Ga naar inhoud

Mijn internet werkt heel traag..?!


handlocker

Aanbevolen berichten

Beste gasten/leden,

Ik was vanavond achter het internet en plotseling werkte het internet ontzettend traag. Internet loopt steeds vast, en het laden duurt een ''eeuwigheid''. Het heeft me uren geduurd om uiteindelijk hier een topic te openen. Ik heb echt jullie hulp nodig, dit is heel irritant.

Ik heb via Speccy alvast een scan gedaan.. Hier de link..

http://speccy.piriform.com/results/4LaU60843d3oJ8UPBSq6pqB

Alvast bedankt voor al jullie hulp,

Groetjes

Link naar reactie
Delen op andere sites

We zullen eerst eens nagaan of malware of virussen de oorzaak zijn van je probleem.

1. Download HijackThis.

Klik bij "HijackThis Downloads" op "Installer".

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere pc en het bestand met een usb stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable downloaden.

Sla deze op in een nieuwe map op de C schijf (bvb C:\hijackthis) en start hijackthis dan vanaf deze map.

De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.


3. Na het plaatsen van je logje wordt dit door een expert (Kape of Kweezie Wabbit) nagekeken en begeleidt hij jou verder door het ganse proces.

Link naar reactie
Delen op andere sites

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 12:06:27, on 24-1-2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\VistaDrive\VistaDrive.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\OpenOffice.org 3\program\soffice.exe

C:\Program Files\OpenOffice.org 3\program\soffice.bin

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\msiexec.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\system32\spoolsv.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Google

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Google

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [{ABA2DD7D-24E5-C007-CCCE-EDBB987D9743}] "C:\Documents and Settings\Administrator\Application Data\Otone\game.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

O4 - HKUS\S-1-5-19\..\Run: [skinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe (User 'Lokale service')

O4 - HKUS\S-1-5-19\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Lokale service')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

O4 - HKUS\S-1-5-20\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Netwerkservice')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

O4 - S-1-5-18 Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')

O4 - .DEFAULT Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

O9 - Extra button: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)

O9 - Extra 'Tools' menuitem: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default.aspx?scid=FH;EN-US;KBHOWTO (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Platinum Play Online Casino - - C:\Microgaming\Casino\PlatinumPlay\casinogame.exe (file missing) (HKCU)

O9 - Extra button: InterCasino EUR - {9536DF30-CF04-4A89-B26B-4781E242230C} - Online Casino - Secure Internet Casino Gambling | InterCasino.com (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: InterCasino EUR - {9536DF30-CF04-4A89-B26B-4781E242230C} - Online Casino - Secure Internet Casino Gambling | InterCasino.com (file missing) (HKCU)

O9 - Extra button: (no name) - °0@±X¤ - (no file) (HKCU)

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 7377 bytes

Link naar reactie
Delen op andere sites

Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O4 - HKUS\S-1-5-19\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Lokale service')

O4 - HKUS\S-1-5-20\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Netwerkservice')

O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

O9 - Extra button: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default...;EN-US;KBHOWTO (file missing)

O9 - Extra 'Tools' menuitem: MS-KB - {8b2d996f-b7d1-4961-a929-414d9cf5ba7b} - http://support.microsoft.com/default...;EN-US;KBHOWTO (file missing)

O9 - Extra button: Platinum Play Online Casino - - C:\Microgaming\Casino\PlatinumPlay\casinogame.exe (file missing) (HKCU)

O9 - Extra button: InterCasino EUR - {9536DF30-CF04-4A89-B26B-4781E242230C} - Online Casino - Secure Internet Casino Gambling | InterCasino.com (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: InterCasino EUR - {9536DF30-CF04-4A89-B26B-4781E242230C} - Online Casino - Secure Internet Casino Gambling | InterCasino.com (file missing) (HKCU)

O9 - Extra button: (no name) - °0@±X¤ - (no file) (HKCU)

Klik op 'Fix checked' om de items te verwijderen.

Download MBAM (Malwarebytes Anti-Malware)

Dubbelklik op mbam-setup.exe om het programma te installeren.

Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".

Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.

Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.

Het scannen kan een tijdje duren, dus wees geduldig.

Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.

Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.

Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).

Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.

MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.

Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.

Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.

Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.

Link naar reactie
Delen op andere sites

Malwarebytes Anti-Malware 1.60.0.1800

Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Databaseversie: v2012.01.24.03

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

Administrator :: UNATTEND-62A32D [administrator]

24-1-2012 14:06:37

mbam-log-2012-01-24 (14-06-37).txt

Scantype: Snelle scan

Ingeschakelde scanopties: Geheugen | Opstarten | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

Uitgeschakelde scanopties: P2P

Objecten gescand: 161501

Verstreken tijd: 3 minuut/minuten, 31 seconde(n)

Geheugenprocessen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 1

HKCU\SOFTWARE\Casino Tropez (Adware.Casino) -> Succesvol in quarantaine geplaatst en verwijderd.

Registerwaarden gedetecteerd: 2

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> Succesvol in quarantaine geplaatst en verwijderd.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{ABA2DD7D-24E5-C007-CCCE-EDBB987D9743} (Trojan.ZbotR.Gen) -> Data: "C:\Documents and Settings\Administrator\Application Data\Otone\game.exe" -> Succesvol in quarantaine geplaatst en verwijderd.

Registerdata gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0

(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 10

C:\Documents and Settings\Administrator\Application Data\Adobe\plugs\mmc236.exe (Trojan.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Administrator\Application Data\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Default User\Application Data\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\WINDOWS\system32\config\systemprofile\Application Data\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Administrator\Local Settings\Temp\D8.tmp (Spyware.Passwords.XGen) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Administrator\Application Data\Adobe\shed\thr1.chm (Malware.Trace) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Administrator\Application Data\Adobe\plugs\mmc227.exe (Trojan.Agent.Gen) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files\Mozilla Firefox\0.6076956277439542.exe (Exploit.Dropper) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Program Files\Unlocker\eBay_shortcuts_1016.exe (Adware.Clicker) -> Succesvol in quarantaine geplaatst en verwijderd.

C:\Documents and Settings\Administrator\Application Data\Otone\game.exe (Trojan.ZbotR.Gen) -> Succesvol in quarantaine geplaatst en verwijderd.

(einde)

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:15:15, on 24-1-2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\VistaDrive\VistaDrive.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\OpenOffice.org 3\program\soffice.exe

C:\Program Files\OpenOffice.org 3\program\soffice.bin

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Google

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Google

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')

O4 - HKUS\S-1-5-19\..\Run: [skinClock] C:\Program Files\Desktop Tray Clock\DTClock.exe (User 'Lokale service')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - S-1-5-18 Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')

O4 - .DEFAULT Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')

O4 - Startup: OpenOffice.org 3.3 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 5808 bytes

Link naar reactie
Delen op andere sites

Malwarebytes heeft behoorlijk wat ongewenste bestanden verwijderd. Over naar de volgende stap :

Download ComboFix van één van deze locaties:

Link 1

Link 2

* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op

1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix. Hier is een handleiding over hoe je ze kan uitschakelen:

Klik hier

Als het je niet lukt om ze uit te schakelen, ga dan gewoon door naar de volgende stap.

2. Dubbelklik op ComboFix.exe en volg de meldingen op het scherm.

3. ComboFix zal controleren of dat de Microsoft Windows Recovery Console reeds is geïnstalleerd.

**Let op: Als de Microsoft Windows Recovery Console al is geïnstalleerd, dan krijg je de volgende schermen niet te zien en zal ComboFix automatisch verder gaan met het scannen naar malware.

4. Volg de meldingen op het scherm om ComboFix de Microsoft Windows Recovery Console te laten downloaden en installeren.

cf-rc-auto.jpg

Je krijgt de volgende melding te zien wanneer ComboFix de Microsoft Windows Recovery Console succesvol heeft geïnstalleerd:

rc-auto-done.jpg

Klik op Ja om verder te gaan met het scannen naar malware.

5. Wanneer ComboFix klaar is, zal het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.

Link naar reactie
Delen op andere sites

ComboFix 12-01-23.02 - Administrator 24-01-2012 18:32:16.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1919.826 [GMT 1:00]

Gestart vanuit: c:\documents and settings\Administrator\Mijn documenten\Downloads\ComboFix.exe

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Administrator\Application Data\.#

c:\documents and settings\Administrator\Application Data\Adobe\plugs

c:\documents and settings\Administrator\Application Data\Adobe\shed

c:\documents and settings\Administrator\Application Data\Desktopicon

c:\documents and settings\Administrator\Menu Start\Programma's\Opstarten\OpenOffice.org 3.3 .lnk

c:\documents and settings\All Users\Menu Start\Programma's\Internet Explorer.lnk

c:\documents and settings\Default User\Application Data\Desktopicon

c:\windows\alcrmv.exe

c:\windows\iun6002.exe

c:\windows\system32\config\systemprofile\Application Data\Desktopicon

c:\windows\system32\SET11A.tmp

c:\windows\system32\SET11C.tmp

c:\windows\system32\SET12A.tmp

c:\windows\TEMP\logishrd\LVPrcInj01.dll

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-12-24 to 2012-01-24 ))))))))))))))))))))))))))))))

.

.

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-01-24 13:05 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-01-24 11:50 . 2012-01-24 11:50 -------- d--h--r- c:\documents and settings\Administrator\Onlangs geopend

2012-01-24 11:05 . 2012-01-24 11:05 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-01-24 11:05 . 2012-01-24 11:05 -------- d-----w- c:\program files\Trend Micro

2012-01-20 21:51 . 2012-01-20 21:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\OpenOffice.org

2012-01-20 21:50 . 2012-01-20 21:50 -------- d-----w- c:\program files\OpenOffice.org 3

2012-01-18 16:03 . 2012-01-18 16:03 -------- d-----w- c:\program files\MWSnap

2012-01-17 18:19 . 2012-01-17 18:19 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2012-01-17 18:19 . 2012-01-17 18:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple

2012-01-16 23:21 . 2011-11-03 15:29 386560 ------w- c:\windows\system32\dllcache\qdvd.dll

2012-01-16 23:21 . 2011-10-14 14:47 23040 ------w- c:\windows\system32\dllcache\mciseq.dll

2012-01-16 23:21 . 2011-10-14 14:47 179200 ------w- c:\windows\system32\dllcache\winmm.dll

2012-01-16 23:21 . 2011-11-20 06:12 60928 ------w- c:\windows\system32\dllcache\packager.exe

2012-01-16 23:04 . 2012-01-16 23:04 -------- d-----w- c:\windows\system32\Lang

2012-01-16 12:37 . 2012-01-19 16:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer

2012-01-15 22:09 . 2012-01-15 22:09 -------- d-----w- c:\program files\Codec Pack - All In 1

2012-01-14 00:28 . 2012-01-14 00:28 -------- d-----w- c:\program files\uTorrent

2012-01-14 00:27 . 2012-01-14 01:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent

2012-01-13 22:02 . 2012-01-13 22:02 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ExtractNow

2012-01-13 22:02 . 2012-01-13 22:02 -------- d-----w- c:\program files\ExtractNow

2012-01-09 16:04 . 2012-01-09 16:04 -------- d-----w- c:\program files\Speccy

2012-01-06 16:17 . 2010-08-27 05:55 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll

2012-01-06 16:17 . 2009-10-21 05:40 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll

2012-01-06 16:17 . 2009-10-21 05:40 25088 ------w- c:\windows\system32\dllcache\httpapi.dll

2012-01-06 16:17 . 2009-10-20 16:20 265728 ------w- c:\windows\system32\dllcache\http.sys

2012-01-06 02:36 . 2012-01-06 02:36 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2

2012-01-06 02:24 . 2012-01-06 02:24 -------- d-----w- c:\program files\MSXML 4.0

2012-01-06 01:14 . 2012-01-06 01:14 -------- d-----w- c:\program files\directx

2012-01-06 01:08 . 2012-01-06 01:08 -------- d-----w- c:\program files\Smart-ActiveX

2012-01-05 21:53 . 2012-01-05 21:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics

2012-01-05 21:53 . 2009-03-21 14:09 1030656 ------w- c:\windows\system32\dllcache\kernel32.dll

2012-01-05 21:53 . 2009-06-15 11:10 82432 ------w- c:\windows\system32\dllcache\tlntsess.exe

2012-01-05 21:53 . 2009-06-15 10:45 79872 ------w- c:\windows\system32\dllcache\telnet.exe

2012-01-05 21:53 . 2009-10-12 13:40 79872 ------w- c:\windows\system32\dllcache\raschap.dll

2012-01-05 21:53 . 2009-10-12 13:40 150016 ------w- c:\windows\system32\dllcache\rastls.dll

2012-01-05 21:53 . 2009-07-17 16:22 1440768 ------w- c:\windows\system32\dllcache\query.dll

2012-01-05 21:53 . 2010-11-18 18:15 86016 ------w- c:\windows\system32\dllcache\isign32.dll

2012-01-05 21:53 . 2011-11-23 14:39 1868672 ------w- c:\windows\system32\dllcache\win32k.sys

2012-01-05 21:53 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe

2012-01-05 21:53 . 2011-02-02 07:58 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll

2012-01-05 21:53 . 2009-06-10 06:20 134144 ------w- c:\windows\system32\dllcache\wkssvc.dll

2012-01-05 21:51 . 2009-12-17 07:42 345600 ------w- c:\windows\system32\dllcache\mspaint.exe

2012-01-05 21:50 . 2011-10-26 10:50 2153472 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2012-01-05 21:50 . 2011-10-26 10:50 2197120 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2012-01-05 21:50 . 2011-10-26 10:50 2073728 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2012-01-05 21:50 . 2011-10-26 10:50 2031616 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2012-01-05 21:50 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe

2012-01-05 21:50 . 2011-04-29 17:23 151552 ------w- c:\windows\system32\dllcache\schannel.dll

2012-01-05 21:50 . 2010-12-22 12:32 301568 ------w- c:\windows\system32\dllcache\kerberos.dll

2012-01-05 21:50 . 2009-09-11 14:16 136704 ------w- c:\windows\system32\dllcache\msv1_0.dll

2012-01-05 21:50 . 2009-06-25 08:42 54272 ------w- c:\windows\system32\dllcache\wdigest.dll

2012-01-05 21:50 . 2009-06-25 08:42 56832 ------w- c:\windows\system32\dllcache\secur32.dll

2012-01-05 21:50 . 2009-06-24 10:28 92928 ------w- c:\windows\system32\dllcache\ksecdd.sys

2012-01-05 21:49 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys

2012-01-05 21:49 . 2010-08-27 08:03 119808 ------w- c:\windows\system32\dllcache\t2embed.dll

2012-01-05 21:49 . 2009-10-15 16:38 81920 ------w- c:\windows\system32\dllcache\fontsub.dll

2012-01-05 21:49 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe

2012-01-05 21:49 . 2009-03-06 14:23 285696 ------w- c:\windows\system32\dllcache\pdh.dll

2012-01-05 21:49 . 2009-02-09 11:27 111104 ------w- c:\windows\system32\dllcache\services.exe

2012-01-05 21:49 . 2009-02-09 10:56 401408 ------w- c:\windows\system32\dllcache\rpcss.dll

2012-01-05 21:49 . 2009-02-09 10:56 473600 ------w- c:\windows\system32\dllcache\fastprox.dll

2012-01-05 21:49 . 2009-02-06 10:39 35328 ------w- c:\windows\system32\dllcache\sc.exe

2012-01-05 21:49 . 2009-02-09 10:56 684544 ------w- c:\windows\system32\dllcache\advapi32.dll

2012-01-05 21:49 . 2009-02-09 10:56 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll

2012-01-05 21:49 . 2009-06-21 21:49 153088 ------w- c:\windows\system32\dllcache\triedit.dll

2012-01-05 21:48 . 2011-06-24 14:09 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys

2012-01-05 21:48 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys

2012-01-05 21:48 . 2009-07-31 04:30 1447424 ------w- c:\windows\system32\dllcache\msxml6.dll

2012-01-05 21:48 . 2010-06-14 07:40 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll

2012-01-05 21:47 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2012-01-05 21:47 . 2010-06-18 13:36 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe

2012-01-05 21:47 . 2012-01-05 21:47 -------- d-----w- c:\program files\Lavalys

2012-01-05 21:45 . 2010-12-09 15:15 739328 ------w- c:\windows\system32\dllcache\ntdll.dll

2012-01-05 21:44 . 2010-07-16 11:57 221184 ------w- c:\windows\system32\dllcache\wordpad.exe

2012-01-05 21:44 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys

2012-01-05 21:43 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe

2012-01-05 21:43 . 2010-08-16 08:45 590848 ------w- c:\windows\system32\dllcache\rpcrt4.dll

2012-01-05 21:43 . 2009-12-24 07:05 177664 ------w- c:\windows\system32\dllcache\wintrust.dll

2012-01-05 21:43 . 2010-01-13 14:06 87040 ------w- c:\windows\system32\dllcache\cabview.dll

2012-01-05 21:30 . 2010-11-03 17:15 84584 ----a-w- c:\windows\SOUNDMAN.EXE

2012-01-05 21:30 . 2008-09-24 09:40 4122368 ----a-r- c:\windows\system32\drivers\alcxwdm.sys

2012-01-05 21:30 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe

2012-01-05 21:30 . 2010-11-03 17:13 285288 ----a-w- c:\windows\system32\ALSNDMGR.CPL

2012-01-05 21:30 . 2006-12-08 14:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe

2012-01-05 21:29 . 2012-01-05 21:29 -------- d-----w- c:\program files\Realtek AC97

2012-01-05 21:29 . 2012-01-16 23:01 -------- d--h--w- c:\program files\InstallShield Installation Information

2012-01-05 21:29 . 2006-07-31 10:19 315392 ----a-w- c:\windows\alcupd.exe

2012-01-05 21:29 . 2012-01-05 21:29 -------- d-----w- c:\program files\Common Files\InstallShield

2012-01-04 23:13 . 2012-01-22 14:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3

2012-01-04 18:37 . 2011-12-29 18:00 79360 ----a-w- c:\windows\system32\ff_vfw.dll

2012-01-04 18:37 . 2011-12-21 18:14 151552 ----a-w- c:\windows\system32\ac3acm.acm

2012-01-04 18:37 . 2011-06-24 15:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll

2012-01-04 18:37 . 2011-06-24 15:28 650752 ----a-w- c:\windows\system32\xvidcore.dll

2012-01-04 18:37 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm

2012-01-04 18:37 . 2012-01-04 18:37 -------- d-----w- c:\program files\K-Lite Codec Pack

2012-01-04 18:31 . 2012-01-24 15:37 -------- d-----w- c:\documents and settings\Administrator\Tracing

2012-01-04 18:30 . 2012-01-04 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!

2012-01-04 18:30 . 2012-01-04 18:30 -------- d-----w- c:\program files\Yuna Software

2012-01-04 18:27 . 2012-01-04 18:27 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE

2012-01-04 18:23 . 2012-01-04 18:23 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache

2012-01-04 18:22 . 2011-12-21 08:02 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll

2012-01-04 18:22 . 2011-12-21 08:02 97240 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll

2012-01-04 18:22 . 2011-12-21 08:02 814040 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll

2012-01-04 18:22 . 2011-12-21 08:02 486360 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll

2012-01-04 18:22 . 2011-12-21 08:02 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll

2012-01-04 18:22 . 2011-12-21 08:02 2124760 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll

2012-01-04 18:22 . 2011-12-21 08:02 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll

2012-01-04 18:22 . 2011-12-21 04:29 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll

2012-01-04 18:22 . 2011-12-21 04:29 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll

2012-01-04 18:22 . 2011-12-21 04:29 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll

2012-01-04 18:22 . 2011-12-21 04:29 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll

2012-01-04 18:22 . 2011-12-21 04:29 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll

2012-01-04 18:20 . 2012-01-04 18:20 -------- d-----w- c:\program files\Microsoft

2012-01-04 18:19 . 2012-01-04 18:19 -------- d-----w- c:\program files\Windows Live SkyDrive

2012-01-04 18:19 . 2012-01-16 23:56 -------- d--h--w- c:\windows\$hf_mig$

2012-01-04 18:19 . 2012-01-04 18:19 -------- d-----w- c:\program files\Windows Live

2012-01-04 18:17 . 2012-01-04 18:18 -------- dc-h--w- c:\windows\ie8

2012-01-04 18:16 . 2012-01-04 18:16 -------- d-----w- c:\program files\Common Files\Windows Live

2012-01-04 18:12 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll

2012-01-04 18:12 . 2011-11-04 19:13 602112 ------w- c:\windows\system32\dllcache\msfeeds.dll

2012-01-04 18:12 . 2011-11-04 19:13 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll

2012-01-04 18:12 . 2011-11-04 19:13 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-01-11 11:59 . 2011-06-27 16:37 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-12-19 19:53 . 2011-12-19 19:53 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-12-19 19:53 . 2011-12-19 19:53 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-11-25 21:57 . 2008-09-23 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll

2011-11-23 14:39 . 2008-09-23 12:00 1868672 ----a-w- c:\windows\system32\win32k.sys

2011-11-20 06:12 . 2008-09-23 12:00 60928 ----a-w- c:\windows\system32\packager.exe

2011-11-04 19:13 . 2008-09-23 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

2011-11-04 19:13 . 2008-09-23 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

2011-11-04 19:13 . 2008-09-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-11-04 11:25 . 2008-09-23 12:00 385024 ------w- c:\windows\system32\html.iec

2011-11-03 15:29 . 2008-09-23 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll

2011-11-03 15:29 . 2008-09-23 12:00 1296384 ----a-w- c:\windows\system32\quartz.dll

2011-11-01 16:05 . 2008-09-23 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll

2011-10-28 05:32 . 2008-09-23 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-21 08:02 . 2012-01-04 18:22 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

.

[-] 2008-09-23 12:00 . 753C7C72C1F462A009C877B41730F3EC . 1475072 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll

.

[-] 2008-09-23 . F7A21A4461BEF6414D9AF587C7D69E7D . 591872 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

.

[-] 2008-09-23 . 15414691C4C039FF03377DC2A27AF592 . 518144 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

.

[-] 2008-09-23 . C55B10AB1C2C8ED9F913BAFB3E296B4A . 1701888 . . [6.00.2900.5634] . . c:\windows\explorer.exe

.

[-] 2008-09-23 . A09F1B50133C856DA9AED1782FD9A64D . 218112 . . [5.1.2600.5512] . . c:\windows\regedit.exe

.

[-] 2008-09-23 . 6C4E087200E46977DFE54147A5B1FDD8 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

.

c:\windows\System32\drivers\beep.sys ... is niet aanwezig !!

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]

"nwiz"="nwiz.exe" [2008-09-17 1657376]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]

"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]

"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-10-24 801792]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]

"RTHDCPL"="RTHDCPL.EXE" [2011-12-05 20065384]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-09-23 37376]

.

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:Remote Desktop

"65533:TCP"= 65533:TCP:Services

"52344:TCP"= 52344:TCP:Services

.

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18-3-2011 22:43 691696]

R3 xcpip;Stuurprogramma voor TCP/IP-protocol;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]

R3 xpsec;IPSEC-stuurprogramma;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]

S1 oieapuvn;oieapuvn;\??\c:\windows\system32\drivers\oieapuvn.sys --> c:\windows\system32\drivers\oieapuvn.sys [?]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17-1-2012 0:01 1691480]

.

Inhoud van de 'Gedeelde Taken' map

.

2012-01-17 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.nl/

uDefault_Search_URL = hxxp://www.google.nl

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

Trusted Zone: abnamro.nl\www

TCP: DhcpNameServer = 10.0.0.138

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whw7hqgz.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.nl/

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false

.

- - - - ORPHANS VERWIJDERD - - - -

.

HKU-Default-Run-SkinClock - c:\program files\Desktop Tray Clock\DTClock.exe

AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-01-24 18:36

Windows 5.1.2600 Service Pack 3 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-606747145-2052111302-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,b2,5d,7b,ea,54,c6,48,8f,dc,a1,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,b2,5d,7b,ea,54,c6,48,8f,dc,a1,\

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'winlogon.exe'(740)

c:\windows\system32\SETUPAPI.dll

c:\windows\system32\COMRes.dll

c:\windows\system32\cscui.dll

.

- - - - - - - > 'lsass.exe'(796)

c:\windows\system32\setupapi.dll

.

Voltooingstijd: 2012-01-24 18:37:49

ComboFix-quarantined-files.txt 2012-01-24 17:37

.

Pre-Run: 88.261.632.000 bytes beschikbaar

Post-Run: 88.605.728.768 bytes beschikbaar

.

WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - E3F7741FAEE5BF8852C4819A04198779

---------- Post toegevoegd om 18:51 ---------- Vorige post was om 18:39 ----------

De scan via ComboFix is hierboven te zien.Trouwens..Kan je me ook goeie programma(s) aanbieden om me pc te beschermen. Ik maak geen gebruik van pc bescherming op dit moment.

Ik wacht op je volgende reactie..

Link naar reactie
Delen op andere sites

Open een kladblokbestand.

Kopieer en plak daarin de onderstaande vetgedrukte tekst.

File::

c:\windows\system32\drivers\oieapuvn.sys

Driver::

oieapuvn

Sla dit bestand op je bureaublad op als CFScript.

Sleep CFScript.txt in ComboFix.exe

Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.

Post na herstart de inhoud van de Combofix.txt in je volgende bericht samen met een nieuw logje van HijackThis.

Als (gratis) antivirusprogramma kan je bvb. kiezen voor Avast, AVG of Antivir ... maar dat je bescherming nodig hebt is wel duidelijk !

Link naar reactie
Delen op andere sites

ComboFix 12-01-23.02 - Administrator 24-01-2012 21:05:58.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1919.1365 [GMT 1:00]

Gestart vanuit: c:\documents and settings\Administrator\Mijn documenten\Downloads\ComboFix.exe

gebruikte Opdracht switches :: c:\documents and settings\Administrator\Bureaublad\CFScript.txt

.

FILE ::

"c:\windows\system32\drivers\oieapuvn.sys"

.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_oieapuvn

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2011-12-24 to 2012-01-24 ))))))))))))))))))))))))))))))

.

.

2012-01-24 20:10 . 2012-01-24 20:10 -------- d-----w- c:\windows\system32\xircom

2012-01-24 20:10 . 2012-01-24 20:10 -------- d-----w- c:\windows\system32\wbem\snmp

2012-01-24 20:10 . 2012-01-24 20:10 -------- d-----w- c:\program files\microsoft frontpage

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2012-01-24 13:05 . 2012-01-24 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2012-01-24 13:05 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-01-24 11:50 . 2012-01-24 20:02 -------- d--h--r- c:\documents and settings\Administrator\Onlangs geopend

2012-01-24 11:05 . 2012-01-24 11:05 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-01-24 11:05 . 2012-01-24 11:05 -------- d-----w- c:\program files\Trend Micro

2012-01-20 21:51 . 2012-01-20 21:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\OpenOffice.org

2012-01-20 21:50 . 2012-01-20 21:50 -------- d-----w- c:\program files\OpenOffice.org 3

2012-01-18 16:03 . 2012-01-18 16:03 -------- d-----w- c:\program files\MWSnap

2012-01-17 18:19 . 2012-01-17 18:19 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2012-01-17 18:19 . 2012-01-17 18:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple

2012-01-16 23:21 . 2011-11-03 15:29 386560 ------w- c:\windows\system32\dllcache\qdvd.dll

2012-01-16 23:21 . 2011-10-14 14:47 23040 ------w- c:\windows\system32\dllcache\mciseq.dll

2012-01-16 23:21 . 2011-10-14 14:47 179200 ------w- c:\windows\system32\dllcache\winmm.dll

2012-01-16 23:21 . 2011-11-20 06:12 60928 ------w- c:\windows\system32\dllcache\packager.exe

2012-01-16 23:04 . 2012-01-16 23:04 -------- d-----w- c:\windows\system32\Lang

2012-01-16 12:37 . 2012-01-19 16:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer

2012-01-15 22:09 . 2012-01-15 22:09 -------- d-----w- c:\program files\Codec Pack - All In 1

2012-01-14 00:28 . 2012-01-14 00:28 -------- d-----w- c:\program files\uTorrent

2012-01-14 00:27 . 2012-01-14 01:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent

2012-01-13 22:02 . 2012-01-13 22:02 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ExtractNow

2012-01-13 22:02 . 2012-01-13 22:02 -------- d-----w- c:\program files\ExtractNow

2012-01-09 16:04 . 2012-01-09 16:04 -------- d-----w- c:\program files\Speccy

2012-01-06 16:17 . 2010-08-27 05:55 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll

2012-01-06 16:17 . 2009-10-21 05:40 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll

2012-01-06 16:17 . 2009-10-21 05:40 25088 ------w- c:\windows\system32\dllcache\httpapi.dll

2012-01-06 16:17 . 2009-10-20 16:20 265728 ------w- c:\windows\system32\dllcache\http.sys

2012-01-06 02:36 . 2012-01-06 02:36 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2

2012-01-06 02:24 . 2012-01-06 02:24 -------- d-----w- c:\program files\MSXML 4.0

2012-01-06 01:14 . 2012-01-06 01:14 -------- d-----w- c:\program files\directx

2012-01-06 01:08 . 2012-01-06 01:08 -------- d-----w- c:\program files\Smart-ActiveX

2012-01-05 21:53 . 2012-01-05 21:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics

2012-01-05 21:53 . 2009-03-21 14:09 1030656 ------w- c:\windows\system32\dllcache\kernel32.dll

2012-01-05 21:53 . 2009-06-15 11:10 82432 ------w- c:\windows\system32\dllcache\tlntsess.exe

2012-01-05 21:53 . 2009-06-15 10:45 79872 ------w- c:\windows\system32\dllcache\telnet.exe

2012-01-05 21:53 . 2009-10-12 13:40 79872 ------w- c:\windows\system32\dllcache\raschap.dll

2012-01-05 21:53 . 2009-10-12 13:40 150016 ------w- c:\windows\system32\dllcache\rastls.dll

2012-01-05 21:53 . 2009-07-17 16:22 1440768 ------w- c:\windows\system32\dllcache\query.dll

2012-01-05 21:53 . 2010-11-18 18:15 86016 ------w- c:\windows\system32\dllcache\isign32.dll

2012-01-05 21:53 . 2011-11-23 14:39 1868672 ------w- c:\windows\system32\dllcache\win32k.sys

2012-01-05 21:53 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe

2012-01-05 21:53 . 2011-02-02 07:58 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll

2012-01-05 21:53 . 2009-06-10 06:20 134144 ------w- c:\windows\system32\dllcache\wkssvc.dll

2012-01-05 21:51 . 2009-12-17 07:42 345600 ------w- c:\windows\system32\dllcache\mspaint.exe

2012-01-05 21:50 . 2011-10-26 10:50 2153472 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2012-01-05 21:50 . 2011-10-26 10:50 2197120 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2012-01-05 21:50 . 2011-10-26 10:50 2073728 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2012-01-05 21:50 . 2011-10-26 10:50 2031616 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2012-01-05 21:50 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe

2012-01-05 21:50 . 2011-04-29 17:23 151552 ------w- c:\windows\system32\dllcache\schannel.dll

2012-01-05 21:50 . 2010-12-22 12:32 301568 ------w- c:\windows\system32\dllcache\kerberos.dll

2012-01-05 21:50 . 2009-09-11 14:16 136704 ------w- c:\windows\system32\dllcache\msv1_0.dll

2012-01-05 21:50 . 2009-06-25 08:42 54272 ------w- c:\windows\system32\dllcache\wdigest.dll

2012-01-05 21:50 . 2009-06-25 08:42 56832 ------w- c:\windows\system32\dllcache\secur32.dll

2012-01-05 21:50 . 2009-06-24 10:28 92928 ------w- c:\windows\system32\dllcache\ksecdd.sys

2012-01-05 21:49 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys

2012-01-05 21:49 . 2010-08-27 08:03 119808 ------w- c:\windows\system32\dllcache\t2embed.dll

2012-01-05 21:49 . 2009-10-15 16:38 81920 ------w- c:\windows\system32\dllcache\fontsub.dll

2012-01-05 21:49 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe

2012-01-05 21:49 . 2009-03-06 14:23 285696 ------w- c:\windows\system32\dllcache\pdh.dll

2012-01-05 21:49 . 2009-02-09 11:27 111104 ------w- c:\windows\system32\dllcache\services.exe

2012-01-05 21:49 . 2009-02-09 10:56 401408 ------w- c:\windows\system32\dllcache\rpcss.dll

2012-01-05 21:49 . 2009-02-09 10:56 473600 ------w- c:\windows\system32\dllcache\fastprox.dll

2012-01-05 21:49 . 2009-02-06 10:39 35328 ------w- c:\windows\system32\dllcache\sc.exe

2012-01-05 21:49 . 2009-02-09 10:56 684544 ------w- c:\windows\system32\dllcache\advapi32.dll

2012-01-05 21:49 . 2009-02-09 10:56 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll

2012-01-05 21:49 . 2009-06-21 21:49 153088 ------w- c:\windows\system32\dllcache\triedit.dll

2012-01-05 21:48 . 2011-06-24 14:09 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys

2012-01-05 21:48 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys

2012-01-05 21:48 . 2009-07-31 04:30 1447424 ------w- c:\windows\system32\dllcache\msxml6.dll

2012-01-05 21:48 . 2010-06-14 07:40 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll

2012-01-05 21:47 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2012-01-05 21:47 . 2010-06-18 13:36 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe

2012-01-05 21:47 . 2012-01-05 21:47 -------- d-----w- c:\program files\Lavalys

2012-01-05 21:45 . 2010-12-09 15:15 739328 ------w- c:\windows\system32\dllcache\ntdll.dll

2012-01-05 21:44 . 2010-07-16 11:57 221184 ------w- c:\windows\system32\dllcache\wordpad.exe

2012-01-05 21:44 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys

2012-01-05 21:43 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe

2012-01-05 21:43 . 2010-08-16 08:45 590848 ------w- c:\windows\system32\dllcache\rpcrt4.dll

2012-01-05 21:43 . 2009-12-24 07:05 177664 ------w- c:\windows\system32\dllcache\wintrust.dll

2012-01-05 21:43 . 2010-01-13 14:06 87040 ------w- c:\windows\system32\dllcache\cabview.dll

2012-01-05 21:30 . 2010-11-03 17:15 84584 ----a-w- c:\windows\SOUNDMAN.EXE

2012-01-05 21:30 . 2008-09-24 09:40 4122368 ----a-r- c:\windows\system32\drivers\alcxwdm.sys

2012-01-05 21:30 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe

2012-01-05 21:30 . 2010-11-03 17:13 285288 ----a-w- c:\windows\system32\ALSNDMGR.CPL

2012-01-05 21:30 . 2006-12-08 14:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe

2012-01-05 21:29 . 2012-01-05 21:29 -------- d-----w- c:\program files\Realtek AC97

2012-01-05 21:29 . 2012-01-16 23:01 -------- d--h--w- c:\program files\InstallShield Installation Information

2012-01-05 21:29 . 2006-07-31 10:19 315392 ----a-w- c:\windows\alcupd.exe

2012-01-05 21:29 . 2012-01-05 21:29 -------- d-----w- c:\program files\Common Files\InstallShield

2012-01-04 23:13 . 2012-01-22 14:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3

2012-01-04 18:37 . 2011-12-29 18:00 79360 ----a-w- c:\windows\system32\ff_vfw.dll

2012-01-04 18:37 . 2011-12-21 18:14 151552 ----a-w- c:\windows\system32\ac3acm.acm

2012-01-04 18:37 . 2011-06-24 15:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll

2012-01-04 18:37 . 2011-06-24 15:28 650752 ----a-w- c:\windows\system32\xvidcore.dll

2012-01-04 18:37 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm

2012-01-04 18:37 . 2012-01-04 18:37 -------- d-----w- c:\program files\K-Lite Codec Pack

2012-01-04 18:31 . 2012-01-24 17:52 -------- d-----w- c:\documents and settings\Administrator\Tracing

2012-01-04 18:30 . 2012-01-04 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!

2012-01-04 18:30 . 2012-01-04 18:30 -------- d-----w- c:\program files\Yuna Software

2012-01-04 18:27 . 2012-01-04 18:27 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE

2012-01-04 18:23 . 2012-01-04 18:23 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache

2012-01-04 18:22 . 2011-12-21 08:02 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll

2012-01-04 18:22 . 2011-12-21 08:02 97240 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll

2012-01-04 18:22 . 2011-12-21 08:02 814040 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll

2012-01-04 18:22 . 2011-12-21 08:02 486360 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll

2012-01-04 18:22 . 2011-12-21 08:02 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll

2012-01-04 18:22 . 2011-12-21 08:02 2124760 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll

2012-01-04 18:22 . 2011-12-21 08:02 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll

2012-01-04 18:22 . 2011-12-21 04:29 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll

2012-01-04 18:22 . 2011-12-21 04:29 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll

2012-01-04 18:22 . 2011-12-21 04:29 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll

2012-01-04 18:22 . 2011-12-21 04:29 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll

2012-01-04 18:22 . 2011-12-21 04:29 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll

2012-01-04 18:20 . 2012-01-04 18:20 -------- d-----w- c:\program files\Microsoft

2012-01-04 18:19 . 2012-01-04 18:19 -------- d-----w- c:\program files\Windows Live SkyDrive

2012-01-04 18:19 . 2012-01-16 23:56 -------- d--h--w- c:\windows\$hf_mig$

2012-01-04 18:19 . 2012-01-04 18:19 -------- d-----w- c:\program files\Windows Live

2012-01-04 18:17 . 2012-01-04 18:18 -------- dc-h--w- c:\windows\ie8

2012-01-04 18:16 . 2012-01-04 18:16 -------- d-----w- c:\program files\Common Files\Windows Live

2012-01-04 18:12 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-01-11 11:59 . 2011-06-27 16:37 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-12-19 19:53 . 2011-12-19 19:53 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-12-19 19:53 . 2011-12-19 19:53 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-11-25 21:57 . 2008-09-23 12:00 293888 ----a-w- c:\windows\system32\winsrv.dll

2011-11-23 14:39 . 2008-09-23 12:00 1868672 ----a-w- c:\windows\system32\win32k.sys

2011-11-20 06:12 . 2008-09-23 12:00 60928 ----a-w- c:\windows\system32\packager.exe

2011-11-04 19:13 . 2008-09-23 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

2011-11-04 19:13 . 2008-09-23 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

2011-11-04 19:13 . 2008-09-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-11-04 11:25 . 2008-09-23 12:00 385024 ------w- c:\windows\system32\html.iec

2011-11-03 15:29 . 2008-09-23 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll

2011-11-03 15:29 . 2008-09-23 12:00 1296384 ----a-w- c:\windows\system32\quartz.dll

2011-11-01 16:05 . 2008-09-23 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll

2011-10-28 05:32 . 2008-09-23 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-12-21 08:02 . 2012-01-04 18:22 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-09-23 12:00 . 753C7C72C1F462A009C877B41730F3EC . 1475072 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll

.

[-] 2008-09-23 . F7A21A4461BEF6414D9AF587C7D69E7D . 591872 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

.

[-] 2008-09-23 . 15414691C4C039FF03377DC2A27AF592 . 518144 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

.

[-] 2008-09-23 . C55B10AB1C2C8ED9F913BAFB3E296B4A . 1701888 . . [6.00.2900.5634] . . c:\windows\explorer.exe

.

[-] 2008-09-23 . A09F1B50133C856DA9AED1782FD9A64D . 218112 . . [5.1.2600.5512] . . c:\windows\regedit.exe

.

[-] 2008-09-23 . 6C4E087200E46977DFE54147A5B1FDD8 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]

"nwiz"="nwiz.exe" [2008-09-17 1657376]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]

"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]

"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]

"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-10-24 801792]

"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]

"RTHDCPL"="RTHDCPL.EXE" [2011-12-05 20065384]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-09-23 37376]

.

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:Remote Desktop

"65533:TCP"= 65533:TCP:Services

"52344:TCP"= 52344:TCP:Services

.

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18-3-2011 22:43 691696]

R3 xcpip;Stuurprogramma voor TCP/IP-protocol;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]

R3 xpsec;IPSEC-stuurprogramma;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17-1-2012 0:01 1691480]

.

--- Andere Services/Drivers In Geheugen ---

.

*NewlyCreated* - WS2IFSL

.

Inhoud van de 'Gedeelde Taken' map

.

2012-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.nl/

uDefault_Search_URL = hxxp://www.google.nl

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

Trusted Zone: abnamro.nl\www

TCP: DhcpNameServer = 10.0.0.138

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\whw7hqgz.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.nl/

FF - user.js: network.cookie.cookieBehavior - 0

FF - user.js: privacy.clearOnShutdown.cookies - false

FF - user.js: security.warn_viewing_mixed - false

FF - user.js: security.warn_viewing_mixed.show_once - false

FF - user.js: security.warn_submit_insecure - false

FF - user.js: security.warn_submit_insecure.show_once - false

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-01-24 21:13

Windows 5.1.2600 Service Pack 3 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

Scan succesvol afgerond

verborgen bestanden: 0

.

**************************************************************************

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\S-1-5-21-606747145-2052111302-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,b2,5d,7b,ea,54,c6,48,8f,dc,a1,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,b2,5d,7b,ea,54,c6,48,8f,dc,a1,\

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'winlogon.exe'(744)

c:\windows\system32\SETUPAPI.dll

c:\windows\system32\COMRes.dll

c:\windows\system32\cscui.dll

.

- - - - - - - > 'lsass.exe'(800)

c:\windows\system32\setupapi.dll

.

- - - - - - - > 'explorer.exe'(4412)

c:\windows\system32\SHDOCVW.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\system32\nview.dll

c:\windows\system32\NVWRSNL.DLL

c:\windows\system32\COMRes.dll

c:\windows\System32\cscui.dll

c:\windows\system32\LINKINFO.dll

c:\windows\system32\ntshrui.dll

c:\windows\system32\msi.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\SETUPAPI.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\windows\system32\NETSHELL.dll

c:\windows\system32\credui.dll

c:\windows\system32\MSVCP60.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\system32\RUNDLL32.EXE

c:\windows\system32\rundll32.exe

c:\windows\RTHDCPL.EXE

c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe

c:\windows\eHome\ehRecvr.exe

c:\windows\eHome\ehSched.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

c:\windows\system32\nvsvc32.exe

c:\windows\eHome\ehmsas.exe

c:\windows\ehome\mcrdsvc.exe

c:\windows\system32\wscntfy.exe

c:\windows\system32\dllhost.exe

.

**************************************************************************

.

Voltooingstijd: 2012-01-24 21:14:19 - machine werd herstart

ComboFix-quarantined-files.txt 2012-01-24 20:14

ComboFix2.txt 2012-01-24 17:37

.

Pre-Run: 88.558.145.536 bytes beschikbaar

Post-Run: 88.554.733.568 bytes beschikbaar

.

- - End Of File - - 31230B15CE2926CF593310DAD1DBA8CC

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 21:15:13, on 24-1-2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\VistaDrive\VistaDrive.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl

O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 4753 bytes

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.