Ga naar inhoud

Laptop werkt traag na verwijderen System Fix


Hillytom

Aanbevolen berichten

Download rkill via één van de onderstaande links naar het bureaublad.

Dubbelklik op "rkill" om het te starten

Dit kan een beetje tijd in beslag nemen.

Indien er een melding komt dat rkill een infectie is kunt u dit negeren, het is namelijk een vals alarm.

Indien u problemen blijft houden qua meldingen download dan hier (iExplorer.exe) een hernoemde rkill versie naar uw bureaublad en voer deze uit.

Let op!!! Herstart de computer niet na het gebruik van rkill

Link naar reactie
Delen op andere sites

  • Reacties 24
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

gedaan en dit is het logje

This log file is located at C:\rkill.log.

Please post this only if requested to by the person helping you.

Otherwise you can close this log when you wish.

Rkill was run on 27/12/2011 at 10:42:57.

Operating System: Windows Vista Home Basic

Processes terminated by Rkill or while it was running:

Rkill completed on 27/12/2011 at 10:44:21.

Link naar reactie
Delen op andere sites

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

Klik hier

2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.

3. Dubbelklik op "Combofix.exe" om de tool te starten.

4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion", herstart dan de computer.

5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

ziehier ;

ComboFix 11-12-26.03 - 27/12/2011 13:03:05.1.2 - x86

Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.2814.1523 [GMT 1:00]

Gestart vanuit: c:\users\Cindy CottenjÚ\Desktop\ComboFix.exe

AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}

SP: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\~njRk4PQtwSwpVC

c:\programdata\~njRk4PQtwSwpVCr

c:\programdata\njRk4PQtwSwpVC

c:\users\Cindy Cottenjé\AppData\Local\Temp\ppcrlui_1444_2

c:\users\CINDYC~1\AppData\Local\Temp\ppcrlui_1444_2

c:\windows\IsUn0413.exe

c:\windows\iun6002.exe

c:\windows\system32\muzapp.exe

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-11-27 to 2011-12-27 ))))))))))))))))))))))))))))))

.

.

2011-12-27 12:43 . 2011-12-27 12:47 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\temp

2011-12-27 12:43 . 2011-12-27 12:43 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-12-26 16:21 . 2011-12-26 16:21 -------- d-----w- c:\programdata\Kaspersky Lab

2011-12-26 15:58 . 2011-12-26 15:58 -------- d-----w- c:\program files\Common Files\Java

2011-12-26 15:58 . 2011-12-26 15:57 476904 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll

2011-12-26 15:58 . 2011-12-26 15:57 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin7.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin.dll

2011-12-26 15:46 . 2011-12-26 15:46 -------- d-----w- c:\programdata\Apple Computer

2011-12-26 15:43 . 2011-12-26 15:43 -------- d-----w- c:\program files\Common Files\Apple

2011-12-26 15:42 . 2011-12-26 15:42 -------- d-----w- c:\program files\Apple Software Update

2011-12-25 18:37 . 2011-12-25 18:37 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll

2011-12-25 18:37 . 2011-12-25 18:37 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll

2011-12-25 18:37 . 2011-12-25 18:37 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll

2011-12-25 18:37 . 2011-12-25 18:37 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll

2011-12-25 09:02 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE21603D-26BC-4582-BEA4-D00E5088B0BC}\mpengine.dll

2011-12-24 13:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-24 13:40 . 2011-12-24 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-24 12:53 . 2011-12-24 12:53 -------- d-----w- c:\program files\Trend Micro

2011-12-24 07:07 . 2011-12-24 07:07 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP

2011-12-24 06:33 . 2011-12-24 06:33 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\InstallShield

2011-12-23 07:56 . 2011-11-22 17:20 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys

2011-12-23 07:56 . 2011-11-22 17:20 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys

2011-12-23 07:56 . 2011-11-22 17:20 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys

2011-12-22 14:42 . 2011-12-22 14:42 58760 ----a-w- C:\symlcsv1.exe

2011-12-22 13:28 . 2011-12-22 13:28 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\Threat Expert

2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1230.old

2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1229.old

2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1229.old

2011-12-22 08:37 . 2011-11-22 18:38 105792 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys

2011-12-22 08:37 . 2011-11-22 18:38 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2011-12-22 08:37 . 2011-11-22 18:41 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys

2011-12-22 08:36 . 2011-11-22 18:43 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2011-12-22 08:36 . 2011-12-22 08:36 -------- d-----w- c:\program files\PC Tools

2011-12-22 08:33 . 2011-10-07 16:52 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys

2011-12-22 08:33 . 2011-10-07 16:52 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys

2011-12-22 08:33 . 2011-11-14 14:12 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2011-12-22 08:33 . 2011-11-14 14:12 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2011-12-22 08:33 . 2011-11-22 18:42 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys

2011-12-22 08:33 . 2011-12-22 08:40 -------- d-----w- c:\program files\Common Files\PC Tools

2011-12-22 08:32 . 2011-12-23 07:56 -------- d-----w- c:\programdata\PC Tools

2011-12-22 08:32 . 2011-12-22 08:32 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\TestApp

2011-12-20 09:19 . 2011-12-22 17:18 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\kbdobjCtrl

2011-12-19 19:56 . 2011-12-19 20:03 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\Trine2

2011-12-14 18:22 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-12-14 18:22 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-12-14 18:22 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys

2011-12-14 18:22 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll

2011-12-14 18:22 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

2011-12-14 18:22 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-14 18:22 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll

2011-12-11 18:28 . 2011-12-24 13:35 -------- d-----w- c:\program files\StartSearch plugin

2011-11-29 17:36 . 2011-12-22 17:17 -------- d-----w- c:\program files\StarCraft II

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-26 19:42 . 2011-06-22 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx

2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts

2011-12-25 18:37 . 2011-05-02 17:20 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]

.

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-21 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"Dvd- of cd-deling"="c:\program files\Dvd- of cd-deling\ODSAgent.exe" [2008-02-20 619832]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"<NO NAME>"= 0

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"<NO NAME>"= 0

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]

@="Service"

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk

backup=c:\windows\pss\Bluetooth.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bureaubladmenu.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bureaubladmenu.lnk

backup=c:\windows\pss\Bureaubladmenu.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board-hulpmiddelen.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board-hulpmiddelen.lnk

backup=c:\windows\pss\SMART Board-hulpmiddelen.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

backup=c:\windows\pss\Dropbox.lnk.Startup

backupExtension=.Startup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kuma_Tray.lnk

backup=c:\windows\pss\Kuma_Tray.lnk.Startup

backupExtension=.Startup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk

backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnk.Startup

backupExtension=.Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]

2011-11-12 00:48 3303000 ----a-w- c:\users\Cindy Cottenjé\AppData\Local\Akamai\netsession_win.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-phishing Domain Advisor]

2011-01-31 22:17 232104 ----a-w- c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

2010-08-31 08:04 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]

2011-08-07 07:26 136176 ----atw- c:\users\Cindy Cottenjé\AppData\Local\Google\Update\GoogleUpdate.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]

2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]

2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]

2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]

2008-06-27 03:42 6295552 ----a-w- c:\windows\RtHDVCpl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service]

2010-08-23 13:02 5347728 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTBoardService.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent]

2010-08-23 13:03 1662352 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTSNMPAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys]

2008-02-04 09:13 1038136 ----a-w- c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]

2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

2009-04-21 08:30 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2007-06-08 17:53 894512 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]

2008-01-21 02:35 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664]

R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-29 20032]

R3 EFUploadSrv;ExtraFilm upload service;c:\program files\ExtraFilm Designer BE NL\EFUploadSrv.exe [2009-07-09 1716224]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]

R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-31 30192]

R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664]

R3 KiesAllShare;SAMSUNG KiesAllShare Service;c:\program files\Samsung\Kies\WiselinkPro\WiselinkPro.exe [x]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-05-06 23096]

R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [2011-11-22 70536]

R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [2011-11-22 402336]

R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]

R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]

R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]

R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]

R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-11-22 35264]

R3 ThreatFire;ThreatFire;c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

S0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\System32\Drivers\pctBTFix.sys [2011-11-22 17848]

S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-14 331880]

S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656]

S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-10-07 660992]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-04 691696]

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-11-22 54328]

S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-11-22 574424]

S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2011-11-22 253096]

S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-11-22 185560]

S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]

S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-25 217088]

S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-06-24 65856]

S2 Response Hardware;Response-hardware;c:\program files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe [2010-08-23 30608]

S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-12-22 29736]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-05-25 36640]

S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-05-07 85136]

S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 350720]

S3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-08-23 11152]

S3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-08-23 14224]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-03-19 22072]

S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-11-17 13976]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - FSUSBEXDISK

*Deregistered* - PCTSDInjDriver32

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

bthsvcs REG_MULTI_SZ BthServ

Akamai REG_MULTI_SZ Akamai

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

ezSharedSvc

.

Inhoud van de 'Gedeelde Taken' map

.

2011-12-27 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-21 07:22]

.

2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40]

.

2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40]

.

2011-12-27 c:\windows\Tasks\Recovery DVD Creator-Cindy Cottenjé.job

- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-10-08 09:13]

.

2011-12-27 c:\windows\Tasks\Uitgebreide garantie-Cindy Cottenjé.job

- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-10-08 09:13]

.

.

------- Bijkomende Scan -------

.

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Afbeelding verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Pagina verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

TCP: DhcpNameServer = 195.130.131.5 195.130.130.133

FF - ProfilePath - c:\users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\

FF - prefs.js: browser.search.selectedEngine - BearShare Web Search

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll

HKCU-Run-Driver Updater - (no file)

MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe

MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe

MSConfigStartUp-UniblueRegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe

AddRemove-GameCenter - c:\program files\Cyanide\GameCenter\uninstall.exe

AddRemove-Robbie Konijn Peuter - c:\windows\IsUn0413.exe

AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe

AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe

AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe

AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe

AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe

AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe

AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe

AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe

AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe

AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe

AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe

AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe

AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2011-12-27 13:46

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover

Windows 6.0.6002 Disk: Hitachi_HTS543216L9A300 rev.FB2OC40C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

.

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user != kernel MBR !!!

sectors 312581791 (+0): user != kernel

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]

"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-4240524916-931938033-4048848888-1000\Software\SecuROM\License information*]

"datasecu"=hex:7d,31,bd,ef,ca,a5,1e,ab,72,34,a0,41,15,5d,16,65,88,78,2a,77,f3,

ae,26,79,4a,74,c1,bf,3c,54,b1,6f,29,67,1c,4e,00,0b,b3,99,cd,c6,ce,9d,93,f6,\

"rkeysecu"=hex:b1,77,54,1c,da,d2,01,20,f4,54,4d,05,27,51,cc,62

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

Voltooingstijd: 2011-12-27 14:06:15

ComboFix-quarantined-files.txt 2011-12-27 13:05

.

Pre-Run: 29.977.309.184 bytes beschikbaar

Post-Run: 30.016.872.448 bytes beschikbaar

.

- - End Of File - - 2333F31F0B5CD9FBD9D4FF376208DBB9

Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

File::

c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP

C:\symlcsv1.exe

Folder::

c:\users\Cindy Cottenjé\AppData\Local\kbdobjCtrl

Registry::

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

[-HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

Firefox::

FF - ProfilePath - c:\users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\

FF - prefs.js: browser.search.selectedEngine -

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht.

Link naar reactie
Delen op andere sites

Voila nieuwe log

ComboFix 11-12-27.01 - Cindy Cottenjé 27/12/2011 17:42:16.3.2 - x86

Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.2814.1389 [GMT 1:00]

Gestart vanuit: c:\users\Cindy Cottenjé\Desktop\ComboFix.exe

gebruikte Opdracht switches :: c:\users\Cindy Cottenjé\Documents\CFScript.txt

AV: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}

SP: PC Tools Spyware Doctor with AntiVirus *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"C:\symlcsv1.exe"

"c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP"

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\symlcsv1.exe

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-11-27 to 2011-12-27 ))))))))))))))))))))))))))))))

.

.

2011-12-27 17:19 . 2011-12-27 17:21 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\temp

2011-12-27 17:19 . 2011-12-27 17:19 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-12-26 16:21 . 2011-12-26 16:21 -------- d-----w- c:\programdata\Kaspersky Lab

2011-12-26 15:58 . 2011-12-26 15:58 -------- d-----w- c:\program files\Common Files\Java

2011-12-26 15:58 . 2011-12-26 15:57 476904 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll

2011-12-26 15:58 . 2011-12-26 15:57 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin7.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll

2011-12-26 15:48 . 2011-12-26 15:48 159744 ----a-w- c:\program files\Mozilla Firefox\Plugins\npqtplugin.dll

2011-12-26 15:46 . 2011-12-26 15:46 -------- d-----w- c:\programdata\Apple Computer

2011-12-26 15:43 . 2011-12-26 15:43 -------- d-----w- c:\program files\Common Files\Apple

2011-12-26 15:42 . 2011-12-26 15:42 -------- d-----w- c:\program files\Apple Software Update

2011-12-25 18:37 . 2011-12-25 18:37 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll

2011-12-25 18:37 . 2011-12-25 18:37 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll

2011-12-25 18:37 . 2011-12-25 18:37 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll

2011-12-25 18:37 . 2011-12-25 18:37 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll

2011-12-25 09:02 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE21603D-26BC-4582-BEA4-D00E5088B0BC}\mpengine.dll

2011-12-24 13:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-12-24 13:40 . 2011-12-24 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-24 12:53 . 2011-12-24 12:53 -------- d-----w- c:\program files\Trend Micro

2011-12-24 07:07 . 2011-12-24 07:07 -------- d-----w- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP

2011-12-24 06:33 . 2011-12-24 06:33 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\InstallShield

2011-12-23 07:56 . 2011-11-22 17:20 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys

2011-12-23 07:56 . 2011-11-22 17:20 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys

2011-12-23 07:56 . 2011-11-22 17:20 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys

2011-12-22 13:28 . 2011-12-22 13:28 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\Threat Expert

2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:06 767952 ----a-w- c:\windows\BDTSupport.dll1230.old

2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:07 149456 ----a-w- c:\windows\SGDetectionTool.dll1229.old

2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1237.old

2011-12-22 08:38 . 2011-11-14 15:07 2246608 ----a-w- c:\windows\PCTBDCore.dll1229.old

2011-12-22 08:37 . 2011-11-22 18:38 105792 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys

2011-12-22 08:37 . 2011-11-22 18:38 253096 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2011-12-22 08:37 . 2011-11-22 18:41 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys

2011-12-22 08:36 . 2011-11-22 18:43 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2011-12-22 08:36 . 2011-12-22 08:36 -------- d-----w- c:\program files\PC Tools

2011-12-22 08:33 . 2011-10-07 16:52 660992 ----a-w- c:\windows\system32\drivers\pctEFA.sys

2011-12-22 08:33 . 2011-10-07 16:52 341656 ----a-w- c:\windows\system32\drivers\pctDS.sys

2011-12-22 08:33 . 2011-11-14 14:12 331880 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2011-12-22 08:33 . 2011-11-14 14:12 162584 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2011-12-22 08:33 . 2011-11-22 18:42 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys

2011-12-22 08:33 . 2011-12-22 08:40 -------- d-----w- c:\program files\Common Files\PC Tools

2011-12-22 08:32 . 2011-12-23 07:56 -------- d-----w- c:\programdata\PC Tools

2011-12-22 08:32 . 2011-12-22 08:32 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\TestApp

2011-12-20 09:19 . 2011-12-22 17:18 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Local\kbdobjCtrl

2011-12-19 19:56 . 2011-12-19 20:03 -------- d-----w- c:\users\Cindy Cottenjé\AppData\Roaming\Trine2

2011-12-14 18:22 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-12-14 18:22 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-12-14 18:22 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys

2011-12-14 18:22 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll

2011-12-14 18:22 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

2011-12-14 18:22 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-14 18:22 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll

2011-11-29 17:36 . 2011-12-22 17:17 -------- d-----w- c:\program files\StarCraft II

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-26 19:42 . 2011-06-22 11:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-12-24 12:53 . 2011-12-24 12:53 388096 ----a-r- c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-10-24 13:29 . 2011-10-24 13:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx

2011-10-24 13:29 . 2011-10-24 13:29 69632 ----a-w- c:\windows\system32\QuickTime.qts

2011-12-25 18:37 . 2011-05-02 17:20 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2011-12-27_12.47.30 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-12-25 09:31 . 2011-12-27 11:23 65536 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-12-25 09:31 . 2011-12-27 16:32 65536 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-12-25 09:31 . 2011-12-27 16:32 311296 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-12-25 09:31 . 2011-12-27 11:23 311296 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-12-25 09:31 . 2011-12-27 16:32 196608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-12-25 09:31 . 2011-12-27 11:23 196608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Cindy Cottenjé\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-21 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"Dvd- of cd-deling"="c:\program files\Dvd- of cd-deling\ODSAgent.exe" [2008-02-20 619832]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"<NO NAME>"= 0

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"<NO NAME>"= 0

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]

@="Service"

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk

backup=c:\windows\pss\Bluetooth.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bureaubladmenu.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bureaubladmenu.lnk

backup=c:\windows\pss\Bureaubladmenu.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SMART Board-hulpmiddelen.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SMART Board-hulpmiddelen.lnk

backup=c:\windows\pss\SMART Board-hulpmiddelen.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

backup=c:\windows\pss\Dropbox.lnk.Startup

backupExtension=.Startup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kuma_Tray.lnk

backup=c:\windows\pss\Kuma_Tray.lnk.Startup

backupExtension=.Startup

.

[HKLM\~\startupfolder\C:^Users^Cindy Cottenjé^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk]

path=c:\users\Cindy Cottenjé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk

backup=c:\windows\pss\OneNote 2007 Schermopname en Snel starten.lnk.Startup

backupExtension=.Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]

2011-11-12 00:48 3303000 ----a-w- c:\users\Cindy Cottenjé\AppData\Local\Akamai\netsession_win.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-phishing Domain Advisor]

2011-01-31 22:17 232104 ----a-w- c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

2010-08-31 08:04 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]

2011-08-07 07:26 136176 ----atw- c:\users\Cindy Cottenjé\AppData\Local\Google\Update\GoogleUpdate.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]

2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]

2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]

2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]

2008-06-27 03:42 6295552 ----a-w- c:\windows\RtHDVCpl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART Board Service]

2010-08-23 13:02 5347728 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTBoardService.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMART SNMP Agent]

2010-08-23 13:03 1662352 ----a-w- c:\program files\SMART Technologies\Classroom Teacher\SMARTSNMPAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys]

2008-02-04 09:13 1038136 ----a-w- c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]

2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

2009-04-21 08:30 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2007-06-08 17:53 894512 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]

2008-01-21 02:35 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664]

R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-29 20032]

R3 EFUploadSrv;ExtraFilm upload service;c:\program files\ExtraFilm Designer BE NL\EFUploadSrv.exe [2009-07-09 1716224]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]

R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-31 30192]

R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 135664]

R3 KiesAllShare;SAMSUNG KiesAllShare Service;c:\program files\Samsung\Kies\WiselinkPro\WiselinkPro.exe [x]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]

R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-05-06 23096]

R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [2011-11-22 70536]

R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools\PC Tools Security\pctsAuxs.exe [2011-11-22 402336]

R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]

R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]

R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]

R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]

R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-11-22 35264]

R3 ThreatFire;ThreatFire;c:\program files\PC Tools\PC Tools Security\TFEngine\TFService.exe service [x]

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

S0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\System32\Drivers\pctBTFix.sys [2011-11-22 17848]

S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-14 331880]

S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-10-07 341656]

S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-10-07 660992]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-04 691696]

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-11-22 54328]

S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-11-22 574424]

S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [2011-11-22 253096]

S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\Drivers\PCTSD.sys [2011-11-22 185560]

S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]

S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-25 217088]

S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-06-24 65856]

S2 Response Hardware;Response-hardware;c:\program files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe [2010-08-23 30608]

S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-12-22 29736]

S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-05-25 36640]

S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-05-07 85136]

S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 350720]

S3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-08-23 11152]

S3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-08-23 14224]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2008-03-19 22072]

S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2006-11-17 13976]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - FSUSBEXDISK

*Deregistered* - PCTSDInjDriver32

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

bthsvcs REG_MULTI_SZ BthServ

Akamai REG_MULTI_SZ Akamai

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

ezSharedSvc

.

Inhoud van de 'Gedeelde Taken' map

.

2011-12-27 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-21 07:22]

.

2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40]

.

2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-29 18:40]

.

2011-12-27 c:\windows\Tasks\Recovery DVD Creator-Cindy Cottenjé.job

- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-10-08 09:13]

.

2011-12-27 c:\windows\Tasks\Uitgebreide garantie-Cindy Cottenjé.job

- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-10-08 09:13]

.

.

------- Bijkomende Scan -------

.

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Afbeelding verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Pagina verzenden naar &Bluetooth-apparaat... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

TCP: DhcpNameServer = 195.130.131.5 195.130.130.133

FF - ProfilePath - c:\users\Cindy Cottenjé\AppData\Roaming\Mozilla\Firefox\Profiles\g01db09y.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - prefs.js: network.proxy.type - 0

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2011-12-27 18:21

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover

Windows 6.0.6002 Disk: Hitachi_HTS543216L9A300 rev.FB2OC40C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

.

device: opened successfully

user: MBR read successfully

kernel: MBR read successfully

user != kernel MBR !!!

sectors 312581791 (+0): user != kernel

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]

"ServiceDll"="c:\program files\common files\akamai/netsession_win_b427739.dll"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-4240524916-931938033-4048848888-1000\Software\SecuROM\License information*]

"datasecu"=hex:7d,31,bd,ef,ca,a5,1e,ab,72,34,a0,41,15,5d,16,65,88,78,2a,77,f3,

ae,26,79,4a,74,c1,bf,3c,54,b1,6f,29,67,1c,4e,00,0b,b3,99,cd,c6,ce,9d,93,f6,\

"rkeysecu"=hex:b1,77,54,1c,da,d2,01,20,f4,54,4d,05,27,51,cc,62

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

Voltooingstijd: 2011-12-27 18:38:05

ComboFix-quarantined-files.txt 2011-12-27 17:37

ComboFix2.txt 2011-12-27 16:29

ComboFix3.txt 2011-12-27 13:06

.

Pre-Run: 30.023.753.728 bytes beschikbaar

Post-Run: 29.882.941.440 bytes beschikbaar

.

- - End Of File - - 621E16826DF27EF7926B754C8B835628

Link naar reactie
Delen op andere sites

hier logje terwijl dat scherm met "iphone gewonnen" op staat.

en google doet ook nog altijd raar. Gaat naar reclame sites als ik op een zoekopdracht klik

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 9:55:37, on 31/12/2011

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Windows\System32\mobsync.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: SMART Sync - {8E1233B3-485A-4E51-B77E-9E075A68C588} - C:\Program Files\SMART Technologies\Classroom Teacher\Sync Teacher\SyncIEToolbar.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [Dvd- of cd-deling] "C:\Program Files\Dvd- of cd-deling\ODSAgent.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O8 - Extra context menu item: Afbeelding verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Pagina verzenden naar &Bluetooth-apparaat... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

O23 - Service: Planner voor Automatische LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

O23 - Service: ExtraFilm upload service (EFUploadSrv) - Textalk AB - C:\Program Files\ExtraFilm Designer BE NL\EFUploadSrv.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe

O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: SAMSUNG KiesAllShare Service (KiesAllShare) - Unknown owner - C:\Program Files\Samsung\Kies\WiselinkPro\WiselinkPro.exe (file missing)

O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe

O23 - Service: Response-hardware (Response Hardware) - SMART Technologies - C:\Program Files\SMART Technologies\Classroom Teacher\ResponseHardwareService.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe

O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--

End of file - 7764 bytes

Link naar reactie
Delen op andere sites


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.