Op deze website gebruiken we cookies om content en advertenties te personaliseren, om functies voor social media te bieden en om ons websiteverkeer te analyseren. Ook delen we informatie over uw gebruik van onze site met onze partners voor social media, adverteren en analyse. Deze partners kunnen deze gegevens combineren met andere informatie die u aan ze heeft verstrekt of die ze hebben verzameld op basis van uw gebruik van hun services. Meer informatie.

Akkoord

Vraag & Antwoord

Beveiliging & privacy

kan een hijack log van m'n PC uitsluitsel geven ?

None
59 antwoorden
  • Rare titel, ik geef het toe. Wat is er aan de hand ? Het geluid van mijn computer valt weer eens weg.
    Zie http://forum.computertotaal.nl/phpBB2/viewtopic.php?t=217128
    Als dit het enige probleem was, had ik dit topic niet aangemaakt maar een ander fenomeen doet zich voor: laat ik mijn computer lange tijd onaangeroerd (kwartier, halfuur) krijg ik Internet explorer niet meer aan de praat. Via Ctrl, Alt Del uitschakelen en weer opstarten en alles is weer normaal. Daarnaast duurt het een eeuwigheid voor ik mijn computer kan opstarten. Ik ben dan ook benieuwd hoe dit komt. Kan iemand de hieronder staande log even bekijken ? Alvast bedankt.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 20:39:04, on 13/05/2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
    C:\WINDOWS\system32
    vsvc32.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Google\Update\1.3.21.111\GoogleCrashHandler.exe
    C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tijd.be/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe /min
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation
    view
    wiz.exe /installquiet
    O4 - HKLM\..\Run: [Driver Update and remove for Windows x64 or x86_32] C:\Program Files\Realtek\Audio\Drivers\RtlUpd.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe" -stealth
    O4 - HKUS\S-1-5-21-842925246-1592454029-1417001333-1010\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: PDF in Word openen (PDF Converter 3.0) - res://C:\Program Files\ScanSoft\PDF Professional 3.0\IEShellExt.dll /700
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
    O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/select/asusTek_sys_ctrl3.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3
    esources/MSNPUpld.cab
    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.spector.be/DesktopModules/SpectorAlbum/ImageUploader5.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224070674171
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
    O16 - DPF: {96816368-C1E3-414D-A193-63C3CC921990} (MJPEGRender Control) - http://sligachanhotel.remotemanager.co.uk/common/activex/MJPEGRender.ocx
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Acronis Scheduler2Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: Acronis Nonstop Backup-service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
    O23 - Service: Google Update Service (gupdate1c9c7b35e2a82cc) (gupdate1c9c7b35e2a82cc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\paul\LOCALS~1\Temp\hpdj.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32
    vsvc32.exe
    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe


    End of file - 10938 bytes




  • Hallo Paul, je log vertoont geen sporen va malware enz.
    Maar dat hoeft nog niks te zeggen.

    Begin met het volgende: verwijder Lavasoft AdAware.
    Dat zal jouw Windows ook blij maken.

    Daarna ga je verder met ondertaande:

  • Hallo Abraham, ik laat even weten dat de scan sinds vanmorgen wordt uitgevoerd. (ik typ dit vanop een laptop) Na zo'n 3 uur zit hij echter nog maar aan 12 %… Laten we het er maar op houden dat dit dan ook héél zorgvuldig wordt gedaan. Als het aan dit tempo doorgaat post ik de resultaten van zodra ik ze heb: morgenvroeg :wink:
  • Je hebt het over de Emisoft scan - ja die is zeer grondig!
  • Oef, eindelijk klaar. Hier is het log-bestand:

    Emsisoft Emergency Kit - Versie 1.0
    Laatste Update: 14/05/2012 9:41:36

    Scaninstellingen:

    Scantype: Diepe Scan
    Objecten: Geheugen, Sporen, Cookies, C:\, F:\
    Scan archieven: Aan
    Heuristieken: Uit
    ADS Scan: Aan

    Scan gestart: 14/05/2012 9:41:51

    c:\documents and settings\marijke\bureaublad\Morpheus Clean Disk 2002.lnk Ontdekt: Trace.File.Morpheus Clean Disc!A2
    Key: HKEY_CURRENT_USER\software\kazaa Ontdekt: Trace.Registry.KaZaA!A2
    Key: HKEY_USERS\marijke\software\microsoft\windows\currentversion\ext\stats\{c1e58a84-95b3-4630-b8c2-d06b77b7a0fc} Ontdekt: Trace.Registry.NavExcel!A2
    Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Ontdekt: Trace.Registry.Trymedia!A2
    Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Ontdekt: Trace.Registry.Trymedia!A2
    C:\Documents and Settings\paul\Cookies\paul@about[3].txt Ontdekt: Trace.TrackingCookie.about!A2
    C:\Documents and Settings\paul\Cookies\paul@angelfire[1].txt Ontdekt: Trace.TrackingCookie.angelfire!A2
    C:\Documents and Settings\paul\Cookies\paul@com[1].txt Ontdekt: Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[2].txt Ontdekt: Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[3].txt Ontdekt: Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[4].txt Ontdekt: Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[5].txt Ontdekt: Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[1].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[2].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[3].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[4].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[5].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[6].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[7].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[8].txt Ontdekt: Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ru4[2].txt Ontdekt: Trace.TrackingCookie.ru4!A2
    C:\Documents and Settings\paul\Cookies\paul@ru4[3].txt Ontdekt: Trace.TrackingCookie.ru4!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[1].txt Ontdekt: Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[2].txt Ontdekt: Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[3].txt Ontdekt: Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@superstats[1].txt Ontdekt: Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\paul\Cookies\paul@superstats[2].txt Ontdekt: Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\paul\Cookies\paul@superstats[3].txt Ontdekt: Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\arno\Cookies\arno@about[1].txt Ontdekt: Trace.TrackingCookie.about!A2
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/acrti80serverkg.exe Ontdekt: Riskware.Keygen.SuspectCRC!IK
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/ssg.nfo Ontdekt: Riskware.Keygen.SuspectCRC!IK
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR.ShareReactor.rar/Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR\keygen.exe Ontdekt: Riskware.RiskTool.Win32.HideRun!IK
    C:\Program Files\FoxTabVideoConverter\VideoConverter.exe Ontdekt: Riskware.Win32.InstallCore.AMN!A2
    C:\Program Files\Vuze\.install4j\i4j_extf_8_5p83tu.exe Ontdekt: Riskware.WebToolbar.Win32.MyWebSearch!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/acrti80serverkg.exe Ontdekt: Riskware.Keygen.SuspectCRC!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/ssg.nfo Ontdekt: Riskware.Keygen.SuspectCRC!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR.ShareReactor.rar/Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR\keygen.exe Ontdekt: Riskware.RiskTool.Win32.HideRun!IK
    F:\Program Files\FoxTabVideoConverter\VideoConverter.exe Ontdekt: Riskware.Win32.InstallCore.AMN!A2
    F:\Program Files\Vuze\.install4j\i4j_extf_8_5p83tu.exe Ontdekt: Riskware.WebToolbar.Win32.MyWebSearch!IK

    Gescand

    Bestanden: 1019420
    Sporen: 592488
    Cookies: 16271
    Processen: 35

    Gevonden

    Bestanden: 10
    Sporen: 5
    Cookies: 24
    Processen: 0
    Registersleutels: 0

    Scan Geëindigd: 14/05/2012 19:28:09
    Scantijd: 9:46:18

    C:\Program Files\Vuze\.install4j\i4j_extf_8_5p83tu.exe Verwijderd Riskware.WebToolbar.Win32.MyWebSearch!IK
    F:\Program Files\Vuze\.install4j\i4j_extf_8_5p83tu.exe Verwijderd Riskware.WebToolbar.Win32.MyWebSearch!IK
    C:\Program Files\FoxTabVideoConverter\VideoConverter.exe Verwijderd Riskware.Win32.InstallCore.AMN!A2
    F:\Program Files\FoxTabVideoConverter\VideoConverter.exe Verwijderd Riskware.Win32.InstallCore.AMN!A2
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR.ShareReactor.rar/Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR\keygen.exe Verwijderd Riskware.RiskTool.Win32.HideRun!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR.ShareReactor.rar/Acronis.Partition.Expert.2003.Build.285.Incl.Keygen-ROR\keygen.exe Verwijderd Riskware.RiskTool.Win32.HideRun!IK
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/acrti80serverkg.exe Verwijderd Riskware.Keygen.SuspectCRC!IK
    C:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/ssg.nfo Verwijderd Riskware.Keygen.SuspectCRC!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/acrti80serverkg.exe Verwijderd Riskware.Keygen.SuspectCRC!IK
    F:\Documents and Settings\paul\Mijn documenten\Downloads\Acronis True Image Server v8.0.774 Incl.Keygen-SSG.rar/ssg.nfo Verwijderd Riskware.Keygen.SuspectCRC!IK
    C:\Documents and Settings\paul\Cookies\paul@superstats[1].txt Verwijderd Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\paul\Cookies\paul@superstats[2].txt Verwijderd Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\paul\Cookies\paul@superstats[3].txt Verwijderd Trace.TrackingCookie.superstats!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[1].txt Verwijderd Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[2].txt Verwijderd Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@stat.dealtime[3].txt Verwijderd Trace.TrackingCookie.stat.dealtime!A2
    C:\Documents and Settings\paul\Cookies\paul@ru4[2].txt Verwijderd Trace.TrackingCookie.ru4!A2
    C:\Documents and Settings\paul\Cookies\paul@ru4[3].txt Verwijderd Trace.TrackingCookie.ru4!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[1].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[2].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[3].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[4].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[5].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[6].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[7].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@ebay.com[8].txt Verwijderd Trace.TrackingCookie.ebay.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[1].txt Verwijderd Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[2].txt Verwijderd Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[3].txt Verwijderd Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[4].txt Verwijderd Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@com[5].txt Verwijderd Trace.TrackingCookie.com!A2
    C:\Documents and Settings\paul\Cookies\paul@angelfire[1].txt Verwijderd Trace.TrackingCookie.angelfire!A2
    C:\Documents and Settings\paul\Cookies\paul@about[3].txt Verwijderd Trace.TrackingCookie.about!A2
    C:\Documents and Settings\arno\Cookies\arno@about[1].txt Verwijderd Trace.TrackingCookie.about!A2
    Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems Verwijderd Trace.Registry.Trymedia!A2
    Key: HKEY_LOCAL_MACHINE\software\Trymedia Systems\ActiveMARK Software Verwijderd Trace.Registry.Trymedia!A2
    Key: HKEY_USERS\marijke\software\microsoft\windows\currentversion\ext\stats\{c1e58a84-95b3-4630-b8c2-d06b77b7a0fc} Verwijderd Trace.Registry.NavExcel!A2
    Key: HKEY_CURRENT_USER\software\kazaa Verwijderd Trace.Registry.KaZaA!A2
    c:\documents and settings\marijke\bureaublad\Morpheus Clean Disk 2002.lnk Verwijderd Trace.File.Morpheus Clean Disc!A2

    Verwijderd

    Bestanden: 10
    Sporen: 5
    Cookies: 24
  • En hier volgt de MBAM log:

    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Databaseversie: v2012.05.14.05

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    paul :: STILLEPC [administrator]

    14/05/2012 19:48:20
    mbam-log-2012-05-14 (19-48-20).txt

    Scantype: Snelle scan
    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scanopties: P2P
    Objecten gescand: 393167
    Verstreken tijd: 8 minuut/minuten, 3 seconde(n)

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    (einde)
  • Hallo Paul, eerst het volgende weetje:

  • 22:24:19.0484 0896 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18
    22:24:19.0484 0896 ============================================================
    22:24:19.0484 0896 Current date / time: 2012/05/14 22:24:19.0484
    22:24:19.0484 0896 SystemInfo:
    22:24:19.0484 0896
    22:24:19.0484 0896 OS Version: 5.1.2600 ServicePack: 3.0
    22:24:19.0484 0896 Product type: Workstation
    22:24:19.0484 0896 ComputerName: STILLEPC
    22:24:19.0484 0896 UserName: paul
    22:24:19.0484 0896 Windows directory: C:\WINDOWS
    22:24:19.0484 0896 System windows directory: C:\WINDOWS
    22:24:19.0484 0896 Processor architecture: Intel x86
    22:24:19.0484 0896 Number of processors: 4
    22:24:19.0484 0896 Page size: 0x1000
    22:24:19.0484 0896 Boot type: Normal boot
    22:24:19.0484 0896 ============================================================
    22:24:21.0093 0896 Drive \Device\Harddisk1\DR1 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
    22:24:21.0093 0896 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
    22:24:21.0109 0896 ============================================================
    22:24:21.0109 0896 \Device\Harddisk1\DR1:
    22:24:21.0109 0896 MBR partitions:
    22:24:21.0109 0896 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41
    22:24:21.0109 0896 \Device\Harddisk0\DR0:
    22:24:21.0109 0896 MBR partitions:
    22:24:21.0109 0896 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74705982
    22:24:21.0109 0896 ============================================================
    22:24:21.0156 0896 C: <-> \Device\Harddisk1\DR1\Partition0
    22:24:21.0187 0896 F: <-> \Device\Harddisk0\DR0\Partition0
    22:24:21.0187 0896 ============================================================
    22:24:21.0187 0896 Initialize success
    22:24:21.0187 0896 ============================================================
    22:24:21.0218 2652 ============================================================
    22:24:21.0218 2652 Scan started
    22:24:21.0218 2652 Mode: Auto (DCExact ); SigCheck; TDLFS; Silent;
    22:24:21.0218 2652 ============================================================
    22:24:22.0437 2652 ACPI (02273a448ba21a7d447daeb47810d40c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    22:24:23.0453 2652 ACPIEC (63f517b1a87dabf3f5acb8a7952fc1d1) C:\WINDOWS\system32\drivers\ACPIEC.sys
    22:24:23.0703 2652 AcrSch2Svc (5f9a7fb02944f0e557d8ee786f04c57f) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    22:24:23.0859 2652 Adobe Version Cue CS3 (14c23516c990dcd6052152cf034dde40) C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    22:24:24.0000 2652 AdobeActiveFileMonitor4.0 (cbce4e5e5cfc29efaac14a9de290a855) C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    22:24:24.0000 2652 AdobeActiveFileMonitor4.0 ( UnsignedFile.Multi.Generic ) - [b:5653d72c70]
  • Zit jouw computer in een thuisnetwerk aangesloten?

    [b:1a5dbc4be7]Welk programma[/b:1a5dbc4be7]:
  • Vooraleer Combofix op te starten heb ik devirus-scanner Avira en de Windows firewall uitgeschakeld. Ik kreeg een melding dat AVG actief was terwijl ik die lang geleden verwijderd heb. Dan maar verder gegaan en hier staat de Combofix-log:

    ComboFix 12-05-14.03 - paul 15/05/2012 8:17.11.4 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.3582.2861 [GMT 2:00]
    Gestart vanuit: c:\documents and settings\paul\Bureaublad\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    .
    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\arno\System
    c:\documents and settings\arno\System\win_qs8.jqx
    c:\documents and settings\paul\WINDOWS
    c:\program files\5100_nld_win2k_xp.exe
    c:\program files\5100_nld_win2k_xpinfu.exe
    c:\windows\IsUn0413.exe
    c:\windows\system32\drivers\etc\hosts.ics
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2012-04-15 to 2012-05-15 ))))))))))))))))))))))))))))))
    .
    .
    2012-05-14 20:24 . 2012-05-14 20:24 ——– d—–w- C:\TDSSStarter
    2012-05-07 11:54 . 2012-05-07 11:54 ——– d—–w- c:\program files\Easeware
    2012-05-07 09:58 . 2011-06-27 16:56 81936 —-a-w- c:\windows\system32\RtNicProp32.dll
    2012-05-07 09:58 . 2011-06-27 16:56 102416 —-a-w- c:\windows\system32\RTNUninst32.dll
    2012-05-07 07:11 . 2012-05-07 07:13 ——– dc-h–w- c:\windows\ie8
    2012-05-06 19:23 . 2012-05-15 06:13 ——– d–h–r- c:\documents and settings\paul\Onlangs geopend
    2012-05-06 19:23 . 2012-05-06 19:23 ——– d—–w- c:\documents and settings\arno\Local Settings\Application Data\Temp
    2012-05-06 17:30 . 2012-03-19 17:01 65128 —-a-w- c:\windows\system32\RtkCoInstIIXP.dll
    2012-05-06 17:30 . 2011-11-22 14:28 11368 —-a-w- c:\windows\system32\RtkCoLDRXP.dll
    2012-05-06 17:17 . 2012-05-06 17:17 ——– d—–w- c:\program files\FinalWire
    2012-05-05 19:42 . 2012-05-05 19:42 ——– d—–w- c:\windows\system32\wbem\Repository
    2012-05-04 16:29 . 2012-05-06 19:23 ——– d—–w- c:\documents and settings\arno\Application Data\SmartDraw
    2012-05-03 11:57 . 2012-05-03 11:57 ——– d—–w- c:\documents and settings\paul\Application Data\ElevatedDiagnostics
    2012-04-30 18:27 . 2012-04-30 18:27 3654896 —-a-w- c:\program files\ccsetup318.exe
    2012-04-17 07:36 . 2012-05-07 09:36 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-05-09 10:56 . 2010-12-11 07:23 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
    2012-05-07 09:36 . 2011-12-31 15:22 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-11 13:55 . 2008-04-14 22:11 2031104 —-a-w- c:\windows\system32
    tkrnlpa.exe
    2012-04-11 13:55 . 2008-04-15 12:00 2152960 —-a-w- c:\windows\system32
    toskrnl.exe
    2012-04-11 13:55 . 2008-04-15 12:00 1862400 —-a-w- c:\windows\system32\win32k.sys
    2012-04-04 13:56 . 2008-10-21 13:29 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
    2012-03-01 11:00 . 2008-04-15 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
    2012-03-01 11:00 . 2008-04-15 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
    2012-03-01 11:00 . 2008-04-15 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
    2012-02-29 23:58 . 2012-03-14 08:49 881984 —-a-w- c:\windows\system32
    vgenco32.dll
    2012-02-29 23:58 . 2012-03-14 08:49 18624512 —-a-w- c:\windows\system32
    voglnt.dll
    2012-02-29 23:58 . 2012-03-14 08:49 1000256 —-a-w- c:\windows\system32
    vdispco32.dll
    2012-02-29 23:58 . 2011-12-27 19:55 65536 —-a-w- c:\windows\system32\OpenCL.dll
    2012-02-29 23:58 . 2011-12-27 19:55 2522944 —-a-w- c:\windows\system32
    vcuvid.dll
    2012-02-29 23:58 . 2011-12-27 19:55 2437440 —-a-w- c:\windows\system32
    vcuvenc.dll
    2012-02-29 23:58 . 2011-12-27 19:55 17534976 —-a-w- c:\windows\system32
    vcompiler.dll
    2012-02-29 23:58 . 2008-09-17 07:55 5918720 —-a-w- c:\windows\system32
    vcuda.dll
    2012-02-29 23:58 . 2007-09-16 17:07 4309760 —-a-w- c:\windows\system32
    v4_disp.dll
    2012-02-29 23:58 . 2007-09-16 17:07 2291712 —-a-w- c:\windows\system32
    vapi.dll
    2012-02-29 23:58 . 2007-09-16 17:07 13417632 —-a-w- c:\windows\system32\drivers
    v4_mini.sys
    2012-02-29 21:15 . 2012-03-14 08:51 335872 —-a-w- c:\windows\system32
    vrshe.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsja.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsesm.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrspl.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrssv.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrseng.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrscs.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrsit.dll
    2012-02-29 21:15 . 2012-03-14 08:51 278528 —-a-w- c:\windows\system32
    vrsde.dll
    2012-02-29 21:15 . 2012-03-14 08:51 270336 —-a-w- c:\windows\system32
    vrsptb.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrssk.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrspt.dll
    2012-02-29 21:15 . 2012-03-14 08:51 262144 —-a-w- c:\windows\system32
    vrshu.dll
    2012-02-29 21:15 . 2012-03-14 08:51 266240 —-a-w- c:\windows\system32
    vrsko.dll
    2012-02-29 21:15 . 2012-03-14 08:51 335872 —-a-w- c:\windows\system32
    vrsar.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrses.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsnl.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrstr.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsth.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsno.dll
    2012-02-29 21:15 . 2012-03-14 08:51 286720 —-a-w- c:\windows\system32
    vrsfr.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrsel.dll
    2012-02-29 21:15 . 2012-03-14 08:51 270336 —-a-w- c:\windows\system32
    vrsru.dll
    2012-02-29 21:15 . 2012-03-14 08:51 229376 —-a-w- c:\windows\system32
    vrszhc.dll
    2012-02-29 21:15 . 2012-03-14 08:51 126976 —-a-w- c:\windows\system32
    vrszht.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsda.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrsfi.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrssl.dll
    2012-02-29 20:30 . 2012-03-14 08:50 54272 —-a-w- c:\windows\system32
    vwddi.dll
    2012-02-29 20:30 . 2012-03-14 08:51 143680 —-a-w- c:\windows\system32
    vcolor.exe
    2012-02-29 20:30 . 2012-03-14 08:50 15494464 —-a-w- c:\windows\system32
    vcpl.dll
    2012-02-29 20:30 . 2012-03-14 08:51 164160 —-a-w- c:\windows\system32
    vsvc32.exe
    2012-02-29 20:30 . 2012-03-14 08:50 108352 —-a-w- c:\windows\system32
    vmctray.dll
    2012-02-29 14:10 . 2008-04-15 12:00 177664 —-a-w- c:\windows\system32\wintrust.dll
    2012-02-29 14:10 . 2008-04-15 12:00 148480 —-a-w- c:\windows\system32\imagehlp.dll
    2012-02-29 12:17 . 2008-04-15 12:00 385024 ——w- c:\windows\system32\html.iec
    2012-02-19 00:05 . 2008-04-15 12:00 26112 —-a-w- c:\windows\system32\userinit.exe
    2012-02-09 15:12 . 2012-02-09 15:12 31181592 —-a-w- c:\program files\DWFWriter4Setup.exe
    2012-02-09 14:57 . 2012-02-09 14:33 62286360 —-a-w- c:\program files\FreeDWGViewer.exe
    2012-02-09 14:42 . 2012-02-09 14:41 808368 —-a-w- c:\program files\AutodeskDesignRevSetup.exe
    2012-01-11 06:54 . 2012-01-11 06:54 3562624 —-a-w- c:\program files\ccsetup314.exe
    2012-01-05 09:37 . 2008-10-22 11:09 86016 —-a-w- c:\program files\setupenne.dll
    2011-12-30 14:08 . 2011-12-30 14:08 1402880 —-a-w- c:\program files\HiJackThis.msi
    2011-12-26 07:01 . 2011-12-26 07:01 21073936 —-a-w- c:\program files\vlc-1.1.11-win32.exe
    2011-10-18 16:51 . 2011-10-18 16:51 3687352 —-a-w- c:\program files\PMB.lnk
    2011-04-10 12:06 . 2011-04-10 12:06 20586196 —-a-w- c:\program files\vlc-1.1.8-win32.exe
    2011-04-10 12:03 . 2011-02-19 15:31 20364702 —-a-w- c:\program files\vlc-1.1.7-win32.exe
    2011-01-29 06:52 . 2011-01-29 06:52 200442456 —-a-w- c:\program files\vegaspro100c_32bit.exe
    2011-01-27 18:35 . 2011-01-27 18:35 1364522 —-a-w- c:\program files\wrar393.exe
    2011-01-16 09:27 . 2011-01-16 09:26 150446976 —-a-w- c:\program files\AVSVideoEditor.exe
    2011-01-12 02:33 . 2011-01-12 02:33 11008549 —-a-w- c:\program files\avidemux_2.5.4_win32.exe
    2011-01-11 17:21 . 2011-01-11 17:20 62701672 —-a-w- c:\program files\AVSVideoConverter.exe
    2010-12-30 16:59 . 2010-12-30 16:58 19985265 —-a-w- c:\program files\vlc-1.1.5-win32.exe
    2010-12-14 19:22 . 2010-12-14 19:22 338760 —-a-w- c:\program files\RegtaskTool_Installer.exe
    2010-12-11 07:22 . 2010-12-11 07:21 25188112 —-a-w- c:\program files\setpoint620.exe
    2010-12-08 18:15 . 2008-10-20 17:25 9039288 —-a-w- c:\program files\Vuze_Installer.exe
    2010-12-04 11:27 . 2010-07-04 06:54 13454568 —-a-w- c:\program files\RegistryReviverSetup.exe
    2010-08-29 11:47 . 2009-04-29 16:04 44089904 —-a-w- c:\program files\avira_antivir_personal_en.exe
    2010-08-29 11:37 . 2010-08-29 11:37 44153664 —-a-w- c:\program files\avira_antivir_personal_de.exe
    2010-08-29 11:23 . 2010-08-29 11:23 3427712 —-a-w- c:\program files\ccsetup235.exe
    2010-08-05 17:43 . 2010-08-05 17:43 3420304 —-a-w- c:\program files\ccsetup234.exe
    2010-03-20 17:37 . 2010-03-20 17:37 1103048 —-a-w- c:\program files\wpsetup.exe
    2010-03-12 12:28 . 2010-03-12 12:28 34506392 —-a-w- c:\program files\Nokia_PC_Suite_dut_web.exe
    2010-03-12 10:46 . 2010-03-12 10:39 98366952 —-a-w- c:\program files\Nokia_Ovi_Suite_webinstaller_ALL.exe
    2010-01-02 22:50 . 2009-10-16 05:08 13731712 —-a-w- c:\program files\AVSRegistryCleaner.exe
    2009-12-25 11:22 . 2009-12-25 11:22 6113439 —-a-w- c:\program files\pci_filerecovery.exe
    2009-10-25 11:52 . 2009-10-25 11:52 77086488 —-a-w- c:\program files\Ad-AwareInstallation.exe
    2009-09-02 18:54 . 2009-09-02 18:54 74160 —-a-w- c:\program files\irfanview_lang_nederlands.exe
    2009-09-02 18:52 . 2009-09-02 18:52 1359360 —-a-w- c:\program files\iview425_setup.exe
    2009-08-30 09:17 . 2009-08-30 09:16 3293088 —-a-w- c:\program files\ccsetup223.exe
    2009-05-28 18:34 . 2009-05-28 18:34 5076056 —-a-w- c:\program files
    uvi760_480.exe
    2009-03-22 12:11 . 2009-03-22 12:11 4310568 —-a-w- c:\program files\WebUpdater_241.exe
    2009-03-14 08:06 . 2009-03-14 08:06 37452296 —-a-w- c:\program files\Ad-AwareAE.exe
    2008-12-21 11:12 . 2008-12-21 11:11 5797488 —-a-w- c:\program files\GOMPLAYERENSETUP.EXE
    2008-12-21 08:57 . 2008-12-21 08:57 27288880 —-a-w- c:\program files\QuickTimeInstaller.exe
    2008-12-21 08:49 . 2008-12-21 08:49 12349806 —-a-w- c:\program files\dvdflick_setup_1.3.0.4.exe
    2008-11-30 11:51 . 2008-10-06 07:04 15083520 —-a-w- c:\program files\spybotsd160.exe
    2008-11-23 14:14 . 2008-10-02 17:20 25129080 —-a-w- c:\program files\antivir_workstation_winu_en_h.exe
    2008-11-23 12:02 . 2008-11-23 12:02 1958864 —-a-w- c:\program files\TrendMicro_Downloader.exe
    2008-11-11 14:44 . 2008-11-11 14:44 860391 —-a-w- c:\program files\7z457.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS5\Bridge.exe" [2011-06-09 12002664]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinPatrol"="c:\progra~1\BILLPS~1\WINPAT~1\winpatrol.exe" [2005-09-26 222784]
    "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
    "NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
    "nwiz"="c:\program files\NVIDIA Corporation
    view
    wiz.exe" [2012-02-29 1634112]
    "Driver Update and remove for Windows x64 or x86_32"="c:\program files\Realtek\Audio\Drivers\RtlUpd.exe" [2011-08-29 1493608]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLinkedConnections"= 1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
    otify\LBTWlgn]
    2010-10-28 10:13 64592 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
    "c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Avira\\AntiVir Desktop\\avscan.exe"=
    "c:\\Program Files\\Vuze\\Azureus.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\system32\\mshta.exe"=
    "c:\\Documents and Settings\\paul\\Local Settings\\Application Data\\Akamai\
    etsession_win.exe"=
    "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
    "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
    "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
    "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
    .
    R0 hotcore;hotcore;c:\windows\system32\drivers\hotcore.sys [4/10/2008 13:21 30820]
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/10/2008 20:41 717296]
    R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [2/12/2010 20:22 752128]
    R2 afcdpsrv;Acronis Nonstop Backup-service ;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [29/12/2010 15:42 3246040]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [22/05/2009 19:54 136360]
    R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [11/12/2010 9:22 10448]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [14/03/2012 10:51 2348352]
    R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [15/03/2011 14:44 428384]
    R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [29/12/2010 15:42 167968]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate1c9c7b35e2a82cc;Google Update Service (gupdate1c9c7b35e2a82cc);c:\program files\Google\Update\GoogleUpdate.exe [28/04/2009 5:42 133104]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [17/04/2012 9:36 257696]
    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [7/05/2012 8:42 1691480]
    S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\gsvr.exe [3/10/2008 0:16 55816]
    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [28/04/2009 5:42 133104]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [24/08/2010 19:30 40912]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [24/08/2010 19:30 10448]
    S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 14:37 517096]
    S4 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [15/04/2008 14:00 14336]
    S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe –> c:\program files\AskBarDis\bar\bin\AskService.exe [?]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Akamai REG_MULTI_SZ Akamai
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2012-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 09:36]
    .
    2011-12-26 c:\windows\Tasks\AdobeAAMUpdater-1.0-STILLEPC-paul.job
    - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-22 02:44]
    .
    2011-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
    .
    2012-05-07 c:\windows\Tasks\DriverNavigator Scheduled Scan.job
    - c:\program files\Easeware\DriverNavigator\DriverNavigator.exe [2012-05-07 16:56]
    .
    2012-01-01 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-05 07:23]
    .
    2012-04-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cce185a38be5ba.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd08544131963a.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-01-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-02-26 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2012-01-03 15:31]
    .
    2012-05-07 c:\windows\Tasks\User_Feed_Synchronization-{1CD3A718-4B83-444F-9C3D-CB870A64AC95}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
    .
    .
    ——- Bijkomende Scan ——-
    .
    uStart Page = hxxp://www.tijd.be/
    uInternet Settings,ProxyOverride = *.local
    IE: PDF in Word openen (PDF Converter 3.0) - c:\program files\ScanSoft\PDF Professional 3.0\IEShellExt.dll /700
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
    DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://sligachanhotel.remotemanager.co.uk/common/activex/MJPEGRender.ocx
    .
    - - - - ORPHANS VERWIJDERD - - - -
    .
    AddRemove-Van Dale Grote woordenboeken Engels - c:\windows\ISUN0413.EXE
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-05-15 08:26
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scannen van verborgen processen …
    .
    scannen van verborgen autostart items …
    .
    scannen van verborgen bestanden …
    .
    Scan succesvol afgerond
    verborgen bestanden: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
    "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_d76cf65.dll"
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
    "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_d76cf65.dll"
    .
    ——————— DLLs Geladen Onder Lopende Processen ———————
    .
    - - - - - - - > 'winlogon.exe'(1000)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    .
    Voltooingstijd: 2012-05-15 08:28:11
    ComboFix-quarantined-files.txt 2012-05-15 06:27
    ComboFix2.txt 2011-12-31 10:24
    .
    Pre-Run: 206.797.115.392 bytes beschikbaar
    Post-Run: 207.369.703.424 bytes beschikbaar
    .
    - - End Of File - - 94D26615879269511AD81DBF6BEB2995

















































  • Wat betreft AVG, die gaan we definitief uit jouw Windows verwijderen.

    Maar om even terug te komen op het gegeven dat jij niet in een thuisnetwerk zit, er staan tig poorten open in de firewall.

    Ik vind dan ook persoonlijk, dat jij beter op een firewall van derden overgaat dan maar met de Windows firewall te blijven werken!


    AVG Remover 32-bit: http://download.avg.com/filedir/util/avgrem/avg_remover_stf_x86_2012_2125.exe

    Gebruik dit tool om de laatste resten van AVG uit jouw Windows te krijgen.
    Windows zal er ook blij mee zijn!
  • 1) Ik kreeg net een bericht van Avira om up te graden naar versie 2012. Hierbij krijg ik een melding dat deze software niet compatibel is met AVG en Spybot Search & Destroy en word ik gevraagd deze te verwijderen.
    Nadat ik AVG gepoogd heb te verwijderen (via link in je laatste post) krijg ik tóch weer dit bericht van Avira. Betekent dit dat AVG nog niet verwijderd is ?

    2) Kun je me een betere Firewall aanbevelen ?

    Alvast bedankt.
  • Wat betreft de firewall is er feitelijk maar één keus:
  • OTL logfile created on: 16/05/2012 7:49:08 - Run 1
    OTL by OldTimer - Version 3.2.43.0 Folder = C:\Documents and Settings\paul\Bureaublad
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy

    3,50 Gb Total Physical Memory | 2,90 Gb Available Physical Memory | 83,00% Memory free
    5,34 Gb Paging File | 4,81 Gb Available in Paging File | 90,13% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 465,75 Gb Total Space | 192,80 Gb Free Space | 41,40% Space Free | Partition Type: NTFS
    Drive F: | 931,51 Gb Total Space | 333,55 Gb Free Space | 35,81% Space Free | Partition Type: NTFS

    Computer Name: STILLEPC | User Name: paul | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

  • OTL Extras logfile created on: 16/05/2012 7:49:08 - Run 1
    OTL by OldTimer - Version 3.2.43.0 Folder = C:\Documents and Settings\paul\Bureaublad
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy

    3,50 Gb Total Physical Memory | 2,90 Gb Available Physical Memory | 83,00% Memory free
    5,34 Gb Paging File | 4,81 Gb Available in Paging File | 90,13% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 465,75 Gb Total Space | 192,80 Gb Free Space | 41,40% Space Free | Partition Type: NTFS
    Drive F: | 931,51 Gb Total Space | 333,55 Gb Free Space | 35,81% Space Free | Partition Type: NTFS

    Computer Name: STILLEPC | User Name: paul | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

  • AVG is goed verwijderd verwijderd - een paar onschuldige resten gaan we nu via script verwijderen.

    [b:5e29d15233]Sluit voordat
  • All processes killed
    ========== OTL ==========
    Service ASKService stopped successfully!
    Service ASKService deleted successfully!
    File C:\Program Files\AskBarDis\bar\bin\AskService.exe not found.
    Registry key HKEY_USERS\S-1-5-21-842925246-1592454029-1417001333-1004\Software\Microsoft\Internet Explorer\SearchScopes\{2A51D3AD-467A-496C-A406-677189F59230}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A51D3AD-467A-496C-A406-677189F59230}\ not found.
    C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF folder moved successfully.
    C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences folder moved successfully.
    C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults folder moved successfully.
    C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome folder moved successfully.
    C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} folder moved successfully.
    C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
    C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012\Temp(2) folder moved successfully.
    C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012\fet(2) folder moved successfully.
    C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012\fet folder moved successfully.
    C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012 folder moved successfully.
    C:\Documents and Settings\paul\Application Data\AVG2012\cfgall folder moved successfully.
    C:\Documents and Settings\paul\Application Data\AVG2012 folder moved successfully.
    File C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] not found.
    File EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
  • Hallo Paul, we gebruiken ComboFix opnieuw.
    Het kan na opstarten van ComboFix gebeuren dat er een melding komt:

    - of ComboFix wil geupdated worden;
    - of ComboFix wil opnieuw gedownload worden.

    Krijg je dus zo'n melding, dan dit ook uitvoeren.
    Post wederom de inhoud van het ComboFix-log.
  • ComboFix 12-05-16.01 - paul 16/05/2012 13:29:14.12.4 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.3582.2953 [GMT 2:00]
    Gestart vanuit: c:\documents and settings\paul\Bureaublad\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
    .
    .
    (((((((((((((((((((( Bestanden Gemaakt van 2012-04-16 to 2012-05-16 ))))))))))))))))))))))))))))))
    .
    .
    2012-05-16 07:37 . 2012-05-16 07:37 ——– d—–w- C:\_OTL
    2012-05-15 21:46 . 2012-05-16 05:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\OnlineArmor
    2012-05-15 21:46 . 2012-05-15 21:46 ——– d—–w- c:\documents and settings\paul\Application Data\OnlineArmor
    2012-05-15 21:45 . 2012-02-10 12:33 42152 —-a-w- c:\windows\system32\drivers\oahlp32.sys
    2012-05-15 21:45 . 2012-02-10 12:33 29464 —-a-w- c:\windows\system32\drivers\OAnet.sys
    2012-05-15 21:45 . 2012-02-10 12:33 25192 —-a-w- c:\windows\system32\drivers\OAmon.sys
    2012-05-15 21:45 . 2012-02-10 12:33 205864 —-a-w- c:\windows\system32\drivers\OADriver.sys
    2012-05-15 21:45 . 2012-05-16 11:18 ——– d—–w- c:\program files\Online Armor
    2012-05-15 21:37 . 2012-05-15 21:37 29588048 —-a-w- c:\program files\OnlineArmorSetup.exe
    2012-05-14 20:24 . 2012-05-14 20:24 ——– d—–w- C:\TDSSStarter
    2012-05-07 11:54 . 2012-05-07 11:54 ——– d—–w- c:\program files\Easeware
    2012-05-07 09:58 . 2011-06-27 16:56 81936 —-a-w- c:\windows\system32\RtNicProp32.dll
    2012-05-07 09:58 . 2011-06-27 16:56 102416 —-a-w- c:\windows\system32\RTNUninst32.dll
    2012-05-07 07:11 . 2012-05-07 07:13 ——– dc-h–w- c:\windows\ie8
    2012-05-06 19:23 . 2012-05-15 06:13 ——– d–h–r- c:\documents and settings\paul\Onlangs geopend
    2012-05-06 19:23 . 2012-05-06 19:23 ——– d—–w- c:\documents and settings\arno\Local Settings\Application Data\Temp
    2012-05-06 17:30 . 2012-03-19 17:01 65128 —-a-w- c:\windows\system32\RtkCoInstIIXP.dll
    2012-05-06 17:30 . 2011-11-22 14:28 11368 —-a-w- c:\windows\system32\RtkCoLDRXP.dll
    2012-05-06 17:17 . 2012-05-06 17:17 ——– d—–w- c:\program files\FinalWire
    2012-05-05 19:42 . 2012-05-05 19:42 ——– d—–w- c:\windows\system32\wbem\Repository
    2012-05-04 16:29 . 2012-05-06 19:23 ——– d—–w- c:\documents and settings\arno\Application Data\SmartDraw
    2012-05-03 11:57 . 2012-05-03 11:57 ——– d—–w- c:\documents and settings\paul\Application Data\ElevatedDiagnostics
    2012-04-30 18:27 . 2012-04-30 18:27 3654896 —-a-w- c:\program files\ccsetup318.exe
    2012-04-17 07:36 . 2012-05-07 09:36 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-05-09 10:56 . 2010-12-11 07:23 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
    2012-05-07 09:36 . 2011-12-31 15:22 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-11 13:55 . 2008-04-14 22:11 2031104 —-a-w- c:\windows\system32
    tkrnlpa.exe
    2012-04-11 13:55 . 2008-04-15 12:00 2152960 —-a-w- c:\windows\system32
    toskrnl.exe
    2012-04-11 13:55 . 2008-04-15 12:00 1862400 —-a-w- c:\windows\system32\win32k.sys
    2012-04-04 13:56 . 2008-10-21 13:29 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
    2012-03-01 11:00 . 2008-04-15 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
    2012-03-01 11:00 . 2008-04-15 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
    2012-03-01 11:00 . 2008-04-15 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
    2012-02-29 23:58 . 2012-03-14 08:49 881984 —-a-w- c:\windows\system32
    vgenco32.dll
    2012-02-29 23:58 . 2012-03-14 08:49 18624512 —-a-w- c:\windows\system32
    voglnt.dll
    2012-02-29 23:58 . 2012-03-14 08:49 1000256 —-a-w- c:\windows\system32
    vdispco32.dll
    2012-02-29 23:58 . 2011-12-27 19:55 65536 —-a-w- c:\windows\system32\OpenCL.dll
    2012-02-29 23:58 . 2011-12-27 19:55 2522944 —-a-w- c:\windows\system32
    vcuvid.dll
    2012-02-29 23:58 . 2011-12-27 19:55 2437440 —-a-w- c:\windows\system32
    vcuvenc.dll
    2012-02-29 23:58 . 2011-12-27 19:55 17534976 —-a-w- c:\windows\system32
    vcompiler.dll
    2012-02-29 23:58 . 2008-09-17 07:55 5918720 —-a-w- c:\windows\system32
    vcuda.dll
    2012-02-29 23:58 . 2007-09-16 17:07 4309760 —-a-w- c:\windows\system32
    v4_disp.dll
    2012-02-29 23:58 . 2007-09-16 17:07 2291712 —-a-w- c:\windows\system32
    vapi.dll
    2012-02-29 23:58 . 2007-09-16 17:07 13417632 —-a-w- c:\windows\system32\drivers
    v4_mini.sys
    2012-02-29 21:15 . 2012-03-14 08:51 335872 —-a-w- c:\windows\system32
    vrshe.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsja.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsesm.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrspl.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrssv.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrseng.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrscs.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrsit.dll
    2012-02-29 21:15 . 2012-03-14 08:51 278528 —-a-w- c:\windows\system32
    vrsde.dll
    2012-02-29 21:15 . 2012-03-14 08:51 270336 —-a-w- c:\windows\system32
    vrsptb.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrssk.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrspt.dll
    2012-02-29 21:15 . 2012-03-14 08:51 262144 —-a-w- c:\windows\system32
    vrshu.dll
    2012-02-29 21:15 . 2012-03-14 08:51 266240 —-a-w- c:\windows\system32
    vrsko.dll
    2012-02-29 21:15 . 2012-03-14 08:51 335872 —-a-w- c:\windows\system32
    vrsar.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrses.dll
    2012-02-29 21:15 . 2012-03-14 08:51 274432 —-a-w- c:\windows\system32
    vrsnl.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrstr.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsth.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsno.dll
    2012-02-29 21:15 . 2012-03-14 08:51 286720 —-a-w- c:\windows\system32
    vrsfr.dll
    2012-02-29 21:15 . 2012-03-14 08:51 282624 —-a-w- c:\windows\system32
    vrsel.dll
    2012-02-29 21:15 . 2012-03-14 08:51 270336 —-a-w- c:\windows\system32
    vrsru.dll
    2012-02-29 21:15 . 2012-03-14 08:51 229376 —-a-w- c:\windows\system32
    vrszhc.dll
    2012-02-29 21:15 . 2012-03-14 08:51 126976 —-a-w- c:\windows\system32
    vrszht.dll
    2012-02-29 21:15 . 2012-03-14 08:51 253952 —-a-w- c:\windows\system32
    vrsda.dll
    2012-02-29 21:15 . 2012-03-14 08:51 249856 —-a-w- c:\windows\system32
    vrsfi.dll
    2012-02-29 21:15 . 2012-03-14 08:51 258048 —-a-w- c:\windows\system32
    vrssl.dll
    2012-02-29 20:30 . 2012-03-14 08:50 54272 —-a-w- c:\windows\system32
    vwddi.dll
    2012-02-29 20:30 . 2012-03-14 08:51 143680 —-a-w- c:\windows\system32
    vcolor.exe
    2012-02-29 20:30 . 2012-03-14 08:50 15494464 —-a-w- c:\windows\system32
    vcpl.dll
    2012-02-29 20:30 . 2012-03-14 08:51 164160 —-a-w- c:\windows\system32
    vsvc32.exe
    2012-02-29 20:30 . 2012-03-14 08:50 108352 —-a-w- c:\windows\system32
    vmctray.dll
    2012-02-29 14:10 . 2008-04-15 12:00 177664 —-a-w- c:\windows\system32\wintrust.dll
    2012-02-29 14:10 . 2008-04-15 12:00 148480 —-a-w- c:\windows\system32\imagehlp.dll
    2012-02-29 12:17 . 2008-04-15 12:00 385024 ——w- c:\windows\system32\html.iec
    2012-02-19 00:05 . 2008-04-15 12:00 26112 —-a-w- c:\windows\system32\userinit.exe
    2012-02-09 15:12 . 2012-02-09 15:12 31181592 —-a-w- c:\program files\DWFWriter4Setup.exe
    2012-02-09 14:57 . 2012-02-09 14:33 62286360 —-a-w- c:\program files\FreeDWGViewer.exe
    2012-02-09 14:42 . 2012-02-09 14:41 808368 —-a-w- c:\program files\AutodeskDesignRevSetup.exe
    2012-01-11 06:54 . 2012-01-11 06:54 3562624 —-a-w- c:\program files\ccsetup314.exe
    2012-01-05 09:37 . 2008-10-22 11:09 86016 —-a-w- c:\program files\setupenne.dll
    2011-12-30 14:08 . 2011-12-30 14:08 1402880 —-a-w- c:\program files\HiJackThis.msi
    2011-12-26 07:01 . 2011-12-26 07:01 21073936 —-a-w- c:\program files\vlc-1.1.11-win32.exe
    2011-10-18 16:51 . 2011-10-18 16:51 3687352 —-a-w- c:\program files\PMB.lnk
    2011-04-10 12:06 . 2011-04-10 12:06 20586196 —-a-w- c:\program files\vlc-1.1.8-win32.exe
    2011-04-10 12:03 . 2011-02-19 15:31 20364702 —-a-w- c:\program files\vlc-1.1.7-win32.exe
    2011-01-29 06:52 . 2011-01-29 06:52 200442456 —-a-w- c:\program files\vegaspro100c_32bit.exe
    2011-01-27 18:35 . 2011-01-27 18:35 1364522 —-a-w- c:\program files\wrar393.exe
    2011-01-16 09:27 . 2011-01-16 09:26 150446976 —-a-w- c:\program files\AVSVideoEditor.exe
    2011-01-12 02:33 . 2011-01-12 02:33 11008549 —-a-w- c:\program files\avidemux_2.5.4_win32.exe
    2011-01-11 17:21 . 2011-01-11 17:20 62701672 —-a-w- c:\program files\AVSVideoConverter.exe
    2010-12-30 16:59 . 2010-12-30 16:58 19985265 —-a-w- c:\program files\vlc-1.1.5-win32.exe
    2010-12-14 19:22 . 2010-12-14 19:22 338760 —-a-w- c:\program files\RegtaskTool_Installer.exe
    2010-12-11 07:22 . 2010-12-11 07:21 25188112 —-a-w- c:\program files\setpoint620.exe
    2010-12-08 18:15 . 2008-10-20 17:25 9039288 —-a-w- c:\program files\Vuze_Installer.exe
    2010-12-04 11:27 . 2010-07-04 06:54 13454568 —-a-w- c:\program files\RegistryReviverSetup.exe
    2010-08-29 11:47 . 2009-04-29 16:04 44089904 —-a-w- c:\program files\avira_antivir_personal_en.exe
    2010-08-29 11:37 . 2010-08-29 11:37 44153664 —-a-w- c:\program files\avira_antivir_personal_de.exe
    2010-08-29 11:23 . 2010-08-29 11:23 3427712 —-a-w- c:\program files\ccsetup235.exe
    2010-08-05 17:43 . 2010-08-05 17:43 3420304 —-a-w- c:\program files\ccsetup234.exe
    2010-03-20 17:37 . 2010-03-20 17:37 1103048 —-a-w- c:\program files\wpsetup.exe
    2010-03-12 12:28 . 2010-03-12 12:28 34506392 —-a-w- c:\program files\Nokia_PC_Suite_dut_web.exe
    2010-03-12 10:46 . 2010-03-12 10:39 98366952 —-a-w- c:\program files\Nokia_Ovi_Suite_webinstaller_ALL.exe
    2010-01-02 22:50 . 2009-10-16 05:08 13731712 —-a-w- c:\program files\AVSRegistryCleaner.exe
    2009-12-25 11:22 . 2009-12-25 11:22 6113439 —-a-w- c:\program files\pci_filerecovery.exe
    2009-10-25 11:52 . 2009-10-25 11:52 77086488 —-a-w- c:\program files\Ad-AwareInstallation.exe
    2009-09-02 18:54 . 2009-09-02 18:54 74160 —-a-w- c:\program files\irfanview_lang_nederlands.exe
    2009-09-02 18:52 . 2009-09-02 18:52 1359360 —-a-w- c:\program files\iview425_setup.exe
    2009-08-30 09:17 . 2009-08-30 09:16 3293088 —-a-w- c:\program files\ccsetup223.exe
    2009-05-28 18:34 . 2009-05-28 18:34 5076056 —-a-w- c:\program files
    uvi760_480.exe
    2009-03-22 12:11 . 2009-03-22 12:11 4310568 —-a-w- c:\program files\WebUpdater_241.exe
    2009-03-14 08:06 . 2009-03-14 08:06 37452296 —-a-w- c:\program files\Ad-AwareAE.exe
    2008-12-21 11:12 . 2008-12-21 11:11 5797488 —-a-w- c:\program files\GOMPLAYERENSETUP.EXE
    2008-12-21 08:57 . 2008-12-21 08:57 27288880 —-a-w- c:\program files\QuickTimeInstaller.exe
    2008-12-21 08:49 . 2008-12-21 08:49 12349806 —-a-w- c:\program files\dvdflick_setup_1.3.0.4.exe
    2008-11-30 11:51 . 2008-10-06 07:04 15083520 —-a-w- c:\program files\spybotsd160.exe
    2008-11-23 14:14 . 2008-10-02 17:20 25129080 —-a-w- c:\program files\antivir_workstation_winu_en_h.exe
    2008-11-23 12:02 . 2008-11-23 12:02 1958864 —-a-w- c:\program files\TrendMicro_Downloader.exe
    2008-11-11 14:44 . 2008-11-11 14:44 860391 —-a-w- c:\program files\7z457.exe
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-05-15_06.26.10 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-06-10 23:58 . 2011-06-10 23:58 51024 c:\windows\system32\vcomp100.dll
    + 2008-04-15 12:00 . 2012-05-16 11:14 84980 c:\windows\system32\perfc013.dat
    + 2008-04-15 12:00 . 2012-05-16 11:14 66748 c:\windows\system32\perfc009.dat
    + 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100u.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 60752 c:\windows\system32\mfc100rus.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 60752 c:\windows\system32\mfc100rus.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 43344 c:\windows\system32\mfc100kor.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 43344 c:\windows\system32\mfc100kor.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 43856 c:\windows\system32\mfc100jpn.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 43856 c:\windows\system32\mfc100jpn.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 62288 c:\windows\system32\mfc100ita.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 62288 c:\windows\system32\mfc100ita.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100fra.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 64336 c:\windows\system32\mfc100fra.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 63824 c:\windows\system32\mfc100esn.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 63824 c:\windows\system32\mfc100esn.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 55120 c:\windows\system32\mfc100enu.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 55120 c:\windows\system32\mfc100enu.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 64336 c:\windows\system32\mfc100deu.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100deu.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 36176 c:\windows\system32\mfc100cht.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100cht.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 36176 c:\windows\system32\mfc100chs.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100chs.dll
    + 2008-04-15 12:00 . 2012-05-16 11:14 496558 c:\windows\system32\perfh013.dat
    + 2008-04-15 12:00 . 2012-05-16 11:14 429990 c:\windows\system32\perfh009.dat
    + 2011-06-10 23:58 . 2011-06-10 23:58 773968 c:\windows\system32\msvcr100.dll
    - 2010-03-18 08:15 . 2010-03-18 08:15 421200 c:\windows\system32\msvcp100.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 421200 c:\windows\system32\msvcp100.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 138056 c:\windows\system32\atl100.dll
    + 2012-05-15 17:58 . 2012-05-15 17:58 160768 c:\windows\Installer\1a330d.msi
    + 2011-06-10 23:58 . 2011-06-10 23:58 4422992 c:\windows\system32\mfc100u.dll
    + 2011-06-10 23:58 . 2011-06-10 23:58 4397384 c:\windows\system32\mfc100.dll
    + 2011-06-28 19:27 . 2011-06-28 19:27 4028928 c:\windows\Installer\22a46f.msp
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS5\Bridge.exe" [2011-06-09 12002664]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinPatrol"="c:\progra~1\BILLPS~1\WINPAT~1\winpatrol.exe" [2005-09-26 222784]
    "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
    "NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
    "nwiz"="c:\program files\NVIDIA Corporation
    view
    wiz.exe" [2012-02-29 1634112]
    "Driver Update and remove for Windows x64 or x86_32"="c:\program files\Realtek\Audio\Drivers\RtlUpd.exe" [2011-08-29 1493608]
    "@OnlineArmor GUI"="c:\program files\Online Armor\OAui.exe" [2012-02-10 2645440]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLinkedConnections"= 1 (0x1)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2012-02-10 359352]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
    otify\LBTWlgn]
    2010-10-28 10:13 64592 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
    "c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Avira\\AntiVir Desktop\\avscan.exe"=
    "c:\\Program Files\\Vuze\\Azureus.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\system32\\mshta.exe"=
    "c:\\Documents and Settings\\paul\\Local Settings\\Application Data\\Akamai\
    etsession_win.exe"=
    "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
    "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
    "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
    "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
    .
    R0 hotcore;hotcore;c:\windows\system32\drivers\hotcore.sys [4/10/2008 13:21 30820]
    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/10/2008 20:41 717296]
    R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [2/12/2010 20:22 752128]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [15/05/2012 23:45 205864]
    R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [15/05/2012 23:45 42152]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [15/05/2012 23:45 25192]
    R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [15/05/2012 23:45 29464]
    R2 afcdpsrv;Acronis Nonstop Backup-service ;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [29/12/2010 15:42 3246040]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [22/05/2009 19:54 136360]
    R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [11/12/2010 9:22 10448]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [14/03/2012 10:51 2348352]
    R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [15/05/2012 23:45 208472]
    R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [15/03/2011 14:44 428384]
    R2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [15/05/2012 23:45 4369208]
    R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [29/12/2010 15:42 167968]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate1c9c7b35e2a82cc;Google Update Service (gupdate1c9c7b35e2a82cc);c:\program files\Google\Update\GoogleUpdate.exe [28/04/2009 5:42 133104]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [17/04/2012 9:36 257696]
    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [7/05/2012 8:42 1691480]
    S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\gsvr.exe [3/10/2008 0:16 55816]
    S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [28/04/2009 5:42 133104]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [24/08/2010 19:30 40912]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [24/08/2010 19:30 10448]
    S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 14:37 517096]
    S4 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [15/04/2008 14:00 14336]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Akamai REG_MULTI_SZ Akamai
    .
    Inhoud van de 'Gedeelde Taken' map
    .
    2012-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 09:36]
    .
    2012-05-16 c:\windows\Tasks\AdobeAAMUpdater-1.0-STILLEPC-paul.job
    - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-22 02:44]
    .
    2011-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
    .
    2012-05-15 c:\windows\Tasks\DriverNavigator Scheduled Scan.job
    - c:\program files\Easeware\DriverNavigator\DriverNavigator.exe [2012-05-07 16:56]
    .
    2012-05-15 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-05 07:23]
    .
    2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cce185a38be5ba.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd08544131963a.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-28 03:42]
    .
    2012-05-16 c:\windows\Tasks\User_Feed_Synchronization-{1CD3A718-4B83-444F-9C3D-CB870A64AC95}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
    .
    .
    ——- Bijkomende Scan ——-
    .
    uStart Page = hxxp://www.tijd.be/home
    uInternet Settings,ProxyOverride = *.local
    IE: PDF in Word openen (PDF Converter 3.0) - c:\program files\ScanSoft\PDF Professional 3.0\IEShellExt.dll /700
    TCP: DhcpNameServer = 192.168.1.1
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
    DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://sligachanhotel.remotemanager.co.uk/common/activex/MJPEGRender.ocx
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-05-16 13:45
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scannen van verborgen processen …
    .
    scannen van verborgen autostart items …
    .
    scannen van verborgen bestanden …
    .
    Scan succesvol afgerond
    verborgen bestanden: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
    "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_d76cf65.dll"
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
    "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_d76cf65.dll"
    .
    ——————— DLLs Geladen Onder Lopende Processen ———————
    .
    - - - - - - - > 'winlogon.exe'(776)
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    .
    - - - - - - - > 'explorer.exe'(1472)
    c:\program files\NVIDIA Corporation
    view
    view.dll
    c:\program files\NVIDIA Corporation
    view\NVWRSNL.DLL
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\msi.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Voltooingstijd: 2012-05-16 13:49:22
    ComboFix-quarantined-files.txt 2012-05-16 11:49
    ComboFix2.txt 2012-05-15 06:28
    ComboFix3.txt 2011-12-31 10:24
    .
    Pre-Run: 206.958.080.000 bytes beschikbaar
    Post-Run: 206.949.658.624 bytes beschikbaar
    .
    - - End Of File - - FDFD67F298950A953C1BE0A5D6998446




















































  • Nu moet eerst iets geregeld gaan worden.
    Waarom?
    Twee geïnstalleerde antivirusprogramma's, te weten:
    AVG Free 2012
    Avira Antivir 2012.

    Dat is één antivirusprogramma teveel, het beveiligingsniveau zal zeer laag zijn, vooral ook omdat AVG zeer aggressief is naar ander andere antivirussoftware.
    Overigens: Windows zelf zal ook last hebben van de onderlinge conflicten.
    Laat weten welk van de twee eruit moet.

Beantwoord deze vraag

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.