Ga naar inhoud

diana864

Lid
  • Items

    6
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door diana864

  1. Dit is de text die in de Combofix log stond na het herstarten:

    ComboFix 12-06-26.02 - Diana 26-06-2012 20:42:47.1.2 - x86

    Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.3002.1999 [GMT 2:00]

    Gestart vanuit: c:\users\Diana\Desktop\ComboFix.exe

    gebruikte Opdracht switches :: c:\users\Diana\Desktop\CFScript.txt

    AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}

    SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    FILE ::

    "C:\user.js"

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\program files\Web Assistant

    c:\program files\Web Assistant\Extension32.dll

    c:\program files\Web Assistant\ExtensionUpdaterService.exe

    c:\program files\Web Assistant\Firefox\chrome.manifest

    c:\program files\Web Assistant\Firefox\chrome\content\libraries\DataExchangeScript.js

    c:\program files\Web Assistant\Firefox\chrome\content\main.js

    c:\program files\Web Assistant\Firefox\chrome\content\main.xul

    c:\program files\Web Assistant\Firefox\chrome\content\resources\localscript.js

    c:\program files\Web Assistant\Firefox\chrome\locale\en-US\overlay.dtd

    c:\program files\Web Assistant\Firefox\chrome\skin\overlay.css

    c:\program files\Web Assistant\Firefox\defaults\preferences\defaults.js

    c:\program files\Web Assistant\Firefox\install.rdf

    c:\program files\Web Assistant\InstallerHelper.dll

    c:\program files\Web Assistant\libraries\DataExchangeScript.js

    c:\program files\Web Assistant\resources\localscript.js

    c:\program files\Web Assistant\source.crx

    c:\program files\Web Assistant\unins000.dat

    c:\program files\Web Assistant\unins000.exe

    C:\user.js

    .

    Besmet exemplaar van c:\windows\system32\Services.exe werd aangetroffen en gedesinfecteerd

    Hersteld exemplaar van - c:\windows\erdnt\cache\services.exe

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    -------\Service_Web Assistant Updater

    -------\Service_Web Assistant Updater

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-05-26 to 2012-06-26 ))))))))))))))))))))))))))))))

    .

    .

    2012-06-26 18:52 . 2012-06-26 18:52 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\users\Diana\AppData\Roaming\Malwarebytes

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\programdata\Malwarebytes

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

    2012-06-26 09:39 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-06-26 07:10 . 2012-06-26 07:10 388096 ----a-r- c:\users\Diana\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

    2012-06-26 07:10 . 2012-06-26 07:10 -------- d-----w- c:\program files\Trend Micro

    2012-06-26 06:22 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FDA9DFA-936A-43F0-AA87-C5700B7D8B41}\mpengine.dll

    2012-06-24 19:03 . 2012-06-24 19:03 -------- d-----w- c:\program files\Perion

    2012-06-24 19:02 . 2012-06-24 19:03 -------- d-----w- c:\program files\1ClickDownload

    2012-06-23 08:37 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-23 08:37 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll

    2012-06-23 08:37 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-23 08:37 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll

    2012-06-23 08:36 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll

    2012-06-23 08:36 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-23 08:36 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll

    2012-06-23 08:35 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll

    2012-06-23 08:35 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe

    2012-06-19 16:30 . 2012-06-19 16:30 -------- d-----w- c:\windows\nl

    2012-06-19 16:22 . 2012-06-19 16:22 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\DSETUP.dll

    2012-06-19 16:22 . 2012-06-19 16:22 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\DXSETUP.exe

    2012-06-19 16:22 . 2012-06-19 16:22 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\dsetup32.dll

    2012-06-16 21:56 . 2012-06-16 21:56 476936 ----a-w- c:\windows\system32\npdeployJava1.dll

    2012-06-13 06:33 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll

    2012-06-13 06:33 . 2012-04-23 16:00 98304 ----a-w- c:\windows\system32\cryptnet.dll

    2012-06-13 06:33 . 2012-04-23 16:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll

    2012-06-13 06:33 . 2012-05-01 14:03 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys

    2012-06-13 06:33 . 2012-05-15 19:51 2045440 ----a-w- c:\windows\system32\win32k.sys

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-06-16 21:56 . 2010-04-16 05:31 472840 ----a-w- c:\windows\system32\deployJava1.dll

    2012-06-14 05:26 . 2012-03-31 07:33 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-06-14 05:26 . 2011-05-21 07:35 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-05-08 07:49 . 2012-03-09 19:07 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys

    2012-05-08 07:49 . 2012-03-09 19:07 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys

    2012-04-03 08:16 . 2012-05-16 08:42 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

    2012-04-03 08:16 . 2012-05-16 08:42 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-03-30 12:39 . 2012-05-16 08:42 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]

    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-11 39408]

    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]

    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]

    "UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-06 210216]

    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]

    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]

    "UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]

    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]

    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-01-12 49208]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]

    "ConsumerClickSysTrayIcon"="c:\program files\ConsumerClick\ConsumerClickSysTrayIcon.exe" [2010-12-17 69632]

    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]

    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    @="Driver"

    .

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]

    .

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    HPService REG_MULTI_SZ HPSLPSVC

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

    ezSharedSvc

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

    2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 05:26]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 18:34]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 18:34]

    .

    2012-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081737216-3728604838-3465313506-1000Core.job

    - c:\users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 16:55]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081737216-3728604838-3465313506-1000UA.job

    - c:\users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 16:55]

    .

    2012-06-17 c:\windows\Tasks\HPCeeScheduleForDiana.job

    - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-08 10:34]

    .

    .

    ------- Bijkomende Scan -------

    .

    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_nl&c=91&bd=Presario&pf=cnnb

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.1.1

    DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab

    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    AddRemove-{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 - c:\program files\Web Assistant\unins000.exe

    .

    .

    .

    **************************************************************************

    scannen van verborgen processen ...

    .

    scannen van verborgen autostart items ...

    .

    scannen van verborgen bestanden ...

    .

    Scan succesvol afgerond

    verborgen bestanden:

    .

    **************************************************************************

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    "BlindDial"=dword:00000000

    .

    ------------------------ Andere Aktieve Processen ------------------------

    .

    c:\program files\Avira\AntiVir Desktop\sched.exe

    c:\windows\System32\lpksetup.exe

    c:\windows\system32\WLANExt.exe

    c:\program files\Avira\AntiVir Desktop\avguard.exe

    c:\program files\Common Files\LightScribe\LSSrvc.exe

    c:\program files\SMINST\BLService.exe

    c:\program files\CyberLink\Shared files\RichVideo.exe

    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    c:\windows\system32\DRIVERS\xaudio.exe

    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    c:\program files\Avira\AntiVir Desktop\avshadow.exe

    c:\windows\servicing\TrustedInstaller.exe

    c:\windows\system32\conime.exe

    c:\windows\system32\igfxsrvc.exe

    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe

    c:\program files\Windows Media Player\wmpnetwk.exe

    c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

    c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    c:\program files\Hewlett-Packard\Shared\HpqToaster.exe

    c:\program files\Synaptics\SynTP\SynTPHelper.exe

    c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe

    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe

    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe

    c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe

    c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe

    .

    **************************************************************************

    .

    Voltooingstijd: 2012-06-26 21:05:14 - machine werd herstart

    ComboFix-quarantined-files.txt 2012-06-26 19:03

    ComboFix2.txt 2012-06-26 15:22

    .

    Pre-Run: 151.985.471.488 bytes beschikbaar

    Post-Run: 151.650.258.944 bytes beschikbaar

    .

    - - End Of File - - 414E1EA7FC5D6C275D0F99EED4145081

  2. Hierbij de log gegevens van ComboFix:

    ComboFix 12-06-26.01 - Diana 26-06-2012 16:55:30.1.2 - x86

    Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.3002.1907 [GMT 2:00]

    Gestart vanuit: c:\users\Diana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FE5GJ30F\ComboFix.exe

    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}

    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\program files\Incredibar.com

    c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibar.crx

    c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarApp.dll

    c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarEng.dll

    c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarsrv.exe

    c:\program files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll

    c:\program files\Incredibar.com\incredibar\1.5.11.14\uninstall.exe

    c:\program files\Mozilla Firefox\components\AskHPRFF.js

    c:\users\Diana\avira_antivir_personal_en.exe

    c:\users\Diana\g2mdlhlpx.exe

    c:\windows\system32\zrAAk.vbs

    .

    Besmet exemplaar van c:\windows\system32\Drivers\atapi.sys werd aangetroffen en gedesinfecteerd

    Hersteld exemplaar van - c:\windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-05-26 to 2012-06-26 ))))))))))))))))))))))))))))))

    .

    .

    2012-06-26 15:07 . 2012-06-26 15:07 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\users\Diana\AppData\Roaming\Malwarebytes

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\programdata\Malwarebytes

    2012-06-26 09:39 . 2012-06-26 09:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

    2012-06-26 09:39 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-06-26 07:10 . 2012-06-26 07:10 388096 ----a-r- c:\users\Diana\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

    2012-06-26 07:10 . 2012-06-26 07:10 -------- d-----w- c:\program files\Trend Micro

    2012-06-24 19:03 . 2012-06-24 19:03 -------- d-----w- c:\program files\Perion

    2012-06-24 19:03 . 2012-06-24 19:03 447 ----a-w- C:\user.js

    2012-06-24 19:03 . 2012-06-24 19:03 -------- d-----w- c:\program files\Web Assistant

    2012-06-24 19:02 . 2012-06-24 19:03 -------- d-----w- c:\program files\1ClickDownload

    2012-06-23 08:37 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-23 08:37 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll

    2012-06-23 08:37 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-23 08:37 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll

    2012-06-23 08:36 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll

    2012-06-23 08:36 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-23 08:36 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll

    2012-06-23 08:35 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll

    2012-06-23 08:35 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe

    2012-06-19 16:30 . 2012-06-19 16:30 -------- d-----w- c:\windows\nl

    2012-06-19 16:22 . 2012-06-19 16:22 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\DSETUP.dll

    2012-06-19 16:22 . 2012-06-19 16:22 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\DXSETUP.exe

    2012-06-19 16:22 . 2012-06-19 16:22 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\c387b7851cd4e3701\dsetup32.dll

    2012-06-16 21:56 . 2012-06-16 21:56 476936 ----a-w- c:\windows\system32\npdeployJava1.dll

    2012-06-13 06:33 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll

    2012-06-13 06:33 . 2012-04-23 16:00 98304 ----a-w- c:\windows\system32\cryptnet.dll

    2012-06-13 06:33 . 2012-04-23 16:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll

    2012-06-13 06:33 . 2012-05-01 14:03 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys

    2012-06-13 06:33 . 2012-05-15 19:51 2045440 ----a-w- c:\windows\system32\win32k.sys

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-06-16 21:56 . 2010-04-16 05:31 472840 ----a-w- c:\windows\system32\deployJava1.dll

    2012-06-14 05:26 . 2012-03-31 07:33 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-06-14 05:26 . 2011-05-21 07:35 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-05-31 03:41 . 2012-06-26 06:22 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FDA9DFA-936A-43F0-AA87-C5700B7D8B41}\mpengine.dll

    2012-05-08 07:49 . 2012-03-09 19:07 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys

    2012-05-08 07:49 . 2012-03-09 19:07 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys

    2012-04-03 08:16 . 2012-05-16 08:42 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe

    2012-04-03 08:16 . 2012-05-16 08:42 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-03-30 12:39 . 2012-05-16 08:42 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]

    .

    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]

    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-11 39408]

    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]

    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]

    "UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-06 210216]

    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]

    "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]

    "UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]

    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]

    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]

    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-01-12 49208]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]

    "ConsumerClickSysTrayIcon"="c:\program files\ConsumerClick\ConsumerClickSysTrayIcon.exe" [2010-12-17 69632]

    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-08 348624]

    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]

    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    @="Driver"

    .

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-14 257224]

    .

    .

    --- Andere Services/Drivers In Geheugen ---

    .

    *NewlyCreated* - WS2IFSL

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    HPService REG_MULTI_SZ HPSLPSVC

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

    ezSharedSvc

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

    2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 05:26]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 18:34]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 18:34]

    .

    2012-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081737216-3728604838-3465313506-1000Core.job

    - c:\users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 16:55]

    .

    2012-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4081737216-3728604838-3465313506-1000UA.job

    - c:\users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 16:55]

    .

    2012-06-17 c:\windows\Tasks\HPCeeScheduleForDiana.job

    - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-08 10:34]

    .

    .

    ------- Bijkomende Scan -------

    .

    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_nl&c=91&bd=Presario&pf=cnnb

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.1.1

    DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab

    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    AddRemove-incredibar - c:\program files\Incredibar.com\incredibar\1.5.11.14\uninstall.exe

    AddRemove-DealAssistant - c:\users\Diana\AppData\Roaming\DealAssistant\DAUninstall.exe

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

    Rootkit scan 2012-06-26 17:13

    Windows 6.0.6002 Service Pack 2 NTFS

    .

    scannen van verborgen processen ...

    .

    scannen van verborgen autostart items ...

    .

    scannen van verborgen bestanden ...

    .

    Scan succesvol afgerond

    verborgen bestanden: 0

    .

    **************************************************************************

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    "BlindDial"=dword:00000000

    .

    ------------------------ Andere Aktieve Processen ------------------------

    .

    c:\program files\Avira\AntiVir Desktop\sched.exe

    c:\windows\System32\lpksetup.exe

    c:\windows\system32\WLANExt.exe

    c:\program files\Avira\AntiVir Desktop\avguard.exe

    c:\program files\Common Files\LightScribe\LSSrvc.exe

    c:\program files\SMINST\BLService.exe

    c:\program files\CyberLink\Shared files\RichVideo.exe

    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    c:\program files\Web Assistant\ExtensionUpdaterService.exe

    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    c:\windows\system32\DRIVERS\xaudio.exe

    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    c:\program files\Avira\AntiVir Desktop\avshadow.exe

    c:\windows\servicing\TrustedInstaller.exe

    c:\windows\system32\conime.exe

    c:\windows\system32\igfxsrvc.exe

    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe

    c:\program files\Windows Media Player\wmpnetwk.exe

    c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

    c:\program files\Hewlett-Packard\Shared\HpqToaster.exe

    c:\program files\Synaptics\SynTP\SynTPHelper.exe

    c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe

    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe

    c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe

    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe

    c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe

    .

    **************************************************************************

    .

    Voltooingstijd: 2012-06-26 17:22:13 - machine werd herstart

    ComboFix-quarantined-files.txt 2012-06-26 15:21

    .

    Pre-Run: 149.991.608.320 bytes beschikbaar

    Post-Run: 152.075.382.784 bytes beschikbaar

    .

    - - End Of File - - 1553050E964A920C5F2EC0A2C589AF5B

    En die van HJT:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 17:47:52, on 26-6-2012

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16446)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\HP\QuickPlay\QPService.exe

    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    C:\Program Files\HP\HP Software Update\hpwuschd2.exe

    C:\Windows\System32\igfxtray.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    C:\Program Files\Windows Live\Contacts\wlcomm.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe

    C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe

    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Compaq | MSN

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

    O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"

    O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

    O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"

    O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

    O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [updatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"

    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [ConsumerClickSysTrayIcon] "C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe"

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Web Assistant Updater - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe

    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --

    End of file - 11406 bytes

    Volgens mij is het probleem nu opgelost, kan weer gewoon foto's kijken via Twitter en een nieuw tabblad openen zonder Mystart te zien. Bedankt voor alle hulp

  3. Hierbij de nieuwe logjes, ik kon alleen AskBar niet verwijderen, weet niet of dit een groot probleem is

    Logje MBAM:

    Malwarebytes Anti-Malware (-evaluatieversie-) 1.61.0.1400

    www.malwarebytes.org

    Databaseversie: v2012.06.26.02

    Windows Vista Service Pack 2 x86 NTFS

    Internet Explorer 9.0.8112.16421

    Diana :: PC_VAN_DIANA [administrator]

    Realtime bescherming: Ingeschakeld

    26-6-2012 11:40:31

    mbam-log-2012-06-26 (11-40-31).txt

    Scantype: Snelle scan

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 220837

    Verstreken tijd: 22 minuut/minuten, 59 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 5

    HKCU\Software\IEBarProperties (Adware.Mirar) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Findbasic (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\RelatedPageInstall (Adware.Mirar) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Findbasic (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    HKLM\SYSTEM\CurrentControlSet\Services\Findbasic Service (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 3

    C:\Users\Diana\AppData\Roaming\DealAssistant (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\ProgramData\Findbasic (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\Findbasic (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    Bestanden gedetecteerd: 9

    C:\Users\Diana\AppData\Local\Temp\93.exe (Adware.Mirar) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Local\Temp\flm56C9.tmp (Trojan.Dropper) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Local\Temp\Low\a968.exe (Rogue.Installer) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Roaming\020000001e6e7f05680C.manifest (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Roaming\020000001e6e7f05680O.manifest (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Roaming\020000001e6e7f05680P.manifest (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Roaming\020000001e6e7f05680S.manifest (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Users\Diana\AppData\Roaming\DealAssistant\config.cfg (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.

    C:\Program Files\Findbasic\uninstall.exe (Adware.FindBasic) -> Succesvol in quarantaine geplaatst en verwijderd.

    (einde)

    Logje HJT:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 12:22:17, on 26-6-2012

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16446)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\HP\QuickPlay\QPService.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    C:\Program Files\HP\HP Software Update\hpwuschd2.exe

    C:\Windows\System32\igfxtray.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

    C:\Program Files\Windows Live\Contacts\wlcomm.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe

    C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe

    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Compaq | MSN

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Compaq | MSN

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Compaq | MSN

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    O1 - Hosts: ::1 localhost

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

    O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"

    O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

    O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"

    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

    O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [updatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"

    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    O4 - HKLM\..\Run: [bar] C:\Users\Diana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZXWQYGTE\MediaPlayerUpgrade[1].exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [ConsumerClickSysTrayIcon] "C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe"

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [Google Update] "C:\Users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe" /c

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Web Assistant Updater - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe

    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --

    End of file - 12742 bytes

  4. Goedemorgen,

    Ik heb opeens Mystart op m'n laptop, heel vervelend kan bijvoorbeeld geen foto's op twitter meer bekijken. Heb al even op dit forum gekeken en HJT gedownload. Alle aanwijzingen hier op het forum verder gevolgd en daar kwam het volgende logje uit, kan iemand me helpen om mystart te verwijderen.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 9:21:45, on 26-6-2012

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16446)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\HP\QuickPlay\QPService.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files\HP\HP Software Update\hpwuschd2.exe

    C:\Windows\System32\igfxtray.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE

    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

    C:\Program Files\Windows Live\Contacts\wlcomm.exe

    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe

    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe

    C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Compaq | MSN

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Mirar=

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MyStart by IncrediBar.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Compaq | MSN

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Mirar=

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Compaq | MSN

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O1 - Hosts: ::1 localhost

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

    O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll

    O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll

    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

    O4 - HKLM\..\Run: [updateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"

    O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

    O4 - HKLM\..\Run: [uCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"

    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

    O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

    O4 - HKLM\..\Run: [updatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"

    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    O4 - HKLM\..\Run: [bar] C:\Users\Diana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZXWQYGTE\MediaPlayerUpgrade[1].exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [ConsumerClickSysTrayIcon] "C:\Program Files\ConsumerClick\ConsumerClickSysTrayIcon.exe"

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [Google Update] "C:\Users\Diana\AppData\Local\Google\Update\GoogleUpdate.exe" /c

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O8 - Extra context menu item: &AOL-werkbalk Zoeken - C:\ProgramData\AOL\ieToolbar\resources\nl-NL\local\search.html

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O20 - AppInit_DLLs: C:\Windows\System32\dimsroam32.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

    O23 - Service: Findbasic Service - Unknown owner - C:\ProgramData\Findbasic\findbasic121.exe (file missing)

    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

    O23 - Service: Web Assistant Updater - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe

    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --

    End of file - 13627 bytes

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.