DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by theo at 21:15:40 on 2012-01-31
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3885.1818 [GMT 1:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\FileServe Toolbar\FileServeSvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\FileServe Toolbar\FileServeVideoToMp3.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_160_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.nl/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://nl.woofi.info
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: Aanmeldhulp voor Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [CursorFX] "C:\Program Files (x86)\Stardock\CursorFX\CursorFX.exe"
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
mRun: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk"
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\theo\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAILWA~1.LNK - C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SRSPRE~1.LNK - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
Trusted Zone: buienradar.nl\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 62.179.104.196 213.46.228.196
TCP: Interfaces\{D0C39DFC-B4E8-4587-8254-20A14671EA7C} : DhcpNameServer = 192.168.1.1 62.179.104.196 213.46.228.196
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9FDDE16B-836F-4806-AB1F-1455CBEFF289}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
{B4F3A835-0E21-4959-BA22-42B3008E02FF}
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
mRun-x64: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk"
mRun-x64: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
mRun-x64: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
mRun-x64: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
mRun-x64: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
mRun-x64: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun-x64: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
mRun-x64: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun-x64: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
mRun-x64: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook
.
============= SERVICES / DRIVERS ===============
.
R0 lullaby;lullaby;C:\Windows\system32\DRIVERS\lullaby.sys --> C:\Windows\system32\DRIVERS\lullaby.sys [?]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys --> C:\Windows\system32\drivers\PCTCore64.sys [?]
R0 TfFsMon;TfFsMon;C:\Windows\system32\drivers\TfFsMon.sys --> C:\Windows\system32\drivers\TfFsMon.sys [?]
R0 TfSysMon;TfSysMon;C:\Windows\system32\drivers\TfSysMon.sys --> C:\Windows\system32\drivers\TfSysMon.sys [?]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 pctgntdi;pctgntdi;\??\C:\Windows\system32\drivers\pctgntdi64.sys --> C:\Windows\system32\drivers\pctgntdi64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-3 15416]
R2 FileServe Toolbar Helper;FileServe Toolbar Helper;C:\Program Files (x86)\FileServe Toolbar\FileServeSvc.exe [2011-3-22 224256]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-14 13592]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-1-21 652872]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-11-6 2255464]
R2 PassThru Service;Internet Pass-Through Service;C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2011-8-12 87040]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2011-3-15 428384]
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-12-5 92592]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-6 2314240]
R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe [2011-11-28 73728]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\Windows\system32\DRIVERS\JME.sys --> C:\Windows\system32\DRIVERS\JME.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 MTsensor64;PU ACPI UTILITY;C:\Windows\system32\DRIVERS\PuAcpi64.sys --> C:\Windows\system32\DRIVERS\PuAcpi64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 AdvancedSystemCareService;Advanced SystemCare Service;C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe --> C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [?]
S2 AFBAgent;AFBAgent; [x]
S2 Amsp;Trend Micro Solution Platform;"C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad --> C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;"C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" --> C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-1-7 253600]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;C:\Windows\system32\Drivers\ssadadb.sys --> C:\Windows\system32\Drivers\ssadadb.sys [?]
S3 AWiCSrvc;AWiCSrvc;C:\Program Files (x86)\Atheros\AWiCSrvc.exe [2011-5-26 50336]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 htcnprot;HTC NDIS Protocol Driver;C:\Windows\system32\DRIVERS\htcnprot.sys --> C:\Windows\system32\DRIVERS\htcnprot.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2010-11-6 332272]
S3 pctplsg;pctplsg;\??\C:\Windows\System32\drivers\pctplsg64.sys --> C:\Windows\System32\drivers\pctplsg64.sys [?]
S3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys --> C:\Windows\system32\DRIVERS\revoflt.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe --> C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe [?]
S3 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe --> C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe [?]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --> C:\Windows\system32\DRIVERS\SiSG664.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);C:\Windows\system32\DRIVERS\ssadserd.sys --> C:\Windows\system32\DRIVERS\ssadserd.sys [?]
S3 TfNetMon;TfNetMon;\??\C:\Windows\system32\drivers\TfNetMon.sys --> C:\Windows\system32\drivers\TfNetMon.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 Browser Defender Update Service;Browser Defender Update Service;"C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe" --> C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe [?]
S4 ThreatFire;ThreatFire;C:\Program Files (x86)\Spyware Doctor\TFEngine\TFService.exe service --> C:\Program Files (x86)\Spyware Doctor\TFEngine\TFService.exe service [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-01-31 18:59:49 -------- d-----w- C:\Users\theo\AppData\Local\{0C05B79A-5616-4216-AFE8-B6510C2CE3DC}
2012-01-31 18:59:38 -------- d-----w- C:\Users\theo\AppData\Local\{271681B9-8E2B-42DF-A882-A1D5E9208DEF}
2012-01-31 17:49:55 -------- d-----w- C:\Users\theo\AppData\Local\Temp
2012-01-30 20:14:25 -------- d-----w- C:\Program Files (x86)\AVG
2012-01-30 18:46:50 -------- d-----w- C:\Users\theo\AppData\Local\{3DE8D6DE-0113-45D2-A674-1D281A30F53C}
2012-01-30 18:46:39 -------- d-----w- C:\Users\theo\AppData\Local\{D0F014B6-5CCF-4511-AAF6-EDFFED45AEDC}
2012-01-29 16:16:16 -------- d-----w- C:\Program Files (x86)\Common Files\ParetoLogic
2012-01-29 16:16:12 -------- d-----w- C:\Program Files (x86)\ParetoLogic
2012-01-29 15:36:58 917840 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{65DD3A62-DBF6-4C11-91FB-2BED36BA32E5}\gapaengine.dll
2012-01-29 15:36:41 8602168 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9395D262-E57F-45A9-BD72-8342153F44DF}\mpengine.dll
2012-01-29 15:33:23 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-01-29 15:33:15 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-01-29 13:42:23 -------- d-----w- C:\Users\theo\AppData\Local\{221BFEC2-794A-494B-9589-887F412258E0}
2012-01-29 13:42:11 -------- d-----w- C:\Users\theo\AppData\Local\{675B63D7-4B05-4019-8D2C-97F3F1A49E4D}
2012-01-28 23:31:58 -------- d-----w- C:\Users\theo\AppData\Local\uTorrent
2012-01-28 22:56:26 -------- d-----w- C:\Users\theo\AppData\Local\{3156DA13-680B-4332-97A7-7F5740ED2421}
2012-01-28 22:56:14 -------- d-----w- C:\Users\theo\AppData\Local\{1987A57E-4D5A-47BD-941A-91B02741C021}
2012-01-28 08:16:57 -------- d-----w- C:\Users\theo\AppData\Local\{50BF5387-3BF8-4151-A6A3-2E2C1C5F209E}
2012-01-28 08:16:45 -------- d-----w- C:\Users\theo\AppData\Local\{7359AD31-CCE9-461A-B044-E6262E65B84A}
2012-01-27 19:16:41 -------- d-----w- C:\Windows\System32\wbem\Logs
2012-01-27 18:12:29 -------- d-----w- C:\Users\theo\AppData\Local\{0D7D0253-1BE7-47DC-9311-8C781086F185}
2012-01-27 18:12:15 -------- d-----w- C:\Users\theo\AppData\Local\{32D679B4-53B0-4F06-A0B8-79C7D9E7C985}
2012-01-26 19:00:00 -------- d-----w- C:\Users\theo\AppData\Local\Babylon
2012-01-26 18:59:58 -------- d-----w- C:\Users\theo\AppData\Roaming\Babylon
2012-01-26 18:59:58 -------- d-----w- C:\ProgramData\Babylon
2012-01-26 18:59:56 -------- d-----w- C:\Program Files (x86)\Your Uninstaller! 7
2012-01-26 16:19:11 -------- d-----w- C:\Users\theo\AppData\Local\{D308063D-1986-4FC0-8C85-1B1C6D93BB12}
2012-01-26 16:19:00 -------- d-----w- C:\Users\theo\AppData\Local\{D350D851-199E-4EB0-96A0-CD71E0100FDC}
2012-01-25 18:12:57 -------- d-----w- C:\Users\theo\AppData\Local\{57A08078-6D19-4FE2-8DFB-43BF6D2CDE21}
2012-01-25 18:12:38 -------- d-----w- C:\Users\theo\AppData\Local\{06107DF7-EE12-4B80-BE99-1CBD9C0505B5}
2012-01-24 18:32:56 -------- d-----w- C:\Program Files (x86)\Firetrust
2012-01-24 18:08:09 -------- d-----w- C:\Users\theo\AppData\Local\{79BCD92D-317F-4204-99A7-5FC3C029143A}
2012-01-24 18:07:54 -------- d-----w- C:\Users\theo\AppData\Local\{48B89403-10C4-4BAA-92C7-3DAD854FACB9}
2012-01-23 18:56:50 -------- d-----w- C:\Users\theo\AppData\Local\{DDA08424-DFA9-4DFB-BAB7-B4A6B0CA0E25}
2012-01-23 18:56:36 -------- d-----w- C:\Users\theo\AppData\Local\{15D62830-659F-4ABE-83D5-76AFB70D64D8}
2012-01-22 18:45:13 -------- d-----w- C:\ProgramData\ASUS
2012-01-22 14:24:54 15880 ----a-w- C:\Windows\System32\drivers\PuAcpi64.sys
2012-01-22 13:45:31 -------- d-----w- C:\Users\theo\AppData\Local\{0A8538A4-F548-4372-8C9E-498B4A51F9A8}
2012-01-22 13:45:15 -------- d-----w- C:\Users\theo\AppData\Local\{876A08A1-27FA-41CF-BE4C-F4DD07AF5759}
2012-01-22 08:40:17 -------- d-----w- C:\Users\theo\AppData\Roaming\ParetoLogic
2012-01-22 08:40:17 -------- d-----w- C:\Users\theo\AppData\Roaming\DriverCure
2012-01-22 08:40:07 -------- d-----w- C:\ProgramData\ParetoLogic
2012-01-21 23:15:19 -------- d-----w- C:\Users\theo\AppData\Local\{67EDE615-F8B6-4A68-9E2C-8D50042CC53C}
2012-01-21 23:15:08 -------- d-----w- C:\Users\theo\AppData\Local\{0B454181-4D21-4BFF-8D38-002A77B73A68}
2012-01-21 15:08:08 -------- d-----w- C:\ProgramData\AVAST Software
2012-01-21 10:28:41 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2012-01-21 10:28:35 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-01-21 10:28:35 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-21 09:40:13 -------- d-----w- C:\Users\theo\AppData\Local\{738B26C3-8F36-4ECE-88D2-29FE52FB4F93}
2012-01-21 09:40:00 -------- d-----w- C:\Users\theo\AppData\Local\{0FB12D15-49E2-462F-A29E-B4B3C69FE161}
2012-01-20 18:16:37 -------- d-----w- C:\Users\theo\AppData\Local\{A03E00DD-359B-4931-B012-043D6928CE94}
2012-01-20 18:16:22 -------- d-----w- C:\Users\theo\AppData\Local\{64CD7399-9A0F-4C5F-9DC1-7E1A2C9E4F2D}
2012-01-19 18:08:28 -------- d-----w- C:\Users\theo\AppData\Local\{9B0AC623-68BB-44CC-B0CB-9E0E6F452EA3}
2012-01-19 18:08:14 -------- d-----w- C:\Users\theo\AppData\Local\{C71EA3C7-C5E3-457E-BC5D-A277C574E39D}
2012-01-18 21:55:58 -------- d-----w- C:\Users\theo\AppData\Local\{01631F1C-CC0C-479A-B033-DD827D00B783}
2012-01-18 21:55:45 -------- d-----w- C:\Users\theo\AppData\Local\{C3CCB702-CF48-4C0A-8F4D-68670F70B2C6}
2012-01-17 18:15:56 -------- d-----w- C:\Users\theo\AppData\Local\{BF32F1F2-7BB3-4467-800E-ABA254A39ABF}
2012-01-17 18:15:36 -------- d-----w- C:\Users\theo\AppData\Local\{924D4452-5794-4943-9F5C-60FB48BAB4A5}
2012-01-16 18:16:57 -------- d-----w- C:\Program Files (x86)\TomTom International B.V
2012-01-16 18:16:42 -------- d-----w- C:\Program Files (x86)\TomTom HOME 2
2012-01-16 18:05:38 -------- d-----w- C:\Users\theo\AppData\Local\{7AB58E8B-18B1-4E4C-95C5-A9CD8EB36960}
2012-01-16 18:05:25 -------- d-----w- C:\Users\theo\AppData\Local\{697E1525-38A2-4813-BCBE-A4F6856F516B}
2012-01-15 20:43:28 -------- d-----w- C:\Users\theo\AppData\Local\{E0A0B2F3-9D70-46E2-89D4-DD4CE0296352}
2012-01-15 20:43:16 -------- d-----w- C:\Users\theo\AppData\Local\{4CEEFBD8-CAA0-4673-91A3-C0675A97EA8B}
2012-01-15 08:31:39 -------- d-----w- C:\Users\theo\AppData\Local\{1DCF2DE3-908B-41D1-B4A4-EB8FC44E47C0}
2012-01-15 08:31:28 -------- d-----w- C:\Users\theo\AppData\Local\{079A78FD-1DC5-4D64-9D5B-42CAA5B42D42}
2012-01-14 20:31:01 -------- d-----w- C:\Users\theo\AppData\Local\{D3363C46-CAB8-4AF6-ACE0-61979BBC28A2}
2012-01-14 20:30:49 -------- d-----w- C:\Users\theo\AppData\Local\{964FC719-07BF-4C08-A215-D6D5C66DBB89}
2012-01-14 13:18:17 -------- d-----w- C:\Users\theo\AppData\Local\Samsung
2012-01-14 13:17:57 -------- d-----w- C:\Users\theo\AppData\Roaming\Samsung
2012-01-14 13:07:44 1917416 ----a-w- C:\Windows\System32\WdfCoInstaller01005.dll
2012-01-14 13:07:44 1917416 ----a-w- C:\Windows\System32\drivers\WdfCoInstaller01005.dll
2012-01-14 13:07:44 177640 ----a-w- C:\Windows\System32\drivers\ssadmdm.sys
2012-01-14 13:07:44 16872 ----a-w- C:\Windows\System32\drivers\ssadmdfl.sys
2012-01-14 13:07:44 157672 ----a-w- C:\Windows\System32\drivers\ssadbus.sys
2012-01-14 13:07:44 13800 ----a-w- C:\Windows\System32\drivers\ssadwhnt.sys
2012-01-14 13:07:44 13800 ----a-w- C:\Windows\System32\drivers\ssadwh.sys
2012-01-14 13:07:44 13288 ----a-w- C:\Windows\System32\drivers\ssadcmnt.sys
2012-01-14 13:07:44 13288 ----a-w- C:\Windows\System32\drivers\ssadcm.sys
2012-01-14 13:07:43 36328 ----a-w- C:\Windows\System32\drivers\ssadadb.sys
2012-01-14 13:07:43 146920 ----a-w- C:\Windows\System32\drivers\ssadserd.sys
2012-01-14 13:01:48 -------- d-----w- C:\Windows\System32\catroot2
2012-01-14 13:00:34 4659712 ----a-w- C:\Windows\SysWow64\Redemption.dll
2012-01-14 13:00:05 821824 ----a-w- C:\Windows\SysWow64\dgderapi.dll
2012-01-14 13:00:05 -------- d-----w- C:\Program Files (x86)\MarkAny
2012-01-14 12:59:36 -------- d-----w- C:\ProgramData\Samsung
2012-01-14 12:59:36 -------- d-----w- C:\Program Files (x86)\Samsung
2012-01-14 08:05:32 -------- d-----w- C:\Users\theo\AppData\Local\{27FF4418-7711-49E9-BF41-CEE077EEEFFF}
2012-01-14 08:05:18 -------- d-----w- C:\Users\theo\AppData\Local\{4988FEC8-EF7E-4AFD-9353-5296AD18606C}
2012-01-13 20:54:38 -------- d-----w- C:\ProgramData\TomTom
2012-01-13 20:43:32 18432 ----a-w- C:\Windows\System32\drivers\NTIDrvr.sys
2012-01-13 20:43:32 16896 ----a-w- C:\Windows\System32\drivers\UBHelper.sys
2012-01-13 17:51:28 -------- d-----w- C:\Users\theo\AppData\Local\{9BFA131D-7CCB-470B-8EF3-5BF8B41F6FFB}
2012-01-13 17:51:02 -------- d-----w- C:\Users\theo\AppData\Local\{7BC7569A-4408-4480-8997-0717A97095CF}
2012-01-12 21:40:40 -------- d-----w- C:\Windows\SoftwareDistributionold
2012-01-12 18:59:46 -------- d-----w- C:\ProgramData\Ocster Backup
2012-01-12 18:22:17 -------- d-----w- C:\Users\theo\AppData\Local\{9DCEEBE5-D14C-4714-8205-2A500B43A8C8}
2012-01-12 18:22:04 -------- d-----w- C:\Users\theo\AppData\Local\{40425E11-CC6A-454F-A143-9E379A8973D7}
2012-01-12 00:16:24 -------- d-----w- C:\Users\theo\AppData\Local\{0A5DE030-B69F-47E1-A674-5F4F19926281}
2012-01-12 00:16:13 -------- d-----w- C:\Users\theo\AppData\Local\{1B885023-BA3C-47F1-B57B-76AA9EB59C84}
2012-01-11 21:17:01 -------- d-----w- C:\Users\theo\AppData\Local\{B56777F6-61E2-4F36-A049-B627CAB3D2AC}
2012-01-11 21:16:49 -------- d-----w- C:\Users\theo\AppData\Local\{406AA5B8-AA34-4011-8802-94D93B7EE149}
2012-01-11 20:01:24 -------- d-----w- C:\Users\theo\AppData\Roaming\Windows Live Writer
2012-01-11 20:01:24 -------- d-----w- C:\Users\theo\AppData\Local\Windows Live Writer
2012-01-11 18:25:03 -------- d-----w- C:\Users\theo\AppData\Local\{9E63D8FB-4BFB-45ED-AB14-5D6CCA4217A1}
2012-01-11 18:24:51 -------- d-----w- C:\Users\theo\AppData\Local\{23A789EB-EAC5-4DF8-8648-71A2836670C8}
2012-01-10 18:25:40 -------- d-----w- C:\Users\theo\AppData\Local\{BC7D7004-854D-4777-8386-3C36F556F80B}
2012-01-10 18:25:17 -------- d-----w- C:\Users\theo\AppData\Local\{CC9A3185-0FB5-41C3-9288-01A3A492AEB8}
2012-01-09 22:07:58 -------- d-----w- C:\Users\theo\AppData\Local\{FF815980-0244-424F-8E2A-767AD4C186FE}
2012-01-09 22:07:44 -------- d-----w- C:\Users\theo\AppData\Local\{FF714952-ABDA-4681-9F17-C872EF1DB078}
2012-01-09 19:22:37 -------- d-----w- C:\Users\theo\Option
2012-01-09 19:18:54 -------- d-----w- C:\ProgramData\BlazeVideo
2012-01-09 18:49:13 -------- d-----w- C:\Users\theo\AppData\Local\{FF0AE8E6-CAB1-4B51-8F35-B8DD72B3C2CD}
2012-01-09 18:49:00 -------- d-----w- C:\Users\theo\AppData\Local\{196BAE5A-72EA-4765-BAF4-608E2A529E8E}
2012-01-08 21:03:25 -------- d-----w- C:\Users\theo\AppData\Local\{7E87E211-F26D-46F7-B01E-105F6BE2C907}
2012-01-08 21:03:13 -------- d-----w- C:\Users\theo\AppData\Local\{A3B44EB6-914F-4A7F-AAED-5D8C7D1F656E}
2012-01-08 19:48:09 -------- d-----w- C:\ProgramData\NTI Launcher
2012-01-08 19:46:06 -------- d-----w- C:\Program Files (x86)\Common Files\muvee Technologies
2012-01-08 19:44:36 -------- d-----w- C:\Program Files (x86)\Common Files\Macrovision Shared
2012-01-08 19:29:00 -------- d-----w- C:\Program Files (x86)\Downloaded Installations
2012-01-08 09:02:41 -------- d-----w- C:\Users\theo\AppData\Local\{DE1C55CA-BE00-487C-8B21-1F4B8FBDA02F}
2012-01-08 09:02:29 -------- d-----w- C:\Users\theo\AppData\Local\{66212391-FB45-4202-84B9-F0AA48538854}
2012-01-07 17:48:02 -------- d-----w- C:\Users\theo\AppData\Local\{114E3808-6F7C-49DE-ADC4-545069FCA6CC}
2012-01-07 17:47:49 -------- d-----w- C:\Users\theo\AppData\Local\{C41BA1D7-3972-47B5-8C62-8A03D0E754F8}
2012-01-07 17:21:37 417440 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-01-07 16:54:20 2200 ----a-w- C:\Windows\System32\ASOROSet.bin
2012-01-07 15:31:51 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-01-07 14:14:03 -------- d-----w- C:\ProgramData\Norton
2012-01-07 14:07:57 -------- d-----w- C:\ProgramData\NortonInstaller
2012-01-07 08:10:35 -------- d-----w- C:\Users\theo\AppData\Roaming\Systweak
2012-01-07 08:10:33 18816 ----a-w- C:\Windows\System32\roboot64.exe
2012-01-07 05:47:20 -------- d-----w- C:\Users\theo\AppData\Local\{794672E9-659D-4E72-97B5-17688F25CB86}
2012-01-07 05:47:08 -------- d-----w- C:\Users\theo\AppData\Local\{BBF12600-D20A-4C85-90DD-3B629FC9BDE6}
2012-01-06 18:10:27 -------- d-sh--w- C:\$RECYCLE.BIN
2012-01-06 16:01:01 -------- d--h--w- C:\ProgramData\MFAData
2012-01-06 11:30:38 -------- d--h--w- C:\ProgramData\Malwarebytes
2012-01-06 10:49:31 90192 ----a-w- C:\Windows\System32\drivers\bdfndisf6.sys
2012-01-06 10:30:00 -------- d-----w- C:\Users\theo\AppData\Local\{BE16C3B4-7AB1-49B1-BF2E-ECE3922221EA}
2012-01-06 10:29:48 -------- d-----w- C:\Users\theo\AppData\Local\{40F109D4-2211-4509-98E7-86076CE60829}
2012-01-05 22:54:23 -------- d-----w- C:\Users\theo\AppData\Roaming\QuickScan
2012-01-05 22:53:26 -------- d-----w- C:\Program Files\Common Files\Bitdefender
2012-01-05 22:16:11 -------- d-----w- C:\Users\theo\AppData\Local\{7C7492C6-AF9D-4333-BB5C-1A9066FE8DAD}
2012-01-05 22:15:59 -------- d-----w- C:\Users\theo\AppData\Local\{D39AE0CB-8D06-471A-9D7D-BA211316B95A}
2012-01-05 08:33:17 -------- d-----w- C:\Users\theo\AppData\Local\{EC6CD73B-D908-4274-BDFA-F0393E139748}
2012-01-05 08:33:05 -------- d-----w- C:\Users\theo\AppData\Local\{3BB92CAA-7BF0-4467-8B89-610FC4F201A3}
2012-01-05 00:32:06 53248 ----a-r- C:\Users\theo\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-01-05 00:29:54 -------- d-----w- C:\Intel
2012-01-05 00:27:51 -------- d--h--w- C:\ProgramData\DriverGenius
2012-01-05 00:09:42 -------- d-----w- C:\Program Files (x86)\SpotLite
2012-01-04 20:51:05 -------- d--h--w- C:\ProgramData\IncrediMail
2012-01-04 20:50:28 -------- d--h--w- C:\ProgramData\IM
2012-01-04 20:22:49 -------- d-----w- C:\ProgramData\Spotnet
2012-01-04 20:06:35 -------- d-----w- C:\ProgramData\SpotGrit
2012-01-04 19:40:09 -------- d-----w- C:\Users\theo\AppData\Local\{C80F4D17-458C-422C-B273-3E56829BF61A}
2012-01-04 19:39:57 -------- d-----w- C:\Users\theo\AppData\Local\{DD457022-DFF8-4FA9-9070-6D10CB7F73F6}
2012-01-04 19:14:19 -------- d--h--w- C:\ProgramData\Messenger Plus!
2012-01-04 18:51:57 -------- d--h--w- C:\ASUS.DAT
2012-01-04 18:15:02 98816 ----a-w- C:\Windows\sed.exe
2012-01-04 18:15:02 518144 ----a-w- C:\Windows\SWREG.exe
2012-01-04 18:15:02 256000 ----a-w- C:\Windows\PEV.exe
2012-01-04 18:15:02 208896 ----a-w- C:\Windows\MBR.exe
2012-01-04 09:42:46 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{841AA7E3-F349-42EB-9BE6-594C79D3338E}\mpengine.dll
2012-01-04 07:39:24 -------- d-----w- C:\Users\theo\AppData\Local\{F18B8555-445E-4D57-A6F3-665CD6E62F49}
2012-01-04 07:39:11 -------- d-----w- C:\Users\theo\AppData\Local\{A6E9B9D1-B8B9-4350-A359-0F64FAD2ED91}
2012-01-03 17:48:49 388096 ----a-r- C:\Users\theo\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-03 17:48:47 -------- d-----w- C:\Program Files (x86)\Trend Micro
2012-01-03 11:23:06 970336 ----a-w- C:\Windows\System32\drivers\timntr.sys
2012-01-03 10:44:18 -------- d-----w- C:\Users\theo\AppData\Local\{15E61083-2F09-4FED-AA2A-E69BF843B84C}
2012-01-03 10:44:06 -------- d-----w- C:\Users\theo\AppData\Local\{9A3E18F3-E8EF-44A3-A22B-7FF50564A329}
2012-01-02 22:19:29 -------- d-----w- C:\Users\theo\AppData\Local\{48087721-F1F9-4BA8-8950-0772D3FB8B16}
2012-01-02 22:19:16 -------- d-----w- C:\Users\theo\AppData\Local\{311C9108-9EA8-47B2-90CB-03521DA4A21B}
2012-01-02 21:36:39 -------- d-----w- C:\Users\theo\AppData\Roaming\EeeStorageUploader
2012-01-02 21:36:30 -------- d-----w- C:\Users\theo\AppData\Roaming\temp
2012-01-02 20:18:04 477696 --sha-w- C:\EUMONBMP.SYS
2012-01-02 16:43:46 270720 ------w- C:\Windows\System32\MpSigStub.exe
2012-01-02 16:29:16 57480 ----a-w- C:\Windows\System32\drivers\eubakup.sys
2012-01-02 16:29:16 19592 ----a-w- C:\Windows\System32\drivers\eudskacs.sys
2012-01-02 16:29:16 189576 ----a-w- C:\Windows\System32\drivers\EuFdDisk.sys
2012-01-02 16:29:12 51336 ----a-w- C:\Windows\System32\drivers\EUBKMON.sys
2012-01-02 10:17:10 -------- d-----w- C:\Users\theo\AppData\Local\{DC0DF5EC-CD37-4B04-B0E1-77D9193F602C}
2012-01-02 10:16:56 -------- d-----w- C:\Users\theo\AppData\Local\{C81428EE-B250-4587-83EB-3AEA69563034}
.
==================== Find3M ====================
.
2012-01-07 17:21:37 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-01-03 11:23:11 1263200 ----a-w- C:\Windows\System32\drivers\tdrpm273.sys
2011-12-26 18:11:09 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-12-21 00:02:26 4448256 ----a-w- C:\Windows\SysWow64\GPhotos.scr
2011-12-20 19:24:47 56 ----a-w- C:\Windows\System32\SupportTool.exe.bat
2011-12-20 19:21:29 91920 ----a-w- C:\Windows\System32\drivers\tmactmon.sys
2011-12-20 19:21:29 70928 ----a-w- C:\Windows\System32\drivers\tmevtmgr.sys
2011-12-20 19:21:29 167696 ----a-w- C:\Windows\System32\drivers\tmcomm.sys
2011-12-20 19:21:29 105744 ----a-w- C:\Windows\System32\drivers\tmtdi.sys
2011-12-06 14:55:48 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-23 14:13:10 2796544 ----a-w- C:\Windows\System32\drivers\athrx.sys
2011-11-23 14:13:10 2796544 ----a-w- C:\Windows\System32\athrx.sys
2011-11-23 13:15:40 34624 ----a-w- C:\Windows\System32\TURegOpt.exe
2011-11-23 13:15:32 28992 ----a-w- C:\Windows\SysWow64\uxtuneup.dll
2011-11-23 13:15:30 35648 ----a-w- C:\Windows\System32\uxtuneup.dll
2011-11-23 13:15:30 21312 ----a-w- C:\Windows\SysWow64\authuitu.dll
2011-11-23 13:15:26 25920 ----a-w- C:\Windows\System32\authuitu.dll
2011-11-17 16:11:52 145424 ----a-w- C:\Windows\System32\drivers\JME.sys
2011-11-10 04:54:13 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-04 01:53:39 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2009-04-08 17:31:56 106496 ----a-w- C:\Program Files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45:20 155648 ----a-w- C:\Program Files (x86)\Common Files\MSIactionall.dll
.
============= FINISH: 21:16:54,16 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 17-3-2011 20:58:08
System Uptime: 31-1-2012 18:45:04 (3 hours ago)
.
Motherboard: ASUSTeK Computer Inc. | | K52Jc
Processor: Intel(R) Pentium(R) CPU P6100 @ 2.00GHz | Socket 989 | 919/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 116 GiB total, 51,715 GiB free.
D: is FIXED (NTFS) - 328 GiB total, 326,549 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: ArcSec
Device ID: ROOT\LEGACY_ARCSEC\0000
Manufacturer:
Name: ArcSec
PNP Device ID: ROOT\LEGACY_ARCSEC\0000
Service: ArcSec
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0000
Manufacturer: Avira
Name: Microsoft Virtual WiFi Miniport Adapter #9 - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0000
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0001
Manufacturer: Avira
Name: Atheros AR9285 Wireless Network Adapter - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0001
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0002
Manufacturer: Avira
Name: Microsoft Virtual WiFi Miniport Adapter #4 - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0002
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0003
Manufacturer: Avira
Name: JMicron PCI Express Gigabit Ethernet Adapter - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0003
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0004
Manufacturer: Avira
Name: WAN-minipoort (IP) - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0004
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0005
Manufacturer: Avira
Name: WAN-minipoort (Network Monitor) - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0005
Service: avfwim
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: AvFw Packet Filter Miniport
Device ID: ROOT\AV_FLTDEV9MP\0006
Manufacturer: Avira
Name: WAN-minipoort (IPv6) - AvFw Packet Filter Miniport
PNP Device ID: ROOT\AV_FLTDEV9MP\0006
Service: avfwim
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: avfwot
Device ID: ROOT\LEGACY_AVFWOT\0000
Manufacturer:
Name: avfwot
PNP Device ID: ROOT\LEGACY_AVFWOT\0000
Service: avfwot
.
==== System Restore Points ===================
.
RP763: 29-1-2012 11:10:53 - Installed AVG 2012
RP764: 29-1-2012 11:12:04 - Removed AVG 2012
RP765: 29-1-2012 14:50:14 - Installed AVG 2012
RP766: 29-1-2012 14:51:03 - Installed AVG 2012
RP767: 29-1-2012 14:52:14 - Removed AVG 2012
RP768: 29-1-2012 15:16:08 - Before uninstalling ParetoLogic PC Health Advisor
RP769: 29-1-2012 15:24:11 - Installed AVG 2012
RP770: 29-1-2012 15:24:50 - Installed AVG 2012
RP771: 29-1-2012 15:26:13 - Removed AVG 2012
RP772: 29-1-2012 15:33:05 - Before uninstalling AVG PC Tuneup
RP773: 29-1-2012 15:52:08 - Installed AVG 2012
RP774: 29-1-2012 15:52:44 - Installed AVG 2012
RP775: 29-1-2012 15:54:22 - Removed AVG 2012
RP776: 29-1-2012 16:05:38 - Installed AVG 2012
RP777: 29-1-2012 16:06:12 - Installed AVG 2012
RP778: 29-1-2012 16:07:40 - Removed AVG 2012
RP779: 29-1-2012 16:20:45 - Installed AVG 2012
RP780: 29-1-2012 16:21:14 - Installed AVG 2012
RP781: 29-1-2012 16:22:07 - Removed AVG 2012
RP782: 29-1-2012 16:26:17 - Installed AVG 2012
RP783: 29-1-2012 16:26:43 - Installed AVG 2012
RP784: 29-1-2012 16:27:46 - Removed AVG 2012
RP785: 29-1-2012 17:22:20 - PC Health Advisor Backup
RP786: 29-1-2012 17:41:50 - PC Health Advisor Backup
RP787: 30-1-2012 23:11:04 - PC Health Advisor Backup
RP788: 30-1-2012 23:13:08 - PC Health Advisor Backup
.
==== Installed Programs ======================
.
Áîëåå 80 òåì äëÿ Windows 7. 2.00
Acrobat.com
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.2) - Nederlands
ASUS AI Recovery
ASUS AP Bank
ASUS CopyProtect
ASUS Data Security Manager
ASUS FancyStart
ASUS LifeFrame3
ASUS SmartLogon
ASUS Splendid Video Enhancement Technology
ASUS Virtual Camera
Atheros Driver Installation Program
ATK Package
AVG PC Tuneup
Bing Bar
Boingo Wi-Fi
Bookworm Deluxe
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco Network Magic
Cisco PEAP Module
ControlDeck
Cooking Dash
CursorFX
D3DX10
Driver Genius Pro 10.0.0.820
Driver Genius Professional Edition
DVD Shrink 2010
eReg
FileServe Toolbar
Game Park Console
Google Toolbar for Internet Explorer
Governor of Poker
GrabIt 1.7.2 Beta 4 (build 997)
HiJackThis
Hotel Dash Suite Success
HTC BMP USB Driver
HTC Driver Installer
HTC Sync
ImgBurn
IncrediMail
IncrediMail 2.0
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
IspAssistant-FileServe
Java Auto Updater
Java(TM) 6 Update 30
Jewel Quest 3
JMicron Ethernet Adapter NDIS Driver
JMicron Flash Media Controller Driver
Junk Mail filter update
LightScribe System Software
Luxor 3
Mahjongg dimensions
MailWasherPro
Malwarebytes Anti-Malware versie 1.60.0.1800
Mesh Runtime
Messenger Companion
Messenger Plus! 5
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MovieTracer
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
Network Magic
NewsLeecher v5.0 Beta 3
NTI Media Maker 8
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Updatus
ParetoLogic PC Health Advisor
Picasa 3
Plants vs Zombies
PMB
PMB-updater
Protection Center
Pure Networks Platform
Qualcomm Atheros Fast Reconnect
Qualcomm Atheros WiFi Driver Installation
Radio Online V7.5.2
Samsung Kies
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)
Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)
Setup
SpotLite
Spotnet
syncables desktop SE
TomTom HOME 2.8.3.2458
TomTom HOME Visual Studio Merge Modules
TuneUp Utilities Language Pack (nl-NL)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Vinny27 - Driver Genius PRO Edition v11.0.0.1112
Vinny27 - Driver Genius PRO v10.0.0.820 NL
Visual Studio 2008 x64 Redistributables
Visual Studio C++ 10.0 Runtime
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinFlash
WinRAR 4.01 (32-bit)
Wireless Console 3
World of Goo
Your Uninstaller! 7
.
==== End Of File ===========================
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:10:42, on 31-1-2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Program Files (x86)\FileServe Toolbar\FileServeVideoToMp3.exe
C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Stardock\CursorFX\CursorFX.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe
C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_160_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\theo\Desktop\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Woofi
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-82P43.exe" /REG /REGSVRMODE
O4 - HKCU\..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files (x86)\Stardock\CursorFX\CursorFX.exe"
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1721353367-264211606-25166001-1000\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: MailWasherPro.lnk = C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
Buienradar.nl - Weer - Actuele neerslag, weerbericht, weersverwachting, sneeuwradar en satellietbeelden
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - Unknown owner - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Trend Micro Solution Platform (Amsp) - Unknown owner - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AWiCSrvc - Atheros Communications - C:\Program Files (x86)\Atheros\AWiCSrvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileServe Toolbar Helper - Unknown owner - C:\Program Files (x86)\FileServe Toolbar\FileServeSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe (file missing)
O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - Unknown owner - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe
--
End of file - 16317 bytes
Malwarebytes Anti-Malware (PRO) 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Databaseversie: v2012.01.31.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
theo :: THEO-PC [administrator]
Realtime bescherming: Uitgeschakeld
31-1-2012 21:24:26
mbam-log-2012-01-31 (21-24-26).txt
Scantype: Volledige scan
Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scanopties: P2P
Objecten gescand: 346255
Verstreken tijd: 1 uur/uren, 51 minuut/minuten, 9 seconde
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 5
C:\Program Files\VS Revo Group\Revo Uninstaller Pro\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\FileServe Toolbar\ffmpeg.exe (Adware.Mp3Tube) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\FileServe Toolbar\ShowMsg.exe (PUP.Zwangi) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\ParetoLogic\PCHA\paretologic.pc.health.advisor.3.1.0.23.patch-SReg.exe (PUP.Hacktool.Patcher) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Program Files (x86)\Pure Networks\Network Magic\Patch.exe (Patch.NetworkMagic) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
hoop dat goed is groetjes theeke