trojaans paard PSW.Agent.Armv & Generic9.Rdx & Ucx

  • blaauw RRC

    beste startpagina forumleden,

    mijn schoonouders hebben een pc met bovenstaand virus.

    heb al verschillende dingen geprobeerd echter zonder succes. hopelijk kunnen jullie ons helpen.

    hieronder het HIJACK this log file;

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 12:12:52, on 18-12-2011

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.17106)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe

    C:\Program Files\AVG\AVG10\avgtray.exe

    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe

    C:\Program Files\Pure Networks\Network Magic\nmapp.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    C:\Program Files\Casema SnelHelp\bin\mpbtn.exe

    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    C:\Program Files\AVG\AVG10\avgwdsvc.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

    C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe

    C:\Program Files\AVG\AVG10\avgnsx.exe

    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe

    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\PROGRA~1\AVG\AVG10\avgrsx.exe

    C:\Program Files\AVG\AVG10\avgcsrvx.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

    C:\Program Files\AVG\AVG10\avgui.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://klant.casema.nl/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nu.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll

    O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll

    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll

    O4 - HKLM\..\Run: C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: “C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe”

    O4 - HKLM\..\Run: C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe”

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot

    O4 - HKLM\..\Run: “C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\CASEMA~1\SMARTB~1\MotiveSB.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

    O4 - HKLM\..\Run: C:\Program Files\AVG\AVG10\avgtray.exe

    O4 - HKLM\..\Run: %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Pure Networks\Network Magic\nmapp.exe” -autorun -nosplash

    O4 - HKLM\..\Run: “C:\Program Files\AVG Secure Search\vprot.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Global Startup: Casema SnelHelp.lnk = C:\Program Files\Casema SnelHelp\bin\matcli.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

    O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

    O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

    O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    O23 - Service: WD File Management Engine (WDFME) - Unknown owner - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe

    O23 - Service: WD File Management Shadow Engine (WDSC) - Unknown owner - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe

    End of file - 10148 bytes

    gr.

    Patrick

  • Ben

    Hallo Patrick,

    Zou je het voledige stappenplan Link willen uitvoeren.

    En dan de 2 gevraagde logjes willen plaatsen dan kunnen we je verder helpen.

    Suc6 Ben

  • blaauw RRC

    Hoi Ben,

    Sorry het mallware bestand hieronder. deze had ik al uitgevoerd…

    Malwarebytes' Anti-Malware 1.51.2.1300

    www.malwarebytes.org

    Databaseversie: 8384

    Windows 5.1.2600 Service Pack 3

    Internet Explorer 7.0.5730.11

    18-12-2011 11:14:53

    mbam-log-2011-12-18 (11-14-52).txt

    Scantype: Volledige scan (C:\|E:\|)

    Objecten gescand: 253729

    Verstreken tijd: 1 uur/uren, 42 minuut/minuten, 57 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 0

    Registerwaarden geïnfecteerd: 0

    Registerdata geïnfecteerd: 2

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 2

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Mappen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden geïnfecteerd:

    c:\documents and settings\fam. kwakkernaat\local settings\temporary internet files\Content.IE5\ODBM11Z0\flvplayersetup.exe (Adware.Agent) -> Quarantined and deleted successfully.

    e:\flvplayersetup.exe (Adware.Agent) -> Quarantined and deleted successfully.

  • Ben

    Hallo Patrick,8-)

    1. Start HijackThis en kies voor “Do a systemscan only”.

    Vink vervolgens (indien nog aanwezig) enkel deze onderstaande regels aan:

    R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    Sluit vervolgens alle vensters, behalve HijackThis. Klik daarna op “Fix checked”.

    Wanneer je een vraag krijgt of je het zeker weet, bevestig deze dan met “Ja”.

    2. Download TDSSKiller en sla het op je Bureaublad op.

    • Pak de bestanden in tdsskiller.zip uit.

    • Open de map tdsskiller en dubbelklik op TDSSKiller.exe om de tool te starten

    Als TDSSKiller bericht geeft van een beschikbare update, dan voer je deze eerst uit.

    • Een nieuwe versie van TDSSkiller zal nu gedownload worden en sla deze op je Bureaublad op.

    • Start TDSSkiller opnieuw.

    • Klik op "Change parameters" en zorg dat de onderstaande opties allemaal aangevinkt zijn.

    • Klik op de knop "Start Scan" en volg de instructies.

    • Wanneer de scan klaar is klik je op de knop "Report".

    • Er opent een kladblokbestand. Post de inhoud van dit bestand.

    Herstart de pc als TDSSKiller die optie geeft. (Reboot now)

    Wanneer er een herstart nodig was, vind je de logfile in C:\TDSSKiller.___log.txt

    Plaats hierna het TDSS samen met een nieuw HijackThis logje en vertel erbij hoe het met je probleem is.

    Suc6 Ben.

  • fazantje

    Hoi Patrick,

    Nadat je Ben's programma hebt uigevoerd, doe dan gelijk het volgende:

    Download combofix Hier.

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner,

    schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    Dubbelklik op Combofix.exe

    Volg de instructies, aanvaard de disclaimer.

    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    Het kan enige tijd duren voordat het logje van combofix komt, dus denk niet van hij is op tilt.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze combo log in je volgende post samen met een nieuw HijackThis logje en het logje TDSS.

    Succes,

    Huib;)

  • Piet

    >>C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe << stenentijd perk

    Als u schoon bent graag alle updates binnen halen van al uw programma's ook van office indien aanwezig.

  • blaauw RRC

    Ja daar ben ik weer !

    het lijkt alsof de pc sneller reageerd !

    hieronder de gevraagde logs

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 20:31:40, on 19-12-2011

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.17106)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe

    C:\PROGRA~1\CASEMA~1\SMARTB~1\MotiveSB.exe

    C:\Program Files\AVG\AVG10\avgtray.exe

    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe

    C:\Program Files\Pure Networks\Network Magic\nmapp.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    C:\Program Files\Casema SnelHelp\bin\mpbtn.exe

    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    C:\Program Files\AVG\AVG10\avgwdsvc.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

    C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe

    C:\Program Files\AVG\AVG10\avgnsx.exe

    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe

    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\eHome\ehmsas.exe

    C:\PROGRA~1\AVG\AVG10\avgrsx.exe

    C:\Program Files\AVG\AVG10\avgcsrvx.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://klant.casema.nl/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nu.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll

    O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll

    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll

    O4 - HKLM\..\Run: C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: “C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe”

    O4 - HKLM\..\Run: C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”

    O4 - HKLM\..\Run: “C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe”

    O4 - HKLM\..\Run: SOUNDMAN.EXE

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot

    O4 - HKLM\..\Run: “C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\CASEMA~1\SMARTB~1\MotiveSB.exe

    O4 - HKLM\..\Run: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

    O4 - HKLM\..\Run: C:\Program Files\AVG\AVG10\avgtray.exe

    O4 - HKLM\..\Run: %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Pure Networks\Network Magic\nmapp.exe” -autorun -nosplash

    O4 - HKLM\..\Run: “C:\Program Files\AVG Secure Search\vprot.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKUS\S-1-5-19\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Lokale service’)

    O4 - HKUS\S-1-5-20\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Netwerkservice’)

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Global Startup: Casema SnelHelp.lnk = C:\Program Files\Casema SnelHelp\bin\matcli.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll

    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

    O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

    O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe

    O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    O23 - Service: WD File Management Engine (WDFME) - Unknown owner - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe

    O23 - Service: WD File Management Shadow Engine (WDSC) - Unknown owner - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe

    End of file - 9898 bytes

    en de TDSS

    20:10:19.0187 1492 TDSS rootkit removing tool 2.6.23.0 Dec 13 2011 10:39:31

    20:10:19.0453 1492 ============================================================

    20:10:19.0453 1492 Current date / time: 2011/12/19 20:10:19.0453

    20:10:19.0453 1492 SystemInfo:

    20:10:19.0453 1492

    20:10:19.0453 1492 OS Version: 5.1.2600 ServicePack: 3.0

    20:10:19.0453 1492 Product type: Workstation

    20:10:19.0453 1492 ComputerName: KWAKKERNAAT

    20:10:19.0453 1492 UserName: Fam. Kwakkernaat

    20:10:19.0453 1492 Windows directory: C:\WINDOWS

    20:10:19.0453 1492 System windows directory: C:\WINDOWS

    20:10:19.0453 1492 Processor architecture: Intel x86

    20:10:19.0453 1492 Number of processors: 2

    20:10:19.0453 1492 Page size: 0x1000

    20:10:19.0453 1492 Boot type: Normal boot

    20:10:19.0453 1492 ============================================================

    20:10:21.0578 1492 Initialize success

    20:10:30.0515 1700 ============================================================

    20:10:30.0515 1700 Scan started

    20:10:30.0515 1700 Mode: Manual; SigCheck; TDLFS;

    20:10:30.0515 1700 ============================================================

    20:10:31.0203 1700 1h8i.sys - ok

    20:10:31.0234 1700 Abiosdsk - ok

    20:10:31.0250 1700 abp480n5 - ok

    20:10:31.0328 1700 ACPI (02273a448ba21a7d447daeb47810d40c) C:\WINDOWS\system32\DRIVERS\ACPI.sys

    20:12:40.0578 1700 ACPI - ok

    20:12:40.0828 1700 ACPIEC (63f517b1a87dabf3f5acb8a7952fc1d1) C:\WINDOWS\system32\drivers\ACPIEC.sys

    20:12:41.0515 1700 ACPIEC - ok

    20:12:41.0687 1700 adpu160m - ok

    20:12:41.0875 1700 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

    20:12:42.0921 1700 aec - ok

    20:12:43.0296 1700 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\WINDOWS\system32\drivers\Afc.sys

    20:12:43.0421 1700 Afc - ok

    20:12:43.0625 1700 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys

    20:12:43.0796 1700 AFD - ok

    20:12:44.0000 1700 Aha154x - ok

    20:12:44.0046 1700 aic78u2 - ok

    20:12:44.0203 1700 aic78xx - ok

    20:12:44.0687 1700 ALCXWDM (a8407775e1b64057418781481b202930) C:\WINDOWS\system32\drivers\ALCXWDM.SYS

    20:12:46.0062 1700 ALCXWDM - ok

    20:12:46.0265 1700 AliIde - ok

    20:12:46.0359 1700 amsint - ok

    20:12:46.0625 1700 APL531 (1fc8a7e5c3aed31f00940c6ab2fd9b49) C:\WINDOWS\system32\Drivers\ov550i.sys

    20:12:46.0812 1700 APL531 ( UnsignedFile.Multi.Generic ) - warning

    20:12:46.0812 1700 APL531 - detected UnsignedFile.Multi.Generic (1)

    20:12:46.0921 1700 asc - ok

    20:12:46.0953 1700 asc3350p - ok

    20:12:46.0968 1700 asc3550 - ok

    20:12:47.0015 1700 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys

    20:12:47.0031 1700 ASCTRM ( UnsignedFile.Multi.Generic ) - warning

    20:12:47.0031 1700 ASCTRM - detected UnsignedFile.Multi.Generic (1)

    20:12:47.0109 1700 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

    20:12:47.0265 1700 AsyncMac - ok

    20:12:47.0328 1700 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

    20:12:47.0484 1700 atapi - ok

    20:12:47.0765 1700 Atdisk - ok

    20:12:47.0843 1700 ati2mtag (9cf018b4d7a31f7ae0bd386d491e6dbf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys

    20:12:47.0953 1700 ati2mtag - ok

    20:12:48.0031 1700 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

    20:12:48.0218 1700 Atmarpc - ok

    20:12:48.0718 1700 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

    20:12:48.0937 1700 audstub - ok

    20:12:49.0031 1700 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys

    20:12:49.0046 1700 AVGIDSDriver - ok

    20:12:49.0109 1700 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys

    20:12:49.0140 1700 AVGIDSEH - ok

    20:12:49.0203 1700 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys

    20:12:49.0234 1700 AVGIDSFilter - ok

    20:12:49.0312 1700 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys

    20:12:49.0328 1700 AVGIDSShim - ok

    20:12:49.0359 1700 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys

    20:12:49.0515 1700 Avgldx86 - ok

    20:12:49.0562 1700 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys

    20:12:49.0578 1700 Avgmfx86 - ok

    20:12:49.0625 1700 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys

    20:12:49.0656 1700 Avgrkx86 - ok

    20:12:49.0687 1700 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys

    20:12:49.0765 1700 Avgtdix - ok

    20:12:49.0843 1700 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

    20:12:50.0062 1700 Beep - ok

    20:12:50.0250 1700 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

    20:12:50.0515 1700 cbidf2k - ok

    20:12:50.0578 1700 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

    20:12:50.0765 1700 CCDECODE - ok

    20:12:50.0859 1700 cd20xrnt - ok

    20:12:50.0921 1700 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

    20:12:51.0093 1700 Cdaudio - ok

    20:12:51.0234 1700 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

    20:12:51.0406 1700 Cdfs - ok

    20:12:51.0453 1700 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

    20:12:51.0625 1700 Cdrom - ok

    20:12:51.0703 1700 Changer - ok

    20:12:51.0750 1700 CmdIde - ok

    20:12:51.0781 1700 Cpqarray - ok

    20:12:51.0859 1700 dac2w2k - ok

    20:12:51.0875 1700 dac960nt - ok

    20:12:51.0953 1700 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

    20:12:52.0109 1700 Disk - ok

    20:12:52.0203 1700 dmboot (dec123e0c75971d0cc7a6c6a75e28429) C:\WINDOWS\system32\drivers\dmboot.sys

    20:12:52.0406 1700 dmboot - ok

    20:12:52.0781 1700 dmio (7268e66259722f6228c730685b201092) C:\WINDOWS\system32\drivers\dmio.sys

    20:12:52.0953 1700 dmio - ok

    20:12:53.0000 1700 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

    20:12:53.0156 1700 dmload - ok

    20:12:53.0296 1700 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

    20:12:53.0468 1700 DMusic - ok

    20:12:53.0515 1700 dpti2o - ok

    20:12:53.0578 1700 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

    20:12:53.0750 1700 drmkaud - ok

    20:12:53.0828 1700 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

    20:12:54.0000 1700 Fastfat - ok

    20:12:54.0140 1700 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys

    20:12:54.0312 1700 Fdc - ok

    20:12:54.0421 1700 Fips (8bfffb5ac954e19dfdb96d56512aa518) C:\WINDOWS\system32\drivers\Fips.sys

    20:12:54.0609 1700 Fips - ok

    20:12:54.0656 1700 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

    20:12:54.0875 1700 Flpydisk - ok

    20:12:54.0968 1700 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys

    20:12:55.0140 1700 FltMgr - ok

    20:12:55.0250 1700 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

    20:12:55.0421 1700 Fs_Rec - ok

    20:12:55.0500 1700 Ftdisk (fa8ca22e70245c81ff29c36af56292fc) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

    20:12:55.0671 1700 Ftdisk - ok

    20:12:55.0781 1700 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

    20:12:55.0953 1700 Gpc - ok

    20:12:56.0015 1700 hpn - ok

    20:12:56.0093 1700 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

    20:12:56.0140 1700 HTTP - ok

    20:12:56.0234 1700 i2omgmt - ok

    20:12:56.0250 1700 i2omp - ok

    20:12:56.0343 1700 i8042prt (c43372d0682f8e32e4ec21117e089ec0) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

    20:12:56.0515 1700 i8042prt - ok

    20:12:56.0656 1700 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

    20:12:56.0812 1700 Imapi - ok

    20:12:56.0859 1700 ini910u - ok

    20:12:56.0953 1700 IntelIde (72c63ad984d427d34bd5b9db838d88eb) C:\WINDOWS\system32\DRIVERS\intelide.sys

    20:12:57.0093 1700 IntelIde - ok

    20:12:57.0234 1700 intelppm (2d2254fac267e6b1c7865e8ebef60c6d) C:\WINDOWS\system32\DRIVERS\intelppm.sys

    20:12:57.0406 1700 intelppm - ok

    20:12:57.0453 1700 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys

    20:12:57.0625 1700 Ip6Fw - ok

    20:12:57.0687 1700 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

    20:12:57.0859 1700 IpFilterDriver - ok

    20:12:57.0953 1700 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

    20:12:58.0125 1700 IpInIp - ok

    20:12:58.0218 1700 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

    20:12:58.0375 1700 IpNat - ok

    20:12:58.0468 1700 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

    20:12:58.0625 1700 IPSec - ok

    20:12:58.0765 1700 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

    20:12:58.0937 1700 IRENUM - ok

    20:12:59.0015 1700 isapnp (0b78e1a31340e1fb1e389d5633f7c3a0) C:\WINDOWS\system32\DRIVERS\isapnp.sys

    20:12:59.0171 1700 isapnp - ok

    20:12:59.0296 1700 Kbdclass (380397621e94b32c744e7b2cc1330390) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

    20:12:59.0484 1700 Kbdclass - ok

    20:12:59.0531 1700 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

    20:12:59.0718 1700 kmixer - ok

    20:12:59.0828 1700 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

    20:12:59.0921 1700 KSecDD - ok

    20:12:59.0953 1700 Lavasoft Kernexplorer - ok

    20:13:00.0062 1700 lbrtfdc - ok

    20:13:00.0093 1700 MBAMSwissArmy - ok

    20:13:00.0140 1700 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys

    20:13:00.0171 1700 MHNDRV ( UnsignedFile.Multi.Generic ) - warning

    20:13:00.0171 1700 MHNDRV - detected UnsignedFile.Multi.Generic (1)

    20:13:00.0218 1700 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

    20:13:00.0406 1700 mnmdd - ok

    20:13:00.0546 1700 Modem (8114eeac353f549331ab73e9af4219ed) C:\WINDOWS\system32\drivers\Modem.sys

    20:13:00.0718 1700 Modem - ok

    20:13:00.0859 1700 Mouclass (1a4e2214dd63e4a876463d3427ee8261) C:\WINDOWS\system32\DRIVERS\mouclass.sys

    20:13:01.0046 1700 Mouclass - ok

    20:13:01.0093 1700 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

    20:13:01.0234 1700 MountMgr - ok

    20:13:01.0281 1700 mraid35x - ok

    20:13:01.0343 1700 MRENDIS5 - ok

    20:13:01.0406 1700 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

    20:13:01.0562 1700 MRxDAV - ok

    20:13:01.0656 1700 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

    20:13:01.0765 1700 MRxSmb - ok

    20:13:01.0921 1700 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

    20:13:02.0078 1700 Msfs - ok

    20:13:02.0140 1700 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

    20:13:02.0312 1700 MSKSSRV - ok

    20:13:02.0437 1700 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

    20:13:02.0609 1700 MSPCLOCK - ok

    20:13:02.0656 1700 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

    20:13:02.0828 1700 MSPQM - ok

    20:13:02.0906 1700 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

    20:13:03.0046 1700 mssmbios - ok

    20:13:03.0187 1700 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys

    20:13:03.0359 1700 MSTEE - ok

    20:13:03.0500 1700 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys

    20:13:03.0562 1700 Mup - ok

    20:13:03.0625 1700 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

    20:13:03.0796 1700 NABTSFEC - ok

    20:13:03.0875 1700 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

    20:13:04.0031 1700 NDIS - ok

    20:13:04.0171 1700 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

    20:13:04.0328 1700 NdisIP - ok

    20:13:04.0406 1700 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

    20:13:04.0437 1700 NdisTapi - ok

    20:13:04.0500 1700 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

    20:13:04.0656 1700 Ndisuio - ok

    20:13:04.0703 1700 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

    20:13:04.0875 1700 NdisWan - ok

    20:13:05.0000 1700 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys

    20:13:05.0046 1700 NDProxy - ok

    20:13:05.0171 1700 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

    20:13:05.0328 1700 NetBIOS - ok

    20:13:05.0421 1700 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

    20:13:05.0593 1700 NetBT - ok

    20:13:05.0750 1700 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

    20:13:05.0906 1700 Npfs - ok

    20:13:05.0984 1700 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

    20:13:06.0171 1700 Ntfs - ok

    20:13:06.0265 1700 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

    20:13:06.0421 1700 Null - ok

    20:13:06.0484 1700 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

    20:13:06.0656 1700 NwlnkFlt - ok

    20:13:06.0734 1700 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

    20:13:07.0031 1700 NwlnkFwd - ok

    20:13:07.0156 1700 Parport (e3934ccc20a4d24f1924e13d36d2a5bd) C:\WINDOWS\system32\drivers\Parport.sys

    20:13:07.0343 1700 Parport - ok

    20:13:07.0562 1700 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

    20:13:07.0875 1700 PartMgr - ok

    20:13:07.0968 1700 ParVdm (1eade28746a64c21e0a808bb12a63326) C:\WINDOWS\system32\drivers\ParVdm.sys

    20:13:08.0406 1700 ParVdm - ok

    20:13:08.0546 1700 PCI (3b166f9f753c21aedaa9a6bd76b49655) C:\WINDOWS\system32\DRIVERS\pci.sys

    20:13:08.0703 1700 PCI - ok

    20:13:08.0875 1700 PCIDump - ok

    20:13:08.0953 1700 PCIIde (b31edeba4da28283f6b8dc4756fb9585) C:\WINDOWS\system32\DRIVERS\pciide.sys

    20:13:09.0125 1700 PCIIde - ok

    20:13:09.0203 1700 Pcmcia (2137ffd65f8e609a3a5acd487c56cce0) C:\WINDOWS\system32\drivers\Pcmcia.sys

    20:13:09.0390 1700 Pcmcia - ok

    20:13:09.0437 1700 PDCOMP - ok

    20:13:09.0484 1700 PDFRAME - ok

    20:13:09.0500 1700 PDRELI - ok

    20:13:09.0546 1700 PDRFRAME - ok

    20:13:09.0609 1700 perc2 - ok

    20:13:09.0671 1700 perc2hib - ok

    20:13:09.0796 1700 pnarp (ce27fc8bdc54b3ac63d53e2d5f6cc929) C:\WINDOWS\system32\DRIVERS\pnarp.sys

    20:13:09.0812 1700 pnarp - ok

    20:13:09.0875 1700 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

    20:13:10.0046 1700 PptpMiniport - ok

    20:13:10.0187 1700 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

    20:13:10.0359 1700 PSched - ok

    20:13:10.0640 1700 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

    20:13:10.0828 1700 Ptilink - ok

    20:13:10.0937 1700 purendis (f4fd591e86ecb6b5d000c7d6c987416b) C:\WINDOWS\system32\DRIVERS\purendis.sys

    20:13:10.0953 1700 purendis - ok

    20:13:10.0968 1700 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys

    20:13:11.0000 1700 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning

    20:13:11.0000 1700 PxHelp20 - detected UnsignedFile.Multi.Generic (1)

    20:13:11.0015 1700 ql1080 - ok

    20:13:11.0031 1700 Ql10wnt - ok

    20:13:11.0078 1700 ql12160 - ok

    20:13:11.0109 1700 ql1240 - ok

    20:13:11.0140 1700 ql1280 - ok

    20:13:11.0187 1700 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

    20:13:11.0359 1700 RasAcd - ok

    20:13:11.0468 1700 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

    20:13:11.0640 1700 Rasl2tp - ok

    20:13:11.0718 1700 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

    20:13:11.0890 1700 RasPppoe - ok

    20:13:11.0937 1700 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

    20:13:12.0140 1700 Raspti - ok

    20:13:12.0328 1700 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

    20:13:12.0578 1700 Rdbss - ok

    20:13:12.0640 1700 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

    20:13:12.0812 1700 RDPCDD - ok

    20:13:12.0906 1700 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

    20:13:13.0062 1700 rdpdr - ok

    20:13:13.0187 1700 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys

    20:13:13.0250 1700 RDPWD - ok

    20:13:13.0343 1700 redbook (4173bc66e485fd77a03c4819f60bd0da) C:\WINDOWS\system32\DRIVERS\redbook.sys

    20:13:13.0500 1700 redbook - ok

    20:13:13.0562 1700 RTL8023xp (8e34400ffc7d647946d9c820678775af) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys

    20:13:13.0640 1700 RTL8023xp - ok

    20:13:13.0765 1700 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS

    20:13:13.0875 1700 rtl8139 - ok

    20:13:13.0953 1700 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

    20:13:14.0109 1700 Secdrv - ok

    20:13:14.0218 1700 Serial (92c21762653bb2ce51147eb8a9aa654f) C:\WINDOWS\system32\drivers\Serial.sys

    20:13:14.0375 1700 Serial - ok

    20:13:14.0484 1700 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys

    20:13:14.0656 1700 Sfloppy - ok

    20:13:14.0750 1700 Simbad - ok

    20:13:14.0812 1700 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys

    20:13:14.0984 1700 SLIP - ok

    20:13:15.0093 1700 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS

    20:13:15.0281 1700 SONYPVU1 - ok

    20:13:15.0375 1700 Sparrow - ok

    20:13:15.0437 1700 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

    20:13:15.0593 1700 splitter - ok

    20:13:15.0640 1700 sr (64d2a7640e0767ecd3bcb38d3200e7ce) C:\WINDOWS\system32\DRIVERS\sr.sys

    20:13:15.0781 1700 sr - ok

    20:13:15.0906 1700 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys

    20:13:15.0984 1700 Srv - ok

    20:13:16.0062 1700 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

    20:13:16.0234 1700 streamip - ok

    20:13:16.0359 1700 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

    20:13:16.0531 1700 swenum - ok

    20:13:16.0578 1700 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

    20:13:16.0734 1700 swmidi - ok

    20:13:16.0781 1700 symc810 - ok

    20:13:16.0812 1700 symc8xx - ok

    20:13:16.0828 1700 sym_hi - ok

    20:13:16.0875 1700 sym_u3 - ok

    20:13:16.0953 1700 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

    20:13:17.0125 1700 sysaudio - ok

    20:13:17.0203 1700 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

    20:13:17.0312 1700 Tcpip - ok

    20:13:17.0453 1700 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

    20:13:17.0625 1700 TDPIPE - ok

    20:13:17.0671 1700 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

    20:13:17.0812 1700 TDTCP - ok

    20:13:17.0875 1700 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

    20:13:18.0046 1700 TermDD - ok

    20:13:18.0109 1700 TosIde - ok

    20:13:18.0171 1700 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

    20:13:18.0343 1700 Udfs - ok

    20:13:18.0375 1700 ultra - ok

    20:13:18.0453 1700 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

    20:13:18.0656 1700 Update - ok

    20:13:18.0796 1700 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

    20:13:18.0968 1700 usbccgp - ok

    20:13:19.0015 1700 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

    20:13:19.0171 1700 usbehci - ok

    20:13:19.0234 1700 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

    20:13:19.0390 1700 usbhub - ok

    20:13:19.0531 1700 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys

    20:13:19.0687 1700 usbohci - ok

    20:13:19.0796 1700 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

    20:13:19.0968 1700 usbprint - ok

    20:13:20.0046 1700 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

    20:13:20.0218 1700 usbscan - ok

    20:13:20.0296 1700 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    20:13:20.0453 1700 usbstor - ok

    20:13:20.0531 1700 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

    20:13:20.0703 1700 VgaSave - ok

    20:13:20.0750 1700 ViaIde - ok

    20:13:20.0812 1700 VolSnap (8ab662b3c4691e6ddf61c96bb5b7d103) C:\WINDOWS\system32\drivers\VolSnap.sys

    20:13:20.0968 1700 VolSnap - ok

    20:13:21.0109 1700 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

    20:13:21.0265 1700 Wanarp - ok

    20:13:21.0375 1700 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\WINDOWS\system32\DRIVERS\wdcsam.sys

    20:13:21.0437 1700 WDC_SAM - ok

    20:13:21.0484 1700 WDICA - ok

    20:13:21.0546 1700 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

    20:13:21.0718 1700 wdmaud - ok

    20:13:21.0890 1700 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

    20:13:22.0062 1700 WSTCODEC - ok

    20:13:22.0187 1700 xcpip - ok

    20:13:22.0218 1700 xpsec - ok

    20:13:22.0250 1700 MBR (0x1B8) (1ff334014dd81828afea0206675f92ba) \Device\Harddisk0\DR0

    20:13:22.0390 1700 \Device\Harddisk0\DR0 - ok

    20:13:22.0406 1700 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk5\DR7

    20:13:22.0906 1700 \Device\Harddisk5\DR7 - ok

    20:13:22.0906 1700 Boot (0x1200) (1cfb8d5e0bb717d4259dadfa937a39c8) \Device\Harddisk0\DR0\Partition0

    20:13:22.0906 1700 \Device\Harddisk0\DR0\Partition0 - ok

    20:13:22.0921 1700 Boot (0x1200) (e164ab8671c941be3d308aa6e0e547d4) \Device\Harddisk5\DR7\Partition0

    20:13:22.0921 1700 \Device\Harddisk5\DR7\Partition0 - ok

    20:13:22.0921 1700 ============================================================

    20:13:22.0921 1700 Scan finished

    20:13:22.0921 1700 ============================================================

    20:13:23.0031 1296 Detected object count: 4

    20:13:23.0031 1296 Actual detected object count: 4

    20:14:07.0984 1296 HKLM\SYSTEM\ControlSet001\services\APL531 - will be deleted on reboot

    20:14:07.0984 1296 HKLM\SYSTEM\ControlSet002\services\APL531 - will be deleted on reboot

    20:14:07.0984 1296 C:\WINDOWS\system32\Drivers\ov550i.sys - will be deleted on reboot

    20:14:07.0984 1296 APL531 ( UnsignedFile.Multi.Generic ) - User select action: Delete

    20:14:07.0984 1296 HKLM\SYSTEM\ControlSet001\services\ASCTRM - will be deleted on reboot

    20:14:07.0984 1296 HKLM\SYSTEM\ControlSet002\services\ASCTRM - will be deleted on reboot

    20:14:07.0984 1296 C:\WINDOWS\system32\drivers\ASCTRM.sys - will be deleted on reboot

    20:14:07.0984 1296 ASCTRM ( UnsignedFile.Multi.Generic ) - User select action: Delete

    20:14:08.0000 1296 HKLM\SYSTEM\ControlSet001\services\MHNDRV - will be deleted on reboot

    20:14:08.0000 1296 HKLM\SYSTEM\ControlSet002\services\MHNDRV - will be deleted on reboot

    20:14:08.0000 1296 C:\WINDOWS\system32\DRIVERS\mhndrv.sys - will be deleted on reboot

    20:14:08.0000 1296 MHNDRV ( UnsignedFile.Multi.Generic ) - User select action: Delete

    20:14:08.0000 1296 HKLM\SYSTEM\ControlSet001\services\PxHelp20 - will be deleted on reboot

    20:14:08.0000 1296 HKLM\SYSTEM\ControlSet002\services\PxHelp20 - will be deleted on reboot

    20:14:08.0015 1296 C:\WINDOWS\system32\Drivers\PxHelp20.sys - will be deleted on reboot

    20:14:08.0015 1296 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Delete

  • fazantje

    Hoi Patrick,

    Dit logje ziet er goed uit, maar voer wel even dat uit wat ik je ook nog schreef:

    http://antivirus.startpagina.nl/prikbord/14928466/14929535/re-trojaans-paard-pswagentarmv-&-generic9rdx-&-ucx#msg-14929535

    Succes,

    Huib;)

  • blaauw RRC

    Hoi Fazant,

    dat is een snelle reactie ! Top gewoon zeg !

    ik zag inderdaad je eerdere reactie. ik heb nu combofix lopen maar duurt dit zo lang ?

    ik zag een scherm waarin enige gegevens voorbij kwamen van unpacking etc.

    dit is nu al enige tijd weg maar de pc start niet opnieuw op ofzo laat staan een log.

    of moet ik meer geduld hebben ?

    gr.

    Patrick

  • Ben

    Hallo Patrick,

    Het kan enige tijd duren voordat het logje van combofix komt, dus denk niet van hij is op tilt.

    Dus heb geduld.

    Ben