Mededeling

Collapse
No announcement yet.

PC denkt geregeld 5 tot 10 minuten na.

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • PC denkt geregeld 5 tot 10 minuten na.

    Beste lezer,

    Ik heb al enig contact gehad en uiteindelijk het advies gekregen bij ‘Hulp bij virusinfectie’ een oproep te doen.

    Het behandelde gedeelte is te vinden via:
    http://www.nucia.eu/forum/threads/71...478#post689478

    MBAM-logje:
    Malwarebytes Anti-Malware 1.75.0.1300
    www.malwarebytes.org

    Databaseversie: v2013.12.11.01

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 11.0.9600.16428
    Mitchell Eestermans :: PC_VAN_MITCHELL [administrator]

    11-12-2013 8:55:27
    mbam-log-2013-12-11 (08-55-27).txt

    Scan type: Snelle scan
    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
    Uitgeschakelde scan opties: P2P
    Objecten gescand: 288817
    Verstreken tijd: 21 minuut/minuten, 34 seconde(n)

    Geheugenprocessen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0
    (Geen kwaadaardige objecten gedetecteerd)

    (einde)
    De negeerlijst van MBAM:


    DDS.txt-log:
    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.45.2
    Run by Mitchell Eestermans at 9:30:39 on 2013-12-11
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3574.2360 [GMT 1:00]
    .
    AV: COMODO Antivirus *Enabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: COMODO Antivirus *Enabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275}
    FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
    .
    ============== Running Processes ================
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Program Files\HitmanPro.Alert\hmpalert.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\EscSvc.exe
    C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
    C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\COMODO\COMODO Internet Security\cis.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\DllHost.exe
    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.nl/
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
    BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
    BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - c:\program files\wot\WOT.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
    TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
    TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
    uRun: c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [fssui] "c:\program files\windows live\family safety\fsui.exe" -autorun
    mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
    mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
    mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    uPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    mPolicies-System: EnableSecureUIAPath = dword:1
    IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
    IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
    DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 192.168.2.254 195.121.1.34 195.121.1.66
    TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754} : DHCPNameServer = 192.168.2.254 195.121.1.34 195.121.1.66
    TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754}\3585535313346433431434 : DHCPNameServer = 192.168.2.1
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2013-6-18 20072]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2013-6-18 582936]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2013-6-18 44752]
    R1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\trusteer\rapport\store\exts\rapportcerber us\baseline\RapportCerberus32_51755.sys [2013-6-24 317112]
    R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]
    R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50RP7.EXE [2013-11-12 142432]
    R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\escsvc.exe [2013-9-19 122000]
    R2 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-5 39272]
    R2 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
    R2 hmpalert;HitmanPro.Alert Service;c:\program files\hitmanpro.alert\hmpalert.exe [2013-6-25 531304]
    R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2013-8-27 93072]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
    R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 379904]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 cleanhlp;cleanhlp;c:\eek\run\cleanhlp32.sys [2013-12-10 50200]
    S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2013-6-18 131288]
    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-2-6 83864]
    S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;c:\windows\system32\drivers\aabed2.sys [2008-3-20 23040]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-7-21 36608]
    S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2013-11-26 108032]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-10-31 14848]
    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-2-6 181784]
    S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudobex.sys [2013-2-6 181912]
    S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [2012-10-20 181344]
    S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-10-31 49664]
    S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2011-7-1 1343400]
    S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
    .
    =============== Created Last 30 ================
    .
    2013-12-11 07:35:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{84F111E7-B4B3-4B35-9F87-991BEBB4A229}
    2013-12-10 15:23:22 -------- d-----w- c:\program files\E Dev
    2013-12-10 08:26:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple Computer
    2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
    2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
    2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
    2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
    2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
    2013-12-10 07:49:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple
    2013-12-10 07:37:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{FAEE061F-479A-4226-8ED7-E421A6EC6409}
    2013-12-09 15:09:03 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{5F02128A-8AF4-477B-826A-E11FFB8290E5}
    2013-12-09 12:09:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{D2B8CDFA-EA15-480B-A944-0E6D346597D1}
    2013-12-07 13:36:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{9803BFC5-5CD0-4594-9F48-29F54D3FE2D2}
    2013-12-06 14:26:09 49940480 ----a-w- c:\program files\GUT2675.tmp
    2013-12-06 14:26:09 -------- d-----w- c:\program files\GUM2674.tmp
    2013-12-06 13:37:58 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1C9682D0-67D4-44BA-A733-BFEC4F72CF56}
    2013-12-05 12:54:32 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{73979CEC-0939-4BCC-B8E9-41F4817E9A21}
    2013-12-04 15:05:18 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{57D3C24D-C68E-4CB5-943A-E4A967BA4B4F}
    2013-12-03 12:31:16 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{6FB3F830-E35C-4033-ABC1-1A69E2211C9B}
    2013-12-02 12:04:41 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{778D2D48-AF4B-44D2-8AB2-91C8319A2CCE}
    2013-12-01 10:37:15 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{71BD9142-31C9-4AAF-83CF-9235EBC7866C}
    2013-11-28 14:52:39 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{E52CDF33-5CB4-473A-821C-C71CAAA0E12E}
    2013-11-27 13:19:29 -------- d-----w- c:\windows\Migration
    2013-11-27 12:16:52 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{05826281-EFDC-4E7C-847B-4B9A15D78897}
    2013-11-26 18:03:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\AdTrustMedia
    2013-11-26 12:00:33 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DE1D39EC-7942-4948-A7A3-91A962C9D9D3}
    2013-11-25 10:16:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{78175844-B8E7-4394-BFE7-71E82461BADF}
    2013-11-22 10:28:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{00C60EFC-D400-44C3-BB3D-E463BD16C126}
    2013-11-21 10:39:44 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{3AB91603-FCE2-45E7-B9A5-457707DFEC2B}
    2013-11-20 10:42:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{671FBA8D-E5FE-474E-ACE8-FC4E4119C23C}
    2013-11-19 11:52:11 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{8B3D4FFB-CF22-4BF6-BB79-5ED98EADA4D6}
    2013-11-18 12:46:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DBE2DE66-C2DF-4FDC-BA3E-BA7107EA6FA2}
    2013-11-17 13:43:21 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{844CFF49-7C86-439D-9114-B26156FFFA03}
    2013-11-16 11:48:53 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{11B3AA79-F2C1-4971-96BF-F006DEF961EA}
    2013-11-15 10:31:49 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{470D2AA2-6197-46FF-B3E9-6DE579C5AF46}
    2013-11-14 17:35:05 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{BF4A555C-7C87-4140-9C7B-5C8C76777FFE}
    2013-11-13 12:04:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1F8E39CA-F70D-4B90-BC7A-E3DF96B9BB63}
    2013-11-12 17:24:24 -------- d-----w- c:\programdata\Adtrustmedia
    2013-11-12 10:09:55 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
    2013-11-12 10:09:52 81408 ----a-w- c:\windows\system32\E_FD4BIJE.DLL
    2013-11-12 09:50:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{A59A68FE-FFFB-441C-BD64-BBE8D8F06FDE}
    2013-11-11 10:03:54 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{651D125B-0BE6-4C70-8B5A-4507B6BF966D}
    .
    ==================== Find3M ====================
    .
    2013-11-14 11:38:16 582936 ----a-w- c:\windows\system32\drivers\cmdguard.sys
    2013-11-14 11:38:01 36000 ----a-w- c:\windows\system32\cmdcsr.dll
    2013-11-07 13:17:49 24064 ----a-w- c:\windows\zoek-delete.exe
    2013-10-18 12:35:59 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-10-12 02:03:08 656896 ----a-w- c:\windows\system32\nshwfp.dll
    2013-10-12 02:01:41 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
    2013-10-12 02:01:25 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
    2013-10-09 14:40:35 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-10-09 14:40:35 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-10-05 19:57:25 1168384 ----a-w- c:\windows\system32\crypt32.dll
    2013-10-04 01:58:50 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
    2013-10-04 01:56:25 168960 ----a-w- c:\windows\system32\credui.dll
    2013-10-04 01:56:00 1796096 ----a-w- c:\windows\system32\authui.dll
    2013-10-03 01:58:07 305152 ----a-w- c:\windows\system32\gdi32.dll
    2013-09-25 02:01:08 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
    2013-09-25 02:01:06 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2013-09-25 01:57:46 99840 ----a-w- c:\windows\system32\sspicli.dll
    2013-09-25 01:57:26 22016 ----a-w- c:\windows\system32\secur32.dll
    2013-09-25 01:57:24 247808 ----a-w- c:\windows\system32\schannel.dll
    2013-09-25 01:56:42 220160 ----a-w- c:\windows\system32\ncrypt.dll
    2013-09-25 01:56:02 1038848 ----a-w- c:\windows\system32\lsasrv.dll
    2013-09-25 00:49:20 22016 ----a-w- c:\windows\system32\lsass.exe
    2013-09-25 00:49:18 15872 ----a-w- c:\windows\system32\sspisrv.dll
    2013-09-24 10:54:08 44752 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
    2013-09-24 10:54:07 20072 ----a-w- c:\windows\system32\drivers\cmderd.sys
    2013-09-24 10:53:51 354240 ----a-w- c:\windows\system32\guard32.dll
    2013-09-24 10:53:35 280792 ----a-w- c:\windows\system32\cmdvrt32.dll
    2013-09-24 10:53:34 40664 ----a-w- c:\windows\system32\cmdkbd32.dll
    2013-09-14 00:48:58 338944 ----a-w- c:\windows\system32\drivers\afd.sys
    .
    ============= FINISH: 9:36:00,51 ===============

    Gmer-log:

    Aangezien deze te groot is (De ingevoerde tekst is te lang (182544 tekens). Verkort de tekst tot maximaal 50000 tekens.) Kan ik deze hier niet plakken. Mocht dit toch nodig zijn, dan hoor ik het graag en ook hoe.

    Tijdens de Gmer-scan is de pc wel een keer of drie aan het slapen geweest. Dit heb ik bij de andere scans niet opgemerkt.

    Ik hoop dat ik via deze weg geholpen kan worden.

    In ieder geval alvast bedankt.

    Groet,

    Kidaatje.

  • #2
    Hoi Kidaatje en welkom op Nucia Security Forum,

    Voor we beginnen , wil ik even vriendelijk op de volgende richtlijnen wijzen:
    .
    • Log enkel in als beheerder met alle rechten.
    • Post je probleem niet in verscheidene fora. het komt je probleem niet ten goede en het is niet netjes tegenover de helpers.
    • Het opruimen van je systeem kan wat tijd in beslag nemen, wees geduldig.
    • Volg aandachtig de instructies die door mij worden gegeven.
    • Volg enkel het door mij gegeven advies op
    • Blijf bij het topic totdat ik gemeldt heb dat je PC clean is.
    • Als je iets niet weet of verstaat, vraag het dan even aub.
    • Installeer of deinstalleer géén software of hardware terwijl we met je probleem bezig zijn.
    • Ga ondertussen niet wat "anders" proberen, dat maakt het alleen maar moeilijker voor ons
    • Zet je emoticons (Smileys) uit als je logs plaatst aub .
    • De logs niet als bijlage, noch tussen codetags zetten aub.

    .
    Opmerking: Vista of Windows 7 ? >> Alle tools steeds uitvoeren als admin.
    De instructies die worden gegeven, zijn enkel geldig voor jouw PC.

    Stap 1:

    Malware scannen en verwijderen....

    Start MBAM
    Zodra het programma gestart is, ga je naar het tabblad "Instellingen"
    .
    • Vink hier aan: "Sluit Internet Explorer tijdens verwijdering van malware".
    • Ga naar het tabblad "Updates" en Update MBAM.
    • Ga daarna naar het tabblad "Scanner", kies hier voor "VOLLEDIGE Scan".
    • Druk vervolgens op "Scannen" om de scan te starten.
    • Het scannen kan een tijdje duren, dus wees geduldig.
    • Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.
    • Zorg ervoor dat daar alles aangevinkt is, daarna klik op: "Verwijder geselecteerde".
      Indien het veel items zijn, kan je in het venster rechtsklikken en "alle items selecteren" kiezen.
    • Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten.

    .
    Indien MBAM vraagt om een herstart, doe dit dan ook.
    Wanneer je de restart hebt gedaan, maak je een nieuwe snelle scan met MBAM.
    In dat geval post je dus de twee logs.

    De log wordt automatisch bewaard door MalwareBytes' Anti-Malware en kan je terugvinden door op de "Logs" tab te klikken in het programma.


    Bij problemen!!!
    .
    .
    ___________________________________________________________

    Stap 2:

    Controle op slechte toolbars...

    Download AdwCleaner by Xplode naar je Bureaublad.
    • Sluit alle openstaande vensters
    • Start AdwCleaner
    • Klik op Scan
    • Klik op Clean
    • KLIK HIER voor een vergroting! 

    Alle icoontjes verdwijnen van het Bureaublad,dit is normaal
    Je PC word opnieuw opgestart en er een opent logfile (C:\ AdwCleaner[xx].txt post de inhoud hier op het Forum.

    Enkel de log na de "clean" optie heb ik nodig.

    Vergeet niet om je "smileys" uit te schakelen.

    Als je Startpagina ook gehijackt was,stel dan de zoekmachine opnieuw in,deze word standaard door AdwCleaner terug gezet naar Google.com

    ___________________________________________________________

    Stap 3:

    Download DDS.com, DDS.scr of DDS.pif van één van deze locaties en plaats het op je bureaublad:


    DDS is een diagnosetool en maakt gebruik van scripts.
    Is het uitvoeren van scripts uitgeschakeld, dan schakel je dit weer in zodat er geen problemen optreden bij gebruik van DDS.


    Dubbelklik op DDS om de tool te starten. (afhankelijk van de download die je gekozen hebt kan dit het bestand DDS.com, DDS.scr of DDS.pif zijn)
    Wanneer het klaar is openen er twee logfiles: DDS.txt en Attach.txt
    Beide logfiles sla je op je bureaublad.

    Post de inhoud van DDS.txt.

    De inhoud Attach.txt moet je niet posten en Attach.txt moet je niet als bijlage toevoegen aan je post, tenzij ik er om vraag.

    ___________________________________________________________

    Stap 4:

    Controle op updates...

    Download Security Check op je bureaublad via hier of hier

    Start Security Check
    Volg de Instructies in het scherm
    Aan het eind verschijnt een log ( checkup.txt )
    Plaats de inhoud ervan in je volgende antwoord.

    In je volgende posting, had ik graag de volgende logs gezien, gemaakt in de opgestelde volgorde:
    .
    • MBAM
    • AdwCleaner
    • DDS
    • checkup.txt

    .
    Deze logs NIET als bijlage of tussen codetags posten aub.
    (Desnoods in meerdere postingen.)


    Emphyrio
    Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
    E Dev * McAfee verwijderen. * Ccleaner * E-Peek

    Comment


    • #3
      Hey Emphyrio,

      Hierbij alvast de MBAM-logjes:

      1e / met nog 2 detecties (volledige scan):
      Malwarebytes Anti-Malware 1.75.0.1300
      www.malwarebytes.org

      Databaseversie: v2013.12.11.02

      Windows 7 Service Pack 1 x86 NTFS
      Internet Explorer 11.0.9600.16428
      Mitchell Eestermans :: PC_VAN_MITCHELL [administrator]

      11-12-2013 11:14:17
      mbam-log-2013-12-11 (11-14-17).txt

      Scan type: Volledige scan (C:\|)
      Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
      Uitgeschakelde scan opties: P2P
      Objecten gescand: 440014
      Verstreken tijd: 1 uur/uren, 45 minuut/minuten, 14 seconde(n)

      Geheugenprocessen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Geheugenmodulen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registersleutels gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registerwaarden gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registerdata gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Mappen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Bestanden gedetecteerd: 2
      C:\zoek_backup\C_Users_Mitchell Eestermans_AppData_Roaming_OpenCandy\E6A2F5D25D864C9CB37E752EB911D811\Findr_ALL_p1v2.exe (PUP.Optional.Conduit.A) -> Succesvol in quarantaine geplaatst en verwijderd.
      C:\zoek_backup\C_Users_Mitchell Eestermans_AppData_Roaming_OpenCandy\ED0CB0F9E155467DB3BB3FD2ACDE4572\LatestDLMgr.exe (PUP.Optional.OpenCandy.A) -> Succesvol in quarantaine geplaatst en verwijderd.

      (einde)


      2e / schone (snelle scan):
      Malwarebytes Anti-Malware 1.75.0.1300
      www.malwarebytes.org

      Databaseversie: v2013.12.11.02

      Windows 7 Service Pack 1 x86 NTFS
      Internet Explorer 11.0.9600.16428
      Mitchell Eestermans :: PC_VAN_MITCHELL [administrator]

      11-12-2013 13:15:28
      mbam-log-2013-12-11 (13-15-28).txt

      Scan type: Snelle scan
      Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
      Uitgeschakelde scan opties: P2P
      Objecten gescand: 289173
      Verstreken tijd: 10 minuut/minuten, 34 seconde(n)

      Geheugenprocessen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Geheugenmodulen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registersleutels gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registerwaarden gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Registerdata gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Mappen gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      Bestanden gedetecteerd: 0
      (Geen kwaadaardige objecten gedetecteerd)

      (einde)

      Straks ga ik verder met de rest van jouw opdrachtlijstje.

      Groet,

      Kidaatje.

      Comment


      • #4
        Emphyrio,

        Hierbij de AdwCleaner-log:

        # AdwCleaner v3.015 - Report created 11/12/2013 at 16:06:00
        # Updated 10/12/2013 by Xplode
        # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
        # Username : Mitchell Eestermans - PC_VAN_MITCHELL
        # Running from : C:\Users\Mitchell Eestermans\Desktop\PC Probleem\adwcleaner.exe
        # Option : Clean

        ***** [ Services ] *****


        ***** [ Files / Folders ] *****


        ***** [ Shortcuts ] *****


        ***** [ Registry ] *****

        [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E237D93-A34A-4BC9-B655-4A9E09F61BEF}
        [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E237D93-A34A-4BC9-B655-4A9E09F61BEF}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
        Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
        Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
        Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
        Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
        Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3240727
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
        Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
        Key Deleted : HKCU\Software\APN
        Key Deleted : HKCU\Software\Ask.com
        Key Deleted : HKCU\Software\Conduit
        Key Deleted : HKCU\Software\Myfree Codec
        Key Deleted : HKCU\Software\YahooPartnerToolbar
        Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
        Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
        Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
        Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
        Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
        Key Deleted : HKLM\Software\APN
        Key Deleted : HKLM\Software\AskToolbar
        Key Deleted : HKLM\Software\Conduit
        Key Deleted : HKLM\Software\Myfree Codec
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
        Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
        Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
        Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
        Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1 C9

        ***** [ Browsers ] *****

        -\\ Internet Explorer v11.0.9600.16428


        -\\ Google Chrome v

        [ File : C:\Users\Mitchell Eestermans\AppData\Local\Google\Chrome\User Data\Default\preferences ]

        Deleted : icon_url
        Deleted : search_url
        Deleted : suggest_url
        Deleted : keyword

        [ File : C:\Users\Danley Eestermans\AppData\Local\Google\Chrome\User Data\Default\preferences ]


        *************************

        AdwCleaner[R0].txt - [7504 octets] - [11/12/2013 16:02:52]
        AdwCleaner[S0].txt - [7550 octets] - [11/12/2013 16:06:00]

        ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7610 octets] ##########

        Ik moest trouwens wel Comodo uitzetten, want deze zag de download van AdwCleaner als malware.

        Ik ga nu de DDS draaien.

        Groet,

        Kidaatje.

        Comment


        • #5
          Emphyrio,

          Hierbij de DDS.txt:

          DDS (Ver_2012-11-20.01) - NTFS_x86
          Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.45.2
          Run by Mitchell Eestermans at 16:13:17 on 2013-12-11
          Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3574.2428 [GMT 1:00]
          .
          AV: COMODO Antivirus *Disabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8}
          SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          SP: COMODO Antivirus *Disabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275}
          FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
          .
          ============== Running Processes ================
          .
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\lsm.exe
          C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
          C:\Program Files\HitmanPro.Alert\hmpalert.exe
          C:\Windows\System32\spoolsv.exe
          C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
          C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
          C:\Windows\system32\EscSvc.exe
          C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
          C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
          C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
          C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
          C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
          C:\Windows\system32\taskhost.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Windows Live\Family Safety\fsui.exe
          C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
          C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Program Files\COMODO\COMODO Internet Security\cis.exe
          C:\Windows\system32\DllHost.exe
          C:\Windows\system32\sppsvc.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\conhost.exe
          C:\Windows\system32\svchost.exe -k DcomLaunch
          C:\Windows\system32\svchost.exe -k RPCSS
          C:\Windows\system32\svchost.exe -k NetworkService
          C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
          C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
          C:\Windows\system32\svchost.exe -k LocalService
          C:\Windows\system32\svchost.exe -k netsvcs
          C:\Windows\system32\svchost.exe -k GPSvcGroup
          C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
          C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
          C:\Windows\system32\svchost.exe -k imgsvc
          C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
          C:\Windows\System32\svchost.exe -k LocalServicePeerNet
          .
          ============== Pseudo HJT Report ===============
          .
          uStart Page = hxxp://www.google.nl/
          BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
          BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
          BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
          BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
          BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - c:\program files\wot\WOT.dll
          BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
          TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
          TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
          TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
          uRun: c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe
          mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
          mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
          mRun: [Persistence] c:\windows\system32\igfxpers.exe
          mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
          mRun: [fssui] "c:\program files\windows live\family safety\fsui.exe" -autorun
          mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
          mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
          mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
          mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
          mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
          uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
          uPolicies-Explorer: NoDrives = dword:0
          mPolicies-Explorer: NoDrives = dword:0
          mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
          mPolicies-System: ConsentPromptBehaviorUser = dword:3
          mPolicies-System: EnableUIADesktopToggle = dword:0
          mPolicies-System: EnableSecureUIAPath = dword:1
          IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
          IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
          IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
          IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
          IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll
          IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
          IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
          IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
          DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
          DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
          DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
          DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
          DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          TCP: NameServer = 192.168.2.254 195.121.1.34 195.121.1.66
          TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754} : DHCPNameServer = 192.168.2.254 195.121.1.34 195.121.1.66
          TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754}\3585535313346433431434 : DHCPNameServer = 192.168.2.1
          Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
          Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
          Notify: igfxcui - igfxdev.dll
          SSODL: WebCheck - <orphaned>
          .
          ============= SERVICES / DRIVERS ===============
          .
          R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2013-6-18 20072]
          R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2013-6-18 582936]
          R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2013-6-18 44752]
          R1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\trusteer\rapport\store\exts\rapportcerber us\baseline\RapportCerberus32_51755.sys [2013-6-24 317112]
          R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]
          R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50RP7.EXE [2013-11-12 142432]
          R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\escsvc.exe [2013-9-19 122000]
          R2 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-5 39272]
          R2 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
          R2 hmpalert;HitmanPro.Alert Service;c:\program files\hitmanpro.alert\hmpalert.exe [2013-6-25 531304]
          R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2013-8-27 93072]
          R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
          R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 379904]
          S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
          S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
          S3 cleanhlp;cleanhlp;c:\eek\run\cleanhlp32.sys [2013-12-10 50200]
          S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2013-6-18 131288]
          S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-2-6 83864]
          S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;c:\windows\system32\drivers\aabed2.sys [2008-3-20 23040]
          S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-7-21 36608]
          S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2013-11-26 108032]
          S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-10-31 14848]
          S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-2-6 181784]
          S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudobex.sys [2013-2-6 181912]
          S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [2012-10-20 181344]
          S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-10-31 49664]
          S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2011-7-1 1343400]
          S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
          .
          =============== Created Last 30 ================
          .
          2013-12-11 15:02:45 -------- d-----w- C:\AdwCleaner
          2013-12-11 07:35:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{84F111E7-B4B3-4B35-9F87-991BEBB4A229}
          2013-12-10 15:23:22 -------- d-----w- c:\program files\E Dev
          2013-12-10 08:26:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple Computer
          2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
          2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
          2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
          2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
          2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
          2013-12-10 07:49:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple
          2013-12-10 07:37:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{FAEE061F-479A-4226-8ED7-E421A6EC6409}
          2013-12-09 15:09:03 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{5F02128A-8AF4-477B-826A-E11FFB8290E5}
          2013-12-09 12:09:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{D2B8CDFA-EA15-480B-A944-0E6D346597D1}
          2013-12-07 13:36:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{9803BFC5-5CD0-4594-9F48-29F54D3FE2D2}
          2013-12-06 14:26:09 49940480 ----a-w- c:\program files\GUT2675.tmp
          2013-12-06 14:26:09 -------- d-----w- c:\program files\GUM2674.tmp
          2013-12-06 13:37:58 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1C9682D0-67D4-44BA-A733-BFEC4F72CF56}
          2013-12-05 12:54:32 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{73979CEC-0939-4BCC-B8E9-41F4817E9A21}
          2013-12-04 15:05:18 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{57D3C24D-C68E-4CB5-943A-E4A967BA4B4F}
          2013-12-03 12:31:16 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{6FB3F830-E35C-4033-ABC1-1A69E2211C9B}
          2013-12-02 12:04:41 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{778D2D48-AF4B-44D2-8AB2-91C8319A2CCE}
          2013-12-01 10:37:15 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{71BD9142-31C9-4AAF-83CF-9235EBC7866C}
          2013-11-28 14:52:39 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{E52CDF33-5CB4-473A-821C-C71CAAA0E12E}
          2013-11-27 13:19:29 -------- d-----w- c:\windows\Migration
          2013-11-27 12:16:52 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{05826281-EFDC-4E7C-847B-4B9A15D78897}
          2013-11-26 18:03:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\AdTrustMedia
          2013-11-26 12:00:33 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DE1D39EC-7942-4948-A7A3-91A962C9D9D3}
          2013-11-25 10:16:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{78175844-B8E7-4394-BFE7-71E82461BADF}
          2013-11-22 10:28:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{00C60EFC-D400-44C3-BB3D-E463BD16C126}
          2013-11-21 10:39:44 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{3AB91603-FCE2-45E7-B9A5-457707DFEC2B}
          2013-11-20 10:42:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{671FBA8D-E5FE-474E-ACE8-FC4E4119C23C}
          2013-11-19 11:52:11 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{8B3D4FFB-CF22-4BF6-BB79-5ED98EADA4D6}
          2013-11-18 12:46:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DBE2DE66-C2DF-4FDC-BA3E-BA7107EA6FA2}
          2013-11-17 13:43:21 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{844CFF49-7C86-439D-9114-B26156FFFA03}
          2013-11-16 11:48:53 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{11B3AA79-F2C1-4971-96BF-F006DEF961EA}
          2013-11-15 10:31:49 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{470D2AA2-6197-46FF-B3E9-6DE579C5AF46}
          2013-11-14 17:35:05 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{BF4A555C-7C87-4140-9C7B-5C8C76777FFE}
          2013-11-13 12:04:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1F8E39CA-F70D-4B90-BC7A-E3DF96B9BB63}
          2013-11-12 17:24:24 -------- d-----w- c:\programdata\Adtrustmedia
          2013-11-12 10:09:55 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
          2013-11-12 10:09:52 81408 ----a-w- c:\windows\system32\E_FD4BIJE.DLL
          2013-11-12 09:50:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{A59A68FE-FFFB-441C-BD64-BBE8D8F06FDE}
          .
          ==================== Find3M ====================
          .
          2013-11-14 11:38:16 582936 ----a-w- c:\windows\system32\drivers\cmdguard.sys
          2013-11-14 11:38:01 36000 ----a-w- c:\windows\system32\cmdcsr.dll
          2013-11-07 13:17:49 24064 ----a-w- c:\windows\zoek-delete.exe
          2013-10-18 12:35:59 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
          2013-10-12 02:03:08 656896 ----a-w- c:\windows\system32\nshwfp.dll
          2013-10-12 02:01:41 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
          2013-10-12 02:01:25 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
          2013-10-09 14:40:35 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
          2013-10-09 14:40:35 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
          2013-10-05 19:57:25 1168384 ----a-w- c:\windows\system32\crypt32.dll
          2013-10-04 01:58:50 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
          2013-10-04 01:56:25 168960 ----a-w- c:\windows\system32\credui.dll
          2013-10-04 01:56:00 1796096 ----a-w- c:\windows\system32\authui.dll
          2013-10-03 01:58:07 305152 ----a-w- c:\windows\system32\gdi32.dll
          2013-09-25 02:01:08 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
          2013-09-25 02:01:06 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
          2013-09-25 01:57:46 99840 ----a-w- c:\windows\system32\sspicli.dll
          2013-09-25 01:57:26 22016 ----a-w- c:\windows\system32\secur32.dll
          2013-09-25 01:57:24 247808 ----a-w- c:\windows\system32\schannel.dll
          2013-09-25 01:56:42 220160 ----a-w- c:\windows\system32\ncrypt.dll
          2013-09-25 01:56:02 1038848 ----a-w- c:\windows\system32\lsasrv.dll
          2013-09-25 00:49:20 22016 ----a-w- c:\windows\system32\lsass.exe
          2013-09-25 00:49:18 15872 ----a-w- c:\windows\system32\sspisrv.dll
          2013-09-24 10:54:08 44752 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
          2013-09-24 10:54:07 20072 ----a-w- c:\windows\system32\drivers\cmderd.sys
          2013-09-24 10:53:51 354240 ----a-w- c:\windows\system32\guard32.dll
          2013-09-24 10:53:35 280792 ----a-w- c:\windows\system32\cmdvrt32.dll
          2013-09-24 10:53:34 40664 ----a-w- c:\windows\system32\cmdkbd32.dll
          2013-09-14 00:48:58 338944 ----a-w- c:\windows\system32\drivers\afd.sys
          .
          ============= FINISH: 16:14:59,61 ===============

          Ik zal nu de Security Check gaan draaien.

          Groet,

          Kidaatje.
          Last edited by Emphyrio; 11-12-13, 15:51. Reden: emicons uitgeschakeld.

          Comment


          • #6
            Emphyrio,

            Ik zie dat mijn emoticons toch niet uitstaan.

            De regel moet zijn:

            uRun: c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe

            Dus een 'Recht haakje openen' meteen gevolgd door een 'Recht haakje sluiten'. "[" + "]"

            Ik zal de emoticons nogmaals uitzetten. Zou je mij kunnen vertellen waar ik dit kan doen?

            Groet,

            Kidaatje.

            Comment


            • #7
              Emphyrio,

              Hierbij de SecurityCheck-log:

              Results of screen317's Security Check version 0.99.77
              Windows 7 Service Pack 1 x86 (UAC is enabled)
              Internet Explorer 11
              ``````````````Antivirus/Firewall Check:``````````````
              COMODO Antivirus
              Antivirus up to date!
              `````````Anti-malware/Other Utilities Check:`````````
              Java 7 Update 45
              Adobe Reader 10.1.8 Adobe Reader out of Date!
              Google Chrome 31.0.1650.57
              Google Chrome 31.0.1650.63
              ````````Process Check: objlist.exe by Laurent````````
              Comodo Firewall cmdagent.exe
              `````````````````System Health check`````````````````
              Total Fragmentation on Drive C:
              ````````````````````End of Log``````````````````````

              Mijn Comodo 'sprong' weer aan en detecteerde meteen AdwCleaner als malware?!

              Groet,

              Kidaatje.

              Comment


              • #8
                Oorspronkelijk geplaatst door Kidaatje Bekijk Berichten
                Mijn Comodo 'sprong' weer aan en detecteerde meteen AdwCleaner als malware?!
                Dit is normaal. Je moet je Commodo "vertellen" dat AdwCleaner een vertrouwd programma is. Of anders "excluden".
                Kijk hier hoe je dat doet: http://help.comodo.com/topic-84-1-161-1532-.html


                Oorspronkelijk geplaatst door Kidaatje Bekijk Berichten
                Ik zal de emoticons nogmaals uitzetten. Zou je mij kunnen vertellen waar ik dit kan doen?
                Wanneer je op "Antwoord" klikt om een bericht te posten, zie je de knop "Geavanceerd", rechtsonder in het midden.
                Als je daar op klikt, krijg je het volledige edit menu.
                Onderaan het venster waar je je bericht typt, zie je "Diversen Opties:".
                Daar kan je "Smiley's uitschakelen" aanvinken.


                We gaan eveneens je opstarters aanpakken:

                Download StartUpLite naar het bureaublad.
                Open het programma StartUpLite en klik vervolgens op "Continue"
                Herstart nu de computer.


                Download of Update Ccleaner

                Start CCleaner op.
                • Run Ccleaner en klik in de linkse kolom op Opties
                • Selecteer het tabblad Geavanceerd
                • Haal het vinkje weg voor Verwijder alleen bestanden in Windows Temp-systeemmap die ouder zijn dan 24 uur
                • Haal het vinkje weg voor Verwijder alleen bestanden in de Prullenbak die ouder zijn dan 24 uur
                • Selecteer het tabblad Instellingen
                • Haal het vinkje weg bij "Computer automatisch schoonmaken...."
                • Klik in de linkse kolom op Cleaner.
                • Klik dan achtereenvolgens op Analyseer en Schoonmaken.
                • Klik vervolgens in de linkse kolom op Register
                • Klik op Scan naar problemen.
                • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen
                • Hier kan de vraag verschijnen of je je register wil backuppen.Antwoord met Ja en OK

                .
                Post een verse DDS aub.
                Kan je me tevens vertellen hoe het nu is?
                Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                Comment


                • #9
                  Emphyrio,

                  Klopt het dat er een aantal foutmeldingen volgen als StartUp Lite aan het draaien is, die je vervolgens met 'OK' kan wegklikken?
                  Als dat klopt, dan is hier de DDS.txt-log en anders hoor ik het wel weer.

                  DDS (Ver_2012-11-20.01) - NTFS_x86
                  Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.45.2
                  Run by Mitchell Eestermans at 17:36:31 on 2013-12-11
                  Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3574.2448 [GMT 1:00]
                  .
                  AV: COMODO Antivirus *Enabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8}
                  SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                  SP: COMODO Antivirus *Enabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275}
                  FW: COMODO Firewall *Enabled* {8F7746F7-FE68-E084-3B6C-7404A51E8FB3}
                  .
                  ============== Running Processes ================
                  .
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\lsm.exe
                  C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
                  C:\Program Files\HitmanPro.Alert\hmpalert.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
                  C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
                  C:\Windows\system32\EscSvc.exe
                  C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                  C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                  C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                  C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                  C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
                  C:\Windows\system32\taskhost.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Windows Live\Family Safety\fsui.exe
                  C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
                  C:\Program Files\Common Files\Java\Java Update\jusched.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
                  C:\Program Files\COMODO\COMODO Internet Security\cis.exe
                  C:\Windows\system32\DllHost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\conhost.exe
                  C:\Windows\system32\svchost.exe -k DcomLaunch
                  C:\Windows\system32\svchost.exe -k RPCSS
                  C:\Windows\system32\svchost.exe -k NetworkService
                  C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
                  C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
                  C:\Windows\system32\svchost.exe -k LocalService
                  C:\Windows\system32\svchost.exe -k netsvcs
                  C:\Windows\system32\svchost.exe -k GPSvcGroup
                  C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
                  C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
                  C:\Windows\system32\svchost.exe -k imgsvc
                  C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
                  C:\Windows\System32\svchost.exe -k LocalServicePeerNet
                  .
                  ============== Pseudo HJT Report ===============
                  .
                  uStart Page = hxxp://www.google.nl/
                  BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
                  BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
                  BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
                  BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
                  BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - c:\program files\wot\WOT.dll
                  BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
                  TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
                  TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - c:\program files\wot\WOT.dll
                  TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - c:\program files\epson software\easy photo print\EPTBL.dll
                  uRun: c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe
                  mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
                  mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
                  mRun: [Persistence] c:\windows\system32\igfxpers.exe
                  mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
                  mRun: [fssui] "c:\program files\windows live\family safety\fsui.exe" -autorun
                  mRun: [COMODO Internet Security] c:\program files\comodo\comodo internet security\cistray.exe
                  mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
                  mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
                  mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
                  mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
                  uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
                  uPolicies-Explorer: NoDrives = dword:0
                  mPolicies-Explorer: NoDrives = dword:0
                  mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
                  mPolicies-System: ConsentPromptBehaviorUser = dword:3
                  mPolicies-System: EnableUIADesktopToggle = dword:0
                  mPolicies-System: EnableSecureUIAPath = dword:1
                  IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
                  IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
                  IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
                  IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
                  IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll
                  IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
                  IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
                  IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
                  DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
                  DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
                  DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
                  DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
                  DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  TCP: NameServer = 192.168.2.254 195.121.1.34 195.121.1.66
                  TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754} : DHCPNameServer = 192.168.2.254 195.121.1.34 195.121.1.66
                  TCP: Interfaces\{4E87F4FA-2A05-49F1-BCFC-076681FA3754}\3585535313346433431434 : DHCPNameServer = 192.168.2.1
                  Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
                  Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
                  Notify: igfxcui - igfxdev.dll
                  SSODL: WebCheck - <orphaned>
                  .
                  ============= SERVICES / DRIVERS ===============
                  .
                  R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [2013-6-18 20072]
                  R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2013-6-18 582936]
                  R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2013-6-18 44752]
                  R1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\trusteer\rapport\store\exts\rapportcerber us\baseline\RapportCerberus32_51755.sys [2013-6-24 317112]
                  R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048]
                  R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\common files\epson\epw!3 ssrp\E_S50RP7.EXE [2013-11-12 142432]
                  R2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\escsvc.exe [2013-9-19 122000]
                  R2 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-5 39272]
                  R2 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
                  R2 hmpalert;HitmanPro.Alert Service;c:\program files\hitmanpro.alert\hmpalert.exe [2013-6-25 531304]
                  R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2013-8-27 93072]
                  R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
                  R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 379904]
                  S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
                  S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
                  S3 cleanhlp;cleanhlp;c:\eek\run\cleanhlp32.sys [2013-12-10 50200]
                  S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\comodo\comodo internet security\cmdvirth.exe [2013-6-18 131288]
                  S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-2-6 83864]
                  S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;c:\windows\system32\drivers\aabed2.sys [2008-3-20 23040]
                  S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-7-21 36608]
                  S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2013-11-26 108032]
                  S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-10-31 14848]
                  S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-2-6 181784]
                  S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudobex.sys [2013-2-6 181912]
                  S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [2012-10-20 181344]
                  S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-10-31 49664]
                  S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2011-7-1 1343400]
                  S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
                  .
                  =============== Created Last 30 ================
                  .
                  2013-12-11 16:24:02 -------- d-----w- c:\program files\CCleaner
                  2013-12-11 15:02:45 -------- d-----w- C:\AdwCleaner
                  2013-12-11 07:35:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{84F111E7-B4B3-4B35-9F87-991BEBB4A229}
                  2013-12-10 15:23:22 -------- d-----w- c:\program files\E Dev
                  2013-12-10 08:26:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple Computer
                  2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
                  2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
                  2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
                  2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
                  2013-12-10 07:50:55 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
                  2013-12-10 07:49:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\Apple
                  2013-12-10 07:37:25 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{FAEE061F-479A-4226-8ED7-E421A6EC6409}
                  2013-12-09 15:09:03 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{5F02128A-8AF4-477B-826A-E11FFB8290E5}
                  2013-12-09 12:09:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{D2B8CDFA-EA15-480B-A944-0E6D346597D1}
                  2013-12-07 13:36:56 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{9803BFC5-5CD0-4594-9F48-29F54D3FE2D2}
                  2013-12-06 14:26:09 49940480 ----a-w- c:\program files\GUT2675.tmp
                  2013-12-06 14:26:09 -------- d-----w- c:\program files\GUM2674.tmp
                  2013-12-06 13:37:58 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1C9682D0-67D4-44BA-A733-BFEC4F72CF56}
                  2013-12-05 12:54:32 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{73979CEC-0939-4BCC-B8E9-41F4817E9A21}
                  2013-12-04 15:05:18 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{57D3C24D-C68E-4CB5-943A-E4A967BA4B4F}
                  2013-12-03 12:31:16 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{6FB3F830-E35C-4033-ABC1-1A69E2211C9B}
                  2013-12-02 12:04:41 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{778D2D48-AF4B-44D2-8AB2-91C8319A2CCE}
                  2013-12-01 10:37:15 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{71BD9142-31C9-4AAF-83CF-9235EBC7866C}
                  2013-11-28 14:52:39 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{E52CDF33-5CB4-473A-821C-C71CAAA0E12E}
                  2013-11-27 13:19:29 -------- d-----w- c:\windows\Migration
                  2013-11-27 12:16:52 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{05826281-EFDC-4E7C-847B-4B9A15D78897}
                  2013-11-26 18:03:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\AdTrustMedia
                  2013-11-26 12:00:33 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DE1D39EC-7942-4948-A7A3-91A962C9D9D3}
                  2013-11-25 10:16:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{78175844-B8E7-4394-BFE7-71E82461BADF}
                  2013-11-22 10:28:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{00C60EFC-D400-44C3-BB3D-E463BD16C126}
                  2013-11-21 10:39:44 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{3AB91603-FCE2-45E7-B9A5-457707DFEC2B}
                  2013-11-20 10:42:35 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{671FBA8D-E5FE-474E-ACE8-FC4E4119C23C}
                  2013-11-19 11:52:11 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{8B3D4FFB-CF22-4BF6-BB79-5ED98EADA4D6}
                  2013-11-18 12:46:10 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{DBE2DE66-C2DF-4FDC-BA3E-BA7107EA6FA2}
                  2013-11-17 13:43:21 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{844CFF49-7C86-439D-9114-B26156FFFA03}
                  2013-11-16 11:48:53 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{11B3AA79-F2C1-4971-96BF-F006DEF961EA}
                  2013-11-15 10:31:49 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{470D2AA2-6197-46FF-B3E9-6DE579C5AF46}
                  2013-11-14 17:35:05 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{BF4A555C-7C87-4140-9C7B-5C8C76777FFE}
                  2013-11-13 12:04:02 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{1F8E39CA-F70D-4B90-BC7A-E3DF96B9BB63}
                  2013-11-12 17:24:24 -------- d-----w- c:\programdata\Adtrustmedia
                  2013-11-12 10:09:55 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
                  2013-11-12 10:09:52 81408 ----a-w- c:\windows\system32\E_FD4BIJE.DLL
                  2013-11-12 09:50:06 -------- d-----w- c:\users\mitchell eestermans\appdata\local\{A59A68FE-FFFB-441C-BD64-BBE8D8F06FDE}
                  .
                  ==================== Find3M ====================
                  .
                  2013-11-14 11:38:16 582936 ----a-w- c:\windows\system32\drivers\cmdguard.sys
                  2013-11-14 11:38:01 36000 ----a-w- c:\windows\system32\cmdcsr.dll
                  2013-11-07 13:17:49 24064 ----a-w- c:\windows\zoek-delete.exe
                  2013-10-18 12:35:59 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
                  2013-10-12 02:03:08 656896 ----a-w- c:\windows\system32\nshwfp.dll
                  2013-10-12 02:01:41 679424 ----a-w- c:\windows\system32\IKEEXT.DLL
                  2013-10-12 02:01:25 216576 ----a-w- c:\windows\system32\FWPUCLNT.DLL
                  2013-10-09 14:40:35 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
                  2013-10-09 14:40:35 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
                  2013-10-05 19:57:25 1168384 ----a-w- c:\windows\system32\crypt32.dll
                  2013-10-04 01:58:50 152576 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
                  2013-10-04 01:56:25 168960 ----a-w- c:\windows\system32\credui.dll
                  2013-10-04 01:56:00 1796096 ----a-w- c:\windows\system32\authui.dll
                  2013-10-03 01:58:07 305152 ----a-w- c:\windows\system32\gdi32.dll
                  2013-09-25 02:01:08 136640 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
                  2013-09-25 02:01:06 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                  2013-09-25 01:57:46 99840 ----a-w- c:\windows\system32\sspicli.dll
                  2013-09-25 01:57:26 22016 ----a-w- c:\windows\system32\secur32.dll
                  2013-09-25 01:57:24 247808 ----a-w- c:\windows\system32\schannel.dll
                  2013-09-25 01:56:42 220160 ----a-w- c:\windows\system32\ncrypt.dll
                  2013-09-25 01:56:02 1038848 ----a-w- c:\windows\system32\lsasrv.dll
                  2013-09-25 00:49:20 22016 ----a-w- c:\windows\system32\lsass.exe
                  2013-09-25 00:49:18 15872 ----a-w- c:\windows\system32\sspisrv.dll
                  2013-09-24 10:54:08 44752 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
                  2013-09-24 10:54:07 20072 ----a-w- c:\windows\system32\drivers\cmderd.sys
                  2013-09-24 10:53:51 354240 ----a-w- c:\windows\system32\guard32.dll
                  2013-09-24 10:53:35 280792 ----a-w- c:\windows\system32\cmdvrt32.dll
                  2013-09-24 10:53:34 40664 ----a-w- c:\windows\system32\cmdkbd32.dll
                  2013-09-14 00:48:58 338944 ----a-w- c:\windows\system32\drivers\afd.sys
                  .
                  ============= FINISH: 17:37:36,60 ===============

                  Ik zal nu even kijken of een dvd-tje blijft draaien.

                  Groet,

                  Kidaatje.

                  Comment


                  • #10
                    Welke foutmeldingen bedoel je?

                    Hier vind je een handleiding om screenshots te maken en toe te voegen >>KLIK<<
                    Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                    E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                    Comment


                    • #11
                      Emphyrio,

                      Zie hier:

                      Click image for larger version

Name:	Foutmelding StartUpLite.jpg
Views:	1
Size:	137,6 KB
ID:	1067441

                      Uiteindelijk heb ik 'Dit programma is correct geïnstalleerd' geklikt.

                      Groet,

                      Kidaatje.

                      Comment


                      • #12
                        Emphyrio,

                        Hij blijft trouwens 'denken'.

                        Groet,

                        Kidaatje.

                        Comment


                        • #13
                          Start je PC op in Veilige Modus mét internetverbinding.
                          Heeft hij het dan nog?
                          Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                          E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                          Comment


                          • #14
                            Emphyrio,

                            Ik heb in de veilige modus + netwerk mogelijkheden wat getest. Ongeveer een half uur twee afzonderlijke gemiste uitzendingen laten afspelen, in een aparte ie wat opgezocht en vervolgens wat aan het werk gegaan in Paint en dat allemaal tegelijk en voor ongeveer drie kwartier. Naar mijn mening deed de pc het in die toestand naar behoren.

                            Hierna de 'gewone' weer opgestart. Radio live stream opgestart en een dvd-tje laten spelen. Dit zag er goed uit, alleen toen ik Nero opende en daar wat in ging werken, stopte het dvd-tje met spelen en ging de pc weer denken. De radio speelde wel door. Toen hij weer bij was, heb ik de dvd eruit gehaald en heb ik de Verkenner trachten te openen. Dit gebeurde niet en de pc ging weer in de denkstand.

                            Groet,

                            Kidaatje.

                            Comment


                            • #15
                              Uit je logs (en het opstarten in Veilige Modus) ben ik geneigd om of Family Safety of Commodo als dader(s) aan te wjzen.
                              Je pc is in elkgeval malwarevrij.
                              Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                              E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X