Hallo,
ik heb weer eens een virusinfectie op mijn PC
Ik heb een 32 bits PC met Windows 7 Premium. Ik heb hierop Avast! Internet Security v.2014.9.0.2021 geïnstalleerd. Gister na een opstartscan kreeg ik allemaal ads in mijn browsers van Offerwizard (Firefox en Chrome). Internet werd ook geblokkeerd, behalve Skype (alhoewel ik geen bestanden en video- of audiogesprekken kon ontvangen). Ik heb een virusscan uitgevoerd en kreeg een hele lijst met .tmp bestanden die niet als virus waren aangegeven. Ik had ook 2 netupdsrv.exe, 2 installd.exe en 1 nethfdrv.sys bestanden. Ik heb alle bestanden verwijderd, mijn PC opnieuw opgestart, maar het probleem bleef zich voortzetten. Ik heb toen opnieuw een scan gedaan en de .tmp bestanden waren weer terug. Ze staan nu gemarkeerd als een Win32:Evo-gen virus. Overigens stonden alle bestanden in quarantaine in Avast.
Na de tweede scan heb ik de stappen in de sticky thread opgevolgd. Ik had het echter niet goed gedaan en heb het opnieuw moeten uitvoeren, dus ik post alleen de laatste scans (indien nodig kan ik ook de logs van de eerste scans posten).
- Defogger staat op disabled.
- MBAM log
Malwarebytes Anti-Malware
Scan Date: 18-8-14
Scan Time: 4:47:20
Logfile: mbamlog2.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.18.01
Rootkit Database: v2014.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: gebruiker
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 822167
Time Elapsed: 3 hr, 32 min, 48 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.Amonetize, C:\Windows\System32\nethtsrv.exe, 2020, Delete-on-Reboot, [65a4992ff98275c166151484b64b0cf4]
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.Amonetize, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NetHttpService, Quarantined, [65a4992ff98275c166151484b64b0cf4],
PUP.Optional.Amonetize, HKLM\SOFTWARE\CLASSES\TYPELIB\{363BB65D-1747-4826-B445-1DA6244E2037}, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.Amonetize, HKLM\SOFTWARE\CLASSES\INTERFACE\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.OffersWizard.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nethfdrv, Quarantined, [e623f3d593e8a5915384cf0f1ce6d62a],
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\SYSTWEAK\RegClean Pro, Quarantined, [31d8d2f69eddb482eb6abf2946bc956b],
PUP.Optional.Softonic.A, HKU\S-1-5-21-419608459-42819607-2235241362-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [e227af19e695bc7a340055a83cc6f20e],
Registry Values: 1
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NETHTTPSERVICE|ImagePath, C:\Windows\system32\nethtsrv.exe, Quarantined, [fb0e07c1e89340f6661296ad768ed030]
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
Files: 13
PUP.Optional.Amonetize, C:\Windows\System32\nethtsrv.exe, Delete-on-Reboot, [65a4992ff98275c166151484b64b0cf4],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe Illustrator CS6\Support Files\Contents\Windows\amtlib.dll, Quarantined, [ba4f37919edd9c9adf0c4dcf877ba25e],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe InDesign CS6\amtlib.dll, Quarantined, [83865b6d94e77fb738b3fc20847e3bc5],
PUP.Optional.Amonetize, C:\Users\gebruiker\AppData\Local\41\a18467.exe, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.OffersWizard.A, C:\Users\gebruiker\AppData\Local\Temp\drvinst001.exe, Quarantined, [db2e02c62a5190a68d4522e07491e21e],
PUP.Optional.OffersWizard.A, C:\Users\gebruiker\AppData\Local\Temp\drvinstal1.exe, Quarantined, [4abfcdfbf3887bbb07cb8b7729dc22de],
PUP.Optional.Amonetize, C:\Users\gebruiker\AppData\Local\Temp\setup64-2.exe, Quarantined, [dc2d7c4c57249b9b51d5ed9f50b1ef11],
PUP.Optional.OpenCandy, D:\Mijn Documenten\Mijn Video's\All Downloads\Programma's\DAEMON.Tools.Pro.Advanced.v5.1.0.0333-Admin_Crack\DAEMONToolsPro510-0333.exe, Quarantined, [3bce18b08eedfd39650b1adf828236ca],
PUP.RiskwareTool.CK, D:\Program files D\Adobe\Adobe Photoshop CS6\amtlib.dll, Quarantined, [34d55d6b1764f6407873bf5d946edb25],
PUP.Optional.OffersWizard.A, C:\Windows\System32\drivers\nethfdrv.sys, Quarantined, [e623f3d593e8a5915384cf0f1ce6d62a],
PUP.Optional.InstallD.A, C:\Windows\System32\installd.exe, Quarantined, [cc3dd4f41863ce68415d4d9634cec838],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\ver.xml, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\data.xml, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
Physical Sectors: 0
(No malicious items detected)
(end)
- DDS log
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17239
Run by gebruiker at 12:42:47 on 2014-08-18
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3582.1436 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Outdated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Outdated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
c:\PROGRA~1\mcafee\SITEAD~1\McSACore.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\vVX1000.exe
D:\Program files D\iTunes\iTunesHelper.exe
C:\Users\gebruiker\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Users\gebruiker\AppData\Local\Google\Update\1.3.24.15\GoogleCrashHandler.exe
C:\Users\gebruiker\AppData\Local\Akamai\netsession_win.exe
D:\Program files D\Rainlendar2\Rainlendar2.exe
C:\Users\gebruiker\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Skype\Phone\Skype.exe
D:\Program files D\Rainmeter.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\gebruiker\AppData\Roaming\pushbullet\pushbullet_94\pushbullet_app.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uProxyOverride = <local>
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
EB: {555D4D79-4BD2-4094-A395-CFC534424A05} - <orphaned>
uRun: [Akamai NetSession Interface] "c:\users\gebruiker\appdata\local\akamai\netsession_win.exe"
uRun: [Google Update] "c:\users\gebruiker\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Rainlendar2] d:\program files d\rainlendar2\Rainlendar2.exe
uRun: [F.lux] "c:\users\gebruiker\appdata\local\fluxsoftware\flux\flux.exe" /noshow
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Pushbullet] "d:\program files d\pushbullet\pushbullet_app.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Windows Mobile-based device management] c:\windows\windowsmobile\wmdcBase.exe
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [iTunesHelper] "d:\program files d\itunes\iTunesHelper.exe"
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - d:\program files d\Rainmeter.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldnl-nl.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: NameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{02865029-FF93-40B4-BC93-3C2D9FA2349A} : DHCPNameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{C9B06480-F092-4C16-B5CA-905DD451E4BC} : DHCPNameServer = 213.46.228.196 62.179.104.196
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - d:\program files d\stardock\object desktop\iconpackager\iprepair.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\gebruiker\appdata\roaming\mozilla\firefox\profiles\wi2b71kq.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxps://www.google.com/search?q=
FF - plugin: c:\program files\adobe\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\threeships shared\dll\npTSHelper.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\users\gebruiker\appdata\local\google\update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: c:\users\gebruiker\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\gebruiker\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\gebruiker\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_14_0_0_145.dll
FF - plugin: d:\program files d\itunes\mozilla plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\drivers\aswNdisFlt.sys [2014-7-10 270752]
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-1-10 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-1-10 192352]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2014-1-10 26136]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswsnx.sys [2014-1-10 779536]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [2014-1-10 414520]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-7-15 242240]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-5-4 24184]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-1-10 67824]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2014-1-10 71944]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-7-10 50344]
R2 avast! Firewall;avast! Firewall;c:\program files\avast software\avast\afwServ.exe [2014-7-10 106488]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-6-25 233472]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-8-18 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-8-18 860472]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\McSACore.exe [2014-8-2 133696]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-1-18 383264]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2013-6-25 37344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-8-18 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-8-18 110296]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-8-18 51928]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-1-12 260640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\wcmvcam.sys [2011-6-23 1068216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-8-13 108032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2013-6-25 136904]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2013-6-25 17864]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2013-6-25 153672]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-21 52224]
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-9 1343400]
S4 fttxr5_O;fttxr5_O;c:\windows\system32\drivers\fttxr5_O.sys [2008-6-16 185352]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2014-08-18 01:31:24 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-18 01:31:01 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-18 01:31:01 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-18 01:31:01 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-18 01:31:01 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-08-15 11:33:38 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-08-15 11:32:09 8217224 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1bb03392-e188-4171-ba5c-d1ce68dd2f9e}\mpengine.dll
2014-08-13 10:22:59 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-02 22:48:32 2425856 ----a-w- c:\windows\system32\wucltux.dll
2014-08-02 22:48:24 92672 ----a-w- c:\windows\system32\wudriver.dll
2014-08-02 22:48:11 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-08-02 22:48:11 179656 ----a-w- c:\windows\system32\wuwebv.dll
2014-07-28 05:35:02 108544 ----a-w- c:\windows\system32\hfnapi.dll
2014-07-28 05:34:50 249856 ----a-w- c:\windows\system32\hfpapi.dll
.
==================== Find3M ====================
.
2014-08-07 01:43:38 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-07 01:39:08 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-25 13:04:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-07-25 13:03:54 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-07-25 12:34:49 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-07-25 12:34:03 455168 ----a-w- c:\windows\system32\vbscript.dll
2014-07-25 12:33:08 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-07-25 12:30:32 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-07-25 12:10:15 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-07-25 12:10:12 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-07-25 12:08:47 597504 ----a-w- c:\windows\system32\jscript9diag.dll
2014-07-25 12:06:47 4204032 ----a-w- c:\windows\system32\jscript9.dll
2014-07-25 11:59:29 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-07-25 11:43:16 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 11:07:49 2001920 ----a-w- c:\windows\system32\inetcpl.cpl
2014-07-25 11:07:10 1068032 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-07-25 10:05:23 1792512 ----a-w- c:\windows\system32\wininet.dll
2014-07-16 02:46:02 2048 ----a-w- c:\windows\system32\tzres.dll
2014-07-16 01:47:53 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-07-14 01:42:02 654336 ----a-w- c:\windows\system32\rpcrt4.dll
2014-07-10 20:32:51 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-10 20:32:51 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-10 20:32:51 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-10 20:32:50 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-10 20:32:50 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-10 20:32:50 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-10 20:32:49 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-10 20:32:49 43152 ----a-w- c:\windows\avastSS.scr
2014-07-10 20:32:41 26136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-07-10 20:32:36 270752 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-07-09 13:49:16 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 13:49:16 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 01:29:32 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-07-09 01:29:31 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-06-18 01:51:32 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-16 01:44:49 730048 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-06-16 01:44:49 219072 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2014-06-16 01:40:20 107520 ----a-w- c:\windows\system32\cdd.dll
2014-06-06 09:44:17 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26:50 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-03 09:30:10 101824 ----a-w- c:\windows\system32\consent.exe
2014-06-03 09:29:50 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-06-03 09:29:50 2363392 ----a-w- c:\windows\system32\msi.dll
2014-06-03 09:29:40 1805824 ----a-w- c:\windows\system32\authui.dll
2014-05-30 12:51:20 205 ----a-w- c:\windows\system32\lsprst7.dll
2014-05-30 12:33:37 1024 ----a-w- c:\windows\system32\clauth2.dll
2014-05-30 12:33:37 1024 ----a-w- c:\windows\system32\clauth1.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\ssprs.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\serauth2.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\serauth1.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\nsprs.dll
2014-05-30 12:32:40 1025 ----a-w- c:\windows\system32\sysprs7.dll
2014-05-30 07:52:51 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 07:52:49 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 07:52:45 247808 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 07:52:41 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 07:52:40 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 07:52:36 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 07:52:30 17408 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 06:36:07 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-26 00:32:46 202144 ----a-w- c:\windows\UTP.exe
2014-05-26 00:17:07 249856 ----a-w- c:\windows\system32\uxtheme.dll
2014-05-26 00:17:05 2755072 ----a-w- c:\windows\system32\themeui.dll
2014-05-26 00:17:03 37376 ----a-w- c:\windows\system32\themeservice.dll
.
============= FINISH: 12:51:03,36 ===============
ik heb weer eens een virusinfectie op mijn PC

Ik heb een 32 bits PC met Windows 7 Premium. Ik heb hierop Avast! Internet Security v.2014.9.0.2021 geïnstalleerd. Gister na een opstartscan kreeg ik allemaal ads in mijn browsers van Offerwizard (Firefox en Chrome). Internet werd ook geblokkeerd, behalve Skype (alhoewel ik geen bestanden en video- of audiogesprekken kon ontvangen). Ik heb een virusscan uitgevoerd en kreeg een hele lijst met .tmp bestanden die niet als virus waren aangegeven. Ik had ook 2 netupdsrv.exe, 2 installd.exe en 1 nethfdrv.sys bestanden. Ik heb alle bestanden verwijderd, mijn PC opnieuw opgestart, maar het probleem bleef zich voortzetten. Ik heb toen opnieuw een scan gedaan en de .tmp bestanden waren weer terug. Ze staan nu gemarkeerd als een Win32:Evo-gen virus. Overigens stonden alle bestanden in quarantaine in Avast.
Na de tweede scan heb ik de stappen in de sticky thread opgevolgd. Ik had het echter niet goed gedaan en heb het opnieuw moeten uitvoeren, dus ik post alleen de laatste scans (indien nodig kan ik ook de logs van de eerste scans posten).
- Defogger staat op disabled.
- MBAM log
Malwarebytes Anti-Malware
Scan Date: 18-8-14
Scan Time: 4:47:20
Logfile: mbamlog2.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.18.01
Rootkit Database: v2014.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: gebruiker
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 822167
Time Elapsed: 3 hr, 32 min, 48 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.Amonetize, C:\Windows\System32\nethtsrv.exe, 2020, Delete-on-Reboot, [65a4992ff98275c166151484b64b0cf4]
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.Amonetize, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NetHttpService, Quarantined, [65a4992ff98275c166151484b64b0cf4],
PUP.Optional.Amonetize, HKLM\SOFTWARE\CLASSES\TYPELIB\{363BB65D-1747-4826-B445-1DA6244E2037}, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.Amonetize, HKLM\SOFTWARE\CLASSES\INTERFACE\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.OffersWizard.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nethfdrv, Quarantined, [e623f3d593e8a5915384cf0f1ce6d62a],
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\SYSTWEAK\RegClean Pro, Quarantined, [31d8d2f69eddb482eb6abf2946bc956b],
PUP.Optional.Softonic.A, HKU\S-1-5-21-419608459-42819607-2235241362-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [e227af19e695bc7a340055a83cc6f20e],
Registry Values: 1
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NETHTTPSERVICE|ImagePath, C:\Windows\system32\nethtsrv.exe, Quarantined, [fb0e07c1e89340f6661296ad768ed030]
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
Files: 13
PUP.Optional.Amonetize, C:\Windows\System32\nethtsrv.exe, Delete-on-Reboot, [65a4992ff98275c166151484b64b0cf4],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe Illustrator CS6\Support Files\Contents\Windows\amtlib.dll, Quarantined, [ba4f37919edd9c9adf0c4dcf877ba25e],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe InDesign CS6\amtlib.dll, Quarantined, [83865b6d94e77fb738b3fc20847e3bc5],
PUP.Optional.Amonetize, C:\Users\gebruiker\AppData\Local\41\a18467.exe, Quarantined, [bc4d38901665ed490e68f8aae61b03fd],
PUP.Optional.OffersWizard.A, C:\Users\gebruiker\AppData\Local\Temp\drvinst001.exe, Quarantined, [db2e02c62a5190a68d4522e07491e21e],
PUP.Optional.OffersWizard.A, C:\Users\gebruiker\AppData\Local\Temp\drvinstal1.exe, Quarantined, [4abfcdfbf3887bbb07cb8b7729dc22de],
PUP.Optional.Amonetize, C:\Users\gebruiker\AppData\Local\Temp\setup64-2.exe, Quarantined, [dc2d7c4c57249b9b51d5ed9f50b1ef11],
PUP.Optional.OpenCandy, D:\Mijn Documenten\Mijn Video's\All Downloads\Programma's\DAEMON.Tools.Pro.Advanced.v5.1.0.0333-Admin_Crack\DAEMONToolsPro510-0333.exe, Quarantined, [3bce18b08eedfd39650b1adf828236ca],
PUP.RiskwareTool.CK, D:\Program files D\Adobe\Adobe Photoshop CS6\amtlib.dll, Quarantined, [34d55d6b1764f6407873bf5d946edb25],
PUP.Optional.OffersWizard.A, C:\Windows\System32\drivers\nethfdrv.sys, Quarantined, [e623f3d593e8a5915384cf0f1ce6d62a],
PUP.Optional.InstallD.A, C:\Windows\System32\installd.exe, Quarantined, [cc3dd4f41863ce68415d4d9634cec838],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\ver.xml, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
PUP.Optional.OffersWizard.A, C:\Program Files\Common Files\Config\data.xml, Quarantined, [c841dfe9fb8076c03cadb531b54dcc34],
Physical Sectors: 0
(No malicious items detected)
(end)
- DDS log
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17239
Run by gebruiker at 12:42:47 on 2014-08-18
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3582.1436 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Outdated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Outdated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
c:\PROGRA~1\mcafee\SITEAD~1\McSACore.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\vVX1000.exe
D:\Program files D\iTunes\iTunesHelper.exe
C:\Users\gebruiker\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Users\gebruiker\AppData\Local\Google\Update\1.3.24.15\GoogleCrashHandler.exe
C:\Users\gebruiker\AppData\Local\Akamai\netsession_win.exe
D:\Program files D\Rainlendar2\Rainlendar2.exe
C:\Users\gebruiker\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Skype\Phone\Skype.exe
D:\Program files D\Rainmeter.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\gebruiker\AppData\Roaming\pushbullet\pushbullet_94\pushbullet_app.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uProxyOverride = <local>
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
EB: {555D4D79-4BD2-4094-A395-CFC534424A05} - <orphaned>
uRun: [Akamai NetSession Interface] "c:\users\gebruiker\appdata\local\akamai\netsession_win.exe"
uRun: [Google Update] "c:\users\gebruiker\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Rainlendar2] d:\program files d\rainlendar2\Rainlendar2.exe
uRun: [F.lux] "c:\users\gebruiker\appdata\local\fluxsoftware\flux\flux.exe" /noshow
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Pushbullet] "d:\program files d\pushbullet\pushbullet_app.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Windows Mobile-based device management] c:\windows\windowsmobile\wmdcBase.exe
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [iTunesHelper] "d:\program files d\itunes\iTunesHelper.exe"
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\gebrui~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - d:\program files d\Rainmeter.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldnl-nl.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: NameServer = 213.46.228.196 62.179.104.196
TCP: Interfaces\{02865029-FF93-40B4-BC93-3C2D9FA2349A} : DHCPNameServer = 62.179.104.196 213.46.228.196
TCP: Interfaces\{C9B06480-F092-4C16-B5CA-905DD451E4BC} : DHCPNameServer = 213.46.228.196 62.179.104.196
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - d:\program files d\stardock\object desktop\iconpackager\iprepair.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\gebruiker\appdata\roaming\mozilla\firefox\profiles\wi2b71kq.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxps://www.google.com/search?q=
FF - plugin: c:\program files\adobe\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\threeships shared\dll\npTSHelper.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.30514.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\users\gebruiker\appdata\local\google\update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: c:\users\gebruiker\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\gebruiker\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\gebruiker\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_14_0_0_145.dll
FF - plugin: d:\program files d\itunes\mozilla plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\drivers\aswNdisFlt.sys [2014-7-10 270752]
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-1-10 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-1-10 192352]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2014-1-10 26136]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswsnx.sys [2014-1-10 779536]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [2014-1-10 414520]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-7-15 242240]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-5-4 24184]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-1-10 67824]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2014-1-10 71944]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-7-10 50344]
R2 avast! Firewall;avast! Firewall;c:\program files\avast software\avast\afwServ.exe [2014-7-10 106488]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-6-25 233472]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-8-18 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-8-18 860472]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\McSACore.exe [2014-8-2 133696]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-1-18 383264]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2013-6-25 37344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-8-18 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-8-18 110296]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-8-18 51928]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-1-12 260640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\wcmvcam.sys [2011-6-23 1068216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-8-13 108032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2013-6-25 136904]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2013-6-25 17864]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2013-6-25 153672]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-21 52224]
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-9 1343400]
S4 fttxr5_O;fttxr5_O;c:\windows\system32\drivers\fttxr5_O.sys [2008-6-16 185352]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2014-08-18 01:31:24 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-18 01:31:01 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-18 01:31:01 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-18 01:31:01 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-18 01:31:01 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-08-15 11:33:38 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-08-15 11:32:09 8217224 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1bb03392-e188-4171-ba5c-d1ce68dd2f9e}\mpengine.dll
2014-08-13 10:22:59 305152 ----a-w- c:\windows\system32\gdi32.dll
2014-08-02 22:48:32 2425856 ----a-w- c:\windows\system32\wucltux.dll
2014-08-02 22:48:24 92672 ----a-w- c:\windows\system32\wudriver.dll
2014-08-02 22:48:11 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-08-02 22:48:11 179656 ----a-w- c:\windows\system32\wuwebv.dll
2014-07-28 05:35:02 108544 ----a-w- c:\windows\system32\hfnapi.dll
2014-07-28 05:34:50 249856 ----a-w- c:\windows\system32\hfpapi.dll
.
==================== Find3M ====================
.
2014-08-07 01:43:38 412160 ----a-w- c:\windows\system32\aepdu.dll
2014-08-07 01:39:08 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-25 13:04:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-07-25 13:03:54 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-07-25 12:34:49 61952 ----a-w- c:\windows\system32\iesetup.dll
2014-07-25 12:34:03 455168 ----a-w- c:\windows\system32\vbscript.dll
2014-07-25 12:33:08 51200 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-07-25 12:30:32 61952 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-07-25 12:10:15 112128 ----a-w- c:\windows\system32\ieUnatt.exe
2014-07-25 12:10:12 108032 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-07-25 12:08:47 597504 ----a-w- c:\windows\system32\jscript9diag.dll
2014-07-25 12:06:47 4204032 ----a-w- c:\windows\system32\jscript9.dll
2014-07-25 11:59:29 646144 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-07-25 11:43:16 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 11:07:49 2001920 ----a-w- c:\windows\system32\inetcpl.cpl
2014-07-25 11:07:10 1068032 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-07-25 10:05:23 1792512 ----a-w- c:\windows\system32\wininet.dll
2014-07-16 02:46:02 2048 ----a-w- c:\windows\system32\tzres.dll
2014-07-16 01:47:53 2352640 ----a-w- c:\windows\system32\win32k.sys
2014-07-14 01:42:02 654336 ----a-w- c:\windows\system32\rpcrt4.dll
2014-07-10 20:32:51 779536 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-07-10 20:32:51 71944 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-07-10 20:32:51 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-07-10 20:32:50 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-07-10 20:32:50 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-07-10 20:32:50 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-07-10 20:32:49 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-07-10 20:32:49 43152 ----a-w- c:\windows\avastSS.scr
2014-07-10 20:32:41 26136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-07-10 20:32:36 270752 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-07-09 13:49:16 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 13:49:16 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-09 01:29:32 6144 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-07-09 01:29:31 6144 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-06-18 01:51:32 646144 ----a-w- c:\windows\system32\osk.exe
2014-06-16 01:44:49 730048 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-06-16 01:44:49 219072 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2014-06-16 01:40:20 107520 ----a-w- c:\windows\system32\cdd.dll
2014-06-06 09:44:17 509440 ----a-w- c:\windows\system32\qedit.dll
2014-06-05 14:26:50 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-06-03 09:30:10 101824 ----a-w- c:\windows\system32\consent.exe
2014-06-03 09:29:50 337408 ----a-w- c:\windows\system32\msihnd.dll
2014-06-03 09:29:50 2363392 ----a-w- c:\windows\system32\msi.dll
2014-06-03 09:29:40 1805824 ----a-w- c:\windows\system32\authui.dll
2014-05-30 12:51:20 205 ----a-w- c:\windows\system32\lsprst7.dll
2014-05-30 12:33:37 1024 ----a-w- c:\windows\system32\clauth2.dll
2014-05-30 12:33:37 1024 ----a-w- c:\windows\system32\clauth1.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\ssprs.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\serauth2.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\serauth1.dll
2014-05-30 12:33:37 0 ----a-w- c:\windows\system32\nsprs.dll
2014-05-30 12:32:40 1025 ----a-w- c:\windows\system32\sysprs7.dll
2014-05-30 07:52:51 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-05-30 07:52:49 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-05-30 07:52:45 247808 ----a-w- c:\windows\system32\schannel.dll
2014-05-30 07:52:41 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-05-30 07:52:40 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-05-30 07:52:36 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-05-30 07:52:30 17408 ----a-w- c:\windows\system32\credssp.dll
2014-05-30 06:36:07 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-26 00:32:46 202144 ----a-w- c:\windows\UTP.exe
2014-05-26 00:17:07 249856 ----a-w- c:\windows\system32\uxtheme.dll
2014-05-26 00:17:05 2755072 ----a-w- c:\windows\system32\themeui.dll
2014-05-26 00:17:03 37376 ----a-w- c:\windows\system32\themeservice.dll
.
============= FINISH: 12:51:03,36 ===============
Comment