Hoi hoi,
laptop is vl trager dan normaal ! Loopt vast, hapert enz ...
Willen jullie aub een checkje doen, of er rare dingen in zitten?
Dankjewel !!
[hjt]
Logfile of HijackThis v1.99.1
Scan saved at 15:25:44, on 1-3-2012
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Running processes:
c:\program files (x86)\daemon tools pro\dtshellhlp.exe
d:\programmas\utorrent.exe
c:\users\mmqi-thabi\appdata\local\temp\torrent2exe\t2e.exe
c:\users\mmqi-thabi\appdata\roaming\drpsu\drvupdater.exe
c:\windows\asscrpro.exe
c:\program files (x86)\skype\phone\skype.exe
c:\program files (x86)\boingo\boingo wi-fi\boingo wi-fi.exe
c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
c:\program files (x86)\asus\atk package\atk media\dmedia.exe
c:\program files (x86)\asus\atk hotkey\hcontroluser.exe
c:\program files (x86)\eset\nod32kui.exe
c:\program files (x86)\cyberlink\power2go\clmlsvc.exe
c:\program files (x86)\internet explorer\ielowutil.exe
c:\program files (x86)\mozilla firefox\firefox.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
d:\downloads\mozilla downloads\hijackthis(1).exe
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url = [noparse]http://asus.msn.com[/noparse]
r1 - hkcu\software\microsoft\internet explorer\main,search page = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hkcu\software\microsoft\internet explorer\main,start page = [noparse]http://asus.msn.com[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = [noparse]http://go.microsoft.com/fwlink/?linkid=69157[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,search page = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hklm\software\microsoft\internet explorer\main,start page = [noparse]http://go.microsoft.com/fwlink/?linkid=69157[/noparse]
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hklm\software\microsoft\internet explorer\main,local page = c:\windows\syswow64\blank.htm
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
f2 - reg:system.ini: userinit=userinit.exe
o1 - hosts: 255.255.255.255 easyanticheat.se # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.se # misleading site
o1 - hosts: 255.255.255.255 easyanticheat.com # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.com # misleading site
o1 - hosts: 255.255.255.255 easyanticheat.org # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.org # misleading site
o2 - bho: acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll
o2 - bho: groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\micros~1\office14\grooveex.dll
o2 - bho: aanmeldhulp voor windows live id - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: altergeo magic scanner - {9bfba68e-e21b-458e-ae12-fe85e903d2c1} - c:\program files (x86)\altergeo\altergeo magic scanner\3.2.1.742\altergeo.browserplugin.dll
o2 - bho: windows live messenger companion helper - {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files (x86)\windows live\companion\companioncore.dll
o2 - bho: skypeiepluginbho - {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o2 - bho: urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\urlredir.dll
o2 - bho: java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
o2 - bho: youtube downloader toolbar - {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files (x86)\youtube downloader toolbar\ie\5.0\youtubedownloadertoolbarie.dll
o3 - toolbar: youtube downloader toolbar - {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files (x86)\youtube downloader toolbar\ie\5.0\youtubedownloadertoolbarie.dll
o4 - hklm\..\run: [updatelbpshortcut] c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
o4 - hklm\..\run: [updatep2goshortcut] c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
o4 - hklm\..\run: [boingo wi-fi] c:\program files (x86)\boingo\boingo wi-fi\boingo.lnk
o4 - hklm\..\run: [atkosd2] c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
o4 - hklm\..\run: [atkmedia] c:\program files (x86)\asus\atk package\atk media\dmedia.exe
o4 - hklm\..\run: [hcontroluser] c:\program files (x86)\asus\atk hotkey\hcontroluser.exe
o4 - hklm\..\run: [nod32kui] c:\program files (x86)\eset\nod32kui.exe /waitservice
o4 - hklm\..\run: [nbagent] d:\programmas\nero\nero backitup\nbagent.exe /winstart
o4 - hklm\..\run: [clmlserver] c:\program files (x86)\cyberlink\power2go\clmlsvc.exe
o4 - hklm\..\run: [asuswebstorage] c:\program files (x86)\asus\asus webstorage\3.0.108.222\asuswspanel.exe /s
o4 - hklm\..\run: [startccc] c:\program files (x86)\atinew\ati.ace\core-static\clistart.exe msrun
o4 - hklm\..\run: [searchsettings] c:\program files (x86)\common files\spigot\search settings\searchsettings.exe
o4 - hkcu\..\run: [msnmsgr] c:\program files (x86)\windows live\messenger\msnmsgr.exe /background
o4 - hkcu\..\run: [utorrent] d:\programmas\utorrent.exe /minimized
o4 - hkcu\..\run: [daemon tools pro agent] c:\program files (x86)\daemon tools pro\dtagent.exe -autorun
o4 - hkcu\..\run: [torrent2exe] c:\users\mmqi-t~1\appdata\local\temp\torrent2exe\t2e.exe --autorun
o4 - hkcu\..\run: [drvupdater] c:\users\mmqi-thabi\appdata\roaming\drpsu\drvupdater.exe
o4 - hkcu\..\run: [eadm] d:\bf3\origin\origin.exe -autostart
o4 - hkcu\..\run: [skype] c:\program files (x86)\skype\phone\skype.exe /nosplash /minimized
o4 - startup: battery doubler.lnk = dachshund software\battery doubler\battery doubler.exe
o4 - global startup: fancystart daemon.lnk = ?
o9 - extra button: @c:\program files (x86)\windows live\companion\companionlang.dll,-600 - {0000036b-c524-4050-81a0-243669a86b9f} - c:\program files (x86)\windows live\companion\companioncore.dll
o9 - extra button: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1004 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1003 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra button: verzenden naar onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: &verzenden naar onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra button: pokerstars - {3ad14f0c-ed16-4e43-b6d8-661b03f6a1ef} - c:\program files (x86)\pokerstars\pokerstarsupdate.exe
o9 - extra button: &gekoppelde notities van onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: &gekoppelde notities van onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra button: skype click to call - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra 'tools' menuitem: skype click to call - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o10 - unknown file in winsock lsp: c:\windows\system32\nlaapi.dll
o10 - unknown file in winsock lsp: c:\windows\system32\napinsp.dll
o10 - unknown file in winsock lsp: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o11 - options group: [accelerated_graphics] accelerated graphics
o11 - options group: [international] international
o13 - gopher prefix:
o18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\program files (x86)\windows live\messenger\msgrapp.dll
o18 - protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - (no file)
o18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\program files (x86)\windows live\messenger\msgrapp.dll
o18 - protocol: skype-ie-addon-data - {91774881-d725-4e58-b298-07617b9b86a8} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o18 - protocol: wlmailhtml - {03c514a3-1efb-4856-9f99-10d7be1653c0} - c:\program files (x86)\windows live\mail\mailcomm.dll
o18 - protocol: wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files (x86)\windows live\photo gallery\albumdownloadprotocolhandler.dll
o18 - filter hijack: text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files (x86)\common files\microsoft shared\office14\msoxmlmf.dll
o23 - service: afbagent - unknown owner - c:\windows\system32\fbagent.exe (file missing)
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: amd external events utility - unknown owner - c:\windows\system32\atiesrxx.exe (file missing)
o23 - service: application updater - unknown owner - c:\program files (x86)\application updater\applicationupdater.exe (file missing)
o23 - service: asldr service (asldrservice) - asus - c:\program files (x86)\asus\atk package\atk hotkey\asldrsrv.exe
o23 - service: atkgfnex service (atkgfnexsrv) - asus - c:\program files (x86)\asus\atk package\atkgfnex\gfnexsrv.exe
o23 - service: @%systemroot%\system32\efssvc.dll,-100 (efs) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\fxsresm.dll,-118 (fax) - unknown owner - c:\windows\system32\fxssvc.exe (file missing)
o23 - service: google update service (gupdate) (gupdate) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: google update-service (gupdatem) (gupdatem) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: intel(r) management and security application local management service (lms) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
o23 - service: mbamservice - malwarebytes corporation - c:\program files (x86)\malwarebytes' anti-malware\mbamservice.exe
o23 - service: microsoft sharepoint workspace audit service - unknown owner - c:\program files\microsoft office\office14\groove.exe /auditservice (file missing)
o23 - service: @c:\program files (x86)\nero\update\nasvc.exe,-200 (naupdate) - nero ag - c:\program files (x86)\nero\update\nasvc.exe
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: nod32 kernel service (nod32krn) - eset - c:\program files (x86)\eset\nod32krn.exe
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\qwave.dll,-1 (qwave) - unknown owner - %windir%\system32\svchost.exe (file missing)
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\seclogon.dll,-7001 (seclogon) - unknown owner - %windir%\system32\svchost.exe (file missing)
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: @%systemroot%\system32\sppsvc.exe,-101 (sppsvc) - unknown owner - c:\windows\system32\sppsvc.exe (file missing)
o23 - service: audio service (stacsv) - idt, inc. - c:\windows\system32\driverstore\filerepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\stacsv64.exe
o23 - service: steam client service - valve corporation - c:\program files (x86)\common files\steam\steamservice.exe
o23 - service: tuneup utilities service (tuneup.utilitiessvc) - tuneup software - c:\program files (x86)\tuneup utilities 2012\tuneuputilitiesservice64.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: intel(r) management & security application user notification service (uns) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
o23 - service: @%systemroot%\system32\vaultsvc.dll,-1003 (vaultsvc) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: @%systemroot%\system32\wat\watux.exe,-601 (watadminsvc) - unknown owner - c:\windows\system32\wat\watadminsvc.exe (file missing)
o23 - service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - unknown owner - c:\windows\system32\wbengine.exe (file missing)
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - %programfiles%\windows media player\wmpnetwk.exe (file missing)
[/hjt]
laptop is vl trager dan normaal ! Loopt vast, hapert enz ...
Willen jullie aub een checkje doen, of er rare dingen in zitten?
Dankjewel !!
[hjt]
Logfile of HijackThis v1.99.1
Scan saved at 15:25:44, on 1-3-2012
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Running processes:
c:\program files (x86)\daemon tools pro\dtshellhlp.exe
d:\programmas\utorrent.exe
c:\users\mmqi-thabi\appdata\local\temp\torrent2exe\t2e.exe
c:\users\mmqi-thabi\appdata\roaming\drpsu\drvupdater.exe
c:\windows\asscrpro.exe
c:\program files (x86)\skype\phone\skype.exe
c:\program files (x86)\boingo\boingo wi-fi\boingo wi-fi.exe
c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
c:\program files (x86)\asus\atk package\atk media\dmedia.exe
c:\program files (x86)\asus\atk hotkey\hcontroluser.exe
c:\program files (x86)\eset\nod32kui.exe
c:\program files (x86)\cyberlink\power2go\clmlsvc.exe
c:\program files (x86)\internet explorer\ielowutil.exe
c:\program files (x86)\mozilla firefox\firefox.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
d:\downloads\mozilla downloads\hijackthis(1).exe
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url = [noparse]http://asus.msn.com[/noparse]
r1 - hkcu\software\microsoft\internet explorer\main,search page = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hkcu\software\microsoft\internet explorer\main,start page = [noparse]http://asus.msn.com[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = [noparse]http://go.microsoft.com/fwlink/?linkid=69157[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r1 - hklm\software\microsoft\internet explorer\main,search page = [noparse]http://go.microsoft.com/fwlink/?linkid=54896[/noparse]
r0 - hklm\software\microsoft\internet explorer\main,start page = [noparse]http://go.microsoft.com/fwlink/?linkid=69157[/noparse]
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hklm\software\microsoft\internet explorer\main,local page = c:\windows\syswow64\blank.htm
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
f2 - reg:system.ini: userinit=userinit.exe
o1 - hosts: 255.255.255.255 easyanticheat.se # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.se # misleading site
o1 - hosts: 255.255.255.255 easyanticheat.com # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.com # misleading site
o1 - hosts: 255.255.255.255 easyanticheat.org # misleading site
o1 - hosts: 255.255.255.255 www.easyanticheat.org # misleading site
o2 - bho: acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll
o2 - bho: groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\micros~1\office14\grooveex.dll
o2 - bho: aanmeldhulp voor windows live id - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: altergeo magic scanner - {9bfba68e-e21b-458e-ae12-fe85e903d2c1} - c:\program files (x86)\altergeo\altergeo magic scanner\3.2.1.742\altergeo.browserplugin.dll
o2 - bho: windows live messenger companion helper - {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files (x86)\windows live\companion\companioncore.dll
o2 - bho: skypeiepluginbho - {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o2 - bho: urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\micros~1\office14\urlredir.dll
o2 - bho: java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
o2 - bho: youtube downloader toolbar - {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files (x86)\youtube downloader toolbar\ie\5.0\youtubedownloadertoolbarie.dll
o3 - toolbar: youtube downloader toolbar - {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files (x86)\youtube downloader toolbar\ie\5.0\youtubedownloadertoolbarie.dll
o4 - hklm\..\run: [updatelbpshortcut] c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
o4 - hklm\..\run: [updatep2goshortcut] c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
o4 - hklm\..\run: [boingo wi-fi] c:\program files (x86)\boingo\boingo wi-fi\boingo.lnk
o4 - hklm\..\run: [atkosd2] c:\program files (x86)\asus\atk package\atkosd2\atkosd2.exe
o4 - hklm\..\run: [atkmedia] c:\program files (x86)\asus\atk package\atk media\dmedia.exe
o4 - hklm\..\run: [hcontroluser] c:\program files (x86)\asus\atk hotkey\hcontroluser.exe
o4 - hklm\..\run: [nod32kui] c:\program files (x86)\eset\nod32kui.exe /waitservice
o4 - hklm\..\run: [nbagent] d:\programmas\nero\nero backitup\nbagent.exe /winstart
o4 - hklm\..\run: [clmlserver] c:\program files (x86)\cyberlink\power2go\clmlsvc.exe
o4 - hklm\..\run: [asuswebstorage] c:\program files (x86)\asus\asus webstorage\3.0.108.222\asuswspanel.exe /s
o4 - hklm\..\run: [startccc] c:\program files (x86)\atinew\ati.ace\core-static\clistart.exe msrun
o4 - hklm\..\run: [searchsettings] c:\program files (x86)\common files\spigot\search settings\searchsettings.exe
o4 - hkcu\..\run: [msnmsgr] c:\program files (x86)\windows live\messenger\msnmsgr.exe /background
o4 - hkcu\..\run: [utorrent] d:\programmas\utorrent.exe /minimized
o4 - hkcu\..\run: [daemon tools pro agent] c:\program files (x86)\daemon tools pro\dtagent.exe -autorun
o4 - hkcu\..\run: [torrent2exe] c:\users\mmqi-t~1\appdata\local\temp\torrent2exe\t2e.exe --autorun
o4 - hkcu\..\run: [drvupdater] c:\users\mmqi-thabi\appdata\roaming\drpsu\drvupdater.exe
o4 - hkcu\..\run: [eadm] d:\bf3\origin\origin.exe -autostart
o4 - hkcu\..\run: [skype] c:\program files (x86)\skype\phone\skype.exe /nosplash /minimized
o4 - startup: battery doubler.lnk = dachshund software\battery doubler\battery doubler.exe
o4 - global startup: fancystart daemon.lnk = ?
o9 - extra button: @c:\program files (x86)\windows live\companion\companionlang.dll,-600 - {0000036b-c524-4050-81a0-243669a86b9f} - c:\program files (x86)\windows live\companion\companioncore.dll
o9 - extra button: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1004 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1003 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra button: verzenden naar onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: &verzenden naar onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files (x86)\microsoft office\office14\onbttnie.dll
o9 - extra button: pokerstars - {3ad14f0c-ed16-4e43-b6d8-661b03f6a1ef} - c:\program files (x86)\pokerstars\pokerstarsupdate.exe
o9 - extra button: &gekoppelde notities van onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: &gekoppelde notities van onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files (x86)\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra button: skype click to call - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra 'tools' menuitem: skype click to call - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o10 - unknown file in winsock lsp: c:\windows\system32\nlaapi.dll
o10 - unknown file in winsock lsp: c:\windows\system32\napinsp.dll
o10 - unknown file in winsock lsp: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o11 - options group: [accelerated_graphics] accelerated graphics
o11 - options group: [international] international
o13 - gopher prefix:
o18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\program files (x86)\windows live\messenger\msgrapp.dll
o18 - protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - (no file)
o18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\program files (x86)\windows live\messenger\msgrapp.dll
o18 - protocol: skype-ie-addon-data - {91774881-d725-4e58-b298-07617b9b86a8} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
o18 - protocol: wlmailhtml - {03c514a3-1efb-4856-9f99-10d7be1653c0} - c:\program files (x86)\windows live\mail\mailcomm.dll
o18 - protocol: wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files (x86)\windows live\photo gallery\albumdownloadprotocolhandler.dll
o18 - filter hijack: text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files (x86)\common files\microsoft shared\office14\msoxmlmf.dll
o23 - service: afbagent - unknown owner - c:\windows\system32\fbagent.exe (file missing)
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: amd external events utility - unknown owner - c:\windows\system32\atiesrxx.exe (file missing)
o23 - service: application updater - unknown owner - c:\program files (x86)\application updater\applicationupdater.exe (file missing)
o23 - service: asldr service (asldrservice) - asus - c:\program files (x86)\asus\atk package\atk hotkey\asldrsrv.exe
o23 - service: atkgfnex service (atkgfnexsrv) - asus - c:\program files (x86)\asus\atk package\atkgfnex\gfnexsrv.exe
o23 - service: @%systemroot%\system32\efssvc.dll,-100 (efs) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\fxsresm.dll,-118 (fax) - unknown owner - c:\windows\system32\fxssvc.exe (file missing)
o23 - service: google update service (gupdate) (gupdate) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: google update-service (gupdatem) (gupdatem) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: intel(r) management and security application local management service (lms) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
o23 - service: mbamservice - malwarebytes corporation - c:\program files (x86)\malwarebytes' anti-malware\mbamservice.exe
o23 - service: microsoft sharepoint workspace audit service - unknown owner - c:\program files\microsoft office\office14\groove.exe /auditservice (file missing)
o23 - service: @c:\program files (x86)\nero\update\nasvc.exe,-200 (naupdate) - nero ag - c:\program files (x86)\nero\update\nasvc.exe
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: nod32 kernel service (nod32krn) - eset - c:\program files (x86)\eset\nod32krn.exe
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\qwave.dll,-1 (qwave) - unknown owner - %windir%\system32\svchost.exe (file missing)
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\seclogon.dll,-7001 (seclogon) - unknown owner - %windir%\system32\svchost.exe (file missing)
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: @%systemroot%\system32\sppsvc.exe,-101 (sppsvc) - unknown owner - c:\windows\system32\sppsvc.exe (file missing)
o23 - service: audio service (stacsv) - idt, inc. - c:\windows\system32\driverstore\filerepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\stacsv64.exe
o23 - service: steam client service - valve corporation - c:\program files (x86)\common files\steam\steamservice.exe
o23 - service: tuneup utilities service (tuneup.utilitiessvc) - tuneup software - c:\program files (x86)\tuneup utilities 2012\tuneuputilitiesservice64.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: intel(r) management & security application user notification service (uns) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
o23 - service: @%systemroot%\system32\vaultsvc.dll,-1003 (vaultsvc) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: @%systemroot%\system32\wat\watux.exe,-601 (watadminsvc) - unknown owner - c:\windows\system32\wat\watadminsvc.exe (file missing)
o23 - service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - unknown owner - c:\windows\system32\wbengine.exe (file missing)
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - %programfiles%\windows media player\wmpnetwk.exe (file missing)
[/hjt]