Op deze website gebruiken we cookies om content en advertenties te personaliseren, om functies voor social media te bieden en om ons websiteverkeer te analyseren. Ook delen we informatie over uw gebruik van onze site met onze partners voor social media, adverteren en analyse. Deze partners kunnen deze gegevens combineren met andere informatie die u aan ze heeft verstrekt of die ze hebben verzameld op basis van uw gebruik van hun services. Meer informatie.

Akkoord

Vraag & Antwoord

Beveiliging & privacy

'bibliotheken' zichtbaar maken

None
8 antwoorden
  • Hallo!
    Ik heb kortgeleden een virus gehad op mijn computer. Mijn antivirus en spyware programma's hebben het inmiddels wel verwijderd. Al mijn bestanden waren onzichtbaar gemaakt. Alle gebruikersaccounts zijn inmiddels weer zichtbaar, alleen bij het hoofdaccount zijn de 'bibliotheken' onzichtbaar, hetgeen eronder zit heb ik wel weer zichtbaar gemaakt.

    Nu is mijn vraag, hoe krijg ik de bibliotheken weer zichtbaar onder het hoofdaccount ? Rechtermuisknop>eigenschappen daar staat niets onder namelijk. Ik heb windows 7 32 bit.

    Alvast bedankt!
    mvg,
    Webbie
  • Doe nu eerst maar de volgende twee opdrachten:

    [b:6190cf130d]Stap •1•[/b:6190cf130d][/color:6190cf130d]
    [b:6190cf130d]Welk programma[/b:6190cf130d]: Trend Micro [b:6190cf130d]Hijack This Versie 2.0.4[/b:6190cf130d]
    [b:6190cf130d]Waarvoor/waarom[/b:6190cf130d]: maakt een duidelijk overzicht van Windows door middel van een scan.
    [b:6190cf130d]Moeilijkheidsgraad[/b:6190cf130d]: geen, enkel Vista- en Win 7 gebruikers dienen even extra aandacht te geven.

    [b:6190cf130d]Download[/b:6190cf130d] de [b:6190cf130d]HijackThis Installer[/b:6190cf130d]

    [b:6190cf130d]Installatie[/b:6190cf130d]:
    [list:6190cf130d][*:6190cf130d]Installeer HijackThis op de aangegeven lokatie - daarmee wordt voorkomen dat eventuele back-ups niet terugvindbaar zijn![/list:u:6190cf130d]
    Gebruikers van [b:6190cf130d]Windows Vista[/b:6190cf130d] en [b:6190cf130d]Windows 7[/b:6190cf130d] gaan daarna naar de installatielokatie van HijackThis.
    [list:6190cf130d][*:6190cf130d]Vervolgens met rechts hijackthis.exe aanklikken en dan Eigenschappen kiezen.
    [*:6190cf130d]Klik nu op de tab Comptabiliteit en zet dan een vinkje bij Als Administrator uitvoeren.
    [*:6190cf130d]Als laatste wordt dan nog op [b:6190cf130d]Toepassen[/b:6190cf130d] en [b:6190cf130d]OK[/b:6190cf130d] geklikt[/list:u:6190cf130d]
    [b:6190cf130d]Hijack This gebruiken[/b:6190cf130d]:
    [list:6190cf130d][*:6190cf130d]Sluit eerst alle openstaande programma's en de webbrowsers.
    [*:6190cf130d]Start nu 'Hijack This' en klik vervolgens op de knop 'Do a system scan and save a logfile'
    [*:6190cf130d]Sluit nu alle openstaande vensters en start vervolgens 'HijackThis' en kies voor 'Do a system scan and save a logfile'.
    [*:6190cf130d]Kopieer en plak inhoud van het Hijack This-logfile in je aansluitende bericht.
    [*:6190cf130d]Hierna mag je Hijack This weer sluiten[/list:u:6190cf130d]
    [b:6190cf130d]Stap •2•[/b:6190cf130d][/color:6190cf130d]
    [b:6190cf130d]Welk programma[/b:6190cf130d]: Malwarebytes MBAM
    [b:6190cf130d]Waarvoor/waarom[/b:6190cf130d]: specialistische scanner om Windows snel te onderzoeken op- en te ontdoen van spy- & malware.
    [b:6190cf130d]Moeilijkheidsgraad[/b:6190cf130d]: geen.

    [b:6190cf130d]Download Malwarebytes MBAM via één van deze locaties[/b:6190cf130d]:
    [list:6190cf130d] [*:6190cf130d][b:6190cf130d]Download.com[/b:6190cf130d]
    [*:6190cf130d][b:6190cf130d]Softpedia.com[/b:6190cf130d][*:6190cf130d][b:6190cf130d]Majorgeeks.com[/b:6190cf130d][/list:u:6190cf130d]
    [b:6190cf130d]Allereerst[/b:6190cf130d]:[list:6190cf130d][*:6190cf130d] Al meteen na de installatie wil 'MBAM' zijn database opwaarderen – toestaan dus.
    [*:6190cf130d] Ook bij herhaald gebruik: eerst 'MBAM' updaten via de tab 'Update'![/list:u:6190cf130d]
    [b:6190cf130d]Malwarebytes MBAM opstarten[/b:6190cf130d]:
    Windows 2000 en Windows XP: start MBAM middels dubbelklik op de snelkoppeling.
    Windows Vista en Windows 7: start MBAM middels rechtsklik op de snelkoppeling en dan kiezen voor Als Administrator uitvoeren.

    [b:6190cf130d]Scannen[/b:6190cf130d]:
    [list:6190cf130d][*:6190cf130d] Bij het starten van 'MBAM' kies je voor 'Snelle Scan'.
    [*:6190cf130d]Het scannen kan een tijdje duren, dus wees geduldig. Indien de scan voltooid is, klik dan op de knop 'OK'.
    [*:6190cf130d]Klik daarna op de knop 'Bekijk Resultaten' om de resultaten te zien.[/list:u:6190cf130d]
    [b:6190cf130d]Infecties gevonden[/b:6190cf130d]:
    [list:6190cf130d][*:6190cf130d]Klik nu eerst op OK om de melding weg te klikken
    [*:6190cf130d]Klik vervolgens rechtsonder op de knop Bekijk resultaten.
    [*:6190cf130d]Zorg er nu voor dat alle gevonden infecties aangevinkt zijn, en klik linksonder op Verwijder geselecteerde.
    [*:6190cf130d]Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten.
    [*:6190cf130d]Indien 'MBAM' moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven – dan telkens op 'OK' klikken!
    [*:6190cf130d]Daarna zal 'MBAM' vragen om de Computer opnieuw op te starten - dus sta toe dat de computer opnieuw opgestart wordt.[/list:u:6190cf130d]
    [b:6190cf130d]MBAM-Log[/b:6190cf130d]:
    [list:6190cf130d][*:6190cf130d] Het log wordt automatisch bewaard door 'MBAM en dat kan je terugvinden door in het hoofdmenu van MBAM op de tab 'Logbestanden' te klikken'.[/list:u:6190cf130d]
    [b:6190cf130d]Als laatste dan Stap •3•[/b:6190cf130d][/color:6190cf130d]
    [b:6190cf130d]Samenvattend: hierna post jij in je nieuwe bericht de inhoud van de volgende logs:[/b:6190cf130d]
    [list:6190cf130d][*:6190cf130d] een nieuw Hijackthis-log
    [*:6190cf130d] MBAM scanlog[/list:u:6190cf130d]
  • Eerste keer vond MBAM 7 geïnfecteerde bestanden. Nadat deze verwijderd waren of in quarantaine geplaatst heb ik beide programma's opnieuw gestart. De logs hiervan staan hieronder. De 4 mappen (afbeeldingen, documenten, muziek en video's) in de bibliotheek zijn nog steeds doorzichtig, alle submappen zijn nogsteeds zichtbaar daarbinnen. Hopelijk kan iemand met deze informatie iets?


    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 16:28:08, on 14-4-2011
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16421)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ubvu.vu.nl/ubvu.pac
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
    O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
    uncleanupscript
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Robbert_2\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
    O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
    O9 - Extra button: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - (no file)
    O9 - Extra 'Tools' menuitem: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - (no file)
    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
    O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: Encarta Winkler Prins Zoekbalk - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
    O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
    O9 - Extra button: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - (no file) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.cn/download/SOPCORE.CAB
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
    O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32
    vvsvc.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision
    vSCPAPISvr.exe


    End of file - 11696 bytes




    —————————————————————————-
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Databaseversie: 6360

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 9.0.8112.16421

    14-4-2011 16:25:00
    mbam-log-2011-04-14 (16-25-00).txt

    Scantype: Snelle scan
    Objecten gescand: 229370
    Verstreken tijd: 6 minuut/minuten, 13 seconde(n)

    Geheugenprocessen geïnfecteerd: 0
    Geheugenmodulen geïnfecteerd: 0
    Registersleutels geïnfecteerd: 0
    Registerwaarden geïnfecteerd: 0
    Registerdata geïnfecteerd: 0
    Mappen geïnfecteerd: 0
    Bestanden geïnfecteerd: 0

    Geheugenprocessen geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden geïnfecteerd:
    (Geen kwaadaardige objecten gedetecteerd)
  • Hoi webbie, indien PCTools Spywaredoctor shareware is - dan deïnstalleren.

    En dan mag je het volgende doen:

    [b:1f4692e4f1]Welk programma[/b:1f4692e4f1]: ComboFix
    [b:1f4692e4f1]Waarvoor/waarom[/b:1f4692e4f1]: Zeer specialistische scanner om Windows diepgaand te onderzoeken
    en zo mogelijk op te schonen.
    [b:1f4692e4f1]Moeilijkheidsgraad[/b:1f4692e4f1]: Min of meer lastige voorbereidingsfase, dus lees alles eerst goed.
    [b:1f4692e4f1]Downloadlokatie[/b:1f4692e4f1]: Dit programma absoluut naar het bureaublad downloaden!
    [b:1f4692e4f1]Download ComboFix via één van deze locaties[/b:1f4692e4f1]:
    [list:1f4692e4f1][*:1f4692e4f1][b:1f4692e4f1]Bleepingcomputer[/b:1f4692e4f1]
    [*:1f4692e4f1][b:1f4692e4f1]ForoSpyware[/b:1f4692e4f1]
    [*:1f4692e4f1][b:1f4692e4f1]Geekstogo[/b:1f4692e4f1][/list:u:1f4692e4f1]
    [b:1f4692e4f1]Hier[/b:1f4692e4f1] zie je hoe je ComboFix moet gebruiken.

    Antivirusprogramma en actieve malwarescanners dienen al voor de ComboFix start gedeaktiveert zijn!
    [b:1f4692e4f1]Hier[/b:1f4692e4f1] en [b:1f4692e4f1]hier[/b:1f4692e4f1] vindt je gegevens hoe antivirusprogramma's en spywarescanners te deaktiveren.

    [b:1f4692e4f1]Voor alle duidelijkheid nogmaals[/b:1f4692e4f1]: ComboFix dient vanaf het bureaublad gestart te worden.

    [b:1f4692e4f1]Opmerkingen[/b:1f4692e4f1]:
    [list:1f4692e4f1][*:1f4692e4f1] Bij gebruik van Windows XP zal er mogelijk gevraagd worden, om de "Recovery Console" te installeren! Sta dit dan toe (hiervoor is een actieve internet verbinding vereist).
    [*:1f4692e4f1]Vista- en Windows 7 gebruikers starten Combofix op via rechtsklik met Administratorrechten.
    [*:1f4692e4f1]Alle openstaande programma's en webpagina's dienen afgesloten te zijn.[/list:u:1f4692e4f1]
    [b:1f4692e4f1]ComboFix is opgestart[/b:1f4692e4f1]:
    [list:1f4692e4f1][*:1f4692e4f1]Niet in het zwarte venster klikken, hierdoor kan ComboFix of zelfs Windows geheel "bevriezen"!
    [*:1f4692e4f1]Combofix sluit tijdens de scan de internet verbinding – probeer deze tussentijds niet te herstellen!
    [*:1f4692e4f1]Het kan voorkomen dat de computer meerdere malen opnieuw opgestart moet worden, dit is normaal.
    [*:1f4692e4f1]Wanneer ComboFix gereed is, zal het het een logbestand voor je maken.
    [*:1f4692e4f1]Post de inhoud van dit logbestand in je volgende bericht.
    [*:1f4692e4f1]Indien het log niet opstart, is dit terug tevinden in C:\ComboFix.txt[/list:u:1f4692e4f1]
    [b:1f4692e4f1]Belangrijke opmerking[/b:1f4692e4f1]:
    [list:1f4692e4f1][*:1f4692e4f1][b:1f4692e4f1]Indien na de scan bij het opstarten van programma's er een error wordt getoond met de melding:[/color:1f4692e4f1][/b:1f4692e4f1]
    [*:1f4692e4f1][b:1f4692e4f1]Illegal operation attempted on a registery key that has been marked for deletion.[/color:1f4692e4f1][/b:1f4692e4f1]
    [*:1f4692e4f1][b:1f4692e4f1]Start dan de computer opnieuw op.[/color:1f4692e4f1][/b:1f4692e4f1][/list:u:1f4692e4f1]
  • Hoi!
    Alle mappen zijn weer zichtbaar:) Ik had alleen na de scan wel een zwart bureaublad achtergrond maar dat zal denk ik wel goed zijn, heb hem nl kunnen veranderen. Dit was de log van combofix:
    Bedankt voor de hulp!

    Webbie

    —————————————————————————
    ComboFix 11-04-14.03 - Webbie_2 15-04-2011 20:24:16.1.4 - x86
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.31.1043.18.3071.1771 [GMT 2:00]
    Gestart vanuit: c:\users\Webbie_2\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    AV: Lavasoft Ad-Watch Live! Antivirus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
    SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Tim.PC_webbie\AppData\Roaming\print32.exe
    c:\users\Webbie_2\AppData\Roaming\Adobe\plugs
    c:\users\Webbie_2\AppData\Roaming\Adobe\shed
    c:\users\Webbie\AppData\Roaming\print32.exe
    c:\webupdater\WebUpdater.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ——-\Legacy_RKHIT
    ——-\Service_RkHit
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2011-03-15 to 2011-04-15 ))))))))))))))))))))))))))))))
    .
    .
    2011-04-15 18:39 . 2011-04-15 18:39 ——– d—–w- c:\users\Tim\AppData\Local\temp
    2011-04-15 18:39 . 2011-04-15 18:44 ——– d—–w- c:\users\Webbie_2\AppData\Local\temp
    2011-04-15 18:39 . 2011-04-15 18:39 ——– d—–w- c:\users\Webbie\AppData\Local\temp
    2011-04-15 18:39 . 2011-04-15 18:39 ——– d—–w- c:\users\Default\AppData\Local\temp
    2011-04-15 07:46 . 2011-04-15 07:46 ——– d—–w- c:\users\Webbie_2\AppData\Local\{E5713EAC-E21A-4E75-B4E6-068870B042F5}
    2011-04-14 19:09 . 2011-04-14 19:10 ——– d—–w- c:\users\Webbie_2\AppData\Local\{185EB551-4D8F-45E6-BA89-945EA1523274}
    2011-04-14 14:43 . 2011-04-14 14:43 ——– d—–w- c:\users\Webbie\AppData\Local\{038F7A93-8FAF-49BA-BBF3-570E69654499}
    2011-04-14 14:43 . 2011-04-14 14:43 ——– d—–w- c:\users\Webbie\AppData\Roaming\Malwarebytes
    2011-04-14 06:56 . 2011-04-14 06:56 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{9C2F6BF8-6762-4EDA-965A-D912F81316F2}
    2011-04-13 14:22 . 2011-04-13 14:22 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{204A2EC6-5A4C-4622-9D2F-D929895F1F0C}
    2011-04-13 08:58 . 2011-03-03 03:42 2333184 —-a-w- c:\windows\system32\win32k.sys
    2011-04-13 08:58 . 2011-02-23 04:48 311808 —-a-w- c:\windows\system32\drivers\srv.sys
    2011-04-13 08:58 . 2011-02-23 04:48 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
    2011-04-13 08:58 . 2011-02-23 04:47 114176 —-a-w- c:\windows\system32\drivers\srvnet.sys
    2011-04-13 08:58 . 2011-03-11 05:33 1164288 —-a-w- c:\windows\system32\mfc42u.dll
    2011-04-13 08:58 . 2011-03-11 05:33 1137664 —-a-w- c:\windows\system32\mfc42.dll
    2011-04-13 08:58 . 2011-02-12 05:35 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
    2011-04-13 08:57 . 2011-02-24 05:38 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-04-13 08:57 . 2011-03-03 05:38 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
    2011-04-13 08:57 . 2011-03-03 05:36 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
    2011-04-13 08:57 . 2011-02-19 06:30 34304 —-a-w- c:\windows\system32\atmlib.dll
    2011-04-13 08:57 . 2011-02-19 04:34 294912 —-a-w- c:\windows\system32\atmfd.dll
    2011-04-13 08:57 . 2011-03-08 05:28 741376 —-a-w- c:\windows\system32\inetcomm.dll
    2011-04-13 08:57 . 2011-02-23 04:47 223232 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-04-13 08:57 . 2011-02-23 04:47 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2011-04-13 08:57 . 2011-02-23 04:47 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-04-13 08:57 . 2011-02-23 04:47 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
    2011-04-13 08:48 . 2011-04-13 08:48 ——– d—–w- c:\users\Webbie\AppData\Roaming\CoffeeCup Software
    2011-04-13 08:27 . 2011-04-13 08:27 ——– d—–w- c:\users\Webbie\AppData\Local\{7279B7F1-9212-4B47-83F3-3EBD6D2186CF}
    2011-04-12 10:58 . 2011-04-12 10:59 ——– d—–w- c:\users\Webbie\AppData\Local\{E489D66C-AF43-4C5F-B001-4E8F7317DA72}
    2011-04-12 09:17 . 2011-04-14 07:26 ——– d–h–w- c:\users\Webbie_2\AppData\Roaming\Xywoiw
    2011-04-12 08:02 . 2011-04-12 08:03 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{3211C92F-6B5F-48FB-817F-85F895F2DD99}
    2011-04-11 09:19 . 2011-04-11 09:19 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{97A992F7-E1A5-45DE-8F98-9EC40F815C2A}
    2011-04-11 07:55 . 2011-04-11 07:56 ——– d—–w- c:\users\Webbie\AppData\Local\{008C9C0E-4015-4CC3-B3DC-74BFA7F7E611}
    2011-04-10 10:48 . 2011-04-10 10:48 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{EF5E0CFA-CAE3-4F8E-A96F-35A6ABC5A766}
    2011-04-10 08:51 . 2011-04-10 08:51 ——– d—–w- c:\users\Webbie\AppData\Local\{A2D58998-0953-490E-89D4-2C646C3D6D5D}
    2011-04-09 14:54 . 2011-04-09 14:54 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{A1FEBE0A-D7FB-4731-9415-E2D7EAE3DF33}
    2011-04-08 07:13 . 2011-04-08 07:14 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{CD63CF4F-00E6-4598-B2FD-DF8C712495EE}
    2011-04-07 14:14 . 2011-04-07 14:25 ——– d–h–w- c:\users\Webbie_2\AppData\Roaming\SWiSH Max4
    2011-04-07 09:11 . 2011-04-07 09:11 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{3DC4DC57-DE4E-4BB0-9E6E-636582524127}
    2011-04-07 07:49 . 2011-04-07 07:49 ——– d—–w- c:\users\Webbie\AppData\Local\{F4BA5B1D-F1CA-4C07-8079-4F45750B95A4}
    2011-04-06 15:38 . 2011-04-06 15:38 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{2B75CD70-A183-4B95-B088-40E71F8F94AD}
    2011-04-06 08:24 . 2011-04-06 08:25 ——– d—–w- c:\users\Webbie\AppData\Local\{6F611C47-5533-47CC-A4D9-02687DC00BC3}
    2011-04-05 16:03 . 2011-04-05 16:03 ——– d—–w- c:\users\Webbie\AppData\Local\{BDB0D6D1-E1E1-45FF-91AA-3A82A71C016D}
    2011-04-05 09:57 . 2011-04-05 09:57 ——– d–h–w- c:\users\Webbie_2\AppData\Roaming\Avira
    2011-04-05 08:34 . 2011-04-05 08:34 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{563F6AA4-FF44-4A22-AB15-6C3E7B220B4B}
    2011-04-04 11:46 . 2011-04-04 11:46 ——– d–h–w- c:\users\Tim\AppData\Local\{3E724AD0-87D5-4A43-A207-FFD9D7FE7C6D}
    2011-04-04 08:53 . 2011-04-04 08:54 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{1DF1D7F5-6D39-4670-BA0B-8E9DDB54210F}
    2011-04-03 08:53 . 2011-04-03 08:54 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{D8CC0C12-C2DE-411F-B1B7-18FD4C2E4F00}
    2011-04-02 13:12 . 2011-04-02 13:12 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{EC33F708-7D7F-4ED6-80B2-4238869D6441}
    2011-04-02 10:27 . 2011-04-02 10:28 ——– d–h–w- c:\users\Tim\AppData\Local\{DCC5FC7A-4861-4177-9355-FDEEC30DAC5B}
    2011-04-01 11:05 . 2011-04-01 11:05 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{E0B8028B-8DA9-4719-812F-63B735B35FC3}
    2011-04-01 09:07 . 2011-04-01 09:08 ——– d—–w- c:\users\Webbie\AppData\Local\{04D51778-E9E0-49B6-80DE-34AB5FAE0A14}
    2011-03-31 15:27 . 2011-03-31 15:27 ——– d—–w- c:\users\WebbieAppData\Local\{6662F767-1CFF-4E36-BACE-1D943AD542A6}
    2011-03-31 11:26 . 2010-03-18 00:41 1431896 ——w- c:\windows\system32\wodFtpDLX.OCX
    2011-03-31 11:26 . 2011-03-31 11:26 ——– d–h–w- c:\users\Webbie_2\AppData\Roaming\InstallShield Installation Information
    2011-03-31 09:26 . 2011-03-31 09:27 ——– d–h–w- c:\users\Webbie_2\AppData\Local\{893E270B-6675-4683-AB03-4BD3B3E5E6C6}
    2011-03-29 08:57 . 2011-03-04 14:11 137656 —-a-w- c:\windows\system32\drivers\avipbb.sys
    2011-03-29 08:57 . 2011-03-04 12:37 61960 —-a-w- c:\windows\system32\drivers\avgntflt.sys
    2011-03-29 08:57 . 2011-03-29 08:57 ——– d—–w- c:\program files\Avira
    2011-03-23 08:37 . 2009-08-19 21:50 22872 —-a-r- c:\windows\system32\AdobePDFUI.dll
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-14 19:10 . 2009-11-15 16:35 16968 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2011-03-16 09:22 . 2011-03-16 09:22 86528 —-a-w- c:\windows\system32\iesysprep.dll
    2011-03-16 09:22 . 2011-03-16 09:22 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
    2011-03-16 09:22 . 2011-03-16 09:22 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
    2011-03-16 09:22 . 2011-03-16 09:22 63488 —-a-w- c:\windows\system32\tdc.ocx
    2011-03-16 09:22 . 2011-03-16 09:22 48640 —-a-w- c:\windows\system32\mshtmler.dll
    2011-03-16 09:22 . 2011-03-16 09:22 367104 —-a-w- c:\windows\system32\html.iec
    2011-03-16 09:22 . 2011-03-16 09:22 161792 —-a-w- c:\windows\system32\msls31.dll
    2011-03-16 09:22 . 2011-03-16 09:22 1126912 —-a-w- c:\windows\system32\wininet.dll
    2011-03-16 09:22 . 2011-03-16 09:22 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
    2011-03-16 09:22 . 2011-03-16 09:22 74752 —-a-w- c:\windows\system32\iesetup.dll
    2011-03-16 09:22 . 2011-03-16 09:22 420864 —-a-w- c:\windows\system32\vbscript.dll
    2011-03-16 09:22 . 2011-03-16 09:22 35840 —-a-w- c:\windows\system32\imgutil.dll
    2011-03-16 09:22 . 2011-03-16 09:22 2382848 —-a-w- c:\windows\system32\mshtml.tlb
    2011-03-16 09:22 . 2011-03-16 09:22 23552 —-a-w- c:\windows\system32\licmgr10.dll
    2011-03-16 09:22 . 2011-03-16 09:22 1797632 —-a-w- c:\windows\system32\jscript9.dll
    2011-03-16 09:22 . 2011-03-16 09:22 152064 —-a-w- c:\windows\system32\wextract.exe
    2011-03-16 09:22 . 2011-03-16 09:22 150528 —-a-w- c:\windows\system32\iexpress.exe
    2011-03-16 09:22 . 2011-03-16 09:22 142848 —-a-w- c:\windows\system32\ieUnatt.exe
    2011-03-16 09:22 . 2011-03-16 09:22 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
    2011-03-16 09:22 . 2011-03-16 09:22 11776 —-a-w- c:\windows\system32\mshta.exe
    2011-03-16 09:22 . 2011-03-16 09:22 101888 —-a-w- c:\windows\system32\admparse.dll
    2011-03-14 13:35 . 2010-06-24 09:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-02-28 01:22 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll
    2011-02-23 06:27 . 2011-02-23 06:27 941160 —-a-w- c:\windows\system32
    vdispco322090.dll
    2011-02-23 06:27 . 2011-02-23 06:27 837736 —-a-w- c:\windows\system32
    vgenco322040.dll
    2011-02-23 06:27 . 2011-02-23 06:27 57960 —-a-w- c:\windows\system32\OpenCL.dll
    2011-02-23 06:27 . 2011-02-23 06:27 4942952 —-a-w- c:\windows\system32
    vcuda.dll
    2011-02-23 06:27 . 2011-02-23 06:27 2895976 —-a-w- c:\windows\system32
    vcuvid.dll
    2011-02-23 06:27 . 2011-02-23 06:27 2251368 —-a-w- c:\windows\system32
    vcuvenc.dll
    2011-02-23 06:27 . 2011-02-23 06:27 15047272 —-a-w- c:\windows\system32
    voglv32.dll
    2011-02-23 06:27 . 2011-02-23 06:27 13011560 —-a-w- c:\windows\system32
    vcompiler.dll
    2011-02-23 06:27 . 2011-02-23 06:27 10920 —-a-w- c:\windows\system32\drivers
    vBridge.kmd
    2011-02-23 06:27 . 2011-02-23 06:27 10468360 —-a-w- c:\windows\system32\drivers
    vlddmkm.sys
    2011-02-23 06:27 . 2011-02-23 06:27 10079336 —-a-w- c:\windows\system32
    vd3dum.dll
    2011-02-23 06:27 . 2009-08-20 10:54 5654120 —-a-w- c:\windows\system32
    vwgf2um.dll
    2011-02-23 06:27 . 2009-08-20 10:54 1965672 —-a-w- c:\windows\system32
    vapi.dll
    2011-02-19 06:30 . 2011-03-14 13:40 805376 —-a-w- c:\windows\system32\FntCache.dll
    2011-02-19 06:30 . 2011-03-14 13:40 1076736 —-a-w- c:\windows\system32\DWrite.dll
    2011-02-19 06:30 . 2011-03-14 13:40 739840 —-a-w- c:\windows\system32\d2d1.dll
    2011-02-03 05:54 . 2011-02-09 17:06 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
    2011-01-17 05:47 . 2011-02-28 00:50 161792 —-a-w- c:\windows\system32\d3d10_1.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    "Google Update"="c:\users\Webbie_2\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-01-08 135664]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
    "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-30 38840]
    "CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-18 104936]
    "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-20 149280]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\startupfolder\C:^Users^Webbie_2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
    path=c:\users\Webbie_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
    backup=c:\windows\pss\MagicDisc.lnk.Startup
    backupExtension=.Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-09-21 18:37 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
    2008-08-14 05:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
    2010-02-22 02:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
    2009-12-17 17:43 116056 —-a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Azureus]
    2010-10-20 12:48 232896 —-a-w- c:\program files\Vuze\Azureus.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
    2010-10-17 14:13 3825080 —-a-w- c:\program files\Babylon\Babylon-Pro\Babylon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
    2004-08-09 16:24 45056 —-a-w- c:\program files\Pinnacle\Studio 9\LaunchList.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    2010-11-10 00:54 4240760 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
    2010-01-16 08:54 717696 —-a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
    2004-03-10 23:26 406016 —-a-w- c:\windows\System32\PSDrvCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
    2007-02-20 10:07 199752 —-a-w- c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 135664]
    R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-07-09 8192]
    R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-04-11 1753048]
    R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-02-04 15232]
    R3 netr28u;Stuurprogramma voor RT2870 USB draadloze LAN-kaart voor Vista;c:\windows\system32\DRIVERS
    etr28u.sys [2009-07-13 657408]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
    R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-21 90112]
    R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-21 14976]
    R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-21 121856]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 VCR2PC;VCR2PC Analog Capture;c:\windows\system32\DRIVERS\0140_ION.sys [2008-09-22 281024]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 vpcuxd;Stubservice voor USB-virtualisatie;c:\windows\system32\drivers\vpcuxd.sys [2010-11-20 12800]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
    R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-07-06 64288]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-06 169312]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
    S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-03-04 135336]
    S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-12-17 238952]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision
    vSCPAPISvr.exe [2010-07-09 248936]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-12-14 36608]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers
    vhda32v.sys [2010-06-21 105576]
    .
    .
    — Andere Services/Drivers In Geheugen —
    .
    *NewlyCreated* - FSUSBEXDISK
    *Deregistered* - AFW
    *Deregistered* - afwcore
    *Deregistered* - BdFileSpy
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Akamai REG_MULTI_SZ Akamai
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2011-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 13:47]
    .
    2011-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 13:47]
    .
    2011-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2750530008-1408819090-949995116-1004Core.job
    - c:\users\Webbie_2\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-08 13:47]
    .
    2011-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2750530008-1408819090-949995116-1004UA.job
    - c:\users\Webbie_2\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-08 13:47]
    .
    2011-01-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2750530008-1408819090-949995116-1006Core.job
    - c:\users\Webbie\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-09 11:04]
    .
    2011-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2750530008-1408819090-949995116-1006UA.job
    - c:\users\Webbie\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-09 11:04]
    .
    .
    ——- Bijkomende Scan ——-
    .
    uStart Page = hxxp://www.google.nl/
    IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert link target to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
    IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
    IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
    IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    FF - ProfilePath - c:\users\Webbie_2\AppData\Roaming\Mozilla\Firefox\Profiles\mcpd52nx.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.nl
    FF - prefs.js: network.proxy.type - 2
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
    FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
    FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
    FF - Ext: Flash Video Resources Downloader: max@subfighter.com - %profile%\extensions\max@subfighter.com
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
    FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
    FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
    FF - Ext: Woordenboek Nederlands: nl-NL@dictionaries.addons.mozilla.org - %profile%\extensions
    l-NL@dictionaries.addons.mozilla.org
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    - - - - ORPHANS VERWIJDERD - - - -
    .
    SafeBoot-BsScanner
    MSConfigStartUp-0ESKOMO9JO - c:\users\Webbie~1\AppData\Local\Temp\Ygm.exe
    MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe
    MSConfigStartUp-PCTools FGuard - c:\program files\Spyware Doctor\BDT\FGuard.exe
    AddRemove-_{E1A63F75-1F72-4450-980D-434496FFC646} - c:\program files\Corel\Corel Painter Essentials 4\MSILauncher {E1A63F75-1F72-4450-980D-434496FFC646}
    AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
    AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
    AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
    AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
    AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe
    AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe
    AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
    AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe
    AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
    AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
    AddRemove-12_Symbian_USB_Download_Driver - c:\program files\SAMSUNG\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
    AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\SAMSUNG\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
    AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
    AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe
    AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
    AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe
    AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
    .
    .
    .
    ——————— VERGRENDELDE REGISTER SLEUTELS ———————
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ———————— Andere Aktieve Processen ————————
    .
    c:\windows\system32
    vvsvc.exe
    c:\windows\system32
    vvsvc.exe
    c:\program files\Avira\AntiVir Desktop\avguard.exe
    c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files\Avira\AntiVir Desktop\avshadow.exe
    c:\windows\system32\conhost.exe
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\system32\taskhost.exe
    c:\windows\system32\conhost.exe
    c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
    c:\windows\system32\DllHost.exe
    .
    **************************************************************************
    .
    Voltooingstijd: 2011-04-15 20:49:44 - machine werd herstart
    ComboFix-quarantined-files.txt 2011-04-15 18:49
    .
    Pre-Run: 303.823.253.504 bytes beschikbaar
    Post-Run: 325.395.304.448 bytes beschikbaar
    .
    - - End Of File - - F1815BD3741374DFE896F660A9549F53
  • Hoi Webbie, mooi dat je jouw mappen terug hebt!

    Hoe draait jouw Windows nu?


    En deze vraag: heb je ooit HitmanPro geïnstalleerd gehad?
  • Hoi
    windows draait weer naar behoren! :)
    Ja dat klopt, ik heb nog steeds HitmanPro geïnstalleerd staan op mijn computer.
  • Heb je HirtmanPro enkel als shareware-versie, deïnstalleer dan HitmanPro.

    Heb je het tool gekocht, deïnstalleer het tool dan ook; opnieuw installeren dan pas nadat de Fix klaar is!

    Herstart na de deïnstallatie je PC, verwijder ComboFix van jouw bureaublad en download het tool opnieuw voor wederom een scan!

Beantwoord deze vraag

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.