Bovenstaande bestanden vond ik na een scan van malewarebytes.
Wat kan ik verder nog doen om mijn pc op te schonen? Hij is ook tergend traag met opstarten.
Malwarebytes Anti-Malware 1.70.0.1100
Databaseversie: v2013.01.07.09
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Claudia :: PC_CLAUDIA [administrator]
12-1-2013 17:01:24
mbam-log-2013-01-12 (17-01-24).txt
Scan type: Volledige scan (C:\|D:\|E:\|)
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 513127
Verstreken tijd: 1 uur/uren, 33 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 1
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 2
C:\Users\Claudia\AppData\Roaming\data.dat (Stolen.Data) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Claudia\AppData\Roaming\Cybergate11.exe (Trojan.Agent.Gen) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.5.0
Run by Claudia at 19:23:57 on 2013-01-12
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.6134.3487 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\SysWOW64\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Samsung\Kies\AllShareDMS\AllShareDMS.exe
C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEService64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe
C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.startpagina.nl/
BHO: Adobe PDF Reader Help bij koppelingen: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: WakoopaBHOClass Class: {FB4D29C1-82DE-4b80-8BB0-A7CDDDCD2773} - C:\Users\Claudia\AppData\Local\Wakoopa Shared\WakoopaBHO.dll
EB: {4A62FAC4-1670-430B-8C6B-9C7B53F51798} - <orphaned>
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [AMD Graphic] "C:\Users\Claudia\AppData\Local\AMD Drivers\AMDgraphics.exe"
uRun: [LightScribe Control Panel] "C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
uRun: [Adobe Updater] C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
uPolicies-System: EnableLUA = dword:0
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to AMV Convert Tool... - D:\MP4\AMVConverter\grab.html
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: MediaManager tool grab multimedia file - D:\MP4\MediaManager\grab.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {44C1E3A2-B594-401C-B27A-D1B4476E4797} - hxxps://vpn.coenbakker.nl/XTSAC.cab
DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} - hxxps://vpn.coenbakker.nl/NELX.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://82.92.48.123:8081/activex/AMC.cab
DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} - hxxp://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{36EE3602-E5B0-414D-8677-CBB375D4F173} : DHCPNameServer = 212.54.40.25 212.54.35.25
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 relog_ap
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\Windows\SysWow64\browseui.dll
x64-BHO: GfK Internet Monitor: {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} -
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Windows Mobile-based device management] "C:\Windows\WindowsMobile\wmdSync.exe"
x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide
x64-Run: [Windows] C:\Users\Claudia\AppData\Roaming\svchostwindows\svchost.bat
x64-Run: [SonicWALLNetExtender] "C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe" -hideGUI -clearReboot
x64-Run: [Skytel] "C:\Program Files\Realtek\Audio\HDA\Skytel.exe"
x64-Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
x64-mPolicies-Explorer: NoDrives = dword:0
x64-mPolicies-System: EnableLUA = dword:0
x64-mPolicies-System: EnableUIADesktopToggle = dword:0
x64-IE: {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} - {80A21664-E813-4F79-B965-2058C0F7A84C} -
x64-DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R0 NBVol;Nero Backup Volume Filter Driver;C:\Windows\System32\drivers\NBVol.sys [2011-12-10 72240]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\Windows\System32\drivers\NBVolUp.sys [2011-12-10 15920]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-9-17 55856]
R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-3-20 128456]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [2012-2-15 474168]
R2 SamsungAllShareV2.0;Samsung AllShare PC;C:\Program Files (x86)\Samsung\Kies\AllShareDMS\AllShareDMS.exe [2011-7-16 24992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 Web Assistant Updater;Web Assistant Updater;C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [2012-9-15 188760]
R3 NisSrv;Microsoft Netwerkinspectie;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
R3 SSLDrv;SSL-VPN NetExtender Adapter;C:\Windows\System32\drivers\SSLDrv.sys [2009-2-23 22168]
S2 .1242745991SsTR;1242745991SsTR;C:\ProgramData\Webroot\gebruiker002217.exe [2009-6-2 343435]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 PerfHost;Host van prestatiemeter-DLL;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 SimpleSlideShowServer;SimpleSlideShowServer;"C:\Program Files (x86)\Samsung\Kies\AllShareSlideShowService.exe" --> C:\Program Files (x86)\Samsung\Kies\AllShareSlideShowService.exe [?]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2011-2-9 16448]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-12 89920]
.
=============== File Associations ===============
.
FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2013-01-10 07:57:54 67599240 ----a-w- C:\Windows\System32\mrt.exe
2013-01-08 19:12:21 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-08 19:12:21 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-08 19:12:10 15739912 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-12-16 13:31:20 48128 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-16 13:12:54 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-16 11:08:21 368128 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-16 10:50:29 293376 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 15:49:28 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-23 01:54:35 2770432 ----a-w- C:\Windows\System32\win32k.sys
2012-11-22 04:22:38 456192 ----a-w- C:\Windows\System32\shlwapi.dll
2012-11-22 03:54:36 353280 ----a-w- C:\Windows\SysWow64\shlwapi.dll
2012-11-20 04:22:50 204288 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-20 04:21:04 253952 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-14 07:06:18 17811968 ----a-w- C:\Windows\System32\mshtml.dll
2012-11-14 06:32:33 10925568 ----a-w- C:\Windows\System32\ieframe.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:44 1346048 ----a-w- C:\Windows\System32\urlmon.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 06:02:04 237056 ----a-w- C:\Windows\System32\url.dll
2012-11-14 05:59:52 85504 ----a-w- C:\Windows\System32\jsproxy.dll
2012-11-14 05:58:36 816640 ----a-w- C:\Windows\System32\jscript.dll
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:55:45 2144768 ----a-w- C:\Windows\System32\iertutil.dll
2012-11-14 05:55:26 729088 ----a-w- C:\Windows\System32\msfeeds.dll
2012-11-14 05:53:22 96768 ----a-w- C:\Windows\System32\mshtmled.dll
2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 05:46:25 248320 ----a-w- C:\Windows\System32\ieui.dll
2012-11-14 02:48:26 12320256 ----a-w- C:\Windows\SysWow64\mshtml.dll
2012-11-14 02:14:59 9738240 ----a-w- C:\Windows\SysWow64\ieframe.dll
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:44 1103872 ----a-w- C:\Windows\SysWow64\urlmon.dll
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:55:46 231936 ----a-w- C:\Windows\SysWow64\url.dll
2012-11-14 01:51:44 65024 ----a-w- C:\Windows\SysWow64\jsproxy.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:49:19 717824 ----a-w- C:\Windows\SysWow64\jscript.dll
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:47:20 607744 ----a-w- C:\Windows\SysWow64\msfeeds.dll
2012-11-14 01:46:38 1793024 ----a-w- C:\Windows\SysWow64\iertutil.dll
2012-11-14 01:45:01 73216 ----a-w- C:\Windows\SysWow64\mshtmled.dll
2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-14 01:41:30 176640 ----a-w- C:\Windows\SysWow64\ieui.dll
2012-11-13 01:45:48 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-11-13 01:29:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-11-07 19:22:30 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-11-07 19:22:29 289768 ----a-w- C:\Windows\System32\javaws.exe
2012-11-07 19:22:29 189416 ----a-w- C:\Windows\System32\javaw.exe
2012-11-07 19:22:28 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-11-07 19:22:28 188904 ----a-w- C:\Windows\System32\java.exe
2012-11-07 19:22:28 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-11-02 10:47:16 1869824 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-02 10:47:16 1794560 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-02 10:45:52 477696 ----a-w- C:\Windows\System32\dpnet.dll
2012-11-02 10:45:51 68096 ----a-w- C:\Windows\System32\dpnathlp.dll
2012-11-02 10:19:34 1400832 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-02 10:19:33 1248768 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-11-02 10:18:17 376320 ----a-w- C:\Windows\SysWow64\dpnet.dll
2012-11-02 08:59:56 26112 ----a-w- C:\Windows\System32\dpnsvr.exe
2012-11-02 08:26:06 23040 ----a-w- C:\Windows\SysWow64\dpnsvr.exe
2012-10-25 02:12:26 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2012-10-25 02:12:26 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2010-02-16 18:46:32 7032780 ----a-w- C:\Program Files\SABnzbd-0.5.0RC6-win32-setup.exe
2010-01-09 10:18:11 3004344 ----a-w- C:\Program Files\BitTorrent-6.2.exe
2009-05-20 03:56:34 65912880 ----a-w- C:\Program Files\20080128135518500_Samsung_PC_Studio_321_HA4.exe
2009-05-20 03:55:57 8420211 ----a-w- C:\Program Files\20070813082717640_Samsung_USB_Driver_Installer.exe
.
============= FINISH: 19:26:56,63 ===============
GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-12 20:50:50
Windows 6.0.6002 Service Pack 2 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3 SAMSUNG_HD103UJ rev.1AA01113 931,51GB
Running: xse2rybl.exe; Driver: C:\Users\Claudia\AppData\Local\Temp\pwlyykog.sys
---- User code sections - GMER 2.0 ----
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WININET.dll!HttpAddRequestHeadersA 000000007755c2b0 5 bytes JMP 000000016fff00d8
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WININET.dll!HttpAddRequestHeadersW 0000000077568074 5 bytes JMP 000000016fff0110
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WINMM.dll!waveOutWrite 000007fefc7e3c90 5 bytes JMP 000007fffc7d00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_A 0000000077926300 7 bytes JMP 00000001037f04c8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_W 00000000779415bc 7 bytes JMP 00000001037f0500
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\kernel32.dll!CreateThread 00000000777fb580 9 bytes JMP 00000001037f0420
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefece16f0 7 bytes [68, 38, 05, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefe6f1190 10 bytes [68, 18, 06, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefe6f33d0 7 bytes [68, A8, 05, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefe6f42e0 6 bytes [68, 70, 05, 7F, 03, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefe6f67c0 10 bytes [68, E0, 05, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefe749b10 9 bytes [68, 78, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheetW 000007fefcf2c404 7 bytes [68, 08, 03, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheet 000007fefcf2c414 9 bytes [68, 40, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefe36b63c 9 bytes [68, B0, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!closesocket 000007fefe801a10 5 bytes JMP 000007fffe5c0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!recv 000007fefe802820 5 bytes JMP 000007fffe5c00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!getaddrinfo 000007fefe8030a0 5 bytes JMP 000007fffe5c01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!connect 000007fefe8033c0 5 bytes JMP 000007fffe5c0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!send 000007fefe8066e0 5 bytes JMP 000007fffe5c0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefe80af70 9 bytes JMP 000007fffe5c01b8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_A 0000000077926300 7 bytes JMP 0000000103e904c8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_W 00000000779415bc 7 bytes JMP 0000000103e90500
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\kernel32.dll!CreateThread 00000000777fb580 9 bytes JMP 0000000103e90420
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefece16f0 7 bytes [68, 38, 05, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefe6f1190 10 bytes [68, 18, 06, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefe6f33d0 7 bytes [68, A8, 05, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefe6f42e0 6 bytes [68, 70, 05, E9, 03, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefe6f67c0 10 bytes [68, E0, 05, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefe749b10 9 bytes [68, 78, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheetW 000007fefcf2c404 7 bytes [68, 08, 03, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheet 000007fefcf2c414 9 bytes [68, 40, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefe36b63c 9 bytes [68, B0, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!closesocket 000007fefe801a10 5 bytes JMP 000007fffe5c0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!recv 000007fefe802820 5 bytes JMP 000007fffe5c00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!getaddrinfo 000007fefe8030a0 5 bytes JMP 000007fffe5c01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!connect 000007fefe8033c0 5 bytes JMP 000007fffe5c0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!send 000007fefe8066e0 5 bytes JMP 000007fffe5c0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefe80af70 9 bytes JMP 000007fffe5c01b8
---- Kernel IAT/EAT - GMER 2.0 ----
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [fffffa6000603578] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [fffffa600060356c] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [fffffa60006035a0] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [fffffa60006035c4] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [fffffa60006035ac] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [fffffa60006035b8] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [fffffa6000603584] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [fffffa6000603590] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\hal.dll[KDCOM.dll!KdRestore] [fffffa60006035ac] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!HalPrivateDispatchTable] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!atol] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeFindConfigurationEntry] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!MmMapIoSpace] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!_strupr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!InbvDisplayString] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KdDebuggerNotPresent] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!strstr] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!HalQueryRealTimeClock] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!KdComPortInUse] [?]
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef9472750] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef9472b98] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef9477de0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef9478130] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef9471908] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef9471c00] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef94781d8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef9472878] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef9477a5c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmIncrement] [7fef9476c48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef94777bc] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef9477064] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef9476544] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef9475e30] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
---- Trace I/O - GMER 2.0 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys >>UNKNOWN [0xfffffa8007a78334]<< ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys fffffa8007a78334
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006a7a060] fffffa8006a7a060
Trace 3 CLASSPNP.SYS[fffffa6000fafc33] -> nt!IofCallDriver -> [0xfffffa800658c720] fffffa800658c720
Trace 5 acpi.sys[fffffa60008defde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa80065984b0] fffffa80065984b0
Trace \Driver\atapi[0xfffffa800656fae0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8007a78334 fffffa8007a78334
---- Threads - GMER 2.0 ----
Thread C:\Windows\system32\svchost.exe [1664:2136] 00000000000a2d50
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3136] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3140] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3144] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3152] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3236] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3240] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3492] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3500] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3520] 0000000066a653b7
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3524] 0000000066a653b7
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3864] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3512] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:8824] 0000000073cc6488
Thread C:\Windows\Explorer.EXE [4364:4460] 0000000003b21430
Thread C:\Windows\Explorer.EXE [4364:4468] 00000000041c3220
Thread C:\Windows\Explorer.EXE [4364:4524] 00000000041abd78
Thread C:\Windows\Explorer.EXE [4364:4528] 00000000041ab704
Thread C:\Windows\Explorer.EXE [4364:1716] 00000000041aa018
Thread C:\Windows\Explorer.EXE [4364:7992] 000000018003b540
Thread C:\Windows\Explorer.EXE [4364:6236] 000000018002f430
Thread C:\Windows\Explorer.EXE [4364:9028] 00000000041ab8ac
---- Processes - GMER 2.0 ----
Library ? (*** suspicious ***) @ C:\Windows\system32\lsass.exe [948] 000007fefd6a0000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988] 0000000074070000
---- Disk sectors - GMER 2.0 ----
Disk \Device\Harddisk0\DR0 sector 0: rootkit-like behavior
Disk \Device\Harddisk0\DR0 suspicious partition 3 80 (A) 17 Hidd HPFS/NTFS NTFS 1 MB offset 1953521664
---- EOF - GMER 2.0 ----
Wat kan ik verder nog doen om mijn pc op te schonen? Hij is ook tergend traag met opstarten.
Malwarebytes Anti-Malware 1.70.0.1100
Databaseversie: v2013.01.07.09
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Claudia :: PC_CLAUDIA [administrator]
12-1-2013 17:01:24
mbam-log-2013-01-12 (17-01-24).txt
Scan type: Volledige scan (C:\|D:\|E:\|)
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 513127
Verstreken tijd: 1 uur/uren, 33 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 1
HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 2
C:\Users\Claudia\AppData\Roaming\data.dat (Stolen.Data) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Claudia\AppData\Roaming\Cybergate11.exe (Trojan.Agent.Gen) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.5.0
Run by Claudia at 19:23:57 on 2013-01-12
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.6134.3487 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\SysWOW64\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Samsung\Kies\AllShareDMS\AllShareDMS.exe
C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEService64.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe
C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.startpagina.nl/
BHO: Adobe PDF Reader Help bij koppelingen: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: WakoopaBHOClass Class: {FB4D29C1-82DE-4b80-8BB0-A7CDDDCD2773} - C:\Users\Claudia\AppData\Local\Wakoopa Shared\WakoopaBHO.dll
EB: {4A62FAC4-1670-430B-8C6B-9C7B53F51798} - <orphaned>
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [AMD Graphic] "C:\Users\Claudia\AppData\Local\AMD Drivers\AMDgraphics.exe"
uRun: [LightScribe Control Panel] "C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
uRun: [Adobe Updater] C:\Users\Claudia\AppData\Roaming\Adobe Reader\Adobe Updater Reader.exe
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoDrives = dword:0
uPolicies-System: EnableLUA = dword:0
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to AMV Convert Tool... - D:\MP4\AMVConverter\grab.html
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: MediaManager tool grab multimedia file - D:\MP4\MediaManager\grab.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {44C1E3A2-B594-401C-B27A-D1B4476E4797} - hxxps://vpn.coenbakker.nl/XTSAC.cab
DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} - hxxps://vpn.coenbakker.nl/NELX.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://82.92.48.123:8081/activex/AMC.cab
DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} - hxxp://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{36EE3602-E5B0-414D-8677-CBB375D4F173} : DHCPNameServer = 212.54.40.25 212.54.35.25
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 relog_ap
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - C:\Windows\SysWow64\browseui.dll
x64-BHO: GfK Internet Monitor: {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} -
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Windows Mobile-based device management] "C:\Windows\WindowsMobile\wmdSync.exe"
x64-Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe -hide
x64-Run: [Windows] C:\Users\Claudia\AppData\Roaming\svchostwindows\svchost.bat
x64-Run: [SonicWALLNetExtender] "C:\Program Files (x86)\SonicWALL\SSL-VPN\NetExtender\NEGui.exe" -hideGUI -clearReboot
x64-Run: [Skytel] "C:\Program Files\Realtek\Audio\HDA\Skytel.exe"
x64-Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
x64-mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
x64-mPolicies-Explorer: NoDrives = dword:0
x64-mPolicies-System: EnableLUA = dword:0
x64-mPolicies-System: EnableUIADesktopToggle = dword:0
x64-IE: {4BEEA052-726D-4A6E-B65D-A6BD07C263F3} - {80A21664-E813-4F79-B965-2058C0F7A84C} -
x64-DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2012-8-30 228768]
R0 NBVol;Nero Backup Volume Filter Driver;C:\Windows\System32\drivers\NBVol.sys [2011-12-10 72240]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;C:\Windows\System32\drivers\NBVolUp.sys [2011-12-10 15920]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-9-17 55856]
R2 FontCache;Windows Font Cache Service;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-3-20 128456]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [2012-2-15 474168]
R2 SamsungAllShareV2.0;Samsung AllShare PC;C:\Program Files (x86)\Samsung\Kies\AllShareDMS\AllShareDMS.exe [2011-7-16 24992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 Web Assistant Updater;Web Assistant Updater;C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [2012-9-15 188760]
R3 NisSrv;Microsoft Netwerkinspectie;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896]
R3 SSLDrv;SSL-VPN NetExtender Adapter;C:\Windows\System32\drivers\SSLDrv.sys [2009-2-23 22168]
S2 .1242745991SsTR;1242745991SsTR;C:\ProgramData\Webroot\gebruiker002217.exe [2009-6-2 343435]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 PerfHost;Host van prestatiemeter-DLL;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 SimpleSlideShowServer;SimpleSlideShowServer;"C:\Program Files (x86)\Samsung\Kies\AllShareSlideShowService.exe" --> C:\Program Files (x86)\Samsung\Kies\AllShareSlideShowService.exe [?]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2011-2-9 16448]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-12 89920]
.
=============== File Associations ===============
.
FileExt: .jse: JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2013-01-10 07:57:54 67599240 ----a-w- C:\Windows\System32\mrt.exe
2013-01-08 19:12:21 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-08 19:12:21 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-08 19:12:10 15739912 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-12-16 13:31:20 48128 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-16 13:12:54 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-16 11:08:21 368128 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-16 10:50:29 293376 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 15:49:28 24176 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-11-23 01:54:35 2770432 ----a-w- C:\Windows\System32\win32k.sys
2012-11-22 04:22:38 456192 ----a-w- C:\Windows\System32\shlwapi.dll
2012-11-22 03:54:36 353280 ----a-w- C:\Windows\SysWow64\shlwapi.dll
2012-11-20 04:22:50 204288 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-20 04:21:04 253952 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-14 07:06:18 17811968 ----a-w- C:\Windows\System32\mshtml.dll
2012-11-14 06:32:33 10925568 ----a-w- C:\Windows\System32\ieframe.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:44 1346048 ----a-w- C:\Windows\System32\urlmon.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 06:02:04 237056 ----a-w- C:\Windows\System32\url.dll
2012-11-14 05:59:52 85504 ----a-w- C:\Windows\System32\jsproxy.dll
2012-11-14 05:58:36 816640 ----a-w- C:\Windows\System32\jscript.dll
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:55:45 2144768 ----a-w- C:\Windows\System32\iertutil.dll
2012-11-14 05:55:26 729088 ----a-w- C:\Windows\System32\msfeeds.dll
2012-11-14 05:53:22 96768 ----a-w- C:\Windows\System32\mshtmled.dll
2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 05:46:25 248320 ----a-w- C:\Windows\System32\ieui.dll
2012-11-14 02:48:26 12320256 ----a-w- C:\Windows\SysWow64\mshtml.dll
2012-11-14 02:14:59 9738240 ----a-w- C:\Windows\SysWow64\ieframe.dll
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:44 1103872 ----a-w- C:\Windows\SysWow64\urlmon.dll
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:55:46 231936 ----a-w- C:\Windows\SysWow64\url.dll
2012-11-14 01:51:44 65024 ----a-w- C:\Windows\SysWow64\jsproxy.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:49:19 717824 ----a-w- C:\Windows\SysWow64\jscript.dll
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:47:20 607744 ----a-w- C:\Windows\SysWow64\msfeeds.dll
2012-11-14 01:46:38 1793024 ----a-w- C:\Windows\SysWow64\iertutil.dll
2012-11-14 01:45:01 73216 ----a-w- C:\Windows\SysWow64\mshtmled.dll
2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-14 01:41:30 176640 ----a-w- C:\Windows\SysWow64\ieui.dll
2012-11-13 01:45:48 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-11-13 01:29:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-11-07 19:22:30 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-11-07 19:22:29 289768 ----a-w- C:\Windows\System32\javaws.exe
2012-11-07 19:22:29 189416 ----a-w- C:\Windows\System32\javaw.exe
2012-11-07 19:22:28 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-11-07 19:22:28 188904 ----a-w- C:\Windows\System32\java.exe
2012-11-07 19:22:28 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-11-02 10:47:16 1869824 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-02 10:47:16 1794560 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-02 10:45:52 477696 ----a-w- C:\Windows\System32\dpnet.dll
2012-11-02 10:45:51 68096 ----a-w- C:\Windows\System32\dpnathlp.dll
2012-11-02 10:19:34 1400832 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-02 10:19:33 1248768 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-11-02 10:18:17 376320 ----a-w- C:\Windows\SysWow64\dpnet.dll
2012-11-02 08:59:56 26112 ----a-w- C:\Windows\System32\dpnsvr.exe
2012-11-02 08:26:06 23040 ----a-w- C:\Windows\SysWow64\dpnsvr.exe
2012-10-25 02:12:26 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2012-10-25 02:12:26 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2010-02-16 18:46:32 7032780 ----a-w- C:\Program Files\SABnzbd-0.5.0RC6-win32-setup.exe
2010-01-09 10:18:11 3004344 ----a-w- C:\Program Files\BitTorrent-6.2.exe
2009-05-20 03:56:34 65912880 ----a-w- C:\Program Files\20080128135518500_Samsung_PC_Studio_321_HA4.exe
2009-05-20 03:55:57 8420211 ----a-w- C:\Program Files\20070813082717640_Samsung_USB_Driver_Installer.exe
.
============= FINISH: 19:26:56,63 ===============
GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-12 20:50:50
Windows 6.0.6002 Service Pack 2 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3 SAMSUNG_HD103UJ rev.1AA01113 931,51GB
Running: xse2rybl.exe; Driver: C:\Users\Claudia\AppData\Local\Temp\pwlyykog.sys
---- User code sections - GMER 2.0 ----
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WININET.dll!HttpAddRequestHeadersA 000000007755c2b0 5 bytes JMP 000000016fff00d8
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WININET.dll!HttpAddRequestHeadersW 0000000077568074 5 bytes JMP 000000016fff0110
.text C:\Windows\Explorer.EXE[4364] C:\Windows\system32\WINMM.dll!waveOutWrite 000007fefc7e3c90 5 bytes JMP 000007fffc7d00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_A 0000000077926300 7 bytes JMP 00000001037f04c8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_W 00000000779415bc 7 bytes JMP 00000001037f0500
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\kernel32.dll!CreateThread 00000000777fb580 9 bytes JMP 00000001037f0420
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefece16f0 7 bytes [68, 38, 05, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefe6f1190 10 bytes [68, 18, 06, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefe6f33d0 7 bytes [68, A8, 05, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefe6f42e0 6 bytes [68, 70, 05, 7F, 03, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefe6f67c0 10 bytes [68, E0, 05, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefe749b10 9 bytes [68, 78, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheetW 000007fefcf2c404 7 bytes [68, 08, 03, 7F, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheet 000007fefcf2c414 9 bytes [68, 40, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefe36b63c 9 bytes [68, B0, 03, 7F, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!closesocket 000007fefe801a10 5 bytes JMP 000007fffe5c0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!recv 000007fefe802820 5 bytes JMP 000007fffe5c00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!getaddrinfo 000007fefe8030a0 5 bytes JMP 000007fffe5c01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!connect 000007fefe8033c0 5 bytes JMP 000007fffe5c0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!send 000007fefe8066e0 5 bytes JMP 000007fffe5c0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5920] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefe80af70 9 bytes JMP 000007fffe5c01b8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_A 0000000077926300 7 bytes JMP 0000000103e904c8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ntdll.dll!NtdllDefWindowProc_W 00000000779415bc 7 bytes JMP 0000000103e90500
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\kernel32.dll!CreateThread 00000000777fb580 9 bytes JMP 0000000103e90420
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\ole32.dll!OleLoadFromStream 000007fefece16f0 7 bytes [68, 38, 05, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!VariantClear 000007fefe6f1190 10 bytes [68, 18, 06, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!SysFreeString 000007fefe6f33d0 7 bytes [68, A8, 05, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 000007fefe6f42e0 6 bytes [68, 70, 05, E9, 03, C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 000007fefe6f67c0 10 bytes [68, E0, 05, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect 000007fefe749b10 9 bytes [68, 78, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheetW 000007fefcf2c404 7 bytes [68, 08, 03, E9, 03, C3, CC]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll!PropertySheet 000007fefcf2c414 9 bytes [68, 40, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\comdlg32.dll!PageSetupDlgW 000007fefe36b63c 9 bytes [68, B0, 03, E9, 03, C3, CC, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!closesocket 000007fefe801a10 5 bytes JMP 000007fffe5c0148
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!recv 000007fefe802820 5 bytes JMP 000007fffe5c00d8
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!getaddrinfo 000007fefe8030a0 5 bytes JMP 000007fffe5c01f0
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!connect 000007fefe8033c0 5 bytes JMP 000007fffe5c0110
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!send 000007fefe8066e0 5 bytes JMP 000007fffe5c0180
.text C:\Program Files\Internet Explorer\iexplore.exe[5492] C:\Windows\system32\WS2_32.dll!gethostbyname 000007fefe80af70 9 bytes JMP 000007fffe5c01b8
---- Kernel IAT/EAT - GMER 2.0 ----
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [fffffa6000603578] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [fffffa600060356c] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [fffffa60006035a0] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [fffffa60006035c4] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [fffffa60006035ac] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [fffffa60006035b8] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [fffffa6000603584] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [fffffa6000603590] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\hal.dll[KDCOM.dll!KdRestore] [fffffa60006035ac] \SystemRoot\system32\kdcom.dll [unknown section]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!HalPrivateDispatchTable] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!atol] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KeFindConfigurationEntry] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!MmMapIoSpace] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!_strupr] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!InbvDisplayString] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!KdDebuggerNotPresent] [?]
IAT C:\Windows\system32\kdcom.dll[ntoskrnl.exe!strstr] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!HalQueryRealTimeClock] [?]
IAT C:\Windows\system32\kdcom.dll[HAL.dll!KdComPortInUse] [?]
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef9472750] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef9472b98] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef9477de0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef9478130] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef9471908] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef9471c00] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef94781d8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef9472878] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef9477a5c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmIncrement] [7fef9476c48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef94777bc] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef9477064] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef9476544] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3056] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef9475e30] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
---- Trace I/O - GMER 2.0 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys >>UNKNOWN [0xfffffa8007a78334]<< ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys fffffa8007a78334
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006a7a060] fffffa8006a7a060
Trace 3 CLASSPNP.SYS[fffffa6000fafc33] -> nt!IofCallDriver -> [0xfffffa800658c720] fffffa800658c720
Trace 5 acpi.sys[fffffa60008defde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa80065984b0] fffffa80065984b0
Trace \Driver\atapi[0xfffffa800656fae0] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8007a78334 fffffa8007a78334
---- Threads - GMER 2.0 ----
Thread C:\Windows\system32\svchost.exe [1664:2136] 00000000000a2d50
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3136] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3140] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3144] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3152] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3236] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3240] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3492] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3500] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3520] 0000000066a653b7
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3524] 0000000066a653b7
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3864] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:3512] 0000000066f31f1f
Thread C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988:8824] 0000000073cc6488
Thread C:\Windows\Explorer.EXE [4364:4460] 0000000003b21430
Thread C:\Windows\Explorer.EXE [4364:4468] 00000000041c3220
Thread C:\Windows\Explorer.EXE [4364:4524] 00000000041abd78
Thread C:\Windows\Explorer.EXE [4364:4528] 00000000041ab704
Thread C:\Windows\Explorer.EXE [4364:1716] 00000000041aa018
Thread C:\Windows\Explorer.EXE [4364:7992] 000000018003b540
Thread C:\Windows\Explorer.EXE [4364:6236] 000000018002f430
Thread C:\Windows\Explorer.EXE [4364:9028] 00000000041ab8ac
---- Processes - GMER 2.0 ----
Library ? (*** suspicious ***) @ C:\Windows\system32\lsass.exe [948] 000007fefd6a0000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [1988] 0000000074070000
---- Disk sectors - GMER 2.0 ----
Disk \Device\Harddisk0\DR0 sector 0: rootkit-like behavior
Disk \Device\Harddisk0\DR0 suspicious partition 3 80 (A) 17 Hidd HPFS/NTFS NTFS 1 MB offset 1953521664
---- EOF - GMER 2.0 ----
Comment