Ga naar inhoud

OXXO

Lid
  • Items

    4
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door OXXO

  1. Hier is ie dan :

    ComboFix 12-09-14.03 - Koen 15/09/2012 15:56:19.4.2 - x86

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.2941.1516 [GMT 2:00]

    Gestart vanuit: c:\users\Koen\Desktop\ComboFix.exe

    gebruikte Opdracht switches :: c:\users\Koen\Desktop\CFScript.txt

    AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    FW: AVG Internet Security 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}

    SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\users\Koen\AppData\Roaming\BabylonToolbar

    c:\users\Koen\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx

    c:\users\Koen\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll

    c:\users\Koen\AppData\Roaming\BabylonToolbar\FF\BUSolution.dll

    c:\users\Koen\AppData\Roaming\BabylonToolbar\IE\BUSolution.dll

    c:\users\Koen\AppData\Roaming\BabylonToolbar\Shared\BabyTBConf.ini

    c:\users\Koen\AppData\Roaming\BabylonToolbar\Shared\BUSolution.dll

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-08-15 to 2012-09-15 ))))))))))))))))))))))))))))))

    .

    .

    2012-09-15 14:02 . 2012-09-15 14:04 -------- d-----w- c:\users\Koen\AppData\Local\temp

    2012-09-15 14:02 . 2012-09-15 14:02 -------- d-----w- c:\users\Mieke\AppData\Local\temp

    2012-09-15 14:02 . 2012-09-15 14:02 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-09-15 10:35 . 2012-09-15 10:35 -------- d-sh--w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}

    2012-09-15 09:11 . 2012-09-15 09:11 -------- d-----w- c:\program files\CCleaner

    2012-09-14 15:06 . 2012-09-14 15:10 -------- d-----w- c:\program files\DownloadManager

    2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-09-07 19:42 . 2012-03-30 14:50 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-09-07 19:42 . 2011-07-10 12:17 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-09-07 15:04 . 2011-12-01 18:52 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-07-26 01:21 . 2012-07-26 01:21 237408 ----a-w- c:\windows\system32\drivers\avgldx86.sys

    2012-07-18 17:47 . 2012-08-15 17:18 2345984 ----a-w- c:\windows\system32\win32k.sys

    2012-07-04 21:14 . 2012-08-15 17:18 41984 ----a-w- c:\windows\system32\browcli.dll

    2012-07-04 21:14 . 2012-08-15 17:18 102912 ----a-w- c:\windows\system32\browser.dll

    2012-06-27 05:53 . 2012-08-15 17:18 981504 ----a-w- c:\windows\system32\wininet.dll

    2012-06-27 04:10 . 2012-08-15 17:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb

    2012-06-25 14:04 . 2012-06-25 14:04 1394248 ----a-w- c:\windows\system32\msxml4.dll

    2012-07-14 00:15 . 2012-07-21 18:31 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    2012-07-10 06:45 2074208 ----a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-07-10 2074208]

    .

    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

    "ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2012-08-22 3113312]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984]

    "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-07-10 1107552]

    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]

    "ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-16 928096]

    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    "Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-09-07 766536]

    .

    c:\users\Koen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    OneNote 2010 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

    "aux"=wdmaud.drv

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

    .

    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [x]

    R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]

    R2 MAGIX StartUp Analyze Service;MAGIX StartUp Analyze Service;c:\program files\MAGIX\PC_Check_Tuning_2011_Download-versie\MXSAS.exe [x]

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]

    R3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys [x]

    R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x]

    R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]

    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]

    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

    R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [x]

    S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]

    S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]

    S0 DiskSec;Magix Volume Filter Driver; [x]

    S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [x]

    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]

    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]

    S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [x]

    S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [x]

    S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x]

    S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]

    S2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [x]

    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]

    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfilterx.sys [x]

    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]

    S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

    S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]

    S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]

    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]

    S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]

    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]

    .

    .

    --- Andere Services/Drivers In Geheugen ---

    .

    *NewlyCreated* - CPUZ132

    *NewlyCreated* - MBAMPROTECTOR

    *Deregistered* - cpuz132

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-09-15 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 19:42]

    .

    2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 05:51]

    .

    2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 05:51]

    .

    2012-09-15 c:\windows\Tasks\PCCT - MAGIX AG.job

    - c:\program files\MAGIX\PC_Check_Tuning_2011_Download-versie\MxTray.exe [2010-10-04 14:05]

    .

    .

    ------- Bijkomende Scan -------

    .

    uStart Page = hxxp://www.www.deredactie.be/

    uInternet Settings,ProxyOverride = *.local

    TCP: DhcpNameServer = 195.130.130.131 195.130.131.131

    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    FF - ProfilePath - c:\users\Koen\AppData\Roaming\Mozilla\Firefox\Profiles\ni1e1amf.default\

    .

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_USERS\S-1-5-21-4263835052-3280959606-4070780750-1001_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]

    @Denied: (Full) (Everyone)

    "scansk"=hex(0):60,78,c2,5a,dc,36,32,f9,1b,39,58,d5,92,58,1e,5b,c9,7c,5a,6d,5c,

    46,57,3d,be,34,9e,ec,93,13,99,ad,9a,9b,39,d4,91,5e,7d,6c,00,00,00,00,00,00,\

    .

    [HKEY_USERS\S-1-5-21-4263835052-3280959606-4070780750-1001_Classes\CLSID\{a7441d4f-3a30-4949-b3c0-fc6f3764eb6d}]

    @Denied: (Full) (Everyone)

    @Allowed: (Read) (RestrictedCode)

    "Model"=dword:00000067

    "Therad"=dword:0000001d

    "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,

    1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

    .

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    Voltooingstijd: 2012-09-15 16:05:55

    ComboFix-quarantined-files.txt 2012-09-15 14:05

    ComboFix2.txt 2012-09-15 08:07

    ComboFix3.txt 2012-09-15 07:01

    ComboFix4.txt 2012-09-14 19:41

    .

    Pre-Run: 456.817.348.608 bytes beschikbaar

    Post-Run: 456.775.294.976 bytes beschikbaar

    .

    - - End Of File - - 460B67DB5EAA89C78BF96C906928CF25

  2. Hoi Kape, bedankt voor je reactie.

    De stappen zijn uitgevoerd, hierbij de logjes :

    * Combofix :

    ComboFix 12-09-14.03 - Koen 15/09/2012 10:00:02.3.2 - x86

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.2941.1801 [GMT 2:00]

    Gestart vanuit: c:\users\Koen\Desktop\ComboFix.exe

    gebruikte Opdracht switches :: c:\users\Koen\Desktop\CFScripts.txt

    AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    FW: AVG Internet Security 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}

    SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    FILE ::

    "c:\user.js"

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-08-15 to 2012-09-15 ))))))))))))))))))))))))))))))

    .

    .

    2012-09-15 08:05 . 2012-09-15 08:05 -------- d-----w- c:\users\Mieke\AppData\Local\temp

    2012-09-15 08:05 . 2012-09-15 08:05 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-09-15 07:01 . 2012-09-15 08:05 -------- d-----w- c:\users\Koen\AppData\Local\temp

    2012-09-14 15:08 . 2012-09-14 15:08 -------- d-----w- c:\users\Koen\AppData\Roaming\BabylonToolbar

    2012-09-14 15:06 . 2012-09-14 15:10 -------- d-----w- c:\program files\DownloadManager

    2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-09-07 19:42 . 2012-03-30 14:50 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-09-07 19:42 . 2011-07-10 12:17 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-09-07 15:04 . 2011-12-01 18:52 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-07-26 01:21 . 2012-07-26 01:21 237408 ----a-w- c:\windows\system32\drivers\avgldx86.sys

    2012-07-18 17:47 . 2012-08-15 17:18 2345984 ----a-w- c:\windows\system32\win32k.sys

    2012-07-04 21:14 . 2012-08-15 17:18 41984 ----a-w- c:\windows\system32\browcli.dll

    2012-07-04 21:14 . 2012-08-15 17:18 102912 ----a-w- c:\windows\system32\browser.dll

    2012-06-27 05:53 . 2012-08-15 17:18 981504 ----a-w- c:\windows\system32\wininet.dll

    2012-06-27 04:10 . 2012-08-15 17:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb

    2012-06-25 14:04 . 2012-06-25 14:04 1394248 ----a-w- c:\windows\system32\msxml4.dll

    2012-07-14 00:15 . 2012-07-21 18:31 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    2012-07-10 06:45 2074208 ----a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-07-10 2074208]

    .

    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984]

    "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-07-10 1107552]

    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]

    "ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-16 928096]

    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]

    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

    .

    c:\users\Koen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    OneNote 2010 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

    "aux"=wdmaud.drv

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

    .

    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [x]

    R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]

    R2 MAGIX StartUp Analyze Service;MAGIX StartUp Analyze Service;c:\program files\MAGIX\PC_Check_Tuning_2011_Download-versie\MXSAS.exe [x]

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]

    R3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys [x]

    R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x]

    R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]

    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]

    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]

    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

    R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [x]

    S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]

    S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]

    S0 DiskSec;Magix Volume Filter Driver; [x]

    S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [x]

    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]

    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]

    S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [x]

    S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [x]

    S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x]

    S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]

    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]

    S2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [x]

    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]

    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfilterx.sys [x]

    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]

    S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

    S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]

    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]

    S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]

    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]

    .

    .

    --- Andere Services/Drivers In Geheugen ---

    .

    *Deregistered* - cpuz132

    .

    Inhoud van de 'Gedeelde Taken' map

    .

    2012-09-15 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 19:42]

    .

    2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 05:51]

    .

    2012-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 05:51]

    .

    2012-09-15 c:\windows\Tasks\PCCT - MAGIX AG.job

    - c:\program files\MAGIX\PC_Check_Tuning_2011_Download-versie\MxTray.exe [2010-10-04 14:05]

    .

    .

    ------- Bijkomende Scan -------

    .

    uStart Page = hxxp://www.www.deredactie.be/

    uInternet Settings,ProxyOverride = *.local

    TCP: DhcpNameServer = 195.130.130.131 195.130.131.131

    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    FF - ProfilePath - c:\users\Koen\AppData\Roaming\Mozilla\Firefox\Profiles\ni1e1amf.default\

    FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=110823&tt=120912_pcp_3712_2&babsrc=HP_ss&mntrId=9ef5796300000000000074f06d1a3aca

    FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=110823&tt=120912_pcp_3712_2&babsrc=KW_ss&mntrId=9ef5796300000000000074f06d1a3aca&q=

    FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

    FF - user.js: extensions.BabylonToolbar.autoRvrt - false

    FF - user.js: extensions.BabylonToolbar_i.newTab - false

    FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=9ef5796300000000000074f06d1a3aca&q=

    FF - user.js: extensions.BabylonToolbar.id - 9ef5796300000000000074f06d1a3aca

    FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

    FF - user.js: extensions.BabylonToolbar.instlDay - 15597

    FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12

    FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12

    FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1217:05

    FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

    FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

    FF - user.js: extensions.BabylonToolbar.aflt - babsst

    FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

    FF - user.js: extensions.BabylonToolbar.tlbrId - tb9

    FF - user.js: extensions.BabylonToolbar.instlRef - sst

    FF - user.js: extensions.BabylonToolbar.dfltLng - en

    FF - user.js: extensions.BabylonToolbar.excTlbr - false

    FF - user.js: extensions.BabylonToolbar.admin - false

    FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110823&tt=120912_pcp_3712_2

    FF - user.js: extensions.BabylonToolbar_i.babExt -

    FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

    .

    .

    --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

    .

    [HKEY_USERS\S-1-5-21-4263835052-3280959606-4070780750-1001_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]

    @Denied: (Full) (Everyone)

    "scansk"=hex(0):60,78,c2,5a,dc,36,32,f9,1b,39,58,d5,92,58,1e,5b,c9,7c,5a,6d,5c,

    46,57,3d,be,34,9e,ec,93,13,99,ad,9a,9b,39,d4,91,5e,7d,6c,00,00,00,00,00,00,\

    .

    [HKEY_USERS\S-1-5-21-4263835052-3280959606-4070780750-1001_Classes\CLSID\{a7441d4f-3a30-4949-b3c0-fc6f3764eb6d}]

    @Denied: (Full) (Everyone)

    @Allowed: (Read) (RestrictedCode)

    "Model"=dword:00000067

    "Therad"=dword:0000001d

    "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,

    1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

    .

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    Voltooingstijd: 2012-09-15 10:07:23

    ComboFix-quarantined-files.txt 2012-09-15 08:07

    ComboFix2.txt 2012-09-15 07:01

    ComboFix3.txt 2012-09-14 19:41

    .

    Pre-Run: 456.441.098.240 bytes beschikbaar

    Post-Run: 456.300.630.016 bytes beschikbaar

    .

    - - End Of File - - 0AB0DF00A5540666BB6E09A67FF6F8E6

    * Malwarebytes :

    Malwarebytes Anti-Malware 1.65.0.1400

    www.malwarebytes.org

    Databaseversie: v2012.09.15.02

    Windows 7 Service Pack 1 x86 NTFS

    Internet Explorer 8.0.7601.17514

    Koen :: KOEN-PC [administrator]

    15/09/2012 10:14:22

    mbam-log-2012-09-15 (10-14-22).txt

    Scantype: Snelle scan

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 220613

    Verstreken tijd: 3 minuut/minuten, 44 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    *HijackThis :

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 10:26:11, on 15/09/2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v8.00 (8.00.7601.17514)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\taskeng.exe

    C:\Program Files\MAGIX\PC_Check_Tuning_2011_Download-versie\MxTray.exe

    C:\Program Files\AVG\AVG2012\avgtray.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Zune\ZuneLauncher.exe

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Users\Koen\Desktop\HijackThis.exe

    C:\Windows\system32\SearchFilterHost.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.www.deredactie.be/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL

    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.6.9.12\BabylonToolbarTlbr.dll (file missing)

    O4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices

    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"

    O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MAGIX StartUp Analyze Service - MAGIX AG - C:\Program Files\MAGIX\PC_Check_Tuning_2011_Download-versie\MXSAS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    --

    End of file - 8272 bytes

  3. Weer eentje erbij :-)

    Ik heb me dan maar geregistreerd om er eens naar te laten kijken door de echte sprecialisten hier.

    Wat ik vreemd vond : wanneer ik mezelf aanmeldde op mijn PC kreeg ik het virus scherm. Bij afloggen en vervolgens aanloggen op een andere gebruiker was er niets te zien.

    Wat heb ik al gedaan :

    * opgestart in veilige modus en vervolgens via systeemherstel terug gegaan naar een vorig herstelpunt, hierna lijkt mij alles terug te werken.

    * vervolgens gescant met MawareBytes AntiMalware : niets gevonden volgens mij , zie verslag hieronder :

    Malwarebytes Anti-Malware 1.65.0.1400

    www.malwarebytes.org

    Databaseversie: v2012.09.14.04

    Windows 7 Service Pack 1 x86 NTFS

    Internet Explorer 8.0.7601.17514

    Koen :: KOEN-PC [administrator]

    14/09/2012 17:51:41

    mbam-log-2012-09-14 (17-51-41).txt

    Scantype: Volledige scan (C:\|)

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 679005

    Verstreken tijd: 1 uur/uren, 40 minuut/minuten, 24 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    * Vervolgens ComboFix gedonwload en laten draaien, verslagje hieronder :

    ComboFix 12-09-14.03 - Koen 14/09/2012 20:24:33.1.2 - x86

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.2941.1565 [GMT 2:00]

    Gestart vanuit: c:\users\Koen\Desktop\ComboFix.exe

    AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

    FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}

    SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\program files\DealPly

    c:\program files\DealPly\DealPlyIE.dll

    c:\program files\DealPly\icon.ico

    c:\program files\DealPly\uninst.exe

    c:\programdata\dsgsdgdsgdsgw.pad

    c:\users\Koen\AppData\Roaming\inst.exe

    c:\users\Koen\AppData\Roaming\vso_ts_preview.xml

    c:\windows\isRS-000.tmp

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-08-14 to 2012-09-14 ))))))))))))))))))))))))))))))

    .

    .

    2012-09-14 18:38 . 2012-09-14 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-09-14 15:06 . 2012-09-14 15:10 -------- d-----w- c:\program files\DownloadManager

    2012-09-14 15:05 . 2012-09-14 15:05 -------- d-----w- c:\programdata\Browser Manager

    2012-09-14 15:05 . 2012-09-14 15:05 315 ----a-w- C:\user.js

    2012-09-14 15:05 . 2012-09-14 15:05 -------- d-----w- c:\program files\BabylonToolbar

    2012-09-14 15:05 . 2012-09-14 15:05 -------- d-----w- c:\users\Koen\AppData\Roaming\Babylon

    2012-09-14 15:05 . 2012-09-14 15:05 -------- d-----w- c:\programdata\Babylon

    2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-09-07 19:42 . 2012-03-30 14:50 696520 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-09-07 19:42 . 2011-07-10 12:17 73416 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-09-07 15:04 . 2011-12-01 18:52 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-07-26 01:21 . 2012-07-26 01:21 237408 ----a-w- c:\windows\system32\drivers\avgldx86.sys

    2012-07-18 17:47 . 2012-08-15 17:18 2345984 ----a-w- c:\windows\system32\win32k.sys

    2012-07-04 21:14 . 2012-08-15 17:18 41984 ----a-w- c:\windows\system32\browcli.dll

    2012-07-04 21:14 . 2012-08-15 17:18 102912 ----a-w- c:\windows\system32\browser.dll

    2012-06-27 05:53 . 2012-08-15 17:18 981504 ----a-w- c:\windows\system32\wininet.dll

    2012-06-27 04:10 . 2012-08-15 17:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb

    2012-06-25 14:04 . 2012-06-25 14:04 1394248 ----a-w- c:\windows\system32\msxml4.dll

    2012-07-14 00:15 . 2012-07-21 18:31 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

    2012-07-10 06:45 2074208 ----a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-07-10 2074208]

    .

    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]

    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

    "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984]

    "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-07-10 1107552]

    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]

    "ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-16 928096]

    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]

    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456]

    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

    .

    c:\users\Koen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    OneNote 2010 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

    "AppInit_DLLs"=c:\progra~2\BROWSE~1\22643~1.41\{16CDF~1\browsemngr.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

    "aux"=wdmaud.drv

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

    * Vervolgens HijackThis gedownload en laten draaien, verslagje hieronder :

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 21:55:10, on 14/09/2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v8.00 (8.00.7601.17514)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\MAGIX\PC_Check_Tuning_2011_Download-versie\MxTray.exe

    C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    C:\Program Files\AVG\AVG2012\avgtray.exe

    C:\Program Files\AVG Secure Search\vprot.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Zune\ZuneLauncher.exe

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\AVG\AVG2012\avgcfgex.exe

    C:\Windows\system32\NOTEPAD.EXE

    C:\Users\Koen\Desktop\HijackThis.exe

    C:\Windows\system32\SearchFilterHost.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = deredactie.be

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.6.9.12\bh\BabylonToolbar.dll

    O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL

    O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll

    O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)

    O4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices

    O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"

    O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

    O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay België (file missing)

    O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay België (file missing)

    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay België (file missing) (HKCU)

    O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - eBay België (file missing) (HKCU)

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll

    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O20 - AppInit_DLLs: c:\progra~2\browse~1\22643~1.41\{16cdf~1\browse~1.dll c:\progra~2\browse~1\22643~1.41\{16cdf~1\browsemngr.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe

    O23 - Service: Browser Manager - Unknown owner - C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MAGIX StartUp Analyze Service - MAGIX AG - C:\Program Files\MAGIX\PC_Check_Tuning_2011_Download-versie\MXSAS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

    --

    End of file - 9544 bytes

    Toch wel even vermelden dat ik een leek ben in dit alles en al hetgeen hierboven staat is pure chinees voor mij :-)

    Moest er iemand eens tijd hebben om ernaar te kijken, weet weet wat er nog allemaal op zit ;-)

    Alvast bedankt voor de moeite, mijn eeuwige dank (en een paar pinten misschien :-), zal uw deel zijn !

    Grtz.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.