Twee weken geleden nog een Ukash op de notebook van mijn ene dochter en nu een super trage notebook van mijn andere dochter. Tja...... Ik weet niet of het spyware is of iets anders. Virusscanner gedraaid waaronder MBAM. Een dds en een GMER gemaakt (volgens de aanwijzingen op deze site) en hopelijk kan iemand me helpen. Alleen die dds draaien duurde al zeker een kwartier (terwijl er staat dat het niet langer dan 3 minuten mag duren). Voor een programma opstarten of het internet opgaan duurt een eeuwigheid. Hieronder de logfiles:
DDS (Ver_2012-11-05.02) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.25.2
Run by Notebook Tony at 22:19:54 on 2013-07-23
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.1979.434 [GMT 2:00]
.
AV: McAfee Antivirus en antispyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: McAfee Antivirus en antispyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\STacSV64.e xe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.e xe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\spool\DRIVERS\x64\3\HP1006MC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\SysWOW64\IoctlSvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.nl/
uProxyServer = 10.31.4.14:8080
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110112132633.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - <orphaned>
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
mRun: [HPUsageTracking] C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe "C:\Program Files (x86)\HP\HP UT\"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - <orphaned>
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
TCP: NameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{13ECD552-9E77-4A10-8A7E-68B8673F8C39} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\A5978554C4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\A597F507279667164756F5738443D4A464 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\D454451443 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
x64-BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110112132633.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2011-1-12 62800]
S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;C:\Windows\System32\drivers\aabed2.sys [2008-3-20 28672]
.
=============== Created Last 30 ================
.
2013-07-23 17:40:28 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-07-23 17:39:49 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-07-23 17:39:43 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-07-11 21:20:04 571904 ----a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-11 21:20:04 1011712 ----a-w- C:\Program Files\Windows Defender\MpSvc.dll
2013-07-11 21:20:03 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2013-07-11 21:20:03 54784 ----a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll
2013-07-11 21:20:03 4608 ----a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll
2013-07-11 21:20:03 392704 ----a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll
2013-07-11 21:20:03 314880 ----a-w- C:\Program Files\Windows Defender\MpCommu.dll
2013-07-11 21:20:01 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-11 21:20:01 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-07-11 21:20:00 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-11 21:19:59 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-11 21:17:26 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-07-11 21:17:14 1367040 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 21:17:13 936448 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 21:15:58 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-11 21:15:58 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-11 20:54:34 -------- d-----w- C:\Program Files (x86)\Total Video Converter
2013-07-08 22:00:46 -------- d-----w- C:\Users\Notebook Tony\www.apowersoft.com
2013-06-29 20:36:55 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Google
2013-06-29 19:04:54 1045072 ----a-w- C:\Program Files\uTorrent.exe
2013-06-29 19:03:18 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\uTorrent
2013-06-29 19:00:53 -------- d-----w- C:\Program Files\hjsplit
2013-06-29 18:44:47 -------- d-----w- C:\Program Files (x86)\iWisoft Free Video Converter
2013-06-29 18:37:23 -------- d-----w- C:\Program Files (x86)\iWisoft Free Video Downloader
2013-06-29 18:06:36 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Apple Computer
2013-06-29 18:05:45 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-06-29 18:04:26 -------- d-----w- C:\Program Files\iPod
2013-06-29 18:04:25 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-29 18:04:25 -------- d-----w- C:\Program Files\iTunes
2013-06-29 18:04:25 -------- d-----w- C:\Program Files (x86)\iTunes
2013-06-29 18:01:36 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Apple
2013-06-29 18:00:23 -------- d-----w- C:\Program Files\Bonjour
2013-06-29 18:00:23 -------- d-----w- C:\Program Files (x86)\Bonjour
2013-06-29 17:57:07 758018 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2013-06-29 17:57:07 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2013-06-29 17:57:07 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2013-06-29 17:57:07 180224 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2013-06-29 17:57:07 173568 ----a-w- C:\Windows\System32\xvid.ax
2013-06-29 17:57:07 139264 ----a-w- C:\Windows\SysWow64\xvid.ax
2013-06-29 17:57:06 -------- d-----w- C:\Program Files (x86)\Xvid
2013-06-29 17:56:05 -------- d-----w- C:\Program Files (x86)\AviSynth 2.5
2013-06-29 17:55:55 -------- d-----w- C:\Program Files (x86)\AVI ReComp
2013-06-29 17:53:29 -------- d-----w- C:\Program Files\VirtualDub-1.9.11
2013-06-29 17:44:48 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\AVI ReComp
2013-06-29 17:43:41 -------- d-----w- C:\Program Files (x86)\Abyssmedia
2013-06-28 19:59:11 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\CyberLink
2013-06-27 21:57:53 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-27 21:30:57 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Programs
2013-06-27 21:23:28 -------- d-----w- C:\Program Files\CCleaner
2013-06-27 18:47:30 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\fontconfig
2013-06-27 18:40:47 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Aegisub
2013-06-27 18:40:46 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\Aegisub
2013-06-27 18:40:10 -------- d-----w- C:\Program Files (x86)\Aegisub
2013-06-27 18:37:11 -------- d-----w- C:\Program Files (x86)\VisualSubSync
.
==================== Find3M ====================
.
2013-06-27 21:57:41 867240 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-06-27 21:57:41 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-06-18 14:31:37 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-18 14:31:37 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-11 23:43:37 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-06-11 23:42:58 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-11 23:42:58 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-06-11 23:25:13 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-06-11 23:25:13 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-06-11 22:51:45 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50:58 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-07 03:22:18 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-06-07 02:37:52 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
.
============= FINISH: 22:30:46,65 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-05.02)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 14-5-2010 10:09:11
System Uptime: 23-7-2013 21:13:32 (1 hours ago)
.
Motherboard: Hewlett-Packard | | 3069
Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz | CPU | 2194/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 220 GiB total, 122,753 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 2,119 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9.5.5 MUI
Adobe Shockwave Player
Aegisub 3.0.2
Apple Application Support
Apple Mobile Device Support
Apple Software Update
µTorrent
AVI ReComp 1.5.5
AviSynth 2.5
Basissoftware voor HP Deskjet 1050 J410 series
Bonjour
CCleaner
Compatibiliteitspakket voor het 2007 Microsoft Office system
CyberLink YouCam
Firebird SQL Server - MAGIX Edition
HP Customer Experience Enhancements
HP Deskjet 1050 J410 series Haelp
HP Games
HP LaserJet P1000 series
HP Quick Launch Buttons
HP Setup
HP Support Assistant
HP Update
HP User Guides 0148
HP Wireless Assistant
HPAsset component for HP Active Support Library
hppMSRedist
hppusgP1000
HPSSupply
IDT Audio
Intel(R) Graphics Media Accelerator Driver
iTunes
iWisoft Free Video Converter 1.2
iWisoft Free Video Downloader 2.1
Java 7 Update 25
Java Auto Updater
Java(TM) 6 Update 15 (64-bit)
Java(TM) SE Development Kit 6 Update 15 (64-bit)
Junk Mail filter update
LabelPrint
LightScribe System Software
Magic Desktop
Malwarebytes Anti-Malware versie 1.75.0.1300
MarketResearch
McAfee AntiVirus Plus
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile NLD Language Pack
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Dutch) 2007
Microsoft Office Excel MUI (Dutch) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (Dutch) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office Outlook MUI (Dutch) 2007
Microsoft Office PowerPoint MUI (Dutch) 2007
Microsoft Office PowerPoint Viewer 2007 (Dutch)
Microsoft Office Professional Plus 2007
Microsoft Office Proof (Dutch) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proofing (Dutch) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Dutch) 2007
Microsoft Office Shared 64-bit MUI (Dutch) 2007
Microsoft Office Shared MUI (Dutch) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (Dutch) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MrvlUsgTracking
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
Nero 8
neroxml
Norton Online Backup
Picasa 3
Power2Go
PowerDirector
QLBCASL
Realtek 8136 8168 8169 Ethernet Driver
Realtek USB 2.0 Card Reader
Recovery Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition
Update voor Microsoft Office Excel 2007 Help (KB963678)
Update voor Microsoft Office Powerpoint 2007 Help (KB963669)
Update voor Microsoft Office Word 2007 Help (KB963665)
VisualSubSync (remove only)
VLC media player 2.0.7
VobSub 2.23
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Toolbar
Windows Live Writer
WinRAR
Xvid Video Codec
Your Uninstaller! 2010
.
==== End Of File ===========================
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-23 23:08:50
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEKT-60V5T1 rev.12.01A12 232,89GB
Running: gexc6gx3.exe; Driver: C:\Users\NOTEBO~1\AppData\Local\Temp\uwliqpoc.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[3616] C:\Windows\system32\kernel32.dll!LoadLibraryW 00000000771b6f80 5 bytes JMP 0000000162423bc8
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[3616] C:\Windows\system32\kernel32.dll!LoadLibraryA 00000000771b7070 5 bytes JMP 0000000162423abc
---- Threads - GMER 2.1 ----
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:4980] 0000000075457587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3992] 000000006d740cb3
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:476] 00000000774f2e25
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3204] 00000000774f3e45
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3260] 00000000774f3e45
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:5036] 000000007595d864
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:3656] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:3824] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:1080] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:4844] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:624] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2268] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2108] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:4864] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:672] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2272] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:740] 000000007595d864
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}\[email protected] isatap.{5C16CED7-C92E-4A8A-A97A-31AEF3AF19D9}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}?\Device\{97668D4E-EE9B-4914-8437-BE5B729D0625}?\Device\{2047383E-E915-4262-BA22-DE07D4E97775}?\Device\{4020A103-129E-4B31-845E-BA023FD66FFF}?\Device\{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}?\Device\{E0175487-4ADE-4D65-A2E6-D1507DA74B28}?\Device\{C3C11393-9CCA-4503-8E66-CCEF63DA8729}?\Device\{D770712A-95FF-42A2-BA72-5E7B93D63AAC}?\Device\{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] "{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}"?"{97668D4E-EE9B-4914-8437-BE5B729D0625}"?"{2047383E-E915-4262-BA22-DE07D4E97775}"?"{4020A103-129E-4B31-845E-BA023FD66FFF}"?"{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}"?"{E0175487-4ADE-4D65-A2E6-D1507DA74B28}"?"{C3C11393-9CCA-4503-8E66-CCEF63DA8729}"?"{D770712A-95FF-42A2-BA72-5E7B93D63AAC}"?"{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\TCPIP6TUNNEL_{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}?\Device\TCPIP6TUNNEL_{97668D4E-EE9B-4914-8437-BE5B729D0625}?\Device\TCPIP6TUNNEL_{2047383E-E915-4262-BA22-DE07D4E97775}?\Device\TCPIP6TUNNEL_{4020A103-129E-4B31-845E-BA023FD66FFF}?\Device\TCPIP6TUNNEL_{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}?\Device\TCPIP6TUNNEL_{E0175487-4ADE-4D65-A2E6-D1507DA74B28}?\Device\TCPIP6TUNNEL_{C3C11393-9CCA-4503-8E66-CCEF63DA8729}?\Device\TCPIP6TUNNEL_{D770712A-95FF-42A2-BA72-5E7B93D63AAC}?\Device\TCPIP6TUNNEL_{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}?
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}@InterfaceName isatap.{5C16CED7-C92E-4A8A-A97A-31AEF3AF19D9}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\b0-b[email protected] 59616
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 2001:0:9d38:6ab8:c2:171f:ad54:59cf
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 8701
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 4417
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Groet,
Tony
DDS (Ver_2012-11-05.02) - NTFS_AMD64
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.25.2
Run by Notebook Tony at 22:19:54 on 2013-07-23
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.1979.434 [GMT 2:00]
.
AV: McAfee Antivirus en antispyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: McAfee Antivirus en antispyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\STacSV64.e xe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.e xe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\spool\DRIVERS\x64\3\HP1006MC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\SysWOW64\IoctlSvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.nl/
uProxyServer = 10.31.4.14:8080
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110112132633.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - <orphaned>
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
mRun: [HPUsageTracking] C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe "C:\Program Files (x86)\HP\HP UT\"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:1
IE: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - <orphaned>
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
TCP: NameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{13ECD552-9E77-4A10-8A7E-68B8673F8C39} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9} : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\A5978554C4 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\A597F507279667164756F5738443D4A464 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
TCP: Interfaces\{E19E4AA8-F5D3-4FCA-8AAB-013FCBF1D1B9}\D454451443 : DHCPNameServer = 192.168.1.254 195.241.77.55 195.241.77.58
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
x64-BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110112132633.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2011-1-12 62800]
S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;C:\Windows\System32\drivers\aabed2.sys [2008-3-20 28672]
.
=============== Created Last 30 ================
.
2013-07-23 17:40:28 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-07-23 17:39:49 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-07-23 17:39:43 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-07-11 21:20:04 571904 ----a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-11 21:20:04 1011712 ----a-w- C:\Program Files\Windows Defender\MpSvc.dll
2013-07-11 21:20:03 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2013-07-11 21:20:03 54784 ----a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll
2013-07-11 21:20:03 4608 ----a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll
2013-07-11 21:20:03 392704 ----a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll
2013-07-11 21:20:03 314880 ----a-w- C:\Program Files\Windows Defender\MpCommu.dll
2013-07-11 21:20:01 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-11 21:20:01 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-07-11 21:20:00 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-11 21:19:59 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-11 21:17:26 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-07-11 21:17:14 1367040 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 21:17:13 936448 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 21:15:58 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-11 21:15:58 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-11 20:54:34 -------- d-----w- C:\Program Files (x86)\Total Video Converter
2013-07-08 22:00:46 -------- d-----w- C:\Users\Notebook Tony\www.apowersoft.com
2013-06-29 20:36:55 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Google
2013-06-29 19:04:54 1045072 ----a-w- C:\Program Files\uTorrent.exe
2013-06-29 19:03:18 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\uTorrent
2013-06-29 19:00:53 -------- d-----w- C:\Program Files\hjsplit
2013-06-29 18:44:47 -------- d-----w- C:\Program Files (x86)\iWisoft Free Video Converter
2013-06-29 18:37:23 -------- d-----w- C:\Program Files (x86)\iWisoft Free Video Downloader
2013-06-29 18:06:36 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Apple Computer
2013-06-29 18:05:45 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-06-29 18:04:26 -------- d-----w- C:\Program Files\iPod
2013-06-29 18:04:25 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-29 18:04:25 -------- d-----w- C:\Program Files\iTunes
2013-06-29 18:04:25 -------- d-----w- C:\Program Files (x86)\iTunes
2013-06-29 18:01:36 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Apple
2013-06-29 18:00:23 -------- d-----w- C:\Program Files\Bonjour
2013-06-29 18:00:23 -------- d-----w- C:\Program Files (x86)\Bonjour
2013-06-29 17:57:07 758018 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2013-06-29 17:57:07 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2013-06-29 17:57:07 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2013-06-29 17:57:07 180224 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2013-06-29 17:57:07 173568 ----a-w- C:\Windows\System32\xvid.ax
2013-06-29 17:57:07 139264 ----a-w- C:\Windows\SysWow64\xvid.ax
2013-06-29 17:57:06 -------- d-----w- C:\Program Files (x86)\Xvid
2013-06-29 17:56:05 -------- d-----w- C:\Program Files (x86)\AviSynth 2.5
2013-06-29 17:55:55 -------- d-----w- C:\Program Files (x86)\AVI ReComp
2013-06-29 17:53:29 -------- d-----w- C:\Program Files\VirtualDub-1.9.11
2013-06-29 17:44:48 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\AVI ReComp
2013-06-29 17:43:41 -------- d-----w- C:\Program Files (x86)\Abyssmedia
2013-06-28 19:59:11 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\CyberLink
2013-06-27 21:57:53 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-27 21:30:57 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Programs
2013-06-27 21:23:28 -------- d-----w- C:\Program Files\CCleaner
2013-06-27 18:47:30 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\fontconfig
2013-06-27 18:40:47 -------- d-----w- C:\Users\Notebook Tony\AppData\Local\Aegisub
2013-06-27 18:40:46 -------- d-----w- C:\Users\Notebook Tony\AppData\Roaming\Aegisub
2013-06-27 18:40:10 -------- d-----w- C:\Program Files (x86)\Aegisub
2013-06-27 18:37:11 -------- d-----w- C:\Program Files (x86)\VisualSubSync
.
==================== Find3M ====================
.
2013-06-27 21:57:41 867240 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-06-27 21:57:41 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-06-18 14:31:37 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-18 14:31:37 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-11 23:43:37 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-06-11 23:43:00 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-06-11 23:42:58 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-11 23:42:58 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-06-11 23:26:20 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-06-11 23:25:16 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-06-11 23:25:13 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-06-11 23:25:13 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-06-11 22:51:45 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-06-11 22:50:58 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-07 03:22:18 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-06-07 02:37:52 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
.
============= FINISH: 22:30:46,65 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-05.02)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 14-5-2010 10:09:11
System Uptime: 23-7-2013 21:13:32 (1 hours ago)
.
Motherboard: Hewlett-Packard | | 3069
Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz | CPU | 2194/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 220 GiB total, 122,753 GiB free.
D: is FIXED (NTFS) - 13 GiB total, 2,119 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9.5.5 MUI
Adobe Shockwave Player
Aegisub 3.0.2
Apple Application Support
Apple Mobile Device Support
Apple Software Update
µTorrent
AVI ReComp 1.5.5
AviSynth 2.5
Basissoftware voor HP Deskjet 1050 J410 series
Bonjour
CCleaner
Compatibiliteitspakket voor het 2007 Microsoft Office system
CyberLink YouCam
Firebird SQL Server - MAGIX Edition
HP Customer Experience Enhancements
HP Deskjet 1050 J410 series Haelp
HP Games
HP LaserJet P1000 series
HP Quick Launch Buttons
HP Setup
HP Support Assistant
HP Update
HP User Guides 0148
HP Wireless Assistant
HPAsset component for HP Active Support Library
hppMSRedist
hppusgP1000
HPSSupply
IDT Audio
Intel(R) Graphics Media Accelerator Driver
iTunes
iWisoft Free Video Converter 1.2
iWisoft Free Video Downloader 2.1
Java 7 Update 25
Java Auto Updater
Java(TM) 6 Update 15 (64-bit)
Java(TM) SE Development Kit 6 Update 15 (64-bit)
Junk Mail filter update
LabelPrint
LightScribe System Software
Magic Desktop
Malwarebytes Anti-Malware versie 1.75.0.1300
MarketResearch
McAfee AntiVirus Plus
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile NLD Language Pack
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Dutch) 2007
Microsoft Office Excel MUI (Dutch) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (Dutch) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office Outlook MUI (Dutch) 2007
Microsoft Office PowerPoint MUI (Dutch) 2007
Microsoft Office PowerPoint Viewer 2007 (Dutch)
Microsoft Office Professional Plus 2007
Microsoft Office Proof (Dutch) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proofing (Dutch) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Dutch) 2007
Microsoft Office Shared 64-bit MUI (Dutch) 2007
Microsoft Office Shared MUI (Dutch) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (Dutch) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MrvlUsgTracking
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
Nero 8
neroxml
Norton Online Backup
Picasa 3
Power2Go
PowerDirector
QLBCASL
Realtek 8136 8168 8169 Ethernet Driver
Realtek USB 2.0 Card Reader
Recovery Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition
Update voor Microsoft Office Excel 2007 Help (KB963678)
Update voor Microsoft Office Powerpoint 2007 Help (KB963669)
Update voor Microsoft Office Word 2007 Help (KB963665)
VisualSubSync (remove only)
VLC media player 2.0.7
VobSub 2.23
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Toolbar
Windows Live Writer
WinRAR
Xvid Video Codec
Your Uninstaller! 2010
.
==== End Of File ===========================
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-23 23:08:50
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEKT-60V5T1 rev.12.01A12 232,89GB
Running: gexc6gx3.exe; Driver: C:\Users\NOTEBO~1\AppData\Local\Temp\uwliqpoc.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[3616] C:\Windows\system32\kernel32.dll!LoadLibraryW 00000000771b6f80 5 bytes JMP 0000000162423bc8
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[3616] C:\Windows\system32\kernel32.dll!LoadLibraryA 00000000771b7070 5 bytes JMP 0000000162423abc
---- Threads - GMER 2.1 ----
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:4980] 0000000075457587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3992] 000000006d740cb3
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:476] 00000000774f2e25
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3204] 00000000774f3e45
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:3260] 00000000774f3e45
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2364:5036] 000000007595d864
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:3656] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:3824] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:1080] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:4844] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:624] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2268] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2108] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:4864] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:672] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:2272] 000000006d33313c
Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4628:740] 000000007595d864
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}\[email protected] isatap.{5C16CED7-C92E-4A8A-A97A-31AEF3AF19D9}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}?\Device\{97668D4E-EE9B-4914-8437-BE5B729D0625}?\Device\{2047383E-E915-4262-BA22-DE07D4E97775}?\Device\{4020A103-129E-4B31-845E-BA023FD66FFF}?\Device\{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}?\Device\{E0175487-4ADE-4D65-A2E6-D1507DA74B28}?\Device\{C3C11393-9CCA-4503-8E66-CCEF63DA8729}?\Device\{D770712A-95FF-42A2-BA72-5E7B93D63AAC}?\Device\{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] "{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}"?"{97668D4E-EE9B-4914-8437-BE5B729D0625}"?"{2047383E-E915-4262-BA22-DE07D4E97775}"?"{4020A103-129E-4B31-845E-BA023FD66FFF}"?"{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}"?"{E0175487-4ADE-4D65-A2E6-D1507DA74B28}"?"{C3C11393-9CCA-4503-8E66-CCEF63DA8729}"?"{D770712A-95FF-42A2-BA72-5E7B93D63AAC}"?"{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\TCPIP6TUNNEL_{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}?\Device\TCPIP6TUNNEL_{97668D4E-EE9B-4914-8437-BE5B729D0625}?\Device\TCPIP6TUNNEL_{2047383E-E915-4262-BA22-DE07D4E97775}?\Device\TCPIP6TUNNEL_{4020A103-129E-4B31-845E-BA023FD66FFF}?\Device\TCPIP6TUNNEL_{6C858E4E-1DC4-497A-B12A-7126D7DEA4CA}?\Device\TCPIP6TUNNEL_{E0175487-4ADE-4D65-A2E6-D1507DA74B28}?\Device\TCPIP6TUNNEL_{C3C11393-9CCA-4503-8E66-CCEF63DA8729}?\Device\TCPIP6TUNNEL_{D770712A-95FF-42A2-BA72-5E7B93D63AAC}?\Device\TCPIP6TUNNEL_{33D78EA6-8163-4A3B-9716-2CC8C79EAE91}?
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}@InterfaceName isatap.{5C16CED7-C92E-4A8A-A97A-31AEF3AF19D9}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{B2D8DF45-24E1-4AB5-A32B-E96243F80DC5}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\b0-b[email protected] 59616
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 2001:0:9d38:6ab8:c2:171f:ad54:59cf
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 8701
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 4417
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Groet,
Tony
Comment