Ga naar inhoud

links worden niet doorverbonden met sites en de PC schakelt zichzelf regelmatig uit


Gast wjhradings

Aanbevolen berichten

De meeste items die moesten verwijderd worden, zijn nu wel degelijk weg ... dat is al iets ! Nog even verder kijken :

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

Klik hier

Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap.

2. Dubbelklik op ComboFix.exe en volg de meldingen op het scherm.

3. ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.

**Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware.

4. Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.

cf-rc-auto.jpg

Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:

rc-auto-done.jpg

Klik op Ja om verder te gaan met het scannen naar malware.

5. Wanneer ComboFix klaar is, zal het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

  • Reacties 48
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Geplaatste afbeeldingen

Gast wjhradings

Beste Kape,

Eindelijk is het zo ver. Het heeft de hele avond gekost om Combofix te downloaden en uit te voeren. Hieronder plak ik de log en hoop dat je me verder kan helpen. met vriendelijke groeten Willem

ComboFix 12-06-21.02 - x 21-06-2012 23:27:52.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1015.471 [GMT 2:00]

Gestart vanuit: c:\documents and settings\x\Mijn documenten\Downloads\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

FW: avast! Internet Security *Enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\Application Data\TEMP

c:\documents and settings\x\Application Data\PriceGong

c:\documents and settings\x\Application Data\PriceGong\Data\1.txt

c:\documents and settings\x\Application Data\PriceGong\Data\2229.txt

c:\documents and settings\x\Application Data\PriceGong\Data\2258.txt

c:\documents and settings\x\Application Data\PriceGong\Data\4489.txt

c:\documents and settings\x\Application Data\PriceGong\Data\450.txt

c:\documents and settings\x\Application Data\PriceGong\Data\459.txt

c:\documents and settings\x\Application Data\PriceGong\Data\946.txt

c:\documents and settings\x\Application Data\PriceGong\Data\a.txt

c:\documents and settings\x\Application Data\PriceGong\Data\b.txt

c:\documents and settings\x\Application Data\PriceGong\Data\c.txt

c:\documents and settings\x\Application Data\PriceGong\Data\d.txt

c:\documents and settings\x\Application Data\PriceGong\Data\e.txt

c:\documents and settings\x\Application Data\PriceGong\Data\f.txt

c:\documents and settings\x\Application Data\PriceGong\Data\g.txt

c:\documents and settings\x\Application Data\PriceGong\Data\h.txt

c:\documents and settings\x\Application Data\PriceGong\Data\i.txt

c:\documents and settings\x\Application Data\PriceGong\Data\j.txt

c:\documents and settings\x\Application Data\PriceGong\Data\k.txt

c:\documents and settings\x\Application Data\PriceGong\Data\l.txt

c:\documents and settings\x\Application Data\PriceGong\Data\m.txt

c:\documents and settings\x\Application Data\PriceGong\Data\mru.xml

c:\documents and settings\x\Application Data\PriceGong\Data\n.txt

c:\documents and settings\x\Application Data\PriceGong\Data\o.txt

c:\documents and settings\x\Application Data\PriceGong\Data\p.txt

c:\documents and settings\x\Application Data\PriceGong\Data\q.txt

c:\documents and settings\x\Application Data\PriceGong\Data\r.txt

c:\documents and settings\x\Application Data\PriceGong\Data\s.txt

c:\documents and settings\x\Application Data\PriceGong\Data\t.txt

c:\documents and settings\x\Application Data\PriceGong\Data\u.txt

c:\documents and settings\x\Application Data\PriceGong\Data\v.txt

c:\documents and settings\x\Application Data\PriceGong\Data\w.txt

c:\documents and settings\x\Application Data\PriceGong\Data\wlu.txt

c:\documents and settings\x\Application Data\PriceGong\Data\x.txt

c:\documents and settings\x\Application Data\PriceGong\Data\y.txt

c:\documents and settings\x\Application Data\PriceGong\Data\z.txt

c:\documents and settings\x\Mijn documenten\windows\winhelp.exe

C:\install.exe

c:\windows\system32\roboot.exe

c:\windows\system32\Thumbs.db

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_usnjsvc

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-05-21 to 2012-06-21 ))))))))))))))))))))))))))))))

.

.

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\windows\system32\wbem\snmp

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\windows\system32\xircom

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\program files\microsoft frontpage

2012-06-21 19:48 . 2012-06-21 19:48 -------- d--h--r- c:\documents and settings\x\Onlangs geopend

2012-06-21 15:30 . 2012-06-21 17:36 -------- d-----w- c:\documents and settings\x\Application Data\GetRightToGo

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\documents and settings\x\Application Data\Malwarebytes

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-06-21 13:43 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-06-21 10:55 . 2012-06-21 10:56 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\WiseConvert

2012-06-21 10:55 . 2012-06-21 11:17 -------- d-----w- c:\program files\WiseConvert

2012-06-18 12:23 . 2012-06-18 12:23 388096 ----a-r- c:\documents and settings\x\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-06-18 12:23 . 2012-06-18 12:23 -------- d-----w- c:\program files\Trend Micro

2012-06-13 22:29 . 2012-06-13 22:29 -------- d-----w- C:\b3591e1f8f50732e0d0b5895

2012-06-13 21:25 . 2012-05-11 14:44 521728 ------w- c:\windows\system32\dllcache\jsdbgui.dll

2012-06-13 19:44 . 2012-06-13 19:44 -------- d-----w- c:\windows\system32\wbem\Repository

2012-06-13 19:43 . 2012-06-20 14:50 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\Face_Search_Netherlands

2012-06-13 19:43 . 2012-06-21 10:24 -------- d-----w- c:\program files\Face_Search_Netherlands

2012-06-13 19:43 . 2012-06-20 14:50 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\GenealogieWerkbalk

2012-06-13 19:43 . 2012-06-17 12:42 -------- d-----w- c:\program files\GenealogieWerkbalk

2012-06-13 19:41 . 2012-06-13 19:41 -------- d-----w- c:\program files\Conduit

2012-06-11 12:24 . 2012-06-13 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache

2012-06-05 12:34 . 2012-06-05 12:34 -------- d-----w- C:\454ae505d269ee18f2251233ced6

2012-05-29 18:48 . 2012-05-29 18:48 6656 ----a-w- c:\windows\system32\drivers\Amfilter.sys

2012-05-29 18:48 . 2012-05-29 18:48 12800 ----a-w- c:\windows\system32\drivers\Amusbprt.sys

2012-05-25 10:28 . 2012-05-25 10:29 -------- d-----w- c:\program files\Lexmark 730 Series

2012-05-25 10:28 . 2005-08-03 09:52 65536 ----a-r- c:\windows\system32\lxcfcfg.dll

2012-05-25 09:13 . 2012-05-25 09:13 -------- d-----w- C:\Temp

2012-05-24 17:41 . 2012-05-24 17:41 94208 ----a-w- c:\windows\system32\oxui.dll

2012-05-24 17:41 . 2012-05-24 17:41 49408 ----a-w- c:\windows\system32\drivers\oxser.sys

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-18 06:05 . 2012-04-03 13:36 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-06-18 06:05 . 2011-07-28 21:46 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-06-02 13:19 . 2008-04-15 12:00 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui

2012-06-02 13:19 . 2011-07-03 23:42 329240 ----a-w- c:\windows\system32\wucltui.dll

2012-06-02 13:19 . 2011-07-03 23:42 219160 ----a-w- c:\windows\system32\wuaucpl.cpl

2012-06-02 13:19 . 2011-07-03 23:42 210968 ----a-w- c:\windows\system32\wuweb.dll

2012-06-02 13:19 . 2011-07-03 23:42 35864 ----a-w- c:\windows\system32\wups.dll

2012-06-02 13:19 . 2011-07-03 23:42 53784 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-02 13:19 . 2009-01-31 08:28 45080 ----a-w- c:\windows\system32\wups2.dll

2012-06-02 13:19 . 2009-01-31 08:26 97304 ----a-w- c:\windows\system32\cdm.dll

2012-06-02 13:19 . 2008-04-15 12:00 15896 ----a-w- c:\windows\system32\wuapi.dll.mui

2012-06-02 13:19 . 2011-07-03 23:42 577048 ----a-w- c:\windows\system32\wuapi.dll

2012-06-02 13:19 . 2008-04-15 12:00 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

2012-06-02 13:19 . 2011-07-03 23:42 1933848 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-02 13:19 . 2008-04-15 12:00 24088 ----a-w- c:\windows\system32\wucltui.dll.mui

2012-06-02 13:19 . 2008-04-15 12:00 18160 ----a-w- c:\windows\system32\mucltui.dll.mui

2012-06-02 13:18 . 2009-01-31 08:28 275696 ----a-w- c:\windows\system32\mucltui.dll

2012-06-02 13:18 . 2009-01-31 08:28 214256 ----a-w- c:\windows\system32\muweb.dll

2012-05-31 13:19 . 2009-01-31 08:26 603136 ----a-w- c:\windows\system32\crypt32.dll

2012-05-16 15:09 . 2009-01-31 08:29 916992 ----a-w- c:\windows\system32\wininet.dll

2012-05-15 13:55 . 2009-01-31 08:27 1872256 ----a-w- c:\windows\system32\win32k.sys

2012-05-12 09:43 . 2012-05-12 09:43 14392 ----a-w- c:\windows\system32\drivers\AtiPcie.sys

2012-05-11 14:44 . 2009-01-31 08:29 43520 ------w- c:\windows\system32\licmgr10.dll

2012-05-11 14:44 . 2008-04-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2012-05-11 11:39 . 2009-01-31 08:29 385024 ------w- c:\windows\system32\html.iec

2012-05-05 03:14 . 2009-01-31 08:27 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-05-05 03:14 . 2008-08-14 17:28 2073472 ----a-w- c:\windows\system32\ntkrnlpa.exe

2012-05-02 13:45 . 2011-07-03 23:40 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-05-01 23:43 . 2012-05-01 23:43 7463 ----a-w- c:\windows\system32\drivers\tkbtnpn.sys

2012-05-01 23:43 . 2012-05-01 23:43 1490999 ----a-w- c:\windows\system32\tkbtnpn1.dll

2012-04-15 15:48 . 2012-04-15 15:48 13440 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

2011-05-09 09:49 176936 ----a-w- c:\program files\GenealogieWerkbalk\prxtbGen0.dll

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

2011-05-09 08:49 176936 ----a-w- c:\program files\WiseConvert\prxtbWis0.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{c2340376-fa00-45c4-a3db-bae7a9367ec9}"= "c:\program files\GenealogieWerkbalk\prxtbGen0.dll" [2011-05-09 176936]

"{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}"= "c:\program files\WiseConvert\prxtbWis0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

.

[HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{C2340376-FA00-45C4-A3DB-BAE7A9367EC9}"= "c:\program files\GenealogieWerkbalk\prxtbGen0.dll" [2011-05-09 176936]

"{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1}"= "c:\program files\WiseConvert\prxtbWis0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

.

[HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2012-05-23 3029344]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Family Tree Builder Update"="c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe" [2011-12-21 229376]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]

"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"="shell32" [X]

"_nltide_3"="advpack.dll" [2009-03-08 128512]

.

c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-14 19:33 1695232 ------w- c:\program files\Messenger\msmsgs.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

.

R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [3-5-2012 23:17 24408]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3-5-2012 23:05 612184]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3-5-2012 23:05 337880]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3-5-2012 23:05 20696]

S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [24-5-2012 19:41 49408]

S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19-7-2011 22:57 136176]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3-4-2012 15:36 257224]

S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [19-7-2011 22:57 136176]

S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [29-7-2010 0:25 25112]

.

Inhoud van de 'Gedeelde Taken' map

.

2012-06-21 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 06:05]

.

2012-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-19 20:57]

.

2012-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-19 20:57]

.

2012-06-21 c:\windows\Tasks\User_Feed_Synchronization-{D708F740-71B0-480A-B3DF-9F22003D4EF2}.job

- c:\windows\system32\msfeedssync.exe [2011-07-03 02:31]

.

.

------- Bijkomende Scan -------

.

TCP: DhcpNameServer = 192.168.1.1

.

- - - - ORPHANS VERWIJDERD - - - -

.

Toolbar-Locked - (no file)

WebBrowser-{FDDDCB24-0B8A-4D1F-A53A-1F9D57193CC4} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

MSConfigStartUp-IncrediMail - c:\program files\IncrediMail\bin\IncMail.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-06-21 23:34

Windows 5.1.2600 Service Pack 3 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

.

scannen van verborgen bestanden ...

.

.

C:\avast! sandbox

.

Scan succesvol afgerond

verborgen bestanden: 1

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1004\ "*_*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

"MachineID"=hex:e0,e4,ed,61,89,ae,c5,00

DUMPHIVE0.003 (REGF)

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'explorer.exe'(1504)

c:\windows\system32\msi.dll

c:\program files\Windows Desktop Search\deskbar.dll

c:\program files\Windows Desktop Search\nl-nl\dbres.dll.mui

c:\program files\Windows Desktop Search\dbres.dll

c:\program files\Windows Desktop Search\wordwheel.dll

c:\program files\Windows Desktop Search\nl-nl\msnlExtRes.dll.mui

c:\program files\Windows Desktop Search\msnlExtRes.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\program files\AVAST Software\Avast\AvastSvc.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\windows\system32\SearchIndexer.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Voltooingstijd: 2012-06-21 23:37:14 - machine werd herstart

ComboFix-quarantined-files.txt 2012-06-21 21:37

.

Pre-Run: 54.888.042.496 bytes beschikbaar

Post-Run: 54.773.383.168 bytes beschikbaar

.

WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - 1FF5436C2901CB6FA65D26F032DA700E

Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

c:\documents and settings\x\Local Settings\Application Data\GenealogieWerkbalk

c:\program files\GenealogieWerkbalk

c:\program files\Conduit

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

[-HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

[-HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"=-

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht.

Link naar reactie
Delen op andere sites

Gast wjhradings
Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

Folder::

c:\documents and settings\x\Local Settings\Application Data\GenealogieWerkbalk

c:\program files\GenealogieWerkbalk

c:\program files\Conduit

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

[-HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

[-HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

[-HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"=-

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht.

Beste Skape, Dit is het resultaat na de scan:

Malwarebytes Anti-Malware 1.61.0.1400

www.malwarebytes.org

Databaseversie: v2012.06.21.05

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

x :: X-242F6149B8534 [administrator]

22-6-2012 11:32:36

mbam-log-2012-06-22 (11-32-36).txt

Scantype: Aangepaste scan

Ingeschakelde scanopties: Bestanden en mappen | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scanopties: Geheugen | Opstartitems | Register | Heuristiek/Extra | P2P

Objecten gescand: 1

Verstreken tijd: 6 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

(einde)

Link naar reactie
Delen op andere sites

Gast wjhradings

het vetgedrukte binnen de lijnen is de opdracht die je me gaf om uit te voeren. en het resultaat staat er onder. bedoel je soms dat ik de PC moet herstarten en dan nog maals mailware uitvoeren en dit resultaat naar je toe zenden?

Link naar reactie
Delen op andere sites

De opdracht die je moest uitvoeren, diende te gebeuren met het programma Combofix : het slepen van het scriptje in de rode snelkoppeling van Combofix om de aangeduide items te kunnen verwijderen. Daarna krijg je een nieuw logje van Combofix ... en dat was wat we nodig hadden om verder te kijken of alles goed verlopen was.

Het logje dat je gepost hebt is er echter eentje van Malwarebytes, een héél ander programma ;-)

Link naar reactie
Delen op andere sites

Gast wjhradings

Ok dat is duidelijk een leesfoutje van mij. Ik heb heel veel moeite gehad met Combofix omdat de koppeling niet werkte. Ik kreeg het maar niet gedownload. Het bleek dat hij al om mijn PC stond. Maar uiteindelijk heb ik nu het logje hieronder:

ComboFix 12-06-21.03 - x 22-06-2012 12:49:38.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1015.658 [GMT 2:00]

Gestart vanuit: c:\documents and settings\x\Mijn documenten\Downloads\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

FW: avast! Internet Security *Enabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-05-22 to 2012-06-22 ))))))))))))))))))))))))))))))

.

.

2012-06-22 08:56 . 2012-06-22 10:42 -------- d--h--r- c:\documents and settings\x\Onlangs geopend

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\windows\system32\wbem\snmp

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\windows\system32\xircom

2012-06-21 21:33 . 2012-06-21 21:33 -------- d-----w- c:\program files\microsoft frontpage

2012-06-21 15:30 . 2012-06-21 17:36 -------- d-----w- c:\documents and settings\x\Application Data\GetRightToGo

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\documents and settings\x\Application Data\Malwarebytes

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-06-21 13:43 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-06-21 13:43 . 2012-06-21 13:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-06-21 10:55 . 2012-06-21 10:56 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\WiseConvert

2012-06-21 10:55 . 2012-06-21 11:17 -------- d-----w- c:\program files\WiseConvert

2012-06-18 12:23 . 2012-06-18 12:23 388096 ----a-r- c:\documents and settings\x\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-06-18 12:23 . 2012-06-18 12:23 -------- d-----w- c:\program files\Trend Micro

2012-06-13 22:29 . 2012-06-13 22:29 -------- d-----w- C:\b3591e1f8f50732e0d0b5895

2012-06-13 21:25 . 2012-05-11 14:44 521728 ------w- c:\windows\system32\dllcache\jsdbgui.dll

2012-06-13 19:44 . 2012-06-13 19:44 -------- d-----w- c:\windows\system32\wbem\Repository

2012-06-13 19:43 . 2012-06-20 14:50 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\Face_Search_Netherlands

2012-06-13 19:43 . 2012-06-21 10:24 -------- d-----w- c:\program files\Face_Search_Netherlands

2012-06-13 19:43 . 2012-06-20 14:50 -------- d-----w- c:\documents and settings\x\Local Settings\Application Data\GenealogieWerkbalk

2012-06-13 19:43 . 2012-06-17 12:42 -------- d-----w- c:\program files\GenealogieWerkbalk

2012-06-13 19:41 . 2012-06-13 19:41 -------- d-----w- c:\program files\Conduit

2012-06-11 12:24 . 2012-06-13 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaInstallerCache

2012-06-05 12:34 . 2012-06-05 12:34 -------- d-----w- C:\454ae505d269ee18f2251233ced6

2012-05-29 18:48 . 2012-05-29 18:48 6656 ----a-w- c:\windows\system32\drivers\Amfilter.sys

2012-05-29 18:48 . 2012-05-29 18:48 12800 ----a-w- c:\windows\system32\drivers\Amusbprt.sys

2012-05-25 10:28 . 2012-05-25 10:29 -------- d-----w- c:\program files\Lexmark 730 Series

2012-05-25 10:28 . 2005-08-03 09:52 65536 ----a-r- c:\windows\system32\lxcfcfg.dll

2012-05-25 09:13 . 2012-05-25 09:13 -------- d-----w- C:\Temp

2012-05-24 17:41 . 2012-05-24 17:41 94208 ----a-w- c:\windows\system32\oxui.dll

2012-05-24 17:41 . 2012-05-24 17:41 49408 ----a-w- c:\windows\system32\drivers\oxser.sys

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-18 06:05 . 2012-04-03 13:36 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2012-06-18 06:05 . 2011-07-28 21:46 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2012-06-02 13:19 . 2008-04-15 12:00 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui

2012-06-02 13:19 . 2011-07-03 23:42 329240 ----a-w- c:\windows\system32\wucltui.dll

2012-06-02 13:19 . 2011-07-03 23:42 219160 ----a-w- c:\windows\system32\wuaucpl.cpl

2012-06-02 13:19 . 2011-07-03 23:42 210968 ----a-w- c:\windows\system32\wuweb.dll

2012-06-02 13:19 . 2011-07-03 23:42 35864 ----a-w- c:\windows\system32\wups.dll

2012-06-02 13:19 . 2011-07-03 23:42 53784 ----a-w- c:\windows\system32\wuauclt.exe

2012-06-02 13:19 . 2009-01-31 08:28 45080 ----a-w- c:\windows\system32\wups2.dll

2012-06-02 13:19 . 2009-01-31 08:26 97304 ----a-w- c:\windows\system32\cdm.dll

2012-06-02 13:19 . 2008-04-15 12:00 15896 ----a-w- c:\windows\system32\wuapi.dll.mui

2012-06-02 13:19 . 2011-07-03 23:42 577048 ----a-w- c:\windows\system32\wuapi.dll

2012-06-02 13:19 . 2008-04-15 12:00 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

2012-06-02 13:19 . 2011-07-03 23:42 1933848 ----a-w- c:\windows\system32\wuaueng.dll

2012-06-02 13:19 . 2008-04-15 12:00 24088 ----a-w- c:\windows\system32\wucltui.dll.mui

2012-06-02 13:19 . 2008-04-15 12:00 18160 ----a-w- c:\windows\system32\mucltui.dll.mui

2012-06-02 13:18 . 2009-01-31 08:28 275696 ----a-w- c:\windows\system32\mucltui.dll

2012-06-02 13:18 . 2009-01-31 08:28 214256 ----a-w- c:\windows\system32\muweb.dll

2012-05-31 13:19 . 2009-01-31 08:26 603136 ----a-w- c:\windows\system32\crypt32.dll

2012-05-16 15:09 . 2009-01-31 08:29 916992 ----a-w- c:\windows\system32\wininet.dll

2012-05-15 13:55 . 2009-01-31 08:27 1872256 ----a-w- c:\windows\system32\win32k.sys

2012-05-12 09:43 . 2012-05-12 09:43 14392 ----a-w- c:\windows\system32\drivers\AtiPcie.sys

2012-05-11 14:44 . 2009-01-31 08:29 43520 ------w- c:\windows\system32\licmgr10.dll

2012-05-11 14:44 . 2008-04-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2012-05-11 11:39 . 2009-01-31 08:29 385024 ------w- c:\windows\system32\html.iec

2012-05-05 03:14 . 2009-01-31 08:27 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe

2012-05-05 03:14 . 2008-08-14 17:28 2073472 ----a-w- c:\windows\system32\ntkrnlpa.exe

2012-05-02 13:45 . 2011-07-03 23:40 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2012-05-01 23:43 . 2012-05-01 23:43 7463 ----a-w- c:\windows\system32\drivers\tkbtnpn.sys

2012-05-01 23:43 . 2012-05-01 23:43 1490999 ----a-w- c:\windows\system32\tkbtnpn1.dll

2012-04-15 15:48 . 2012-04-15 15:48 13440 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

2011-05-09 09:49 176936 ----a-w- c:\program files\GenealogieWerkbalk\prxtbGen0.dll

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

2011-05-09 08:49 176936 ----a-w- c:\program files\WiseConvert\prxtbWis0.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{c2340376-fa00-45c4-a3db-bae7a9367ec9}"= "c:\program files\GenealogieWerkbalk\prxtbGen0.dll" [2011-05-09 176936]

"{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}"= "c:\program files\WiseConvert\prxtbWis0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

.

[HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{C2340376-FA00-45C4-A3DB-BAE7A9367EC9}"= "c:\program files\GenealogieWerkbalk\prxtbGen0.dll" [2011-05-09 176936]

"{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1}"= "c:\program files\WiseConvert\prxtbWis0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{c2340376-fa00-45c4-a3db-bae7a9367ec9}]

.

[HKEY_CLASSES_ROOT\clsid\{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1}]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2012-05-23 3029344]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Family Tree Builder Update"="c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe" [2011-12-21 229376]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]

"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"="shell32" [X]

"_nltide_3"="advpack.dll" [2009-03-08 128512]

.

c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-14 19:33 1695232 ------w- c:\program files\Messenger\msmsgs.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

.

R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [3-5-2012 23:17 24408]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3-5-2012 23:05 612184]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3-5-2012 23:05 337880]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3-5-2012 23:05 20696]

S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [24-5-2012 19:41 49408]

S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19-7-2011 22:57 136176]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3-4-2012 15:36 257224]

S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [19-7-2011 22:57 136176]

S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [29-7-2010 0:25 25112]

.

Inhoud van de 'Gedeelde Taken' map

.

2012-06-22 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 06:05]

.

2012-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-19 20:57]

.

2012-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-19 20:57]

.

.

------- Bijkomende Scan -------

.

TCP: DhcpNameServer = 192.168.1.1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-06-22 12:54

Windows 5.1.2600 Service Pack 3 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

LXCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-789336058-1214440339-1417001333-1004\ "*_*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

"MachineID"=hex:e0,e4,ed,61,89,ae,c5,00

DUMPHIVE0.003 (REGF)

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'explorer.exe'(420)

c:\windows\system32\msi.dll

c:\program files\Windows Desktop Search\deskbar.dll

c:\program files\Windows Desktop Search\nl-nl\dbres.dll.mui

c:\program files\Windows Desktop Search\dbres.dll

c:\program files\Windows Desktop Search\wordwheel.dll

c:\program files\Windows Desktop Search\nl-nl\msnlExtRes.dll.mui

c:\program files\Windows Desktop Search\msnlExtRes.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

Voltooingstijd: 2012-06-22 12:55:54

ComboFix-quarantined-files.txt 2012-06-22 10:55

ComboFix2.txt 2012-06-21 21:37

.

Pre-Run: 54.744.059.904 bytes beschikbaar

Post-Run: 54.744.039.424 bytes beschikbaar

.

- - End Of File - - 536B8BEDD9D9187AE5E4FC9891F2F057

Link naar reactie
Delen op andere sites

Nu heb je Combofix gewoon opnieuw laten scannen. Bedoeling is dat je het bestandje CFScript.txt , dat je opgeslagen hebt, IN de rode snelkoppeling van Combofix op je bureaublad sleept. Dan start Combofix opnieuw op en worden de items in het scriptje verwijderd. Daarna mag je een nieuw logje met het resultaat in een bericht zetten.

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.