Ga naar inhoud

combifix en hijack this logs nakijken


2012

Aanbevolen berichten

kan iemand mijn logs van hijack this and combifix even checken verstuur soms spam naar mensen had last van hidden files en trage computer heb met mbam superantispyware en avira premium al aardig wat verwijdert heb alleen nog last van die spam....mvg tim

---------- Post toegevoegd om 13:14 ---------- Vorige post was om 13:13 ----------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:47:19 AM, on 9/13/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v8.00 (8.00.6001.18813)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\RtHDVCpl.exe

C:\Windows\system32\taskeng.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Windows\System32\wpcumi.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Windows\WindowsMobile\wmdcBase.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\RocketDock\RocketDock.exe

C:\Program Files\MagicTune Premium\GammaTray.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe

O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Global Startup: GammaTray.lnk = ?

O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra button: Eurolinx - {00000000-0000-0000-0000-000000000000} - (no file) (HKCU)

O13 - Gopher Prefix:

O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE

O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe

O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

--

End of file - 7728 bytes

Link naar reactie
Delen op andere sites

ComboFix 09-09-12.A0 - Tim 09/13/2009 6:17.2.2 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1470.661 [GMT -7:00]

Running from: c:\users\Tim\Downloads\ComboFix.exe

SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

.

((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))

.

2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Tim\AppData\Local\temp

2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Public\AppData\Local\temp

2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Default\AppData\Local\temp

2009-09-13 09:43 . 2008-03-02 10:28 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys

2009-09-13 09:43 . 2009-09-13 09:44 -------- d-----w- c:\program files\Trend Micro

2009-09-12 13:39 . 2009-09-12 13:39 -------- d-----w- c:\programdata\vsosdk

2009-09-12 12:56 . 2009-09-12 13:50 -------- d-----w- c:\users\Tim\AppData\Roaming\Vso

2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

2009-09-12 12:56 . 2007-03-19 03:37 65602 ----a-w- c:\windows\system32\cook3260.dll

2009-09-12 12:56 . 2006-09-29 18:26 176165 ----a-w- c:\windows\system32\drv23260.dll

2009-09-12 12:56 . 2006-09-29 18:25 208935 ----a-w- c:\windows\system32\drv33260.dll

2009-09-12 12:56 . 2006-09-29 18:24 217127 ----a-w- c:\windows\system32\drv43260.dll

2009-09-12 12:56 . 2004-05-04 18:53 1645320 ----a-w- c:\windows\gdiplus.dll

2009-09-12 12:56 . 2009-09-12 12:56 -------- d-----w- c:\program files\VSO

2009-09-12 09:59 . 2009-09-12 12:00 -------- d-----w- c:\users\Tim\AppData\Roaming\Any Video Converter Professional

2009-09-12 09:59 . 2009-09-12 10:01 -------- d-----w- c:\program files\Any Video Converter Professional

2009-09-11 09:42 . 2009-09-11 09:42 680 ----a-w- c:\users\Tim\AppData\Local\d3d9caps.dat

2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Toolbar

2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Lite

2009-09-10 13:05 . 2009-09-10 13:06 -------- d-----w- c:\program files\QuickTime

2009-09-10 13:05 . 2009-09-10 13:05 -------- d-----w- c:\programdata\Apple Computer

2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Common Files\Apple

2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\users\Tim\AppData\Local\Apple

2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Apple Software Update

2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\programdata\Apple

2009-09-10 10:28 . 2009-09-10 10:28 -------- d-----w- c:\windows\system32\EventProviders

2009-09-09 14:13 . 2009-09-09 14:15 -------- d-----w- C:\Betsson

2009-09-09 12:51 . 2009-09-09 12:51 -------- d-----w- c:\programdata\Azureus

2009-09-09 12:51 . 2009-09-12 09:57 -------- d-----w- c:\users\Tim\AppData\Roaming\Azureus

2009-09-09 12:50 . 2009-09-09 12:51 -------- d-----w- c:\program files\Vuze

2009-09-09 08:05 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll

2009-09-09 08:05 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-09 08:05 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll

2009-09-09 08:05 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2009-09-09 08:05 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll

2009-09-09 08:05 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll

2009-09-09 08:05 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll

2009-09-09 08:05 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe

2009-09-08 16:53 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys

2009-09-08 16:53 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll

2009-09-08 16:53 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE

2009-09-08 16:53 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll

2009-09-08 16:53 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE

2009-09-08 16:53 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE

2009-09-08 16:53 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE

2009-09-08 16:53 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE

2009-09-08 16:53 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE

2009-09-08 16:53 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe

2009-09-08 16:52 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll

2009-09-08 16:52 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll

2009-09-08 16:52 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll

2009-09-08 16:52 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll

2009-09-08 16:52 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll

2009-09-08 16:08 . 2009-09-08 16:08 -------- d-----w- C:\SAV32CLI

2009-09-08 15:11 . 2009-09-08 17:48 -------- d-----w- C:\SDFix

2009-09-08 13:29 . 2009-09-08 13:54 -------- d-----w- c:\windows\BDOSCAN8

2009-09-08 11:42 . 2009-09-08 11:42 -------- d-----w- c:\programdata\F-Secure

2009-09-07 20:05 . 2009-09-07 20:05 -------- d-----w- c:\program files\Java

2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\users\Tim\AppData\Roaming\IrfanView

2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\program files\IrfanView

2009-09-07 16:52 . 2004-08-04 14:00 506368 ----a-w- c:\windows\system32\msxml.dll

2009-09-07 12:42 . 2009-09-11 21:51 -------- d-----w- c:\users\Tim\AppData\Roaming\Skype

2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\programdata\Skype

2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Common Files\Skype

2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Skype

2009-09-06 15:40 . 2009-09-06 15:40 -------- d-----w- c:\program files\Common Files\xing shared

2009-09-06 14:25 . 2009-09-12 17:06 -------- d-----w- c:\program files\Everest Poker

2009-09-06 13:58 . 2009-09-06 14:13 -------- d-----w- c:\users\Tim\AppData\Local\P5

2009-09-06 13:48 . 2009-09-09 14:11 -------- d-----w- c:\program files\A-Winning-Hand

2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\users\Tim\AppData\Roaming\VistaCodecs

2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\program files\VistaCodecPack

2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\programdata\VistaCodecs

2009-09-06 12:57 . 2009-09-06 14:32 -------- d-----w- C:\Poker

2009-09-06 12:54 . 2009-09-12 13:48 -------- d-----w- c:\programdata\Boss Media

2009-09-06 11:53 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll

2009-09-06 04:04 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll

2009-09-06 04:04 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll

2009-09-06 04:02 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll

2009-09-06 04:02 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll

2009-09-06 04:02 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll

2009-09-06 04:02 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL

2009-09-06 04:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll

2009-09-06 03:50 . 2009-09-06 03:50 -------- d-----w- c:\program files\MSXML 4.0

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-09-13 10:06 . 2009-05-25 22:55 12 ----a-w- c:\windows\bthservsdp.dat

2009-09-13 09:43 . 2009-05-13 02:25 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-09-12 16:28 . 2009-05-25 10:47 -------- d-----w- c:\program files\POKER

2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\users\Tim\AppData\Roaming\pcouffin.sys

2009-09-11 11:59 . 2009-05-12 19:39 -------- d-----w- c:\programdata\NVIDIA

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar

2009-09-11 11:51 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery

2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender

2009-09-11 09:20 . 2009-05-25 06:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-09-10 21:54 . 2009-05-25 06:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-09-10 21:53 . 2009-05-25 06:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-09-09 14:17 . 2009-05-25 10:40 -------- d-----w- c:\program files\Poker Heaven

2009-09-08 14:36 . 2009-05-26 04:42 -------- d-----w- c:\programdata\Soulseek

2009-09-08 14:36 . 2009-05-25 10:08 -------- d-----w- c:\users\Tim\AppData\Roaming\vlc

2009-09-07 20:06 . 2009-05-12 18:37 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-09-07 00:32 . 2009-05-25 06:20 -------- d-----w- c:\programdata\Avira

2009-09-06 16:57 . 2009-05-28 00:24 -------- d-----w- c:\program files\Betsson

2009-09-06 15:41 . 2009-05-25 10:10 -------- d-----w- c:\program files\Common Files\Real

2009-09-06 13:59 . 2009-05-25 11:22 -------- d-----w- c:\users\Tim\AppData\Roaming\Microgaming

2009-09-06 04:09 . 2009-05-30 08:29 -------- d-----w- c:\program files\Google

2009-09-06 04:00 . 2009-05-27 13:32 -------- d-----w- c:\programdata\Electronic Arts

2009-09-06 03:58 . 2009-05-25 05:51 -------- d-----w- c:\programdata\LogiShrd

2009-09-06 03:58 . 2009-05-25 05:50 -------- d-----w- c:\program files\Common Files\Logishrd

2009-09-06 03:49 . 2009-05-25 08:57 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-08-28 12:39 . 2009-09-06 04:03 28672 ----a-w- c:\windows\system32\Apphlpdm.dll

2009-08-28 10:15 . 2009-09-06 04:03 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

2009-08-04 16:48 . 2009-08-04 16:48 2744800 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys

2009-08-04 16:17 . 2009-08-04 16:17 1265696 ----a-w- c:\windows\system32\RtkPgExt.dll

2009-08-04 16:17 . 2009-05-13 02:25 52256 ----a-w- c:\windows\system32\RtkCoInst.dll

2009-08-04 16:17 . 2009-08-04 16:17 326176 ----a-w- c:\windows\system32\RtkApoApi.dll

2009-08-04 16:17 . 2009-05-13 02:25 2898464 ----a-w- c:\windows\system32\RtkAPO.dll

2009-07-21 21:52 . 2009-09-06 04:03 915456 ----a-w- c:\windows\system32\wininet.dll

2009-07-21 21:47 . 2009-09-06 04:03 109056 ----a-w- c:\windows\system32\iesysprep.dll

2009-07-21 21:47 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\iesetup.dll

2009-07-21 21:01 . 2009-07-21 21:01 266240 ----a-w- c:\windows\system32\FMAPO.dll

2009-07-21 20:13 . 2009-09-06 04:03 133632 ----a-w- c:\windows\system32\ieUnatt.exe

2009-07-20 19:26 . 2009-05-25 05:50 84496 ----a-w- c:\windows\system32\KemXML.dll

2009-07-20 19:26 . 2009-05-25 05:50 117264 ----a-w- c:\windows\system32\KemWnd.dll

2009-07-20 19:26 . 2009-05-25 05:50 145936 ----a-w- c:\windows\system32\KemUtil.dll

2009-07-20 19:26 . 2009-05-25 05:50 170512 ----a-w- c:\windows\system32\kemutb.dll

2009-07-20 19:25 . 2009-05-25 05:50 301656 ----a-w- c:\windows\system32\BtCoreIf.dll

2009-07-17 14:35 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\atl.dll

2009-06-17 16:56 . 2009-06-17 16:56 28560 ----a-w- c:\windows\system32\drivers\LUsbFilt.sys

2009-06-17 16:56 . 2009-06-17 16:56 37392 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys

2009-06-17 16:56 . 2009-06-17 16:56 35472 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys

2009-06-17 16:55 . 2009-06-17 16:55 20240 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys

2009-06-17 16:55 . 2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe

2009-06-15 15:24 . 2009-09-06 04:03 156672 ----a-w- c:\windows\system32\t2embed.dll

2009-06-15 15:20 . 2009-09-06 04:03 72704 ----a-w- c:\windows\system32\fontsub.dll

2009-06-15 15:20 . 2009-09-06 04:03 10240 ----a-w- c:\windows\system32\dciman32.dll

.

------- Sigcheck -------

[7] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll

[-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll

[-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll

.

((((((((((((((((((((((((((((( SnapShot@2009-09-13_10.02.01 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-05-13 01:34 . 2009-09-13 09:29 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-05-13 01:34 . 2009-09-13 13:09 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2006-11-02 10:33 . 2009-09-13 13:11 595446 c:\windows\System32\perfh009.dat

- 2006-11-02 10:33 . 2009-09-13 09:31 595446 c:\windows\System32\perfh009.dat

- 2006-11-02 10:33 . 2009-09-13 09:31 101144 c:\windows\System32\perfc009.dat

+ 2006-11-02 10:33 . 2009-09-13 13:11 101144 c:\windows\System32\perfc009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-05-25 209153]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

"MagicTuneEngine"="c:\program files\MagicTune Premium\MagicTuneEngine.exe" [2009-02-28 69632]

"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-07 149280]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-06 198160]

"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

"TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088]

"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2009-06-17 55824]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2009-5-29 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup

backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk

backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup

backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"VistaSp2"=hex(B):76,83,2d,99,6e,32,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1625430939-434094062-2039484060-1000]

"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{E7A0DE10-0AAC-4D47-A6A6-85DA84EE592E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

"TCP Query User{8641B803-3AAE-4A39-8D19-7A80255E1A28}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar

"UDP Query User{C1BF1F0C-85B7-4144-8E3B-15AB73E87AC4}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar

"TCP Query User{D92F81F6-AAF7-4086-A2D1-67AE1B0230B3}c:\\program files\\soulseekns\\slsk.exe"= UDP:c:\program files\soulseekns\slsk.exe:SoulSeek

"UDP Query User{573FEA67-D015-46C3-83C8-0212631D7E5F}c:\\program files\\soulseekns\\slsk.exe"= TCP:c:\program files\soulseekns\slsk.exe:SoulSeek

"TCP Query User{C7F2A80C-8052-4CCE-82CC-A177927B5DCA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"UDP Query User{FE35F96B-7C19-40AB-88EF-E8B2261BA86C}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

"TCP Query User{3452DD1D-75B1-498D-99A7-155A77F3BCCF}c:\\program files\\magictune premium\\magictune.exe"= UDP:c:\program files\magictune premium\magictune.exe:MagicTune

"UDP Query User{BD43CA06-4386-4293-813C-1E8023476CED}c:\\program files\\magictune premium\\magictune.exe"= TCP:c:\program files\magictune premium\magictune.exe:MagicTune

"TCP Query User{9C9AD9EF-3BFB-440D-9471-943A74F700E1}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= UDP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary

"UDP Query User{45F6A493-9AF8-42B6-A68C-968604630DF0}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= TCP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary

"TCP Query User{5488F78E-58D8-4E43-9181-17684ADB63DA}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus

"UDP Query User{C4ED2645-2AF1-4E58-8655-096FDF675744}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus

"{4EFAEA45-D0CA-4514-90F3-35BBC7832F2E}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype

"{8B623564-7EDC-47A8-AE6E-416F86659A74}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype

R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [6/1/2009 4:02 AM 20392]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]

R1 SAS***IL;SAS***IL;c:\program files\SUPERAntiSpyware\SAS***IL.SYS [4/28/2009 11:33 AM 72944]

R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [5/25/2009 1:57 AM 194817]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/25/2009 1:57 AM 108289]

R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [5/25/2009 1:57 AM 434945]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/24/2009 11:21 PM 269648]

R2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [9/13/2009 2:43 AM 582992]

R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [5/24/2009 11:21 PM 19160]

R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [2/26/2008 5:17 PM 493568]

R3 TMPassthruMP;TMPassthruMP;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]

S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2/22/2007 7:53 PM 2217416]

S2 gupdate1c9e100d4e6a22b;Google Update Service (gupdate1c9e100d4e6a22b);c:\program files\Google\Update\GoogleUpdate.exe [5/30/2009 1:30 AM 133104]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]

S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WindowsMobile REG_MULTI_SZ wcescomm rapimgr

LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

bthsvcs REG_MULTI_SZ BthServ

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Contents of the 'Scheduled Tasks' folder

2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]

2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]

2009-09-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000Core.job

- c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]

2009-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000UA.job

- c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]

2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Tim.job

- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]

2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Update for Tim.job

- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]

2009-09-13 c:\windows\Tasks\User_Feed_Synchronization-{627C8EAA-BB82-4C9A-83B7-A17FA49E136D}.job

- c:\windows\system32\msfeedssync.exe [2009-09-06 20:13]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.nl/

LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll

FF - ProfilePath - c:\users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\i49klk1y.default\

FF - prefs.js: browser.search.selectedEngine -

FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll

FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll

FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll

FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll

FF - plugin: c:\users\Tim\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2009-09-13 06:27

Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(936)

c:\windows\system32\relog_ap.dll

.

Completion time: 2009-09-13 6:29

ComboFix-quarantined-files.txt 2009-09-13 13:29

ComboFix2.txt 2009-09-13 10:04

Pre-Run: 5,452,574,720 bytes free

Post-Run: 5,393,772,544 bytes free

305 --- E O F --- 2009-09-11 11:35

---------- Post toegevoegd om 13:35 ---------- Vorige post was om 13:33 ----------

En wat ook zo raar was is dat ik gister een online scan met f-secure wou doen en avira premium zegt bij het downloaden van de f-secure files dat er een script virus in zit heel raar al eerder ermee gescaned en geen problemen meer mensen daar last van...? mvg tim

Link naar reactie
Delen op andere sites

Start Hijackthis op. Ben je gebruiker van Vista kies dan voor “Run as administrator" of "Uitvoeren als administrator". Selecteer “Do a system scan only”. Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O9 - Extra button: Eurolinx - {00000000-0000-0000-0000-000000000000} - (no file) (HKCU)

Klik op 'Fix checked' om de items te verwijderen.

Download MBAM (Malwarebytes' Anti-Malware).

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder). De log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in MBAM.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computeropnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.

Link naar reactie
Delen op andere sites

he bedankt voor je reaktie maar de eerste 2 die R0 die waren al weg vreemd

---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:26 ----------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:25:45 PM, on 9/13/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v8.00 (8.00.6001.18813)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

C:\Windows\System32\wpcumi.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Windows\WindowsMobile\wmdcBase.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\RocketDock\RocketDock.exe

C:\Program Files\MagicTune Premium\GammaTray.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\Program Files\MagicTune Premium\MagicTune.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Skype\Plugin Manager\SkypePM.exe

C:\Program Files\FTDv3.8\KoalaFTDSearch.exe

C:\Program Files\FTDv3.8\ftdv3.exe

C:\Windows\system32\mfpmp.exe

C:\Program Files\DFX\WMP\Apps\dfxgApp.exe

C:\Program Files\Poker Heaven\poker.exe

C:\Program Files\Poker Heaven\browserhost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe

O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

O4 - Global Startup: GammaTray.lnk = ?

O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE

O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe

O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

--

End of file - 7462 bytes

---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:28 ----------

Malwarebytes' Anti-Malware 1.41

Database versie: 2791

Windows 6.0.6001 Service Pack 1

9/13/2009 11:28:31 PM

mbam-log-2009-09-13 (23-28-31).txt

Scan type: Snelle Scan

Objecten gescand: 83884

Verstreken tijd: 3 minute(s), 43 second(s)

Geheugenprocessen geïnfecteerd: 0

Geheugenmodulen geïnfecteerd: 0

Registersleutels geïnfecteerd: 0

Registerwaarden geïnfecteerd: 0

Registerdata bestanden geïnfecteerd: 0

Mappen geïnfecteerd: 0

Bestanden geïnfecteerd: 0

Geheugenprocessen geïnfecteerd:

(Geen kwaadaardige items gevonden)

Geheugenmodulen geïnfecteerd:

(Geen kwaadaardige items gevonden)

Registersleutels geïnfecteerd:

(Geen kwaadaardige items gevonden)

Registerwaarden geïnfecteerd:

(Geen kwaadaardige items gevonden)

Registerdata bestanden geïnfecteerd:

(Geen kwaadaardige items gevonden)

Mappen geïnfecteerd:

(Geen kwaadaardige items gevonden)

Bestanden geïnfecteerd:

(Geen kwaadaardige items gevonden)

Link naar reactie
Delen op andere sites

Logjes zien er goed uit nu :-)

Als je SPAM-berichten verstuurt, hoeft dat niet noodzakelijk vanop jouw computer te gebeuren. Het kan best dat professionele SPAMmers je mailadres op één of andere manier te pakken hebben gekregen en daar nu gebruik (of misbruik) van maken om SPAM rond te sturen. Dat heb je dus niet helemaal zelf in de hand ... en in dat geval is er ook geen oplossing voor :s

Link naar reactie
Delen op andere sites

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.