Trojan Injector enz

  • irmz

    .

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

    IF REQUESTED, ZIP IT UP & ATTACH IT

    .

    DDS (Ver_2012-11-07.01)

    .

    Microsoft Windows 7 Home Premium

    Boot Device: \Device\HarddiskVolume1

    Install Date: 26-1-2012 13:34:27

    System Uptime: 9-11-2012 13:19:31 (0 hours ago)

    .

    Motherboard: Hewlett-Packard | | 3577

    Processor: AMD E-450 APU with Radeon™ HD Graphics | Socket FT1 | 1650/100mhz

    .

    ==== Disk Partitions =========================

    .

    C: is FIXED (NTFS) - 446 GiB total, 406,459 GiB free.

    D: is FIXED (NTFS) - 15 GiB total, 1,678 GiB free.

    E: is FIXED (FAT32) - 4 GiB total, 1,084 GiB free.

    F: is CDROM ()

    .

    ==== Disabled Device Manager Items =============

    .

    ==== System Restore Points ===================

    .

    RP89: 28-10-2012 22:01:03 - avast! Internet Security Setup

    RP90: 29-10-2012 10:50:04 - avast! Free Antivirus Setup

    RP91: 29-10-2012 11:04:23 - Installed Fighters.

    RP92: 29-10-2012 19:53:59 - Installed Java 7 Update 9

    RP93: 29-10-2012 20:11:53 - Windows Update

    RP94: 5-11-2012 16:41:51 - Windows Update

    RP95: 8-11-2012 22:56:17 - avast! Free Antivirus Setup

    RP96: 8-11-2012 23:48:17 - avast! Free Antivirus Setup

    RP97: 9-11-2012 13:24:31 - Windows Update

    .

    ==== Installed Programs ======================

    .

    Adobe Flash Player 11 ActiveX

    Adobe Flash Player 11 Plugin

    Adobe Reader X (10.1.4) MUI

    Adobe Shockwave Player 11.5

    Agatha Christie - Peril at End House

    AMD APP SDK Runtime

    AMD Fuel

    AMD Media Foundation Decoders

    AMD VISION Engine Control Center

    ATI Catalyst Install Manager

    avast! Free Antivirus

    Bejeweled 3

    Blackhawk Striker 2

    Blasterball 3

    Bounce Symphony

    Broadcom 802.11 Wireless LAN Adapter

    Broadcom Bluetooth Software

    Broadcom InConcert Maestro

    Cake Mania

    Catalyst Control Center - Branding

    Catalyst Control Center Graphics Previews Common

    Catalyst Control Center InstallProxy

    Catalyst Control Center Localization All

    ccc-utility64

    CCC Help Chinese Standard

    CCC Help Chinese Traditional

    CCC Help Czech

    CCC Help Danish

    CCC Help Dutch

    CCC Help English

    CCC Help Finnish

    CCC Help French

    CCC Help German

    CCC Help Greek

    CCC Help Hungarian

    CCC Help Italian

    CCC Help Japanese

    CCC Help Korean

    CCC Help Norwegian

    CCC Help Polish

    CCC Help Portuguese

    CCC Help Russian

    CCC Help Spanish

    CCC Help Swedish

    CCC Help Thai

    CCC Help Turkish

    CCleaner

    Chronicles of Albian

    Chuzzle Deluxe

    Compaq Setup Manager

    Cradle of Rome 2

    CyberLink YouCam

    D3DX10

    Emsisoft Anti-Malware

    ESU for Microsoft Windows 7 SP1

    Evernote v. 4.2.3

    Facebook Video Calling 1.2.0.287

    Farm Frenzy

    FATE

    Final Drive: Nitro

    Governor of Poker 2 Premium Edition

    Hewlett-Packard ACLM.NET v1.1.2.0

    HP Auto

    HP Client Services

    HP Customer Experience Enhancements

    HP Documentation

    HP Games

    HP Launch Box

    HP On Screen Display

    HP Power Manager

    HP Quick Launch

    HP QuickWeb

    HP Setup

    HP Software Framework

    HP Support Assistant

    Java 7 Update 9

    Java Auto Updater

    Java(TM) 6 Update 31

    JavaFX 2.1.0

    Jewel Quest: The Sleepless Star - Collector's Edition

    Junk Mail filter update

    Magic Desktop

    Mah Jong Medley

    Malwarebytes Anti-Malware versie 1.65.1.1000

    Mesh Runtime

    Messenger Companion

    Microsoft .NET Framework 4 Client Profile

    Microsoft .NET Framework 4 Client Profile NLD Language Pack

    Microsoft Application Error Reporting

    Microsoft Office 2010

    Microsoft Office Klik-en-Klaar 2010

    Microsoft Office Starter 2010 - Nederlands

    Microsoft PowerPoint Viewer

    Microsoft Silverlight

    Microsoft SQL Server 2005 Compact Edition

    Microsoft Visual C++ 2005 Redistributable

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319

    Mozilla Firefox 16.0.2 (x86 nl)

    Mozilla Maintenance Service

    MSVCRT

    MSVCRT_amd64

    Mystery of Mortlake Mansion

    Namco All-Stars: PAC-MAN

    Penguins!

    Plants vs. Zombies - Game of the Year

    Poker Superstars III

    Polar Bowler

    Polar Golfer

    Realtek Ethernet Controller Driver

    Realtek High Definition Audio Driver

    Realtek PCIE Card Reader

    Recovery Manager

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

    Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)

    Skype Click to Call

    Skype™ 5.10

    Slingo Supreme

    SpywareBlaster 4.6

    Synaptics TouchPad Driver

    Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

    TweetDeck

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

    Update Installer for WildTangent Games App

    Vacation Quest - The Hawaiian Islands

    Virtual Villagers 5 - New Believers

    WildTangent Games App

    Windows Live Communications Platform

    Windows Live Essentials

    Windows Live Family Safety

    Windows Live ID Sign-in Assistant

    Windows Live Installer

    Windows Live Language Selector

    Windows Live Mail

    Windows Live Mesh

    Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen

    Windows Live Mesh ActiveX Control for Remote Connections

    Windows Live Messenger

    Windows Live Messenger Companion Core

    Windows Live MIME IFilter

    Windows Live Movie Maker

    Windows Live Photo Common

    Windows Live Photo Gallery

    Windows Live PIMT Platform

    Windows Live Remote Client

    Windows Live Remote Client Resources

    Windows Live Remote Service

    Windows Live Remote Service Resources

    Windows Live SOXE

    Windows Live SOXE Definitions

    Windows Live UX Platform

    Windows Live UX Platform Language Pack

    Windows Live Writer

    Windows Live Writer Resources

    Zuma Deluxe

    .

    ==== End Of File ===========================

  • Ben

    Hallo,

    Ik wil graag het DDS.txt logje zien (tu)

    Je heb nu het Attach.txt logje geplaats.

    Gr.Ben

    Antivirusprikbord.nl

  • irmz

    Sorry had ik niet gezien, ik heb gewoon de 1e link aangeklikt

    nu wel goed hopelijk ??

    enneuh..bedankt voor je geduld :)

    DDS (Ver_2012-11-07.01) - NTFS_AMD64

    Internet Explorer: 9.0.8112.16450 BrowserJavaVersion: 10.9.2

    Run by Anca at 14:14:56 on 2012-11-09

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3691.2307

    .

    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    ============== Running Processes ===============

    .

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\system32\atiesrxx.exe

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k GPSvcGroup

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\atieclxx.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\system32\WLANExt.exe

    C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

    C:\Windows\SysWOW64\ezSharedSvcHost.exe

    C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

    C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Windows\System32\svchost.exe -k secsvcs

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe

    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

    C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\AVAST Software\Avast\AvastUI.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

    C:\Windows\system32\svchost.exe -k bthsvcs

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Windows\SysWOW64\RunDll32.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe

    C:\Windows\SysWOW64\NOTEPAD.EXE

    C:\Windows\SysWOW64\NOTEPAD.EXE

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\System32\cscript.exe

    .

    ============== Pseudo HJT Report ===============

    .

    uStart Page = hxxp://www.google.com

    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    uRun: “C:\Users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe” /c /nocrashserver

    mRun: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun

    mRun: “C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe”

    mRun: C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

    mRun: “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”

    mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    mRun: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe

    mRun: C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe

    mRun: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”

    mRun: “C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe” /d=60

    mRun: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    uPolicies-Explorer: NoDrives = dword:0

    mPolicies-Explorer: EnableShellExecuteHooks = dword:1

    mPolicies-Explorer: NoDrives = dword:0

    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

    mPolicies-System: ConsentPromptBehaviorUser = dword:3

    mPolicies-System: EnableUIADesktopToggle = dword:0

    mPolicies-System: HideFastUserSwitching = dword:0

    IE: Afbeelding verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

    IE: Pagina verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204

    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    .

    INFO: HKCU has more than 50 listed domains.

    If you wish to scan all of them, select the ‘Force scan all domains’ option.

    .

    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

    TCP: NameServer = 192.168.2.254

    TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1} : DHCPNameServer = 192.168.2.254

    TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1}\16B6B65627D616E637 : DHCPNameServer = 192.168.7.1 192.168.7.1

    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    SSODL: WebCheck -

    SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll

    LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

    x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-Run: C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s

    x64-Run: C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe

    x64-Run: C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe

    x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -

    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath - C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\

    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll

    FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    FF - plugin: C:\Users\Anca\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll

    FF - plugin: C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll

    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

    FF - ExtSQL: 2012-10-28 15:19; {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}; C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}

    FF - ExtSQL: 2012-10-29 20:38; {e001c731-5e37-4538-a5cb-8168736a2360}; C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}

    FF - ExtSQL: 2012-11-09 00:08; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys

    R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys

    R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Users\Anca\Downloads\EmsisoftEmergencyKit\Run\a2ddax64.sys

    R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys

    R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys

    R2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe

    R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe

    R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys

    R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys

    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE

    R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe –> C:\Windows\System32\ezSharedSvcHost.exe

    R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe

    R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

    R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

    R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

    R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys

    R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys

    R3 btwampfl;btwampfl;C:\Windows\System32\drivers\btwampfl.sys

    R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys

    R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys

    R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys

    R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys

    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys

    R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys

    R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys

    R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys

    R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys

    R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

    R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe

    S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys

    S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys

    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe

    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys

    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS

    S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS

    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS

    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys

    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys

    S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe

    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

    .

    =============== Created Last 30 ================

    .

    2012-11-09 12:25:28 9291768 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F70FD25A-493D-4041-909C-82E64927C3EA}\mpengine.dll

    2012-11-08 22:49:36 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys

    2012-11-08 22:49:34 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys

    2012-11-08 22:49:27 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys

    2012-11-08 22:49:02 41224 —-a-w- C:\Windows\avastSS.scr

    2012-11-08 22:15:02 24064 —-a-w- C:\Windows\zoek-delete.exe

    2012-11-08 22:15:02 ——– d—–w- C:\Users\Anca\AppData\Local\Temp

    2012-10-31 08:54:29 ——– d-sh–w- C:\$RECYCLE.BIN

    2012-10-30 18:52:38 ——– d—–w- C:\ComboFix

    2012-10-29 19:37:55 ——– d—–w- C:\Users\Anca\AppData\Local\Macromedia

    2012-10-29 19:24:26 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

    2012-10-29 19:15:11 3584 —-a-w- C:\Windows\System32\drivers\nl-NL\tsusbflt.sys.mui

    2012-10-29 19:15:09 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll

    2012-10-29 19:15:08 15360 —-a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll

    2012-10-29 19:15:08 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe

    2012-10-29 19:15:00 19456 —-a-w- C:\Windows\System32\drivers\rdpvideominiport.sys

    2012-10-29 19:11:46 340992 —-a-w- C:\Windows\System32\schannel.dll

    2012-10-29 19:11:46 247808 —-a-w- C:\Windows\SysWow64\schannel.dll

    2012-10-29 19:11:45 458712 —-a-w- C:\Windows\System32\drivers\cng.sys

    2012-10-29 19:11:45 307200 —-a-w- C:\Windows\System32\ncrypt.dll

    2012-10-29 19:11:45 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys

    2012-10-29 19:11:44 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll

    2012-10-29 19:11:44 1448448 —-a-w- C:\Windows\System32\lsasrv.dll

    2012-10-29 19:11:43 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll

    2012-10-29 19:11:43 22016 —-a-w- C:\Windows\SysWow64\secur32.dll

    2012-10-29 19:11:39 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll

    2012-10-29 19:11:39 366592 —-a-w- C:\Windows\System32\qdvd.dll

    2012-10-29 18:55:14 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

    2012-10-28 21:36:43 98816 —-a-w- C:\Windows\sed.exe

    2012-10-28 21:36:43 256000 —-a-w- C:\Windows\PEV.exe

    2012-10-28 21:36:43 208896 —-a-w- C:\Windows\MBR.exe

    2012-10-27 18:01:12 ——– d—–w- C:\ProgramData\clp

    2012-10-27 18:00:48 ——– d—–w- C:\Users\Anca\AppData\Roaming\Fighters

    2012-10-27 17:59:56 ——– d—–w- C:\ProgramData\Common Toolkit Suite

    2012-10-27 17:58:09 ——– d—–w- C:\ProgramData\Fighters

    2012-10-27 14:51:27 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware

    2012-10-10 14:36:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll

    2012-10-10 14:36:53 2048 —-a-w- C:\Windows\System32\tzres.dll

    2012-10-10 14:36:37 715776 —-a-w- C:\Windows\System32\kerberos.dll

    2012-10-10 14:36:37 542208 —-a-w- C:\Windows\SysWow64\kerberos.dll

    2012-10-10 14:36:11 1464320 —-a-w- C:\Windows\System32\crypt32.dll

    2012-10-10 14:36:11 1159680 —-a-w- C:\Windows\SysWow64\crypt32.dll

    2012-10-10 14:36:10 184320 —-a-w- C:\Windows\System32\cryptsvc.dll

    2012-10-10 14:36:10 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll

    2012-10-10 14:36:10 140288 —-a-w- C:\Windows\System32\cryptnet.dll

    2012-10-10 14:36:10 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll

    .

    ==================== Find3M ====================

    .

    2012-10-29 19:51:15 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-09-29 17:54:26 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys

    2012-09-27 20:26:59 821736 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll

    2012-09-27 20:26:59 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll

    2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys

    2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe

    2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe

    2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe

    2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll

    2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll

    2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll

    2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll

    2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl

    2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe

    2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll

    2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb

    2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll

    2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll

    2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl

    2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe

    2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll

    2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb

    2012-08-23 14:13:11 243200 —-a-w- C:\Windows\System32\rdpudd.dll

    2012-08-23 14:08:26 30208 —-a-w- C:\Windows\System32\drivers\TsUsbGD.sys

    2012-08-23 14:07:35 57856 —-a-w- C:\Windows\System32\drivers\TsUsbFlt.sys

    2012-08-23 13:47:20 46592 —-a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll

    2012-08-23 13:46:20 16896 —-a-w- C:\Windows\SysWow64\wksprtPS.dll

    2012-08-23 13:20:40 54272 —-a-w- C:\Windows\System32\MsRdpWebAccess.dll

    2012-08-23 13:18:14 37376 —-a-w- C:\Windows\SysWow64\tsgqec.dll

    2012-08-23 13:17:54 18432 —-a-w- C:\Windows\System32\wksprtPS.dll

    2012-08-23 13:06:58 43520 —-a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll

    2012-08-23 12:52:53 44032 —-a-w- C:\Windows\System32\tsgqec.dll

    2012-08-23 11:20:06 62976 —-a-w- C:\Windows\System32\TSWbPrxy.exe

    2012-08-23 11:15:57 269312 —-a-w- C:\Windows\SysWow64\aaclient.dll

    2012-08-23 11:14:09 384000 —-a-w- C:\Windows\System32\wksprt.exe

    2012-08-23 11:12:17 192000 —-a-w- C:\Windows\SysWow64\rdpendp_winip.dll

    2012-08-23 10:54:24 322560 —-a-w- C:\Windows\System32\aaclient.dll

    2012-08-23 10:51:14 228864 —-a-w- C:\Windows\System32\rdpendp_winip.dll

    2012-08-23 10:39:24 1048064 —-a-w- C:\Windows\SysWow64\mstsc.exe

    2012-08-23 10:22:22 1123840 —-a-w- C:\Windows\System32\mstsc.exe

    2012-08-23 09:51:57 3174912 —-a-w- C:\Windows\System32\rdpcorets.dll

    2012-08-23 08:19:01 4916224 —-a-w- C:\Windows\SysWow64\mstscax.dll

    2012-08-23 08:13:07 5773824 —-a-w- C:\Windows\System32\mstscax.dll

    2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys

    2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys

    2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys

    2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

    2012-08-21 21:01:00 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe

    2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll

    2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll

    2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll

    2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll

    2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll

    2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll

    2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe

    2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll

    2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll

    2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe

    2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll

    2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll

    2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe

    2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe

    2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

    2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

    2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

    2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

    .

    ============= FINISH: 14:15:28,95 ===============

  • Ben

    Hallo,

    Het logje ziet er netjes uit doe het volgende;

    Klik op Start > (Instellingen) > Configuratiescherm > Een programma verwijderen:

    Java(TM) 6 Update 31

    Download OTC.exe (by OldTimer)

    • Plaats het bestand op je bureaublad.

    • Zorg dat er een internetverbinding is.

    • Klik vervolgens met je rechtermuisknop op OTCleanIt.exe en kies voor Run as Administrator (Nederlands: Uitvoeren als Administrator) om het programma te starten.

    • Lukt dat niet , doen dan dubbelklikken op het icoon.

    • Klik nu op de knop “CleanUp!”

    • Als je firewall, of een ander beveiligingsprogramma, een waarschuwing geeft dat OTC.exe internettoegang wil, mag je dit toestaan, het programma heeft die connectie nodig.

    • OTC zal als laatste vragen of je de computer herstarten wilt, dit mag je toestaan, hiermee verwijdert het zichzelf ook.

    Nota: Het gebruik van OTC.exe zal alle gebruikte tools(inclusief bijbehorende logs en backupmappen) van je computer doen verwijderen.

    Start CCleaner op.

    • Klik in de linkse kolom op Cleaner.

    • Klik achtereenvolgens op Analyseren en Opschonen.

    • Klik vervolgens in de linkse kolom op Register en klik op Scan naar problemen.

    • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen en OK.

    • Dan krijg je de vraag om een back-up te maken, klik op JA en kies dan Herstel alle geselecteerde fouten.

    • Sluit hierna CCleaner af.

    systeemherstelpunten verwijderen.

    •Ga naar Start>Configuratiescherm>Systeem >Systeembeveiliging> schakel nu systeemherstel uit door de gewenste schijf te selecteren en op “configureren” te klikken.

    •Klik nu op “verwijderen” om alle herstelpunten te verwijderen.

    •Klik op “Toepassen” en “OK“.

    •Herstart nu de PC.

    Vertel hoe de pc het hierna doet.

    Gr.Ben

    Antivirusprikbord.nl

  • irmz

    Hai Ben,

    ik heb alles uitgevoerd en heb de lap even gebruikt

    ik denk dat alles weer goed werkt, de lap is weer snel

    de toolbars zijn weg, kortom…het lijkt allemaal weer goed

    te werken…we zijn er erg blij mee….en willen je/jullie erg bedanken

    voor de hulp….

    ik neem aan dat ik alle programma's kan verwijderen die ik moest

    downloaden zoals combofix ed ??

    zou je mij misschien ook willen helpen met de pc van mijn vriend ?

    die heeft niet zoveel rommel als de vorige lap hoor :)

    het probleem is echter wel dat het muziekprogramma - clear.fi-

    uit het niets opstart….terwijl mijn vriend gewoon aan het surfen is…

    als de lap uit staat ( slaapstand ) dan spint ie de lap ook ineens op….

    gaarne advies….

    heel erg bedankt alvast, vr groet Irene.

  • Ben

    Hallo,

    >>>ik neem aan dat ik alle programma's kan verwijderen die ik moest

    downloaden zoals combofix ed ?? <<<

    Ja die kan je allemaal verwijderen inclusief de gemaakte logjes.

    Combo fix op deze manier: ga naar Start,

    Kopieer en plak: Combofix /Uninstall in de startzoekbalk.

    Druk ENTER en bevestig met OK.

    Als het goed is krijg je dan een melding dat Combofix verwijderd werd.

    Leeg hierna je prullenbak en maak een nieuw systeemherstelpunt aan:

    •Ga naar Start>Configuratiescherm>Systeem >Systeembeveiliging> schakel nu systeemherstel uit door de gewenste schijf te selecteren en op “configureren” te klikken.

    •Klik nu op “verwijderen” om alle herstelpunten te verwijderen.

    •Klik op “Toepassen” en “OK“.

    •Herstart nu de PC.

    Maak voor de pc van je vriend een nieuw Topic aan.

    Doe eerst de stappen uit deze link: http://antivirus.startpagina.nl/prikbord/4625317/voer-dit-eerst-uit-voordat-je-de-logjes-plaatst!!#msg-4625317

    En plaats dan in het nieuwe Topic de 2 gemaakte logjes.

    Gr.Ben

    Antivirusprikbord.nl

  • irmz

    Hai Ben

    ik heb alles gedaan wat je vroeg, maar moet ik systeemherstel dan

    niet weer inschakelen ?

    ik heb met Emisisoft malware een scan gedaan, maar er zit toch nog een

    verdacht bestand in tnv : MyWebSearchToolbar(A) en zit in een registersleutel

    is het nodig om nog een logje te maken ? zo niet dan wil ik je nogmaals bedanken en dan

    begin ik morgen met de lap van mijn vriend.

    vr groet Irene.

  • Ben

    Hallo,

    >>>ik heb alles gedaan wat je vroeg, maar moet ik systeemherstel dan

    niet weer inschakelen ? <<<<

    Ja die mag je weer inschakelen.

    Plaats ter contole nog maar een DDS.txt logje.

    Download DDS van sUBS van één van deze locaties en plaats het op je bureaublad:

    DDS - Bleeping Computer download.

    DDS - Bleeping Computer download.

    DDS - Infospyware.

    DDS is een diagnosetool en maakt gebruik van scripts.

    Schakel je beveiligings software uit voordat je DDS uitvoert!

    (hier of hier) kan je lezen hoe je dat doet.

    Dubbelklik op DDS om de tool te starten.

    Er worden nu automatisch twee log bestanden op het bureablad opgeslagen.

    DDS.txt

    Attach.txt (Plaats deze alleen indien hierom wordt gevraagd!)

    Post het DDS.txt in het volgende bericht.

    Plaats ook het gemaakte logje van Emisisoft malware.

    Gr.Ben

    Antivirusprikbord.nl

  • irmz

    Hai Ben

    hierbij het DDS logje, ik ga dat logje van Emisoft even zoeken,

    ik heb ook een scan gedaan met avast, maar die geeft weer een hele

    lijst met verdachte bestanden in de kluis, die niet gescand kunnen worden

    omdat ze met een wachtwoord beveiligd zijn zegt ie,…. hetzelfde als het

    begin van dit verzoek om hulp…

    zal ik proberen om dat hier te plaatsen ?

    bvd Irene.

    DDS (Ver_2012-11-07.01) - NTFS_AMD64

    Internet Explorer: 9.0.8112.16450 BrowserJavaVersion: 10.9.2

    Run by Anca at 20:36:41 on 2012-11-13

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3691.2305

    .

    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    ============== Running Processes ===============

    .

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\system32\atiesrxx.exe

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k GPSvcGroup

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\atieclxx.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    C:\Windows\system32\WLANExt.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

    C:\Windows\SysWOW64\ezSharedSvcHost.exe

    C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

    C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Windows\System32\svchost.exe -k secsvcs

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

    C:\Windows\system32\svchost.exe -k bthsvcs

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe

    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

    C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files\AVAST Software\Avast\AvastUI.exe

    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE

    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

    C:\Windows\SysWOW64\RunDll32.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe

    C:\Windows\servicing\TrustedInstaller.exe

    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\System32\cscript.exe

    .

    ============== Pseudo HJT Report ===============

    .

    uStart Page = hxxp://www.google.com

    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    uRun: “C:\Users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe” /c /nocrashserver

    mRun: “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun

    mRun: “C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe”

    mRun: C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

    mRun: “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”

    mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    mRun: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe

    mRun: C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe

    mRun: “C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe” /d=60

    mRun: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    uPolicies-Explorer: NoDrives = dword:0

    mPolicies-Explorer: EnableShellExecuteHooks = dword:1

    mPolicies-Explorer: NoDrives = dword:0

    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

    mPolicies-System: ConsentPromptBehaviorUser = dword:3

    mPolicies-System: EnableUIADesktopToggle = dword:0

    mPolicies-System: HideFastUserSwitching = dword:0

    IE: Afbeelding verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

    IE: Pagina verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204

    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    .

    INFO: HKCU has more than 50 listed domains.

    If you wish to scan all of them, select the ‘Force scan all domains’ option.

    .

    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab

    DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab

    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab

    TCP: NameServer = 192.168.2.254

    TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1} : DHCPNameServer = 192.168.2.254

    TCP: Interfaces\{490A553E-01A7-4292-9E78-E3F2B990C2A1}\16B6B65627D616E637 : DHCPNameServer = 192.168.7.1 192.168.7.1

    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    SSODL: WebCheck -

    SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll

    LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

    x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-Run: C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s

    x64-Run: C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe

    x64-Run: C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe

    x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -

    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath - C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\

    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll

    FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    FF - plugin: C:\Users\Anca\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll

    FF - plugin: C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll

    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll

    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

    FF - ExtSQL: 2012-10-29 20:38; {e001c731-5e37-4538-a5cb-8168736a2360}; C:\Users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}

    FF - ExtSQL: 2012-11-09 00:08; wrc@avast.com; C:\Program Files\AVAST Software\Avast\WebRep\FF

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys

    R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys

    R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Users\Anca\Downloads\EmsisoftEmergencyKit\Run\a2ddax64.sys

    R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys

    R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys

    R2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe

    R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe

    R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe

    R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys

    R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys

    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE

    R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe –> C:\Windows\System32\ezSharedSvcHost.exe

    R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe

    R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

    R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

    R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

    R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe

    R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys

    R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys

    R3 btwampfl;btwampfl;C:\Windows\System32\drivers\btwampfl.sys

    R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys

    R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys

    R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys

    R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys

    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys

    R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys

    R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys

    R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys

    R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys

    R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe

    R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe

    S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys

    S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys

    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe

    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys

    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS

    S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS

    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS

    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys

    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys

    S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe

    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

    .

    =============== Created Last 30 ================

    .

    2012-11-12 19:53:55 ——– d—–w- C:\Users\Anca\AppData\Roaming\QuickScan

    2012-11-09 12:25:28 9291768 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F70FD25A-493D-4041-909C-82E64927C3EA}\mpengine.dll

    2012-11-08 22:49:36 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys

    2012-11-08 22:49:34 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys

    2012-11-08 22:49:27 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys

    2012-11-08 22:49:02 41224 —-a-w- C:\Windows\avastSS.scr

    2012-11-08 22:15:02 24064 —-a-w- C:\Windows\zoek-delete.exe

    2012-11-08 22:15:02 ——– d—–w- C:\Users\Anca\AppData\Local\Temp

    2012-10-31 08:54:29 ——– d-sh–w- C:\$RECYCLE.BIN

    2012-10-29 19:37:55 ——– d—–w- C:\Users\Anca\AppData\Local\Macromedia

    2012-10-29 19:24:26 696760 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

    2012-10-29 19:15:11 3584 —-a-w- C:\Windows\System32\drivers\nl-NL\tsusbflt.sys.mui

    2012-10-29 19:15:09 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll

    2012-10-29 19:15:08 15360 —-a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll

    2012-10-29 19:15:08 13312 —-a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe

    2012-10-29 19:15:00 19456 —-a-w- C:\Windows\System32\drivers\rdpvideominiport.sys

    2012-10-29 19:11:46 340992 —-a-w- C:\Windows\System32\schannel.dll

    2012-10-29 19:11:46 247808 —-a-w- C:\Windows\SysWow64\schannel.dll

    2012-10-29 19:11:45 458712 —-a-w- C:\Windows\System32\drivers\cng.sys

    2012-10-29 19:11:45 307200 —-a-w- C:\Windows\System32\ncrypt.dll

    2012-10-29 19:11:45 154480 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys

    2012-10-29 19:11:44 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll

    2012-10-29 19:11:44 1448448 —-a-w- C:\Windows\System32\lsasrv.dll

    2012-10-29 19:11:43 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll

    2012-10-29 19:11:43 22016 —-a-w- C:\Windows\SysWow64\secur32.dll

    2012-10-29 19:11:39 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll

    2012-10-29 19:11:39 366592 —-a-w- C:\Windows\System32\qdvd.dll

    2012-10-29 18:55:14 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

    2012-10-27 18:01:12 ——– d—–w- C:\ProgramData\clp

    2012-10-27 18:00:48 ——– d—–w- C:\Users\Anca\AppData\Roaming\Fighters

    2012-10-27 17:59:56 ——– d—–w- C:\ProgramData\Common Toolkit Suite

    2012-10-27 17:58:09 ——– d—–w- C:\ProgramData\Fighters

    2012-10-27 14:51:27 ——– d—–w- C:\Program Files (x86)\Emsisoft Anti-Malware

    .

    ==================== Find3M ====================

    .

    2012-10-29 19:51:15 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-09-29 17:54:26 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys

    2012-09-27 20:26:59 821736 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll

    2012-09-27 20:26:59 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll

    2012-09-14 19:19:29 2048 —-a-w- C:\Windows\System32\tzres.dll

    2012-09-14 18:28:53 2048 —-a-w- C:\Windows\SysWow64\tzres.dll

    2012-08-31 18:19:35 1659760 —-a-w- C:\Windows\System32\drivers\ntfs.sys

    2012-08-30 18:03:45 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe

    2012-08-30 17:12:02 3968880 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe

    2012-08-30 17:12:02 3914096 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe

    2012-08-24 18:05:07 220160 —-a-w- C:\Windows\System32\wintrust.dll

    2012-08-24 16:57:48 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll

    2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll

    2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll

    2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl

    2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe

    2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll

    2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb

    2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll

    2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll

    2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl

    2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe

    2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll

    2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb

    2012-08-23 14:13:11 243200 —-a-w- C:\Windows\System32\rdpudd.dll

    2012-08-23 14:08:26 30208 —-a-w- C:\Windows\System32\drivers\TsUsbGD.sys

    2012-08-23 14:07:35 57856 —-a-w- C:\Windows\System32\drivers\TsUsbFlt.sys

    2012-08-23 13:47:20 46592 —-a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll

    2012-08-23 13:46:20 16896 —-a-w- C:\Windows\SysWow64\wksprtPS.dll

    2012-08-23 13:20:40 54272 —-a-w- C:\Windows\System32\MsRdpWebAccess.dll

    2012-08-23 13:18:14 37376 —-a-w- C:\Windows\SysWow64\tsgqec.dll

    2012-08-23 13:17:54 18432 —-a-w- C:\Windows\System32\wksprtPS.dll

    2012-08-23 13:06:58 43520 —-a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll

    2012-08-23 12:52:53 44032 —-a-w- C:\Windows\System32\tsgqec.dll

    2012-08-23 11:20:06 62976 —-a-w- C:\Windows\System32\TSWbPrxy.exe

    2012-08-23 11:15:57 269312 —-a-w- C:\Windows\SysWow64\aaclient.dll

    2012-08-23 11:14:09 384000 —-a-w- C:\Windows\System32\wksprt.exe

    2012-08-23 11:12:17 192000 —-a-w- C:\Windows\SysWow64\rdpendp_winip.dll

    2012-08-23 10:54:24 322560 —-a-w- C:\Windows\System32\aaclient.dll

    2012-08-23 10:51:14 228864 —-a-w- C:\Windows\System32\rdpendp_winip.dll

    2012-08-23 10:39:24 1048064 —-a-w- C:\Windows\SysWow64\mstsc.exe

    2012-08-23 10:22:22 1123840 —-a-w- C:\Windows\System32\mstsc.exe

    2012-08-23 09:51:57 3174912 —-a-w- C:\Windows\System32\rdpcorets.dll

    2012-08-23 08:19:01 4916224 —-a-w- C:\Windows\SysWow64\mstscax.dll

    2012-08-23 08:13:07 5773824 —-a-w- C:\Windows\System32\mstscax.dll

    2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys

    2012-08-22 18:12:40 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys

    2012-08-22 18:12:40 376688 —-a-w- C:\Windows\System32\drivers\netio.sys

    2012-08-22 18:12:33 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

    2012-08-21 21:01:00 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe

    2012-08-20 18:48:44 362496 —-a-w- C:\Windows\System32\wow64win.dll

    2012-08-20 18:48:44 243200 —-a-w- C:\Windows\System32\wow64.dll

    2012-08-20 18:48:44 13312 —-a-w- C:\Windows\System32\wow64cpu.dll

    2012-08-20 18:48:43 215040 —-a-w- C:\Windows\System32\winsrv.dll

    2012-08-20 18:48:37 16384 —-a-w- C:\Windows\System32\ntvdm64.dll

    2012-08-20 18:48:35 424448 —-a-w- C:\Windows\System32\KernelBase.dll

    2012-08-20 18:46:22 338432 —-a-w- C:\Windows\System32\conhost.exe

    2012-08-20 17:40:21 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll

    2012-08-20 17:38:44 44032 —-a-w- C:\Windows\apppatch\acwow64.dll

    2012-08-20 17:38:26 25600 —-a-w- C:\Windows\SysWow64\setup16.exe

    2012-08-20 17:37:19 5120 —-a-w- C:\Windows\SysWow64\wow32.dll

    2012-08-20 17:37:18 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll

    2012-08-20 15:38:21 7680 —-a-w- C:\Windows\SysWow64\instnm.exe

    2012-08-20 15:38:20 2048 —-a-w- C:\Windows\SysWow64\user.exe

    2012-08-20 15:33:28 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

    2012-08-20 15:33:28 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

    2012-08-20 15:33:28 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

    2012-08-20 15:33:28 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

    .

    ============= FINISH: 20:37:27,34 ===============

  • irmz

    Hai Ben,

    hierbij het Emsisoft logje, pffff ik hoop dat alles nu goed is,

    ik heb net weer een snelle avast scan gedaan en daar is de

    virus kluis nu leeg en hopelijk blijft dat zo…

    ik wacht je bevindingen rustig af,

    vr groet Irene.

    Emsisoft Anti-Malware - Version 7.0

    quarantine log

    Datum Bron Gebeurtenis Gedrag/Infectie

    12-11-2012 22:02:07 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 22:02:07 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:32:51 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:32:43 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Infectie verwijderd Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:21:53 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:21:53 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:20:50 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:20:43 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:20:43 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:35 Key: HKEY_CLASSES_ROOT\INTERFACE\{90449521-D834-4703-BB4E-D3AA44042FF8} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:29 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:26 Key: HKEY_CLASSES_ROOT\INTERFACE\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:22 Key: HKEY_CLASSES_ROOT\INTERFACE\{991AAC62-B100-47CE-8B75-253965244F69} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:18 C:\Users\Anca\AppData\Roaming\32BE.exe Verwijderd uit quarantaine Trojan.Generic.KDV.771531 (B)

    12-11-2012 21:19:15 C:\Users\Anca\AppData\Roaming\CBEF.exe Verwijderd uit quarantaine Trojan.Generic.KDV.771531 (B)

    12-11-2012 21:19:12 C:\Users\Anca\AppData\Roaming\BCC3.exe Verwijderd uit quarantaine Trojan.Generic.KDV.771531 (B)

    12-11-2012 21:19:09 Key: HKEY_CLASSES_ROOT\INTERFACE\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:06 Key: HKEY_CLASSES_ROOT\INTERFACE\{1F52A5FA-A705-4415-B975-88503B291728} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:19:03 Key: HKEY_CLASSES_ROOT\INTERFACE\{3E720453-B472-4954-B7AA-33069EB53906} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:59 Key: HKEY_CLASSES_ROOT\INTERFACE\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:55 Key: HKEY_CLASSES_ROOT\INTERFACE\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:51 Key: HKEY_CLASSES_ROOT\INTERFACE\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:46 Key: HKEY_CLASSES_ROOT\INTERFACE\{120927BF-1700-43BC-810F-FAB92549B390} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:43 C:\Users\Anca\AppData\Roaming\Biqwqx.exe Verwijderd uit quarantaine Trojan.Win32.Bublik.AMN (A)

    12-11-2012 21:18:39 C:\Users\Anca\AppData\Roaming\9CD.exe Verwijderd uit quarantaine Trojan.Generic.KDV.771289 (B)

    12-11-2012 21:18:35 Key: HKEY_CLASSES_ROOT\INTERFACE\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF} Verwijderd uit quarantaine Trace.Registry.FunWebProducts (A)

    12-11-2012 21:18:31 Key: HKEY_CLASSES_ROOT\INTERFACE\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:18:09 Key: HKEY_CLASSES_ROOT\INTERFACE\{07B18EAC-A523-4961-B6BB-170DE4475CCA} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:17:59 Key: HKEY_CLASSES_ROOT\INTERFACE\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    12-11-2012 21:17:15 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Infectie verwijderd Trace.Registry.MyWebSearchToobar (A)

    29-10-2012 21:27:33 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Infectie verwijderd Trace.Registry.MyWebSearchToobar (A)

    29-10-2012 21:26:34 C:\Users\Anca\AppData\Roaming\309C.exe Teruggezet uit quarantaine Trojan.Generic.KDV.771531 (B)

    27-10-2012 19:40:25 Key: HKEY_CLASSES_ROOT\INTERFACE\{BBABDC90-F3D5-4801-863A-EE6AE529862D} Verwijderd uit quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{120927BF-1700-43BC-810F-FAB92549B390} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF} Verplaatst naar quarantaine Trace.Registry.FunWebProducts (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{3E720453-B472-4954-B7AA-33069EB53906} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{1F52A5FA-A705-4415-B975-88503B291728} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{991AAC62-B100-47CE-8B75-253965244F69} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: hkey_users\s-1-5-21-139012978-1220910512-2524659261-501\software\mywebsearch Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{90449521-D834-4703-BB4E-D3AA44042FF8} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{07B18EAC-A523-4961-B6BB-170DE4475CCA} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{BBABDC90-F3D5-4801-863A-EE6AE529862D} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:24 Key: HKEY_CLASSES_ROOT\INTERFACE\{07B18EAC-A523-4961-B6BB-170DE4475CCA} Verplaatst naar quarantaine Trace.Registry.MyWebSearchToobar (A)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\CBEF.exe Verplaatst naar quarantaine Trojan.Generic.KDV.771531 (B)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\BCC3.exe Verplaatst naar quarantaine Trojan.Generic.KDV.771531 (B)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\32BE.exe Verplaatst naar quarantaine Trojan.Generic.KDV.771531 (B)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\309C.exe Verplaatst naar quarantaine Trojan.Generic.KDV.771531 (B)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\9CD.exe Verplaatst naar quarantaine Trojan.Generic.KDV.771289 (B)

    27-10-2012 18:57:23 C:\Users\Anca\AppData\Roaming\Biqwqx.exe Verplaatst naar quarantaine Trojan.Win32.Bublik.AMN (A)

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.