
HupRonnyHup
Lid-
Items
3 -
Registratiedatum
-
Laatst bezocht
Inhoudstype
Profielen
Forums
Store
Alles dat geplaatst werd door HupRonnyHup
-
Ja die del.bat had ik al eens laten lopen, ook in een andere post gezien. Hier de logfile: Deleting files I:\WINDOWS\TEMP\conhost.exe not found en hijackthis Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:29:27, on 30/08/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16850) Boot mode: Normal Running processes: I:\WINDOWS\System32\smss.exe I:\PROGRA~1\AVG\AVG10\avgchsvx.exe I:\WINDOWS\system32\winlogon.exe I:\WINDOWS\system32\services.exe I:\WINDOWS\system32\lsass.exe I:\WINDOWS\system32\Ati2evxx.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\system32\spoolsv.exe I:\WINDOWS\Explorer.EXE I:\WINDOWS\stsystra.exe I:\Program Files\HP\HP Software Update\HPWuSchd2.exe I:\Program Files\AVG\AVG10\avgtray.exe I:\Program Files\Common Files\Java\Java Update\jusched.exe I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe I:\Program Files\Belgium Identity Card\beid35gui.exe I:\WINDOWS\system32\ctfmon.exe I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe I:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe I:\Program Files\AVG\AVG10\avgwdsvc.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\Program Files\Java\jre6\bin\jqs.exe I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE I:\WINDOWS\System32\svchost.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\Program Files\AVG\AVG10\avgnsx.exe I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe I:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe I:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe I:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\PROGRA~1\AVG\AVG10\avgrsx.exe I:\Program Files\AVG\AVG10\avgcsrvx.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\PROGINST\hijact\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - I:\Program Files\AVG\AVG10\avgssie.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - I:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [HP Software Update] I:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [AVG_TRAY] I:\Program Files\AVG\AVG10\avgtray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [beid] I:\Program Files\Belgium Identity Card\beid35gui.exe O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://I:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe O15 - Trusted Zone: http://*.mcafee.com O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://portal.brusselsairport.be/dana/download/icaweb.cab?url=/dana/term/winlaunchterm.cgi?op=DownloadCitrixCab O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://express.foto.com/ImageUploader5.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172749852671 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227109954984 O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://virusscanner.telenet.be/fscax.cab O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - I:\Program Files\AVG\AVG10\avgpp.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: MBackMonitor - Unknown owner - I:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing) O23 - Service: MBAMService - Malwarebytes Corporation - I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- End of file - 9708 bytes TDSS vind ik niet meer. Bedankt voor de hulp, alles lijkt opgelost. Ronny
-
sorry ondertussen TDSSKiller laten lopen, en geen warning meer gehad, als het terugkomt begin ik een nieuwe discussie. groeten, Ronny
-
Hallo, Ik heb zowat hetzelfde probleem op mijn pa zijn pc. Heb hijackthis mbam en combofix laten lopen met de nodige herstarts, maar AVG geeft nog dezelfde conhost.exe warning. XP home edition 3 AVG free 2011 Erg bedankt voor enige hulp Hier de hijackthis, mbam en combofix logs: hijack this Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:31:19, on 30/08/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16850) Boot mode: Normal Running processes: I:\WINDOWS\System32\smss.exe I:\PROGRA~1\AVG\AVG10\avgchsvx.exe I:\WINDOWS\system32\winlogon.exe I:\WINDOWS\system32\services.exe I:\WINDOWS\system32\lsass.exe I:\WINDOWS\system32\Ati2evxx.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\system32\spoolsv.exe I:\WINDOWS\Explorer.EXE I:\WINDOWS\stsystra.exe I:\Program Files\HP\HP Software Update\HPWuSchd2.exe I:\Program Files\AVG\AVG10\avgtray.exe I:\Program Files\Common Files\Java\Java Update\jusched.exe I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe I:\Program Files\Belgium Identity Card\beid35gui.exe I:\WINDOWS\system32\ctfmon.exe I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe I:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe I:\Program Files\Malwarebytes' Anti-Malware\mbam.exe I:\Program Files\AVG\AVG10\avgwdsvc.exe I:\WINDOWS\system32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\Program Files\Java\jre6\bin\jqs.exe I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE I:\WINDOWS\System32\svchost.exe I:\Program Files\AVG\AVG10\avgnsx.exe I:\WINDOWS\System32\svchost.exe I:\WINDOWS\system32\svchost.exe I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe I:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe I:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe I:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe I:\WINDOWS\system32\NOTEPAD.EXE I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe I:\PROGRA~1\AVG\AVG10\avgrsx.exe I:\Program Files\AVG\AVG10\avgcsrvx.exe I:\PROGINST\hijact\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - I:\Program Files\AVG\AVG10\avgssie.dll O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - I:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - I:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing) O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [HP Software Update] I:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [AVG_TRAY] I:\Program Files\AVG\AVG10\avgtray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [beid] I:\Program Files\Belgium Identity Card\beid35gui.exe O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://I:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe O15 - Trusted Zone: http://*.mcafee.com O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://portal.brusselsairport.be/dana/download/icaweb.cab?url=/dana/term/winlaunchterm.cgi?op=DownloadCitrixCab O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://express.foto.com/ImageUploader5.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172749852671 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227109954984 O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://virusscanner.telenet.be/fscax.cab O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - I:\Program Files\AVG\AVG10\avgpp.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: MBackMonitor - Unknown owner - I:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing) O23 - Service: MBAMService - Malwarebytes Corporation - I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- End of file - 10176 bytes MBAM log Malwarebytes' Anti-Malware 1.51.1.1800 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Database version: 7609 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 30/08/2011 14:12:45 mbam-log-2011-08-30 (14-12-45).txt Scan type: Quick scan Objects scanned: 201884 Time elapsed: 16 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 10 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\GodLib (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Value: UID -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: i:\documents and settings\localservice\application data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully. i:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Quarantined and deleted successfully. Files Infected: i:\documents and settings\networkservice\start menu\Programs\Startup\winupdate.lnk (Trojan.Downloader) -> Quarantined and deleted successfully. i:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully. i:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. i:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully. i:\WINDOWS\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully. i:\documents and settings\networkservice\local settings\application data\microsoft\Windows\winupdate.exe (Trojan.Agent) -> Quarantined and deleted successfully. i:\documents and settings\localservice\application data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully. i:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Quarantined and deleted successfully. i:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Quarantined and deleted successfully. i:\WINDOWS\system32\drivers\uacbfrkcxeo.sys (Rootkit.TDSS) -> Quarantined and deleted successfully. combofix log ComboFix 11-08-30.01 - Administrator 08/30/2011 14:42:59.1.2 - x86 NETWORK Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3710.3433 [GMT 2:00] Running from: i:\documents and settings\Administrator\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: McAfee VirusScan *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . i:\documents and settings\NetworkService\Local Settings\Application Data\Google\Update\gupdate.exe i:\windows\system32\comct332.ocx i:\windows\system32\UACaneenwkb.log i:\windows\system32\UACbqhosjvu.log i:\windows\system32\UACbsutucke.log i:\windows\system32\UACceetnkig.log i:\windows\system32\UACetnetyxv.log i:\windows\system32\UACfpdocxtb.log i:\windows\system32\UACgqrxmcjc.log i:\windows\system32\UACiemuscti.log i:\windows\system32\UACktepuqbe.log i:\windows\system32\UACmmbftpdw.log i:\windows\system32\UACmqibqtvt.log i:\windows\system32\UACnpbiriyp.log i:\windows\system32\UACpqgxyqmb.log i:\windows\system32\UACqgijllxs.log i:\windows\system32\UACqsmdxvnc.log i:\windows\system32\UACqsnodyew.log i:\windows\system32\UACrdomyeor.dat i:\windows\system32\UACtssaurer.log i:\windows\system32\UACujdqmivr.log i:\windows\system32\UACvbbpmstg.log i:\windows\system32\UACvqpylqrj.log i:\windows\system32\UACwwbxtmdh.log i:\windows\system32\UACxyusiuya.log . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Legacy_SSHNAS -------\Service_NPF . . ((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-30 ))))))))))))))))))))))))))))))) . . 2011-08-30 11:52 . 2011-08-30 11:52 -------- d-----w- i:\documents and settings\JOS CORNELIS\Application Data\Malwarebytes 2011-08-30 11:51 . 2011-07-08 05:55 41272 ----a-w- i:\windows\system32\drivers\mbamswissarmy.sys 2011-08-30 11:51 . 2011-08-30 11:51 -------- d-----w- i:\documents and settings\All Users\Application Data\Malwarebytes 2011-08-30 11:51 . 2011-08-30 11:51 -------- d-----w- i:\program files\Malwarebytes' Anti-Malware 2011-08-30 11:51 . 2011-07-08 05:55 22712 ----a-w- i:\windows\system32\drivers\mbam.sys 2011-08-29 07:58 . 2011-08-29 07:58 -------- d-----w- i:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation 2011-08-08 10:53 . 2011-08-10 16:38 -------- d-----w- i:\documents and settings\JOS CORNELIS\Application Data\PoivY 2011-08-08 10:53 . 2011-08-08 10:53 -------- d-----w- i:\program files\PoivY.com . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-24 12:35 . 2011-07-24 12:35 404640 ----a-w- i:\windows\system32\FlashPlayerCPLApp.cpl 2008-04-16 19:35 . 2008-04-16 19:35 14336 ----a-w- i:\program files\wmdmhelper.dll 2008-04-16 19:35 . 2008-04-16 19:35 692224 ----a-w- i:\program files\dtdr3260.dll 2008-04-16 19:35 . 2008-04-16 19:35 659456 ----a-w- i:\program files\rjbres.dll 2008-04-16 19:35 . 2008-04-16 19:35 36352 ----a-w- i:\program files\ierjplug.dll 2008-04-16 19:35 . 2008-04-16 19:35 339968 ----a-w- i:\program files\rjdlg.dll 2008-04-16 19:35 . 2008-04-16 19:35 19456 ----a-w- i:\program files\rjprog.dll 2008-04-16 19:35 . 2008-04-16 19:35 139264 ----a-w- i:\program files\DUNZIP32.dll 2008-04-16 19:35 . 2008-04-16 19:35 81920 ----a-w- i:\program files\tsasdk.dll 2008-04-16 19:35 . 2008-04-16 19:35 6656 ----a-w- i:\program files\fixrjb.exe 2008-04-16 19:35 . 2008-04-16 19:35 57344 ----a-w- i:\program files\tpasdk.dll 2008-04-16 19:35 . 2008-04-16 19:35 41472 ----a-w- i:\program files\mmcdda32.dll 2008-04-16 19:35 . 2008-04-16 19:35 19456 ----a-w- i:\program files\tnetdtct.dll 2008-04-16 19:35 . 2008-04-16 19:35 43088 ----a-w- i:\program files\rpshellsearch.dll 2008-04-16 19:35 . 2008-04-16 19:35 32768 ----a-w- i:\program files\rpwa3260.dll 2008-04-16 19:35 . 2008-04-16 19:35 16296 ----a-w- i:\program files\realtfon.fon 2008-04-16 19:35 . 2008-04-16 19:35 719360 ----a-w- i:\program files\dbghelp.dll 2008-04-16 19:35 . 2008-04-16 19:35 153176 ----a-w- i:\program files\RecordingManager.exe 2008-04-16 19:35 . 2008-04-16 19:35 65536 ----a-w- i:\program files\rjwmapln.dll 2008-04-16 19:35 . 2008-04-16 19:35 53248 ----a-w- i:\program files\rpau3260.dll 2008-04-16 19:35 . 2008-04-16 19:35 102400 ----a-w- i:\program files\HXAudioDeviceHook.dll 2008-04-16 19:35 . 2008-04-16 19:35 98304 ----a-w- i:\program files\rpshellextension.dll 2008-04-16 19:35 . 2008-04-16 19:35 95816 ----a-w- i:\program files\rdsf3260.dll 2008-04-16 19:35 . 2008-04-16 19:35 86016 ----a-w- i:\program files\rpplugprot.dll 2008-04-16 19:35 . 2008-04-16 19:35 63040 ----a-w- i:\program files\rpshell.dll 2008-04-16 19:35 . 2008-04-16 19:35 9216 ----a-w- i:\program files\rphelperapp.exe 2008-04-16 19:35 . 2008-04-16 19:35 7168 ----a-w- i:\program files\realjbox.exe 2008-04-16 19:35 . 2008-04-16 19:35 214560 ----a-w- i:\program files\realplay.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}] 2009-12-20 09:51 87480 ----a-w- i:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}] 2011-01-06 14:06 721840 ----a-w- i:\progra~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "i:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll" [2009-12-20 87480] . [HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-06 68856] "beid"="i:\program files\Belgium Identity Card\beid35gui.exe" [2008-10-30 2023424] "ctfmon.exe"="i:\windows\system32\ctfmon.exe" [2008-04-14 15360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="i:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-29 339968] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968] "Adobe Reader Speed Launcher"="i:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "QuickTime Task"="i:\program files\QuickTime\qttask.exe" [2010-03-18 421888] "HP Software Update"="i:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "AVG_TRAY"="i:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560] "SunJavaUpdateSched"="i:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "Malwarebytes' Anti-Malware"="i:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-08 449584] . i:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - i:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0i:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0i:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "i:\\Program Files\\Messenger\\msmsgs.exe"= "i:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"= "i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"= "i:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "i:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"= "i:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"= "i:\\Documents and Settings\\JOS CORNELIS\\Application Data\\Juniper Networks\\Juniper Citrix Services Client\\dsCitrixProxy.exe"= "i:\\Documents and Settings\\JOS CORNELIS\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"= "i:\\Program Files\\Skype\\Phone\\Skype.exe"= "i:\\Program Files\\PoivY.com\\PoivY\\PoivY.exe"= "i:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"= "i:\\Program Files\\AVG\\AVG10\\avgnsx.exe"= "i:\\Program Files\\AVG\\AVG10\\avgemcx.exe"= . R0 AVGIDSEH;AVGIDSEH;i:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 16:27 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;i:\windows\system32\drivers\avgrkx86.sys [7/09/2010 4:48 32592] R1 Avgldx86;AVG AVI Loader Driver;i:\windows\system32\drivers\avgldx86.sys [7/09/2010 4:48 248656] R1 Avgtdix;AVG TDI Driver;i:\windows\system32\drivers\avgtdix.sys [9/11/2010 23:20 297168] R2 avgwd;AVG WatchDog;i:\program files\AVG\AVG10\avgwdsvc.exe [8/02/2011 5:33 269520] R2 MBAMService;MBAMService;i:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [30/08/2011 13:51 366640] R2 WDDMService;WD SmartWare Drive Manager;i:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13/11/2009 12:28 110592] R2 WDSmartWareBackgroundService;WD SmartWare Background Service;i:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 9:58 20480] R3 AVGIDSDriver;AVGIDSDriver;i:\windows\system32\drivers\AVGIDSDriver.sys [19/08/2010 21:42 134480] R3 AVGIDSFilter;AVGIDSFilter;i:\windows\system32\drivers\AVGIDSFilter.sys [19/08/2010 21:42 24144] R3 AVGIDSShim;AVGIDSShim;i:\windows\system32\drivers\AVGIDSShim.sys [19/08/2010 21:42 27216] R3 MBAMProtector;MBAMProtector;i:\windows\system32\drivers\mbam.sys [30/08/2011 13:51 22712] S2 AVGIDSAgent;AVGIDSAgent;i:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18/04/2011 17:39 7398752] S3 ACSSCR;ACR38 Smart Card Reader;i:\windows\system32\drivers\a38usb.sys [24/03/2006 20:14 33536] S3 cxbu0wdm;CardMan 3x21;i:\windows\system32\drivers\cxbu0wdm.sys [15/01/2008 12:39 97792] S3 MBAMSwissArmy;MBAMSwissArmy;i:\windows\system32\drivers\mbamswissarmy.sys [30/08/2011 13:51 41272] S3 P1130VID;Creative WebCam NX Pro;i:\windows\system32\drivers\P1130Vid.sys [26/05/2007 17:46 90229] S3 WDC_SAM;WD SCSI Pass Thru driver;i:\windows\system32\drivers\wdcsam.sys [13/03/2010 10:54 11520] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{144cf342-2e7d-11df-99da-001372e5df1c}] \Shell\AutoRun\command - "L:\WD SmartWare.exe" autoplay=true . Contents of the 'Scheduled Tasks' folder . 2011-08-30 i:\windows\Tasks\Google Software Updater.job - i:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-14 19:10] . 2011-08-12 i:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1606980848-1801674531-1004Core.job - i:\documents and settings\JOS CORNELIS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-09 11:19] . 2011-08-29 i:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1606980848-1801674531-1004UA.job - i:\documents and settings\JOS CORNELIS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-09 11:19] . 2011-08-30 i:\windows\Tasks\User_Feed_Synchronization-{C3A91DC5-13DF-4100-A733-6A8BDC840A51}.job - i:\windows\system32\msfeedssync.exe [2007-08-13 17:36] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - i:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - i:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: dexia.be\directnet Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 195.130.131.129 195.130.130.1 FF - ProfilePath - i:\documents and settings\JOS CORNELIS\Application Data\Mozilla\Firefox\Profiles\64lm23s4.default\ FF - prefs.js: browser.search.selectedEngine - BearShare Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/ FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - i:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - i:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - i:\program files\AVG\AVG10\Firefox4 . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) HKCU-Run-Picasa Media Detector - i:\program files\Picasa2\PicasaMediaDetector.exe HKLM-Run-MBkLogonHook - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2011-08-30 15:02 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover Windows 5.1.2600 Disk: TEAC____ rev.4.00 -> Harddisk4\DR5 -> \Device\0000006f . device: opened successfully user: MBR read successfully . Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys USBSTOR.SYS hal.dll usbhub.sys USBPORT.SYS usbehci.sys 1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk4\DR5[0x8AE71AB8] 3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000006f[0x8B0296A8] 5 USBSTOR[0xACE43706] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\USBPDO-7[0x8AE7E1F0] 7 usbhub[0xBA148596] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\USBPDO-0[0x8AC29030] kernel: MBR read successfully _asm { CLI ; XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV SI, SP; PUSH AX; POP ES; PUSH AX; POP DS; STI ; CLD ; MOV DI, 0x600; MOV CX, 0x100; REPNZ MOVSW ; JMP FAR 0x0:0x61d; } detected disk devices: \Device\Ide\IdeDeviceP1T0L0-17 -> \??\IDE#DiskST3160812AS_____________________________3.ADJ___#5&2510770d&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found detected hooks: \Driver\atapi DriverStartIo -> 0x8B0F527F user & kernel MBR OK error: Read The parameter is incorrect. . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1177238915-1606980848-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(976) i:\windows\system32\WPDShServiceObj.dll i:\windows\system32\PortableDeviceTypes.dll i:\windows\system32\PortableDeviceApi.dll i:\program files\Malwarebytes' Anti-Malware\mbamext.dll i:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll i:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll i:\program files\Microsoft Office\OFFICE11\msohev.dll i:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll . ------------------------ Other Running Processes ------------------------ . i:\windows\system32\Ati2evxx.exe i:\windows\System32\SCardSvr.exe i:\windows\stsystra.exe i:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe i:\program files\Java\jre6\bin\jqs.exe i:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE i:\program files\AVG\AVG10\avgui.exe i:\program files\HP\Digital Imaging\bin\hpqSTE08.exe i:\program files\HP\Digital Imaging\bin\hpqbam08.exe i:\program files\HP\Digital Imaging\bin\hpqgpc01.exe i:\windows\TEMP\conhost.exe . ************************************************************************** . Completion time: 2011-08-30 15:09:04 - machine was rebooted ComboFix-quarantined-files.txt 2011-08-30 13:08 . Pre-Run: 56,532,701,184 bytes free Post-Run: 58.904.739.840 bytes free . - - End Of File - - 5FD61C26E9A6DBB5D575C88A7DB12B59

OVER ONS
PC Helpforum helpt GRATIS computergebruikers sinds juli 2006. Ons team geeft via het forum professioneel antwoord op uw vragen en probeert uw pc problemen zo snel mogelijk op te lossen. Word lid vandaag, plaats je vraag online en het PC Helpforum-team helpt u graag verder!