Ga naar inhoud

Ontbrekende vermelding: run taakbalk valt weg.....


Aanbevolen berichten

Gast jeroen_daniels
Geplaatst:

Na het opstarten van mun laptop krijg ik de volgende foutmelding: Ontbrekende vermelding: run

C:\Users\Jeroen\Appdata\local\temp\tiyqmumw.dll

Verder kan ik ook geen toegang krijgen tot mijn bestanden en dergelijke, want het scherm verdwijnt steeds en, dan ben ik weer terug bij het bureaublad. Daarnaast valt mijn taakbalk weg als ik op inernet zit en kan ik verder ook niks meer, behalve internet explorer. Wie kan mij helpen?

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:52:12, on 13-3-2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16609)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\ASUS\ATK Media\DMedia.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Infineon\Security Platform Software\PSDrt.exe

C:\Program Files\Infineon\Security Platform Software\SpTna.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\explorer.exe

c:\Users\Jeroen\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ASUSTeK Computer

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE

O4 - HKLM\..\Run: [iFXSPMGT] C:\Windows\system32\IFXSPMGT.exe /NotifyLogon

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [1c1a6320] rundll32.exe "C:\Users\Jeroen\AppData\Local\Temp\macfuckv.dll",b

O4 - HKCU\..\Run: [bM1f2950bc] Rundll32.exe "C:\Users\Jeroen\AppData\Local\Temp\ufymhdym.dll",s

O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Users\Jeroen\AppData\Local\Temp\{BA8AD2D9-5003-4B7D-B5C1-4D8150063C72}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe

O4 - Startup: RollerCoaster Tycoon 3_ Wild Registration.lnk = C:\Users\Jeroen\AppData\Local\Temp\{7392C5E8-1423-4623-B269-01076CA2137A}\{45653847-497F-47BB-A878-46FBDE34A3E0}\ATR1.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: MultiFrame.lnk = ?

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\IFXSPMGT.exe

O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\IFXTCS.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--

End of file - 9641 bytes

Geplaatst:

Download Combofix.exe en zet het op je Bureaublad.

Start Hijackthis op en kies voor 'Do a system scan only'. Selecteer alleen de items hieronder genoemd:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [iFXSPMGT] C:\Windows\system32\IFXSPMGT.exe /NotifyLogon

O4 - HKCU\..\Run: [1c1a6320] rundll32.exe "C:\Users\Jeroen\AppData\Local\Temp\macfuckv.dll", b

O4 - HKCU\..\Run: [bM1f2950bc] Rundll32.exe "C:\Users\Jeroen\AppData\Local\Temp\ufymhdym.dll", s

O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Users\Jeroen\AppData\Local\Temp\{BA8AD2D9-5003-4B7D-B5C1-4D8150063C72}\{907B4 640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe

Klik op 'Fix checked' om de items te verwijderen.

Dubbelklik op Combofix.exe en volg de instructies, aanvaard de disclaimer door y te typen. Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

NOTA: Indien je virusscanner reageert met een melding van een scriptuitvoering, moet je dit toestaan.

Hang daarna een nieuw log van HJT en Combofix aan je volgende bericht.

Gast jeroen_daniels
Geplaatst:

ComboFix 08-03-13.2 - Jeroen 2008-03-13 21:31:25.1 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1043.18.286 [GMT 1:00]

Gestart vanuit: C:\Users\Jeroen\ComboFix.exe

* Nieuw herstelpunt werd aangemaakt

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Users\Jeroen\AppData\Roaming\macromedia\Flash Player\#SharedObjects\NL82AG26\Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More

C:\Users\Jeroen\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More

C:\Users\Jeroen\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol

C:\Windows\system32\drivers\RevHDD.exe

.

(((((((((((((((((((( Bestanden Gemaakt van 2008-02-13 to 2008-03-13 ))))))))))))))))))))))))))))))

.

Geen nieuwe bestanden aangemaakt in deze periode

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-13 20:29 1,581,314 ----a-w C:\Users\Jeroen\ComboFix.exe

2008-03-13 19:45 50,688 ----a-w C:\Users\Jeroen\ATF-Cleaner.exe

2008-03-13 19:43 13,072 ----a-w C:\Users\Jeroen\AppData\Roaming\nvModes.dat

2008-03-13 19:43 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Skype

2008-03-13 19:41 45,056 ----a-w C:\Windows\System32\acovcnt.exe

2008-03-13 19:28 401,720 ----a-w C:\Users\Jeroen\HiJackThis.exe

2008-03-12 20:17 --------- d-----w C:\Program Files\Windows Mail

2008-03-11 15:01 --------- d-----w C:\Program Files\Norton Internet Security

2008-03-11 15:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-03-09 10:23 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Azureus

2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat

2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf

2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys

2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys

2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys

2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys

2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys

2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys

2008-03-05 21:05 --------- d-----w C:\Program Files\Belastingdienst

2008-03-05 20:27 --------- d-----w C:\Program Files\Everest Poker

2008-02-29 11:41 --------- d-----w C:\ProgramData\McPoker

2008-02-25 17:05 --------- d-----w C:\ProgramData\Symantec

2008-02-17 15:50 --------- d-----w C:\Users\Jeroen\AppData\Roaming\LimeWire

2008-02-16 14:15 --------- d-----w C:\ProgramData\DVD Shrink

2008-02-13 21:47 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-02-13 21:47 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-02-13 21:42 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-02-13 21:42 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-02-13 21:42 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-02-13 21:42 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-02-13 21:42 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-02-13 21:42 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-02-13 21:42 216,632 ----a-w C:\Windows\system32\drivers\netio.sys

2008-02-13 21:42 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-02-13 21:42 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys

2008-02-13 21:42 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-02-13 21:42 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-02-13 21:42 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-02-13 21:41 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll

2008-02-13 21:41 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-02-13 21:41 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll

2008-02-13 21:41 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-02-13 21:41 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-02-13 21:41 1,686,528 ----a-w C:\Windows\System32\gameux.dll

2008-02-13 21:38 824,832 ----a-w C:\Windows\System32\wininet.dll

2008-02-13 21:38 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-02-13 21:37 56,320 ----a-w C:\Windows\System32\iesetup.dll

2008-02-13 21:37 26,624 ----a-w C:\Windows\System32\ieUnatt.exe

2008-02-13 09:26 --------- d-----w C:\ProgramData\Microsoft Help

2008-02-13 09:26 --------- d-----w C:\Program Files\Microsoft Works

2008-02-13 09:26 --------- d-----w C:\Program Files\Google

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\Skype

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\LightScribe

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\Autodesk Shared

2008-02-13 09:26 --------- d-----w C:\Program Files\Anno 1701

2008-02-11 17:13 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Autodesk

2008-02-11 17:13 --------- d-----w C:\ProgramData\Autodesk

2008-02-11 16:55 --------- d-----w C:\Program Files\QuickTime

2008-02-11 16:54 --------- d-----w C:\ProgramData\Apple Computer

2008-01-29 10:53 --------- d-----w C:\Users\Jeroen\AppData\Roaming\VoipBuster

2008-01-15 08:54 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat

2008-01-15 04:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf

2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll

2008-01-08 22:55 11,776 ----a-w C:\Windows\System32\sbunattend.exe

2007-08-30 12:47 174 --sha-w C:\Program Files\desktop.ini

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 23:55 1232896]

"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-05-21 14:42 171448]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]

"VoipBuster"="C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe" [2008-01-29 11:51 8811824]

"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-31 16:40 22879528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-11 11:39 1006264]

"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 12:43 729088]

"NvSvc"="C:\Windows\system32\nvsvc.dll" [2006-12-10 07:46 90191]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2006-12-10 07:46 7766016]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2006-12-10 07:46 81920]

"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 06:36 4186112 C:\Windows\RtHDVCpl.exe]

"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 17:27 61440]

"IFXSPMGT"="C:\Windows\system32\IFXSPMGT.exe" [2006-11-13 07:23 661024]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 06:27 815104]

"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-01-11 02:36 778240]

"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]

"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [ ]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 10:29 115816]

"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 20:01 71216]

"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 15:21 54832]

"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]

"RevHDD"="C:\WINDOWS\SYSTEM\RevHDD.exe" [ ]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 13:44:06 29696]

MultiFrame.lnk - C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe [2007-02-15 22:27:36 991600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{32CEE89E-314F-41CC-BE9D-AC66E10FFDB2}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|

"{6A13C7C5-B308-45F5-A836-EEBDBFCD75E6}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{0B13BB70-B4F3-40B6-9A51-50F3236BE59B}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{BEBC50CC-0C08-4736-9913-BFFFEC058FB1}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"TCP Query User{B86C3EB2-0CFC-4D62-B1B3-1EBECB0D8FFE}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus

"UDP Query User{5806339B-7C5A-42D0-A262-2C5EAF8B4F31}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus

"TCP Query User{AB9D721A-571A-46D2-8839-A195C87E7C3B}C:\program files\microsoft games\halo\halo.exe"= UDP:C:\program files\microsoft games\halo\halo.exe:Halo|Desc=Halo

"UDP Query User{D10DCC10-65B0-4BDA-AB48-CC81CF820E9F}C:\program files\microsoft games\halo\halo.exe"= TCP:C:\program files\microsoft games\halo\halo.exe:Halo|Desc=Halo

"{786F6649-3A98-4879-B07A-84388BE7381D}"= UDP:C:\Program Files\McAfee\MWL\MwlSvc.exe:McAfee Wireless Network Security

"{5A4BE456-1149-4960-81C2-6BE30BF9B7CF}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{65BF3D10-424E-4923-9197-209769AF52D3}"= UDP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{D2D2D35D-5DFF-4982-9427-9C7F5D56A3AC}"= TCP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{DDA53E69-DAB5-4A5E-A25B-AE98E5EDD2FA}"= C:\Program Files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD|Desc=CyberLink PowerDVD

"{1A4449CC-2A82-4563-99A7-E31C129F4850}"= UDP:C:\Program Files\Anno 1701\Anno1701.exe:Anno 1701

"{4F309925-69A8-4932-9D65-A14027BCD3EE}"= TCP:C:\Program Files\Anno 1701\Anno1701.exe:Anno 1701

"{F580ED2B-B91E-4713-B36D-EFC3C3AF64B7}"= UDP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{672AC098-695D-4BD8-8441-D35B1594F32E}"= TCP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080312.001\IDSvix86.sys [2008-02-13 17:18]

R1 PersonalSecureDrive;PersonalSecureDrive;C:\Windows\system32\drivers\psd.sys [2006-10-12 13:37]

R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 15:51]

R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\Windows\System32\StkCSrv.exe [2006-12-10 17:31]

R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2006-12-21 19:36]

R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 13:39]

R3 TPM;TPM;C:\Windows\system32\drivers\tpm.sys [2006-11-02 10:50]

R3 WCPU;WCPU;C:\Program Files\P4G\WCPU.sys [2007-01-03 00:37]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

*Newly Created Service* - COMHOST

.

Inhoud van de 'Gedeelde Taken' map

"2008-03-03 19:00:20 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Jeroen.job"

- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-13 21:35:03

Windows 6.0.6000 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

Voltooingstijd: 2008-03-13 21:35:50

ComboFix-quarantined-files.txt 2008-03-13 20:35:48

.

2008-03-12 18:17:51 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:37:05, on 13-3-2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16609)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\ASUS\ATK Media\DMedia.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe

C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe

C:\Windows\ehome\ehmsas.exe

C:\Program Files\Infineon\Security Platform Software\PSDrt.exe

C:\Program Files\Infineon\Security Platform Software\SpTna.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

c:\Users\Jeroen\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ASUSTeK Computer

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE

O4 - HKLM\..\Run: [iFXSPMGT] C:\Windows\system32\IFXSPMGT.exe /NotifyLogon

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Startup: RollerCoaster Tycoon 3_ Wild Registration.lnk = C:\Users\Jeroen\AppData\Local\Temp\{7392C5E8-1423-4623-B269-01076CA2137A}\{45653847-497F-47BB-A878-46FBDE34A3E0}\ATR1.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: MultiFrame.lnk = ?

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\IFXSPMGT.exe

O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\IFXTCS.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--

End of file - 8991 bytes

Geplaatst:

Ziet er al een stuk beter uit. Maar nog even dit : start Hijackthis op en kies voor 'Do a system scan only'. Selecteer alleen de items hieronder genoemd:

O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe

Klik op 'Fix checked' om de items te verwijderen.

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

File::

C:\WINDOWS\SYSTEM\RevHDD.exe

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]

"RevHDD"="C:\WINDOWS\SYSTEM\RevHDD.exe" [ ]

Sla dit bestand op je bureaublad op als CFScript.txt.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

En wil je dit bestand eens scannen bij Jotti : C:\Windows\System32\acovcnt.exe en ons het resultaat meedelen ?

Vraagje : heb je deze twee programma’s bewust gedownload en gebruik je die ?

C:\Program Files\Everest Poker

C:\ProgramData\McPoker

Hang tot slot een nieuw log van HJT en van Combofix in een volgend bericht en weet ons even te melden of je nog foutmeldingen krijgt of andere problemen hebt.

Gast jeroen_daniels
Geplaatst:

Op het moment krijg ik geen foutmelding meer en heb ik gewoon toegang tot mijn bestanden.

Verder heb ik het bestand wat je vroeg gescand. Alle scanners geven aan dat ze niks vinden. Is het nu opgelost of moet ik nog meer handelingen verrichten?

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:42:28, on 14-3-2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16609)

Boot mode: Normal

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\ASUS\ATK Media\DMedia.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Windows\ehome\ehtray.exe

C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Infineon\Security Platform Software\PSDrt.exe

C:\Program Files\Infineon\Security Platform Software\SpTna.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe

C:\Windows\Explorer.exe

c:\Users\Jeroen\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ASUSTeK Computer

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE

O4 - HKLM\..\Run: [iFXSPMGT] C:\Windows\system32\IFXSPMGT.exe /NotifyLogon

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Startup: RollerCoaster Tycoon 3_ Wild Registration.lnk = C:\Users\Jeroen\AppData\Local\Temp\{7392C5E8-1423-4623-B269-01076CA2137A}\{45653847-497F-47BB-A878-46FBDE34A3E0}\ATR1.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: MultiFrame.lnk = ?

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\IFXSPMGT.exe

O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\IFXTCS.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe

O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--

End of file - 8803 bytes

ComboFix 08-03-13.2 - Jeroen 2008-03-14 14:37:28.2 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1043.18.249 [GMT 1:00]

Gestart vanuit: C:\Users\Jeroen\Desktop\ComboFix.exe

Command switches used :: C:\Users\Jeroen\Desktop\CFScript.txt

* Nieuw herstelpunt werd aangemaakt

FILE ::

C:\WINDOWS\SYSTEM\RevHDD.exe

.

(((((((((((((((((((( Bestanden Gemaakt van 2008-02-14 to 2008-03-14 ))))))))))))))))))))))))))))))

.

Geen nieuwe bestanden aangemaakt in deze periode

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-14 13:22 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Skype

2008-03-14 13:21 45,056 ----a-w C:\Windows\System32\acovcnt.exe

2008-03-13 19:45 50,688 ----a-w C:\Users\Jeroen\ATF-Cleaner.exe

2008-03-13 19:43 13,072 ----a-w C:\Users\Jeroen\AppData\Roaming\nvModes.dat

2008-03-13 19:28 401,720 ----a-w C:\Users\Jeroen\HiJackThis.exe

2008-03-12 20:17 --------- d-----w C:\Program Files\Windows Mail

2008-03-11 15:01 --------- d-----w C:\Program Files\Norton Internet Security

2008-03-11 15:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-03-09 10:23 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Azureus

2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat

2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf

2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys

2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys

2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys

2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys

2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys

2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys

2008-03-05 21:05 --------- d-----w C:\Program Files\Belastingdienst

2008-03-05 20:27 --------- d-----w C:\Program Files\Everest Poker

2008-02-29 11:41 --------- d-----w C:\ProgramData\McPoker

2008-02-25 17:05 --------- d-----w C:\ProgramData\Symantec

2008-02-17 15:50 --------- d-----w C:\Users\Jeroen\AppData\Roaming\LimeWire

2008-02-16 14:15 --------- d-----w C:\ProgramData\DVD Shrink

2008-02-13 21:47 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-02-13 21:47 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-02-13 21:42 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-02-13 21:42 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-02-13 21:42 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-02-13 21:42 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-02-13 21:42 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-02-13 21:42 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-02-13 21:42 216,632 ----a-w C:\Windows\system32\drivers\netio.sys

2008-02-13 21:42 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-02-13 21:42 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys

2008-02-13 21:42 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-02-13 21:42 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-02-13 21:42 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-02-13 21:41 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll

2008-02-13 21:41 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-02-13 21:41 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll

2008-02-13 21:41 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-02-13 21:41 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-02-13 21:41 1,686,528 ----a-w C:\Windows\System32\gameux.dll

2008-02-13 21:38 824,832 ----a-w C:\Windows\System32\wininet.dll

2008-02-13 21:38 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-02-13 21:37 56,320 ----a-w C:\Windows\System32\iesetup.dll

2008-02-13 21:37 26,624 ----a-w C:\Windows\System32\ieUnatt.exe

2008-02-13 09:26 --------- d-----w C:\ProgramData\Microsoft Help

2008-02-13 09:26 --------- d-----w C:\Program Files\Microsoft Works

2008-02-13 09:26 --------- d-----w C:\Program Files\Google

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\Skype

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\LightScribe

2008-02-13 09:26 --------- d-----w C:\Program Files\Common Files\Autodesk Shared

2008-02-13 09:26 --------- d-----w C:\Program Files\Anno 1701

2008-02-11 17:13 --------- d-----w C:\Users\Jeroen\AppData\Roaming\Autodesk

2008-02-11 17:13 --------- d-----w C:\ProgramData\Autodesk

2008-02-11 16:55 --------- d-----w C:\Program Files\QuickTime

2008-02-11 16:54 --------- d-----w C:\ProgramData\Apple Computer

2008-01-29 10:53 --------- d-----w C:\Users\Jeroen\AppData\Roaming\VoipBuster

2008-01-15 08:54 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat

2008-01-15 04:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf

2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll

2008-01-08 22:55 11,776 ----a-w C:\Windows\System32\sbunattend.exe

2007-08-30 12:47 174 --sha-w C:\Program Files\desktop.ini

.

((((((((((((((((((((((((((((( snapshot@2008-03-13_21.35.25,39 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-03-13 19:41:00 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2008-03-14 13:19:40 67,584 --s-a-w C:\Windows\bootstat.dat

- 2008-03-13 19:43:35 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-03-14 13:22:03 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

- 2008-03-13 20:34:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-03-14 13:41:10 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-03-14 13:41:10 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-03-13 19:46:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-03-14 13:35:26 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-03-13 19:46:48 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-03-14 13:35:26 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-03-13 19:46:48 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-03-14 13:35:26 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-03-13 19:43:37 12,356 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3098023568-2803115584-4071668146-1000_UserData.bin

+ 2008-03-14 13:22:58 12,364 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3098023568-2803115584-4071668146-1000_UserData.bin

- 2008-03-13 19:43:36 68,158 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-03-14 13:22:58 68,190 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-03-13 19:43:32 51,160 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-03-14 13:22:56 51,160 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 23:55 1232896]

"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-05-21 14:42 171448]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]

"VoipBuster"="C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe" [2008-01-29 11:51 8811824]

"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-31 16:40 22879528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-11 11:39 1006264]

"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 12:43 729088]

"NvSvc"="C:\Windows\system32\nvsvc.dll" [2006-12-10 07:46 90191]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2006-12-10 07:46 7766016]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2006-12-10 07:46 81920]

"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 06:36 4186112 C:\Windows\RtHDVCpl.exe]

"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 17:27 61440]

"IFXSPMGT"="C:\Windows\system32\IFXSPMGT.exe" [2006-11-13 07:23 661024]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 06:27 815104]

"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-01-11 02:36 778240]

"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]

"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [ ]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 10:29 115816]

"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 20:01 71216]

"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 15:21 54832]

"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]

"RevHDD"="C:\WINDOWS\SYSTEM\RevHDD.exe" [ ]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 13:44:06 29696]

MultiFrame.lnk - C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe [2007-02-15 22:27:36 991600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{32CEE89E-314F-41CC-BE9D-AC66E10FFDB2}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|

"{6A13C7C5-B308-45F5-A836-EEBDBFCD75E6}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

"{0B13BB70-B4F3-40B6-9A51-50F3236BE59B}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"{BEBC50CC-0C08-4736-9913-BFFFEC058FB1}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

"TCP Query User{B86C3EB2-0CFC-4D62-B1B3-1EBECB0D8FFE}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus

"UDP Query User{5806339B-7C5A-42D0-A262-2C5EAF8B4F31}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus

"TCP Query User{AB9D721A-571A-46D2-8839-A195C87E7C3B}C:\program files\microsoft games\halo\halo.exe"= UDP:C:\program files\microsoft games\halo\halo.exe:Halo|Desc=Halo

"UDP Query User{D10DCC10-65B0-4BDA-AB48-CC81CF820E9F}C:\program files\microsoft games\halo\halo.exe"= TCP:C:\program files\microsoft games\halo\halo.exe:Halo|Desc=Halo

"{786F6649-3A98-4879-B07A-84388BE7381D}"= UDP:C:\Program Files\McAfee\MWL\MwlSvc.exe:McAfee Wireless Network Security

"{5A4BE456-1149-4960-81C2-6BE30BF9B7CF}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent

"{65BF3D10-424E-4923-9197-209769AF52D3}"= UDP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{D2D2D35D-5DFF-4982-9427-9C7F5D56A3AC}"= TCP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{DDA53E69-DAB5-4A5E-A25B-AE98E5EDD2FA}"= C:\Program Files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD|Desc=CyberLink PowerDVD

"{1A4449CC-2A82-4563-99A7-E31C129F4850}"= UDP:C:\Program Files\Anno 1701\Anno1701.exe:Anno 1701

"{4F309925-69A8-4932-9D65-A14027BCD3EE}"= TCP:C:\Program Files\Anno 1701\Anno1701.exe:Anno 1701

"{F580ED2B-B91E-4713-B36D-EFC3C3AF64B7}"= UDP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

"{672AC098-695D-4BD8-8441-D35B1594F32E}"= TCP:C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe:VoipBuster

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080312.001\IDSvix86.sys [2008-02-13 17:18]

R1 PersonalSecureDrive;PersonalSecureDrive;C:\Windows\system32\drivers\psd.sys [2006-10-12 13:37]

R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 15:51]

R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\Windows\System32\StkCSrv.exe [2006-12-10 17:31]

R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2006-12-21 19:36]

R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 13:39]

R3 TPM;TPM;C:\Windows\system32\drivers\tpm.sys [2006-11-02 10:50]

R3 WCPU;WCPU;C:\Program Files\P4G\WCPU.sys [2007-01-03 00:37]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

*Newly Created Service* - COMHOST

.

Inhoud van de 'Gedeelde Taken' map

"2008-03-03 19:00:20 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Jeroen.job"

- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-14 14:41:12

Windows 6.0.6000 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond

verborgen bestanden: 0

**************************************************************************

.

Voltooingstijd: 2008-03-14 14:42:00

ComboFix-quarantined-files.txt 2008-03-14 13:41:56

ComboFix2.txt 2008-03-13 20:35:51

.

2008-03-12 18:17:51 --- E O F ---

Gast jeroen_daniels
Geplaatst:

owja en die twee programmas heb ik bewust gedownload. Eentje heb ik als het goed is al weer verwijderd van de pc. Dat is Mcpoker......

Geplaatst:

Dat ziet er goed uit en vermits je geen problemen meer hebt lijkt dit ook te kloppen in de praktijk. Dan gaan we nog even de gebruikte programma's opkuisen, je PC cleanen en de oude herstelpunten verwijderen ... en dan kunnen de boeken hier dicht.

Verwijderen Combofix: Start -> Uitvoeren en typ: combofix /u

Combofix wordt verwijderd en een nieuw systeemherstelpunt wordt aangemaakt.

Download CCleaner.

Installeer het en start het op. Klik in de linkse kolom op “Opties”. Selecteer het tabblad ‘Geavanceerd’ en haal het vinkje weg voor “Verwijder alleen tijdelijke bestanden in de Windows systeemmap die ouder zijn dan 48 uur” en sluit hierna het programma.

Start CCleaner op en klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Opschonen'. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scannen voor fouten’. Als er fouten gevonden worden klik je op ”alle fouten herstellen” en ”OK”. Sluit hierna CCleaner terug af.

Het is aangewezen om de bestaande herstelpunten te verwijderen (daar zitten besmette herstelpunten tussen die je eventueel zou kunnen terugzetten) door systeemherstel tijdelijk uit te schakelen.

- Ga naar Start/Alle programma's/Bureau-accessoires/Systeemwerkset/Systeemherstel.

- Klik in de linkerhelft van het venster op "Instellingen van systeemherstel".

- Zet een vinkje voor "Systeemherstel uitschakelen".

- Klik "Toepassen".

- Windows vraagt of je dat zeker weet.

- Klik "Ja".

- Klik "OK".

- Start de pc opnieuw op.

- Ga weer naar Start/Alle programma's/Bureau-accessoires/Systeemwerkset/Systeemherstel.

- Je krijgt de melding: "Systeemherstel is uitgeschakeld. Wilt u systeemherstel nu inschakelen?"

- Klik "Ja".

- Verwijder het vinkje voor "Systeemherstel uitschakelen".

- Klik "Toepassen".

- Klik "OK".

- Start de pc opnieuw op

- Er is nu een nieuw herstelpunt aangemaakt.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.