Hijacklog - BearShare verwijderen

  • fazantje

    Hoi Danielle,

    Start HijackThis en klik op “scan” en vink de volgende regels aan:

    O3 - Toolbar: (no name) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)

    O23 - Service: oocdretvliwruy - Unknown owner - c:\windows\system32\hnhjpdps.exe (file missing)

    Sluit alle vensters, behalve HijackThis en klik op Fix checked.

    Verwijder, indien aanwezig het volgende vetgedrukte bestand:

    c:\windows\system32\hnhjpdps.exe <—– dit bestand.

    Download Combofix naar je Bureaublad:

    Klik hier.

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    Dubbelklik op Combofix.exe

    Volg de instructies, aanvaard de disclaimer.

    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze log in je volgende post samen met een nieuw HijackThis logje

    Succes,

    Huib;)

  • sterretje1979

    Ik heb geprobeerd combofix te installeren met de AVG virusscanner uitgeschakeld. Ik krijg de melding dat ik AVG helemaal van de laptop moet afhalen wil combofix kunnen draaien.

    Kan ik dit eraf halen en later probleemloos weer installeren?

  • Ben

    Hallo Danielle,

    download Avast (maar installeer nog niet)

    http://www.av.eu/web/index.php?pageId=67&downloadItems=1&languagecode=nl

    verwijder AVG

    verwijdertool AVG

    http://aa-download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

    Sluit alle geopende vensters en start de AVG Remover.

    Herstart de computer als u hierom wordt gevraagd.

    instaleer daarna Avast

    scan daarna met combo en plaats dan het logje sammen met een nieuw hijack this logje

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

    Ben

  • sterretje1979

    Combofix:

    (wat ben ik eigenlijk allemaal aan het doen met die programma's? haha :D)

    ComboFix 11-05-30.07 - Danielle 31-05-2011 14:06:19.1.2 - x86

    Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.1916.1130

    Gestart vanuit: c:\Users\Danielle\Downloads\ComboFix.exe

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    C:\Install.exe

    C:\Users\Danielle\AppData\Local\Microsoft\Windows\Temporary Internet Files\lsn_6FBA808F-2580-48c3-8C6B-C08BBB800B8E.xml

    C:\Users\Danielle\AppData\Roaming\.#

    (((((((((((((((((((( Bestanden Gemaakt van 2011-04-28 to 2011-05-31 ))))))))))))))))))))))))))))))

    2011-05-31 12:14:33 . 2011-05-31 12:14:33 ——– d—–w- C:\Users\Default\AppData\Local\temp

    2011-05-31 05:39:36 . 2011-05-31 05:39:48 ——– d—–w- C:\Users\Danielle\AppData\Local\{EE86C806-E635-43AD-B845-A1BB6932D6DB}

    2011-05-30 09:50:32 . 2011-05-30 09:50:32 ——– d—–w- C:\Program Files\Sophos

    2011-05-30 07:23:35 . 2011-05-30 07:23:35 ——– d—–w- C:\Users\Danielle\AppData\Roaming\Reviversoft

    2011-05-30 07:23:21 . 2011-05-30 07:23:21 ——– d—–w- C:\Program Files\Reviversoft

    2011-05-30 07:23:21 . 2011-05-17 12:51:06 16704 —-a-w- C:\Windows\system32\roboot.exe

    2011-05-30 05:42:11 . 2011-05-30 05:42:23 ——– d—–w- C:\Users\Danielle\AppData\Local\{02FDEBC7-668E-4161-84B9-35305DAE0816}

    2011-05-29 16:30:36 . 2011-05-29 16:30:36 ——– d—–w- C:\Program Files\Trend Micro

    2011-05-29 15:40:22 . 2011-05-29 15:40:22 ——– d—–w- C:\Users\Danielle\AppData\Roaming\Malwarebytes

    2011-05-29 15:39:32 . 2011-05-29 15:39:32 ——– d—–w- C:\ProgramData\Malwarebytes

    2011-05-29 15:39:32 . 2010-12-20 16:09:00 38224 —-a-w- C:\Windows\system32\drivers\mbamswissarmy.sys

    2011-05-29 15:39:29 . 2011-05-29 15:39:34 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware

    2011-05-29 15:39:29 . 2010-12-20 16:08:40 20952 —-a-w- C:\Windows\system32\drivers\mbam.sys

    2011-05-29 10:25:56 . 2011-05-29 10:26:08 ——– d—–w- C:\Users\Danielle\AppData\Local\{F673ED40-B808-4CAD-A116-2B16761C1A76}

    2011-05-28 06:45:45 . 2011-05-28 06:45:55 ——– d—–w- C:\Users\Danielle\AppData\Local\{3F3F52CC-C2EB-41C6-9DC8-DD897B69C264}

    2011-05-27 06:44:30 . 2011-05-27 18:45:19 ——– d—–w- C:\Users\Danielle\AppData\Local\{6021974A-8472-4599-8D1C-FE6CD96DADC2}

    2011-05-26 18:04:59 . 2011-05-26 18:05:10 ——– d—–w- C:\Users\Danielle\AppData\Local\{EAE9AFBB-5502-4BA7-88BA-510A762735C6}

    2011-05-26 06:04:36 . 2011-05-26 06:04:46 ——– d—–w- C:\Users\Danielle\AppData\Local\{162DD58F-7DB2-4BEF-948F-BC411D925843}

    2011-05-25 19:10:04 . 2011-05-25 19:10:04 ——– d—–w- C:\Users\Danielle\AppData\Local\{09C4D603-71FA-42AB-B75A-462390765E25}

    2011-05-25 06:54:07 . 2011-05-25 06:54:20 ——– d—–w- C:\Users\Danielle\AppData\Local\{AC39D514-5912-4A7A-8D8A-7D8FFA23A94D}

    2011-05-24 07:05:01 . 2011-05-24 07:05:12 ——– d—–w- C:\Users\Danielle\AppData\Local\{86C1A8A3-89C8-4197-9D37-8CFBD3D6AF47}

    2011-05-23 18:25:47 . 2011-05-23 18:26:01 ——– d—–w- C:\Users\Danielle\AppData\Local\{8B1044C2-EB04-4F33-AD7A-6C80CE134D44}

    2011-05-23 05:29:36 . 2011-05-23 05:29:49 ——– d—–w- C:\Users\Danielle\AppData\Local\{EA7C57C2-F6BE-441D-87F1-0AC6F87152D0}

    2011-05-22 08:38:28 . 2011-05-22 08:38:38 ——– d—–w- C:\Users\Danielle\AppData\Local\{C91425B3-2413-4980-AF6F-7160834EE32A}

    2011-05-21 10:03:27 . 2011-05-21 10:03:38 ——– d—–w- C:\Users\Danielle\AppData\Local\{FF719DC4-2F9A-4015-ABAE-F597E80D578C}

    2011-05-20 09:54:40 . 2011-05-20 09:55:15 ——– d—–w- C:\Users\Danielle\AppData\Local\{044BEC18-4D7C-4239-AE17-5060C03C8FE5}

    2011-05-19 20:08:08 . 2011-05-19 20:08:18 ——– d—–w- C:\Users\Danielle\AppData\Local\{1477F10D-0E53-4AB3-84E5-E08FC863428D}

    2011-05-19 08:07:41 . 2011-05-19 08:07:53 ——– d—–w- C:\Users\Danielle\AppData\Local\{0524C409-BBAD-4EAE-AFC8-47024494381B}

    2011-05-18 18:41:37 . 2011-05-18 18:41:47 ——– d—–w- C:\Users\Danielle\AppData\Local\{98BC4520-5877-4831-8F42-A165FD62199E}

    2011-05-18 06:40:50 . 2011-05-18 06:41:07 ——– d—–w- C:\Users\Danielle\AppData\Local\{10E6D346-1347-40B7-8745-8B85405F15C9}

    2011-05-17 06:39:38 . 2011-05-17 18:40:11 ——– d—–w- C:\Users\Danielle\AppData\Local\{F8F7D71A-AED2-4283-8270-205BE15400C1}

    2011-05-16 06:38:39 . 2011-05-16 18:39:14 ——– d—–w- C:\Users\Danielle\AppData\Local\{27C30652-7582-4F8B-B7B6-63A89B46BC25}

    2011-05-15 18:38:03 . 2011-05-15 18:38:13 ——– d—–w- C:\Users\Danielle\AppData\Local\{2D2E4EA6-617C-4F7D-AE95-7A5D5005636D}

    2011-05-15 06:37:26 . 2011-05-15 06:37:37 ——– d—–w- C:\Users\Danielle\AppData\Local\{D1A82A37-33DE-422B-BB22-1B6290F00DA7}

    2011-05-14 06:24:41 . 2011-05-14 06:24:53 ——– d—–w- C:\Users\Danielle\AppData\Local\{FE1BEDA7-4531-458E-AFBA-E9D470DEDA07}

    2011-05-13 18:00:13 . 2011-05-13 18:00:22 ——– d—–w- C:\Users\Danielle\AppData\Local\{D5016906-D082-497D-826C-2E1972DB669C}

    2011-05-13 05:59:35 . 2011-05-13 05:59:46 ——– d—–w- C:\Users\Danielle\AppData\Local\{F9A1786E-D595-4CAE-806E-1CE76D59C7F4}

    2011-05-12 17:28:29 . 2011-05-12 17:28:39 ——– d—–w- C:\Users\Danielle\AppData\Local\{A2027D23-FB78-42F7-8DA6-4C2595BF8BE6}

    2011-05-12 05:27:54 . 2011-05-12 05:28:04 ——– d—–w- C:\Users\Danielle\AppData\Local\{E1460455-552E-4925-A144-663123DE5126}

    2011-05-12 05:25:56 . 2011-04-07 12:01:52 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat

    2011-05-11 05:26:46 . 2011-05-11 17:27:28 ——– d—–w- C:\Users\Danielle\AppData\Local\{2B7EBEF4-DB2D-4CB3-BC0D-595B5D1E350F}

    2011-05-10 14:21:14 . 2011-05-10 14:21:24 ——– d—–w- C:\Users\Danielle\AppData\Local\{8193E160-472D-43D8-A515-93E9ACFF733D}

    2011-05-09 20:13:46 . 2011-05-09 20:13:56 ——– d—–w- C:\Users\Danielle\AppData\Local\{C8CB7844-C4E8-4003-B8AF-A881FC4D8BE7}

    2011-05-09 08:13:23 . 2011-05-09 08:13:33 ——– d—–w- C:\Users\Danielle\AppData\Local\{8D398243-F1FE-4D5A-86E9-BC648C61DFC0}

    2011-05-08 20:12:48 . 2011-05-08 20:12:58 ——– d—–w- C:\Users\Danielle\AppData\Local\{C9B9D69B-7C37-4643-B399-FE8D37432172}

    2011-05-08 08:12:26 . 2011-05-08 08:12:36 ——– d—–w- C:\Users\Danielle\AppData\Local\{F72AE0E6-F110-410D-BF6B-744E703132CE}

    2011-05-07 20:11:50 . 2011-05-07 20:12:00 ——– d—–w- C:\Users\Danielle\AppData\Local\{B2D6F2BE-C886-4EC2-8E13-E1150A52EC5B}

    2011-05-07 20:05:03 . 2011-05-07 20:05:03 ——– d—–w- C:\Users\Danielle\AppData\Local\{5E3B6B83-26FA-46B4-AE4C-D65B8BAF6964}

    2011-05-07 07:16:48 . 2011-05-07 07:17:00 ——– d—–w- C:\Users\Danielle\AppData\Local\{2C66BEDC-C331-44A9-BE1F-A795142C6D62}

    2011-05-06 07:49:30 . 2011-05-06 07:49:40 ——– d—–w- C:\Users\Danielle\AppData\Local\{31623E8A-26CD-4A50-99F2-945BAD78266C}

    2011-05-05 19:49:10 . 2011-05-05 19:49:13 ——– d—–w- C:\Users\Danielle\AppData\Local\{8EE36AB1-053C-4645-AEC7-9178DAA98DC5}

    2011-05-05 06:55:03 . 2011-05-05 06:55:13 ——– d—–w- C:\Users\Danielle\AppData\Local\{925A49D1-C693-49D6-9A37-99655ECB9B73}

    2011-05-04 20:24:52 . 2011-05-04 20:24:52 ——– d—–w- C:\Users\Danielle\AppData\Local\{2E836B31-4C09-4A31-A146-4DB226DFB349}

    2011-05-04 07:10:22 . 2011-05-04 07:10:32 ——– d—–w- C:\Users\Danielle\AppData\Local\{EBBD2CBC-503F-494C-8F3E-3B58E26F696F}

    2011-05-03 18:45:29 . 2011-05-03 18:45:39 ——– d—–w- C:\Users\Danielle\AppData\Local\{9655AA77-BEEB-4B20-86AC-FEC157FA151D}

    2011-05-03 06:44:59 . 2011-05-03 06:45:10 ——– d—–w- C:\Users\Danielle\AppData\Local\{375B1FCB-1378-4986-90DF-E8419B1E0249}

    2011-05-02 18:29:30 . 2011-05-02 18:29:40 ——– d—–w- C:\Users\Danielle\AppData\Local\{A9DE47AE-7128-46EC-AFB9-3CDBCDBD76AC}

    2011-05-02 06:28:54 . 2011-05-02 06:29:04 ——– d—–w- C:\Users\Danielle\AppData\Local\{60A436E7-416E-42AB-8035-9F13F39D2D9E}

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2011-03-12 21:55:52 . 2011-04-27 09:47:54 876032 —-a-w- C:\Windows\system32\XpsPrint.dll

    2011-03-10 17:03:51 . 2011-04-16 07:30:05 1162240 —-a-w- C:\Windows\system32\mfc42u.dll

    2011-03-10 17:03:51 . 2011-04-16 07:30:03 1136640 —-a-w- C:\Windows\system32\mfc42.dll

    2011-03-09 07:08:02 . 2010-06-24 09:33:56 18328 —-a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

    2011-03-03 15:42:03 . 2011-04-16 07:29:37 739328 —-a-w- C:\Windows\system32\inetcomm.dll

    2011-03-03 15:40:13 . 2011-04-27 09:47:58 28672 —-a-w- C:\Windows\system32\Apphlpdm.dll

    2011-03-03 15:40:07 . 2011-04-27 09:47:58 173056 —-a-w- C:\Windows\apppatch\AcXtrnal.dll

    2011-03-03 15:40:05 . 2011-04-27 09:47:58 542720 —-a-w- C:\Windows\apppatch\AcLayers.dll

    2011-03-03 15:40:05 . 2011-04-27 09:47:58 458752 —-a-w- C:\Windows\apppatch\AcSpecfc.dll

    2011-03-03 15:40:04 . 2011-04-27 09:47:58 2159616 —-a-w- C:\Windows\apppatch\AcGenral.dll

    2011-03-03 13:35:36 . 2011-04-27 09:47:58 4240384 —-a-w- C:\Windows\system32\GameUXLegacyGDFs.dll

    2011-03-03 13:25:11 . 2011-04-16 07:29:44 2041856 —-a-w- C:\Windows\system32\win32k.sys

    2011-03-02 15:44:27 . 2011-04-16 07:29:49 86528 —-a-w- C:\Windows\system32\dnsrslvr.dll

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    “SmpcSys”=“C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe”

    “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    “msnmsgr”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”

    “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe”

    “RtHDVCpl”=“RtHDVCpl.exe”

    “SiSTray”=“C:\Program Files\SiS VGA Utilities\SiSTray.exe”

    “Google Desktop Search”=“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe”

    “toolbar_eula_launcher”=“C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe”

    “fssui”=“C:\Program Files\Windows Live\Family Safety\fsui.exe”

    “Skytel”=“Skytel.exe”

    “CanonSolutionMenu”=“C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe”

    “CanonMyPrinter”=“C:\Program Files\Canon\MyPrinter\BJMyPrt.exe”

    “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    “Adobe ARM”=“C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “SunJavaUpdateSched”=“C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    “EnableUIADesktopToggle”= 0 (0x0)

    “AppInit_DLLs”=C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

    “DisableMonitoring”=dword:00000001

    “DisableMonitoring”=dword:00000001

    “DisableMonitoring”=dword:00000001

    “AntiVirusOverride”=dword:00000001

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    R2 gupdate;Google Updateservice (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe

    R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    R3 gupdatem;Google Update-service (gupdatem);C:\Program Files\Google\Update\GoogleUpdate.exe

    R3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\system32\DRIVERS\massfilter.sys

    R3 MEMSWEEP2;MEMSWEEP2;C:\Windows\system32\8323.tmp

    R3 netr73;RT73 USB Wireless LAN Card Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys

    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

    R3 ZTEusbnet;ZTE USB-NDIS miniport;C:\Windows\system32\DRIVERS\ZTEusbnet.sys

    R4 oocdretvliwruy;oocdretvliwruy;c:\windows\system32\hnhjpdps.exe

    S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys

    S3 SiS6350;SiS6350;C:\Windows\system32\DRIVERS\SISGRKMD.sys

    S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSGB6.sys

    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    Inhoud van de ‘Gedeelde Taken’ map

    2011-05-31 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

    - C:\Program Files\Google\Update\GoogleUpdate.exe

    2011-05-31 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

    - C:\Program Files\Google\Update\GoogleUpdate.exe

    2011-05-31 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3233025038-488707028-2052865575-1000Core.job

    - C:\Users\Danielle\AppData\Local\Google\Update\GoogleUpdate.exe

    2011-05-31 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3233025038-488707028-2052865575-1000UA.job

    - C:\Users\Danielle\AppData\Local\Google\Update\GoogleUpdate.exe

    2011-05-31 C:\Windows\Tasks\Recovery DVD Creator-Danielle.job

    - C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe

    2011-05-31 C:\Windows\Tasks\Uitgebreide garantie-Danielle.job

    - C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe

    ——- Bijkomende Scan ——-

    uStart Page = hxxp://www.ad.nl/

    IE: E&xporteren naar Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    IE: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

    TCP: DhcpNameServer = 192.168.1.254

    - - - - ORPHANS VERWIJDERD - - - -

    URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)

    BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)

    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    Toolbar-10 - (no file)

    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    AddRemove-Picasa2 - C:\Program Files\Picasa2\Uninstall.exe

    Nieuwe Hijack:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 14:32:47, on 31-5-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v8.00 (8.00.6001.19048)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Windows\RtHDVCpl.exe

    C:\Program Files\SiS VGA Utilities\SiSTray.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files\Reviversoft\Registry Reviver\RegistryReviver.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Windows\system32\rundll32.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Windows\system32\NOTEPAD.EXE

    C:\Program Files\AVG\AVG10\avgtray.exe

    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    C:\Program Files\Trend Micro\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ad.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: RtHDVCpl.exe

    O4 - HKLM\..\Run: %ProgramFiles%\SiS VGA Utilities\SiSTray.exe

    O4 - HKLM\..\Run: “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup

    O4 - HKLM\..\Run: C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe

    O4 - HKLM\..\Run: “C:\Program Files\Windows Live\Family Safety\fsui.exe” -autorun

    O4 - HKLM\..\Run: Skytel.exe

    O4 - HKLM\..\Run: C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon

    O4 - HKLM\..\Run: C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: C:\Program Files\AVG\AVG10\avgtray.exe

    O4 - HKCU\..\Run: C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

    O4 - HKCU\..\Run: “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\RunOnce: “C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe” /SETCHROME 1 26 0

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe

    End of file - 8143 bytes

  • Ben

    hallo Danielle,

    Het gaat goed zo (tu) we houden je wel bezig (:P)

    Ik zie dat je AVG toch kon behouden? (vergeet hem niet aan te zetten)

    Start HijackThis en klik op “scan” en vink de volgende regel aan:

    O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)

    Sluit alle vensters, behalve HijackThis en klik op Fix checked.

    En plaats een nieuw hijack this logje.,en vertel hoe het gaat met je computer problemen.

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

    Ben

  • sterretje1979

    Ik merk het… haha… geloof dat mijn laptop nog net niet op instorten staat :O

    En AVG draait weer… gelukkig :)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 15:32:02, on 31-5-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v8.00 (8.00.6001.19048)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\taskeng.exe

    C:\Program Files\Reviversoft\Registry Reviver\RegistryReviver.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Windows\RtHDVCpl.exe

    C:\Program Files\SiS VGA Utilities\SiSTray.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\AVG\AVG10\avgtray.exe

    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Windows\system32\rundll32.exe

    C:\Users\Danielle\AppData\Local\Google\Chrome\Application\chrome.exe

    C:\Program Files\Trend Micro\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ad.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: RtHDVCpl.exe

    O4 - HKLM\..\Run: %ProgramFiles%\SiS VGA Utilities\SiSTray.exe

    O4 - HKLM\..\Run: “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup

    O4 - HKLM\..\Run: C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe

    O4 - HKLM\..\Run: “C:\Program Files\Windows Live\Family Safety\fsui.exe” -autorun

    O4 - HKLM\..\Run: Skytel.exe

    O4 - HKLM\..\Run: C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon

    O4 - HKLM\..\Run: C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon

    O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: C:\Program Files\AVG\AVG10\avgtray.exe

    O4 - HKCU\..\Run: C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

    O4 - HKCU\..\Run: “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe

    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe

    End of file - 8068 bytes

  • Ben

    Hallo Danielle,

    Volgens mij zijn je logjes goed (tu)

    (maar wacht even op bevestiging van fazantje die is er weer eind vannavond)

    Na goed keuring van fazantje doe deze stap;

    Verwijder Combofix: Start -> Uitvoeren en typ: combofix /u

    Dit zal Combofix verwijderen

    Of je sophos moet verwijderen hoor je dan van fazantje.

    En update je adobe reader ook meteen even

    En dit probleem:

    De inlogproblemen met hotmail heb ik niet meer. Wel is afgelopen weekend nog iemand naar me toe gekomen met een vraag over mijn prive leven waarvan maar 2 personen weten dat het speelt/gespeeld heeft. Dus vermoed nog wel ergens een ‘lek’.

    Dit lek hoeft niet perse op je computer te zitten!!(hoeft niet zeg het er alleen bij;))

    En vertel bij je volgende antwoord hoe met je pc gaat??(of alles nou goed werkt)

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

    Ben

  • Teaser

    Kijk nog eens goed naar het combolog 8-)

  • Ben

    Hallo Teaser,

    Heb jij een hint voor mij welke richting ik op moet zoeken??

    Alvast bedankt?(ben nog lerend)

    Ben

  • fazantje

    Hoi Danielle,

    Open Kladblok, kopiëer en plak het volgende (vetgedrukte, blauwe tekst) in een leeg venster:

    • File::

      C:\Windows\system32\8323.tmp

      c:\windows\system32\hnhjpdps.exe

      Driver:

      hnhjpdps.exe

    Sla dit op op je Bureaublad als CFScript.txt

    Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld :

    Dit zal ComboFix doen herstarten.

    Start opnieuw op als daarom gevraagd wordt,

    en post de inhoud van de Combofix.txt in je volgende antwoord samen met een nieuw HijackThislogje.

    Succes,

    Huib;)