Ga naar inhoud

update problemen windows 7


anoniem

Aanbevolen berichten

sinds 15 augustus worden de updates wel gedownload en geinstalleerd. Dit gebeurd bij het afsluiten van de pc. maar als de pc weer wordt opgestart kgaat hij windows configureren en krijg ik de foutmelding fout bij configuren windows update. Dan sluit de pc af verwijderd de wijzigingen en start gewoon op. Fix-it lost niets op, en de services staan goed. Het tereft zover ik kan zien de foutcode 8007002 en 8007003. Wie weet weet hoe ik deze updates toch geinstalleerd krijg of hoe ik ze definitief kan verwijderen. Alvast bedankt voor het meedenken
Link naar reactie
Ik zal graag zien, dat deze topic verplaatst wordt naar "Beveiliging". Hallo Rijntje, [img:104a46f307]http://www.smartestcomputing.us.com/public/style_emoticons/default/smiley_says_hello.gif[/img:104a46f307]van harte welkom op dit geweldige forum. Graag het volgende doen: [color=#FF0000:104a46f307][b:104a46f307]Stap •1•[/b:104a46f307][/color:104a46f307] [b:104a46f307]Welk programma[/b:104a46f307]: [color=#008000:104a46f307][b:104a46f307]AdwCleaner[/b:104a46f307][/color:104a46f307] [b:104a46f307]Waarvoor/waarom[/b:104a46f307]: Scanner om Windows op te schonen en te ontdoen van malafide toolbars. [b:104a46f307]Moeilijkheidsgraad[/b:104a46f307]: Geen. [b:104a46f307]Downloadlokatie[/b:104a46f307]: Dit programma absoluut naar het bureaublad downloaden dan wel daar naar toe verplaatsen! [b:104a46f307]Download[/b:104a46f307]: [url=http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner]AdwCleaner by Xplode[/url]. [b:104a46f307]Opmerkingen[/b:104a46f307]: [list:104a46f307][*:104a46f307][color=#FF0000:104a46f307][b:104a46f307] Alle openstaande programma's en webpagina's dienen afgesloten te zijn[/b:104a46f307][/color:104a46f307]. [*:104a46f307]Dat na opstarten van [color=#008000:104a46f307][b:104a46f307]AdwCleaner[/b:104a46f307][/color:104a46f307] de snelkoppelingen verdwijnen van bureaublad, is normaal.[/list:u:104a46f307] [b:104a46f307][color=#008000:104a46f307]AdwCleaner[/color:104a46f307] opstarten[/b:104a46f307]: [list:104a46f307][*:104a46f307][b:104a46f307][color=#0000FF:104a46f307]Windows 2000[/color:104a46f307][/b:104a46f307] en [color=#0000FF:104a46f307][b:104a46f307]Windows XP[/b:104a46f307][/color:104a46f307]: dubbelklik op adwcleaner.exe. [*:104a46f307][color=#0000FF:104a46f307][b:104a46f307]Windows Vista[/b:104a46f307][/color:104a46f307] en [color=#0000FF:104a46f307][b:104a46f307]Windows 7[/b:104a46f307][/color:104a46f307]: via rechtsklik op adwcleaner.exe en kies voor "Als Administrator uitvoeren".[/list:u:104a46f307] [b:104a46f307][color=#008000:104a46f307]AdwCleaner[/color:104a46f307] is opgestart[/b:104a46f307]: [list:104a46f307][*:104a46f307]Klik vervolgens op [color=#0000FF:104a46f307][b:104a46f307]Delete[/b:104a46f307][/color:104a46f307] [*:104a46f307]Klik bij [color=#0000FF:104a46f307][b:104a46f307]AdwCleaner – Information[/b:104a46f307][/color:104a46f307] op [b:104a46f307]OK[/b:104a46f307] [*:104a46f307]Klik bij [color=#0000FF:104a46f307][b:104a46f307]AdwCleaner – Restart Required[/b:104a46f307][/color:104a46f307] op [b:104a46f307]OK[/b:104a46f307][/list:u:104a46f307] [b:104a46f307][color=#008000:104a46f307]AdwCleaner[/color:104a46f307] logbestand[/b:104a46f307]: [list:104a46f307][*:104a46f307]Nadat de PC opnieuw is opgestart, opent een logfile. [*:104a46f307]Post vervolgens aansluitend de inhoud van dit log in je volgende bericht.[/list:u:104a46f307] [color=#FF0000:104a46f307][b:104a46f307]Stap •2•[/b:104a46f307][/color:104a46f307] [b:104a46f307]Welk programma[/b:104a46f307]: [color=#008000:104a46f307][b:104a46f307]sUbs dds[/b:104a46f307][/color:104a46f307] [b:104a46f307]Waarvoor/waarom[/b:104a46f307]: DDS is een diagnosetool en maakt gebruik van scripts. [b:104a46f307]Moeilijkheidsgraad[/b:104a46f307]: Lees eerst goed wat te doen. [b:104a46f307]Downloadlokatie[/b:104a46f307]: Dit programma absoluut naar het bureaublad downloaden of anders eerst daar naar toe verplaatsen! [b:104a46f307]Download DDS[/b:104a46f307] van [b:104a46f307]sUBS[/b:104a46f307] van één van deze locaties en plaats het op je [b:104a46f307]bureaublad[/b:104a46f307]: [b:104a46f307][url=http://download.bleepingcomputer.com/sUBs/dds.com]DDS - Bleeping Computer download[/url]. [url=http://download.bleepingcomputer.com/sUBs/dds.scr]DDS - Bleeping Computer download[/url]. [url=http://www.infospyware.net/sUBs/dds]DDS - Infospyware[/url].[/b:104a46f307] [img:104a46f307]http://img.photobucket.com/albums/v666/sUBs/dds_scr.gif[/img:104a46f307] [b:104a46f307]sUBs dds. gebruiken[/b:104a46f307]: [list:104a46f307][*:104a46f307][b:104a46f307][color=#0000FF:104a46f307]Sluit vervolgens eerst alle nog openstaande programmavensters![/color:104a46f307][/b:104a46f307] [*:104a46f307] [b:104a46f307][color=#008000:104a46f307]Antivirusprogramma en actieve malwarescanners dienen gedeaktiveerd zijn!/COLOR][/b:104a46f307] [list:104a46f307][*:104a46f307][url=http://www.hijackthis.nl/forum/viewtopic.php?f=86&t=32608][b:104a46f307][color=#0000FF]Hier[/color:104a46f307][/b:104a46f307][/url] of [url=http://www.hijackthis.nl/forum/viewtopic.php?f=86&t=32607][color=#0000FF:104a46f307][b:104a46f307]hier[/b:104a46f307][/color:104a46f307][/url] kan je lezen hoe je dat doet.[/list:u:104a46f307] [list:104a46f307][*:104a46f307][b:104a46f307][color=#0000FF:104a46f307]Windows 2000[/color:104a46f307][/b:104a46f307] en [color=#0000FF:104a46f307][b:104a46f307]Windows XP[/b:104a46f307][/color:104a46f307]: start sUBs dds. middels dubbelklik op de snelkoppeling. [*:104a46f307][color=#0000FF:104a46f307][b:104a46f307]Windows Vista[/b:104a46f307][/color:104a46f307] en [color=#0000FF:104a46f307][b:104a46f307]Windows 7[/b:104a46f307][/color:104a46f307]: start sUBs dds. rechtsklik op de snelkoppeling en dan kiezen voor Als Administrator uitvoeren.[/list:u:104a46f307][/list:u:104a46f307] [b:104a46f307]Na de scan[/b:104a46f307] [list:104a46f307][*:104a46f307] [b:104a46f307][color=#FF0000:104a46f307]Heraktiveer nu de actieve beveiligingssoftware[/color:104a46f307][/b:104a46f307] [*:104a46f307]Er worden twee tekstdocumnenten geopend - DDS.txt en Attach.txt - let even op het volgende! [*:104a46f307]Kopieer en plak de gehele inhoud van de [b:104a46f307]DDS-logfile[/b:104a46f307] in jouw volgende bericht. [*:104a46f307]De inhoud van [b:104a46f307]Attach.txt[/b:104a46f307] post je wanneer ik daarom vraag.[/list:u:104a46f307]
Link naar reactie
Beste mensen het is helemaal top dat jullie mij zo uitgebreid willen helpen. Alvast dank daar voor. Hier is danhet gevraagde logfile: # AdwCleaner v1.801 - Logfile created 08/19/2012 at 22:26:55 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : John - WOONKAMER # Boot Mode : Normal # Running from : C:\Users\John\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Folder Deleted : C:\Users\John\AppData\Local\Linkury Folder Deleted : C:\Program Files (x86)\Babylon Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\BrowserCompanion ***** [Registry] ***** [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1460988 Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\BrowserCompanion Key Deleted : HKLM\SOFTWARE\Conduit Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] [x64] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03} [x64] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus --> hxxp://www.google.com -\\ Google Chrome v21.0.1180.79 File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted : "homepage": "hxxp://www.plusnetwork.com/?sp=hp/", Deleted : "urls_to_restore_on_startup": [ "hxxp://www.plusnetwork.com/?sp=hp/" ] Deleted : "icon_url": "hxxp://www.plusnetwork.com/assets/56674c9b/img/favicon.ico", Deleted : "keyword": "www.plusnetwork.com", Deleted : "name": "Messenger Plus Smartbar Search", Deleted : "search_url": "hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus", Deleted : "description": "Babylon tool translates texts from within your Google Chrome in a sin[...] Deleted : "128": "babylon48.png", Deleted : "48": "babylon48.png" Deleted : "name": "Babylon Translator", Deleted : "path": "BabylonChromePI.dll", Deleted : "homepage": "hxxp://www.plusnetwork.com/?sp=hp/", Deleted : "name": "Babylon Chrome Plugin", Deleted : "path": "C:\\Users\\John\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\d[...] Deleted : "name": "Babylon Chrome Plugin" Deleted : "urls_to_restore_on_startup": [ "hxxp://www.plusnetwork.com/?sp=hp/" ] ************************* AdwCleaner[S1].txt - [4140 octets] - [19/08/2012 22:26:55] ########## EOF - C:\AdwCleaner[S1].txt - [4268 octets] ##########
Link naar reactie
. DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 Run by John at 22:36:22 on 2012-08-19 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4091.2466 [GMT 2:00] . AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork D:\foto's\progs\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\SysWOW64\astsrv.exe C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Windows\SysWOW64\XSrvSetup.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k HPService C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesApp64.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\wuauclt.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com mWinlogon: Userinit=userinit.exe, BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL BHO: Aanmeldhulp voor Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" mRun: [<NO NAME>] mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Download with x-ipad-magic-platinum - C:\Program Files (x86)\Xilisoft\iPad Magic Platinum\upod_link.HTM IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} - hxxp://www.normandie-webcam.com/plugins/h263ctrl20013/h263ctrl.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab DPF: {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 213.46.228.196 62.179.104.196 TCP: Interfaces\{14AE854E-BE7E-4F5C-BE6D-B34BF3B8296F} : DhcpNameServer = 213.46.228.196 62.179.104.196 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache {0347C33E-8762-4905-BF09-768834316C61} {18DF081C-E8AD-4283-A596-FA578C2EBDC3} {72853161-30C5-4D22-B7F9-0BBC1D38A37E} {9030D464-4C02-4ABF-8ECC-5164760863C6} {9FDDE16B-836F-4806-AB1F-1455CBEFF289} {AA58ED58-01DD-4d91-8333-CF10577473F7} {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} {B4F3A835-0E21-4959-BA22-42B3008E02FF} {DBC80044-A445-435b-BC74-9C25C1C588A9} {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} {2318C2B1-4965-11d4-9B18-009027A5CD4F} EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File mRun-x64: [(standaard)] mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun-x64: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun SEH-X64: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}: Groove GFS Stub Execution Hook . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?] R2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-5-20 219360] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-8-9 974944] R2 epfwwfpr;epfwwfpr;C:\Windows\system32\DRIVERS\epfwwfpr.sys --> C:\Windows\system32\DRIVERS\epfwwfpr.sys [?] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-5-20 13336] R2 JMB36X;JMB36X;C:\Windows\SysWOW64\XSrvSetup.exe [2010-5-20 65536] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-14 655944] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2010-6-24 92008] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-10 1394504] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 CyberMania;CyberMania;C:\Program Files\ESET\ServiceEx.exe run --> C:\Program Files\ESET\ServiceEx.exe run [?] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-24 136176] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840] S3 gupdatem;Google Update-service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-24 136176] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-08-19 10:15:57 -------- d-----w- C:\Users\John\AppData\Local\{613F45F1-24DA-4F45-A252-3D9D8D8CCF8C} 2012-08-18 18:30:49 -------- d-----w- C:\Users\John\AppData\Local\{39954B93-9436-4249-9BC4-9B5B31B9BF95} 2012-08-18 18:30:27 -------- d-----w- C:\Users\John\AppData\Local\{44567C0E-998E-4CEC-AFCD-299FBC4BC1A9} 2012-08-17 21:01:51 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B65155D5-4855-44CA-8476-27F33B693849}\mpengine.dll 2012-08-17 21:00:34 -------- d-----w- C:\Users\John\AppData\Local\{9DBED091-42F0-4B2A-9ACB-56A5FC059402} 2012-08-17 21:00:11 -------- d-----w- C:\Users\John\AppData\Local\{9CE197DD-E3A6-4654-8A99-5D4194FC7DEA} 2012-08-16 15:02:28 -------- d-----w- C:\Users\John\AppData\Local\{A7E8C85D-98BD-49B2-90B2-AED58BAE3C6C} 2012-08-16 15:02:06 -------- d-----w- C:\Users\John\AppData\Local\{85BB200F-530F-446C-B549-C973A6A00EC3} 2012-08-15 12:56:12 -------- d-----w- C:\Users\John\AppData\Local\{78C4D676-F75D-4E53-9498-84EF3515C9F4} 2012-08-15 12:55:50 -------- d-----w- C:\Users\John\AppData\Local\{2DF632AA-DD9A-4D38-BE3F-D6BD8FFA5775} 2012-08-14 15:54:10 -------- d-----w- C:\Users\John\AppData\Local\{126A4BB8-9E80-4FB5-BE52-2F09EBD38F29} 2012-08-14 15:53:47 -------- d-----w- C:\Users\John\AppData\Local\{132B1089-B880-4B8C-9DC8-2E0EC9A9B100} 2012-08-13 19:26:31 -------- d-----w- C:\Users\John\AppData\Local\{BC08AF3B-9CE7-4C6D-9AA0-2EBA737445FF} 2012-08-13 19:26:10 -------- d-----w- C:\Users\John\AppData\Local\{8AABE870-80D4-41AA-BF03-C08D3130DA5A} 2012-08-12 21:07:59 -------- d-----w- C:\Users\John\AppData\Local\{2B15EB9A-6E01-467B-9F74-825D276A0FB1} 2012-08-12 21:07:48 -------- d-----w- C:\Users\John\AppData\Local\{5EBE598A-18BA-4A31-B886-30458B357302} 2012-08-11 21:58:52 -------- d-----w- C:\Users\John\AppData\Local\{924312E9-8023-4ED5-8FDA-35DF24415CB9} 2012-08-11 21:58:30 -------- d-----w- C:\Users\John\AppData\Local\{FB480108-653A-4266-AEA5-851354952887} 2012-08-11 09:58:04 -------- d-----w- C:\Users\John\AppData\Local\{5D35081F-33A6-4278-BC6D-4508BC4796BC} 2012-08-11 09:57:53 -------- d-----w- C:\Users\John\AppData\Local\{8A9A15B4-5AEF-4917-8D68-8DD001E0A47F} 2012-08-10 18:52:04 -------- d-----w- C:\Users\John\AppData\Local\{3F42B053-C521-401B-BF8C-BED3C1269393} 2012-08-10 18:51:42 -------- d-----w- C:\Users\John\AppData\Local\{19B903AD-FA18-4B9C-9364-C0BCC588DA7F} 2012-08-09 20:51:23 -------- d-----w- C:\Users\John\AppData\Local\{D3563ECE-53EE-4AB1-94C3-FA753D577897} 2012-08-09 20:51:01 -------- d-----w- C:\Users\John\AppData\Local\{8212B5F6-9230-4C28-84ED-908A6D99CD40} 2012-08-08 16:59:33 -------- d-----w- C:\Users\John\AppData\Local\{65E6DCFB-9648-4B27-9F0B-A51823F7732F} 2012-08-08 16:59:10 -------- d-----w- C:\Users\John\AppData\Local\{041584EA-02D4-4762-BC7B-0F3FEA83EB06} 2012-08-07 19:13:49 -------- d-----w- C:\Users\John\AppData\Local\{E935C0DF-49E4-47CF-9552-49E52855FF1D} 2012-08-07 19:13:39 -------- d-----w- C:\Users\John\AppData\Local\{581BE5CF-F01F-4AEB-846B-770060B462CE} 2012-08-06 17:27:45 -------- d-----w- C:\Users\John\AppData\Local\{E93A1C37-EB83-4604-8875-8CA338D4CAC0} 2012-08-06 17:27:34 -------- d-----w- C:\Users\John\AppData\Local\{B286DC55-B7E3-4503-8EA6-0D3885126450} 2012-08-05 22:36:28 -------- d-----w- C:\Users\John\AppData\Local\{4F6B8280-635E-49BF-836A-B2DC00E8C819} 2012-08-05 10:06:28 -------- d-----w- C:\Users\John\AppData\Local\{043D6F86-6CCF-4AE4-BFB1-5CFBECD2C301} 2012-08-05 10:06:17 -------- d-----w- C:\Users\John\AppData\Local\{B76EC56B-5911-4AD7-8BB4-27AFE35810D2} 2012-08-04 16:15:02 -------- d-----w- C:\Users\John\AppData\Local\{7CCFC122-C37E-4A73-AC2B-35D6410E52DB} 2012-08-04 16:14:39 -------- d-----w- C:\Users\John\AppData\Local\{05EC9B70-6D98-4F24-BF79-B5792E9ABBFB} 2012-08-03 16:03:13 -------- d-----w- C:\Users\John\AppData\Local\{92AFE790-1270-4AEC-A78D-1E4E5A242E53} 2012-08-03 16:02:52 -------- d-----w- C:\Users\John\AppData\Local\{B9597C7C-9771-4736-86EE-8E8D4494FA27} 2012-08-02 20:57:38 -------- d-----w- C:\Users\John\AppData\Local\{825FABF2-FFA7-4E42-89AD-CE2A54F22FC9} 2012-08-02 20:57:27 -------- d-----w- C:\Users\John\AppData\Local\{A54853BC-365C-4B20-9E78-B4B17A8290C9} 2012-08-01 17:34:54 -------- d-----w- C:\Users\John\AppData\Local\{C23855B9-E6EB-4CCD-B17B-DFF62677C620} 2012-08-01 17:34:43 -------- d-----w- C:\Users\John\AppData\Local\{1B04D3F1-0EBA-4B8B-B6D0-7CE0D9BB0587} 2012-07-31 20:33:30 -------- d-----w- C:\Users\John\AppData\Local\{B493A9EE-78FC-4323-B727-13490AD972EC} 2012-07-31 20:33:08 -------- d-----w- C:\Users\John\AppData\Local\{D4E0E26D-F60F-4EC6-9ADA-601EBE8C4D18} 2012-07-30 20:46:35 -------- d-----w- C:\Users\John\AppData\Local\{37FF5186-5CBD-443C-9C9E-FDD72E933A7F} 2012-07-30 20:46:23 -------- d-----w- C:\Users\John\AppData\Local\{AE86675C-56CB-4CF4-A28F-2804DFA15408} 2012-07-29 17:11:50 -------- d-----w- C:\Users\John\AppData\Local\{2311F599-D6D3-413A-8248-9882C61C2BEB} 2012-07-29 17:11:39 -------- d-----w- C:\Users\John\AppData\Local\{D0C8B713-E9C8-407F-85AC-071A5D4FEC12} 2012-07-28 15:21:18 -------- d-----w- C:\Users\John\AppData\Local\{C8D3C548-B205-47C9-9E4C-BA0958C68131} 2012-07-28 15:20:57 -------- d-----w- C:\Users\John\AppData\Local\{35AB3D6A-99A5-4227-8D1F-895127F7A8E6} 2012-07-27 21:32:02 -------- d-----w- C:\Users\John\AppData\Local\{18453B9C-8B74-41F0-A33E-E6C580AE8DAD} 2012-07-27 21:31:51 -------- d-----w- C:\Users\John\AppData\Local\{3A703224-355A-4860-935B-C1FB4C538710} 2012-07-27 20:51:30 184248 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll 2012-07-26 21:21:36 -------- d-----w- C:\Users\John\AppData\Local\{932A8189-55E1-43A9-A4BB-AE4C2CC5A82C} 2012-07-26 21:21:14 -------- d-----w- C:\Users\John\AppData\Local\{4830FB75-D9A7-42D2-AF34-F38F141B1567} 2012-07-25 21:41:11 -------- d-----w- C:\Users\John\AppData\Local\{53EC542C-539B-4ED8-B31B-42C814B76021} 2012-07-25 21:41:00 -------- d-----w- C:\Users\John\AppData\Local\{CF63F903-2633-4045-88BF-C6D90DBBCA60} 2012-07-24 20:39:54 -------- d-----w- C:\Users\John\AppData\Local\{23021E54-DEBD-4376-86E4-E8EDAB157F32} 2012-07-24 20:39:43 -------- d-----w- C:\Users\John\AppData\Local\{3432E296-3424-4A7C-B33E-BBFCE89EBA8D} 2012-07-23 16:17:34 -------- d-----w- C:\Users\John\AppData\Local\{B08827A8-B2C2-43E7-B83A-4BA0656F0006} 2012-07-23 16:17:12 -------- d-----w- C:\Users\John\AppData\Local\{0E54EBA4-DDCC-48DD-927B-8779675D5735} 2012-07-22 20:07:27 -------- d-----w- C:\Users\John\AppData\Local\{AF2B6B5E-8545-4D39-8D8E-49120429442E} 2012-07-22 20:07:06 -------- d-----w- C:\Users\John\AppData\Local\{536DF13C-3D79-4B1D-AA35-A03A9ED4C271} 2012-07-21 21:42:16 -------- d-----w- C:\Users\John\AppData\Local\{9BE1CF5B-52ED-428A-AE62-664F52BC2BB5} 2012-07-21 21:41:54 -------- d-----w- C:\Users\John\AppData\Local\{3062FE56-FFC6-453D-A6BA-FF1E7782110C} . ==================== Find3M ==================== . 2012-08-18 22:00:53 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-18 22:00:53 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-07-03 11:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys 2012-06-12 16:24:40 123904 ----a-w- C:\Windows\System32\bcrypt.dll 2012-06-12 03:08:36 3148800 ----a-w- C:\Windows\System32\win32k.sys 2012-06-11 18:59:38 10248192 ----a-w- C:\Windows\System32\drivers\atikmdag.sys 2012-06-11 18:35:48 70144 ----a-w- C:\Windows\System32\coinst_8.98.dll 2012-06-11 18:29:34 24826368 ----a-w- C:\Windows\System32\atio6axx.dll 2012-06-11 18:00:32 20467712 ----a-w- C:\Windows\SysWow64\atioglxx.dll 2012-06-11 17:25:06 163840 ----a-w- C:\Windows\System32\atiapfxx.exe 2012-06-11 17:24:58 924160 ----a-w- C:\Windows\SysWow64\aticfx32.dll 2012-06-11 17:23:12 1090560 ----a-w- C:\Windows\System32\aticfx64.dll 2012-06-11 17:20:02 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll 2012-06-11 17:19:58 532992 ----a-w- C:\Windows\System32\atieclxx.exe 2012-06-11 17:19:14 239616 ----a-w- C:\Windows\System32\atiesrxx.exe 2012-06-11 17:17:56 120320 ----a-w- C:\Windows\System32\atitmm64.dll 2012-06-11 17:17:42 21504 ----a-w- C:\Windows\System32\atimuixx.dll 2012-06-11 17:17:38 59392 ----a-w- C:\Windows\System32\atiedu64.dll 2012-06-11 17:17:32 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll 2012-06-11 17:16:48 6301696 ----a-w- C:\Windows\SysWow64\atidxx32.dll 2012-06-11 17:01:56 6914560 ----a-w- C:\Windows\System32\atidxx64.dll 2012-06-11 16:51:54 4246528 ----a-w- C:\Windows\System32\atiumd6a.dll 2012-06-11 16:45:48 51200 ----a-w- C:\Windows\System32\aticalrt64.dll 2012-06-11 16:45:46 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll 2012-06-11 16:45:44 5480448 ----a-w- C:\Windows\SysWow64\atiumdag.dll 2012-06-11 16:45:40 44544 ----a-w- C:\Windows\System32\aticalcl64.dll 2012-06-11 16:45:38 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll 2012-06-11 16:45:26 15703040 ----a-w- C:\Windows\System32\aticaldd64.dll 2012-06-11 16:43:18 4729344 ----a-w- C:\Windows\SysWow64\atiumdva.dll 2012-06-11 16:40:58 13277696 ----a-w- C:\Windows\SysWow64\aticaldd.dll 2012-06-11 16:36:56 6605824 ----a-w- C:\Windows\System32\atiumd64.dll 2012-06-11 16:27:02 539136 ----a-w- C:\Windows\System32\atiadlxx.dll 2012-06-11 16:26:52 368640 ----a-w- C:\Windows\SysWow64\atiadlxy.dll 2012-06-11 16:26:40 17920 ----a-w- C:\Windows\System32\atig6pxx.dll 2012-06-11 16:26:36 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll 2012-06-11 16:26:36 14848 ----a-w- C:\Windows\System32\atiglpxx.dll 2012-06-11 16:26:30 41984 ----a-w- C:\Windows\System32\atig6txx.dll 2012-06-11 16:26:22 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll 2012-06-11 16:26:14 367616 ----a-w- C:\Windows\System32\drivers\atikmpag.sys 2012-06-11 16:25:20 54784 ----a-w- C:\Windows\System32\atiuxp64.dll 2012-06-11 16:25:12 42496 ----a-w- C:\Windows\SysWow64\atiuxpag.dll 2012-06-11 16:25:06 45056 ----a-w- C:\Windows\System32\atiu9p64.dll 2012-06-11 16:24:58 32768 ----a-w- C:\Windows\SysWow64\atiu9pag.dll 2012-06-11 16:24:24 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll 2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\atimpc64.dll 2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\amdpcom64.dll 2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll 2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll 2012-06-11 11:50:46 187392 ----a-w- C:\Windows\System32\clinfo.exe 2012-06-11 11:50:30 75264 ----a-w- C:\Windows\System32\OpenVideo64.dll 2012-06-11 11:50:24 65024 ----a-w- C:\Windows\SysWow64\OpenVideo.dll 2012-06-11 11:50:18 63488 ----a-w- C:\Windows\System32\OVDecode64.dll 2012-06-11 11:50:14 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll 2012-06-11 11:50:06 16457728 ----a-w- C:\Windows\System32\amdocl64.dll 2012-06-11 11:49:22 13008896 ----a-w- C:\Windows\SysWow64\amdocl.dll 2012-06-06 06:49:52 1070152 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll 2012-06-02 13:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 13:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe 2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-31 10:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe . ============= FINISH: 22:36:50,50 ===============
Link naar reactie
Je gebruikt Eset internetsecurity, dus controleer nu eerst of de Windows Firewall nog aktief is. Controleer dat; daarvoor ga je naar Start\Uitvoeren en de opdracht luidt: [b:be6e6fc95f]services.msc[/b:be6e6fc95f]. Klik op de knop OK. N.B.: Uitvoeren kan ook gestart worden door gelijktijdig de "Windowstoets + R-toets" in te drukken. In het venster Services scroll je naar [b:be6e6fc95f][color=#0000FF:be6e6fc95f]Windows Firewall[/color:be6e6fc95f][/b:be6e6fc95f]. Dubbelklikk op die vermelding, bij "Opstarttype" zet je de instelling op "Gedeaktiveerd". Klik nu eerst op de knop [b:be6e6fc95f]Toepassen[/b:be6e6fc95f]; vervolgens klik je op de knop [b:be6e6fc95f]Stoppen[/b:be6e6fc95f], wacht even en klik uiteindelijk op [b:be6e6fc95f]OK[/b:be6e6fc95f]. [b:be6e6fc95f]Welk programma[/b:be6e6fc95f]: [color=#008000:be6e6fc95f][b:be6e6fc95f]ComboFix[/b:be6e6fc95f][/color:be6e6fc95f] [b:be6e6fc95f]Waarvoor/waarom[/b:be6e6fc95f]: Zeer specialistische scanner om Windows diepgaand te onderzoeken en op te schonen. [b:be6e6fc95f]Moeilijkheidsgraad[/b:be6e6fc95f]: Min of meer lastige voorbereidingsfase, dus lees alles eerst goed. [b:be6e6fc95f]Downloadlokatie[/b:be6e6fc95f]: Dit programma absoluut naar het bureaublad downloaden! [b:be6e6fc95f]Download ComboFix via één van deze locaties[/b:be6e6fc95f]: [list:be6e6fc95f][*:be6e6fc95f][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][b:be6e6fc95f]Bleepingcomputer[/b:be6e6fc95f][/url] [*:be6e6fc95f][url=http://www.forospyware.com/sUBs/ComboFix.exe][b:be6e6fc95f]ForoSpyware[/b:be6e6fc95f][/url] [*:be6e6fc95f][url=http://subs.geekstogo.com/ComboFix.exe][b:be6e6fc95f]Geekstogo[/b:be6e6fc95f][/url][/list:u:be6e6fc95f] [url=http://www.bleepingcomputer.com/combofix/nl/hoe-dient-combofix-gebruikt-te-worden][b:be6e6fc95f][color=#0000FF:be6e6fc95f]Hier[/color:be6e6fc95f][/b:be6e6fc95f][/url] zie je hoe je ComboFix moet gebruiken. Antivirusprogramma en actieve malwarescanners dienen al voor je ComboFix start gedeaktiveert zijn! [url=http://www.hijackthis.nl/forum/viewtopic.php?f=86&t=32608][b:be6e6fc95f][color=#0000FF:be6e6fc95f]Hier[/color:be6e6fc95f][/b:be6e6fc95f][/url] en [url=http://www.hijackthis.nl/forum/viewtopic.php?f=86&t=32607][b:be6e6fc95f][color=#0000FF:be6e6fc95f]hier[/color:be6e6fc95f][/b:be6e6fc95f][/url] vindt je gegevens hoe antivirusprogramma's en spywarescanners te deaktiveren. [b:be6e6fc95f]Opmerkingen[/b:be6e6fc95f]: [list:be6e6fc95f][*:be6e6fc95f] Bij gebruik van Windows XP zal er mogelijk gevraagd worden, om de "Recovery Console" te installeren! Sta dit dan toe (hiervoor is een actieve internet verbinding vereist). [*:be6e6fc95f]Alle openstaande programma's en webpagina's dienen afgesloten te zijn. [*:be6e6fc95f]Indien ComboFix een melding geeft over Zero-acces, meld dat vervolgens erbij in je nieuwe bericht.[/list:u:be6e6fc95f] [b:be6e6fc95f]ComboFix opstarten[/b:be6e6fc95f]: [list:be6e6fc95f][*:be6e6fc95f][b:be6e6fc95f][color=#0000FF:be6e6fc95f]Windows 2000[/color:be6e6fc95f][/b:be6e6fc95f] en [color=#0000FF:be6e6fc95f][b:be6e6fc95f]Windows XP[/b:be6e6fc95f][/color:be6e6fc95f]: dubbelklik op ComboFix.exe. [*:be6e6fc95f][color=#0000FF:be6e6fc95f][b:be6e6fc95f]Windows Vista[/b:be6e6fc95f][/color:be6e6fc95f] en [color=#0000FF:be6e6fc95f][b:be6e6fc95f]Windows 7[/b:be6e6fc95f][/color:be6e6fc95f]: via rechtsklik op ComboFix.exe en kies voor "Als Administrator uitvoeren".[/list:u:be6e6fc95f] [b:be6e6fc95f]ComboFix is opgestart[/b:be6e6fc95f]: [list:be6e6fc95f][*:be6e6fc95f]Niet in het zwarte venster klikken, hierdoor kan ComboFix of zelfs Windows geheel "bevriezen"! [*:be6e6fc95f]Combofix sluit tijdens de scan de internet verbinding – probeer deze tussentijds niet te herstellen! [*:be6e6fc95f]Het kan voorkomen dat de computer meerdere malen opnieuw opgestart moet worden, dit is normaal. [*:be6e6fc95f]Wanneer ComboFix gereed is, zal het het een logbestand voor je maken. [*:be6e6fc95f]Post de inhoud van dit logbestand in je volgende bericht. [*:be6e6fc95f]Indien het log niet opstart, is dit terug tevinden in C:\ComboFix.txt[/list:u:be6e6fc95f] [b:be6e6fc95f]Belangrijke opmerking[/b:be6e6fc95f]: [list:be6e6fc95f][*:be6e6fc95f][b:be6e6fc95f][color=#0000FF:be6e6fc95f]Indien na de scan bij het opstarten van programma's er een error wordt getoond met de melding:[/color:be6e6fc95f][/b:be6e6fc95f] [*:be6e6fc95f][b:be6e6fc95f][color=#FF0000:be6e6fc95f]Er is geprobeerd een ongeldige bewerking uit te voeren op een registersleutel die is gemarkeerd voor verwijdering.[/color:be6e6fc95f][/b:be6e6fc95f] [*:be6e6fc95f][b:be6e6fc95f][color=#008000:be6e6fc95f]Start dan de computer opnieuw op.[/color:be6e6fc95f][/b:be6e6fc95f][/list:u:be6e6fc95f]
Link naar reactie
ComboFix 12-08-18.03 - John 19-08-2012 23:12:18.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4091.2336 [GMT 2:00] Gestart vanuit: c:\users\John\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\John\AppData\Roaming\inst.exe c:\windows\IsUn0413.exe c:\windows\pkunzip.pif c:\windows\pkzip.pif c:\windows\SysWow64\URTTemp c:\windows\SysWow64\URTTemp\regtlib.exe . . (((((((((((((((((((( Bestanden Gemaakt van 2012-07-19 to 2012-08-19 )))))))))))))))))))))))))))))) . . 2012-08-17 21:01 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B65155D5-4855-44CA-8476-27F33B693849}\mpengine.dll 2012-08-15 21:54 . 2012-08-15 21:54 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2012-07-27 20:51 . 2012-07-27 20:51 184248 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-18 22:00 . 2012-03-29 07:50 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-18 22:00 . 2011-06-01 13:15 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 21:51 . 2010-05-26 12:52 62134624 ----a-w- c:\windows\system32\MRT.exe 2012-07-03 11:46 . 2010-10-30 21:51 24904 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-06-12 16:24 . 2009-07-13 23:49 123904 ----a-w- c:\windows\system32\bcrypt.dll 2012-06-12 03:08 . 2012-07-10 22:32 3148800 ----a-w- c:\windows\system32\win32k.sys 2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll 2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll 2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll 2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe 2012-06-11 17:24 . 2012-06-11 17:24 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll 2012-06-11 17:23 . 2011-03-09 04:55 1090560 ----a-w- c:\windows\system32\aticfx64.dll 2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll 2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe 2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe 2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll 2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll 2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll 2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll 2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll 2012-06-11 17:01 . 2009-09-19 02:04 6914560 ----a-w- c:\windows\system32\atidxx64.dll 2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll 2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll 2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll 2012-06-11 16:45 . 2012-06-11 16:45 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll 2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll 2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll 2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll 2012-06-11 16:43 . 2012-06-11 16:43 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll 2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll 2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll 2012-06-11 16:27 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll 2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll 2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll 2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll 2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll 2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll 2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2012-06-11 16:25 . 2011-03-09 04:17 54784 ----a-w- c:\windows\system32\atiuxp64.dll 2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll 2012-06-11 16:24 . 2012-06-11 16:24 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll 2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll 2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll 2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll 2012-06-11 11:50 . 2012-06-11 11:50 187392 ----a-w- c:\windows\system32\clinfo.exe 2012-06-11 11:50 . 2012-06-11 11:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll 2012-06-11 11:50 . 2012-06-11 11:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll 2012-06-11 11:50 . 2012-06-11 11:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll 2012-06-11 11:50 . 2012-06-11 11:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll 2012-06-11 11:50 . 2012-06-11 11:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll 2012-06-11 11:49 . 2012-06-11 11:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll 2012-06-09 05:43 . 2012-07-10 20:31 14172672 ----a-w- c:\windows\system32\shell32.dll 2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06 . 2012-07-10 20:31 2004480 ----a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-10 20:31 1881600 ----a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-10 20:31 1133568 ----a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-10 20:31 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-10 20:31 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-10 20:31 805376 ----a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-19 16:19 38424 ----a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-19 16:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-19 16:19 57880 ----a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-19 16:19 44056 ----a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-19 16:19 701976 ----a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-19 16:19 2622464 ----a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-19 16:19 99840 ----a-w- c:\windows\system32\wudriver.dll 2012-06-02 13:19 . 2012-06-19 16:19 186752 ----a-w- c:\windows\system32\wuwebv.dll 2012-06-02 13:15 . 2012-06-19 16:19 36864 ----a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-10 20:31 458704 ----a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-10 20:31 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:48 . 2012-07-10 20:31 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:45 . 2012-07-10 20:31 340992 ----a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-10 20:31 307200 ----a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-10 20:31 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-10 20:31 225280 ----a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-10 20:31 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-10 20:31 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 10:25 . 2010-06-01 20:41 279656 ------w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-09-04 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe "iTunesHelper"="e:\downloads\muziek\itunes\iTunesHelper.exe" "Adobe Photo Downloader"="d:\foto's\progs\apdproxy.exe" "AppleSyncNotifier"=c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "NBKeyScan"="c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 CyberMania;CyberMania;c:\program files\ESET\ServiceEx.exe run [x] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 136176] R3 gupdatem;Google Update-service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 136176] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-26 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-05-26 52856] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-26 834544] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 146432] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616] S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-08-09 974944] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2011-08-04 137144] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336] S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2009-08-06 65536] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe [2009-12-10 1394504] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760] S3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 202576] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2010-11-02 82816] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-04-13 45432] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys [2009-10-14 11856] . . --- Andere Services/Drivers In Geheugen --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Inhoud van de 'Gedeelde Taken' map . 2012-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 10:02] . 2012-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 10:02] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 ----a-w- c:\users\John\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-01-27 1612880] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-08-09 4030008] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Bijkomende Scan ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com IE: Download with x-ipad-magic-platinum - c:\program files (x86)\Xilisoft\iPad Magic Platinum\upod_link.HTM TCP: DhcpNameServer = 213.46.228.196 62.179.104.196 DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab . - - - - ORPHANS VERWIJDERD - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE . . . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-2194303437-3576856376-202698016-1000\Software\SecuROM\License information*] "datasecu"=hex:a3,f1,2b,ac,c5,0c,ef,3d,e5,36,fb,a2,a9,aa,35,8e,a6,7d,e5,2d,d4, 82,50,d3,50,fe,87,95,62,bb,e0,5c,5d,ca,76,03,ee,0a,b3,02,88,15,40,b2,2b,1e,\ "rkeysecu"=hex:15,da,ed,c4,7f,3c,28,2a,44,3f,62,f0,d7,20,34,5b . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info] @Denied: (2) (LocalSystem) @SACL= "packagetag"=dword:6090e758 "AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\" "DataDir"="ESET\\ESET NOD32 Antivirus\\" "EditionName"=" " "InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\" "LanguageId"=dword:00000413 "ProductBase"=dword:00000000 "ProductCode"="{B4BC9421-3578-4447-A40D-993EDA32E1D3}" "ProductName"="ESET NOD32 Antivirus" "ProductType"="eav" "ProductVersion"="4.2.64.12" "UniqueId"="00106EF84D88D8ED" "ScannerBuild"=dword:00001dd3 "ScannerVersionId"=dword:000014f0 "ScannerVersion"="Locked/open ESET for status." "ei2"=hex(b):ba,83,93,8a,b5,5a,d6,67 "ei1"=hex(b):6c,f0,49,7a,4c,27,00,00 "ei3"=hex(b):bf,41,88,4e,00,00,00,00 "ei4"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Andere Aktieve Processen ------------------------ . d:\foto's\progs\PhotoshopElementsFileAgent.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\SysWOW64\astsrv.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe . ************************************************************************** . Voltooingstijd: 2012-08-19 23:24:15 - machine werd herstart ComboFix-quarantined-files.txt 2012-08-19 21:24 . Pre-Run: 45.973.151.744 bytes beschikbaar Post-Run: 45.756.153.856 bytes beschikbaar . - - End Of File - - 3290DEC341D6BE68926D3E8B6946DD46
Link naar reactie
Controleer dan het volgende ook: of onderstaande diensten op de juiste wijze zijn ingesteld: - Background Intelligent Transfer Server > Opstarttype=Automatisch - DCOM Process Server Launcher > Opstarttype=Automatisch - Remote Procedure Call (RPC) > Opstarttype=Automatisch - RPC Endpoint Mapper > Opstarttype=Automatisch - Windows Update > Opstarttype=Automatisch Indien je niet weet hoe in Services te geraken: [list:5955178d17][*:5955178d17] ga daarvoor naar Start - Uitvoeren: [*:5955178d17] kopieer en plak hierin het volgende: [b:5955178d17]services.msc[/b:5955178d17] [*:5955178d17] klik daarna op [b:5955178d17]OK[/b:5955178d17]. [list:5955178d17][*:5955178d17]Uitvoeren kan ook gestart worden door gelijktijdig de "Windowstoets + R-toets" in te drukken.[/list:u:5955178d17][/list:u:5955178d17]
Link naar reactie

Om een reactie te plaatsen, moet je eerst inloggen

Gast
Reageer op dit topic

×   Geplakt als verrijkte tekst.   Herstel opmaak

  Er zijn maximaal 75 emoji toegestaan.

×   Je link werd automatisch ingevoegd.   Tonen als normale link

×   Je vorige inhoud werd hersteld.   Leeg de tekstverwerker

×   Je kunt afbeeldingen niet direct plakken. Upload of voeg afbeeldingen vanaf een URL in

×
×
  • Nieuwe aanmaken...