Ga naar inhoud

mis rtl120bpl file


bique

Aanbevolen berichten

en ik krijg steed te zien: for some reason your system denied write acces to the hosts file. if any Hijacked domains are in the files, hijackedsThis may NOT be able to fix this.

if that happens, you need to edit the file yourself. To do this , click start Run and type;

notepad C:\\ windows\system32\drivers\etc\host

and press Enter. find the line (s) HijackThis reports and delete them.

Save the file as "host". with qoutes, and rebout.

---------- Post toegevoegd om 13:50 ---------- Vorige post was om 13:46 ----------

en als ik dat gedaan heb dan krijg ik: Kan het bestand C:\\windows\system32\drivers\etc\host niet vinden. Controleer of u de naam juist hebt ingevoerd en proberr het daarna opnieuw

Dit is omdat je Hijackthis niet hebt uitgevoerd als administrator.

Start Hijackthis op. Klik met de rechter muisknop op de icoon en kies dan voor “Run as administrator" of "Uitvoeren als administrator".

Selecteer “Do a system scan only”.

Vink alleen de items aan die hieronder zijn genoemd:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)

R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.0\PriceGongIE.dll

O2 - BHO: ToolbarOrange.InitToolbarBHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - mscoree.dll (file missing)

O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll

O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - !{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

O3 - Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O3 - Toolbar: (no name) - !{c9a6357b-25cc-4bcf-96c1-78736985d412} - (no file)

O3 - Toolbar: barre d'outils Orange - {c9a6357b-25cc-4bcf-96c1-78736985d412} - mscoree.dll (file missing)

O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll

Klik op 'Fix checked' om de items te verwijderen.

Download MBAM (Malwarebytes Anti-Malware)

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.

MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.

Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... Dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.

Link naar reactie
Delen op andere sites

  • Reacties 25
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

het probleem is , of ik nu rechts of links op het icoon druk van de snelkoppeling , ik krijg niet te zien : run als administrator

---------- Post toegevoegd om 14:12 ---------- Vorige post was om 14:10 ----------

krijg alleen: do a systemscan and save a logfile

do a system scan only

vieuw the list of backups

open this misc tools section

open online hijackthis quickstart

nen of the above , just start the programme

---------- Post toegevoegd om 14:27 ---------- Vorige post was om 14:12 ----------

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 12:33:35, on 12-11-2011

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\Orange\Connexion Internet Orange\Launcher\Launcher.exe

C:\Program Files\HP\HP Software Update\hpwuschd2.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe

C:\Users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\Program Files\Orange\MailNotifier\MailNotifier.exe

C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

C:\Windows\system32\wuauclt.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\rundll32.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\Windows\system32\taskeng.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Portail Orange : Actu, Sport, Assistance Internet, Web Mail Orange

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\Connexion Internet Orange\SearchURLHook\SearchPageURL.dll

R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.0\PriceGongIE.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: ToolbarOrange.InitToolbarBHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - mscoree.dll (file missing)

O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL

O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll

O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn0.dll

O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll (file missing)

O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - !{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

O3 - Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O3 - Toolbar: (no name) - !{c9a6357b-25cc-4bcf-96c1-78736985d412} - (no file)

O3 - Toolbar: barre d'outils Orange - {c9a6357b-25cc-4bcf-96c1-78736985d412} - mscoree.dll (file missing)

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll

O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe

O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

O4 - HKLM\..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKCU\..\Run: [MailNotifier] C:\Program Files\Orange\MailNotifier\MailNotifier.exe

O4 - HKCU\..\Run: [orangeinside] C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: envoyer le texte sélectionné par sms - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html

O8 - Extra context menu item: envoyer par sms - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html

O8 - Extra context menu item: envoyer un mail - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

O8 - Extra context menu item: orange.fr - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html

O8 - Extra context menu item: rechercher le texte sélectionné - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html

O8 - Extra context menu item: traduire la page - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html

O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html

O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: Logiciels gratuits - Orange

O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://kitchenplanner.ikea.com/fr/Core/Player/2020PlayerAX_Win32.cab

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll

O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: Bandoo Coordinator - Bandoo Media Inc. - C:\PROGRA~1\Bandoo\Bandoo.exe

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe

O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe

O23 - Service: Orange update Core Service - Unknown owner - C:\Program Files\Orange\OrangeUpdate\Service\OUCore.exe

--

End of file - 10422 bytes

---------- Post toegevoegd om 14:28 ---------- Vorige post was om 14:27 ----------

Malwarebytes' Anti-Malware 1.51.2.1300

Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Databaseversie: 8146

Windows 6.1.7601 Service Pack 1

Internet Explorer 9.0.8112.16421

12-11-2011 13:26:38

mbam-log-2011-11-12 (13-26-38).txt

Scantype: Snelle scan

Objecten gescand: 159812

Verstreken tijd: 4 minuut/minuten, 38 seconde(n)

Geheugenprocessen geïnfecteerd: 0

Geheugenmodulen geïnfecteerd: 0

Registersleutels geïnfecteerd: 0

Registerwaarden geïnfecteerd: 0

Registerdata geïnfecteerd: 0

Mappen geïnfecteerd: 0

Bestanden geïnfecteerd: 1

Geheugenprocessen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registerdata geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Mappen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Bestanden geïnfecteerd:

c:\Users\suzanne\downloads\flvplayersetup.exe (Adware.Agent) -> Quarantined and deleted successfully.

Link naar reactie
Delen op andere sites

ik heb het nu via c:\\programfiles\\trend micro\\hijackthis gedaan en dan via administrator, maar dan kan ik alleen een scan doen en geen systeemscan

---------- Post toegevoegd om 15:03 ---------- Vorige post was om 14:55 ----------

na verwijdering volgens bovenstaande de nieuwe :

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:03:02, on 12-11-2011

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Program Files\Launch Manager\LManager.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\Orange\Connexion Internet Orange\Launcher\Launcher.exe

C:\Program Files\HP\HP Software Update\hpwuschd2.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\Program Files\Orange\MailNotifier\MailNotifier.exe

C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\suzanne\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\wuauclt.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Portail Orange : Actu, Sport, Assistance Internet, Web Mail Orange

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\Connexion Internet Orange\SearchURLHook\SearchPageURL.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - !{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

O3 - Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O3 - Toolbar: (no name) - !{c9a6357b-25cc-4bcf-96c1-78736985d412} - (no file)

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll

O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe

O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

O4 - HKLM\..\Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKCU\..\Run: [MailNotifier] C:\Program Files\Orange\MailNotifier\MailNotifier.exe

O4 - HKCU\..\Run: [orangeinside] C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: envoyer le texte sélectionné par sms - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html

O8 - Extra context menu item: envoyer par sms - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html

O8 - Extra context menu item: envoyer un mail - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

O8 - Extra context menu item: orange.fr - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html

O8 - Extra context menu item: rechercher le texte sélectionné - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html

O8 - Extra context menu item: traduire la page - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html

O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html

O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: Logiciels gratuits - Orange

O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://kitchenplanner.ikea.com/fr/Core/Player/2020PlayerAX_Win32.cab

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe

O23 - Service: Bandoo Coordinator - Bandoo Media Inc. - C:\PROGRA~1\Bandoo\Bandoo.exe

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe

O23 - Service: Orange update Core Service - Unknown owner - C:\Program Files\Orange\OrangeUpdate\Service\OUCore.exe

--

End of file - 9893 bytes

Link naar reactie
Delen op andere sites

heb net een hele scan gedaan en dit is het resultaat:

Malwarebytes' Anti-Malware 1.51.2.1300

Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Databaseversie: 8146

Windows 6.1.7601 Service Pack 1

Internet Explorer 9.0.8112.16421

12-11-2011 17:09:26

mbam-log-2011-11-12 (17-09-26).txt

Scantype: Volledige scan (C:\|)

Objecten gescand: 452203

Verstreken tijd: 2 uur/uren, 34 minuut/minuten, 10 seconde(n)

Geheugenprocessen geïnfecteerd: 0

Geheugenmodulen geïnfecteerd: 0

Registersleutels geïnfecteerd: 0

Registerwaarden geïnfecteerd: 0

Registerdata geïnfecteerd: 0

Mappen geïnfecteerd: 0

Bestanden geïnfecteerd: 8

Geheugenprocessen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Registerdata geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Mappen geïnfecteerd:

(Geen kwaadaardige objecten gedetecteerd)

Bestanden geïnfecteerd:

c:\windows.old\program files\queryexplorer\queryexplorer.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.

c:\windows.old\program files\queryexplorer\uninstall.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.

c:\windows.old\program files\queryexplorer\queryexplorer_deleted_\queryexplorer.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.

c:\Windows.old\program files\shopperreports3\bin\3.0.491.0\cntntcntr.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.

c:\Windows.old\program files\shopperreports3\bin\3.0.491.0\shopperreportsuninstaller.exe (Adware.ShopperReports) -> Quarantined and deleted successfully.

c:\windows.old\programdata\queryexplorer\queryexplorer117.exe (Adware.QueryExplorer) -> Quarantined and deleted successfully.

c:\windows.old\users\suzanne\appdata\local\microsoft\windows\temporary internet files\content.ie5\jtsjxk00\vlcsetup[1].exe (Adware.Hotbar) -> Quarantined and deleted successfully.

c:\windows.old\users\suzanne\appdata\local\temp\nsjced.tmp\setup.dll (Adware.Seekmo) -> Quarantined and deleted successfully.

Link naar reactie
Delen op andere sites

Start Hijackthis op als administrator.

Selecteer “Do a system scan only”.

Vink alleen de items aan die hieronder zijn genoemd:

O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - !{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

O3 - Toolbar: (no name) - !{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

O3 - Toolbar: (no name) - !{c9a6357b-25cc-4bcf-96c1-78736985d412} - (no file)

Klik op 'Fix checked' om de items te verwijderen.

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

  • Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:
    Klik hier
    Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap.
  • Dubbelklik op ComboFix.exe en volg de meldingen op het scherm.
  • ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.
    **Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware.
  • Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.

cf-rc-auto.jpg

Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:

rc-auto-done.jpg

Klik op Ja om verder te gaan met het scannen naar malware.

Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion", herstart dan de computer.

Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Indien je problemen hebt bij het uitvoeren van ComboFix, gelieve dit te melden.

Link naar reactie
Delen op andere sites

het log bestand van ComboFix:

ComboFix 11-11-13.01 - suzanne 12-11-2011 16:17:00.2.2 - x86

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3067.1976 [GMT 1:00]

Gestart vanuit: c:\users\suzanne\Downloads\ComboFix.exe

AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

.

---- Voorgaande Run -------

.

c:\program files\UNWISE.EXE

c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

.

-- Voorgaande Run --

.

Besmet exemplaar van c:\windows\system32\userinit.exe werd aangetroffen en gedesinfecteerd

Hersteld exemplaar van - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe

.

--------

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-10-12 to 2011-11-12 ))))))))))))))))))))))))))))))

.

.

2011-11-12 15:24 . 2011-11-12 15:24 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-12 12:50 . 2011-11-12 12:50 388096 ----a-r- c:\users\suzanne\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-11-12 12:19 . 2011-11-12 12:19 -------- d-----w- c:\users\suzanne\AppData\Roaming\Malwarebytes

2011-11-12 12:19 . 2011-11-12 12:19 -------- d-----w- c:\programdata\Malwarebytes

2011-11-12 11:27 . 2011-11-12 11:27 -------- d-----w- c:\program files\Trend Micro

2011-11-11 17:14 . 2011-11-12 00:11 -------- d-----w- c:\program files\Microsoft Works

2011-11-11 17:12 . 2011-11-11 17:12 -------- d-----w- c:\program files\Microsoft.NET

2011-11-11 17:10 . 2011-11-11 17:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8

2011-11-11 06:26 . 2011-11-12 15:26 -------- d-----w- c:\users\suzanne\AppData\Local\CrashDumps

2011-11-10 20:05 . 2011-11-10 20:05 -------- d-----w- c:\program files\Common Files\Java

2011-11-10 18:50 . 2011-11-10 18:50 -------- d-----w- c:\windows\system32\N360_BACKUP

2011-11-10 18:41 . 2010-08-21 03:59 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys

2011-11-10 18:41 . 2011-11-11 17:27 -------- d-----w- c:\program files\Symantec

2011-11-10 18:41 . 2011-11-11 17:26 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2011-11-10 18:41 . 2011-11-10 19:02 -------- d-----w- c:\program files\Common Files\Symantec Shared

2011-11-10 18:41 . 2010-08-21 03:59 106928 ----a-w- c:\windows\system32\GEARAspi.dll

2011-11-10 18:40 . 2011-11-12 07:35 -------- d-----w- c:\windows\system32\drivers\N360

2011-11-10 18:40 . 2011-11-10 18:40 -------- d-----w- c:\program files\Norton 360

2011-11-10 18:40 . 2011-11-10 18:41 -------- d-----w- c:\programdata\Norton

2011-11-10 18:40 . 2011-11-10 18:40 -------- d-----w- c:\program files\NortonInstaller

2011-11-10 13:50 . 2011-11-10 13:50 -------- d-----w- c:\users\suzanne\AppData\Roaming\IObit

2011-11-10 13:50 . 2011-11-10 13:50 -------- d-----w- c:\program files\IObit

2011-11-10 11:09 . 2011-11-10 11:10 -------- d--h--w- c:\program files\Temp

2011-11-10 10:12 . 2011-11-10 10:12 -------- d-----w- c:\users\suzanne\AppData\Local\VS Revo Group

2011-11-10 10:06 . 2011-11-10 10:12 -------- d-----w- c:\program files\VS Revo Group

2011-11-09 19:56 . 2011-11-10 10:49 -------- d-----w- c:\program files\DownVision

2011-11-09 18:27 . 2011-11-10 11:55 -------- d-----w- c:\users\suzanne\AppData\Local\Adobe

2011-11-09 18:01 . 2011-09-29 16:03 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys

2011-11-09 18:01 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll

2011-11-09 18:01 . 2011-09-29 03:37 2341888 ----a-w- c:\windows\system32\win32k.sys

2011-11-09 17:53 . 2011-11-09 17:53 -------- d-----w- c:\users\suzanne\AppData\Roaming\Fighters

2011-11-09 17:53 . 2011-11-09 17:53 -------- d-----w- c:\programdata\Fighters

2011-11-09 17:35 . 2011-11-09 17:35 -------- d-----w- c:\program files\BabylonToolbar

2011-11-09 17:35 . 2011-11-09 20:27 -------- d-----w- c:\users\suzanne\AppData\Roaming\Media Finder

2011-11-09 14:50 . 2011-11-10 09:57 -------- d-----w- c:\users\suzanne\AppData\Local\ElevatedDiagnostics

2011-11-09 14:45 . 2011-11-12 12:12 -------- d-----w- c:\users\suzanne\AppData\Local\Diagnostics

2011-11-09 13:05 . 2011-11-09 13:05 -------- d-----w- c:\programdata\Premium

2011-11-09 13:05 . 2011-11-09 13:06 -------- d-----w- c:\programdata\InstallMate

2011-11-09 12:59 . 2011-11-09 15:05 -------- d-----w- c:\users\suzanne\AppData\Roaming\Raptr

2011-11-09 12:59 . 2011-11-09 13:35 -------- d-----w- c:\program files\Raptr

2011-10-27 12:16 . 2011-11-10 10:48 -------- d-----w- c:\programdata\AVG2012

2011-10-18 09:34 . 2011-10-18 09:34 -------- d-----w- c:\users\suzanne\AppData\Roaming\f-secure

2011-10-18 09:33 . 2011-10-18 09:33 -------- d-----w- c:\programdata\F-Secure

2011-10-15 17:13 . 2011-08-17 04:24 465408 ----a-w- c:\windows\system32\psisdecd.dll

2011-10-15 17:13 . 2011-08-17 04:19 75776 ----a-w- c:\windows\system32\psisrndr.ax

2011-10-15 17:13 . 2011-08-27 04:26 571904 ----a-w- c:\windows\system32\oleaut32.dll

2011-10-15 17:13 . 2011-08-27 04:26 233472 ----a-w- c:\windows\system32\oleacc.dll

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-11-12 14:51 . 2011-11-12 14:12 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{27D0A041-EC65-42E4-B19E-DA8FD46D516C}\offreg.dll

2011-11-12 11:33 . 2011-11-08 15:53 159080 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin

2011-11-10 20:03 . 2011-02-04 16:42 544656 ----a-w- c:\windows\system32\deployJava1.dll

2011-10-18 00:28 . 2011-11-11 16:38 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{27D0A041-EC65-42E4-B19E-DA8FD46D516C}\mpengine.dll

2011-09-16 09:24 . 2011-09-05 17:27 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll

2011-09-16 09:24 . 2011-09-16 09:24 882496 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll

2011-09-11 20:00 . 2011-08-01 09:05 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll

2010-12-01 10:27 . 2011-01-28 19:36 2735200 ----a-w- c:\program files\tbZyng.dll

2011-10-18 09:37 . 2011-08-05 19:07 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-08 39408]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]

"MailNotifier"="c:\program files\Orange\MailNotifier\MailNotifier.exe" [2010-11-04 634368]

"orangeinside"="c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-08-27 1194504]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]

"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"ORAHSSSessionManager"="c:\program files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe" [2009-08-24 135920]

"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 136176]

R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run [x]

R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 136176]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-17 1343400]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\SYMDS.SYS [2011-01-27 340088]

S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS [2011-03-15 744568]

S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20111027.001\BHDrvx86.sys [2011-10-27 818808]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-06 218688]

S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20111111.030\IDSvix86.sys [2011-11-10 368248]

S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\Ironx86.SYS [2010-11-16 136312]

S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360\0501000.01D\SYMNETS.SYS [2011-07-08 299640]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]

S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]

S2 Orange update Core Service;Orange update Core Service;c:\program files\Orange\OrangeUpdate\Service\OUCore.exe [2011-05-20 1055872]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-12 106104]

.

.

Inhoud van de 'Gedeelde Taken' map

.

2011-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 10:32]

.

2011-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 10:32]

.

2011-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2877954855-1833977058-2358803089-1000Core.job

- c:\users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-15 10:32]

.

2011-11-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2877954855-1833977058-2358803089-1000UA.job

- c:\users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-15 10:32]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

IE: ajouter cette page à vos favoris Orange - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000

IE: envoyer le texte sélectionné par sms - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html

IE: envoyer par sms - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html

IE: envoyer un mail - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: orange.fr - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html

IE: rechercher le texte sélectionné - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html

IE: traduire la page - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html

IE: traduire le texte sélectionné - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html

Trusted Zone: orange.fr\logicielsgratuits

TCP: DhcpNameServer = 192.168.1.1

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

FF - ProfilePath - c:\users\suzanne\AppData\Roaming\Mozilla\Firefox\Profiles\ko9psdws.default\

FF - prefs.js: browser.search.selectedEngine - Orange

FF - prefs.js: browser.startup.homepage - hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

FF - prefs.js: keyword.URL - hxxp://rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=

FF - prefs.js: network.proxy.type - 0

FF - user.js: browser.startup.homepage - hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

FF - user.js: browser.search.selectedEngine - Orange

FF - user.js: keyword.URL - hxxp://rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-10 - (no file)

Toolbar-!{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)

Toolbar-!{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)

WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file)

HKLM-Run-Malwarebytes' Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe

AddRemove-OrangeToolbar - c:\program files\Orange\ToolbarFr\uninstall.exe

AddRemove-Zynga Toolbar - c:\progra~1\UNWISE.EXE

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-2877954855-1833977058-2358803089-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-2877954855-1833977058-2358803089-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (S-1-5-21-2877954855-1833977058-2358803089-1000)

@Denied: (2) (LocalSystem)

"Progid"="Outlook.File.vcf"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'Explorer.exe'(3316)

c:\windows\system32\msi.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\system32\atieclxx.exe

c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

c:\windows\system32\taskhost.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\progra~1\Bandoo\Bandoo.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\conhost.exe

c:\program files\Orange\Connexion Internet Orange\Launcher\Launcher.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\system32\DllHost.exe

.

**************************************************************************

.

Voltooingstijd: 2011-11-12 16:59:05 - machine werd herstart

ComboFix-quarantined-files.txt 2011-11-12 15:59

.

Pre-Run: 354.224.918.528 bytes beschikbaar

Post-Run: 354.170.163.200 bytes beschikbaar

.

- - End Of File - - 0A35C40A1CE6B5BA3148D13D757B9127

---------- Post toegevoegd om 17:08 ---------- Vorige post was om 17:02 ----------

ik heb hijackthis als administrator gedaan maar dan kan ik toch allen maar de scan uitvoeren en niet de systeem scan en dan can ik die files niet verwijderen, weet ook niet waarom.

Link naar reactie
Delen op andere sites

Open een nieuw kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

c:\users\suzanne\AppData\Roaming\IObit

c:\program files\IObit

c:\program files\BabylonToolbar

c:\programdata\AVG2012

c:\programdata\AVG2012

c:\users\suzanne\AppData\Roaming\f-secure

c:\programdata\F-Secure:\users\suzanne\AppData\Roaming\f-secure

c:\programdata\F-Secure

c:\Program Files\Bandoo

File::

c:\program files\tbZyng.dll

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"= -

Sla dit bestand op je bureaublad op als CFScript

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht samen met een nieuw logje van HijackThis.

Link naar reactie
Delen op andere sites

ik heb de onderstaande tekst in een kladblok gedaan en op mijn bureaublad geplaatst. nou kan ik combifix.exe nergens vinden, als ik combifix wil openen dan start hij direct op en kan ik niks meer, weet niet hoe ik het moet doen.

maar wil wel even melden dat mijn computer reeds weer voor 90% goed werkt, zijn nog enkele kleine programma's die het niet doen, zolals silverlight,ik heb office opnieuw geinstaleerd en die werkt nu ook weer.

daarvoor wil ik jullie alvast hartelijk danken, jullie hebben mij heel goed geholpen

bedankt

Link naar reactie
Delen op andere sites

Combofix staat in je download map (c:\users\suzanne\Downloads\ComboFix.exe)

Verplaats combofix naar het bureaublad en sleep dan het scriptje op de rode icoon van combofix.

Dit zal combofix doen opstarten en de instructies in het scriptje uitvoeren.

Post daarna het nieuwe logje van combofix in je volgende bericht samen met een nieuw logje van HijackThis.

Link naar reactie
Delen op andere sites

ComboFix 11-11-13.01 - suzanne 16-11-2011 10:07:47.3.2 - x86

Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3067.2048 [GMT 1:00]

Gestart vanuit: c:\users\suzanne\Downloads\ComboFix.exe

gebruikte Opdracht switches :: c:\users\suzanne\Desktop\CFScript - Snelkoppeling.lnk

AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-10-16 to 2011-11-16 ))))))))))))))))))))))))))))))

.

.

2011-11-16 09:15 . 2011-11-16 09:15 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-11-16 09:15 . 2011-11-16 09:15 -------- d-----w- c:\users\Administrator\AppData\Local\temp

2011-11-12 12:50 . 2011-11-12 12:50 388096 ----a-r- c:\users\suzanne\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-11-12 12:19 . 2011-11-12 12:19 -------- d-----w- c:\users\suzanne\AppData\Roaming\Malwarebytes

2011-11-12 12:19 . 2011-11-12 12:19 -------- d-----w- c:\programdata\Malwarebytes

2011-11-12 11:27 . 2011-11-12 11:27 -------- d-----w- c:\program files\Trend Micro

2011-11-11 17:14 . 2011-11-12 00:11 -------- d-----w- c:\program files\Microsoft Works

2011-11-11 17:12 . 2011-11-11 17:12 -------- d-----w- c:\program files\Microsoft.NET

2011-11-11 17:10 . 2011-11-11 17:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8

2011-11-11 06:26 . 2011-11-16 09:17 -------- d-----w- c:\users\suzanne\AppData\Local\CrashDumps

2011-11-10 20:05 . 2011-11-10 20:05 -------- d-----w- c:\program files\Common Files\Java

2011-11-10 18:50 . 2011-11-10 18:50 -------- d-----w- c:\windows\system32\N360_BACKUP

2011-11-10 18:41 . 2011-07-06 11:44 27888 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys

2011-11-10 18:41 . 2011-11-11 17:27 -------- d-----w- c:\program files\Symantec

2011-11-10 18:41 . 2011-11-11 17:26 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS

2011-11-10 18:41 . 2011-11-10 19:02 -------- d-----w- c:\program files\Common Files\Symantec Shared

2011-11-10 18:41 . 2010-08-21 03:59 106928 ----a-w- c:\windows\system32\GEARAspi.dll

2011-11-10 18:40 . 2011-11-12 07:35 -------- d-----w- c:\windows\system32\drivers\N360

2011-11-10 18:40 . 2011-11-10 18:40 -------- d-----w- c:\program files\Norton 360

2011-11-10 18:40 . 2011-11-10 18:41 -------- d-----w- c:\programdata\Norton

2011-11-10 18:40 . 2011-11-10 18:40 -------- d-----w- c:\program files\NortonInstaller

2011-11-10 13:50 . 2011-11-10 13:50 -------- d-----w- c:\users\suzanne\AppData\Roaming\IObit

2011-11-10 13:50 . 2011-11-10 13:50 -------- d-----w- c:\program files\IObit

2011-11-10 11:09 . 2011-11-10 11:10 -------- d--h--w- c:\program files\Temp

2011-11-10 10:12 . 2011-11-10 10:12 -------- d-----w- c:\users\suzanne\AppData\Local\VS Revo Group

2011-11-10 10:06 . 2011-11-10 10:12 -------- d-----w- c:\program files\VS Revo Group

2011-11-09 19:56 . 2011-11-10 10:49 -------- d-----w- c:\program files\DownVision

2011-11-09 18:27 . 2011-11-10 11:55 -------- d-----w- c:\users\suzanne\AppData\Local\Adobe

2011-11-09 18:01 . 2011-09-29 16:03 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys

2011-11-09 18:01 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll

2011-11-09 18:01 . 2011-09-29 03:37 2341888 ----a-w- c:\windows\system32\win32k.sys

2011-11-09 17:53 . 2011-11-09 17:53 -------- d-----w- c:\users\suzanne\AppData\Roaming\Fighters

2011-11-09 17:53 . 2011-11-09 17:53 -------- d-----w- c:\programdata\Fighters

2011-11-09 17:35 . 2011-11-09 17:35 -------- d-----w- c:\program files\BabylonToolbar

2011-11-09 17:35 . 2011-11-09 20:27 -------- d-----w- c:\users\suzanne\AppData\Roaming\Media Finder

2011-11-09 14:50 . 2011-11-10 09:57 -------- d-----w- c:\users\suzanne\AppData\Local\ElevatedDiagnostics

2011-11-09 14:45 . 2011-11-12 12:12 -------- d-----w- c:\users\suzanne\AppData\Local\Diagnostics

2011-11-09 13:05 . 2011-11-09 13:05 -------- d-----w- c:\programdata\Premium

2011-11-09 13:05 . 2011-11-09 13:06 -------- d-----w- c:\programdata\InstallMate

2011-11-09 12:59 . 2011-11-09 15:05 -------- d-----w- c:\users\suzanne\AppData\Roaming\Raptr

2011-11-09 12:59 . 2011-11-09 13:35 -------- d-----w- c:\program files\Raptr

2011-10-27 12:16 . 2011-11-10 10:48 -------- d-----w- c:\programdata\AVG2012

2011-10-18 09:34 . 2011-10-18 09:34 -------- d-----w- c:\users\suzanne\AppData\Roaming\f-secure

2011-10-18 09:33 . 2011-10-18 09:33 -------- d-----w- c:\programdata\F-Secure

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-11-16 08:26 . 2011-11-16 08:26 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F1FDA8AA-3323-46D6-B942-284869E7F559}\offreg.dll

2011-11-15 12:32 . 2011-11-08 15:53 159080 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin

2011-11-10 20:03 . 2011-02-04 16:42 544656 ----a-w- c:\windows\system32\deployJava1.dll

2011-10-18 00:28 . 2011-11-15 12:09 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F1FDA8AA-3323-46D6-B942-284869E7F559}\mpengine.dll

2011-09-16 09:24 . 2011-09-05 17:27 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll

2011-09-16 09:24 . 2011-09-16 09:24 882496 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll

2011-09-11 20:00 . 2011-08-01 09:05 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll

2011-09-01 02:35 . 2011-10-15 18:59 1798144 ----a-w- c:\windows\system32\jscript9.dll

2011-09-01 02:28 . 2011-10-15 18:59 1126912 ----a-w- c:\windows\system32\wininet.dll

2011-09-01 02:22 . 2011-10-15 18:59 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2011-08-27 04:26 . 2011-10-15 17:13 571904 ----a-w- c:\windows\system32\oleaut32.dll

2011-08-27 04:26 . 2011-10-15 17:13 233472 ----a-w- c:\windows\system32\oleacc.dll

2010-12-01 10:27 . 2011-01-28 19:36 2735200 ----a-w- c:\program files\tbZyng.dll

2011-10-18 09:37 . 2011-08-05 19:07 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-08 39408]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]

"MailNotifier"="c:\program files\Orange\MailNotifier\MailNotifier.exe" [2010-11-04 634368]

"orangeinside"="c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe" [bU]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-08-27 1194504]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]

"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-07-06 1833504]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"ORAHSSSessionManager"="c:\program files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe" [2009-08-24 135920]

"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 136176]

R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run [x]

R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 136176]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-17 1343400]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\SYMDS.SYS [2011-01-27 340088]

S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS [2011-03-15 744568]

S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\BASHDefs\20111114.002\BHDrvx86.sys [2011-11-14 819320]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-06 218688]

S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.2.1\Definitions\IPSDefs\20111115.030\IDSvix86.sys [2011-11-10 368248]

S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\Ironx86.SYS [2010-11-16 136312]

S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360\0501000.01D\SYMNETS.SYS [2011-07-08 299640]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]

S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-04-17 130008]

S2 Orange update Core Service;Orange update Core Service;c:\program files\Orange\OrangeUpdate\Service\OUCore.exe [2011-05-20 1055872]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-12 106104]

.

.

Inhoud van de 'Gedeelde Taken' map

.

2011-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 10:32]

.

2011-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-08 10:32]

.

2011-11-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2877954855-1833977058-2358803089-1000Core.job

- c:\users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-15 10:32]

.

2011-11-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2877954855-1833977058-2358803089-1000UA.job

- c:\users\suzanne\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-15 10:32]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

IE: ajouter cette page à vos favoris Orange - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000

IE: envoyer le texte sélectionné par sms - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html

IE: envoyer par sms - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html

IE: envoyer un mail - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: orange.fr - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html

IE: rechercher le texte sélectionné - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html

IE: traduire la page - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html

IE: traduire le texte sélectionné - c:\users\suzanne\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html

Trusted Zone: orange.fr\logicielsgratuits

TCP: DhcpNameServer = 192.168.1.1

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

FF - ProfilePath - c:\users\suzanne\AppData\Roaming\Mozilla\Firefox\Profiles\ko9psdws.default\

FF - prefs.js: browser.search.selectedEngine - Orange

FF - prefs.js: browser.startup.homepage - hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

FF - prefs.js: keyword.URL - hxxp://rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=

FF - prefs.js: network.proxy.type - 0

FF - user.js: browser.startup.homepage - hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage

FF - user.js: browser.search.selectedEngine - Orange

FF - user.js: keyword.URL - hxxp://rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-2877954855-1833977058-2358803089-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-2877954855-1833977058-2358803089-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (S-1-5-21-2877954855-1833977058-2358803089-1000)

@Denied: (2) (LocalSystem)

"Progid"="Outlook.File.vcf"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'Explorer.exe'(1152)

c:\windows\System32\gameux.dll

c:\windows\system32\dxp.dll

c:\windows\System32\pnidui.dll

c:\program files\Internet Explorer\ieproxy.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\system32\atieclxx.exe

c:\windows\system32\taskhost.exe

c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\progra~1\Bandoo\Bandoo.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\conhost.exe

c:\program files\Orange\Connexion Internet Orange\Launcher\Launcher.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\system32\DllHost.exe

.

**************************************************************************

.

Voltooingstijd: 2011-11-16 10:49:50 - machine werd herstart

ComboFix-quarantined-files.txt 2011-11-16 09:49

ComboFix2.txt 2011-11-12 15:59

.

Pre-Run: 357.712.023.552 bytes beschikbaar

Post-Run: 357.656.309.760 bytes beschikbaar

.

- - End Of File - - D261AE5F662F19A1A633330CA6F559C1

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.