Ga naar inhoud

DutchRaver

Lid
  • Items

    78
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door DutchRaver

  1. Ik heb de pc zojuist opgehaald, het bleek een probleem te zijn met een service in de achtergrond (AODDriver 4.3). Deze is onderdeel van het catalyst pakket en hij is opnieuw geïnstalleerd dus dit topic kan bij deze dicht.
  2. Bedankt, ik zal hem even langs brengen bij de desbetreffende winkel.
  3. http://speccy.piriform.com/results/QiHg7aYRy632wBwyNOSSRMN
  4. Iemand nog advies? Hij maakt nu ook een raar geluid als hij vastloopt, soort piepgeluid.
  5. [ATTACH]36786[/ATTACH] Vorige bijlage opende volgens mij niet goed, deze hopelijk wel. ComboFix.txt
  6. Hallo, De afgelopen 2 weken loopt mijn pc (windows vista) nogal vaak vast, soms direct na het opstarten tot 30 minuten erna. Hij loop helemaal vast en ik moet dan de stroom eraf halen om hem opnieuw op te kunnen starten. Heb de pc schoongemaakt en wat scanners laten lopen, onder andere anti-malwarebytes en superantispyware maar deze gaven geen ernstige bedreigingen weer. Iemand advies? Vriendelijke groet.
  7. Is het een vereiste om de installatie cd/dvd erbij te pakken? Ik weet helaas niet waar deze op het moment ligt.
  8. Dump File : Mini040414-01.dmp Crash Time : 4-4-2014 9:14:37 Bug Check String : UNEXPECTED_KERNEL_MODE_TRAP Bug Check Code : 0x0000007f Parameter 1 : 00000000`00000008 Parameter 2 : 00000000`80050031 Parameter 3 : 00000000`000006f8 Parameter 4 : fffff800`02aa4494 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+57150 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.0.6002.18881 (vistasp2_gdr.130707-1535) Processor : x64 Crash Address : ntoskrnl.exe+57150 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\Mini040414-01.dmp Processors Count : 4 Major Version : 15 Minor Version : 6002 Dump File Size : 275.472 Dump File Time : 4-4-2014 9:15:56 ================================================== ================================================== Dump File : Mini031214-01.dmp Crash Time : 12-3-2014 11:05:55 Bug Check String : Bug Check Code : 0x00000101 Parameter 1 : 00000000`00000031 Parameter 2 : 00000000`00000000 Parameter 3 : fffffa60`005ec180 Parameter 4 : 00000000`00000001 Caused By Driver : hal.dll Caused By Address : hal.dll+2d460 File Description : Hardware Abstraction Layer DLL Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 6.0.6002.18005 (lh_sp2rtm.090410-1830) Processor : x64 Crash Address : ntoskrnl.exe+57150 Stack Address 1 : Stack Address 2 : Stack Address 3 : Computer Name : Full Path : C:\Windows\Minidump\Mini031214-01.dmp Processors Count : 4 Major Version : 15 Minor Version : 6002 Dump File Size : 262.144 Dump File Time : 12-3-2014 11:08:14 ==================================================
  9. Daar heb je gelijk in, die BSOD's vind ik eigenlijk belangrijker. Gisteren weer 1tje gehad waar volgens mij iets instond over ''run a memory check''. Plus de andere ''A clock was not received on the secondary processor'', wat zou dit kunnen betekenen?
  10. Goedendag, Ik krijg al een tijdje een melding bij het opstarten van de computer dat via audio cpl niet meer werkt, als ik met de muis over het geluidsicoontje ga rechtsonder in beeld gebeurt er niks en verdwijnt hij. Via het configuratiescherm krijg ik dezelfde melding als ik op het via hd audio deck icoontje klik. Maar ik heb wel gewoon geluid en via apparaatbeheer werkt het apparaat blijkbaar correct, iemand die me zou kunnen helpen? Daarbij heb ik de afgelopen maand 1 BSOD gekregen met de tekst '' A clock was not received on the secondary processor'' plus 2x een vastgelopen pc. Groeten [h=1][/h]
  11. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64 Running in: Normal Mode Internet Access Detected ==== Running Processes ====================== C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files (x86)\Logitech\Vid HD\Vid.exe C:\Users\Eric Donckers\AppData\Local\Akamai\netsession_win.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe C:\Users\Eric Donckers\AppData\Local\Akamai\netsession_win.exe C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\viakaraokesrv.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\WUDFHost.exe C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\mobsync.exe C:\Windows\system32\taskeng.exe C:\Windows\splwow64.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Windows\SysWOW64\DllHost.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Eric Donckers\Desktop\zoek.exe C:\Users\ERICDO~1\AppData\Local\Temp\RarSFX0\zoek.com C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\conime.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\SysWOW64\mshta.exe C:\Windows\system32\taskeng.exe ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-767261209-82459258-975220786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-767261209-82459258-975220786-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully ==== FireFox Fix ====================== Deleted from C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\prefs.js: user_pref("browser.startup.homepage", "https://www.google.nl/"); user_pref("browser.newtab.url", "http://search.babylon.com/?affID=110809&tt=3412_6&babsrc=NT_ss&mntrId=9ccad048000000000000002354c48a3a"); user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); user_pref("browser.search.order.1", "Search the web (Babylon)"); Added to C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\prefs.js: user_pref("browser.startup.homepage", "http://www.google.com"); user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "http://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default ---- Lines BabylonToolbar removed from prefs.js ---- user_pref("extensions.BabylonToolbar_i.newTab", true); user_pref("extensions.BabylonToolbar_i.newTabUrl", "http://search.babylon.com/?affID=110809&tt=3412_6&babsrc=NT_ss&mntrId=9ccad048000000000000002354c48a3a"); ---- Lines BabylonToolbar modified from prefs.js ---- ---- Lines BabylonToolbar removed from user.js ---- ---- Lines ask.com removed from prefs.js ---- user_pref("extensions.asktb.default-channel-url-mask", "http://nl.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&dm=lang"); user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}"); user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); ---- Lines ask.com modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1307269214007},\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\IPSFFPlgn\",\"mtime\":1359797912497},\"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\coFFPlgn\",\"mtime\":1359906066781}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1358547870771}}},{\"name\":\"app-profile\",\"addons\":{\"bbrs_002@blabbers.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\bbrs_002@blabbers.com\",\"mtime\":1326988452688},\"OneClickDownload@OneClickDownload.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\",\"mtime\":1359629134069},\"toolbar@ask.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\toolbar@ask.com\",\"mtime\":1317044928722},\"{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi\",\"mtime\":1359888441296}}}]"); ---- Lines ask.com removed from user.js ---- ---- Lines asktb removed from prefs.js ---- user_pref("extensions.asktb.cbid", "EV"); user_pref("extensions.asktb.crumb", "2011.09.26+06.48.49-toolbar005iad-NL-QW1lcnNmb29ydCxOZXRoZXJsYW5kcw%3D%3D"); user_pref("extensions.asktb.dtid", "YYYYYYYYNL"); user_pref("extensions.asktb.first-launch", true); user_pref("extensions.asktb.fresh-install", false); user_pref("extensions.asktb.l", "dis"); user_pref("extensions.asktb.last-config-req", "1317044928262"); user_pref("extensions.asktb.locale", "nl_NL"); user_pref("extensions.asktb.o", "101917"); user_pref("extensions.asktb.overlay-reloaded-using-restart", true); user_pref("extensions.asktb.qsrc", "2871"); user_pref("extensions.asktb.r", "6"); ---- Lines asktb modified from prefs.js ---- ---- Lines asktb removed from user.js ---- ---- Lines blabbers.com removed from prefs.js ---- ---- Lines blabbers.com modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1307269214007},\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\IPSFFPlgn\",\"mtime\":1359797912497},\"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\coFFPlgn\",\"mtime\":1359906066781}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1358547870771}}},{\"name\":\"app-profile\",\"addons\":{\"bbrs_002@blabbers.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\bbrs_002@blabbers.com\",\"mtime\":1326988452688},\"OneClickDownload@OneClickDownload.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\",\"mtime\":1359629134069},\"toolbar@disabled\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\toolbar@disabled\",\"mtime\":1317044928722},\"{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi\",\"mtime\":1359888441296}}}]"); ---- Lines blabbers.com removed from user.js ---- ---- Lines OneClickDownload removed from prefs.js ---- user_pref("extensions.bootstrappedAddons", "{\"OneClickDownload@OneClickDownload.com\":{\"version\":\"1.3\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\"},\"{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\":{\"version\":\"2.2.2\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi\"}}"); user_pref("extensions.OneClickDownload.filter", "1,2"); user_pref("extensions.OneClickDownload.lastUpdate", "{\"hours\":11,\"min\":14}"); ---- Lines OneClickDownload modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1307269214007},\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\IPSFFPlgn\",\"mtime\":1359797912497},\"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\NIS_19.1.0.28\\\\coFFPlgn\",\"mtime\":1359906066781}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1358547870771}}},{\"name\":\"app-profile\",\"addons\":{\"bbrs_002@disabled\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\bbrs_002@disabled\",\"mtime\":1326988452688},\"OneClickDownload@OneClickDownload.com\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\",\"mtime\":1359629134069},\"toolbar@disabled\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\toolbar@disabled\",\"mtime\":1317044928722},\"{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\":{\"descriptor\":\"C:\\\\Users\\\\Eric Donckers\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\uaa4qloc.default\\\\extensions\\\\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi\",\"mtime\":1359888441296}}}]"); ---- Lines OneClickDownload removed from user.js ---- ---- FireFox user.js and prefs.js backups ---- user_03-02-2013_1655_.backup prefs_03-02-2013_1655_.backup ==== Deleting Files \ Folders ====================== "C:\user.js" deleted "C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\extensions\OneClickDownload@OneClickDownload.com.xpi" deleted "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" deleted "C:\user.js" deleted "C:\END" deleted "C:\Program Files (x86)\Giant Savings" deleted "C:\Program Files (x86)\1ClickDownload" deleted "C:\Program Files (x86)\Ask.com" deleted "C:\Users\Eric Donckers\AppData\Roaming\Babylon" deleted "C:\ProgramData\InstallMate" deleted "C:\ProgramData\Tarma Installer" deleted "C:\ProgramData\Premium" deleted "C:\ProgramData\Babylon" deleted "C:\Users\Eric Donckers\AppData\Local\AskToolbar" deleted "C:\Users\Eric Donckers\AppData\LocalLow\AskToolbar" deleted "C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\extensions\toolbar@ask.com" deleted "C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\extensions\bbrs_002@blabbers.com" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\ERICDO~1\AppData\Local\Temp ==== 2013-02-03 15:55:49 6F1168F463578A0FAC882863E26CDFCF 2317312 ----a-w- C:\Users\ERICDO~1\AppData\Local\Temp\SysSpec.exe 2013-01-29 12:47:42 E04AF911CAC8510868E7C21B6257B097 204800 ----a-w- C:\Users\ERICDO~1\AppData\Local\Temp\drm_dyndata_7380007.dll ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\Program Files (x86) ===== ======= C: ===== ====== C:\Users\Eric Donckers\AppData\Roaming ====== 2013-01-29 12:47:57 -------- d-----w- C:\users\Eric Donckers\AppData\Local\Electronic Arts 2013-01-19 21:13:07 8C628962387A7B42AAC0ED4B2F717BE3 357922 ----a-w- C:\users\Eric Donckers\AppData\Local\dd_vcredistMSI619E.txt 2013-01-19 21:13:04 97AB3959BE512F4593E515C28103E92F 13394 ----a-w- C:\users\Eric Donckers\AppData\Local\dd_vcredistUI619E.txt ====== C:\Users\Eric Donckers ====== 2013-02-03 10:36:44 -------- d-----w- C:\Users\Eric Donckers\Doctor Web ====== C: exe-files == 2013-02-03 15:55:49 6F1168F463578A0FAC882863E26CDFCF 2317312 ----a-w- C:\Users\Eric Donckers\AppData\Local\temp\SysSpec.exe 2013-02-03 10:34:52 7611B6951BC723F1ADC6F3150EE42DCE 110655728 ----a-w- C:\Users\Eric Donckers\Downloads\launch.exe 2013-01-30 14:36:11 885B713E4547904EF2962C7BE9C2CF0C 195493384 ----a-w- C:\Users\Eric Donckers\Downloads\20130130-004-v5i32.exe === C: other files == 2013-01-29 12:47:42 E04AF911CAC8510868E7C21B6257B097 204800 ----a-w- C:\Users\Eric Donckers\AppData\Local\temp\drm_dyndata_7380007.dll ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-767261209-82459258-975220786-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Logitech Vid"="C:\Program Files (x86)\Logitech\Vid HD\Vid.exe -bootmode" "Akamai NetSession Interface"="C:\Users\Eric Donckers\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Pro Agent"="C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe -autorun" "Steam"="L:\steam\Steam.exe -silent" "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" "Xvid"="C:\Program Files (x86)\Xvid\CheckUpdate.exe" [HKEY_USERS\S-1-5-21-767261209-82459258-975220786-1002\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe /hide" "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "NBAgent"="C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe /WinStart" "RIMBBLaunchAgent.exe"="C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "SSBkgdUpdate"="C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot" "PaperPort PTD"="C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe" "IndexSearch"="C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe" "PPort11reminder"="C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe -r C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" "BrMfcWnd"="C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN" "ControlCenter3"="C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "HDAudDeck"="C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Logitech Vid"="C:\Program Files (x86)\Logitech\Vid HD\Vid.exe -bootmode" "Akamai NetSession Interface"="C:\Users\Eric Donckers\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Pro Agent"="C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe -autorun" "Steam"="L:\steam\Steam.exe -silent" "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" "Xvid"="C:\Program Files (x86)\Xvid\CheckUpdate.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EvtMgr6"="C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09-01-2013 12:34] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default 9AC863FD5976316C29D4CB5E4C9EFD9C - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll - Shockwave Flash AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions clbfjfbnelcflpgpklppgplejolacbej - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\Exts\Chrome.crx[26-09-2012 04:11] pmlghpafmmnmmkjdhacccolfgnkiboco - C:\Program Files (x86)\1ClickDownload\oneclickdownloader10.crx[] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} Unknown Url="Not_Found" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-767261209-82459258-975220786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\clbfjfbnelcflpgpklppgplejolacbej deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe, O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\IPS\IPSBHO.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Nero Update (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eric Donckers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Eric Donckers\AppData\Local\temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eric Donckers\AppData\Local\temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eric Donckers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\users\Eric Donckers\AppData\Local\Mozilla\Firefox\Profiles\uaa4qloc.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome Cache found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully After Reboot ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\ERICDO~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Eric Donckers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
  12. Beste experts, helaas heb ik weer last van coupondropdown. Ik heb mijn norton scanner laten lopen maar die lost het niet op. Waar moet ik beginnen? Mvg
  13. Scan statistieken ----------------------------------------------------------------------------- Objecten gescand: 781473 Geïnfecteerde objecten gevonden: 0 Gemodificeerde objecten gevonden: 0 Verdachte objecten gevonden: 0 Adware programma's gevonden: 4 Dialer programma's gevonden: 0 Joke programma's gevonden: 0 Riskware programma's gevonden: 0 Hacktool programma's gevonden: 0 Objecten gerepareerd: 0 Objecten verwijderd: 0 Objecten hernoemd: 0 Objecten verplaatst: 4 Objecten genegeerd: 0 Scan snelheid: 71 Kb/s Scan tijd: 6:27:35 ----------------------------------------------------------------------------- ============================================================================= Totale sessie statistieken ============================================================================= Objecten gescand: 818110 Geïnfecteerde objecten gevonden: 0 Gemodificeerde objecten gevonden: 0 Verdachte objecten gevonden: 0 Adware programma's gevonden: 4 Dialer programma's gevonden: 0 Joke programma's gevonden: 0 Riskware programma's gevonden: 0 Hacktool programma's gevonden: 0 Objecten gerepareerd: 0 Objecten verwijderd: 0 Objecten hernoemd: 0 Objecten verplaatst: 4 Objecten genegeerd: 0 Scan snelheid: 134 Kb/s Scan tijd: 6:30:27 - - - Updated - - - Het zier er naar uit dat doctorweb de klus heeft geklaard. Ik zie nergens meer dikgedrukte woorden staan die me naar coupondropdown leiden.
  14. Prima, heb het verwijderd. Heb wel nog last van coupondropdown.
  15. Helaas zonder succes. Lukt in veilige modus ook niet.
  16. Helaas zonder succes, krijg wel de melding done! maar combofix wordt niet verwijderd.
  17. Hmm ik krijg de volgende meldingen; Combofix wordt niet herkend als een interne of externe opdracht, programma of bestand. En bij de andere poging (del C:\Qoobox) krijg ik de melding dat de toegang is geweigerd.
  18. Hoe doe ik dat precies met windows vista? Als ik bij start/zoekopdracht dat intyp krijg ik alleen een zoekopdracht waar niks gevonden wordt.
  19. Heb het scriptje gemaakt en naar het combofix icoontje gesleept en krijg nu echt dit: ComboFix 12-11-16.02 - Eric Donckers 16-11-2012 21:36:40.1.4 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.4094.2519 [GMT 1:00] Gestart vanuit: c:\users\Eric Donckers\Desktop\ComboFix.exe gebruikte Opdracht switches :: c:\users\Eric Donckers\Desktop\CFScript.txt AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((( Bestanden Gemaakt van 2012-10-16 to 2012-11-16 )))))))))))))))))))))))))))))) . . 2012-11-16 20:43 . 2012-11-16 20:43 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2012-11-16 20:43 . 2012-11-16 20:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-11-16 18:35 . 2012-11-16 20:43 -------- d-----w- c:\users\Eric Donckers\AppData\Local\temp 2012-11-16 13:13 . 2012-11-16 13:13 -------- d-----w- C:\temp 2012-11-16 13:09 . 2012-10-10 20:23 1482600 ----a-w- c:\windows\system32\nvdispgenco64.dll 2012-11-16 13:08 . 2012-11-16 13:08 53248 ----a-r- c:\users\Eric Donckers\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2012-11-16 13:07 . 2012-11-16 13:07 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2012-11-16 13:03 . 2012-11-16 13:08 -------- d-----w- c:\users\Eric Donckers\AppData\Roaming\Logitech 2012-11-16 13:03 . 2012-11-16 13:03 -------- d-----w- c:\users\Eric Donckers\AppData\Roaming\Logishrd 2012-11-16 13:02 . 2012-03-30 14:49 56448 ----a-w- c:\windows\system32\drivers\usbfilter.sys 2012-11-16 13:00 . 2012-11-16 13:00 -------- d-----w- C:\AMD 2012-11-16 12:53 . 2012-11-16 12:53 -------- d-----w- C:\ATI 2012-11-15 20:48 . 2012-11-16 20:34 -------- d-----w- C:\32788R22FWJFW 2012-11-15 20:43 . 2012-09-25 16:31 91648 ----a-w- c:\windows\system32\synceng.dll 2012-11-15 20:43 . 2012-09-25 16:19 75776 ----a-w- c:\windows\SysWow64\synceng.dll 2012-11-15 20:43 . 2012-10-12 14:53 2769920 ----a-w- c:\windows\system32\win32k.sys 2012-10-21 11:09 . 2012-09-24 21:16 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-11-16 11:38 . 2006-11-02 12:35 66395536 ----a-w- c:\windows\system32\mrt.exe 2012-10-10 20:23 . 2012-10-10 20:23 1867112 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2012-10-10 20:23 . 2012-10-10 20:23 18252136 ----a-w- c:\windows\system32\nvd3dumx.dll 2012-10-10 20:23 . 2012-10-10 20:23 6127464 ----a-w- c:\windows\SysWow64\nvopencl.dll 2012-10-10 20:23 . 2012-10-10 20:23 2574696 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2012-10-10 20:23 . 2012-10-10 20:23 25256296 ----a-w- c:\windows\system32\nvcompiler.dll 2012-10-10 20:23 . 2012-10-10 20:23 7414632 ----a-w- c:\windows\system32\nvopencl.dll 2012-10-10 20:23 . 2012-04-09 19:19 2731880 ----a-w- c:\windows\system32\nvapi64.dll 2012-10-10 20:23 . 2012-10-10 20:23 14922600 ----a-w- c:\windows\system32\nvwgf2umx.dll 2012-10-10 20:23 . 2012-10-10 20:23 9146728 ----a-w- c:\windows\system32\nvcuda.dll 2012-10-10 20:23 . 2012-10-10 20:23 7697768 ----a-w- c:\windows\SysWow64\nvcuda.dll 2012-10-10 20:23 . 2012-10-10 20:23 2218344 ----a-w- c:\windows\system32\nvcuvenc.dll 2012-10-10 20:23 . 2012-10-10 20:23 12501352 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2012-10-10 20:22 . 2012-10-10 20:22 2428776 ----a-w- c:\windows\SysWow64\nvapi.dll 2012-10-10 20:22 . 2012-10-10 20:22 26331496 ----a-w- c:\windows\system32\nvoglv64.dll 2012-10-10 20:22 . 2011-08-10 15:22 1760104 ----a-w- c:\windows\system32\nvdispco64.dll 2012-10-10 20:22 . 2012-10-10 20:22 15309160 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2012-10-10 20:22 . 2012-10-10 20:22 2747240 ----a-w- c:\windows\system32\nvcuvid.dll 2012-10-10 20:22 . 2012-10-10 20:22 19906920 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2012-10-10 20:22 . 2012-10-10 20:22 13443944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-10-10 20:22 . 2012-10-10 20:22 17559912 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2012-10-09 14:34 . 2012-04-03 14:16 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-09 14:34 . 2011-05-28 13:34 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-02 19:51 . 2011-04-07 21:18 3293544 ----a-w- c:\windows\system32\nvsvc64.dll 2012-10-02 19:51 . 2011-04-07 21:19 6200680 ----a-w- c:\windows\system32\nvcpl.dll 2012-10-02 19:50 . 2011-04-07 21:19 891240 ----a-w- c:\windows\system32\nvvsvc.exe 2012-10-02 19:50 . 2011-04-07 21:19 2557800 ----a-w- c:\windows\system32\nvsvcr.dll 2012-10-02 19:50 . 2011-04-07 21:19 118120 ----a-w- c:\windows\system32\nvmctray.dll 2012-10-02 19:50 . 2011-02-22 23:38 63336 ----a-w- c:\windows\system32\nvshext.dll 2012-10-02 12:15 . 2012-10-02 12:15 430952 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2012-09-29 18:54 . 2012-01-21 15:11 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-09-13 13:45 . 2012-10-11 08:34 2048 ----a-w- c:\windows\system32\tzres.dll 2012-09-13 13:28 . 2012-10-11 08:34 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2012-09-08 10:47 . 2012-06-20 11:38 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-09-08 10:47 . 2012-04-08 19:27 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll 2012-08-29 11:40 . 2012-10-11 08:33 4699520 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-08-24 16:07 . 2012-10-11 08:34 218624 ----a-w- c:\windows\system32\wintrust.dll 2012-08-24 15:53 . 2012-10-11 08:34 172544 ----a-w- c:\windows\SysWow64\wintrust.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496] "Akamai NetSession Interface"="c:\users\Eric Donckers\AppData\Local\Akamai\netsession_win.exe" [2012-10-09 4441920] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-02-02 3035968] "Steam"="l:\steam\Steam.exe" [2012-08-04 1353080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304] "EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "NBAgent"="c:\program files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-09-20 1493288] "RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-11-02 90448] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "PaperPort PTD"="c:\program files (x86)\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984] "IndexSearch"="c:\program files (x86)\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368] "PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-01-19 1150976] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-08-16 5264016] . c:\users\Eric Donckers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech . Productregistratie.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Inhoud van de 'Gedeelde Taken' map . 2012-11-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 14:34] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152] . ------- Bijkomende Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Eric Donckers\AppData\Roaming\Mozilla\Firefox\Profiles\uaa4qloc.default\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.nl/ FF - prefs.js: network.proxy.type - 0 FF - user.js: extensions.autoDisableScopes - 14 . - - - - ORPHANS VERWIJDERD - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.9.0.9\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai] "ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Voltooingstijd: 2012-11-16 21:45:30 ComboFix-quarantined-files.txt 2012-11-16 20:45 ComboFix2.txt 2012-11-16 18:35 ComboFix3.txt 2012-11-15 21:13 . Pre-Run: 34.724.876.288 bytes beschikbaar Post-Run: 34.579.562.496 bytes beschikbaar . - - End Of File - - 33F2E3BF3B6EA19659E8B821F066C760
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.