46:01.0110 4840 O2MDRDR - ok

11:46:01.0188 4840 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE

11:46:01.0220 4840 odserv - ok

11:46:01.0252 4840 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys

11:46:01.0267 4840 ohci1394 - ok

11:46:01.0298 4840 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE

11:46:01.0314 4840 ose - ok

11:46:01.0408 4840 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll

11:46:01.0423 4840 p2pimsvc - ok

11:46:01.0439 4840 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll

11:46:01.0439 4840 p2psvc - ok

11:46:01.0470 4840 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys

11:46:01.0470 4840 Parport - ok

11:46:01.0501 4840 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys

11:46:01.0501 4840 partmgr - ok

11:46:01.0532 4840 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys

11:46:01.0532 4840 Parvdm - ok

11:46:01.0579 4840 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll

11:46:01.0579 4840 PcaSvc - ok

11:46:01.0610 4840 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys

11:46:01.0610 4840 pci - ok

11:46:01.0626 4840 [ 3B1901E401473E03EB8C874271E50C26 ] pciide C:\Windows\system32\drivers\pciide.sys

11:46:01.0642 4840 pciide - ok

11:46:01.0657 4840 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys

11:46:01.0673 4840 pcmcia - ok

11:46:01.0720 4840 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys

11:46:01.0720 4840 PEAUTH - ok

11:46:01.0813 4840 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll

11:46:01.0829 4840 pla - ok

11:46:01.0860 4840 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll

11:46:01.0876 4840 PlugPlay - ok

11:46:01.0922 4840 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll

11:46:01.0922 4840 PNRPAutoReg - ok

11:46:01.0938 4840 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll

11:46:01.0954 4840 PNRPsvc - ok

11:46:01.0969 4840 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll

11:46:02.0000 4840 PolicyAgent - ok

11:46:02.0032 4840 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys

11:46:02.0047 4840 PptpMiniport - ok

11:46:02.0078 4840 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys

11:46:02.0094 4840 Processor - ok

11:46:02.0125 4840 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll

11:46:02.0125 4840 ProfSvc - ok

11:46:02.0141 4840 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe

11:46:02.0141 4840 ProtectedStorage - ok

11:46:02.0172 4840 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys

11:46:02.0172 4840 PSched - ok

11:46:02.0235 4840 [ 674EBA70A52C02696E503B0A57AE6372 ] QIOMem C:\Windows\system32\DRIVERS\QIOMem.sys

11:46:02.0235 4840 QIOMem - ok

11:46:02.0282 4840 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys

11:46:02.0313 4840 ql2300 - ok

11:46:02.0329 4840 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys

11:46:02.0345 4840 ql40xx - ok

11:46:02.0391 4840 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll

11:46:02.0391 4840 QWAVE - ok

11:46:02.0423 4840 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys

11:46:02.0423 4840 QWAVEdrv - ok

11:46:02.0501 4840 [ 70DBDAB246C18B78E2200D6401D038BE ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll

11:46:02.0501 4840 RapiMgr - ok

11:46:02.0532 4840 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys

11:46:02.0547 4840 RasAcd - ok

11:46:02.0594 4840 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll

11:46:02.0594 4840 RasAuto - ok

11:46:02.0625 4840 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys

11:46:02.0641 4840 Rasl2tp - ok

11:46:02.0688 4840 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll

11:46:02.0688 4840 RasMan - ok

11:46:02.0719 4840 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys

11:46:02.0735 4840 RasPppoe - ok

11:46:02.0781 4840 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys

11:46:02.0797 4840 RasSstp - ok

11:46:02.0828 4840 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys

11:46:02.0844 4840 rdbss - ok

11:46:02.0891 4840 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys

11:46:02.0891 4840 RDPCDD - ok

11:46:02.0906 4840 [ 943B18305EAE3935598A9B4A3D560B4C ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys

11:46:02.0922 4840 rdpdr - ok

11:46:02.0937 4840 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys

11:46:02.0937 4840 RDPENCDD - ok

11:46:02.0984 4840 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys

11:46:03.0000 4840 RDPWD - ok

11:46:03.0031 4840 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll

11:46:03.0031 4840 RemoteAccess - ok

11:46:03.0078 4840 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll

11:46:03.0078 4840 RemoteRegistry - ok

11:46:03.0125 4840 [ 75E8A6BFA7374ABA833AE92BF41AE4E6 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys

11:46:03.0125 4840 ROOTMODEM - ok

11:46:03.0156 4840 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe

11:46:03.0171 4840 RpcLocator - ok

11:46:03.0218 4840 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll

11:46:03.0218 4840 RpcSs - ok

11:46:03.0249 4840 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys

11:46:03.0265 4840 rspndr - ok

11:46:03.0265 4840 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe

11:46:03.0265 4840 SamSs - ok

11:46:03.0296 4840 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys

11:46:03.0312 4840 sbp2port - ok

11:46:03.0343 4840 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll

11:46:03.0343 4840 SCardSvr - ok

11:46:03.0405 4840 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll

11:46:03.0421 4840 Schedule - ok

11:46:03.0437 4840 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll

11:46:03.0437 4840 SCPolicySvc - ok

11:46:03.0483 4840 [ 1BD2D39C88D4F6112949FD84FCFBDB30 ] SDActMon C:\Windows\system32\drivers\SDActMon.sys

11:46:03.0499 4840 SDActMon - ok

11:46:03.0530 4840 [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys

11:46:03.0546 4840 sdbus - ok

11:46:03.0577 4840 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll

11:46:03.0577 4840 SDRSVC - ok

11:46:03.0608 4840 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys

11:46:03.0608 4840 secdrv - ok

11:46:03.0671 4840 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll

11:46:03.0671 4840 seclogon - ok

11:46:03.0686 4840 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll

11:46:03.0686 4840 SENS - ok

11:46:03.0702 4840 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys

11:46:03.0702 4840 Serenum - ok

11:46:03.0733 4840 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys

11:46:03.0733 4840 Serial - ok

11:46:03.0749 4840 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys

11:46:03.0749 4840 sermouse - ok

11:46:03.0811 4840 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll

11:46:03.0811 4840 SessionEnv - ok

11:46:03.0827 4840 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys

11:46:03.0842 4840 sffdisk - ok

11:46:03.0873 4840 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys

11:46:03.0889 4840 sffp_mmc - ok

11:46:03.0905 4840 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys

11:46:03.0920 4840 sffp_sd - ok

11:46:03.0920 4840 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys

11:46:03.0936 4840 sfloppy - ok

11:46:03.0983 4840 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll

11:46:03.0983 4840 ShellHWDetection - ok

11:46:03.0998 4840 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys

11:46:04.0014 4840 sisagp - ok

11:46:04.0029 4840 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys

11:46:04.0045 4840 SiSRaid2 - ok

11:46:04.0061 4840 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys

11:46:04.0061 4840 SiSRaid4 - ok

11:46:04.0154 4840 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe

11:46:04.0154 4840 SkypeUpdate - ok

11:46:04.0326 4840 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe

11:46:04.0373 4840 slsvc - ok

11:46:04.0388 4840 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll

11:46:04.0388 4840 SLUINotify - ok

11:46:04.0435 4840 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys

11:46:04.0451 4840 Smb - ok

11:46:04.0497 4840 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe

11:46:04.0497 4840 SNMPTRAP - ok

11:46:04.0544 4840 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys

11:46:04.0544 4840 spldr - ok

11:46:04.0591 4840 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe

11:46:04.0591 4840 Spooler - ok

11:46:04.0685 4840 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys

11:46:04.0685 4840 srv - ok

11:46:04.0731 4840 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys

11:46:04.0731 4840 srv2 - ok

11:46:04.0794 4840 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys

11:46:04.0794 4840 srvnet - ok

11:46:04.0825 4840 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll

11:46:04.0825 4840 SSDPSRV - ok

11:46:04.0903 4840 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll

11:46:04.0903 4840 SstpSvc - ok

11:46:04.0950 4840 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll

11:46:04.0965 4840 stisvc - ok

11:46:04.0981 4840 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys

11:46:04.0997 4840 swenum - ok

11:46:05.0043 4840 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll

11:46:05.0043 4840 swprv - ok

11:46:05.0075 4840 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys

11:46:05.0075 4840 Symc8xx - ok

11:46:05.0090 4840 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys

11:46:05.0106 4840 Sym_hi - ok

11:46:05.0106 4840 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys

11:46:05.0121 4840 Sym_u3 - ok

11:46:05.0168 4840 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll

11:46:05.0184 4840 SysMain - ok

11:46:05.0199 4840 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll

11:46:05.0215 4840 TabletInputService - ok

11:46:05.0262 4840 [ 3A710AB5FD0F7F32CC3F65067FB27B12 ] taphss6 C:\Windows\system32\DRIVERS\taphss6.sys

11:46:05.0262 4840 taphss6 - ok

11:46:05.0309 4840 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll

11:46:05.0309 4840 TapiSrv - ok

11:46:05.0355 4840 [ 27A2C318CD28CFB3EB2200FD96AF1E58 ] tapvpn C:\Windows\system32\DRIVERS\tapvpn.sys

11:46:05.0371 4840 tapvpn - ok

11:46:05.0402 4840 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll

11:46:05.0418 4840 TBS - ok

11:46:05.0465 4840 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys

11:46:05.0480 4840 Tcpip - ok

11:46:05.0496 4840 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys

11:46:05.0511 4840 Tcpip6 - ok

11:46:05.0543 4840 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys

11:46:05.0543 4840 tcpipreg - ok

11:46:05.0574 4840 [ 1825BCEB47BF41C5A9F0E44DE82FC27A ] tdcmdpst C:\Windows\system32\DRIVERS\tdcmdpst.sys

11:46:05.0574 4840 tdcmdpst - ok

11:46:05.0605 4840 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys

11:46:05.0621 4840 TDPIPE - ok

11:46:05.0636 4840 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys

11:46:05.0652 4840 TDTCP - ok

11:46:05.0683 4840 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys

11:46:05.0699 4840 tdx - ok

11:46:05.0714 4840 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys

11:46:05.0730 4840 TermDD - ok

11:46:05.0777 4840 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll

11:46:05.0777 4840 TermService - ok

11:46:05.0792 4840 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll

11:46:05.0792 4840 Themes - ok

11:46:05.0823 4840 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll

11:46:05.0823 4840 THREADORDER - ok

11:46:05.0870 4840 [ E47F35A87FF0DA38DEF37A0EB0C2D2DF ] TNaviSrv C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe

11:46:05.0870 4840 TNaviSrv - ok

11:46:05.0901 4840 [ C5AC715B65B01788ABC22D10749DDDD8 ] TODDSrv C:\Windows\system32\TODDSrv.exe

11:46:05.0901 4840 TODDSrv - ok

11:46:05.0979 4840 [ DA6903958CBDC091FFCBBCA70CCFF34C ] TosCoSrv C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe

11:46:05.0979 4840 TosCoSrv - ok

11:46:06.0042 4840 [ 2E7315B147E524E055026E6634B14EA6 ] TOSHIBA Bluetooth Service c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

11:46:06.0042 4840 TOSHIBA Bluetooth Service - ok

11:46:06.0057 4840 [ 22690DFFC7F2A18279A7A0489AA02BAC ] TOSHIBA SMART Log Service C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

11:46:06.0057 4840 TOSHIBA SMART Log Service - ok

11:46:06.0104 4840 [ 8D624D3BD1F2D78BD1C01A2D4E954B4E ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys

11:46:06.0120 4840 tosporte - ok

11:46:06.0167 4840 [ AE43138B0DEA239B3621B0FAF1BB1FE7 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys

11:46:06.0167 4840 tosrfbd - ok

11:46:06.0198 4840 [ 181E217A7A326817D97946D045B3CB46 ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys

11:46:06.0198 4840 tosrfbnp - ok

11:46:06.0229 4840 [ E90ACE3B4FA7A85F992BC21EB779C407 ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys

11:46:06.0229 4840 Tosrfcom - ok

11:46:06.0260 4840 [ 5C4103544612E5011EF46301B93D1AA6 ] tosrfec C:\Windows\system32\DRIVERS\tosrfec.sys

11:46:06.0276 4840 tosrfec - ok

11:46:06.0307 4840 [ 87700714F25131ED21901D617B8B321F ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys

11:46:06.0323 4840 Tosrfhid - ok

11:46:06.0338 4840 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys

11:46:06.0354 4840 tosrfnds - ok

11:46:06.0385 4840 [ 98C04A6432CE9C2AD328F57B9384D348 ] Tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys

11:46:06.0385 4840 Tosrfusb - ok

11:46:06.0447 4840 [ 1EA5F27C29405BF49799FECA77186DA9 ] tos_sps32 C:\Windows\system32\DRIVERS\tos_sps32.sys

11:46:06.0447 4840 tos_sps32 - ok

11:46:06.0479 4840 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll

11:46:06.0479 4840 TrkWks - ok

11:46:06.0557 4840 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe

11:46:06.0557 4840 TrustedInstaller - ok

11:46:06.0588 4840 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys

11:46:06.0603 4840 tssecsrv - ok

11:46:06.0619 4840 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys

11:46:06.0635 4840 tunmp - ok

11:46:06.0666 4840 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys

11:46:06.0681 4840 tunnel - ok

11:46:06.0713 4840 [ 792A8B80F8188ABA4B2BE271583F3E46 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS

11:46:06.0713 4840 TVALZ - ok

11:46:06.0853 4840 [ 685A80878BAB2E587B07053793C47BC4 ] TVersityMediaServer C:\Users\Toshiba\AppData\Local\TVersity\Media Server\MediaServer.exe

11:46:06.0869 4840 TVersityMediaServer - ok

11:46:06.0900 4840 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys

11:46:06.0915 4840 uagp35 - ok

11:46:06.0947 4840 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys

11:46:06.0962 4840 udfs - ok

11:46:07.0009 4840 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe

11:46:07.0009 4840 UI0Detect - ok

11:46:07.0040 4840 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys

11:46:07.0040 4840 uliagpkx - ok

11:46:07.0071 4840 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys

11:46:07.0087 4840 uliahci - ok

11:46:07.0103 4840 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys

11:46:07.0118 4840 UlSata - ok

11:46:07.0134 4840 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys

11:46:07.0149 4840 ulsata2 - ok

11:46:07.0181 4840 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys

11:46:07.0196 4840 umbus - ok

11:46:07.0227 4840 [ 8A66360F38F81E960E2367B428CBD5D9 ] UmRdpService C:\Windows\System32\umrdp.dll

11:46:07.0243 4840 UmRdpService - ok

11:46:07.0290 4840 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll

11:46:07.0290 4840 upnphost - ok

11:46:07.0321 4840 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys

11:46:07.0337 4840 USBAAPL - ok

11:46:07.0368 4840 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys

11:46:07.0368 4840 usbccgp - ok

11:46:07.0415 4840 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys

11:46:07.0415 4840 usbcir - ok

11:46:07.0477 4840 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys

11:46:07.0477 4840 usbehci - ok

11:46:07.0508 4840 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys

11:46:07.0508 4840 usbhub - ok

11:46:07.0539 4840 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys

11:46:07.0555 4840 usbohci - ok

11:46:07.0586 4840 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys

11:46:07.0586 4840 usbprint - ok

11:46:07.0617 4840 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys

11:46:07.0633 4840 usbscan - ok

11:46:07.0664 4840 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS

11:46:07.0680 4840 USBSTOR - ok

11:46:07.0711 4840 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys

11:46:07.0727 4840 usbuhci - ok

11:46:07.0789 4840 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys

11:46:07.0789 4840 usbvideo - ok

11:46:07.0851 4840 [ 35C9095FA7076466AFBFC5B9EC4B779E ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys

11:46:07.0851 4840 usb_rndisx - ok

11:46:07.0914 4840 [ 8C5094A8AB24DE7496C7C19942F2DF04 ] UVCFTR C:\Windows\system32\Drivers\UVCFTR_S.SYS

11:46:07.0914 4840 UVCFTR - ok

11:46:07.0961 4840 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll

11:46:07.0961 4840 UxSms - ok

11:46:07.0992 4840 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe

11:46:08.0007 4840 vds - ok

11:46:08.0039 4840 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys

11:46:08.0039 4840 vga - ok

11:46:08.0070 4840 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys

11:46:08.0070 4840 VgaSave - ok

11:46:08.0085 4840 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys

11:46:08.0101 4840 viaagp - ok

11:46:08.0117 4840 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys

11:46:08.0132 4840 ViaC7 - ok

11:46:08.0148 4840 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys

11:46:08.0163 4840 viaide - ok

11:46:08.0195 4840 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys

11:46:08.0195 4840 volmgr - ok

11:46:08.0241 4840 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys

11:46:08.0241 4840 volmgrx - ok

11:46:08.0273 4840 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys

11:46:08.0273 4840 volsnap - ok

11:46:08.0319 4840 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys

11:46:08.0319 4840 vsmraid - ok

11:46:08.0382 4840 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe

11:46:08.0397 4840 VSS - ok

11:46:08.0444 4840 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll

11:46:08.0460 4840 W32Time - ok

11:46:08.0475 4840 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys

11:46:08.0491 4840 WacomPen - ok

11:46:08.0522 4840 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys

11:46:08.0538 4840 Wanarp - ok

11:46:08.0538 4840 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys

11:46:08.0538 4840 Wanarpv6 - ok

11:46:08.0694 4840 [ 20B23332885DFB93FE0185362EE811E9 ] wbengine C:\Windows\system32\wbengine.exe

11:46:08.0709 4840 wbengine - ok

11:46:08.0756 4840 [ 779F9C90D3FE9C70B6FFD8EF035F3E83 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll

11:46:08.0756 4840 WcesComm - ok

11:46:08.0865 4840 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll

11:46:08.0865 4840 wcncsvc - ok

11:46:08.0881 4840 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll

11:46:08.0897 4840 WcsPlugInService - ok

11:46:08.0959 4840 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys

11:46:08.0959 4840 Wd - ok

11:46:09.0006 4840 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys

11:46:09.0021 4840 Wdf01000 - ok

11:46:09.0053 4840 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll

11:46:09.0053 4840 WdiServiceHost - ok

11:46:09.0053 4840 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll

11:46:09.0053 4840 WdiSystemHost - ok

11:46:09.0099 4840 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll

11:46:09.0115 4840 WebClient - ok

11:46:09.0146 4840 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll

11:46:09.0162 4840 Wecsvc - ok

11:46:09.0193 4840 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll

11:46:09.0193 4840 wercplsupport - ok

11:46:09.0240 4840 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll

11:46:09.0240 4840 WerSvc - ok

11:46:09.0287 4840 [ 0ACD399F5DB3DF1B58903CF4949AB5A8 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys

11:46:09.0302 4840 winachsf - ok

11:46:09.0318 4840 WinHttpAutoProxySvc - ok

11:46:09.0365 4840 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll

11:46:09.0380 4840 Winmgmt - ok

11:46:09.0489 4840 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll

11:46:09.0521 4840 WinRM - ok

11:46:09.0552 4840 [ 676F4B665BDD8053EAA53AC1695B8074 ] winusb C:\Windows\system32\DRIVERS\winusb.sys

11:46:09.0567 4840 winusb - ok

11:46:09.0879 4840 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll

11:46:09.0879 4840 Wlansvc - ok

11:46:09.0942 4840 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys

11:46:09.0942 4840 WmiAcpi - ok

11:46:10.0004 4840 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe

11:46:10.0004 4840 wmiApSrv - ok

11:46:10.0113 4840 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe

11:46:10.0129 4840 WMPNetworkSvc - ok

11:46:10.0160 4840 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll

11:46:10.0176 4840 WPDBusEnum - ok

11:46:10.0191 4840 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys

11:46:10.0207 4840 WpdUsb - ok

11:46:10.0347 4840 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

11:46:10.0347 4840 WPFFontCache_v0400 - ok

11:46:10.0379 4840 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys

11:46:10.0394 4840 ws2ifsl - ok

11:46:10.0394 4840 WSearch - ok

11:46:10.0457 4840 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys

11:46:10.0472 4840 WUDFRd - ok

11:46:10.0503 4840 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll

11:46:10.0519 4840 wudfsvc - ok

11:46:10.0535 4840 [ DAB33CFA9DD24251AAA389FF36B64D4B ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys

11:46:10.0535 4840 XAudio - ok

11:46:10.0566 4840 [ CD5F291A1161F15896D1A4D63DAFF5DF ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe

11:46:10.0566 4840 XAudioService - ok

11:46:10.0597 4840 [ 04E268ADFC81964C49DC0C082D520F7E ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys

11:46:10.0597 4840 yukonwlh - ok

11:46:10.0659 4840 [ 32396B4D2BF707D81C20E5E9022A2055 ] ZTEusbmdm6k C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys

11:46:10.0675 4840 ZTEusbmdm6k - ok

11:46:10.0722 4840 [ 48B9F83939F56622FAB71B526D28D89F ] ZTEusbnet C:\Windows\system32\DRIVERS\ZTEusbnet.sys

11:46:10.0737 4840 ZTEusbnet - ok

11:46:10.0769 4840 [ 32396B4D2BF707D81C20E5E9022A2055 ] ZTEusbnmea C:\Windows\system32\DRIVERS\ZTEusbnmea.sys

11:46:10.0769 4840 ZTEusbnmea - ok

11:46:10.0784 4840 [ 32396B4D2BF707D81C20E5E9022A2055 ] ZTEusbser6k C:\Windows\system32\DRIVERS\ZTEusbser6k.sys

11:46:10.0800 4840 ZTEusbser6k - ok

11:46:10.0831 4840 ================ Scan global ===============================

11:46:10.0862 4840 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll

11:46:10.0909 4840 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll

11:46:10.0940 4840 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll

11:46:10.0987 4840 [ 8737764F4FD36D6808EE80578409C843 ] C:\Windows\system32\services.exe

11:46:11.0003 4840 C:\Windows\system32\services.exe ( Virus.Win32.ZAccess.m ) - infected

11:46:11.0003 4840 C:\Windows\system32\services.exe - detected Virus.Win32.ZAccess.m (0)

11:46:11.0003 4840 ================ Scan MBR ==================================

11:46:11.0018 4840 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0

11:46:11.0408 4840 \Device\Harddisk0\DR0 - ok

11:46:11.0408 4840 ================ Scan VBR ==================================

11:46:11.0424 4840 [ E542D35AFCABE8AED681FB7AA576B9AF ] \Device\Harddisk0\DR0\Partition1

11:46:11.0424 4840 \Device\Harddisk0\DR0\Partition1 - ok

11:46:11.0439 4840 [ 40E2F7BC0216B311370FD4032E021BC9 ] \Device\Harddisk0\DR0\Partition2

11:46:11.0439 4840 \Device\Harddisk0\DR0\Partition2 - ok

11:46:11.0439 4840 ============================================================

11:46:11.0439 4840 Scan finished

11:46:11.0439 4840 ============================================================

11:46:11.0455 5892 Detected object count: 1

11:46:11.0455 5892 Actual detected object count: 1

11:46:45.0834 5892 C:\Windows\system32\services.exe - copied to quarantine

11:46:47.0803 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\@ - copied to quarantine

11:46:47.0803 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\00000001.@ - copied to quarantine

11:46:47.0803 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\80000000.@ - copied to quarantine

11:46:47.0813 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\800000cb.@ - copied to quarantine

11:46:47.0843 5892 C:\Users\Toshiba\AppData\Local\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\@ - copied to quarantine

11:46:47.0873 5892 C:\Users\Toshiba\AppData\Local\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\80000000.@ - copied to quarantine

11:46:53.0309 5892 Backup copy found, using it..

11:46:53.0388 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\@ - will be deleted on reboot

11:46:53.0389 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\00000001.@ - will be deleted on reboot

11:46:53.0389 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\80000000.@ - will be deleted on reboot

11:46:53.0389 5892 C:\Windows\installer\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\800000cb.@ - will be deleted on reboot

11:46:53.0405 5892 C:\Users\Toshiba\AppData\Local\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\@ - will be deleted on reboot

11:46:53.0406 5892 C:\Users\Toshiba\AppData\Local\{589ae09e-926c-da4f-68ef-7d0feea3ff19}\U\80000000.@ - will be deleted on reboot

11:46:53.0407 5892 C:\Windows\system32\services.exe - will be cured on reboot

11:46:53.0407 5892 C:\Windows\system32\services.exe ( Virus.Win32.ZAccess.m ) - User select action: Cure

11:47:00.0330 5044 Deinitialize success

Link naar reactie
Delen op andere sites

Hoi Kape,

Ik laat AVG een gehele scan doen, hij is nogsteeds bezig, na 2 uur heeft hij 30 threats gevonden, waaronder 2 Trojan Horse Generic30.HEH in onder andere C:\toshiba\drivers\valueaddedpackage\data1.can en een submap hiervan. de rest zijn tracking coockies en virus found HTML/Framer in de system32 map

Link naar reactie
Delen op andere sites

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

Hier kan je lezen hoe je Combofix moet gebruiken.

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen: klik hier of hier

2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.

3. Dubbelklik op "Combofix.exe" om de tool te starten.

4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registry key that has been marked for deletion", herstart dan de computer.

5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

Zie bijgaand het logje, ik heb nadat het programma klaar was handmatig de computer opnieuw opgestart; hij gaf bij het openen van bijv chrome de melding van bewerking op een registerkey die gemarkeerd staat voor verwijdering. Na het opnieuw opstarten is dit weg.

ComboFix 13-05-04.01 - Toshiba 05-05-2013 10:50:17.1.2 - x86

Microsoft® Windows Vista™ Business 6.0.6002.2.1252.31.1043.18.3062.1658 [GMT 2:00]

Gestart vanuit: c:\users\Toshiba\Downloads\ComboFix.exe

AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}

SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Nieuw herstelpunt werd aangemaakt

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\Complitly

c:\program files\Complitly\chrome\ComplitlyChrome.crx

c:\program files\Complitly\FireFoxExtensionWithFF8Fix.exe

c:\program files\Complitly\FireFoxUninstaller.exe

c:\program files\Complitly\InstTracker.exe

c:\program files\Complitly\support@Complitly.com\chrome.manifest

c:\program files\Complitly\support@Complitly.com\chrome\content\appIcon.png

c:\program files\Complitly\support@Complitly.com\chrome\content\browserOverlay.xul

c:\program files\Complitly\support@Complitly.com\chrome\content\options.js

c:\program files\Complitly\support@Complitly.com\chrome\content\options.xul

c:\program files\Complitly\support@Complitly.com\chrome\content\utils.js

c:\program files\Complitly\support@Complitly.com\defaults\preferences\predictad.js

c:\program files\Complitly\support@Complitly.com\install.rdf

c:\program files\Complitly\System.Data.SQLite.dll

c:\program files\Complitly\unins000.dat

c:\program files\Complitly\unins000.exe

c:\program files\DealPly

c:\program files\DealPly\DealPly.crx

c:\program files\DealPly\DealPlyUpdate.exe

c:\program files\DealPly\DealPlyUpdate.log

c:\program files\DealPly\DealPlyUpdateRun.exe

c:\program files\DealPly\icon.ico

c:\program files\DealPly\uninst.exe

c:\users\Toshiba\AppData\Local\Temp\ppcrlui_3392_2

c:\users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3 .lnk

c:\windows\security\Database\tmp.edb

c:\windows\system32\drivers\etc\hosts.ics

c:\windows\system32\drivers\MaxTdss.sys

c:\windows\system32\pt

c:\windows\system32\pt\toscdspd.cpl.mui

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-04-05 to 2013-05-05 ))))))))))))))))))))))))))))))

.

.

2013-05-04 09:46 . 2013-05-04 09:46 -------- d-----w- C:\TDSSKiller_Quarantine

2013-04-28 21:32 . 2013-04-28 21:32 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software

2013-04-28 21:18 . 2013-04-28 21:18 -------- d-----w- c:\users\Toshiba\AppData\Roaming\TuneUp Software

2013-04-28 21:17 . 2013-04-28 21:17 -------- d-----w- C:\$AVG

2013-04-28 21:17 . 2013-04-28 21:19 -------- d-----w- c:\programdata\AVG2013

2013-04-28 21:14 . 2013-04-28 21:14 -------- d--h--w- c:\programdata\Common Files

2013-04-28 21:14 . 2013-05-03 12:58 -------- d-----w- c:\programdata\MFAData

2013-04-28 21:14 . 2013-04-28 22:23 -------- d-----w- c:\users\Toshiba\AppData\Local\Avg2013

2013-04-28 21:14 . 2013-04-28 21:14 -------- d-----w- c:\users\Toshiba\AppData\Local\MFAData

2013-04-28 21:13 . 2013-04-28 21:14 -------- d-----w- c:\programdata\AVG8UPG

2013-04-28 20:54 . 2013-04-28 21:03 -------- d-----w- C:\MaxAVLiveUpdate

2013-04-28 20:44 . 2013-04-13 18:20 117248 ----a-w- c:\windows\system32\MaxNative.exe

2013-04-28 20:43 . 2013-04-13 18:38 77792 ----a-w- c:\windows\system32\drivers\MaxProtector64.sys

2013-04-28 20:43 . 2013-04-13 18:38 68576 ----a-w- c:\windows\system32\drivers\MaxProc64.sys

2013-04-28 20:43 . 2013-04-13 18:38 74208 ----a-w- c:\windows\system32\drivers\SDActMon2K.sys

2013-04-28 20:43 . 2013-05-03 15:04 -------- d-----w- c:\program files\Max Spyware Detector

2013-04-28 20:43 . 2013-04-13 18:38 13280 ----a-w- c:\windows\system32\drivers\004.sys

2013-04-28 20:43 . 2013-04-13 18:38 85984 ----a-w- c:\windows\system32\drivers\MaxProtector32.sys

2013-04-28 20:43 . 2013-04-13 18:38 72160 ----a-w- c:\windows\system32\drivers\MaxMgr.sys

2013-04-28 20:43 . 2013-04-13 18:38 123360 ----a-w- c:\windows\system32\drivers\SDActMon.sys

2013-04-28 20:39 . 2013-04-28 20:43 -------- d-----w- c:\programdata\Max Secure

2013-04-28 20:36 . 2013-04-28 20:36 -------- d-----w- c:\users\Toshiba\AppData\Local\Max Secure Software

2013-04-28 20:35 . 2013-05-03 15:04 -------- d-----w- c:\users\Toshiba\AppData\Roaming\GetRightToGo

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-04 09:47 . 2009-09-24 16:26 279552 ----a-w- c:\windows\system32\services.exe

2013-04-04 12:50 . 2011-08-13 09:14 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

2007-03-12 17:59 . 2007-03-12 17:59 299008 ----a-w- c:\program files\navigram_register.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-12-29 430080]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-24 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-25 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-25 154136]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-25 129560]

"NDSTray.exe"="NDSTray.exe" [bU]

"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]

"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [2007-06-18 1507328]

"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]

"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]

"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-25 413696]

"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]

"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-01-25 509816]

"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]

"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2013-04-28 2042208]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]

"CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-1-25 2938184]

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-5-3 66864]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

WindowsMobile REG_MULTI_SZ wcescomm rapimgr

LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-04-16 18:49 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe

.

Inhoud van de 'Gedeelde Taken' map

.

2013-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:56]

.

2013-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 11:56]

.

.

------- Bijkomende Scan -------

.

uDefault_Search_URL = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000

TCP: DhcpNameServer = 192.168.2.254

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

FF - ProfilePath - c:\users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\03jh1t15.default\

FF - prefs.js: browser.search.selectedEngine -

FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=119998&babsrc=HP_ss&mntrId=76e116c1000000000000001f3b8a9c93

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=119998&babsrc=adbartrp&mntrId=76e116c1000000000000001f3b8a9c93&q=

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

FF - Ext: Complitly - Speed up your search with your personal search suggestions tool: {33e0daa6-3af3-d8b5-6752-10e949c61516} - %profile%\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}

FF - Ext: DealPly: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} - %profile%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}

FF - user.js: extensions.BabylonToolbar_i.id - 76e116c1000000000000001f3b8a9c93

FF - user.js: extensions.BabylonToolbar_i.hardId - 76e116c1000000000000001f3b8a9c93

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15403

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:59

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=119998

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

.

- - - - ORPHANS VERWIJDERD - - - -

.

WebBrowser-{3BBD3C14-4C16-4989-8366-95BC9179779D} - (no file)

HKLM-Run-SDAutoScan - (no file)

SafeBoot-81871137.sys

AddRemove-Alchemy Deluxe - c:\program files\Zylom Games\Alchemy Deluxe\GameInstaller.exe

AddRemove-DealPly - c:\program files\DealPly\uninst.exe

AddRemove-Feeding Frenzy Deluxe - c:\program files\Zylom Games\Feeding Frenzy Deluxe\GameInstaller.exe

AddRemove-Pizza Frenzy Deluxe - c:\program files\Zylom Games\Pizza Frenzy Deluxe\GameInstaller.exe

AddRemove-{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 - c:\program files\Complitly\unins000.exe

AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2013-05-05 11:02

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Shell = Explorer.exe?

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Userinit = c:\windows\system32\userinit.exe,?

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i??????A?g??????9???9?(?9?h?9???

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,

89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b

"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,

27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b

"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"=hex:51,66,7a,6c,4c,1d,38,12,f1,9d,97,

02,e5,86,37,08,c7,6b,3b,0b,78,35,a4,a7

"{0FB6A909-6086-458F-BD92-1F8EE10042A0}"=hex:51,66,7a,6c,4c,1d,38,12,67,aa,a5,

0b,b4,2e,e1,00,c2,84,5c,ce,e4,5e,06,b4

"{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,

36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0

"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,

38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4

"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,

72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}"=hex:51,66,7a,6c,4c,1d,38,12,49,4c,04,

a2,cd,51,b8,a4,d6,29,f9,08,a8,03,90,5c

"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,

ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3

"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,

aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83

"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,

d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:cc,0b,98,46,87,b7,cd,01

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'Explorer.exe'(5032)

c:\program files\IDM\Desktop SMS\oehook.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\progra~1\AVG\AVG8\avgwdsvc.exe

c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe

c:\program files\KPN\Mobiel Internet Software\BecHelperService.exe

c:\progra~1\AVG\AVG8\avgrsx.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe

c:\program files\KPN\Mobiel Internet Software\LoggerServer.exe

c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe

c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe

c:\windows\system32\TODDSrv.exe

c:\program files\Toshiba\Power Saver\TosCoSrv.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

c:\users\Toshiba\AppData\Local\TVersity\Media Server\MediaServer.exe

c:\windows\system32\DRIVERS\xaudio.exe

c:\windows\system32\conime.exe

c:\windows\system32\igfxsrvc.exe

c:\program files\Toshiba\ConfigFree\NDSTray.exe

c:\program files\AVG\AVG8\avgtray.exe

c:\program files\iPod\bin\iPodService.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

c:\program files\Windows Mail\WinMail.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\servicing\TrustedInstaller.exe

c:\\?\c:\windows\system32\wbem\WMIADAP.EXE

.

**************************************************************************

.

Voltooingstijd: 2013-05-05 11:07:22 - machine werd herstart

ComboFix-quarantined-files.txt 2013-05-05 09:07

.

Pre-Run: 20.568.510.464 bytes beschikbaar

Post-Run: 20.628.201.472 bytes beschikbaar

.

- - End Of File - - B7FBFAB3BB813428E720DAA518CF7680

Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Firefox::

FF - ProfilePath - c:\users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\03jh1t15.default\

FF - prefs.js: browser.startup.homepage -

FF - prefs.js: keyword.URL -

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

FF - Ext: Complitly - Speed up your search with your personal search suggestions tool: {33e0daa6-3af3-d8b5-6752-10e949c61516} - %profile%\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}

FF - Ext: DealPly: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} - %profile%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}

FF - user.js: extensions.BabylonToolbar_i.id - 76e116c1000000000000001f3b8a9c93

FF - user.js: extensions.BabylonToolbar_i.hardId - 76e116c1000000000000001f3b8a9c93

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15403

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:59

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=119998

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar_i.instlRef – sst

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in de rode snelkoppeling van ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.