Af en toe spontaan een spelletjes site in Internet Explorer, gebruik alleen Firefox

  • filatelist

    Hoi,

    Af en toe verschijnt er spontaan een spelletjes website in mijn beeldscherm. Geopend door Internet Explorer terwijl ik deze nooit gebruik. Kan hem zo weg klikken en weer verder gaan. En verschijnt ook sporadisch.

    Hierbij alle logjes inclusief alvast een Combofix logje:

    Hier mijn logjes voor de zekerheid:

    # AdwCleaner v2.107 - Verslag gemaakt op 24/01/2013 om 17:35:14

    # Geactualiseerd op 21/01/2013 door Xplode

    # Besturingssysteem : Windows 7 Ultimate Service Pack 1 (64 bits)

    # Gebruiker : Ronald - RONALD-PC

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : F:\adwcleaner.exe

    # Optie

    ***** *****

    ***** *****

    ***** *****

    ***** *****

    -\\ Internet Explorer v9.0.8112.16457

    Het register bevat geen enkele ongeoorloofde invoer.

    -\\ Mozilla Firefox v18.0.1 (nl)

    File : C:\Users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default\prefs.js

    De file bevat geen enkele ongeoorloofde invoer.

    *************************

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner.txt - ##########

    Hier Malwarebytes waar ik overigens een betaalde versie van heb:

    Malwarebytes Anti-Malware (PRO) 1.70.0.1100

    www.malwarebytes.org

    Databaseversie: v2013.01.24.08

    Windows 7 Service Pack 1 x64 NTFS

    Internet Explorer 9.0.8112.16421

    Ronald :: RONALD-PC

    Bescherming: Ingeschakeld

    24-1-2013 17:25:25

    mbam-log-2013-01-24 (17-25-25).txt

    Scan type: Volledige scan (C:\|)

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 355682

    Verstreken tijd: 7 minuut/minuten, 30 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    Hier het hijackthis logje:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 18:38:11, on 24-1-2013

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v9.00 (9.00.8112.16457)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\Cobian Backup 10\Cobian.exe

    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe

    C:\Program Files (x86)\Winamp\winampa.exe

    C:\Program Files (x86)\Cobian Backup 10\cbInterface.exe

    C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe

    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe

    C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE

    C:\Program Files (x86)\Nexus Radio\Nexus Radio.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\Spotnet\Spotnet.exe

    C:\Program Files (x86)\Spotnet\SABnzbd.exe

    F:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe” -autostart

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Cobian Backup 10\Cobian.exe”

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

    O4 - HKLM\..\Run: C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Winamp\winampa.exe”

    O4 - HKUS\S-1-5-21-3485982240-1827776346-149275893-1002\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘UpdatusUser’)

    O4 - HKUS\S-1-5-21-3485982240-1827776346-149275893-1002\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘UpdatusUser’)

    O4 - S-1-5-21-3485982240-1827776346-149275893-1002 User Startup: RUN.CMD (User ‘UpdatusUser’)

    O4 - .DEFAULT User Startup: RUN.CMD (User ‘Default user’)

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL

    O11 - Options group: Accelerated graphics

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Cobian Backup 10 Volume Shadow Copy service (cbVSCService) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 10\cbVSCService.exe

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    End of file - 8771 bytes

    Ook TDSSKILLER gedaan vind niets.

    En hier alvast het Combofix logje

    ComboFix 13-01-24.02 - Ronald 24-01-2013 18:46:43.2.8 - x64

    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.31.1043.18.16301.12392

    Gestart vanuit: F:\ComboFix.exe

    AV: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}

    SP: ESET NOD32 Antivirus 5.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    * Nieuw herstelpunt werd aangemaakt

    * Aanwezig AV is actief

    .

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-12-24 to 2013-01-24 ))))))))))))))))))))))))))))))

    .

    .

    2013-01-24 17:48 . 2013-01-24 17:48 ——– d—–w- c:\users\Default\AppData\Local\temp

    2013-01-24 16:37 . 2013-01-24 16:37 ——– d—–w- c:\program files (x86)\ESET

    2013-01-22 07:05 . 2013-01-08 05:32 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{15E0EC34-CB48-49E7-A130-528DF35EF5B1}\mpengine.dll

    2013-01-16 14:33 . 2013-01-16 14:33 ——– d—–w- c:\programdata\Canneverbe Limited

    2013-01-16 14:16 . 2013-01-16 14:16 ——– d—–w- c:\program files (x86)\LSoft Technologies

    2013-01-14 12:53 . 2013-01-14 12:53 ——– d—–w- c:\windows\ERUNT

    2013-01-14 12:53 . 2013-01-14 12:53 ——– d—–w- C:\JRT

    2013-01-13 20:09 . 2013-01-13 20:09 ——– d—–w- c:\users\Administrator

    2013-01-13 08:55 . 2009-09-04 16:29 1892184 —-a-w- c:\windows\SysWow64\D3DX9_42.dll

    2013-01-13 08:55 . 2006-09-28 15:05 2414360 —-a-w- c:\windows\SysWow64\d3dx9_31.dll

    2013-01-13 08:54 . 2013-01-13 08:54 ——– d—–w- c:\program files (x86)\Winamp Detect

    2013-01-13 08:54 . 2013-01-13 08:54 ——– d—–w- c:\program files (x86)\Common Files\PX Storage Engine

    2013-01-13 08:54 . 2013-01-13 08:55 ——– d—–w- c:\program files (x86)\Winamp

    2013-01-12 23:15 . 2008-10-17 19:04 179712 ——w- c:\windows\system32\BrfxDA5b.dll

    2013-01-12 23:15 . 2007-12-13 21:16 73728 ——w- c:\windows\SysWow64\BrDctF2.dll

    2013-01-12 23:15 . 2007-12-13 21:16 5120 ——w- c:\windows\SysWow64\BrDctF2L.dll

    2013-01-12 23:15 . 2007-01-15 20:54 12288 ——w- c:\windows\SysWow64\BrDctF2S.dll

    2013-01-12 23:15 . 2006-12-28 12:39 176128 ——w- c:\windows\SysWow64\BroSNMP.dll

    2013-01-12 23:15 . 2013-01-12 23:15 ——– d—–w- c:\program files (x86)\Brother

    2013-01-12 23:15 . 2008-06-17 14:33 167936 ——w- c:\windows\SysWow64\NSSearch.dll

    2013-01-12 23:15 . 2013-01-12 23:15 ——– d—–w- c:\programdata\Brother

    2013-01-12 15:29 . 2013-01-12 15:29 ——– d—–w- c:\program files (x86)\Google

    2013-01-12 15:14 . 2013-01-19 20:04 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service

    2013-01-12 15:11 . 2013-01-12 15:11 ——– d—–w- c:\programdata\Malwarebytes

    2013-01-12 15:11 . 2013-01-12 15:11 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware

    2013-01-12 15:11 . 2012-12-14 15:49 24176 —-a-w- c:\windows\system32\drivers\mbam.sys

    2013-01-12 15:03 . 2013-01-12 15:03 ——– d—–w- c:\program files (x86)\Common Files\Adobe

    2013-01-12 14:58 . 2013-01-12 14:58 ——– d—–w- c:\program files\CCleaner

    2013-01-12 14:57 . 2013-01-12 14:57 ——– d—–w- c:\program files (x86)\MahJong Medley

    2013-01-12 14:57 . 2013-01-12 14:57 ——– d—–w- c:\program files (x86)\Dont Angry

    2013-01-12 14:57 . 2013-01-12 14:57 ——– d—–w- c:\program files\AdventurePinballDemo

    2013-01-12 14:56 . 2013-01-12 14:56 ——– d—–w- c:\program files (x86)\Thinking Blocks

    2013-01-12 14:54 . 2013-01-12 14:54 ——– d—–w- c:\program files (x86)\VS Revo Group

    2013-01-12 14:53 . 2013-01-12 14:53 ——– d—–w- c:\windows\SysWow64\C2MP

    2013-01-12 14:53 . 2013-01-12 14:53 ——– d—–w- c:\program files (x86)\K-Lite Codec Pack

    2013-01-12 14:51 . 2013-01-12 14:51 ——– d—–w- c:\program files (x86)\CDBurnerXP

    2013-01-12 14:50 . 2013-01-12 14:50 ——– d—–w- c:\program files (x86)\Araneae

    2013-01-12 14:49 . 2013-01-12 14:49 ——– d—–w- c:\program files (x86)\FileZilla FTP Client

    2013-01-12 14:49 . 2013-01-12 14:49 ——– d—–w- c:\program files (x86)\Xiph.Org

    2013-01-12 14:48 . 2013-01-12 14:48 ——– d—–w- c:\program files (x86)\Calibre2

    2013-01-12 14:48 . 2013-01-12 14:48 ——– d—–w- c:\program files (x86)\Cobian Backup 10

    2013-01-12 14:47 . 2013-01-12 14:47 ——– d—–w- c:\program files (x86)\FastCopy

    2013-01-12 14:45 . 2013-01-24 16:24 ——– d—–w- c:\program files (x86)\Nexus Radio

    2013-01-12 14:45 . 2013-01-12 14:45 ——– d—–w- c:\windows\SysWow64\Nexus Radio

    2013-01-12 14:45 . 2013-01-12 14:45 ——– d—–w- C:\My Plugins

    2013-01-12 14:45 . 2013-01-12 14:45 ——– d—–w- C:\My Saved Files

    2013-01-12 14:45 . 2013-01-12 14:45 ——– d—–w- C:\My Recorded Files

    2013-01-12 14:44 . 2013-01-12 14:44 ——– d—–w- c:\program files (x86)\GrabIt

    2013-01-12 14:39 . 2013-01-12 15:52 ——– d—–w- c:\programdata\Spotnet

    2013-01-12 14:39 . 2013-01-12 14:43 ——– d—–w- c:\program files (x86)\Spotnet

    2013-01-12 11:45 . 2013-01-12 11:45 ——– d—–w- c:\program files\Microsoft Silverlight

    2013-01-12 11:45 . 2013-01-12 11:45 ——– d—–w- c:\program files (x86)\Microsoft Silverlight

    2013-01-12 11:44 . 2013-01-12 11:44 ——– d—–w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2

    2013-01-12 11:33 . 2010-10-05 19:50 8192 —-a-w- c:\windows\SysWow64\drivers\IntelMEFWVer.dll

    2013-01-12 11:33 . 2010-10-05 19:50 8192 —-a-w- c:\windows\system32\drivers\IntelMEFWVer.dll

    2013-01-12 11:33 . 2013-01-12 11:33 ——– d—–w- c:\program files (x86)\Common Files\postureAgent

    2013-01-12 11:33 . 2013-01-12 11:33 ——– d—–w- c:\program files (x86)\Etron Technology

    2013-01-12 11:31 . 2011-07-22 11:35 1247848 —-a-w- c:\windows\system32\RTCOM64.dll

    2013-01-12 11:29 . 2013-01-12 11:47 ——– d—–w- c:\program files (x86)\Intel

    2013-01-12 11:29 . 2010-12-23 03:09 53248 —-a-r- c:\windows\SysWow64\CSVer.dll

    2013-01-12 11:29 . 2013-01-12 11:30 ——– d—–w- C:\Intel

    2013-01-12 11:28 . 2013-01-12 15:05 ——– d—–w- c:\program files (x86)\Microsoft Works

    2013-01-12 11:27 . 2013-01-12 11:27 ——– d—–w- c:\windows\PCHEALTH

    2013-01-12 11:26 . 2013-01-12 11:26 ——– d—–w- c:\program files\Microsoft Office

    2013-01-12 11:26 . 2013-01-12 11:26 ——– d—–w- c:\program files (x86)\Microsoft Visual Studio 8

    2013-01-12 11:26 . 2013-01-12 15:10 ——– d—–w- c:\programdata\Microsoft Help

    2013-01-12 11:26 . 2013-01-12 11:26 ——– d—–r- C:\MSOCache

    2013-01-12 11:21 . 2013-01-19 10:22 ——– d—–w- c:\users\Ronald

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d—–w- C:\Recovery

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d-sh–we c:\users\Default\Sjablonen

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d-sh–we c:\users\Default\Netwerkprinteromgeving

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d-sh–we c:\users\Default\Mijn documenten

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d-sh–we c:\users\Default\Menu Start

    2013-01-12 11:21 . 2013-01-12 11:21 ——– d-sh–we c:\users\Default\AppData\Local\Geschiedenis

    2013-01-09 11:43 . 2012-06-12 21:00 726160 —-a-w- c:\windows\system32\drivers\Rt64win7.sys

    2013-01-08 20:38 . 2013-01-08 20:38 ——– d—–w- c:\program files\ESET

    2013-01-08 20:29 . 2013-01-08 20:29 ——– d—–w- c:\programdata\Shark007

    2013-01-08 20:29 . 2013-01-08 20:29 ——– d—–w- c:\program files\Shark007

    2013-01-08 20:29 . 2012-11-27 04:58 4282368 —-a-w- c:\windows\system32\x264vfw.dll

    2013-01-08 20:29 . 2012-07-21 10:55 180736 —-a-w- c:\windows\system32\ac3acm.acm

    2013-01-08 20:29 . 2012-07-21 10:54 361472 —-a-w- c:\windows\system32\aacacm.acm

    2013-01-08 20:29 . 2012-06-09 17:21 206336 —-a-w- c:\windows\system32\unrar.dll

    2013-01-08 20:29 . 2009-08-11 16:22 580096 —-a-w- c:\windows\system32\ac3filter.acm

    2013-01-08 20:29 . 2009-01-22 20:51 124909 —-a-w- c:\windows\system32\pthreadGC2.dll

    2013-01-08 20:27 . 2013-01-13 20:09 ——– d—–w- c:\program files (x86)\Win7codecs

    2013-01-08 20:27 . 2013-01-13 20:09 ——– d—–w- c:\programdata\Win7codecs

    2013-01-08 20:26 . 2013-01-08 20:26 959976 —-a-w- c:\windows\system32\deployJava1.dll

    2013-01-08 20:26 . 2013-01-08 20:26 308200 —-a-w- c:\windows\system32\javaws.exe

    2013-01-08 20:26 . 2013-01-08 20:26 1081320 —-a-w- c:\windows\system32\npDeployJava1.dll

    2013-01-08 20:26 . 2013-01-08 20:26 188392 —-a-w- c:\windows\system32\javaw.exe

    2013-01-08 20:26 . 2013-01-08 20:26 188392 —-a-w- c:\windows\system32\java.exe

    2013-01-08 20:26 . 2013-01-08 20:26 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll

    2013-01-08 20:26 . 2013-01-08 20:26 ——– d—–w- c:\program files\Java

    2013-01-08 20:26 . 2013-01-08 20:26 ——– d—–w- c:\program files (x86)\Common Files\Java

    2013-01-08 20:25 . 2013-01-08 20:25 859072 —-a-w- c:\windows\SysWow64\npDeployJava1.dll

    2013-01-08 20:25 . 2013-01-08 20:25 779704 —-a-w- c:\windows\SysWow64\deployJava1.dll

    2013-01-08 20:25 . 2013-01-12 02:30 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

    2013-01-08 20:25 . 2013-01-14 19:59 ——– d—–w- c:\program files (x86)\Java

    2013-01-08 20:24 . 2013-01-08 20:24 70584 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2013-01-08 20:24 . 2013-01-08 20:24 691128 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2013-01-08 20:24 . 2013-01-08 20:24 ——– d—–w- c:\windows\SysWow64\Macromed

    2013-01-08 20:24 . 2013-01-08 20:24 ——– d—–w- c:\windows\system32\Macromed

    2013-01-08 20:18 . 2013-01-08 20:18 ——– d—–w- c:\program files\WinRAR

    2013-01-08 19:40 . 2011-03-11 06:41 189824 —-a-w- c:\windows\system32\drivers\storport.sys

    2013-01-08 19:40 . 2011-03-11 06:41 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys

    2013-01-08 19:40 . 2011-03-11 06:41 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys

    2013-01-08 19:40 . 2011-03-11 06:41 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys

    2013-01-08 19:40 . 2011-03-11 06:41 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys

    2013-01-08 19:40 . 2011-03-11 06:41 107904 —-a-w- c:\windows\system32\drivers\amdsata.sys

    2013-01-08 19:40 . 2011-03-11 06:33 2565632 —-a-w- c:\windows\system32\esent.dll

    2013-01-08 19:40 . 2011-03-11 06:30 96768 —-a-w- c:\windows\system32\fsutil.exe

    2013-01-08 19:40 . 2011-03-11 05:33 1699328 —-a-w- c:\windows\SysWow64\esent.dll

    2013-01-08 19:40 . 2011-03-11 05:31 74240 —-a-w- c:\windows\SysWow64\fsutil.exe

    2013-01-08 19:39 . 2011-03-11 04:37 91648 —-a-w- c:\windows\system32\drivers\USBSTOR.SYS

    2013-01-08 19:39 . 2012-07-06 20:07 552960 —-a-w- c:\windows\system32\drivers\bthport.sys

    2013-01-08 19:39 . 2011-04-28 03:54 80384 —-a-w- c:\windows\system32\drivers\BTHUSB.SYS

    2013-01-08 19:39 . 2011-03-25 03:29 325120 —-a-w- c:\windows\system32\drivers\usbport.sys

    2013-01-08 19:39 . 2011-03-25 03:29 52736 —-a-w- c:\windows\system32\drivers\usbehci.sys

    2013-01-08 19:39 . 2011-03-25 03:29 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys

    2013-01-08 19:39 . 2011-03-25 03:29 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys

    2013-01-08 19:39 . 2011-03-25 03:29 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys

    2013-01-08 19:39 . 2011-03-25 03:29 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys

    2013-01-08 19:39 . 2011-03-25 03:28 7936 —-a-w- c:\windows\system32\drivers\usbd.sys

    2013-01-08 19:31 . 2013-01-12 11:27 ——– d—–w- c:\program files (x86)\Microsoft.NET

    2013-01-08 19:31 . 2013-01-18 14:47 ——– d-sh–w- c:\windows\Installer

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-12-12 21:37 . 2012-12-12 21:37 4472832 —-a-w- c:\windows\SysWow64\GPhotos.scr

    2012-11-30 04:45 . 2013-01-08 18:36 44032 —-a-w- c:\windows\apppatch\acwow64.dll

    2012-11-16 12:56 . 2012-11-16 12:56 209808 —-a-w- c:\windows\system32\drivers\eamonm.sys

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    “SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe”

    “Dolby Home Theater v4”=“c:\program files (x86)\Dolby Home Theater v4\pcee4.exe”

    “Cobian Backup 10”=“c:\program files (x86)\Cobian Backup 10\Cobian.exe”

    “Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “BrMfcWnd”=“c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe”

    “ControlCenter3”=“c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe”

    “WinampAgent”=“c:\program files (x86)\Winamp\winampa.exe”

    .

    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    RUN.CMD

    .

    “ConsentPromptBehaviorAdmin”= 0 (0x0)

    “ConsentPromptBehaviorUser”= 0 (0x0)

    “EnableLUA”= 0 (0x0)

    “EnableUIADesktopToggle”= 0 (0x0)

    .

    “NoResolveTrack”= 1 (0x1)

    .

    “aux”=wdmaud.drv

    .

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys

    R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys

    R3 BFNVis64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\XenoVa64.sys

    R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys

    R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys

    R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys

    R3 IAMTVE;Stuurprogramma voor Intel(R) Active Management Technology - KCS;c:\windows\system32\drivers\IAMTVE.sys

    R3 IAMTXPE;Stuurprogramma voor Intel(R) Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXPE.sys

    R3 IFCoEMP;IFCoEMP;c:\windows\system32\drivers\ifM60x64.sys

    R3 IFCoEVB;IFCoEVB;c:\windows\system32\drivers\ifP60X64.sys

    R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys

    R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys

    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys

    R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\drivers\Synth3dVsc.sys

    R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys

    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys

    R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys

    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys

    S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys

    S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files (x86)\Cobian Backup 10\cbVSCService.exe

    S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

    S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys

    S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    S3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys

    S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys

    S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys

    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys

    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys

    .

    .

    — Andere Services/Drivers In Geheugen —

    .

    *NewlyCreated* - 54669820

    *Deregistered* - 54669820

    .

    .

    ——— X64 Entries ———–

    .

    .

    “egui”=“c:\program files\ESET\ESET NOD32 Antivirus\egui.exe”

    “RTHDVCPL”=“c:\program files\Realtek\Audio\HDA\RAVCpl64.exe”

    “RtHDVBg_Dolby”=“c:\program files\Realtek\Audio\HDA\RAVBg64.exe”

    “IgfxTray”=“c:\windows\system32\igfxtray.exe”

    “HotKeysCmds”=“c:\windows\system32\hkcmd.exe”

    “Persistence”=“c:\windows\system32\igfxpers.exe”

    .

    ——- Bijkomende Scan ——-

    .

    uLocal Page = c:\windows\system32\blank.htm

    uStart Page = hxxp://www.google.nl/

    uDefault_Search_URL = hxxp://www.google.com/ie

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uSearchAssistant = hxxp://www.google.com/ie

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

    IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 212.54.40.25 212.54.35.25

    FF - ProfilePath - c:\users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default\

    FF - prefs.js: browser.startup.homepage - hxxp://www.familiehuls.nl/

    FF - ExtSQL: 2013-01-12 16:16; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

    FF - ExtSQL: 2013-01-12 16:18; support@lastpass.com; c:\users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default\extensions\support@lastpass.com

    .

    .

    ——————— VERGRENDELDE REGISTER SLEUTELS ———————

    .

    @Denied: (A 2) (Everyone)

    @=“FlashBroker”

    “LocalizedString”=“@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_108_ActiveX.exe,-101”

    .

    “Enabled”=dword:00000001

    .

    @=“c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_108_ActiveX.exe”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    .

    @Denied: (A 2) (Everyone)

    @=“IFlashBroker5”

    .

    @=“{00020424-0000-0000-C000-000000000046}”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    “Version”=“1.0”

    .

    @Denied: (A 2) (Everyone)

    @=“FlashBroker”

    “LocalizedString”=“@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_108_ActiveX.exe,-101”

    .

    “Enabled”=dword:00000001

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_108_ActiveX.exe”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    .

    @Denied: (A 2) (Everyone)

    @=“Shockwave Flash Object”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_108.ocx”

    “ThreadingModel”=“Apartment”

    .

    @=“0”

    .

    @=“ShockwaveFlash.ShockwaveFlash.11”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_108.ocx, 1”

    .

    @=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”

    .

    @=“1.0”

    .

    @=“ShockwaveFlash.ShockwaveFlash”

    .

    @Denied: (A 2) (Everyone)

    @=“Macromedia Flash Factory Object”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_108.ocx”

    “ThreadingModel”=“Apartment”

    .

    @=“FlashFactory.FlashFactory.1”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_108.ocx, 1”

    .

    @=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”

    .

    @=“1.0”

    .

    @=“FlashFactory.FlashFactory”

    .

    @Denied: (A 2) (Everyone)

    @=“IFlashBroker5”

    .

    @=“{00020424-0000-0000-C000-000000000046}”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    “Version”=“1.0”

    .

    @Denied: (Full) (Everyone)

    .

    Voltooingstijd: 2013-01-24 18:50:04

    ComboFix-quarantined-files.txt 2013-01-24 17:50

    ComboFix2.txt 2013-01-22 17:39

    .

    Pre-Run: 74.354.917.376 bytes beschikbaar

    Post-Run: 74.191.634.432 bytes beschikbaar

    .

    - - End Of File - - E9B9A3AB19FBA31B99A7EC7992174ABD

  • fazantje

    Hoi Ronald,

    Vreemd dat er zomaar spontaan een game te voorschijn komt op IE ondanks dat je deze nooit gebruikt.

    Even een verzoek voor een volgende keer:

    Zou je niet zomaar programma's gaan draaien die niet in het stappenplan staan aangegeven.

    De programma's zo als TDSSkiller en Combofix kunnen in het ergste geval schade aan jou computer brengen.

    In de mee geleverde logjes is niets te zien over het probleem wat jij schreef.

    Doe het volgende eens:

    Download zoek.exe naar het bureaublad.

    Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe

    Dubbelklik op Zoek.exe om de tool te starten.

    Windows Vista, 7 en 8 gebruikers dienen de tool als “administrator” uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.

    Kopieer nu onderstaande code en plak die in het grote invulvenster:

    Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.

    startupall;

    filesrcm;

    Vink nu de onderstaande opties aan.

    (Deze moet je zelf in vullen)

    Standaard Search

    Auto Clean

    Empty All Temp

    Firefox Look

    Chrome Look

    Klik nu op de knop "Run script".

    Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    Post nu de inhoud van het geopende logje in het volgende bericht.

    Succes,

    Huib;)

  • filatelist

    Huib,

    Dank voor je snelle reactie. Die programma's worden hier wel vaker genoemd dus dacht dit kan ik zo wel doen. Mijn excuus hiervoor.

    Hier het zoek logje. Vreemde is dus ook dat het soms een dag helemaal niet naar voren komt die game popup's en dan opeens weer een paar keer kort achter elkaar, en dan weer niet.

    Zoek.exe Version 4.0.0.1 Updated 24-January-2013

    Tool run by Ronald on vr 25-01-2013 at 15:15:18,77.

    Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    ==== Running Processes ======================

    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\Cobian Backup 10\Cobian.exe

    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe

    C:\Program Files (x86)\Winamp\winampa.exe

    C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe

    C:\Program Files (x86)\Cobian Backup 10\cbInterface.exe

    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE

    C:\Program Files (x86)\Nexus Radio\Nexus Radio.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Users\Ronald\Desktop\zoek.exe

    C:\Users\Ronald\AppData\Local\Temp\RarSFX0\zoek.com

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\mshta.exe

    ==== System Specs ======================

    Windows: Windows 7 Ultimate Edition (64-bit) Service Pack 1 (Build 7601)

    Internet Explorer: 9.0.8112.16421

    Memory (RAM): 16302 MB

    CPU Info: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz

    CPU Speed: 3389,3 MHz

    Sound Card: Luidsprekers (Realtek High Defi |

    Realtek Digital Output(Optical) |

    Realtek Digital Output (Realtek |

    Display Adapters: NVIDIA GeForce 8400 GS | NVIDIA GeForce 8400 GS | Intel(R) HD Graphics | Intel(R) HD Graphics | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver

    Monitors: 1x; Algemeen niet-PnP-beeldscherm |

    Screen Resolution: 1920 X 1080 - 32 bit

    Network: Network Present

    Network Adapters: Bluetooth-apparaat (Personal Area Network) | Realtek PCIe GBE Family Controller

    CD / DVD Drives: 2x (G: | H: | ) G: Optiarc DVD RW AD-5280S | H: Optiarc DVD RW AD-5280S

    Ports: COM1 LPT Port NOT Present.

    Mouse: 3 Button Wheel Mouse Present

    Hard Disks: C: 111,8GB | D: 931,5GB | E: 1397,3GB | F: 931,5GB

    Hard Disks - Free: C: 69,4GB | D: 718,6GB | E: 875,3GB | F: 924,2GB

    Manufacturer *: Award Software International, Inc.

    BIOS Info: AT/AT COMPATIBLE | 03/20/12 | GBT - 42302e31

    Time Zone: West-Europa (standaardtijd)

    Motherboard *: Gigabyte Technology Co., Ltd. Z68X-UD3H-B3

    Sun Java version: 1.7.0_11

    Country: Nederland

    Language: NLD

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    2013-01-22 17:34:00 F042EE4C8D66248D9B86DCF52ABAE416 256000 —-a-w- C:\Windows\PEV.exe

    2013-01-22 17:34:00 9E05A9C264C8A908A8E79450FCBFF047 80412 —-a-w- C:\Windows\grep.exe

    2013-01-22 17:34:00 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 —-a-w- C:\Windows\zip.exe

    2013-01-22 17:34:00 0297C72529807322B152F517FDB0A9FC 406528 —-a-w- C:\Windows\SWSC.exe

    2013-01-22 17:34:00 0277C027A26428DB64EF4F64F52BB4FD 208896 —-a-w- C:\Windows\MBR.exe

    2013-01-12 23:16:32 D1D85E071DB722FEE6799BD94346E7D0 93 —-a-w- C:\Windows\brpcfx.ini

    2013-01-12 23:16:32 56430B545BE30EC64E7D5D3981872152 241 —-a-w- C:\Windows\Brpfx04a.ini

    2013-01-12 23:16:18 EC18EF8FA864F4B276879EEACAB7D5E1 434 —-a-w- C:\Windows\BRWMARK.INI

    2013-01-12 23:16:18 75EA639395DD07D90ED78458C7916744 27 —-a-w- C:\Windows\BRPP2KA.INI

    2013-01-12 23:15:26 D41D8CD98F00B204E9800998ECF8427E 0 —-a-w- C:\Windows\brdfxspd.dat

    2013-01-12 14:56:12 2945E52CDE2CCD7E320C317FA3B17AA9 392 —-a-w- C:\Windows\ODBC.INI

    2013-01-12 11:31:39 45013019015A113A142AFBEE4BC4FD1F 1698408 ——r- C:\Windows\RtlExUpd.dll

    2013-01-12 11:28:44 A40AC03F1A016B02D8D951BF82D19307 10 —-a-w- C:\Windows\GSetup.ini

    2013-01-09 16:01:27 DF38961CAB652AF0EA98F218A9BA042B 15867 —-a-w- C:\Windows\noarrow.ico

    2013-01-08 18:36:05 332FEAB1435662FC6C672E25BEB37BE3 2871808 —-a-w- C:\Windows\explorer.exe

    2013-01-08 18:33:32 127AA81343A7C6F665C22CB1293B0A90 67072 —-a-w- C:\Windows\splwow64.exe

    ====== C:\Users\Ronald\AppData\Local\Temp ====

    ====== C:\Windows\SysWOW64 =====

    2013-01-13 08:55:14 C6A44FC3CF2F5801561804272217B14D 1892184 —-a-w- C:\Windows\SysWOW64\D3DX9_42.dll

    2013-01-13 08:55:14 797E24743937D67D69F28F2CF5052EE8 2414360 —-a-w- C:\Windows\SysWOW64\d3dx9_31.dll

    2013-01-12 23:15:26 D884E6B2EDF335AE38A6D860A1240DAF 176128 ——w- C:\Windows\SysWOW64\BroSNMP.dll

    2013-01-12 23:15:26 D6A6E13D8C0E1BAB7FE02015D3E8058B 73728 ——w- C:\Windows\SysWOW64\BrDctF2.dll

    2013-01-12 23:15:26 BE1EAFB5EC2AC86065C39372FF1A8F99 5120 ——w- C:\Windows\SysWOW64\BrDctF2L.dll

    2013-01-12 23:15:26 3256BF7FA0E45C76CA0B0F6F4BFA1B65 12288 ——w- C:\Windows\SysWOW64\BrDctF2S.dll

    2013-01-12 23:15:24 5142D792080F0B8D1CACACCE004DE07A 167936 ——w- C:\Windows\SysWOW64\NSSearch.dll

    2013-01-12 11:48:58 B40DC472472F064A72A01BFC66BF4C0C 52584 —-a-w- C:\Windows\SysWOW64\OpenCL.dll

    2013-01-12 11:32:02 FDDC4D6EC3B2BD3B5A04C22881305621 74064 —-a-w- C:\Windows\SysWOW64\SFCOM.dll

    2013-01-12 11:31:04 59A50FF01D18065CC7A4D884769D636F 577024 —-a-w- C:\Windows\SysWOW64\igdumdx32.dll

    2013-01-12 11:31:03 481F6E1CD63E09F0516B5E78B35D333E 145804 —-a-w- C:\Windows\SysWOW64\igcompkrng600.bin

    2013-01-12 11:31:03 2DAE8EF56FA66F1A76A628CF7B039596 963116 —-a-w- C:\Windows\SysWOW64\igkrng600.bin

    2013-01-12 11:31:03 155F4CBCEE52D4E46FA0DA233C2FFD22 218304 —-a-w- C:\Windows\SysWOW64\igfcg600m.bin

    2013-01-12 11:29:24 7F0A9C71155C2C99E87BE082F63D1174 53248 —-a-r- C:\Windows\SysWOW64\CSVer.dll

    ====== C:\Windows\SysWOW64\drivers =====

    2013-01-12 11:33:38 F39FD2993B86B55082F2AB76C17D660B 8192 —-a-w- C:\Windows\SysWOW64\drivers\IntelMEFWVer.dll

    ====== C:\Windows\Sysnative =====

    2013-01-12 23:15:32 3FC8CD18DA06D8D2F990EF4ECC42AB99 50 —-a-w- C:\Windows\Sysnative\bridf07a.dat

    2013-01-12 23:15:26 646CF36D9F133AD06B4C1D6469EC9DDE 179712 ——w- C:\Windows\Sysnative\BrfxDA5b.dll

    2013-01-12 11:49:08 DDFAFCE89A5C93D04712B86F94E9FCBA 891240 —-a-w- C:\Windows\Sysnative\nvvsvc.exe

    2013-01-12 11:49:08 D7CA52F89A7F4520610FF3682F0E42EE 2557800 —-a-w- C:\Windows\Sysnative\nvsvcr.dll

    2013-01-12 11:49:08 C7BEFB8747FEFBF4350E325850C8D7E5 63336 —-a-w- C:\Windows\Sysnative\nvshext.dll

    2013-01-12 11:49:08 BC2A18841494B3756894627FF279C65E 6200680 —-a-w- C:\Windows\Sysnative\nvcpl.dll

    2013-01-12 11:49:08 4CE5C4F80620D6DBBB054003EAD71F95 3293544 —-a-w- C:\Windows\Sysnative\nvsvc64.dll

    2013-01-12 11:49:08 2B65607ABE1B55CB2B6B06E87D4E6EE6 118120 —-a-w- C:\Windows\Sysnative\nvmctray.dll

    2013-01-12 11:48:58 6FA88320ECA6BF68E750D804C51198D3 60776 —-a-w- C:\Windows\Sysnative\OpenCL.dll

    2013-01-12 11:35:48 960E9E48CECAE388AC145A67D7B6907C 20200 —-a-w- C:\Windows\Sysnative\results.xml

    2013-01-12 11:32:05 F419CC0D724C7044DAE245EC2ED4E348 65432 —-a-w- C:\Windows\Sysnative\tepeqapo64.dll

    2013-01-12 11:32:03 C93EF8EE4A8D85FA39C8C5F9F2885648 2604376 —-a-w- C:\Windows\Sysnative\WavesGUILib.dll

    2013-01-12 11:32:03 2FCADCC14F8E540F6ADE4BF92BD8AEDD 155888 —-a-w- C:\Windows\Sysnative\SRSWOW64.dll

    2013-01-12 11:32:02 ED27D943336C2956DCE43A7B777FAEFE 81248 —-a-w- C:\Windows\Sysnative\SFCOM64.dll

    2013-01-12 11:32:02 D95A37963E504EBE32693F3C2946C4C9 220512 —-a-w- C:\Windows\Sysnative\SFNHK64.dll

    2013-01-12 11:32:02 A88BE9A6C4E646A2B2A1BD3A7F4B58E7 198896 —-a-w- C:\Windows\Sysnative\SRSHP64.dll

    2013-01-12 11:32:02 A028717B791416182959B325D5B40679 211184 —-a-w- C:\Windows\Sysnative\SRSTSH64.dll

    2013-01-12 11:32:02 9C4CF2E875035DBA252A736E424BF37D 78176 —-a-w- C:\Windows\Sysnative\SFAPO64.dll

    2013-01-12 11:32:02 03E343EECFC59323AAD97AACC1BDB275 121744 —-a-w- C:\Windows\Sysnative\SFSS_APO.dll

    2013-01-12 11:32:02 018D3D2478754AA411DE6DA6DE5F8F21 518896 —-a-w- C:\Windows\Sysnative\SRSTSX64.dll

    2013-01-12 11:32:01 4A73114B2BEE7AC77AA7703EB58DD393 332392 —-a-w- C:\Windows\Sysnative\RtlCPAPI64.dll

    2013-01-12 11:32:00 65F2AB70E0CC262AFB0E337BD066CCEA 1827944 —-a-w- C:\Windows\Sysnative\RtkApi64.dll

    2013-01-12 11:32:00 0805289E121F3E3C458C970B08314EB2 149608 —-a-w- C:\Windows\Sysnative\RtkCfg64.dll

    2013-01-12 11:31:59 ED626E3931E6969B510F2D37345864B3 1247848 —-a-w- C:\Windows\Sysnative\RTCOM64.dll

    2013-01-12 11:31:59 625FAA5DA008395D66943A449C4A6637 2432104 —-a-w- C:\Windows\Sysnative\RtPgEx64.dll

    2013-01-12 11:31:59 448E073D8FA3016DBA69EF2421B6F9D9 3150440 —-a-w- C:\Windows\Sysnative\RtkAPO64.dll

    2013-01-12 11:31:58 D0D0D82B7366E691275E433CD34F89B2 375128 —-a-w- C:\Windows\Sysnative\RTEEP64A.dll

    2013-01-12 11:31:58 3B1D07E101EBECCA30F613C65761C57D 1560168 —-a-w- C:\Windows\Sysnative\RTSnMg64.cpl

    2013-01-12 11:31:57 ECAEC5FBBBEF8612AF0A866AFA5F7EF2 101208 —-a-w- C:\Windows\Sysnative\RTEEL64A.dll

    2013-01-12 11:31:57 E9D4A333DF15D06C68AC4BFB9B6581CB 310104 —-a-w- C:\Windows\Sysnative\RP3DAA64.dll

    2013-01-12 11:31:57 B6FE01558CC03F3866C9AD0ED19261D8 310104 —-a-w- C:\Windows\Sysnative\RP3DHT64.dll

    2013-01-12 11:31:57 A6286A6C7A1BBFCBA17AA54384A21D1C 204120 —-a-w- C:\Windows\Sysnative\RTEED64A.dll

    2013-01-12 11:31:57 812F09535CD408049B71BFE612B52AC3 92776 —-a-w- C:\Windows\Sysnative\RCoInst64.dll

    2013-01-12 11:31:57 6F4CD493196100EEF349D7132CECAFD9 78680 —-a-w- C:\Windows\Sysnative\RTEEG64A.dll

    2013-01-12 11:31:57 55347E16E4979ED42B0DF416FE72C77D 1483264 —-a-w- C:\Windows\Sysnative\RCoRes64.dat

    2013-01-12 11:31:54 E0B4052B55114ACD0BFE627AE050E751 136024 —-a-w- C:\Windows\Sysnative\R4EEL64A.dll

    2013-01-12 11:31:54 E05E98B73A089BC6DDADE5577B64D1E6 74072 —-a-w- C:\Windows\Sysnative\R4EEG64A.dll

    2013-01-12 11:31:54 CF171618F3999FEB4F95C77A8C376C92 334680 —-a-w- C:\Windows\Sysnative\MaxxVolumeSDAPO.dll

    2013-01-12 11:31:54 B90443404596E62B2E60A9EEA5FAF5CA 426328 —-a-w- C:\Windows\Sysnative\R4EED64A.dll

    2013-01-12 11:31:54 8D2AF770C4781E11A2AEC2089D5154C5 3308376 —-a-w- C:\Windows\Sysnative\R4EEP64A.dll

    2013-01-12 11:31:54 8B211FFCCC2C08DDC0FD023E70A13DD8 118104 —-a-w- C:\Windows\Sysnative\R4EEA64A.dll

    2013-01-12 11:31:53 8F982624FFFE2779B2965E03A67FE511 3768152 —-a-w- C:\Windows\Sysnative\MaxxAudioRealtek.dll

    2013-01-12 11:31:53 87B5AB256A5A068EDDA0F4B4FAC728CC 2197264 —-a-w- C:\Windows\Sysnative\MaxxAudioEQ.dll

    2013-01-12 11:31:53 03E0955A7D8E5E74E7F6986A56A66196 341336 —-a-w- C:\Windows\Sysnative\MaxxAudioAPO30.dll

    2013-01-12 11:31:52 75616F8DB5C092A8A50AFEC273859DD7 318808 —-a-w- C:\Windows\Sysnative\MaxxAudioAPO20.dll

    2013-01-12 11:31:51 EC422DEC87AFC605D9F5AB7BC397E0FF 603984 —-a-w- C:\Windows\Sysnative\KAAPORT64.dll

    2013-01-12 11:31:47 973D8D0843F65B69DE13B649F5570975 2085440 —-a-w- C:\Windows\Sysnative\FMAPO64.dll

    2013-01-12 11:31:46 F132C08BD8C58579B400DFAA71F34CFB 1756264 —-a-w- C:\Windows\Sysnative\DTSS2SpeakerDLL64.dll

    2013-01-12 11:31:46 DE32448E6B40141C80DAABFF6FBE1744 693352 —-a-w- C:\Windows\Sysnative\DTSVoiceClarityDLL64.dll

    2013-01-12 11:31:46 9948969B2C1987B1D64789EFEB284A84 712296 —-a-w- C:\Windows\Sysnative\DTSSymmetryDLL64.dll

    2013-01-12 11:31:45 FF31A2F57AAAB58DB78FCC961A58B206 428648 —-a-w- C:\Windows\Sysnative\DTSGainCompensatorDLL64.dll

    2013-01-12 11:31:45 F7C357462077156DC211AC2112FC8C53 1568360 —-a-w- C:\Windows\Sysnative\DTSS2HeadphoneDLL64.dll

    2013-01-12 11:31:45 B3977C8BA77559F4F8752AE8EB724C87 242792 —-a-w- C:\Windows\Sysnative\DTSLFXAPO64.dll

    2013-01-12 11:31:45 3B8FB5376F5431C0101747D5138BCB9B 241768 —-a-w- C:\Windows\Sysnative\DTSGFXAPONS64.dll

    2013-01-12 11:31:45 2EF5442E8E7ED20F7634EEFB09640C8F 491112 —-a-w- C:\Windows\Sysnative\DTSNeoPCDLL64.dll

    2013-01-12 11:31:45 192A03A21636D3775CEE4C049C3BEB2A 432744 —-a-w- C:\Windows\Sysnative\DTSLimiterDLL64.dll

    2013-01-12 11:31:44 BC0474E5476E5EA0D0E1AA5AC41E2061 242792 —-a-w- C:\Windows\Sysnative\DTSGFXAPO64.dll

    2013-01-12 11:31:44 8B5A737AD11EF45D9B1AEB4ED6884968 728680 —-a-w- C:\Windows\Sysnative\DTSBassEnhancementDLL64.dll

    2013-01-12 11:31:44 21B38D4D86A87909491F690883AE6D1E 1486952 —-a-w- C:\Windows\Sysnative\DTSBoostDLL64.dll

    2013-01-12 11:31:43 A7138E6FFA25D5281A0E35ABF60D60A9 200800 —-a-w- C:\Windows\Sysnative\AERTAC64.dll

    2013-01-12 11:31:43 973ADB6AD47AC047F900C0D760AB6BE2 108960 —-a-w- C:\Windows\Sysnative\AERTAR64.dll

    2013-01-12 11:31:19 77C7555B9DFE9D11813CB11E093111FC 14848 —-a-w- C:\Windows\Sysnative\IntcDAuC.dll

    2013-01-12 11:31:04 F1288E4CE82EE9F3A00E164BDFA54130 110592 —-a-w- C:\Windows\Sysnative\hccutils.dll

    2013-01-12 11:31:04 4BC67DC2BB58DC6E2A6BCB9B4450B0B8 63488 —-a-w- C:\Windows\Sysnative\igfxsrvc.dll

    2013-01-12 11:31:03 69C261788D6475383798B424CF9E4086 90112 —-a-w- C:\Windows\Sysnative\igfxCoIn_v2418.dll

    2013-01-12 11:31:03 481F6E1CD63E09F0516B5E78B35D333E 145804 —-a-w- C:\Windows\Sysnative\igcompkrng600.bin

    2013-01-12 11:31:03 40DFD4CFB98AB5E4666B0F607CB64921 1981696 —-a-w- C:\Windows\Sysnative\iglhxa64.cpa

    2013-01-12 11:31:03 2DAE8EF56FA66F1A76A628CF7B039596 963116 —-a-w- C:\Windows\Sysnative\igkrng600.bin

    2013-01-12 11:31:03 155F4CBCEE52D4E46FA0DA233C2FFD22 218304 —-a-w- C:\Windows\Sysnative\igfcg600m.bin

    2013-01-12 11:31:03 105CFE016CCB20175BEACEC146F175AB 94208 —-a-w- C:\Windows\Sysnative\IccLibDll_x64.dll

    ====== C:\Windows\Sysnative\drivers =====

    2013-01-12 15:11:23 92EB844D90615CB266F84C3202B8786E 24176 —-a-w- C:\Windows\Sysnative\drivers\mbam.sys

    2013-01-12 11:33:38 F39FD2993B86B55082F2AB76C17D660B 8192 —-a-w- C:\Windows\Sysnative\drivers\IntelMEFWVer.dll

    2013-01-12 11:31:58 98F4E841EA43ED5A442F0DC60CAB4326 3039592 —-a-w- C:\Windows\Sysnative\drivers\RTKVHD64.sys

    2013-01-12 11:31:19 FC727061C0F47C8059E88E05D5C8E381 317440 —-a-w- C:\Windows\Sysnative\drivers\IntcDAud.sys

    2013-01-12 11:14:58 D41D8CD98F00B204E9800998ECF8427E 0 —ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdFs_01_09_00.Wdf

    2013-01-09 11:43:23 FB9FCFFA42FF44F9D10204FC28127A05 157288 —-a-w- C:\Windows\Sysnative\drivers\XenoVa64.sys

    2013-01-09 11:43:23 F5B9183A7F10E8E08BC33D2EABE73739 40144 —-a-w- C:\Windows\Sysnative\drivers\qd160x64.sys

    2013-01-09 11:43:23 E45575812630B049CE0F679D87561A4D 40144 —-a-w- C:\Windows\Sysnative\drivers\qd162x64.sys

    2013-01-09 11:43:23 501A619CAA9C40AFAC89F6F00F278682 41168 —-a-w- C:\Windows\Sysnative\drivers\qd260x64.sys

    2013-01-09 11:43:23 3713DACCA1025B05A6343104112708D9 726160 —-a-w- C:\Windows\Sysnative\drivers\Rt64win7.sys

    2013-01-09 11:43:23 33B114FC0394358DB521828B6F6ACC54 157288 —-a-w- C:\Windows\Sysnative\drivers\Xeno7x64.sys

    2013-01-09 11:43:23 2C23820DD9E81199E60F553EB50BC449 42192 —-a-w- C:\Windows\Sysnative\drivers\qd262x64.sys

    2013-01-09 11:43:22 EA0E9CEAE6041C434AC2954E9AA1CD7A 77584 —-a-w- C:\Windows\Sysnative\drivers\ifP60x64.sys

    2013-01-09 11:43:22 C5B951EAA618AEB33C1348BD11779691 387344 —-a-w- C:\Windows\Sysnative\drivers\ifM60x64.sys

    2013-01-09 11:43:22 8947C98CC212AEEE1FABEC4582F652EE 3341904 —-a-w- C:\Windows\Sysnative\drivers\evbda.sys

    2013-01-09 11:43:22 87A72502C8AC5E89B5A46FF6E874F5C5 43416 —-a-w- C:\Windows\Sysnative\drivers\IAMTVE.sys

    2013-01-09 11:43:22 5516F8E518A2F6A8755498F3E73957CF 51096 —-a-w- C:\Windows\Sysnative\drivers\IAMTXPE.sys

    2013-01-09 11:43:21 CFE42B9C72CD047E478C3B7F4B1FAFFD 88104 —-a-w- C:\Windows\Sysnative\drivers\bxdiaga.sys

    2013-01-09 11:43:21 96858ECF6D017E33A5A1A87E7A1E3206 178216 —-a-w- C:\Windows\Sysnative\drivers\bxfcoe.sys

    2013-01-09 11:43:21 33B60616D5DE1D7FE8B5939D437BC74F 539176 —-a-w- C:\Windows\Sysnative\drivers\bxois.sys

    2013-01-09 11:43:21 1FED668A08CD871ED317A0388CDD4537 529448 —-a-w- C:\Windows\Sysnative\drivers\bxvbda.sys

    2013-01-08 19:40:00 DAB0E87525C10052BF65F06152F37E4A 166272 —-a-w- C:\Windows\Sysnative\drivers\nvstor.sys

    2013-01-08 19:40:00 D4121AE6D0C0E7E13AA221AA57EF2D49 107904 —-a-w- C:\Windows\Sysnative\drivers\amdsata.sys

    2013-01-08 19:40:00 AAAF44DB3BD0B9D1FB6969B23ECC8366 410496 —-a-w- C:\Windows\Sysnative\drivers\iaStorV.sys

    2013-01-08 19:40:00 540DAF1CEA6094886D72126FD7C33048 27008 —-a-w- C:\Windows\Sysnative\drivers\amdxata.sys

    2013-01-08 19:40:00 19CB37AC38B802BE9C441D094521A29A 189824 —-a-w- C:\Windows\Sysnative\drivers\storport.sys

    2013-01-08 19:40:00 0A92CB65770442ED0DC44834632F66AD 148352 —-a-w- C:\Windows\Sysnative\drivers\nvraid.sys

    2013-01-08 19:39:59 FED648B01349A3C8395A5169DB5FB7D6 91648 —-a-w- C:\Windows\Sysnative\drivers\USBSTOR.SYS

    2013-01-08 19:39:49 F188B7394D81010767B6DF3178519A37 80384 —-a-w- C:\Windows\Sysnative\drivers\BTHUSB.SYS

    2013-01-08 19:39:49 C025055FE7B87701EB042095DF1A2D7B 52736 —-a-w- C:\Windows\Sysnative\drivers\usbehci.sys

    2013-01-08 19:39:49 AE259C75F9A0B057B6BF9E9695632B09 325120 —-a-w- C:\Windows\Sysnative\drivers\usbport.sys

    2013-01-08 19:39:49 738D0E9272F59EB7A1449C3EC118E6C4 552960 —-a-w- C:\Windows\Sysnative\drivers\bthport.sys

    2013-01-08 19:39:48 CCA2AB1752A61F29C3C941CD79D78CEA 7936 —-a-w- C:\Windows\Sysnative\drivers\usbd.sys

    2013-01-08 19:39:48 9840FC418B4CBD632D3D0A667A725C31 25600 —-a-w- C:\Windows\Sysnative\drivers\usbohci.sys

    2013-01-08 19:39:48 6F1A3157A1C89435352CEB543CDB359C 98816 —-a-w- C:\Windows\Sysnative\drivers\usbccgp.sys

    2013-01-08 19:39:48 62069A34518BCF9C1FD9E74B3F6DB7CD 30720 —-a-w- C:\Windows\Sysnative\drivers\usbuhci.sys

    2013-01-08 19:39:48 287C6C9410B111B68B52CA298F7B8C24 343040 —-a-w- C:\Windows\Sysnative\drivers\usbhub.sys

    2013-01-08 19:03:26 AEA0A67275CFBA0E463E00C6E9A1DDAE 54376 —-a-w- C:\Windows\Sysnative\drivers\WdfLdr.sys

    2013-01-08 19:03:26 933222B19FF3E7EA5F65517EA1F7D57E 3 —-a-w- C:\Windows\Sysnative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf

    2013-01-08 19:03:26 442783E2CB0DA19873B7A63833FF4CB4 785512 —-a-w- C:\Windows\Sysnative\drivers\Wdf01000.sys

    2013-01-08 18:58:40 EF4469AB69EB15E5D3754E6AEAFBCD3D 29696 —-a-w- C:\Windows\Sysnative\drivers\terminpt.sys

    2013-01-08 18:58:40 AD64450A4ABE076F5CB34CC08EEACB07 30208 —-a-w- C:\Windows\Sysnative\drivers\TsUsbGD.sys

    2013-01-08 18:58:40 313F68E1A3E6345A4F47A36B07062F34 19456 —-a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys

    2013-01-08 18:58:40 17C6B51CBCCDED95B3CC14E22791F85E 57856 —-a-w- C:\Windows\Sysnative\drivers\TsUsbFlt.sys

    2013-01-08 18:50:28 DDA4CAF29D8C0A297F886BFE561E6659 198656 —-a-w- C:\Windows\Sysnative\drivers\WUDFRd.sys

    2013-01-08 18:50:28 AB886378EEB55C6C75B4F2D14B6C869F 87040 —-a-w- C:\Windows\Sysnative\drivers\WUDFPf.sys

    2013-01-08 18:50:28 933222B19FF3E7EA5F65517EA1F7D57E 3 —-a-w- C:\Windows\Sysnative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf

    2013-01-08 18:49:07 6BD9295CC032DD3077C671FCCF579A7B 23408 —-a-w- C:\Windows\Sysnative\drivers\fs_rec.sys

    2013-01-08 18:35:27 AAFCB52FE0037207FB6FBEA070D25EFE 458712 —-a-w- C:\Windows\Sysnative\drivers\cng.sys

    2013-01-08 18:35:27 7EFB9333E4ECCE6AE4AE9D777D9E553E 154480 —-a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys

    2013-01-08 18:34:43 910DD6694848872FD3B8F42BAF801D0A 288624 —-a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS

    2013-01-08 18:34:43 7942B7AC3FF598F8A1736D51ADAF04E8 376688 —-a-w- C:\Windows\Sysnative\drivers\netio.sys

    2013-01-08 18:34:43 37608401DFDB388CAF66917F6B2D6FB0 1914248 —-a-w- C:\Windows\Sysnative\drivers\tcpip.sys

    2013-01-08 18:34:42 1B16D0BD9841794A6E0CDE0CEF744ABC 45568 —-a-w- C:\Windows\Sysnative\drivers\tcpipreg.sys

    2013-01-08 18:34:33 97A7070AEA4C058B6418519E869A63B4 95600 —-a-w- C:\Windows\Sysnative\drivers\ksecdd.sys

    2013-01-08 18:34:07 760E38053BF56E501D562B70AD796B88 950128 —-a-w- C:\Windows\Sysnative\drivers\ndis.sys

    2013-01-08 18:34:06 0E01641D96889BDEB22DE12D30575B08 41472 —-a-w- C:\Windows\Sysnative\drivers\RNDISMP.sys

    2013-01-08 18:33:51 D711B3C1D5F42C0C2415687BE09FC163 288768 —-a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys

    2013-01-08 18:33:50 A5D9106A73DC88564C825D317CAC68AC 158208 —-a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys

    2013-01-08 18:33:50 9423E9D355C8D303E76B8CFBD8A5C30C 128000 —-a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys

    2013-01-08 18:33:27 E453ACF4E7D44E5530B5D5F2B9CA8563 1659760 —-a-w- C:\Windows\Sysnative\drivers\ntfs.sys

    2013-01-08 18:32:35 B4ADEBBF5E3677CCE9651E0F01F7CC28 410112 —-a-w- C:\Windows\Sysnative\drivers\srv2.sys

    2013-01-08 18:32:35 441FBA48BFF01FDB9D5969EBC1838F0B 467456 —-a-w- C:\Windows\Sysnative\drivers\srv.sys

    2013-01-08 18:32:35 27E461F0BE5BFF5FC737328F749538C3 168448 —-a-w- C:\Windows\Sysnative\drivers\srvnet.sys

    2013-01-08 18:32:09 9BBD8B5855BC6578957F82341F9CDE5A 27520 —-a-w- C:\Windows\Sysnative\drivers\Diskdump.sys

    2013-01-08 18:32:02 6C02A83164F5CC0A262F4199F0871CF5 90624 —-a-w- C:\Windows\Sysnative\drivers\bowser.sys

    2013-01-08 18:31:51 E61608AA35E98999AF9AAEEEA6114B0A 210944 —-a-w- C:\Windows\Sysnative\drivers\rdpwd.sys

    2013-01-08 18:31:48 E9766131EEADE40A27DC27D2D68FBA9C 75120 —-a-w- C:\Windows\Sysnative\drivers\partmgr.sys

    2013-01-08 18:31:43 1C7857B62DE5994A75B054A9FD4C3825 498688 —-a-w- C:\Windows\Sysnative\drivers\afd.sys

    2013-01-08 18:20:27 51C5ECEB1CDEE2468A1748BE550CFBC8 23552 —-a-w- C:\Windows\Sysnative\drivers\tdtcp.sys

    ====== C:\Windows\Tasks ======

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    2013-01-12 14:57:17 ——– d—–w- C:\Program Files\AdventurePinballDemo

    2013-01-12 11:48:41 ——– d—–w- C:\Program Files\NVIDIA Corporation

    2013-01-12 11:45:34 ——– d—–w- C:\Program Files\Microsoft Silverlight

    2013-01-12 11:32:20 ——– d—–w- C:\Program Files\Realtek

    2013-01-12 11:31:24 ——– d—–w- C:\Program Files\Common Files\Intel

    2013-01-12 11:26:49 ——– d—–w- C:\Program Files\Microsoft Office

    2013-01-08 20:38:34 ——– d—–w- C:\Program Files\ESET

    2013-01-08 20:29:00 ——– d—–w- C:\Program Files\Shark007

    2013-01-08 20:18:19 ——– d—–w- C:\Program Files\WinRAR

    ======= C:\Program Files (x86) =====

    2013-01-24 16:37:40 ——– d—–w- C:\Program Files (x86)\ESET

    2013-01-13 08:54:51 ——– d—–w- C:\Program Files (x86)\Winamp Detect

    2013-01-13 08:54:47 ——– d—–w- C:\Program Files (x86)\Common Files\PX Storage Engine

    2013-01-13 08:54:44 ——– d—–w- C:\Program Files (x86)\Winamp

    2013-01-12 23:15:24 ——– d—–w- C:\Program Files (x86)\Brother

    2013-01-12 15:29:53 ——– d—–w- C:\Program Files (x86)\Google

    2013-01-12 15:14:32 ——– d—–w- C:\Program Files (x86)\Mozilla Maintenance Service

    2013-01-12 15:03:32 ——– d—–w- C:\Program Files (x86)\Common Files\Adobe

    2013-01-12 15:03:32 ——– d—–w- C:\Program Files (x86)\Adobe

    2013-01-12 14:57:42 ——– d—–w- C:\Program Files (x86)\MahJong Medley

    2013-01-12 14:57:31 ——– d—–w- C:\Program Files (x86)\Dont Angry

    2013-01-12 14:56:46 ——– d—–w- C:\Program Files (x86)\Thinking Blocks

    2013-01-12 14:54:10 ——– d—–w- C:\Program Files (x86)\VS Revo Group

    2013-01-12 14:53:09 ——– d—–w- C:\Program Files (x86)\K-Lite Codec Pack

    2013-01-12 14:51:44 ——– d—–w- C:\Program Files (x86)\CDBurnerXP

    2013-01-12 14:50:48 ——– d—–w- C:\Program Files (x86)\Araneae

    2013-01-12 14:49:38 ——– d—–w- C:\Program Files (x86)\FileZilla FTP Client

    2013-01-12 14:49:12 ——– d—–w- C:\Program Files (x86)\Xiph.Org

    2013-01-12 14:48:46 ——– d—–w- C:\Program Files (x86)\Calibre2

    2013-01-12 14:48:11 ——– d—–w- C:\Program Files (x86)\Cobian Backup 10

    2013-01-12 14:47:32 ——– d—–w- C:\Program Files (x86)\FastCopy

    2013-01-12 14:45:45 ——– d—–w- C:\Program Files (x86)\Nexus Radio

    2013-01-12 14:44:27 ——– d—–w- C:\Program Files (x86)\GrabIt

    2013-01-12 14:39:57 ——– d—–w- C:\Program Files (x86)\Spotnet

    2013-01-12 11:49:12 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation

    2013-01-12 11:45:34 ——– d—–w- C:\Program Files (x86)\Microsoft Silverlight

    2013-01-12 11:44:14 ——– d—–w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2

    2013-01-12 11:33:36 ——– d—–w- C:\Program Files (x86)\Common Files\postureAgent

    2013-01-12 11:32:44 ——– d—–w- C:\Program Files (x86)\Dolby Home Theater v4

    2013-01-12 11:31:43 ——– d–h–w- C:\Program Files (x86)\InstallShield Installation Information

    2013-01-12 11:31:43 ——– d—–w- C:\Program Files (x86)\Realtek

    2013-01-12 11:31:40 ——– d–h–w- C:\Program Files (x86)\Temp

    2013-01-12 11:31:36 ——– d—–w- C:\Program Files (x86)\Common Files\InstallShield

    2013-01-12 11:31:22 ——– d—–w- C:\Program Files (x86)\Common Files\Intel

    2013-01-12 11:29:24 ——– d—–w- C:\Program Files (x86)\Intel

    2013-01-12 11:28:09 ——– d—–w- C:\Program Files (x86)\Microsoft Works

    2013-01-12 11:27:52 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio

    2013-01-12 11:27:52 ——– d—–w- C:\Program Files (x86)\Common Files\DESIGNER

    2013-01-12 11:26:45 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio 8

    2013-01-12 11:26:31 ——– d—–w- C:\Program Files (x86)\Microsoft Office

    2013-01-08 20:27:53 ——– d—–w- C:\Program Files (x86)\Win7codecs

    2013-01-08 19:31:37 ——– d—–w- C:\Program Files (x86)\Microsoft.NET

    ======= C: =====

    2013-01-24 16:35:14 0A00FC6D7EADBA919B212C09F59E4AB8 866 —-a-w- C:\AdwCleaner.txt

    2013-01-12 11:21:52 C37017C621FCE22F4D8D48A8C013BF86 304832 –sh–r- C:\DXUVY

    2013-01-12 11:13:00 8E90FFED9FC33C6240AAC457D9C85FA3 8192 –sha-r- C:\BOOTSECT.BAK

    2013-01-12 11:12:59 259525CFB422E6AC8E87BC9777B1DF73 383786 –sha-r- C:\bootmgr

    ====== C:\Users\Ronald\AppData\Roaming ======

    2013-01-24 17:50:05 ——– d—–w- C:\users\UpdatusUser\AppData\Local\temp

    2013-01-24 17:50:05 ——– d—–w- C:\users\Public\AppData\Local\temp

    2013-01-24 17:50:05 ——– d—–w- C:\users\Default\AppData\Local\temp

    2013-01-24 17:50:05 ——– d—–w- C:\users\Default User\AppData\Local\temp

    2013-01-24 17:50:05 ——– d—–w- C:\users\Administrator\AppData\Local\temp

    2013-01-22 17:35:04 ——– d—–w- C:\users\Ronald\AppData\Local\ESET

    2013-01-18 14:43:00 ——– d—–w- C:\users\Ronald\AppData\Locallow\Adobe

    2013-01-18 14:43:00 ——– d—–w- C:\users\Ronald\AppData\Local\Adobe

    2013-01-18 10:47:06 ——– d—–w- C:\users\Ronald\AppData\Local\Total Availability

    2013-01-16 18:02:30 ——– d—–w- C:\users\Ronald\AppData\Local\Microsoft Games

    2013-01-16 14:33:57 ——– d—–w- C:\users\Ronald\AppData\Roaming\Canneverbe Limited

    2013-01-15 18:22:38 ——– d—–w- C:\users\Ronald\AppData\Roaming\NVIDIA

    2013-01-13 20:09:37 ——– d—–w- C:\users\Ronald\AppData\Roaming\Win7codecs

    2013-01-13 20:09:24 ——– d—–w- C:\users\Administrator\AppData\Roaming\Win7codecs

    2013-01-13 17:05:49 ——– d—–w- C:\users\Ronald\AppData\Roaming\calibre

    2013-01-13 08:54:44 ——– d—–w- C:\users\Ronald\AppData\Roaming\Winamp

    2013-01-12 15:39:39 ——– d—–w- C:\users\Ronald\AppData\Roaming\WinRAR

    2013-01-12 15:29:58 ——– d—–w- C:\users\Ronald\AppData\Local\Google

    2013-01-12 15:18:31 ——– d—–w- C:\users\Ronald\AppData\Locallow\LastPass

    2013-01-12 15:14:46 ——– d—–w- C:\users\Ronald\AppData\Roaming\Mozilla

    2013-01-12 15:14:46 ——– d—–w- C:\users\Ronald\AppData\Local\Mozilla

    2013-01-12 15:11:16 ——– d—–w- C:\users\Ronald\AppData\Local\Programs

    2013-01-12 15:05:20 5CF223DF4371E426F8CB970D12670B5B 109296 —-a-w- C:\users\Ronald\AppData\Local\GDIPFONTCACHEV1.DAT

    2013-01-12 14:49:48 ——– d—–w- C:\users\Ronald\AppData\Roaming\FileZilla

    2013-01-12 14:48:22 ——– d—–w- C:\users\Ronald\AppData\Local\Safe mirror

    2013-01-12 14:47:33 ——– d—–w- C:\users\Ronald\AppData\Roaming\FastCopy

    2013-01-12 14:44:53 ——– d—–w- C:\users\Ronald\AppData\Roaming\GrabIt

    2013-01-12 14:43:52 ——– d—–w- C:\users\Ronald\AppData\Local\Spotnet

    2013-01-12 14:35:41 ——– d—–w- C:\users\Ronald\AppData\Locallow\Sun

    2013-01-12 11:49:12 ——– d-sh–we C:\users\UpdatusUser\AppData\Local\Temporary Internet Files

    2013-01-12 11:49:12 ——– d-sh–we C:\users\UpdatusUser\AppData\Local\Geschiedenis

    2013-01-12 11:49:12 ——– d-sh–we C:\users\UpdatusUser\AppData\Local\Application Data

    2013-01-12 11:49:12 ——– d-s—w- C:\users\UpdatusUser\AppData\Roaming\Microsoft

    2013-01-12 11:49:12 ——– d—–w- C:\users\UpdatusUser\AppData\Roaming\Media Center Programs

    2013-01-12 11:49:12 ——– d—–w- C:\users\UpdatusUser\AppData\Local\Microsoft

    2013-01-12 11:37:32 ——– d—–w- C:\users\Ronald\AppData\Roaming\Adobe

    2013-01-12 11:33:24 ——– d—–w- C:\users\Ronald\AppData\Roaming\InstallShield

    2013-01-12 11:26:32 ——– d—–w- C:\users\Ronald\AppData\Local\Microsoft Help

    2013-01-12 11:26:01 ——– d-s—w- C:\users\Ronald\AppData\Locallow\Microsoft

    2013-01-12 11:22:51 ——– d—–w- C:\users\Ronald\AppData\Roaming\Identities

    2013-01-12 11:21:58 ——– d-sh–we C:\users\Ronald\AppData\Local\Temporary Internet Files

    2013-01-12 11:21:58 ——– d-sh–we C:\users\Ronald\AppData\Local\Geschiedenis

    2013-01-12 11:21:58 ——– d-sh–we C:\users\Ronald\AppData\Local\Application Data

    2013-01-12 11:21:58 ——– d-s—w- C:\users\Ronald\AppData\Roaming\Microsoft

    2013-01-12 11:21:58 ——– d—–w- C:\users\Ronald\AppData\Roaming\Media Center Programs

    2013-01-12 11:21:58 ——– d—–w- C:\users\Ronald\AppData\Local\Temp

    2013-01-12 11:21:58 ——– d—–w- C:\users\Ronald\AppData\Local\Microsoft

    2013-01-12 11:21:36 ——– d-sh–we C:\users\Default\AppData\Local\Geschiedenis

    2013-01-12 11:21:36 ——– d-sh–we C:\users\Default User\AppData\Local\Geschiedenis

    ====== C:\Users\Ronald ======

    2013-01-22 17:39:40 ——– d—–w- C:\Users\Public\AppData

    2013-01-18 10:47:06 ——– d—–w- C:\Users\Ronald\zeZebra Inbox

    2013-01-16 14:33:57 ——– d—–w- C:\ProgramData\Canneverbe Limited

    2013-01-16 14:16:27 ——– d—–w- C:\ProgramData\TEMP

    2013-01-13 20:09:24 ——– d—–w- C:\Users\Administrator\AppData

    2013-01-12 23:15:08 ——– d—–w- C:\ProgramData\Brother

    2013-01-12 15:14:32 ——– d—–w- C:\ProgramData\Mozilla

    2013-01-12 15:03:07 ——– d—–w- C:\ProgramData\Adobe

    2013-01-12 14:39:57 ——– d—–w- C:\ProgramData\Spotnet

    2013-01-12 11:49:12 6FC234AD3752E1267B34FB12BCD6718B 20 –sh–w- C:\Users\UpdatusUser\ntuser.ini

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Sjablonen

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\SendTo

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Recent

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Netwerkprinteromgeving

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\NetHood

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Mijn documenten

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Menu Start

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Local Settings

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Cookies

    2013-01-12 11:49:12 ——– d-sh–we C:\Users\UpdatusUser\Application Data

    2013-01-12 11:49:12 ——– d–h–w- C:\Users\UpdatusUser\AppData

    2013-01-12 11:49:12 ——– d—–w- C:\Users\UpdatusUser\Searches

    2013-01-12 11:49:12 ——– d—–w- C:\Users\UpdatusUser\Saved Games

    2013-01-12 11:49:12 ——– d—–w- C:\Users\UpdatusUser\Contacts

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Videos

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Pictures

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Music

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Links

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Favorites

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Downloads

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Documents

    2013-01-12 11:49:12 ——– d—–r- C:\Users\UpdatusUser\Desktop

    2013-01-12 11:49:11 ——– d—–w- C:\ProgramData\NVIDIA

    2013-01-12 11:48:49 ——– d—–w- C:\ProgramData\NVIDIA Corporation

    2013-01-12 11:26:31 ——– d—–w- C:\ProgramData\Microsoft Help

    2013-01-12 11:23:01 ——– d—–r- C:\Users\Ronald\Searches

    2013-01-12 11:22:50 ——– d—–r- C:\Users\Ronald\Contacts

    2013-01-12 11:21:58 6FC234AD3752E1267B34FB12BCD6718B 20 –sh–w- C:\Users\Ronald\ntuser.ini

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Sjablonen

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\SendTo

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Recent

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Netwerkprinteromgeving

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\NetHood

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Mijn documenten

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Menu Start

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Local Settings

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Cookies

    2013-01-12 11:21:58 ——– d-sh–we C:\Users\Ronald\Application Data

    2013-01-12 11:21:58 ——– d–h–w- C:\Users\Ronald\AppData

    2013-01-12 11:21:58 ——– d—–r- C:\Users\Ronald\Links

    2013-01-12 11:21:58 ——– d—–r- C:\Users\Ronald\Favorites

    2013-01-12 11:21:58 ——– d—–r- C:\Users\Ronald\Desktop

    2013-01-12 11:21:36 ——– d-sh–we C:\Users\Default\Sjablonen

    2013-01-12 11:21:36 ——– d-sh–we C:\Users\Default\Netwerkprinteromgeving

    2013-01-12 11:21:36 ——– d-sh–we C:\Users\Default\Mijn documenten

    2013-01-12 11:21:36 ——– d-sh–we C:\Users\Default\Menu Start

    2013-01-12 11:21:36 ——– d-sh–we C:\ProgramData\Sjablonen

    2013-01-12 11:21:36 ——– d-sh–we C:\ProgramData\Menu Start

    2013-01-12 11:21:36 ——– d-sh–we C:\ProgramData\Favorieten

    2013-01-12 11:21:36 ——– d-sh–we C:\ProgramData\Documenten

    2013-01-12 11:21:36 ——– d-sh–we C:\ProgramData\Bureaublad

    2013-01-08 20:38:34 ——– d—–w- C:\ProgramData\ESET

    2013-01-08 20:29:01 ——– d—–w- C:\ProgramData\Shark007

    2013-01-08 20:27:37 ——– d—–w- C:\ProgramData\Win7codecs

    2013-01-08 20:26:03 ——– d—–w- C:\ProgramData\Sun

    ====== C: exe-files ==

    2013-01-24 16:37:46 C5AE6C22277C68BDA3BA8F17A192BC78 2347384 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

    2013-01-24 16:37:46 B751AAFE4363D2AA29AE056291D50468 575784 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe

    2013-01-24 16:37:46 5B339084BB3D5DEC9F73458A104245D1 538704 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScannerA.exe

    2013-01-24 16:37:46 54DC905A55BB7315B7316038FE848D5B 546944 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe

    2013-01-24 16:37:46 39C7334C28FA1DF222281C4A2AFFF695 122584 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe

    2013-01-22 17:34:00 F042EE4C8D66248D9B86DCF52ABAE416 256000 —-a-w- C:\Windows\PEV.exe

    2013-01-22 17:34:00 9E05A9C264C8A908A8E79450FCBFF047 80412 —-a-w- C:\Windows\grep.exe

    2013-01-22 17:34:00 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 —-a-w- C:\Windows\zip.exe

    2013-01-22 17:34:00 0297C72529807322B152F517FDB0A9FC 406528 —-a-w- C:\Windows\SWSC.exe

    2013-01-22 17:34:00 0277C027A26428DB64EF4F64F52BB4FD 208896 —-a-w- C:\Windows\MBR.exe

    === C: other files ==

    2013-01-24 16:37:46 F8D176DB5B14AED7C9B25E0640226BD1 258352 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\unicows.dll

    2013-01-24 16:37:46 B4FCBD36F2E93E8689876639AF6A35DE 637584 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\esets_apiW_a.dll

    2013-01-24 16:37:46 7F76BA71412B3715E99BFBEBA9EE3FE4 476904 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\esets_apiA.dll

    2013-01-24 16:37:46 7E4597A397FFEF6919FF6C611149A2E7 324464 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerLang.dll

    2013-01-24 16:37:46 2329E6A4BDCA2AA2DF172F3F87637963 493384 —-a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\esets_apiW.dll

    ==== Startup Registry Enabled ======================

    “Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /autoRun”

    “mctadmin”=“C:\Windows\System32\mctadmin.exe”

    “SunJavaUpdateSched”=“C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”

    “Dolby Home Theater v4”=“C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe -autostart”

    “Cobian Backup 10”=“C:\Program Files (x86)\Cobian Backup 10\Cobian.exe”

    “Adobe ARM”=“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “BrMfcWnd”=“C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN”

    “ControlCenter3”=“C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun”

    “WinampAgent”=“C:\Program Files (x86)\Winamp\winampa.exe”

    ==== Startup Folders ======================

    2013-01-09 16:03:35 289 —-a-w- C:\users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RUN.CMD

    2013-01-09 16:03:35 289 —-a-w- C:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RUN.CMD

    2013-01-12 11:49:12 289 —-a-w- C:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RUN.CMD

    ==== Firefox Extensions ======================

    ProfilePath: C:\Users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default

    - LastPass - %ProfilePath%\extensions\support@lastpass.com

    - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

    AppDir: C:\Program Files (x86)\Mozilla Firefox

    - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

    ==== Firefox Plugins ======================

    Profilepath: C:\Users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\ikbh7m58.default

    CF28AD14811DB6B2D92D49EC3E26610C - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_108.dll - Shockwave Flash

    ==== Set IE to Default ======================

    Old Values:

    “Start Page”=“http://www.google.nl/”

    “Default_Search_URL”=“http://www.google.com/ie”

    @=“http://www.google.com/search?q=%s”

    “SearchAssistant”=“http://www.google.com/ie”

    “Default_Search_URL”=“http://www.google.com/ie”

    “DefaultScope”=“{0633EE93-D776-472f-A0FF-E1416B8B2E3A}”

    not found

    New Values:

    “Default_Search_URL”=“http://go.microsoft.com/fwlink/?LinkId=54896”

    “Start Page”=“http://www.google.nl/”

    “(Default)”=“http://search.msn.com/results.asp?q=%s”

    “Default_Search_URL”=“http://go.microsoft.com/fwlink/?LinkId=54896”

    “SearchAssistant”=“http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm”

    “DefaultScope”=“{6A1806CD-94D4-4689-BA73-E35EA1EA9990}”

    ==== All HKCU SearchScopes ======================

    HKCU\*\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=“http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC”

    HKCU\*\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url=“http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}”

    HKCU\*\SearchScopes\{803CA8DA-0935-49A8-9241-3BAB8D6C4C66} Google Url=“http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8”

    ==== HijackThis Entries ======================

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL

    O11 - Options group: Accelerated graphics

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: Cobian Backup 10 Volume Shadow Copy service (cbVSCService) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 10\cbVSCService.exe

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

    C:\Users\Ronald\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0E2S3L10 will be deleted at reboot

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C4WSE36W will be deleted at reboot

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P0ZL172G will be deleted at reboot

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S8BYSXA4 will be deleted at reboot

    C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    C:\users\Ronald\AppData\Local\Mozilla\Firefox\Profiles\ikbh7m58.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    No Chrome User Data found

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    After Reboot

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Ronald\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    “C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat” not found

    “C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0E2S3L10” not found

    “C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C4WSE36W” not found

    “C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P0ZL172G” not found

    “C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S8BYSXA4” not found

  • filatelist

    Ben ondertussen erachter gekomen wat de veroorzaker is van die spelletjes sites. Kreeg vanmiddag een dating site te zien.

    Nexus Radio het programma wat ik gebruik voor radio luisteren is de veroorzaker hiervan. Die zelfde dating site stond namelijk met een banner in het programma zelf.

    Ik aan een virus denken is het dus dit programma die het doet, en die staat niet altijd open, dus vandaar dat het ook niet constant verschijnt maar af en toe.

    Probleem dus bekend wat het is, geen virus.

  • fazantje

    Hoi Ronald,

    Mooi dat je de oorzaak hebt gevonden(tu)

    Een bijkomende zaak is dat je nu ook weet dat jou computer geen besmettingen bevat.

    ADWcleaner en Zoek exe kun je verwijderen.

    Combofix verwijder je op de volgende manier:

    Download OTC exe hier, om combo weer helemaal te verwijderen.

    Plaats het bestand op je bureaublad.

    Zorg dat er een internetverbinding is.

    Klik vervolgens met je rechtermuisknop op OTCleanIt.exe en kies voor Run as Administrator (Nederlands: Uitvoeren als Administrator) om het programma te starten.

    Lukt dat niet , dan dubbelklikken op het icoon.

    Klik nu op de knop "CleanUp!"

    Als je firewall, of een ander beveiligingsprogramma, een waarschuwing geeft dat OTC.exe internettoegang wil, mag je dit toestaan, het programma heeft die connectie nodig.

    OTC zal als laatste vragen of je de computer herstarten wilt, dit mag je toestaan, hiermee verwijdert het zichzelf ook.

    Groetjes Huib;)

  • filatelist

    Huib,

    Dank voor je uitleg omtrent verwijdering programma's. En mooi om te lezen dat mijn computer verder helemaal schoon is.

  • fazantje

    Omdat dit topic is opgelost word het gesloten.

    Wilt U Uw topic als nog weer openen, stuur dan een privé bericht naar Ben of Huib (fazantje).

    Zij zullen dan het “slotje” er van af halen en het topic is weer geopend.

    Het AV team.

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.