Antivirus werkt niet meer

  • Frank

    Prima, hierna het log:

    DDS (Ver_2012-11-20.01) - NTFS_AMD64

    Internet Explorer: 10.0.9200.16611 BrowserJavaVersion: 10.15.2

    Run by Frank at 16:11:42 on 2013-07-03

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4087.2178

    .

    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    FW: avast! Antivirus *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}

    .

    ============== Running Processes ===============

    .

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\nvvsvc.exe

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe

    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

    C:\Windows\system32\nvvsvc.exe

    C:\Windows\system32\Hpservice.exe

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe

    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

    C:\Windows\SysWOW64\svchost.exe -k netsvcs

    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Windows\System32\svchost.exe -k HPZ12

    C:\Windows\System32\svchost.exe -k HPZ12

    C:\Program Files (x86)\Remote Access Host\RemotePCM.exe

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Windows\system32\UI0Detect.exe

    C:\Windows\system32\svchost.exe -k HPService

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\servicing\TrustedInstaller.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

    C:\Windows\system32\taskeng.exe

    c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

    c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe

    c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe

    C:\Program Files\IDT\WDM\sttray64.exe

    C:\Users\Frank\AppData\Local\Akamai\netsession_win.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

    C:\Users\Frank\AppData\Local\Akamai\netsession_win.exe

    C:\Program Files (x86)\Sitecom\Common\RaUI.exe

    C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

    C:\Program Files\AVAST Software\Avast\AvastUI.exe

    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

    C:\Program Files (x86)\iTunes\iTunesHelper.exe

    C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Windows\System32\MsSpellCheckingFacility.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe

    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    C:\Windows\System32\cscript.exe

    .

    ============== Pseudo HJT Report ===============

    .

    uStart Page = hxxp://www.google.nl/

    uProxyOverride =

    uURLSearchHooks: {46735dee-f862-49d1-876d-6382794dc625} -

    mWinlogon: Userinit = userinit.exe,

    BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\Hp\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -

    BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

    BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\Hp\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\Hp\Digital Imaging\Smart Web Printing\hpswp_bho.dll

    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\Hp\Digital Imaging\Smart Web Printing\hpswp_bho.dll

    uRun: “C:\Users\Frank\AppData\Local\Akamai\netsession_win.exe”

    uRun: “C:\Program Files (x86)\Electronic Arts\EADM\Core.exe” -silent

    mRun: “c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe” “c:\Program Files (x86)\Hewlett-Packard\Media\Webcam” UpdateWithCreateOnce “Software\Hewlett-Packard\Media\Webcam”

    mRun: “C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe” “C:\Program Files (x86)\Hewlett-Packard\Recovery” UpdateWithCreateOnce “Software\CyberLink\PowerRecover”

    mRun: C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe

    mRun: C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    mRun: “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”

    mRun: C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

    mRun: “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”

    mRun: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    mRun: “C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui

    mRun: “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime

    mRun: “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”

    mRun: “C:\Program Files (x86)\iTunes\iTunesHelper.exe”

    StartupFolder: C:\Users\Frank\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SITECO~1.LNK - C:\Program Files (x86)\Sitecom\Common\RaUI.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WDDMST~1.LNK - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WDSMAR~1.LNK - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe

    mPolicies-Explorer: NoActiveDesktop = dword:1

    mPolicies-Explorer: NoActiveDesktopChanges = dword:1

    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

    mPolicies-System: ConsentPromptBehaviorUser = dword:3

    mPolicies-System: EnableUIADesktopToggle = dword:0

    mPolicies-System: HideFastUserSwitching = dword:0

    IE: Afbeelding verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

    IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

    IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

    IE: Pagina verzenden naar &Bluetooth-apparaat… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll

    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\Hp\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

    DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/nl-NL/wlscctrl2.cab

    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1259.cab

    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

    DPF: {A8203263-E018-4106-BDBE-8BF6915E8190} - hxxps://download.infotriever.com/bin/ifhelper.cab

    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

    DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx

    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    TCP: NameServer = 192.168.0.1

    TCP: Interfaces\{E584EE1A-E458-4BA4-9036-EFA871078213} : DHCPNameServer = 192.168.0.1

    TCP: Interfaces\{E584EE1A-E458-4BA4-9036-EFA871078213}\377796373736F6D6 : DHCPNameServer = 192.168.48.1

    TCP: Interfaces\{E584EE1A-E458-4BA4-9036-EFA871078213}\65940535F534C455244454D41425 : DHCPNameServer = 194.179.1.100 194.179.1.101 80.58.0.33

    TCP: Interfaces\{E584EE1A-E458-4BA4-9036-EFA871078213}\745554354535F534C455244454D41425 : DHCPNameServer = 80.58.0.33

    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll

    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    SSODL: WebCheck -

    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - “C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe”

    x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -

    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

    x64-Run: C:\Program Files\IDT\WDM\sttray64.exe

    x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    x64-DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

    x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab

    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -

    x64-SSODL: WebCheck -

    .

    ================= FIREFOX ===================

    .

    FF - ProfilePath - C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\fb3p5lov.default\

    FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll

    FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll

    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    FF - plugin: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll

    FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll

    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

    FF - ExtSQL: 2013-07-01 18:40; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn

    FF - ExtSQL: 2013-07-01 18:40; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn

    FF - ExtSQL: !HIDDEN! 2010-08-27 18:52; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys

    R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys

    R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys

    R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys

    R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys

    R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe

    R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys

    R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys

    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe

    R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\System32\svchost.exe -k netsvcs

    R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe

    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    R2 remotepc;RemotePC HOST;C:\Program Files (x86)\Remote Access Host\RemotePCM.exe

    R2 WDDMService;WD SmartWare Drive Manager Service;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

    R2 WDSmartWareBackgroundService;WD SmartWare Background Service;C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

    R3 enecir;ENE CIR Receiver;C:\Windows\System32\drivers\enecir.sys

    R3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys

    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys

    R3 NETw5s64;Intel(R) Wireless WiFi Link adapter stuurprogramma onder Windows 7 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys

    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe

    S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys

    S3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys

    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS

    S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS

    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS

    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys

    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys

    S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe

    S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys

    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys

    .

    =============== Created Last 30 ================

    .

    2013-07-03 11:59:45 ——– d-sh–w- C:\$RECYCLE.BIN

    2013-07-03 11:54:24 24064 —-a-w- C:\Windows\zoek-delete.exe

    2013-07-03 11:54:24 ——– d—–w- C:\Users\Frank\AppData\Local\Temp

    2013-07-03 07:54:50 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys

    2013-07-03 07:54:50 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

    2013-07-01 20:41:48 ——– d—–w- C:\Program Files\trend micro

    2013-07-01 16:39:16 ——– d—–w- C:\Program Files\Common Files\Symantec Shared

    2013-07-01 15:26:35 99384 —-a-w- C:\Users\Frank\AppData\Roaming\inst.exe

    2013-07-01 15:26:35 82816 —-a-w- C:\Users\Frank\AppData\Roaming\pcouffin.sys

    2013-07-01 15:25:25 ——– d—–w- C:\Program Files (x86)\ESET

    2013-06-21 15:22:36 ——– d—–w- C:\89162dd95fe763cf66e0

    2013-06-16 09:01:00 2706432 —-a-w- C:\Windows\System32\mshtml.tlb

    2013-06-12 19:05:37 9089416 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

    2013-06-11 18:09:50 1910632 —-a-w- C:\Windows\System32\drivers\tcpip.sys

    2013-06-04 17:02:33 ——– d—–w- C:\Users\Frank\AppData\Roaming\Wargaming.net

    2013-06-03 21:57:46 ——– d—–w- C:\Windows\SysWow64\directx

    .

    ==================== Find3M ====================

    .

    2013-06-27 19:14:11 189936 —-a-w- C:\Windows\System32\drivers\aswVmm.sys

    2013-06-27 19:14:10 1030952 —-a-w- C:\Windows\System32\drivers\aswSnx.sys

    2013-06-12 19:05:52 71048 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

    2013-06-12 19:05:52 692104 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

    2013-06-08 11:13:19 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb

    2013-05-17 01:25:57 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll

    2013-05-17 01:25:27 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll

    2013-05-17 01:25:26 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll

    2013-05-17 01:25:26 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll

    2013-05-17 00:59:03 2241024 —-a-w- C:\Windows\System32\wininet.dll

    2013-05-17 00:58:10 3958784 —-a-w- C:\Windows\System32\jscript9.dll

    2013-05-17 00:58:08 67072 —-a-w- C:\Windows\System32\iesetup.dll

    2013-05-17 00:58:08 136704 —-a-w- C:\Windows\System32\iesysprep.dll

    2013-05-14 12:23:25 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2013-05-14 08:40:13 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe

    2013-05-13 05:51:01 184320 —-a-w- C:\Windows\System32\cryptsvc.dll

    2013-05-13 05:51:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll

    2013-05-13 05:51:00 139776 —-a-w- C:\Windows\System32\cryptnet.dll

    2013-05-13 05:50:40 52224 —-a-w- C:\Windows\System32\certenc.dll

    2013-05-13 04:45:55 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll

    2013-05-13 04:45:55 1160192 —-a-w- C:\Windows\SysWow64\crypt32.dll

    2013-05-13 04:45:55 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll

    2013-05-13 03:43:55 1192448 —-a-w- C:\Windows\System32\certutil.exe

    2013-05-13 03:08:10 903168 —-a-w- C:\Windows\SysWow64\certutil.exe

    2013-05-13 03:08:06 43008 —-a-w- C:\Windows\SysWow64\certenc.dll

    2013-05-10 05:49:27 30720 —-a-w- C:\Windows\System32\cryptdlg.dll

    2013-05-10 03:20:54 24576 —-a-w- C:\Windows\SysWow64\cryptdlg.dll

    2013-05-09 08:59:07 72016 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys

    2013-05-09 08:59:07 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys

    2013-05-09 08:59:06 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys

    2013-05-09 08:59:06 22600 —-a-w- C:\Windows\System32\drivers\aswKbd.sys

    2013-05-09 08:58:37 41664 —-a-w- C:\Windows\avastSS.scr

    2013-04-26 05:51:36 751104 —-a-w- C:\Windows\System32\win32spl.dll

    2013-04-26 04:55:21 492544 —-a-w- C:\Windows\SysWow64\win32spl.dll

    2013-04-25 23:30:32 1505280 —-a-w- C:\Windows\SysWow64\d3d11.dll

    2013-04-17 07:02:06 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll

    2013-04-17 06:24:46 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll

    2013-04-13 05:49:23 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll

    2013-04-13 05:49:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll

    2013-04-13 05:49:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll

    2013-04-13 05:49:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll

    2013-04-13 04:45:16 474624 —-a-w- C:\Windows\apppatch\AcSpecfc.dll

    2013-04-13 04:45:15 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll

    2013-04-12 14:45:08 1656680 —-a-w- C:\Windows\System32\drivers\ntfs.sys

    2013-04-10 06:01:54 265064 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys

    2013-04-10 06:01:53 983400 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys

    2013-04-10 03:30:50 3153920 —-a-w- C:\Windows\System32\win32k.sys

    .

    ============= FINISH: 16:12:52,86 ===============

  • Ben

    Hallo,

    We gaan de goede kant op.

    Kijk eens wat er in deze dik gedrukte map zit: C:\89162dd95fe763cf66e0

    Voer nu AdwCleaner uit en plaats hier het verkregen logje.

    Gr.Ben

  • Frank

    Het lijkt er inderdaad op, mijn Avast heetf al een hele tijd geen alarm geslagen en dat gebeurde best regelmatig!

    Hierna het Adx-Log:

    # AdwCleaner v2.303 - Verslag gemaakt op 03/07/2013 om 16:25:01

    # Geactualiseerd op 08/06/2013 door Xplode

    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Gebruiker : Frank - FRANK-PC

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : C:\Users\Frank\Desktop\adwcleaner.exe

    # Optie

    ***** *****

    ***** *****

    ***** *****

    Sleutel Aanwezig : HKCU\Software\1ClickDownload

    Sleutel Aanwezig : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

    Sleutel Aanwezig : HKCU\Software\Softonic

    Sleutel Aanwezig : HKCU\Software\YahooPartnerToolbar

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\34faae0dcfd1e8d23e8cfdf2184c4f79

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\73a13abf6b9ebe4d769bb50d27271b98

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7CD74AFF-3433-4E34-92E2-D98DFDB30754}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

    ***** *****

    -\\ Internet Explorer v10.0.9200.16611

    Het register bevat geen enkele ongeoorloofde invoer.

    -\\ Mozilla Firefox v22.0 (nl)

    File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js

    De file bevat geen enkele ongeoorloofde invoer.

    File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\fb3p5lov.default\prefs.js

    De file bevat geen enkele ongeoorloofde invoer.

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner.txt - ##########

  • Ben

    Hallo,

    Kijk eens wat er in deze dik gedrukte map zit: C:\89162dd95fe763cf66e0

    Gr.Ben

  • Frank

    Sorry Ben,

    Ik maak er even een rommel van. Ik was zo blij met de vooruitgang dat ik geen goede scan heb gemaakt. Deze zou wel goed moeten zijn.

    De map heb ik bekeken maar daar staat iets over add-ons bij Firefox. Ik gebruik die eigenlijk nooit, dus ben ik te snel als ik zeg: wegwezen met die hap?

    Het log:

    # AdwCleaner v2.303 - Verslag gemaakt op 03/07/2013 om 16:30:12

    # Geactualiseerd op 08/06/2013 door Xplode

    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Gebruiker : Frank - FRANK-PC

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : C:\Users\Frank\Desktop\adwcleaner.exe

    # Optie

    ***** *****

    ***** *****

    ***** *****

    Sleutel Verwijderd : HKCU\Software\1ClickDownload

    Sleutel Verwijderd : HKCU\Software\Softonic

    Sleutel Verwijderd : HKCU\Software\YahooPartnerToolbar

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\34faae0dcfd1e8d23e8cfdf2184c4f79

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\73a13abf6b9ebe4d769bb50d27271b98

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7CD74AFF-3433-4E34-92E2-D98DFDB30754}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof

    Sleutel Verwijderd : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

    Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

    ***** *****

    -\\ Internet Explorer v10.0.9200.16611

    Het register bevat geen enkele ongeoorloofde invoer.

    -\\ Mozilla Firefox v22.0 (nl)

    File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js

    De file bevat geen enkele ongeoorloofde invoer.

    File : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\fb3p5lov.default\prefs.js

    De file bevat geen enkele ongeoorloofde invoer.

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner.txt - ##########

  • Ben

    Hallo,

    >>>De map heb ik bekeken maar daar staat iets over add-ons bij Firefox. Ik gebruik die eigenlijk nooit, dus ben ik te snel als ik zeg: wegwezen met die hap? <<<

    Ze eten geen brood dus laat ze maar staan.

    AdwCleaner is zo netjes uit gevoerd.

    Hoe draait de pc nu?

    Gr.Ben

  • Frank

    Akkoord.

    Nou, ik moet zeggen dat de boel weer een stabiele indruk maakt. Ik hoor/zie geen Avastmeldingen meer en ik heb net even geprobeerd of ik nu wel CC Cleaner kon downloaden en laten draaien. Nu lukte dat inderdaad weer. Ik ben helemaal blij! Zijn we er zo of moeten er nog dingen worden gedaan?

  • Ben

    Hallo,

    Even kijken of alles geüpdatete is.

    Download: http://www.bleepingcomputer.com/download/securitycheck/ en sla het op je Bureaublad op.

    Start Security Check.

    Volg de Instructies in het scherm.

    Aan het eind verschijnt een log (checkup.txt) plaats de inhoud ervan in je volgende antwoord.

    Gr.Ben

  • Frank

    Oh, zoveel service ben ik niet gewend, ik was even koken. Hieronder het log:

    Results of screen317's Security Check version 0.99.68

    Windows 7 Service Pack 1 x64 (UAC is enabled)

    Internet Explorer 10

    ``````````````Antivirus/Firewall Check:``````````````

    avast! Antivirus

    Antivirus up to date!

    `````````Anti-malware/Other Utilities Check:`````````

    Java 7 Update 15

    Java version out of Date!

    Adobe Flash Player 11.7.700.224

    Adobe Reader 9 Adobe Reader out of Date!

    Mozilla Firefox (22.0)

    ````````Process Check: objlist.exe by Laurent````````

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C: 0%

    ````````````````````End of Log``````````````````````

  • Ben

    Hallo,

    Kom zo eten (:P)

    Update alles wat rood aangegeven woord.

    Met het onderstaande tooltje ruim je o.a. alle gebruikte tools op:

    Download

    Delfix by Xplode naar het bureaublad.

    Dubbelklik op Delfix.exe om de tool te starten.

    Zet nu vinkjes voor de volgende items:

    Remove disinfection tools

    Create registry backup

    Purge System Restore

    Reset system settings

    Klik nu op "Run" en wacht geduldig tot de tool gereed is.

    Wanneer de tool gereed is wordt er een logbestand aangemaakt. Dit hoeft je echter niet te plaatsen.

    Mochten er nog tools overgebleven zijn dan kan je die zelf verwijderen.

    Hierna is alles oke.

    Gr.Ben

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.