Ga naar inhoud

Fout melding explore.exe "klasse is niet geregistreerd"


Gast Diizyx

Aanbevolen berichten

hallo,

ik heb sinds kort een probleem.

als ik in mijn mappen wil gaan dan komt er deze fout melding

(kijk de bijlagen)

post-40821-1417705237,9324_thumb.jpg

dit is zo bij mijn document, updates, configuratiescherm,...

het internet en games werken nog correct ik kan nog dinge opslaan en openen alleen ik kan niet meer mijn mappen openen.

iemand heeft me gezegt dat het een fout is in mijn register, maar hoe los ik dit op?

systeem herstel heb ik al gedaan maar dat hielp niks dus heb ik dit ongedaan gemaakt.

Mvg,

Lennert

Link naar reactie
Delen op andere sites

We zullen eerst eens nagaan of malware of virussen de oorzaak zijn van je probleem.

1. Download HijackThis. (klik er op)

Klik op HijackThis.msi en de download start automatisch na 5 seconden.

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere pc en het bestand met een usb stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable (HijackThis.exe) downloaden.

Sla deze op in een nieuwe map op de C schijf (bvb C:\hijackthis) en start hijackthis dan vanaf deze map.

De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)


3. Na het plaatsen van je logje wordt dit door een expert (Kape of Kweezie Wabbit) nagekeken en begeleidt hij jou verder door het ganse proces.

Tip!

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.

Link naar reactie
Delen op andere sites

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:56:07, on 24/12/2012

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v9.00 (9.00.8112.16457)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\Steam\Steam.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\SplitMediaLabs\XSplit\XSplit.Core.exe

C:\Windows\SysWOW64\conime.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silent

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: vToolbarUpdater13.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 7400 bytes

Link naar reactie
Delen op andere sites

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

Klik hier

2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.

3. Dubbelklik op "Combofix.exe" om de tool te starten.

4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.

Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion", herstart dan de computer.

5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

ComboFix 12-12-20.02 - user1 21/12/2012 22:13:22.1.4 - x64

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.4094.2215 [GMT 1:00]

Gestart vanuit: c:\users\user1\Desktop\ComboFix.exe

AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}

SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-11-21 to 2012-12-21 ))))))))))))))))))))))))))))))

.

.

2012-12-21 21:09 . 2012-12-21 21:11 -------- d-----w- C:\32788R22FWJFW

2012-12-21 19:49 . 2012-12-21 19:49 76232 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9A914D2-BB3B-4429-B195-B97C62BCAEDF}\offreg.dll

2012-12-21 19:26 . 2012-11-01 21:55 24064 ----a-w- c:\windows\zoek-delete.exe

2012-12-21 19:02 . 2007-08-13 12:51 446464 ----a-w- c:\windows\SysWow64\wmvdmoe.dll

2012-12-21 19:01 . 2012-12-21 19:01 -------- d-----w- c:\programdata\PY_Software

2012-12-21 19:01 . 2012-12-21 19:14 -------- d-----w- c:\program files\Webcam Software

2012-12-21 17:02 . 2012-12-21 17:16 -------- d-----w- c:\users\user1\Doctor Web

2012-12-21 16:19 . 2012-12-21 17:24 -------- d-----w- c:\program files (x86)\Common Files\PC Tools

2012-12-21 16:19 . 2012-12-21 16:19 -------- d-----w- c:\programdata\PC Tools

2012-12-21 16:19 . 2012-12-21 16:19 -------- d-----w- c:\users\user1\AppData\Roaming\Product_RM

2012-12-21 15:48 . 2012-12-21 15:48 -------- d-----w- c:\program files\Fighters

2012-12-21 09:46 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B9A914D2-BB3B-4429-B195-B97C62BCAEDF}\mpengine.dll

2012-12-19 13:03 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-12-19 12:38 . 2012-12-19 12:38 -------- d-----w- c:\users\user1\AppData\Roaming\Malwarebytes

2012-12-19 12:38 . 2012-12-19 12:38 -------- d-----w- c:\programdata\Malwarebytes

2012-12-19 12:38 . 2012-12-19 12:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-12-19 12:38 . 2012-09-29 18:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-12-18 23:41 . 2012-12-18 23:41 -------- d-----w- c:\users\user1\AppData\Local\ezvid,_inc

2012-12-18 23:38 . 2012-09-16 14:14 143248 ----a-w- c:\windows\SysWow64\VisioForge_YUV2RGB.ax

2012-12-18 23:38 . 2012-09-16 14:14 2287504 ----a-w- c:\windows\SysWow64\VisioForge_Video_Resize.ax

2012-12-18 23:38 . 2012-09-16 14:14 1727888 ----a-w- c:\windows\SysWow64\VisioForge_Video_Mixer.ax

2012-12-18 23:38 . 2012-09-16 14:14 155024 ----a-w- c:\windows\SysWow64\VisioForge_RGB2YUV.ax

2012-12-18 23:38 . 2012-09-16 14:14 175504 ----a-w- c:\windows\SysWow64\VisioForge_MediaBridge_WPF_35.ax

2012-12-18 23:38 . 2012-12-18 23:36 751141 ----a-w- c:\windows\unins000.exe

2012-12-18 23:38 . 2012-11-16 10:14 216064 ----a-w- c:\windows\SysWow64\LAGARITH.DLL

2012-12-18 23:38 . 2012-09-16 14:14 121232 ----a-w- c:\windows\SysWow64\VisioForge_Screen_Capture.ax

2012-12-18 23:38 . 2012-09-16 14:14 138640 ----a-w- c:\windows\SysWow64\VisioForge_Dump.ax

2012-12-18 23:38 . 2012-12-18 23:38 -------- d-----w- c:\program files (x86)\ezvid

2012-12-17 03:03 . 2012-12-19 12:28 -------- d-----w- C:\Fraps

2012-12-17 01:32 . 2012-12-20 01:15 -------- d-----w- c:\program files (x86)\XZONE REACTOR Application

2012-12-16 17:09 . 2012-12-16 17:09 -------- d-----w- c:\program files (x86)\WB Games

2012-12-16 16:45 . 2012-12-16 16:45 -------- d-----w- c:\programdata\%Installer_PublisherName%

2012-12-13 15:26 . 2012-11-14 05:53 96768 ----a-w- c:\windows\system32\mshtmled.dll

2012-12-12 15:14 . 2012-09-28 16:34 1210368 ----a-w- c:\windows\system32\kernel32.dll

2012-12-11 16:34 . 2012-12-11 16:34 -------- d-----w- c:\users\user1\AppData\Roaming\Theta

2012-12-11 16:15 . 2012-12-11 16:27 -------- d-----w- c:\program files (x86)\Assassins Creed III

2012-12-05 14:17 . 2012-12-05 14:17 -------- d-----w- c:\program files (x86)\Common Files\Skype

2012-11-29 16:23 . 2012-11-29 16:23 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1610B947-7E69-4175-A3CB-E103214D4381}\gapaengine.dll

2012-11-26 16:12 . 2009-11-04 04:49 33280 ----a-w- c:\windows\system32\drivers\nl-NL\http.sys.mui

2012-11-26 16:12 . 2012-02-29 14:06 1556480 ----a-w- c:\windows\system32\DWrite.dll

2012-11-26 16:12 . 2012-02-29 13:41 1069056 ----a-w- c:\windows\SysWow64\DWrite.dll

2012-11-26 16:12 . 2012-03-01 15:39 327680 ----a-w- c:\windows\system32\d3d10_1core.dll

2012-11-26 16:12 . 2012-03-01 15:39 196096 ----a-w- c:\windows\system32\d3d10_1.dll

2012-11-26 16:12 . 2012-03-01 14:46 219648 ----a-w- c:\windows\SysWow64\d3d10_1core.dll

2012-11-26 16:12 . 2012-03-01 14:46 160768 ----a-w- c:\windows\SysWow64\d3d10_1.dll

2012-11-26 16:12 . 2012-02-29 14:40 2002944 ----a-w- c:\windows\system32\d3d10warp.dll

2012-11-26 16:12 . 2012-02-29 14:09 834048 ----a-w- c:\windows\system32\d2d1.dll

2012-11-26 16:12 . 2012-02-29 14:08 1172480 ----a-w- c:\windows\SysWow64\d3d10warp.dll

2012-11-26 16:12 . 2012-02-29 13:44 683008 ----a-w- c:\windows\SysWow64\d2d1.dll

2012-11-26 16:11 . 2010-09-06 18:28 179712 ----a-w- c:\windows\system32\srvsvc.dll

2012-11-26 16:11 . 2010-09-06 18:28 12288 ----a-w- c:\windows\system32\sscore.dll

2012-11-26 16:11 . 2010-09-06 18:27 17920 ----a-w- c:\windows\system32\netevent.dll

2012-11-26 16:11 . 2010-09-06 16:20 9728 ----a-w- c:\windows\SysWow64\sscore.dll

2012-11-26 16:11 . 2010-09-06 16:19 17920 ----a-w- c:\windows\SysWow64\netevent.dll

2012-11-26 16:11 . 2011-03-12 22:52 1653760 ----a-w- c:\windows\system32\XpsPrint.dll

2012-11-26 16:11 . 2011-03-12 21:55 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll

2012-11-26 03:55 . 2012-11-26 03:55 -------- d-----w- c:\program files\Windows Portable Devices

2012-11-26 03:55 . 2012-11-26 03:55 -------- d-----w- c:\program files (x86)\Windows Portable Devices

2012-11-26 03:55 . 2012-11-26 03:55 -------- d-----w- c:\windows\SysWow64\spool

2012-11-26 03:54 . 2012-11-26 03:54 -------- d-----w- c:\windows\system32\WindowsPowerShell

2012-11-26 02:53 . 2010-02-24 09:26 294912 ----a-w- c:\windows\system32\browserchoice.exe

2012-11-26 02:50 . 2012-11-26 02:50 222208 ----a-w- c:\windows\system32\msls31.dll

2012-11-26 02:48 . 2012-11-26 02:48 979456 ----a-w- c:\windows\SysWow64\MFH264Dec.dll

2012-11-26 02:47 . 2012-11-26 02:47 3584 ----a-w- c:\windows\system32\drivers\nl-NL\dxgkrnl.sys.mui

2012-11-26 02:36 . 2010-02-20 23:15 32768 ----a-w- c:\windows\system32\nshhttp.dll

2012-11-26 02:36 . 2010-02-20 23:06 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll

2012-11-26 02:36 . 2010-02-20 21:30 620032 ----a-w- c:\windows\system32\drivers\http.sys

2012-11-26 02:36 . 2010-02-20 23:14 33792 ----a-w- c:\windows\system32\httpapi.dll

2012-11-26 02:36 . 2010-02-20 23:05 30720 ----a-w- c:\windows\SysWow64\httpapi.dll

2012-11-26 02:26 . 2009-10-09 21:56 2048 ----a-w- c:\windows\SysWow64\winrsmgr.dll

2012-11-26 02:26 . 2009-10-09 21:35 2048 ----a-w- c:\windows\system32\winrsmgr.dll

2012-11-26 02:26 . 2009-10-09 21:35 13312 ----a-w- c:\windows\system32\wsmplpxy.dll

2012-11-26 02:26 . 2009-10-09 21:34 13312 ----a-w- c:\windows\system32\winrssrv.dll

2012-11-26 02:26 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\wsmplpxy.dll

2012-11-26 02:26 . 2009-10-09 21:56 10240 ----a-w- c:\windows\SysWow64\winrssrv.dll

2012-11-26 02:23 . 2009-09-10 02:05 103424 ----a-w- c:\windows\system32\UIAnimation.dll

2012-11-26 02:23 . 2009-09-10 02:00 92672 ----a-w- c:\windows\SysWow64\UIAnimation.dll

2012-11-26 02:23 . 2009-09-10 02:06 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll

2012-11-26 02:23 . 2009-09-10 02:07 3815424 ----a-w- c:\windows\system32\UIRibbon.dll

2012-11-26 02:23 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll

2012-11-26 02:23 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\SysWow64\UIRibbon.dll

2012-11-25 20:48 . 2012-11-25 20:48 -------- d-----w- c:\programdata\VirtualizedApplications

2012-11-25 18:56 . 2009-09-10 15:27 1486848 ----a-w- c:\program files\Windows Media Player\setup_wm.exe

2012-11-25 18:56 . 2009-09-10 14:58 1418752 ----a-w- c:\program files (x86)\Windows Media Player\setup_wm.exe

2012-11-25 18:56 . 2009-09-10 15:27 372736 ----a-w- c:\windows\system32\unregmp2.exe

2012-11-25 18:56 . 2009-09-10 14:58 310784 ----a-w- c:\windows\SysWow64\unregmp2.exe

2012-11-25 18:54 . 2011-02-22 14:13 288768 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2012-11-25 18:54 . 2011-02-22 14:47 479744 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2012-11-25 18:54 . 2011-02-22 13:53 1149440 ----a-w- c:\windows\system32\FntCache.dll

2012-11-25 18:54 . 2012-09-25 16:31 91648 ----a-w- c:\windows\system32\synceng.dll

2012-11-25 18:54 . 2012-09-25 16:19 75776 ----a-w- c:\windows\SysWow64\synceng.dll

2012-11-25 18:54 . 2012-03-01 11:01 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat

2012-11-25 18:54 . 2012-03-01 11:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

2012-11-25 18:46 . 2012-11-25 18:46 -------- d-----r- C:\MSOCache

2012-11-25 18:45 . 2010-08-26 17:42 1927680 ----a-w- c:\windows\system32\gameux.dll

2012-11-25 18:45 . 2010-08-26 16:34 1696256 ----a-w- c:\windows\SysWow64\gameux.dll

2012-11-25 18:45 . 2011-03-03 15:59 32256 ----a-w- c:\windows\system32\Apphlpdm.dll

2012-11-25 18:45 . 2011-03-03 15:40 28672 ----a-w- c:\windows\SysWow64\Apphlpdm.dll

2012-11-25 18:45 . 2011-03-03 14:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

2012-11-25 18:45 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\SysWow64\GameUXLegacyGDFs.dll

2012-11-25 18:36 . 2012-12-17 06:02 -------- d-----w- c:\users\user1\AppData\Roaming\SoftGrid Client

2012-11-25 18:36 . 2012-11-25 18:36 -------- d-----w- c:\users\user1\AppData\Local\SoftGrid Client

2012-11-25 18:35 . 2012-11-25 18:35 -------- d-----w- c:\program files\Microsoft Office

2012-11-25 18:35 . 2012-11-25 18:35 -------- d-----w- c:\program files (x86)\Microsoft Application Virtualization Client

2012-11-25 18:35 . 2012-11-25 18:35 -------- d-----w- c:\windows\PCHEALTH

2012-11-25 18:34 . 2012-11-25 19:07 -------- d-----w- c:\users\user1\AppData\Roaming\TP

2012-11-25 18:33 . 2012-12-12 16:43 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-11-25 18:33 . 2012-12-12 16:43 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-11-25 18:33 . 2012-11-25 18:33 -------- d-----w- c:\windows\SysWow64\Macromed

2012-11-25 18:33 . 2012-11-25 18:33 -------- d-----w- c:\windows\system32\Macromed

2012-11-23 22:51 . 2012-11-23 22:51 -------- d-----w- c:\users\user1\AppData\Local\SkypeFx

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-10-26 20:21 . 2012-10-26 20:21 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2012-10-26 20:20 . 2012-10-26 20:21 30568 ----a-w- c:\windows\system32\drivers\avgtpx64.sys

2012-10-11 15:12 . 2012-10-11 15:12 972192 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

2012-10-10 20:23 . 2012-10-10 20:23 1867112 ----a-w- c:\windows\SysWow64\nvcuvenc.dll

2012-10-10 20:23 . 2007-01-22 08:53 18252136 ----a-w- c:\windows\system32\nvd3dumx.dll

2012-10-10 20:23 . 2007-01-22 08:53 1482600 ----a-w- c:\windows\system32\nvdispgenco64.dll

2012-10-10 20:23 . 2012-10-10 20:23 6127464 ----a-w- c:\windows\SysWow64\nvopencl.dll

2012-10-10 20:23 . 2012-10-10 20:23 2574696 ----a-w- c:\windows\SysWow64\nvcuvid.dll

2012-10-10 20:23 . 2012-10-10 20:23 25256296 ----a-w- c:\windows\system32\nvcompiler.dll

2012-10-10 20:23 . 2012-10-10 20:23 7414632 ----a-w- c:\windows\system32\nvopencl.dll

2012-10-10 20:23 . 2007-01-22 08:53 2731880 ----a-w- c:\windows\system32\nvapi64.dll

2012-10-10 20:23 . 2012-10-10 20:23 14922600 ----a-w- c:\windows\system32\nvwgf2umx.dll

2012-10-10 20:23 . 2012-10-10 20:23 9146728 ----a-w- c:\windows\system32\nvcuda.dll

2012-10-10 20:23 . 2012-10-10 20:23 7697768 ----a-w- c:\windows\SysWow64\nvcuda.dll

2012-10-10 20:23 . 2012-10-10 20:23 2218344 ----a-w- c:\windows\system32\nvcuvenc.dll

2012-10-10 20:23 . 2012-10-10 20:23 12501352 ----a-w- c:\windows\SysWow64\nvwgf2um.dll

2012-10-10 20:22 . 2007-01-22 08:53 2428776 ----a-w- c:\windows\SysWow64\nvapi.dll

2012-10-10 20:22 . 2012-10-10 20:22 26331496 ----a-w- c:\windows\system32\nvoglv64.dll

2012-10-10 20:22 . 2007-01-22 08:53 1760104 ----a-w- c:\windows\system32\nvdispco64.dll

2012-10-10 20:22 . 2007-01-22 08:53 15309160 ----a-w- c:\windows\SysWow64\nvd3dum.dll

2012-10-10 20:22 . 2012-10-10 20:22 2747240 ----a-w- c:\windows\system32\nvcuvid.dll

2012-10-10 20:22 . 2012-10-10 20:22 19906920 ----a-w- c:\windows\SysWow64\nvoglv32.dll

2012-10-10 20:22 . 2012-10-10 20:22 13443944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2012-10-10 20:22 . 2012-10-10 20:22 17559912 ----a-w- c:\windows\SysWow64\nvcompiler.dll

2012-10-09 18:14 . 2012-10-09 18:14 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-09 18:14 . 2012-10-09 18:14 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-10-09 18:14 . 2012-10-09 18:14 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-10-02 19:51 . 2007-01-22 08:56 3293544 ----a-w- c:\windows\system32\nvsvc64.dll

2012-10-02 19:51 . 2007-01-22 08:56 6200680 ----a-w- c:\windows\system32\nvcpl.dll

2012-10-02 19:50 . 2007-01-22 08:56 891240 ----a-w- c:\windows\system32\nvvsvc.exe

2012-10-02 19:50 . 2007-01-22 08:56 63336 ----a-w- c:\windows\system32\nvshext.dll

2012-10-02 19:50 . 2007-01-22 08:56 2557800 ----a-w- c:\windows\system32\nvsvcr.dll

2012-10-02 19:50 . 2007-01-22 08:56 118120 ----a-w- c:\windows\system32\nvmctray.dll

2012-10-02 12:15 . 2012-10-02 12:15 430952 ----a-w- c:\windows\SysWow64\nvStreaming.exe

.

<pre>
c:\program files (x86)\XZONE REACTOR Application\XZONE REACTOR Application .exe
</pre>

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1555968]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2012-12-04 1354736]

"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-10-24 963984]

"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [N/A]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [N/A]

"ROC_roc_ssl_v12"="c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" [N/A]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"mixer8"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

@="Service"

.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

Themes

.

Inhoud van de 'Gedeelde Taken' map

.

2012-12-21 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-25 16:43]

.

2012-12-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2007-02-13 18:30]

.

2012-12-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2007-02-13 18:30]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 1289704]

"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]

.

------- Bijkomende Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.google.com

mLocal Page = c:\windows\SysWOW64\blank.htm

TCP: DhcpNameServer = 195.130.130.131 192.168.123.254

.

- - - - ORPHANS VERWIJDERD - - - -

.

SafeBoot-WudfPf

SafeBoot-WudfRd

.

.

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]

@Denied: (A 2) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]

@="Shockwave Flash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]

@Denied: (A 2) (Everyone)

@=""

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]

@="FlashBroker"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]

"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\

.

Voltooingstijd: 2012-12-21 22:23:56

ComboFix-quarantined-files.txt 2012-12-21 21:23

.

Pre-Run: 60.920.909.824 bytes beschikbaar

Post-Run: 60.068.212.736 bytes beschikbaar

.

- - End Of File - - C39CAEE1E0436409368FBD0D437734D9

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.