Hallo allemaal,
Ik heb sinds gisteren een probleem met mijn laptop.
Ik probeerde mijn laptop op te starten terwij mijn accu leeg was. Dit lukte niet, ik heb de adapter aangesloten en er is vervolgens in de herstelmodus opgestart.
Nu krijg ik volgende meldingen:
RunDLL: Er is een probleem opgetreden tijdens het starten van NVCPL.DLL; Bewerking is niet voltooid omdat het bestand een virus bevat.

IAStorIcon.exe - Onherstelbare fout: CLR-fout: 800004005 Het programma wordt nu afgesloten.
Ook kreeg ik de melding van mijn virusscanner dat de firewall uitgeschakeld is. Ik kan deze ook niet meer inschakelen.

Ik heb mijn virusscanner hierna gedraaid (Avast Internet Security) over het gehele systeem. Hier kwamen geen bedreigingen naar voren.
Ook heb ik gemerkt dat de icoontjes op mijn snelstartbalk niet meer werken.
Ook mijn webbrowser Firefox werkt niet meer als voorheen; mijn startpagina komt niet meer naar voren.
Ook de snelkoppelingen op het bureaublad werken niet meer. Ik ben normaliter ingelogd als administrator maar moet nu sommige programma's met mijn rechter muisknop als administrator starten.
Zelfs MalwareBytes (wat ik standaard wekelijks draai) kan ik niet meer opstarten
Ook krijg ik volgende meldingen:

Wie kan me helpen??
Hieronder de logbestanden:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428
Run by PSchellekens at 8:33:48 on 2014-01-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4013.2652 [GMT 1:00]
.
AV: avast! Internet Security *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Internet Security *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\System Control Manager\MSIService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SnippingTool.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=MDNB&bmod=MDNB
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=MDNB&bmod=MDNB
mWinlogon: Userinit = userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [MGSysCtrl] C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
mRun: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK -
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: LastPass - C:\Users\PSchellekens\AppData\LocalLow\LastPass\context.html?cmd=lastpass
IE: LastPass Invulformulieren - C:\Users\PSchellekens\AppData\LocalLow\LastPass\context.html?cmd=fillforms
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF} : DHCPNameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF}\C41627965637472716164753 : DHCPNameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF}\C41627965637472716164753D213 : DHCPNameServer = 192.168.1.1 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-IE: {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\PSchellekens\AppData\Roaming\Mozilla\Firefox\Profiles\xz0bs3h4.default\
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-10-10 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-10-10 207904]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2013-10-10 28184]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-10-10 1034464]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-10-10 422216]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-10-10 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-1-2 50344]
R2 Micro Star SCM;Micro Star SCM;C:\Program Files (x86)\System Control Manager\MSIService.exe [2010-12-22 160768]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-8-8 5087584]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-9-30 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-9-30 180736]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-12-22 344680]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2010-12-22 1098784]
S2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-1-2 116776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-22 13336]
S3 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-1-2 79672]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2010-12-22 52264]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-17 111616]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUVStor.sys [2010-12-22 290920]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-14 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-17 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2014-01-02 17:39:28 79672 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-01-02 17:39:06 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-01-02 17:39:06 1034464 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-01-02 17:39:05 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-01-02 17:39:05 422216 ----a-w- C:\Windows\System32\drivers\aswSP.sys
2014-01-02 17:39:05 334136 ----a-w- C:\Windows\System32\aswBoot.exe
2014-01-02 17:39:01 43152 ----a-w- C:\Windows\avastSS.scr
2013-12-17 16:19:05 90708896 ----a-w- C:\Windows\System32\MRT.exe
2013-12-11 11:22:31 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 11:22:31 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-26 11:54:49 23183360 ----a-w- C:\Windows\System32\mshtml.dll
2013-11-26 10:19:07 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2013-11-26 10:18:23 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2013-11-26 10:11:50 17112576 ----a-w- C:\Windows\SysWow64\mshtml.dll
2013-11-26 09:48:07 66048 ----a-w- C:\Windows\System32\iesetup.dll
2013-11-26 09:46:25 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2013-11-26 09:41:43 2764288 ----a-w- C:\Windows\System32\iertutil.dll
2013-11-26 09:29:38 53760 ----a-w- C:\Windows\System32\jsproxy.dll
2013-11-26 09:27:54 33792 ----a-w- C:\Windows\System32\iernonce.dll
2013-11-26 09:23:02 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-11-26 09:21:24 574976 ----a-w- C:\Windows\System32\ieui.dll
2013-11-26 09:18:39 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-11-26 09:18:09 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2013-11-26 09:16:57 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2013-11-26 08:57:44 218624 ----a-w- C:\Windows\System32\ie4uinit.exe
2013-11-26 08:38:54 2166784 ----a-w- C:\Windows\SysWow64\iertutil.dll
2013-11-26 08:38:07 43008 ----a-w- C:\Windows\SysWow64\jsproxy.dll
2013-11-26 08:35:02 5769216 ----a-w- C:\Windows\System32\jscript9.dll
2013-11-26 08:32:08 440832 ----a-w- C:\Windows\SysWow64\ieui.dll
2013-11-26 08:28:16 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2013-11-26 08:16:12 4243968 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-11-26 08:02:16 1995264 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-11-26 07:48:24 12996608 ----a-w- C:\Windows\System32\ieframe.dll
2013-11-26 07:32:06 1928192 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-11-26 07:26:42 11221504 ----a-w- C:\Windows\SysWow64\ieframe.dll
2013-11-26 07:07:57 2334208 ----a-w- C:\Windows\System32\wininet.dll
2013-11-26 06:40:01 1395200 ----a-w- C:\Windows\System32\urlmon.dll
2013-11-26 06:34:55 703488 ----a-w- C:\Windows\SysWow64\ieapfltr.dll
2013-11-26 06:34:27 817664 ----a-w- C:\Windows\System32\ieapfltr.dll
2013-11-26 06:33:33 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-11-26 06:27:32 1157632 ----a-w- C:\Windows\SysWow64\urlmon.dll
2013-11-23 18:26:20 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-11-23 17:47:34 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-11-19 19:45:59 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-11-19 19:45:56 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-11-19 19:45:09 28184 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2013-11-19 19:44:54 447888 ----a-w- C:\Windows\System32\drivers\aswNdisFlt.sys
2013-11-19 02:33:38 267936 ----a-w- C:\Windows\System32\MpSigStub.exe
2013-11-12 02:23:09 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-11-12 02:07:29 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-10-31 06:46:13 270824 ----a-w- C:\Windows\System32\drivers\aswNdis2.sys
2013-10-31 06:46:12 131232 ----a-w- C:\Windows\System32\drivers\aswFW.sys
2013-10-30 02:32:01 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-10-30 01:24:31 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-10-19 02:18:57 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-10-19 01:36:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-10-14 17:00:00 28368 ----a-w- C:\Windows\System32\IEUDINIT.EXE
2013-10-12 02:32:04 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-10-12 02:31:04 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:36 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-10-12 02:03:31 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:33:39 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-10-12 01:33:26 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-10-12 01:15:48 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-10-12 01:15:48 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2012-11-14 21:16:59 14794312 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
.
============= FINISH: 8:34:21,17 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2014-01-05 08:48:20
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB
Running: gg7icjfn.exe; Driver: C:\Users\PSCHEL~1\AppData\Local\Temp\kftyiaog.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\wininit.exe[652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\services.exe[704] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\winlogon.exe[776] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[360] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[452] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[440] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[456] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1144] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[1332] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\spoolsv.exe[1616] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1656] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\taskhost.exe[1988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\Explorer.EXE[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1444] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[1384] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[1940] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1920] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756f1465 2 bytes [6F, 75]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756f14bb 2 bytes [6F, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2456] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[2748] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\System Control Manager\MSIService.exe[2788] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[2892] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2932] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe[3020] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3028] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2356] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2552] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2684] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\SnippingTool.exe[3076] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[3240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3956] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\SYSTEM32\WISPTIS.EXE[4284] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\AUDIODG.EXE[3320] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Users\PSchellekens\Desktop\gg7icjfn.exe[3808] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:5112] 000007fefab62a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4444] 000007feef2f4830
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4524] 000007feef2f4830
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4676] 000007feef279d90
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4344] 000007feef2f4830
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Ik heb sinds gisteren een probleem met mijn laptop.
Ik probeerde mijn laptop op te starten terwij mijn accu leeg was. Dit lukte niet, ik heb de adapter aangesloten en er is vervolgens in de herstelmodus opgestart.
Nu krijg ik volgende meldingen:
RunDLL: Er is een probleem opgetreden tijdens het starten van NVCPL.DLL; Bewerking is niet voltooid omdat het bestand een virus bevat.
IAStorIcon.exe - Onherstelbare fout: CLR-fout: 800004005 Het programma wordt nu afgesloten.
Ook kreeg ik de melding van mijn virusscanner dat de firewall uitgeschakeld is. Ik kan deze ook niet meer inschakelen.
Ik heb mijn virusscanner hierna gedraaid (Avast Internet Security) over het gehele systeem. Hier kwamen geen bedreigingen naar voren.
Ook heb ik gemerkt dat de icoontjes op mijn snelstartbalk niet meer werken.
Ook mijn webbrowser Firefox werkt niet meer als voorheen; mijn startpagina komt niet meer naar voren.
Ook de snelkoppelingen op het bureaublad werken niet meer. Ik ben normaliter ingelogd als administrator maar moet nu sommige programma's met mijn rechter muisknop als administrator starten.
Zelfs MalwareBytes (wat ik standaard wekelijks draai) kan ik niet meer opstarten
Ook krijg ik volgende meldingen:
Wie kan me helpen??
Hieronder de logbestanden:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428
Run by PSchellekens at 8:33:48 on 2014-01-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4013.2652 [GMT 1:00]
.
AV: avast! Internet Security *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Internet Security *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\System Control Manager\MSIService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SnippingTool.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=MDNB&bmod=MDNB
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=MDNB&bmod=MDNB
mWinlogon: Userinit = userinit.exe
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [MGSysCtrl] C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
mRun: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK -
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: LastPass - C:\Users\PSchellekens\AppData\LocalLow\LastPass\context.html?cmd=lastpass
IE: LastPass Invulformulieren - C:\Users\PSchellekens\AppData\LocalLow\LastPass\context.html?cmd=fillforms
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: NameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF} : DHCPNameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF}\C41627965637472716164753 : DHCPNameServer = 212.54.40.25 212.54.35.25
TCP: Interfaces\{44F9542B-0E3E-4470-826B-E225A16491FF}\C41627965637472716164753D213 : DHCPNameServer = 192.168.1.1 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: LastPass Vault: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-IE: {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_39-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\PSchellekens\AppData\Roaming\Mozilla\Firefox\Profiles\xz0bs3h4.default\
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-10-10 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-10-10 207904]
R1 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2013-10-10 28184]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-10-10 1034464]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-10-10 422216]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-10-10 78648]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-1-2 50344]
R2 Micro Star SCM;Micro Star SCM;C:\Program Files (x86)\System Control Manager\MSIService.exe [2010-12-22 160768]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-8-8 5087584]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-9-30 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-9-30 180736]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-12-22 344680]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2010-12-22 1098784]
S2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-1-2 116776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-22 13336]
S3 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-1-2 79672]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2010-12-22 52264]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-12-17 111616]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUVStor.sys [2010-12-22 290920]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-14 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-17 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2014-01-02 17:39:28 79672 ----a-w- C:\Windows\System32\drivers\aswstm.sys
2014-01-02 17:39:06 207904 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2014-01-02 17:39:06 1034464 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2014-01-02 17:39:05 78648 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2014-01-02 17:39:05 422216 ----a-w- C:\Windows\System32\drivers\aswSP.sys
2014-01-02 17:39:05 334136 ----a-w- C:\Windows\System32\aswBoot.exe
2014-01-02 17:39:01 43152 ----a-w- C:\Windows\avastSS.scr
2013-12-17 16:19:05 90708896 ----a-w- C:\Windows\System32\MRT.exe
2013-12-11 11:22:31 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 11:22:31 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-26 11:54:49 23183360 ----a-w- C:\Windows\System32\mshtml.dll
2013-11-26 10:19:07 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2013-11-26 10:18:23 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2013-11-26 10:11:50 17112576 ----a-w- C:\Windows\SysWow64\mshtml.dll
2013-11-26 09:48:07 66048 ----a-w- C:\Windows\System32\iesetup.dll
2013-11-26 09:46:25 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2013-11-26 09:41:43 2764288 ----a-w- C:\Windows\System32\iertutil.dll
2013-11-26 09:29:38 53760 ----a-w- C:\Windows\System32\jsproxy.dll
2013-11-26 09:27:54 33792 ----a-w- C:\Windows\System32\iernonce.dll
2013-11-26 09:23:02 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-11-26 09:21:24 574976 ----a-w- C:\Windows\System32\ieui.dll
2013-11-26 09:18:39 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-11-26 09:18:09 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2013-11-26 09:16:57 708608 ----a-w- C:\Windows\System32\jscript9diag.dll
2013-11-26 08:57:44 218624 ----a-w- C:\Windows\System32\ie4uinit.exe
2013-11-26 08:38:54 2166784 ----a-w- C:\Windows\SysWow64\iertutil.dll
2013-11-26 08:38:07 43008 ----a-w- C:\Windows\SysWow64\jsproxy.dll
2013-11-26 08:35:02 5769216 ----a-w- C:\Windows\System32\jscript9.dll
2013-11-26 08:32:08 440832 ----a-w- C:\Windows\SysWow64\ieui.dll
2013-11-26 08:28:16 553472 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2013-11-26 08:16:12 4243968 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-11-26 08:02:16 1995264 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-11-26 07:48:24 12996608 ----a-w- C:\Windows\System32\ieframe.dll
2013-11-26 07:32:06 1928192 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-11-26 07:26:42 11221504 ----a-w- C:\Windows\SysWow64\ieframe.dll
2013-11-26 07:07:57 2334208 ----a-w- C:\Windows\System32\wininet.dll
2013-11-26 06:40:01 1395200 ----a-w- C:\Windows\System32\urlmon.dll
2013-11-26 06:34:55 703488 ----a-w- C:\Windows\SysWow64\ieapfltr.dll
2013-11-26 06:34:27 817664 ----a-w- C:\Windows\System32\ieapfltr.dll
2013-11-26 06:33:33 1820160 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-11-26 06:27:32 1157632 ----a-w- C:\Windows\SysWow64\urlmon.dll
2013-11-23 18:26:20 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-11-23 17:47:34 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-11-19 19:45:59 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-11-19 19:45:56 92544 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-11-19 19:45:09 28184 ----a-w- C:\Windows\System32\drivers\aswKbd.sys
2013-11-19 19:44:54 447888 ----a-w- C:\Windows\System32\drivers\aswNdisFlt.sys
2013-11-19 02:33:38 267936 ----a-w- C:\Windows\System32\MpSigStub.exe
2013-11-12 02:23:09 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-11-12 02:07:29 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-10-31 06:46:13 270824 ----a-w- C:\Windows\System32\drivers\aswNdis2.sys
2013-10-31 06:46:12 131232 ----a-w- C:\Windows\System32\drivers\aswFW.sys
2013-10-30 02:32:01 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-10-30 01:24:31 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-10-19 02:18:57 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-10-19 01:36:59 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-10-14 17:00:00 28368 ----a-w- C:\Windows\System32\IEUDINIT.EXE
2013-10-12 02:32:04 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-10-12 02:31:04 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:36 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-10-12 02:03:31 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:33:39 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-10-12 01:33:26 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-10-12 01:15:48 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-10-12 01:15:48 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2012-11-14 21:16:59 14794312 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
.
============= FINISH: 8:34:21,17 ===============
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2014-01-05 08:48:20
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB
Running: gg7icjfn.exe; Driver: C:\Users\PSCHEL~1\AppData\Local\Temp\kftyiaog.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\wininit.exe[652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\services.exe[704] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\winlogon.exe[776] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[872] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[952] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[360] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[452] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[440] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[456] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1144] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[1332] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\System32\spoolsv.exe[1616] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1656] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\taskhost.exe[1988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\Explorer.EXE[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1444] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[1384] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[1940] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1920] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756f1465 2 bytes [6F, 75]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756f14bb 2 bytes [6F, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2456] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[2748] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\System Control Manager\MSIService.exe[2788] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[2892] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2932] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe[3020] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3028] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2356] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2552] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2684] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\SnippingTool.exe[3076] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[3240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3956] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\SYSTEM32\WISPTIS.EXE[4284] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Windows\system32\AUDIODG.EXE[3320] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 000000007719eecd 1 byte [62]
.text C:\Users\PSchellekens\Desktop\gg7icjfn.exe[3808] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007672a2ba 1 byte [62]
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:5112] 000007fefab62a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4444] 000007feef2f4830
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4524] 000007feef2f4830
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4676] 000007feef279d90
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4104:4344] 000007feef2f4830
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Comment