|
Plagegeister aller Art und deren Bekämpfung: mail delivery failed: returning message to sender - web.de accountWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.03.2014, 06:45 | #1 |
| mail delivery failed: returning message to sender - web.de account Hallo Trojaner-Board-Team, habe seit ein paar Tagen das Problem, dass ich in meinem web.de-Account andauernd Benachrichtigungen über nicht zugestellte Spam?-Mails an beliebige Empfänger erhalte. Ich habe aber keine Mails versendet und schon gar nicht an die angegebenen mir unbekannten Adressen. Hier mal ein Beispiel: Mail delivery failed: returning message to sender Würde mich sehr freuen, wenn das Problem gelöst werden könnte! Vielen Dank im voraus! Freundeliche Grüße Michael |
14.03.2014, 07:33 | #2 |
/// the machine /// TB-Ausbilder | mail delivery failed: returning message to sender - web.de account hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.03.2014, 07:42 | #3 |
| mail delivery failed: returning message to sender - web.de account FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Michael Kempen (administrator) on MICHAELKEMPEN on 14-03-2014 06:39:34 Running from C:\Users\Michael Kempen\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Dutch Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Green Eclipse) C:\Program Files (x86)\StickyPad\StickyPad.exe (Bandoo Media Inc.) C:\Users\Michael Kempen\AppData\Local\iLivid\iLivid.exe (ArcSoft Inc.) C:\Program Files (x86)\ArcSoft\MediaConverter 4 Platinum\Monitor.exe (Dropbox, Inc.) C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Geek Software GmbH) C:\Program Files (x86)\pdf24\pdf24.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-09] (VIA) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\pdf24\pdf24.exe [162856 2013-02-19] (Geek Software GmbH) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-21] (AVAST Software) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\Run: [Sticky Pad] - C:\Program Files (x86)\StickyPad\StickyPad.exe [516153 2012-08-13] (Green Eclipse) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\Run: [iLivid] - C:\Users\Michael Kempen\AppData\Local\iLivid\iLivid.exe [6827008 2013-09-08] (Bandoo Media Inc.) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2164b8d4-8d4c-11e2-9cfa-08606ed7325f} - E:\LaunchU3.exe -a HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2ba6a1cc-8bda-11e2-ab7f-806e6f6e6963} - D:\Autorun.exe Startup: C:\Users\Michael Kempen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0E0DyBtAtByD0F0Bzz0BzytN0D0Tzu0CyByCtDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=7123389&ir= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://nl.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF5E3955AEB1FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0E0DyBtAtByD0F0Bzz0BzytN0D0Tzu0CyByCtDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=7123389&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0E0DyBtAtByD0F0Bzz0BzytN0D0Tzu0CyByCtDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=7123389&ir= SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0E0DyBtAtByD0F0Bzz0BzytN0D0Tzu0CyByCtDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=7123389&ir= SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutDzzyCtDyC0E0DyBtAtByD0F0Bzz0BzytN0D0Tzu0CyByCtDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=7123389&ir= SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {C1374C69-C05C-43BA-9D2A-C99E5BDD545F} URL = hxxp://www.google.nl/search?hl=nl&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://news.google.de/ CHR DefaultSearchURL: hxxp://www.google.nl/search?hl=nl&q={searchTerms} CHR DefaultNewTabURL: CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Extension: (Google Documenten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-29] CHR Extension: (Google Drive) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-29] CHR Extension: (TabletGuide pushberichten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglnombgigadbabocmfhaglkifjonoim [2014-02-01] CHR Extension: (YouTube) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-29] CHR Extension: (Extended Protection) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml [2014-01-29] CHR Extension: (Adblock Plus) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-26] CHR Extension: (Google Zoeken) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-29] CHR Extension: (avast! Online Security) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-29] CHR Extension: (Google Wallet) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-29] CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\MICHAE~1\AppData\Local\mysearchdial-speeddial.crx [2014-01-26] CHR HKCU\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\MICHAE~1\AppData\Local\mysearchdial-speeddial.crx [2014-01-26] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-01-15] CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\MICHAE~1\AppData\Local\mysearchdial-speeddial.crx [2014-01-26] ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-21] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-21] (AVAST Software) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-11-11] (VIA Technologies, Inc.) S2 Update RightSurf; "C:\Program Files (x86)\RightSurf\updateRightSurf.exe" [X] S2 Util RightSurf; "C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe" [X] ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-02-21] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-21] (AVAST Software) R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [440672 2014-02-21] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-21] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-21] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-15] () R3 DxVGrb; C:\Windows\System32\drivers\DxVGrb.sys [222464 2012-01-10] (Dexetek ) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-17] () R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-14 06:39 - 2014-03-14 06:40 - 00016458 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-14 06:39 - 2014-03-14 06:39 - 00000000 ____D () C:\FRST 2014-03-13 08:59 - 2014-03-13 09:01 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-12 06:27 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:27 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:27 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:27 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:27 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:27 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:27 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:27 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-12 06:27 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:27 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:27 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-12 06:27 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-12 06:27 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-12 06:27 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:27 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:27 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-12 06:27 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-12 06:27 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-12 06:27 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:27 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-12 06:27 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:27 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-12 06:27 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-10 16:41 - 2014-03-10 16:42 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:13 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 11:01 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-26 18:03 - 2014-02-27 18:02 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml 2014-02-15 18:01 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-15 18:01 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-15 13:35 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-15 13:35 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-15 13:35 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-15 13:35 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-15 13:35 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-15 13:35 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-15 13:35 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-15 13:35 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-15 13:35 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-15 13:35 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-15 13:35 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-15 13:34 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-15 13:34 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-15 13:34 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-15 13:34 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll ==================== One Month Modified Files and Folders ======= 2014-03-14 06:40 - 2014-03-14 06:39 - 00016458 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-14 06:39 - 2014-03-14 06:39 - 00000000 ____D () C:\FRST 2014-03-14 06:39 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-14 06:39 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-14 06:38 - 2013-07-03 04:39 - 00004014 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D20AD8BA-418C-4CB9-97A2-117293E3D896} 2014-03-14 06:37 - 2013-03-13 17:18 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-14 06:35 - 2013-03-13 13:42 - 01524438 _____ () C:\Windows\WindowsUpdate.log 2014-03-14 06:33 - 2013-05-25 15:31 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Dropbox 2014-03-14 06:33 - 2013-04-28 16:32 - 00000000 ___RD () C:\Users\Michael Kempen\Dropbox 2014-03-14 06:32 - 2014-01-15 07:38 - 00004350 _____ () C:\Windows\setupact.log 2014-03-14 06:32 - 2013-03-13 17:18 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-14 06:32 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-13 21:15 - 2013-03-13 14:16 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-13 09:01 - 2014-03-13 08:59 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-12 17:03 - 2013-04-05 08:51 - 00025600 _____ () C:\Users\Michael Kempen\Desktop\Hoogvliet.xls 2014-03-12 16:21 - 2009-07-14 05:45 - 00923144 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 07:15 - 2013-03-13 14:16 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 07:15 - 2013-03-13 14:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 07:15 - 2013-03-13 14:16 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 06:20 - 2014-01-14 22:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-12 06:19 - 2013-03-13 13:42 - 00000000 ____D () C:\Users\Michael Kempen 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-03-11 08:47 - 2013-08-07 04:56 - 00000000 ____D () C:\ProgramData\tmp 2014-03-10 16:42 - 2014-03-10 16:41 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 16:28 - 2011-04-12 14:00 - 00745764 _____ () C:\Windows\system32\perfh013.dat 2014-03-10 16:28 - 2011-04-12 14:00 - 00153716 _____ () C:\Windows\system32\perfc013.dat 2014-03-10 16:28 - 2009-07-14 06:13 - 01670960 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:13 - 2014-03-10 13:02 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:01 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-06 07:51 - 2013-10-12 06:54 - 00000000 ____D () C:\Users\Michael Kempen\Desktop\Word 2014-03-05 08:45 - 2013-04-02 12:12 - 00000000 ___RD () C:\Users\Michael Kempen\Desktop\Ongebruikt 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 10:25 - 2013-03-13 14:21 - 00243632 _____ () C:\Users\Michael Kempen\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-03-01 07:05 - 2014-03-12 06:27 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-12 06:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-12 06:27 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-12 06:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-12 06:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-12 06:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-12 06:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-12 06:27 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-12 06:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-12 06:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-12 06:27 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-12 06:27 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-12 06:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-12 06:27 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-12 06:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-12 06:27 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-12 06:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:27 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-12 06:27 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-12 06:27 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-12 06:27 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-12 06:27 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-12 06:27 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-12 06:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:27 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-12 06:27 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-12 06:27 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:27 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:27 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-12 06:27 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-12 06:27 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 18:02 - 2014-02-26 18:03 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-26 18:21 - 2014-01-15 09:54 - 00342710 _____ () C:\Windows\PFRO.log 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-21 14:07 - 2014-01-15 12:48 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-21 14:07 - 2013-03-13 14:09 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-17 16:32 - 2013-03-13 17:18 - 00004068 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 16:32 - 2013-03-13 17:18 - 00003816 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-16 18:01 - 2013-08-06 17:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 18:00 - 2013-03-13 15:37 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml 2014-02-15 19:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache Some content of TEMP: ==================== C:\Users\Michael Kempen\AppData\Local\Temp\82504uninstall.exe C:\Users\Michael Kempen\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaf0jby.dll C:\Users\Michael Kempen\AppData\Local\Temp\Quarantine.exe C:\Users\Michael Kempen\AppData\Local\Temp\Sqlite3.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-10 07:19 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Michael Kempen at 2014-03-14 06:40:16 Running from C:\Users\Michael Kempen\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Internet Security (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Internet Security (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: avast! Internet Security (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} ==================== Installed Programs ====================== Aangifte inkomstenbelasting 2012 (HKLM-x32\...\Aangifte inkomstenbelasting 2012) (Version: - Belastingdienst) Aangifte inkomstenbelasting 2013 (HKLM-x32\...\Aangifte inkomstenbelasting 2013) (Version: - Belastingdienst) Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Albelli Fotoboeken (HKCU\...\{B7961CCE-CF36-4858-BC1A-D06D3D25ECE5}_is1) (Version: - Albelli) AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Fuel (Version: 2012.1219.1521.27485 - Uw bedrijfsnaam) Hidden AMD Media Foundation Decoders (Version: 1.0.71219.1540 - Advanced Micro Devices, Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2012.1219.1521.27485 - Uw bedrijfsnaam) Hidden Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArcSoft MediaConverter 4 Platinum (HKLM-x32\...\{92C2E624-CC06-4309-BE91-A33EA04572F1}) (Version: 4.0.24.215 - ArcSoft) ArcSoft PhotoBase 3 (HKLM-x32\...\{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}) (Version: - ) ArcSoft PhotoStudio 5 (HKLM-x32\...\{03F1CC67-5BD8-4C36-8394-76311B2AE69A}) (Version: - ) ArcSoft ShowBiz (HKLM-x32\...\{9D41D2EF-2D33-4CFD-8A3E-C7E6FCC3303B}) (Version: - ArcSoft) Ashampoo Burning Studio Elements 10.0.9 (HKLM-x32\...\Ashampoo Burning Studio Elements_is1) (Version: 3.1.1 - Ashampoo GmbH & Co. KG) avast! Internet Security (HKLM-x32\...\avast) (Version: 9.0.2013 - Avast Software) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform) Cewe Fotoservice (HKLM-x32\...\Cewe Fotoservice) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG) Compatibiliteitspakket voor het 2007 Microsoft Office system (HKLM-x32\...\{90120000-0020-0413-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Conexant Polaris Unused CIR Function (HKLM\...\VID_1D19&PID_6108&MI_00) (Version: 1.0.0.0 - Conexant Systems) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.6.5 - Dropbox, Inc.) EnterImage 3.0 (HKLM-x32\...\EnterImage 3.0_is1) (Version: - Entersite Design) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.) Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden iLivid (HKCU\...\iLivid) (Version: 5.0.0.4286 - Bandoo Media Inc) <==== ATTENTION iLivid (HKLM-x32\...\iLivid) (Version: 5.0.0.3958 - Bandoo Media Inc) <==== ATTENTION IncrediMail (x32 Version: 6.6.0.5273 - IncrediMail) Hidden IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5273 - IncrediMail Ltd.) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Kurso de Esperanto 4 (HKLM-x32\...\{021F206C-3243-420E-9F0B-82639583E425}_is1) (Version: 4.1.2 - Esperanto) LibreOffice 4.0.1.2 (HKLM-x32\...\{604B2A5C-B1CE-45B2-ADCC-6B7C721AC3AC}) (Version: 4.0.1.2 - The Document Foundation) MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{6F9F914A-D8FA-468D-9584-9E6E290263F8}) (Version: 7.0.1.29 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.1.29 - MAGIX AG) Hidden MAGIX USB-Videowandler 2 (HKLM-x32\...\{38874054-65D0-45D0-9486-FBEFD42A2251}) (Version: 1.03.0000 - Uw bedrijfsnaam) MAGIX Video easy Red uw video's 6 (HKLM-x32\...\MAGIX_{4F394EC0-28F2-44D1-BAB9-42C65CA2371E}) (Version: 4.0.1.86 - MAGIX AG) MAGIX Video easy Red uw video's 6 (Version: 4.0.1.86 - MAGIX AG) Hidden MAGIX Video easy Rescue Your Videotapes 6 Update (Version: 4.0.2.92 - MAGIX AG) Hidden Malwarebytes Anti-Malware versie 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (NLD) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office FrontPage 2003 (HKLM-x32\...\{90170413-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Professional Editie 2003 (HKLM-x32\...\{90110413-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) PDF24 Creator 5.3.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.) Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - Uw bedrijfsnaam) Hidden Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.52.203.2012 - Realtek) Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) simplitec simplicheck (HKLM-x32\...\{CDFF966D-6D05-4E17-B9E2-B1F2A9B92B4B}) (Version: 1.3.10.0 - simplitec GmbH) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) StickyPad (HKLM-x32\...\{F33AFEF6-ECC6-40C4-9C08-A4DC9D21F7EE}) (Version: 2.3.53 - Green Eclipse) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer) VIA Platform apparaatbeheer (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Video Grabber (HKLM\...\VID_1D19&PID_6108&MI_01) (Version: 1.0.0.0 - Conexant Systems) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Restore Points ========================= 27-02-2014 17:00:12 Windows Update 04-03-2014 06:14:23 Windows Update 07-03-2014 06:59:23 Windows Update 11-03-2014 06:07:46 Windows Update 11-03-2014 17:47:59 avast! antivirus system restore point 12-03-2014 05:16:50 Herstelbewerking 12-03-2014 12:17:59 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {14F9C374-48AE-4E5F-9178-CC4622BE6AF3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-13] (Google Inc.) Task: {32726CC5-AC2C-4C3B-9ECD-5A444EDA9DEB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-02-25] (Piriform Ltd) Task: {4E58D70C-C0DD-4074-9F54-7419F42BBFBF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {515D1F5A-8B1A-4362-ADA8-4B1B00E313D4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-13] (Google Inc.) Task: {60C9A27F-D869-4F57-92EE-7627140ED72F} - \BrowserProtect No Task File Task: {8F42A6D9-001B-4B19-BEE7-A3956DC7A0D5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-21] (AVAST Software) Task: {C63DDEFF-66CE-4123-8A0D-CF810F336127} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-12-19 15:32 - 2012-12-19 15:32 - 00210944 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll 2012-10-17 18:39 - 2012-10-17 18:39 - 00749056 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll 2012-10-17 18:39 - 2012-10-17 18:39 - 03645952 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll 2013-03-13 14:04 - 2011-12-06 02:58 - 00078448 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2013-03-13 14:04 - 2011-12-06 02:58 - 00386160 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2012-12-19 15:32 - 2012-12-19 15:32 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-03-13 18:50 - 2014-03-13 09:22 - 02186752 _____ () C:\Program Files\AVAST Software\Avast\defs\14031300\algo.dll 2014-03-14 06:32 - 2014-03-13 18:32 - 02186752 _____ () C:\Program Files\AVAST Software\Avast\defs\14031301\algo.dll 2014-03-14 06:32 - 2014-03-14 06:32 - 00041984 _____ () C:\Users\Michael Kempen\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaf0jby.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\libcef.dll 2014-01-15 12:48 - 2014-01-15 12:48 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libglesv2.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\libegl.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll 2014-03-04 07:39 - 2014-03-02 03:35 - 13632840 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 AlternateDataStreams: C:\Users\Michael Kempen\Downloads\noname.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: USB-controller Description: USB-controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/14/2014 06:33:46 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/13/2014 06:52:12 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/13/2014 06:43:10 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 04:21:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 06:21:10 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 06:04:07 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/11/2014 02:14:34 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/11/2014 08:47:48 AM) (Source: Application Error) (User: ) Description: Naam van toepassing met fout: Cewe Fotoservice.exe, versie: 0.0.0.0, tijdstempel: 0x51cc87fa Naam van module met fout: CWFoto0.dll, versie: 0.1.0.0, tijdstempel: 0x51cc81cb Uitzonderingscode: 0xc0000005 Foutoffset: 0x000286db Id van proces met fout: 0x13e4 Starttijd van toepassing met fout: 0xCewe Fotoservice.exe0 Pad naar toepassing met fout: Cewe Fotoservice.exe1 Pad naar module met fout: Cewe Fotoservice.exe2 Rapport-id: Cewe Fotoservice.exe3 Error: (03/11/2014 07:05:05 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/10/2014 02:36:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/14/2014 06:32:07 AM) (Source: Service Control Manager) (User: ) Description: De Util RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/14/2014 06:32:07 AM) (Source: Service Control Manager) (User: ) Description: De Update RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/13/2014 06:50:37 PM) (Source: Service Control Manager) (User: ) Description: De Util RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/13/2014 06:50:37 PM) (Source: Service Control Manager) (User: ) Description: De Update RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/13/2014 06:41:34 AM) (Source: Service Control Manager) (User: ) Description: De Util RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/13/2014 06:41:34 AM) (Source: Service Control Manager) (User: ) Description: De Update RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/12/2014 04:20:51 PM) (Source: Service Control Manager) (User: ) Description: De Util RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/12/2014 04:20:51 PM) (Source: Service Control Manager) (User: ) Description: De Update RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/12/2014 06:19:35 AM) (Source: Service Control Manager) (User: ) Description: De Util RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Error: (03/12/2014 06:19:35 AM) (Source: Service Control Manager) (User: ) Description: De Update RightSurf-service kan vanwege de volgende fout niet worden gestart: %%2 Microsoft Office Sessions: ========================= Error: (03/14/2014 06:33:46 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/13/2014 06:52:12 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/13/2014 06:43:10 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 04:21:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 06:21:10 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/12/2014 06:04:07 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/11/2014 02:14:34 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/11/2014 08:47:48 AM) (Source: Application Error)(User: ) Description: Cewe Fotoservice.exe0.0.0.051cc87faCWFoto0.dll0.1.0.051cc81cbc0000005000286db13e401cf3cfe2e7f91b5C:\Program Files (x86)\Cewe Fotoservice\Cewe Fotoservice\Cewe Fotoservice.exeC:\Program Files (x86)\Cewe Fotoservice\Cewe Fotoservice\CWFoto0.dll70426010-a8f1-11e3-8704-08606ed7325f Error: (03/11/2014 07:05:05 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/10/2014 02:36:46 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8174.12 MB Available physical RAM: 5768.74 MB Total Pagefile: 16346.41 MB Available Pagefile: 13573.11 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:731.51 GB) (Free:469.08 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DVD Maker) (CDROM) (Total:0.16 GB) (Free:0 GB) CDFS Drive g: (HEMA 2 GB) (Removable) (Total:1.89 GB) (Free:0.86 GB) FAT Drive m: (200 GB HDD) (Fixed) (Total:199 GB) (Free:183.64 GB) NTFS Drive n: (1 GB HDD) (Fixed) (Total:1 GB) (Free:0.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 66C07E91) Partition 1: (Active) - (Size=732 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=199 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=1 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 2 GB) (Disk ID: 8BBF40D9) Partition 1: (Active) - (Size=2 GB) - (Type=06) ==================== End Of Log ============================ |
15.03.2014, 11:28 | #4 |
/// the machine /// TB-Ausbilder | mail delivery failed: returning message to sender - web.de account Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.03.2014, 13:37 | #5 |
| mail delivery failed: returning message to sender - web.de account Malwarebytes Anti-Malware 1.75.0.1300 Malwarebytes : Free Anti-Malware Datenbank Version: v2014.03.15.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16521 Michael Kempen :: MICHAELKEMPEN [Administrator] 15-3-2014 12:19:12 mbam-log-2014-03-15 (12-19-12).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 218419 Laufzeit: 3 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 7 HKCR\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B} (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0} (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SYSTEM\CurrentControlSet\Services\Update RightSurf (PUP.Optional.RightSurf.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0R0DtO0U1C1S1U1StR0J1Q2P1J1K1I2R -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 2 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.MySearchDial.A) -> Bösartig: (Mysearchdial Search) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.MySearchDial.A) -> Bösartig: (Mysearchdial Search) Gut: (Google) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 6 C:\Users\Michael Kempen\AppData\Roaming\mysearchdial (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Roaming\mysearchdial\icons_2.2.15.1631 (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.4_0 (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService\update (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 13 C:\Users\Michael Kempen\AppData\Local\Temp\fullpackage_temp1391007627\package1.zip (PUP.Optional.SkyTech.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Temp\iLivid\iLividSetup.exe (PUP.Optional.Bandoo) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\Downloads\iLividSetup-r161-n-bc.exe (PUP.Optional.Bandoo) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\Downloads\SallandoItalic_Font_Installer.exe (PUP.Optional.Freemium.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx (PUP.Optional.NewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\mysearchdial-speeddial.crx (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Roaming\mysearchdial\icons_2.2.15.1631\62.ico (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Roaming\mysearchdial\icons_2.2.15.1631\80.ico (PUP.Optional.MySearchDial.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.4_0\background.html (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.4_0\data.json (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.4_0\icon128.png (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.4_0\manifest.json (PUP.Optional.Lightning.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\IePluginService\update\conf (PUP.Optional.IePluginService.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.022 - Report created 15/03/2014 at 12:43:17 # Updated 13/03/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Michael Kempen - MICHAELKEMPEN # Running from : C:\Users\Michael Kempen\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** [#] Service Deleted : Util RightSurf ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\WPM Folder Deleted : C:\Program Files (x86)\SupTab Folder Deleted : C:\Program Files (x86)\Surftastic Folder Deleted : C:\Users\Michael Kempen\AppData\Local\iLivid Folder Deleted : C:\Users\Michael Kempen\AppData\Local\SwvUpdater Folder Deleted : C:\Users\MICHAE~1\AppData\Local\Temp\iLivid Folder Deleted : C:\Users\Michael Kempen\Documents\PC Speed Maximizer File Deleted : C:\Users\Michael Kempen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff Key Deleted : HKCU\Software\Classes\iLivid.torrent Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [iLivid] Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ilivid Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16521 Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Google Chrome v33.0.1750.154 [ File : C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2828 octets] - [15/03/2014 12:41:37] AdwCleaner[S0].txt - [2284 octets] - [15/03/2014 12:43:17] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2344 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.2 (02.20.2014:1) OS: Windows 7 Home Premium x64 Ran by Michael Kempen on za 15-03-2014 at 13:28:41,10 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1758146858-1784735532-1013142320-1000\Software\sweetim ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on za 15-03-2014 at 13:34:53,37 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Michael Kempen (administrator) on MICHAELKEMPEN on 15-03-2014 13:35:42 Running from C:\Users\Michael Kempen\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Dutch Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Green Eclipse) C:\Program Files (x86)\StickyPad\StickyPad.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (ArcSoft Inc.) C:\Program Files (x86)\ArcSoft\MediaConverter 4 Platinum\Monitor.exe (Dropbox, Inc.) C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Geek Software GmbH) C:\Program Files (x86)\pdf24\pdf24.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-09] (VIA) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\pdf24\pdf24.exe [162856 2013-02-19] (Geek Software GmbH) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-21] (AVAST Software) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\Run: [Sticky Pad] - C:\Program Files (x86)\StickyPad\StickyPad.exe [516153 2012-08-13] (Green Eclipse) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2164b8d4-8d4c-11e2-9cfa-08606ed7325f} - E:\LaunchU3.exe -a HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2ba6a1cc-8bda-11e2-ab7f-806e6f6e6963} - D:\Autorun.exe Startup: C:\Users\Michael Kempen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF5E3955AEB1FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Google SearchScopes: HKCU - {C1374C69-C05C-43BA-9D2A-C99E5BDD545F} URL = hxxp://www.google.nl/search?hl=nl&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://news.google.de/ CHR DefaultSearchURL: hxxp://www.google.nl/search?hl=nl&q={searchTerms} CHR DefaultNewTabURL: CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Extension: (Google Documenten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-29] CHR Extension: (Google Drive) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-29] CHR Extension: (TabletGuide pushberichten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglnombgigadbabocmfhaglkifjonoim [2014-02-01] CHR Extension: (YouTube) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-29] CHR Extension: (Adblock Plus) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-26] CHR Extension: (Google Zoeken) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-29] CHR Extension: (avast! Online Security) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-29] CHR Extension: (Google Wallet) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-29] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-01-15] ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-21] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-21] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-11-11] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-02-21] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-21] (AVAST Software) R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [440672 2014-02-21] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-21] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-21] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-15] () R3 DxVGrb; C:\Windows\System32\drivers\DxVGrb.sys [222464 2012-01-10] (Dexetek ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-17] () R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-15 13:34 - 2014-03-15 13:34 - 00001146 _____ () C:\Users\Michael Kempen\Desktop\JRT.txt 2014-03-15 13:27 - 2014-03-15 13:27 - 00000000 ____D () C:\Windows\ERUNT 2014-03-15 13:26 - 2014-03-15 13:26 - 01037734 _____ (Thisisu) C:\Users\Michael Kempen\Downloads\JRT.exe 2014-03-15 12:41 - 2014-03-15 12:44 - 00000000 ____D () C:\AdwCleaner 2014-03-15 12:40 - 2014-03-15 12:40 - 01950720 _____ () C:\Users\Michael Kempen\Downloads\adwcleaner.exe 2014-03-15 12:17 - 2014-03-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-15 12:17 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-15 12:09 - 2014-03-15 12:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Michael Kempen\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-14 08:17 - 2014-03-14 08:17 - 00075310 _____ () C:\Users\Michael Kempen\Downloads\NuevaStd-Regular.otf 2014-03-14 06:40 - 2014-03-14 06:40 - 00027489 _____ () C:\Users\Michael Kempen\Downloads\Addition.txt 2014-03-14 06:39 - 2014-03-15 13:35 - 00014227 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-14 06:39 - 2014-03-15 13:35 - 00000000 ____D () C:\FRST 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-13 08:59 - 2014-03-15 11:28 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-12 06:27 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:27 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:27 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:27 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:27 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:27 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:27 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:27 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-12 06:27 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:27 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:27 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-12 06:27 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-12 06:27 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-12 06:27 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:27 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:27 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-12 06:27 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-12 06:27 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-12 06:27 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:27 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-12 06:27 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:27 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-12 06:27 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-10 16:41 - 2014-03-10 16:42 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:13 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 11:01 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-26 18:03 - 2014-02-27 18:02 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml 2014-02-15 18:01 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-15 18:01 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-15 13:35 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-15 13:35 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-15 13:35 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-15 13:35 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-15 13:35 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-15 13:35 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-15 13:35 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-15 13:35 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-15 13:35 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-15 13:35 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-15 13:35 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-15 13:35 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-15 13:35 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-15 13:35 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-15 13:35 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-15 13:34 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-15 13:34 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-15 13:34 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-15 13:34 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll ==================== One Month Modified Files and Folders ======= 2014-03-15 13:36 - 2014-03-14 06:39 - 00014227 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-15 13:35 - 2014-03-14 06:39 - 00000000 ____D () C:\FRST 2014-03-15 13:34 - 2014-03-15 13:34 - 00001146 _____ () C:\Users\Michael Kempen\Desktop\JRT.txt 2014-03-15 13:27 - 2014-03-15 13:27 - 00000000 ____D () C:\Windows\ERUNT 2014-03-15 13:26 - 2014-03-15 13:26 - 01037734 _____ (Thisisu) C:\Users\Michael Kempen\Downloads\JRT.exe 2014-03-15 13:26 - 2013-05-25 15:31 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Dropbox 2014-03-15 13:26 - 2013-04-28 16:32 - 00000000 ___RD () C:\Users\Michael Kempen\Dropbox 2014-03-15 13:26 - 2013-03-13 17:18 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-15 13:15 - 2013-03-13 14:16 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-15 12:53 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-15 12:53 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-15 12:46 - 2014-01-15 07:38 - 00004518 _____ () C:\Windows\setupact.log 2014-03-15 12:46 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-15 12:45 - 2013-03-13 13:42 - 01595773 _____ () C:\Windows\WindowsUpdate.log 2014-03-15 12:44 - 2014-03-15 12:41 - 00000000 ____D () C:\AdwCleaner 2014-03-15 12:40 - 2014-03-15 12:40 - 01950720 _____ () C:\Users\Michael Kempen\Downloads\adwcleaner.exe 2014-03-15 12:37 - 2014-01-15 09:54 - 00348664 _____ () C:\Windows\PFRO.log 2014-03-15 12:21 - 2013-07-03 04:39 - 00004014 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D20AD8BA-418C-4CB9-97A2-117293E3D896} 2014-03-15 12:17 - 2014-03-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-15 12:09 - 2014-03-15 12:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Michael Kempen\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-15 11:37 - 2013-03-13 17:18 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-15 11:28 - 2014-03-13 08:59 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-15 09:36 - 2013-03-13 17:08 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Local\Windows Live 2014-03-15 09:21 - 2013-10-12 06:54 - 00000000 ____D () C:\Users\Michael Kempen\Desktop\Word 2014-03-15 08:39 - 2009-07-14 05:45 - 00923168 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 15:24 - 2011-04-12 14:00 - 00745764 _____ () C:\Windows\system32\perfh013.dat 2014-03-14 15:24 - 2011-04-12 14:00 - 00153716 _____ () C:\Windows\system32\perfc013.dat 2014-03-14 15:24 - 2009-07-14 06:13 - 01670960 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-14 11:12 - 2013-03-13 14:21 - 00243632 _____ () C:\Users\Michael Kempen\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-14 08:17 - 2014-03-14 08:17 - 00075310 _____ () C:\Users\Michael Kempen\Downloads\NuevaStd-Regular.otf 2014-03-14 06:40 - 2014-03-14 06:40 - 00027489 _____ () C:\Users\Michael Kempen\Downloads\Addition.txt 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-12 17:03 - 2013-04-05 08:51 - 00025600 _____ () C:\Users\Michael Kempen\Desktop\Hoogvliet.xls 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 07:15 - 2013-03-13 14:16 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 07:15 - 2013-03-13 14:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 07:15 - 2013-03-13 14:16 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 06:20 - 2014-01-14 22:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-12 06:19 - 2013-03-13 13:42 - 00000000 ____D () C:\Users\Michael Kempen 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-03-11 08:47 - 2013-08-07 04:56 - 00000000 ____D () C:\ProgramData\tmp 2014-03-10 16:42 - 2014-03-10 16:41 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:13 - 2014-03-10 13:02 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:01 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-05 08:45 - 2013-04-02 12:12 - 00000000 ___RD () C:\Users\Michael Kempen\Desktop\Ongebruikt 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-03-01 07:05 - 2014-03-12 06:27 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-12 06:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-12 06:27 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-12 06:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-12 06:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-12 06:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-12 06:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-12 06:27 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-12 06:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-12 06:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-12 06:27 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-12 06:27 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-12 06:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-12 06:27 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-12 06:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-12 06:27 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-12 06:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:27 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-12 06:27 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-12 06:27 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-12 06:27 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-12 06:27 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-12 06:27 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-12 06:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:27 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-12 06:27 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-12 06:27 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:27 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:27 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-12 06:27 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-12 06:27 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 18:02 - 2014-02-26 18:03 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-21 14:07 - 2014-01-15 12:48 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-21 14:07 - 2013-03-13 14:09 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-17 16:32 - 2013-03-13 17:18 - 00004068 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 16:32 - 2013-03-13 17:18 - 00003816 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-16 18:01 - 2013-08-06 17:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 18:00 - 2013-03-13 15:37 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml 2014-02-15 19:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache Some content of TEMP: ==================== C:\Users\Michael Kempen\AppData\Local\Temp\82504uninstall.exe C:\Users\Michael Kempen\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjcf2ho.dll C:\Users\Michael Kempen\AppData\Local\Temp\Quarantine.exe C:\Users\Michael Kempen\AppData\Local\Temp\Sqlite3.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-10 07:19 ==================== End Of Log ============================ --- --- --- |
15.03.2014, 17:52 | #6 |
/// the machine /// TB-Ausbilder | mail delivery failed: returning message to sender - web.de accountESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> mail delivery failed: returning message to sender - web.de account |
18.03.2014, 18:39 | #7 |
| mail delivery failed: returning message to sender - web.de account ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5a42d2e3d946aa469f38d7d8ec89b3a2 # engine=17462 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-03-15 06:21:38 # local_time=2014-03-15 07:21:38 (+0100, West-Europa (standaardtijd)) # country="Netherlands" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 82 309789 1923251 0 0 # compatibility_mode=5893 16776573 100 94 27121 146537548 0 0 # scanned=144841 # found=0 # cleaned=0 # scan_time=2560 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=5a42d2e3d946aa469f38d7d8ec89b3a2 # engine=17495 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-03-18 05:30:43 # local_time=2014-03-18 06:30:43 (+0100, West-Europa (standaardtijd)) # country="Netherlands" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=772 16777213 83 82 562334 2179396 0 0 # compatibility_mode=5893 16776573 100 94 36062 146793693 0 0 # scanned=270781 # found=1 # cleaned=0 # scan_time=4523 sh=736D658CC686191A4DDB5AE090BCE1DBB1631092 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\zoek_backup\C_PROGRA~2_Yontoo\YontooLayers.crx" Results of screen317's Security Check version 0.99.80 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Internet Security Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` SpywareBlaster 5.0 Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Reader XI Google Chrome 33.0.1750.146 Google Chrome 33.0.1750.154 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast afwServ.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 0% ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Michael Kempen (administrator) on MICHAELKEMPEN on 18-03-2014 18:38:24 Running from C:\Users\Michael Kempen\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: Dutch Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Green Eclipse) C:\Program Files (x86)\StickyPad\StickyPad.exe (ArcSoft Inc.) C:\Program Files (x86)\ArcSoft\MediaConverter 4 Platinum\Monitor.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Dropbox, Inc.) C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Geek Software GmbH) C:\Program Files (x86)\pdf24\pdf24.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-09] (VIA) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\pdf24\pdf24.exe [162856 2013-02-19] (Geek Software GmbH) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-21] (AVAST Software) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\Run: [Sticky Pad] - C:\Program Files (x86)\StickyPad\StickyPad.exe [516153 2012-08-13] (Green Eclipse) HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2164b8d4-8d4c-11e2-9cfa-08606ed7325f} - E:\LaunchU3.exe -a HKU\S-1-5-21-1758146858-1784735532-1013142320-1000\...\MountPoints2: {2ba6a1cc-8bda-11e2-ab7f-806e6f6e6963} - D:\Autorun.exe Startup: C:\Users\Michael Kempen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Michael Kempen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN NL: Hotmail, Outlook, Skype, het laatste nieuws, entertainment en meer! HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF5E3955AEB1FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Google SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Google SearchScopes: HKCU - {C1374C69-C05C-43BA-9D2A-C99E5BDD545F} URL = hxxp://www.google.nl/search?hl=nl&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://news.google.de/ CHR DefaultSearchURL: hxxp://www.google.nl/search?hl=nl&q={searchTerms} CHR DefaultNewTabURL: CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Extension: (Google Documenten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-29] CHR Extension: (Google Drive) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-29] CHR Extension: (TabletGuide pushberichten) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglnombgigadbabocmfhaglkifjonoim [2014-02-01] CHR Extension: (YouTube) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-29] CHR Extension: (Adblock Plus) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-26] CHR Extension: (Google Zoeken) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-29] CHR Extension: (avast! Online Security) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-29] CHR Extension: (Google Wallet) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR Extension: (Gmail) - C:\Users\Michael Kempen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-29] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-01-15] ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-21] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-21] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-11-11] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-02-21] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-21] (AVAST Software) R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [440672 2014-02-21] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-01-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-01-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-21] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-21] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-12-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-15] () R3 DxVGrb; C:\Windows\System32\drivers\DxVGrb.sys [222464 2012-01-10] (Dexetek ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-17] () R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-18 18:34 - 2014-03-18 18:34 - 00987442 _____ () C:\Users\Michael Kempen\Downloads\SecurityCheck.exe 2014-03-15 18:34 - 2014-03-15 18:34 - 02347384 _____ (ESET) C:\Users\Michael Kempen\Downloads\esetsmartinstaller_enu.exe 2014-03-15 13:34 - 2014-03-15 13:34 - 00001146 _____ () C:\Users\Michael Kempen\Desktop\JRT.txt 2014-03-15 13:27 - 2014-03-15 13:27 - 00000000 ____D () C:\Windows\ERUNT 2014-03-15 13:26 - 2014-03-15 13:26 - 01037734 _____ (Thisisu) C:\Users\Michael Kempen\Downloads\JRT.exe 2014-03-15 12:41 - 2014-03-15 12:44 - 00000000 ____D () C:\AdwCleaner 2014-03-15 12:40 - 2014-03-15 12:40 - 01950720 _____ () C:\Users\Michael Kempen\Downloads\adwcleaner.exe 2014-03-15 12:17 - 2014-03-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-15 12:17 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-15 12:09 - 2014-03-15 12:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Michael Kempen\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-14 08:17 - 2014-03-14 08:17 - 00075310 _____ () C:\Users\Michael Kempen\Downloads\NuevaStd-Regular.otf 2014-03-14 06:40 - 2014-03-14 06:40 - 00027489 _____ () C:\Users\Michael Kempen\Downloads\Addition.txt 2014-03-14 06:39 - 2014-03-18 18:38 - 00014390 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-14 06:39 - 2014-03-18 18:38 - 00000000 ____D () C:\FRST 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-13 08:59 - 2014-03-16 13:54 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-12 06:27 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-12 06:27 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-12 06:27 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-12 06:27 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-12 06:27 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-12 06:27 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-12 06:27 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-12 06:27 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-12 06:27 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-12 06:27 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-12 06:27 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-12 06:27 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-12 06:27 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-12 06:27 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-12 06:27 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-12 06:27 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-12 06:27 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-12 06:27 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-12 06:27 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-12 06:27 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-12 06:27 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-12 06:27 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-12 06:27 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-12 06:27 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-12 06:27 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-12 06:27 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-12 06:27 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-12 06:27 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-12 06:27 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-12 06:27 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-12 06:27 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-12 06:27 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-12 06:27 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-12 06:27 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-10 16:41 - 2014-03-10 16:42 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:13 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 11:01 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-26 18:03 - 2014-02-27 18:02 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml ==================== One Month Modified Files and Folders ======= 2014-03-18 18:38 - 2014-03-14 06:39 - 00014390 _____ () C:\Users\Michael Kempen\Downloads\FRST.txt 2014-03-18 18:38 - 2014-03-14 06:39 - 00000000 ____D () C:\FRST 2014-03-18 18:37 - 2013-03-13 17:18 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-18 18:34 - 2014-03-18 18:34 - 00987442 _____ () C:\Users\Michael Kempen\Downloads\SecurityCheck.exe 2014-03-18 18:30 - 2013-07-03 04:39 - 00004014 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D20AD8BA-418C-4CB9-97A2-117293E3D896} 2014-03-18 18:15 - 2013-03-13 14:16 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-18 18:04 - 2013-03-13 13:42 - 01711593 _____ () C:\Windows\WindowsUpdate.log 2014-03-18 18:01 - 2013-08-06 17:02 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 18:00 - 2013-03-13 15:37 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-18 17:16 - 2011-04-12 14:00 - 00745764 _____ () C:\Windows\system32\perfh013.dat 2014-03-18 17:16 - 2011-04-12 14:00 - 00153716 _____ () C:\Windows\system32\perfc013.dat 2014-03-18 17:16 - 2009-07-14 06:13 - 01670960 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-18 16:37 - 2013-03-13 17:18 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-18 05:24 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-18 05:24 - 2009-07-14 05:45 - 00022736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-18 05:18 - 2013-05-25 15:31 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Dropbox 2014-03-18 05:18 - 2013-04-28 16:32 - 00000000 ___RD () C:\Users\Michael Kempen\Dropbox 2014-03-18 05:16 - 2014-01-15 07:38 - 00004686 _____ () C:\Windows\setupact.log 2014-03-18 05:16 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-17 07:35 - 2014-01-14 22:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-03-16 13:54 - 2014-03-13 08:59 - 00018432 _____ () C:\Users\Michael Kempen\Desktop\Welke Museums wil ik kijken.xls 2014-03-16 08:22 - 2013-04-05 08:51 - 00025600 _____ () C:\Users\Michael Kempen\Desktop\Hoogvliet.xls 2014-03-15 18:34 - 2014-03-15 18:34 - 02347384 _____ (ESET) C:\Users\Michael Kempen\Downloads\esetsmartinstaller_enu.exe 2014-03-15 13:34 - 2014-03-15 13:34 - 00001146 _____ () C:\Users\Michael Kempen\Desktop\JRT.txt 2014-03-15 13:27 - 2014-03-15 13:27 - 00000000 ____D () C:\Windows\ERUNT 2014-03-15 13:26 - 2014-03-15 13:26 - 01037734 _____ (Thisisu) C:\Users\Michael Kempen\Downloads\JRT.exe 2014-03-15 12:44 - 2014-03-15 12:41 - 00000000 ____D () C:\AdwCleaner 2014-03-15 12:40 - 2014-03-15 12:40 - 01950720 _____ () C:\Users\Michael Kempen\Downloads\adwcleaner.exe 2014-03-15 12:37 - 2014-01-15 09:54 - 00348664 _____ () C:\Windows\PFRO.log 2014-03-15 12:17 - 2014-03-15 12:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-15 12:09 - 2014-03-15 12:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Michael Kempen\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-15 09:36 - 2013-03-13 17:08 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Local\Windows Live 2014-03-15 09:21 - 2013-10-12 06:54 - 00000000 ____D () C:\Users\Michael Kempen\Desktop\Word 2014-03-15 08:39 - 2009-07-14 05:45 - 00923168 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 11:12 - 2013-03-13 14:21 - 00243632 _____ () C:\Users\Michael Kempen\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-14 08:17 - 2014-03-14 08:17 - 00075310 _____ () C:\Users\Michael Kempen\Downloads\NuevaStd-Regular.otf 2014-03-14 06:40 - 2014-03-14 06:40 - 00027489 _____ () C:\Users\Michael Kempen\Downloads\Addition.txt 2014-03-14 06:39 - 2014-03-14 06:39 - 02157056 _____ (Farbar) C:\Users\Michael Kempen\Downloads\FRST64.exe 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-12 16:20 - 2013-03-13 17:33 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 07:15 - 2013-03-13 14:16 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 07:15 - 2013-03-13 14:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 07:15 - 2013-03-13 14:16 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 06:19 - 2013-03-13 13:42 - 00000000 ____D () C:\Users\Michael Kempen 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-12 06:18 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-03-11 08:47 - 2013-08-07 04:56 - 00000000 ____D () C:\ProgramData\tmp 2014-03-10 16:42 - 2014-03-10 16:41 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\EnterImage 2014-03-10 16:41 - 2014-03-10 16:41 - 01362695 _____ (Entersite Design ) C:\Users\Michael Kempen\Downloads\setup.exe 2014-03-10 16:41 - 2014-03-10 16:41 - 00000000 ____D () C:\Program Files (x86)\EnterImage 2014-03-10 13:13 - 2014-03-10 13:13 - 00032544 _____ () C:\Users\Michael Kempen\Downloads\HitmanPro_20140310_1313.log 2014-03-10 13:13 - 2014-03-10 13:02 - 00000000 ____D () C:\ProgramData\HitmanPro 2014-03-10 13:09 - 2014-03-10 13:09 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2014-03-10 13:02 - 2014-03-10 13:02 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael Kempen\Downloads\hitmanpro_x64.exe 2014-03-06 11:01 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\AppData\Roaming\Belastingdienst 2014-03-06 11:00 - 2014-03-06 11:00 - 00035881 _____ () C:\Users\Michael Kempen\Downloads\086692719.ibv2013 2014-03-06 10:59 - 2014-03-06 10:59 - 00001411 _____ () C:\Users\Public\Desktop\Aangifte inkomstenbelasting 2013.lnk 2014-03-06 07:58 - 2014-03-06 07:58 - 00000000 ____D () C:\Users\Michael Kempen\Documents\Belastingdienst 2014-03-06 07:57 - 2014-03-06 07:57 - 02836400 _____ (Belastingdienst) C:\Users\Michael Kempen\Downloads\ib2013_win_setup.exe 2014-03-06 07:57 - 2014-03-06 07:57 - 00016780 _____ () C:\Users\Michael Kempen\Downloads\230470488.ibv2013 2014-03-05 08:45 - 2013-04-02 12:12 - 00000000 ___RD () C:\Users\Michael Kempen\Desktop\Ongebruikt 2014-03-04 13:49 - 2014-03-04 13:49 - 71195306 _____ () C:\Users\Michael Kempen\Downloads\Russisch Sprachübung - Wichtige Ausdrücke - Teil 1.mp4 2014-03-04 13:48 - 2014-03-04 13:48 - 10885409 _____ () C:\Users\Michael Kempen\Downloads\Jon Kortajarena entrevista en Cosmopolitan TV.webm 2014-03-04 13:47 - 2014-03-04 13:47 - 38900875 _____ () C:\Users\Michael Kempen\Downloads\Andres Velencoso Segura Models.com Interview.webm 2014-03-04 13:30 - 2014-03-04 13:30 - 93859047 _____ () C:\Users\Michael Kempen\Downloads\Denkstof Waarom hebben christenen rituelen (lang) EO _ ZvK.mp4 2014-03-04 13:30 - 2014-03-04 13:30 - 20690926 _____ () C:\Users\Michael Kempen\Downloads\▶ Convo in Rochester.mp4 2014-03-03 08:13 - 2014-03-03 08:13 - 06542336 _____ () C:\Users\Michael Kempen\Downloads\Asgraphic_presentation_js.pps 2014-03-02 17:04 - 2014-03-02 17:04 - 01927168 _____ () C:\Users\Michael Kempen\Downloads\Hoe_doen_ze_dat_toch.pps 2014-03-01 07:05 - 2014-03-12 06:27 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-12 06:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-12 06:27 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-12 06:27 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-12 06:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-12 06:27 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-12 06:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-12 06:27 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-12 06:27 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-12 06:27 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-12 06:27 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-12 06:27 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-12 06:27 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-12 06:27 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-12 06:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-12 06:27 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-12 06:27 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-12 06:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-12 06:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-12 06:27 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-12 06:27 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-12 06:27 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-12 06:27 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-12 06:27 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-12 06:27 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-12 06:27 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-12 06:27 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-12 06:27 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-12 06:27 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-12 06:27 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-12 06:27 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-12 06:27 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-12 06:27 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-12 06:27 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-12 06:27 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-12 06:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-12 06:27 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-27 19:39 - 2014-02-27 19:39 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-02-27 19:39 - 2014-02-27 19:39 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-02-27 19:21 - 2014-02-27 19:21 - 05852504 _____ (TeamViewer GmbH) C:\Users\Michael Kempen\Downloads\TeamViewer_Setup_nl-ckg.exe 2014-02-27 18:02 - 2014-02-26 18:03 - 01644692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-27 09:24 - 2014-02-27 09:24 - 00196960 _____ () C:\Users\Michael Kempen\Downloads\leeftijd.ppsx 2014-02-23 10:17 - 2014-02-23 10:17 - 05526016 _____ () C:\Users\Michael Kempen\Downloads\Amsterdam_speciaal_CC.pps 2014-02-22 16:05 - 2014-02-22 16:05 - 18240707 _____ () C:\Users\Michael Kempen\Downloads\Fotos_gedownload_door_AirDroid.zip 2014-02-21 14:08 - 2014-02-21 14:08 - 00440672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswndisflt.sys 2014-02-21 14:08 - 2014-02-21 14:08 - 00002032 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-02-21 14:08 - 2014-02-21 14:08 - 00001972 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk 2014-02-21 14:07 - 2014-02-21 14:07 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-02-21 14:07 - 2014-01-15 12:48 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-21 14:07 - 2013-04-04 15:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-21 14:07 - 2013-03-13 14:09 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-17 16:32 - 2013-03-13 17:18 - 00004068 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 16:32 - 2013-03-13 17:18 - 00003816 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-16 07:47 - 2014-02-16 07:47 - 00092438 _____ () C:\Users\Michael Kempen\Downloads\noname.eml Some content of TEMP: ==================== C:\Users\Michael Kempen\AppData\Local\Temp\82504uninstall.exe C:\Users\Michael Kempen\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwxcv3v.dll C:\Users\Michael Kempen\AppData\Local\Temp\Quarantine.exe C:\Users\Michael Kempen\AppData\Local\Temp\Sqlite3.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-10 07:19 ==================== End Of Log ============================ --- --- --- |
19.03.2014, 14:34 | #8 |
/// the machine /// TB-Ausbilder | mail delivery failed: returning message to sender - web.de account Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.03.2014, 17:36 | #9 |
| mail delivery failed: returning message to sender - web.de account Hallo lieber Schrauber, so wie es aussieht, kommen keine Spams mehr rein! Ich möchte mich ganz herzlich bedanken dafür! Herzliche Grüße Michake Hallo, Es ist mir aufgefallen, dass das Programm iliVid nicht mehr da ist. Ist diese Software der übeltäter der Spams? Danke Michake |
23.03.2014, 11:15 | #10 |
/// the machine /// TB-Ausbilder | mail delivery failed: returning message to sender - web.de account Das ist Adware bzw eine Adware-Schleuder, nicht benutzen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu mail delivery failed: returning message to sender - web.de account |
benachrichtigungen, mail delivery ..., mail delivery failed, mail delivery failed: returning message to sender, problem gelöst, pup.optional.bandoo, pup.optional.freemium.a, pup.optional.iepluginservice.a, pup.optional.installcore.a, pup.optional.lightning.a, pup.optional.mysearchdial.a, pup.optional.newtab.a, pup.optional.rightsurf.a, pup.optional.skytech.a, returning message to sender, tagen, unbekannten, versendet, web.de |