Hallo
Mijn partner heeft last van een gijzelvirus
Kreeg een melding dat hij 100 euro moest betalen omdat hij op een kindeporno site of een politiek onjuiste site zou zitten
sindsdien kregen we een bericht dat de IAStorcoIcon zou ontbreken.
Hebben de aanwijzingen gevolgd onder een eerdere melding van 6 juli.
Konden ook geen vasja vinden.
Zijn wel de andere stappen doorgelopen.
hebben inmiddels geen last meer van de melding over het ontbrekende bestand maar zijn er niet gerust op dat alles nu in orde is.
Bijgaand de logjes.
Emsisoft Emergency Kit - Versie 2.0
Laatste Update: 19-7-2012 19:40:50
Scaninstellingen:
Scantype: Diepe scan
Objecten: Rootkits, Geheugen, Sporen, C:\, D:\
Scan archieven: Aan
ADS Scan: Aan
Scan gestart: 19-7-2012 19:41:33
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Original Downloads\Garmin KeyGen v1.2.rar -> Garmin KeyGen v1.2\KeyGen v1.2.exe Ontdekt: Backdoor.Win32.Poison!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Original Downloads\GarminKeygen_v1.3+ IMEI Converter v1.0.rar -> GarminKeygen_v1.3+ IMEI Converter v1.0\keygen.exe Ontdekt: not-a-virus.Hacktool.Keygen.garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Garmin Keygen v1.5\garmin_kgen.exe Ontdekt: Riskware.Keygen.Garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin Topo France v2\Support\Garmin Keygen v1.5.rar -> Garmin Keygen v1.5\garmin_kgen.exe Ontdekt: not-a-virus.Keygen.Garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin Topo Belgium-Luxembourg\Garmin Keygen 1.5\garmin_kgen.exe Ontdekt: Riskware.Keygen.Garmin!E2
C:\Users\Frans\AppData\Local\Mozilla\Firefox\Profiles\3ejk19s3.default\Cache\E\ED\06359d01 Ontdekt: Exploit.PDF!E2
C:\Users\Frans\AppData\Local\Mozilla\Firefox\Profiles\3ejk19s3.default\Cache\C\2C\6ECBEd01 -> unnamed Ontdekt: Exploit.JS.Blacole!E2
C:\$Recycle.Bin\S-1-5-21-795546400-1110544162-4112724898-1000\$R27UVBN.exe Ontdekt: Riskware.WebToolbar.Win32.InstallCore.AMN!E1
Gescand 719904
Gevonden 8
Scan geëindigd: 19-7-2012 22:06:44
Scantijd: 2:25:11
C:\$Recycle.Bin\S-1-5-21-795546400-1110544162-4112724898-1000\$R27UVBN.exe Verwijderd Riskware.WebToolbar.Win32.InstallCore.AMN!E1
C:\Users\Frans\AppData\Local\Mozilla\Firefox\Profiles\3ejk19s3.default\Cache\C\2C\6ECBEd01 -> unnamed Verwijderd Exploit.JS.Blacole!E2
C:\Users\Frans\AppData\Local\Mozilla\Firefox\Profiles\3ejk19s3.default\Cache\E\ED\06359d01 Verwijderd Exploit.PDF!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin Topo France v2\Support\Garmin Keygen v1.5.rar -> Garmin Keygen v1.5\garmin_kgen.exe Verwijderd not-a-virus.Keygen.Garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Garmin Keygen v1.5\garmin_kgen.exe Verwijderd Riskware.Keygen.Garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin Topo Belgium-Luxembourg\Garmin Keygen 1.5\garmin_kgen.exe Verwijderd Riskware.Keygen.Garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Original Downloads\GarminKeygen_v1.3+ IMEI Converter v1.0.rar -> GarminKeygen_v1.3+ IMEI Converter v1.0\keygen.exe Verwijderd not-a-virus.Hacktool.Keygen.garmin!E2
C:\Users\Frans\Documents\Mijn Garmin\Garmin unlock\Garmin Unlock Utility\Original Downloads\Garmin KeyGen v1.2.rar -> Garmin KeyGen v1.2\KeyGen v1.2.exe Verwijderd Backdoor.Win32.Poison!E2
Verwijderd 8
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Frans at 22:20:02 on 2012-07-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.6071.3870
.
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Sitecom\Common\RaUI.exe
C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
K:\EmsisoftEmergencyKit\start.exe
K:\EmsisoftEmergencyKit\Run\a2emergencykit.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun: %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun: C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: “C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe”
mRun: “C:\Program Files (x86)\AVG\AVG2012\avgtray.exe”
mRun: “C:\Program Files (x86)\AVG Secure Search\vprot.exe”
mRun: C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun:
mRun: “C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe” /DoAction
mRun: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
StartupFolder: C:\Users\Frans\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SITECO~1.LNK - C:\Program Files (x86)\Sitecom\Common\RaUI.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SPYDER~1.LNK - C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7E5407AD-9D9A-472E-A51F-CFCC0E81EA9F} : DhcpNameServer = 192.168.0.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{95B7759C-8C7F-4BF1-B163-73684A933233}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{95B7759C-8C7F-4BF1-B163-73684A933233}
mRun-x64: c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun-x64: %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun-x64: C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun-x64: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: “C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe”
mRun-x64: “C:\Program Files (x86)\AVG\AVG2012\avgtray.exe”
mRun-x64: “C:\Program Files (x86)\AVG Secure Search\vprot.exe”
mRun-x64: C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64:
mRun-x64: “C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe” /DoAction
mRun-x64: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun-x64: “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun-x64: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
IE-X64: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
SEH-X64: {E54729E8-BB3D-4270-9D49-7389EA579090}: EasyBits Security Shield Hook - prevents launching insecure programs by kids
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\3ejk19s3.default\
FF - prefs.js: browser.startup.homepage - hxxp://nl.startkabel.nl
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B0e3e7f70-f89d-4210-9a31-40a41bc678f5%7D&mid=c9ba9867ff0c47d186259128c0647fc5-149c76dc139fda7aa54551bedf1b1dbe86d36a1f&ds=AVG&v=11.1.0.12&lang=nl&pr=fr&d=2012-06-08%2008%3A09%3A50&sap=ku&q=
FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\3ejk19s3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys
R1 A2DDA;A2 Direct Disk Access Support Driver;K:\EmsisoftEmergencyKit\Run\a2ddax64.sys
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\Sitecom\Common\RegistryWriter.exe
R2 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
R2 Sentinel64;Sentinel64;C:\Windows\system32\Drivers\Sentinel64.sys –> C:\Windows\system32\Drivers\Sentinel64.sys
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys –> C:\Windows\system32\DRIVERS\netr28x.sys
R3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys
R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;C:\Windows\system32\DRIVERS\SNTUSB64.SYS –> C:\Windows\system32\DRIVERS\SNTUSB64.SYS
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
S2 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
S2 SessionLauncher;SessionLauncher;C:\Users\Frans\AppData\Local\Temp\DX9\SessionLauncher.exe –> C:\Users\Frans\AppData\Local\Temp\DX9\SessionLauncher.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 gupdatem;Google Update-service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
S3 Spyder3;Datacolor Spyder3;C:\Windows\system32\DRIVERS\Spyder3.sys –> C:\Windows\system32\DRIVERS\Spyder3.sys
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe
.
=============== Created Last 30 ================
.
2012-07-18 19:02:58 ——– d—–w- C:\Program Files (x86)\Oracle
2012-07-18 19:02:12 687544 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-07-18 19:02:10 772544 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-07-16 01:40:41 ——– d—–w- C:\Windows\System32\SPReview
2012-07-16 01:38:42 ——– d—–w- C:\Windows\System32\EventProviders
2012-07-15 09:15:07 53248 —-a-r- C:\Users\Frans\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-07-15 09:15:04 ——– d—–w- C:\Users\Frans\AppData\Local\Logishrd
2012-07-15 09:12:23 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys
2012-07-15 08:51:25 ——– d—–w- C:\Users\Frans\AppData\Roaming\Logishrd
2012-07-14 22:20:09 ——– d—–w- C:\Users\Frans\AppData\Local\Macromedia
2012-07-14 22:19:42 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-14 22:19:42 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-14 13:46:04 48976 —-a-w- C:\Windows\System32\netfxperf.dll
2012-07-14 13:46:04 1942856 —-a-w- C:\Windows\System32\dfshim.dll
2012-07-14 13:44:59 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2012-07-14 13:43:59 94720 —-a-w- C:\Windows\System32\cabinet.dll
2012-07-14 13:41:14 529408 —-a-w- C:\Windows\System32\wbemcomn.dll
2012-07-14 13:41:14 244736 —-a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2012-07-14 13:41:10 244736 —-a-w- C:\Windows\System32\sqmapi.dll
2012-07-14 10:21:10 ——– d—–w- C:\Users\Frans\AppData\Local\Apps
2012-07-14 07:40:49 ——– d—–w- C:\Program Files (x86)\Nikon
2012-07-14 07:40:48 ——– d—–w- C:\Program Files (x86)\Common Files\Nikon
2012-07-14 05:20:27 ——– d—–w- C:\Program Files (x86)\MSXML 4.0
2012-07-14 04:50:15 ——– d—–w- C:\Users\Frans\AppData\Local\CyberLink
2012-07-14 04:50:14 ——– d—–w- C:\Users\Frans\AppData\Local\PowerCinema
2012-07-14 04:42:49 ——– d—–w- C:\Windows\SysWow64\wbem\en-US
2012-07-14 04:42:43 ——– d—–w- C:\Windows\System32\wbem\en-US
2012-07-14 04:29:54 ——– d—–w- C:\Windows\SysWow64\Wat
2012-07-14 04:29:54 ——– d—–w- C:\Windows\System32\Wat
2012-07-13 18:58:37 3148800 —-a-w- C:\Windows\System32\win32k.sys
2012-07-13 17:55:01 294912 —-a-w- C:\Windows\System32\browserchoice.exe
2012-07-13 17:38:20 81408 —-a-w- C:\Windows\System32\imagehlp.dll
2012-07-13 17:38:20 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-07-13 17:38:20 5120 —-a-w- C:\Windows\System32\wmi.dll
2012-07-13 17:38:20 23408 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-07-13 17:38:20 220672 —-a-w- C:\Windows\System32\wintrust.dll
2012-07-13 17:38:20 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-07-13 17:38:20 159232 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-07-13 16:39:31 ——– d—–w- C:\Program Files (x86)\WinGDB3
2012-07-13 16:35:37 ——– d—–w- C:\Users\Frans\AppData\Local\Google
2012-07-13 16:28:59 ——– d—–w- C:\Program Files (x86)\Canon
2012-07-13 16:26:35 ——– d—–w- C:\Program Files (x86)\Common Files\Canon
2012-07-13 16:22:45 90112 —-a-w- C:\Windows\unvise32.exe
2012-07-13 16:22:14 ——– d—–w- C:\Program Files (x86)\Datacolor
2012-07-13 15:40:42 ——– d—–w- C:\Program Files (x86)\MozBackup
2012-07-13 14:56:59 ——– d—–w- C:\Users\Frans\AppData\Local\Garmin
2012-07-13 14:56:47 ——– d—–w- C:\ProgramData\Garmin
2012-07-13 14:56:23 ——– d—–w- C:\Users\Frans\AppData\Local\GARMIN_Corp
2012-07-13 14:45:29 ——– d—–w- C:\Program Files (x86)\Garmin
2012-07-13 14:45:24 ——– d—–w- C:\Users\Frans\AppData\Roaming\Garmin
2012-07-13 06:27:53 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll
2012-07-13 06:26:52 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
2012-07-13 06:24:50 77312 —-a-w- C:\Windows\System32\packager.dll
2012-07-13 06:24:50 67072 —-a-w- C:\Windows\SysWow64\packager.dll
2012-07-13 04:42:56 ——– d—–w- C:\ProgramData\Recovery
2012-07-12 21:56:31 ——– d—–w- C:\ProgramData\HP Photo Creations
2012-07-12 21:56:31 ——– d—–w- C:\Program Files (x86)\HP Photo Creations
2012-07-12 21:56:11 778088 ——w- C:\Windows\System32\HPDiscoPMA511.dll
2012-07-12 21:56:11 ——– d—–w- C:\Users\Frans\AppData\Roaming\HpUpdate
2012-07-12 21:55:26 ——– d—–w- C:\Program Files\HP
2012-07-12 21:55:02 ——– d—–w- C:\Users\Frans\AppData\Local\HP
2012-07-12 21:34:08 145448 —-a-w- C:\Windows\System32\drivers\sentinel64.sys
2012-07-12 21:34:04 ——– d—–w- C:\Program Files (x86)\Common Files\SafeNet Sentinel
2012-07-12 21:27:36 ——– d—–w- C:\Users\Frans\AppData\Local\AV Stumpfl
2012-07-12 21:27:34 ——– d—–w- C:\Users\Frans\AppData\Roaming\AV Stumpfl
2012-07-12 21:27:34 ——– d—–w- C:\Program Files (x86)\AV Stumpfl
2012-07-12 21:12:34 ——– d—–w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-12 21:09:10 ——– d—–w- C:\Users\Frans\AppData\Local\Mozilla
2012-07-12 21:05:09 ——– d—–w- C:\Users\Frans\AppData\Roaming\AVG2012
2012-07-12 21:04:38 ——– d—–w- C:\Users\Frans\AppData\Local\AVG Secure Search
2012-07-12 21:04:35 ——– d—–w- C:\ProgramData\AVG Secure Search
2012-07-12 21:04:35 ——– d—–w- C:\Program Files (x86)\Common Files\AVG Secure Search
2012-07-12 21:04:35 ——– d—–w- C:\Program Files (x86)\AVG Secure Search
2012-07-12 21:04:23 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2012-07-12 21:04:19 ——– d–h–w- C:\$AVG
2012-07-12 21:04:19 ——– d—–w- C:\Windows\System32\drivers\AVG
2012-07-12 21:04:19 ——– d—–w- C:\ProgramData\AVG2012
2012-07-12 21:03:49 ——– d—–w- C:\Program Files (x86)\AVG
2012-07-12 21:02:12 ——– d–h–w- C:\ProgramData\Common Files
2012-07-12 21:02:12 ——– d—–w- C:\ProgramData\MFAData
2012-07-12 20:58:34 53488 ——w- C:\Windows\System32\drivers\PxHlpa64.sys
2012-07-12 20:57:16 ——– d—–w- C:\Program Files (x86)\Common Files\Sonic Shared
2012-07-12 20:57:16 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine
2012-07-12 20:57:06 ——– d—–w- C:\Users\Frans\AppData\Local\Programs
2012-07-12 20:57:05 ——– d—–w- C:\Program Files (x86)\Roxio
2012-07-12 20:56:14 506728 —-a-w- C:\Windows\System32\d3dx10_33.dll
2012-07-12 20:56:14 4494184 —-a-w- C:\Windows\System32\d3dx9_33.dll
2012-07-12 20:56:14 443752 —-a-w- C:\Windows\SysWow64\d3dx10_33.dll
2012-07-12 20:56:14 3495784 —-a-w- C:\Windows\SysWow64\d3dx9_33.dll
2012-07-12 20:56:14 1400176 —-a-w- C:\Windows\System32\D3DCompiler_33.dll
2012-07-12 20:56:14 1123696 —-a-w- C:\Windows\SysWow64\D3DCompiler_33.dll
2012-07-12 20:55:25 ——– d—–w- C:\Windows\SysWow64\URTTEMP
2012-07-12 20:49:46 ——– d—–w- C:\Windows\PCHEALTH
2012-07-12 20:48:33 ——– d—–w- C:\Users\Frans\AppData\Local\Microsoft Help
2012-07-12 20:42:11 ——– d—–w- C:\Users\Frans\AppData\Local\Adobe
2012-07-12 20:20:27 ——– d—–w- C:\Program Files (x86)\Bonjour
2012-07-12 20:18:33 ——– d—–w- C:\Windows\SysWow64\spool
2012-07-12 20:16:44 ——– d—–w- C:\Program Files (x86)\Common Files\Macrovision Shared
2012-07-12 20:10:36 9013136 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5BEB332A-FA05-42FE-8B0F-53508BA62DA5}\mpengine.dll
2012-07-12 20:10:35 279656 ——w- C:\Windows\System32\MpSigStub.exe
2012-07-12 20:09:30 826880 —-a-w- C:\Windows\SysWow64\rdpcore.dll
2012-07-12 20:09:30 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-07-12 20:09:30 1031680 —-a-w- C:\Windows\System32\rdpcore.dll
2012-07-12 20:07:15 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-07-12 20:07:01 99840 —-a-w- C:\Windows\System32\wudriver.dll
2012-07-12 20:06:54 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-07-12 20:06:54 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-07-12 20:05:55 327008 —-a-w- C:\Windows\System32\RaCoInstx.dll
2012-07-12 20:05:55 1488448 —-a-w- C:\Windows\System32\drivers\netr28x.sys
2012-07-12 20:05:55 ——– d—–w- C:\ProgramData\Ralink Driver
2012-07-12 19:57:38 ——– d—–w- C:\ProgramData\Ralink
2012-07-12 19:57:28 4096 —-a-w- C:\Windows\SysWow64\drivers\rt2870.bin
2012-07-12 19:57:28 4096 —-a-w- C:\Windows\System32\drivers\rt2870.bin
2012-07-12 19:57:20 ——– d—–w- C:\ProgramData\Sitecom Driver
2012-07-12 19:57:13 ——– d—–w- C:\Program Files (x86)\Cisco
2012-07-12 19:57:12 527360 —-a-w- C:\Windows\SysWow64\RAIHV.dll
2012-07-12 19:57:12 527360 —-a-w- C:\Windows\System32\RAIHV.dll
2012-07-12 19:57:12 25088 —-a-w- C:\Windows\System32\RAEXTUI.dll
2012-07-12 19:57:11 25088 —-a-w- C:\Windows\SysWow64\RAEXTUI.dll
2012-07-12 19:57:11 ——– d—–w- C:\Program Files (x86)\Sitecom
2012-07-12 19:53:28 ——– d—–w- C:\Users\Frans\AppData\Local\ATI
2012-07-12 19:52:28 ——– d—–w- C:\Users\Frans\AppData\Roaming\Intel Corporation
2012-07-12 19:49:41 ——– d—–w- C:\Users\Frans\AppData\Local\Hewlett-Packard
2012-07-12 19:49:10 ——– d—–w- C:\Users\Frans\AppData\Local\VirtualStore
.
==================== Find3M ====================
.
2012-07-16 01:50:48 175616 —-a-w- C:\Windows\System32\msclmd.dll
2012-07-16 01:50:48 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll
2012-07-13 06:13:35 588472 —-a-w- C:\Windows\SysWow64\ezsvc7x.dll
2012-06-06 06:06:16 2004480 —-a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 —-a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 05:50:10 458704 —-a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-04 11:06:22 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 —-a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-24 05:37:37 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 —-a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 —-a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 —-a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
.
============= FINISH: 22:21:01,33 ===============
Alvast bedankt
Rikje