Ga naar inhoud

Sabam virus


Aanbevolen berichten

ComboFix 12-05-24.02 - Bobke 24/05/2012 18:02:04.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3062.2134 [GMT 2:00]

Gestart vanuit: c:\users\Bobke\Downloads\ComboFix.exe

AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}

SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Astrid\Verkiezingen - Buitenland .doc

c:\users\Bobke\AppData\Roaming\Ebyda

c:\users\Bobke\AppData\Roaming\Ebyda\cyoc.exe

c:\windows\$NtUninstallKB28722$\2850513296

c:\windows\$NtUninstallKB28722$\4195191359\@

c:\windows\$NtUninstallKB28722$\4195191359\cfg.ini

c:\windows\$NtUninstallKB28722$\4195191359\Desktop.ini

c:\windows\$NtUninstallKB28722$\4195191359\L\qnbwvoto

c:\windows\$NtUninstallKB28722$\4195191359\twl.dll

c:\windows\$NtUninstallKB28722$\4195191359\U\00000001.@

c:\windows\$NtUninstallKB28722$\4195191359\U\00000002.@

c:\windows\$NtUninstallKB28722$\4195191359\U\00000004.@

c:\windows\$NtUninstallKB28722$\4195191359\U\80000000.@

c:\windows\$NtUninstallKB28722$\4195191359\U\80000004.@

c:\windows\$NtUninstallKB28722$\4195191359\U\80000032.@

c:\windows\$NtUninstallKB28722$\4195191359\version

c:\windows\system32\dds_trash_log.cmd

c:\windows\system32\DLH5X.dll

c:\windows\system32\muzapp.exe

c:\windows\system32\sbcssvc.dll

c:\windows\system32\smapint.dll

c:\windows\system32\system32

c:\windows\system32\system32\3DAudio.ax

c:\windows\system32\system32\avrt.dll

c:\windows\system32\system32\cis-2.4.dll

c:\windows\system32\system32\issacapi_bs-2.3.dll

c:\windows\system32\system32\issacapi_pe-2.3.dll

c:\windows\system32\system32\issacapi_se-2.3.dll

c:\windows\system32\system32\MACXMLProto.dll

c:\windows\system32\system32\MaDRM.dll

c:\windows\system32\system32\MaJGUILib.dll

c:\windows\system32\system32\MAMACExtract.dll

c:\windows\system32\system32\MASetupCleaner.exe

c:\windows\system32\system32\MaXMLProto.dll

c:\windows\system32\system32\mfplat.dll

c:\windows\system32\system32\MK_Lyric.dll

c:\windows\system32\system32\MSCLib.dll

c:\windows\system32\system32\MSFLib.dll

c:\windows\system32\system32\MSLUR71.dll

c:\windows\system32\system32\msvcp60.dll

c:\windows\system32\system32\MTTELECHIP.dll

c:\windows\system32\system32\MTXSYNCICON.dll

c:\windows\system32\system32\muzaf1.dll

c:\windows\system32\system32\muzapp.dll

c:\windows\system32\system32\muzapp.exe

c:\windows\system32\system32\muzdecode.ax

c:\windows\system32\system32\muzeffect.ax

c:\windows\system32\system32\muzmp4sp.ax

c:\windows\system32\system32\muzmpgsp.ax

c:\windows\system32\system32\muzoggsp.ax

c:\windows\system32\system32\muzwmts.dll

c:\windows\system32\system32\psapi.dll

c:\windows\$NtUninstallKB28722$ . . . . konden niet verwijderd worden

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_framework

-------\Service_hcwPP2

-------\Service_UBHelper

-------\Service_VC4CB104

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-04-24 to 2012-05-24 ))))))))))))))))))))))))))))))

.

.

2012-05-24 16:17 . 2012-05-24 16:17 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-05-24 16:17 . 2012-05-24 16:17 -------- d-----w- c:\users\Astrid\AppData\Local\temp

2012-05-24 16:17 . 2012-05-24 16:27 -------- d-----w- c:\users\Bobke\AppData\Local\temp

2012-05-24 15:33 . 2012-05-24 15:33 -------- d-----w- c:\users\Bobke\AppData\Roaming\Vogeyg

2012-05-24 15:33 . 2012-05-24 15:33 -------- d-----w- c:\users\Bobke\AppData\Roaming\Omdyec

2012-05-22 16:51 . 2012-05-22 16:51 -------- d-----w- c:\users\Astrid\AppData\Roaming\Malwarebytes

2012-05-22 16:51 . 2012-05-22 16:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-05-22 16:51 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-05-18 19:23 . 2012-05-22 17:32 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0

2012-05-15 16:06 . 2012-05-15 16:06 -------- d-----w- c:\windows\Sun

2012-05-05 14:06 . 2012-05-05 14:06 -------- d-----w- C:\found.000

2012-04-30 16:33 . 2012-05-05 13:23 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-05 13:23 . 2011-06-30 11:55 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-04-19 02:50 . 2012-04-19 02:50 24896 ----a-w- c:\windows\system32\drivers\avgidshx.sys

2012-04-11 18:00 . 2012-04-12 08:39 51144 ----a-w- c:\windows\system32\drivers\Soluto.sys

2012-03-22 19:12 . 2012-03-22 19:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr

2012-03-19 03:17 . 2012-03-19 03:17 301248 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2012-03-14 02:15 . 2012-04-11 13:38 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{2668078C-33FE-4D98-AE30-FFEE0EEEE66A}\mpengine.dll ERROR(0x00000005)

2012-03-14 02:15 . 2009-05-05 12:33 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)

2012-02-29 15:11 . 2012-04-13 01:18 5120 ----a-w- c:\windows\system32\wmi.dll

2012-02-29 15:11 . 2012-04-13 01:18 172032 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 15:09 . 2012-04-13 01:18 157696 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 13:32 . 2012-04-13 01:18 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-02-28 01:18 . 2012-04-15 10:31 1799168 ----a-w- c:\windows\system32\jscript9.dll

2012-02-28 01:11 . 2012-04-15 10:31 1427456 ----a-w- c:\windows\system32\inetcpl.cpl

2012-02-28 01:11 . 2012-04-15 10:31 1127424 ----a-w- c:\windows\system32\wininet.dll

2012-02-28 01:03 . 2012-04-15 10:31 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2011-08-11 10:18 . 2011-08-11 10:18 128960 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll

2011-08-10 21:16 . 2011-08-10 21:16 96192 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2011-08-11 10:18 . 2011-08-11 10:18 92096 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2011-08-11 10:18 . 2011-08-11 10:18 22976 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2011-08-11 10:18 . 2011-08-11 10:18 370624 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2011-08-11 10:18 . 2011-08-11 10:18 32192 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2011-08-11 10:18 . 2011-08-11 10:18 40896 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2011-08-10 21:18 . 2011-08-10 21:18 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2011-08-10 21:16 . 2011-08-10 21:16 24512 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2012-03-13 04:38 . 2011-12-11 18:35 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-09 39408]

"gStart"="c:\program files\Garmin\gStart.exe" [2008-08-13 1891416]

"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-12-27 937360]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-12-27 3508624]

"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-12-27 21392]

"ANT Agent"="c:\program files\Garmin\ANT Agent\ANT Agent.exe" [2011-11-07 14767976]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-08 1111336]

"MDS_Menu"="c:\program files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]

"PDVD8LanguageShortcut"="c:\program files\HomeCinema\PowerDVD8\Language\Language.exe" [2007-12-14 50472]

"UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]

"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]

"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2009-04-10 191488]

"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]

"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]

"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2009-04-28 389120]

"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]

"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]

"SS_MW"="c:\program files\Radica\Stylin' Studio\SS_MW.exe" [2008-04-25 524288]

"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

.

c:\users\Bobke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

.

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

GTSCSER

prism_a02

portmapper

TNaviSrv

AR5523

UBHelper

hcwPP2

VC4CB104

DirectUpdate

ipodservice

vetfddnt

lightscribeservice

ltxred

.

Inhoud van de 'Gedeelde Taken' map

.

2012-05-24 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 13:23]

.

2012-05-14 c:\windows\Tasks\At1.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-18 c:\windows\Tasks\At10.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At11.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-17 c:\windows\Tasks\At12.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At13.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-20 c:\windows\Tasks\At14.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At15.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At16.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-20 c:\windows\Tasks\At17.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At18.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-24 c:\windows\Tasks\At19.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At2.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At20.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At21.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-22 c:\windows\Tasks\At22.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At23.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At24.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At3.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At4.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At5.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At6.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At7.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-14 c:\windows\Tasks\At8.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-16 c:\windows\Tasks\At9.job

- c:\programdata\1Dab58Ta.exe [2012-05-14 14:36]

.

2012-05-20 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-09 15:48]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 16:07]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 16:07]

.

.

------- Bijkomende Scan -------

.

uSearch Page = hxxp://www.google.com

uStart Page = hxxp://www.google.be/

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\AVG\AVG2012\avgdtiex.dll

TCP: DhcpNameServer = 192.168.2.1

DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB

FF - ProfilePath - c:\users\Bobke\AppData\Roaming\Mozilla\Firefox\Profiles\bk7xqb7s.default\

FF - prefs.js: browser.search.selectedEngine - BearShare Web Search

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com

FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q=

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-10 - (no file)

HKCU-Run-Yfisoxb - c:\users\Bobke\AppData\Roaming\Ebyda\cyoc.exe

AddRemove-_{ADDBE07D-95B8-4789-9C76-187FFF9624B4} - c:\program files\Corel\CorelDRAW Essential Edition 3\Programs\MSILauncher {ADDBE07D-95B8-4789-9C76-187FFF9624B4}

AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe

AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe

AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe

AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe

AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe

AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe

AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe

AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe

AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe

AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe

AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe

AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe

AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe

AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe

AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe

AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe

AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe

AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe

AddRemove-RewardsArcade - c:\program files\RewardsArcade\Uninstall.exe

.

.

.

**************************************************************************

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden:

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}"=hex:51,66,7a,6c,4c,1d,38,12,e1,e2,cd,

d7,56,95,85,0e,e0,e7,a2,b0,a0,5d,7a,5e

"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,

27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b

"{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}"=hex:51,66,7a,6c,4c,1d,38,12,99,4c,c5,

c6,8a,44,0d,07,f6,df,a9,7b,0a,d1,41,18

"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,

89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b

"{BA14329E-9550-4989-B3F2-9732E92D17CC}"=hex:51,66,7a,6c,4c,1d,38,12,f0,31,07,

be,62,db,e7,0c,cc,e4,d4,72,ec,73,53,d8

"{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea,

34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89

"{043C5167-00BB-4324-AF7E-62013FAEDACF}"=hex:51,66,7a,6c,4c,1d,38,12,09,52,2f,

00,89,4e,4a,06,d0,68,21,41,3a,f0,9e,db

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,38,12,81,2d,20,

35,ad,85,e1,00,d0,fd,90,4e,9f,38,f2,ae

"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,

38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4

"{4A368E80-174F-4872-96B5-0B27DDD11DB2}"=hex:51,66,7a,6c,4c,1d,38,12,ee,8d,25,

4e,7d,59,1c,0d,e9,a3,48,67,d8,8f,59,a6

"{597A9974-8CB0-4F41-B61F-ED065738A397}"=hex:51,66,7a,6c,4c,1d,38,12,1a,9a,69,

5d,82,c2,2f,0a,c9,09,ae,46,52,66,e7,83

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,

ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3

"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,

aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83

"{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a,

ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49

"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,

d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,

36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:10,04,22,2b,df,31,cd,01

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,95,2b,f5,c3,47,77,f5,4f,8c,0b,6c,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,95,2b,f5,c3,47,77,f5,4f,8c,0b,6c,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

c:\program files\AVG\AVG2012\avgwdsvc.exe

c:\program files\Microsoft\BingBar\SeaPort.EXE

c:\windows\system32\FsUsbExService.Exe

c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe

c:\windows\system32\IoctlSvc.exe

c:\windows\system32\PSIService.exe

c:\program files\Cyberlink\Shared files\RichVideo.exe

c:\program files\Soluto\SolutoService.exe

c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\windows\system32\conime.exe

c:\windows\RtHDVCpl.exe

c:\windows\system32\igfxsrvc.exe

c:\windows\ehome\ehmsas.exe

c:\program files\Launch Manager\WisLMSvc.exe

c:\program files\Citrix\ICA Client\Receiver\Receiver.exe

c:\program files\Common Files\Nero\Lib\NMIndexingService.exe

c:\program files\SpywareGuard\sgbhp.exe

c:\program files\Citrix\ICA Client\wfcrun32.exe

c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

c:\windows\ehome\mcupdate.EXE

c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac

.

**************************************************************************

.

Voltooingstijd: 2012-05-24 18:32:23 - machine werd herstart

ComboFix-quarantined-files.txt 2012-05-24 16:32

.

Pre-Run: 94.270.898.176 bytes beschikbaar

Post-Run: 94.774.726.656 bytes beschikbaar

.

- - End Of File - - F822E804EF0AD72327595F9C842AB1FB

Link naar reactie
Delen op andere sites

  • Reacties 36
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Mijn PC is verlost.

Heb je nog enkele tips, programmatjes om zulke zaken in de toekomst te vermijden ?

1. Installeer een goede antivirus, avast (free) of microsoft security essentials zijn beide gratis. Met beide heb ik goede ervaring, maar specialisten vinden Avast beter.

2. Bezoek geen s e x sites of klik niet op onveilige bestanden. Kunt u niet aan de verleiding weerstaan, installeer dan sandboxie. Als je daarmee start, kom je in een soort zandbak terecht waarbij er (theoretisch) geen virussen tijdens de zandbak-sessie op je pc kunnen. Sandboxie is hier te downloaden.

3. Klik niet te snel op "Next" bij de installatie van een programma. Standaard staat het installeren van vervelende balken reeds aangevinkt. Vink die dus uit. Die reclame (en malware) kan je missen als kiespijn

4. Scan je pc regelmatig handmatig met Malwarebytes (klik erop) en Spybot.

aangepast door Kurtt
Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

c:\users\Bobke\AppData\Roaming\Vogeyg

c:\users\Bobke\AppData\Roaming\Omdyec

C:\found.000

Registry::

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

[-HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

[-HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

AtJob::

Firefox::

FF - ProfilePath - c:\users\Bobke\AppData\Roaming\Mozilla\Firefox\Profiles\bk7xqb7s.default\

FF - prefs.js: browser.search.selectedEngine -

FF - prefs.js: keyword.URL -

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht.

Link naar reactie
Delen op andere sites

Dit is het vorige logje van Combofix. Bedoeling is dat je het CFScript.txt (uit bericht 23) in ComboFix.exe sleept, zodat dit weer kan opstarten en de fouten uit het scriptje kan oplossen. Daarna mag je een nieuw logje van Combofix plaatsen.

Link naar reactie
Delen op andere sites

ComboFix 12-05-24.02 - Bobke 24/05/2012 19:33:58.2.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3062.1949 [GMT 2:00]

Gestart vanuit: c:\users\Bobke\Downloads\ComboFix.exe

gebruikte Opdracht switches :: c:\users\Bobke\Desktop\CFScript.txt

AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}

SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\found.000

c:\found.000\file0000.chk

c:\users\Bobke\AppData\Roaming\Hofu

c:\users\Bobke\AppData\Roaming\Hofu\imuv.exe

c:\users\Bobke\AppData\Roaming\Omdyec

c:\users\Bobke\AppData\Roaming\Omdyec\uhedt.iph

c:\users\Bobke\AppData\Roaming\Vogeyg

c:\users\Bobke\AppData\Roaming\Vogeyg\izzuk.qud

c:\users\Bobke\AppData\Roaming\Vogeyg\izzuk.tmp

c:\windows\Tasks\At1.job

c:\windows\Tasks\At10.job

c:\windows\Tasks\At11.job

c:\windows\Tasks\At12.job

c:\windows\Tasks\At13.job

c:\windows\Tasks\At14.job

c:\windows\Tasks\At15.job

c:\windows\Tasks\At16.job

c:\windows\Tasks\At17.job

c:\windows\Tasks\At18.job

c:\windows\Tasks\At19.job

c:\windows\Tasks\At2.job

c:\windows\Tasks\At20.job

c:\windows\Tasks\At21.job

c:\windows\Tasks\At22.job

c:\windows\Tasks\At23.job

c:\windows\Tasks\At24.job

c:\windows\Tasks\At3.job

c:\windows\Tasks\At4.job

c:\windows\Tasks\At5.job

c:\windows\Tasks\At6.job

c:\windows\Tasks\At7.job

c:\windows\Tasks\At8.job

c:\windows\Tasks\At9.job

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-04-24 to 2012-05-24 ))))))))))))))))))))))))))))))

.

.

2012-05-24 17:46 . 2012-05-24 17:46 -------- d-----w- c:\users\Bobke\AppData\Local\temp

2012-05-24 17:46 . 2012-05-24 17:46 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-05-24 17:46 . 2012-05-24 17:46 -------- d-----w- c:\users\Astrid\AppData\Local\temp

2012-05-24 16:33 . 2012-05-24 17:06 -------- d-----w- c:\users\Bobke\AppData\Roaming\Wimoka

2012-05-24 16:33 . 2012-05-24 16:33 -------- d-----w- c:\users\Bobke\AppData\Roaming\Hiov

2012-05-22 16:51 . 2012-05-22 16:51 -------- d-----w- c:\users\Astrid\AppData\Roaming\Malwarebytes

2012-05-22 16:51 . 2012-05-22 16:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-05-22 16:51 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-05-18 19:23 . 2012-05-22 17:32 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0

2012-05-15 16:06 . 2012-05-15 16:06 -------- d-----w- c:\windows\Sun

2012-04-30 16:33 . 2012-05-05 13:23 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-05-05 13:23 . 2011-06-30 11:55 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-04-19 02:50 . 2012-04-19 02:50 24896 ----a-w- c:\windows\system32\drivers\avgidshx.sys

2012-04-11 18:00 . 2012-04-12 08:39 51144 ----a-w- c:\windows\system32\drivers\Soluto.sys

2012-03-22 19:12 . 2012-03-22 19:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr

2012-03-19 03:17 . 2012-03-19 03:17 301248 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2012-03-14 02:15 . 2012-04-11 13:38 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{2668078C-33FE-4D98-AE30-FFEE0EEEE66A}\mpengine.dll ERROR(0x00000005)

2012-03-14 02:15 . 2009-05-05 12:33 6582328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll ERROR(0x00000005)

2012-02-29 15:11 . 2012-04-13 01:18 5120 ----a-w- c:\windows\system32\wmi.dll

2012-02-29 15:11 . 2012-04-13 01:18 172032 ----a-w- c:\windows\system32\wintrust.dll

2012-02-29 15:09 . 2012-04-13 01:18 157696 ----a-w- c:\windows\system32\imagehlp.dll

2012-02-29 13:32 . 2012-04-13 01:18 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys

2012-02-28 01:18 . 2012-04-15 10:31 1799168 ----a-w- c:\windows\system32\jscript9.dll

2012-02-28 01:11 . 2012-04-15 10:31 1427456 ----a-w- c:\windows\system32\inetcpl.cpl

2012-02-28 01:11 . 2012-04-15 10:31 1127424 ----a-w- c:\windows\system32\wininet.dll

2012-02-28 01:03 . 2012-04-15 10:31 2382848 ----a-w- c:\windows\system32\mshtml.tlb

2011-08-11 10:18 . 2011-08-11 10:18 128960 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll

2011-08-10 21:16 . 2011-08-10 21:16 96192 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2011-08-11 10:18 . 2011-08-11 10:18 92096 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2011-08-11 10:18 . 2011-08-11 10:18 22976 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2011-08-11 10:18 . 2011-08-11 10:18 370624 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2011-08-11 10:18 . 2011-08-11 10:18 32192 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2011-08-11 10:18 . 2011-08-11 10:18 40896 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2011-08-10 21:18 . 2011-08-10 21:18 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2011-08-10 21:16 . 2011-08-10 21:16 24512 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2012-03-13 04:38 . 2011-12-11 18:35 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-09 39408]

"gStart"="c:\program files\Garmin\gStart.exe" [2008-08-13 1891416]

"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-12-27 937360]

"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-12-27 3508624]

"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-12-27 21392]

"ANT Agent"="c:\program files\Garmin\ANT Agent\ANT Agent.exe" [2011-11-07 14767976]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]

"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-08 1111336]

"MDS_Menu"="c:\program files\HomeCinema\MediaShow4\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]

"PDVD8LanguageShortcut"="c:\program files\HomeCinema\PowerDVD8\Language\Language.exe" [2007-12-14 50472]

"UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]

"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]

"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2009-04-10 191488]

"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]

"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]

"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2009-04-28 389120]

"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]

"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2011-08-11 358336]

"SS_MW"="c:\program files\Radica\Stylin' Studio\SS_MW.exe" [2008-04-25 524288]

"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]

.

c:\users\Bobke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

.

R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - FSUSBEXDISK

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

GTSCSER

prism_a02

portmapper

TNaviSrv

AR5523

UBHelper

hcwPP2

VC4CB104

DirectUpdate

ipodservice

vetfddnt

lightscribeservice

ltxred

.

Inhoud van de 'Gedeelde Taken' map

.

2012-05-24 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 13:23]

.

2012-05-20 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-09 15:48]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 16:07]

.

2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 16:07]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.be/

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\AVG\AVG2012\avgdtiex.dll

TCP: DhcpNameServer = 192.168.2.1

DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB

FF - ProfilePath - c:\users\Bobke\AppData\Roaming\Mozilla\Firefox\Profiles\bk7xqb7s.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com

.

- - - - ORPHANS VERWIJDERD - - - -

.

HKCU-Run-Daefb - c:\users\Bobke\AppData\Roaming\Hofu\imuv.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-05-24 19:46

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

@Denied: (2) (LocalSystem)

"{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}"=hex:51,66,7a,6c,4c,1d,38,12,e1,e2,cd,

d7,56,95,85,0e,e0,e7,a2,b0,a0,5d,7a,5e

"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,

27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b

"{C2D64FF7-0AB8-4263-89C9-EA3B0F8F050C}"=hex:51,66,7a,6c,4c,1d,38,12,99,4c,c5,

c6,8a,44,0d,07,f6,df,a9,7b,0a,d1,41,18

"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,

89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b

"{BA14329E-9550-4989-B3F2-9732E92D17CC}"=hex:51,66,7a,6c,4c,1d,38,12,f0,31,07,

be,62,db,e7,0c,cc,e4,d4,72,ec,73,53,d8

"{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea,

34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89

"{043C5167-00BB-4324-AF7E-62013FAEDACF}"=hex:51,66,7a,6c,4c,1d,38,12,09,52,2f,

00,89,4e,4a,06,d0,68,21,41,3a,f0,9e,db

"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,

1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7

"{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,38,12,81,2d,20,

35,ad,85,e1,00,d0,fd,90,4e,9f,38,f2,ae

"{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,

38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4

"{4A368E80-174F-4872-96B5-0B27DDD11DB2}"=hex:51,66,7a,6c,4c,1d,38,12,ee,8d,25,

4e,7d,59,1c,0d,e9,a3,48,67,d8,8f,59,a6

"{597A9974-8CB0-4F41-B61F-ED065738A397}"=hex:51,66,7a,6c,4c,1d,38,12,1a,9a,69,

5d,82,c2,2f,0a,c9,09,ae,46,52,66,e7,83

"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,

76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a

"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,

94,30,02,d1,0f,f1,da,12,24,73,56,27,d2

"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,

ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3

"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,

aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83

"{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a,

ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49

"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,

d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b

"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,

df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd

"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,

2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85

"{32004B8A-44A9-43E7-84E9-808838809519}"=hex:51,66,7a,6c,4c,1d,38,12,e4,48,13,

36,9b,0a,89,06,fb,ff,c3,c8,3d,de,d1,0d

"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,

fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17

"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,

b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]

@Denied: (2) (LocalSystem)

"Timestamp"=hex:10,04,22,2b,df,31,cd,01

.

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,95,2b,f5,c3,47,77,f5,4f,8c,0b,6c,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,95,2b,f5,c3,47,77,f5,4f,8c,0b,6c,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

Voltooingstijd: 2012-05-24 19:49:35

ComboFix-quarantined-files.txt 2012-05-24 17:49

ComboFix2.txt 2012-05-24 16:32

.

Pre-Run: 94.624.587.776 bytes beschikbaar

Post-Run: 94.120.554.496 bytes beschikbaar

.

- - End Of File - - D2AAF3BCB12B33BC3E1488C895980315

Link naar reactie
Delen op andere sites

Problemen van de baan, dan is het tijd voor de “grote schoonmaak” : verwijderen van gebruikte programma’s, een cleaning en het verwijderen van de besmette herstelpunten.

Verwijder Combofix: Start -> Uitvoeren/Zoekopdracht en typ: ComboFix /Uninstall

Dit zal Combofix verwijderen + gerelateerde mappen en bestanden, herstelt de klokinstellingen opnieuw, verbergt de bestandsextensies, gaat verborgen bestanden en systeembestanden terug verbergen en maakt een nieuw herstelpunt.

Indien aanwezig mag je de map C:\Qoobox manueel verwijderen.

Download CCleaner.

Klik op “Download Latest Version” en dan start de download van CCleaner automatisch en gratis op.

Installeer het en start CCleaner op. Klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Schoonmaken'. Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”. Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Het is aangewezen om de bestaande herstelpunten te verwijderen (daar zitten besmette herstelpunten tussen die je eventueel zou kunnen terugzetten). Doe dit via Configuratiescherm -> Systeem en Onderhoud -> Systeem -> tabblad "Systeembeveiliging" -> vinkje weghalen bij de schijf waarvan je de herstelpunten wil verwijderen -> klikken op "toepassen". Dan krijg je de schermmelding “Weet u zeker dat u systeemherstel wil uitschakelen”. Klik hier op “Systeemherstel uitschakelen”. Dan zijn alle herstelpunten verwijderd op de aangeduide schijf.

Zet daarna opnieuw een vinkje bij de harde schijf. Maak meteen ook een nieuw herstelpunt, zodat je niet hoeft te wachten op een automatisch herstelpunt van het systeem.

Indien dit probleemloos verlopen is, mag je hieronder op "markeer als opgelost" tokkelen !

P.S. : de belangrijkste zaken waarmee je rekening moet houden om je PC clean te houden, staan al in bericht 22.

aangepast door kape
Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.