Trojan Horse - Adware.DoubleD

  • Yvonne0603

    Hallo,

    Sinds gisteren last van een hardnekkigge trojan horse. Volgens mij heb ik alle stappen uitgevoerd. Willen jullie dit bekijken?

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 20:03:43, on 8-8-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16421)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\taskeng.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Windows\WindowsMobile\wmdcBase.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\NETGEAR\WPN111\wpn111.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Users\SpoJag\AppData\Local\Apps\2.0\BJDEXLQG.RYT\TXWAVZ8N.LAR\curs..tion_eee711038731a406_0004.0000_0d453ed5fea2fe48\CurseClient.exe

    C:\Program Files\Razer\Diamondback 3G\razerofa.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\System32\mobsync.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\NOTEPAD.EXE

    C:\Windows\system32\conime.exe

    C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nl.intl.acer.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O1 - Hosts: ::1 localhost

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: %WINDIR%\WindowsMobile\wmdcBase.exe

    O4 - HKLM\..\Run: %windir%\WindowsMobile\wmdc.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F “C:\Windows\TEMP\E_S96C.tmp” /EF “HKLM”

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: C:\Program Files\GameSpy\Comrade\Comrade.exe

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\Run: rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Startup: CurseClientStartup.ccip

    O4 - Startup: OneNote-inhoudsopgave.onetoc2

    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O11 - Options group: Accelerated graphics

    O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} (CeWe Color AG & Co. OHG Control) - https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6431/mcfscan.cab

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    End of file - 8177 bytes

    Malwarebytes' Anti-Malware 1.51.1.1800

    www.malwarebytes.org

    Databaseversie: 7411

    Windows 6.0.6002 Service Pack 2

    Internet Explorer 9.0.8112.16421

    8-8-2011 19:56:14

    mbam-log-2011-08-08 (19-56-14).txt

    Scantype: Snelle scan

    Objecten gescand: 156271

    Verstreken tijd: 3 minuut/minuten, 8 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 4

    Registerwaarden geïnfecteerd: 0

    Registerdata geïnfecteerd: 0

    Mappen geïnfecteerd: 14

    Bestanden geïnfecteerd: 26

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    HKEY_CURRENT_USER\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} (Adware.DoubleD) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Funband Serach (Adware.DoubleD) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Web Search Operator (Adware.DoubleD) -> Quarantined and deleted successfully.

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:

    c:\program files\automated content enhancer (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570 (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\Data (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome\content (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\components (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330 (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\Data (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome\content (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\components (Adware.Agent) -> Quarantined and deleted successfully.

    Bestanden geïnfecteerd:

    c:\Windows\run_setup.exe (Adware.Agent) -> Quarantined and deleted successfully.

    c:\Users\SpoJag\AppData\Roaming\microsoft\Windows\start menu\Programs\security tool.lnk (Rogue.SecurityTool) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\acecommon.dll (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\Data\config.md (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome.manifest (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\install.rdf (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome\ACEAddOn.jar (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome\content\ACEAddOn.js (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\chrome\content\ACEAddOn.xul (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\components\aceffaddon.dll (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\components\aceffaddon.xpt (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\automated content enhancer\4.3.0.5570\FF\components\aceffhelpercomponent.js (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\wsocommon.dll (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\Data\config.md (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome.manifest (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\install.rdf (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome\WSOAddOn.jar (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome\content\WSOAddOn.js (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\chrome\content\WSOAddOn.xul (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\components\wsoffaddon.dll (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\components\wsoffaddon.xpt (Adware.Agent) -> Quarantined and deleted successfully.

    c:\program files\web search operator\4.3.0.2330\FF\components\wsoffhelpercomponent.js (Adware.Agent) -> Quarantined and deleted successfully.

  • Ben

    Hallo Yvonne,

    Start HijackThis, klik op scan en vink de volgende regels aan:

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    Sluit alle vensters, behalve HijackThis en klik op fix checked.

    Download http://download.bleepingcomputer.com/sUBs/ComboFix.exe Combofix naar je Bureaublad:

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner,

    schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    Dubbelklik op Combofix.exe

    Volg de instructies, aanvaard de disclaimer.

    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    LET OP!!

    Het kan enige tijd duren voordat het logje van combofix komt, dus denk niet van hij is op tilt.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze log in je volgende post samen met een nieuw HijackThis logje.

    En vertel er bij hoe het staat met je problemen.

    suc6 Ben

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

  • Yvonne0603

    Hallo Ben,

    Dank voor je hulp, alles ziet er nu goed uit. Ik krijg geen meldingen meer van Vista 2012 en internet is weer beschikbaar. Dit zijn de nieuwe logfiles.

    groet, YVonne

    ComboFix 11-08-08.01 - SpoJag 08-08-2011 21:03:38.1.2 - x86

    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.2047.1314

    Gestart vanuit: c:\users\SpoJag\Documents\Downloads\ComboFix.exe

    AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}

    SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\windows\Tasks\pbpdowmf.job

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2011-07-08 to 2011-08-08 ))))))))))))))))))))))))))))))

    .

    .

    2011-08-08 18:57 . 2011-08-08 18:57 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A435BF8B-D6A0-4DAC-88E8-17A6E012E411}\MpKsl0b11ec5f.sys

    2011-08-08 18:01 . 2011-08-08 18:01 388096 —-a-r- c:\users\SpoJag\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

    2011-08-08 18:01 . 2011-08-08 18:01 ——– d—–w- c:\program files\Trend Micro

    2011-08-08 17:47 . 2011-08-08 17:47 ——– d—–w- c:\users\SpoJag\AppData\Roaming\Malwarebytes

    2011-08-08 17:46 . 2011-07-06 17:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys

    2011-08-08 17:46 . 2011-08-08 17:46 ——– d—–w- c:\programdata\Malwarebytes

    2011-08-08 17:46 . 2011-07-06 17:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys

    2011-08-08 17:46 . 2011-08-08 17:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware

    2011-08-08 15:20 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A435BF8B-D6A0-4DAC-88E8-17A6E012E411}\mpengine.dll

    2011-08-08 10:49 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll

    2011-08-08 09:39 . 2009-06-30 08:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys

    2011-08-08 09:39 . 2011-08-08 09:39 ——– d—–w- c:\program files\Panda Security

    2011-08-08 09:23 . 2011-08-08 09:23 ——– d—–w- c:\windows\McAfee.com

    2011-07-13 20:05 . 2011-06-02 13:34 2043392 —-a-w- c:\windows\system32\win32k.sys

    2011-07-13 20:05 . 2011-04-20 15:55 375808 —-a-w- c:\windows\system32\winsrv.dll

    2011-07-13 20:05 . 2011-04-20 15:50 49152 —-a-w- c:\windows\system32\csrsrv.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2011-07-13 03:39 . 2010-05-23 07:00 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

    2011-06-28 06:54 . 2011-06-28 06:54 161792 —-a-w- c:\windows\system32\msls31.dll

    2011-06-28 06:54 . 2011-06-28 06:54 1126912 —-a-w- c:\windows\system32\wininet.dll

    2011-06-28 06:54 . 2011-06-28 06:54 86528 —-a-w- c:\windows\system32\iesysprep.dll

    2011-06-28 06:54 . 2011-06-28 06:54 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe

    2011-06-28 06:54 . 2011-06-28 06:54 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe

    2011-06-28 06:54 . 2011-06-28 06:54 63488 —-a-w- c:\windows\system32\tdc.ocx

    2011-06-28 06:54 . 2011-06-28 06:54 48640 —-a-w- c:\windows\system32\mshtmler.dll

    2011-06-28 06:54 . 2011-06-28 06:54 74752 —-a-w- c:\windows\system32\iesetup.dll

    2011-06-28 06:54 . 2011-06-28 06:54 367104 —-a-w- c:\windows\system32\html.iec

    2011-06-28 06:54 . 2011-06-28 06:54 23552 —-a-w- c:\windows\system32\licmgr10.dll

    2011-06-28 06:54 . 2011-06-28 06:54 152064 —-a-w- c:\windows\system32\wextract.exe

    2011-06-28 06:54 . 2011-06-28 06:54 150528 —-a-w- c:\windows\system32\iexpress.exe

    2011-06-28 06:54 . 2011-06-28 06:54 1427456 —-a-w- c:\windows\system32\inetcpl.cpl

    2011-06-28 06:54 . 2011-06-28 06:54 420864 —-a-w- c:\windows\system32\vbscript.dll

    2011-06-28 06:54 . 2011-06-28 06:54 35840 —-a-w- c:\windows\system32\imgutil.dll

    2011-06-28 06:54 . 2011-06-28 06:54 2382848 —-a-w- c:\windows\system32\mshtml.tlb

    2011-06-28 06:54 . 2011-06-28 06:54 1797632 —-a-w- c:\windows\system32\jscript9.dll

    2011-06-28 06:54 . 2011-06-28 06:54 142848 —-a-w- c:\windows\system32\ieUnatt.exe

    2011-06-28 06:54 . 2011-06-28 06:54 11776 —-a-w- c:\windows\system32\mshta.exe

    2011-06-28 06:54 . 2011-06-28 06:54 101888 —-a-w- c:\windows\system32\admparse.dll

    2011-06-28 06:54 . 2011-06-28 06:54 110592 —-a-w- c:\windows\system32\IEAdvpack.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    “ehTray.exe”=“c:\windows\ehome\ehTray.exe”

    .

    “Acer Empowering Technology Monitor”=“c:\acer\Empowering Technology\SysMonitor.exe”

    “NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”

    “NeroFilterCheck”=“c:\program files\Common Files\Nero\Lib\NeroCheck.exe”

    “Windows Mobile-based device management”=“c:\windows\WindowsMobile\wmdcBase.exe”

    “StartCCC”=“c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe”

    “eDataSecurity Loader”=“c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe”

    “Diamondback”=“c:\program files\Razer\Diamondback 3G\razerhid.exe”

    “TkBellExe”=“c:\program files\Common Files\Real\Update_OB\realsched.exe”

    “MSC”=“c:\program files\Microsoft Security Client\msseces.exe”

    “Malwarebytes' Anti-Malware (reboot)”=“c:\program files\Malwarebytes' Anti-Malware\mbam.exe”

    .

    “Acer Tour Reminder”=“c:\acer\AcerTour\Reminder.exe”

    .

    c:\users\SpoJag\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

    CurseClientStartup.ccip

    OneNote-inhoudsopgave.onetoc2

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    NETGEAR WPN111 Smart Wizard.lnk - c:\program files\NETGEAR\WPN111\wpn111.exe

    .

    “EnableUIADesktopToggle”= 0 (0x0)

    .

    @=“Service”

    .

    “CTRegRun”=c:\windows\CTRegRun.EXE

    .

    “DisableMonitoring”=dword:00000001

    .

    “DisableMonitoring”=dword:00000001

    .

    “DisableMonitoring”=dword:00000001

    .

    R1 MpKsl0e2a16f1;MpKsl0e2a16f1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9C9A1493-A875-43E1-9BA7-9EF0298A23A0}\MpKsl0e2a16f1.sys

    R1 MpKsl1069cf7c;MpKsl1069cf7c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3DE1C755-D863-4095-A771-87BA23B9D8F4}\MpKsl1069cf7c.sys

    R1 MpKsl19d306cf;MpKsl19d306cf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B862C2B0-51CF-4565-BBB7-511AC23D32AA}\MpKsl19d306cf.sys

    R1 MpKsl3732e018;MpKsl3732e018;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1642753-2BDA-46E5-B3A4-92C7C2F4D30B}\MpKsl3732e018.sys

    R1 MpKsl4e34948b;MpKsl4e34948b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BE663683-2CF7-4614-9DED-F2E6D62BCA42}\MpKsl4e34948b.sys

    R1 MpKsl7994bdee;MpKsl7994bdee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{432DEFA3-7C55-4E85-9B37-766AA15432F0}\MpKsl7994bdee.sys

    R1 MpKsl91c96ace;MpKsl91c96ace;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{25BCDB80-9BE7-4FFC-88E9-B1D295F8B135}\MpKsl91c96ace.sys

    R1 MpKsl9541d92b;MpKsl9541d92b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E6923FAE-A673-4BBA-8DEE-5DA3BCB1A891}\MpKsl9541d92b.sys

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\Drivers\DB3G.sys

    R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys

    R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys

    R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys

    R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys

    R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys

    R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys

    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

    S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys

    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys

    S1 MpKsl0b11ec5f;MpKsl0b11ec5f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A435BF8B-D6A0-4DAC-88E8-17A6E012E411}\MpKsl0b11ec5f.sys

    S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys

    S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys

    S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe

    S3 RTL85n86;Stuurprogramma voor Realtek 8180/8185 Extensible 802.11-draadloos apparaat;c:\windows\system32\DRIVERS\RTL85n86.sys

    S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111.sys

    .

    .

    — Andere Services/Drivers In Geheugen —

    .

    *NewlyCreated* - MPKSL0B11EC5F

    .

    WindowsMobile REG_MULTI_SZ wcescomm rapimgr

    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    .

    .

    ——- Bijkomende Scan ——-

    .

    uStart Page = hxxp://www.startpagina.nl/

    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7

    mStart Page = hxxp://nl.intl.acer.yahoo.com

    uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.1.1

    DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

    HKCU-Run-Comrade.exe - c:\program files\GameSpy\Comrade\Comrade.exe

    HKLM-Run-Windows Mobile Device Center - c:\windows\WindowsMobile\wmdc.exe

    AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\uninstall_activeX.exe

    AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\uninstall_plugin.exe

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2011-08-08 21:09

    Windows 6.0.6002 Service Pack 2 NTFS

    .

    scannen van verborgen processen …

    .

    scannen van verborgen autostart items …

    .

    scannen van verborgen bestanden …

    .

    Scan succesvol afgerond

    verborgen bestanden: 0

    .

    **************************************************************************

    .

    ——————— VERGRENDELDE REGISTER SLEUTELS ———————

    .

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    “BlindDial”=dword:00000000

    .

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    “BlindDial”=dword:00000000

    .

    Voltooingstijd: 2011-08-08 21:12:41

    ComboFix-quarantined-files.txt 2011-08-08 19:12

    .

    Pre-Run: 28.646.588.416 bytes beschikbaar

    Post-Run: 28.866.330.624 bytes beschikbaar

    .

    - - End Of File - - 171465AEA73BE8A66ED48B0F27AC1151

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 21:16:24, on 8-8-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16421)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\system32\taskeng.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Windows\WindowsMobile\wmdcBase.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\NETGEAR\WPN111\wpn111.exe

    C:\Users\SpoJag\AppData\Local\Apps\2.0\BJDEXLQG.RYT\TXWAVZ8N.LAR\curs..tion_eee711038731a406_0004.0000_0d453ed5fea2fe48\CurseClient.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Program Files\Razer\Diamondback 3G\razerofa.exe

    C:\Windows\System32\mobsync.exe

    C:\Windows\system32\conime.exe

    C:\Windows\explorer.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: %WINDIR%\WindowsMobile\wmdcBase.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Startup: CurseClientStartup.ccip

    O4 - Startup: OneNote-inhoudsopgave.onetoc2

    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O11 - Options group: Accelerated graphics

    O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} (CeWe Color AG & Co. OHG Control) - https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6431/mcfscan.cab

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    End of file - 7031 bytes

  • Ben

    Hallo Yvonne,

    Heb je deze stap niet uitgevoerd??

    Start HijackThis, klik op scan en vink de volgende regels aan:

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

    Sluit alle vensters, behalve HijackThis en klik op fix checked.

    zo ja start Hijack this op met administrator rechten door Hijack this op te starten via rechter muis knop,

    en dan te kiezen opstarten met administrator rechten probeer het dan nog een keer.

    Plaats daarna nog een nieuw Hijack this logje,

    Suc6 Ben

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

  • Yvonne0603

    Hoi Ben,

    Ik heb een nieuwe logfile gepost. IK heb het programma nu uitgevoerd als administrator. Ziet het er nu beter uit?

    Groet,

    YVonne

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 14:39:17, on 10-8-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v9.00 (9.00.8112.16421)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\taskeng.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Windows\WindowsMobile\wmdcBase.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Microsoft Security Client\msseces.exe

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\NETGEAR\WPN111\wpn111.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Program Files\Razer\Diamondback 3G\razerofa.exe

    C:\Program Files\Trend Micro\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: %WINDIR%\WindowsMobile\wmdcBase.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Razer\Diamondback 3G\razerhid.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Startup: OneNote-inhoudsopgave.onetoc2

    O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O11 - Options group: Accelerated graphics

    O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} (CeWe Color AG & Co. OHG Control) - https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,6431/mcfscan.cab

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    End of file - 6062 bytes

  • Ben

    Hallo Yvonne,

    Naar mijn mening zijn je logjes nu goed (maar wacht even tot fazantje ook zijn goedkeuring geeft ben nog lerende)

    Doe deze stappen na goedkeuring van fazantje;

    Verwijderen ComboFix, kopiëer het onderstaande commando met (Ctrl + C):

    Combofix /Uninstall (let op!!! de spatie voor /Uninstall)

    Klik Start -> Uitvoeren, en plak (Ctrl + V) het commando, toets vervolgens Ctrl + Shift + Enter.

    http://www.emphyrio.be/images/SMUninstall_combofix.png

    1.) Systeemherstelpunten verwijderen

    Als de computer geïnfecteerd is geweest met een malware infectie is het raadzaam om alle aanwezige systeemherstelpunten te verwijderen, want hier kunnen namelijk besmette herstelpunten tussen zitten.

    Hoe u de herstelpunten verwijderd leest u hier: http://www.malwareinfo.nl/malware/systeemherstel.html

    Hoe u zelf snel een nieuw systeemherstelpunt aan kunt maken leest u hier: http://www.websonic.nl/pctips/windowsvista/vista_systeemherstelstartenuitschakelen.php

    Update daarna ook nog even Adobe reader en Java

    Suc6 Ben

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif

  • Ben

    Hallo Yvonne,

    Na overleg met fazantje mag je de stappen uit deze link doen;

    http://antivirus.startpagina.nl/prikbord/14403445/14410465/re-willen-jullie-mijn-logfiles-bekijken#msg-14410465

    Suc6 Ben

    http://2.bp.blogspot.com/_NAn8-ZItaHE/Scq3w6FaicI/AAAAAAAACVY/QqPkGy7EU7U/s320/school69.gif