Ahoi,
ik denk dat een of meerdere virus(sen) deze pc een beetje naar de gal gebracht hebben. BITS-service was foetsie, Windows-update idem, en Windows fire-wall enzo. Wilde gewoon eens windows updaten, zag toen foutmelding, via microsoft proberen te fixen. Volgens mij maar half gelukt. Laatste automatische update was vanaf 7-9-2012. Nu lukt updaten wel, maar wel erg vaak nog mislukkingen en fout bij configureren van windows-updates.
Gaarne een deskundige blik en hulp via de logjes...
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.07.27.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Michiel&Lisette :: PC-KINDEREN [administrator]
27-7-2013 17:33:34
mbam-log-2013-07-27 (17-33-34).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 289994
Verstreken tijd: 7 minuut/minuten, 44 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.21.2
Run by Michiel&Lisette at 17:48:03 on 2013-07-27
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3326.1708 [GMT 2:00]
.
AV: McAfee Antivirus en antispyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
SP: McAfee Antivirus en antispyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\PROGRA~1\McAfee\MSC\McAPExe.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\spotify.exe
C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\McAfee\MAT\McPvTray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.nl/
uWindow Title = Internet Explorer aangeboden door Dell
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: {22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - <orphaned>
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Web Assistant: {336D0C35-8A85-403a-B9D2-65C292C39087} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - c:\program files\yontoo\YontooIEClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
uRun: [Spotify] "c:\users\michiel&lisette\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart
uRun: [Spotify Web Helper] "c:\users\michiel&lisette\appdata\roaming\spotify\data\SpotifyWebHelper.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Logitech Hardware Abstraction Layer] "c:\program files\common files\logitech\khalshared\KHALMNPR.EXE"
mRun: [NMSSupport] "c:\program files\common files\intel\inteldh\nms\support\IntelHCTAgent.exe" /startup
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [mcpltui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [CDAServer] c:\program files\common files\common desktop agent\CDASrv.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{EFE0253E-2E9C-4755-BA10-4154E35A5008} : DHCPNameServer = 62.133.126.28 62.133.126.29
TCP: Interfaces\{FDB63842-7666-4353-A971-1461F551E547} : DHCPNameServer = 212.54.40.25 212.54.35.25
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [2013-5-10 66296]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2012-9-15 566656]
R0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-9-15 212432]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2007-2-12 208896]
R2 HomeNetSvc;McAfee Home Network;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2012-9-28 167784]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 mcpltsvc;McAfee Platform Services;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 mfecore;McAfee Anti-Malware Core;c:\program files\common files\mcafee\amcore\mcshield.exe [2013-1-15 638976]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2013-1-15 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-3-13 172416]
R2 NMSCore;Intel(R) NMSCore;c:\program files\common files\intel\inteldh\nms\nmscore\NMSCore.exe [2007-6-27 317656]
R2 nmsunidr;UniDriver for NMS;c:\windows\system32\drivers\nmsunidr.sys [2007-2-18 5376]
R2 QualityManager;Intel(R) Quality Manager;c:\program files\intel\inteldh\intel media server\media server\bin\QualityManager.exe [2007-6-27 272600]
R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.sys [2012-7-19 5120]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2012-11-9 235520]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-11-9 363432]
R3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\drivers\mfencbdc.sys [2013-2-18 257496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 MCLServiceATL;Intel(R) Application Tracker;c:\program files\intel\inteldh\intel media server\shells\MCLServiceATL.exe [2007-6-27 157912]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-11-9 60920]
S3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\common files\intel\inteldh\bin\DHTraceController.exe [2007-6-27 39640]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-7 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-20 30192]
S3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2013-4-10 147472]
S3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2012-9-15 203080]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2012-11-9 65928]
S3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\drivers\mfencrk.sys [2013-2-18 80592]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-5-10 18432]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-1 52224]
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-23 1343400]
S3 WSDScan;Ondersteuning voor WSD-scan via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-7-14 20480]
S3 Yontoo Desktop Updater;Yontoo Desktop Updater;c:\program files\yontoo\Y2Desktop.Updater.exe [2013-5-18 23552]
S4 McOobeSv;McAfee OOBE Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2012-9-28 167784]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2013-07-27 15:32:56 -------- d-----w- c:\users\michiel&lisette\appdata\roaming\Malwarebytes
2013-07-27 15:32:42 -------- d-----w- c:\programdata\Malwarebytes
2013-07-27 15:32:39 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-27 15:32:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-07-26 14:06:21 -------- d-----w- c:\windows\system32\MRT
2013-07-26 13:58:13 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-07-26 13:54:47 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-07-26 13:41:51 -------- d-----w- c:\windows\Panther
2013-07-25 23:49:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-07-25 23:49:59 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-07-25 23:25:10 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-07-25 23:25:10 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-07-25 23:25:10 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-07-25 23:24:06 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-07-25 23:24:06 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-07-25 23:24:06 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-07-25 23:24:06 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-07-25 23:24:05 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-07-25 23:24:05 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-07-25 23:24:05 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-07-25 23:10:37 369856 ----a-w- c:\windows\system32\drivers\cng.sys
2013-07-25 23:10:37 247808 ----a-w- c:\windows\system32\schannel.dll
2013-07-25 23:10:37 136560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-07-25 23:10:36 1039360 ----a-w- c:\windows\system32\lsasrv.dll
2013-07-25 23:10:27 509440 ----a-w- c:\windows\system32\qedit.dll
2013-07-25 23:10:24 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-07-25 23:10:20 903168 ----a-w- c:\windows\system32\certutil.exe
2013-07-25 23:10:19 43008 ----a-w- c:\windows\system32\certenc.dll
2013-07-25 23:10:19 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-25 23:10:19 1160192 ----a-w- c:\windows\system32\crypt32.dll
2013-07-25 23:10:19 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-25 23:07:31 1620480 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 23:07:26 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-07-25 23:07:25 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-07-25 23:07:24 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-07-25 23:07:09 1389568 ----a-w- c:\windows\system32\msxml6.dll
2013-07-25 23:07:06 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-07-25 23:07:04 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-07-25 23:06:55 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-07-25 23:06:41 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-07-25 23:06:36 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-07-25 23:06:31 156672 ----a-w- c:\windows\system32\ncsi.dll
2013-07-25 23:06:30 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-07-25 23:06:30 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-07-25 23:06:30 242176 ----a-w- c:\windows\system32\nlasvc.dll
2013-07-25 23:06:30 175104 ----a-w- c:\windows\system32\netcorehc.dll
2013-07-25 23:06:29 52224 ----a-w- c:\windows\system32\nlaapi.dll
2013-07-25 23:06:29 18944 ----a-w- c:\windows\system32\netevent.dll
2013-07-25 23:06:04 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-07-25 23:06:02 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-07-25 23:05:36 626688 ----a-w- c:\windows\system32\usp10.dll
2013-07-25 23:05:34 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-07-25 23:05:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-07-25 23:05:33 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-07-25 23:05:30 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-07-25 23:05:30 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-07-25 23:05:27 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-07-25 23:04:55 542208 ----a-w- c:\windows\system32\kerberos.dll
2013-07-25 23:04:52 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-07-25 22:59:02 46592 ----a-w- c:\windows\system32\fpb.rs
2013-07-25 22:59:02 45568 ----a-w- c:\windows\system32\oflc-nz.rs
2013-07-25 22:59:02 43520 ----a-w- c:\windows\system32\csrr.rs
2013-07-25 22:59:02 40960 ----a-w- c:\windows\system32\cob-au.rs
2013-07-25 22:59:01 44544 ----a-w- c:\windows\system32\pegibbfc.rs
2013-07-25 22:59:01 30720 ----a-w- c:\windows\system32\usk.rs
2013-07-25 22:59:01 15360 ----a-w- c:\windows\system32\djctq.rs
2013-07-25 22:59:00 2576384 ----a-w- c:\windows\system32\gameux.dll
2013-07-25 22:59:00 21504 ----a-w- c:\windows\system32\grb.rs
2013-07-25 22:59:00 20480 ----a-w- c:\windows\system32\pegi.rs
2013-07-25 22:59:00 20480 ----a-w- c:\windows\system32\pegi-pt.rs
2013-07-25 22:58:59 308736 ----a-w- c:\windows\system32\Wpc.dll
2013-07-25 22:58:55 51712 ----a-w- c:\windows\system32\esrb.rs
2013-07-25 22:58:55 20480 ----a-w- c:\windows\system32\pegi-fi.rs
2013-07-25 22:58:54 55296 ----a-w- c:\windows\system32\cero.rs
2013-07-25 22:58:54 23552 ----a-w- c:\windows\system32\oflc.rs
2013-07-25 22:58:21 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-07-25 22:58:20 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-07-25 22:58:17 936448 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2013-07-25 22:58:16 988672 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2013-07-25 22:58:16 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll
2013-07-25 22:58:15 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL
2013-07-25 22:58:00 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-07-25 22:56:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-07-25 22:53:58 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-07-25 22:53:58 1796096 ----a-w- c:\windows\system32\authui.dll
2013-07-25 22:53:58 101720 ----a-w- c:\windows\system32\consent.exe
2013-07-25 21:27:41 -------- d-----w- C:\AULOGS
2013-07-20 19:07:21 -------- d-----w- c:\users\michiel&lisette\appdata\roaming\Dofus
2013-07-19 19:16:12 -------- d-----w- c:\users\michiel&lisette\appdata\local\{702211F5-FD05-44EE-8152-AB34E8DFACD6}
.
==================== Find3M ====================
.
2013-07-24 09:39:28 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-24 09:39:28 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-21 11:32:20 212600 ----a-w- c:\windows\system32\SBuySupplies.exe
2013-06-21 11:32:14 28672 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\sst6cpc.dll
2013-05-08 05:38:00 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-06 05:06:47 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-06 05:06:47 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe
.
============= FINISH: 17:49:10,42 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-27 18:12:47
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500630AS rev.3.ADG 465,76GB
Running: uewodbpf.exe; Driver: C:\Users\MICHIE~1\AppData\Local\Temp\aglyiaoc.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 834449F5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8347E1F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92A09000, 0x2D5378, 0xE8000020]
? C:\Users\MICHIE~1\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven pad niet vinden. !
---- User code sections - GMER 2.1 ----
.text C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\spotify.exe[2240] ntdll.dll!DbgBreakPoint 7724410C 1 Byte [C3]
.text C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe[2292] kernel32.dll!LoadLibraryA 755FDC65 5 Bytes JMP 70068A00 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll
.text C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe[2292] kernel32.dll!LoadLibraryW 755FEF42 5 Bytes JMP 70068B00 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] shell32.DLL!RealDriveType + 173D 7665FE30 4 Bytes [E5, 36, 0C, 73] {IN EAX, 0x36; OR AL, 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] shell32.DLL!RealDriveType + 1745 7665FE38 8 Bytes [1B, 57, 0C, 73, 9F, 83, 0D, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5548] shell32.DLL!RealDriveType + 173D 7665FE30 4 Bytes [E5, 36, 0C, 73] {IN EAX, 0x36; OR AL, 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[5548] shell32.DLL!RealDriveType + 1745 7665FE38 8 Bytes [1B, 57, 0C, 73, 9F, 83, 0D, ...]
---- Devices - GMER 2.1 ----
Device \Driver\BTHUSB \Device\00000075 bthport.sys
Device \Driver\BTHUSB \Device\00000077 bthport.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0007619eb73f
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\[email protected] 0x9B 0xF3 0xA1 0x21 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd503294
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0002
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0007619eb73f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\[email protected] 0x9B 0xF3 0xA1 0x21 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd503294 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Type 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Before Out of Range 8
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Max Channels 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
---- EOF - GMER 2.1 ----
de GMER-scan kreeg op een gegeven moment een foutmelding, dat er geen disk in the device zat. Misschien heb ik een instelling verkeerd gezet of is er iets anders aan de hand? Bij deze regel ging het volgens mij fout...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
BVD voor de hulp iig!
Groet.
ik denk dat een of meerdere virus(sen) deze pc een beetje naar de gal gebracht hebben. BITS-service was foetsie, Windows-update idem, en Windows fire-wall enzo. Wilde gewoon eens windows updaten, zag toen foutmelding, via microsoft proberen te fixen. Volgens mij maar half gelukt. Laatste automatische update was vanaf 7-9-2012. Nu lukt updaten wel, maar wel erg vaak nog mislukkingen en fout bij configureren van windows-updates.
Gaarne een deskundige blik en hulp via de logjes...
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.07.27.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16635
Michiel&Lisette :: PC-KINDEREN [administrator]
27-7-2013 17:33:34
mbam-log-2013-07-27 (17-33-34).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 289994
Verstreken tijd: 7 minuut/minuten, 44 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.21.2
Run by Michiel&Lisette at 17:48:03 on 2013-07-27
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3326.1708 [GMT 2:00]
.
AV: McAfee Antivirus en antispyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
SP: McAfee Antivirus en antispyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\PROGRA~1\McAfee\MSC\McAPExe.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\spotify.exe
C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\McAfee\MAT\McPvTray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.nl/
uWindow Title = Internet Explorer aangeboden door Dell
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: {22dfbf5b-a7cd-4b25-9471-3dc68c71855f} - <orphaned>
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Web Assistant: {336D0C35-8A85-403a-B9D2-65C292C39087} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - c:\program files\yontoo\YontooIEClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
uRun: [Spotify] "c:\users\michiel&lisette\appdata\roaming\spotify\Spotify.exe" /uri spotify:autostart
uRun: [Spotify Web Helper] "c:\users\michiel&lisette\appdata\roaming\spotify\data\SpotifyWebHelper.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Logitech Hardware Abstraction Layer] "c:\program files\common files\logitech\khalshared\KHALMNPR.EXE"
mRun: [NMSSupport] "c:\program files\common files\intel\inteldh\nms\support\IntelHCTAgent.exe" /startup
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [mcpltui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [CDAServer] c:\program files\common files\common desktop agent\CDASrv.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{EFE0253E-2E9C-4755-BA10-4154E35A5008} : DHCPNameServer = 62.133.126.28 62.133.126.29
TCP: Interfaces\{FDB63842-7666-4353-A971-1461F551E547} : DHCPNameServer = 212.54.40.25 212.54.35.25
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [2013-5-10 66296]
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2012-9-15 566656]
R0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-9-15 212432]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2007-2-12 208896]
R2 HomeNetSvc;McAfee Home Network;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2012-9-28 167784]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 mcpltsvc;McAfee Platform Services;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
R2 mfecore;McAfee Anti-Malware Core;c:\program files\common files\mcafee\amcore\mcshield.exe [2013-1-15 638976]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2013-1-15 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-3-13 172416]
R2 NMSCore;Intel(R) NMSCore;c:\program files\common files\intel\inteldh\nms\nmscore\NMSCore.exe [2007-6-27 317656]
R2 nmsunidr;UniDriver for NMS;c:\windows\system32\drivers\nmsunidr.sys [2007-2-18 5376]
R2 QualityManager;Intel(R) Quality Manager;c:\program files\intel\inteldh\intel media server\media server\bin\QualityManager.exe [2007-6-27 272600]
R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.sys [2012-7-19 5120]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2012-11-9 235520]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-11-9 363432]
R3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\drivers\mfencbdc.sys [2013-2-18 257496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 MCLServiceATL;Intel(R) Application Tracker;c:\program files\intel\inteldh\intel media server\shells\MCLServiceATL.exe [2007-6-27 157912]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\platform\mcsvchost\McSvHost.exe [2013-1-15 184728]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-11-9 60920]
S3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\common files\intel\inteldh\bin\DHTraceController.exe [2007-6-27 39640]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-7 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-20 30192]
S3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2013-4-10 147472]
S3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2012-9-15 203080]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2012-11-9 65928]
S3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\drivers\mfencrk.sys [2013-2-18 80592]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-5-10 18432]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-1 52224]
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-23 1343400]
S3 WSDScan;Ondersteuning voor WSD-scan via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-7-14 20480]
S3 Yontoo Desktop Updater;Yontoo Desktop Updater;c:\program files\yontoo\Y2Desktop.Updater.exe [2013-5-18 23552]
S4 McOobeSv;McAfee OOBE Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2012-9-28 167784]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2013-07-27 15:32:56 -------- d-----w- c:\users\michiel&lisette\appdata\roaming\Malwarebytes
2013-07-27 15:32:42 -------- d-----w- c:\programdata\Malwarebytes
2013-07-27 15:32:39 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-27 15:32:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-07-26 14:06:21 -------- d-----w- c:\windows\system32\MRT
2013-07-26 13:58:13 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-07-26 13:54:47 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-07-26 13:41:51 -------- d-----w- c:\windows\Panther
2013-07-25 23:49:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-07-25 23:49:59 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-07-25 23:25:10 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-07-25 23:25:10 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-07-25 23:25:10 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-07-25 23:24:06 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-07-25 23:24:06 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-07-25 23:24:06 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-07-25 23:24:06 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-07-25 23:24:05 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-07-25 23:24:05 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-07-25 23:24:05 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-07-25 23:10:37 369856 ----a-w- c:\windows\system32\drivers\cng.sys
2013-07-25 23:10:37 247808 ----a-w- c:\windows\system32\schannel.dll
2013-07-25 23:10:37 136560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-07-25 23:10:36 1039360 ----a-w- c:\windows\system32\lsasrv.dll
2013-07-25 23:10:27 509440 ----a-w- c:\windows\system32\qedit.dll
2013-07-25 23:10:24 376832 ----a-w- c:\windows\system32\dpnet.dll
2013-07-25 23:10:20 903168 ----a-w- c:\windows\system32\certutil.exe
2013-07-25 23:10:19 43008 ----a-w- c:\windows\system32\certenc.dll
2013-07-25 23:10:19 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-25 23:10:19 1160192 ----a-w- c:\windows\system32\crypt32.dll
2013-07-25 23:10:19 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-25 23:07:31 1620480 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 23:07:26 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-07-25 23:07:25 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-07-25 23:07:24 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-07-25 23:07:09 1389568 ----a-w- c:\windows\system32\msxml6.dll
2013-07-25 23:07:06 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-07-25 23:07:04 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-07-25 23:06:55 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-07-25 23:06:41 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-07-25 23:06:36 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-07-25 23:06:31 156672 ----a-w- c:\windows\system32\ncsi.dll
2013-07-25 23:06:30 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-07-25 23:06:30 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-07-25 23:06:30 242176 ----a-w- c:\windows\system32\nlasvc.dll
2013-07-25 23:06:30 175104 ----a-w- c:\windows\system32\netcorehc.dll
2013-07-25 23:06:29 52224 ----a-w- c:\windows\system32\nlaapi.dll
2013-07-25 23:06:29 18944 ----a-w- c:\windows\system32\netevent.dll
2013-07-25 23:06:04 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-07-25 23:06:02 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-07-25 23:05:36 626688 ----a-w- c:\windows\system32\usp10.dll
2013-07-25 23:05:34 514560 ----a-w- c:\windows\system32\qdvd.dll
2013-07-25 23:05:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-07-25 23:05:33 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-07-25 23:05:30 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-07-25 23:05:30 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-07-25 23:05:27 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-07-25 23:04:55 542208 ----a-w- c:\windows\system32\kerberos.dll
2013-07-25 23:04:52 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-07-25 22:59:02 46592 ----a-w- c:\windows\system32\fpb.rs
2013-07-25 22:59:02 45568 ----a-w- c:\windows\system32\oflc-nz.rs
2013-07-25 22:59:02 43520 ----a-w- c:\windows\system32\csrr.rs
2013-07-25 22:59:02 40960 ----a-w- c:\windows\system32\cob-au.rs
2013-07-25 22:59:01 44544 ----a-w- c:\windows\system32\pegibbfc.rs
2013-07-25 22:59:01 30720 ----a-w- c:\windows\system32\usk.rs
2013-07-25 22:59:01 15360 ----a-w- c:\windows\system32\djctq.rs
2013-07-25 22:59:00 2576384 ----a-w- c:\windows\system32\gameux.dll
2013-07-25 22:59:00 21504 ----a-w- c:\windows\system32\grb.rs
2013-07-25 22:59:00 20480 ----a-w- c:\windows\system32\pegi.rs
2013-07-25 22:59:00 20480 ----a-w- c:\windows\system32\pegi-pt.rs
2013-07-25 22:58:59 308736 ----a-w- c:\windows\system32\Wpc.dll
2013-07-25 22:58:55 51712 ----a-w- c:\windows\system32\esrb.rs
2013-07-25 22:58:55 20480 ----a-w- c:\windows\system32\pegi-fi.rs
2013-07-25 22:58:54 55296 ----a-w- c:\windows\system32\cero.rs
2013-07-25 22:58:54 23552 ----a-w- c:\windows\system32\oflc.rs
2013-07-25 22:58:21 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-07-25 22:58:20 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-07-25 22:58:17 936448 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2013-07-25 22:58:16 988672 ----a-w- c:\program files\windows journal\JNTFiltr.dll
2013-07-25 22:58:16 969216 ----a-w- c:\program files\windows journal\JNWDRV.dll
2013-07-25 22:58:15 1221632 ----a-w- c:\program files\windows journal\NBDoc.DLL
2013-07-25 22:58:00 220160 ----a-w- c:\windows\system32\ncrypt.dll
2013-07-25 22:56:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-07-25 22:53:58 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-07-25 22:53:58 1796096 ----a-w- c:\windows\system32\authui.dll
2013-07-25 22:53:58 101720 ----a-w- c:\windows\system32\consent.exe
2013-07-25 21:27:41 -------- d-----w- C:\AULOGS
2013-07-20 19:07:21 -------- d-----w- c:\users\michiel&lisette\appdata\roaming\Dofus
2013-07-19 19:16:12 -------- d-----w- c:\users\michiel&lisette\appdata\local\{702211F5-FD05-44EE-8152-AB34E8DFACD6}
.
==================== Find3M ====================
.
2013-07-24 09:39:28 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-24 09:39:28 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-21 11:32:20 212600 ----a-w- c:\windows\system32\SBuySupplies.exe
2013-06-21 11:32:14 28672 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\sst6cpc.dll
2013-05-08 05:38:00 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-06 05:06:47 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-06 05:06:47 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe
.
============= FINISH: 17:49:10,42 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-27 18:12:47
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500630AS rev.3.ADG 465,76GB
Running: uewodbpf.exe; Driver: C:\Users\MICHIE~1\AppData\Local\Temp\aglyiaoc.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 834449F5 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8347E1F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92A09000, 0x2D5378, 0xE8000020]
? C:\Users\MICHIE~1\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven pad niet vinden. !
---- User code sections - GMER 2.1 ----
.text C:\Users\Michiel&Lisette\AppData\Roaming\Spotify\spotify.exe[2240] ntdll.dll!DbgBreakPoint 7724410C 1 Byte [C3]
.text C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe[2292] kernel32.dll!LoadLibraryA 755FDC65 5 Bytes JMP 70068A00 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll
.text C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe[2292] kernel32.dll!LoadLibraryW 755FEF42 5 Bytes JMP 70068B00 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] shell32.DLL!RealDriveType + 173D 7665FE30 4 Bytes [E5, 36, 0C, 73] {IN EAX, 0x36; OR AL, 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[3804] shell32.DLL!RealDriveType + 1745 7665FE38 8 Bytes [1B, 57, 0C, 73, 9F, 83, 0D, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5548] shell32.DLL!RealDriveType + 173D 7665FE30 4 Bytes [E5, 36, 0C, 73] {IN EAX, 0x36; OR AL, 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[5548] shell32.DLL!RealDriveType + 1745 7665FE38 8 Bytes [1B, 57, 0C, 73, 9F, 83, 0D, ...]
---- Devices - GMER 2.1 ----
Device \Driver\BTHUSB \Device\00000075 bthport.sys
Device \Driver\BTHUSB \Device\00000077 bthport.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0007619eb73f
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\[email protected] 0x9B 0xF3 0xA1 0x21 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0009dd503294
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\0002
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0007619eb73f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\[email protected] 0x9B 0xF3 0xA1 0x21 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0009dd503294 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\0002 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Type 1
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Before Out of Range 8
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Max Channels 2
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
---- EOF - GMER 2.1 ----
de GMER-scan kreeg op een gegeven moment een foutmelding, dat er geen disk in the device zat. Misschien heb ik een instelling verkeerd gezet of is er iets anders aan de hand? Bij deze regel ging het volgens mij fout...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings\[email protected] \??\USB#VID_046D&PID_C709#0007619EB73F#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
BVD voor de hulp iig!
Groet.
Comment