Hallo,
Ik heb hier een laptop van iemand van mijn famillie en ik heb daar een aantal scans op uitgevoerd en er is uitgekomen dat de laptop misschien geinfecteerd zou zijn. Dit is gekomen omdat de gebruiker naar een normale youtube link is gegaan. De virusscanner die de gebruiker heeft gaf aan dat het om de trojan "JS-:Agent-CDN [Trj]" zou gaan.
Ik heb direct een scan uitgevoerd met MBAM en daar kwam niets uit. Verder heb ik ook nog met CCleaner alles opgeschoond. Daarna heb ik met GMER een scan gedaan en deze heeft wel wat threats gevonden. Daarna heb ik ook nog logjes met DDS gemaakt.
Ik hoop dat iemand mij hier kan helpen, want tot zo ver merk ik er niets van, maar ik ben bang dat de gebruiker van de laptop er in de toekomst problemen mee gaat krijgen en het is niet bepaald veilig omdat er bankzaken op de laptop uitgevoerd worden
Op internet heb ik uitgevonden dat dit de laatste tijd meer is voorgekomen. De gebruikers hebben dit gekregen uit een totaal normale youtube link.
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-25 02:54:31
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545032B9A300 rev.PB3OC60F 298,09GB
Running: 1dvud5qc.exe; Driver: C:\Users\Diana\AppData\Local\Temp\ugloapog.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [624:2260] 000007fef73814a0
Thread C:\Windows\System32\svchost.exe [624:2568] 000007fef661a2b0
Thread C:\Windows\System32\svchost.exe [624:3920] 000007fef93944e0
Thread C:\Windows\System32\svchost.exe [624:516] 000007fef96188f8
Thread C:\Windows\system32\svchost.exe [804:3436] 000007fef95c5124
Thread C:\Windows\system32\svchost.exe [804:3852] 000007fef21f506c
Thread C:\Windows\system32\svchost.exe [804:3856] 000007fef5c21c20
Thread C:\Windows\system32\svchost.exe [804:3860] 000007fef5c21c20
Thread C:\Windows\system32\svchost.exe [804:2316] 000007fef9c01ab0
Thread C:\Windows\system32\svchost.exe [1144:4952] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:5016] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:3200] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:5020] 000007fef341d3c8
Thread C:\Windows\System32\spoolsv.exe [1708:2760] 000007fef91c10c8
Thread C:\Windows\System32\spoolsv.exe [1708:2772] 000007fef7b76144
Thread C:\Windows\System32\spoolsv.exe [1708:2780] 000007fef7965fd0
Thread C:\Windows\System32\spoolsv.exe [1708:2784] 000007fef7953438
Thread C:\Windows\System32\spoolsv.exe [1708:2788] 000007fef79663ec
Thread C:\Windows\System32\spoolsv.exe [1708:2796] 000007fef8d75e5c
Thread C:\Windows\System32\spoolsv.exe [1708:3064] 000007fef86a5074
Thread C:\Windows\system32\svchost.exe [1760:2964] 000007fef70e2888
Thread C:\Windows\system32\svchost.exe [1760:2376] 000007fef70e2a40
Thread C:\Windows\system32\svchost.exe [2188:2228] 000007feff4da808
Thread C:\Windows\system32\svchost.exe [2188:2268] 000007fef9567130
Thread C:\Windows\system32\svchost.exe [2188:2272] 000007fef955d5c0
Thread C:\Windows\system32\taskhost.exe [2352:2468] 000007fef8d61f38
Thread C:\Windows\system32\taskhost.exe [2352:2472] 000007feff639274
Thread C:\Windows\system32\taskhost.exe [2352:2488] 000007fef8802740
Thread C:\Windows\system32\taskhost.exe [2352:2612] 000007fefb071010
Thread C:\Windows\system32\Dwm.exe [2704:2756] 000007fef843f0d8
Thread C:\Windows\system32\Dwm.exe [2704:2764] 000007fef7bbabf0
Thread C:\Windows\system32\svchost.exe [3040:3056] 000007feff4da808
Thread C:\Windows\system32\svchost.exe [2552:2676] 000007fef5888470
Thread C:\Windows\system32\svchost.exe [2552:1920] 000007fef5892418
Thread C:\Windows\system32\svchost.exe [2552:4072] 000007fef7965fd0
Thread C:\Windows\system32\svchost.exe [2552:4076] 000007fef79663ec
Thread C:\Windows\system32\svchost.exe [2552:2588] 000007fef2375f1c
Thread C:\Windows\system32\SearchIndexer.exe [3424:3644] 000007fef4b65170
Thread C:\Windows\system32\SearchIndexer.exe [3424:3668] 000007fef4ff69ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3676] 000007fef4dc3dac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3680] 000007fef4dc1700
Thread C:\Windows\system32\SearchIndexer.exe [3424:3684] 000007fef4deb248
Thread C:\Windows\system32\SearchIndexer.exe [3424:3688] 000007fef4dec4ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3808] 000007fef4ff69ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:1312] 000007fef4ff69ac
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:3180] 000007fefeb30168
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:3204] 000007fefbae2a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:244] 000007fef95c5124
Thread C:\Windows\System32\svchost.exe [2292:600] 000007fef1df9688
---- EOF - GMER 2.1 ----
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7601.17514
Run by Diana at 2:56:44 on 2013-07-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1787.904 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
G:\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
G:\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\PLFSetI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
G:\Avast\AvastUI.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
G:\Malwarebytes' Anti-Malware\mbamscheduler.exe
G:\Malwarebytes' Anti-Malware\mbamservice.exe
G:\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Avast\aswWebRepIE.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [avast] "G:\Avast\avastUI.exe" /nogui
mRunOnce: [Malwarebytes Anti-Malware] G:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{0F642EF0-90EA-4FAE-B783-D1D9375945F1} : DHCPNameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{79395291-EB9D-4E5B-AC2C-1E7D4FCA3E90} : DHCPNameServer = 62.179.104.196 213.46.228.196
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - G:\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Nieuwe map (2)\Java\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Nieuwe map (2)\Java\bin\jp2ssv.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - G:\Avast\aswWebRepIE64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [PLFSetI] C:\Windows\PLFSetI.exe
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-6-30 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-6-30 189936]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-6-30 1030952]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-6-30 378944]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-6-30 203264]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-6-30 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-6-30 80816]
R2 avast! Antivirus;avast! Antivirus;G:\Avast\AvastSvc.exe [2013-6-30 46808]
R2 MBAMScheduler;MBAMScheduler;G:\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-7-25 418376]
R2 MBAMService;MBAMService;G:\Malwarebytes' Anti-Malware\mbamservice.exe [2013-7-25 701512]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-6-30 116752]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2010-5-15 384040]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-7-25 25928]
R3 SbieDrv;SbieDrv;G:\Sandboxie\SbieDrv.sys [2013-7-8 199384]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-6-30 38528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-6-30 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-7-21 59392]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-6-30 1255736]
SUnknown tsusbhub;tsusbhub; [x]
.
=============== Created Last 30 ================
.
2013-07-25 00:42:52 -------- d-----w- C:\Users\Diana\AppData\Roaming\Malwarebytes
2013-07-25 00:42:41 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-25 00:42:39 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-25 00:42:26 -------- d-----w- C:\Users\Diana\AppData\Local\Programs
2013-07-23 10:21:49 -------- d-----w- C:\Users\Diana\AppData\Roaming\Remere's Map Editor
2013-07-21 15:22:02 -------- d-----w- C:\ProgramData\Caphyon
2013-07-21 14:59:08 -------- d-----w- C:\ProgramData\Package Cache
2013-07-21 14:57:59 238088 ----a-w- C:\Windows\SysWow64\xactengine3_1.dll
2013-07-21 14:54:14 -------- d-----w- C:\Windows\SysWow64\directx
2013-07-21 14:51:46 -------- d-----w- C:\Users\Diana\AppData\Roaming\AetherNet
2013-07-21 14:10:57 -------- d-----w- C:\Windows\System32\SPReview
2013-07-21 14:10:13 -------- d-----w- C:\Windows\System32\EventProviders
2013-07-21 14:01:24 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2013-07-21 14:01:23 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2013-07-21 14:01:14 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2013-07-21 14:01:07 59392 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2013-07-21 14:01:07 12288 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-07-21 14:01:06 1838080 ----a-w- C:\Windows\System32\d3d10warp.dll
2013-07-21 14:01:05 14967808 ----a-w- C:\Program Files\DVD Maker\OmdBase.dll
2013-07-21 13:59:59 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-07-21 13:58:59 378880 ----a-w- C:\Windows\System32\msinfo32.exe
2013-07-21 13:57:59 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-21 13:56:59 73216 ----a-w- C:\Windows\System32\unimdmat.dll
2013-07-21 13:55:59 8192 ----a-w- C:\Windows\System32\KBDTUF.DLL
2013-07-21 13:54:58 399872 ----a-w- C:\Windows\System32\dpx.dll
2013-07-21 13:54:58 189952 ----a-w- C:\Windows\SysWow64\wdscore.dll
2013-07-21 13:54:36 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2013-07-21 13:54:29 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2013-07-21 13:52:06 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-07-19 14:35:59 -------- d-----w- C:\Users\Diana\AppData\Roaming\Ableton
2013-07-19 14:33:47 -------- d-----w- C:\Program Files (x86)\Common Files\Propellerhead Software
2013-07-19 00:21:20 51712 ----a-w- C:\Windows\AutosetFrequency.exe
2013-07-19 00:21:20 214400 ----a-w- C:\Windows\SysWow64\snpropwp.dll
2013-07-19 00:21:20 206208 ----a-w- C:\Windows\PLFSetI.exe
2013-07-19 00:21:07 -------- d-----w- C:\Program Files (x86)\VideoWebCamera
2013-07-16 19:07:33 -------- d-----r- C:\Sandbox
2013-07-15 23:46:08 -------- d-----w- C:\Users\Diana\AppData\Roaming\uTorrent
2013-07-15 18:08:18 -------- d-----w- C:\Users\Diana\AppData\Roaming\.minecraft
2013-07-15 18:06:44 972712 ----a-w- C:\Windows\System32\deployJava1.dll
2013-07-15 18:06:44 1093032 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-07-15 18:06:28 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-07-09 17:29:52 -------- d--h--w- C:\ProgramData\CanonIJMIG
2013-07-09 17:28:59 -------- d--h--w- C:\ProgramData\CanonIJScan
2013-07-05 20:26:26 -------- d--h--w- C:\ProgramData\CanonIJEGV
2013-07-05 20:24:55 320000 ----a-w- C:\Windows\SysWow64\CNC_B8L.dll
2013-07-05 20:24:55 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2013-07-05 20:24:55 103424 ----a-w- C:\Windows\SysWow64\CNC_B8U.dll
2013-07-05 20:21:54 -------- d-----w- C:\Program Files\Common Files\CANON
2013-07-05 20:21:41 -------- d-----w- C:\ProgramData\CanonIJWSpt
2013-07-05 20:14:48 -------- d-----w- C:\Program Files\Canon
2013-07-05 20:13:34 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDB8.DLL
2013-07-05 20:13:34 100352 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPB8.DLL
2013-07-05 20:13:19 363520 ----a-w- C:\Windows\System32\CNC_B8L.dll
2013-07-05 20:13:19 287744 ----a-w- C:\Windows\System32\CNC_B8C.dll
2013-07-05 20:13:19 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2013-07-05 20:13:19 106496 ----a-w- C:\Windows\System32\CNC_B8I.dll
2013-07-05 20:12:48 389120 ----a-w- C:\Windows\System32\CNMLMB8.DLL
2013-07-05 20:12:13 39424 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2013-07-05 20:12:13 359936 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2013-07-05 20:12:13 -------- d-----w- C:\Windows\System32\STRING
2013-07-05 20:10:58 -------- d--h--w- C:\ProgramData\CanonIJETV
2013-07-05 20:10:31 -------- d-----w- C:\Program Files (x86)\Canon
2013-07-01 14:29:18 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-01 14:29:18 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-01 14:28:37 -------- d-----w- C:\Users\Diana\AppData\Local\Adobe
2013-06-30 23:59:38 -------- d-----w- C:\Windows\Panther
2013-06-30 22:21:13 -------- d-----w- C:\Program Files\CCleaner
2013-06-30 22:12:43 2229608 ----a-w- C:\Windows\System32\drivers\athrx.sys
2013-06-30 22:12:43 2229608 ----a-w- C:\Windows\System32\athrx.sys
2013-06-30 22:12:43 -------- d-----w- C:\Program Files (x86)\Atheros
2013-06-30 21:43:17 -------- d-----w- C:\Windows\SysWow64\Wat
2013-06-30 21:43:17 -------- d-----w- C:\Windows\System32\Wat
2013-06-30 21:24:06 2560 ----a-w- C:\Windows\System32\drivers\nl-NL\wdf01000.sys.mui
2013-06-30 21:24:05 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-06-30 21:24:04 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-06-30 21:24:04 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-06-30 21:24:04 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-06-30 21:20:47 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-06-30 21:20:46 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-06-30 21:20:44 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-06-30 21:20:44 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-06-30 21:20:41 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-06-30 21:20:40 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-06-30 21:20:40 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-06-30 21:03:18 902656 ----a-w- C:\Windows\System32\d2d1.dll
2013-06-30 21:03:17 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2013-06-30 21:03:16 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2013-06-30 21:03:13 220160 ----a-w- C:\Windows\System32\wintrust.dll
2013-06-30 21:03:13 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-06-30 21:00:15 -------- d-----w- C:\Windows\System32\appmgmt
2013-06-30 20:53:31 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-06-30 20:53:31 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-06-30 20:53:31 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-06-30 20:53:29 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-06-30 20:53:29 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-06-30 20:53:29 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-06-30 20:41:27 -------- d-----w- C:\Windows\SysWow64\nl
2013-06-30 20:41:27 -------- d-----w- C:\Windows\SysWow64\0413
2013-06-30 20:41:27 -------- d-----w- C:\Windows\nl-NL
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\XPSViewer
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\drivers\UMDF\nl-NL
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\drivers\nl-NL
2013-06-30 20:41:05 -------- d-----w- C:\Windows\SysWow64\wbem\nl-NL
2013-06-30 20:41:02 -------- d-----w- C:\Windows\System32\nl
2013-06-30 20:41:02 -------- d-----w- C:\Windows\System32\0413
2013-06-30 20:40:39 -------- d-----w- C:\Windows\System32\drivers\UMDF\nl-NL
2013-06-30 20:40:39 -------- d-----w- C:\Windows\System32\drivers\nl-NL
2013-06-30 20:40:27 -------- d-----w- C:\Windows\System32\wbem\nl-NL
2013-06-30 19:11:58 5632 ----a-w- C:\Windows\System32\drivers\nl-NL\ndiscap.sys.mui
2013-06-30 18:51:24 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-06-30 18:51:24 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-06-30 18:51:24 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-06-30 18:51:23 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-06-30 18:51:23 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-06-30 18:51:22 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-06-30 18:44:14 515584 ----a-w- C:\Windows\System32\timedate.cpl
2013-06-30 18:44:14 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2013-06-30 18:44:04 503808 ----a-w- C:\Windows\System32\srcore.dll
2013-06-30 18:44:04 296960 ----a-w- C:\Windows\System32\rstrui.exe
2013-06-30 18:44:03 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2013-06-30 18:42:41 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-06-30 18:42:40 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-06-30 18:42:36 2871808 ----a-w- C:\Windows\explorer.exe
2013-06-30 18:42:34 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2013-06-30 18:40:56 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-06-30 18:40:56 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-06-30 18:40:56 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-06-30 18:40:55 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-06-30 18:40:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-06-30 18:39:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2013-06-30 18:39:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-06-30 18:39:35 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
2013-06-30 18:39:34 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-06-30 18:39:07 33792 ----a-w- C:\Windows\System32\profprov.dll
2013-06-30 18:39:07 209920 ----a-w- C:\Windows\System32\profsvc.dll
2013-06-30 18:39:03 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2013-06-30 18:39:01 800768 ----a-w- C:\Windows\System32\usp10.dll
2013-06-30 18:39:00 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2013-06-30 18:37:44 3216384 ----a-w- C:\Windows\System32\msi.dll
2013-06-30 18:37:41 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2013-06-30 18:35:32 605552 ----a-w- C:\Windows\System32\winload.exe
2013-06-30 18:35:31 642944 ----a-w- C:\Windows\System32\winload.efi
2013-06-30 18:35:31 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-06-30 18:35:30 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-06-30 18:35:29 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-06-30 18:35:29 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-06-30 18:35:29 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-06-30 18:35:28 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2013-06-30 18:34:01 31232 ----a-w- C:\Windows\System32\prevhost.exe
2013-06-30 18:34:00 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2013-06-30 18:29:49 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-06-30 18:29:47 67072 ----a-w- C:\Windows\splwow64.exe
2013-06-30 18:27:38 -------- d-----w- C:\Users\Diana\AppData\Roaming\Windows Live Writer
2013-06-30 18:27:38 -------- d-----w- C:\Users\Diana\AppData\Local\Windows Live Writer
2013-06-30 17:35:00 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2013-06-30 17:34:58 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-06-30 17:31:32 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2013-06-30 17:31:32 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2013-06-30 17:31:32 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2013-06-30 17:29:17 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2013-06-30 17:29:08 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2013-06-30 17:29:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
2013-06-30 17:26:50 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-06-30 17:25:56 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-30 17:25:55 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-06-30 17:25:54 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-06-30 17:25:32 162816 ----a-w- C:\Windows\System32\rdpudd.dll
2013-06-30 17:25:32 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2013-06-30 17:25:31 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-06-30 17:25:31 20992 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2013-06-30 17:25:19 395776 ----a-w- C:\Windows\System32\webio.dll
2013-06-30 17:25:17 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2013-06-30 17:25:05 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-06-30 17:23:18 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2013-06-30 17:23:17 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2013-06-30 17:23:07 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2013-06-30 17:23:06 288256 ----a-w- C:\Windows\System32\MSNP.ax
2013-06-30 17:23:05 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2013-06-30 17:23:04 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2013-06-30 17:23:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2013-06-30 17:23:01 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2013-06-30 17:23:00 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2013-06-30 17:23:00 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2013-06-30 17:21:56 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-06-30 17:20:41 478208 ----a-w- C:\Windows\System32\dpnet.dll
2013-06-30 17:20:40 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
2013-06-30 17:20:39 3072 ----a-w- C:\Windows\System32\dpnaddr.dll
2013-06-30 17:20:39 2560 ----a-w- C:\Windows\SysWow64\dpnaddr.dll
2013-06-30 17:20:35 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2013-06-30 17:20:16 2164224 ----a-w- C:\Program Files\Windows Journal\Journal.exe
2013-06-30 17:20:12 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-06-30 17:20:10 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-06-30 17:20:08 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-06-30 17:20:04 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-06-30 17:20:03 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-06-30 17:00:10 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2013-06-30 17:00:09 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2013-06-30 17:00:07 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2013-06-30 17:00:06 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2013-06-30 17:00:05 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2013-06-30 17:00:05 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2013-06-30 17:00:03 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2013-06-30 17:00:00 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2013-06-30 16:59:59 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll
2013-06-30 16:59:59 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2013-06-30 16:59:58 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll
2013-06-30 16:59:58 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll
2013-06-30 16:59:55 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2013-06-30 16:59:38 77312 ----a-w- C:\Windows\System32\packager.dll
2013-06-30 16:59:38 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-06-30 16:59:16 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2013-06-30 16:59:13 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-06-30 16:58:44 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-06-30 16:58:39 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-06-30 16:58:34 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-06-30 16:58:28 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-06-30 16:58:28 112640 ----a-w- C:\Windows\System32\smss.exe
2013-06-30 16:58:26 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-06-30 16:56:17 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-06-30 16:56:14 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-06-30 16:56:13 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-06-30 16:42:00 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-06-30 16:41:49 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-06-30 16:41:37 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-06-30 16:41:37 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-06-30 16:14:23 -------- d-----w- C:\Windows\PCHEALTH
2013-06-30 16:13:27 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{38305BDA-257D-4BEF-9CBD-CE66C875AE11}\mpengine.dll
2013-06-30 16:13:25 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-06-30 16:05:47 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-06-30 16:05:44 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-06-30 16:05:43 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-06-30 16:05:42 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-06-30 16:05:34 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-06-30 16:04:10 41664 ----a-w- C:\Windows\avastSS.scr
2013-06-30 16:02:07 -------- d-----w- C:\ProgramData\AVAST Software
2013-06-30 16:01:36 889416 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\18ea83851ce75ab01\dotNetFx40_Full_setup.exe
2013-06-30 16:01:32 -------- d-----w- C:\Users\Diana\AppData\Local\Windows Live
2013-06-30 16:01:13 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-06-30 15:56:39 -------- d-----w- C:\Users\Diana\AppData\Local\Google
2013-06-30 15:56:22 -------- d-----w- C:\Users\Diana\AppData\Local\Deployment
2013-06-30 15:56:22 -------- d-----w- C:\Users\Diana\AppData\Local\Apps
2013-06-30 15:52:52 -------- d-----w- C:\ProgramData\Atheros
2013-06-30 15:51:49 6656 ----a-w- C:\Windows\System32\bcmwlrc.dll
2013-06-30 15:51:48 -------- d-----w- C:\Program Files\Broadcom
2013-06-30 15:34:50 -------- d-----w- C:\Users\Diana\AppData\Local\Diagnostics
2013-06-30 15:20:29 0 ----a-w- C:\Windows\ativpsrm.bin
2013-06-30 15:19:24 38528 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2013-06-30 15:18:00 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-06-30 15:15:44 -------- d-sh--w- C:\Windows\Installer
2013-06-30 15:15:31 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
2013-06-30 14:06:42 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2013-07-21 14:30:27 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-07-21 14:30:27 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-05-19 10:54:27 97176 ----a-w- C:\Windows\SysWow64\ElbyCDIO.dll
.
============= FINISH: 2:58:37,49 ===============
Ik heb hier een laptop van iemand van mijn famillie en ik heb daar een aantal scans op uitgevoerd en er is uitgekomen dat de laptop misschien geinfecteerd zou zijn. Dit is gekomen omdat de gebruiker naar een normale youtube link is gegaan. De virusscanner die de gebruiker heeft gaf aan dat het om de trojan "JS-:Agent-CDN [Trj]" zou gaan.
Ik heb direct een scan uitgevoerd met MBAM en daar kwam niets uit. Verder heb ik ook nog met CCleaner alles opgeschoond. Daarna heb ik met GMER een scan gedaan en deze heeft wel wat threats gevonden. Daarna heb ik ook nog logjes met DDS gemaakt.
Ik hoop dat iemand mij hier kan helpen, want tot zo ver merk ik er niets van, maar ik ben bang dat de gebruiker van de laptop er in de toekomst problemen mee gaat krijgen en het is niet bepaald veilig omdat er bankzaken op de laptop uitgevoerd worden
Op internet heb ik uitgevonden dat dit de laatste tijd meer is voorgekomen. De gebruikers hebben dit gekregen uit een totaal normale youtube link.
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-25 02:54:31
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545032B9A300 rev.PB3OC60F 298,09GB
Running: 1dvud5qc.exe; Driver: C:\Users\Diana\AppData\Local\Temp\ugloapog.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [624:2260] 000007fef73814a0
Thread C:\Windows\System32\svchost.exe [624:2568] 000007fef661a2b0
Thread C:\Windows\System32\svchost.exe [624:3920] 000007fef93944e0
Thread C:\Windows\System32\svchost.exe [624:516] 000007fef96188f8
Thread C:\Windows\system32\svchost.exe [804:3436] 000007fef95c5124
Thread C:\Windows\system32\svchost.exe [804:3852] 000007fef21f506c
Thread C:\Windows\system32\svchost.exe [804:3856] 000007fef5c21c20
Thread C:\Windows\system32\svchost.exe [804:3860] 000007fef5c21c20
Thread C:\Windows\system32\svchost.exe [804:2316] 000007fef9c01ab0
Thread C:\Windows\system32\svchost.exe [1144:4952] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:5016] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:3200] 000007fef341d3c8
Thread C:\Windows\system32\svchost.exe [1144:5020] 000007fef341d3c8
Thread C:\Windows\System32\spoolsv.exe [1708:2760] 000007fef91c10c8
Thread C:\Windows\System32\spoolsv.exe [1708:2772] 000007fef7b76144
Thread C:\Windows\System32\spoolsv.exe [1708:2780] 000007fef7965fd0
Thread C:\Windows\System32\spoolsv.exe [1708:2784] 000007fef7953438
Thread C:\Windows\System32\spoolsv.exe [1708:2788] 000007fef79663ec
Thread C:\Windows\System32\spoolsv.exe [1708:2796] 000007fef8d75e5c
Thread C:\Windows\System32\spoolsv.exe [1708:3064] 000007fef86a5074
Thread C:\Windows\system32\svchost.exe [1760:2964] 000007fef70e2888
Thread C:\Windows\system32\svchost.exe [1760:2376] 000007fef70e2a40
Thread C:\Windows\system32\svchost.exe [2188:2228] 000007feff4da808
Thread C:\Windows\system32\svchost.exe [2188:2268] 000007fef9567130
Thread C:\Windows\system32\svchost.exe [2188:2272] 000007fef955d5c0
Thread C:\Windows\system32\taskhost.exe [2352:2468] 000007fef8d61f38
Thread C:\Windows\system32\taskhost.exe [2352:2472] 000007feff639274
Thread C:\Windows\system32\taskhost.exe [2352:2488] 000007fef8802740
Thread C:\Windows\system32\taskhost.exe [2352:2612] 000007fefb071010
Thread C:\Windows\system32\Dwm.exe [2704:2756] 000007fef843f0d8
Thread C:\Windows\system32\Dwm.exe [2704:2764] 000007fef7bbabf0
Thread C:\Windows\system32\svchost.exe [3040:3056] 000007feff4da808
Thread C:\Windows\system32\svchost.exe [2552:2676] 000007fef5888470
Thread C:\Windows\system32\svchost.exe [2552:1920] 000007fef5892418
Thread C:\Windows\system32\svchost.exe [2552:4072] 000007fef7965fd0
Thread C:\Windows\system32\svchost.exe [2552:4076] 000007fef79663ec
Thread C:\Windows\system32\svchost.exe [2552:2588] 000007fef2375f1c
Thread C:\Windows\system32\SearchIndexer.exe [3424:3644] 000007fef4b65170
Thread C:\Windows\system32\SearchIndexer.exe [3424:3668] 000007fef4ff69ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3676] 000007fef4dc3dac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3680] 000007fef4dc1700
Thread C:\Windows\system32\SearchIndexer.exe [3424:3684] 000007fef4deb248
Thread C:\Windows\system32\SearchIndexer.exe [3424:3688] 000007fef4dec4ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:3808] 000007fef4ff69ac
Thread C:\Windows\system32\SearchIndexer.exe [3424:1312] 000007fef4ff69ac
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:3180] 000007fefeb30168
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:3204] 000007fefbae2a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3596:244] 000007fef95c5124
Thread C:\Windows\System32\svchost.exe [2292:600] 000007fef1df9688
---- EOF - GMER 2.1 ----
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7601.17514
Run by Diana at 2:56:44 on 2013-07-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1787.904 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
G:\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
G:\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\PLFSetI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
G:\Avast\AvastUI.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
G:\Malwarebytes' Anti-Malware\mbamscheduler.exe
G:\Malwarebytes' Anti-Malware\mbamservice.exe
G:\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - G:\Avast\aswWebRepIE.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [avast] "G:\Avast\avastUI.exe" /nogui
mRunOnce: [Malwarebytes Anti-Malware] G:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{0F642EF0-90EA-4FAE-B783-D1D9375945F1} : DHCPNameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{79395291-EB9D-4E5B-AC2C-1E7D4FCA3E90} : DHCPNameServer = 62.179.104.196 213.46.228.196
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - G:\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Nieuwe map (2)\Java\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Nieuwe map (2)\Java\bin\jp2ssv.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - G:\Avast\aswWebRepIE64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [PLFSetI] C:\Windows\PLFSetI.exe
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-6-30 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-6-30 189936]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-6-30 1030952]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-6-30 378944]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-6-30 203264]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-6-30 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-6-30 80816]
R2 avast! Antivirus;avast! Antivirus;G:\Avast\AvastSvc.exe [2013-6-30 46808]
R2 MBAMScheduler;MBAMScheduler;G:\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-7-25 418376]
R2 MBAMService;MBAMService;G:\Malwarebytes' Anti-Malware\mbamservice.exe [2013-7-25 701512]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-6-30 116752]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2010-5-15 384040]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-7-25 25928]
R3 SbieDrv;SbieDrv;G:\Sandboxie\SbieDrv.sys [2013-7-8 199384]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-6-30 38528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-6-30 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-7-21 59392]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-6-30 1255736]
SUnknown tsusbhub;tsusbhub; [x]
.
=============== Created Last 30 ================
.
2013-07-25 00:42:52 -------- d-----w- C:\Users\Diana\AppData\Roaming\Malwarebytes
2013-07-25 00:42:41 -------- d-----w- C:\ProgramData\Malwarebytes
2013-07-25 00:42:39 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-25 00:42:26 -------- d-----w- C:\Users\Diana\AppData\Local\Programs
2013-07-23 10:21:49 -------- d-----w- C:\Users\Diana\AppData\Roaming\Remere's Map Editor
2013-07-21 15:22:02 -------- d-----w- C:\ProgramData\Caphyon
2013-07-21 14:59:08 -------- d-----w- C:\ProgramData\Package Cache
2013-07-21 14:57:59 238088 ----a-w- C:\Windows\SysWow64\xactengine3_1.dll
2013-07-21 14:54:14 -------- d-----w- C:\Windows\SysWow64\directx
2013-07-21 14:51:46 -------- d-----w- C:\Users\Diana\AppData\Roaming\AetherNet
2013-07-21 14:10:57 -------- d-----w- C:\Windows\System32\SPReview
2013-07-21 14:10:13 -------- d-----w- C:\Windows\System32\EventProviders
2013-07-21 14:01:24 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2013-07-21 14:01:23 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2013-07-21 14:01:14 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2013-07-21 14:01:07 59392 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2013-07-21 14:01:07 12288 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-07-21 14:01:06 1838080 ----a-w- C:\Windows\System32\d3d10warp.dll
2013-07-21 14:01:05 14967808 ----a-w- C:\Program Files\DVD Maker\OmdBase.dll
2013-07-21 13:59:59 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-07-21 13:58:59 378880 ----a-w- C:\Windows\System32\msinfo32.exe
2013-07-21 13:57:59 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-21 13:56:59 73216 ----a-w- C:\Windows\System32\unimdmat.dll
2013-07-21 13:55:59 8192 ----a-w- C:\Windows\System32\KBDTUF.DLL
2013-07-21 13:54:58 399872 ----a-w- C:\Windows\System32\dpx.dll
2013-07-21 13:54:58 189952 ----a-w- C:\Windows\SysWow64\wdscore.dll
2013-07-21 13:54:36 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2013-07-21 13:54:29 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2013-07-21 13:52:06 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-07-19 14:35:59 -------- d-----w- C:\Users\Diana\AppData\Roaming\Ableton
2013-07-19 14:33:47 -------- d-----w- C:\Program Files (x86)\Common Files\Propellerhead Software
2013-07-19 00:21:20 51712 ----a-w- C:\Windows\AutosetFrequency.exe
2013-07-19 00:21:20 214400 ----a-w- C:\Windows\SysWow64\snpropwp.dll
2013-07-19 00:21:20 206208 ----a-w- C:\Windows\PLFSetI.exe
2013-07-19 00:21:07 -------- d-----w- C:\Program Files (x86)\VideoWebCamera
2013-07-16 19:07:33 -------- d-----r- C:\Sandbox
2013-07-15 23:46:08 -------- d-----w- C:\Users\Diana\AppData\Roaming\uTorrent
2013-07-15 18:08:18 -------- d-----w- C:\Users\Diana\AppData\Roaming\.minecraft
2013-07-15 18:06:44 972712 ----a-w- C:\Windows\System32\deployJava1.dll
2013-07-15 18:06:44 1093032 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-07-15 18:06:28 108968 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-07-09 17:29:52 -------- d--h--w- C:\ProgramData\CanonIJMIG
2013-07-09 17:28:59 -------- d--h--w- C:\ProgramData\CanonIJScan
2013-07-05 20:26:26 -------- d--h--w- C:\ProgramData\CanonIJEGV
2013-07-05 20:24:55 320000 ----a-w- C:\Windows\SysWow64\CNC_B8L.dll
2013-07-05 20:24:55 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2013-07-05 20:24:55 103424 ----a-w- C:\Windows\SysWow64\CNC_B8U.dll
2013-07-05 20:21:54 -------- d-----w- C:\Program Files\Common Files\CANON
2013-07-05 20:21:41 -------- d-----w- C:\ProgramData\CanonIJWSpt
2013-07-05 20:14:48 -------- d-----w- C:\Program Files\Canon
2013-07-05 20:13:34 30208 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDB8.DLL
2013-07-05 20:13:34 100352 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPB8.DLL
2013-07-05 20:13:19 363520 ----a-w- C:\Windows\System32\CNC_B8L.dll
2013-07-05 20:13:19 287744 ----a-w- C:\Windows\System32\CNC_B8C.dll
2013-07-05 20:13:19 17920 ----a-w- C:\Windows\System32\CNHMCA6.dll
2013-07-05 20:13:19 106496 ----a-w- C:\Windows\System32\CNC_B8I.dll
2013-07-05 20:12:48 389120 ----a-w- C:\Windows\System32\CNMLMB8.DLL
2013-07-05 20:12:13 39424 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2013-07-05 20:12:13 359936 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2013-07-05 20:12:13 -------- d-----w- C:\Windows\System32\STRING
2013-07-05 20:10:58 -------- d--h--w- C:\ProgramData\CanonIJETV
2013-07-05 20:10:31 -------- d-----w- C:\Program Files (x86)\Canon
2013-07-01 14:29:18 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-01 14:29:18 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-01 14:28:37 -------- d-----w- C:\Users\Diana\AppData\Local\Adobe
2013-06-30 23:59:38 -------- d-----w- C:\Windows\Panther
2013-06-30 22:21:13 -------- d-----w- C:\Program Files\CCleaner
2013-06-30 22:12:43 2229608 ----a-w- C:\Windows\System32\drivers\athrx.sys
2013-06-30 22:12:43 2229608 ----a-w- C:\Windows\System32\athrx.sys
2013-06-30 22:12:43 -------- d-----w- C:\Program Files (x86)\Atheros
2013-06-30 21:43:17 -------- d-----w- C:\Windows\SysWow64\Wat
2013-06-30 21:43:17 -------- d-----w- C:\Windows\System32\Wat
2013-06-30 21:24:06 2560 ----a-w- C:\Windows\System32\drivers\nl-NL\wdf01000.sys.mui
2013-06-30 21:24:05 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-06-30 21:24:04 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-06-30 21:24:04 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-06-30 21:24:04 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-06-30 21:20:47 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-06-30 21:20:46 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-06-30 21:20:44 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-06-30 21:20:44 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-06-30 21:20:41 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-06-30 21:20:40 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-06-30 21:20:40 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-06-30 21:03:18 902656 ----a-w- C:\Windows\System32\d2d1.dll
2013-06-30 21:03:17 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2013-06-30 21:03:16 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2013-06-30 21:03:13 220160 ----a-w- C:\Windows\System32\wintrust.dll
2013-06-30 21:03:13 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-06-30 21:00:15 -------- d-----w- C:\Windows\System32\appmgmt
2013-06-30 20:53:31 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-06-30 20:53:31 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-06-30 20:53:31 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-06-30 20:53:29 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-06-30 20:53:29 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-06-30 20:53:29 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-06-30 20:41:27 -------- d-----w- C:\Windows\SysWow64\nl
2013-06-30 20:41:27 -------- d-----w- C:\Windows\SysWow64\0413
2013-06-30 20:41:27 -------- d-----w- C:\Windows\nl-NL
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\XPSViewer
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\drivers\UMDF\nl-NL
2013-06-30 20:41:08 -------- d-----w- C:\Windows\SysWow64\drivers\nl-NL
2013-06-30 20:41:05 -------- d-----w- C:\Windows\SysWow64\wbem\nl-NL
2013-06-30 20:41:02 -------- d-----w- C:\Windows\System32\nl
2013-06-30 20:41:02 -------- d-----w- C:\Windows\System32\0413
2013-06-30 20:40:39 -------- d-----w- C:\Windows\System32\drivers\UMDF\nl-NL
2013-06-30 20:40:39 -------- d-----w- C:\Windows\System32\drivers\nl-NL
2013-06-30 20:40:27 -------- d-----w- C:\Windows\System32\wbem\nl-NL
2013-06-30 19:11:58 5632 ----a-w- C:\Windows\System32\drivers\nl-NL\ndiscap.sys.mui
2013-06-30 18:51:24 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-06-30 18:51:24 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-06-30 18:51:24 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-06-30 18:51:23 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-06-30 18:51:23 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-06-30 18:51:22 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-06-30 18:44:14 515584 ----a-w- C:\Windows\System32\timedate.cpl
2013-06-30 18:44:14 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2013-06-30 18:44:04 503808 ----a-w- C:\Windows\System32\srcore.dll
2013-06-30 18:44:04 296960 ----a-w- C:\Windows\System32\rstrui.exe
2013-06-30 18:44:03 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2013-06-30 18:42:41 142336 ----a-w- C:\Windows\System32\poqexec.exe
2013-06-30 18:42:40 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2013-06-30 18:42:36 2871808 ----a-w- C:\Windows\explorer.exe
2013-06-30 18:42:34 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2013-06-30 18:40:56 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-06-30 18:40:56 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-06-30 18:40:56 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-06-30 18:40:55 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-06-30 18:40:54 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-06-30 18:39:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2013-06-30 18:39:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-06-30 18:39:35 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
2013-06-30 18:39:34 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-06-30 18:39:07 33792 ----a-w- C:\Windows\System32\profprov.dll
2013-06-30 18:39:07 209920 ----a-w- C:\Windows\System32\profsvc.dll
2013-06-30 18:39:03 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2013-06-30 18:39:01 800768 ----a-w- C:\Windows\System32\usp10.dll
2013-06-30 18:39:00 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2013-06-30 18:37:44 3216384 ----a-w- C:\Windows\System32\msi.dll
2013-06-30 18:37:41 2342400 ----a-w- C:\Windows\SysWow64\msi.dll
2013-06-30 18:35:32 605552 ----a-w- C:\Windows\System32\winload.exe
2013-06-30 18:35:31 642944 ----a-w- C:\Windows\System32\winload.efi
2013-06-30 18:35:31 518672 ----a-w- C:\Windows\System32\winresume.exe
2013-06-30 18:35:30 566208 ----a-w- C:\Windows\System32\winresume.efi
2013-06-30 18:35:29 20352 ----a-w- C:\Windows\System32\kdusb.dll
2013-06-30 18:35:29 19328 ----a-w- C:\Windows\System32\kd1394.dll
2013-06-30 18:35:29 17792 ----a-w- C:\Windows\System32\kdcom.dll
2013-06-30 18:35:28 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2013-06-30 18:34:01 31232 ----a-w- C:\Windows\System32\prevhost.exe
2013-06-30 18:34:00 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2013-06-30 18:29:49 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2013-06-30 18:29:47 67072 ----a-w- C:\Windows\splwow64.exe
2013-06-30 18:27:38 -------- d-----w- C:\Users\Diana\AppData\Roaming\Windows Live Writer
2013-06-30 18:27:38 -------- d-----w- C:\Users\Diana\AppData\Local\Windows Live Writer
2013-06-30 17:35:00 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2013-06-30 17:34:58 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-06-30 17:31:32 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2013-06-30 17:31:32 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2013-06-30 17:31:32 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2013-06-30 17:29:17 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2013-06-30 17:29:08 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2013-06-30 17:29:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
2013-06-30 17:26:50 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-06-30 17:25:56 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-30 17:25:55 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2013-06-30 17:25:54 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-06-30 17:25:32 162816 ----a-w- C:\Windows\System32\rdpudd.dll
2013-06-30 17:25:32 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2013-06-30 17:25:31 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2013-06-30 17:25:31 20992 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
2013-06-30 17:25:19 395776 ----a-w- C:\Windows\System32\webio.dll
2013-06-30 17:25:17 314880 ----a-w- C:\Windows\SysWow64\webio.dll
2013-06-30 17:25:05 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-06-30 17:23:18 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2013-06-30 17:23:17 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2013-06-30 17:23:07 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2013-06-30 17:23:06 288256 ----a-w- C:\Windows\System32\MSNP.ax
2013-06-30 17:23:05 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2013-06-30 17:23:04 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2013-06-30 17:23:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2013-06-30 17:23:01 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2013-06-30 17:23:00 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2013-06-30 17:23:00 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2013-06-30 17:21:56 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-06-30 17:20:41 478208 ----a-w- C:\Windows\System32\dpnet.dll
2013-06-30 17:20:40 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
2013-06-30 17:20:39 3072 ----a-w- C:\Windows\System32\dpnaddr.dll
2013-06-30 17:20:39 2560 ----a-w- C:\Windows\SysWow64\dpnaddr.dll
2013-06-30 17:20:35 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2013-06-30 17:20:16 2164224 ----a-w- C:\Program Files\Windows Journal\Journal.exe
2013-06-30 17:20:12 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-06-30 17:20:10 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-06-30 17:20:08 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-06-30 17:20:04 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-06-30 17:20:03 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-06-30 17:00:10 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2013-06-30 17:00:09 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2013-06-30 17:00:07 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2013-06-30 17:00:06 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2013-06-30 17:00:05 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2013-06-30 17:00:05 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2013-06-30 17:00:03 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2013-06-30 17:00:00 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2013-06-30 16:59:59 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll
2013-06-30 16:59:59 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2013-06-30 16:59:58 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll
2013-06-30 16:59:58 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll
2013-06-30 16:59:55 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2013-06-30 16:59:38 77312 ----a-w- C:\Windows\System32\packager.dll
2013-06-30 16:59:38 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-06-30 16:59:16 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2013-06-30 16:59:13 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-06-30 16:58:44 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-06-30 16:58:39 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-06-30 16:58:34 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-06-30 16:58:28 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-06-30 16:58:28 112640 ----a-w- C:\Windows\System32\smss.exe
2013-06-30 16:58:26 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-06-30 16:56:17 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-06-30 16:56:14 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-06-30 16:56:13 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-06-30 16:42:00 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-06-30 16:41:49 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-06-30 16:41:37 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-06-30 16:41:37 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2013-06-30 16:14:23 -------- d-----w- C:\Windows\PCHEALTH
2013-06-30 16:13:27 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{38305BDA-257D-4BEF-9CBD-CE66C875AE11}\mpengine.dll
2013-06-30 16:13:25 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-06-30 16:05:47 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-06-30 16:05:44 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-06-30 16:05:43 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-06-30 16:05:42 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-06-30 16:05:34 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-06-30 16:04:10 41664 ----a-w- C:\Windows\avastSS.scr
2013-06-30 16:02:07 -------- d-----w- C:\ProgramData\AVAST Software
2013-06-30 16:01:36 889416 -c--a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\18ea83851ce75ab01\dotNetFx40_Full_setup.exe
2013-06-30 16:01:32 -------- d-----w- C:\Users\Diana\AppData\Local\Windows Live
2013-06-30 16:01:13 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-06-30 15:56:39 -------- d-----w- C:\Users\Diana\AppData\Local\Google
2013-06-30 15:56:22 -------- d-----w- C:\Users\Diana\AppData\Local\Deployment
2013-06-30 15:56:22 -------- d-----w- C:\Users\Diana\AppData\Local\Apps
2013-06-30 15:52:52 -------- d-----w- C:\ProgramData\Atheros
2013-06-30 15:51:49 6656 ----a-w- C:\Windows\System32\bcmwlrc.dll
2013-06-30 15:51:48 -------- d-----w- C:\Program Files\Broadcom
2013-06-30 15:34:50 -------- d-----w- C:\Users\Diana\AppData\Local\Diagnostics
2013-06-30 15:20:29 0 ----a-w- C:\Windows\ativpsrm.bin
2013-06-30 15:19:24 38528 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2013-06-30 15:18:00 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2013-06-30 15:15:44 -------- d-sh--w- C:\Windows\Installer
2013-06-30 15:15:31 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
2013-06-30 14:06:42 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2013-07-21 14:30:27 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-07-21 14:30:27 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-05-19 10:54:27 97176 ----a-w- C:\Windows\SysWow64\ElbyCDIO.dll
.
============= FINISH: 2:58:37,49 ===============
Comment