Hallo, op deze computer is al een tijdje sprake van hardnekkige pop-ups (die niet verdwijnen met AdBlock) en nog vervelender, talloze advertenties in de browser zelf. Op een willekeurige YouTube-pagina zijn bijvoorbeeld op zijn minst 5 venstertjes met irritante advertenties niet van YouTube. Ook hebben zich vervelende programma's in de pc genesteld die zich voordoen als anti-spyware programma, als prestatieverbeteringsprogramma (SpeedUpMyPc) of als backup-programma (MyPcBackup). Deze heb ik deels weg kunnen gooien, maar ze lijken soms weer terug te komen.
Het grootste probleem is een programma dat ''BrowseToSave'' heet, die is verantwoordelijk voor alle on-screen advertenties. Ik heb al eens eerder gescand met MBAM, en die heeft dit programma toen deels weggegooid, maar er is blijkbaar nog steeds iets van over, want ik krijg nog steeds advertenties. Ik heb de sticky gelezen en de stappen gevolgd, hier zijn de logjes (MBAM vond dit keer niks) :
MBAM log:
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.06.17.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16618
Eeftink :: EEFTINK-LAPTOP [administrator]
17-6-2013 15:02:35
mbam-log-2013-06-17 (15-02-35).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 215947
Verstreken tijd: 7 minuut/minuten, 34 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS log :
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16611 BrowserJavaVersion: 10.13.2
Run by Eeftink at 15:53:22 on 2013-06-17
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.1900.380 [GMT 2:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\MyPC Backup\BackupStack.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\Windows\system32\lxducoms.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Users\Eeftink\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\Desktop\Defogger.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\notepad.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.claro-search.com/?affID=117423&tt=5212_6&babsrc=HP_ss&mntrId=4ac4b68200000000000016de2bae98b2
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
StartupFolder: C:\Users\Eeftink\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Eeftink\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Eeftink\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MYPCBA~1.LNK - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986} : DHCPNameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\3596475636F6D6342354131483 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\3596475636F6D6F5466673735383 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\550534234323238383533393 : DHCPNameServer = 192.168.192.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\8656E6B6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\A597F507279667164756F5050505253485 : DHCPNameServer = 192.168.1.254 195.241.77.51 195.241.77.52
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-5-7 283200]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-11-8 98208]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-1 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-1 76448]
R2 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2013-5-27 32808]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-1 36000]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-1 298656]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-1 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-1 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-1 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-1 154272]
R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-1 280224]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-21 25928]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-11-8 335464]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-11-8 436840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
.
=============== Created Last 30 ================
.
2013-06-16 07:41:11 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-06-16 07:41:11 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-06-16 07:41:10 279040 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2013-06-16 07:41:10 218112 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2013-06-14 08:02:28 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4B658DED-DA4B-4C43-9FEB-4A0E432F836F}\mpengine.dll
2013-06-12 08:11:52 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-29 17:00:44 -------- d-----w- C:\Program Files (x86)\MyPC Backup
2013-05-21 11:11:06 -------- d-sh--w- C:\$RECYCLE.BIN
2013-05-21 10:36:14 98816 ----a-w- C:\Windows\sed.exe
2013-05-21 10:36:14 256000 ----a-w- C:\Windows\PEV.exe
2013-05-21 10:36:14 208896 ----a-w- C:\Windows\MBR.exe
2013-05-21 10:35:35 -------- d-----w- C:\Users\Eeftink\AppData\Local\Avg2013
2013-05-21 08:54:20 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-05-19 23:07:46 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-05-19 15:33:31 -------- d-----w- C:\Users\Eeftink\AppData\Local\{BEFA27A8-9C42-47B4-B971-01071930B322}
.
==================== Find3M ====================
.
2013-06-12 18:18:45 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 18:18:45 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-17 01:25:57 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-05-17 01:25:27 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-05-17 01:25:26 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-05-17 01:25:26 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-05-17 00:59:03 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-05-17 00:58:10 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-05-17 00:58:08 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-05-17 00:58:08 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-05-14 12:23:25 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-14 08:40:13 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-02 00:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-04-17 07:02:06 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-04-17 06:24:46 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-03-31 22:52:16 1887232 ----a-w- C:\Windows\System32\d3d11.dll
.
============= FINISH: 15:55:51,83 ===============
en tenslotte de GMER log
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-17 16:16:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.ES2O 298,09GB
Running: 9f1g0imv.exe; Driver: C:\Users\Eeftink\AppData\Local\Temp\axdiikog.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [1004:1044] 000007fefb4c331c
Thread C:\Windows\System32\svchost.exe [1004:1256] 000007fefa8a59a0
Thread C:\Windows\System32\svchost.exe [1004:1456] 000007fefd2c1a70
Thread C:\Windows\System32\svchost.exe [1004:2732] 000007fef17420c0
Thread C:\Windows\System32\svchost.exe [1004:2752] 000007fef17426a8
Thread C:\Windows\System32\svchost.exe [1004:2756] 000007fef17429dc
Thread C:\Windows\System32\svchost.exe [1004:2536] 000007fef35c44e0
Thread C:\Windows\System32\svchost.exe [1004:2988] 000007fef38c88f8
Thread C:\Windows\system32\svchost.exe [488:2564] 000007fef2f10d00
Thread C:\Windows\system32\svchost.exe [488:2568] 000007fef2bd9498
Thread C:\Windows\system32\svchost.exe [488:3024] 000007fef3865124
Thread C:\Windows\system32\svchost.exe [488:2996] 000007fefa26506c
Thread C:\Windows\system32\svchost.exe [488:1704] 000007fef1a91c20
Thread C:\Windows\system32\svchost.exe [488:2512] 000007fef1a91c20
Thread C:\Windows\system32\svchost.exe [488:4472] 000007fefb404164
Thread C:\Windows\system32\svchost.exe [488:236] 000007fef1211ab0
Thread C:\Windows\system32\WLANExt.exe [1268:1464] 000000018000d8b8
Thread C:\Windows\system32\WLANExt.exe [1268:1468] 000000018000d8d4
Thread C:\Windows\system32\WLANExt.exe [1268:1472] 000000018000d89c
Thread C:\Windows\system32\WLANExt.exe [1268:1476] 0000000180027b90
Thread C:\Windows\system32\WLANExt.exe [1268:1480] 000007fefa3c2f9c
Thread C:\Windows\System32\spoolsv.exe [1392:2928] 0000000051074ba0
Thread C:\Windows\System32\spoolsv.exe [1392:232] 000000006508e0e0
Thread C:\Windows\System32\spoolsv.exe [1392:540] 000007fef12b10c8
Thread C:\Windows\System32\spoolsv.exe [1392:852] 000007fef0a26144
Thread C:\Windows\System32\spoolsv.exe [1392:428] 000007fef5f35fd0
Thread C:\Windows\System32\spoolsv.exe [1392:596] 000007fef0a03438
Thread C:\Windows\System32\spoolsv.exe [1392:1060] 000007fef5f363ec
Thread C:\Windows\System32\spoolsv.exe [1392:1108] 000007fefa145e5c
Thread C:\Windows\System32\spoolsv.exe [1392:304] 000007fefa175074
Thread C:\Windows\system32\svchost.exe [1424:1788] 000007fef64835c0
Thread C:\Windows\system32\svchost.exe [1424:2636] 000007fef6485600
Thread C:\Windows\system32\svchost.exe [1424:2780] 000007fef12e2940
Thread C:\Windows\system32\svchost.exe [1424:1364] 000007fefb102888
Thread C:\Windows\system32\svchost.exe [1424:3252] 000007fefb102a40
Thread C:\Windows\system32\svchost.exe [1768:1928] 000007fef5f35fd0
Thread C:\Windows\system32\svchost.exe [1768:1932] 000007fef5f363ec
Thread C:\Windows\system32\svchost.exe [1768:2824] 000007fef13e8470
Thread C:\Windows\system32\svchost.exe [1768:2828] 000007fef13f2418
Thread C:\Windows\System32\svchost.exe [2136:2524] 000007fef2559688
Thread C:\Windows\system32\wbem\wmiprvse.exe [2532:2168] 000007fef1a91c20
Thread C:\Windows\system32\taskhost.exe [1836:2972] 000007fefb8d1010
Thread C:\Windows\system32\taskhost.exe [1836:3772] 000007fef25a5170
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BackupStack
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 16
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 2
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] C:\Program Files (x86)\MyPC Backup\BackupStack.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] Computer Backup (MyPC Backup)
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\services\BackupStack
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74de2baf0842
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74de2baf0842 (not active ControlSet)
---- EOF - GMER 2.1 ----
Ik hoop dat jullie er iets mee kunnen. Alvast bedankt,
Rob
Het grootste probleem is een programma dat ''BrowseToSave'' heet, die is verantwoordelijk voor alle on-screen advertenties. Ik heb al eens eerder gescand met MBAM, en die heeft dit programma toen deels weggegooid, maar er is blijkbaar nog steeds iets van over, want ik krijg nog steeds advertenties. Ik heb de sticky gelezen en de stappen gevolgd, hier zijn de logjes (MBAM vond dit keer niks) :
MBAM log:
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.06.17.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16618
Eeftink :: EEFTINK-LAPTOP [administrator]
17-6-2013 15:02:35
mbam-log-2013-06-17 (15-02-35).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 215947
Verstreken tijd: 7 minuut/minuten, 34 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS log :
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16611 BrowserJavaVersion: 10.13.2
Run by Eeftink at 15:53:22 on 2013-06-17
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.1900.380 [GMT 2:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files (x86)\MyPC Backup\BackupStack.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
C:\Windows\system32\lxducoms.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Users\Eeftink\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Eeftink\Desktop\Defogger.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\notepad.exe
C:\Users\Eeftink\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.claro-search.com/?affID=117423&tt=5212_6&babsrc=HP_ss&mntrId=4ac4b68200000000000016de2bae98b2
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
StartupFolder: C:\Users\Eeftink\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Eeftink\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Eeftink\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MYPCBA~1.LNK - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986} : DHCPNameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\3596475636F6D6342354131483 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\3596475636F6D6F5466673735383 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\550534234323238383533393 : DHCPNameServer = 192.168.192.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\8656E6B6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{D1830E4F-4D3B-49A0-BDBD-1D3FDE316986}\A597F507279667164756F5050505253485 : DHCPNameServer = 192.168.1.254 195.241.77.51 195.241.77.52
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-5-7 283200]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-11-8 98208]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-1 138400]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-1 76448]
R2 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2013-5-27 32808]
R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-1 36000]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-1 298656]
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-1 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-1 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-1 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-1 154272]
R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-1 280224]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-5-21 25928]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-11-8 335464]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-11-8 436840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
.
=============== Created Last 30 ================
.
2013-06-16 07:41:11 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-06-16 07:41:11 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-06-16 07:41:10 279040 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2013-06-16 07:41:10 218112 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2013-06-14 08:02:28 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4B658DED-DA4B-4C43-9FEB-4A0E432F836F}\mpengine.dll
2013-06-12 08:11:52 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-29 17:00:44 -------- d-----w- C:\Program Files (x86)\MyPC Backup
2013-05-21 11:11:06 -------- d-sh--w- C:\$RECYCLE.BIN
2013-05-21 10:36:14 98816 ----a-w- C:\Windows\sed.exe
2013-05-21 10:36:14 256000 ----a-w- C:\Windows\PEV.exe
2013-05-21 10:36:14 208896 ----a-w- C:\Windows\MBR.exe
2013-05-21 10:35:35 -------- d-----w- C:\Users\Eeftink\AppData\Local\Avg2013
2013-05-21 08:54:20 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-05-19 23:07:46 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-05-19 15:33:31 -------- d-----w- C:\Users\Eeftink\AppData\Local\{BEFA27A8-9C42-47B4-B971-01071930B322}
.
==================== Find3M ====================
.
2013-06-12 18:18:45 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 18:18:45 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-17 01:25:57 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-05-17 01:25:27 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-05-17 01:25:26 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-05-17 01:25:26 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-05-17 00:59:03 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-05-17 00:58:10 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-05-17 00:58:08 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-05-17 00:58:08 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-05-14 12:23:25 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-14 08:40:13 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-02 00:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-04-17 07:02:06 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-04-17 06:24:46 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-03-31 22:52:16 1887232 ----a-w- C:\Windows\System32\d3d11.dll
.
============= FINISH: 15:55:51,83 ===============
en tenslotte de GMER log
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-17 16:16:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.ES2O 298,09GB
Running: 9f1g0imv.exe; Driver: C:\Users\Eeftink\AppData\Local\Temp\axdiikog.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [1004:1044] 000007fefb4c331c
Thread C:\Windows\System32\svchost.exe [1004:1256] 000007fefa8a59a0
Thread C:\Windows\System32\svchost.exe [1004:1456] 000007fefd2c1a70
Thread C:\Windows\System32\svchost.exe [1004:2732] 000007fef17420c0
Thread C:\Windows\System32\svchost.exe [1004:2752] 000007fef17426a8
Thread C:\Windows\System32\svchost.exe [1004:2756] 000007fef17429dc
Thread C:\Windows\System32\svchost.exe [1004:2536] 000007fef35c44e0
Thread C:\Windows\System32\svchost.exe [1004:2988] 000007fef38c88f8
Thread C:\Windows\system32\svchost.exe [488:2564] 000007fef2f10d00
Thread C:\Windows\system32\svchost.exe [488:2568] 000007fef2bd9498
Thread C:\Windows\system32\svchost.exe [488:3024] 000007fef3865124
Thread C:\Windows\system32\svchost.exe [488:2996] 000007fefa26506c
Thread C:\Windows\system32\svchost.exe [488:1704] 000007fef1a91c20
Thread C:\Windows\system32\svchost.exe [488:2512] 000007fef1a91c20
Thread C:\Windows\system32\svchost.exe [488:4472] 000007fefb404164
Thread C:\Windows\system32\svchost.exe [488:236] 000007fef1211ab0
Thread C:\Windows\system32\WLANExt.exe [1268:1464] 000000018000d8b8
Thread C:\Windows\system32\WLANExt.exe [1268:1468] 000000018000d8d4
Thread C:\Windows\system32\WLANExt.exe [1268:1472] 000000018000d89c
Thread C:\Windows\system32\WLANExt.exe [1268:1476] 0000000180027b90
Thread C:\Windows\system32\WLANExt.exe [1268:1480] 000007fefa3c2f9c
Thread C:\Windows\System32\spoolsv.exe [1392:2928] 0000000051074ba0
Thread C:\Windows\System32\spoolsv.exe [1392:232] 000000006508e0e0
Thread C:\Windows\System32\spoolsv.exe [1392:540] 000007fef12b10c8
Thread C:\Windows\System32\spoolsv.exe [1392:852] 000007fef0a26144
Thread C:\Windows\System32\spoolsv.exe [1392:428] 000007fef5f35fd0
Thread C:\Windows\System32\spoolsv.exe [1392:596] 000007fef0a03438
Thread C:\Windows\System32\spoolsv.exe [1392:1060] 000007fef5f363ec
Thread C:\Windows\System32\spoolsv.exe [1392:1108] 000007fefa145e5c
Thread C:\Windows\System32\spoolsv.exe [1392:304] 000007fefa175074
Thread C:\Windows\system32\svchost.exe [1424:1788] 000007fef64835c0
Thread C:\Windows\system32\svchost.exe [1424:2636] 000007fef6485600
Thread C:\Windows\system32\svchost.exe [1424:2780] 000007fef12e2940
Thread C:\Windows\system32\svchost.exe [1424:1364] 000007fefb102888
Thread C:\Windows\system32\svchost.exe [1424:3252] 000007fefb102a40
Thread C:\Windows\system32\svchost.exe [1768:1928] 000007fef5f35fd0
Thread C:\Windows\system32\svchost.exe [1768:1932] 000007fef5f363ec
Thread C:\Windows\system32\svchost.exe [1768:2824] 000007fef13e8470
Thread C:\Windows\system32\svchost.exe [1768:2828] 000007fef13f2418
Thread C:\Windows\System32\svchost.exe [2136:2524] 000007fef2559688
Thread C:\Windows\system32\wbem\wmiprvse.exe [2532:2168] 000007fef1a91c20
Thread C:\Windows\system32\taskhost.exe [1836:2972] 000007fefb8d1010
Thread C:\Windows\system32\taskhost.exe [1836:3772] 000007fef25a5170
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BackupStack
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 16
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 2
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] C:\Program Files (x86)\MyPC Backup\BackupStack.exe
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] Computer Backup (MyPC Backup)
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\services\[email protected] LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\services\BackupStack
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74de2baf0842
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74de2baf0842 (not active ControlSet)
---- EOF - GMER 2.1 ----
Ik hoop dat jullie er iets mee kunnen. Alvast bedankt,
Rob
Comment