Op deze website gebruiken we cookies om content en advertenties te personaliseren, om functies voor social media te bieden en om ons websiteverkeer te analyseren. Ook delen we informatie over uw gebruik van onze site met onze partners voor social media, adverteren en analyse. Deze partners kunnen deze gegevens combineren met andere informatie die u aan ze heeft verstrekt of die ze hebben verzameld op basis van uw gebruik van hun services. Meer informatie.

Akkoord

Vraag & Antwoord

Beveiliging & privacy

ongewenste toolbars in HJT te zien

Anoniem
Abraham54
10 antwoorden
  • Af en toe doe ik een HJT controle. Dit keer zag ik (minstens) 2 ongevraagde en ongewenste toolbars, waarbij ik dacht dat ik searchqu had verwijderd. nee dus? En die onder "03" daarvan vertrouw ik die "noname" ook niet.

    Hierbij alvast een logje:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 13:23:39, on 4-10-2012
    Platform: Windows 7 SP1 (WinNT 6.00.3505)
    MSIE: Internet Explorer v9.00 (9.00.8112.16450)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
    C:\Program Files\MailWasher Pro\MailWasher.exe
    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nl.msn.com/?ocid=OIE9HP
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com/406
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
    O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
    O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
    O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
    O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
    O4 - HKCU\..\Run: [MailWasher] C:\PROGRA~1\MAILWA~1\MAILWA~1.EXE
    O4 - Startup: MailWasher.lnk = C:\Program Files\Firetrust\MailWasher\MailWasher.exe
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O20 - AppInit_DLLs:
    O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
    O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\Ultimate\AppData\Local\CrossLoop\CrossLoopService.exe
    O23 - Service: EaseUS Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
    O23 - Service: Guard Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe
    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - Unknown owner - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    O23 - Service: uvnc_service - UltraVNC - C:\Users\Ultimate\AppData\Local\CrossLoop\winvnc.exe


    End of file - 5452 bytes

    in eerste instantie en bij voorbaat alvast hartelijk dank!
  • We gaan kijken:

  • ADW cleaner kon ik alleen afsluiten door opnieuw te laten draaien in V.M. ; een logje heb ik niet meer maar er waren geen ongeoorloofde bestanden te zien. Hier volgt het log van de MBAM:
    Malwarebytes Anti-Malware 1.65.0.1400
    www.malwarebytes.org

    Databaseversie: v2012.10.04.09

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Ultimate :: ULTIMATE-PC [administrator]

    4-10-2012 18:52:18
    mbam-log-2012-10-04 (18-52-18).txt

    Scantype: Snelle scan
    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scanopties: P2P
    Objecten gescand: 187141
    Verstreken tijd: 3 minuut/minuten, 51 seconde(n)

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    ———
    Zelf doe ik ook al met regelmaat MBAM, Ccleaner en Eset online scan. Ben benieuwd.!
  • het logo van Adw Cleaner deed mij denken aan een teek die ik eergisteren oogstte, maar dit terzijde:
    [img:7f566f17b8]http://i50.tinypic.com/kn8sp.jpg[/img:7f566f17b8]
  • Vergelijkbaar dus met unwanted sofware in Windows!

    Dan gaan we uitgebreider op zoek:

    [b:f19aa6c047]Welk programma[/b:f19aa6c047]:
  • hier het OTL:
    OTL logfile created on: 4-10-2012 20:29:21 - Run 1
    OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Ultimate\Desktop
    Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

    3,25 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 77,88% Memory free
    6,50 Gb Paging File | 5,34 Gb Available in Paging File | 82,20% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 232,79 Gb Total Space | 190,43 Gb Free Space | 81,80% Space Free | Partition Type: NTFS
    Drive X: | 465,73 Gb Total Space | 211,66 Gb Free Space | 45,45% Space Free | Partition Type: NTFS
    Drive Z: | 298,09 Gb Total Space | 239,69 Gb Free Space | 80,41% Space Free | Partition Type: NTFS

    Computer Name: ULTIMATE-PC | User Name: Ultimate | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

  • Hoi, kijk hier: http://www.sevenforums.com/software/138171-uimbus-uim_im-drivers.html voor de foutmeldingen: [b:3719b7cd29]Error - 13-8-2012 2:54:24 | Computer Name = Ultimate-PC | Source = Service Control Manager | ID = 7026
    Description = De volgende opstartstuurprogramma's zijn niet geladen: UimBus Uim_IM Uim_Vim[/b:3719b7cd29]


    [b:3719b7cd29]Sluit voordat
  • hier komt ie:
    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
    C:\ProgramData\xml3CC9.tmp deleted successfully.
    C:\ProgramData\xml3DF3.tmp deleted successfully.
    C:\ProgramData\xml3E81.tmp deleted successfully.
    C:\ProgramData\xml3F0E.tmp deleted successfully.
    C:\ProgramData\xml443B.tmp deleted successfully.
    C:\ProgramData\xml44B9.tmp deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleCrashHandler.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleCrashHandler64.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleUpdate.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleUpdateBroker.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleUpdateHelper.msi deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleUpdateOnDemand.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\GoogleUpdateSetup.exe deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdate.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_am.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ar.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_bg.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_bn.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ca.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_cs.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_da.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_de.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_el.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_en-GB.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_en.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_es-419.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_es.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_et.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_fa.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_fi.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_fil.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_fr.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_gu.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_hi.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_hr.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_hu.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_id.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_is.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_it.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_iw.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ja.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_kn.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ko.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_lt.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_lv.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ml.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_mr.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ms.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_nl.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_no.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_pl.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_pt-BR.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_pt-PT.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ro.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ru.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_sk.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_sl.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_sr.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_sv.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_sw.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ta.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_te.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_th.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_tr.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_uk.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_ur.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_vi.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_zh-CN.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\goopdateres_zh-TW.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp
    pGoogleUpdate3.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\psmachine.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp\psuser.dll deleted successfully.
    C:\Program Files\GUME2F5.tmp folder deleted successfully.
    C:\Program Files\GUTE2F6.tmp deleted successfully.
    ADS C:\ProgramData\TEMP:07BF512B deleted successfully.
    ADS C:\ProgramData\TEMP:C31F31E6 deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========

  • Hoe gaat het nu?
  • ik zag met HJT dat de rommel weg is. Voor mij mag je 30 april een lintje krijgen. Hartelijk dank. f.j.s.
    p.s. klachten had ik niet maar ik heb een hekel aan toolbars, vooral als ze niet te de-installeren zijn.

Beantwoord deze vraag

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.