Ga naar inhoud

taha_alto

Lid
  • Items

    11
  • Registratiedatum

  • Laatst bezocht

taha_alto's prestaties

  1. ik heb geprobeert via de update, en ook vie rechtstreeks maar ze werken van allebij de kanten niet :S en dat vind ik ook raar. heb je mischien een oplossing? MVG,
  2. Hallo, ik heb de test gedaan, en hij deed er 14uur over, maar hij heeft niets gevonden, en ik kan dus die log niet klikken via ''bestand, reportagelijst opslaan'' Kun je me vertellen wat ik nu moet doen? MVG,
  3. hallo, ik merk niet zoveel verschil, maar mijn probleem eigenlijk was het niet kunnen installeren van de update naar vist service pack 2, heb je mischien een oplossing hiervoor die ik nog niet heb gedaan? MVG,
  4. hallo, ik heb geprobeert die sfc scan uit te voeren, maar als ik er op klik komt er zo'n scherm en is binnen een miliseconde weer weg, en er gebeurt dan niets. kun je me nog helpen? MVG,
  5. hallo, ik heb northon verdwijdert, en toen weer een log gemaakt met combofix, dit is de log: ComboFix 09-10-30.01 - Taha 31-10-2009 17:59.2.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.3062.1769 [GMT 1:00] Gestart vanuit: c:\users\Taha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OQDAKY5M\ComboFix.exe AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Aanwezig AV is actief . (((((((((((((((((((( Bestanden Gemaakt van 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))) . 2009-10-31 17:14 . 2009-10-31 17:14 -------- d-----w- c:\users\Public\AppData\Local\temp 2009-10-31 17:14 . 2009-10-31 17:14 -------- d-----w- c:\users\Gast\AppData\Local\temp 2009-10-31 17:14 . 2009-10-31 17:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-10-31 17:14 . 2009-10-31 17:14 -------- d-----w- c:\users\Alknaty\AppData\Local\temp 2009-10-31 16:59 . 2008-03-12 06:38 21560 ----a-w- c:\windows\system32\drivers\atapi.sys 2009-10-31 16:59 . 2007-09-29 21:03 308248 ----a-w- c:\windows\system32\drivers\iaStor.sys 2009-10-31 16:59 . 2007-06-01 08:29 210736 ----a-w- c:\windows\system32\drivers\Si3531.sys 2009-10-28 21:09 . 2009-10-28 21:09 -------- d-----w- c:\users\Taha\AppData\Roaming\Pointstone 2009-10-28 20:48 . 2009-10-31 16:43 -------- d-----w- c:\program files\Pointstone 2009-10-28 20:48 . 2009-10-31 16:32 -------- d-----w- c:\program files\Common Files\Pointstone 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\users\Taha\AppData\Roaming\Malwarebytes 2009-10-28 19:41 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\programdata\Malwarebytes 2009-10-28 19:41 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-28 10:12 . 2009-10-28 10:12 -------- d-----w- c:\program files\Trend Micro 2009-10-28 08:27 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe 2009-10-28 08:27 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-10-26 08:16 . 2009-10-28 11:10 -------- d-----w- c:\users\Taha\School 2009-10-25 19:05 . 2009-10-25 19:05 -------- d-----w- c:\users\Taha\AppData\Local\mdnslib 2009-10-25 19:04 . 2009-10-30 23:28 -------- d-----w- c:\users\Taha\AppData\Local\FLVService 2009-10-20 21:47 . 2009-10-20 21:49 -------- d-----w- C:\53e63e85f50a7cc159c0a06e 2009-10-20 10:14 . 2009-10-28 21:09 -------- d-----w- c:\program files\Replay Media Catcher 2009-10-15 07:38 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-15 07:38 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-10-15 07:38 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-10-13 19:51 . 2009-10-13 19:51 -------- d-----w- c:\program files\AAALOGO2009 2009-10-09 21:18 . 2009-10-09 22:16 -------- d-----w- c:\programdata\FLEXnet 2009-10-09 21:09 . 2009-10-09 21:09 -------- d-----w- c:\program files\Adobe Media Player 2009-10-09 21:08 . 2009-10-09 21:08 -------- d-----w- c:\programdata\WindowsSearch 2009-10-09 21:05 . 2009-10-09 21:05 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-10-09 20:59 . 2009-10-09 20:59 -------- d-----w- c:\program files\Common Files\Macrovision Shared 2009-10-09 15:37 . 2009-10-09 17:11 -------- d-----w- c:\users\Taha\AppData\Roaming\Download Manager 2009-10-08 14:35 . 2009-10-08 14:36 -------- d-----w- c:\users\Taha\AppData\Roaming\Media Player Classic 2009-10-04 11:23 . 2009-10-04 11:24 -------- d-----w- c:\users\Gast\AppData\Local\Adobe 2009-10-04 09:15 . 2009-10-04 09:15 -------- d-----w- c:\users\Gast\AppData\Local\Google 2009-10-03 18:30 . 2009-10-24 18:24 -------- d-----w- c:\program files\ALLPlayer 2009-10-03 18:26 . 2009-10-03 18:26 -------- d-----w- c:\users\Taha\AppData\Roaming\CyberLink 2009-10-03 18:26 . 2009-10-03 18:26 -------- d-----w- c:\users\Public\CyberLink 2009-10-03 18:24 . 2009-10-03 18:25 -------- d-----w- c:\program files\Avi Player . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-31 16:50 . 2008-01-21 06:47 667352 ----a-w- c:\windows\system32\perfh013.dat 2009-10-31 16:50 . 2008-01-21 06:47 126854 ----a-w- c:\windows\system32\perfc013.dat 2009-10-31 16:43 . 2009-09-29 18:17 -------- d-----w- c:\programdata\Norton 2009-10-28 21:29 . 2009-08-25 15:38 73008 ----a-w- c:\users\Taha\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-28 21:09 . 2008-04-25 08:04 -------- d-----w- c:\program files\Launch Manager 2009-10-25 19:05 . 2009-08-27 12:51 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll 2009-10-25 19:05 . 2009-08-27 12:51 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe 2009-10-24 18:28 . 2009-06-08 19:29 -------- d-----w- c:\program files\Philips 2009-10-24 18:28 . 2008-04-24 14:02 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-24 18:22 . 2009-08-27 12:51 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL 2009-10-20 20:55 . 2008-04-25 10:40 -------- d-----w- c:\program files\Common Files\Adobe 2009-10-15 15:15 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-10-15 15:08 . 2008-04-28 06:59 -------- d-----w- c:\programdata\Microsoft Help 2009-10-09 13:11 . 2009-09-01 19:46 680 ----a-w- c:\users\Taha\AppData\Local\d3d9caps.dat 2009-10-03 18:26 . 2008-04-28 06:44 -------- d-----w- c:\programdata\CyberLink 2009-10-01 08:30 . 2009-10-01 08:30 -------- d-----w- c:\programdata\Symantec 2009-09-29 18:17 . 2009-09-29 18:17 -------- d-----w- c:\programdata\NortonInstaller 2009-09-26 20:38 . 2009-09-26 20:24 -------- d-----w- c:\users\Gast\AppData\Roaming\DivX 2009-09-26 19:36 . 2009-09-26 19:36 73008 ----a-w- c:\users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-24 15:18 . 2009-08-26 13:58 -------- d-----w- c:\users\Taha\AppData\Roaming\Apple Computer 2009-09-24 13:47 . 2009-09-24 13:46 -------- d-----w- c:\program files\iTunes 2009-09-24 13:46 . 2009-09-24 13:46 -------- d-----w- c:\program files\iPod 2009-09-24 13:46 . 2009-08-26 14:06 -------- d-----w- c:\program files\Common Files\Apple 2009-09-23 19:04 . 2009-09-01 13:42 -------- d-----w- c:\users\Taha\AppData\Roaming\DivX 2009-09-19 08:23 . 2009-09-19 08:23 -------- d-----w- c:\programdata\SiteAdvisor 2009-09-18 09:34 . 2009-08-31 11:18 -------- d-----w- c:\programdata\McAfee 2009-09-18 09:34 . 2009-09-18 09:34 -------- d-----w- c:\program files\Common Files\McAfee 2009-09-18 09:34 . 2009-08-31 11:18 -------- d-----w- c:\program files\McAfee 2009-09-17 12:15 . 2008-04-25 10:57 -------- d-----w- c:\program files\Common Files\Nero 2009-09-17 12:15 . 2008-04-25 10:57 -------- d-----w- c:\programdata\Nero 2009-09-14 09:44 . 2009-10-15 07:37 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-09-11 10:28 . 2009-09-04 09:31 -------- d-----w- c:\users\Taha\AppData\Roaming\HpUpdate 2009-09-11 09:08 . 2009-09-11 09:06 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-09-11 09:05 . 2009-09-11 09:04 -------- d-----w- c:\program files\QuickTime 2009-09-09 09:23 . 2008-04-28 07:23 -------- d-----w- c:\program files\Microsoft Silverlight 2009-09-04 21:24 . 2009-09-04 21:23 -------- d-----w- c:\program files\Common Files\Real 2009-09-04 21:24 . 2009-09-04 21:24 -------- d-----w- c:\program files\Common Files\xing shared 2009-09-04 21:23 . 2009-09-04 21:23 -------- d-----w- c:\program files\Real 2009-09-04 12:24 . 2009-10-15 07:37 61440 ----a-w- c:\windows\system32\msasn1.dll 2009-08-31 13:55 . 2009-10-15 07:37 293376 ----a-w- c:\windows\system32\psisdecd.dll 2009-08-31 13:55 . 2009-10-15 07:37 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-08-28 12:39 . 2009-09-02 08:00 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-28 10:15 . 2009-09-02 08:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-28 09:39 . 2009-08-28 09:33 118133 ----a-w- c:\windows\hpqins00.dat 2009-08-27 11:05 . 2009-08-27 11:06 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-08-27 05:22 . 2009-10-15 07:37 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 05:17 . 2009-10-15 07:37 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 05:17 . 2009-10-15 07:37 109056 ----a-w- c:\windows\system32\iesysprep.dll 2009-08-27 03:42 . 2009-10-15 07:37 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 17:07 . 2009-09-09 07:24 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 16:29 . 2009-09-09 07:24 104960 ----a-w- c:\windows\system32\netiohlp.dll 2009-08-14 16:29 . 2009-09-09 07:24 17920 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 14:16 . 2009-09-09 07:24 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:16 . 2009-09-09 07:24 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 14:16 . 2009-09-09 07:24 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 14:16 . 2009-09-09 07:24 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:16 . 2009-09-09 07:24 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 14:16 . 2009-09-09 07:24 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:16 . 2009-09-09 07:24 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-03 13:07 . 2009-08-03 13:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll 2009-08-03 13:07 . 2009-08-03 13:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll 2009-08-03 13:07 . 2009-08-03 13:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe . ((((((((((((((((((((((((((((( SnapShot@2009-10-30_09.34.58 ))))))))))))))))))))))))))))))))))))))))) . + 2008-01-21 01:58 . 2009-10-31 16:46 55854 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2006-11-02 13:05 . 2009-10-31 16:46 76834 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2009-08-25 15:39 . 2009-10-31 16:46 10916 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3055018389-3510018732-2939917457-1001_UserData.bin - 2008-04-29 12:25 . 2009-10-30 09:02 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-04-29 12:25 . 2009-10-31 16:43 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-04-29 12:25 . 2009-10-31 17:10 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-04-29 12:25 . 2009-10-30 09:31 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-04-29 12:25 . 2009-10-30 09:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-04-29 12:25 . 2009-10-31 17:10 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2006-11-02 10:25 . 2009-10-31 16:34 86016 c:\windows\inf\infstor.dat - 2006-11-02 10:25 . 2009-10-01 06:19 86016 c:\windows\inf\infstor.dat - 2006-11-02 10:25 . 2009-10-01 06:19 51200 c:\windows\inf\infpub.dat + 2006-11-02 10:25 . 2009-10-31 16:34 51200 c:\windows\inf\infpub.dat + 2009-10-30 15:19 . 2009-10-30 15:19 5706 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\zoek.upc.nl\upc.nl\Data.dat + 2009-10-30 21:33 . 2009-10-30 21:33 4590 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\vvalmerehaven.nl\vvalmerehaven.nl\Data.dat - 2009-10-30 08:18 . 2009-10-30 08:18 5188 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\pc%2Dhelpforum.be\pc%2Dhelpforum.be\Data.dat + 2009-10-30 22:31 . 2009-10-30 22:31 5188 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\pc%2Dhelpforum.be\pc%2Dhelpforum.be\Data.dat + 2009-10-30 20:57 . 2009-10-30 20:57 5788 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\microsoft.com\microsoft.com\Data.dat - 2009-10-28 19:33 . 2009-10-28 19:33 5788 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\microsoft.com\microsoft.com\Data.dat - 2009-10-27 21:18 . 2009-10-27 21:18 5766 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\ioffer.com\ioffer.com\Data.dat + 2009-10-30 15:16 . 2009-10-30 15:16 5766 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\ioffer.com\ioffer.com\Data.dat + 2009-10-30 15:30 . 2009-10-30 15:30 3250 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\hi5i.cn\hi5i.cn\Data.dat - 2009-10-30 08:30 . 2009-10-30 08:30 5916 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\google.nl\google.nl\Data.dat + 2009-10-30 21:00 . 2009-10-30 21:00 5916 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\google.nl\google.nl\Data.dat + 2009-10-30 15:18 . 2009-10-30 15:18 3264 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\google.l\google.l\Data.dat + 2009-10-30 15:20 . 2009-10-30 15:20 4562 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\dean%2Ddeluca.nl\dean%2Ddeluca.nl\Data.dat + 2009-10-30 15:11 . 2009-10-30 15:11 3320 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\bbbtrade.com\bbbtrade.com\Data.dat + 2009-10-30 20:57 . 2009-10-30 20:57 5752 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\atdmt.com\atdmt.com\Data.dat + 2009-10-30 21:35 . 2009-10-30 21:35 4940 c:\windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\armaan.nl\armaan.nl\Data.dat - 2009-10-30 09:02 . 2009-10-30 09:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-10-31 16:43 . 2009-10-31 16:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-10-30 09:02 . 2009-10-30 09:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-10-31 16:43 . 2009-10-31 16:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2006-11-02 10:33 . 2009-10-31 16:50 587178 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-10-30 09:09 587178 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-10-31 16:50 101250 c:\windows\System32\perfc009.dat - 2006-11-02 10:33 . 2009-10-30 09:09 101250 c:\windows\System32\perfc009.dat + 2006-11-02 10:25 . 2009-10-31 16:34 143360 c:\windows\inf\infstrng.dat - 2006-11-02 10:25 . 2009-10-01 06:19 143360 c:\windows\inf\infstrng.dat . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-06-04 869888] "AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-05-18 136512] "LanguageShortcut"="c:\program files\HomeCinema\PowerDVD\Language\Language.exe" [2007-01-08 52256] "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2007-09-07 86016] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-04 198160] "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-27 149280] "snpstd3"="c:\windows\vsnpstd3.exe" [2005-09-05 339968] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-09 124240] "RemoteControl"="c:\program files\HomeCinema\PowerDVD\PDVDServ.exe" [2007-02-09 71216] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656] "LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224] "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424] "HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-29 220160] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" [2009-09-22 156672] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-04-01 6025216] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" R0 Si3531;SiI-3531 SATA Controller;c:\windows\System32\drivers\Si3531.sys [31-10-2009 17:59 210736] R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [9-4-2009 19:07 21256] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\System32\mfevtps.exe [18-9-2009 10:34 70216] R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [25-4-2008 8:55 327168] R3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [25-4-2008 9:04 118784] S2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [20-11-2008 16:11 231424] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\System32\drivers\mferkdet.sys [18-9-2009 10:35 65224] --- Andere Services/Drivers In Geheugen --- *Deregistered* - mbr [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhoud van de 'Gedeelde Taken' map 2009-10-30 c:\windows\Tasks\User_Feed_Synchronization-{74F5618A-40BF-480C-96B4-4DA946C57076}.job - c:\windows\system32\msfeedssync.exe [2009-10-15 03:41] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.nl/ uInternet Settings,ProxyOverride = <local> IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2009-10-31 18:15 Windows 6.0.6001 Service Pack 1 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 "MSCurrentCountry"=dword:0000007b . --------------------- DLLs Geladen Onder Lopende Processen --------------------- - - - - - - - > 'Explorer.exe'(5332) c:\users\Taha\AppData\Local\FLVService\lib\FLVSrvLib.dll c:\program files\Softex\OmniPass\SCUREDLL.dll c:\program files\McAfee\Common Framework\JrMac.dll . Voltooingstijd: 2009-10-31 18:18 ComboFix-quarantined-files.txt 2009-10-31 17:18 ComboFix2.txt 2009-10-30 09:39 Pre-Run: 70.219.157.504 bytes beschikbaar Post-Run: 70.184.583.168 bytes beschikbaar - - End Of File - - EC1FB0851FA3DEDEE72E647EECF297C3 ==================================== Ik heb op die link bekeken van microsoft, daarin staat dat ik een DVD van vista moet hebben ofso,... maar ik heb geen DVD of iets dergelijke van vista want ik had vista automatisch in mijn laptop toen ik hem kocht. kun je me vertellen wat ik nu moet doen? =D MVG,
  6. haha..oke!! bedankt, ik heb een eraf gehaald. en nu wachten op de pro die mijn log ff checkt =D MVG,
  7. ik gebruik northon, moet ik ze dus allebij verdwijderen? kan ik niet 1 houden? kun je me ook gelijk vertellen wat ik daarna moet doen?? MVG,
  8. hallo, oke haha.. ik heb het gedaan en dit is het logg: ComboFix 09-10-28.08 - Taha 30-10-2009 10:13.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.3062.1735 [GMT 1:00] Gestart vanuit: c:\users\Taha\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AHMP642G\ComboFix.exe AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} SP: VirusScan Enterprise + AntiSpyware Enterprise *enabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Aanwezig AV is actief . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\programdata\Microsoft\Network\Downloader\qmgr0.dat c:\programdata\Microsoft\Network\Downloader\qmgr1.dat ----- BITS: Mogelijk geïnfecteerde sites ----- hxxp://armmf.adobe.com . (((((((((((((((((((( Bestanden Gemaakt van 2009-09-28 to 2009-10-30 )))))))))))))))))))))))))))))) . 2009-10-30 09:34 . 2009-10-30 09:34 -------- d-----w- c:\users\Gast\AppData\Local\temp 2009-10-30 09:34 . 2009-10-30 09:34 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-10-30 09:34 . 2009-10-30 09:34 -------- d-----w- c:\users\Alknaty\AppData\Local\temp 2009-10-30 09:13 . 2008-03-12 06:38 21560 ----a-w- c:\windows\system32\drivers\atapi.sys 2009-10-30 09:13 . 2007-09-29 21:03 308248 ----a-w- c:\windows\system32\drivers\iaStor.sys 2009-10-30 09:13 . 2007-06-01 08:29 210736 ----a-w- c:\windows\system32\drivers\Si3531.sys 2009-10-28 21:09 . 2009-10-28 21:09 -------- d-----w- c:\users\Taha\AppData\Roaming\Pointstone 2009-10-28 20:48 . 2009-10-28 20:48 -------- d-----w- c:\program files\Pointstone 2009-10-28 20:48 . 2009-10-28 20:48 -------- d-----w- c:\program files\Common Files\Pointstone 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\users\Taha\AppData\Roaming\Malwarebytes 2009-10-28 19:41 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\programdata\Malwarebytes 2009-10-28 19:41 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-28 19:41 . 2009-10-28 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-28 10:12 . 2009-10-28 10:12 -------- d-----w- c:\program files\Trend Micro 2009-10-28 08:27 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe 2009-10-28 08:27 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-10-26 08:16 . 2009-10-28 11:10 -------- d-----w- c:\users\Taha\School 2009-10-25 19:05 . 2009-10-25 19:05 -------- d-----w- c:\users\Taha\AppData\Local\mdnslib 2009-10-25 19:04 . 2009-10-30 08:11 -------- d-----w- c:\users\Taha\AppData\Local\FLVService 2009-10-20 21:47 . 2009-10-20 21:49 -------- d-----w- C:\53e63e85f50a7cc159c0a06e 2009-10-20 10:14 . 2009-10-28 21:09 -------- d-----w- c:\program files\Replay Media Catcher 2009-10-15 07:38 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-15 07:38 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-10-15 07:38 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-10-13 19:51 . 2009-10-13 19:51 -------- d-----w- c:\program files\AAALOGO2009 2009-10-09 21:18 . 2009-10-09 22:16 -------- d-----w- c:\programdata\FLEXnet 2009-10-09 21:09 . 2009-10-09 21:09 -------- d-----w- c:\program files\Adobe Media Player 2009-10-09 21:08 . 2009-10-09 21:08 -------- d-----w- c:\programdata\WindowsSearch 2009-10-09 21:05 . 2009-10-09 21:05 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-10-09 20:59 . 2009-10-09 20:59 -------- d-----w- c:\program files\Common Files\Macrovision Shared 2009-10-09 15:37 . 2009-10-09 17:11 -------- d-----w- c:\users\Taha\AppData\Roaming\Download Manager 2009-10-08 14:35 . 2009-10-08 14:36 -------- d-----w- c:\users\Taha\AppData\Roaming\Media Player Classic 2009-10-04 11:23 . 2009-10-04 11:24 -------- d-----w- c:\users\Gast\AppData\Local\Adobe 2009-10-04 09:15 . 2009-10-04 09:15 -------- d-----w- c:\users\Gast\AppData\Local\Google 2009-10-03 18:30 . 2009-10-24 18:24 -------- d-----w- c:\program files\ALLPlayer 2009-10-03 18:26 . 2009-10-03 18:26 -------- d-----w- c:\users\Taha\AppData\Roaming\CyberLink 2009-10-03 18:26 . 2009-10-03 18:26 -------- d-----w- c:\users\Public\CyberLink 2009-10-03 18:24 . 2009-10-03 18:25 -------- d-----w- c:\program files\Avi Player 2009-10-01 08:30 . 2009-10-01 08:30 -------- d-----w- c:\programdata\Symantec . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-30 09:09 . 2008-01-21 06:47 667352 ----a-w- c:\windows\system32\perfh013.dat 2009-10-30 09:09 . 2008-01-21 06:47 126854 ----a-w- c:\windows\system32\perfc013.dat 2009-10-28 21:29 . 2009-08-25 15:38 73008 ----a-w- c:\users\Taha\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-28 21:09 . 2008-04-25 08:04 -------- d-----w- c:\program files\Launch Manager 2009-10-25 19:05 . 2009-08-27 12:51 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll 2009-10-25 19:05 . 2009-08-27 12:51 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe 2009-10-24 18:28 . 2009-06-08 19:29 -------- d-----w- c:\program files\Philips 2009-10-24 18:28 . 2008-04-24 14:02 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-24 18:22 . 2009-08-27 12:51 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL 2009-10-20 20:55 . 2008-04-25 10:40 -------- d-----w- c:\program files\Common Files\Adobe 2009-10-15 15:15 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-10-15 15:08 . 2008-04-28 06:59 -------- d-----w- c:\programdata\Microsoft Help 2009-10-09 13:11 . 2009-09-01 19:46 680 ----a-w- c:\users\Taha\AppData\Local\d3d9caps.dat 2009-10-03 18:26 . 2008-04-28 06:44 -------- d-----w- c:\programdata\CyberLink 2009-09-30 18:44 . 2009-09-29 18:18 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF 2009-09-30 18:44 . 2009-09-29 18:18 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2009-09-30 18:44 . 2009-09-29 18:18 -------- d-----w- c:\program files\Symantec 2009-09-30 18:44 . 2009-09-29 18:18 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2009-09-29 18:53 . 2009-09-29 18:18 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-09-29 18:18 . 2009-09-29 18:17 -------- d-----w- c:\programdata\Norton 2009-09-29 18:18 . 2009-09-29 18:17 -------- d-----w- c:\program files\Norton AntiVirus 2009-09-29 18:17 . 2009-09-29 18:17 -------- d-----w- c:\program files\NortonInstaller 2009-09-29 18:17 . 2009-09-29 18:17 -------- d-----w- c:\programdata\NortonInstaller 2009-09-26 20:38 . 2009-09-26 20:24 -------- d-----w- c:\users\Gast\AppData\Roaming\DivX 2009-09-26 19:36 . 2009-09-26 19:36 73008 ----a-w- c:\users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-24 15:18 . 2009-08-26 13:58 -------- d-----w- c:\users\Taha\AppData\Roaming\Apple Computer 2009-09-24 13:47 . 2009-09-24 13:46 -------- d-----w- c:\program files\iTunes 2009-09-24 13:46 . 2009-09-24 13:46 -------- d-----w- c:\program files\iPod 2009-09-24 13:46 . 2009-08-26 14:06 -------- d-----w- c:\program files\Common Files\Apple 2009-09-23 19:04 . 2009-09-01 13:42 -------- d-----w- c:\users\Taha\AppData\Roaming\DivX 2009-09-19 08:23 . 2009-09-19 08:23 -------- d-----w- c:\programdata\SiteAdvisor 2009-09-18 09:34 . 2009-08-31 11:18 -------- d-----w- c:\programdata\McAfee 2009-09-18 09:34 . 2009-09-18 09:34 -------- d-----w- c:\program files\Common Files\McAfee 2009-09-18 09:34 . 2009-08-31 11:18 -------- d-----w- c:\program files\McAfee 2009-09-17 12:15 . 2008-04-25 10:57 -------- d-----w- c:\program files\Common Files\Nero 2009-09-17 12:15 . 2008-04-25 10:57 -------- d-----w- c:\programdata\Nero 2009-09-14 09:44 . 2009-10-15 07:37 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-09-11 10:28 . 2009-09-04 09:31 -------- d-----w- c:\users\Taha\AppData\Roaming\HpUpdate 2009-09-11 09:08 . 2009-09-11 09:06 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-09-11 09:05 . 2009-09-11 09:04 -------- d-----w- c:\program files\QuickTime 2009-09-09 09:23 . 2008-04-28 07:23 -------- d-----w- c:\program files\Microsoft Silverlight 2009-09-04 21:24 . 2009-09-04 21:23 -------- d-----w- c:\program files\Common Files\Real 2009-09-04 21:24 . 2009-09-04 21:24 -------- d-----w- c:\program files\Common Files\xing shared 2009-09-04 21:23 . 2009-09-04 21:23 -------- d-----w- c:\program files\Real 2009-09-04 12:24 . 2009-10-15 07:37 61440 ----a-w- c:\windows\system32\msasn1.dll 2009-09-01 06:39 . 2009-09-01 06:39 -------- d-----w- c:\program files\BitLord 2009-09-01 06:01 . 2009-09-01 06:00 -------- d-----w- c:\program files\Windows Live 2009-09-01 06:00 . 2009-09-01 06:00 -------- d-----w- c:\program files\Microsoft 2009-09-01 06:00 . 2009-09-01 06:00 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-08-31 13:55 . 2009-10-15 07:37 293376 ----a-w- c:\windows\system32\psisdecd.dll 2009-08-31 13:55 . 2009-10-15 07:37 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-08-31 11:18 . 2009-08-31 11:18 -------- d-----w- c:\program files\Common Files\Cisco Systems 2009-08-28 12:39 . 2009-09-02 08:00 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-28 10:15 . 2009-09-02 08:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-28 09:39 . 2009-08-28 09:33 118133 ----a-w- c:\windows\hpqins00.dat 2009-08-27 11:05 . 2009-08-27 11:06 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-08-27 05:22 . 2009-10-15 07:37 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 05:17 . 2009-10-15 07:37 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 05:17 . 2009-10-15 07:37 109056 ----a-w- c:\windows\system32\iesysprep.dll 2009-08-27 03:42 . 2009-10-15 07:37 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-25 23:34 . 2009-09-29 18:18 25648 ----a-r- c:\windows\system32\drivers\SymIMV.sys 2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 17:07 . 2009-09-09 07:24 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 16:29 . 2009-09-09 07:24 104960 ----a-w- c:\windows\system32\netiohlp.dll 2009-08-14 16:29 . 2009-09-09 07:24 17920 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 14:16 . 2009-09-09 07:24 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:16 . 2009-09-09 07:24 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 14:16 . 2009-09-09 07:24 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 14:16 . 2009-09-09 07:24 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:16 . 2009-09-09 07:24 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 14:16 . 2009-09-09 07:24 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:16 . 2009-09-09 07:24 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-03 13:07 . 2009-08-03 13:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll 2009-08-03 13:07 . 2009-08-03 13:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll 2009-08-03 13:07 . 2009-08-03 13:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-06-04 869888] "AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-05-18 136512] "LanguageShortcut"="c:\program files\HomeCinema\PowerDVD\Language\Language.exe" [2007-01-08 52256] "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2007-09-07 86016] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-04 198160] "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-27 149280] "snpstd3"="c:\windows\vsnpstd3.exe" [2005-09-05 339968] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-09 124240] "RemoteControl"="c:\program files\HomeCinema\PowerDVD\PDVDServ.exe" [2007-02-09 71216] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656] "LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224] "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424] "HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-29 220160] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" [2009-09-22 156672] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-04-01 6025216] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" R0 Si3531;SiI-3531 SATA Controller;c:\windows\System32\drivers\Si3531.sys [30-10-2009 10:13 210736] R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1007020.00B\SymEFA.sys [30-9-2009 19:44 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1007020.00B\BHDrvx86.sys [30-9-2009 19:44 259632] R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1007020.00B\cchpx86.sys [30-9-2009 19:43 482432] R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091021.001\IDSvix86.sys [23-10-2009 17:16 342576] R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [9-4-2009 19:07 21256] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\System32\mfevtps.exe [18-9-2009 10:34 70216] R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe [30-9-2009 19:43 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [29-9-2009 9:00 102448] R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [25-4-2008 8:55 327168] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NAV\1007020.00B\symndisv.sys [30-9-2009 19:44 48688] R3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [25-4-2008 9:04 118784] S2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [20-11-2008 16:11 231424] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\System32\drivers\mferkdet.sys [18-9-2009 10:35 65224] --- Andere Services/Drivers In Geheugen --- *NewlyCreated* - MBR *Deregistered* - mbr [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhoud van de 'Gedeelde Taken' map 2009-10-30 c:\windows\Tasks\User_Feed_Synchronization-{74F5618A-40BF-480C-96B4-4DA946C57076}.job - c:\windows\system32\msfeedssync.exe [2009-10-15 03:41] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.nl/ uInternet Settings,ProxyOverride = <local> IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover Rootkit scan 2009-10-30 10:34 Windows 6.0.6001 Service Pack 1 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Norton AntiVirus] "ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.7.2.11\diMaster.dll\" /prefetch:1" . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 "MSCurrentCountry"=dword:0000007b . --------------------- DLLs Geladen Onder Lopende Processen --------------------- - - - - - - - > 'Explorer.exe'(4240) c:\users\Taha\AppData\Local\FLVService\lib\FLVSrvLib.dll c:\program files\Softex\OmniPass\SCUREDLL.dll c:\program files\McAfee\VirusScan Enterprise\scriptsn.dll c:\program files\McAfee\VirusScan Enterprise\mytilus3.dll c:\program files\McAfee\VirusScan Enterprise\mytilus3_worker.dll c:\program files\McAfee\VirusScan Enterprise\Res1300\McShield.dll c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll . Voltooingstijd: 2009-10-30 10:39 ComboFix-quarantined-files.txt 2009-10-30 09:39 Pre-Run: 72.346.025.984 bytes beschikbaar Post-Run: 72.394.366.976 bytes beschikbaar - - End Of File - - 0DF3868B55AC3710C8A843D8AF67E704 ================================= Ik hoor nog van je... nogmaals bedankt voor je hulp! =D
  9. hallo, ik heb geprobeert hem te downloaden en te installeren,...ik lees op die site en wat die programma zelf aangeeft dat het een grote risico is. heb je mischien een andere programma, dat geen grote risico heeft? alvast heel erg bedankt. MVG,
  10. hallo, bedankt voor je reactie, ik heb gedaan wat je me vroeg. Bij de hijackthis programma wou ik die dingen aanvinken en verdwijderen maar sommige bleven daar, ''waarom, weet ik niet :S'' dit is de nieuwe log van hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:14:26, on 28-10-2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18828) Boot mode: Normal Running processes: C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Softex\OmniPass\scureapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Launch Manager\WButton.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Launch Manager\OSD.exe C:\Program Files\Launch Manager\LaunchAp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\igfxtray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\hkcmd.exe C:\Program Files\Launch Manager\HotkeyApp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Replay Media Catcher\FLVSrvc.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Avi Player\AviPlayer.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\WerCon.exe C:\Windows\helppane.exe C:\Program Files\Safari\Safari.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:3128 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: McAfee SiteAdvisor - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe" O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSD.exe" O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [HotkeyApp] "C:\Program Files\Launch Manager\HotkeyApp.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Ask and Record FLV Service] "C:\Program Files\Replay Media Catcher\FLVSrvc.exe" /run O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth O4 - HKCU\..\Run: [PopRock] C:\Users\Taha\AppData\Local\Temp\b.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: HP Slim selecteren - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O13 - Gopher Prefix: O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee SiteAdvisor Enterprise Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\OmniServ.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe -- End of file - 11937 bytes ==================================== Ik heb ook dat programma geinstalleerd en de scan gedaan, dit is mbam log: Malwarebytes' Anti-Malware 1.41 Database versie: 3048 Windows 6.0.6001 Service Pack 1 28-10-2009 20:58:56 mbam-log-2009-10-28 (20-58-56).txt Scan type: Snelle Scan Objecten gescand: 111488 Verstreken tijd: 15 minute(s), 57 second(s) Geheugenprocessen geïnfecteerd: 0 Geheugenmodulen geïnfecteerd: 0 Registersleutels geïnfecteerd: 7 Registerwaarden geïnfecteerd: 0 Registerdata bestanden geïnfecteerd: 0 Mappen geïnfecteerd: 0 Bestanden geïnfecteerd: 1 Geheugenprocessen geïnfecteerd: (Geen kwaadaardige items gevonden) Geheugenmodulen geïnfecteerd: (Geen kwaadaardige items gevonden) Registersleutels geïnfecteerd: HKEY_CLASSES_ROOT\xml.xml (Worm.Allaple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\xml.xml.1 (Worm.Allaple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Worm.Allaple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> Quarantined and deleted successfully. Registerwaarden geïnfecteerd: (Geen kwaadaardige items gevonden) Registerdata bestanden geïnfecteerd: (Geen kwaadaardige items gevonden) Mappen geïnfecteerd: (Geen kwaadaardige items gevonden) Bestanden geïnfecteerd: C:\Windows\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully. ============================================ Ik heb weer geprobeerd om de update weer te doen maar hij werkt nogsteeds niet, ik hoop dat je een oplossing voor mijn probleem hebt. alvast heel ereg bedankt,
  11. Hallo, ik heb echt hulp nodig, ik probeer al zo lang de sp.2 te installeren voor mijn vista maar hij werkt maar steeds niet. kan iemand mij aub helpen. geeft aan ''Fout: ERROR_NOT_FOUND(0x80070490) dit is mijn hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:14:26, on 28-10-2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18828) Boot mode: Normal Running processes: C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Softex\OmniPass\scureapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Launch Manager\WButton.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Launch Manager\OSD.exe C:\Program Files\Launch Manager\LaunchAp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\igfxtray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\hkcmd.exe C:\Program Files\Launch Manager\HotkeyApp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Replay Media Catcher\FLVSrvc.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Avi Player\AviPlayer.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\WerCon.exe C:\Windows\helppane.exe C:\Program Files\Safari\Safari.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:3128 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: McAfee SiteAdvisor - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe" O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSD.exe" O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [HotkeyApp] "C:\Program Files\Launch Manager\HotkeyApp.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Ask and Record FLV Service] "C:\Program Files\Replay Media Catcher\FLVSrvc.exe" /run O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth O4 - HKCU\..\Run: [PopRock] C:\Users\Taha\AppData\Local\Temp\b.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: HP Slim selecteren - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O13 - Gopher Prefix: O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee SiteAdvisor Enterprise Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\OmniServ.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe -- End of file - 11937 bytes --------------------------------------------- Ik wacht op jullie hulp.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.