Hallo,
Ik heb recent een cleane herinstallatie gedaan van mijn Vista 64bit. Bijna van in het begin heb ik het probleem dat 9 vd 10 keer mijn pcvastloopt op het bureaublad. Meestal verschijnt de taakbalk onderaan niet, soms heeft deze een rare kleur.
Hierbij de HiJackThis log: (en alvast bedankt voor de moeite )
Ik denk niet dat dit iets met spyware/malware te maken heeft, aangezien het een verse herinstallatie is, en ik zo goed als onmiddelijk Avast! heb geïnstalleerd.
Het lijkt mij raar dat iexplorer.exe meerdere keren vermeld is, aangezien ik maar 1 internetpagina had openstaan toen de scan liep...
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at
18:18:35, on 4/12/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE:
Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal
Running
processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program
Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files
(x86)\HP\HP Software
Update\hpwuSchd2.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files
(x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet
Explorer\iexplore.exe
C:\Program Files (x86)\Windows
Mail\WinMail.exe
C:\Program Files (x86)\Internet
Explorer\iexplore.exe
C:\Program Files (x86)\Internet
Explorer\iexplore.exe
C:\Program Files (x86)\Internet
Explorer\iexplore.exe
C:\Users\Van den
Broeck\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page = Bing
R0
- HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 -
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN | Hotmail
| Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel
meer, dat is MSN !
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = Bing
R1
- HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN | Hotmail
| Messenger | Nieuws, sport, entertainment, video, lifestyle, auto en nog veel
meer, dat is MSN !
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 -
HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 -
REGystem.ini:
UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub
- {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java Plug-In
SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
(x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep -
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST
Software\Avast\aswWebRepIE.dll
O2 - BHO: Java Plug-In 2 SSV Helper -
{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
(x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep -
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST
Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program
Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run:
[sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java
Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files
(x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [startCCC]
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
MSRun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common
Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run:
[QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4
- HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [beid] "C:\Program Files
(x86)\Belgium Identity Card\beid35gui.exe" /startup
O4 - HKLM\..\Run:
[bePCSC] C:\Program Files (x86)\EmvSmartCardReader\BePCSC.exe
O4 -
HKLM\..\Run: [smartMon] C:\Program Files
(x86)\EmvSmartCardReader\SmartMON.exe
O4 - HKUS\S-1-5-19\..\Run: [sidebar]
%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL
SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe
oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 -
HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe
/detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item:
E&xporteren naar Microsoft Excel -
res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button:
Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group:
[ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: Taalkeuze/Choix de langue
fedict.belgium.be
O15 - Trusted Zone: *.minfin.fgov.be
O16 - DPF:
{A996E48C-D3DC-4244-89F7-AFA33EC60679} (Settings Class) - http://ccff02.minfin.fgov.be/diagnos...js/capicom.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{5DC78DDE-29C4-4CA4-8B89-D78DB9B0C551}:
NameServer = 193.121.171.135 193.74.208.135
O17 -
HKLM\System\CS1\Services\Tcpip\..\{5DC78DDE-29C4-4CA4-8B89-D78DB9B0C551}:
NameServer = 193.121.171.135 193.74.208.135
O22 - SharedTaskScheduler:
Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -
C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service
(AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common
Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service:
@%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner -
C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events
Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23
- Service: ASP.NET-statusservice (aspnet_state) - Unknown owner -
C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspn et_state.exe (file
missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program
Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Canon Camera Access
Library 8 (CCALib8) - Canon Inc. - C:\Program Files
(x86)\Canon\CAL\CALMAIN.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown
owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service:
@keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file
missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner -
C:\Windows\System32\msdtc.exe (file missing)
O23 - Service:
@%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner -
C:\Windows\system32\lsass.exe (file missing)
O23 - Service:
@%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner -
C:\Windows\system32\lsass.exe (file missing)
O23 - Service:
@%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner -
C:\Windows\system32\locator.exe (file missing)
O23 - Service:
@%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner -
C:\Windows\system32\lsass.exe (file missing)
O23 - Service:
@%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner -
C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service:
@%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner -
C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service:
@%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner -
C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service:
@%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner -
C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service:
@%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner -
C:\Windows\System32\vds.exe (file missing)
O23 - Service:
@%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner -
C:\Windows\system32\vssvc.exe (file missing)
O23 - Service:
@%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner -
C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service:
@%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown
owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file
missing)
--
End of file - 7441 bytes