Heb last van een trage laptop. Volgens de instructies heb ik de diverse scans uitgevoerd. Bij deze post ik dan mijn logbestanden. Wie is zo vriendelijk hier naar te kijken? Alvast bedankt voor jullie tijd.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Linda at 2013-08-10 16:18:29
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 423 MB (1%) free of 58 GB
Total RAM: 2038 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:19:03, on 10-08-2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16496)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Users\Linda\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Linda\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Linda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Linda\AppData\Roaming\Spotify\spotify.exe
C:\Users\Linda\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Users\Linda\AppData\Local\Akamai\netsession_win.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Linda\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Linda\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Linda\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Linda\Desktop\RSIT.exe
C:\Program Files\trend micro\Linda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: “C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe”
O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKLM\..\Run: C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
O4 - HKLM\..\Run: “C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe”
O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime
O4 - HKLM\..\Run: “C:\Program Files\AVG\AVG2013\avgui.exe” /TRAYONLY
O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: “C:\Users\Linda\AppData\Local\Google\Update\GoogleUpdate.exe” /c
O4 - HKCU\..\Run: “C:\Users\Linda\AppData\Local\Akamai\netsession_win.exe”
O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: “C:\Users\Linda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe”
O4 - HKCU\..\Run: “C:\Users\Linda\AppData\Roaming\Spotify\Spotify.exe” /uri spotify:autostart
O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-19\..\Run: rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘NETWORK SERVICE’)
O4 - Startup: Dropbox.lnk = C:\Users\Linda\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Waarschuwen.lnk = C:\Program Files\Sureplus\Care\Waarschuwen.exe
O4 - Global Startup: Bluetooth Monitor.lnk = ?
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
–
End of file - 7292 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1510788046-593148464-897797110-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1510788046-593148464-897797110-1000UA.job
C:\Windows\tasks\ROC_REG_JAN_DELETE.job
C:\Windows\tasks\schedule!1507535609.job
C:\Windows\tasks\User_Feed_Synchronization-{FF9F60FD-087E-468D-9273-CC936A755F42}.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\s8l03dcf.default
“{20a82645-c095-46ed-80e3-08825760534b}”=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
“Description”=Adobe® Flash® Player 11.7.700.224 Plugin
“Path”=C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
“Description”=Adobe Shockwave Player
“Path”=C:\Windows\system32\Adobe\Director\np32dsw.dll
“Description”=
“Path”=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
“Description”=Google Earth in your browser
“Path”=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
“Description”=Java™ Deployment Toolkit
“Path”=C:\Windows\system32\npDeployJava1.dll
“Description”=Oracle® Next Generation Java™ Plug-In
“Path”=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
“Description”=Ag Player Plugin
“Path”=C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
“Description”=Windows Presentation Foundation plug-in for Mozilla browsers
“Path”=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
“Description”=TSHelper
“Path”=C:\Program Files\Common Files\ThreeShips Shared\Dll\\npTSHelper.dll
“Description”=Google Update
“Path”=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
“Description”=Google Update
“Path”=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
“Description”=VLC Multimedia Plugin
“Path”=C:\Program Files\VideoLAN\VLC\npvlc.dll
“Description”=Handles PDFs in-place in Firefox
“Path”=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\searchplugins\
bing.xml
bolcom-nl.xml
google.xml
marktplaats-nl.xml
wikipedia-nl.xml
C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\s8l03dcf.default\extensions\
{5384767E-00D9-40E9-B72F-9CC39D655D6F}
======Registry dump======
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll
“Windows Defender”=C:\Program Files\Windows Defender\MSASCui.exe
“IgfxTray”=C:\Windows\system32\igfxtray.exe
“HotKeysCmds”=C:\Windows\system32\hkcmd.exe
“Persistence”=C:\Windows\system32\igfxpers.exe
“Camera Assistant Software”=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
“Adobe Reader Speed Launcher”=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
“Adobe ARM”=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
“Aimersoft Helper Compact.exe”=C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
“APSDaemon”=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
“QuickTime Task”=C:\Program Files\QuickTime\QTTask.exe
“AVG_UI”=C:\Program Files\AVG\AVG2013\avgui.exe
“iTunesHelper”=C:\Program Files\iTunes\iTunesHelper.exe
“SunJavaUpdateSched”=C:\Program Files\Common Files\Java\Java Update\jusched.exe
“Sidebar”=C:\Program Files\Windows Sidebar\sidebar.exe
“TOSCDSPD”=C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
“Google Update”=C:\Users\Linda\AppData\Local\Google\Update\GoogleUpdate.exe
“Akamai NetSession Interface”=C:\Users\Linda\AppData\Local\Akamai\netsession_win.exe
“WMPNSCFG”=C:\Program Files\Windows Media Player\WMPNSCFG.exe
“Spotify Web Helper”=C:\Users\Linda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
“Spotify”=C:\Users\Linda\AppData\Roaming\Spotify\Spotify.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Monitor.lnk - C:\Program Files\TOSHIBA\Bluetooth Monitor\BtMon2.exe
C:\Users\Linda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Linda\AppData\Roaming\Dropbox\bin\Dropbox.exe
Waarschuwen.lnk - C:\Program Files\Sureplus\Care\Waarschuwen.exe
C:\Windows\system32\igfxdev.dll
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“EnableUIADesktopToggle”=0
“BindDirectlyToPropertySetStorage”=0
“vidc.mrle”=msrle32.dll
“vidc.msvc”=msvidc32.dll
“msacm.imaadpcm”=imaadp32.acm
“msacm.msg711”=msg711.acm
“msacm.msgsm610”=msgsm32.acm
“msacm.msadpcm”=msadp32.acm
“midimapper”=midimap.dll
“wavemapper”=msacm32.drv
“VIDC.UYVY”=msyuv.dll
“VIDC.YUY2”=msyuv.dll
“VIDC.YVYU”=msyuv.dll
“VIDC.IYUV”=iyuv_32.dll
“vidc.i420”=iyuv_32.dll
“VIDC.YVU9”=tsbyuv.dll
“msacm.l3acm”=l3codecp.acm
“vidc.cvid”=iccvid.dll
“MSVideo8”=VfWWDM32.dll
“wave”=wdmaud.drv
“midi”=wdmaud.drv
“mixer”=wdmaud.drv
“aux”=wdmaud.drv
“VIDC.X264”=x264vfw.dll
“VIDC.HFYU”=huffyuv.dll
“VIDC.FFDS”=ff_vfw.dll
“VIDC.LAGS”=lagarith.dll
“VIDC.XVID”=xvidvfw.dll
“msacm.ac3acm”=ac3acm.acm
“msacm.lameacm”=lameACM.acm
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe “%1” %*
======List of files/folders created in the last 3 months======
2013-08-10 16:18:29 —-D—- C:\rsit
2013-08-10 16:18:29 —-D—- C:\Program Files\trend micro
2013-08-10 15:43:00 —-A—- C:\Windows\system32\javaws.exe
2013-08-10 15:42:46 —-A—- C:\Windows\system32\WindowsAccessBridge.dll
2013-08-10 15:42:46 —-A—- C:\Windows\system32\javaw.exe
2013-08-10 15:42:45 —-A—- C:\Windows\system32\java.exe
2013-08-10 13:16:25 —-A—- C:\Windows\system32\drivers\mbamswissarmy.sys
2013-08-10 13:16:18 —-D—- C:\Users\Linda\AppData\Roaming\Malwarebytes
2013-08-10 13:15:22 —-D—- C:\ProgramData\Malwarebytes
2013-08-10 13:15:21 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2013-08-10 13:15:21 —-A—- C:\Windows\system32\drivers\mbam.sys
2013-08-10 13:04:47 —-A—- C:\Windows\DeleteOnReboot.bat
2013-08-10 13:04:42 —-A—- C:\AdwCleaner.txt
2013-07-10 03:13:03 —-A—- C:\Windows\system32\mshtmled.dll
2013-07-10 03:13:02 —-A—- C:\Windows\system32\vbscript.dll
2013-07-10 03:13:02 —-A—- C:\Windows\system32\ieui.dll
2013-07-10 03:13:01 —-A—- C:\Windows\system32\msfeeds.dll
2013-07-10 03:13:01 —-A—- C:\Windows\system32\jsproxy.dll
2013-07-10 03:13:01 —-A—- C:\Windows\system32\ieUnatt.exe
2013-07-10 03:13:00 —-A—- C:\Windows\system32\wininet.dll
2013-07-10 03:13:00 —-A—- C:\Windows\system32\jscript.dll
2013-07-10 03:12:59 —-A—- C:\Windows\system32\url.dll
2013-07-10 03:12:59 —-A—- C:\Windows\system32\jscript9.dll
2013-07-10 03:12:58 —-A—- C:\Windows\system32\urlmon.dll
2013-07-10 03:12:58 —-A—- C:\Windows\system32\iertutil.dll
2013-07-10 03:12:56 —-A—- C:\Windows\system32\mshtml.dll
2013-07-10 03:12:56 —-A—- C:\Windows\system32\ieframe.dll
2013-07-10 02:39:05 —-A—- C:\Windows\system32\win32k.sys
2013-07-10 02:38:46 —-A—- C:\Windows\system32\FntCache.dll
2013-07-10 02:38:46 —-A—- C:\Windows\system32\DWrite.dll
2013-07-10 02:38:45 —-A—- C:\Windows\system32\d3d10warp.dll
2013-07-10 02:38:45 —-A—- C:\Windows\system32\d3d10level9.dll
2013-07-10 02:38:45 —-A—- C:\Windows\system32\d3d10core.dll
2013-07-10 02:38:45 —-A—- C:\Windows\system32\d3d10_1core.dll
2013-07-10 02:38:45 —-A—- C:\Windows\system32\d3d10.dll
2013-07-10 02:38:44 —-A—- C:\Windows\system32\d3d10_1.dll
2013-07-10 02:38:44 —-A—- C:\Windows\system32\d2d1.dll
2013-07-10 02:38:43 —-A—- C:\Windows\system32\qedit.dll
2013-07-10 02:38:41 —-A—- C:\Windows\system32\WMVDECOD.DLL
2013-06-12 09:17:42 —-A—- C:\Windows\system32\drivers\tcpip.sys
2013-06-12 09:17:39 —-A—- C:\Windows\system32\win32spl.dll
2013-06-12 09:17:39 —-A—- C:\Windows\system32\printcom.dll
2013-06-12 09:17:35 —-A—- C:\Windows\system32\certutil.exe
2013-06-12 09:17:33 —-A—- C:\Windows\system32\cryptsvc.dll
2013-06-12 09:17:33 —-A—- C:\Windows\system32\cryptnet.dll
2013-06-12 09:17:33 —-A—- C:\Windows\system32\crypt32.dll
2013-06-12 09:17:33 —-A—- C:\Windows\system32\certenc.dll
2013-06-12 09:17:18 —-A—- C:\Windows\system32\ntkrnlpa.exe
2013-06-12 09:17:15 —-A—- C:\Windows\system32\ntoskrnl.exe
2013-06-12 09:17:03 —-A—- C:\Windows\system32\cryptdlg.dll
2013-05-23 21:28:46 —-D—- C:\Program Files\Common Files\Java
2013-05-22 16:39:56 —-A—- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-22 16:39:55 —-A—- C:\Windows\system32\cdd.dll
2013-05-14 13:02:41 —-A—- C:\Windows\system32\drivers\ntfs.sys
======List of files/folders modified in the last 3 months======
2013-08-10 16:18:41 —-D—- C:\Windows\Prefetch
2013-08-10 16:18:29 —-RD—- C:\Program Files
2013-08-10 16:18:08 —-D—- C:\Windows\Temp
2013-08-10 15:43:16 —-SHD—- C:\Windows\Installer
2013-08-10 15:43:14 —-D—- C:\Users\Linda\AppData\Roaming\Spotify
2013-08-10 15:43:10 —-SHD—- C:\Config.Msi
2013-08-10 15:43:00 —-D—- C:\Windows\System32
2013-08-10 15:42:29 —-A—- C:\Windows\system32\npDeployJava1.dll
2013-08-10 15:42:28 —-A—- C:\Windows\system32\deployJava1.dll
2013-08-10 15:41:20 —-SHD—- C:\System Volume Information
2013-08-10 15:33:46 —-D—- C:\Users\Linda\AppData\Roaming\Dropbox
2013-08-10 15:31:08 —-D—- C:\Windows\system32\drivers
2013-08-10 15:31:08 —-D—- C:\Windows\IME
2013-08-10 13:15:22 —-HD—- C:\ProgramData
2013-08-10 13:04:47 —-D—- C:\Windows
2013-08-10 13:00:00 —-D—- C:\ProgramData\MFAData
2013-08-08 18:37:24 —-D—- C:\Program Files\Google
2013-08-08 18:04:08 —-D—- C:\Program Files\BrowseToSave
2013-07-10 07:58:09 —-D—- C:\Windows\Microsoft.NET
2013-07-10 07:57:55 —-RSD—- C:\Windows\assembly
2013-07-10 07:36:15 —-D—- C:\Program Files\Microsoft Silverlight
2013-07-10 03:46:54 —-D—- C:\Windows\system32\XPSViewer
2013-07-10 03:46:51 —-D—- C:\Windows\system32\migration
2013-07-10 03:46:46 —-D—- C:\Program Files\Internet Explorer
2013-07-10 03:27:43 —-A—- C:\Windows\system32\PerfStringBackup.INI
2013-07-10 03:27:41 —-D—- C:\Windows\inf
2013-07-10 03:25:02 —-D—- C:\Windows\winsxs
2013-07-10 03:23:37 —-D—- C:\ProgramData\Microsoft Help
2013-07-10 03:17:26 —-A—- C:\Windows\system32\mrt.exe
2013-07-10 03:13:46 —-D—- C:\Windows\system32\catroot
2013-07-10 03:13:44 —-D—- C:\Windows\system32\catroot2
2013-07-10 03:01:02 —-D—- C:\Program Files\Windows Journal
2013-06-12 14:53:46 —-D—- C:\Windows\rescache
2013-06-12 14:34:26 —-D—- C:\Windows\system32\nl-NL
2013-06-12 10:04:39 —-A—- C:\Windows\system32\FlashPlayerApp.exe
2013-05-23 21:28:46 —-D—- C:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys
R3 BthPan;Bluetooth-apparaat (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys
R3 BTHUSB;USB-stuurprogramma voor Bluetooth-radio; C:\Windows\System32\Drivers\BTHUSB.sys
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
R3 HdAudAddService;Microsoft 1.1 UAA Functiestuurprogramma voor High Definition Audio-service; C:\Windows\system32\drivers\HdAudio.sys
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys
R3 RFCOMM;Bluetooth-apparaat (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys
R3 usbvideo;Chicony USB 2.0 Camera; C:\Windows\System32\Drivers\usbvideo.sys
R3 UVCFTR;UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys
S3 BTHPORT;Stuurprogramma voor Bluetooth-poort; C:\Windows\System32\Drivers\BTHport.sys
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys
S3 dot4;Microsoft IEEE-1284.4-stuurprogramma; C:\Windows\system32\DRIVERS\Dot4.sys
S3 Dot4Print;Stuurprogramma voor printerklasse voor IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys
S3 drmkaud;Microsoft Kernel DRM-audiodecoder; C:\Windows\system32\drivers\drmkaud.sys
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver; C:\Windows\system32\DRIVERS\MijXfilt.sys
S3 MSKSSRV;Microsoft Streaming Service-proxy; C:\Windows\system32\drivers\MSKSSRV.sys
S3 MSPCLOCK;Microsoft Streaming Clock-proxy; C:\Windows\system32\drivers\MSPCLOCK.sys
S3 MSPQM;Microsoft Streaming Kwaliteitsbeheer Proxy; C:\Windows\system32\drivers\MSPQM.sys
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-conversieprogramma; C:\Windows\system32\drivers\MSTEE.sys
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl.sys
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2013\avgwdsvc.exe
R2 Bonjour Service;Bonjour-service; C:\Program Files\Bonjour\mDNSResponder.exe
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe
R3 iPod Service;iPod-service; C:\Program Files\iPod\bin\iPodService.exe
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
—————–EOF—————–
# AdwCleaner v2.306 - Verslag gemaakt op 10/08/2013 om 13:04:42
# Geactualiseerd op 19/07/2013 door Xplode
# Besturingssysteem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Gebruiker : Linda - PC_VAN_LINDA
# Opstarten Modus : Normale modus
# Gelanceerd vanaf : C:\Users\Linda\Desktop\adwcleaner.exe
# Optie
***** *****
***** *****
File Verwijderd : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\s8l03dcf.default\searchplugins\WebSearch.xml
File Verwijderd : C:\Users\Linda\Desktop\Optimizer Pro.lnk
Map Verwijderd : C:\Program Files\optimizer pro
Map Verwijderd : C:\Program Files\WebSearch
Map Verwijderd : C:\ProgramData\BrrooWsse2usave
Map Verwijderd : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrrooWsse2usave
Map Verwijderd : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro
Map Verwijderd : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSEarcuh–NewaTab
Map Verwijderd : C:\ProgramData\SoftSafe
Map Verwijderd : C:\ProgramData\SSEarcuh–NewaTab
Map Verwijderd : C:\Users\Linda\AppData\LocalLow\BrrooWsse2usave
Map Verwijderd : C:\Users\Linda\AppData\LocalLow\SSEarcuh–NewaTab
Map Verwijderd : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\s8l03dcf.default\extensions\staged
Map Verwijderd : C:\Users\Linda\AppData\Roaming\optimizer pro
Verwijderd bij het opstarten : C:\ProgramData\BetterSoft
***** *****
Data Verwijderd : HKLM\..\Windows = c:\progra~1\browse~1\sprote~1.dll
Data Verwijderd : HKLM\..\Windows = c:\progra~1\websea~1\sprote~1.dll
Sleutel Verwijderd : HKCU\Software\AppDataLow\SProtector
Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E897599-B2CC-3C4C-50F4-83FDABB8C5CD}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E6E3B3B1-E673-CE22-A219-A1C43381A6C9}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E897599-B2CC-3C4C-50F4-83FDABB8C5CD}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6E3B3B1-E673-CE22-A219-A1C43381A6C9}
Sleutel Verwijderd : HKCU\Software\Optimizer Pro
Sleutel Verwijderd : HKCU\Software\Softonic
Sleutel Verwijderd : HKLM\Software\AVG Secure Search
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{1E897599-B2CC-3C4C-50F4-83FDABB8C5CD}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{E6E3B3B1-E673-CE22-A219-A1C43381A6C9}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E897599-B2CC-3C4C-50F4-83FDABB8C5CD}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6E3B3B1-E673-CE22-A219-A1C43381A6C9}
Sleutel Verwijderd : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Sleutel Verwijderd : HKLM\Software\SP Global
Sleutel Verwijderd : HKLM\Software\SProtector
Waarde Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Run
***** *****
-\\ Internet Explorer v9.0.8112.16496
Vervangen : = hxxp://websearch.pu-results.info/?pid=95&r=2013/03/03&hid=2004187613&lg=EN&cc=NL –> hxxp://www.google.com
Vervangen : = hxxp://websearch.pu-results.info/?pid=95&r=2013/03/03&hid=2004187613&lg=EN&cc=NL –> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.2 (nl)
File : C:\Users\Linda\AppData\Roaming\Mozilla\Firefox\Profiles\s8l03dcf.default\prefs.js
Verwijderd : user_pref(“browser.startup.homepage”, "hxxp://websearch.pu-results.info/?pid=95&r=2013/03/03&hid=200
Verwijderd : user_pref(“browser.search.order.1”, “WebSearch”);
Verwijderd : user_pref(“browser.search.defaultenginename”, “WebSearch”);
Verwijderd : user_pref(“browser.search.selectedEngine”, “WebSearch”);
Verwijderd : user_pref(“browser.search.defaulturl”, "hxxp://websearch.pu-results.info/?pid=95&r=2013/03/03&hid=20
Verwijderd : user_pref(“browser.search.order.1,S”, “WebSearch”);
Verwijderd : user_pref(“browser.search.defaultenginename,S”, “WebSearch”);
Verwijderd : user_pref(“browser.search.selectedEngine,S”, “WebSearch”);
Verwijderd : user_pref(“keyword.URL”, "hxxp://websearch.pu-results.info/?pid=95&r=2013/03/03&hid=2004187613&lg=EN
-\\ Google Chrome v28.0.1500.95
File : C:\Users\Linda\AppData\Local\Google\Chrome\User Data\Default\Preferences
De file bevat geen enkele ongeoorloofde invoer.
*************************
AdwCleaner.txt - -
########## EOF - C:\AdwCleaner.txt - ##########
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Databaseversie: v2013.08.09.07
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Linda :: PC_VAN_LINDA
10-08-2013 13:17:19
mbam-log-2013-08-10 (13-17-19).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 212112
Verstreken tijd: 17 minuut/minuten, 2 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 4
C:\Users\Linda\Downloads\installer_xilisoft_dvd_to_mp4_converter.exe (PUP.BundleInstaller.BT) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Linda\Downloads\Media_Player_Classic_Setup.exe (PUP.Bundle.Installer.OI) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Linda\Downloads\ReFX_Nexus_v2.exe (PUP.BundleInstaller.DW) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Linda\Downloads\SoftonicDownloader_voor_avg-remover.exe (PUP.Optional.Softonic) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)