Ga naar inhoud

benny123snow

Lid
  • Items

    16
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door benny123snow

  1. Als ik alle addons verwijderde veranderde niks maar als ik bij extensies Onetab 1.0 uitschakelde waren de reclames weg. Alvast bedankt. Als ik niks meer moet doen nu zal ik het als opgelost markeren.
  2. Hellaas is de reclame er nog steeds. # AdwCleaner v2.006 - Verslag gemaakt op 05/11/2012 om 11:40:58 # Geactualiseerd op 30/10/2012 door Xplode # Besturingssysteem : Windows Vista Home Basic Service Pack 2 (32 bits) # Gebruiker : gebruiker - PC_VAN_GEBRUIKE # Opstarten Modus : Normale modus # Gelanceerd vanaf : C:\Users\gebruiker\oude mijn documenten\Desktop\adwcleaner.exe # Optie [Verwijderen] ***** [Diensten] ***** ***** [Files / Mappen] ***** File Verwijdert : C:\Program Files\Mozilla Firefox\plugins\npdnu.dll File Verwijdert : C:\Program Files\Mozilla Firefox\plugins\npdnu.xpt File Verwijdert : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll File Verwijdert : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.xpt File Verwijdert : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml File Verwijdert : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml File Verwijdert : C:\Program Files\Mozilla Firefox\searchplugins\SearchResults.xml File Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\searchplugins\Conduit.xml File Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\searchplugins\SearchResults.xml Map Verwijdert : C:\Program Files\AVG Secure Search Map Verwijdert : C:\Program Files\Common Files\AVG Secure Search Map Verwijdert : C:\Program Files\Common Files\Software Update Utility Map Verwijdert : C:\Program Files\Conduit Map Verwijdert : C:\ProgramData\AVG Secure Search Map Verwijdert : C:\ProgramData\boost_interprocess Map Verwijdert : C:\ProgramData\InstallMate Map Verwijdert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ilivid Map Verwijdert : C:\ProgramData\Premium Map Verwijdert : C:\Users\benny\AppData\LocalLow\boost_interprocess Map Verwijdert : C:\Users\benny\AppData\LocalLow\Conduit Map Verwijdert : C:\Users\benny\AppData\LocalLow\PriceGong Map Verwijdert : C:\Users\gebruiker\AppData\Local\Conduit Map Verwijdert : C:\Users\gebruiker\AppData\Local\Ilivid Player Map Verwijdert : C:\Users\gebruiker\AppData\LocalLow\AVG Secure Search Map Verwijdert : C:\Users\gebruiker\AppData\LocalLow\boost_interprocess Map Verwijdert : C:\Users\gebruiker\AppData\LocalLow\Conduit Map Verwijdert : C:\Users\gebruiker\AppData\LocalLow\searchquband Map Verwijdert : C:\Users\gebruiker\AppData\LocalLow\Searchqutoolbar Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Media Finder Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\Conduit Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\ConduitCommon Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\SweetIMToolbarData Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\WinampToolbarData Map Verwijdert : C:\Users\gebruiker\AppData\Roaming\OpenCandy ***** [Register] ***** Sleutel Verwijdert : HKCU\Software\AppDataLow\Software Sleutel Verwijdert : HKCU\Software\AVG Secure Search Sleutel Verwijdert : HKCU\Software\BrowserCompanion Sleutel Verwijdert : HKCU\Software\Conduit Sleutel Verwijdert : HKCU\Software\MediaFinder Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Crossrider Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com Sleutel Verwijdert : HKCU\Software\Softonic Sleutel Verwijdert : HKCU\Software\StartSearch Sleutel Verwijdert : HKLM\Software\AVG Secure Search Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Conduit.Engine Sleutel Verwijdert : HKLM\SOFTWARE\Classes\dnUpdate Sleutel Verwijdert : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Sleutel Verwijdert : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Sleutel Verwijdert : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Sleutel Verwijdert : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{6427058B-217C-4C7F-A6CE-C7934C0BDCEB} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Prod.cap Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Toolbar.CT2102399 Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Toolbar.CT2233703 Sleutel Verwijdert : HKLM\SOFTWARE\Classes\Toolbar.CT2790392 Sleutel Verwijdert : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Sleutel Verwijdert : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Sleutel Verwijdert : HKLM\Software\Conduit Sleutel Verwijdert : HKLM\SOFTWARE\Google\Chrome\Extensions\clbfjfbnelcflpgpklppgplejolacbej Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Crossrider Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility ***** [browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Het register bevat geen enkele ongeoorloofde invoer. -\\ Mozilla Firefox v16.0.2 (nl) Profielnaam : default File : C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\prefs.js C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\user.js ... Verwijdert ! Verwijdert : user_pref("CT2233703..clientLogIsEnabled", false); Verwijdert : user_pref("CT2233703..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...] Verwijdert : user_pref("CT2233703..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...] Verwijdert : user_pref("CT2233703.ALLOW_SHOWING_HIDDEN_TOOLBAR", false); Verwijdert : user_pref("CT2233703.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Verwijdert : user_pref("CT2233703.BrowserCompStateIsOpen_129690223998609054", true); Verwijdert : user_pref("CT2233703.CTID", "CT2233703"); Verwijdert : user_pref("CT2233703.CurrentServerDate", "2-3-2012"); Verwijdert : user_pref("CT2233703.DSInstall", true); Verwijdert : user_pref("CT2233703.DialogsAlignMode", "LTR"); Verwijdert : user_pref("CT2233703.DialogsGetterLastCheckTime", "Thu Mar 01 2012 08:23:15 GMT+0100 (Romance (stand[...] Verwijdert : user_pref("CT2233703.DownloadReferralCookieData", ""); Verwijdert : user_pref("CT2233703.EMailNotifierCheckInterval", "5"); Verwijdert : user_pref("CT2233703.EMailNotifierLabelLength", 5); Verwijdert : user_pref("CT2233703.EMailNotifierPollDate", "Fri Mar 02 2012 20:14:51 GMT+0100 (Romance (standaardt[...] Verwijdert : user_pref("CT2233703.EMailNotifierSound", "NONE"); Verwijdert : user_pref("CT2233703.FirstServerDate", "1-3-2012"); Verwijdert : user_pref("CT2233703.FirstTime", true); Verwijdert : user_pref("CT2233703.FirstTimeFF3", true); Verwijdert : user_pref("CT2233703.FixPageNotFoundErrors", true); Verwijdert : user_pref("CT2233703.GroupingServerCheckInterval", 1440); Verwijdert : user_pref("CT2233703.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Verwijdert : user_pref("CT2233703.HPInstall", true); Verwijdert : user_pref("CT2233703.HasUserGlobalKeys", true); Verwijdert : user_pref("CT2233703.HomePageProtectorEnabled", false); Verwijdert : user_pref("CT2233703.HomepageBeforeUnload", "hxxp://www.google.be/"); Verwijdert : user_pref("CT2233703.Initialize", true); Verwijdert : user_pref("CT2233703.InitializeCommonPrefs", true); Verwijdert : user_pref("CT2233703.InstallationAndCookieDataSentCount", 3); Verwijdert : user_pref("CT2233703.InstallationId", "ConduitNSISIntegration"); Verwijdert : user_pref("CT2233703.InstallationType", "ConduitXPEIntegration"); Verwijdert : user_pref("CT2233703.InstalledDate", "Thu Mar 01 2012 08:23:15 GMT+0100 (Romance (standaardtijd))"); Verwijdert : user_pref("CT2233703.InvalidateCache", false); Verwijdert : user_pref("CT2233703.IsAlertDBUpdated", true); Verwijdert : user_pref("CT2233703.IsGrouping", false); Verwijdert : user_pref("CT2233703.IsInitSetupIni", true); Verwijdert : user_pref("CT2233703.IsMulticommunity", false); Verwijdert : user_pref("CT2233703.IsOpenThankYouPage", false); Verwijdert : user_pref("CT2233703.IsOpenUninstallPage", true); Verwijdert : user_pref("CT2233703.IsProtectorsInit", true); Verwijdert : user_pref("CT2233703.LanguagePackLastCheckTime", "Fri Mar 02 2012 09:32:07 GMT+0100 (Romance (standa[...] Verwijdert : user_pref("CT2233703.LanguagePackReloadIntervalMM", 1440); Verwijdert : user_pref("CT2233703.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...] Verwijdert : user_pref("CT2233703.LastLogin_3.10.0.1", "Fri Mar 02 2012 18:49:25 GMT+0100 (Romance (standaardtijd[...] Verwijdert : user_pref("CT2233703.LatestVersion", "3.9.0.3"); Verwijdert : user_pref("CT2233703.Locale", "en"); Verwijdert : user_pref("CT2233703.MCDetectTooltipHeight", "83"); Verwijdert : user_pref("CT2233703.MCDetectTooltipShow", false); Verwijdert : user_pref("CT2233703.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Verwijdert : user_pref("CT2233703.MCDetectTooltipWidth", "295"); Verwijdert : user_pref("CT2233703.MyStuffEnabledAtInstallation", true); Verwijdert : user_pref("CT2233703.OriginalFirstVersion", "3.10.0.1"); Verwijdert : user_pref("CT2233703.RadioIsPodcast", false); Verwijdert : user_pref("CT2233703.RadioLastCheckTime", "Fri Mar 02 2012 09:32:07 GMT+0100 (Romance (standaardtijd[...] Verwijdert : user_pref("CT2233703.RadioLastUpdateIPServer", "3"); Verwijdert : user_pref("CT2233703.RadioLastUpdateServer", "129141247792900000"); Verwijdert : user_pref("CT2233703.RadioMediaID", "11027882"); Verwijdert : user_pref("CT2233703.RadioMediaType", "Media Player"); Verwijdert : user_pref("CT2233703.RadioMenuSelectedID", "EBRadioMenu_CT223370311027882"); Verwijdert : user_pref("CT2233703.RadioShrinkedFromSetup", false); Verwijdert : user_pref("CT2233703.RadioStationName", "DANCE%20radio"); Verwijdert : user_pref("CT2233703.RadioStationURL", "hxxp://www.abradio.cz/asx/danceradio32.asx"); Verwijdert : user_pref("CT2233703.SavedHomepage", "hxxp://www.google.be/"); Verwijdert : user_pref("CT2233703.SearchCaption", "4shared.com Customized Web Search"); Verwijdert : user_pref("CT2233703.SearchEngineBeforeUnload", "4shared.com Customized Web Search"); Verwijdert : user_pref("CT2233703.SearchFromAddressBarIsInit", true); Verwijdert : user_pref("CT2233703.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT223[...] Verwijdert : user_pref("CT2233703.SearchInNewTabEnabled", true); Verwijdert : user_pref("CT2233703.SearchInNewTabIntervalMM", 1440); Verwijdert : user_pref("CT2233703.SearchInNewTabLastCheckTime", "Fri Mar 02 2012 09:32:04 GMT+0100 (Romance (stan[...] Verwijdert : user_pref("CT2233703.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...] Verwijdert : user_pref("CT2233703.SearchProtectorEnabled", true); Verwijdert : user_pref("CT2233703.SearchProtectorToolbarDisabled", false); Verwijdert : user_pref("CT2233703.SendProtectorDataViaLogin", true); Verwijdert : user_pref("CT2233703.ServiceMapLastCheckTime", "Fri Mar 02 2012 09:32:06 GMT+0100 (Romance (standaar[...] Verwijdert : user_pref("CT2233703.SettingsLastCheckTime", "Fri Mar 02 2012 19:02:48 GMT+0100 (Romance (standaardt[...] Verwijdert : user_pref("CT2233703.SettingsLastUpdate", "1327080125"); Verwijdert : user_pref("CT2233703.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2233703&SearchSource=13"); Verwijdert : user_pref("CT2233703.ThirdPartyComponentsInterval", 504); Verwijdert : user_pref("CT2233703.ThirdPartyComponentsLastCheck", "Thu Mar 01 2012 08:23:13 GMT+0100 (Romance (st[...] Verwijdert : user_pref("CT2233703.ThirdPartyComponentsLastUpdate", "1312887586"); Verwijdert : user_pref("CT2233703.ToolbarShrinkedFromSetup", false); Verwijdert : user_pref("CT2233703.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2233703"); Verwijdert : user_pref("CT2233703.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...] Verwijdert : user_pref("CT2233703.UserID", "UN94581887549920360"); Verwijdert : user_pref("CT2233703.ValidationData_Search", 0); Verwijdert : user_pref("CT2233703.ValidationData_Toolbar", 2); Verwijdert : user_pref("CT2233703.WeatherNetwork", ""); Verwijdert : user_pref("CT2233703.WeatherPollDate", "Fri Mar 02 2012 20:10:31 GMT+0100 (Romance (standaardtijd))"[...] Verwijdert : user_pref("CT2233703.WeatherUnit", "C"); Verwijdert : user_pref("CT2233703.alertChannelId", "631527"); Verwijdert : user_pref("CT2233703.approveUntrustedApps", false); Verwijdert : user_pref("CT2233703.autoDisableScopes", -1); Verwijdert : user_pref("CT2233703.backendstorage.cb_firstuse0100", "31"); Verwijdert : user_pref("CT2233703.backendstorage.cb_user_id_000", "43423334383039383837333130315F46697265666F78")[...] Verwijdert : user_pref("CT2233703.backendstorage.cbfirsttime", "546875204D617220303120323031322030383A32333A32362[...] Verwijdert : user_pref("CT2233703.backendstorage.shoppingapp.gk.exipres", "547565204D617220303620323031322030383A[...] Verwijdert : user_pref("CT2233703.backendstorage.shoppingapp.gk.geolocation", "62656C6769756D"); Verwijdert : user_pref("CT2233703.backendstorage.url_history0001", "687474703A2F2F7777772E636F757469652E636F6D2F6[...] Verwijdert : user_pref("CT2233703.components.1000082", false); Verwijdert : user_pref("CT2233703.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...] Verwijdert : user_pref("CT2233703.globalFirstTimeInfoLastCheckTime", "Thu Mar 01 2012 08:23:15 GMT+0100 (Romance [...] Verwijdert : user_pref("CT2233703.homepageProtectorEnableByLogin", true); Verwijdert : user_pref("CT2233703.initDone", true); Verwijdert : user_pref("CT2233703.isAppTrackingManagerOn", true); Verwijdert : user_pref("CT2233703.isFirstRadioInstallation", false); Verwijdert : user_pref("CT2233703.myStuffEnabled", true); Verwijdert : user_pref("CT2233703.myStuffPublihserMinWidth", 400); Verwijdert : user_pref("CT2233703.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...] Verwijdert : user_pref("CT2233703.myStuffServiceIntervalMM", 1440); Verwijdert : user_pref("CT2233703.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...] Verwijdert : user_pref("CT2233703.navigateToUrlOnSearch", false); Verwijdert : user_pref("CT2233703.revertSettingsEnabled", true); Verwijdert : user_pref("CT2233703.searchProtectorDialogDelayInSec", 10); Verwijdert : user_pref("CT2233703.searchProtectorEnableByLogin", true); Verwijdert : user_pref("CT2233703.testingCtid", ""); Verwijdert : user_pref("CT2233703.toolbarAppMetaDataLastCheckTime", "Fri Mar 02 2012 09:32:07 GMT+0100 (Romance ([...] Verwijdert : user_pref("CT2233703.toolbarContextMenuLastCheckTime", "Thu Mar 01 2012 08:23:24 GMT+0100 (Romance ([...] Verwijdert : user_pref("CT2233703.usagesFlag", 2); Verwijdert : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2233703&Search[...] Verwijdert : user_pref("CommunityToolbar.ConduitSearchList", "4shared.com Customized Web Search"); Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2233703/CT2233703[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/518308/514178/BE", "\"0\"")[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/631527/627389/BE", "\"0\"")[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2233703", [...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2233703",[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...] Verwijdert : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cde[...] Verwijdert : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\gebruiker\\AppData\\Roaming\\Mozill[...] Verwijdert : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.10.0.1"); Verwijdert : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.my-tools-app.com/?babsrc=h[...] Verwijdert : user_pref("CommunityToolbar.ToolbarsList", "CT2233703"); Verwijdert : user_pref("CommunityToolbar.ToolbarsList2", "CT2233703"); Verwijdert : user_pref("CommunityToolbar.ToolbarsList4", "CT2233703"); Verwijdert : user_pref("CommunityToolbar.globalUserId", "3bc9ee61-2e72-4ea8-8b84-a0c135836397"); Verwijdert : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Verwijdert : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Verwijdert : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2233703"); Verwijdert : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Mar 01 2012 08:23:1[...] Verwijdert : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Verwijdert : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Mar 02 2012 13:04:41 GMT+010[...] Verwijdert : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Verwijdert : user_pref("CommunityToolbar.notifications.locale", "en"); Verwijdert : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Verwijdert : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Mar 02 2012 09:32:06 GMT+0100 (R[...] Verwijdert : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Verwijdert : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Verwijdert : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Verwijdert : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Verwijdert : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Verwijdert : user_pref("CommunityToolbar.notifications.userId", "887eb01d-af7c-4647-90a2-3d85f329abea"); Verwijdert : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.be/"); Verwijdert : user_pref("CommunityToolbar.originalSearchEngine", "MyTools"); Verwijdert : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\10.0.0.7"); Verwijdert : user_pref("browser.search.defaultenginename", "AVG Secure Search"); Verwijdert : user_pref("browser.search.defaultthis.engineName", "4shared.com Customized Web Search"); Verwijdert : user_pref("extensions.crossriderapp435.435.active", true); Verwijdert : user_pref("extensions.crossriderapp435.435.affid", "0"); Verwijdert : user_pref("extensions.crossriderapp435.435.backgroundjs", "\n\nfunction buttonClick() { \n \[...] Verwijdert : user_pref("extensions.crossriderapp435.435.backgroundver", 8); Verwijdert : user_pref("extensions.crossriderapp435.435.certdomaininstaller", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GM[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.value", "%221330775647%22"); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_geo.expiration", "Tue Jul 17 2012 21:11:07 GM[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_geo.value", "%7B%22geoplugin_request%22%3A%22[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 0[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.value", "%2214974%22"); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.value", "%2222312%22"); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.expiration", "Fri Feb 01 2030 00:00:00 GM[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.value", "435"); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.expiration", "Fri Feb 01 2030 [...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.value", "14969"); Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.expiration", "Fri Feb 01 2030 00:00:00[...] Verwijdert : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.value", "%222993%22"); Verwijdert : user_pref("extensions.crossriderapp435.435.description", "Premiumplay Codec check"); Verwijdert : user_pref("extensions.crossriderapp435.435.domain", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.emailsig", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.exposesites", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.fbremoteurl", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.group", 0); Verwijdert : user_pref("extensions.crossriderapp435.435.homepage", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.iframe", false); Verwijdert : user_pref("extensions.crossriderapp435.435.js", "\n\n//------------------ PLUGIN app_435_specific S[...] Verwijdert : user_pref("extensions.crossriderapp435.435.name", "Codec-V"); Verwijdert : user_pref("extensions.crossriderapp435.435.premium", true); Verwijdert : user_pref("extensions.crossriderapp435.435.publisher", "Premiumplay"); Verwijdert : user_pref("extensions.crossriderapp435.435.settingsurl", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.thankyou", ""); Verwijdert : user_pref("extensions.crossriderapp435.435.ver", 51); Verwijdert : user_pref("extensions.crossriderapp435.apps", "435"); Verwijdert : user_pref("extensions.crossriderapp435.bic", "135d8687754d7b353d6563258c046b3e"); Verwijdert : user_pref("extensions.crossriderapp435.cid", 435); Verwijdert : user_pref("extensions.crossriderapp435.firstrun", false); Verwijdert : user_pref("extensions.crossriderapp435.hadappinstalled", true); Verwijdert : user_pref("extensions.crossriderapp435.installationdate", 1330775619); Verwijdert : user_pref("extensions.crossriderapp435.jsver", 3); Verwijdert : user_pref("extensions.crossriderapp435.lastcheck", 22370878); Verwijdert : user_pref("extensions.crossriderapp435.lastcheckitem", 22370939); Verwijdert : user_pref("extensions.crossriderapp435.misc.lastBgWorkerTimer", "1342256759685"); Verwijdert : user_pref("extensions.crossriderapp435.misc.lastDomWorkerTimer", "1342256759682"); Profielnaam : default File : C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\prefs.js Verwijdert : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\10.0.0.7"); Verwijdert : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid=%7Bacc85055-ae31-4d1c-b67d-0244f9c4dd91%[...] -\\ Google Chrome v [Onmogelijk de versie te verkrijgen] File : C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] De file bevat geen enkele ongeoorloofde invoer. File : C:\Users\benny\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] De file bevat geen enkele ongeoorloofde invoer. -\\ Opera v12.2.1578.0 File : C:\Users\gebruiker\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] De file bevat geen enkele ongeoorloofde invoer. ************************* AdwCleaner[s1].txt - [27485 octets] - [05/11/2012 11:40:58] ########## EOF - C:\AdwCleaner[s1].txt - [27546 octets] ##########
  3. Ik heb eens een foto van mijn scherm gemaakt. Onderaan is de balk te zien met reclame en in het midden staat mijn muispijlje op een onderlijnd woord en dan verschijnt er ook reclame.
  4. Ik heb nog steeds last van reclame. Zou er geen programmaatje voor verantwoordelijk zijn? maar ik kan er niet achter komen hoe het noemt, dan zou ik het kunnen verwijderen of is dit altijd spyware of familie er van.
  5. Hallo Hier is mijn volgende log. Ik heb terug mijn virusscanner uitgezet tijdens het scannen, ik denk dat dit de bedoeling was of moest hij nog aanstaan? ComboFix 12-11-03.02 - gebruiker 03/11/2012 22:19:34.4.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.988.255 [GMT 1:00] Gestart vanuit: c:\users\gebruiker\oude mijn documenten\Desktop\ComboFix.exe gebruikte Opdracht switches :: c:\users\gebruiker\oude mijn documenten\Desktop\CFScript.txt AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((( Bestanden Gemaakt van 2012-10-03 to 2012-11-03 )))))))))))))))))))))))))))))) . . 2012-11-03 21:29 . 2012-11-03 21:29 -------- d-----w- c:\users\gebruiker\AppData\Local\temp 2012-11-03 21:29 . 2012-11-03 21:29 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-11-03 21:29 . 2012-11-03 21:29 -------- d-----w- c:\users\benny\AppData\Local\temp 2012-11-02 14:32 . 2012-11-02 14:32 388096 ----a-r- c:\users\gebruiker\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-10-16 23:21 . 2012-10-16 23:21 -------- d-----w- c:\program files\Common Files\Java 2012-10-16 23:21 . 2012-10-16 23:18 821736 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-10-16 23:19 . 2012-10-16 23:18 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-10-16 13:31 . 2012-10-16 13:31 -------- d-----w- c:\programdata\McAfee 2012-10-16 13:30 . 2012-10-16 13:31 -------- d-----w- c:\program files\Common Files\Adobe 2012-10-11 07:37 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll 2012-10-11 07:36 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll 2012-10-11 07:36 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll 2012-10-11 07:36 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll 2012-10-10 19:03 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-10 19:03 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-10-10 16:29 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll 2012-10-09 18:39 . 2012-10-09 18:39 10220472 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-31 09:54 . 2010-12-07 08:00 1398680 ----a-w- c:\users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent.exe 2012-10-16 23:18 . 2010-11-04 10:05 746984 ----a-w- c:\windows\system32\deployJava1.dll 2012-10-09 18:39 . 2012-04-09 08:02 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-09 18:39 . 2011-05-25 15:47 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-29 18:54 . 2011-03-31 08:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2012-08-24 06:59 . 2012-09-22 12:31 1800704 ----a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51 . 2012-09-22 19:03 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51 . 2012-09-22 12:31 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47 . 2012-09-22 12:31 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47 . 2012-09-22 12:31 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43 . 2012-09-22 19:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2007-03-12 16:59 . 2007-03-12 16:59 299008 ----a-w- c:\program files\navigram_register.exe 2012-10-27 09:14 . 2012-10-27 09:12 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Spotify Web Helper"="c:\users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-09-16 1193176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568] "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-04-27 939872] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "emsisoft anti-malware"="c:\program files\Emsisoft Anti-Malware\a2guard.exe" [2012-09-19 3363240] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk backup=c:\windows\pss\CodeMeter Control Center.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-09-27 06:22 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify] 2012-09-16 14:32 5576408 ----a-w- c:\users\gebruiker\AppData\Roaming\Spotify\spotify.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper] 2012-09-16 14:32 1193176 ----a-w- c:\users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-07-03 07:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:33 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe . R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [x] S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files\Emsisoft Anti-Malware\a2ddax86.sys [x] S2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhoud van de 'Gedeelde Taken' map . 2012-11-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2012-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 17:37] . 2012-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 17:37] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.be/ TCP: DhcpNameServer = 192.168.1.1 DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://ips.poi.de/ips-opdata/layout/fnac/objects/jordan.cab FF - ProfilePath - c:\users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/ FF - ExtSQL: 2012-09-15 16:32; onetab@onetab.net; c:\users\gebruiker\AppData\Roaming\OneTab\xpi FF - ExtSQL: !HIDDEN! 2011-06-14 15:58; belgiumeid@eid.belgium.be; c:\program files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be FF - user.js: network.protocol-handler.warn-external.dnupdate - false FF - user.js: browser.sessionstore.resume_from_crash - false . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-11-03 22:29 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . Voltooingstijd: 2012-11-03 22:31:39 ComboFix-quarantined-files.txt 2012-11-03 21:31 ComboFix2.txt 2012-11-03 20:30 . Pre-Run: 57.143.054.336 bytes beschikbaar Post-Run: 57.103.052.800 bytes beschikbaar . - - End Of File - - 73CE52DBC66250A6A4C4551B31762181
  6. ComboFix 12-11-03.02 - gebruiker 03/11/2012 21:05:36.3.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.32.1043.18.988.377 [GMT 1:00] Gestart vanuit: c:\users\gebruiker\oude mijn documenten\Desktop\ComboFix.exe AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B} SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent.exe.28671.tmp . ---- Voorgaande Run ------- . c:\users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent.exe.8723.tmp c:\windows\$NtUninstallKB56067$ . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_RKHIT -------\Service_RkHit . . (((((((((((((((((((( Bestanden Gemaakt van 2012-10-03 to 2012-11-03 )))))))))))))))))))))))))))))) . . 2012-11-03 20:14 . 2012-11-03 20:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-11-03 20:14 . 2012-11-03 20:14 -------- d-----w- c:\users\benny\AppData\Local\temp 2012-11-03 20:14 . 2012-11-03 20:25 -------- d-----w- c:\users\gebruiker\AppData\Local\temp 2012-11-02 14:32 . 2012-11-02 14:32 388096 ----a-r- c:\users\gebruiker\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-10-16 23:21 . 2012-10-16 23:21 -------- d-----w- c:\program files\Common Files\Java 2012-10-16 23:21 . 2012-10-16 23:18 821736 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-10-16 23:19 . 2012-10-16 23:18 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-10-16 13:31 . 2012-10-16 13:31 -------- d-----w- c:\programdata\McAfee 2012-10-16 13:30 . 2012-10-16 13:31 -------- d-----w- c:\program files\Common Files\Adobe 2012-10-11 07:37 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll 2012-10-11 07:36 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll 2012-10-11 07:36 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll 2012-10-11 07:36 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll 2012-10-10 19:03 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-10 19:03 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-10-10 16:29 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll 2012-10-09 18:39 . 2012-10-09 18:39 10220472 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-31 09:54 . 2010-12-07 08:00 1398680 ----a-w- c:\users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent.exe 2012-10-16 23:18 . 2010-11-04 10:05 746984 ----a-w- c:\windows\system32\deployJava1.dll 2012-10-09 18:39 . 2012-04-09 08:02 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-09 18:39 . 2011-05-25 15:47 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-29 18:54 . 2011-03-31 08:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2012-08-24 06:59 . 2012-09-22 12:31 1800704 ----a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51 . 2012-09-22 19:03 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51 . 2012-09-22 12:31 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47 . 2012-09-22 12:31 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47 . 2012-09-22 12:31 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43 . 2012-09-22 19:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2007-03-12 16:59 . 2007-03-12 16:59 299008 ----a-w- c:\program files\navigram_register.exe 2012-10-27 09:14 . 2012-10-27 09:12 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Spotify Web Helper"="c:\users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-09-16 1193176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568] "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-04-27 939872] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "emsisoft anti-malware"="c:\program files\Emsisoft Anti-Malware\a2guard.exe" [2012-09-19 3363240] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk backup=c:\windows\pss\CodeMeter Control Center.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-09-27 06:22 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify] 2012-09-16 14:32 5576408 ----a-w- c:\users\gebruiker\AppData\Roaming\Spotify\spotify.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper] 2012-09-16 14:32 1193176 ----a-w- c:\users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-07-03 07:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:33 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe . R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [x] S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files\Emsisoft Anti-Malware\a2ddax86.sys [x] S2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhoud van de 'Gedeelde Taken' map . 2012-11-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 18:39] . 2012-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 17:37] . 2012-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 17:37] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.be/ mStart Page = hxxp://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9851 TCP: DhcpNameServer = 192.168.1.1 DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} - hxxp://ips.poi.de/ips-opdata/layout/fnac/objects/jordan.cab FF - ProfilePath - c:\users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B14ad4858-e80b-4be5-bb28-ca541928ed4b%7D&mid=f69962fbde1a47d697d8d16daec1d760-ed30465edeaa12e582872361c9fd847db3e25150&ds=AVG&v=10.0.0.7〈=nl&pr=pr&d=2012-04-27%2009%3A12%3A40&sap=ku&q= FF - ExtSQL: 2012-09-15 16:32; onetab@onetab.net; c:\users\gebruiker\AppData\Roaming\OneTab\xpi FF - ExtSQL: !HIDDEN! 2011-06-14 15:58; belgiumeid@eid.belgium.be; c:\program files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be FF - user.js: extensions.BabylonToolbar_i.id - 00c6435c0000000000000024e8253e93 FF - user.js: extensions.BabylonToolbar_i.hardId - 00c6435c0000000000000024e8253e93 FF - user.js: extensions.BabylonToolbar_i.instlDay - 15351 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:54 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.newTab - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101241 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: network.protocol-handler.warn-external.dnupdate - false FF - user.js: browser.sessionstore.resume_from_crash - false . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-10 - (no file) WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe MSConfigStartUp-beid - c:\program files\Belgium Identity Card\beid35gui.exe MSConfigStartUp-CrossRiderPlugin - c:\program files\CrossriderWebApps\Crossrider.exe MSConfigStartUp-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe MSConfigStartUp-PrivitizeVPN - c:\program files\PrivitizeVPN\PrivitizeVPN.exe MSConfigStartUp-spydig - c:\program files\SpyDig\spydig.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2012-11-03 21:25 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . ------------------------ Andere Aktieve Processen ------------------------ . c:\progra~1\AVG\AVG2012\avgrsx.exe c:\program files\AVG\AVG2012\avgcsrvx.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\AVG\AVG2012\avgfws.exe c:\program files\AVG\AVG2012\avgwdsvc.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Spybot - Search & Destroy\SDWinSec.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\AVG\AVG2012\AVGIDSAgent.exe c:\program files\AVG\AVG2012\avgnsx.exe c:\program files\AVG\AVG2012\avgemcx.exe c:\program files\Google\Update\1.3.21.123\GoogleCrashHandler.exe c:\program files\AVG\AVG2012\avgcsrvx.exe c:\windows\system32\conime.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Voltooingstijd: 2012-11-03 21:30:22 - machine werd herstart ComboFix-quarantined-files.txt 2012-11-03 20:30 . Pre-Run: 57.531.228.160 bytes beschikbaar Post-Run: 57.101.066.240 bytes beschikbaar . - - End Of File - - F933CF925B1836199DEC75B783C8176C
  7. Deze in hijack this heb ik niet verwijderd want dit staat er niet tussen R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = eSnips Search De scan is gebeurt maar er zijn nog altijd woorden onderstreept op website's en dan zie ik reclame. Malwarebytes Anti-Malware 1.65.1.1000 Malwarebytes : Free anti-malware download Databaseversie: v2012.11.02.09 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 gebruiker :: PC_VAN_GEBRUIKE [administrator] 2/11/2012 18:22:50 mbam-log-2012-11-02 (18-22-50).txt Scantype: Snelle scan Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scanopties: P2P Objecten gescand: 219960 Verstreken tijd: 7 minuut/minuten, 21 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Bestanden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) (einde) - - - Updated - - - De advertenties onderaan de websites zijn ook nog aanwezig.
  8. Hallo, Sinds een tijd je heb ik ongewenste reclame op mijn browser. er verschijnt onder aan het scherm reclame en soms ook boven aan het scherm en dan verschijnt er skip this ad. Onder sommige zijn onderstreept en als ik er met mijn muis over ga verschijnt er ook reclame. Mijn computer loopt ook zeer traag dus denk ik dat er veel spyware en zo op staat. Ik plaats alvast een hijack this log. Alvast bedankt Benny Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:44:46, on 2/11/2012 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16450) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\Dwm.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_287.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = eSnips Search R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - URLSearchHook: (no name) - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file) O1 - Hosts: ::1 localhost O2 - BHO: OneTab Add-on - {16ADEA98-D215-4F51-80AF-5E5ED660B9C0} - C:\Users\gebruiker\AppData\Roaming\OneTab\OneTab.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: CrossRider - {A876E312-7D08-401a-B7A6-FAFC5DC2F292} - C:\Program Files\CrossriderWebApps\Crossrider.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [emsisoft anti-malware] "C:\Program Files\Emsisoft Anti-Malware\a2guard.exe" /d=60 O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [spotify Web Helper] "C:\Users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://ips.poi.de/ips-opdata/layout/fnac/objects/jordan.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v1120/Navigram.cab O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Emsisoft Anti-Malware 7.0 - Service (a2AntiMalware) - Emsisoft GmbH - C:\Program Files\Emsisoft Anti-Malware\a2service.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing) -- End of file - 7497 bytes
  9. Ik heb geen meldingen meer gehad dus vermoet ik dat het Trojaantjes weg zijn. Bedankt. Groeten Benny
  10. Emsisoft Emergency Kit - Versie 1.0 Laatste Update: 10/02/2012 18:09:57 Scaninstellingen: Scantype: Diepe Scan Objecten: Geheugen, Sporen, Cookies, C:\ Scan archieven: Aan Heuristieken: Uit ADS Scan: Aan Scan gestart: 10/02/2012 18:10:35 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2637 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2638 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2640 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2641 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2642 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2643 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2644 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2645 Ontdekt: Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:3479 Ontdekt: Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6112 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6113 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6465 Ontdekt: Trace.TrackingCookie.adserv!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:10379 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:10813 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:11166 Ontdekt: Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:12209 Ontdekt: Trace.TrackingCookie.fr.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:12210 Ontdekt: Trace.TrackingCookie.fr.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:16023 Ontdekt: Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17281 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17544 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17545 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19510 Ontdekt: Trace.TrackingCookie.stat.onestat!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19511 Ontdekt: Trace.TrackingCookie.stat.onestat!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19575 Ontdekt: Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19576 Ontdekt: Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19577 Ontdekt: Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19653 Ontdekt: Trace.TrackingCookie.adserv!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19665 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20470 Ontdekt: Trace.TrackingCookie.this.content.served.by.adshuffle.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20821 Ontdekt: Trace.TrackingCookie.track.adform.net!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20885 Ontdekt: Trace.TrackingCookie.track.adform.net!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21176 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21177 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21183 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21302 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21484 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:22909 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:24176 Ontdekt: Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:27612 Ontdekt: Trace.TrackingCookie.d1.openx.org!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:38905 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:39386 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:39403 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43016 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43023 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43024 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43025 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43026 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43061 Ontdekt: Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:48132 Ontdekt: Trace.TrackingCookie.ad.zanox.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51166 Ontdekt: Trace.TrackingCookie.media!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51398 Ontdekt: Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51399 Ontdekt: Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:52863 Ontdekt: Trace.TrackingCookie.tribalfusion.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:54911 Ontdekt: Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55253 Ontdekt: Trace.TrackingCookie.ad.zanox.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55682 Ontdekt: Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55697 Ontdekt: Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55708 Ontdekt: Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@adtech[1].txt Ontdekt: Trace.TrackingCookie.adtech!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@metriweb[1].txt Ontdekt: Trace.TrackingCookie.metriweb!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@specificclick[1].txt Ontdekt: Trace.TrackingCookie.specificclick!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:50 Ontdekt: Trace.TrackingCookie.www.etracker.de!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:88 Ontdekt: Trace.TrackingCookie.doubleclick.net!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:126 Ontdekt: Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:386 Ontdekt: Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:387 Ontdekt: Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:534 Ontdekt: Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:775 Ontdekt: Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:776 Ontdekt: Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:864 Ontdekt: Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:865 Ontdekt: Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:866 Ontdekt: Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:867 Ontdekt: Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1081 Ontdekt: Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1104 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1586 Ontdekt: Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1587 Ontdekt: Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1588 Ontdekt: Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1661 Ontdekt: Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1670 Ontdekt: Trace.TrackingCookie.stat.onestat!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1671 Ontdekt: Trace.TrackingCookie.stat.onestat!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1751 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1752 Ontdekt: Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1875 Ontdekt: Trace.TrackingCookie.www.belstat.be!A2 C:\Windows\System32\drivers\smb.sys Ontdekt: Trojan-Dropper.Win32.Sirefef!IK Gescand Bestanden: 249174 Sporen: 461154 Cookies: 3084 Processen: 52 Gevonden Bestanden: 1 Sporen: 0 Cookies: 92 Processen: 0 Registersleutels: 0 Scan Geëindigd: 10/02/2012 20:23:28 Scantijd: 2:12:53 C:\Windows\System32\drivers\smb.sys Verwijderd Trojan-Dropper.Win32.Sirefef!IK C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1586 Verwijderd Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1587 Verwijderd Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1588 Verwijderd Trace.TrackingCookie.www.sedoparking.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:386 Verwijderd Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:387 Verwijderd Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:534 Verwijderd Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:775 Verwijderd Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:776 Verwijderd Trace.TrackingCookie.zedo.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:126 Verwijderd Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:864 Verwijderd Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:865 Verwijderd Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:866 Verwijderd Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:867 Verwijderd Trace.TrackingCookie.ad.yieldmanager.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:88 Verwijderd Trace.TrackingCookie.doubleclick.net!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@specificclick[1].txt Verwijderd Trace.TrackingCookie.specificclick!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@metriweb[1].txt Verwijderd Trace.TrackingCookie.metriweb!A2 C:\Users\benny\AppData\Roaming\Microsoft\Windows\Cookies\Low\benny@adtech[1].txt Verwijderd Trace.TrackingCookie.adtech!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:52863 Verwijderd Trace.TrackingCookie.tribalfusion.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51398 Verwijderd Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51399 Verwijderd Trace.TrackingCookie.tracking.publicidees.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:51166 Verwijderd Trace.TrackingCookie.media!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:48132 Verwijderd Trace.TrackingCookie.ad.zanox.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55253 Verwijderd Trace.TrackingCookie.ad.zanox.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:27612 Verwijderd Trace.TrackingCookie.d1.openx.org!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21302 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21484 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:38905 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1104 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1661 Verwijderd Trace.TrackingCookie.www.googleadservices.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21183 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43016 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43023 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43024 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43025 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43026 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:43061 Verwijderd Trace.TrackingCookie.myspace.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20821 Verwijderd Trace.TrackingCookie.track.adform.net!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20885 Verwijderd Trace.TrackingCookie.track.adform.net!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:20470 Verwijderd Trace.TrackingCookie.this.content.served.by.adshuffle.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19575 Verwijderd Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19576 Verwijderd Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19577 Verwijderd Trace.TrackingCookie.fl01.ct2.comclick!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19510 Verwijderd Trace.TrackingCookie.stat.onestat!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19511 Verwijderd Trace.TrackingCookie.stat.onestat!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1670 Verwijderd Trace.TrackingCookie.stat.onestat!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1671 Verwijderd Trace.TrackingCookie.stat.onestat!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:16023 Verwijderd Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55682 Verwijderd Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55697 Verwijderd Trace.TrackingCookie.www.etracker.de!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:50 Verwijderd Trace.TrackingCookie.www.etracker.de!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:12209 Verwijderd Trace.TrackingCookie.fr.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:12210 Verwijderd Trace.TrackingCookie.fr.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:11166 Verwijderd Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1081 Verwijderd Trace.TrackingCookie.bimonline.insites.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:10813 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17281 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:39386 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:39403 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1875 Verwijderd Trace.TrackingCookie.www.belstat.be!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6465 Verwijderd Trace.TrackingCookie.adserv!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19653 Verwijderd Trace.TrackingCookie.adserv!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6112 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:6113 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:10379 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17544 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:17545 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:19665 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21176 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:21177 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:22909 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1751 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\benny\AppData\Roaming\Mozilla\Firefox\Profiles\8l9r79r8.default\cookies.sqlite:1752 Verwijderd Trace.TrackingCookie.be.sitestat.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:3479 Verwijderd Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:24176 Verwijderd Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:54911 Verwijderd Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:55708 Verwijderd Trace.TrackingCookie.eas.apm.emediate.eu!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2637 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2638 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2640 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2641 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2642 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2643 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2644 Verwijderd Trace.TrackingCookie.about.com!A2 C:\Users\gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\thjeja5s.default\cookies.sqlite:2645 Verwijderd Trace.TrackingCookie.about.com!A2 Verwijderd Bestanden: 1 Sporen: 0 Cookies: 84
  11. hallo Als ik terug met hijackthis scande vond ik niet alle bestanden om te verwijderen. Hieronder zet ik de bestanden die niet meer terug te vinden waren. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) R3 - URLSearchHook: (no name) - {46735dee-f862-49d1-876d-6382794dc625} - (no file) O2 - BHO: (no name) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - (no file) O4 - HKLM\..\Run: [browser companion helper] C:\Program Files\BrowserCompanion\BCHelper.exe /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O20 - AppInit_DLLs: ____________________________________________________________________________________________________________ Malwarebytes Anti-Malware 1.60.1.1000 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Databaseversie: v2012.02.10.03 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 gebruiker :: PC_VAN_GEBRUIKE [administrator] 10/02/2012 11:27:31 mbam-log-2012-02-10 (11-27-31).txt Scantype: Snelle scan Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM Uitgeschakelde scanopties: P2P Objecten gescand: 191565 Verstreken tijd: 17 minuut/minuten, 53 seconde(n) Geheugenprocessen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Geheugenmodulen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registersleutels gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerwaarden gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Registerdata gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Mappen gedetecteerd: 0 (Geen kwaadaardige objecten gedetecteerd) Bestanden gedetecteerd: 2 C:\$Recycle.Bin\S-1-5-21-2202758371-4231288872-1693215706-1000\$RJE581S.exe (Affiliate.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd. C:\$Recycle.Bin\S-1-5-21-2202758371-4231288872-1693215706-1000\$RZZMVN6.exe (Affiliate.Downloader) -> Succesvol in quarantaine geplaatst en verwijderd. (einde) ____________________________________________________________________________________________________________ Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:25:48, on 10/02/2012 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O1 - Hosts: ::1 localhost O2 - BHO: CrossriderApp0000435 - {11111111-1111-1111-1111-110011041135} - C:\Program Files\Premiumplay Codec-C\Premiumplay Codec-C.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: CrossRider - {A876E312-7D08-401a-B7A6-FAFC5DC2F292} - C:\Program Files\CrossriderWebApps\Crossrider.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://ips.poi.de/ips-opdata/layout/fnac/objects/jordan.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v1120/Navigram.cab O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing) -- End of file - 5315 bytes
  12. Hallo Ik krijg van AVG steeds de melding Trojaans paard Dropper.Generic5.TKC Ik heb met hijackthis gescand en dit is mijn log. Alvast bedankt. groeten Benny Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:25:26, on 18/01/2012 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\AVG\AVG2012\avgtray.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\BrowserCompanion\BCHelper.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\conime.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\PROGRA~1\MICROS~2\wkcalrem.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file) R3 - URLSearchHook: (no name) - {46735dee-f862-49d1-876d-6382794dc625} - (no file) O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: CrossRider - {A876E312-7D08-401a-B7A6-FAFC5DC2F292} - C:\Program Files\CrossriderWebApps\Crossrider.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe" O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [browser companion helper] C:\Program Files\BrowserCompanion\BCHelper.exe /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://ips.poi.de/ips-opdata/layout/fnac/objects/jordan.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v1120/Navigram.cab O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - (no file) O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing) -- End of file - 6664 bytes
  13. Hallo, Ik had mijn harde schijf opgedeeld in 2 delen en wou er terug 1 van maken. via schijf beheer heb ik op het tweede deel geklikt dat ik niet gebruikt gedrukt op "volume verwijderen". Nu staat er alleen nog schijf C: wat de bedoeling was. Nu ben ik de gb kwijt van het tweede deel dat ik verwijderd heb. Hoe kan ik deze terug bij mijn C: voegen? Of is het de nu bedoeling dat ik mijn volledige harde schijf formateer. Alvast bedankt voor jullie reactie. Groeten Benny
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.