Ga naar inhoud

internet loopt vast,


Aanbevolen berichten

ComboFix 12-04-31.02 - HP_Eigenaar 30/04/2012 21:55:27.3.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1023.416 [GMT 2:00]

Gestart vanuit: c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Bureaublad\ComboFix.exe

gebruikte Opdracht switches :: c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Bureaublad\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

FILE ::

"c:\windows\~DF4A3D.tmp"

"c:\windows\~DFE5D9.tmp"

"c:\windows\~DFF864.tmp"

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\4fdb71e325699258d029bc45cda40310

c:\4fdb71e325699258d029bc45cda40310\$shtdwn$.req

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\aspnet.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\clr.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\crt.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\dw.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\netfx_ca.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\netfx_core.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\netfx_other.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\netfx20a_x86.msi

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\prexp.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx20\winforms.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\netfx30a_x86.msi

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\rgb9rast_x86.msi

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wcf.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wcs.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wf.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wf_32.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wic_x86_enu.exe

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wpf_other.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wpf_other_32.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wpf1.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wpf2.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\wpf2_32.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\x86\msxml6.msi

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\xps.msp

c:\4fdb71e325699258d029bc45cda40310\dotnetfx30\xpsepsc-x86-en-us.exe

c:\4fdb71e325699258d029bc45cda40310\dotnetfx35\x86\netfx35_x86.exe

c:\4fdb71e325699258d029bc45cda40310\dotnetfx35setup.exe

c:\4fdb71e325699258d029bc45cda40310\tools\clwireg.exe

c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Local Settings\Application Data\Conduit

c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Local Settings\Application Data\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_8_8_8.xml

C:\f673d44ffb79198f2cd0038b373c29

c:\f673d44ffb79198f2cd0038b373c29\baseline.dat

c:\f673d44ffb79198f2cd0038b373c29\deffactory.dat

c:\f673d44ffb79198f2cd0038b373c29\DeleteTemp.exe

c:\f673d44ffb79198f2cd0038b373c29\dlmgr.dll

c:\f673d44ffb79198f2cd0038b373c29\DW20.EXE

c:\f673d44ffb79198f2cd0038b373c29\DWINTL20.DLL

c:\f673d44ffb79198f2cd0038b373c29\eula.1025.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1028.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1029.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1030.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1031.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1032.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1033.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1035.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1036.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1037.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1038.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1040.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1041.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1042.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1043.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1044.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1045.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1046.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1049.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1053.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.1055.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.2052.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.2070.rtf

c:\f673d44ffb79198f2cd0038b373c29\eula.3082.rtf

c:\f673d44ffb79198f2cd0038b373c29\gencomp.dll

c:\f673d44ffb79198f2cd0038b373c29\HtmlLite.dll

c:\f673d44ffb79198f2cd0038b373c29\locdata.1025.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1028.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1029.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1030.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1031.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1032.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1035.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1036.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1037.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1038.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1040.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1041.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1042.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1043.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1044.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1045.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1046.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1049.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1053.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.1055.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.2052.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.2070.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.3082.ini

c:\f673d44ffb79198f2cd0038b373c29\locdata.ini

c:\f673d44ffb79198f2cd0038b373c29\logo.bmp

c:\f673d44ffb79198f2cd0038b373c29\setup.exe

c:\f673d44ffb79198f2cd0038b373c29\setup.sdb

c:\f673d44ffb79198f2cd0038b373c29\setupres.1025.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1028.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1029.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1030.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1031.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1032.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1035.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1036.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1037.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1038.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1040.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1041.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1042.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1043.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1044.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1045.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1046.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1049.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1053.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.1055.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.2052.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.2070.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.3082.dll

c:\f673d44ffb79198f2cd0038b373c29\setupres.dll

c:\f673d44ffb79198f2cd0038b373c29\SITSetup.dll

c:\f673d44ffb79198f2cd0038b373c29\vs_setup.dll

c:\f673d44ffb79198f2cd0038b373c29\vs_setup.MS_

c:\f673d44ffb79198f2cd0038b373c29\vs_setup.pdi

c:\f673d44ffb79198f2cd0038b373c29\vs70uimgr.dll

c:\f673d44ffb79198f2cd0038b373c29\vsbasereqs.dll

c:\f673d44ffb79198f2cd0038b373c29\vsscenario.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1025.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1028.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1029.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1030.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1031.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1032.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1035.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1036.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1037.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1038.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1040.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1041.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1042.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1043.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1044.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1045.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1046.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1049.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1053.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.1055.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.2052.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.2070.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.3082.dll

c:\f673d44ffb79198f2cd0038b373c29\WapRes.dll

c:\f673d44ffb79198f2cd0038b373c29\WapUI.dll

c:\program files\Conduit

c:\program files\Conduit\Community Alerts\Alert.dll

c:\windows\~DF4A3D.tmp

c:\windows\~DFE5D9.tmp

c:\windows\~DFF864.tmp

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-03-28 to 2012-04-30 ))))))))))))))))))))))))))))))

.

.

2012-04-25 13:45 . 2012-04-25 13:45 -------- d-----w- c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Application Data\Malwarebytes

2012-04-25 13:45 . 2012-04-25 13:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-04-25 13:45 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-04-23 13:44 . 2012-04-23 13:44 -------- d-----w- c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Local Settings\Application Data\Temp

2012-04-15 04:44 . 2012-04-30 19:49 -------- d--h--r- c:\documents and settings\HP_Eigenaar.UW-4B58D8528225\Onlangs geopend

2012-04-13 14:34 . 2012-04-13 14:34 -------- d-----w- c:\program files\Garmin GPS Plugin

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-04-12 03:24 . 2011-12-17 12:58 73728 ----a-w- c:\windows\ALCFDRTM.VER

2012-03-18 19:25 . 2012-03-18 19:25 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-03-13 15:11 . 2012-03-13 15:12 73728 ----a-w- c:\windows\system32\javacpl.cpl

2012-03-13 15:11 . 2012-02-29 16:19 472808 ----a-w- c:\windows\system32\deployJava1.dll

2012-03-07 00:15 . 2012-03-22 09:52 41184 ----a-w- c:\windows\avastSS.scr

2012-03-07 00:15 . 2012-03-22 09:52 201352 ----a-w- c:\windows\system32\aswBoot.exe

2012-03-07 00:03 . 2012-03-22 09:53 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2012-03-07 00:03 . 2012-03-22 09:53 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys

2012-03-07 00:02 . 2012-03-22 09:53 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2012-03-07 00:01 . 2012-03-22 09:53 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2012-03-07 00:01 . 2012-03-22 09:53 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2012-03-07 00:01 . 2012-03-22 09:53 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys

2012-03-07 00:01 . 2012-03-22 09:53 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2012-03-06 23:58 . 2012-03-22 09:53 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2012-03-01 11:00 . 2010-09-07 21:37 43520 ------w- c:\windows\system32\licmgr10.dll

2012-03-01 11:00 . 2010-09-07 21:36 1469440 ------w- c:\windows\system32\inetcpl.cpl

2012-03-01 11:00 . 2004-08-04 11:00 916992 ----a-w- c:\windows\system32\wininet.dll

2012-02-29 14:10 . 2010-09-07 21:39 177664 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 14:10 . 2004-08-04 18:00 148480 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 12:17 . 2010-09-07 21:36 385024 ------w- c:\windows\system32\html.iec

2012-02-23 16:11 . 2012-02-29 15:01 24408 ----a-w- c:\windows\system32\drivers\aswKbd.sys

2012-02-03 09:57 . 2010-09-07 21:39 1860224 ----a-w- c:\windows\system32\win32k.sys

.

.

((((((((((((((((((((((((((((( SnapShot@2012-04-26_13.23.53 )))))))))))))))))))))))))))))))))))))))))

.

+ 2012-04-30 15:18 . 2012-04-30 15:18 16384 c:\windows\Temp\Perflib_Perfdata_5ec.dat

+ 2008-07-25 09:16 . 2005-09-23 06:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp10.dll

- 2005-09-23 06:28 . 2005-09-23 06:28 7680 c:\windows\Microsoft.NET\Framework\sbscmp10.dll

+ 2008-07-29 15:37 . 2008-07-29 15:37 911360 c:\windows\Installer\5aed912.msp

+ 2008-07-29 15:33 . 2008-07-29 15:33 506368 c:\windows\Installer\5aed911.msp

+ 2008-07-29 15:35 . 2008-07-29 15:35 553472 c:\windows\Installer\5aed90f.msp

+ 2008-07-29 15:37 . 2008-07-29 15:37 911360 c:\windows\Installer\3cc684f.msp

+ 2008-07-29 15:33 . 2008-07-29 15:33 506368 c:\windows\Installer\3cc684e.msp

+ 2008-07-29 15:35 . 2008-07-29 15:35 553472 c:\windows\Installer\3cc684c.msp

+ 2008-07-29 15:37 . 2008-07-29 15:37 911360 c:\windows\Installer\1f17536.msp

+ 2008-07-29 15:33 . 2008-07-29 15:33 506368 c:\windows\Installer\1f17535.msp

+ 2008-07-29 15:35 . 2008-07-29 15:35 553472 c:\windows\Installer\1f17533.msp

+ 2008-07-29 15:31 . 2008-07-29 15:31 6083072 c:\windows\Installer\5aed913.msp

+ 2008-07-29 15:43 . 2008-07-29 15:43 1013248 c:\windows\Installer\5aed910.msp

+ 2008-07-29 15:39 . 2008-07-29 15:39 3403264 c:\windows\Installer\5aed90e.msp

+ 2008-07-29 15:41 . 2008-07-29 15:41 6487040 c:\windows\Installer\5aed90d.msp

+ 2008-07-29 15:29 . 2008-07-29 15:29 2926080 c:\windows\Installer\5aed90c.msp

+ 2008-07-29 15:45 . 2008-07-29 15:45 2543616 c:\windows\Installer\5aed90b.msp

+ 2008-07-29 15:31 . 2008-07-29 15:31 6083072 c:\windows\Installer\3cc6850.msp

+ 2008-07-29 15:43 . 2008-07-29 15:43 1013248 c:\windows\Installer\3cc684d.msp

+ 2008-07-29 15:39 . 2008-07-29 15:39 3403264 c:\windows\Installer\3cc684b.msp

+ 2008-07-29 15:41 . 2008-07-29 15:41 6487040 c:\windows\Installer\3cc684a.msp

+ 2008-07-29 15:29 . 2008-07-29 15:29 2926080 c:\windows\Installer\3cc6849.msp

+ 2008-07-29 15:45 . 2008-07-29 15:45 2543616 c:\windows\Installer\3cc6848.msp

+ 2008-07-29 15:31 . 2008-07-29 15:31 6083072 c:\windows\Installer\1f17537.msp

+ 2008-07-29 15:43 . 2008-07-29 15:43 1013248 c:\windows\Installer\1f17534.msp

+ 2008-07-29 15:39 . 2008-07-29 15:39 3403264 c:\windows\Installer\1f17532.msp

+ 2008-07-29 15:41 . 2008-07-29 15:41 6487040 c:\windows\Installer\1f17531.msp

+ 2008-07-29 15:29 . 2008-07-29 15:29 2926080 c:\windows\Installer\1f17530.msp

+ 2008-07-29 15:45 . 2008-07-29 15:45 2543616 c:\windows\Installer\1f1752f.msp

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]

"Snelkoppeling naar eigenschappenvenster voor High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-08-02 7110656]

"nwiz"="nwiz.exe" [2005-08-02 1519616]

"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]

"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]

"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2005-06-10 61440]

"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]

"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]

"Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]

"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-05-04 278528]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]

"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]

"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-10-11 98304]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

.

c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=

"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=

"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

.

R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [29/02/2012 17:01 24408]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22/03/2012 11:53 612184]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22/03/2012 11:53 337880]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22/03/2012 11:53 20696]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [25/04/2012 15:45 654408]

R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/10/2005 17:14 2786176]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [25/04/2012 15:45 22344]

S2 gupdate;Google Update-service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/09/2010 15:22 136176]

S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usbxp.sys [30/04/2004 15:35 24832]

S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/09/2010 15:22 136176]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

HPService REG_MULTI_SZ HPSLPSVC

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Inhoud van de 'Gedeelde Taken' map

.

2012-04-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd053ce728536e.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 13:22]

.

2012-04-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cd053ce7749eae.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 13:22]

.

2012-04-30 c:\windows\Tasks\User_Feed_Synchronization-{0B2E3EB1-E7B8-43E9-91E4-F5DE6EFABA99}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.be/

IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

IE: Gelijkwaardige pagina's - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

IE: Koppelingspagina's - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html

IE: Opgeslagen momentopname van de pagina - c:\program files\Google\GoogleToolbar1.dll/cmcache.html

Trusted Zone: dexia.be\www

TCP: DhcpNameServer = 195.130.131.3 195.130.130.131

DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-04-30 22:06

Windows 5.1.2600 Service Pack 3 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\Enum\¬ ©**\DirectSound\Device Presence]

"VxD"=dword:00000001

"WDM"=dword:00000001

.

Voltooingstijd: 2012-04-30 22:09:01

ComboFix-quarantined-files.txt 2012-04-30 20:08

ComboFix2.txt 2012-04-26 13:26

ComboFix3.txt 2012-03-22 16:05

.

Pre-Run: 125.531.934.720 bytes beschikbaar

Post-Run: 125.713.403.904 bytes beschikbaar

.

- - End Of File - - CA43688BB3CFCD914C91B3898CB98D74

Link naar reactie
Delen op andere sites

Dan kunnen we beginnen opruimen.

Verwijder Combofix: Start -> Uitvoeren en typ: ComboFix /Uninstall (met spatie voor de /)

Dit zal Combofix verwijderen + gerelateerde mappen en bestanden, herstelt de klokinstellingen opnieuw, verbergt de bestandsextensies, gaat verborgen bestanden en systeembestanden terug verbergen en maakt een nieuw herstelpunt.

Indien aanwezig mag je de map C:\Qoobox manueel verwijderen.

Download CCleaner. (Als je het nog niet hebt)

Let op bij de installatie.

Haal beide vinkjes weg bij de vraag over de Chrome browser.

Installeer het en start CCleaner op.

Klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Schoonmaken'. Bevestigen met JA of OK

Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”.

Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft.

Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, lees dan deze handleiding.

Het is aangewezen om de bestaande herstelpunten te verwijderen (daar kunnen besmette herstelpunten tussen zitten die je zou kunnen terugzetten) door systeemherstel tijdelijk uit te schakelen.

Doe dit via Configuratiescherm -> Prestaties en onderhoud -> Systeem -> tab Systeemherstel

Vink het vakje aan bij systeemherstel en klik OK.

Herstart de pc.

Ga opnieuw naar Configuratiescherm -> Prestaties en onderhoud -> Systeem -> tab Systeemherstel

Vink het vakje uit bij systeemherstel en klik OK.

Dan maak je een nieuw herstelpunt.

Ga naar Start - help en ondersteuning, bij kies een taak klik je op Wijzigingen ongedaan maken met systeemherstel.

Selecteer herstelpunt aanmaken en klik op volgende.

Geef een beschrijving voor het herstelpunt en klik op aanmaken.

Je krijgt dan de melding dat het herstelpunt is aangemaakt en dan kan je alle vensters sluiten.

Wat betreft de slaapstand; ik vind dit een overbodige functie en ik schakel die dan ook uit.

Als je toch de slaapstand wil blijven gebruiken, moet je eens kijken bij de netwerkadapters.

De vermelding dit apparaat mag de pc uit slaapstand halen moet je uitvinken

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.