Ga naar inhoud

Antimalware Doctor


Aanbevolen berichten

Geplaatst: (aangepast)

Ik heb de Combofix laten draaien en dit kwam eruit:

ComboFix 10-05-05.0B - Muriël Wijnia 06-05-2010 15:57:06.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.502.178 [GMT 2:00]

Gestart vanuit: c:\documents and settings\Muriël Wijnia\Bureaublad\ComboFixx.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Muriël Wijnia\Application Data\05E8E560CAF3D9AA1D9B110DE15C5765

c:\documents and settings\Muriël Wijnia\Application Data\05E8E560CAF3D9AA1D9B110DE15C5765\enemies-names.txt

c:\documents and settings\Muriël Wijnia\Application Data\05E8E560CAF3D9AA1D9B110DE15C5765\gotnewupdate000.exe

c:\recycler\S-1-5-21-4712163600-0518897430-860320300-7964

c:\windows\system32\mmdfrggt.dll

Besmet exemplaar van c:\windows\system32\drivers\cdrom.sys werd aangetroffen en gedesinfecteerd

Hersteld exemplaar van - Kitty had a snack :P

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_SSHNAS

(((((((((((((((((((( Bestanden Gemaakt van 2010-04-06 to 2010-05-06 ))))))))))))))))))))))))))))))

.

2010-05-06 13:49 . 2010-05-06 13:50 -------- d-----w- C:\ComboFix

2010-05-06 11:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-06 11:19 . 2010-05-06 11:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-05-06 11:19 . 2010-05-06 11:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-06 11:19 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-06 10:16 . 2010-05-06 10:16 -------- d-----w- c:\program files\Trend Micro

2010-05-05 22:01 . 2010-05-05 22:01 -------- d-----w- c:\program files\Enigma Software Group

2010-05-05 21:59 . 2010-05-06 00:47 -------- d-----w- c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP

2010-05-05 21:59 . 2010-05-05 21:59 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-05-05 21:22 . 2010-05-05 21:22 50990 ----a-w- c:\windows\system32\ousloegesajbt.exe

2010-04-22 11:24 . 2010-04-22 11:24 242696 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys

2010-04-22 11:20 . 2010-04-22 11:20 1689952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll

2010-04-10 21:38 . 2005-02-26 05:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll

2010-04-09 14:23 . 2010-04-09 14:24 -------- d-----w- c:\program files\Zylom Games

2010-04-08 07:23 . 2010-04-08 07:23 4255072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-05-06 12:13 . 2009-09-04 17:25 -------- d-----w- c:\program files\Lexmark 1200 Series

2010-05-06 10:39 . 2010-03-11 19:17 -------- d-----w- c:\program files\Xvid

2010-05-06 10:39 . 2009-08-29 07:58 -------- d-----w- c:\program files\QuickTime

2010-05-06 10:38 . 2009-08-27 17:24 -------- d-----w- c:\program files\Microsoft Silverlight

2010-05-06 10:36 . 2009-10-19 12:06 -------- d-----w- c:\program files\LimeWire

2010-05-06 10:35 . 2009-08-29 07:59 -------- d-----w- c:\program files\iTunes

2010-05-06 10:34 . 2009-11-18 14:55 -------- d-----w- c:\program files\DivX

2010-05-06 10:33 . 2009-11-05 21:44 -------- d-----w- c:\program files\Common Files\DVDVideoSoft

2010-05-06 10:32 . 2009-08-29 07:58 -------- d-----w- c:\program files\Bonjour

2010-05-06 10:32 . 2009-08-29 07:58 -------- d-----w- c:\program files\Apple Software Update

2010-05-06 00:29 . 2009-11-27 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

2010-05-05 23:50 . 2009-08-27 17:14 -------- d-----w- c:\program files\Windows Media Connect 2

2010-05-05 23:50 . 2009-08-29 07:52 -------- d-----w- c:\program files\Windows Live SkyDrive

2010-05-05 23:39 . 2009-11-05 21:47 -------- d-----w- c:\program files\PHPNukeDU

2010-05-05 23:38 . 2009-08-27 18:51 -------- d-----w- c:\program files\Microsoft Works

2010-05-05 22:46 . 2009-11-27 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar

2010-04-22 11:23 . 2009-08-27 18:36 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-04-15 13:00 . 2009-08-27 18:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-03-28 07:25 . 2008-04-15 12:00 87068 ----a-w- c:\windows\system32\perfc013.dat

2010-03-28 07:25 . 2008-04-15 12:00 501868 ----a-w- c:\windows\system32\perfh013.dat

2010-03-17 07:55 . 2010-03-17 07:55 12464 ----a-w- c:\windows\system32\avgrsstx.dll

2010-03-17 07:55 . 2009-08-27 18:36 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2010-03-17 07:53 . 2009-08-27 18:36 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-03-10 06:17 . 2009-08-17 09:36 420352 ----a-w- c:\windows\system32\vbscript.dll

2010-02-25 06:13 . 2009-08-17 09:36 919040 ----a-w- c:\windows\system32\wininet.dll

2010-02-24 11:57 . 2009-08-17 09:34 457216 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2010-02-16 19:02 . 2009-08-17 09:34 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe

2010-02-16 19:02 . 2009-02-09 11:19 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe

2010-02-12 10:03 . 2010-03-11 19:07 293376 ------w- c:\windows\system32\browserchoice.exe

2010-02-12 04:32 . 2008-04-15 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll

2010-02-11 11:36 . 2009-08-17 09:34 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys

2009-11-18 14:55 . 2009-11-18 14:55 6666536 ----a-w- c:\program files\DivXWebPlayerInstaller.exe

2009-11-04 16:42 . 2009-11-04 16:42 90357136 ----a-w- c:\program files\HEMA_NL_Fotoservice.exe

.

------- Sigcheck -------

[-] 2009-08-17 . 497BEF5C5FAD126CA16437C1682F64EA . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-11-25 12:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27-8-2009 20:36 216200]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [27-8-2009 20:36 242896]

R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [17-3-2010 9:55 308064]

.

Inhoud van de 'Gedeelde Taken' map

2010-05-05 c:\windows\Tasks\ParetoLogic Registration3.job

- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-08-04 18:19]

2009-12-16 c:\windows\Tasks\ParetoLogic Update Version3.job

- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-08-04 18:19]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.nl/

uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

uInternet Settings,ProxyOverride = *.local

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

.

- - - - ORPHANS VERWIJDERD - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

WebBrowser-{46735DEE-F862-49D1-876D-6382794DC625} - (no file)

AddRemove-Aangifte inkomstenbelasting 2008 - c:\documents and settings\Muriël Wijnia\Mijn documenten\2008\ib2008u.exe

AddRemove-Aangifte inkomstenbelasting 2009 - c:\documents and settings\Muriël Wijnia\Mijn documenten\Belastingdienst\2009\ib2009u.exe

AddRemove-{C1C441C4-57FA-4950-BDBA-BABFBAA2AA39} - c:\program files\ParetoLogic\FileCure\uninstall.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2010-05-06 16:05

Windows 5.1.2600 Service Pack 3 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,39,c7,ba,83,69,22,42,4f,8d,ee,76,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,39,c7,ba,83,69,22,42,4f,8d,ee,76,\

[HKEY_USERS\S-1-5-21-1935655697-813497703-842925246-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*T%î*Ú*]

@Class="Shell"

[HKEY_USERS\S-1-5-21-1935655697-813497703-842925246-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*T%î*Ú*\OpenWithList]

@Class="Shell"

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

- - - - - - - > 'explorer.exe'(6412)

c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll

c:\windows\system32\msi.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

c:\program files\Microsoft Office\Office12\1043\GrooveIntlResource.dll

c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll

c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.NLD

c:\program files\Malwarebytes' Anti-Malware\mbamext.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\system32\LEXBCES.EXE

c:\windows\system32\LEXPPS.EXE

c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

c:\program files\AVG\AVG9\avgnsx.exe

c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

c:\windows\system32\wscntfy.exe

c:\program files\AVG\AVG9\avgrsx.exe

c:\program files\AVG\AVG9\avgchsvx.exe

c:\program files\AVG\AVG9\avgcsrvx.exe

c:\combofix\CF17305.cfxxe

.

**************************************************************************

.

Voltooingstijd: 2010-05-06 16:09:04 - machine werd herstart

ComboFix-quarantined-files.txt 2010-05-06 14:09

Pre-Run: 25.257.160.704 bytes beschikbaar

Post-Run: 26.122.604.544 bytes beschikbaar

WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - E2F01470F817FB0EDA4C69FD1A488493

En dit zegt de HiJack:

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 16:12:03, on 6-5-2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - S-1-5-18 Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'SYSTEM')

O4 - S-1-5-18 Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')

O4 - .DEFAULT Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'Default user')

O4 - .DEFAULT Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')

O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe

O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.hema.nl/xupload/XUpload.ocx

O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe

--

End of file - 7780 bytes

Duss..... ben benieuwd..!

---------- Post toegevoegd om 14:19 ---------- Vorige post was om 14:13 ----------

aangepast door kimbeau
Dubbel gepost
Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

File::

c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP

c:\windows\system32\ousloegesajbt.exe

Folder::

c:\program files\PHPNukeDU

Sla dit bestand op je bureaublad op als CFScript.txt.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht. En laat dan eens weten of er nog merkbare problemen zijn ?

Link naar reactie
Delen op andere sites

ComboFix 10-05-05.0B - Muriël Wijnia 06-05-2010 16:54:14.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.502.168 [GMT 2:00]

Gestart vanuit: c:\documents and settings\Muriël Wijnia\Bureaublad\ComboFixx.exe

gebruikte Opdracht switches :: c:\documents and settings\Muriël Wijnia\Bureaublad\CFScript.txt..txt

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::

"c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP"

"c:\windows\system32\ousloegesajbt.exe"

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\program files\PHPNukeDU

c:\program files\PHPNukeDU\INSTALL.LOG

c:\program files\PHPNukeDU\tbPHP1.dll

c:\program files\PHPNukeDU\tbPHPN.dll

c:\program files\PHPNukeDU\UNWISE.EXE

c:\windows\system32\ousloegesajbt.exe

.

(((((((((((((((((((( Bestanden Gemaakt van 2010-04-06 to 2010-05-06 ))))))))))))))))))))))))))))))

.

2010-05-06 13:49 . 2010-05-06 14:47 -------- d-----w- C:\ComboFix

2010-05-06 11:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-06 11:19 . 2010-05-06 11:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-05-06 11:19 . 2010-05-06 11:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-06 11:19 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-06 10:16 . 2010-05-06 10:16 -------- d-----w- c:\program files\Trend Micro

2010-05-05 22:01 . 2010-05-05 22:01 -------- d-----w- c:\program files\Enigma Software Group

2010-05-05 21:59 . 2010-05-06 00:47 -------- d-----w- c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP

2010-05-05 21:59 . 2010-05-05 21:59 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-04-22 11:24 . 2010-04-22 11:24 242696 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys

2010-04-22 11:20 . 2010-04-22 11:20 1689952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll

2010-04-10 21:38 . 2005-02-26 05:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll

2010-04-09 14:23 . 2010-04-09 14:24 -------- d-----w- c:\program files\Zylom Games

2010-04-08 07:23 . 2010-04-08 07:23 4255072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-05-06 12:13 . 2009-09-04 17:25 -------- d-----w- c:\program files\Lexmark 1200 Series

2010-05-06 10:39 . 2010-03-11 19:17 -------- d-----w- c:\program files\Xvid

2010-05-06 10:39 . 2009-08-29 07:58 -------- d-----w- c:\program files\QuickTime

2010-05-06 10:38 . 2009-08-27 17:24 -------- d-----w- c:\program files\Microsoft Silverlight

2010-05-06 10:36 . 2009-10-19 12:06 -------- d-----w- c:\program files\LimeWire

2010-05-06 10:35 . 2009-08-29 07:59 -------- d-----w- c:\program files\iTunes

2010-05-06 10:34 . 2009-11-18 14:55 -------- d-----w- c:\program files\DivX

2010-05-06 10:33 . 2009-11-05 21:44 -------- d-----w- c:\program files\Common Files\DVDVideoSoft

2010-05-06 10:32 . 2009-08-29 07:58 -------- d-----w- c:\program files\Bonjour

2010-05-06 10:32 . 2009-08-29 07:58 -------- d-----w- c:\program files\Apple Software Update

2010-05-06 00:29 . 2009-11-27 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

2010-05-05 23:50 . 2009-08-27 17:14 -------- d-----w- c:\program files\Windows Media Connect 2

2010-05-05 23:50 . 2009-08-29 07:52 -------- d-----w- c:\program files\Windows Live SkyDrive

2010-05-05 23:38 . 2009-08-27 18:51 -------- d-----w- c:\program files\Microsoft Works

2010-05-05 22:46 . 2009-11-27 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar

2010-04-22 11:23 . 2009-08-27 18:36 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-04-15 13:00 . 2009-08-27 18:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-03-28 07:25 . 2008-04-15 12:00 87068 ----a-w- c:\windows\system32\perfc013.dat

2010-03-28 07:25 . 2008-04-15 12:00 501868 ----a-w- c:\windows\system32\perfh013.dat

2010-03-17 07:55 . 2010-03-17 07:55 12464 ----a-w- c:\windows\system32\avgrsstx.dll

2010-03-17 07:55 . 2009-08-27 18:36 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2010-03-17 07:53 . 2009-08-27 18:36 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-03-10 06:17 . 2009-08-17 09:36 420352 ----a-w- c:\windows\system32\vbscript.dll

2010-02-25 06:13 . 2009-08-17 09:36 919040 ----a-w- c:\windows\system32\wininet.dll

2010-02-24 11:57 . 2009-08-17 09:34 457216 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2010-02-16 19:02 . 2009-08-17 09:34 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe

2010-02-16 19:02 . 2009-02-09 11:19 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe

2010-02-12 10:03 . 2010-03-11 19:07 293376 ------w- c:\windows\system32\browserchoice.exe

2010-02-12 04:32 . 2008-04-15 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll

2010-02-11 11:36 . 2009-08-17 09:34 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys

2009-11-18 14:55 . 2009-11-18 14:55 6666536 ----a-w- c:\program files\DivXWebPlayerInstaller.exe

2009-11-04 16:42 . 2009-11-04 16:42 90357136 ----a-w- c:\program files\HEMA_NL_Fotoservice.exe

.

------- Sigcheck -------

[-] 2009-08-17 . 497BEF5C5FAD126CA16437C1682F64EA . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-11-25 12:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\documents and settings\Muri‰l Wijnia\Menu Start\Programma's\Opstarten\

LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-9-30 503808]

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27-8-2009 20:36 216200]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [27-8-2009 20:36 242896]

R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [17-3-2010 9:55 308064]

.

Inhoud van de 'Gedeelde Taken' map

2010-05-05 c:\windows\Tasks\ParetoLogic Registration3.job

- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-08-04 18:19]

2009-12-16 c:\windows\Tasks\ParetoLogic Update Version3.job

- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-08-04 18:19]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.nl/

uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

uInternet Settings,ProxyOverride = *.local

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

.

- - - - ORPHANS VERWIJDERD - - - -

AddRemove-ousloegesajbt - c:\windows\system32\ousloegesajbt.exe

AddRemove-PHPNukeDU Toolbar - c:\progra~1\PHPNUK~1\UNWISE.EXE

**************************************************************************

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden:

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,39,c7,ba,83,69,22,42,4f,8d,ee,76,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,39,c7,ba,83,69,22,42,4f,8d,ee,76,\

[HKEY_USERS\S-1-5-21-1935655697-813497703-842925246-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*T%î*Ú*]

@Class="Shell"

[HKEY_USERS\S-1-5-21-1935655697-813497703-842925246-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*T%î*Ú*\OpenWithList]

@Class="Shell"

.

Voltooingstijd: 2010-05-06 17:00:23

ComboFix-quarantined-files.txt 2010-05-06 15:00

ComboFix2.txt 2010-05-06 14:09

Pre-Run: 26.123.792.384 bytes beschikbaar

Post-Run: 26.113.454.080 bytes beschikbaar

- - End Of File - - 7F14014B6AAED7983161021C143EEAA6

Hier is de logfile van Combofix.... Ik merkte al een tijd niets meer van het virus maar naar ik begrijp is het nu opgelost? Kan ik vanavond weer rustig slapen? Haha

En kan ik verder nog iets doen wat bevordelijk is voor mijn pc, welke programma's kunnen eraf die ik voor dit probleem heb gedownload en moet ik de virusscan alweer helemaal aanzetten?

Link naar reactie
Delen op andere sites

Problemen van de baan, dan is het tijd voor de “grote schoonmaak” : verwijderen van gebruikte programma’s, een cleaning en het verwijderen van de besmette herstelpunten. En dat antivirusprogramma mag onmiddellijk weer ingeschakeld worden.

Verwijder Combofix: Start -> Uitvoeren en typ: ComboFix /Uninstall

Dit zal Combofix verwijderen + gerelateerde mappen en bestanden, herstelt de klokinstellingen opnieuw, verbergt de bestandsextensies, gaat verborgen bestanden en systeembestanden terug verbergen en maakt een nieuw herstelpunt.

Indien aanwezig mag je de map C:\Qoobox manueel verwijderen.

HijackThis mag je eveneens verwijderen.

Download hier CCleaner. en dan start de download van CCleaner automatisch en gratis op.

Installeer het en start CCleaner op. Klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Schoonmaken'. Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”. Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Het is aangewezen om de bestaande herstelpunten te verwijderen (daar zitten besmette herstelpunten tussen die je eventueel zou kunnen terugzetten) door systeemherstel tijdelijk uit te schakelen. Doe dit via Start -> Configuratiescherm -> Prestaties en Onderhoud -> Systeem -> Systeemherstel -> "Systeemherstel op alle stations uitschakelen" aanvinken. Toepassen en OK. PC herstarten en het vinkje terug weg halen.

Mag ik je dan nog een prettige nachtrust toewensen :D

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.