Interpol Politie virus

  • Ben

    Hallo,

    Had je Java alweer terug geïnstalleerd?

    Schakel eerst de Antivirussoftware uit voordat je zoek.exe download.

    Schakel je antivirus- en antispywareprogramma's tijdelijk uit, deze kunnen namelijk conflicteren met Zoek.exe.

    Download Zoek.exe naar het bureaublad.

    * Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.

    Zoek.exe uitvoeren

    Wanneer u problemen ondervindt bij het uitvoeren van dit programma of bepaalde foutmeldingen te zien krijgt laat dit dan even weten in uw bericht.

    * Dubbelklik vervolgens op Zoek.exe om de tool te starten.

    * Windows Vista, 7 en 8 gebruikers dienen de tool als “administrator” uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.

    * Kopieer nu onderstaande vet gedrukte code en plak die in het grote invulvenster:

    * Note: Dit script is speciaal bedoeld voor deze computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.

    firefoxlook;

    emptyclsid;

    torpigcheck;

    emptyfolderscheck;delete

    chromelook;

    standardsearch;

    filesrcm;

    autoclean;

    startupall;

    * Klik nu op de knop "Run script".

    * Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    * Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    * Post het geopende logje in het volgende bericht.

  • Dizciple

    Voor zover ik weet is Java weg, via configuratiescherm..

    Zoek.exe v5.0.0.0 Updated 07-March-2014

    Tool run by Silver on zo 16-03-2014 at 19:20:30,47.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Silver\Desktop\zoek.exe

    ==== System Restore Info ======================

    16-3-2014 19:20:59 Zoek.exe System Restore Point Created Succesfully.

    ==== Torpig Check ======================

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll

    ==== Empty Folders Check ======================

    C:\Program Files\Google deleted successfully

    C:\PROGRA~3\Oracle deleted successfully

    C:\Users\Silver\AppData\Local\Downloaded Installations deleted successfully

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Running Processes ======================

    C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe

    C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe

    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    C:\Windows\SysWOW64\DllHost.exe

    C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    C:\Users\Silver\Desktop\zoek.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\cmd.exe

    C:\Windows\SysWOW64\cmd.exe

    ==== Deleting Services ======================

    ==== System Specs ======================

    Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601)

    Memory (RAM): 8068 MB

    CPU Info: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz

    CPU Speed: 3362,2 MHz

    Sound Card: Speakers (Realtek High Definiti |

    Display Adapters: Intel(R) HD Graphics | Intel(R) HD Graphics | Intel(R) HD Graphics | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver

    Monitors: 1x; Generic PnP Monitor |

    Screen Resolution: 1024 X 768 - 32 bit

    Network: Network Present

    Network Adapters: Realtek PCIe GBE Family Controller

    CD / DVD Drives: 1x (E: | ) E: HL-DT-STDVDRAM GH24NS95

    Ports: COM1 LPT1

    Mouse: 3 Button Wheel Mouse Present

    Hard Disks: C: 150,0GB | D: 1705,0GB

    Hard Disks - Free: C: 122,0GB | D: 1674,0GB

    Manufacturer *: American Megatrends Inc.

    BIOS Info: AT/AT COMPATIBLE | 10/23/12 | ALASKA - 1072009

    Time Zone: West-Europa (standaardtijd)

    Motherboard *: Gigabyte Technology Co., Ltd. B75M-D3V

    Country: Nederland

    Language: NLD

    ==== System Specs (Software) ======================

    Anti-Virus: G Data AntiVirus 2014 On-access scanning disabled (Outdated)

    Anti-Spyware: G Data AntiVirus 2014 disabled (Outdated)

    Anti-Spyware: Windows Defender disabled (Outdated)

    Internet Explorer Version: 10.0.9200.16844

    Adobe Reader version: 10.1.9.22

    Flash Player version: 11.1.102.55

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    ====== C:\Users\Silver\AppData\Local\Temp ====

    2014-03-16 17:02:42 7931CD72C76EBD0208D0931C4747D25A 1356920 —-a-w- C:\Users\Silver\AppData\Local\Temp\GDATA_Online_Update\UpdatePGM\UpdateGUI.exe

    2014-03-16 16:46:51 BF2749B55175E423BDA67C8CF1CCBEF0 54648 —-a-w- C:\Users\Silver\AppData\Local\Temp\gdwfpcd32.sys

    2014-03-16 16:45:04 41CB698F967B4D9F2580EA2A21A5A710 107320 —-a-w- C:\Users\Silver\AppData\Local\Temp\{49D283DD-7A61-4DC1-8181-68E01A0079CB}\ISBEW64.exe

    2014-03-16 16:45:03 41CB698F967B4D9F2580EA2A21A5A710 107320 —-a-w- C:\Users\Silver\AppData\Local\Temp\{CB6DE837-78BE-4510-A163-123304576B04}\ISBEW64.exe

    2014-03-14 19:11:56 FE447D1CD38CECAC2331FA932078D9A0 271360 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\SmiProvider.dll

    2014-03-14 19:11:56 FC2DB5842190C6E78A40CD7DA483B27C 435712 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DmiProvider.dll

    2014-03-14 19:11:56 FC00A05639494779002682A9B965EF9C 471040 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\WimProvider.dll

    2014-03-14 19:11:56 F2B0771A7CD27F20689E0AB787B7EB7C 289792 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DismCore.dll

    2014-03-14 19:11:56 EFCB002ABC3529D71B61E6FB6434566C 762368 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\CbsProvider.dll

    2014-03-14 19:11:56 E7CAED467F80B29F4E63BA493614DBB1 127488 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\OSProvider.dll

    2014-03-14 19:11:56 C9D74156913061BE6C51D8FC3ACF8E93 53760 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\FolderProvider.dll

    2014-03-14 19:11:56 BBB9E4FA2561F6A6E5CCF25DA069AC1B 313344 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\IntlProvider.dll

    2014-03-14 19:11:56 9A821D8D62F4C60232B856E98CBA7E4F 96768 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DismHost.exe

    2014-03-14 19:11:56 8D3855B133E21143E8B4BFADB9FB14A3 302080 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\UnattendProvider.dll

    2014-03-14 19:11:56 8CA117CB9338C0351236939717CB7084 186368 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DismProv.dll

    2014-03-14 19:11:56 7B38D7916A7CD058C16A0A6CA5077901 271360 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\wdscore.dll

    2014-03-14 19:11:56 739968678548BA15F6B9372E8760C012 444416 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\TransmogProvider.dll

    2014-03-14 19:11:56 6A4BD682396F29FD7DF5AB389509B950 183296 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\CompatProvider.dll

    2014-03-14 19:11:56 5488E381238FF19687FDD7AB2F44CFCC 111616 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DismCorePS.dll

    2014-03-14 19:11:56 45FF4FA5CA5432BFCCDED4433FE2A85B 216576 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\MsiProvider.dll

    2014-03-02 20:39:04 10CE1874520612E5F9BDC21C962AEF1B 918016 —-a-w- C:\Users\Silver\AppData\Local\Temp\Quarantine.exe

    ====== Java Cache =====

    ====== C:\Windows\SysWOW64 =====

    2014-03-14 18:06:14 B8BF98AB4F9408C0C0AC5504E8BF4BBA 523776 —-a-w- C:\Windows\SysWOW64\vbscript.dll

    2014-03-14 18:04:18 0F3B6590824D9C61B107A4134BB13A2F 163840 —-a-w- C:\Windows\SysWOW64\msrating.dll

    2014-03-14 18:04:18 0CAB066DB859BC54551E94453B963359 391168 —-a-w- C:\Windows\SysWOW64\ieui.dll

    2014-03-14 18:04:18 03430E5004CFEBAE4BC8C47A366F869A 2706432 —-a-w- C:\Windows\SysWOW64\mshtml.tlb

    2014-03-14 18:04:17 BE2E9A1E68FB4EC3603037DEFEE54ACE 109056 —-a-w- C:\Windows\SysWOW64\iesysprep.dll

    2014-03-14 18:04:17 ABB14EEA787B326975C53E7ED05B91F6 61440 —-a-w- C:\Windows\SysWOW64\iesetup.dll

    2014-03-14 18:04:17 31AA1C6779231BFC6F5D498363DA25F1 71680 —-a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2014-03-14 18:04:17 24E07A483C6FA35F91E9D2F84495819E 2049024 —-a-w- C:\Windows\SysWOW64\iertutil.dll

    2014-03-14 18:04:17 006345E0F3F4C34CFFDA6CE0DB59E2F6 33280 —-a-w- C:\Windows\SysWOW64\iernonce.dll

    2014-03-14 18:04:16 CAF4F8373A49BF979F2F296966E7E2A0 690688 —-a-w- C:\Windows\SysWOW64\jscript.dll

    2014-03-14 18:04:16 803063FFA8F118D8F4CB9161F02B7B84 493056 —-a-w- C:\Windows\SysWOW64\msfeeds.dll

    2014-03-14 18:04:15 D7B1721B587698D495079B28758F13B3 1140736 —-a-w- C:\Windows\SysWOW64\urlmon.dll

    2014-03-14 18:04:15 3F2FD720B6C4EF55B25B330808121069 2877952 —-a-w- C:\Windows\SysWOW64\jscript9.dll

    2014-03-14 18:04:14 CA0398A7BEB5DB12594EF4ABDB078A5D 39936 —-a-w- C:\Windows\SysWOW64\jsproxy.dll

    2014-03-14 18:04:14 9284BA6C27D360D71A5C0ECC8456E78E 1767936 —-a-w- C:\Windows\SysWOW64\wininet.dll

    2014-03-14 18:04:14 67B5955F5F2F36D58993EB87101B3D2B 13761024 —-a-w- C:\Windows\SysWOW64\ieframe.dll

    2014-03-14 18:04:12 9F378D86F983E84A0212678C1D18D7FC 14358016 —-a-w- C:\Windows\SysWOW64\mshtml.dll

    2014-03-14 18:03:27 E4561704CBFA193761743E5AF746C669 1237504 —-a-w- C:\Windows\SysWOW64\msxml3.dll

    2014-03-14 18:03:27 4F8CCD3E7D9F17A7C60FA0AE2466CACF 381440 —-a-w- C:\Windows\SysWOW64\wer.dll

    2014-03-14 18:03:27 17B06F23237FCD731FA2E10ECD6EDFE1 2048 —-a-w- C:\Windows\SysWOW64\msxml3r.dll

    2014-03-14 18:03:24 204882085A7D984D455AA4DE7B7074C6 5694464 —-a-w- C:\Windows\SysWOW64\mstscax.dll

    2014-03-14 18:03:23 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 —-a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

    2014-03-14 18:03:23 BBCE3E9E74C7CEA47FA4115B360AC2C6 423936 —-a-w- C:\Windows\SysWOW64\secproc_isv.dll

    2014-03-14 18:03:23 9158DBE2F8483434FC72F320690C9DB8 87040 —-a-w- C:\Windows\SysWOW64\secproc_ssp_isv.dll

    2014-03-14 18:03:23 7FA485555BF802FE3DB5598004DBDFAC 390144 —-a-w- C:\Windows\SysWOW64\msdrm.dll

    2014-03-14 18:03:23 6142C5540C8D2764D59CBC11AF4A5900 572416 —-a-w- C:\Windows\SysWOW64\RMActivate.exe

    2014-03-14 18:03:23 58712A48D31B40EBCB35B47205F87771 87040 —-a-w- C:\Windows\SysWOW64\secproc_ssp.dll

    2014-03-14 18:03:23 12A9F24DC9F465DA79AC2272D829A81E 428032 —-a-w- C:\Windows\SysWOW64\secproc.dll

    2014-03-14 18:03:23 0F5FEF37588AF457E02125674F171A4F 508928 —-a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

    2014-03-14 18:03:23 08D323750350A8A29611D1004C0CF319 510976 —-a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

    2014-03-14 18:03:19 D96106CF60505734B14F6AE80AAA4B07 1987584 —-a-w- C:\Windows\SysWOW64\d3d10warp.dll

    2014-03-14 18:03:18 14800BD31701A5047AC3145BB1E698AE 3419136 —-a-w- C:\Windows\SysWOW64\d2d1.dll

    2014-03-14 18:03:15 EA093130471090037BB70A4AF86FAD1B 420008 —-a-w- C:\Windows\SysWOW64\locale.nls

    2014-03-14 18:03:14 B0BE998802DEDEE1FD8F5E5F9F207A30 509440 —-a-w- C:\Windows\SysWOW64\qedit.dll

    2014-03-14 18:02:36 A054EA8FBE16D4D34F06D81A4F0088E2 1230336 —-a-w- C:\Windows\SysWOW64\WindowsCodecs.dll

    ====== C:\Windows\SysWOW64\drivers =====

    ====== C:\Windows\Sysnative =====

    2014-03-14 18:06:14 3EA9300DB7A2987A755F2EF83598A92D 600064 —-a-w- C:\Windows\Sysnative\vbscript.dll

    2014-03-14 18:04:18 E230D5CD7249CF451A9B345A1353C59A 2706432 —-a-w- C:\Windows\Sysnative\mshtml.tlb

    2014-03-14 18:04:18 97FE0CAE98FCCAF5BB97681F38A01CEC 197120 —-a-w- C:\Windows\Sysnative\msrating.dll

    2014-03-14 18:04:18 2B1CE9F820801E011664FEC664E06983 526336 —-a-w- C:\Windows\Sysnative\ieui.dll

    2014-03-14 18:04:17 EB9402ABE2A48993A829964FA55625CC 51712 —-a-w- C:\Windows\Sysnative\ie4uinit.exe

    2014-03-14 18:04:17 D12B64D097BF978D52720593D492674D 67072 —-a-w- C:\Windows\Sysnative\iesetup.dll

    2014-03-14 18:04:17 A2D58DB0C1C9C0BBCF10F59855D460BD 39936 —-a-w- C:\Windows\Sysnative\iernonce.dll

    2014-03-14 18:04:17 8D06EB11925D312D276C672CF5E8EE9C 2648576 —-a-w- C:\Windows\Sysnative\iertutil.dll

    2014-03-14 18:04:17 50D39089BDAE2582B227587DA982DDEF 89600 —-a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe

    2014-03-14 18:04:17 10322D8C1BC36CA7EAA5C754A54045F8 136704 —-a-w- C:\Windows\Sysnative\iesysprep.dll

    2014-03-14 18:04:16 5EA008B3EEEC19ED0AB6A5345C811499 3960320 —-a-w- C:\Windows\Sysnative\jscript9.dll

    2014-03-14 18:04:16 3D08744AD10BF721361214D88462F094 855552 —-a-w- C:\Windows\Sysnative\jscript.dll

    2014-03-14 18:04:16 2BFCEB6DC571E3277927D2E7C051C922 603136 —-a-w- C:\Windows\Sysnative\msfeeds.dll

    2014-03-14 18:04:15 7D3FD710460FC0155C0F6A877AE46A48 1365504 —-a-w- C:\Windows\Sysnative\urlmon.dll

    2014-03-14 18:04:14 C8F4FB5B401942E6E25D3D2360B47C86 53760 —-a-w- C:\Windows\Sysnative\jsproxy.dll

    2014-03-14 18:04:14 79EDF01FA13D886F8E1B655D542011FB 2241536 —-a-w- C:\Windows\Sysnative\wininet.dll

    2014-03-14 18:04:12 EC8AE061C8F2134B9BD89634C156F425 15404032 —-a-w- C:\Windows\Sysnative\ieframe.dll

    2014-03-14 18:04:11 87478BFD51053034E45AAB2740285AF1 19273216 —-a-w- C:\Windows\Sysnative\mshtml.dll

    2014-03-14 18:03:28 E918C0DE5CF2AE6BEDBF387C09627D93 3156480 —-a-w- C:\Windows\Sysnative\win32k.sys

    2014-03-14 18:03:27 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 —-a-w- C:\Windows\Sysnative\msxml3r.dll

    2014-03-14 18:03:27 1075AB2C077B415760C0E948856B5126 484864 —-a-w- C:\Windows\Sysnative\wer.dll

    2014-03-14 18:03:27 0D298133C359AB8CB9EB4FA178BF3947 1882112 —-a-w- C:\Windows\Sysnative\msxml3.dll

    2014-03-14 18:03:25 04F82965C09CBDF646B487E145060301 228864 —-a-w- C:\Windows\Sysnative\wwansvc.dll

    2014-03-14 18:03:24 879A3F94118D686E63041A386FE91EBE 6574592 —-a-w- C:\Windows\Sysnative\mstscax.dll

    2014-03-14 18:03:23 DC6DD779F35BB42E2E76FDFEC565C251 123392 —-a-w- C:\Windows\Sysnative\secproc_ssp_isv.dll

    2014-03-14 18:03:23 C6AC2C91541D24F9E236A670C0CA793D 528384 —-a-w- C:\Windows\Sysnative\msdrm.dll

    2014-03-14 18:03:23 B41B1FEDEBBD955B4E25676B42087885 123392 —-a-w- C:\Windows\Sysnative\secproc_ssp.dll

    2014-03-14 18:03:23 5693212AB2EBCACBBE05EC3A642113E2 485888 —-a-w- C:\Windows\Sysnative\secproc_isv.dll

    2014-03-14 18:03:23 399FC1B75790EE606A6FD9F2FB4C891C 488448 —-a-w- C:\Windows\Sysnative\secproc.dll

    2014-03-14 18:03:23 297926B15AE5390409F1007EB28A8EFB 552960 —-a-w- C:\Windows\Sysnative\RMActivate_ssp_isv.exe

    2014-03-14 18:03:23 1B3741488AA7E237961A29D1E7A44C0A 626176 —-a-w- C:\Windows\Sysnative\RMActivate.exe

    2014-03-14 18:03:23 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 —-a-w- C:\Windows\Sysnative\RMActivate_isv.exe

    2014-03-14 18:03:23 03F8F411F118CFDA508E77C747BB05EA 553984 —-a-w- C:\Windows\Sysnative\RMActivate_ssp.exe

    2014-03-14 18:03:19 E8710B5DDA963E6BA198DF5FB209E72A 2565120 —-a-w- C:\Windows\Sysnative\d3d10warp.dll

    2014-03-14 18:03:18 C676E5EA388AF7C4C031F56F9B42E362 3928064 —-a-w- C:\Windows\Sysnative\d2d1.dll

    2014-03-14 18:03:15 EA093130471090037BB70A4AF86FAD1B 420008 —-a-w- C:\Windows\Sysnative\locale.nls

    2014-03-14 18:03:14 2C619F6023E3F7A3ABF3475ED2223359 624128 —-a-w- C:\Windows\Sysnative\qedit.dll

    2014-03-14 18:02:36 AFCA5C1ECEAF948FC815178BC077680E 1424384 —-a-w- C:\Windows\Sysnative\WindowsCodecs.dll

    2014-03-14 17:52:11 CDFF6B12BDD764AFDB4FCCC16008D6A2 2804 —-a-w- C:\Windows\Sysnative\.crusader

    ====== C:\Windows\Sysnative\drivers =====

    2014-03-16 17:15:23 899C214FD95D66BE8CBD036D265FED53 19016 —-a-w- C:\Windows\Sysnative\drivers\GdPhyMem.sys

    2014-03-16 16:51:28 380B83300E019065C3B5FA47136F8356 106272 —-a-w- C:\Windows\Sysnative\drivers\GRD.sys

    2014-03-16 16:47:21 7CA2CB5F8190F7E4123AED0C7E50AF24 63320 —-a-w- C:\Windows\Sysnative\drivers\PktIcpt.sys

    2014-03-16 16:46:52 318BA73C601AACAC3036124B6BBFBE2E 130392 —-a-w- C:\Windows\Sysnative\drivers\MiniIcpt.sys

    2014-03-16 16:46:52 29F589B1543DD7AB2086C95B152B0C3D 65368 —-a-w- C:\Windows\Sysnative\drivers\HookCentre.sys

    2014-03-16 16:46:51 3029AA9AA2A3CD7C7B35B9F7D1933FDB 64856 —-a-w- C:\Windows\Sysnative\drivers\gdwfpcd64.sys

    2014-03-16 16:46:51 04E86E408C505EA00C45777347905616 60248 —-a-w- C:\Windows\Sysnative\drivers\GDBehave.sys

    2014-03-16 16:32:51 05A0C2744CEAC6F1B723EC469B650EF0 47632 —-a-w- C:\Windows\Sysnative\drivers\PSKMAD.sys

    2014-03-14 18:03:15 FFA06EF43987ED0DD42AD59B260C0C78 7808 —-a-w- C:\Windows\Sysnative\drivers\usbd.sys

    2014-03-14 18:03:15 DD253AFC3BC6CBA412342DE60C3647F3 30720 —-a-w- C:\Windows\Sysnative\drivers\usbuhci.sys

    2014-03-14 18:03:15 DCA68B0943D6FA415F0C56C92158A83A 99840 —-a-w- C:\Windows\Sysnative\drivers\usbccgp.sys

    2014-03-14 18:03:15 8D1196CFBB223621F2C67D45710F25BA 343040 —-a-w- C:\Windows\Sysnative\drivers\usbhub.sys

    2014-03-14 18:03:15 765A92D428A8DB88B960DA5A8D6089DC 25600 —-a-w- C:\Windows\Sysnative\drivers\usbohci.sys

    2014-03-14 18:03:15 18A85013A3E0F7E1755365D287443965 53248 —-a-w- C:\Windows\Sysnative\drivers\usbehci.sys

    2014-03-14 18:03:15 12FEB33791920678F8433701C822BCFD 325120 —-a-w- C:\Windows\Sysnative\drivers\usbport.sys

    2014-03-14 18:03:14 3555BA97171CD153118F73FDCCC8BFDE 376768 —-a-w- C:\Windows\Sysnative\drivers\netio.sys

    ====== C:\Windows\Tasks ======

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    ======= C:\PROGRA~2 =====

    2014-03-16 16:46:44 ——– d—–w- C:\PROGRA~2\G Data

    2014-03-16 16:46:44 ——– d—–w- C:\PROGRA~2\COMMON~1\G Data

    2014-03-14 16:13:11 ——– d—–w- C:\PROGRA~2\COMMON~1\Skype

    2014-03-14 16:13:11 ——– d—–r- C:\PROGRA~2\Skype

    ======= C: =====

    2014-03-15 12:57:34 8C4AA0A427451E366CF758EA31CCCD8D 32166 —-a-w- C:\cc_20140315_135710.reg

    ====== C:\Users\Silver\AppData\Roaming ======

    2014-03-16 17:11:19 ——– d—–w- C:\Users\Silver\AppData\Local\G DATA

    2014-03-14 19:07:36 ——– d—–w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp

    2014-03-14 19:07:36 ——– d—–w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp

    2014-03-14 19:07:36 ——– d—–w- C:\Users\Silver\AppData\Local\Temp

    2014-03-14 19:07:36 ——– d—–w- C:\Users\Default\AppData\Local\Temp

    2014-03-14 19:07:36 ——– d—–w- C:\Users\Default User\AppData\Local\Temp

    2014-03-14 19:07:36 ——– d—–w- C:\Users\Administrator\AppData\Local\Temp

    2014-03-14 18:25:26 ——– d—–w- C:\Users\Silver\AppData\Local\Programs

    2014-03-14 16:13:14 ——– d—–w- C:\Users\Silver\AppData\Local\Skype

    2014-02-19 16:26:50 ——– d—–w- C:\Users\Silver\AppData\Roaming\Stella

    ====== C:\Users\Silver ======

    2014-03-16 17:04:08 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data AntiVirus 2014

    2014-03-16 16:46:44 ——– d—–w- C:\ProgramData\G DATA

    2014-03-14 16:13:11 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

    ====== C: exe-files ==

    2014-03-16 17:08:45 1A74B2B90A643C6CE6C304BAC5293A4A 632952 —-a-w- C:\Program Files (x86)\Common Files\G Data\AVKProxy\ExploitProtectionHelper.exe

    2014-03-16 17:03:37 217FAD6415EBD9A30FAD44A972CEFA06 1752184 —-a-w- C:\Program Files (x86)\G Data\AntiVirus\AVK\UpdatePGM\setup.exe

    2014-03-16 17:02:48 7931CD72C76EBD0208D0931C4747D25A 1356920 —-a-w- C:\Program Files (x86)\G Data\AntiVirus\AVK\UpdatePGM\UpdateGUI.exe

    2014-03-16 17:02:48 6B953EB50B3DBF6BCD6521D9EC3A2930 1442936 —-a-w- C:\Program Files (x86)\G Data\AntiVirus\AVK\UpdatePGM\IUpdateAVK.exe

    2014-03-16 17:02:42 7931CD72C76EBD0208D0931C4747D25A 1356920 —-a-w- C:\Users\Silver\AppData\Local\Temp\GDATA_Online_Update\UpdatePGM\UpdateGUI.exe

    2014-03-16 16:45:04 41CB698F967B4D9F2580EA2A21A5A710 107320 —-a-w- C:\Users\Silver\AppData\Local\Temp\{49D283DD-7A61-4DC1-8181-68E01A0079CB}\ISBEW64.exe

    2014-03-16 16:45:03 41CB698F967B4D9F2580EA2A21A5A710 107320 —-a-w- C:\Users\Silver\AppData\Local\Temp\{CB6DE837-78BE-4510-A163-123304576B04}\ISBEW64.exe

    2014-03-16 14:02:44 CB139AE37B93E21CD858D748B3DF0EEA 34509664 —-atw- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\29.0.1547.66\chrome_installer.exe

    2014-03-16 14:02:30 2040B57C08F7A97E4E44ACB324647CF2 6110688 —-atw- C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_full_signed.exe

    2014-03-14 19:11:56 9A821D8D62F4C60232B856E98CBA7E4F 96768 —-a-w- C:\Users\Silver\AppData\Local\Temp\FBC7C18F-942D-4C32-AD4A-EAA1BEDAB4F0\DismHost.exe

    2014-03-14 18:04:17 EB9402ABE2A48993A829964FA55625CC 51712 —-a-w- C:\Windows\System32\ie4uinit.exe

    2014-03-14 18:04:17 50D39089BDAE2582B227587DA982DDEF 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2014-03-14 18:04:17 4EC501866D7ED803170F1268A1CAD692 484352 —-a-w- C:\Program Files\Internet Explorer\ieinstal.exe

    2014-03-14 18:04:17 31AA1C6779231BFC6F5D498363DA25F1 71680 —-a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe

    2014-03-14 18:04:17 0FF67F61FA609F645E815DB7FC10A255 469504 —-a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe

    2014-03-14 18:04:16 F71D97B6B631D565AF7C6E0BDF9D49F4 770736 —-a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe

    2014-03-14 18:04:16 A4916CEE3278F39F606CCA2CAC35CF31 775344 —-a-w- C:\Program Files\Internet Explorer\iexplore.exe

    2014-03-14 18:03:23 E01D2AC63453534DB8AD1EA97DEE9C3A 594944 —-a-w- C:\Windows\SysWOW64\RMActivate_isv.exe

    2014-03-14 18:03:23 6142C5540C8D2764D59CBC11AF4A5900 572416 —-a-w- C:\Windows\SysWOW64\RMActivate.exe

    2014-03-14 18:03:23 297926B15AE5390409F1007EB28A8EFB 552960 —-a-w- C:\Windows\System32\RMActivate_ssp_isv.exe

    2014-03-14 18:03:23 1B3741488AA7E237961A29D1E7A44C0A 626176 —-a-w- C:\Windows\System32\RMActivate.exe

    2014-03-14 18:03:23 17CF3B3F68272BD40C878D4DBAB0EBC9 658432 —-a-w- C:\Windows\System32\RMActivate_isv.exe

    2014-03-14 18:03:23 0F5FEF37588AF457E02125674F171A4F 508928 —-a-w- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe

    2014-03-14 18:03:23 08D323750350A8A29611D1004C0CF319 510976 —-a-w- C:\Windows\SysWOW64\RMActivate_ssp.exe

    2014-03-14 18:03:23 03F8F411F118CFDA508E77C747BB05EA 553984 —-a-w- C:\Windows\System32\RMActivate_ssp.exe

    === C: other files ==

    2014-03-16 17:15:23 899C214FD95D66BE8CBD036D265FED53 19016 —-a-w- C:\Windows\System32\drivers\GdPhyMem.sys

    2014-03-16 17:08:45 228C16B23B958C258902049B3D83D91E 1742893 —-a-w- C:\Program Files (x86)\Common Files\G Data\AVKScanP\G Data\GDAV.dll.zip

    2014-03-16 17:04:07 A224F5EB3D9C49F58E199F4D72B46181 54104 —-a-w- C:\Windows\Temp\gdwfpcd32.sys

    2014-03-16 16:51:28 380B83300E019065C3B5FA47136F8356 106272 —-a-w- C:\Windows\System32\drivers\GRD.sys

    2014-03-16 16:47:21 7CA2CB5F8190F7E4123AED0C7E50AF24 63320 —-a-w- C:\Windows\System32\drivers\PktIcpt.sys

    2014-03-16 16:46:52 318BA73C601AACAC3036124B6BBFBE2E 130392 —-a-w- C:\Windows\System32\drivers\MiniIcpt.sys

    2014-03-16 16:46:52 29F589B1543DD7AB2086C95B152B0C3D 65368 —-a-w- C:\Windows\System32\drivers\HookCentre.sys

    2014-03-16 16:46:51 BF2749B55175E423BDA67C8CF1CCBEF0 54648 —-a-w- C:\Users\Silver\AppData\Local\Temp\gdwfpcd32.sys

    2014-03-16 16:46:51 3029AA9AA2A3CD7C7B35B9F7D1933FDB 64856 —-a-w- C:\Windows\System32\drivers\gdwfpcd64.sys

    2014-03-16 16:46:51 04E86E408C505EA00C45777347905616 60248 —-a-w- C:\Windows\System32\drivers\GDBehave.sys

    2014-03-16 16:32:51 05A0C2744CEAC6F1B723EC469B650EF0 47632 —-a-w- C:\Windows\System32\drivers\PSKMAD.sys

    2014-03-14 18:03:28 E918C0DE5CF2AE6BEDBF387C09627D93 3156480 —-a-w- C:\Windows\System32\win32k.sys

    2014-03-14 18:03:15 FFA06EF43987ED0DD42AD59B260C0C78 7808 —-a-w- C:\Windows\System32\drivers\usbd.sys

    2014-03-14 18:03:15 DD253AFC3BC6CBA412342DE60C3647F3 30720 —-a-w- C:\Windows\System32\drivers\usbuhci.sys

    2014-03-14 18:03:15 DCA68B0943D6FA415F0C56C92158A83A 99840 —-a-w- C:\Windows\System32\drivers\usbccgp.sys

    2014-03-14 18:03:15 8D1196CFBB223621F2C67D45710F25BA 343040 —-a-w- C:\Windows\System32\drivers\usbhub.sys

    2014-03-14 18:03:15 765A92D428A8DB88B960DA5A8D6089DC 25600 —-a-w- C:\Windows\System32\drivers\usbohci.sys

    2014-03-14 18:03:15 18A85013A3E0F7E1755365D287443965 53248 —-a-w- C:\Windows\System32\drivers\usbehci.sys

    2014-03-14 18:03:15 12FEB33791920678F8433701C822BCFD 325120 —-a-w- C:\Windows\System32\drivers\usbport.sys

    2014-03-14 18:03:14 3555BA97171CD153118F73FDCCC8BFDE 376768 —-a-w- C:\Windows\System32\drivers\netio.sys

    ==== Startup Registry Enabled ======================

    “Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /autoRun”

    “Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /autoRun”

    “mctadmin”=“C:\Windows\System32\mctadmin.exe”

    “mctadmin”=“C:\Windows\System32\mctadmin.exe”

    “IMSS”=“C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe”

    “Adobe ARM”=“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “G Data AntiVirus Tray”=“C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe”

    ==== Startup Registry Enabled x64 ======================

    “RtHDVCpl”=“C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s”

    ==== Startup Registry Disabled x64 ======================

    “key”=“SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“Adobe ARM”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\“”

    “key”=“SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“IAStorIcon”

    “hkey”=“HKLM”

    “command”=“C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIconLaunch.exe \”C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIcon.exe\“ 60”

    “key”=“SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run”

    “item”=“USB3MON”

    “hkey”=“HKLM”

    “command”=“\”C:\\Program Files (x86)\\Intel\\Intel(R) USB 3.0 eXtensible Host Controller Driver\\Application\\iusb3mon.exe\“”

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job –a—— C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job –a—— C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==== Other Scheduled Tasks ======================

    “C:\Windows\SysNative\tasks\CCleanerSkipUAC”

    “C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore”

    “C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA”

    “C:\Windows\SysNative\tasks\{BD6C5BA8-671B-42BF-90BE-2F0350C7DBB1}”

    ==== Folders in C:\PROGRA~3 0-6 Months Old ======================

    2013-09-25 14:34:58 ——– d—–w- C:\PROGRA~3\HP

    2013-09-25 14:35:32 ——– d—–w- C:\PROGRA~3\Visan

    2013-09-27 12:22:39 ——– d—–w- C:\PROGRA~3\HP Photo Creations

    2014-03-16 16:46:44 ——– d—–w- C:\PROGRA~3\G DATA

    ==== Set IE to Default ======================

    Old Values:

    “Start Page”=“http://www.startpagina.nl/”

    New Values:

    “Start Page”=“http://www.startpagina.nl/”

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    “DefaultScope”=“{60B6C5E0-64AC-4817-BEFB-94F9B6EC8657}”

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url=“Not_Found”

    {60B6C5E0-64AC-4817-BEFB-94F9B6EC8657} Google Url=“http://www.google.nl/search?hl=nl&q={searchTerms}”

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url=“http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}”

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-3511177411-2812235252-1749893902-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== HijackThis Entries ======================

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe”

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: Accelerated graphics

    O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/NL/Core/Player/2020PlayerAX_IKEA_Win32.cab

    O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (Bitdefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe

    O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe

    O23 - Service: G Data Bestandssysteembewaker (AVKWCtl) - G Data Software AG - C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlX64.exe

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe

    O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe

    O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    ==== Empty IE Cache ======================

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Silver\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Silver\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

    C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    ==== Empty FireFox Cache ======================

    No FireFox Cache found

    ==== Empty Chrome Cache ======================

    No Chrome User Data found

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    No Java Cache Found

    ==== C:\zoek_backup content ======================

    C:\zoek_backup (files=0 folders=0 0 bytes)

    ==== Empty Temp Folders ======================

    C:\Users\Administrator\AppData\Local\Temp emptied successfully

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\Silver\AppData\Local\Temp will be emptied at reboot

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\Windows\Temp will be emptied at reboot

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Silver\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== EOF on zo 16-03-2014 at 19:31:22,20 ======================

  • Ben

    Hallo,

    Voer zoek.exe nogmaals uit met de volgende code;

    installedprogs;

    Plaats het verkregen logje.

  • Dizciple

    Voorlopig alweer hele tijd die pop-up niet gehad… Enkelt 3 keer maar dus..

    Virusscanner vond vandaag een trojan in uninstall bestand van vlc player, dat bestand is verwijderd, en een trojan in C\Recovery, winre.wim, die staat nu in quarantaine..

    Zoek.exe v5.0.0.0 Updated 07-March-2014

    Tool run by Silver on zo 16-03-2014 at 19:41:37,43.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Silver\Desktop\zoek.exe

    ==== System Restore Info ======================

    16-3-2014 19:42:04 Zoek.exe System Restore Point Created Succesfully.

    ==== Installed Programs ======================

    Adobe Flash Player 11 Plugin 64-bit

    Adobe Flash Player 12 ActiveX

    Adobe Reader X (10.1.9)

    CCleaner

    Compl‚ment Messenger

    D3DX10

    G Data AntiVirus 2014

    Galerie de photos Windows Live

    Google Earth Plug-in

    Google Update Helper

    HP Deskjet 3520 series Basissoftware van het apparaat

    HP Deskjet 3520 series Help

    HP Deskjet 3520 series Setup Guide

    HP Photo Creations

    Intel(R) Control Center

    Intel(R) Management Engine Components

    Intel(R) Processor Graphics

    Intel(R) Rapid Storage Technology

    Intel(R) SDK for OpenCL - CPU Only Runtime Package

    Intel(R) USB 3.0 eXtensible Host Controller Driver

    Intel© Trusted Connect Service Client

    Junk Mail filter update

    Mesh Runtime

    Messenger Companion

    Microsoft .NET Framework 4.5.1

    Microsoft .NET Framework 4.5.1 (Nederlands)

    Microsoft .NET Framework 4.5.1 (NLD)

    Microsoft Application Error Reporting

    Microsoft Office Professional Editie 2003

    Microsoft Silverlight

    Microsoft SQL Server 2005 Compact Edition

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

    MSVCRT

    MSVCRT_amd64

    Realtek Ethernet Controller Driver

    Realtek High Definition Audio Driver

    Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)

    Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)

    SkypeT 6.14

    VLC media player 2.0.6

    Vuze

    Windows Live Communications Platform

    Windows Live Essentials

    Windows Live Family Safety

    Windows Live Fotogalerie

    Windows Live ID Sign-in Assistant

    Windows Live Installer

    Windows Live Language Selector

    Windows Live Mail

    Windows Live Mesh

    Windows Live Messenger

    Windows Live Messenger Companion Core

    Windows Live MIME IFilter

    Windows Live Movie Maker

    Windows Live Photo Common

    Windows Live Photo Gallery

    Windows Live PIMT Platform

    Windows Live Remote Client

    Windows Live Remote Client Resources

    Windows Live Remote Service

    Windows Live Remote Service Resources

    Windows Live SOXE

    Windows Live SOXE Definitions

    Windows Live UX Platform

    Windows Live UX Platform Language Pack

    Windows Live Writer

    Windows Live Writer Resources

    WinRAR 4.20 (64-bit)

    ==== C:\zoek_backup content ======================

    C:\zoek_backup (files=0 folders=0 0 bytes)

    ==== EOF on zo 16-03-2014 at 19:42:17,51 ======================

  • Ben

    Hallo,

    Download

    ComboFix van één van de onderstaande locaties naar het bureaublad.

    Bleeping Computer

    Info Spyware

    Antivirussoftware uitschakelen

    Schakel je antivirus- en antispywareprogramma's tijdelijk uit, deze kunnen namelijk conflicteren met ComboFix (ComboFix.exe).

    Antivirus software uitschakelen

    Antispy & malware software uitschakelen

    ComboFix uitvoeren

    Wanneer u problemen ondervindt bij het uitvoeren van dit programma of bepaalde foutmeldingen te zien krijgt laat dit dan even weten in uw bericht.

    Dubbelklik op "ComboFix" om de tool te starten, Windows Vista, 7 & 8 gebruikers zullen een melding krijgen van UAC (Gebruikersaccountbeheer), klik hier op Ja / yes.

    Op een Windows XP computer zal ComboFix de "Recovery Console" installeren als deze nog niet aanwezig is. (Een actieve internet verbinding is dan een vereiste).

    Klik in het venster bij het ‘Installeren van de Recovery Console’ op "Ok".

    Klik in het info scherm op "Ja" als de Recovery Console met succes is geïnstalleerd.

    Klik in het scherm van de disclaimer op "I Agree", de benodigde onderdelen worden nu uitgepakt en middels ERUNT wordt er een register back-up gemaakt.

    Wanneer dit gereed is zal ComboFix vanzelf starten, in het blauwe scherm ziet u de voortgang van de systeemscan die wordt uitgevoerd.

    Belangrijk! gebruik de computer tijdens de scan niet voor andere zaken.

    Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden zoals bijvoorbeeld bij de aanwezigheid van een rootkit, dit is normaal.

    Wanneer ComboFix gereed is, zal het een logbestand aanmaken. Post de inhoud van dit logbestand in het volgende bericht .

    * Noot !!! Indien u één van de onderstaande meldingen krijgt na het gebruik van ComboFix herstart dan de computer.

    Er is geprobeerd een ongeldige bewerking uit te voeren op een registersleutel die is gemarkeerd voor verwijdering.

    Illegal operation attempted on a registry key that has been marked for deletion.

    ComboFix Logbestand plaatsen

    Voeg het logbestand met de naam "ComboFix.txt" toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\ComboFix.txt.)

  • Dizciple

    Duurt wel erg lang…

    Staat nu al hele tijd in blauwe scherm: voltooid deel 1 tm 4..

    Correct, of staatie vast?

  • Dizciple

    Draait al anderhalf uur bijna, gaat hem toch maar stoppen nu hoor. Lees ook veel hier en daar dat dat combofix aardig wat problemen kan gaan geven..

  • Ben

    Hallo,

    Dat klopt bij verkeerd gebruik, maar probeer het eens in veilige modus.

  • Dizciple

    Bleef voor tweede keer in normale modus, en eenmaal in veilige modus zo'n twee uur staan op ‘deel 4’…

    Heeft aantal mappen en bestanden neergekwakt, wat kan ik allemaal weer weghalen als je t niet erg vind?

  • Ben

    Hallo,

    De mappen en alles gaan we straks verwijderen, hoe draait de pc nu?

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.