Ga naar inhoud

Hillytom

Lid
  • Items

    14
  • Registratiedatum

  • Laatst bezocht

Hillytom's prestaties

  1. Beste, Om plaats te maken op mn ssd heb ik een "clean disk" en defragmentatie gedaan op die ssd schijf die ook mn C: was. Na wat op internet te zoeken had ik beter van die ssd gebleven... Nu bij opstart kom ik in system recovery en probeert de pc Startup repair te doen. Er komt op het scherm " Windows cannot repair this computer automatically". Via "System image recovery" heb ik gezien dat mn C: veranderd is in D: en omgekeerd... Waarschijnlijk daarom dat hij niet meer start... Ik heb ook al enkele tips geprobeerd van op internet maar voorlopig is niets gelukt... Hopelijk heb ik dit een beetje verstaanbaar kunnen uitleggen. Kan mij iemand helpen?? Mvg
  2. ziehier : Emsisoft Emergency Kit - Versie 1.0 Laatste Update: 15/01/2012 10:31:05 Scaninstellingen: Scantype: Diepe Scan Objecten: Geheugen, Sporen, Cookies, C:\ Scan archieven: Aan Heuristieken: Uit ADS Scan: Aan Scan gestart: 15/01/2012 19:53:07 c:\programdata\microsoft\windows\start menu\programs\PopCap Games Ontdekt: Trace.Directory.Bejeweled 2 Deluxe 1.0!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Ontdekt: Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Ontdekt: Trace.Registry.Trymedia!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 1 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 10 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 2 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 4 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 5 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 6 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 7 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 9 Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> AdsLastKnownState Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> AppPath Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> id Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> InitialPort Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> InstallState Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> SL Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> TableType Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> useCount Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> AutoLoginToOtherGames Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> CFDialogShown Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> FreshInstall Ontdekt: Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> OldCFformat Ontdekt: Trace.Registry.PartyPoker!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:207 Ontdekt: Trace.TrackingCookie.doubleclick.net!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:532 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:7710 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:9748 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:10492 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:11974 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:12014 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:12422 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:14061 Ontdekt: Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:14062 Ontdekt: Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:15119 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:15428 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:17805 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:18130 Ontdekt: Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:18742 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19698 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19730 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19854 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:20028 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21183 Ontdekt: Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21184 Ontdekt: Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21185 Ontdekt: Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21614 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:22403 Ontdekt: Trace.TrackingCookie.media!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23018 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23132 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23141 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25079 Ontdekt: Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25092 Ontdekt: Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25099 Ontdekt: Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25476 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:26532 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:27365 Ontdekt: Trace.TrackingCookie.www.emjcd.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:29734 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:31674 Ontdekt: Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:33159 Ontdekt: Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:33160 Ontdekt: Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:34783 Ontdekt: Trace.TrackingCookie.doubleclick.net!A2 C:\System Volume Information\SystemRestore\FRStaging\Users\Cindy Cottenjé\AppData\Roaming\.minecraft\Minecraft Cracked.exe Ontdekt: possible-Threat.Crack.Minecraft!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\68d71ddc-729447c7/Translate.class Ontdekt: Exploit.Java.CVE-2011!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\44f16cac-18b0658d/Market.class Ontdekt: Exploit.Java.CVE!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\a$1.class Ontdekt: Java.Trojan-Downloader.OpenConnection!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\a.class Ontdekt: Trojan-Downloader.Java.OpenConnection!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\b.class Ontdekt: Trojan.Java.Agent!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\KAVS.class Ontdekt: Trojan-Downloader.Java.OpenConnection!IK C:\Users\Cindy Cottenjé\Documents\Cindy\6de\Frans\ru-s3gnp.rar/The.Sims.3.Generic.NoDVD.Patcher.exe Ontdekt: Riskware.Patch.Sims3!IK Gescand Bestanden: 663894 Sporen: 404020 Cookies: 2695 Processen: 56 Gevonden Bestanden: 8 Sporen: 23 Cookies: 38 Processen: 0 Registersleutels: 0 Scan Geëindigd: 16/01/2012 2:36:09 Scantijd: 6:43:02 C:\Users\Cindy Cottenjé\Documents\Cindy\6de\Frans\ru-s3gnp.rar/The.Sims.3.Generic.NoDVD.Patcher.exe Verwijderd Riskware.Patch.Sims3!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\b.class Verwijderd Trojan.Java.Agent!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\a.class Verwijderd Trojan-Downloader.Java.OpenConnection!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\KAVS.class Verwijderd Trojan-Downloader.Java.OpenConnection!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\75c2b5f1-5dcc5cf0/bpac\a$1.class Verwijderd Java.Trojan-Downloader.OpenConnection!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\44f16cac-18b0658d/Market.class Verwijderd Exploit.Java.CVE!IK C:\Users\Cindy Cottenjé\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\68d71ddc-729447c7/Translate.class Verwijderd Exploit.Java.CVE-2011!IK C:\System Volume Information\SystemRestore\FRStaging\Users\Cindy Cottenjé\AppData\Roaming\.minecraft\Minecraft Cracked.exe Verwijderd possible-Threat.Crack.Minecraft!IK C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:33159 Verwijderd Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:33160 Verwijderd Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:27365 Verwijderd Trace.TrackingCookie.www.emjcd.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25476 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25079 Verwijderd Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25092 Verwijderd Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:25099 Verwijderd Trace.TrackingCookie.cms!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:22403 Verwijderd Trace.TrackingCookie.media!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21183 Verwijderd Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21184 Verwijderd Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21185 Verwijderd Trace.TrackingCookie.d1.openx.org!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:18130 Verwijderd Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:14061 Verwijderd Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:14062 Verwijderd Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:31674 Verwijderd Trace.TrackingCookie.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:532 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:7710 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:9748 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:10492 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:11974 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:12014 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:12422 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:15119 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:15428 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:17805 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:18742 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19698 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19730 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:19854 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:20028 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:21614 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23018 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23132 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:23141 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:26532 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:29734 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:207 Verwijderd Trace.TrackingCookie.doubleclick.net!A2 C:\Users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\cookies.sqlite:34783 Verwijderd Trace.TrackingCookie.doubleclick.net!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 1 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 10 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 2 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 4 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 5 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 6 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 7 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> 9 Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> AdsLastKnownState Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> AppPath Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> id Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> InitialPort Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> InstallState Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> SL Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> TableType Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming\PartyPoker --> useCount Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> AutoLoginToOtherGames Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> CFDialogShown Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> FreshInstall Verwijderd Trace.Registry.PartyPoker!A2 Value: HKEY_CURRENT_USER\Software\PartyGaming --> OldCFformat Verwijderd Trace.Registry.PartyPoker!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Verwijderd Trace.Registry.Trymedia!A2 Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Verwijderd Trace.Registry.Trymedia!A2 c:\programdata\microsoft\windows\start menu\programs\PopCap Games Verwijderd Trace.Directory.Bejeweled 2 Deluxe 1.0!A2 Verwijderd Bestanden: 8 Sporen: 23 Cookies: 38
  3. Beste; Sorry voor late reply maar die "ipconfig /flushdns " werkte mss 1 dag goed en kwam dan terug. Ben dit virus redelijk moe aan het worden, kan nu TDSSkiller ook niet meer starten... Mgv
  4. hier logje terwijl dat scherm met "iphone gewonnen" op staat. en google doet ook nog altijd raar. Gaat naar reclame sites als ik op een zoekopdracht klik Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:55:37, on 31/12/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\System32\mobsync.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: SMART Sync - {8E1233B3-485A-4E51-B77E-9E075A68C588} - C:\Program Files\SMART Technologies\Classroom Teacher\Sync Teacher\SyncIEToolbar.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Dvd- of cd-deling] "C:\Program Files\Dvd- of cd-deling\ODSAgent.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [iSTray] "C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O8 - Extra context menu item: Afbeelding verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Pagina verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Planner voor Automatische LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: ExtraFilm upload service (EFUploadSrv) - Textalk AB - C:\Program Files\ExtraFilm Designer BE NL\EFUploadSrv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: SAMSUNG KiesAllShare Service (KiesAllShare) - Unknown owner - C:\Program Files\Samsung\Kies\WiselinkPro\WiselinkPro.exe (file missing) O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: Response-hardware (Response Hardware) - SMART Technologies - C:\Program Files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe -- End of file - 7764 bytes
  5. Alles lijkt perfect! Bedankt! Kreeg zonet nog een bericht op bureaublad dat ik een Iphone gewonnen heb! Weet wel niet welke infectie dat is! Alvast bedankt!!!!
  6. Voila nieuwe log ComboFix 11-12-27.01 - Cindy Cottenjé 27/12/2011 17:42:16.3.2 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.2814.1389 [GMT 1:00] Gestart vanuit: c:\users\Cindy Cottenjé\Desktop\ComboFix.exe gebruikte Opdracht switches :: c:\users\Cindy Cottenjé\Documents\CFScript.txt AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "C:\symlcsv1.exe" "c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP" . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\symlcsv1.exe . . (((((((((((((((((((( Bestanden Gemaakt van 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))) . . 2011-12-27 17:19 . 2011-12-27 17:21 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\temp 2011-12-27 17:19 . 2011-12-27 17:19 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-12-26 16:21 . 2011-12-26 16:21 -------- d-----w- c:\programdata\Kaspersky Lab 2011-12-26 15:58 . 2011-12-26 15:58 -------- d-----w- c:\program files\Common Files\Java 2011-12-26 15:58 . 2011-12-26 15:57 476904 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll 2011-12-26 15:58 . 2011-12-26 15:57 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin7.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin.dll 2011-12-26 15:46 . 2011-12-26 15:46 -------- d-----w- c:\programdata\Apple Computer 2011-12-26 15:43 . 2011-12-26 15:43 -------- d-----w- c:\program files\Common Files\Apple 2011-12-26 15:42 . 2011-12-26 15:42 -------- d-----w- c:\program files\Apple Software Update 2011-12-25 18:37 . 2011-12-25 18:37 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll 2011-12-25 18:37 . 2011-12-25 18:37 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll 2011-12-25 18:37 . 2011-12-25 18:37 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll 2011-12-25 18:37 . 2011-12-25 18:37 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll 2011-12-25 09:02 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE21603D-26BC-4582-BEA4-D00E5088B0BC}\mpengine.dll 2011-12-24 13:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-12-24 13:40 . 2011-12-24 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-24 12:53 . 2011-12-24 12:53 -------- d-----w- c:\program files\Trend Micro 2011-12-24 07:07 . 2011-12-24 07:07 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2011-12-24 06:33 . 2011-12-24 06:33 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\InstallShield 2011-12-23 07:56 . 2011-11-22 17:20 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys 2011-12-23 07:56 . 2011-11-22 17:20 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys 2011-12-23 07:56 . 2011-11-22 17:20 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys 2011-12-22 13:28 . 2011-12-22 13:28 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\Threat Expert 2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1230.old 2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1229.old 2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1229.old 2011-12-22 08:37 . 2011-11-22 18:38 105792 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys 2011-12-22 08:37 . 2011-11-22 18:38 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2011-12-22 08:37 . 2011-11-22 18:41 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys 2011-12-22 08:36 . 2011-11-22 18:43 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2011-12-22 08:36 . 2011-12-22 08:36 -------- d-----w- c:\program files\PC Tools 2011-12-22 08:33 . 2011-10-07 16:52 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys 2011-12-22 08:33 . 2011-10-07 16:52 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys 2011-12-22 08:33 . 2011-11-14 14:12 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2011-12-22 08:33 . 2011-11-14 14:12 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2011-12-22 08:33 . 2011-11-22 18:42 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys 2011-12-22 08:33 . 2011-12-22 08:40 -------- d-----w- c:\program files\Common Files\PC Tools 2011-12-22 08:32 . 2011-12-23 07:56 -------- d-----w- c:\programdata\PC Tools 2011-12-22 08:32 . 2011-12-22 08:32 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\TestApp 2011-12-20 09:19 . 2011-12-22 17:18 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\kbdobjCtrl 2011-12-19 19:56 . 2011-12-19 20:03 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\Trine2 2011-12-14 18:22 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-12-14 18:22 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-12-14 18:22 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys 2011-12-14 18:22 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll 2011-12-14 18:22 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-12-14 18:22 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll 2011-12-14 18:22 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll 2011-11-29 17:36 . 2011-12-22 17:17 -------- d-----w- c:\program files\StarCraft II . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-26 19:42 . 2011-06-22 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts 2011-12-25 18:37 . 2011-05-02 17:20 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-12-27_12.47.30 ))))))))))))))))))))))))))))))))))))))))) . - 2008-12-25 09:31 . 2011-12-27 11:23 65536 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-12-25 09:31 . 2011-12-27 16:32 65536 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-12-25 09:31 . 2011-12-27 16:32 311296 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-12-25 09:31 . 2011-12-27 11:23 311296 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-12-25 09:31 . 2011-12-27 16:32 196608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-12-25 09:31 . 2011-12-27 11:23 196608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-21 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Dvd- of cd-deling"="c:\program files\Dvd- of cd-deling\ODSAgent.exe" [2008-02-20 619832] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "<NO NAME>"= 0 . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "<NO NAME>"= 0 . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk backup=c:\windows\pss\Bluetooth.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bureaubladmenu.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bureaubladmenu.lnk backup=c:\windows\pss\Bureaubladmenu.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board-hulpmiddelen.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board-hulpmiddelen.lnk backup=c:\windows\pss\SMART Board-hulpmiddelen.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk backup=c:\windows\pss\Dropbox.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kuma_Tray.lnk backup=c:\windows\pss\Kuma_Tray.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface] 2011-11-12 00:48 3303000 ----a-w- c:\users\Cindy Cottenjé\AppData\Local\Akamai\netsession_win.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-phishing Domain Advisor] 2011-01-31 22:17 232104 ----a-w- c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] 2010-08-31 08:04 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2011-08-07 07:26 136176 ----atw- c:\users\Cindy Cottenjé\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper] 2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR] 2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2008-06-27 03:42 6295552 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service] 2010-08-23 13:02 5347728 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTBoardService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent] 2010-08-23 13:03 1662352 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTSNMPAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys] 2008-02-04 09:13 1038136 ----a-w- c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2009-04-21 08:30 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2007-06-08 17:53 894512 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:35 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-29 20032] R3 EFUploadSrv;ExtraFilm upload service;c:\program files\ExtraFilm Designer BE NL\EFUploadSrv.exe [2009-07-09 1716224] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-31 30192] R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664] R3 KiesAllShare;SAMSUNG KiesAllShare Service;c:\program files\Samsung\Kies\WiselinkPro\WiselinkPro.exe [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x] R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-05-06 23096] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [2011-11-22 70536] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [2011-11-22 402336] R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560] R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848] R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648] R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-11-22 35264] R3 ThreatFire;ThreatFire;c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\System32\Drivers\pctBTFix.sys [2011-11-22 17848] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-14 331880] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-10-07 660992] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-04 691696] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-11-22 54328] S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-11-22 574424] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2011-11-22 253096] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-11-22 185560] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504] S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-25 217088] S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-06-24 65856] S2 Response Hardware;Response-hardware;c:\program files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe [2010-08-23 30608] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-12-22 29736] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-05-25 36640] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-05-07 85136] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 350720] S3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-08-23 11152] S3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-08-23 14224] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-03-19 22072] S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-11-17 13976] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - FSUSBEXDISK *Deregistered* - PCTSDInjDriver32 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache bthsvcs REG_MULTI_SZ BthServ Akamai REG_MULTI_SZ Akamai . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . Inhoud van de 'Gedeelde Taken' map . 2011-12-27 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-21 07:22] . 2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40] . 2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40] . 2011-12-27 c:\windows\Tasks\Recovery DVD Creator-Cindy Cottenjé.job - c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-10-08 09:13] . 2011-12-27 c:\windows\Tasks\Uitgebreide garantie-Cindy Cottenjé.job - c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-10-08 09:13] . . ------- Bijkomende Scan ------- . mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Afbeelding verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Pagina verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll TCP: DhcpNameServer = 195.130.131.5 195.130.130.133 FF - ProfilePath - c:\users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2011-12-27 18:21 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover Windows 6.0.6002 Disk: Hitachi_HTS543216L9A300 rev.FB2OC40C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 . device: opened successfully user: MBR read successfully kernel: MBR read successfully user != kernel MBR !!! sectors 312581791 (+0): user != kernel . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai] "ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-4240524916-931938033-4048848888-1000\Software\SecuROM\License information*] "datasecu"=hex:7d,31,bd,ef,ca,a5,1e,ab,72,34,a0,41,15,5d,16,65,88,78,2a,77,f3, ae,26,79,4a,74,c1,bf,3c,54,b1,6f,29,67,1c,4e,00,0b,b3,99,cd,c6,ce,9d,93,f6,\ "rkeysecu"=hex:b1,77,54,1c,da,d2,01,20,f4,54,4d,05,27,51,cc,62 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Voltooingstijd: 2011-12-27 18:38:05 ComboFix-quarantined-files.txt 2011-12-27 17:37 ComboFix2.txt 2011-12-27 16:29 ComboFix3.txt 2011-12-27 13:06 . Pre-Run: 30.023.753.728 bytes beschikbaar Post-Run: 29.882.941.440 bytes beschikbaar . - - End Of File - - 621E16826DF27EF7926B754C8B835628
  7. ziehier ; ComboFix 11-12-26.03 - 27/12/2011 13:03:05.1.2 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.2814.1523 [GMT 1:00] Gestart vanuit: c:\users\Cindy CottenjÚ\Desktop\ComboFix.exe AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\~njRk4PQtwSwpVC c:\programdata\~njRk4PQtwSwpVCr c:\programdata\njRk4PQtwSwpVC c:\users\Cindy Cottenjé\AppData\Local\Temp\ppcrlui_1444_2 c:\users\CINDYC~1\AppData\Local\Temp\ppcrlui_1444_2 c:\windows\IsUn0413.exe c:\windows\iun6002.exe c:\windows\system32\muzapp.exe . . (((((((((((((((((((( Bestanden Gemaakt van 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))) . . 2011-12-27 12:43 . 2011-12-27 12:47 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\temp 2011-12-27 12:43 . 2011-12-27 12:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-12-26 16:21 . 2011-12-26 16:21 -------- d-----w- c:\programdata\Kaspersky Lab 2011-12-26 15:58 . 2011-12-26 15:58 -------- d-----w- c:\program files\Common Files\Java 2011-12-26 15:58 . 2011-12-26 15:57 476904 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll 2011-12-26 15:58 . 2011-12-26 15:57 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin7.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll 2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin.dll 2011-12-26 15:46 . 2011-12-26 15:46 -------- d-----w- c:\programdata\Apple Computer 2011-12-26 15:43 . 2011-12-26 15:43 -------- d-----w- c:\program files\Common Files\Apple 2011-12-26 15:42 . 2011-12-26 15:42 -------- d-----w- c:\program files\Apple Software Update 2011-12-25 18:37 . 2011-12-25 18:37 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll 2011-12-25 18:37 . 2011-12-25 18:37 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll 2011-12-25 18:37 . 2011-12-25 18:37 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll 2011-12-25 18:37 . 2011-12-25 18:37 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll 2011-12-25 09:02 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE21603D-26BC-4582-BEA4-D00E5088B0BC}\mpengine.dll 2011-12-24 13:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-12-24 13:40 . 2011-12-24 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-24 12:53 . 2011-12-24 12:53 -------- d-----w- c:\program files\Trend Micro 2011-12-24 07:07 . 2011-12-24 07:07 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP 2011-12-24 06:33 . 2011-12-24 06:33 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\InstallShield 2011-12-23 07:56 . 2011-11-22 17:20 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys 2011-12-23 07:56 . 2011-11-22 17:20 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys 2011-12-23 07:56 . 2011-11-22 17:20 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys 2011-12-22 14:42 . 2011-12-22 14:42 58760 ----a-w- C:\symlcsv1.exe 2011-12-22 13:28 . 2011-12-22 13:28 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\Threat Expert 2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1230.old 2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1229.old 2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1237.old 2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1229.old 2011-12-22 08:37 . 2011-11-22 18:38 105792 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys 2011-12-22 08:37 . 2011-11-22 18:38 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2011-12-22 08:37 . 2011-11-22 18:41 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys 2011-12-22 08:36 . 2011-11-22 18:43 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2011-12-22 08:36 . 2011-12-22 08:36 -------- d-----w- c:\program files\PC Tools 2011-12-22 08:33 . 2011-10-07 16:52 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys 2011-12-22 08:33 . 2011-10-07 16:52 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys 2011-12-22 08:33 . 2011-11-14 14:12 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2011-12-22 08:33 . 2011-11-14 14:12 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2011-12-22 08:33 . 2011-11-22 18:42 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys 2011-12-22 08:33 . 2011-12-22 08:40 -------- d-----w- c:\program files\Common Files\PC Tools 2011-12-22 08:32 . 2011-12-23 07:56 -------- d-----w- c:\programdata\PC Tools 2011-12-22 08:32 . 2011-12-22 08:32 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\TestApp 2011-12-20 09:19 . 2011-12-22 17:18 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\kbdobjCtrl 2011-12-19 19:56 . 2011-12-19 20:03 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\Trine2 2011-12-14 18:22 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-12-14 18:22 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-12-14 18:22 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys 2011-12-14 18:22 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll 2011-12-14 18:22 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-12-14 18:22 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll 2011-12-14 18:22 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll 2011-12-11 18:28 . 2011-12-24 13:35 -------- d-----w- c:\program files\StartSearch plugin 2011-11-29 17:36 . 2011-12-22 17:17 -------- d-----w- c:\program files\StarCraft II . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-26 19:42 . 2011-06-22 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts 2011-12-25 18:37 . 2011-05-02 17:20 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-21 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Dvd- of cd-deling"="c:\program files\Dvd- of cd-deling\ODSAgent.exe" [2008-02-20 619832] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "<NO NAME>"= 0 . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "<NO NAME>"= 0 . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk backup=c:\windows\pss\Bluetooth.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bureaubladmenu.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bureaubladmenu.lnk backup=c:\windows\pss\Bureaubladmenu.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board-hulpmiddelen.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board-hulpmiddelen.lnk backup=c:\windows\pss\SMART Board-hulpmiddelen.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk backup=c:\windows\pss\Dropbox.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kuma_Tray.lnk backup=c:\windows\pss\Kuma_Tray.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk] path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface] 2011-11-12 00:48 3303000 ----a-w- c:\users\Cindy Cottenjé\AppData\Local\Akamai\netsession_win.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-phishing Domain Advisor] 2011-01-31 22:17 232104 ----a-w- c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] 2010-08-31 08:04 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2011-08-07 07:26 136176 ----atw- c:\users\Cindy Cottenjé\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper] 2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR] 2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl] 2008-06-27 03:42 6295552 ----a-w- c:\windows\RtHDVCpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service] 2010-08-23 13:02 5347728 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTBoardService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent] 2010-08-23 13:03 1662352 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTSNMPAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys] 2008-02-04 09:13 1038136 ----a-w- c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2009-04-21 08:30 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2007-06-08 17:53 894512 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2008-01-21 02:35 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-29 20032] R3 EFUploadSrv;ExtraFilm upload service;c:\program files\ExtraFilm Designer BE NL\EFUploadSrv.exe [2009-07-09 1716224] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-31 30192] R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664] R3 KiesAllShare;SAMSUNG KiesAllShare Service;c:\program files\Samsung\Kies\WiselinkPro\WiselinkPro.exe [x] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x] R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-05-06 23096] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [2011-11-22 70536] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [2011-11-22 402336] R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560] R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848] R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648] R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-11-22 35264] R3 ThreatFire;ThreatFire;c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\System32\Drivers\pctBTFix.sys [2011-11-22 17848] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-14 331880] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-10-07 660992] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-04 691696] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-11-22 54328] S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-11-22 574424] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2011-11-22 253096] S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-11-22 185560] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504] S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-25 217088] S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-06-24 65856] S2 Response Hardware;Response-hardware;c:\program files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe [2010-08-23 30608] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-12-22 29736] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-05-25 36640] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-05-07 85136] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 350720] S3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-08-23 11152] S3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-08-23 14224] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-03-19 22072] S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-11-17 13976] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - FSUSBEXDISK *Deregistered* - PCTSDInjDriver32 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache bthsvcs REG_MULTI_SZ BthServ Akamai REG_MULTI_SZ Akamai . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc . Inhoud van de 'Gedeelde Taken' map . 2011-12-27 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-21 07:22] . 2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40] . 2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40] . 2011-12-27 c:\windows\Tasks\Recovery DVD Creator-Cindy Cottenjé.job - c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-10-08 09:13] . 2011-12-27 c:\windows\Tasks\Uitgebreide garantie-Cindy Cottenjé.job - c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-10-08 09:13] . . ------- Bijkomende Scan ------- . mStart Page = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Afbeelding verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Pagina verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll TCP: DhcpNameServer = 195.130.131.5 195.130.130.133 FF - ProfilePath - c:\users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\ FF - prefs.js: browser.search.selectedEngine - BearShare Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll HKCU-Run-Driver Updater - (no file) MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe MSConfigStartUp-UniblueRegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe AddRemove-GameCenter - c:\program files\Cyanide\GameCenter\uninstall.exe AddRemove-Robbie Konijn Peuter - c:\windows\IsUn0413.exe AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2011-12-27 13:46 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover Windows 6.0.6002 Disk: Hitachi_HTS543216L9A300 rev.FB2OC40C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 . device: opened successfully user: MBR read successfully kernel: MBR read successfully user != kernel MBR !!! sectors 312581791 (+0): user != kernel . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai] "ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-4240524916-931938033-4048848888-1000\Software\SecuROM\License information*] "datasecu"=hex:7d,31,bd,ef,ca,a5,1e,ab,72,34,a0,41,15,5d,16,65,88,78,2a,77,f3, ae,26,79,4a,74,c1,bf,3c,54,b1,6f,29,67,1c,4e,00,0b,b3,99,cd,c6,ce,9d,93,f6,\ "rkeysecu"=hex:b1,77,54,1c,da,d2,01,20,f4,54,4d,05,27,51,cc,62 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Voltooingstijd: 2011-12-27 14:06:15 ComboFix-quarantined-files.txt 2011-12-27 13:05 . Pre-Run: 29.977.309.184 bytes beschikbaar Post-Run: 30.016.872.448 bytes beschikbaar . - - End Of File - - 2333F31F0B5CD9FBD9D4FF376208DBB9
  8. gedaan en dit is het logje This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Rkill was run on 27/12/2011 at 10:42:57. Operating System: Windows Vista Home Basic Processes terminated by Rkill or while it was running: Rkill completed on 27/12/2011 at 10:44:21.
  9. Neen niets lukt. Heb opgezocht op internet en is iets in de vorm van "redirect virus" een zoekopdracht in google brengt ja naar een andere site met reclame.
  10. Als ik TDSSkiller wil openen als administrator vraagt het "Uw toestemming is nodig om programma te openen" en klik op doorgaan maar dan gebeurt er niks ... Mvg
  11. Die laatste opdarachten van KiesAllShare zijn niet gelukt. Toegang geweigerd. Enkel IExplorer werkt traag bij start maar voor de is het stukken beter. Heb ook weer een virusscan gedaan en weer waren een 8 geïnfecteerde bestanden. Waaronder rootkit.rss.v103. Is dat een probleem? Alvast bedankt!!!!!
  12. Bij deze Mbam log : Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Databaseversie: 911122403 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 24/12/2011 15:01:06 mbam-log-2011-12-24 (15-01-06).txt Scantype: Snelle scan Objecten gescand: 178631 Verstreken tijd: 6 minuut/minuten, 29 seconde(n) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 8 Registerwaarden geïnfecteerd: 0 Registerdata geïnfecteerd: 2 Mappen geïnfecteerd: 0 Bestanden geïnfecteerd: 0 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registersleutels geïnfecteerd: HKEY_CLASSES_ROOT\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{BB7256DD-EBA9-480B-8441-A00388C2BEC3} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} (PUP.VShareRedir) -> Quarantined and deleted successfully. Registerwaarden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Registerdata geïnfecteerd: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Mappen geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) Bestanden geïnfecteerd: (Geen kwaadaardige objecten gedetecteerd) en nieuw Hijackthis log : Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:14:26, on 24/12/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: SMART Sync - {8E1233B3-485A-4E51-B77E-9E075A68C588} - C:\Program Files\SMART Technologies\Classroom Teacher\Sync Teacher\SyncIEToolbar.dll O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Dvd- of cd-deling] "C:\Program Files\Dvd- of cd-deling\ODSAgent.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [iSTray] "C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra context menu item: Afbeelding verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Pagina verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Planner voor Automatische LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: ExtraFilm upload service (EFUploadSrv) - Textalk AB - C:\Program Files\ExtraFilm Designer BE NL\EFUploadSrv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: SAMSUNG KiesAllShare Service (KiesAllShare) - Unknown owner - C:\Program Files\Samsung\Kies\WiselinkPro\WiselinkPro.exe (file missing) O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: Response-hardware (Response Hardware) - SMART Technologies - C:\Program Files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe -- End of file - 8431 bytes
  13. Kape ; Bedankt voor de snelle reply!!!!! Is nu een Malwarebyte scan aan het doen... zal zo rap mogelijk de log's posten
  14. Beste; Heb na 2 dagen proberen uiteindelijk System Fix van mijn computer gekregen. Alle problemen zijn echter niet van de baan: Computer werkt/reageert zeertraag, loopt soms vast met foutmelding "windows verkenner werkt nietmeer". Internetbrowser loopt soms vast maar na een tijdje werkt het welgoed. Heb eerst wat ruimte gemaakt op HD door programmas te verwijderen en heb nu Pc Tools Spyware Doctor met antivirus lopen. Wie kan mij aub helpen? Hier een log van HijackThis Mvg ; Tom Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:04:09, on 24/12/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\explorer.exe C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: PC Tools Browser Defender - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O2 - BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\StartSearch plugin\ssBarLcher.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll O3 - Toolbar: Sopcast Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll O3 - Toolbar: SMART Sync - {8E1233B3-485A-4E51-B77E-9E075A68C588} - C:\Program Files\SMART Technologies\Classroom Teacher\Sync Teacher\SyncIEToolbar.dll O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll O3 - Toolbar: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll O3 - Toolbar: StartSearchToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\ssBarLcher.dll O3 - Toolbar: PC Tools Browser Defender - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Dvd- of cd-deling] "C:\Program Files\Dvd- of cd-deling\ODSAgent.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [iSTray] "C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [spyware Doctor with AntiVirus] C:\Users\Cindy Cottenjé\Desktop\iexplorer.exe.exe -min O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra context menu item: Afbeelding verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Pagina verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: http://.get.adobe.com O15 - Trusted Zone: Adobe O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O20 - AppInit_DLLs: C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Planner voor Automatische LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: ExtraFilm upload service (EFUploadSrv) - Textalk AB - C:\Program Files\ExtraFilm Designer BE NL\EFUploadSrv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: SAMSUNG KiesAllShare Service (KiesAllShare) - Unknown owner - C:\Program Files\Samsung\Kies\WiselinkPro\WiselinkPro.exe (file missing) O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe O23 - Service: Response-hardware (Response Hardware) - SMART Technologies - C:\Program Files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe -- End of file - 9925 bytes
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.