Na opstart van de laptop blijft het scherm zwart alleen de muis cursorverschijnt.
Met F8 in veilige modus, of met systeem fouten controle start win 7 wel op.
Na het lezen van verschillende topics,heb ik deze tools al gedownload en installeerd in de deze volgorde.
Hopende dat iemand me verder kan en wil helpen. met deze informatie.
B.V.D Patricia
Stap 1: uitschakelen van emulatiesoftware
Stap 2: scannen op malware met Malwarebytes Anti-Malware
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.07.30.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
grapjes :: GRAPJES-PC [administrator]
30-7-2013 13:32:10
mbam-log-2013-07-30 (13-32-10).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 215983
Verstreken tijd: 3 minuut/minuten, 19 seconde(n)
Geheugenprocessen gedetecteerd: 1
C:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe (PUP.Optional.Datamngr) -> 1412 -> Zal worden verwijderd tijdens het herstarten.
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 15
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014} (PUP.Datamngr) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014} (PUP.Datamngr) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|DATAMNGR (PUP.Optional.Datamngr) -> Data: C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater|ImagePath (PUP.Optional.SoftwareUpdater.A) -> Data: C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe -> Succesvol in quarantaine geplaatst en verwijderd.
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 9
C:\Program Files (x86)\DealPly (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly\UpdateProc (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
Bestanden gedetecteerd: 24
C:\Program Files (x86)\Wajam\IE\priam_bho.dll (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\DealPly\DealPly.crx (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\DealPly\DealPly.xpi (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\KeyGen.dll (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe.config (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\config.xml (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\Interop.Shell32.dll (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\translations.xml (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\uninstall.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe (PUP.Optional.Datamngr) -> Zal worden verwijderd tijdens het herstarten.
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly\UpdateProc\config.dat (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
Stap 3: maak een DDS-logbestand
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.25.2
Run by grapjes at 13:52:37 on 2013-07-30
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4000.3225 [GMT 2:00]
.
AV: Panda Cloud Antivirus *Enabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
SP: Panda Cloud Antivirus *Enabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAService.exe
D:\software instal\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.bing.com/search?q={searchTerms}
uSearch Page = hxxp://www.bing.com/search?q={searchTerms}
uDefault_Page_URL = hxxp://asus.msn.com
uDefault_Search_URL = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
uSearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
uURLSearchHooks: <No Name>: {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
mWinlogon: Userinit = userinit.exe,
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Search-Results Toolbar: {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HomeTab: {e18b913b-dd1e-4df9-8985-622ccacee799} - C:\Users\grapjes\AppData\Roaming\HomeTab\HomeTab.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
TB: VideoDownloadConverter: {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: Search-Results Toolbar: {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll
TB: HomeTab: {e18b913b-dd1e-4df9-8985-622ccacee799} - C:\Users\grapjes\AppData\Roaming\HomeTab\HomeTab.dll
TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [PSUAMain] "D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" /LaunchSysTray
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {a39a8780-f414-42de-af33-5d1e0b0328c2} - {e18b913b-dd1e-4df9-8985-622ccacee799}
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/Select/asusTek_sys_ctrl3.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{A1082F0E-F703-4BE6-9AA9-1D8C11A6BDF4}\14256573531393544353235433 : DHCPNameServer = 192.168.2.254
TCP: Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995} : DHCPNameServer = 212.54.40.25 212.54.35.25
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll c:\progra~3\wincert\win32c~1.dll c:\progra~3\browse~1\251005~1.80\{c16c1~1\browse~1.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: DataMngr: {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\BrowserConnection.dll
x64-TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [SynAsusAcpi] C:\Program Files (x86)\Synaptics\SynTP\SynAsusAcpi.exe
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?rls=org.mozilla:en-US
fficial&client=firefox-a&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\grapjes\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-07-01 17:42; [email protected]; C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\extensions\[email protected]
FF - ExtSQL: 2013-07-13 21:54; [email protected]; C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\extensions\[email protected] com.xpi
FF - ExtSQL: !HIDDEN! 2013-05-27 19:59; [email protected]_4z.com; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin
.
============= SERVICES / DRIVERS ===============
.
R1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;C:\Windows\System32\drivers\NNSNAHSL.sys [2013-5-7 36584]
R2 NanoServiceMain;Panda Cloud Antivirus Service;D:\software instal\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2013-5-28 140768]
R2 PSUAService;Panda Product Service;D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAService.exe [2013-5-28 37344]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-11-23 130024]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-11-23 395752]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2012-3-5 76912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2012-5-15 1838656]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
S1 NNSALPC;NNSALPC;C:\Windows\System32\drivers\NNSAlpc.sys [2013-5-29 91368]
S1 NNSHTTP;NNSHTTP;C:\Windows\System32\drivers\NNSHttp.sys [2013-5-29 122088]
S1 NNSHTTPS;NNSHTTPS;C:\Windows\System32\drivers\NNSHttps.sys [2013-5-29 109288]
S1 NNSIDS;NNSIDS;C:\Windows\System32\drivers\NNSIds.sys [2013-5-29 114920]
S1 NNSPICC;NNSPICC;C:\Windows\System32\drivers\NNSpicc.sys [2013-5-29 95464]
S1 NNSPIHSW;NNSPIHSW;C:\Windows\System32\drivers\NNSPihsw.sys [2013-5-29 69864]
S1 NNSPOP3;NNSPOP3;C:\Windows\System32\drivers\NNSPop3.sys [2013-5-29 119016]
S1 NNSPROT;NNSPROT;C:\Windows\System32\drivers\NNSProt.sys [2013-5-29 305896]
S1 NNSPRV;NNSPRV;C:\Windows\System32\drivers\NNSPrv.sys [2013-5-29 118504]
S1 NNSSMTP;NNSSMTP;C:\Windows\System32\drivers\NNSSmtp.sys [2013-5-29 114920]
S1 NNSSTRM;NNSSTRM;C:\Windows\System32\drivers\NNSStrm.sys [2013-5-29 246504]
S1 NNSTLSC;NNSTLSC;C:\Windows\System32\drivers\NNStlsc.sys [2013-5-29 106216]
S1 PSINKNC;PSINKNC;C:\Windows\System32\drivers\PSINKNC.sys [2013-5-28 205544]
S2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2012-5-15 379520]
S2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
S2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-2-17 277120]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 PSINAflt;PSINAflt;C:\Windows\System32\drivers\PSINAflt.sys [2013-5-28 168680]
S2 PSINFile;PSINFile;C:\Windows\System32\drivers\PSINFile.sys [2013-5-28 122088]
S2 PSINProc;PSINProc;C:\Windows\System32\drivers\PSINProc.sys [2013-5-28 124648]
S2 PSINProt;PSINProt;C:\Windows\System32\drivers\PSINProt.sys [2013-5-29 137448]
S2 SkypeUpdate;Skype Updater;D:\software instal\Skype\Updater\Updater.exe [2013-6-21 162408]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-5-15 2656280]
S2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-4-20 23552]
S3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2011-3-18 74840]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-2-12 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-14 1492840]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-5 317440]
S3 PSINReg;PSINReg;C:\Windows\System32\drivers\PSINReg.sys [2013-5-28 105704]
S3 PSKMAD;PSKMAD;C:\Windows\System32\drivers\PSKMAD.sys [2013-7-30 58808]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-4 19456]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-4 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-4 30208]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-29 1255736]
S4 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbars vc.exe [2013-5-27 42504]
.
=============== Created Last 30 ================
.
2013-07-30 11:34:27 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1AACE542-017A-49F6-9738-B5FB6EF508CC}\offreg.dll
2013-07-30 11:25:59 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-30 10:11:45 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-07-30 10:11:41 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1AACE542-017A-49F6-9738-B5FB6EF508CC}\mpengine.dll
2013-07-30 10:08:38 58808 ----a-w- C:\Windows\System32\drivers\PSKMAD.sys
2013-07-28 21:43:31 -------- d-----w- C:\Windows\System32\MRT
2013-07-28 14:55:12 -------- d-----w- C:\Users\grapjes\AppData\Local\VS Revo Group
2013-07-28 10:01:40 -------- d-----w- C:\Users\grapjes\AppData\Roaming\temp
2013-07-28 09:37:28 -------- d-sh--w- C:\aws
2013-07-28 09:37:18 -------- d-----w- C:\Asus WebStorage
2013-07-28 08:33:12 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-28 08:08:57 -------- d-----w- C:\Users\grapjes\AppData\Roaming\Panda Security
2013-07-28 08:07:38 -------- d-----w- C:\ProgramData\Panda Security
2013-07-28 00:48:34 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-28 00:19:19 314880 ----a-w- C:\Program Files\Windows Defender\MpCommu.dll
2013-07-28 00:19:18 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2013-07-28 00:19:18 54784 ----a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll
2013-07-28 00:19:17 571904 ----a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-28 00:19:16 1011712 ----a-w- C:\Program Files\Windows Defender\MpSvc.dll
2013-07-28 00:00:41 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-24 06:41:50 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-24 06:41:50 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-07-24 06:23:01 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-07-24 06:22:40 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-24 06:22:40 1393152 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-24 06:22:39 936448 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-24 06:22:35 1732608 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-24 06:22:35 1367040 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-23 18:20:42 -------- d-----w- C:\Windows\pss
2013-07-20 18:51:23 -------- d-----w- C:\Users\grapjes\temp
2013-07-20 18:51:22 -------- d-----w- C:\Users\grapjes\AppData\Roaming\TeamViewer
2013-07-20 05:44:34 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 08:13:17 392704 ----a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll
2013-07-19 08:13:16 4608 ----a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll
2013-07-17 17:43:56 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-14 10:19:49 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-02 17:27:23 -------- d-----w- C:\Users\grapjes\SyncFolder
2013-07-02 16:42:43 -------- d-----w- C:\Program Files (x86)\MyPC Backup
2013-07-01 15:42:33 -------- d-----w- C:\ProgramData\AskPartnerNetwork
2013-07-01 15:42:33 -------- d-----w- C:\Program Files (x86)\AskPartnerNetwork
2013-07-01 15:42:23 -------- d-----w- C:\ProgramData\APN
.
==================== Find3M ====================
.
2013-07-30 11:23:20 380 ----a-w- C:\Users\grapjes\AppData\Roaming\sp_data.sys
2013-07-28 00:48:18 867240 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-07-28 00:48:18 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-28 00:06:59 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-14 18:44:34 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-14 18:44:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-29 15:16:45 137448 ----a-w- C:\Windows\System32\drivers\PSINProt.sys
2013-05-29 03:55:24 246504 ----a-w- C:\Windows\System32\drivers\NNSStrm.sys
2013-05-29 03:55:24 106216 ----a-w- C:\Windows\System32\drivers\NNStlsc.sys
2013-05-29 03:55:23 118504 ----a-w- C:\Windows\System32\drivers\NNSPrv.sys
2013-05-29 03:55:23 114920 ----a-w- C:\Windows\System32\drivers\NNSSmtp.sys
2013-05-29 03:55:22 69864 ----a-w- C:\Windows\System32\drivers\NNSPihsw.sys
2013-05-29 03:55:22 305896 ----a-w- C:\Windows\System32\drivers\NNSProt.sys
2013-05-29 03:55:22 119016 ----a-w- C:\Windows\System32\drivers\NNSPop3.sys
2013-05-29 03:55:21 95464 ----a-w- C:\Windows\System32\drivers\NNSpicc.sys
2013-05-29 03:55:21 114920 ----a-w- C:\Windows\System32\drivers\NNSIds.sys
2013-05-29 03:55:21 109288 ----a-w- C:\Windows\System32\drivers\NNSHttps.sys
2013-05-29 03:55:20 91368 ----a-w- C:\Windows\System32\drivers\NNSAlpc.sys
2013-05-29 03:55:20 122088 ----a-w- C:\Windows\System32\drivers\NNSHttp.sys
2013-05-28 09:25:41 105704 ----a-w- C:\Windows\System32\drivers\PSINReg.sys
2013-05-28 09:25:40 205544 ----a-w- C:\Windows\System32\drivers\PSINKNC.sys
2013-05-28 09:25:40 124648 ----a-w- C:\Windows\System32\drivers\PSINProc.sys
2013-05-28 09:25:05 122088 ----a-w- C:\Windows\System32\drivers\PSINFile.sys
2013-05-28 09:25:04 168680 ----a-w- C:\Windows\System32\drivers\PSINAflt.sys
2013-05-17 03:02:53 1346560 ----a-w- C:\Windows\System32\urlmon(217).dll
2013-05-17 02:56:00 599040 ----a-w- C:\Windows\System32\vbscript(203).dll
2013-05-16 22:49:25 9738752 ----a-w- C:\Windows\SysWow64\ieframe(204).dll
2013-05-16 22:28:40 1104384 ----a-w- C:\Windows\SysWow64\urlmon(222).dll
2013-05-16 22:17:30 1796096 ----a-w- C:\Windows\SysWow64\iertutil(205).dll
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-07 12:29:42 36584 ----a-w- C:\Windows\System32\drivers\NNSNAHSL.sys
2013-05-06 00:48:20 17408 ----a-w- C:\Windows\Launcher.exe
2013-05-02 00:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 13:53:50,35 ===============
Stap 4: scannen op rootkits met GMER
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-30 14:20:14
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.AX00 298,09GB
Running: jof7ymo7.exe; Driver: C:\Users\grapjes\AppData\Local\Temp\kwtirfoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800029a3000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 606 fffff800029a302e 17 bytes [CD, 01, 00, 00, 00, 00, 00, ...]
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@LeaseObtainedTime 1375184557
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@T1 1375186357
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@T2 1375187707
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@LeaseTerminatesTime 1375188157
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)
---- EOF - GMER 2.1 ----
Met F8 in veilige modus, of met systeem fouten controle start win 7 wel op.
Na het lezen van verschillende topics,heb ik deze tools al gedownload en installeerd in de deze volgorde.
Hopende dat iemand me verder kan en wil helpen. met deze informatie.
B.V.D Patricia
Stap 1: uitschakelen van emulatiesoftware
Stap 2: scannen op malware met Malwarebytes Anti-Malware
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.07.30.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
grapjes :: GRAPJES-PC [administrator]
30-7-2013 13:32:10
mbam-log-2013-07-30 (13-32-10).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 215983
Verstreken tijd: 3 minuut/minuten, 19 seconde(n)
Geheugenprocessen gedetecteerd: 1
C:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe (PUP.Optional.Datamngr) -> 1412 -> Zal worden verwijderd tijdens het herstarten.
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 15
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014} (PUP.Datamngr) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014} (PUP.Datamngr) -> Succesvol in quarantaine geplaatst en verwijderd.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} (Adware.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
Registerwaarden gedetecteerd: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|DATAMNGR (PUP.Optional.Datamngr) -> Data: C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE -> Succesvol in quarantaine geplaatst en verwijderd.
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater|ImagePath (PUP.Optional.SoftwareUpdater.A) -> Data: C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe -> Succesvol in quarantaine geplaatst en verwijderd.
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 9
C:\Program Files (x86)\DealPly (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly\UpdateProc (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
Bestanden gedetecteerd: 24
C:\Program Files (x86)\Wajam\IE\priam_bho.dll (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\DealPly\DealPly.crx (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\DealPly\DealPly.xpi (PUP.Optional.DealPly) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\KeyGen.dll (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe.config (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\config.xml (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\Interop.Shell32.dll (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\translations.xml (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\uninstall.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe (PUP.Optional.SoftwareUpdater.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe (PUP.Optional.Datamngr) -> Zal worden verwijderd tijdens het herstarten.
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\grapjes\AppData\Roaming\DealPly\UpdateProc\config.dat (PUP.Optional.DealPly.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (PUP.Optional.Tarma.A) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
Stap 3: maak een DDS-logbestand
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16635 BrowserJavaVersion: 10.25.2
Run by grapjes at 13:52:37 on 2013-07-30
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4000.3225 [GMT 2:00]
.
AV: Panda Cloud Antivirus *Enabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
SP: Panda Cloud Antivirus *Enabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAService.exe
D:\software instal\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.bing.com/search?q={searchTerms}
uSearch Page = hxxp://www.bing.com/search?q={searchTerms}
uDefault_Page_URL = hxxp://asus.msn.com
uDefault_Search_URL = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
uSearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
uURLSearchHooks: <No Name>: {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
mWinlogon: Userinit = userinit.exe,
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
BHO: Search-Results Toolbar: {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HomeTab: {e18b913b-dd1e-4df9-8985-622ccacee799} - C:\Users\grapjes\AppData\Roaming\HomeTab\HomeTab.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
TB: VideoDownloadConverter: {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: Search-Results Toolbar: {377e5d4d-77e5-476a-8716-7e70a9272da0} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll
TB: HomeTab: {e18b913b-dd1e-4df9-8985-622ccacee799} - C:\Users\grapjes\AppData\Roaming\HomeTab\HomeTab.dll
TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" /m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [PSUAMain] "D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" /LaunchSysTray
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
uPolicies-Explorer: NoDriveAutoRun = dword:0
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {a39a8780-f414-42de-af33-5d1e0b0328c2} - {e18b913b-dd1e-4df9-8985-622ccacee799}
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/Select/asusTek_sys_ctrl3.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{A1082F0E-F703-4BE6-9AA9-1D8C11A6BDF4}\14256573531393544353235433 : DHCPNameServer = 192.168.2.254
TCP: Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995} : DHCPNameServer = 212.54.40.25 212.54.35.25
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll c:\progra~3\wincert\win32c~1.dll c:\progra~3\browse~1\251005~1.80\{c16c1~1\browse~1.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Snap.DoEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} -
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: DataMngr: {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - C:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\BrowserConnection.dll
x64-TB: Snap.Do: {ae07101b-46d4-4a98-af68-0333ea26e113} -
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [SynAsusAcpi] C:\Program Files (x86)\Synaptics\SynTP\SynAsusAcpi.exe
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?rls=org.mozilla:en-US

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\grapjes\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-07-01 17:42; [email protected]; C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\extensions\[email protected]
FF - ExtSQL: 2013-07-13 21:54; [email protected]; C:\Users\grapjes\AppData\Roaming\Mozilla\Firefox\Profiles\xi4pl1nr.default\extensions\[email protected] com.xpi
FF - ExtSQL: !HIDDEN! 2013-05-27 19:59; [email protected]_4z.com; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin
.
============= SERVICES / DRIVERS ===============
.
R1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;C:\Windows\System32\drivers\NNSNAHSL.sys [2013-5-7 36584]
R2 NanoServiceMain;Panda Cloud Antivirus Service;D:\software instal\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2013-5-28 140768]
R2 PSUAService;Panda Product Service;D:\software instal\Panda Security\Panda Cloud Antivirus\PSUAService.exe [2013-5-28 37344]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-11-23 130024]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-11-23 395752]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2012-3-5 76912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2012-5-15 1838656]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
S1 NNSALPC;NNSALPC;C:\Windows\System32\drivers\NNSAlpc.sys [2013-5-29 91368]
S1 NNSHTTP;NNSHTTP;C:\Windows\System32\drivers\NNSHttp.sys [2013-5-29 122088]
S1 NNSHTTPS;NNSHTTPS;C:\Windows\System32\drivers\NNSHttps.sys [2013-5-29 109288]
S1 NNSIDS;NNSIDS;C:\Windows\System32\drivers\NNSIds.sys [2013-5-29 114920]
S1 NNSPICC;NNSPICC;C:\Windows\System32\drivers\NNSpicc.sys [2013-5-29 95464]
S1 NNSPIHSW;NNSPIHSW;C:\Windows\System32\drivers\NNSPihsw.sys [2013-5-29 69864]
S1 NNSPOP3;NNSPOP3;C:\Windows\System32\drivers\NNSPop3.sys [2013-5-29 119016]
S1 NNSPROT;NNSPROT;C:\Windows\System32\drivers\NNSProt.sys [2013-5-29 305896]
S1 NNSPRV;NNSPRV;C:\Windows\System32\drivers\NNSPrv.sys [2013-5-29 118504]
S1 NNSSMTP;NNSSMTP;C:\Windows\System32\drivers\NNSSmtp.sys [2013-5-29 114920]
S1 NNSSTRM;NNSSTRM;C:\Windows\System32\drivers\NNSStrm.sys [2013-5-29 246504]
S1 NNSTLSC;NNSTLSC;C:\Windows\System32\drivers\NNStlsc.sys [2013-5-29 106216]
S1 PSINKNC;PSINKNC;C:\Windows\System32\drivers\PSINKNC.sys [2013-5-28 205544]
S2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2012-5-15 379520]
S2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
S2 ASUS InstantOn;ASUS InstantOn Service;C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-2-17 277120]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 PSINAflt;PSINAflt;C:\Windows\System32\drivers\PSINAflt.sys [2013-5-28 168680]
S2 PSINFile;PSINFile;C:\Windows\System32\drivers\PSINFile.sys [2013-5-28 122088]
S2 PSINProc;PSINProc;C:\Windows\System32\drivers\PSINProc.sys [2013-5-28 124648]
S2 PSINProt;PSINProt;C:\Windows\System32\drivers\PSINProt.sys [2013-5-29 137448]
S2 SkypeUpdate;Skype Updater;D:\software instal\Skype\Updater\Updater.exe [2013-6-21 162408]
S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-5-15 2656280]
S2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-4-20 23552]
S3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2011-3-18 74840]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-2-12 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-14 1492840]
S3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-5 317440]
S3 PSINReg;PSINReg;C:\Windows\System32\drivers\PSINReg.sys [2013-5-28 105704]
S3 PSKMAD;PSKMAD;C:\Windows\System32\drivers\PSKMAD.sys [2013-7-30 58808]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-4 19456]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-4 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-4 30208]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-29 1255736]
S4 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbars vc.exe [2013-5-27 42504]
.
=============== Created Last 30 ================
.
2013-07-30 11:34:27 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1AACE542-017A-49F6-9738-B5FB6EF508CC}\offreg.dll
2013-07-30 11:25:59 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-07-30 10:11:45 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-07-30 10:11:41 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1AACE542-017A-49F6-9738-B5FB6EF508CC}\mpengine.dll
2013-07-30 10:08:38 58808 ----a-w- C:\Windows\System32\drivers\PSKMAD.sys
2013-07-28 21:43:31 -------- d-----w- C:\Windows\System32\MRT
2013-07-28 14:55:12 -------- d-----w- C:\Users\grapjes\AppData\Local\VS Revo Group
2013-07-28 10:01:40 -------- d-----w- C:\Users\grapjes\AppData\Roaming\temp
2013-07-28 09:37:28 -------- d-sh--w- C:\aws
2013-07-28 09:37:18 -------- d-----w- C:\Asus WebStorage
2013-07-28 08:33:12 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-28 08:08:57 -------- d-----w- C:\Users\grapjes\AppData\Roaming\Panda Security
2013-07-28 08:07:38 -------- d-----w- C:\ProgramData\Panda Security
2013-07-28 00:48:34 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-07-28 00:19:19 314880 ----a-w- C:\Program Files\Windows Defender\MpCommu.dll
2013-07-28 00:19:18 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2013-07-28 00:19:18 54784 ----a-w- C:\Program Files (x86)\Windows Defender\MpOAV.dll
2013-07-28 00:19:17 571904 ----a-w- C:\Program Files\Windows Defender\MpClient.dll
2013-07-28 00:19:16 1011712 ----a-w- C:\Program Files\Windows Defender\MpSvc.dll
2013-07-28 00:00:41 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-07-24 06:41:50 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-07-24 06:41:50 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-07-24 06:23:01 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-07-24 06:22:40 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-24 06:22:40 1393152 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-24 06:22:39 936448 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-24 06:22:35 1732608 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-24 06:22:35 1367040 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-23 18:20:42 -------- d-----w- C:\Windows\pss
2013-07-20 18:51:23 -------- d-----w- C:\Users\grapjes\temp
2013-07-20 18:51:22 -------- d-----w- C:\Users\grapjes\AppData\Roaming\TeamViewer
2013-07-20 05:44:34 1620480 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 08:13:17 392704 ----a-w- C:\Program Files (x86)\Windows Defender\MpClient.dll
2013-07-19 08:13:16 4608 ----a-w- C:\Program Files (x86)\Windows Defender\MsMpLics.dll
2013-07-17 17:43:56 1887744 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-14 10:19:49 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-07-02 17:27:23 -------- d-----w- C:\Users\grapjes\SyncFolder
2013-07-02 16:42:43 -------- d-----w- C:\Program Files (x86)\MyPC Backup
2013-07-01 15:42:33 -------- d-----w- C:\ProgramData\AskPartnerNetwork
2013-07-01 15:42:33 -------- d-----w- C:\Program Files (x86)\AskPartnerNetwork
2013-07-01 15:42:23 -------- d-----w- C:\ProgramData\APN
.
==================== Find3M ====================
.
2013-07-30 11:23:20 380 ----a-w- C:\Users\grapjes\AppData\Roaming\sp_data.sys
2013-07-28 00:48:18 867240 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2013-07-28 00:48:18 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-28 00:06:59 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-06-14 18:44:34 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-06-14 18:44:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-29 15:16:45 137448 ----a-w- C:\Windows\System32\drivers\PSINProt.sys
2013-05-29 03:55:24 246504 ----a-w- C:\Windows\System32\drivers\NNSStrm.sys
2013-05-29 03:55:24 106216 ----a-w- C:\Windows\System32\drivers\NNStlsc.sys
2013-05-29 03:55:23 118504 ----a-w- C:\Windows\System32\drivers\NNSPrv.sys
2013-05-29 03:55:23 114920 ----a-w- C:\Windows\System32\drivers\NNSSmtp.sys
2013-05-29 03:55:22 69864 ----a-w- C:\Windows\System32\drivers\NNSPihsw.sys
2013-05-29 03:55:22 305896 ----a-w- C:\Windows\System32\drivers\NNSProt.sys
2013-05-29 03:55:22 119016 ----a-w- C:\Windows\System32\drivers\NNSPop3.sys
2013-05-29 03:55:21 95464 ----a-w- C:\Windows\System32\drivers\NNSpicc.sys
2013-05-29 03:55:21 114920 ----a-w- C:\Windows\System32\drivers\NNSIds.sys
2013-05-29 03:55:21 109288 ----a-w- C:\Windows\System32\drivers\NNSHttps.sys
2013-05-29 03:55:20 91368 ----a-w- C:\Windows\System32\drivers\NNSAlpc.sys
2013-05-29 03:55:20 122088 ----a-w- C:\Windows\System32\drivers\NNSHttp.sys
2013-05-28 09:25:41 105704 ----a-w- C:\Windows\System32\drivers\PSINReg.sys
2013-05-28 09:25:40 205544 ----a-w- C:\Windows\System32\drivers\PSINKNC.sys
2013-05-28 09:25:40 124648 ----a-w- C:\Windows\System32\drivers\PSINProc.sys
2013-05-28 09:25:05 122088 ----a-w- C:\Windows\System32\drivers\PSINFile.sys
2013-05-28 09:25:04 168680 ----a-w- C:\Windows\System32\drivers\PSINAflt.sys
2013-05-17 03:02:53 1346560 ----a-w- C:\Windows\System32\urlmon(217).dll
2013-05-17 02:56:00 599040 ----a-w- C:\Windows\System32\vbscript(203).dll
2013-05-16 22:49:25 9738752 ----a-w- C:\Windows\SysWow64\ieframe(204).dll
2013-05-16 22:28:40 1104384 ----a-w- C:\Windows\SysWow64\urlmon(222).dll
2013-05-16 22:17:30 1796096 ----a-w- C:\Windows\SysWow64\iertutil(205).dll
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-07 12:29:42 36584 ----a-w- C:\Windows\System32\drivers\NNSNAHSL.sys
2013-05-06 00:48:20 17408 ----a-w- C:\Windows\Launcher.exe
2013-05-02 00:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 13:53:50,35 ===============
Stap 4: scannen op rootkits met GMER
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-30 14:20:14
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.AX00 298,09GB
Running: jof7ymo7.exe; Driver: C:\Users\grapjes\AppData\Local\Temp\kwtirfoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800029a3000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 606 fffff800029a302e 17 bytes [CD, 01, 00, 00, 00, 00, 00, ...]
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@LeaseObtainedTime 1375184557
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@T1 1375186357
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@T2 1375187707
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F82CDCC4-24FA-463C-B71B-6FD7C7708995}@LeaseTerminatesTime 1375188157
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)
---- EOF - GMER 2.1 ----
Comment