Ga naar inhoud

Portaldosite


Aanbevolen berichten

Dan nemen we die map ineens mee in de volgende fix:

Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

Schakel alle antivirus- en antispywareprogramma's uit, want deze kunnen namelijk conflicteren met ComboFix.

(hier of hier) kan je lezen hoe je de gebruikte beveiligingssoftware kunt uitschakelen.

Open een nieuw leeg Kladblok scherm, kopieer en plak hierin de volgende code.

 
Folder::
c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP
c:\users\PAUL\AppData\Roaming\Virus Scan

File::
c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP

Driver::
BBSvc
BingBar Service  

Sla dit op op je Bureaublad als CFScript.txt

Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld:

CFScript.gif

Nu zal ComboFix vanzelf worden gestart.

Start opnieuw op als daarom gevraagd wordt, en post de inhoud van de Combofix.txt in je volgende antwoord.

Link naar reactie
Delen op andere sites

Ziehier de gevraagde inhoud van Combifix.txt :

ComboFix 13-07-14.01 - PAUL 15/07/2013 15:36:24.2.2 - x64Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.4044.2243 [GMT 2:00]

Gestart vanuit: c:\users\PAUL\Downloads\ComboFix.exe

gebruikte Opdracht switches :: c:\users\PAUL\Desktop\CFScript.txt

AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}

AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}

FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}

SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP"

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\PAUL\AppData\Roaming\Virus Scan

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCall.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla2.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla21.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla31.exe

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla32.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla33.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla34.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla37.dll

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseCustomCalla37.exe

c:\windows\8AE3CFB678B24F55A7BE618FCFF43A03.TMP\WiseData.ini

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_BBSvc

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2013-06-15 to 2013-07-15 ))))))))))))))))))))))))))))))

.

.

2013-07-14 21:29 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CCD1E47E-C35C-436A-97CB-73899150FE52}\mpengine.dll

2013-07-14 21:23 . 2013-07-14 21:23 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2 SDK

2013-07-13 19:55 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2013-07-13 07:18 . 2013-07-13 07:18 -------- d-----w- c:\program files (x86)\Common Files\Java

2013-07-13 07:18 . 2013-07-13 07:17 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-07-10 21:06 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll

2013-07-10 06:56 . 2013-07-10 06:56 -------- d-----w- c:\users\PAUL\AppData\Roaming\AVG2013

2013-07-10 06:53 . 2013-07-10 11:18 -------- d-----w- c:\programdata\AVG2013

2013-07-10 06:53 . 2013-07-10 11:18 -------- d-----w- C:\$AVG

2013-07-10 06:48 . 2013-07-10 11:19 -------- d-----w- c:\programdata\MFAData

2013-07-10 06:48 . 2013-07-10 06:57 -------- d-----w- c:\users\PAUL\AppData\Local\Avg2013

2013-07-10 06:48 . 2013-07-10 06:48 -------- d-----w- c:\users\PAUL\AppData\Local\MFAData

2013-07-09 08:00 . 2013-07-09 08:00 -------- d-----w- c:\programdata\Systweak

2013-07-09 08:00 . 2012-07-25 10:03 16896 ----a-w- c:\windows\system32\sasnative64.exe

2013-07-09 07:59 . 2013-07-10 11:31 -------- d-----w- c:\users\PAUL\AppData\Roaming\Systweak

2013-07-09 07:59 . 2012-12-10 10:01 19896 ----a-w- c:\windows\system32\roboot64.exe

2013-07-08 16:57 . 2013-07-08 16:57 88 ----a-w- c:\windows\DeleteOnReboot.bat

2013-07-08 14:00 . 2013-03-12 08:27 93976 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll

2013-07-08 14:00 . 2013-07-08 14:00 388096 ----a-r- c:\users\PAUL\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2013-07-08 14:00 . 2013-07-08 14:00 -------- d-----w- c:\program files (x86)\Trend Micro

2013-07-08 13:59 . 2013-07-08 14:01 -------- d-----w- c:\users\PAUL\AppData\Local\Rich Media Player

2013-07-06 14:48 . 2013-07-06 14:48 -------- d-----w- c:\program files\Enigma Software Group

2013-07-06 13:12 . 2013-07-06 13:12 972712 ----a-w- c:\windows\system32\deployJava1.dll

2013-07-06 13:12 . 2013-07-06 13:12 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll

2013-07-06 12:20 . 2013-07-06 12:20 1920512 ----a-w- c:\users\PAUL\capicom_dc_sdk.msi

2013-06-21 12:57 . 2013-06-21 12:56 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{875E9711-AF34-4D6E-B3DD-9D1B9C674ACC}\gapaengine.dll

2013-06-18 19:50 . 2013-06-18 19:50 247216 ----a-w- c:\windows\system32\drivers\MpFilter.sys

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-07-13 07:17 . 2012-07-08 07:02 867240 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

2013-07-13 07:17 . 2012-03-20 21:57 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-07-10 21:18 . 2012-05-05 11:29 78185248 ----a-w- c:\windows\system32\MRT.exe

2013-06-18 19:50 . 2012-03-20 18:44 139616 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys

2013-06-12 16:42 . 2012-04-23 08:13 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-06-12 16:42 . 2011-11-10 13:13 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-06-09 18:43 . 2013-06-09 18:44 90112 ----a-w- c:\windows\system32\igfxCoIn_v2559.dll

2013-06-09 18:43 . 2013-06-09 18:44 510232 ----a-w- c:\windows\system32\igfxsrvc.exe

2013-06-09 18:43 . 2013-06-09 18:44 378368 ----a-w- c:\windows\system32\igfxTMM.dll

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrtrk.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrsve.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrslv.lrc

2013-06-09 18:43 . 2013-06-09 18:44 285696 ----a-w- c:\windows\system32\igfxrtha.lrc

2013-06-09 18:43 . 2013-06-09 18:44 167704 ----a-w- c:\windows\system32\igfxtray.exe

2013-06-09 18:43 . 2011-08-26 19:54 62464 ----a-w- c:\windows\system32\igfxsrvc.dll

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrsky.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrrus.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrrom.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrptg.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrplk.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrptb.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrnor.lrc

2013-06-09 18:43 . 2013-06-09 18:44 9014784 ----a-w- c:\windows\system32\igfxress.dll

2013-06-09 18:43 . 2013-06-09 18:44 287232 ----a-w- c:\windows\system32\igfxrfra.lrc

2013-06-09 18:43 . 2013-06-09 18:44 287232 ----a-w- c:\windows\system32\igfxresn.lrc

2013-06-09 18:43 . 2013-06-09 18:44 287232 ----a-w- c:\windows\system32\igfxrell.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrnld.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrita.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrhrv.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrhun.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286208 ----a-w- c:\windows\system32\igfxrfin.lrc

2013-06-09 18:43 . 2013-06-09 18:44 285696 ----a-w- c:\windows\system32\igfxrenu.lrc

2013-06-09 18:43 . 2013-06-09 18:44 285184 ----a-w- c:\windows\system32\igfxrheb.lrc

2013-06-09 18:43 . 2013-06-09 18:44 283648 ----a-w- c:\windows\system32\igfxrjpn.lrc

2013-06-09 18:43 . 2013-06-09 18:44 283136 ----a-w- c:\windows\system32\igfxrkor.lrc

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrdeu.lrc

2013-06-09 18:43 . 2013-06-09 18:44 285696 ----a-w- c:\windows\system32\igfxrdan.lrc

2013-06-09 18:43 . 2013-06-09 18:44 416024 ----a-w- c:\windows\system32\igfxpers.exe

2013-06-09 18:43 . 2013-06-09 18:44 375808 ----a-w- c:\windows\system32\igfxpph.dll

2013-06-09 18:43 . 2013-06-09 18:44 286720 ----a-w- c:\windows\system32\igfxrcsy.lrc

2013-06-09 18:43 . 2013-06-09 18:44 28672 ----a-w- c:\windows\system32\igfxexps.dll

2013-06-09 18:43 . 2013-06-09 18:44 285184 ----a-w- c:\windows\system32\igfxrara.lrc

2013-06-09 18:43 . 2013-06-09 18:44 282624 ----a-w- c:\windows\system32\igfxrcht.lrc

2013-06-09 18:43 . 2013-06-09 18:44 282624 ----a-w- c:\windows\system32\igfxrchs.lrc

2013-06-09 18:43 . 2013-06-09 18:44 24576 ----a-w- c:\windows\SysWow64\igfxexps32.dll

2013-06-09 18:43 . 2013-06-09 18:44 239896 ----a-w- c:\windows\system32\igfxext.exe

2013-06-09 18:43 . 2013-06-09 18:44 4096 ----a-w- c:\windows\system32\IGFXDEVLib.dll

2013-06-09 18:43 . 2013-06-09 18:44 390144 ----a-w- c:\windows\system32\igfxdev.dll

2013-06-09 18:43 . 2013-06-09 18:44 294400 ----a-w- c:\windows\SysWow64\igfxdv32.dll

2013-06-09 18:43 . 2013-06-09 18:44 2177536 ----a-w- c:\windows\system32\igfxcmjit64.dll

2013-06-09 18:43 . 2013-06-09 18:44 171520 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll

2013-06-09 18:43 . 2013-06-09 18:44 1663488 ----a-w- c:\windows\SysWow64\igfxcmjit32.dll

2013-06-09 18:43 . 2013-06-09 18:44 148480 ----a-w- c:\windows\system32\igfxcmrt64.dll

2013-06-09 18:43 . 2013-06-09 18:44 142336 ----a-w- c:\windows\system32\igfxdo.dll

2013-06-09 18:43 . 2013-06-09 18:44 126976 ----a-w- c:\windows\system32\igfxcpl.cpl

2013-06-09 18:43 . 2013-06-09 18:44 6323712 ----a-w- c:\windows\SysWow64\igdumd32.dll

2013-06-09 18:43 . 2013-06-09 18:44 581120 ----a-w- c:\windows\SysWow64\igdumdx32.dll

2013-06-09 18:43 . 2013-06-09 18:44 217536 ----a-w- c:\windows\system32\igfcg600m.bin

2013-06-09 18:43 . 2013-06-09 18:44 12310112 ----a-w- c:\windows\system32\drivers\igdkmd64.sys

2013-06-09 18:43 . 2011-08-26 19:53 8313856 ----a-w- c:\windows\system32\igdumd64.dll

2013-06-09 18:43 . 2013-06-09 18:44 75776 ----a-w- c:\windows\system32\igdde64.dll

2013-06-09 18:43 . 2013-06-09 18:44 56832 ----a-w- c:\windows\SysWow64\igdde32.dll

2013-06-09 18:43 . 2011-08-26 19:53 14592512 ----a-w- c:\windows\system32\igd10umd64.dll

2013-06-09 18:43 . 2013-06-09 18:44 12340224 ----a-w- c:\windows\SysWow64\igd10umd32.dll

2013-06-09 18:43 . 2013-06-09 18:44 18651648 ----a-w- c:\windows\system32\ig4icd64.dll

2013-06-09 18:43 . 2013-06-09 18:44 13903872 ----a-w- c:\windows\SysWow64\ig4icd32.dll

2013-06-09 18:43 . 2013-06-09 18:44 392472 ----a-w- c:\windows\system32\hkcmd.exe

2013-06-09 18:43 . 2011-08-26 19:53 110080 ----a-w- c:\windows\system32\hccutils.dll

2013-06-09 18:43 . 2013-06-09 18:44 4378392 ----a-w- c:\windows\system32\GfxUI.exe

2013-06-09 18:43 . 2013-06-09 18:44 184600 ----a-w- c:\windows\system32\difx64.exe

2013-06-09 18:43 . 2013-06-09 18:44 146432 ----a-w- c:\windows\system32\gfxSrvc.dll

2013-05-22 05:52 . 2012-06-13 10:21 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2013-05-13 05:51 . 2013-06-13 06:54 184320 ----a-w- c:\windows\system32\cryptsvc.dll

2013-05-13 05:51 . 2013-06-13 06:54 1464320 ----a-w- c:\windows\system32\crypt32.dll

2013-05-13 05:51 . 2013-06-13 06:54 139776 ----a-w- c:\windows\system32\cryptnet.dll

2013-05-13 05:50 . 2013-06-13 06:54 52224 ----a-w- c:\windows\system32\certenc.dll

2013-05-13 04:45 . 2013-06-13 06:54 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll

2013-05-13 04:45 . 2013-06-13 06:54 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll

2013-05-13 04:45 . 2013-06-13 06:54 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll

2013-05-13 03:43 . 2013-06-13 06:54 1192448 ----a-w- c:\windows\system32\certutil.exe

2013-05-13 03:08 . 2013-06-13 06:54 903168 ----a-w- c:\windows\SysWow64\certutil.exe

2013-05-13 03:08 . 2013-06-13 06:54 43008 ----a-w- c:\windows\SysWow64\certenc.dll

2013-05-10 05:49 . 2013-06-13 06:54 30720 ----a-w- c:\windows\system32\cryptdlg.dll

2013-05-10 03:20 . 2013-06-13 06:54 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll

2013-05-09 12:30 . 2011-03-28 17:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-09 12:21 . 2013-05-09 12:21 20013776 ----a-w- c:\users\PAUL\DAEMONToolsPro520-0348.exe

2013-05-08 06:39 . 2013-06-13 06:54 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys

2013-05-02 15:29 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-30 11:09 . 2013-04-30 11:09 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-04-30 11:09 . 2013-04-30 11:09 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-04-30 11:09 . 2013-04-30 11:09 523264 ----a-w- c:\windows\SysWow64\vbscript.dll

2013-04-30 11:09 . 2013-04-30 11:09 226304 ----a-w- c:\windows\system32\elshyph.dll

2013-04-30 11:09 . 2013-04-30 11:09 185344 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-04-30 11:09 . 2013-04-30 11:09 158720 ----a-w- c:\windows\SysWow64\msls31.dll

2013-04-30 11:09 . 2013-04-30 11:09 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-04-30 11:09 . 2013-04-30 11:09 138752 ----a-w- c:\windows\SysWow64\wextract.exe

2013-04-30 11:09 . 2013-04-30 11:09 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-04-30 11:09 . 2013-04-30 11:09 61952 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-04-30 11:09 . 2013-04-30 11:09 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-04-30 11:09 . 2013-04-30 11:09 38400 ----a-w- c:\windows\SysWow64\imgutil.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19876968]

"TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2013-03-22 248208]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"HPQuickWebProxy"="c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-10-08 169528]

"HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960]

"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-09-15 61112]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

"Family Tree Builder Update"="c:\program files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe" [2011-12-21 229376]

"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-03-05 578944]

.

c:\users\PAUL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OneNote 2007 Schermopname en Snel starten.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"HideFastUserSwitching"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"EnableShellExecuteHooks"= 1 (0x1)

.

[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime

"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]

R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]

R2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]

R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]

R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]

R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]

R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]

R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]

R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]

R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]

S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]

S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe;c:\windows\SYSNATIVE\ezSharedSvcHost.exe [x]

S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]

S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]

S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]

S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe [x]

S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]

S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x]

S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]

S3 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120507.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120507.001\BHDrvx64.sys [x]

S3 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1301000.01C\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1301000.01C\ccSetx64.sys [x]

S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]

S3 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120515.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120515.001\IDSvia64.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]

S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]

S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]

S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]

S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]

S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]

S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]

S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]

S3 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1301000.01C\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1301000.01C\SYMDS64.SYS [x]

S3 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1301000.01C\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1301000.01C\SYMEFA64.SYS [x]

S3 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1301000.01C\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1301000.01C\Ironx64.SYS [x]

S3 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\NISx64\1301000.01C\SYMNETS.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1301000.01C\SYMNETS.SYS [x]

S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]

.

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - WS2IFSL

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-07-13 06:46 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe

.

Inhoud van de 'Gedeelde Taken' map

.

2013-07-15 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-23 16:42]

.

2013-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-05 16:48]

.

2013-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-05 16:48]

.

2013-07-14 c:\windows\Tasks\HPCeeScheduleForPAUL.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 03:43]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-09-08 1424896]

"SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-09-30 43320]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 1356240]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-06-09 167704]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-06-09 392472]

"Persistence"="c:\windows\system32\igfxpers.exe" [2013-06-09 416024]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.be/

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

Trusted Zone: fgov.be\ccff02.minfin

Trusted Zone: fgov.be\minfin

TCP: DhcpNameServer = 192.168.1.1

DPF: {FB54FA27-96CF-4C62-80DC-DA7616EBD326} - hxxp://downloads.bullguard.com/VirusScan/bgvax.cab

.

- - - - ORPHANS VERWIJDERD - - - -

.

AddRemove-00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 - c:\program files (x86)\Advanced System Protector\unins000.exe

AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe

AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe

AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]

"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.1.0.28\diMaster.dll\" /prefetch:1"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\windows\SysWOW64\ezSharedSvcHost.exe

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

.

**************************************************************************

.

Voltooingstijd: 2013-07-15 15:49:56 - machine werd herstart

ComboFix-quarantined-files.txt 2013-07-15 13:49

ComboFix2.txt 2013-07-15 07:21

.

Pre-Run: 373.205.352.448 bytes beschikbaar

Post-Run: 372.737.064.960 bytes beschikbaar

.

- - End Of File - - 42CFC4A1A7A29949971D44E06A65D98B

D41D8CD98F00B204E9800998ECF8427E

Link naar reactie
Delen op andere sites

Ik krijg nog steeds foutmelding 510 Ik heb Capicom verwijderd en opnieuw geinstalleerd, ook heb ik de certificaten vernieuwd, echter zonder resultaat. Ik begin te vrezen dat ik de harde schijf zal moeten formateren, of niet? alleszins al oprechte dank voor de gedane moeite :-)

Link naar reactie
Delen op andere sites

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.