ComboFix 14-04-17.01 - User 18/04/2014 17:43:06.2.4 - x86 Microsoft Windows 7 Professional 6.1.7600.0.1252.32.1043.18.2868.1480 [GMT 2:00] Gestart vanuit: c:\users\User\Desktop\ComboFix.exe gebruikte Opdracht switches :: c:\users\User\Desktop\CFScript.txt AV: AVG Internet Security 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} FW: AVG Internet Security 2014 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2} SP: AVG Internet Security 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files\AVG Secure Search\18.0.5.292\AVG Secure Search_toolbar.dll" . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\AskPartnerNetwork c:\program files\AskPartnerNetwork\Toolbar\apnmcp.exe c:\program files\AskPartnerNetwork\Toolbar\APNSetup.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1031.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1033.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1034.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1036.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1040.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1041.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1043.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1045.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\1049.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\2070.mst c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\appdata\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\extensions\toolbar_ORJ-V7@apn.ask.com.xpi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\AskToolbarInstaller-12.10.0_ORJ-V7.msi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\AskToolbarInstaller-12.10.3_ORJ-V7.msi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\AskToolbarInstaller-12.10.6_ORJ-V7.msi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\AskToolbarInstaller-12.6.0_ORJ-V7.msi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\AskToolbarInstaller-12.9.1_ORJ-V7.msi c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\{Crx_Version}\Toolbar.crx c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\ToolbarCR.crx c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\common appdata\AskPartnerNetwork\Toolbar\{PartnerID}\CRX\Update.xml c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\{PartnerID}\Passport_x64.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\apnmcp.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\searchhook.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\ServiceLocator.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\SO.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\toolbar.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\Toolbar.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\toolbar_x64.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\ToolbarPS.dll c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\{PartnerID}\config.xml c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\VNT\content.zip c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\VNT\vntldr.exe c:\program files\AskPartnerNetwork\Toolbar\ORJ-V7\Source\program files\VNT\vntsrv.dll c:\program files\AskPartnerNetwork\Toolbar\UpdateManager.exe c:\program files\AskPartnerNetwork\Toolbar\Updater\ask-search.xml c:\program files\AskPartnerNetwork\Toolbar\Updater\ORJ-V7\config.xml c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe c:\program files\Productivity_2.2 c:\program files\Productivity_2.2\GottenAppsContextMenu.xml c:\program files\Productivity_2.2\OtherAppsContextMenu.xml c:\program files\Productivity_2.2\Productivity_2.2ToolbarHelper.exe c:\program files\Productivity_2.2\prxtbProd.dll c:\program files\Productivity_2.2\SharedAppsContextMenu.xml c:\program files\Productivity_2.2\tbProd.dll c:\program files\Productivity_2.2\toolbar.cfg c:\program files\Productivity_2.2\ToolbarContextMenu.xml c:\program files\Productivity_2.2\uninstall.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_APNMCP -------\Service_APNMCP . . (((((((((((((((((((( Bestanden Gemaakt van 2014-03-18 to 2014-04-18 )))))))))))))))))))))))))))))) . . 2014-04-18 15:56 . 2014-04-18 16:01 -------- d-----w- c:\users\User\AppData\Local\temp 2014-04-17 17:40 . 2014-04-18 16:00 107736 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-04-17 17:40 . 2014-04-17 17:42 -------- d-----w- c:\program files\Malwarebytes Anti-Malware 2014-04-17 17:40 . 2014-04-17 17:40 -------- d-----w- c:\programdata\Malwarebytes 2014-04-17 17:40 . 2014-04-03 07:51 51416 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-04-17 17:40 . 2014-04-03 07:51 73432 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-04-17 17:40 . 2014-04-03 07:50 23256 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-04-17 17:36 . 2014-04-17 17:36 -------- d-----w- c:\users\User\AppData\Local\Programs 2014-04-17 09:37 . 2014-04-17 09:51 -------- d-----w- C:\zoek_backup 2014-04-13 09:53 . 2014-04-13 09:54 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2014-04-13 09:53 . 2014-04-13 09:54 -------- d-----w- c:\program files\iTunes 2014-04-13 09:53 . 2014-04-13 09:53 -------- d-----w- c:\program files\iPod 2014-04-06 12:25 . 2014-04-17 07:33 -------- d-----w- C:\rsit 2014-04-06 12:25 . 2014-04-17 07:33 -------- d-----w- c:\program files\trend micro 2014-04-06 11:12 . 2014-04-06 12:40 -------- d-----w- c:\program files\Mozilla Maintenance Service 2014-04-01 19:07 . 2014-04-01 19:07 199448 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2014-03-31 14:11 . 2014-03-31 14:11 211224 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2014-03-31 14:11 . 2014-03-31 14:11 108312 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2014-03-27 20:15 . 2014-03-27 20:15 193304 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2014-03-27 20:14 . 2014-03-27 20:14 123160 ----a-w- c:\windows\system32\drivers\avgdiskx.sys 2014-03-27 20:04 . 2014-03-27 20:04 150296 ----a-w- c:\windows\system32\drivers\avgidshx.sys 2014-03-27 20:04 . 2014-03-27 20:04 238872 ----a-w- c:\windows\system32\drivers\avglogx.sys 2014-03-27 20:03 . 2014-03-27 20:03 28440 ----a-w- c:\windows\system32\drivers\avgrkx86.sys 2014-03-27 20:03 . 2014-03-27 20:03 22296 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys 2014-03-20 20:43 . 2014-04-06 12:40 -------- d-----w- c:\programdata\AVG Secure Search . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-03-20 20:43 . 2012-08-29 15:12 42272 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2014-03-12 18:06 . 2012-04-04 04:23 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-03-12 18:06 . 2011-06-02 10:49 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2014-01-30 14:05 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2014-01-30 14:05 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2014-01-30 14:05 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2014-01-30 14:05 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2014-01-30 14:05 579400 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmileboxTray"="c:\users\User\AppData\Roaming\Smilebox\SmileboxTray.exe" [2012-08-13 305000] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2008-11-17 210208] "KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2012-06-08 958392] "KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-06-08 21432] "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2013-04-22 720064] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2010-03-04 496184] "AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2010-06-10 233472] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-04-22 1725736] "ODDPwr"="c:\program files\Acer\Optical Drive Power Management\ODDPwr.exe" [2010-04-22 186912] "NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648] "BackupManagerTray"="c:\program files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-07 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-07 175640] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-07 169496] "LManager"="c:\program files\Launch Manager\LManager.exe" [2010-04-08 908368] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-04-23 715296] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "FLMOFFICE4DMOUSE"="c:\program files\Labtec\Desktop\V5.1\moffice.exe" [2011-06-25 958464] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2014-03-20 2544664] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368] "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "AtherosBtStack"="c:\program files\Bluetooth Suite\BtvStack.exe" [2011-03-31 605344] "AthBtTray"="c:\program files\Bluetooth Suite\AthBtTray.exe" [2011-03-31 519328] "PDFHook"="c:\program files\Nuance\PDF Professional 6\pdfpro6hook.exe" [2009-07-24 2080768] "PDF6 Registry Controller"="c:\program files\Nuance\PDF Professional 6\RegistryController.exe" [2009-06-30 111904] "Nuance PDF Professional 6-reminder"="c:\program files\Nuance\PDF Professional 6\Ereg\Ereg.exe" [2008-11-03 54560] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2014-02-12 43848] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888] "AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-04-06 5180432] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-02-21 152392] . c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2010-6-23 704032] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 828704] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192] R2 XAMPP;XAMPP Service;c:\xampp\service.exe [2012-04-16 60928] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-03-31 35488] R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys [2011-03-31 43680] R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-11-10 167264] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-03-31 226976] R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys [2011-03-31 97440] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-03-31 147104] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-03-31 52384] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-03-31 266272] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-03-31 247968] R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-03-05 286248] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-01 33320] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-05-21 80824] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-04-17 50432] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-06-02 121064] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-06-02 12776] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-06-02 136808] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-05-21 181432] R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys [2012-05-21 181432] R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-23 1343400] S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2014-03-27 150296] S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2014-03-27 238872] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2014-03-27 28440] S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiskx.sys [2014-03-27 123160] S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2013-09-26 47928] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2014-04-01 199448] S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2014-03-27 22296] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2014-03-27 193304] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2014-03-31 211224] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2014-03-20 42272] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-18 242240] S2 AtherosSvc;AtherosSvc;c:\program files\Bluetooth Suite\adminservice.exe [2011-03-31 68768] S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2014\avgfws.exe [2014-04-03 1473280] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2014\avgidsagent.exe [2014-04-01 3655184] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2014\avgwdsvc.exe [2014-03-27 291912] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2010-04-08 312400] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-04-23 735776] S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\Drivers\FPSensor.sys [2010-10-11 29232] S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-04-03 1809720] S2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2014-04-03 857912] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-04-17 144640] S2 ODDPwrSvc;Acer ODD Power Service;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [2010-04-22 129568] S2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-06-30 134944] S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032] S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S2 vToolbarUpdater18.0.5;vToolbarUpdater18.0.5;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [2014-03-20 1771032] S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2010-06-10 25600] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-03-31 24736] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-04-03 23256] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-04-18 107736] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-04-03 51416] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - MBAMWEBACCESSCONTROL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HsfXAudioService REG_MULTI_SZ HsfXAudioService . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-10 06:04 1077576 ----a-w- c:\program files\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhoud van de 'Gedeelde Taken' map . 2014-04-18 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:06] . 2014-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-23 18:39] . 2014-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-23 18:39] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0813&m=travelmate_8572t&r=27051210z016l0453z215x48j1q32r IE: Open with Nuance PDF Converter 6.0 - c:\program files\Nuance\PDF Professional 6\cnvres_eng.dll /100 TCP: DhcpNameServer = 192.168.1.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.5\ViProtocol.dll FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\jlsr90bq.default-1364328719161\ FF - prefs.js: browser.startup.homepage - about:home FF - ExtSQL: !HIDDEN! 2013-03-15 18:15; belgiumeid@eid.belgium.be; c:\program files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be . - - - - ORPHANS VERWIJDERD - - - - . HKLM-Run-ApnTBMon - c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe AddRemove-Productivity_2.2 Toolbar - c:\progra~1\PRODUC~1.2\UNINST~1.EXE . . . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- DLLs Geladen Onder Lopende Processen --------------------- . - - - - - - - > 'Explorer.exe'(3420) c:\program files\Bluetooth Suite\AthCopyHook.dll c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll . ------------------------ Andere Aktieve Processen ------------------------ . c:\progra~1\AVG\AVG2014\avgrsx.exe c:\program files\AVG\AVG2014\avgcsrvx.exe c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files\Malwarebytes Anti-Malware\mbam.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Protexis\License Service\PsiService_2.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\loggingserver.exe c:\windows\system32\conhost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\AVG\AVG2014\avgnsx.exe c:\program files\AVG\AVG2014\avgemcx.exe c:\program files\AVG\AVG2014\avgcsrvx.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\conhost.exe c:\windows\system32\sppsvc.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Voltooingstijd: 2014-04-18 18:06:48 - machine werd herstart ComboFix-quarantined-files.txt 2014-04-18 16:06 ComboFix2.txt 2014-04-18 08:45 . Pre-Run: 157.955.018.752 bytes beschikbaar Post-Run: 157.936.455.680 bytes beschikbaar . - - End Of File - - AC178E443E053B36C46E80665B42B707 A36C5E4F47E84449FF07ED3517B43A31