hier de gevraagde logjes GMER liep telkens vast dus hiervan geen log
alvast vooraf bedankt

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org


Databaseversie: v2013.12.07.03


Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Rosetteke tet :: PC_VAN_ROSETTE [administrator]


8/12/2013 8:29:50
mbam-log-2013-12-08 (08-29-50).txt


Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 219849
Verstreken tijd: 40 minuut/minuten, 7 seconde


Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)


Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)


Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)


Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)


Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)


Mappen gedetecteerd: 1
C:\Users\Rosetteke tet\AppData\Local\Slick Savings (PUP.Optional.Spigot.A) -> Succesvol in quarantaine geplaatst en verwijderd.


Bestanden gedetecteerd: 1
C:\Users\Rosetteke tet\AppData\Local\Slick Savings\coupons.crx (PUP.Optional.Spigot.A) -> Succesvol in quarantaine geplaatst en verwijderd.


(einde)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16520 BrowserJavaVersion: 1.6.0_24
Run by Rosetteke tet at 9:48:55 on 2013-12-08
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3070.1965 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Common Files\SPBA\upeksvr.exe
C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Windows\system32\mfevtps.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
C:\Windows\system32\wbem\wmiprvse.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.be/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0813&s=2&o=vp32&d=0109&m=aspire_ 6530g
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: PHPNukeDU Toolbar: {46735dee-f862-49d1-876d-6382794dc625} - c:\program files\phpnukedu\tbPHPN.dll
mURLSearchHooks: PHPNukeDU Toolbar: {46735dee-f862-49d1-876d-6382794dc625} - c:\program files\phpnukedu\tbPHPN.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - c:\program files\mcafee security scan\3.8.130\McAfeeMSS_IE.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PHPNukeDU Toolbar: {46735dee-f862-49d1-876d-6382794dc625} - c:\program files\phpnukedu\tbPHPN.dll
BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll
BHO: ShowBarObj Class: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - <orphaned>
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\s wg.dll
BHO: Google Dictionary Compression sdch: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Acer eDataSecurity Management: {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: PHPNukeDU Toolbar: {46735dee-f862-49d1-876d-6382794dc625} - c:\program files\phpnukedu\tbPHPN.dll
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: DisableCAD = dword:1
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{5A1627D3-4F47-4309-9793-CD213B961F90} : DHCPNameServer = 192.168.0.1
Handler: skype-ie-addon-data - <Clsid value has no data>
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AWinNotifyVitaKey MC3000 - c:\program files\acer\acer bio protection\WinNotify.dll
Notify: spba - c:\program files\common files\spba\homefus2.dll
AppInit_DLLs= c:\progra~1\google\google~1\GoogleDesktopNetwork3. dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\insta ller\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [2008-12-31 43184]
S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [2010-2-24 35712]
.
=============== Created Last 30 ================
.
2013-12-07 16:35:13 -------- d-----w- c:\users\rosetteke tet\appdata\roaming\DriverCure
2013-12-07 16:35:12 -------- d-----w- c:\users\rosetteke tet\appdata\roaming\ParetoLogic
2013-12-07 16:34:40 -------- d-----w- c:\programdata\ParetoLogic
2013-12-07 14:47:55 -------- d-----w- c:\windows\Migration
2013-12-07 14:09:46 -------- d-----w- c:\users\rosetteke tet\appdata\local\temp
2013-12-07 14:07:03 -------- d-sh--w- C:\$RECYCLE.BIN
2013-12-07 12:24:39 15672 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-12-07 11:58:15 -------- d-----w- c:\programdata\ProductData
2013-12-07 11:57:19 -------- d-----w- c:\programdata\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-12-07 11:57:12 -------- d-----w- c:\programdata\IObit
2013-12-07 11:57:10 -------- d-----w- c:\users\rosetteke tet\appdata\roaming\IObit
2013-12-07 11:56:27 -------- d-----w- c:\program files\common files\Spigot
2013-12-07 11:55:17 -------- d-----w- c:\program files\IObit
2013-12-07 11:45:01 -------- d-----w- c:\program files\iPod
2013-12-07 11:44:49 -------- d-----w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-12-07 11:44:48 -------- d-----w- c:\program files\iTunes
2013-12-07 09:10:27 -------- d-----w- c:\users\rosetteke tet\appdata\roaming\Malwarebytes
2013-12-07 09:09:29 -------- d-----w- c:\programdata\Malwarebytes
2013-12-07 09:09:14 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-07 09:09:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-12-07 07:23:37 208896 ----a-w- c:\windows\MBR.exe
2013-12-07 07:23:31 256000 ----a-w- c:\windows\PEV.exe
2013-12-07 07:23:30 98816 ----a-w- c:\windows\sed.exe
2013-12-07 06:54:29 -------- d-----w- c:\windows\pss
2013-12-07 06:39:09 7772552 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{c5993bd1-95ce-47fe-9dc0-0d9e689ced74}\mpengine.dll
2013-12-05 12:13:48 297984 ----a-w- c:\windows\system32\gdi32.dll
2013-12-05 12:13:23 993792 ----a-w- c:\windows\system32\crypt32.dll
2013-12-05 12:12:21 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2013-12-05 12:12:19 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
.
==================== Find3M ====================
.
2013-11-19 02:33:38 230048 ------w- c:\windows\system32\MpSigStub.exe
2013-10-13 09:48:06 1806848 ----a-w- c:\windows\system32\jscript9.dll
2013-10-13 09:35:52 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2013-10-13 09:35:38 1129472 ----a-w- c:\windows\system32\wininet.dll
2013-10-13 09:30:14 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2013-10-13 09:29:02 420864 ----a-w- c:\windows\system32\vbscript.dll
2013-10-13 09:25:39 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2013-10-12 09:26:58 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-10-12 09:26:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-11 20:21:54 863344 ----a-w- c:\windows\system32\msvcr110_clr0400.dll
2013-09-11 20:21:54 501872 ----a-w- c:\windows\system32\msvcp110_clr0400.dll
2013-09-11 20:21:54 28776 ----a-w- c:\windows\system32\aspnet_counters.dll
2013-09-11 20:21:54 18000 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
.
============= FINISH: 9:52:28,79 ===============