Goedenavond Ben,
Hier weer eentje:
22:04:53.0625 1436 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
22:04:53.0625 1436 ============================================================
22:04:53.0625 1436 Current date / time: 2012/09/11 22:04:53.0625
22:04:53.0625 1436 SystemInfo:
22:04:53.0625 1436
22:04:53.0625 1436 OS Version: 5.1.2600 ServicePack: 3.0
22:04:53.0625 1436 Product type: Workstation
22:04:53.0625 1436 ComputerName: GEBRUIKE-56D891
22:04:53.0625 1436 UserName: Gebruiker
22:04:53.0625 1436 Windows directory: C:\WINDOWS
22:04:53.0625 1436 System windows directory: C:\WINDOWS
22:04:53.0625 1436 Processor architecture: Intel x86
22:04:53.0625 1436 Number of processors: 1
22:04:53.0625 1436 Page size: 0x1000
22:04:53.0625 1436 Boot type: Normal boot
22:04:53.0625 1436 ============================================================
22:04:55.0359 1436 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2861, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type ‘K0’, Flags 0x00000054
22:04:55.0421 1436 ============================================================
22:04:55.0421 1436 \Device\Harddisk0\DR0:
22:04:55.0437 1436 MBR partitions:
22:04:55.0437 1436 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x9506AB1
22:04:55.0437 1436 ============================================================
22:04:55.0546 1436 C: <-> \Device\Harddisk0\DR0\Partition1
22:04:55.0546 1436 ============================================================
22:04:55.0546 1436 Initialize success
22:04:55.0546 1436 ============================================================
22:04:55.0609 3436 ============================================================
22:04:55.0609 3436 Scan started
22:04:55.0609 3436 Mode: Auto (DCExact ); SigCheck; TDLFS; Silent;
22:04:55.0609 3436 ============================================================
22:04:57.0687 3436 ================ Scan system memory ========================
22:04:57.0703 3436 ================ Scan services =============================
22:04:57.0843 3436 ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:04:59.0468 3436 ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:04:59.0671 3436 ADM8511 C:\WINDOWS\system32\DRIVERS\ADM8511.SYS
22:04:59.0906 3436 AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:05:00.0000 3436 aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
22:05:00.0078 3436 aec C:\WINDOWS\system32\drivers\aec.sys
22:05:00.0281 3436 AFD C:\WINDOWS\System32\drivers\afd.sys
22:05:00.0421 3436 Alerter C:\WINDOWS\system32\alrsvc.dll
22:05:00.0609 3436 ALG C:\WINDOWS\System32\alg.exe
22:05:00.0703 3436 AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:05:00.0890 3436 aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:05:00.0937 3436 AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:05:01.0109 3436 atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:05:01.0281 3436 Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:05:01.0484 3436 AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:05:01.0671 3436 audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:05:01.0875 3436 b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys
22:05:01.0968 3436 Beep C:\WINDOWS\system32\drivers\Beep.sys
22:05:02.0156 3436 BITS C:\WINDOWS\system32\qmgr.dll
22:05:02.0375 3436 Blfp C:\WINDOWS\system32\DRIVERS\baspxp32.sys
22:05:02.0468 3436 Browser C:\WINDOWS\System32\browser.dll
22:05:02.0609 3436 cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:05:02.0812 3436 Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:05:03.0015 3436 Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:05:03.0218 3436 Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:05:03.0406 3436 CiSvc C:\WINDOWS\system32\cisvc.exe
22:05:03.0578 3436 ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:05:03.0765 3436 clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:05:04.0000 3436 CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:05:04.0218 3436 DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:05:04.0343 3436 Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:05:04.0546 3436 Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:05:04.0750 3436 dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:05:05.0046 3436 dmio C:\WINDOWS\system32\drivers\dmio.sys
22:05:05.0234 3436 dmload C:\WINDOWS\system32\drivers\dmload.sys
22:05:05.0406 3436 dmserver C:\WINDOWS\System32\dmserver.dll
22:05:05.0593 3436 DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:05:05.0796 3436 Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:05:05.0937 3436 Dot3svc C:\WINDOWS\System32\dot3svc.dll
22:05:06.0140 3436 drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:05:06.0328 3436 eamon C:\WINDOWS\system32\DRIVERS\eamon.sys
22:05:06.0734 3436 EapHost C:\WINDOWS\System32\eapsvc.dll
22:05:06.0953 3436 ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys
22:05:07.0125 3436 ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
22:05:07.0250 3436 epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
22:05:07.0312 3436 ERSvc C:\WINDOWS\System32\ersvc.dll
22:05:07.0531 3436 Eventlog C:\WINDOWS\system32\services.exe
22:05:07.0593 3436 EventSystem C:\WINDOWS\system32\es.dll
22:05:07.0718 3436 Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:05:07.0906 3436 FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:05:08.0031 3436 Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
22:05:08.0203 3436 Fips C:\WINDOWS\system32\drivers\Fips.sys
22:05:08.0390 3436 Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
22:05:08.0593 3436 FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:05:08.0796 3436 FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
22:05:08.0843 3436 Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:05:09.0031 3436 Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:05:09.0218 3436 Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:05:09.0484 3436 gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
22:05:09.0515 3436 gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
22:05:09.0562 3436 gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
22:05:09.0671 3436 helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:05:09.0843 3436 HidServ C:\WINDOWS\System32\hidserv.dll
22:05:10.0046 3436 HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:05:10.0234 3436 hkmsvc C:\WINDOWS\System32\kmsvc.dll
22:05:10.0437 3436 HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:05:10.0531 3436 HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:05:10.0734 3436 i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:05:10.0968 3436 ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
22:05:11.0156 3436 idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:05:11.0250 3436 Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:05:11.0468 3436 ImapiService C:\WINDOWS\system32\imapi.exe
22:05:11.0671 3436 InCDfs C:\WINDOWS\system32\drivers\InCDFs.sys
22:05:11.0703 3436 InCDPass C:\WINDOWS\system32\drivers\InCDPass.sys
22:05:11.0718 3436 InCDRec C:\WINDOWS\system32\drivers\InCDRec.sys
22:05:11.0734 3436 incdrm C:\WINDOWS\system32\drivers\InCDRm.sys
22:05:11.0875 3436 InCDsrv C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
22:05:12.0046 3436 IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
22:05:12.0250 3436 intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:05:12.0437 3436 Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:05:12.0718 3436 IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:05:12.0937 3436 IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:05:13.0203 3436 IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:05:13.0453 3436 IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:05:13.0687 3436 irda C:\WINDOWS\system32\DRIVERS\irda.sys
22:05:13.0812 3436 IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:05:13.0921 3436 Irmon C:\WINDOWS\System32\irmon.dll
22:05:14.0062 3436 irsir C:\WINDOWS\system32\DRIVERS\irsir.sys
22:05:14.0203 3436 isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:05:14.0546 3436 JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
22:05:14.0625 3436 Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:05:14.0906 3436 kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:05:15.0171 3436 kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:05:15.0468 3436 KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:05:15.0703 3436 LanmanServer C:\WINDOWS\System32\srvsvc.dll
22:05:15.0968 3436 lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:05:16.0187 3436 LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:05:16.0421 3436 Messenger C:\WINDOWS\System32\msgsvc.dll
22:05:16.0671 3436 mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:05:16.0859 3436 mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:05:17.0046 3436 Modem C:\WINDOWS\system32\drivers\Modem.sys
22:05:17.0218 3436 Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:05:17.0406 3436 mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:05:17.0578 3436 MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:05:17.0781 3436 MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:05:17.0968 3436 MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:05:18.0140 3436 MSDTC C:\WINDOWS\system32\msdtc.exe
22:05:18.0328 3436 Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:05:18.0500 3436 MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:05:18.0656 3436 MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:05:18.0812 3436 MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:05:19.0015 3436 mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:05:19.0218 3436 Mup C:\WINDOWS\system32\drivers\Mup.sys
22:05:19.0328 3436 napagent C:\WINDOWS\System32\qagentrt.dll
22:05:19.0531 3436 NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:05:19.0718 3436 NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:05:19.0843 3436 Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:05:20.0046 3436 NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:05:20.0250 3436 NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:05:20.0390 3436 NeroRegInCDSrv C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
22:05:20.0406 3436 NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:05:20.0593 3436 NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:05:20.0781 3436 NetDDE C:\WINDOWS\system32\netdde.exe
22:05:20.0937 3436 NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:05:21.0125 3436 Netlogon C:\WINDOWS\system32\lsass.exe
22:05:21.0312 3436 Netman C:\WINDOWS\System32\netman.dll
22:05:21.0500 3436 NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:05:21.0562 3436 Nla C:\WINDOWS\System32\mswsock.dll
22:05:21.0718 3436 NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
22:05:21.0796 3436 Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:05:22.0000 3436 Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:05:22.0234 3436 NtLmSsp C:\WINDOWS\system32\lsass.exe
22:05:22.0406 3436 NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:05:22.0609 3436 Null C:\WINDOWS\system32\drivers\Null.sys
22:05:22.0796 3436 NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:05:22.0968 3436 NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:05:23.0203 3436 ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:05:23.0234 3436 Parport C:\WINDOWS\system32\DRIVERS\parport.sys
22:05:23.0390 3436 PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:05:23.0578 3436 ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:05:23.0750 3436 PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:05:23.0890 3436 PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:05:24.0078 3436 Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:05:24.0265 3436 PlugPlay C:\WINDOWS\system32\services.exe
22:05:24.0312 3436 PolicyAgent C:\WINDOWS\system32\lsass.exe
22:05:24.0468 3436 PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:05:24.0640 3436 ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:05:24.0796 3436 PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:05:24.0937 3436 Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:05:25.0140 3436 RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:05:25.0312 3436 RasAuto C:\WINDOWS\System32\rasauto.dll
22:05:25.0500 3436 Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys
22:05:25.0578 3436 Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:05:25.0765 3436 RasMan C:\WINDOWS\System32\rasmans.dll
22:05:25.0968 3436 RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:05:26.0140 3436 Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:05:26.0312 3436 Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:05:26.0500 3436 RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:05:26.0703 3436 rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:05:26.0906 3436 RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:05:27.0000 3436 RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:05:27.0171 3436 redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:05:27.0359 3436 RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:05:27.0546 3436 RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:05:27.0734 3436 RpcLocator C:\WINDOWS\system32\locator.exe
22:05:27.0921 3436 RpcSs C:\WINDOWS\system32\rpcss.dll
22:05:27.0984 3436 RSVP C:\WINDOWS\system32\rsvp.exe
22:05:28.0140 3436 SamSs C:\WINDOWS\system32\lsass.exe
22:05:28.0328 3436 SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:05:28.0531 3436 Schedule C:\WINDOWS\system32\schedsvc.dll
22:05:28.0703 3436 Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:05:28.0796 3436 seclogon C:\WINDOWS\System32\seclogon.dll
22:05:28.0984 3436 SENS C:\WINDOWS\system32\sens.dll
22:05:29.0187 3436 Ser2pl C:\WINDOWS\system32\DRIVERS\ser2pl.sys
22:05:29.0250 3436 serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
22:05:29.0421 3436 Serial C:\WINDOWS\system32\DRIVERS\serial.sys
22:05:29.0609 3436 Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:05:29.0796 3436 SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:05:30.0000 3436 ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:05:30.0093 3436 smwdm C:\WINDOWS\system32\drivers\smwdm.sys
22:05:30.0218 3436 SoundMAX Agent Service (default) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
22:05:30.0234 3436 SoundMAX Agent Service (default) ( UnsignedFile.Multi.Generic ) - warning
22:05:30.0234 3436 SoundMAX Agent Service (default) - detected UnsignedFile.Multi.Generic (1)
22:05:30.0281 3436 splitter C:\WINDOWS\system32\drivers\splitter.sys
22:05:30.0468 3436 Spooler C:\WINDOWS\system32\spoolsv.exe
22:05:30.0578 3436 sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:05:30.0687 3436 srservice C:\WINDOWS\system32\srsvc.dll
22:05:30.0812 3436 Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:05:30.0984 3436 SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:05:31.0125 3436 stisvc C:\WINDOWS\system32\wiaservc.dll
22:05:31.0328 3436 swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:05:31.0515 3436 swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:05:31.0718 3436 sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:05:31.0890 3436 SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:05:32.0093 3436 TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:05:32.0328 3436 Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:05:32.0406 3436 TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:05:32.0578 3436 TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:05:32.0750 3436 TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:05:32.0953 3436 TermService C:\WINDOWS\System32\termsrv.dll
22:05:33.0125 3436 Themes C:\WINDOWS\System32\shsvcs.dll
22:05:33.0187 3436 TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:05:33.0296 3436 TrkWks C:\WINDOWS\system32\trkwks.dll
22:05:33.0468 3436 Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:05:33.0671 3436 Update C:\WINDOWS\system32\DRIVERS\update.sys
22:05:33.0875 3436 upnphost C:\WINDOWS\System32\upnphost.dll
22:05:34.0000 3436 UPS C:\WINDOWS\System32\ups.exe
22:05:34.0187 3436 usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:05:34.0390 3436 usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:05:34.0578 3436 usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:05:34.0765 3436 usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:05:34.0968 3436 usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:05:35.0109 3436 USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:05:35.0296 3436 usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:05:35.0468 3436 VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:05:35.0656 3436 VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:05:35.0859 3436 VSS C:\WINDOWS\System32\vssvc.exe
22:05:36.0000 3436 W32Time C:\WINDOWS\system32\w32time.dll
22:05:36.0171 3436 Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:05:36.0359 3436 wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:05:36.0531 3436 WebClient C:\WINDOWS\System32\webclnt.dll
22:05:36.0765 3436 winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:05:36.0968 3436 WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
22:05:37.0093 3436 Wmi C:\WINDOWS\System32\advapi32.dll
22:05:37.0218 3436 WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:05:37.0437 3436 WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
22:05:37.0578 3436 wscsvc C:\WINDOWS\system32\wscsvc.dll
22:05:37.0765 3436 wuauserv C:\WINDOWS\system32\wuauserv.dll
22:05:37.0984 3436 WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:05:38.0062 3436 WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:05:38.0109 3436 WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
22:05:38.0187 3436 WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:05:38.0390 3436 xmlprov C:\WINDOWS\System32\xmlprov.dll
22:05:38.0546 3436 ================ Scan global ===============================
22:05:38.0593 3436 C:\WINDOWS\system32\basesrv.dll
22:05:38.0640 3436 C:\WINDOWS\system32\winsrv.dll
22:05:38.0671 3436 C:\WINDOWS\system32\winsrv.dll
22:05:38.0687 3436 C:\WINDOWS\system32\services.exe
22:05:38.0687 3436 ================ Scan MBR ==================================
22:05:38.0718 3436 \Device\Harddisk0\DR0
22:05:39.0015 3436 ================ Scan VBR ==================================
22:05:39.0031 3436 \Device\Harddisk0\DR0\Partition1
22:05:39.0031 3436 ================ Scan UEFI extensions ======================
22:05:39.0031 3436 ================ Scan active images ========================
22:05:39.0031 3436 ============================================================
22:05:39.0031 3436 Scan finished
22:05:39.0031 3436 ============================================================
22:05:39.0953 1792 Deinitialize success
.
==============================================
System Restore Point Check:
.
TDSSKiller Starter Restore Point Created Succesfully
==============================================
Registry Export
.
==============================================
EOF
De pc is nog niet weer vastgelopen, krijg geen pop up van Nod dat er een paard is. Hij is nog wel traag, maar we hebben ook een super trage verbinding en als er teveel buren online zijn kan dat ook de oorzaak zijn.
Groet Aktie