goedemiddag,
Een tijdje terug heb ik een laptop gekregen van een kennis. Ze gaf aan dat de laptop traag is en er een hoop narigheid op zit. Ze vroeg mij om er naar te kijken. Ze heeft er alleen maar een gratis versie van AVG op en verder niets, ik heb haar al vaker geadviseerd een goede anti-virus te kopen.
Ik heb inmiddels een hoop schoon gemaakt op de laptop (o.a. Yontoo verwijderd) maar er zit ook nog het een en ander in.
Onder andere de browser hijacker Delta-homes, welke ik niet krijg verwijderd. Ik heb het idee dat er nog wel wat meer narigheid in zit maar de diverse anti-malware scanners en anti-virus scanners geven dat niet aan.
Ik hoop dat jullie mij verder kunnen helpen.
Ik heb jullie stappenplan gevolgd. Hier zijn de logjes:
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.08.12.07
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
kim :: PC_VAN_KIM [administrator]
13-8-2013 10:50:26
mbam-log-2013-08-13 (10-50-26).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 232813
Verstreken tijd: 12 minuut/minuten, 31 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
----------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16496 BrowserJavaVersion: 10.25.2
Run by kim at 11:15:00 on 2013-08-13
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.31.1043.18.1976.567 [GMT 2:00]
.
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ================
.
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\kim\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe"
mRun: [PLFSetI] c:\windows\PLFSetI.exe
mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Skytel] Skytel.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\programs\partygaming\partypoker\RunApp.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{CD54D1C7-7B66-4288-B527-91A00FF911FC} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{EF2A9FCC-3244-44C7-89B6-BD11F31A5BD0} : DHCPNameServer = 192.168.0.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-16 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 164832]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2013-5-23 119056]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-11-16 5814904]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-22 196664]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2009-1-14 24576]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
S2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2012-10-2 1314720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-1-14 81296]
S3 netr73;Sitecom RT73 Wireless Driver for Vista;c:\windows\system32\drivers\netr73.sys [2009-8-10 256000]
S3 PAC207;SoC PC-Camera;c:\windows\system32\drivers\PFC027.SYS [2006-12-5 507136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-18 754856]
.
=============== Created Last 30 ================
.
2013-08-13 08:24:36 -------- d-----w- c:\users\kim\appdata\roaming\SUPERAntiSpyware.com
2013-08-13 08:24:18 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2013-08-13 08:24:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2013-08-12 17:23:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-08-12 17:22:18 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-08-12 16:30:08 -------- d-----w- c:\program files\VS Revo Group
2013-08-12 14:09:19 -------- d-----w- c:\users\kim\Option
2013-08-11 19:15:49 -------- d-----w- c:\programdata\HitmanPro
2013-08-11 19:08:22 -------- d-----w- c:\program files\trend micro
2013-08-11 13:49:20 -------- d-----w- c:\users\kim\appdata\roaming\Malwarebytes
2013-08-11 13:49:00 -------- d-----w- c:\programdata\Malwarebytes
2013-08-11 13:48:59 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-11 13:48:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-08-11 12:11:14 -------- d-----w- c:\program files\Defraggler
2013-08-11 11:36:40 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2013-08-11 11:36:39 683008 ----a-w- c:\windows\system32\d2d1.dll
2013-08-11 11:36:39 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2013-08-11 11:36:38 1069056 ----a-w- c:\windows\system32\DWrite.dll
2013-08-11 11:36:37 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-11 11:36:36 798208 ----a-w- c:\windows\system32\FntCache.dll
2013-08-11 11:36:36 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-11 11:36:36 189952 ----a-w- c:\windows\system32\d3d10core.dll
2013-08-11 11:36:36 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2013-08-11 11:36:36 1029120 ----a-w- c:\windows\system32\d3d10.dll
2013-08-11 11:06:39 -------- d-----w- c:\program files\Windows Portable Devices
2013-08-11 10:21:14 -------- d-----w- c:\windows\nl
2013-08-11 10:16:05 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2013-08-11 10:16:05 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-08-11 10:16:04 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2013-08-11 09:47:02 469256 ----a-w- c:\program files\common files\windows live\.cache\b95928041ce96772b\InstallManager_WLE_WLE.exe
2013-08-11 09:46:11 15712 ----a-w- c:\program files\common files\windows live\.cache\9ccd43b41ce96771f\MeshBetaRemover.exe
2013-08-11 09:45:26 94040 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\DSETUP.dll
2013-08-11 09:45:26 525656 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\DXSETUP.exe
2013-08-11 09:45:26 1691480 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\dsetup32.dll
2013-08-11 09:45:20 94040 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\DSETUP.dll
2013-08-11 09:45:20 525656 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\DXSETUP.exe
2013-08-11 09:45:20 1691480 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\dsetup32.dll
2013-08-11 09:43:01 -------- d-----w- c:\users\kim\appdata\local\Windows Live
2013-08-11 09:40:57 754688 ----a-w- c:\windows\system32\webservices.dll
2013-08-11 09:32:21 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2013-08-11 09:32:20 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2013-08-11 09:32:20 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2013-08-11 09:16:19 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-11 09:16:19 157696 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-11 09:16:19 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-11 08:56:01 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2013-08-11 08:56:00 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2013-08-11 08:54:17 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-11 08:54:16 252928 ----a-w- c:\windows\system32\dxdiag.exe
2013-08-11 08:54:16 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2013-08-11 08:54:13 519680 ----a-w- c:\windows\system32\d3d11.dll
2013-08-11 08:54:10 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-08-11 08:54:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-11 08:54:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-08-11 08:15:45 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-11 08:15:38 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-11 08:15:38 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-11 08:15:37 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-11 08:15:37 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-11 08:15:37 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-11 08:15:37 16896 ----a-w- c:\windows\system32\winusb.dll
2013-08-11 08:15:36 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-11 08:15:35 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-11 08:15:35 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-11 08:15:35 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-11 08:01:48 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-08-11 08:01:48 293376 ----a-w- c:\windows\system32\atmfd.dll
2013-08-11 08:00:35 623616 ----a-w- c:\windows\system32\localspl.dll
2013-08-11 08:00:10 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-08-11 07:59:46 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-11 07:58:50 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-11 07:58:50 37376 ----a-w- c:\windows\system32\cdd.dll
2013-08-11 07:58:29 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-08-11 07:58:29 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-11 07:58:29 812544 ----a-w- c:\windows\system32\certutil.exe
2013-08-11 07:58:29 41984 ----a-w- c:\windows\system32\certenc.dll
2013-08-11 07:58:29 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-11 07:58:00 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-11 07:56:56 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2013-08-11 07:55:44 376320 ----a-w- c:\windows\system32\winsrv.dll
2013-08-11 07:52:28 231424 ----a-w- c:\windows\system32\msshsq.dll
2013-08-11 07:39:31 613376 ----a-w- c:\windows\system32\rdpencom.dll
2013-08-11 07:17:29 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-08-11 07:16:53 88576 ----a-w- c:\windows\system32\wudriver.dll
2013-08-11 07:16:46 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-08-11 07:16:46 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-08-11 07:02:47 -------- d-----w- c:\windows\system32\MRT
2013-08-11 07:01:14 675152 ----a-w- c:\windows\system32\gpprefcl.dll
2013-08-11 06:41:13 -------- d-----w- c:\windows\system32\eu-ES
2013-08-11 06:41:13 -------- d-----w- c:\windows\system32\ca-ES
2013-08-11 06:41:12 -------- d-----w- c:\windows\system32\vi-VN
2013-08-11 06:11:28 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-11 06:11:27 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-11 06:11:00 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-10 18:51:06 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2013-08-11 08:55:59 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2013-08-11 08:55:59 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-08-11 08:55:58 98816 ----a-w- c:\windows\system32\mfps.dll
2013-08-11 08:55:58 2873344 ----a-w- c:\windows\system32\mf.dll
2013-08-11 08:55:56 209920 ----a-w- c:\windows\system32\mfplat.dll
2013-08-11 08:55:54 586240 ----a-w- c:\windows\system32\stobject.dll
2013-08-11 08:55:51 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-08-11 08:55:43 478720 ----a-w- c:\windows\system32\dxgi.dll
2013-08-11 08:55:41 258048 ----a-w- c:\windows\system32\winspool.drv
2013-08-11 08:55:40 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2013-08-11 08:55:39 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2013-08-11 08:55:38 847360 ----a-w- c:\windows\system32\OpcServices.dll
2013-08-11 08:55:37 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2013-08-11 08:54:22 4096 ----a-w- c:\windows\system32\drivers\nl-nl\dxgkrnl.sys.mui
2013-06-12 18:53:55 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-12 18:53:55 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-04 04:17:26 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2013-06-04 01:50:43 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-06-01 04:06:08 505344 ----a-w- c:\windows\system32\qedit.dll
.
============= FINISH: 11:20:09,22 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-08-13 11:53:03
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FB2O 149,05GB
Running: t5kwl6o3.exe; Driver: C:\Users\kim\AppData\Local\Temp\kgldypob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0x8D29A14A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0x8D29A21A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0x8D299D7C]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0x8D299F6A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0x8D29A000]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x827C5640]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0x8D299ECE]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0x8D29A09C]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!KeSetEvent + 3BD 820BB988 8 Bytes [4A, A1, 29, 8D, 1A, A2, 29, ...]
.text ntkrnlpa.exe!KeSetEvent + 3F1 820BB9BC 4 Bytes [7C, 9D, 29, 8D]
.text ntkrnlpa.exe!KeSetEvent + 611 820BBBDC 8 Bytes [6A, 9F, 29, 8D, 00, A0, 29, ...] {PUSH -0x61; SUB [EBP-0x72d66000], ECX}
.text ntkrnlpa.exe!KeSetEvent + 621 820BBBEC 3 Bytes [40, 56, 7C]
.text ntkrnlpa.exe!KeSetEvent + 625 820BBBF0 4 Bytes [CE, 9E, 29, 8D]
.text ...
? C:\Users\kim\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven bestand niet vinden. !
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!EnableWindow 759ACD8B 5 Bytes JMP 6A109EBC C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxParamW 759D10B0 5 Bytes JMP 6A06189B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxIndirectParamW 759D2EF5 5 Bytes JMP 6A2591B6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxParamA 759E8152 5 Bytes JMP 6A259151 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxIndirectParamA 759E847D 5 Bytes JMP 6A25921B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxIndirectA 759FD4D9 5 Bytes JMP 6A2590D8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxIndirectW 759FD5D3 5 Bytes JMP 6A25905F C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxExA 759FD639 5 Bytes JMP 6A258FFB C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxExW 759FD65D 5 Bytes JMP 6A258F97 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] kernel32.dll!CreateThread 753ECB0E 5 Bytes JMP 6A0C75E3 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamW 759A72A2 3 Bytes JMP 6A259520 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamW + 4 759A72A6 1 Byte [F4]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!GetAsyncKeyState 759A863C 5 Bytes JMP 6A0ADEDD C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetWindowsHookExW 759A87AD 5 Bytes JMP 6A1025B4 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CallNextHookEx 759A8E3B 5 Bytes JMP 6A127FF1 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!UnhookWindowsHookEx 759A98DB 5 Bytes JMP 6A14ED14 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!EnableWindow 759ACD8B 5 Bytes JMP 6A109EBC C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DefWindowProcA 759ADB88 7 Bytes JMP 6A0C980D C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateWindowExA 759ADC2A 5 Bytes JMP 6A0D3643 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateWindowExW 759B1305 5 Bytes JMP 6A1303DF C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!GetKeyState 759B8CB1 5 Bytes JMP 6A0ADDB3 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DefWindowProcW 759C03B4 7 Bytes JMP 6A128054 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!IsDialogMessageW 759C0745 5 Bytes JMP 6A259C7A C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamA 759C17AA 5 Bytes JMP 6A2594E8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!IsDialogMessage 759C1847 5 Bytes JMP 6A259C52 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogIndirectParamA 759C26F1 5 Bytes JMP 6A259558 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogIndirectParamW 759C9A62 5 Bytes JMP 6A259590 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetKeyboardState 759D0987 5 Bytes JMP 6A25A571 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxParamW 759D10B0 5 Bytes JMP 6A06189B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxIndirectParamW 759D2EF5 5 Bytes JMP 6A2591B6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SendInput 759D2F75 5 Bytes JMP 6A25A519 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!EndDialog 759D326E 5 Bytes JMP 6A259F26 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetCursorPos 759E6FB2 5 Bytes JMP 6A25A5F2 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxParamA 759E8152 5 Bytes JMP 6A259151 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxIndirectParamA 759E847D 5 Bytes JMP 6A25921B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxIndirectA 759FD4D9 5 Bytes JMP 6A2590D8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxIndirectW 759FD5D3 5 Bytes JMP 6A25905F C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxExA 759FD639 5 Bytes JMP 6A258FFB C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxExW 759FD65D 5 Bytes JMP 6A258F97 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!keybd_event 759FD972 5 Bytes JMP 6A25A4D6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] SHELL32.dll!SHRestricted + D95 761189A8 4 Bytes [CF, 01, 91, 69]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] SHELL32.dll!SHRestricted + D9D 761189B0 8 Bytes [E0, 61, 90, 69, 79, F7, 90, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] ole32.dll!OleLoadFromStream 755F1E80 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] ole32.dll!OleLoadFromStream 755F1E80 5 Bytes JMP 6A259984 C:\Windows\system32\IEFRAME.dll
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73BB7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73BFB4F1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73BBBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73BAF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73BB75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73BAE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73BE73F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73BBDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73BAFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73BAFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73BA71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73C3CB00] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73BDC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73BAD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73BA6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73BA687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73BB2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Een tijdje terug heb ik een laptop gekregen van een kennis. Ze gaf aan dat de laptop traag is en er een hoop narigheid op zit. Ze vroeg mij om er naar te kijken. Ze heeft er alleen maar een gratis versie van AVG op en verder niets, ik heb haar al vaker geadviseerd een goede anti-virus te kopen.
Ik heb inmiddels een hoop schoon gemaakt op de laptop (o.a. Yontoo verwijderd) maar er zit ook nog het een en ander in.
Onder andere de browser hijacker Delta-homes, welke ik niet krijg verwijderd. Ik heb het idee dat er nog wel wat meer narigheid in zit maar de diverse anti-malware scanners en anti-virus scanners geven dat niet aan.
Ik hoop dat jullie mij verder kunnen helpen.
Ik heb jullie stappenplan gevolgd. Hier zijn de logjes:
Malwarebytes Anti-Malware 1.75.0.1300
Databaseversie: v2013.08.12.07
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
kim :: PC_VAN_KIM [administrator]
13-8-2013 10:50:26
mbam-log-2013-08-13 (10-50-26).txt
Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 232813
Verstreken tijd: 12 minuut/minuten, 31 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
----------------------------------------
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16496 BrowserJavaVersion: 10.25.2
Run by kim at 11:15:00 on 2013-08-13
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.31.1043.18.1976.567 [GMT 2:00]
.
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ================
.
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\kim\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ProductReg] "c:\program files\acer\wr_popup\ProductReg.exe"
mRun: [PLFSetI] c:\windows\PLFSetI.exe
mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
mRun: [ePower_DMC] c:\program files\acer\empowering technology\epower\ePower_DMC.exe
mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Skytel] Skytel.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\programs\partygaming\partypoker\RunApp.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{CD54D1C7-7B66-4288-B527-91A00FF911FC} : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{EF2A9FCC-3244-44C7-89B6-BD11F31A5BD0} : DHCPNameServer = 192.168.0.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-16 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 164832]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2013-5-23 119056]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-11-16 5814904]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-22 196664]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2009-1-14 24576]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
S2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2012-10-2 1314720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-1-14 81296]
S3 netr73;Sitecom RT73 Wireless Driver for Vista;c:\windows\system32\drivers\netr73.sys [2009-8-10 256000]
S3 PAC207;SoC PC-Camera;c:\windows\system32\drivers\PFC027.SYS [2006-12-5 507136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-18 754856]
.
=============== Created Last 30 ================
.
2013-08-13 08:24:36 -------- d-----w- c:\users\kim\appdata\roaming\SUPERAntiSpyware.com
2013-08-13 08:24:18 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2013-08-13 08:24:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2013-08-12 17:23:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-08-12 17:22:18 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-08-12 16:30:08 -------- d-----w- c:\program files\VS Revo Group
2013-08-12 14:09:19 -------- d-----w- c:\users\kim\Option
2013-08-11 19:15:49 -------- d-----w- c:\programdata\HitmanPro
2013-08-11 19:08:22 -------- d-----w- c:\program files\trend micro
2013-08-11 13:49:20 -------- d-----w- c:\users\kim\appdata\roaming\Malwarebytes
2013-08-11 13:49:00 -------- d-----w- c:\programdata\Malwarebytes
2013-08-11 13:48:59 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-08-11 13:48:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-08-11 12:11:14 -------- d-----w- c:\program files\Defraggler
2013-08-11 11:36:40 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2013-08-11 11:36:39 683008 ----a-w- c:\windows\system32\d2d1.dll
2013-08-11 11:36:39 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2013-08-11 11:36:38 1069056 ----a-w- c:\windows\system32\DWrite.dll
2013-08-11 11:36:37 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-08-11 11:36:36 798208 ----a-w- c:\windows\system32\FntCache.dll
2013-08-11 11:36:36 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2013-08-11 11:36:36 189952 ----a-w- c:\windows\system32\d3d10core.dll
2013-08-11 11:36:36 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2013-08-11 11:36:36 1029120 ----a-w- c:\windows\system32\d3d10.dll
2013-08-11 11:06:39 -------- d-----w- c:\program files\Windows Portable Devices
2013-08-11 10:21:14 -------- d-----w- c:\windows\nl
2013-08-11 10:16:05 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2013-08-11 10:16:05 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-08-11 10:16:04 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2013-08-11 09:47:02 469256 ----a-w- c:\program files\common files\windows live\.cache\b95928041ce96772b\InstallManager_WLE_WLE.exe
2013-08-11 09:46:11 15712 ----a-w- c:\program files\common files\windows live\.cache\9ccd43b41ce96771f\MeshBetaRemover.exe
2013-08-11 09:45:26 94040 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\DSETUP.dll
2013-08-11 09:45:26 525656 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\DXSETUP.exe
2013-08-11 09:45:26 1691480 ----a-w- c:\program files\common files\windows live\.cache\815f04641ce967718\dsetup32.dll
2013-08-11 09:45:20 94040 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\DSETUP.dll
2013-08-11 09:45:20 525656 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\DXSETUP.exe
2013-08-11 09:45:20 1691480 ----a-w- c:\program files\common files\windows live\.cache\7d4083441ce967717\dsetup32.dll
2013-08-11 09:43:01 -------- d-----w- c:\users\kim\appdata\local\Windows Live
2013-08-11 09:40:57 754688 ----a-w- c:\windows\system32\webservices.dll
2013-08-11 09:32:21 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2013-08-11 09:32:20 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2013-08-11 09:32:20 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2013-08-11 09:16:19 5120 ----a-w- c:\windows\system32\wmi.dll
2013-08-11 09:16:19 157696 ----a-w- c:\windows\system32\imagehlp.dll
2013-08-11 09:16:19 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-08-11 08:56:01 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2013-08-11 08:56:00 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2013-08-11 08:54:17 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2013-08-11 08:54:16 252928 ----a-w- c:\windows\system32\dxdiag.exe
2013-08-11 08:54:16 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2013-08-11 08:54:13 519680 ----a-w- c:\windows\system32\d3d11.dll
2013-08-11 08:54:10 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2013-08-11 08:54:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-11 08:54:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-08-11 08:15:45 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-08-11 08:15:38 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-08-11 08:15:38 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-08-11 08:15:37 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-08-11 08:15:37 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-08-11 08:15:37 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-08-11 08:15:37 16896 ----a-w- c:\windows\system32\winusb.dll
2013-08-11 08:15:36 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-08-11 08:15:35 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-08-11 08:15:35 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-08-11 08:15:35 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-08-11 08:01:48 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-08-11 08:01:48 293376 ----a-w- c:\windows\system32\atmfd.dll
2013-08-11 08:00:35 623616 ----a-w- c:\windows\system32\localspl.dll
2013-08-11 08:00:10 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-08-11 07:59:46 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-08-11 07:58:50 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-11 07:58:50 37376 ----a-w- c:\windows\system32\cdd.dll
2013-08-11 07:58:29 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-08-11 07:58:29 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-11 07:58:29 812544 ----a-w- c:\windows\system32\certutil.exe
2013-08-11 07:58:29 41984 ----a-w- c:\windows\system32\certenc.dll
2013-08-11 07:58:29 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-11 07:58:00 2048 ----a-w- c:\windows\system32\tzres.dll
2013-08-11 07:56:56 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2013-08-11 07:55:44 376320 ----a-w- c:\windows\system32\winsrv.dll
2013-08-11 07:52:28 231424 ----a-w- c:\windows\system32\msshsq.dll
2013-08-11 07:39:31 613376 ----a-w- c:\windows\system32\rdpencom.dll
2013-08-11 07:17:29 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-08-11 07:16:53 88576 ----a-w- c:\windows\system32\wudriver.dll
2013-08-11 07:16:46 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-08-11 07:16:46 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-08-11 07:02:47 -------- d-----w- c:\windows\system32\MRT
2013-08-11 07:01:14 675152 ----a-w- c:\windows\system32\gpprefcl.dll
2013-08-11 06:41:13 -------- d-----w- c:\windows\system32\eu-ES
2013-08-11 06:41:13 -------- d-----w- c:\windows\system32\ca-ES
2013-08-11 06:41:12 -------- d-----w- c:\windows\system32\vi-VN
2013-08-11 06:11:28 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-08-11 06:11:27 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-08-11 06:11:00 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-08-10 18:51:06 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2013-08-11 08:55:59 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2013-08-11 08:55:59 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2013-08-11 08:55:58 98816 ----a-w- c:\windows\system32\mfps.dll
2013-08-11 08:55:58 2873344 ----a-w- c:\windows\system32\mf.dll
2013-08-11 08:55:56 209920 ----a-w- c:\windows\system32\mfplat.dll
2013-08-11 08:55:54 586240 ----a-w- c:\windows\system32\stobject.dll
2013-08-11 08:55:51 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2013-08-11 08:55:43 478720 ----a-w- c:\windows\system32\dxgi.dll
2013-08-11 08:55:41 258048 ----a-w- c:\windows\system32\winspool.drv
2013-08-11 08:55:40 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2013-08-11 08:55:39 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2013-08-11 08:55:38 847360 ----a-w- c:\windows\system32\OpcServices.dll
2013-08-11 08:55:37 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2013-08-11 08:54:22 4096 ----a-w- c:\windows\system32\drivers\nl-nl\dxgkrnl.sys.mui
2013-06-12 18:53:55 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-12 18:53:55 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-04 04:17:26 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2013-06-04 01:50:43 2049024 ----a-w- c:\windows\system32\win32k.sys
2013-06-01 04:06:08 505344 ----a-w- c:\windows\system32\qedit.dll
.
============= FINISH: 11:20:09,22 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-08-13 11:53:03
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FB2O 149,05GB
Running: t5kwl6o3.exe; Driver: C:\Users\kim\AppData\Local\Temp\kgldypob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0x8D29A14A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0x8D29A21A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0x8D299D7C]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0x8D299F6A]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0x8D29A000]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x827C5640]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0x8D299ECE]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0x8D29A09C]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!KeSetEvent + 3BD 820BB988 8 Bytes [4A, A1, 29, 8D, 1A, A2, 29, ...]
.text ntkrnlpa.exe!KeSetEvent + 3F1 820BB9BC 4 Bytes [7C, 9D, 29, 8D]
.text ntkrnlpa.exe!KeSetEvent + 611 820BBBDC 8 Bytes [6A, 9F, 29, 8D, 00, A0, 29, ...] {PUSH -0x61; SUB [EBP-0x72d66000], ECX}
.text ntkrnlpa.exe!KeSetEvent + 621 820BBBEC 3 Bytes [40, 56, 7C]
.text ntkrnlpa.exe!KeSetEvent + 625 820BBBF0 4 Bytes [CE, 9E, 29, 8D]
.text ...
? C:\Users\kim\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven bestand niet vinden. !
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!EnableWindow 759ACD8B 5 Bytes JMP 6A109EBC C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxParamW 759D10B0 5 Bytes JMP 6A06189B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxIndirectParamW 759D2EF5 5 Bytes JMP 6A2591B6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxParamA 759E8152 5 Bytes JMP 6A259151 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!DialogBoxIndirectParamA 759E847D 5 Bytes JMP 6A25921B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxIndirectA 759FD4D9 5 Bytes JMP 6A2590D8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxIndirectW 759FD5D3 5 Bytes JMP 6A25905F C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxExA 759FD639 5 Bytes JMP 6A258FFB C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[1168] USER32.dll!MessageBoxExW 759FD65D 5 Bytes JMP 6A258F97 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] kernel32.dll!CreateThread 753ECB0E 5 Bytes JMP 6A0C75E3 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamW 759A72A2 3 Bytes JMP 6A259520 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamW + 4 759A72A6 1 Byte [F4]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!GetAsyncKeyState 759A863C 5 Bytes JMP 6A0ADEDD C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetWindowsHookExW 759A87AD 5 Bytes JMP 6A1025B4 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CallNextHookEx 759A8E3B 5 Bytes JMP 6A127FF1 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!UnhookWindowsHookEx 759A98DB 5 Bytes JMP 6A14ED14 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!EnableWindow 759ACD8B 5 Bytes JMP 6A109EBC C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DefWindowProcA 759ADB88 7 Bytes JMP 6A0C980D C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateWindowExA 759ADC2A 5 Bytes JMP 6A0D3643 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateWindowExW 759B1305 5 Bytes JMP 6A1303DF C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!GetKeyState 759B8CB1 5 Bytes JMP 6A0ADDB3 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DefWindowProcW 759C03B4 7 Bytes JMP 6A128054 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!IsDialogMessageW 759C0745 5 Bytes JMP 6A259C7A C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogParamA 759C17AA 5 Bytes JMP 6A2594E8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!IsDialogMessage 759C1847 5 Bytes JMP 6A259C52 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogIndirectParamA 759C26F1 5 Bytes JMP 6A259558 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!CreateDialogIndirectParamW 759C9A62 5 Bytes JMP 6A259590 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetKeyboardState 759D0987 5 Bytes JMP 6A25A571 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxParamW 759D10B0 5 Bytes JMP 6A06189B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxIndirectParamW 759D2EF5 5 Bytes JMP 6A2591B6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SendInput 759D2F75 5 Bytes JMP 6A25A519 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!EndDialog 759D326E 5 Bytes JMP 6A259F26 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!SetCursorPos 759E6FB2 5 Bytes JMP 6A25A5F2 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxParamA 759E8152 5 Bytes JMP 6A259151 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!DialogBoxIndirectParamA 759E847D 5 Bytes JMP 6A25921B C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxIndirectA 759FD4D9 5 Bytes JMP 6A2590D8 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxIndirectW 759FD5D3 5 Bytes JMP 6A25905F C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxExA 759FD639 5 Bytes JMP 6A258FFB C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!MessageBoxExW 759FD65D 5 Bytes JMP 6A258F97 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] USER32.dll!keybd_event 759FD972 5 Bytes JMP 6A25A4D6 C:\Windows\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] SHELL32.dll!SHRestricted + D95 761189A8 4 Bytes [CF, 01, 91, 69]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] SHELL32.dll!SHRestricted + D9D 761189B0 8 Bytes [E0, 61, 90, 69, 79, F7, 90, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] ole32.dll!OleLoadFromStream 755F1E80 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3924] ole32.dll!OleLoadFromStream 755F1E80 5 Bytes JMP 6A259984 C:\Windows\system32\IEFRAME.dll
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73BB7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73BFB4F1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73BBBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73BAF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73BB75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73BAE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73BE73F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73BBDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73BAFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73BAFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73BA71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73C3CB00] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73BDC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73BAD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73BA6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73BA687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3684] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73BB2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a 4\gdiplus.dll
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Comment