Ga naar inhoud

Blanco pagina


Tjoeptjie

Aanbevolen berichten

  • Reacties 41
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Kape

Ik heb combofix zijn ding laten doen. Het enige probleem, was het opstarten. Namelijk bij het herstarten van de laptop, kreeg ik na mij aan te loggen weer een zwart scherm en deed mijn pc niets meer.

Heb het logje van combofix gaan zoeken en ik denk dat het dit is...

ComboFix 12-10-25.01 - Tommeke 25/10/2012 11:04:22.1.2 - x86 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3068.2262 [GMT 2:00]

Gestart vanuit: C:\Users\Tommeke\Downloads\ComboFix.exe

AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}

FW: FireWall *Enabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}

SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Nieuw herstelpunt werd aangemaakt

ADS - Windows: deleted 24 bytes in 1 streams.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

C:\Program Files\Acer\Acer Bio Protection\PwdFilter.dll

C:\ProgramData\Roaming

C:\ProgramData\Roaming\Intel\Wireless\Settings\Settings.ini

C:\Users\Schattie\AppData\Roaming\.#

C:\Users\Schattie\WINDOWS

C:\Users\Tommeke\AppData\Roaming\.#

C:\Windows\system32\roboot.exe

C:\Windows\system32\SET58A3.tmp

C:\Windows\system32\SET68BC.tmp

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_nvsvc

Hopelijk ben je er iets mee, want zo in veilige modus werken is toch ook niet alles...

grts

Link naar reactie
Delen op andere sites

Kape

Dit is alles wat ik op mijn c-partitie terugvind. Misschien omdat combofix bij het herstarten niet is kunnen starten door het niet normaal kunnen opstarten van mijn pc dat ik daarom geen volledig logje heb...

Misschien best systeemherstel doen en dan combofix laten draaien...?

Link naar reactie
Delen op andere sites

Dit logje is beter denk ik....

ComboFix 12-10-26.05 - Tommeke 27/10/2012 16:42:55.1.2 - x86

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3068.1445 [GMT 2:00]

Gestart vanuit: c:\users\Tommeke\Downloads\ComboFix.exe

AV: Avira Desktop *Disabled/Outdated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}

FW: FireWall *Disabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}

SP: Avira Desktop *Disabled/Outdated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

ADS - Windows: deleted 24 bytes in 1 streams.

.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files\Acer\Acer Bio Protection\PwdFilter.dll

c:\program files\Web Assistant\ExTEnsion32.dll

c:\programdata\Roaming

c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini

c:\windows\system32\SET58A3.tmp

c:\windows\system32\SET68BC.tmp

.

---- Voorgaande Run -------

.

c:\program files\Acer\Acer Bio Protection\PwdFilter.dll

c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini

c:\windows\system32\roboot.exe

c:\windows\system32\SET58A3.tmp

c:\windows\system32\SET68BC.tmp

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_nvsvc

-------\Service_nvsvc

.

.

(((((((((((((((((((( Bestanden Gemaakt van 2012-09-27 to 2012-10-27 ))))))))))))))))))))))))))))))

.

.

2012-10-27 14:54 . 2012-10-27 14:59 -------- d-----w- c:\users\Tommeke\AppData\Local\temp

2012-10-25 09:10 . 2012-10-25 09:10 -------- d-----w- c:\users\Schattie\AppData\Local\Temp(22)

2012-10-18 11:57 . 2012-10-18 11:57 -------- d-----w- c:\users\Schattie\AppData\Roaming\Avira

2012-10-15 19:54 . 2012-10-15 19:54 388096 ----a-r- c:\users\Tommeke\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2012-10-15 18:21 . 2012-10-15 18:21 -------- d-----w- c:\users\Tommeke\AppData\Roaming\Avira

2012-10-15 18:19 . 2012-10-15 18:01 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys

2012-10-15 18:19 . 2012-10-15 18:01 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys

2012-10-15 18:19 . 2012-10-15 18:01 91968 ----a-w- c:\windows\system32\drivers\avfwim.sys

2012-10-15 18:19 . 2012-10-15 18:01 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2012-10-15 18:19 . 2012-10-15 18:01 112032 ----a-w- c:\windows\system32\drivers\avfwot.sys

2012-10-15 18:19 . 2012-10-15 18:19 -------- d-----w- c:\program files\Avira

2012-10-11 09:58 . 2011-07-07 11:08 17280 ----a-w- c:\windows\system32\roboot.exe

.

.

.

((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-09-24 13:32 . 2012-07-15 15:51 477168 ----a-w- c:\windows\system32\npdeployJava1.dll

2012-09-24 13:32 . 2010-05-05 19:29 473072 ----a-w- c:\windows\system32\deployJava1.dll

2012-08-06 12:27 . 2012-08-06 12:27 15248 ----a-w- c:\windows\system32\drivers\pmkbdfltr.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]

@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"

[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]

2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2008-08-04 488808]

"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2012-08-06 366576]

"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2012-09-24 3129184]

"SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2012-09-28 406936]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"PLFSetI"="c:\windows\PLFSetI.exe" [2008-06-30 200704]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-10-15 348664]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]

2009-01-02 23:50 3162624 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk

backup=c:\windows\pss\Acer VCM.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk

backup=c:\windows\pss\BTTray.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2008-10-15 00:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]

2008-07-24 14:54 147456 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]

2008-07-24 14:54 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]

2008-05-30 11:24 544768 ------w- c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]

2008-07-29 16:52 526896 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]

2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]

2008-08-01 08:51 405504 ----a-w- c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

2009-01-02 23:44 24064 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]

2008-07-20 16:45 182808 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

2009-03-25 11:30 1840424 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]

2008-06-16 09:58 809480 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]

2008-12-02 13:29 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]

2008-07-18 15:04 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2008-11-04 09:30 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]

2011-09-26 20:41 9398888 ----a-w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]

2011-09-26 20:41 1833576 ----a-w- c:\program files\Realtek\Audio\HDA\SkyTel.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2011-12-12 19:02 1549608 ------w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]

2008-01-29 08:03 303104 ----a-w- c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]

2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]

2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZPdtWzdVitaKey MC3000]

2009-01-02 23:49 3719680 ----a-w- c:\program files\Acer\Acer Bio Protection\PdtWzd.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

bdx REG_MULTI_SZ scan

.

Inhoud van de 'Gedeelde Taken' map

.

2012-10-27 c:\windows\Tasks\DriverScanner.job

- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2012-10-15 10:51]

.

2012-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-26 16:48]

.

2012-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-26 16:48]

.

2010-04-24 c:\windows\Tasks\Install_NSS.job

- c:\program files\Vuze\nssstub.exe [2010-04-24 15:02]

.

2012-10-10 c:\windows\Tasks\OGADaily.job

- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]

.

2012-10-27 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]

.

2012-10-27 c:\windows\Tasks\RegistryBooster.job

- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2012-07-15 12:39]

.

2012-10-27 c:\windows\Tasks\SpeedUpMyPC.job

- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2012-08-06 13:38]

.

.

------- Bijkomende Scan -------

.

uStart Page = hxxp://www.google.be/

uInternet Settings,ProxyOverride = localhost

LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll

TCP: DhcpNameServer = 195.130.130.141 195.130.131.141

.

- - - - ORPHANS VERWIJDERD - - - -

.

URLSearchHooks-{87775fdb-6972-41f9-ae51-8326e38cb206} - (no file)

URLSearchHooks-{95324e44-4b0a-47a9-8f77-9c6415e51c29} - (no file)

MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

MSConfigStartUp-BDAgent - c:\program files\BitDefender\BitDefender 2010\bdagent.exe

MSConfigStartUp-BitDefender Antiphishing Helper - c:\program files\BitDefender\BitDefender 2010\IEShow.exe

MSConfigStartUp-BkupTray - c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe

MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe

MSConfigStartUp-MediaGet2 - c:\users\Tommeke\AppData\Local\MediaGet2\mediaget.exe

MSConfigStartUp-SiteAdvisor - c:\program files\SiteAdvisor\6172\SiteAdv.exe

MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2012-10-27 16:58

Windows 6.0.6002 Service Pack 2 NTFS

.

scannen van verborgen processen ...

.

scannen van verborgen autostart items ...

.

scannen van verborgen bestanden ...

.

.

c:\users\Tommeke\AppData\Roaming\Microsoft\Windows\Cookies\Low\tommeke@incredimail[1].txt 1590 bytes

.

Scan succesvol afgerond

verborgen bestanden: 1

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]

"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"

.

--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------

.

[HKEY_USERS\.Default\Software\SetID\Internal]

@Denied: (A 2) (LocalSystem)

"DATA"="<settings expireTime=\"0\" productStatus=\"1\" obSize=\"0\" InstallTS=\"2145870353\" isSubsc=\"0\" version=\"12.0.1\" timeDiff=\"1\" oldDevice=\"\" authStatus_ts=\"0\" />"

"Device"="yM29zbvPzMnLvrm+x8fPzce+zro="

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

"MSCurrentCountry"=dword:000000b5

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

--------------------- DLLs Geladen Onder Lopende Processen ---------------------

.

- - - - - - - > 'Explorer.exe'(3644)

c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll

.

------------------------ Andere Aktieve Processen ------------------------

.

c:\windows\servicing\TrustedInstaller.exe

c:\windows\system32\vfsFPService.exe

c:\windows\system32\WLANExt.exe

c:\program files\Avira\AntiVir Desktop\sched.exe

c:\windows\system32\agrsmsvc.exe

c:\program files\Avira\AntiVir Desktop\avfwsvc.exe

c:\program files\Avira\AntiVir Desktop\avguard.exe

c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe

c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe

c:\program files\Acer\Empowering Technology\Service\ETService.exe

c:\program files\Intel\WiFi\bin\EvtEng.exe

c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

c:\program files\Acer\Acer Bio Protection\BASVC.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\acer\Mobility Center\MobilityService.exe

c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe

c:\windows\system32\IoctlSvc.exe

c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe

c:\program files\Acer\Acer VCM\RS_Service.exe

c:\program files\Web Assistant\ExtensionUpdaterService.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\windows\system32\WUDFHost.exe

c:\program files\Avira\AntiVir Desktop\avshadow.exe

c:\program files\Avira\AntiVir Desktop\avmailc.exe

c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE

c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe

c:\windows\system32\conime.exe

c:\progra~1\Magentic\bin\MgApp.exe

c:\program files\IncrediMail\Bin\ImApp.exe

c:\\?\c:\windows\system32\wbem\WMIADAP.EXE

c:\program files\avira\antivir desktop\guardgui.exe

.

**************************************************************************

.

Voltooingstijd: 2012-10-27 17:04:49 - machine werd herstart

ComboFix-quarantined-files.txt 2012-10-27 15:04

.

Pre-Run: 92.797.689.856 bytes beschikbaar

Post-Run: 92.761.096.192 bytes beschikbaar

.

- - End Of File - - 58050C021374F49894AB9C395E073E81

Blanco pagina kwam er wel nog op....

Grts

Link naar reactie
Delen op andere sites

  • 1 maand later...

Oeps ... ben je topic wel even uit het oog verloren. Maar vooral ook omdat ik niet echt kon achterhalen welke blanco pagina's je krijgt als je niet met je browser werkt. Is dat dan in andere programma's (type Word, Excel, o.i.d.) ? Of waar komt die blanco pagina dan opdagen ? Met internetverbinding werk je uiteraard met je browser en dan zou het kunnen, maar zonder internet in je browser lijkt me vreemd. Kan je dat eens verduidelijken ?

Link naar reactie
Delen op andere sites

Gast
Dit topic is nu gesloten voor nieuwe reacties.

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.