Jump to content

apparent infection


Recommended Posts

After asking whether a blocked ip was a possible f/p i got redirected to this, as it appeared to not be a f/p... Down here are the contents of attach.txt and dds.txt which were requested in the topic 'I'm infected - What do I do now?'. I also added them as an attatchment if needed. Thanks in advance.

PS, some information is in dutch, as it is the default language of my computer. If any clarification is needed just ask for it.

Attatch.txt

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 12-8-2010 9:10:52

System Uptime: 15-2-2013 15:30:50 (1 hours ago)

.

Motherboard: Intel Corporation | | DH55TC

Processor: Intel® Core™ i5 CPU 650 @ 3.20GHz | XU1 | 3193/533mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 75 GiB total, 2,479 GiB free.

D: is FIXED (NTFS) - 856 GiB total, 317,947 GiB free.

E: is CDROM ()

F: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP836: 15-2-2013 15:55:45 - Removed Autodesk MatchMover 2012 64-bit.

.

==== Installed Programs ======================

.

Adobe AIR

Adobe Community Help

Adobe Download Assistant

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Media Player

Adobe Photoshop CS5

Adobe Photoshop Elements 7.0

Adobe Premiere Elements 7.0

Adobe Premiere Elements 7.0 Templates

Adobe Reader X (10.1.5) - Nederlands

Adobe Shockwave Player 11.5

AIWI

AIWI JoyStick

Amnesia - The Dark Descent

Anark Client 1.0

Any Video Converter 3.2.3

APB Reloaded

Apple Application Support

Apple Software Update

applicationupdater

Assassin's Creed Brotherhood

Assassin's Creed Revelations 1.02

Audacity 1.3.12 (Unicode)

Audiosurf

Autodesk Maya 2012 64-bit

AVG 2011

Bonjour

Borderlands 2

Capsule

Composite 2012 64-bit

Conceptronic 300N Wireless Adapter (v3.0)

Cooliris for Internet Explorer

Curse Client

D3DX10

Darksiders II

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

Device Simulation Framework 1.0.1

Dishonored

Dota 2

eBook Reader

EPN werkboek-i Numbers and Space/1 havo vwo

F-N

FFmpeg for Audacity on Windows

Firebird SQL Server - MAGIX Edition

Fluency TTS 5.0

Fraps (remove only)

Free Audio CD to MP3 Converter version 1.3.7

Free YouTube to MP3 Converter version 3.11.35.1031

FTL version 1.01

gamelauncher-ps2-live

GameMaker 8.1

GamersFirst LIVE!

GameSpy Arcade

Ghost Control 2.1

Google Chrome

Google Update Helper

Heaven DX11 Benchmark version 3.0

Hi-Rez Studios Authenticate and Update Service

House of Night Screensaver Screensaver

HTML-Kit

ImagXpress

Intel® Management Engine Components

Intel® Network Connections 15.3.68.0

J2SE Runtime Environment 5.0 Update 1

JamGuru 1.0 RC5

Java 7 Update 13

Java 7 Update 13 (64-bit)

Java Auto Updater

Junk Mail filter update

LAME v3.98.2 for Audacity

League of Legends

Loadout

LogMeIn Hamachi

Magic The Gathering - Duels of the Planeswalkers 2013

MagicDisc 2.7.106

Magicka

MAGIX Music Maker 17 Premium Download Version

MAGIX Screenshare

MAGIX Speed burnR (MSI)

Malwarebytes Anti-Malware versie 1.70.0.1100

Matrix-ks

Microsoft .NET Framework 1.1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile NLD Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended NLD Language Pack

Microsoft .NET Framework 4 Multi-Targeting Pack

Microsoft Antimalware Service NL-NL Language Pack

Microsoft Application Error Reporting

Microsoft Games for Windows - LIVE Redistributable

Microsoft Games for Windows Marketplace

Microsoft Help Viewer 1.0

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (Dutch) 2010

Microsoft Office Excel MUI (Dutch) 2010

Microsoft Office Groove MUI (Dutch) 2010

Microsoft Office InfoPath MUI (Dutch) 2010

Microsoft Office Office 64-bit Components 2010

Microsoft Office OneNote MUI (Dutch) 2010

Microsoft Office Outlook MUI (Dutch) 2010

Microsoft Office PowerPoint MUI (Dutch) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (Dutch) 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (German) 2010

Microsoft Office Proofing (Dutch) 2010

Microsoft Office Publisher MUI (Dutch) 2010

Microsoft Office Shared 64-bit MUI (Dutch) 2010

Microsoft Office Shared MUI (Dutch) 2010

Microsoft Office Word MUI (Dutch) 2010

Microsoft Rise Of Nations

Microsoft Security Client

Microsoft Security Client NL-NL Language Pack

Microsoft Security Essentials

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft SQL Server 2008 R2 Management Objects

Microsoft SQL Server Compact 3.5 SP2 ENU

Microsoft SQL Server Compact 3.5 SP2 x64 ENU

Microsoft SQL Server System CLR Types

Microsoft Visual C# 2010 Express - ENU

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools

Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU

Microsoft XNA Framework Redistributable 3.1

Microsoft XNA Framework Redistributable 4.0

Microsoft XNA Game Studio 4.0

Microsoft XNA Game Studio 4.0 (ARP entry)

Microsoft XNA Game Studio 4.0 (Redists)

Microsoft XNA Game Studio 4.0 (Shared Components)

Microsoft XNA Game Studio 4.0 (Visual Studio)

Microsoft XNA Game Studio 4.0 (XnaLiveProxy)

Microsoft XNA Game Studio 4.0 Documentation

Microsoft XNA Game Studio Platform Tools

Microsoft_VC80_ATL_x86

Microsoft_VC80_ATL_x86_x64

Microsoft_VC80_CRT_x86

Microsoft_VC80_CRT_x86_x64

Microsoft_VC80_MFC_x86

Microsoft_VC80_MFC_x86_x64

Microsoft_VC80_MFCLOC_x86

Microsoft_VC80_MFCLOC_x86_x64

Microsoft_VC90_ATL_x86

Microsoft_VC90_ATL_x86_x64

Microsoft_VC90_CRT_x86

Microsoft_VC90_CRT_x86_x64

Microsoft_VC90_MFC_x86

Microsoft_VC90_MFC_x86_x64

MSI Afterburner 2.2.3

MSI Kombustor 2.3.0

MSVCRT

MSVCRT Redists

MSVCRT_amd64

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP2 Parser and SDK

MSXML4 Parser

MuseScore 0.9.6.3 MuseScore score typesetter

N-F

neroxml

NoteWorthy Composer 2

NVIDIA-configuratiescherm 310.70

NVIDIA 3D Vision controllerstuurprogramma 310.70

NVIDIA 3D Vision stuurprogramma 310.70

NVIDIA Grafisch stuurprogramma 310.70

NVIDIA HD Audio-stuurprogramma 1.3.18.0

NVIDIA Install Application

NVIDIA PhysX

NVIDIA PhysX systeemsoftware 9.12.1031

NVIDIA Stereoscopic 3D Driver

Oblivion

OpenAL

Orcs Must Die 2

Orcs Must Die!

PDF Settings CS5

Perspective 1.0

PlanetSide 2

PlanetSide 2 Beta

Portal 2 version 2.0.0.1

Primal Carnage Beta

PunkBuster Services

QuickTime

Ravaged

Razer Game Booster

Rise of Nations Thrones and Patriots

Roller Coaster World 3D

RollerCoaster Tycoon 3

RuneScape Launcher 1.2.2

Saints Row The Third

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Extended (KB2416472)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition

Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition

Security Update for Microsoft Visual C# 2010 Express - ENU (KB2251489)

Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition

Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)

Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)

Simple Port Forwarding

Skype Click to Call

Skype™ 6.1

Skyrim Dawnguard DLC+Update v1.7706-=AviaRa=- 1.7706

Smite

SnagIt 8

Star Wars: The Old Republic

Steam

Synthesia (remove only)

System Requirements Lab for Intel

Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

Taalpakket voor Microsoft .NET Framework 4 Extended - NLD

Tabulator

TeamSpeak 3 Client

Text-To-Speech-Runtime

The Lost Watch II NV 3D Screensaver 1.0

The Witcher 2 - Assassins of Kings Enhanced Edition

TI Connect 1.6

Torchlight II © Runic Games version 1

Transcripted Alienware Demo

Trust 5.1 Gaming Headset

Trust Gaming Mouse Driver V1.1

Tunngle beta

TuxGuitar

Ubisoft Game Launcher

Unity Web Player

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2473228)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2494150)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition

Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition

Vegas Pro 11.0

VirtualCloneDrive

Visual Studio 2008 x64 Redistributables

Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU

vReveal

VST Bridge 1.1

Western Railway NV 3D Screensaver 2.0

Windows Driver Package - Texas Instruments Inc. (SilvrLnk) USB (06/11/2009 1.0.0.0)

Windows Driver Package - Texas Instruments Inc. (TIEHDUSB) USB (09/02/2009 1.0.0.1)

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Media Center-gadgets voor Windows SideShow

Windows Media Player Firefox Plugin

Windows SideShow Managed Runtime 1.0

WinISO 5.3

WinRAR

World of Warcraft

World of Warcraft Beta

Zoo Tycoon: Complete Collection

.

==== End Of File ===========================

dds.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.13.2

Run by McDos at 16:01:04 on 2013-02-15

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3957.1730 [GMT 1:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}

SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\WLANExt.exe

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

D:\Mijn Documenten\Games\HiPatchService.exe

C:\Program Files (x86)\AVG\AVG10\avgnsa.exe

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\SysWOW64\PnkBstrA.exe

C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe

C:\Program Files (x86)\Conceptronic\Common\RaRegistry64.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Microsoft Security Client\NisSrv.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Windows\System32\StikyNot.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\AVG\AVG10\avgtray.exe

C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\System32\svchost.exe -k swprv

C:\Windows\system32\msiexec.exe

C:\Program Files (x86)\Windows Media Player\wmplayer.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uURLSearchHooks: {ba14329e-9550-4989-b3f2-9732e92d17cc} - <orphaned>

uURLSearchHooks: {87775fdb-6972-41f9-ae51-8326e38cb206} - <orphaned>

mWinlogon: Userinit = userinit.exe,

BHO: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItBHO.dll

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: Cooliris Plug-In for Internet Explorer: {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll

TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll

uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe

mRun: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s

mRun: [Trust Gaming Mouse] C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105

IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000

IE: Free YouTube to Mp3 Converter - C:\Users\McDos\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - C:\Program Files (x86)\PicLensIE\cooliris.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: Interfaces\{1595706F-7DEE-4E62-A5AA-CF00A0419D29} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B} : DHCPNameServer = 192.168.0.1

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B}\A597F507279667164756F595A4432585E4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B}\A597F507279667164756F5E465344343A4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{CC3B6A59-6FEA-419E-A76F-A7BDA7B9749B} : DHCPNameServer = 7.254.254.254

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\x64\SnagItBHO64.dll

x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll

x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

x64-TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\x64\SnagItIEAddin64.dll

x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe

x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe

x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe

x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

x64-Run: [Cm106Sound] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: igfxcui - igfxdev.dll

x64-SSODL: WebCheck - <orphaned>

x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

.

============= SERVICES / DRIVERS ===============

.

P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;D:\Mijn Documenten\Games\HiPatchService.exe [2012-8-3 8704]

R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2011-2-22 26704]

R0 DSFKSVCS;Kernel Services for DSF;C:\Windows\System32\drivers\dsfksvcs.sys [2010-2-8 676232]

R0 dsfroot;root enumerated bus driver;C:\Windows\System32\drivers\dsfroot.sys [2010-2-8 35832]

R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-9-28 52856]

R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2011-4-4 377936]

R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]

R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]

R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-8-27 1253376]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-2-13 398184]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-2-13 682344]

R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 128456]

R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe [2010-8-14 185632]

R2 RalinkRegistryWriter64;Ralink Registry Writer 64;C:\Program Files (x86)\Conceptronic\Common\RaRegistry64.exe [2010-8-14 212256]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]

R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-7-7 2320920]

R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2010-4-5 301232]

R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]

R3 HRMCFGSPC;DSF General Configuration Space Redirection Module;C:\Windows\System32\drivers\hrmcfgspc.sys [2010-2-8 133512]

R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-2-13 24176]

R3 NisSrv;Microsoft Netwerkinspectie;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]

R3 softehci;Microsoft USB 2.0 Enhanced Host Controller Interface (EHCI) Simulator Driver";C:\Windows\System32\drivers\softehci.sys [2010-2-8 366592]

R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\System32\drivers\tap0901t.sys [2011-10-10 31232]

R3 trustms;Trust Mouse;C:\Windows\System32\drivers\trustms.sys [2010-11-15 12416]

R3 usbehci_dsf;Microsoft DSF-enabled USB 2.0 Enhanced Host Controller Interface (EHCI) Miniport Driver;C:\Windows\System32\drivers\usbehci_dsf.sys [2010-2-8 52736]

R3 USBMULCD;USB Multi-Channel Audio Device Interface;C:\Windows\System32\drivers\CM10664.sys [2012-12-29 1310720]

S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-12-8 308304]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]

S3 androidusb;ADB Interface Driver;C:\Windows\System32\drivers\androidusb.sys [2010-4-29 32768]

S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-8-7 3276800]

S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-2-1 1431888]

S3 HRMINTS;DSF Interrupt Redirection Module;C:\Windows\System32\drivers\hrmints.sys [2010-2-8 128504]

S3 HRMPORTS;DSF IO Port Redirection Module;C:\Windows\System32\drivers\hrmports.sys [2010-2-8 148360]

S3 IAMTVE;Stuurprogramma voor Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTVE.sys [2010-7-7 43416]

S3 IAMTXPE;Stuurprogramma voor Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTXPE.sys [2010-7-7 51096]

S3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]

S3 ioatdma1;ioatdma1;C:\Windows\System32\drivers\qd162x64.sys [2009-11-16 40144]

S3 ioatdma2;Intel® QuickData Technology device ver.2;C:\Windows\System32\drivers\qd262x64.sys [2009-11-16 42192]

S3 SOFTHIDUSBK;USB HID Layer;C:\Windows\System32\drivers\softhidusbk.sys [2010-2-8 206848]

S3 SOFTUSBK;Generic USB device;C:\Windows\System32\drivers\softusbk.sys [2010-2-8 675328]

S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-26 59392]

S3 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2012-6-1 745368]

S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-7 1255736]

S3 WinRing0_1_2_0;WinRing0_1_2_0;D:\Mijn Documenten\Games\razer\Driver\WinRing0x64.sys [2012-9-17 14544]

.

=============== File Associations ===============

.

FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [userChoice]

FileExt: .js: JSFile=C:\Windows\System32\WScript.exe "%1" %* [userChoice]

.

=============== Created Last 30 ================

.

2013-02-15 14:57:38 -------- d-----w- C:\Users\McDos\AppData\Local\Autodesk

2013-02-15 14:55:09 -------- d-----w- C:\Users\McDos\AppData\Local\backburner

2013-02-15 14:42:08 9161176 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9896DB58-1E9C-4E05-9DCC-BA1F3B9AC38B}\mpengine.dll

2013-02-14 10:04:11 -------- d-----w- C:\Users\McDos\AppData\Local\{BE33C8F2-90DA-44B3-AACF-61302F59D330}

2013-02-14 01:08:37 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 01:08:37 768000 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 00:21:46 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-02-14 00:21:44 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-02-14 00:21:44 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-02-14 00:21:35 3153408 ----a-w- C:\Windows\System32\win32k.sys

2013-02-14 00:21:33 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2013-02-14 00:21:33 215040 ----a-w- C:\Windows\System32\winsrv.dll

2013-02-14 00:21:33 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2013-02-14 00:21:32 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2013-02-14 00:21:32 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2013-02-14 00:21:32 2048 ----a-w- C:\Windows\SysWow64\user.exe

2013-02-14 00:21:25 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

2013-02-14 00:21:25 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-02-13 15:58:14 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-02-13 15:58:14 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-02-13 15:56:02 -------- d-----w- C:\Users\McDos\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant

2013-02-13 15:46:44 -------- d-----w- C:\Program Files (x86)\Adobe Download Assistant

2013-02-13 15:43:05 -------- d-----w- C:\Users\McDos\AppData\Local\{DB1FD5E3-BDBF-4884-A0DA-CCE77F155243}

2013-02-13 14:10:49 9161176 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-02-12 22:00:42 -------- d-----w- C:\Users\McDos\AppData\Local\{8C0B7E7C-1B8A-48CF-833E-25F38ED2E306}

2013-02-11 14:01:06 -------- d-----w- C:\Users\McDos\AppData\Roaming\.minecraft

2013-02-11 13:56:53 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-02-11 13:32:41 -------- d-----w- C:\Users\McDos\AppData\Roaming\BlackBean

2013-02-11 12:28:31 -------- d-----w- C:\Users\McDos\AppData\Local\{76ABD2BD-B70D-41D0-82A2-627C9C18DF1E}

2013-02-10 00:51:02 -------- d-----w- C:\Users\McDos\AppData\Local\{0F114ABE-AD15-4084-AE49-4F1954F71BA9}

2013-02-09 18:35:37 -------- d-----w- C:\Users\McDos\AppData\Local\Green Man Gaming

2013-02-09 12:33:51 -------- d-----w- C:\Users\McDos\AppData\Local\{C38784D2-3A26-4370-8028-D79E7C37D727}

2013-02-07 22:49:31 -------- d-----w- C:\Users\McDos\AppData\Local\{88524854-8220-445E-8D77-8543CE357118}

2013-02-07 13:05:56 -------- d-----w- C:\Users\McDos\AppData\Local\{3175A617-D512-4A87-AC54-A759084F3DAE}

2013-02-06 15:30:35 -------- d-----w- C:\Users\McDos\AppData\Local\{E3F38BF3-4716-436D-8F4F-E1AE2D9D9FC7}

2013-02-06 13:34:29 -------- d-----w- C:\Users\McDos\AppData\Local\{FA7CFF0C-369B-4711-A6CD-7774EC637654}

2013-02-06 12:26:24 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll

2013-02-05 18:06:55 -------- d-----w- C:\Users\McDos\AppData\Local\{799D16F1-1BCE-4EFD-8980-8383B5AFFE93}

2013-02-04 14:30:26 -------- d-----w- C:\Users\McDos\AppData\Local\{C6DA0895-9E64-4E85-8F37-AEE9B3B7B820}

2013-02-03 14:37:56 -------- d-----w- C:\Users\McDos\AppData\Local\{D3CD0F8C-8F47-4141-851E-4FFB8BCEA2FE}

2013-02-01 16:15:55 -------- d-----w- C:\Users\McDos\AppData\Roaming\Malwarebytes

2013-02-01 16:15:14 -------- d-----w- C:\ProgramData\Malwarebytes

2013-02-01 16:14:59 -------- d-----w- C:\Users\McDos\AppData\Local\Programs

2013-02-01 08:38:48 -------- d-----w- C:\Program Files\Common Files\Macrovision Shared

2013-01-30 21:55:29 -------- d-----w- C:\Users\McDos\AppData\Local\{F747D08C-D86C-4F3C-808C-5CBCF9C69D02}

2013-01-30 15:03:25 -------- d-----w- C:\Users\McDos\AppData\Local\{5C5A1662-ED91-40CA-B0E1-F20EEA6062D7}

2013-01-29 13:50:10 -------- d-----w- C:\Users\McDos\AppData\Local\{3EB20C87-E99B-401A-A1CA-98009913F757}

2013-01-28 12:48:08 -------- d-----w- C:\Users\McDos\AppData\Local\{31BC587D-BFC1-4376-A13C-814CD635C215}

2013-01-26 17:40:24 -------- d-----w- C:\Users\McDos\AppData\Local\{180ED5A0-F463-41B0-B9F3-E31F23C09973}

2013-01-25 12:24:50 -------- d-----w- C:\Users\McDos\AppData\Local\{7FB777CB-57A4-4865-B778-2D62295D26B7}

2013-01-24 10:10:11 -------- d-----w- C:\Users\McDos\AppData\Local\{CE28031B-21FB-43D3-BF2A-D84D5A40D7B4}

2013-01-23 12:33:23 -------- d-----w- C:\Users\McDos\AppData\Local\{D660AA8D-BE91-4220-9F4A-A0F76C3BD004}

2013-01-22 12:07:32 -------- d-----w- C:\Users\McDos\AppData\Local\{FF610585-A544-4545-89EB-E6D50325E074}

2013-01-21 11:50:24 -------- d-----w- C:\Users\McDos\AppData\Local\{4A81DFB9-E522-4940-BAEB-8A510CEE0C65}

2013-01-20 11:58:07 -------- d-----w- C:\Users\McDos\AppData\Local\{A5C9EF33-31D1-4E09-ADB7-56AF596A83E5}

2013-01-19 12:39:00 -------- d-----w- C:\Users\McDos\AppData\Local\{E7722CD4-5CC9-458F-872F-4074970DEC10}

2013-01-17 20:03:44 -------- d-----w- C:\Program Files (x86)\Pando Networks

2013-01-17 18:01:00 -------- d-----w- C:\Users\McDos\AppData\Local\{41BAA6A0-5693-4F59-BA61-1869DA656E8B}

2013-01-16 15:12:03 -------- d-----w- C:\ProgramData\3fa603c2-68ea-4c9d-8934-c6835142108f

.

==================== Find3M ====================

.

2013-02-11 13:56:40 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-02-11 13:56:40 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-02-09 20:42:57 74096 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-02-09 20:42:57 697712 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-02-06 12:26:18 963488 ----a-w- C:\Windows\System32\deployJava1.dll

2013-02-06 12:26:18 1085344 ----a-w- C:\Windows\System32\npDeployJava1.dll

2013-01-30 10:53:22 273840 ------w- C:\Windows\System32\MpSigStub.exe

2013-01-09 01:19:09 2312704 ----a-w- C:\Windows\System32\jscript9.dll

2013-01-09 01:12:03 1392128 ----a-w- C:\Windows\System32\wininet.dll

2013-01-09 01:11:06 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2013-01-09 01:07:51 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2013-01-09 01:07:47 599040 ----a-w- C:\Windows\System32\vbscript.dll

2013-01-09 01:04:42 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2013-01-08 22:11:21 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-01-08 22:03:20 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-01-08 22:03:12 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2013-01-08 21:59:02 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2013-01-08 21:58:29 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2013-01-08 21:56:23 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll

2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll

2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll

2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll

2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll

2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll

2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll

2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs

2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs

2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs

2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs

2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs

2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs

2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs

2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs

2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs

2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs

2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs

2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs

2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs

2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs

2012-12-03 15:47:14 983936 ----a-w- C:\Windows\System32\nvumdshimx.dll

2012-12-01 05:49:26 3663213 ----a-w- C:\Windows\System32\nvcoproc.bin

2012-12-01 05:49:25 63336 ----a-w- C:\Windows\System32\nvshext.dll

2012-12-01 05:49:25 118120 ----a-w- C:\Windows\System32\nvmctray.dll

2012-12-01 05:49:24 890216 ----a-w- C:\Windows\System32\nvvsvc.exe

2012-12-01 05:48:41 6223208 ----a-w- C:\Windows\System32\nvcpl.dll

2012-12-01 05:48:37 3311464 ----a-w- C:\Windows\System32\nvsvc64.dll

2012-11-30 21:43:52 438632 ----a-w- C:\Windows\SysWow64\nvStreaming.exe

2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll

2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll

2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll

2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll

2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe

2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe

2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll

2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll

2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2012-11-17 17:28:36 466456 ----a-w- C:\Windows\System32\wrap_oal.dll

2012-11-17 17:28:36 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll

2012-11-17 17:28:36 122904 ----a-w- C:\Windows\System32\OpenAL32.dll

2012-11-17 17:28:36 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll

.

============= FINISH: 16:01:15,71 ===============</orphaned></orphaned></orphaned></orphaned></orphaned></orphaned></orphaned>

attach.txt

dds.txt

Link to post
Share on other sites

Hello Danaiden,

Before we get going, please advise as to why this system appears to have 2 or more antivirus programs ?

We must trim it down to only 1 real-time monitor antivirus.

This shows MS Security Essentials, plus 1 or two versions of AVG.

Decide on 1 to keep and Uninstall any others. And let me know what you have decided on.

Having more than 1 antivirus monitoring a system will lead to deadlocks & or conflicts and result in less protection, not more.

Link to post
Share on other sites

Since most all antivirus do not fully remove themselves, See this topic http://forums.malwar...?showtopic=7368

Get and run the AVG removal tool.

Reminder: If you have PRO MBAM license, you may contact the Consumer Help Desk for free expert help here.

If you are in an organization or a corporate customer, contact Corporate Support for assistance.

If you elect to do that, let me know.

General pointers on website blocking:

See this forum articles about website blocking of malicious sites.

http://helpdesk.malwarebytes.org/entries/22785462-What-does-it-mean-when-I-get-an-IP-alert-about-blocking-a-malicious-site-

Also see and review section G of the FAQ article on MBAM

http://forums.malwarebytes.org/index.php?act=findpost&pid=162100

So that you have an understaing of the basics.

Are the blocks noted as Outgoing?

Do you use any instant messenger programs? if so, which?

You should not be using any peer-to-peer filesharing apps as those are one avenue to facilitate malware.

Close all IM programs, remove any peer-to-peer apps. Close all browsers. There whould not be any IP blocks during that period .....barring an "onboard bad-guy" trying to go "out".

Do a quick scan with MBAM and provide copy of log.

Link to post
Share on other sites

Yes the blocks are noted as outgoing, i've pasted the last 5 lines of the last log file underneath. As for im programs... Maybe skype counts, but other than that i use none. I should add that i even get the popups when skype's not working (i have it set to not start together with windows). As for P2P sharing things, i know League of Legends and WoW use it to let you update faster, but it can be disabled if necessary.

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49567, Process: chrome.exe)

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49568, Process: chrome.exe)

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49569, Process: chrome.exe)

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49570, Process: chrome.exe)

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49571, Process: chrome.exe)

2013/02/15 19:01:42 +0100 JASPER McDos IP-BLOCK 88.80.7.57 (Type: outgoing, Port: 49572, Process: chrome.exe)

Link to post
Share on other sites

I'm sorry for the second reply, i forgot about the last part in bold. Yes it's true i don't have any IP blocks when i'm not browsing/using skype or any other programme requiring internet. Also i'm not running a pro version.

Here are the results of the quick scan,

Malwarebytes Anti-Malware (Trial) 1.70.0.1100

www.malwarebytes.org

Database version: v2013.02.15.07

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

McDos :: JASPER [administrator]

Protection: Enabled

15-2-2013 19:52:26

mbam-log-2013-02-15 (19-52-26).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 272559

Time elapsed: 5 minute(s), 26 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

Start Chrome and then .....

Press & hold SHIFT+CTRL+Del keys to get menu for clearing browing data:

Check Empty the cache

Delete cookies and other site and plug-in data

and press Clear browsing data button

Still in Chrome, press ALT+F then Settings

Click Extensions on the left.

Closely review the browser extensions that are listed. Disable any that you are not familiar with or that you do not trust.

Now, Close / exit Chrome so that no Chrome windows are left open.

For the next 30 minutes or so, do you get any "outbound" IP blocks ?

Please download Junkware Removal Tool to your Desktop.

  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click JRT.exe and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply. And tell me, How is the system now?
  • Re-enable your security software.

  • Download & SAVE to your Desktop >> Tigzy's RogueKillerfrom here << or
    >> from here <<
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
    For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on Scan button at upper right of screen.
  • Wait until the Status box shows "Scan Finished"
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Do NOT press any Fix button.
  • Exit/Close RogueKiller

Link to post
Share on other sites

I did not receive any popups during the 30 minutes chrome was shutdown. The contents of both the scans are underneath here. I didn't have a clue how to shutdown MS Security Essentials, if it did cause a conflict, please let me know.

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.6.3 (02.12.2013:1)

OS: Windows 7 Home Premium x64

Ran by McDos on vr 15-02-2013 at 20:59:07,37

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{87775fdb-6972-41f9-ae51-8326e38cb206}

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{87775fdb-6972-41f9-ae51-8326e38cb206}

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc}

~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\conduit

Successfully deleted: [Registry Key] hkey_local_machine\software\conduit

Successfully deleted: [Registry Key] hkey_current_user\software\cr_installer

Successfully deleted: [Registry Key] hkey_current_user\software\softonic

Successfully deleted: [Registry Key] hkey_current_user\software\startsearch

Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\pricegong

Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar

Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\bho.dll

Successfully deleted: [Registry Key] hkey_local_machine\software\classes\conduit.engine

Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\babylon_rasapi32

Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\babylon_rasmancs

Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2504091

Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2865317

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"

Successfully deleted: [Folder] "C:\Users\McDos\AppData\Roaming\dvdvideosoftiehelpers"

Successfully deleted: [Folder] "C:\Users\McDos\appdata\local\conduit"

Successfully deleted: [Folder] "C:\Users\McDos\appdata\locallow\conduit"

Successfully deleted: [Folder] "C:\Users\McDos\appdata\locallow\pricegong"

Successfully deleted: [Folder] "C:\Program Files (x86)\babylon"

~~~ Chrome

Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\dhkplhfnhceodhffomolpfigojocbpcb

Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on vr 15-02-2013 at 21:04:50,07

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RogueKiller

RogueKiller V8.5.1 [Feb 12 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/

Website : http://tigzy.geekstogo.com/roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : McDos [Admin rights]

Mode : Scan -- Date : 02/15/2013 21:09:55

| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤

[RUN][PREVRUN] HKLM\[...]\Run : Cm106Sound (C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd) [7] -> FOUND

[HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND

[HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

[Tr.Karagany][FOLDER] plugs : C:\Users\McDos\AppData\Roaming\Adobe\plugs --> FOUND

[Tr.Karagany][FOLDER] shed : C:\Users\McDos\AppData\Roaming\Adobe\shed --> FOUND

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD10EARS-00Z5B1 ATA Device +++++

--- User ---

[MBR] a94d4258123ce89ae66ce37ba6a1a59a

[bSP] e3f99f0f1d0a50c4d0ea723c9a6728ac : Windows 7/8 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76799 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 157491200 | Size: 876967 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[2]_S_02152013_02d2109.txt >>

RKreport[1]_S_02152013_02d2108.txt ; RKreport[2]_S_02152013_02d2109.txt

Link to post
Share on other sites

hopefully these items removed by Junkware Removal tool did "the benefical" fix for your Chrome.

~~~ Chrome

Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\dhkplhfnhceodhffomolpfigojocbpcb

Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ojpijjmpahflnipadmlpgbjmagmjchkk

  • Disable your anti-virus program, How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • Right-Click RogueKiller and select Run as Administrator.
  • Wait until Prescan finishes.
  • On the RogueKiller console, click the Registry tab.
    Put a check next to -these- and uncheck the rest: (if found)
    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
    [Tr.Karagany][FOLDER] plugs : C:\Users\McDos\AppData\Roaming\Adobe\plugs --> FOUND
    [Tr.Karagany][FOLDER] shed : C:\Users\McDos\AppData\Roaming\Adobe\shed --> FOUND

  • Then click on Delete on the right hand column under Options.
  • When done, logoff & Restart the system.
  • The log will be found as RKreport
    Copy & Paste the contents into next reply.

Step 2

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Please download Rkill by Grinler and save it to your desktop.

Link 2
Link 3
Link 4
Double-click on the Rkill desktop icon to run the tool.
If using Vista or Windows 7, right-click on it and Run As Administrator.
A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
If not, delete the file, then download and use the one provided in Link 2.
If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
If the tool does not run from any of the links provided, please let me know.
If your antivirus program gives a prompt message, respond positive to allow RKILL to run.
If a malware-rogue gives a message regarding RKILL, proceed forward to running RKILL

IF you still have a problem running RKILL, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

When all done, rkill.txt log file will be on your desktop. Copy & Paste contents of Rkill.txt into a reply.

More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html

Step 3

Save and close any work documents, close any apps that you started.

Temporarily turn off (disable) your antivirus program

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Start your MBAM MalwareBytes' Anti-Malware.

Click the Settings Tab and then the General Settings sub-tab. Make sure all option lines have a checkmark.

Then click the Scanner settings sub-tab in second row of tabs. Make sure all option lines have a checkmark.

If you have the PRO license, then do this too: Click the Protection tab. Make sure all option lines have a checkmark.

Next, Click the Update tab. Press the "Check for Updates" button.

If prompted for a Restart, do that.

When done, click the Scanner tab.

Do a Full Scan. i_arrow-l.gif

When the scan is complete, click OK, then Show Results to view the results.

Make sure that everything is checked, and click Remove Selected.

When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

When all done, Copy & paste the MBAM scan log into a new reply.

Step 3

Download Dr.Web CureIt to the desktop.

The download is nearly 104.6 MB in size

  • Turn OFF your antivirus program.
    How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
  • Turn off any other add-on security app {if you have them} like MBAM File System Protection.
  • If this system is Windows 8/7 or VISTA, then Right-click on Drweb-cureit-9_zpsa6b7b265.gifdrweb-cureit.exe and select Run as Administrator.
  • Otherwise, on Windows XP, doubleclick on Drweb-cureit-9_zpsa6b7b265.gifdrweb-cureit.exe file to start the tool.
  • You will see a screen similar to this:
    Drweb-cureit-1_zps34a2f747.gif
    Click the checkbox to participate, and then click on Continue button.
  • Next
    Drweb-cureit-2_zpsee7bdcb6.gif
    Click on Select onjects for scanning
  • Next
    Drweb-cureit-3_zps137b4332.gif
    Put a checkmark by clicking on the boxes as shown.
    Do not select Temporary files or System Restore points.
    Then click on Start scanning button
  • The scan in progress will be shown like this
    Drweb-cureit-4_zps211037d0.gif
  • IF something is detected, you will see a screen similar to this
    Drweb-cureit-5_zpsd7be6acf.gif
    For each item "detected", click on the Action column down arrow, like this
    Drweb-cureit-8_zpsb099f9d5.gif
    Your options will be Cure or Ignore
    IF you see an item that you are very sure is ok, then un-check the checkbox for that item.
    Typically, you will keep the Cute default.
    Then click on the Neutralize button.
  • When the actions are completed, you will see this
    Drweb-cureit-7_zpsd290a127.gif
  • Click on the green Open Report line. It will pop-up the report in NOTEPAD.
    Save the report to your desktop. The report will be called Cureit.log
  • While in NOTEPAD, do a CTRL+A to Copy all to clipboard.
  • You should be able to get back to your forum topic, start a new reply,
    click 1 time in the box
    and do a CTRL+V (Paste}
    into reply.
  • Close Dr.Web Cureit.
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, post the contents of the log from Cureit.log you saved previously in your next reply.
    ONLY if the log is too large, then you may "attach" it.

Re-Enable your antivirus program when all done.

Tell me, How is the system ?

Link to post
Share on other sites

Down below are the reports the scans produced. Sadly i made a mistake with the Dr. Web, and didn't save the report. It did remove 4 files from my pc.

MBAM

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.02.16.01

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

McDos :: JASPER [administrator]

16-2-2013 2:52:05

mbam-log-2013-02-16 (02-52-05).txt

Scan type: Full scan (C:\|D:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 665007

Time elapsed: 1 hour(s), 15 minute(s), 11 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

rkill

Rkill 2.4.7 by Lawrence Abrams (Grinler)

http://www.bleepingcomputer.com/

Copyright 2008-2013 BleepingComputer.com

More Information about Rkill can be found at this link:

http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 02/16/2013 02:50:33 AM in x64 mode.

Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 02/16/2013 02:51:11 AM

Execution time: 0 hours(s), 0 minute(s), and 37 seconds(s)

roguekiller

RogueKiller V8.5.1 [Feb 12 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/

Website : http://tigzy.geekstogo.com/roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : McDos [Admin rights]

Mode : Remove -- Date : 02/16/2013 02:40:07

| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤

[RUN][PREVRUN] HKLM\[...]\Run : Cm106Sound (C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd) [7] -> NOT SELECTED

[HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED

[HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NOT SELECTED

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED

¤¤¤ Particular Files / Folders: ¤¤¤

[Tr.Karagany][FOLDER] ROOT : C:\Users\McDos\AppData\Roaming\Adobe\plugs --> REMOVED

[Tr.Karagany][FOLDER] ROOT : C:\Users\McDos\AppData\Roaming\Adobe\shed --> REMOVED

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD10EARS-00Z5B1 ATA Device +++++

--- User ---

[MBR] a94d4258123ce89ae66ce37ba6a1a59a

[bSP] e3f99f0f1d0a50c4d0ea723c9a6728ac : Windows 7/8 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 76799 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 157491200 | Size: 876967 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[4]_D_02162013_02d0240.txt >>

RKreport[2]_S_02152013_02d2109.txt ; RKreport[3]_S_02162013_02d0237.txt ; RKreport[4]_D_02162013_02d0240.txt

Link to post
Share on other sites

You will want to print out or copy these instructions to Notepad for offline reference!

These steps are for member Danaiden only. If you are a casual viewer, do NOT try this on your system!

If you are not Danaiden and have a similar problem, do NOT post here; start your own topic

Do not run or start any other programs while these utilities and tools are in use!

Do NOT run any other tools on your own or do any fixes other than what is listed here.

If you have questions, please ask before you do something on your own.

But it is important that you get going on these following steps.

=

Close any of your open programs while you run these tools.

On most all of the following programs and tools, you will need to do a right-click on the program link or shortcut or desktop icon (as appropriate) and then select "Run as Administrator". Please remember that as you go along and use these tools, each in turn.

Close all open browsers at this point.

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Start Internet Explorer

Using Internet Explorer browser only, go to BitDefender Quickscan website:

http://quickscan.bitdefender.com

and click "Start Scan".

Observe your browser in case it shows a notice/message bar to allow download and installation of a tool.

Allow the download and install of qsax.cab from BitDefender. Right-click the IE info bar and select Install to install the BitDefender quick scan module.

If prompted, reply yes to allow it to run.

Press the Allow button and follow prompts.

Press the "Start Scan" once more.

You'll see the EULA in a pop-up window. Click the I accept & then the OK button

Note: The FAQ is here --> http://quickscan.bitdefender.com/faq/

and that QuickScan has no removal capability.

The site boasts a 60-second scan. Do have patience as it likely will take longer.

It may seem to stall at moments, but have patience; it will move on.

You'll see a progress bar at top right of window.

Hopefully you will see a No infections found in the bar-winddow. Press the View Log button.

The log report will show in your text editor. Save the log.

Do a Select ALL, Copy. Then paste contents into your next reply.

Step 2

If you have a prior copy of Combofix, delete it now

Download Combofix from any of the links below, and SAVE it to your Desktop.

Link 1

Link 2

**Note: It is important that it is saved directly to your Desktop and not run straight away from download **

Turn OFF your antivirus, otherwise it will interfere. How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Have infinite patience during the run & scan by Combofix. It has many phases: some 50+ stages

It will display it's "stage" within the Command prompt window. Do NOT panic if it seems slow to change ! It has lots of work.

You may notice the desktop icons disappear. Do NOT panic, as that is expected behavior.

Combofix my take as little as 10 minutes and perhaps as much as 30-40 minutes. Time taken will depend on speed of your system and how much there is to scan & how much it needs to clean.

If this is on a notebook system, make sure first the notebook is connected to wall-power (AC power)or a UPS system

Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.

Right- click on Combo-Fix.exe on your Desktop cf-icon.jpg and select "Run as Administrator".

  • A window may open with a warning or prompts. Accept the EULA and follow the prompts during the start phase of Combofix.
    When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.

A caution - Do not run Combofix more than once.

Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.

The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled.

If this occurs, please reboot to restore the desktop.

A file will be created at => C:\Combofix.txt.

Notes:

[1] IF after Combofix reboot you get the message

Illegal operation attempted on registry key that has been marked for deletion

....please reboot the computer, this should resolve the problem. You may have reboot the pc a second time if needed.

[2] Do not mouseclick combofix's window nor run any program while Combofix is running.

That may cause it to stall.

[3]When all done, IF Combofix did not do a Restart...then ... I need for you to Restart the system fresh :excl:

Reply & Copy & Paste contents of the C:\Combofix.txt log and tell me, How is the system now ?

Re-enable your antivirus program.

Link to post
Share on other sites

Underneath i pasted the bitdefender and the combofix logs. As for my system, i haven't had any popups yet, so at least something's fixed. I just noticed combofix is partially in dutch, if you need any help translating, ask me.

Bitdefender

QuickScan 32-bit v0.9.9.118

---------------------------

Scan date: Sat Feb 16 16:50:33 2013

Machine ID: 7430CFE3

No infection found.

-------------------

Processes

---------

(unsigned) FABS - file change and backup server 1956 C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(unsigned) Gaming Mouse Driver 3856 C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

(verified) Adobe Acrobat Update Service 1404 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

(verified) Adobe Photoshop Elements 1832 C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe

(verified) Besturingssysteem Microsoft® Windows® 3484 C:\Windows\SysWOW64\rundll32.exe

(verified) Bonjour 512 C:\Program Files (x86)\Bonjour\mDNSResponder.exe

(verified) Hamachi Client 3416 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

(verified) Intel® Active Management Technology L 1280 C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

(verified) Intel® Management & Security Applicat 4968 C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

(verified) Java Platform SE Auto Updater 2 0 3360 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(verified) Malwarebytes Anti-Malware 2164 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

(verified) Malwarebytes Anti-Malware 1596 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

(verified) Malwarebytes Anti-Malware 2052 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

(verified) Microsoft® .NET Framework 4680 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

(verified) PnkBstrA.exe 2228 C:\Windows\SysWOW64\PnkBstrA.exe

(verified) Ralink RalinkRegistryWriter 2300 C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe

(verified) Stereo Vision Control Panel API Server 908 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

(verified) Virtual CloneDrive 3756 C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

(verified) Windows® Internet Explorer 1344 C:\Program Files (x86)\Internet Explorer\iexplore.exe

(verified) Windows® Internet Explorer 1704 C:\Program Files (x86)\Internet Explorer\iexplore.exe

Network activity

----------------

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 173.194.67.102

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 173.194.67.102

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 2.18.191.139

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 2.18.191.139

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 37.59.67.149

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 66.235.142.58

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 66.235.142.58

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 77.67.28.43

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 77.67.28.43

Process iexplore.exe (1344) connected on port 80 (HTTP) --> 95.172.94.16

Process LMS.exe (1280) listens on ports: 623, 16992

Autoruns and critical files

---------------------------

(unsigned) Axialis Screen Saver Producer C:\Windows\System32\HouseOfNightScreensaver.scr

(unsigned) Gaming Mouse Driver C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

(unsigned) QuickTime C:\Program Files (x86)\QuickTime\QTTask.exe

(verified) Adobe CS5 Service Manager C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe

(verified) Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

(verified) Adobe® Flash® Player Update Service C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

(verified) Apple Push C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(verified) Besturingssysteem Microsoft® Windows® C:\Windows\system32\userinit.exe

(verified) Google Update C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

(verified) Hamachi Client C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

(verified) Java Platform SE Auto Updater 2 0 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(verified) Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe

(verified) Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

(verified) SBSV 2010/02/19-11:02:07 C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

(verified) Virtual CloneDrive C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

Browser plugins

---------------

(unsigned) Cooliris for Internet Explorer c:\program files (x86)\piclensie\cooliris.dll

(unsigned) NVIDIA 3D Vision C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

(unsigned) NVIDIA 3D VISION C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll

(unsigned) QuickTime Plug-in 7.7.3 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll

(verified) AcroIEHelperShim Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll

(verified) Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

(verified) Adobe Acrobat C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll

(verified) Besturingssysteem Microsoft® Windows® C:\Windows\system32\mswsock.dll

(verified) Besturingssysteem Microsoft® Windows® C:\Windows\system32\napinsp.dll

(verified) Besturingssysteem Microsoft® Windows® C:\Windows\system32\pnrpnsp.dll

(verified) Bitdefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll

(verified) Bitdefender QuickScan C:\Windows\Downloaded Program Files\qsax64.dll

(verified) Bonjour C:\Program Files (x86)\Bonjour\mdnsNSP.dll

(verified) Bonjour C:\Program Files\Bonjour\mdnsNSP.dll

(verified) Google Update C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

(verified) Java Deployment Toolkit 7.0.130.20 C:\Windows\SysWOW64\npDeployJava1.dll

(verified) Java Platform SE 7 U13 C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

(verified) Java Platform SE 7 U13 C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

(verified) Java Platform SE 7 U13 C:\Program Files (x86)\Java\jre7\bin\ssv.dll

(verified) Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

(verified) Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL

(verified) Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL

(verified) Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\urlredir.dll

(verified) Microsoft® CoReXT c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll

(verified) Microsoft® CoReXT C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

(verified) Microsoft® CoReXT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

(verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll

(verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll

(verified) NPSWF32_11_5_502_149.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll

(verified) Shockwave for Director C:\Windows\system32\Adobe\Director\np32dsw.dll

(verified) Silverlight Plug-In C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

(verified) Skype Toolbars c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll

(verified) SnagIt c:\program files (x86)\techsmith\snagit 8\snagitbho.dll

(verified) SnagIt c:\program files (x86)\techsmith\snagit 8\snagitieaddin.dll

(verified) Unity Player C:\Users\McDos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll

(verified) Uplay PC C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll

(verified) Windows Live Photo Gallery C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

(verified) Windows® Internet Explorer c:\windows\syswow64\ieframe.dll

Missing files

-------------

File not found: C:\Windows\system32\Macromed\Flash\FlashUtil64_11_5_502_149_ActiveX.exe -update activex

--> HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\"FlashPlayerUpdate"

Scan

----

MD5: 1355ebe184f9dab1718bc587f8a7e05e C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

MD5: fff1130f7c9fa01d093a1edfc5cce8fc C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll

MD5: 9fca15cc38f2e2c6f5e722ed0e1a9e7a C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll

MD5: 38466120732c4c35206561da0ad5e2eb C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

MD5: ec97912ec59bf86050e48b4054cd906e C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

MD5: 98e58a72bdef7584201ace3b2906e879 c:\program files (x86)\piclensie\cooliris.dll

MD5: 8dda2b606279753601f9415da503ca63 C:\Program Files (x86)\QuickTime\QTTask.exe

MD5: aaef87641f5b8d07cd4b919886e38780 C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

MD5: 5531bada5736f1c34d1a9f30022ac1af C:\Windows\System32\HouseOfNightScreensaver.scr

MD5: 3f636d6791048df1d16b5fdf3af496e4 C:\Windows\Syswow64\cm106.dll

MD5: 5350aef38ca2d8885f47d4455e7ef4ee D:\Mijn Documenten\Games\HiPatchService.exe

No file uploaded.

Scan finished - communication took 0 sec

Total traffic - 0.00 MB sent, 0.08 KB recvd

Scanned 359 files and modules - 4 seconds

==============================================================================

Combofix

ComboFix 13-02-15.01 - McDos 16-02-2013 16:56:25.1.4 - x64

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3957.2364 [GMT 1:00]

Gestart vanuit: c:\users\McDos\Desktop\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\b3d0e153-181e-4993-8f87-8d487b52110a

c:\programdata\Windows

c:\users\McDos\AppData\Roaming\terraria2.exe

c:\users\McDos\ia_remove.sh4514.tmp

c:\windows\IsUn0413.exe

c:\windows\SysWow64\URTTemp

c:\windows\SysWow64\URTTemp\regtlib.exe

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-01-16 to 2013-02-16 ))))))))))))))))))))))))))))))

.

.

2013-02-16 16:02 . 2013-02-16 16:02 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

2013-02-16 16:02 . 2013-02-16 16:02 -------- d-----w- c:\users\UpdatusUser.JASPER\AppData\Local\temp

2013-02-16 16:02 . 2013-02-16 16:02 -------- d-----w- c:\users\hedev\AppData\Local\temp

2013-02-16 16:02 . 2013-02-16 16:02 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-02-16 15:46 . 2013-02-16 15:50 -------- d-----w- c:\users\McDos\AppData\Roaming\QuickScan

2013-02-16 15:28 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{214EB23E-ECC9-4539-A2CA-0B78BF865E56}\mpengine.dll

2013-02-16 15:23 . 2013-01-08 05:32 9161176 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-02-16 13:12 . 2013-02-16 14:48 -------- d-----w- c:\users\McDos\Doctor Web

2013-02-15 22:02 . 2013-02-15 22:03 -------- d-----w- c:\windows\rescache

2013-02-15 19:59 . 2013-02-15 19:59 -------- d-----w- c:\windows\ERUNT

2013-02-15 19:57 . 2013-02-15 19:58 -------- d-----w- C:\JRT

2013-02-15 19:19 . 2013-02-15 19:19 -------- d-----w- c:\windows\symbols

2013-02-15 19:17 . 2013-02-15 19:17 -------- d-----w- c:\programdata\VS

2013-02-15 19:07 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

2013-02-15 19:07 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll

2013-02-15 19:07 . 2012-08-24 18:13 154480 ----a-w- c:\windows\system32\drivers\ksecpkg.sys

2013-02-15 19:07 . 2012-08-24 18:09 458712 ----a-w- c:\windows\system32\drivers\cng.sys

2013-02-15 19:07 . 2012-08-24 18:05 340992 ----a-w- c:\windows\system32\schannel.dll

2013-02-15 19:07 . 2012-08-24 18:03 1448448 ----a-w- c:\windows\system32\lsasrv.dll

2013-02-15 19:07 . 2012-08-24 16:57 247808 ----a-w- c:\windows\SysWow64\schannel.dll

2013-02-15 19:07 . 2012-08-24 16:57 22016 ----a-w- c:\windows\SysWow64\secur32.dll

2013-02-15 19:07 . 2012-08-24 16:53 96768 ----a-w- c:\windows\SysWow64\sspicli.dll

2013-02-15 18:33 . 2013-02-15 18:33 -------- d-----w- c:\users\McDos\AppData\Local\Avg2013

2013-02-15 14:57 . 2013-02-15 14:57 -------- d-----w- c:\users\McDos\AppData\Local\Autodesk

2013-02-15 14:55 . 2013-02-15 14:55 -------- d-----w- c:\users\McDos\AppData\Local\backburner

2013-02-14 01:08 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 01:08 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 00:21 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-02-14 00:21 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-02-14 00:21 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-02-14 00:21 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys

2013-02-14 00:21 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll

2013-02-14 00:21 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe

2013-02-14 00:21 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

2013-02-14 00:21 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll

2013-02-14 00:21 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe

2013-02-14 00:21 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe

2013-02-14 00:21 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys

2013-02-14 00:21 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS

2013-02-13 15:58 . 2013-02-13 15:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2013-02-13 15:58 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-02-13 15:56 . 2013-02-13 15:56 -------- d-----w- c:\users\McDos\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant

2013-02-13 15:46 . 2013-02-13 15:46 -------- d-----w- c:\program files (x86)\Adobe Download Assistant

2013-02-11 14:01 . 2013-02-12 15:26 -------- d-----w- c:\users\McDos\AppData\Roaming\.minecraft

2013-02-11 13:56 . 2013-02-11 13:56 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-02-11 13:32 . 2013-02-11 13:32 -------- d-----w- c:\users\McDos\AppData\Roaming\BlackBean

2013-02-09 22:20 . 2013-02-09 22:20 -------- d--h--r- c:\users\McDos\AppData\Roaming\SecuROM

2013-02-09 18:35 . 2013-02-09 18:36 -------- d-----w- c:\users\McDos\AppData\Local\Green Man Gaming

2013-02-06 12:26 . 2013-02-06 12:26 310688 ----a-w- c:\windows\system32\javaws.exe

2013-02-06 12:26 . 2013-02-06 12:26 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll

2013-02-06 12:26 . 2013-02-06 12:26 188832 ----a-w- c:\windows\system32\javaw.exe

2013-02-06 12:26 . 2013-02-06 12:26 188320 ----a-w- c:\windows\system32\java.exe

2013-02-06 12:26 . 2013-02-06 12:26 -------- d-----w- c:\program files\Java

2013-02-01 20:52 . 2013-02-01 20:52 -------- d-----w- c:\program files (x86)\Google

2013-02-01 16:15 . 2013-02-01 16:15 -------- d-----w- c:\users\McDos\AppData\Roaming\Malwarebytes

2013-02-01 16:15 . 2013-02-01 16:15 -------- d-----w- c:\programdata\Malwarebytes

2013-02-01 16:14 . 2013-02-01 16:14 -------- d-----w- c:\users\McDos\AppData\Local\Programs

2013-02-01 08:38 . 2013-02-01 08:38 -------- d-----w- c:\program files\Common Files\Macrovision Shared

2013-01-20 15:09 . 2013-01-20 15:09 -------- d-----w- c:\program files (x86)\Common Files\Skype

2013-01-20 14:59 . 2013-01-20 14:59 230320 ----a-w- c:\windows\system32\drivers\MpFilter.sys

2013-01-17 20:03 . 2013-01-17 20:03 -------- d-----w- c:\program files (x86)\Pando Networks

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-02-16 15:29 . 2011-07-28 21:16 190656 ----a-w- c:\programdata\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll

2013-02-14 01:12 . 2010-07-07 09:34 70004024 ----a-w- c:\windows\system32\MRT.exe

2013-02-11 13:56 . 2012-06-08 12:16 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2013-02-11 13:56 . 2010-08-12 13:05 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-02-09 20:42 . 2012-04-05 13:31 697712 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-02-09 20:42 . 2011-06-20 19:52 74096 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-02-06 12:26 . 2012-08-24 12:40 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll

2013-02-06 12:26 . 2012-03-24 16:58 963488 ----a-w- c:\windows\system32\deployJava1.dll

2013-01-30 10:53 . 2010-07-07 09:30 273840 ------w- c:\windows\system32\MpSigStub.exe

2013-01-20 14:59 . 2010-10-24 20:25 130008 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys

2013-01-04 04:43 . 2013-02-14 00:21 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2012-12-16 17:11 . 2012-12-22 02:35 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-12-16 14:45 . 2012-12-22 02:35 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-12-16 14:13 . 2012-12-22 02:35 295424 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-12-16 14:13 . 2012-12-22 02:35 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-12-07 13:20 . 2013-01-09 14:17 441856 ----a-w- c:\windows\system32\Wpc.dll

2012-12-07 13:15 . 2013-01-09 14:17 2746368 ----a-w- c:\windows\system32\gameux.dll

2012-12-07 12:26 . 2013-01-09 14:17 308736 ----a-w- c:\windows\SysWow64\Wpc.dll

2012-12-07 12:20 . 2013-01-09 14:17 2576384 ----a-w- c:\windows\SysWow64\gameux.dll

2012-12-07 11:20 . 2013-01-09 14:17 30720 ----a-w- c:\windows\system32\usk.rs

2012-12-07 11:20 . 2013-01-09 14:17 43520 ----a-w- c:\windows\system32\csrr.rs

2012-12-07 11:20 . 2013-01-09 14:17 23552 ----a-w- c:\windows\system32\oflc.rs

2012-12-07 11:20 . 2013-01-09 14:17 45568 ----a-w- c:\windows\system32\oflc-nz.rs

2012-12-07 11:20 . 2013-01-09 14:17 44544 ----a-w- c:\windows\system32\pegibbfc.rs

2012-12-07 11:20 . 2013-01-09 14:17 20480 ----a-w- c:\windows\system32\pegi-fi.rs

2012-12-07 11:20 . 2013-01-09 14:17 20480 ----a-w- c:\windows\system32\pegi-pt.rs

2012-12-07 11:19 . 2013-01-09 14:17 20480 ----a-w- c:\windows\system32\pegi.rs

2012-12-07 11:19 . 2013-01-09 14:17 46592 ----a-w- c:\windows\system32\fpb.rs

2012-12-07 11:19 . 2013-01-09 14:17 40960 ----a-w- c:\windows\system32\cob-au.rs

2012-12-07 11:19 . 2013-01-09 14:17 21504 ----a-w- c:\windows\system32\grb.rs

2012-12-07 11:19 . 2013-01-09 14:17 15360 ----a-w- c:\windows\system32\djctq.rs

2012-12-07 11:19 . 2013-01-09 14:17 55296 ----a-w- c:\windows\system32\cero.rs

2012-12-07 11:19 . 2013-01-09 14:17 51712 ----a-w- c:\windows\system32\esrb.rs

2012-12-07 10:46 . 2013-01-09 14:17 43520 ----a-w- c:\windows\SysWow64\csrr.rs

2012-12-07 10:46 . 2013-01-09 14:17 30720 ----a-w- c:\windows\SysWow64\usk.rs

2012-12-07 10:46 . 2013-01-09 14:17 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs

2012-12-07 10:46 . 2013-01-09 14:17 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs

2012-12-07 10:46 . 2013-01-09 14:17 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs

2012-12-07 10:46 . 2013-01-09 14:17 23552 ----a-w- c:\windows\SysWow64\oflc.rs

2012-12-07 10:46 . 2013-01-09 14:17 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs

2012-12-07 10:46 . 2013-01-09 14:17 46592 ----a-w- c:\windows\SysWow64\fpb.rs

2012-12-07 10:46 . 2013-01-09 14:17 20480 ----a-w- c:\windows\SysWow64\pegi.rs

2012-12-07 10:46 . 2013-01-09 14:17 21504 ----a-w- c:\windows\SysWow64\grb.rs

2012-12-07 10:46 . 2013-01-09 14:17 40960 ----a-w- c:\windows\SysWow64\cob-au.rs

2012-12-07 10:46 . 2013-01-09 14:17 15360 ----a-w- c:\windows\SysWow64\djctq.rs

2012-12-07 10:46 . 2013-01-09 14:17 55296 ----a-w- c:\windows\SysWow64\cero.rs

2012-12-07 10:46 . 2013-01-09 14:17 51712 ----a-w- c:\windows\SysWow64\esrb.rs

2012-12-03 15:47 . 2012-12-18 17:25 983936 ----a-w- c:\windows\system32\nvumdshimx.dll

2012-12-03 15:47 . 2012-12-18 17:25 9271352 ----a-w- c:\windows\system32\nvcuda.dll

2012-12-03 15:47 . 2012-12-18 17:25 841272 ----a-w- c:\windows\SysWow64\nvumdshim.dll

2012-12-03 15:47 . 2012-12-18 17:25 7819016 ----a-w- c:\windows\SysWow64\nvcuda.dll

2012-12-03 15:47 . 2012-12-18 17:25 7446192 ----a-w- c:\windows\system32\nvopencl.dll

2012-12-03 15:47 . 2012-12-18 17:25 6149904 ----a-w- c:\windows\SysWow64\nvopencl.dll

2012-12-03 15:47 . 2012-12-18 17:25 2816824 ----a-w- c:\windows\system32\nvapi64.dll

2012-12-03 15:47 . 2012-12-18 17:25 2784104 ----a-w- c:\windows\system32\nvcuvid.dll

2012-12-03 15:47 . 2012-12-18 17:25 26811240 ----a-w- c:\windows\system32\nvoglv64.dll

2012-12-03 15:47 . 2012-12-18 17:25 2606440 ----a-w- c:\windows\SysWow64\nvcuvid.dll

2012-12-03 15:47 . 2012-12-18 17:25 25256296 ----a-w- c:\windows\system32\nvcompiler.dll

2012-12-03 15:47 . 2012-12-18 17:25 2496976 ----a-w- c:\windows\SysWow64\nvapi.dll

2012-12-03 15:47 . 2012-12-18 17:25 245432 ----a-w- c:\windows\system32\nvinitx.dll

2012-12-03 15:47 . 2012-12-18 17:25 2226024 ----a-w- c:\windows\system32\nvcuvenc.dll

2012-12-03 15:47 . 2012-12-18 17:25 20335976 ----a-w- c:\windows\SysWow64\nvoglv32.dll

2012-12-03 15:47 . 2012-12-18 17:25 201136 ----a-w- c:\windows\SysWow64\nvinit.dll

2012-12-03 15:47 . 2012-12-18 17:25 1874280 ----a-w- c:\windows\SysWow64\nvcuvenc.dll

2012-12-03 15:47 . 2012-12-18 17:25 1805672 ----a-w- c:\windows\system32\nvdispco64.dll

2012-12-03 15:47 . 2012-12-18 17:25 18045968 ----a-w- c:\windows\system32\nvd3dumx.dll

2012-12-03 15:47 . 2012-12-18 17:25 17559912 ----a-w- c:\windows\SysWow64\nvcompiler.dll

2012-12-03 15:47 . 2012-12-18 17:25 15122280 ----a-w- c:\windows\SysWow64\nvd3dum.dll

2012-12-03 15:47 . 2012-12-18 17:25 1504104 ----a-w- c:\windows\system32\nvdispgenco64.dll

2012-12-03 15:47 . 2012-12-18 17:25 15016256 ----a-w- c:\windows\system32\nvwgf2umx.dll

2012-12-03 15:47 . 2012-12-18 17:25 12603960 ----a-w- c:\windows\SysWow64\nvwgf2um.dll

2012-12-03 15:47 . 2012-12-18 17:25 11532648 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2012-12-01 05:49 . 2012-12-18 17:26 3663213 ----a-w- c:\windows\system32\nvcoproc.bin

2012-12-01 05:49 . 2012-12-18 17:26 63336 ----a-w- c:\windows\system32\nvshext.dll

2012-12-01 05:49 . 2012-12-18 17:26 118120 ----a-w- c:\windows\system32\nvmctray.dll

2012-12-01 05:49 . 2012-12-18 17:26 890216 ----a-w- c:\windows\system32\nvvsvc.exe

2012-12-01 05:48 . 2012-12-18 17:26 6223208 ----a-w- c:\windows\system32\nvcpl.dll

2012-12-01 05:48 . 2012-12-18 17:26 3311464 ----a-w- c:\windows\system32\nvsvc64.dll

2012-11-30 21:43 . 2012-11-30 21:43 438632 ----a-w- c:\windows\SysWow64\nvStreaming.exe

2012-11-30 05:45 . 2013-01-09 14:15 362496 ----a-w- c:\windows\system32\wow64win.dll

2012-11-30 05:45 . 2013-01-09 14:15 243200 ----a-w- c:\windows\system32\wow64.dll

2012-11-30 05:45 . 2013-01-09 14:15 13312 ----a-w- c:\windows\system32\wow64cpu.dll

2012-11-30 05:43 . 2013-01-09 14:15 16384 ----a-w- c:\windows\system32\ntvdm64.dll

2012-11-30 05:41 . 2013-01-09 14:15 424448 ----a-w- c:\windows\system32\KernelBase.dll

2012-11-30 05:41 . 2013-01-09 14:15 1161216 ----a-w- c:\windows\system32\kernel32.dll

2012-11-30 05:38 . 2013-01-09 14:15 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll

2012-11-30 05:38 . 2013-01-09 14:15 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]

"Trust Gaming Mouse"="c:\program files (x86)\Trust Gaming Mouse\Mouse.exe" [2011-01-17 2245632]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer9"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

R1 bqtjzojq;bqtjzojq;c:\windows\system32\drivers\bqtjzojq.sys [x]

R1 kushbwau;kushbwau;c:\windows\system32\drivers\kushbwau.sys [x]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]

R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]

R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]

R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-01 1431888]

R3 HRMACPI;DSF ACPI Redirection Module;c:\windows\system32\DRIVERS\HRMACPI.SYS [x]

R3 HRMINTS;DSF Interrupt Redirection Module;c:\windows\system32\DRIVERS\HRMINTS.SYS [2010-02-08 128504]

R3 HRMPORTS;DSF IO Port Redirection Module;c:\windows\system32\DRIVERS\HRMPORTS.SYS [2010-02-08 148360]

R3 IAMTVE;Stuurprogramma voor Intel® Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTVE.sys [2007-04-11 43416]

R3 IAMTXPE;Stuurprogramma voor Intel® Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTXPE.sys [2007-04-11 51096]

R3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-03 271872]

R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [2009-11-16 40144]

R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [2009-11-16 42192]

R3 MSICDSetup;MSICDSetup;E:\CDriver64.sys [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]

R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 SOFTHIDUSBK;USB HID Layer;c:\windows\system32\DRIVERS\SOFTHIDUSBK.SYS [2010-02-08 206848]

R3 SOFTUSBK;Generic USB device;c:\windows\system32\DRIVERS\SOFTUSBK.SYS [2010-02-08 675328]

R3 SOFTUSBTESTHUB;Generic USB Test Hub;c:\windows\system32\DRIVERS\SOFTUSBTESTHUB.SYS [x]

R3 SOFTWADP;Wireless adapter devices;c:\windows\system32\DRIVERS\SOFTWADP.SYS [x]

R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe [2012-11-26 745368]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-07 1255736]

R3 WinRing0_1_2_0;WinRing0_1_2_0;d:\mijn documenten\Games\razer\Driver\WinRing0x64.sys [2012-09-17 14544]

R3 WSOFTUSBK;Generic wireless USB device;c:\windows\system32\DRIVERS\WSOFTUSBK.SYS [x]

S0 DSFKSVCS;Kernel Services for DSF;c:\windows\system32\DRIVERS\dsfksvcs.sys [2010-02-08 676232]

S0 dsfroot;root enumerated bus driver;c:\windows\system32\DRIVERS\dsfroot.sys [2010-02-08 35832]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-09-28 52856]

S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]

S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]

S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]

S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]

S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Conceptronic\Common\RaRegistry64.exe [2009-12-10 212256]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]

S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]

S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2010-04-05 301232]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]

S3 HRMCFGSPC;DSF General Configuration Space Redirection Module;c:\windows\system32\DRIVERS\HRMCFGSPC.SYS [2010-02-08 133512]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]

S3 softehci;Microsoft USB 2.0 Enhanced Host Controller Interface (EHCI) Simulator Driver;c:\windows\system32\DRIVERS\softehci.sys [2010-02-08 366592]

S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]

S3 trustms;Trust Mouse;c:\windows\system32\drivers\trustms.sys [2010-11-14 12416]

S3 usbehci_dsf;Microsoft DSF-enabled USB 2.0 Enhanced Host Controller Interface (EHCI) Miniport Driver;c:\windows\system32\DRIVERS\usbehci_dsf.sys [2010-02-08 52736]

S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys [2011-04-28 1310720]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-02-01 20:52 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe

.

Inhoud van de 'Gedeelde Taken' map

.

2013-02-16 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 20:42]

.

2013-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 20:52]

.

2013-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 20:52]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]

"Cm106Sound"="c:\windows\Syswow64\cm106.dll" [2011-04-28 8757248]

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE: &Verzenden naar OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105

IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000

IE: Free YouTube to Mp3 Converter - c:\users\McDos\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

.

- - - - ORPHANS VERWIJDERD - - - -

.

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-Free Audio CD to MP3 Converter_is1 - c:\program files (x86)\DVDVideoSoft\Free Audio CD to MP3 Converter\unins000.exe

AddRemove-Ghost Control_is1 - c:\program files (x86)\Ghost Control\unins000.exe

AddRemove-JamGuru - c:\program files (x86)\UltimateGuitar\JamGuru\uninst.exe

AddRemove-MagicDisc 2.7.106 - c:\progra~2\MAGICD~1\UNWISE.EXE

AddRemove-Magicka_is1 - d:\mijn documenten\Games\Steam\steamapps\common\Magicka\unins000.exe

AddRemove-MAGIX_MSI_mm17dlx - c:\program files (x86)\MAGIX\Music_Maker_17_Premium_Download_Version\mm17dlx_en-GB_setup.exe

AddRemove-NoteWorthy Composer 2 - c:\program files (x86)\Noteworthy Software\NoteWorthy Composer 2\Uninstall.exe

AddRemove-Skyrim Dawnguard DLC+Update v1.7706-=AviaRa=- 1.7706 - d:\mijn documenten\Games\The Elder Scrolls V Skyrim\Skyrim Dawnguard DLC+Update v1.7706-=AviaRa=-\Uninstall.exe

AddRemove-The Lost Watch II NV 3D Screensaver_is1 - c:\program files (x86)\The Lost Watch II NV 3D Screensaver\unins000.exe

AddRemove-vReveal - c:\program files (x86)\vReveal\Uninstall.exe

AddRemove-Western Railway NV 3D Screensaver_is1 - c:\program files (x86)\Western Railway NV 3D Screensaver\unins000.exe

AddRemove-WinISO_is1 - c:\program files (x86)\WinISO\unins000.exe

AddRemove-{16F0EE77-B2B1-4417-A8CC-07E06C78CCC4} - c:\program files (x86)\KellySoftware\Matrix-ks\Uninstall.exe

AddRemove-SOE-PlanetSide 2 Beta - d:\planetside\Uninstaller.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DSFKSVCS\MofImagePath]

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-3876104778-1600678488-752456974-1000\Software\SecuROM\License information*]

"datasecu"=hex:10,d0,29,c2,dd,37,bc,f5,bf,97,12,f7,c5,2f,28,b9,9f,c3,de,6f,d1,

74,63,99,b0,c8,e7,d3,e2,28,86,1c,fd,6d,2a,a8,40,ec,ae,af,9a,dc,99,41,31,65,\

"rkeysecu"=hex:41,f2,72,e7,97,8d,0f,09,89,ee,81,32,d9,e4,30,b5

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Voltooingstijd: 2013-02-16 17:04:39

ComboFix-quarantined-files.txt 2013-02-16 16:04

.

Pre-Run: 1.769.779.200 bytes beschikbaar

Post-Run: 3.851.087.872 bytes beschikbaar

.

- - End Of File - - 2966D9B9943A7A4F9BB72ED1FE85BC32

Link to post
Share on other sites

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Double-Click on TDSSKiller.exe to run the application, then on Start Scan.
    If running Vista or Windows 7, do a RIGHT-Click and select Run as Administrator to start TDSSKILLER.exe.
  • If an infected file is detected, the default action will be Cure, click on Continue.
    TDSSKillerMal-1.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    TDSSKillerCompleted.png
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Step 2

You should already have the DDS tool from before. If you do not have, you should download and save it.

I need for you to run it and at end, copy and paste DDS.txt into a new reply.

Download DDS and save it to your desktop from http://download.bleepingcomputer.com/sUBs/dds.com here

or http://download.bleepingcomputer.com/sUBs/dds.scr or

http://www.infospyware.net/sUBs/dds

Disable any script blocker if your antivirus/antimalware has it.

On Vista/ Windows 7/ Windows 8 do a RIGHT-click on dds and select Run As Administrator :excl:

On Windows XP double click dds to run the tool.

DDS will run in a command prompt window and will take 3 to 4 minutes or so.

Follow and answer the prompts as appropriate.

  • When done, DDS will open two (2) logs:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.

Please Copy & Paste contents of the following logs in your next reply:
DDS.txt
Attach.txt
Step 3
Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

I've done the scans and posted the logs below. In step 2 it wasn't clear whether you wanted both DDS.txt and Attach.txt or just DDS.txt so i posted both.

Attach

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 12-8-2010 9:10:52

System Uptime: 16-2-2013 16:31:54 (3 hours ago)

.

Motherboard: Intel Corporation | | DH55TC

Processor: Intel® Core i5 CPU 650 @ 3.20GHz | XU1 | 3193/533mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 75 GiB total, 3,357 GiB free.

D: is FIXED (NTFS) - 856 GiB total, 372,778 GiB free.

E: is CDROM ()

F: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP841: 16-2-2013 18:43:17 - Gepland controlepunt

.

==== Installed Programs ======================

.

Adobe AIR

Adobe Community Help

Adobe Download Assistant

Adobe Flash Player 11 ActiveX

Adobe Flash Player 11 Plugin

Adobe Media Player

Adobe Photoshop CS5

Adobe Photoshop Elements 7.0

Adobe Premiere Elements 7.0

Adobe Premiere Elements 7.0 Templates

Adobe Reader X (10.1.5) - Nederlands

Adobe Shockwave Player 11.5

AIWI

AIWI JoyStick

Amnesia - The Dark Descent

Anark Client 1.0

Any Video Converter 3.2.3

APB Reloaded

Apple Application Support

Apple Software Update

applicationupdater

Assassin's Creed Brotherhood

Assassin's Creed Revelations 1.02

Audacity 1.3.12 (Unicode)

Audiosurf

Autodesk Maya 2012 64-bit

Bonjour

Borderlands 2

Capsule

Composite 2012 64-bit

Conceptronic 300N Wireless Adapter (v3.0)

Cooliris for Internet Explorer

Curse Client

D3DX10

Darksiders II

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

Device Simulation Framework 1.0.1

Dishonored

Dota 2

eBook Reader

EPN werkboek-i Numbers and Space/1 havo vwo

F-N

FFmpeg for Audacity on Windows

Firebird SQL Server - MAGIX Edition

Fluency TTS 5.0

Fraps (remove only)

Free Audio CD to MP3 Converter version 1.3.7

Free YouTube to MP3 Converter version 3.11.35.1031

FTL version 1.01

gamelauncher-ps2-live

GameMaker 8.1

GamersFirst LIVE!

GameSpy Arcade

Ghost Control 2.1

Google Chrome

Google Update Helper

Heaven DX11 Benchmark version 3.0

Hi-Rez Studios Authenticate and Update Service

Hotfix for Microsoft Visual C# 2010 Express - ENU (KB2635973)

House of Night Screensaver Screensaver

HTML-Kit

ImagXpress

Intel® Management Engine Components

Intel® Network Connections 15.3.68.0

J2SE Runtime Environment 5.0 Update 1

JamGuru 1.0 RC5

Java 7 Update 13

Java 7 Update 13 (64-bit)

Java Auto Updater

Junk Mail filter update

LAME v3.98.2 for Audacity

League of Legends

Loadout

LogMeIn Hamachi

Magic The Gathering - Duels of the Planeswalkers 2013

MagicDisc 2.7.106

Magicka

MAGIX Music Maker 17 Premium Download Version

MAGIX Screenshare

MAGIX Speed burnR (MSI)

Malwarebytes Anti-Malware versie 1.70.0.1100

Matrix-ks

Microsoft .NET Framework 1.1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile NLD Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended NLD Language Pack

Microsoft .NET Framework 4 Multi-Targeting Pack

Microsoft Antimalware Service NL-NL Language Pack

Microsoft Application Error Reporting

Microsoft Games for Windows - LIVE Redistributable

Microsoft Games for Windows Marketplace

Microsoft Help Viewer 1.1

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (Dutch) 2010

Microsoft Office Excel MUI (Dutch) 2010

Microsoft Office Groove MUI (Dutch) 2010

Microsoft Office InfoPath MUI (Dutch) 2010

Microsoft Office Office 64-bit Components 2010

Microsoft Office OneNote MUI (Dutch) 2010

Microsoft Office Outlook MUI (Dutch) 2010

Microsoft Office PowerPoint MUI (Dutch) 2010

Microsoft Office Professional Plus 2010

Microsoft Office Proof (Dutch) 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (German) 2010

Microsoft Office Proofing (Dutch) 2010

Microsoft Office Publisher MUI (Dutch) 2010

Microsoft Office Shared 64-bit MUI (Dutch) 2010

Microsoft Office Shared MUI (Dutch) 2010

Microsoft Office Word MUI (Dutch) 2010

Microsoft Rise Of Nations

Microsoft Security Client

Microsoft Security Client NL-NL Language Pack

Microsoft Security Essentials

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft SQL Server 2008 R2 Management Objects

Microsoft SQL Server Compact 3.5 SP2 ENU

Microsoft SQL Server Compact 3.5 SP2 x64 ENU

Microsoft SQL Server System CLR Types

Microsoft Visual C# 2010 Express - ENU

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219

Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools

Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU

Microsoft Visual Studio 2010 Service Pack 1

Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD

Microsoft XNA Framework Redistributable 3.1

Microsoft XNA Framework Redistributable 4.0

Microsoft XNA Game Studio 4.0

Microsoft XNA Game Studio 4.0 (ARP entry)

Microsoft XNA Game Studio 4.0 (Redists)

Microsoft XNA Game Studio 4.0 (Shared Components)

Microsoft XNA Game Studio 4.0 (Visual Studio)

Microsoft XNA Game Studio 4.0 (XnaLiveProxy)

Microsoft XNA Game Studio 4.0 Documentation

Microsoft XNA Game Studio Platform Tools

Microsoft_VC80_ATL_x86

Microsoft_VC80_ATL_x86_x64

Microsoft_VC80_CRT_x86

Microsoft_VC80_CRT_x86_x64

Microsoft_VC80_MFC_x86

Microsoft_VC80_MFC_x86_x64

Microsoft_VC80_MFCLOC_x86

Microsoft_VC80_MFCLOC_x86_x64

Microsoft_VC90_ATL_x86

Microsoft_VC90_ATL_x86_x64

Microsoft_VC90_CRT_x86

Microsoft_VC90_CRT_x86_x64

Microsoft_VC90_MFC_x86

Microsoft_VC90_MFC_x86_x64

MSI Afterburner 2.2.3

MSI Kombustor 2.3.0

MSVCRT

MSVCRT Redists

MSVCRT_amd64

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP2 Parser and SDK

MSXML4 Parser

MuseScore 0.9.6.3 MuseScore score typesetter

N-F

neroxml

NoteWorthy Composer 2

NVIDIA-configuratiescherm 310.70

NVIDIA 3D Vision controllerstuurprogramma 310.70

NVIDIA 3D Vision stuurprogramma 310.70

NVIDIA Grafisch stuurprogramma 310.70

NVIDIA HD Audio-stuurprogramma 1.3.18.0

NVIDIA Install Application

NVIDIA PhysX

NVIDIA PhysX systeemsoftware 9.12.1031

NVIDIA Stereoscopic 3D Driver

Oblivion

OpenAL

Orcs Must Die 2

Orcs Must Die!

PDF Settings CS5

Perspective 1.0

PlanetSide 2

Portal 2 version 2.0.0.1

Primal Carnage Beta

PunkBuster Services

QuickTime

Ravaged

Razer Game Booster

Rise of Nations Thrones and Patriots

Roller Coaster World 3D

RollerCoaster Tycoon 3

RuneScape Launcher 1.2.2

Saints Row The Third

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Extended (KB2416472)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition

Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition

Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition

Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)

Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)

Simple Port Forwarding

Skype Click to Call

Skype™ 6.1

Skyrim Dawnguard DLC+Update v1.7706-=AviaRa=- 1.7706

Smite

SnagIt 8

Star Wars: The Old Republic

Steam

Synthesia (remove only)

System Requirements Lab for Intel

Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

Taalpakket voor Microsoft .NET Framework 4 Extended - NLD

Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD

Tabulator

TeamSpeak 3 Client

Text-To-Speech-Runtime

The Lost Watch II NV 3D Screensaver 1.0

The Witcher 2 - Assassins of Kings Enhanced Edition

TI Connect 1.6

Torchlight II © Runic Games version 1

Transcripted Alienware Demo

Trust 5.1 Gaming Headset

Trust Gaming Mouse Driver V1.1

Tunngle beta

TuxGuitar

Ubisoft Game Launcher

Unity Web Player

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2473228)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2494150)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553092)

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition

Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition

Vegas Pro 11.0

VirtualCloneDrive

Visual Studio 2008 x64 Redistributables

Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU

vReveal

VST Bridge 1.1

Western Railway NV 3D Screensaver 2.0

Windows Driver Package - Texas Instruments Inc. (SilvrLnk) USB (06/11/2009 1.0.0.0)

Windows Driver Package - Texas Instruments Inc. (TIEHDUSB) USB (09/02/2009 1.0.0.1)

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Windows Media Center-gadgets voor Windows SideShow

Windows Media Player Firefox Plugin

Windows SideShow Managed Runtime 1.0

WinISO 5.3

WinRAR

World of Warcraft

World of Warcraft Beta

Zoo Tycoon: Complete Collection

.

==== End Of File ===========================

dds

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.13.2

Run by McDos at 19:02:33 on 2013-02-16

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3957.1586 [GMT 1:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

D:\Mijn Documenten\Games\HiPatchService.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Windows\SysWOW64\PnkBstrA.exe

C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe

C:\Program Files (x86)\Conceptronic\Common\RaRegistry64.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\taskhost.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files\Microsoft Security Client\NisSrv.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

BHO: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItBHO.dll

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: Cooliris Plug-In for Internet Explorer: {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll

TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll

mRun: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s

mRun: [Trust Gaming Mouse] C:\Program Files (x86)\Trust Gaming Mouse\Mouse.exe

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105

IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000

IE: Free YouTube to Mp3 Converter - C:\Users\McDos\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - C:\Program Files (x86)\PicLensIE\cooliris.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: NameServer = 192.168.0.1

TCP: Interfaces\{1595706F-7DEE-4E62-A5AA-CF00A0419D29} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B} : DHCPNameServer = 192.168.0.1

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B}\A597F507279667164756F595A4432585E4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{3EA217B0-267C-4673-8C20-4C7FF1FE314B}\A597F507279667164756F5E465344343A4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58

TCP: Interfaces\{CC3B6A59-6FEA-419E-A76F-A7BDA7B9749B} : DHCPNameServer = 7.254.254.254

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\x64\SnagItBHO64.dll

x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

x64-TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\x64\SnagItIEAddin64.dll

x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe

x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe

x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe

x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey

x64-Run: [Cm106Sound] C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-DPF: {615A1925-0E5B-4767-A65E-3165AEAC32A3} - hxxp://quickscan.bitdefender.com/qsax/qsax64.cab

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>

x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: igfxcui - igfxdev.dll

x64-SSODL: WebCheck - <orphaned>

x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

.

============= SERVICES / DRIVERS ===============

.

P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;D:\Mijn Documenten\Games\HiPatchService.exe [2012-8-3 8704]

R0 DSFKSVCS;Kernel Services for DSF;C:\Windows\System32\drivers\dsfksvcs.sys [2010-2-8 676232]

R0 dsfroot;root enumerated bus driver;C:\Windows\System32\drivers\dsfroot.sys [2010-2-8 35832]

R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-9-28 52856]

R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]

R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-8-27 1253376]

R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-2-13 398184]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-2-13 682344]

R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2010-10-24 130008]

R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe [2010-8-14 185632]

R2 RalinkRegistryWriter64;Ralink Registry Writer 64;C:\Program Files (x86)\Conceptronic\Common\RaRegistry64.exe [2010-8-14 212256]

R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-11-30 382824]

R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-7-7 2320920]

R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2010-4-5 301232]

R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]

R3 HRMCFGSPC;DSF General Configuration Space Redirection Module;C:\Windows\System32\drivers\hrmcfgspc.sys [2010-2-8 133512]

R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-2-13 24176]

R3 NisSrv;Microsoft Netwerkinspectie;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]

R3 softehci;Microsoft USB 2.0 Enhanced Host Controller Interface (EHCI) Simulator Driver";C:\Windows\System32\drivers\softehci.sys [2010-2-8 366592]

R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\System32\drivers\tap0901t.sys [2011-10-10 31232]

R3 trustms;Trust Mouse;C:\Windows\System32\drivers\trustms.sys [2010-11-15 12416]

R3 usbehci_dsf;Microsoft DSF-enabled USB 2.0 Enhanced Host Controller Interface (EHCI) Miniport Driver;C:\Windows\System32\drivers\usbehci_dsf.sys [2010-2-8 52736]

R3 USBMULCD;USB Multi-Channel Audio Device Interface;C:\Windows\System32\drivers\CM10664.sys [2012-12-29 1310720]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]

S3 androidusb;ADB Interface Driver;C:\Windows\System32\drivers\androidusb.sys [2010-4-29 32768]

S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-8-7 3276800]

S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-2-1 1431888]

S3 HRMINTS;DSF Interrupt Redirection Module;C:\Windows\System32\drivers\hrmints.sys [2010-2-8 128504]

S3 HRMPORTS;DSF IO Port Redirection Module;C:\Windows\System32\drivers\hrmports.sys [2010-2-8 148360]

S3 IAMTVE;Stuurprogramma voor Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTVE.sys [2010-7-7 43416]

S3 IAMTXPE;Stuurprogramma voor Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTXPE.sys [2010-7-7 51096]

S3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]

S3 ioatdma1;ioatdma1;C:\Windows\System32\drivers\qd162x64.sys [2009-11-16 40144]

S3 ioatdma2;Intel® QuickData Technology device ver.2;C:\Windows\System32\drivers\qd262x64.sys [2009-11-16 42192]

S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-15 19456]

S3 SOFTHIDUSBK;USB HID Layer;C:\Windows\System32\drivers\softhidusbk.sys [2010-2-8 206848]

S3 SOFTUSBK;Generic USB device;C:\Windows\System32\drivers\softusbk.sys [2010-2-8 675328]

S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-15 57856]

S3 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2012-6-1 745368]

S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-7 1255736]

S3 WinRing0_1_2_0;WinRing0_1_2_0;D:\Mijn Documenten\Games\razer\Driver\WinRing0x64.sys [2012-9-17 14544]

.

=============== File Associations ===============

.

FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [userChoice]

FileExt: .js: JSFile=C:\Windows\System32\WScript.exe "%1" %* [userChoice]

.

=============== Created Last 30 ================

.

2013-02-16 16:30:03 -------- d-sh--w- C:\$RECYCLE.BIN

2013-02-16 16:23:54 9161176 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5BADC2DC-4E05-4E99-81BD-91A0D663514A}\mpengine.dll

2013-02-16 15:54:44 98816 ----a-w- C:\Windows\sed.exe

2013-02-16 15:54:44 256000 ----a-w- C:\Windows\PEV.exe

2013-02-16 15:54:44 208896 ----a-w- C:\Windows\MBR.exe

2013-02-16 15:46:09 -------- d-----w- C:\Users\McDos\AppData\Roaming\QuickScan

2013-02-16 15:23:38 9161176 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-02-16 13:12:52 -------- d-----w- C:\Users\McDos\Doctor Web

2013-02-15 22:02:56 -------- d-----w- C:\Windows\rescache

2013-02-15 19:59:04 -------- d-----w- C:\Windows\ERUNT

2013-02-15 19:57:57 -------- d-----w- C:\JRT

2013-02-15 19:17:02 -------- d-----w- C:\ProgramData\VS

2013-02-15 19:07:24 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll

2013-02-15 19:07:23 366592 ----a-w- C:\Windows\System32\qdvd.dll

2013-02-15 19:07:22 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll

2013-02-15 19:07:22 458712 ----a-w- C:\Windows\System32\drivers\cng.sys

2013-02-15 19:07:22 340992 ----a-w- C:\Windows\System32\schannel.dll

2013-02-15 19:07:22 247808 ----a-w- C:\Windows\SysWow64\schannel.dll

2013-02-15 19:07:22 22016 ----a-w- C:\Windows\SysWow64\secur32.dll

2013-02-15 19:07:22 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys

2013-02-15 19:07:22 1448448 ----a-w- C:\Windows\System32\lsasrv.dll

2013-02-15 18:33:10 -------- d-----w- C:\Users\McDos\AppData\Local\Avg2013

2013-02-15 17:29:50 -------- d-----w- C:\Users\McDos\AppData\Local\{89E4E5C6-37A3-436B-A903-12E5BA81A989}

2013-02-15 14:57:38 -------- d-----w- C:\Users\McDos\AppData\Local\Autodesk

2013-02-15 14:55:09 -------- d-----w- C:\Users\McDos\AppData\Local\backburner

2013-02-14 10:04:11 -------- d-----w- C:\Users\McDos\AppData\Local\{BE33C8F2-90DA-44B3-AACF-61302F59D330}

2013-02-14 01:08:37 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 01:08:37 768000 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2013-02-14 00:21:46 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-02-14 00:21:44 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-02-14 00:21:44 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-02-14 00:21:35 3153408 ----a-w- C:\Windows\System32\win32k.sys

2013-02-14 00:21:33 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2013-02-14 00:21:33 215040 ----a-w- C:\Windows\System32\winsrv.dll

2013-02-14 00:21:33 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2013-02-14 00:21:32 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2013-02-14 00:21:32 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2013-02-14 00:21:32 2048 ----a-w- C:\Windows\SysWow64\user.exe

2013-02-14 00:21:25 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

2013-02-14 00:21:25 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-02-13 15:58:14 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-02-13 15:58:14 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2013-02-13 15:56:02 -------- d-----w- C:\Users\McDos\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant

2013-02-13 15:46:44 -------- d-----w- C:\Program Files (x86)\Adobe Download Assistant

2013-02-13 15:43:05 -------- d-----w- C:\Users\McDos\AppData\Local\{DB1FD5E3-BDBF-4884-A0DA-CCE77F155243}

2013-02-12 22:00:42 -------- d-----w- C:\Users\McDos\AppData\Local\{8C0B7E7C-1B8A-48CF-833E-25F38ED2E306}

2013-02-11 14:01:06 -------- d-----w- C:\Users\McDos\AppData\Roaming\.minecraft

2013-02-11 13:56:53 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-02-11 13:32:41 -------- d-----w- C:\Users\McDos\AppData\Roaming\BlackBean

2013-02-11 12:28:31 -------- d-----w- C:\Users\McDos\AppData\Local\{76ABD2BD-B70D-41D0-82A2-627C9C18DF1E}

2013-02-10 00:51:02 -------- d-----w- C:\Users\McDos\AppData\Local\{0F114ABE-AD15-4084-AE49-4F1954F71BA9}

2013-02-09 18:35:37 -------- d-----w- C:\Users\McDos\AppData\Local\Green Man Gaming

2013-02-09 12:33:51 -------- d-----w- C:\Users\McDos\AppData\Local\{C38784D2-3A26-4370-8028-D79E7C37D727}

2013-02-07 22:49:31 -------- d-----w- C:\Users\McDos\AppData\Local\{88524854-8220-445E-8D77-8543CE357118}

2013-02-07 13:05:56 -------- d-----w- C:\Users\McDos\AppData\Local\{3175A617-D512-4A87-AC54-A759084F3DAE}

2013-02-06 15:30:35 -------- d-----w- C:\Users\McDos\AppData\Local\{E3F38BF3-4716-436D-8F4F-E1AE2D9D9FC7}

2013-02-06 13:34:29 -------- d-----w- C:\Users\McDos\AppData\Local\{FA7CFF0C-369B-4711-A6CD-7774EC637654}

2013-02-06 12:26:24 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll

2013-02-05 18:06:55 -------- d-----w- C:\Users\McDos\AppData\Local\{799D16F1-1BCE-4EFD-8980-8383B5AFFE93}

2013-02-04 14:30:26 -------- d-----w- C:\Users\McDos\AppData\Local\{C6DA0895-9E64-4E85-8F37-AEE9B3B7B820}

2013-02-03 14:37:56 -------- d-----w- C:\Users\McDos\AppData\Local\{D3CD0F8C-8F47-4141-851E-4FFB8BCEA2FE}

2013-02-01 16:15:55 -------- d-----w- C:\Users\McDos\AppData\Roaming\Malwarebytes

2013-02-01 16:15:14 -------- d-----w- C:\ProgramData\Malwarebytes

2013-02-01 16:14:59 -------- d-----w- C:\Users\McDos\AppData\Local\Programs

2013-02-01 08:38:48 -------- d-----w- C:\Program Files\Common Files\Macrovision Shared

2013-01-30 21:55:29 -------- d-----w- C:\Users\McDos\AppData\Local\{F747D08C-D86C-4F3C-808C-5CBCF9C69D02}

2013-01-30 15:03:25 -------- d-----w- C:\Users\McDos\AppData\Local\{5C5A1662-ED91-40CA-B0E1-F20EEA6062D7}

2013-01-29 13:50:10 -------- d-----w- C:\Users\McDos\AppData\Local\{3EB20C87-E99B-401A-A1CA-98009913F757}

2013-01-28 12:48:08 -------- d-----w- C:\Users\McDos\AppData\Local\{31BC587D-BFC1-4376-A13C-814CD635C215}

2013-01-26 17:40:24 -------- d-----w- C:\Users\McDos\AppData\Local\{180ED5A0-F463-41B0-B9F3-E31F23C09973}

2013-01-25 12:24:50 -------- d-----w- C:\Users\McDos\AppData\Local\{7FB777CB-57A4-4865-B778-2D62295D26B7}

2013-01-24 10:10:11 -------- d-----w- C:\Users\McDos\AppData\Local\{CE28031B-21FB-43D3-BF2A-D84D5A40D7B4}

2013-01-23 12:33:23 -------- d-----w- C:\Users\McDos\AppData\Local\{D660AA8D-BE91-4220-9F4A-A0F76C3BD004}

2013-01-22 12:07:32 -------- d-----w- C:\Users\McDos\AppData\Local\{FF610585-A544-4545-89EB-E6D50325E074}

2013-01-21 11:50:24 -------- d-----w- C:\Users\McDos\AppData\Local\{4A81DFB9-E522-4940-BAEB-8A510CEE0C65}

2013-01-20 14:59:04 230320 ----a-w- C:\Windows\System32\drivers\MpFilter.sys

2013-01-20 11:58:07 -------- d-----w- C:\Users\McDos\AppData\Local\{A5C9EF33-31D1-4E09-ADB7-56AF596A83E5}

2013-01-19 12:39:00 -------- d-----w- C:\Users\McDos\AppData\Local\{E7722CD4-5CC9-458F-872F-4074970DEC10}

2013-01-17 20:03:44 -------- d-----w- C:\Program Files (x86)\Pando Networks

.

==================== Find3M ====================

.

2013-02-11 13:56:40 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-02-11 13:56:40 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-02-09 20:42:57 74096 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-02-09 20:42:57 697712 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-02-06 12:26:18 963488 ----a-w- C:\Windows\System32\deployJava1.dll

2013-02-06 12:26:18 1085344 ----a-w- C:\Windows\System32\npDeployJava1.dll

2013-01-30 10:53:22 273840 ------w- C:\Windows\System32\MpSigStub.exe

2013-01-20 14:59:04 130008 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys

2013-01-09 01:19:09 2312704 ----a-w- C:\Windows\System32\jscript9.dll

2013-01-09 01:12:03 1392128 ----a-w- C:\Windows\System32\wininet.dll

2013-01-09 01:11:06 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2013-01-09 01:07:51 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2013-01-09 01:07:47 599040 ----a-w- C:\Windows\System32\vbscript.dll

2013-01-09 01:04:42 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2013-01-08 22:11:21 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-01-08 22:03:20 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-01-08 22:03:12 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2013-01-08 21:59:02 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2013-01-08 21:58:29 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2013-01-08 21:56:23 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll

2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll

2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll

2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll

2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll

2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll

2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll

2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs

2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs

2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs

2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs

2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs

2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs

2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs

2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs

2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs

2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs

2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs

2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs

2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs

2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs

2012-12-03 15:47:14 983936 ----a-w- C:\Windows\System32\nvumdshimx.dll

2012-12-01 05:49:26 3663213 ----a-w- C:\Windows\System32\nvcoproc.bin

2012-12-01 05:49:25 63336 ----a-w- C:\Windows\System32\nvshext.dll

2012-12-01 05:49:25 118120 ----a-w- C:\Windows\System32\nvmctray.dll

2012-12-01 05:49:24 890216 ----a-w- C:\Windows\System32\nvvsvc.exe

2012-12-01 05:48:41 6223208 ----a-w- C:\Windows\System32\nvcpl.dll

2012-12-01 05:48:37 3311464 ----a-w- C:\Windows\System32\nvsvc64.dll

2012-11-30 21:43:52 438632 ----a-w- C:\Windows\SysWow64\nvStreaming.exe

2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll

2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll

2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll

2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll

2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe

2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe

2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll

2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll

2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll

.

============= FINISH: 19:03:01,52 ===============

Link to post
Share on other sites

Kaspersky log

18:59:57.0354 4904 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

18:59:57.0504 4904 ============================================================

18:59:57.0504 4904 Current date / time: 2013/02/16 18:59:57.0504

18:59:57.0504 4904 SystemInfo:

18:59:57.0504 4904

18:59:57.0504 4904 OS Version: 6.1.7601 ServicePack: 1.0

18:59:57.0504 4904 Product type: Workstation

18:59:57.0504 4904 ComputerName: JASPER

18:59:57.0504 4904 UserName: McDos

18:59:57.0504 4904 Windows directory: C:\Windows

18:59:57.0504 4904 System windows directory: C:\Windows

18:59:57.0504 4904 Running under WOW64

18:59:57.0504 4904 Processor architecture: Intel x64

18:59:57.0504 4904 Number of processors: 4

18:59:57.0504 4904 Page size: 0x1000

18:59:57.0504 4904 Boot type: Normal boot

18:59:57.0504 4904 ============================================================

18:59:59.0222 4904 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

18:59:59.0225 4904 ============================================================

18:59:59.0225 4904 \Device\Harddisk0\DR0:

18:59:59.0226 4904 MBR partitions:

18:59:59.0226 4904 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

18:59:59.0226 4904 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x95FF800

18:59:59.0226 4904 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x9632000, BlocksNum 0x6B0D3DB0

18:59:59.0226 4904 ============================================================

18:59:59.0242 4904 C: <-> \Device\Harddisk0\DR0\Partition2

18:59:59.0291 4904 D: <-> \Device\Harddisk0\DR0\Partition3

18:59:59.0292 4904 ============================================================

18:59:59.0292 4904 Initialize success

18:59:59.0292 4904 ============================================================

19:00:07.0097 0836 ============================================================

19:00:07.0097 0836 Scan started

19:00:07.0097 0836 Mode: Manual;

19:00:07.0097 0836 ============================================================

19:00:07.0858 0836 ================ Scan system memory ========================

19:00:07.0858 0836 System memory - ok

19:00:07.0858 0836 ================ Scan services =============================

19:00:07.0960 0836 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys

19:00:07.0962 0836 1394ohci - ok

19:00:08.0013 0836 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys

19:00:08.0016 0836 ACPI - ok

19:00:08.0055 0836 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys

19:00:08.0056 0836 AcpiPmi - ok

19:00:08.0195 0836 [ 3FD8DC2C9735C2AA70155102CFB93EDA ] AdobeActiveFileMonitor7.0 C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe

19:00:08.0196 0836 AdobeActiveFileMonitor7.0 - ok

19:00:08.0328 0836 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

19:00:08.0329 0836 AdobeARMservice - ok

19:00:08.0476 0836 [ EC807244904FA170C299AB06D87FBDBE ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

19:00:08.0477 0836 AdobeFlashPlayerUpdateSvc - ok

19:00:08.0513 0836 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys

19:00:08.0518 0836 adp94xx - ok

19:00:08.0555 0836 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys

19:00:08.0558 0836 adpahci - ok

19:00:08.0575 0836 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys

19:00:08.0577 0836 adpu320 - ok

19:00:08.0603 0836 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll

19:00:08.0604 0836 AeLookupSvc - ok

19:00:08.0643 0836 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys

19:00:08.0648 0836 AFD - ok

19:00:08.0673 0836 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys

19:00:08.0674 0836 agp440 - ok

19:00:08.0687 0836 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe

19:00:08.0688 0836 ALG - ok

19:00:08.0706 0836 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys

19:00:08.0707 0836 aliide - ok

19:00:08.0722 0836 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys

19:00:08.0723 0836 amdide - ok

19:00:08.0749 0836 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys

19:00:08.0750 0836 AmdK8 - ok

19:00:08.0767 0836 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys

19:00:08.0768 0836 AmdPPM - ok

19:00:08.0789 0836 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys

19:00:08.0791 0836 amdsata - ok

19:00:08.0822 0836 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys

19:00:08.0824 0836 amdsbs - ok

19:00:08.0842 0836 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys

19:00:08.0843 0836 amdxata - ok

19:00:08.0883 0836 [ 363571BC0C79E394E69300D1F2E3DDAE ] androidusb C:\Windows\system32\Drivers\androidusb.sys

19:00:08.0884 0836 androidusb - ok

19:00:08.0924 0836 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys

19:00:08.0925 0836 AppID - ok

19:00:08.0941 0836 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll

19:00:08.0942 0836 AppIDSvc - ok

19:00:08.0976 0836 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll

19:00:08.0978 0836 Appinfo - ok

19:00:09.0003 0836 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys

19:00:09.0004 0836 arc - ok

19:00:09.0013 0836 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys

19:00:09.0015 0836 arcsas - ok

19:00:09.0107 0836 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

19:00:09.0108 0836 aspnet_state - ok

19:00:09.0131 0836 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys

19:00:09.0132 0836 AsyncMac - ok

19:00:09.0146 0836 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys

19:00:09.0146 0836 atapi - ok

19:00:09.0189 0836 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

19:00:09.0196 0836 AudioEndpointBuilder - ok

19:00:09.0204 0836 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll

19:00:09.0207 0836 AudioSrv - ok

19:00:09.0239 0836 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll

19:00:09.0241 0836 AxInstSV - ok

19:00:09.0269 0836 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys

19:00:09.0273 0836 b06bdrv - ok

19:00:09.0292 0836 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys

19:00:09.0295 0836 b57nd60a - ok

19:00:09.0318 0836 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll

19:00:09.0319 0836 BDESVC - ok

19:00:09.0336 0836 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys

19:00:09.0337 0836 Beep - ok

19:00:09.0384 0836 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll

19:00:09.0391 0836 BFE - ok

19:00:09.0430 0836 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll

19:00:09.0439 0836 BITS - ok

19:00:09.0454 0836 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys

19:00:09.0455 0836 blbdrive - ok

19:00:09.0511 0836 [ 673CF4F6BB1FBE09331B526802FBB892 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe

19:00:09.0513 0836 Bonjour Service - ok

19:00:09.0582 0836 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys

19:00:09.0583 0836 bowser - ok

19:00:09.0593 0836 bqtjzojq - ok

19:00:09.0611 0836 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys

19:00:09.0612 0836 BrFiltLo - ok

19:00:09.0625 0836 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys

19:00:09.0626 0836 BrFiltUp - ok

19:00:09.0646 0836 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys

19:00:09.0647 0836 BridgeMP - ok

19:00:09.0686 0836 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll

19:00:09.0688 0836 Browser - ok

19:00:09.0693 0836 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys

19:00:09.0696 0836 Brserid - ok

19:00:09.0707 0836 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys

19:00:09.0708 0836 BrSerWdm - ok

19:00:09.0729 0836 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys

19:00:09.0730 0836 BrUsbMdm - ok

19:00:09.0743 0836 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys

19:00:09.0744 0836 BrUsbSer - ok

19:00:09.0837 0836 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys

19:00:09.0838 0836 BTHMODEM - ok

19:00:09.0858 0836 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll

19:00:09.0859 0836 bthserv - ok

19:00:09.0862 0836 catchme - ok

19:00:09.0880 0836 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys

19:00:09.0881 0836 cdfs - ok

19:00:09.0907 0836 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys

19:00:09.0909 0836 cdrom - ok

19:00:09.0930 0836 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll

19:00:09.0932 0836 CertPropSvc - ok

19:00:09.0948 0836 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys

19:00:09.0949 0836 circlass - ok

19:00:09.0972 0836 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys

19:00:09.0975 0836 CLFS - ok

19:00:09.0995 0836 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

19:00:09.0996 0836 clr_optimization_v2.0.50727_32 - ok

19:00:10.0005 0836 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe

19:00:10.0007 0836 clr_optimization_v2.0.50727_64 - ok

19:00:10.0077 0836 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

19:00:10.0078 0836 clr_optimization_v4.0.30319_32 - ok

19:00:10.0111 0836 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

19:00:10.0112 0836 clr_optimization_v4.0.30319_64 - ok

19:00:10.0126 0836 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys

19:00:10.0127 0836 CmBatt - ok

19:00:10.0143 0836 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys

19:00:10.0145 0836 cmdide - ok

19:00:10.0184 0836 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys

19:00:10.0189 0836 CNG - ok

19:00:10.0206 0836 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys

19:00:10.0207 0836 Compbatt - ok

19:00:10.0241 0836 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys

19:00:10.0242 0836 CompositeBus - ok

19:00:10.0245 0836 COMSysApp - ok

19:00:10.0270 0836 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys

19:00:10.0271 0836 crcdisk - ok

19:00:10.0325 0836 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll

19:00:10.0328 0836 CryptSvc - ok

19:00:10.0368 0836 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll

19:00:10.0371 0836 DcomLaunch - ok

19:00:10.0401 0836 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll

19:00:10.0404 0836 defragsvc - ok

19:00:10.0442 0836 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys

19:00:10.0443 0836 DfsC - ok

19:00:10.0491 0836 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll

19:00:10.0495 0836 Dhcp - ok

19:00:10.0505 0836 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys

19:00:10.0506 0836 discache - ok

19:00:10.0524 0836 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys

19:00:10.0525 0836 Disk - ok

19:00:10.0567 0836 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll

19:00:10.0569 0836 Dnscache - ok

19:00:10.0616 0836 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll

19:00:10.0619 0836 dot3svc - ok

19:00:10.0630 0836 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll

19:00:10.0632 0836 DPS - ok

19:00:10.0653 0836 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys

19:00:10.0654 0836 drmkaud - ok

19:00:10.0726 0836 [ 4C639A503201E3F9FB001B840B934A3F ] DSFKSVCS C:\Windows\system32\DRIVERS\dsfksvcs.sys

19:00:10.0733 0836 DSFKSVCS - ok

19:00:10.0783 0836 [ 13699BA0680D8EEEF67945F5A405610C ] dsfroot C:\Windows\system32\DRIVERS\dsfroot.sys

19:00:10.0784 0836 dsfroot - ok

19:00:10.0830 0836 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys

19:00:10.0839 0836 DXGKrnl - ok

19:00:10.0881 0836 [ 60C5B36E07BE8B3AF3911C3D10303CFE ] e1kexpress C:\Windows\system32\DRIVERS\e1k62x64.sys

19:00:10.0884 0836 e1kexpress - ok

19:00:10.0896 0836 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll

19:00:10.0898 0836 EapHost - ok

19:00:10.0961 0836 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys

19:00:11.0014 0836 ebdrv - ok

19:00:11.0047 0836 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe

19:00:11.0048 0836 EFS - ok

19:00:11.0107 0836 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe

19:00:11.0114 0836 ehRecvr - ok

19:00:11.0138 0836 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe

19:00:11.0140 0836 ehSched - ok

19:00:11.0180 0836 [ A05FC7ECA0966EBB70E4D17B855A853B ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys

19:00:11.0181 0836 ElbyCDIO - ok

19:00:11.0197 0836 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys

19:00:11.0202 0836 elxstor - ok

19:00:11.0219 0836 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys

19:00:11.0220 0836 ErrDev - ok

19:00:11.0229 0836 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll

19:00:11.0233 0836 EventSystem - ok

19:00:11.0263 0836 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys

19:00:11.0265 0836 exfat - ok

19:00:11.0351 0836 Fabs - ok

19:00:11.0395 0836 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys

19:00:11.0397 0836 fastfat - ok

19:00:11.0454 0836 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe

19:00:11.0463 0836 Fax - ok

19:00:11.0485 0836 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys

19:00:11.0487 0836 fdc - ok

19:00:11.0500 0836 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll

19:00:11.0501 0836 fdPHost - ok

19:00:11.0516 0836 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll

19:00:11.0518 0836 FDResPub - ok

19:00:11.0528 0836 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys

19:00:11.0529 0836 FileInfo - ok

19:00:11.0543 0836 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys

19:00:11.0545 0836 Filetrace - ok

19:00:11.0624 0836 [ FFF1130F7C9FA01D093A1EDFC5CCE8FC ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe

19:00:11.0667 0836 FirebirdServerMAGIXInstance - ok

19:00:11.0723 0836 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

19:00:11.0726 0836 FLEXnet Licensing Service - ok

19:00:12.0045 0836 [ 5CEE6CD43AE5844C49300EA0B1E557EE ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

19:00:12.0325 0836 FLEXnet Licensing Service 64 - ok

19:00:12.0341 0836 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys

19:00:12.0342 0836 flpydisk - ok

19:00:12.0383 0836 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys

19:00:12.0386 0836 FltMgr - ok

19:00:12.0433 0836 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll

19:00:12.0444 0836 FontCache - ok

19:00:12.0488 0836 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

19:00:12.0490 0836 FontCache3.0.0.0 - ok

19:00:12.0507 0836 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys

19:00:12.0509 0836 FsDepends - ok

19:00:12.0537 0836 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys

19:00:12.0538 0836 Fs_Rec - ok

19:00:12.0587 0836 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys

19:00:12.0589 0836 fvevol - ok

19:00:12.0603 0836 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys

19:00:12.0604 0836 gagp30kx - ok

19:00:12.0651 0836 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll

19:00:12.0658 0836 gpsvc - ok

19:00:12.0711 0836 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

19:00:12.0711 0836 gupdate - ok

19:00:12.0715 0836 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

19:00:12.0715 0836 gupdatem - ok

19:00:12.0753 0836 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys

19:00:12.0754 0836 hamachi - ok

19:00:12.0872 0836 [ 785FD63B74B30986A9F2C7D965CA509F ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe

19:00:12.0990 0836 Hamachi2Svc - ok

19:00:13.0003 0836 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys

19:00:13.0004 0836 hcw85cir - ok

19:00:13.0062 0836 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys

19:00:13.0066 0836 HdAudAddService - ok

19:00:13.0108 0836 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys

19:00:13.0109 0836 HDAudBus - ok

19:00:13.0133 0836 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys

19:00:13.0134 0836 HECIx64 - ok

19:00:13.0148 0836 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys

19:00:13.0149 0836 HidBatt - ok

19:00:13.0164 0836 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys

19:00:13.0166 0836 HidBth - ok

19:00:13.0175 0836 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys

19:00:13.0176 0836 HidIr - ok

19:00:13.0188 0836 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll

19:00:13.0190 0836 hidserv - ok

19:00:13.0221 0836 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys

19:00:13.0222 0836 HidUsb - ok

19:00:13.0306 0836 [ 5350AEF38CA2D8885F47D4455E7EF4EE ] HiPatchService D:\Mijn Documenten\Games\HiPatchService.exe

19:00:13.0314 0836 HiPatchService - ok

19:00:13.0348 0836 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll

19:00:13.0350 0836 hkmsvc - ok

19:00:13.0379 0836 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll

19:00:13.0382 0836 HomeGroupListener - ok

19:00:13.0391 0836 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll

19:00:13.0394 0836 HomeGroupProvider - ok

19:00:13.0422 0836 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys

19:00:13.0423 0836 HpSAMD - ok

19:00:13.0431 0836 HRMACPI - ok

19:00:13.0449 0836 [ 1696A06C0EF55DFCD540B32556D3819A ] HRMCFGSPC C:\Windows\system32\DRIVERS\HRMCFGSPC.SYS

19:00:13.0451 0836 HRMCFGSPC - ok

19:00:13.0482 0836 [ F58F8F2A11CE4A695C9333C416D0321F ] HRMINTS C:\Windows\system32\DRIVERS\HRMINTS.SYS

19:00:13.0484 0836 HRMINTS - ok

19:00:13.0493 0836 [ 6BC42DC759D42A4EDCA7452B4D08D870 ] HRMPORTS C:\Windows\system32\DRIVERS\HRMPORTS.SYS

19:00:13.0495 0836 HRMPORTS - ok

19:00:13.0530 0836 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys

19:00:13.0538 0836 HTTP - ok

19:00:13.0561 0836 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys

19:00:13.0562 0836 hwpolicy - ok

19:00:13.0570 0836 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys

19:00:13.0572 0836 i8042prt - ok

19:00:13.0606 0836 [ 87A72502C8AC5E89B5A46FF6E874F5C5 ] IAMTVE C:\Windows\system32\DRIVERS\IAMTVE.sys

19:00:13.0608 0836 IAMTVE - ok

19:00:13.0620 0836 [ 5516F8E518A2F6A8755498F3E73957CF ] IAMTXPE C:\Windows\system32\DRIVERS\IAMTXPE.sys

19:00:13.0621 0836 IAMTXPE - ok

19:00:13.0647 0836 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys

19:00:13.0651 0836 iaStorV - ok

19:00:13.0689 0836 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe

19:00:13.0698 0836 idsvc - ok

19:00:13.0897 0836 [ C6238C6ABD6AC99F5D152DA4E9439A3D ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys

19:00:14.0103 0836 igfx - ok

19:00:14.0122 0836 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys

19:00:14.0124 0836 iirsp - ok

19:00:14.0147 0836 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll

19:00:14.0155 0836 IKEEXT - ok

19:00:14.0168 0836 IntcAzAudAddService - ok

19:00:14.0207 0836 [ 58CF58DEE26C909BD6F977B61D246295 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys

19:00:14.0221 0836 IntcDAud - ok

19:00:14.0239 0836 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys

19:00:14.0240 0836 intelide - ok

19:00:14.0256 0836 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys

19:00:14.0258 0836 intelppm - ok

19:00:14.0274 0836 [ E45575812630B049CE0F679D87561A4D ] ioatdma1 C:\Windows\System32\Drivers\qd162x64.sys

19:00:14.0275 0836 ioatdma1 - ok

19:00:14.0284 0836 [ 2C23820DD9E81199E60F553EB50BC449 ] ioatdma2 C:\Windows\System32\Drivers\qd262x64.sys

19:00:14.0285 0836 ioatdma2 - ok

19:00:14.0296 0836 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll

19:00:14.0298 0836 IPBusEnum - ok

19:00:14.0327 0836 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys

19:00:14.0329 0836 IpFilterDriver - ok

19:00:14.0369 0836 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll

19:00:14.0375 0836 iphlpsvc - ok

19:00:14.0408 0836 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys

19:00:14.0410 0836 IPMIDRV - ok

19:00:14.0441 0836 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys

19:00:14.0442 0836 IPNAT - ok

19:00:14.0464 0836 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys

19:00:14.0465 0836 IRENUM - ok

19:00:14.0479 0836 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys

19:00:14.0480 0836 isapnp - ok

19:00:14.0523 0836 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys

19:00:14.0526 0836 iScsiPrt - ok

19:00:14.0557 0836 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys

19:00:14.0558 0836 kbdclass - ok

19:00:14.0573 0836 [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys

19:00:14.0574 0836 kbdhid - ok

19:00:14.0580 0836 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe

19:00:14.0580 0836 KeyIso - ok

19:00:14.0616 0836 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys

19:00:14.0618 0836 KSecDD - ok

19:00:14.0643 0836 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys

19:00:14.0644 0836 KSecPkg - ok

19:00:14.0663 0836 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys

19:00:14.0664 0836 ksthunk - ok

19:00:14.0692 0836 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll

19:00:14.0696 0836 KtmRm - ok

19:00:14.0716 0836 kushbwau - ok

19:00:14.0754 0836 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll

19:00:14.0757 0836 LanmanServer - ok

19:00:14.0792 0836 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll

19:00:14.0794 0836 LanmanWorkstation - ok

19:00:14.0833 0836 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys

19:00:14.0835 0836 lltdio - ok

19:00:14.0864 0836 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll

19:00:14.0868 0836 lltdsvc - ok

19:00:14.0885 0836 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll

19:00:14.0886 0836 lmhosts - ok

19:00:14.0942 0836 [ 1D82A01A368255FE78C65CF66B5B8281 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

19:00:14.0944 0836 LMS - ok

19:00:14.0971 0836 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys

19:00:14.0973 0836 LSI_FC - ok

19:00:14.0988 0836 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys

19:00:14.0990 0836 LSI_SAS - ok

19:00:15.0020 0836 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys

19:00:15.0021 0836 LSI_SAS2 - ok

19:00:15.0044 0836 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys

19:00:15.0046 0836 LSI_SCSI - ok

19:00:15.0076 0836 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys

19:00:15.0077 0836 luafv - ok

19:00:15.0123 0836 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys

19:00:15.0123 0836 MBAMProtector - ok

19:00:15.0179 0836 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

19:00:15.0181 0836 MBAMScheduler - ok

19:00:15.0200 0836 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

19:00:15.0203 0836 MBAMService - ok

19:00:15.0236 0836 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll

19:00:15.0238 0836 Mcx2Svc - ok

19:00:15.0258 0836 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys

19:00:15.0258 0836 megasas - ok

19:00:15.0296 0836 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys

19:00:15.0298 0836 MegaSR - ok

19:00:15.0370 0836 Microsoft SharePoint Workspace Audit Service - ok

19:00:15.0383 0836 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll

19:00:15.0384 0836 MMCSS - ok

19:00:15.0404 0836 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys

19:00:15.0405 0836 Modem - ok

19:00:15.0409 0836 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys

19:00:15.0410 0836 monitor - ok

19:00:15.0418 0836 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys

19:00:15.0420 0836 mouclass - ok

19:00:15.0432 0836 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys

19:00:15.0433 0836 mouhid - ok

19:00:15.0474 0836 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys

19:00:15.0475 0836 mountmgr - ok

19:00:15.0541 0836 [ F8A10560B35C66F9DE212F03DAD5BFA7 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys

19:00:15.0544 0836 MpFilter - ok

19:00:15.0563 0836 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys

19:00:15.0566 0836 mpio - ok

19:00:15.0581 0836 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys

19:00:15.0583 0836 mpsdrv - ok

19:00:15.0614 0836 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll

19:00:15.0622 0836 MpsSvc - ok

19:00:15.0657 0836 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys

19:00:15.0659 0836 MRxDAV - ok

19:00:15.0696 0836 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys

19:00:15.0697 0836 mrxsmb - ok

19:00:15.0734 0836 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys

19:00:15.0737 0836 mrxsmb10 - ok

19:00:15.0746 0836 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys

19:00:15.0747 0836 mrxsmb20 - ok

19:00:15.0769 0836 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys

19:00:15.0770 0836 msahci - ok

19:00:15.0799 0836 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys

19:00:15.0801 0836 msdsm - ok

19:00:15.0817 0836 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe

19:00:15.0820 0836 MSDTC - ok

19:00:15.0825 0836 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys

19:00:15.0825 0836 Msfs - ok

19:00:15.0828 0836 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys

19:00:15.0829 0836 mshidkmdf - ok

19:00:15.0831 0836 MSICDSetup - ok

19:00:15.0861 0836 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys

19:00:15.0861 0836 msisadrv - ok

19:00:15.0877 0836 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll

19:00:15.0880 0836 MSiSCSI - ok

19:00:15.0882 0836 msiserver - ok

19:00:15.0902 0836 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys

19:00:15.0904 0836 MSKSSRV - ok

19:00:15.0964 0836 [ E07DEC52FF801841BA9B6878A60304FB ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe

19:00:15.0964 0836 MsMpSvc - ok

19:00:15.0975 0836 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys

19:00:15.0976 0836 MSPCLOCK - ok

19:00:15.0987 0836 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys

19:00:15.0988 0836 MSPQM - ok

19:00:16.0022 0836 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys

19:00:16.0025 0836 MsRPC - ok

19:00:16.0043 0836 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys

19:00:16.0044 0836 mssmbios - ok

19:00:16.0060 0836 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys

19:00:16.0061 0836 MSTEE - ok

19:00:16.0075 0836 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys

19:00:16.0076 0836 MTConfig - ok

19:00:16.0079 0836 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys

19:00:16.0080 0836 Mup - ok

19:00:16.0119 0836 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll

19:00:16.0124 0836 napagent - ok

19:00:16.0140 0836 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys

19:00:16.0144 0836 NativeWifiP - ok

19:00:16.0190 0836 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys

19:00:16.0198 0836 NDIS - ok

19:00:16.0214 0836 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys

19:00:16.0215 0836 NdisCap - ok

19:00:16.0224 0836 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys

19:00:16.0225 0836 NdisTapi - ok

19:00:16.0261 0836 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys

19:00:16.0262 0836 Ndisuio - ok

19:00:16.0294 0836 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys

19:00:16.0296 0836 NdisWan - ok

19:00:16.0315 0836 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys

19:00:16.0316 0836 NDProxy - ok

19:00:16.0335 0836 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys

19:00:16.0336 0836 NetBIOS - ok

19:00:16.0364 0836 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys

19:00:16.0366 0836 NetBT - ok

19:00:16.0375 0836 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe

19:00:16.0376 0836 Netlogon - ok

19:00:16.0408 0836 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll

19:00:16.0412 0836 Netman - ok

19:00:16.0449 0836 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

19:00:16.0450 0836 NetMsmqActivator - ok

19:00:16.0482 0836 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

19:00:16.0483 0836 NetPipeActivator - ok

19:00:16.0521 0836 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll

19:00:16.0526 0836 netprofm - ok

19:00:16.0579 0836 [ AAED8CDB31A88C702DA4212C2AA886F9 ] netr28ux C:\Windows\system32\DRIVERS\netr28ux.sys

19:00:16.0589 0836 netr28ux - ok

19:00:16.0593 0836 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

19:00:16.0593 0836 NetTcpActivator - ok

19:00:16.0596 0836 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

19:00:16.0597 0836 NetTcpPortSharing - ok

19:00:16.0624 0836 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys

19:00:16.0625 0836 nfrd960 - ok

19:00:16.0669 0836 [ 162100E0BC8377710F9D170631921C03 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys

19:00:16.0671 0836 NisDrv - ok

19:00:16.0702 0836 [ C6E15F2F95F9C0A6098D43510B604E52 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe

19:00:16.0704 0836 NisSrv - ok

19:00:16.0751 0836 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll

19:00:16.0755 0836 NlaSvc - ok

19:00:16.0767 0836 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys

19:00:16.0768 0836 Npfs - ok

19:00:16.0791 0836 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll

19:00:16.0793 0836 nsi - ok

19:00:16.0796 0836 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys

19:00:16.0797 0836 nsiproxy - ok

19:00:16.0857 0836 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys

19:00:16.0872 0836 Ntfs - ok

19:00:16.0885 0836 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys

19:00:16.0886 0836 Null - ok

19:00:16.0943 0836 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys

19:00:16.0945 0836 NVHDA - ok

19:00:17.0188 0836 [ FE2909F7DFB12B9A20AD207FE23B7E96 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys

19:00:17.0492 0836 nvlddmkm - ok

19:00:17.0533 0836 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys

19:00:17.0535 0836 nvraid - ok

19:00:17.0559 0836 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys

19:00:17.0561 0836 nvstor - ok

19:00:17.0630 0836 [ 3341D2C91989BC87C3C0BAA97C27253B ] nvsvc C:\Windows\system32\nvvsvc.exe

19:00:17.0639 0836 nvsvc - ok

19:00:17.0670 0836 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys

19:00:17.0672 0836 nv_agp - ok

19:00:17.0713 0836 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys

19:00:17.0715 0836 ohci1394 - ok

19:00:17.0754 0836 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE

19:00:17.0755 0836 ose - ok

19:00:17.0886 0836 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

19:00:17.0905 0836 osppsvc - ok

19:00:17.0955 0836 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll

19:00:17.0959 0836 p2pimsvc - ok

19:00:17.0974 0836 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll

19:00:17.0980 0836 p2psvc - ok

19:00:18.0004 0836 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys

19:00:18.0006 0836 Parport - ok

19:00:18.0044 0836 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys

19:00:18.0045 0836 partmgr - ok

19:00:18.0053 0836 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll

19:00:18.0056 0836 PcaSvc - ok

19:00:18.0066 0836 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys

19:00:18.0068 0836 pci - ok

19:00:18.0077 0836 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys

19:00:18.0077 0836 pciide - ok

19:00:18.0103 0836 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys

19:00:18.0105 0836 pcmcia - ok

19:00:18.0120 0836 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys

19:00:18.0121 0836 pcw - ok

19:00:18.0140 0836 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys

19:00:18.0146 0836 PEAUTH - ok

19:00:18.0217 0836 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe

19:00:18.0219 0836 PerfHost - ok

19:00:18.0272 0836 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll

19:00:18.0285 0836 pla - ok

19:00:18.0337 0836 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll

19:00:18.0342 0836 PlugPlay - ok

19:00:18.0371 0836 PnkBstrA - ok

19:00:18.0381 0836 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll

19:00:18.0382 0836 PNRPAutoReg - ok

19:00:18.0389 0836 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll

19:00:18.0390 0836 PNRPsvc - ok

19:00:18.0435 0836 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll

19:00:18.0440 0836 PolicyAgent - ok

19:00:18.0456 0836 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll

19:00:18.0459 0836 Power - ok

19:00:18.0498 0836 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys

19:00:18.0500 0836 PptpMiniport - ok

19:00:18.0517 0836 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys

19:00:18.0518 0836 Processor - ok

19:00:18.0556 0836 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll

19:00:18.0559 0836 ProfSvc - ok

19:00:18.0562 0836 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe

19:00:18.0563 0836 ProtectedStorage - ok

19:00:18.0603 0836 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys

19:00:18.0605 0836 Psched - ok

19:00:18.0639 0836 [ A6BF0A9B5A30D743623CA0D3BE35DF05 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys

19:00:18.0640 0836 PxHlpa64 - ok

19:00:18.0687 0836 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys

19:00:18.0701 0836 ql2300 - ok

19:00:18.0712 0836 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys

19:00:18.0714 0836 ql40xx - ok

19:00:18.0732 0836 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll

19:00:18.0735 0836 QWAVE - ok

19:00:18.0750 0836 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys

19:00:18.0752 0836 QWAVEdrv - ok

19:00:18.0806 0836 [ 583608EE65AABF971117A61AEE4BCAAE ] RalinkRegistryWriter C:\Program Files (x86)\Conceptronic\Common\RaRegistry.exe

19:00:18.0844 0836 RalinkRegistryWriter - ok

19:00:18.0860 0836 [ 2DD4830AB9543BD9067380A7E8E99258 ] RalinkRegistryWriter64 C:\Program Files (x86)\Conceptronic\Common\RaRegistry64.exe

19:00:18.0899 0836 RalinkRegistryWriter64 - ok

19:00:18.0909 0836 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys

19:00:18.0910 0836 RasAcd - ok

19:00:18.0936 0836 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys

19:00:18.0938 0836 RasAgileVpn - ok

19:00:18.0947 0836 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll

19:00:18.0949 0836 RasAuto - ok

19:00:18.0980 0836 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys

19:00:18.0982 0836 Rasl2tp - ok

19:00:19.0025 0836 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll

19:00:19.0029 0836 RasMan - ok

19:00:19.0039 0836 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys

19:00:19.0040 0836 RasPppoe - ok

19:00:19.0047 0836 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys

19:00:19.0049 0836 RasSstp - ok

19:00:19.0071 0836 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys

19:00:19.0074 0836 rdbss - ok

19:00:19.0088 0836 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys

19:00:19.0089 0836 rdpbus - ok

19:00:19.0097 0836 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys

19:00:19.0098 0836 RDPCDD - ok

19:00:19.0125 0836 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys

19:00:19.0126 0836 RDPENCDD - ok

19:00:19.0137 0836 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys

19:00:19.0138 0836 RDPREFMP - ok

19:00:19.0182 0836 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys

19:00:19.0183 0836 RdpVideoMiniport - ok

19:00:19.0219 0836 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys

19:00:19.0221 0836 RDPWD - ok

19:00:19.0239 0836 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys

19:00:19.0241 0836 rdyboost - ok

19:00:19.0271 0836 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll

19:00:19.0273 0836 RemoteAccess - ok

19:00:19.0277 0836 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll

19:00:19.0279 0836 RemoteRegistry - ok

19:00:19.0288 0836 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll

19:00:19.0290 0836 RpcEptMapper - ok

19:00:19.0314 0836 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe

19:00:19.0315 0836 RpcLocator - ok

19:00:19.0355 0836 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll

19:00:19.0358 0836 RpcSs - ok

19:00:19.0376 0836 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys

19:00:19.0377 0836 rspndr - ok

19:00:19.0380 0836 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe

19:00:19.0381 0836 SamSs - ok

19:00:19.0409 0836 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys

19:00:19.0410 0836 sbp2port - ok

19:00:19.0428 0836 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll

19:00:19.0431 0836 SCardSvr - ok

19:00:19.0463 0836 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys

19:00:19.0464 0836 scfilter - ok

19:00:19.0520 0836 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll

19:00:19.0531 0836 Schedule - ok

19:00:19.0570 0836 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll

19:00:19.0572 0836 SCPolicySvc - ok

19:00:19.0609 0836 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll

19:00:19.0611 0836 SDRSVC - ok

19:00:19.0653 0836 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys

19:00:19.0654 0836 secdrv - ok

19:00:19.0683 0836 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll

19:00:19.0685 0836 seclogon - ok

19:00:19.0699 0836 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll

19:00:19.0700 0836 SENS - ok

19:00:19.0716 0836 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll

19:00:19.0718 0836 SensrSvc - ok

19:00:19.0742 0836 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys

19:00:19.0743 0836 Serenum - ok

19:00:19.0759 0836 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys

19:00:19.0761 0836 Serial - ok

19:00:19.0797 0836 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys

19:00:19.0798 0836 sermouse - ok

19:00:19.0826 0836 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll

19:00:19.0829 0836 SessionEnv - ok

19:00:19.0851 0836 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys

19:00:19.0852 0836 sffdisk - ok

19:00:19.0864 0836 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys

19:00:19.0864 0836 sffp_mmc - ok

19:00:19.0881 0836 [ 178298F767FE638C9FEDCBDEF58BB5E4 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys

19:00:19.0882 0836 sffp_sd - ok

19:00:19.0895 0836 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys

19:00:19.0896 0836 sfloppy - ok

19:00:19.0954 0836 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll

19:00:19.0958 0836 SharedAccess - ok

19:00:20.0004 0836 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll

19:00:20.0008 0836 ShellHWDetection - ok

19:00:20.0034 0836 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys

19:00:20.0035 0836 SiSRaid2 - ok

19:00:20.0052 0836 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys

19:00:20.0054 0836 SiSRaid4 - ok

19:00:20.0114 0836 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe

19:00:20.0115 0836 SkypeUpdate - ok

19:00:20.0132 0836 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys

19:00:20.0134 0836 Smb - ok

19:00:20.0152 0836 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe

19:00:20.0154 0836 SNMPTRAP - ok

19:00:20.0192 0836 [ 5DA8039E58B3A557C6A744E476CDEB7F ] softehci C:\Windows\system32\DRIVERS\softehci.sys

19:00:20.0195 0836 softehci - ok

19:00:20.0222 0836 [ 26D2B0FF718219809C0BC3A8B061C6EC ] SOFTHIDUSBK C:\Windows\system32\DRIVERS\SOFTHIDUSBK.SYS

19:00:20.0225 0836 SOFTHIDUSBK - ok

19:00:20.0247 0836 [ E1702BBE8D31B6EDD5C6881C80F123A8 ] SOFTUSBK C:\Windows\system32\DRIVERS\SOFTUSBK.SYS

19:00:20.0254 0836 SOFTUSBK - ok

19:00:20.0256 0836 SOFTUSBTESTHUB - ok

19:00:20.0259 0836 SOFTWADP - ok

19:00:20.0277 0836 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys

19:00:20.0277 0836 spldr - ok

19:00:20.0324 0836 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe

19:00:20.0330 0836 Spooler - ok

19:00:20.0394 0836 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe

19:00:20.0566 0836 sppsvc - ok

19:00:20.0587 0836 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll

19:00:20.0589 0836 sppuinotify - ok

19:00:20.0654 0836 [ D519AD2DE7968CD2B47FEA807C5B29B2 ] sptd C:\Windows\System32\Drivers\sptd.sys

19:00:20.0655 0836 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: D519AD2DE7968CD2B47FEA807C5B29B2

19:00:20.0656 0836 sptd ( LockedFile.Multi.Generic ) - warning

19:00:20.0656 0836 sptd - detected LockedFile.Multi.Generic (1)

19:00:20.0695 0836 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys

19:00:20.0699 0836 srv - ok

19:00:20.0740 0836 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys

19:00:20.0744 0836 srv2 - ok

19:00:20.0759 0836 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys

19:00:20.0761 0836 srvnet - ok

19:00:20.0795 0836 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll

19:00:20.0797 0836 SSDPSRV - ok

19:00:20.0806 0836 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll

19:00:20.0808 0836 SstpSvc - ok

19:00:20.0870 0836 Steam Client Service - ok

19:00:20.0958 0836 [ 0632004181860960CF6E10DE8DDEF78B ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

19:00:20.0959 0836 Stereo Service - ok

19:00:20.0974 0836 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys

19:00:20.0975 0836 stexstor - ok

19:00:21.0018 0836 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll

19:00:21.0024 0836 stisvc - ok

19:00:21.0055 0836 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys

19:00:21.0056 0836 swenum - ok

19:00:21.0128 0836 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

19:00:21.0130 0836 SwitchBoard - ok

19:00:21.0152 0836 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll

19:00:21.0157 0836 swprv - ok

19:00:21.0221 0836 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll

19:00:21.0237 0836 SysMain - ok

19:00:21.0279 0836 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll

19:00:21.0281 0836 TabletInputService - ok

19:00:21.0337 0836 [ B08740047145B9BCE15BF75CA0F9718A ] tap0901t C:\Windows\system32\DRIVERS\tap0901t.sys

19:00:21.0339 0836 tap0901t - ok

19:00:21.0374 0836 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll

19:00:21.0378 0836 TapiSrv - ok

19:00:21.0395 0836 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll

19:00:21.0396 0836 TBS - ok

19:00:21.0460 0836 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys

19:00:21.0486 0836 Tcpip - ok

19:00:21.0517 0836 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys

19:00:21.0524 0836 TCPIP6 - ok

19:00:21.0559 0836 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys

19:00:21.0560 0836 tcpipreg - ok

19:00:21.0574 0836 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys

19:00:21.0575 0836 TDPIPE - ok

19:00:21.0610 0836 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys

19:00:21.0611 0836 TDTCP - ok

19:00:21.0651 0836 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys

19:00:21.0652 0836 tdx - ok

19:00:21.0664 0836 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys

19:00:21.0668 0836 TermDD - ok

19:00:21.0700 0836 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll

19:00:21.0707 0836 TermService - ok

19:00:21.0714 0836 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll

19:00:21.0715 0836 Themes - ok

19:00:21.0734 0836 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll

19:00:21.0735 0836 THREADORDER - ok

19:00:21.0764 0836 [ 199C2E87D9A5EC58D0BCD94E893BF629 ] TIEHDUSB C:\Windows\system32\DRIVERS\tiehdusb.sys

19:00:21.0766 0836 TIEHDUSB - ok

19:00:21.0788 0836 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll

19:00:21.0790 0836 TrkWks - ok

19:00:21.0845 0836 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe

19:00:21.0846 0836 TrustedInstaller - ok

19:00:21.0880 0836 [ 2670B4F69E530C9DE602488CA8C55AD3 ] trustms C:\Windows\system32\drivers\trustms.sys

19:00:21.0880 0836 trustms - ok

19:00:21.0910 0836 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys

19:00:21.0911 0836 tssecsrv - ok

19:00:21.0941 0836 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys

19:00:21.0942 0836 TsUsbFlt - ok

19:00:21.0979 0836 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys

19:00:21.0981 0836 tunnel - ok

19:00:22.0079 0836 [ 2FD0FE0A0C721C8E47C5A3AE16E519B1 ] TunngleService C:\Program Files (x86)\Tunngle\TnglCtrl.exe

19:00:22.0389 0836 TunngleService - ok

19:00:22.0405 0836 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys

19:00:22.0406 0836 uagp35 - ok

19:00:22.0445 0836 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys

19:00:22.0448 0836 udfs - ok

19:00:22.0470 0836 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe

19:00:22.0472 0836 UI0Detect - ok

19:00:22.0500 0836 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys

19:00:22.0526 0836 uliagpkx - ok

19:00:22.0624 0836 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys

19:00:22.0672 0836 umbus - ok

19:00:22.0736 0836 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys

19:00:22.0737 0836 UmPass - ok

19:00:22.0863 0836 [ C6142B8CB72558D91CEA8E38F1B7D905 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

19:00:22.0872 0836 UNS - ok

19:00:22.0896 0836 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll

19:00:22.0900 0836 upnphost - ok

19:00:22.0931 0836 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys

19:00:22.0932 0836 usbaudio - ok

19:00:22.0966 0836 [ B26AFB54A534D634523C4FB66765B026 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys

19:00:22.0968 0836 usbccgp - ok

19:00:23.0003 0836 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys

19:00:23.0005 0836 usbcir - ok

19:00:23.0042 0836 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys

19:00:23.0043 0836 usbehci - ok

19:00:23.0077 0836 [ DC2B97B8865042FC17C82381AC426D1C ] usbehci_dsf C:\Windows\system32\DRIVERS\usbehci_dsf.sys

19:00:23.0078 0836 usbehci_dsf - ok

19:00:23.0100 0836 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys

19:00:23.0103 0836 usbhub - ok

19:00:23.0132 0836 [ 957EC5620FB055E9DF2250D6FA4188E1 ] USBMULCD C:\Windows\system32\drivers\CM10664.sys

19:00:23.0143 0836 USBMULCD - ok

19:00:23.0158 0836 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys

19:00:23.0159 0836 usbohci - ok

19:00:23.0174 0836 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys

19:00:23.0175 0836 usbprint - ok

19:00:23.0189 0836 [ 080D3820DA6C046BE82FC8B45A893E83 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS

19:00:23.0190 0836 USBSTOR - ok

19:00:23.0202 0836 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys

19:00:23.0203 0836 usbuhci - ok

19:00:23.0220 0836 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll

19:00:23.0222 0836 UxSms - ok

19:00:23.0227 0836 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe

19:00:23.0228 0836 VaultSvc - ok

19:00:23.0260 0836 [ FD911873C0BB6945FA38C16E9A2B58F9 ] VClone C:\Windows\system32\DRIVERS\VClone.sys

19:00:23.0261 0836 VClone - ok

19:00:23.0272 0836 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys

19:00:23.0273 0836 vdrvroot - ok

19:00:23.0319 0836 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe

19:00:23.0325 0836 vds - ok

19:00:23.0335 0836 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys

19:00:23.0336 0836 vga - ok

19:00:23.0346 0836 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys

19:00:23.0348 0836 VgaSave - ok

19:00:23.0388 0836 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys

19:00:23.0391 0836 vhdmp - ok

19:00:23.0422 0836 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys

19:00:23.0423 0836 viaide - ok

19:00:23.0437 0836 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys

19:00:23.0438 0836 volmgr - ok

19:00:23.0477 0836 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys

19:00:23.0481 0836 volmgrx - ok

19:00:23.0498 0836 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys

19:00:23.0501 0836 volsnap - ok

19:00:23.0525 0836 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys

19:00:23.0527 0836 vsmraid - ok

19:00:23.0569 0836 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe

19:00:23.0584 0836 VSS - ok

19:00:23.0587 0836 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys

19:00:23.0588 0836 vwifibus - ok

19:00:23.0596 0836 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys

19:00:23.0598 0836 vwififlt - ok

19:00:23.0609 0836 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys

19:00:23.0610 0836 vwifimp - ok

19:00:23.0634 0836 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll

19:00:23.0639 0836 W32Time - ok

19:00:23.0670 0836 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys

19:00:23.0671 0836 WacomPen - ok

19:00:23.0690 0836 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys

19:00:23.0692 0836 WANARP - ok

19:00:23.0694 0836 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys

19:00:23.0695 0836 Wanarpv6 - ok

19:00:23.0751 0836 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe

19:00:23.0762 0836 WatAdminSvc - ok

19:00:23.0811 0836 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe

19:00:23.0825 0836 wbengine - ok

19:00:23.0850 0836 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll

19:00:23.0853 0836 WbioSrvc - ok

19:00:23.0888 0836 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll

19:00:23.0892 0836 wcncsvc - ok

19:00:23.0910 0836 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll

19:00:23.0912 0836 WcsPlugInService - ok

19:00:23.0926 0836 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys

19:00:23.0927 0836 Wd - ok

19:00:23.0966 0836 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys

19:00:23.0973 0836 Wdf01000 - ok

19:00:23.0988 0836 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll

19:00:23.0990 0836 WdiServiceHost - ok

19:00:23.0993 0836 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll

19:00:23.0994 0836 WdiSystemHost - ok

19:00:24.0035 0836 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll

19:00:24.0039 0836 WebClient - ok

19:00:24.0049 0836 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll

19:00:24.0052 0836 Wecsvc - ok

19:00:24.0061 0836 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll

19:00:24.0063 0836 wercplsupport - ok

19:00:24.0080 0836 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll

19:00:24.0083 0836 WerSvc - ok

19:00:24.0093 0836 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys

19:00:24.0095 0836 WfpLwf - ok

19:00:24.0109 0836 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys

19:00:24.0110 0836 WIMMount - ok

19:00:24.0129 0836 WinDefend - ok

19:00:24.0133 0836 WinHttpAutoProxySvc - ok

19:00:24.0177 0836 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll

19:00:24.0180 0836 Winmgmt - ok

19:00:24.0280 0836 [ 0C0195C48B6B8582FA6F6373032118DA ] WinRing0_1_2_0 D:\Mijn Documenten\Games\razer\Driver\WinRing0x64.sys

19:00:24.0286 0836 WinRing0_1_2_0 - ok

19:00:24.0353 0836 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll

19:00:24.0393 0836 WinRM - ok

19:00:24.0456 0836 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys

19:00:24.0457 0836 WinUsb - ok

19:00:24.0500 0836 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll

19:00:24.0509 0836 Wlansvc - ok

19:00:24.0643 0836 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

19:00:24.0651 0836 wlidsvc - ok

19:00:24.0686 0836 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys

19:00:24.0687 0836 WmiAcpi - ok

19:00:24.0701 0836 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe

19:00:24.0703 0836 wmiApSrv - ok

19:00:24.0719 0836 WMPNetworkSvc - ok

19:00:24.0733 0836 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll

19:00:24.0735 0836 WPCSvc - ok

19:00:24.0744 0836 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll

19:00:24.0747 0836 WPDBusEnum - ok

19:00:24.0757 0836 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys

19:00:24.0758 0836 ws2ifsl - ok

19:00:24.0774 0836 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll

19:00:24.0776 0836 wscsvc - ok

19:00:24.0779 0836 WSearch - ok

19:00:24.0783 0836 WSOFTUSBK - ok

19:00:24.0855 0836 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll

19:00:24.0896 0836 wuauserv - ok

19:00:24.0960 0836 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys

19:00:24.0962 0836 WudfPf - ok

19:00:25.0000 0836 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys

19:00:25.0003 0836 WUDFRd - ok

19:00:25.0038 0836 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll

19:00:25.0041 0836 wudfsvc - ok

19:00:25.0054 0836 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll

19:00:25.0058 0836 WwanSvc - ok

19:00:25.0079 0836 ================ Scan global ===============================

19:00:25.0104 0836 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll

19:00:25.0145 0836 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll

19:00:25.0152 0836 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll

19:00:25.0176 0836 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll

19:00:25.0207 0836 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe

19:00:25.0211 0836 [Global] - ok

19:00:25.0211 0836 ================ Scan MBR ==================================

19:00:25.0226 0836 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0

19:00:25.0408 0836 \Device\Harddisk0\DR0 - ok

19:00:25.0409 0836 ================ Scan VBR ==================================

19:00:25.0410 0836 [ 4F9AC5CE8D645E675C1C6F7BBEF76DD4 ] \Device\Harddisk0\DR0\Partition1

19:00:25.0411 0836 \Device\Harddisk0\DR0\Partition1 - ok

19:00:25.0418 0836 [ 3F7A94CDC2AEE962F1A2CEA312A8DF3D ] \Device\Harddisk0\DR0\Partition2

19:00:25.0420 0836 \Device\Harddisk0\DR0\Partition2 - ok

19:00:25.0434 0836 [ A9A8B190499952794693EB1D6F6E2DC7 ] \Device\Harddisk0\DR0\Partition3

19:00:25.0436 0836 \Device\Harddisk0\DR0\Partition3 - ok

19:00:25.0436 0836 ============================================================

19:00:25.0436 0836 Scan finished

19:00:25.0436 0836 ============================================================

19:00:25.0442 4684 Detected object count: 1

19:00:25.0442 4684 Actual detected object count: 1

19:00:47.0740 4684 sptd ( LockedFile.Multi.Generic ) - skipped by user

19:00:47.0740 4684 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

securitycheck

Results of screen317's Security Check version 0.99.57

Windows 7 Service Pack 1 x64 (UAC is enabled)

Internet Explorer 9

``````````````Antivirus/Firewall Check:``````````````

Microsoft Security Essentials

Antivirus up to date!

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware versie 1.70.0.1100

Java 7 Update 13

Java version out of Date!

Adobe Flash Player 11.5.502.149

Adobe Reader 10.1.5 Adobe Reader out of Date!

Google Chrome 24.0.1312.57

````````Process Check: objlist.exe by Laurent````````

Microsoft Security Essentials MSMpEng.exe

Microsoft Security Essentials msseces.exe

Malwarebytes Anti-Malware mbamservice.exe

Malwarebytes Anti-Malware mbamgui.exe

Malwarebytes' Anti-Malware mbamscheduler.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 2%

````````````````````End of Log``````````````````````

Link to post
Share on other sites

Your system has an old version (also insecure) of Adobe Reader. You need to uninstall Adobe Reader.

Consider getting a alternate tool like Sumatra PDF as mentioned by Corrine on her Security Garden blog.

http://securitygarden.blogspot.com/

You need to Uninstall J2SE Runtime Environment 5.0 Update 1

And if you do not need Java for the programs that you use, keep Java off your system .

How to disable Java in various browsers : http://blog.eset.com/2012/08/29/disabling-java-a-safer-way-to-browse

Also see No, Seriously, Just Disable Java in Your Browser Right Now

The result of Tdsskiller scan is good. I do not see something "amiss" in your DDS log.

I think we can likely proceed to cleanup of tools (I will guide you) tomorrow.

In the meantime, let me know how the system is now, in general?

And also let me know, tomorrow, if the IP website blocks are "no more"

Link to post
Share on other sites

Very well, then.

We can wrap this up now. I see that you are clear of your original issues.

If you have a problem with these steps, or something does not quite work here, do let me know.

The following few steps will remove tools we used. Advise me after you have completed the cleanups.

We have to remove Combofix and all its associated folders. By whichever name you named it, ( you had named it ComboFix icon_exclaim.gif),

put that name in the RUN box stated just below.

The "/uninstall" in the Run line below is to start Combofix for it's cleanup & removal function.

Note the space before the slash mark.

The utility must be removed to prevent any un-intentional or accidental usage, PLUS, to free up much space on your hard disk.

  • Highlight the line in this CODEBOX.
    Select & Copy the entire line within this codebox (so that it is in Windows clipboard memory)
    c:\users\McDos\Desktop\ComboFix.exe /uninstall


  • Start >> type in cmd >> press the Ctrl+Shift+Enter keyboard combination and cmd.exe will be launched as if you selected Run as Administrator. You will then see a User Account Control prompt asking if you would like to allow the Command Prompt to be able to make changes on your computer. Click on the Yes button and you will now be at the Elevated Command Prompt.
    Do a Right click within the command prompt window and select Paste. This must show the line from Codebox above.
    Then tap Enter

IF in the case Combofix un-install has an issue, skip that step.

NEXT

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

ERUNT you should keep and use periodically to backup Windows registry.

Delete the following if still present:

Jrt.exe

roguekiller.exe

RKILL

Dr Web Cure-It

Tdsskiller.exe

securitycheck.exe

You may use Control Panel >> Programs and Features and uninstall BitDefender Quickscan.

Safer practices & malware prevention

We are finished here. Best regards. cool.gif

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.