Ga naar inhoud

geen IP , geen internet, wel lanverbinding


marky marc

Aanbevolen berichten

comboverslagje 2

Bedankt voor je reactie.

ComboFix 10-08-03.04 - Marc 04/08/2010 19:56:51.22.2 - x86 MINIMAL

Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1022.797 [GMT 2:00]

Gestart vanuit: J:\ComboFix.exe

gebruikte Opdracht switches :: J:\CFScript.txt

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_EERMTB

-------\Legacy_XHYWIYVIBDKKPAQ

-------\Service_EERMTB

-------\Service_XHYWIYVIBDKKPAQ

(((((((((((((((((((( Bestanden Gemaakt van 2010-07-04 to 2010-08-04 ))))))))))))))))))))))))))))))

.

2010-08-03 07:49 . 2008-04-13 19:19 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys

2010-08-02 09:03 . 2010-08-02 09:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP

2010-08-02 09:02 . 2010-08-02 09:04 -------- d-----w- c:\program files\FLAC to MP3 Converter

2010-08-01 12:39 . 2010-08-01 12:39 -------- d-----w- c:\windows\system32\wbem\Repository

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-07-31 18:18 . 2010-07-30 19:17 112 ----a-w- c:\documents and settings\All Users\Application Data\6pq0BV.dat

2010-07-31 18:14 . 2007-03-21 14:42 -------- d-----w- c:\program files\McAfee

2010-07-31 14:09 . 2009-11-24 10:29 -------- d-----w- c:\program files\Everest Poker

2010-07-30 21:01 . 2008-10-22 17:04 -------- d-----w- c:\program files\USD

2010-07-30 18:57 . 2008-04-21 13:32 -------- d-----w- c:\documents and settings\Marc\Application Data\OpenOffice.org2

2010-07-30 18:55 . 2008-04-21 13:35 1 ----a-w- c:\documents and settings\Marc\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys

2010-07-16 10:52 . 2006-04-07 13:57 -------- d-----w- c:\program files\Google

2010-07-15 13:18 . 2007-03-21 14:43 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys

2010-07-03 13:16 . 2009-11-28 17:35 -------- d-----w- c:\program files\PokerStars

2010-06-30 10:53 . 2009-10-31 15:54 -------- d-----w- c:\program files\PokerStars.NET

2010-06-25 11:35 . 2010-06-25 11:35 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2010-06-25 11:35 . 2010-06-25 11:35 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-06-25 11:29 . 2006-05-07 16:08 -------- d-----w- c:\program files\Lavasoft

2010-06-25 11:29 . 2010-06-25 11:29 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}

2010-06-25 11:28 . 2006-12-19 12:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-06-23 14:30 . 2010-06-23 14:30 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb48.tmp.exe

2010-06-19 15:31 . 2010-05-05 18:14 -------- d-----w- c:\program files\QuickTime

2010-06-18 15:09 . 2010-06-18 15:09 388096 ----a-r- c:\documents and settings\Marc\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2010-06-16 12:13 . 2010-04-27 14:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-06-12 18:26 . 2006-12-15 13:58 -------- d-----w- c:\program files\Belgacom

2010-06-12 18:24 . 2006-01-05 14:24 -------- d-----w- c:\program files\support.com

2010-06-12 18:18 . 2005-12-15 01:49 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-06-12 18:18 . 2006-12-25 13:19 -------- d-----w- c:\program files\Ubisoft

2010-06-12 08:43 . 2010-05-14 18:41 300384 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\detect.dll

2010-06-12 08:43 . 2009-03-30 16:31 300384 ----a-w- c:\documents and settings\Marc\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll

2010-06-08 09:30 . 2007-07-11 09:12 -------- d-----w- c:\program files\CCleaner

2010-06-04 17:53 . 2010-06-04 17:53 503808 ----a-w- c:\documents and settings\Marc\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6e4ec1e2-n\msvcp71.dll

2010-06-04 17:53 . 2010-06-04 17:53 61440 ----a-w- c:\documents and settings\Marc\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-46c7c7c1-n\decora-sse.dll

2010-06-04 17:53 . 2010-06-04 17:53 499712 ----a-w- c:\documents and settings\Marc\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6e4ec1e2-n\jmc.dll

2010-06-04 17:53 . 2010-06-04 17:53 348160 ----a-w- c:\documents and settings\Marc\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6e4ec1e2-n\msvcr71.dll

2010-06-04 17:53 . 2010-06-04 17:53 12800 ----a-w- c:\documents and settings\Marc\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-46c7c7c1-n\decora-d3d.dll

2010-06-04 17:52 . 2010-06-04 17:53 411368 ----a-w- c:\windows\system32\deployJava1.dll

2010-06-03 18:19 . 2004-09-14 08:38 182656 ----a-w- c:\windows\system32\drivers\ndis.sys

2010-06-02 10:06 . 2006-06-14 09:53 29184 ----a-w- c:\windows\system32\drivers\usbccid.sys

2010-05-22 12:14 . 2004-09-14 08:38 91518 ----a-w- c:\windows\system32\perfc013.dat

2010-05-22 12:14 . 2004-09-14 08:38 510428 ----a-w- c:\windows\system32\perfh013.dat

2010-05-21 17:52 . 2006-01-05 16:03 42080 ----a-w- c:\documents and settings\Marc\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-05-17 19:53 . 2010-05-17 19:53 942960 ----a-w- c:\documents and settings\Marc\Local Settings\Application Data\MvtApp.exe

2006-11-08 15:01 . 2006-11-08 15:01 774144 ----a-w- c:\program files\RngInterstitial.dll

.

<pre>
c:\program files\McAfee.com\Agent\mcagent .exe
</pre>

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\program files\QuickTime\qttask .exe -atboottime" [X]

"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-10 1218008]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 69632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\

Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-12-25 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]

2008-11-07 15:41 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2010-02-18 09:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\WINDOWS\\system32\\LEXPPS.EXE"=

"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

"c:\\Program Files\\Java\\jre1.6.0_07\\launch4j-tmp\\frd.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25/06/2010 13:35 64288]

R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [25/12/2008 13:14 10384]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [13/12/2008 14:04 210216]

S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31/01/2010 17:26 135664]

S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [29/08/2006 0:54 10664]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [4/02/2010 17:52 1352832]

S4 XJZEOLTBW;XJZEOLTBW;c:\docume~1\Marc\LOCALS~1\Temp\XJZEOLTBW.exe --> c:\docume~1\Marc\LOCALS~1\Temp\XJZEOLTBW.exe [?]

.

Inhoud van de 'Gedeelde Taken' map

2010-07-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 11:35]

2010-05-07 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 15:26]

2010-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 15:26]

2009-08-14 c:\windows\Tasks\McDefragTask.job

- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-21 10:22]

2009-11-01 c:\windows\Tasks\McQcTask.job

- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-21 10:22]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.hln.be/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe

Trusted Zone: dexia.be

Trusted Zone: dexia.be\directnet

Trusted Zone: internet

Trusted Zone: mcafee.com

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2010-08-04 20:08

Windows 5.1.2600 Service Pack 3 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,25,69,ba,e7,f8,7c,31,49,a3,08,b5,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,25,69,ba,e7,f8,7c,31,49,a3,08,b5,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

- - - - - - - > 'winlogon.exe'(368)

c:\windows\system32\Ati2evxx.dll

c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2228)

c:\program files\McAfee\SiteAdvisor\saHook.dll

c:\program files\Logitech\SetPoint\lgscroll.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll

c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL

c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_dut.nlr

c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\windows\system32\Ati2evxx.exe

c:\windows\system32\LEXBCES.EXE

c:\windows\system32\LEXPPS.EXE

c:\windows\System32\SCardSvr.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\windows\system32\drivers\CDAC11BA.EXE

c:\program files\Java\jre6\bin\jqs.exe

c:\progra~1\McAfee\MSC\mcmscsvc.exe

c:\program files\common files\mcafee\mna\mcnasvc.exe

c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

c:\progra~1\McAfee\VIRUSS~1\mcshield.exe

c:\program files\McAfee\MPF\MPFSrv.exe

c:\program files\McAfee\MSK\MskSrver.exe

c:\windows\system32\HPZipm12.exe

c:\progra~1\mcafee.com\agent\mcagent.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe

c:\progra~1\mcafee\msc\mcupdmgr.exe

.

**************************************************************************

.

Voltooingstijd: 2010-08-04 20:14:42 - machine werd herstart

ComboFix-quarantined-files.txt 2010-08-04 18:14

ComboFix2.txt 2010-08-04 12:25

ComboFix3.txt 2010-08-03 08:12

Pre-Run: 24.232.873.984 bytes beschikbaar

Post-Run: 23.142.240.256 bytes beschikbaar

- - End Of File - - 3E9BC03FACDD722C0EE555E1441D58A1

Link naar reactie
Delen op andere sites

  • Reacties 34
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

kape,

Mcafee online geupdated van 2006 naar 2008 versie. Hoe kan ik beide zaken uitvoeren zonder internetverbinding. Is het veilig om het bestandje te kopieren naar mijn usb-stick en dan op mijn laptop te scannen ?

Kan ik ergens testen of mijn netwerkkaart niet stuk is ?

Of denk je dat alles virus gerelateerd is.

Link naar reactie
Delen op andere sites

kape,

Mcafee online geupdated van 2006 naar 2008 versie. Hoe kan ik beide zaken uitvoeren zonder internetverbinding. Is het veilig om het bestandje te kopieren naar mijn usb-stick en dan op mijn laptop te scannen ?

Of denk je dat alles virus gerelateerd is.

Het is geen zekerheid, maar een zoektocht naar het bestand dat oorzaak is van de problemen. Het opgegeven bestand komt daarvoor (eventueel) in aanmerking. Overbrengen naar de laptop zou moeten kunnen. Het updaten van McAfee is minder cruciaal, dat kan nadat de verbinding terug tot stand gebracht is.
Link naar reactie
Delen op andere sites

Laat dit vetgedrukte bestand c:\program files\RngInterstitial.dll eens scannen bij Jotti en hang het resultaat in je volgende bericht.

Vraagje : heb je McAfee op CD-rom of on-line gedownload ? Een herinstallatie ervan zou nuttig kunnen zijn.

Bestandsnaam: RngInterstitial.dll

Status:

Scan voltooid. 0 uit 21 scanners vonden malware.

Scan genomen op: vr 23 okt 2009 05:35:42 (CET) Permalink

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.