Ga naar inhoud

Conhost (5)


Aanbevolen berichten

Hallo,

Ik heb zowat hetzelfde probleem op mijn pa zijn pc.

Heb hijackthis mbam en combofix laten lopen met de nodige herstarts,

maar AVG geeft nog dezelfde conhost.exe warning.

XP home edition 3

AVG free 2011

Erg bedankt voor enige hulp

Hier de hijackthis, mbam en combofix logs:

hijack this

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 15:31:19, on 30/08/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16850)

Boot mode: Normal

Running processes:

I:\WINDOWS\System32\smss.exe

I:\PROGRA~1\AVG\AVG10\avgchsvx.exe

I:\WINDOWS\system32\winlogon.exe

I:\WINDOWS\system32\services.exe

I:\WINDOWS\system32\lsass.exe

I:\WINDOWS\system32\Ati2evxx.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\System32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\system32\spoolsv.exe

I:\WINDOWS\Explorer.EXE

I:\WINDOWS\stsystra.exe

I:\Program Files\HP\HP Software Update\HPWuSchd2.exe

I:\Program Files\AVG\AVG10\avgtray.exe

I:\Program Files\Common Files\Java\Java Update\jusched.exe

I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

I:\Program Files\Belgium Identity Card\beid35gui.exe

I:\WINDOWS\system32\ctfmon.exe

I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

I:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

I:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

I:\Program Files\AVG\AVG10\avgwdsvc.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\Program Files\Java\jre6\bin\jqs.exe

I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

I:\WINDOWS\System32\svchost.exe

I:\Program Files\AVG\AVG10\avgnsx.exe

I:\WINDOWS\System32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

I:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

I:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

I:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

I:\WINDOWS\system32\NOTEPAD.EXE

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\PROGRA~1\AVG\AVG10\avgrsx.exe

I:\Program Files\AVG\AVG10\avgcsrvx.exe

I:\PROGINST\hijact\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - I:\Program Files\AVG\AVG10\avgssie.dll

O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - I:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - I:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)

O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HP Software Update] I:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [AVG_TRAY] I:\Program Files\AVG\AVG10\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [beid] I:\Program Files\Belgium Identity Card\beid35gui.exe

O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://I:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://*.mcafee.com

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://portal.brusselsairport.be/dana/download/icaweb.cab?url=/dana/term/winlaunchterm.cgi?op=DownloadCitrixCab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://express.foto.com/ImageUploader5.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172749852671

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227109954984

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://virusscanner.telenet.be/fscax.cab

O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - I:\Program Files\AVG\AVG10\avgpp.dll

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: MBackMonitor - Unknown owner - I:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing)

O23 - Service: MBAMService - Malwarebytes Corporation - I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

--

End of file - 10176 bytes

MBAM log

Malwarebytes' Anti-Malware 1.51.1.1800

Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 7609

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

30/08/2011 14:12:45

mbam-log-2011-08-30 (14-12-45).txt

Scan type: Quick scan

Objects scanned: 201884

Time elapsed: 16 minute(s), 0 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 5

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 2

Files Infected: 10

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\GodLib (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UACd.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Value: UID -> Quarantined and deleted successfully.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

i:\documents and settings\localservice\application data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully.

i:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Quarantined and deleted successfully.

Files Infected:

i:\documents and settings\networkservice\start menu\Programs\Startup\winupdate.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.

i:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.

i:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

i:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

i:\WINDOWS\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully.

i:\documents and settings\networkservice\local settings\application data\microsoft\Windows\winupdate.exe (Trojan.Agent) -> Quarantined and deleted successfully.

i:\documents and settings\localservice\application data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully.

i:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Quarantined and deleted successfully.

i:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Quarantined and deleted successfully.

i:\WINDOWS\system32\drivers\uacbfrkcxeo.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.

combofix log

ComboFix 11-08-30.01 - Administrator 08/30/2011 14:42:59.1.2 - x86 NETWORK

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3710.3433 [GMT 2:00]

Running from: i:\documents and settings\Administrator\Desktop\ComboFix.exe

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

AV: McAfee VirusScan *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

i:\documents and settings\NetworkService\Local Settings\Application Data\Google\Update\gupdate.exe

i:\windows\system32\comct332.ocx

i:\windows\system32\UACaneenwkb.log

i:\windows\system32\UACbqhosjvu.log

i:\windows\system32\UACbsutucke.log

i:\windows\system32\UACceetnkig.log

i:\windows\system32\UACetnetyxv.log

i:\windows\system32\UACfpdocxtb.log

i:\windows\system32\UACgqrxmcjc.log

i:\windows\system32\UACiemuscti.log

i:\windows\system32\UACktepuqbe.log

i:\windows\system32\UACmmbftpdw.log

i:\windows\system32\UACmqibqtvt.log

i:\windows\system32\UACnpbiriyp.log

i:\windows\system32\UACpqgxyqmb.log

i:\windows\system32\UACqgijllxs.log

i:\windows\system32\UACqsmdxvnc.log

i:\windows\system32\UACqsnodyew.log

i:\windows\system32\UACrdomyeor.dat

i:\windows\system32\UACtssaurer.log

i:\windows\system32\UACujdqmivr.log

i:\windows\system32\UACvbbpmstg.log

i:\windows\system32\UACvqpylqrj.log

i:\windows\system32\UACwwbxtmdh.log

i:\windows\system32\UACxyusiuya.log

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_NPF

-------\Legacy_SSHNAS

-------\Service_NPF

.

.

((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-30 )))))))))))))))))))))))))))))))

.

.

2011-08-30 11:52 . 2011-08-30 11:52 -------- d-----w- i:\documents and settings\JOS CORNELIS\Application Data\Malwarebytes

2011-08-30 11:51 . 2011-07-08 05:55 41272 ----a-w- i:\windows\system32\drivers\mbamswissarmy.sys

2011-08-30 11:51 . 2011-08-30 11:51 -------- d-----w- i:\documents and settings\All Users\Application Data\Malwarebytes

2011-08-30 11:51 . 2011-08-30 11:51 -------- d-----w- i:\program files\Malwarebytes' Anti-Malware

2011-08-30 11:51 . 2011-07-08 05:55 22712 ----a-w- i:\windows\system32\drivers\mbam.sys

2011-08-29 07:58 . 2011-08-29 07:58 -------- d-----w- i:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation

2011-08-08 10:53 . 2011-08-10 16:38 -------- d-----w- i:\documents and settings\JOS CORNELIS\Application Data\PoivY

2011-08-08 10:53 . 2011-08-08 10:53 -------- d-----w- i:\program files\PoivY.com

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-07-24 12:35 . 2011-07-24 12:35 404640 ----a-w- i:\windows\system32\FlashPlayerCPLApp.cpl

2008-04-16 19:35 . 2008-04-16 19:35 14336 ----a-w- i:\program files\wmdmhelper.dll

2008-04-16 19:35 . 2008-04-16 19:35 692224 ----a-w- i:\program files\dtdr3260.dll

2008-04-16 19:35 . 2008-04-16 19:35 659456 ----a-w- i:\program files\rjbres.dll

2008-04-16 19:35 . 2008-04-16 19:35 36352 ----a-w- i:\program files\ierjplug.dll

2008-04-16 19:35 . 2008-04-16 19:35 339968 ----a-w- i:\program files\rjdlg.dll

2008-04-16 19:35 . 2008-04-16 19:35 19456 ----a-w- i:\program files\rjprog.dll

2008-04-16 19:35 . 2008-04-16 19:35 139264 ----a-w- i:\program files\DUNZIP32.dll

2008-04-16 19:35 . 2008-04-16 19:35 81920 ----a-w- i:\program files\tsasdk.dll

2008-04-16 19:35 . 2008-04-16 19:35 6656 ----a-w- i:\program files\fixrjb.exe

2008-04-16 19:35 . 2008-04-16 19:35 57344 ----a-w- i:\program files\tpasdk.dll

2008-04-16 19:35 . 2008-04-16 19:35 41472 ----a-w- i:\program files\mmcdda32.dll

2008-04-16 19:35 . 2008-04-16 19:35 19456 ----a-w- i:\program files\tnetdtct.dll

2008-04-16 19:35 . 2008-04-16 19:35 43088 ----a-w- i:\program files\rpshellsearch.dll

2008-04-16 19:35 . 2008-04-16 19:35 32768 ----a-w- i:\program files\rpwa3260.dll

2008-04-16 19:35 . 2008-04-16 19:35 16296 ----a-w- i:\program files\realtfon.fon

2008-04-16 19:35 . 2008-04-16 19:35 719360 ----a-w- i:\program files\dbghelp.dll

2008-04-16 19:35 . 2008-04-16 19:35 153176 ----a-w- i:\program files\RecordingManager.exe

2008-04-16 19:35 . 2008-04-16 19:35 65536 ----a-w- i:\program files\rjwmapln.dll

2008-04-16 19:35 . 2008-04-16 19:35 53248 ----a-w- i:\program files\rpau3260.dll

2008-04-16 19:35 . 2008-04-16 19:35 102400 ----a-w- i:\program files\HXAudioDeviceHook.dll

2008-04-16 19:35 . 2008-04-16 19:35 98304 ----a-w- i:\program files\rpshellextension.dll

2008-04-16 19:35 . 2008-04-16 19:35 95816 ----a-w- i:\program files\rdsf3260.dll

2008-04-16 19:35 . 2008-04-16 19:35 86016 ----a-w- i:\program files\rpplugprot.dll

2008-04-16 19:35 . 2008-04-16 19:35 63040 ----a-w- i:\program files\rpshell.dll

2008-04-16 19:35 . 2008-04-16 19:35 9216 ----a-w- i:\program files\rphelperapp.exe

2008-04-16 19:35 . 2008-04-16 19:35 7168 ----a-w- i:\program files\realjbox.exe

2008-04-16 19:35 . 2008-04-16 19:35 214560 ----a-w- i:\program files\realplay.exe

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]

2009-12-20 09:51 87480 ----a-w- i:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]

2011-01-06 14:06 721840 ----a-w- i:\progra~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "i:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll" [2009-12-20 87480]

.

[HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="i:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-06 68856]

"beid"="i:\program files\Belgium Identity Card\beid35gui.exe" [2008-10-30 2023424]

"ctfmon.exe"="i:\windows\system32\ctfmon.exe" [2008-04-14 15360]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="i:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-29 339968]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]

"Adobe Reader Speed Launcher"="i:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"QuickTime Task"="i:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

"HP Software Update"="i:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

"AVG_TRAY"="i:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]

"SunJavaUpdateSched"="i:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]

"Malwarebytes' Anti-Malware"="i:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-08 449584]

.

i:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - i:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0i:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0i:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"i:\\Program Files\\Messenger\\msmsgs.exe"=

"i:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=

"i:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=

"i:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=

"i:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=

"i:\\Documents and Settings\\JOS CORNELIS\\Application Data\\Juniper Networks\\Juniper Citrix Services Client\\dsCitrixProxy.exe"=

"i:\\Documents and Settings\\JOS CORNELIS\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"=

"i:\\Program Files\\Skype\\Phone\\Skype.exe"=

"i:\\Program Files\\PoivY.com\\PoivY\\PoivY.exe"=

"i:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=

"i:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=

"i:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=

.

R0 AVGIDSEH;AVGIDSEH;i:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 16:27 22992]

R0 Avgrkx86;AVG Anti-Rootkit Driver;i:\windows\system32\drivers\avgrkx86.sys [7/09/2010 4:48 32592]

R1 Avgldx86;AVG AVI Loader Driver;i:\windows\system32\drivers\avgldx86.sys [7/09/2010 4:48 248656]

R1 Avgtdix;AVG TDI Driver;i:\windows\system32\drivers\avgtdix.sys [9/11/2010 23:20 297168]

R2 avgwd;AVG WatchDog;i:\program files\AVG\AVG10\avgwdsvc.exe [8/02/2011 5:33 269520]

R2 MBAMService;MBAMService;i:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [30/08/2011 13:51 366640]

R2 WDDMService;WD SmartWare Drive Manager;i:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [13/11/2009 12:28 110592]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;i:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 9:58 20480]

R3 AVGIDSDriver;AVGIDSDriver;i:\windows\system32\drivers\AVGIDSDriver.sys [19/08/2010 21:42 134480]

R3 AVGIDSFilter;AVGIDSFilter;i:\windows\system32\drivers\AVGIDSFilter.sys [19/08/2010 21:42 24144]

R3 AVGIDSShim;AVGIDSShim;i:\windows\system32\drivers\AVGIDSShim.sys [19/08/2010 21:42 27216]

R3 MBAMProtector;MBAMProtector;i:\windows\system32\drivers\mbam.sys [30/08/2011 13:51 22712]

S2 AVGIDSAgent;AVGIDSAgent;i:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18/04/2011 17:39 7398752]

S3 ACSSCR;ACR38 Smart Card Reader;i:\windows\system32\drivers\a38usb.sys [24/03/2006 20:14 33536]

S3 cxbu0wdm;CardMan 3x21;i:\windows\system32\drivers\cxbu0wdm.sys [15/01/2008 12:39 97792]

S3 MBAMSwissArmy;MBAMSwissArmy;i:\windows\system32\drivers\mbamswissarmy.sys [30/08/2011 13:51 41272]

S3 P1130VID;Creative WebCam NX Pro;i:\windows\system32\drivers\P1130Vid.sys [26/05/2007 17:46 90229]

S3 WDC_SAM;WD SCSI Pass Thru driver;i:\windows\system32\drivers\wdcsam.sys [13/03/2010 10:54 11520]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

HPService REG_MULTI_SZ HPSLPSVC

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{144cf342-2e7d-11df-99da-001372e5df1c}]

\Shell\AutoRun\command - "L:\WD SmartWare.exe" autoplay=true

.

Contents of the 'Scheduled Tasks' folder

.

2011-08-30 i:\windows\Tasks\Google Software Updater.job

- i:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-14 19:10]

.

2011-08-12 i:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1606980848-1801674531-1004Core.job

- i:\documents and settings\JOS CORNELIS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-09 11:19]

.

2011-08-29 i:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1606980848-1801674531-1004UA.job

- i:\documents and settings\JOS CORNELIS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-03-09 11:19]

.

2011-08-30 i:\windows\Tasks\User_Feed_Synchronization-{C3A91DC5-13DF-4100-A733-6A8BDC840A51}.job

- i:\windows\system32\msfeedssync.exe [2007-08-13 17:36]

.

.

------- Supplementary Scan -------

.

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - i:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - i:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Trusted Zone: dexia.be\directnet

Trusted Zone: internet

Trusted Zone: mcafee.com

TCP: DhcpNameServer = 195.130.131.129 195.130.130.1

FF - ProfilePath - i:\documents and settings\JOS CORNELIS\Application Data\Mozilla\Firefox\Profiles\64lm23s4.default\

FF - prefs.js: browser.search.selectedEngine - BearShare Web Search

FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/

FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q=

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - i:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - i:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - i:\program files\AVG\AVG10\Firefox4

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-10 - (no file)

HKCU-Run-Picasa Media Detector - i:\program files\Picasa2\PicasaMediaDetector.exe

HKLM-Run-MBkLogonHook - (no file)

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2011-08-30 15:02

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover

Windows 5.1.2600 Disk: TEAC____ rev.4.00 -> Harddisk4\DR5 -> \Device\0000006f

.

device: opened successfully

user: MBR read successfully

.

Disk trace:

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys USBSTOR.SYS hal.dll usbhub.sys USBPORT.SYS usbehci.sys

1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk4\DR5[0x8AE71AB8]

3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\0000006f[0x8B0296A8]

5 USBSTOR[0xACE43706] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\USBPDO-7[0x8AE7E1F0]

7 usbhub[0xBA148596] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\USBPDO-0[0x8AC29030]

kernel: MBR read successfully

_asm { CLI ; XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV SI, SP; PUSH AX; POP ES; PUSH AX; POP DS; STI ; CLD ; MOV DI, 0x600; MOV CX, 0x100; REPNZ MOVSW ; JMP FAR 0x0:0x61d; }

detected disk devices:

\Device\Ide\IdeDeviceP1T0L0-17 -> \??\IDE#DiskST3160812AS_____________________________3.ADJ___#5&2510770d&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

detected hooks:

\Driver\atapi DriverStartIo -> 0x8B0F527F

user & kernel MBR OK

error: Read The parameter is incorrect.

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-1177238915-1606980848-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(976)

i:\windows\system32\WPDShServiceObj.dll

i:\windows\system32\PortableDeviceTypes.dll

i:\windows\system32\PortableDeviceApi.dll

i:\program files\Malwarebytes' Anti-Malware\mbamext.dll

i:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

i:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll

i:\program files\Microsoft Office\OFFICE11\msohev.dll

i:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll

.

------------------------ Other Running Processes ------------------------

.

i:\windows\system32\Ati2evxx.exe

i:\windows\System32\SCardSvr.exe

i:\windows\stsystra.exe

i:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

i:\program files\Java\jre6\bin\jqs.exe

i:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

i:\program files\AVG\AVG10\avgui.exe

i:\program files\HP\Digital Imaging\bin\hpqSTE08.exe

i:\program files\HP\Digital Imaging\bin\hpqbam08.exe

i:\program files\HP\Digital Imaging\bin\hpqgpc01.exe

i:\windows\TEMP\conhost.exe

.

**************************************************************************

.

Completion time: 2011-08-30 15:09:04 - machine was rebooted

ComboFix-quarantined-files.txt 2011-08-30 13:08

.

Pre-Run: 56,532,701,184 bytes free

Post-Run: 58.904.739.840 bytes free

.

- - End Of File - - 5FD61C26E9A6DBB5D575C88A7DB12B59

Link naar reactie
Delen op andere sites

Malwarebytes en Combofix hebben hun werk gedaan. Via HijackThis mag je dit nog uitvoeren :

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - I:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll

O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)

O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - I:\PROGRA~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll

Klik op 'Fix checked' om de items te verwijderen.

Open een kladblokbestand.

Kopieer onderstaande (alles wat vetgedrukt is) in dit kladblokbestand.

@ECHO OFF

IF EXIST log.txt DEL log.txt

ECHO Deleting files>>log.txt

FOR %%g in (

C:\WINDOWS\TEMP\conhost.exe) DO (

DEL /Q %%gHJTNL

IF EXIST %%g (

ATTRIB -r -s -h %%g

DEL %%g

REN %%g *HJTNL

IF EXIST %%gHJTNL (

ECHO renamed to %%gHJTNL>>log.txt)

IF EXIST %%g (

ECHO %%g not deleted>>log.txt

) ELSE (

ECHO %%g deleted>>log.txt)

) ELSE (

ECHO %%g not found>>log.txt))

START NOTEPAD.EXE log.txt

Ga naar Bestand - Opslaan als.

Bij "Opslaan in" kies je: Bureaublad

Bij "Bestandsnaam" zet je: del.bat

Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).

Klik op de knop Opslaan.

Dubbelklik op del.bat en post de inhoud van de logfile die opent, samen met een nieuw log van HijackThis en graag ook het log van TDSS. Dan weten we meteen of je probleem definitief opgelost is ?

Link naar reactie
Delen op andere sites

Ja die del.bat had ik al eens laten lopen, ook in een andere post gezien.

Hier de logfile:

Deleting files

I:\WINDOWS\TEMP\conhost.exe not found

en hijackthis

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 17:29:27, on 30/08/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16850)

Boot mode: Normal

Running processes:

I:\WINDOWS\System32\smss.exe

I:\PROGRA~1\AVG\AVG10\avgchsvx.exe

I:\WINDOWS\system32\winlogon.exe

I:\WINDOWS\system32\services.exe

I:\WINDOWS\system32\lsass.exe

I:\WINDOWS\system32\Ati2evxx.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\System32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\system32\spoolsv.exe

I:\WINDOWS\Explorer.EXE

I:\WINDOWS\stsystra.exe

I:\Program Files\HP\HP Software Update\HPWuSchd2.exe

I:\Program Files\AVG\AVG10\avgtray.exe

I:\Program Files\Common Files\Java\Java Update\jusched.exe

I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

I:\Program Files\Belgium Identity Card\beid35gui.exe

I:\WINDOWS\system32\ctfmon.exe

I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

I:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

I:\Program Files\AVG\AVG10\avgwdsvc.exe

I:\WINDOWS\system32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\Program Files\Java\jre6\bin\jqs.exe

I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

I:\WINDOWS\System32\svchost.exe

I:\WINDOWS\System32\svchost.exe

I:\WINDOWS\system32\svchost.exe

I:\Program Files\AVG\AVG10\avgnsx.exe

I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

I:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

I:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

I:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\PROGRA~1\AVG\AVG10\avgrsx.exe

I:\Program Files\AVG\AVG10\avgcsrvx.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\Documents and Settings\JOS CORNELIS\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

I:\PROGINST\hijact\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - I:\Program Files\AVG\AVG10\avgssie.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - I:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HP Software Update] I:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [AVG_TRAY] I:\Program Files\AVG\AVG10\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [beid] I:\Program Files\Belgium Identity Card\beid35gui.exe

O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://I:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - I:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://*.mcafee.com

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://portal.brusselsairport.be/dana/download/icaweb.cab?url=/dana/term/winlaunchterm.cgi?op=DownloadCitrixCab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://express.foto.com/ImageUploader5.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172749852671

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227109954984

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://virusscanner.telenet.be/fscax.cab

O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - I:\Program Files\AVG\AVG10\avgpp.dll

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - I:\Program Files\AVG\AVG10\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: MBackMonitor - Unknown owner - I:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing)

O23 - Service: MBAMService - Malwarebytes Corporation - I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - I:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe

O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - I:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

--

End of file - 9708 bytes

TDSS vind ik niet meer.

Bedankt voor de hulp, alles lijkt opgelost.

Ronny

Link naar reactie
Delen op andere sites

Dat ziet er inderdaad netjes uit :top:

Problemen van de baan, dan is het tijd voor de “grote schoonmaak” : verwijderen van gebruikte programma’s, een cleaning en het verwijderen van de besmette herstelpunten.

Verwijder Combofix: Start -> Uitvoeren/Zoekopdracht en typ: ComboFix /Uninstall

Dit zal Combofix verwijderen + gerelateerde mappen en bestanden, herstelt de klokinstellingen opnieuw, verbergt de bestandsextensies, gaat verborgen bestanden en systeembestanden terug verbergen en maakt een nieuw herstelpunt.

Indien aanwezig mag je de map C:\Qoobox manueel verwijderen.

Download CCleaner.

Klik op “Download Latest Version” en dan start de download van CCleaner automatisch en gratis op.

Installeer het en start CCleaner op. Klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Schoonmaken'. Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”. Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Het is aangewezen om de bestaande herstelpunten te verwijderen (daar zitten besmette herstelpunten tussen die je eventueel zou kunnen terugzetten) door systeemherstel tijdelijk uit te schakelen. Doe dit via Start -> Configuratiescherm -> Prestaties en Onderhoud -> Systeem -> Systeemherstel -> "Systeemherstel op alle stations uitschakelen" aanvinken. Toepassen en OK. PC herstarten en het vinkje terug weg halen.

Indien dit probleemloos verlopen is, mag je hieronder op "opgelost" tokkelen ;-)

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.