PCM Media Sharing.exe werkt niet meer

  • maria

    hallo , na installeren nieuwe adobe en update van quick time en andere adobe onderdelen kreeg ik na herstart deze mededeling.iemand zei me dan zal je wel een trojan ergens hebben. ik heb het stappenplan gedaan , wil iemand a.u.b. mijn logjes nakijken alvast vriendelijk dank.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:53:11, on 21-9-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v8.00 (8.00.6001.19120)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Windows\RtHDVCpl.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe

    C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Ask.com\Updater\Updater.exe

    C:\Windows\WindowsMobile\wmdSync.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Users\Dario\Program Files\DNA\btdna.exe

    C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Windows\System32\mobsync.exe

    C:\Program Files\OpenOffice.org 3\program\soffice.exe

    C:\Program Files\OpenOffice.org 3\program\soffice.bin

    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE

    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

    C:\Windows\system32\conime.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\Hijackthis\HijackThis.exe

    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nl.intl.acer.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O1 - Hosts: ::1 localhost

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll

    O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: RtHDVCpl.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe

    O4 - HKLM\..\Run: Skytel.exe

    O4 - HKLM\..\Run: “C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe”

    O4 - HKLM\..\Run: C:\ACERSW\config\SetApanel.cmd

    O4 - HKLM\..\Run: C:\Acer\WR_PopUp\WarReg_PopUp.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Acer\AcerTour\Reminder.exe

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe” /WinStart

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Ask.com\Updater\Updater.exe”

    O4 - HKLM\..\Run: %windir%\WindowsMobile\wmdSync.exe

    O4 - HKLM\..\Run: C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F “C:\Windows\TEMP\E_SCE56.tmp” /EF “HKLM”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEJE.EXE /FU “C:\Windows\TEMP\E_S8F86.tmp” /EF “HKCU”

    O4 - HKCU\..\Run: “C:\Users\D\Program Files\DNA\btdna.exe”

    O4 - HKCU\..\Run: “C:\Program Files\Uniblue\RegistryBooster\launcher.exe” delay 20000

    O4 - HKCU\..\Run: C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\Run: rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Startup: OpenOffice.org 3.1 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    O4 - Global Startup: Empowering Technology Launcher.lnk = ?

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe

    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe

    End of file - 11840 bytes

    alwarebytes' Anti-Malware 1.51.2.1300

    www.malwarebytes.org

    Databaseversie: 7765

    Windows 6.0.6002 Service Pack 2

    Internet Explorer 8.0.6001.19120

    21-9-2011 22:42:44

    mbam-log-2011-09-21 (22-42-44).txt

    Scantype: Snelle scan

    Objecten gescand: 251508

    Verstreken tijd: 8 minuut/minuten, 41 seconde(n)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 3

    Registerwaarden geïnfecteerd: 4

    Registerdata geïnfecteerd: 0

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 2

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels geïnfecteerd:

    HKEY_CLASSES_ROOT\CLSID\{4PLQWI0B-JX1N-Y22T-8553-145WGV50S02X} (Trojan.Downloader) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4PLQWI0B-JX1N-Y22T-8553-145WGV50S02X} (Trojan.Downloader) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{4PLQWI0B-JX1N-Y22T-8553-145WGV50S02X} (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registerwaarden geïnfecteerd:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HKCU (Backdoor.Bot.M) -> Value: HKCU -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HKLM (Trojan.Downloader) -> Value: HKLM -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies (Trojan.Downloader) -> Value: Policies -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Policies (Trojan.Downloader) -> Value: Policies -> Quarantined and deleted successfully.

    Registerdata geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen geïnfecteerd:

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden geïnfecteerd:

    c:\Users\D\AppData\Roaming\install\server.exe (Backdoor.Bot.M) -> Quarantined and deleted successfully.

    c:\Windows\System32\install\server.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

  • maria

    in de lijst van windows defender staat de PCM Media Sharing.exe nu - toegestaan , dus neem ik aan dat dat nu in orde is. er staan nog meer dingen met nog niet ingedeeld , maar ik weet niet waar die van zijn

  • fazantje

    Hoi Maria,

    Verwijder eerst de volgende toolbars:

    Toolbar: EPSON Web-To-Page

    Toolbar: Ask Toolbar

    Toolbar: Easy Photo Print

    Toolbar: Acer eDataSecurity Management

    Start HijackThis, klik op scan en vink daarna de volgende regels aan:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    Download combofix Hier

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt van je Antivirus- of een andere realtime scanner,

    schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    Dubbelklik op Combofix.exe

    Volg de instructies, aanvaard de disclaimer.

    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    Het kan enige tijd duren voordat het logje van combofix komt, dus denk niet van hij is op tilt.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze log in je volgende post samen met een nieuw HijackThis logje.

    En vertel hoe het nu is.

    Succes,

    Huib;)

  • maria

    alleen de ask toolbar stond bij programma`s en onderdelen. waar vind ik de andere 3 ?

  • fazantje

    Hoi Maria,

    Werk je met Firefox, dan het volgende doen:

    Open firefox, in het menu Extra de optie Add-ons selecteren.

    Bij Extensies zal je de toolbar zien staan.

    Selecteer die en kies Deïnstalleren.

    Herstart Firefox na je bevestiging: de toolbar is verdwenen.

    Andere optie voor Firefox:

    In Firefox 4 klikt u links van de zoekbalk op het keuzemenu en kiest u Zoekmachines beheren.

    Selecteer uw favoriete zoekmachine en klik net zolang op de knop Omhoog tot die zoekmachine bovenaan in het lijstje staat.

    Overbodige zoekmachines verwijdert u met de knop Verwijderen.

    Voor Internet Explorer 8:

    Open Internet Explorer.

    Hier klik je achtereenvolgens op Extra en Invoegtoepassingen beheren.

    Bij Werkbalken en extensies selecteer je de toolbar en klik je op Uitschakelen.

    Druk op Sluiten en herstart de browser.

    Andere optie voor IE 9:

    In Internet Explorer 9 klikt u aan de rechterzijde op het pictogram met het tandwiel en kiest u Invoegtoepassingen beheren / Zoekmachines.

    Selecteer uw favoriete zoekmachine en klik op Als standaardinvoegtoepassing installeren.

    Overbodige zoekmachines verwijdert u met de knop Verwijderen.

    Als dit niet lukt Maria, dan gewoon verder gaan met de stappen die ik heb aangegeven.

    Voor dat je combofix gaat starten, eerst NOD32 even uitschakelen.

    Dat doe je als volgt:

    Klik met de rechter muisknop op het NOD32 icoontje, rechts onderin de taakbalk.

    Klik nu op antivirus en antispyware beveiliging uitschakelen en je ziet dat het icoontje oranje/rood wordt.

    Nu kun je verder gaan.

    Succes,

    Huib;)

  • maria

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:53:11, on 21-9-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v8.00 (8.00.6001.19120)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Windows\RtHDVCpl.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe

    C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Ask.com\Updater\Updater.exe

    C:\Windows\WindowsMobile\wmdSync.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Users\Dario\Program Files\DNA\btdna.exe

    C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Windows\System32\mobsync.exe

    C:\Program Files\OpenOffice.org 3\program\soffice.exe

    C:\Program Files\OpenOffice.org 3\program\soffice.bin

    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE

    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

    C:\Windows\system32\conime.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\Hijackthis\HijackThis.exe

    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*http://uk.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nl.intl.acer.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O1 - Hosts: ::1 localhost

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll

    O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O4 - HKLM\..\Run: %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: RtHDVCpl.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe

    O4 - HKLM\..\Run: Skytel.exe

    O4 - HKLM\..\Run: “C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe”

    O4 - HKLM\..\Run: C:\ACERSW\config\SetApanel.cmd

    O4 - HKLM\..\Run: C:\Acer\WR_PopUp\WarReg_PopUp.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Acer\AcerTour\Reminder.exe

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe” /WinStart

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Ask.com\Updater\Updater.exe”

    O4 - HKLM\..\Run: %windir%\WindowsMobile\wmdSync.exe

    O4 - HKLM\..\Run: C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /F “C:\Windows\TEMP\E_SCE56.tmp” /EF “HKLM”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEJE.EXE /FU “C:\Windows\TEMP\E_S8F86.tmp” /EF “HKCU”

    O4 - HKCU\..\Run: “C:\Users\Dario\Program Files\DNA\btdna.exe”

    O4 - HKCU\..\Run: “C:\Program Files\Uniblue\RegistryBooster\launcher.exe” delay 20000

    O4 - HKCU\..\Run: C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\Run: rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Startup: OpenOffice.org 3.1 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    O4 - Global Startup: Empowering Technology Launcher.lnk = ?

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe

    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe

    End of file - 11840 bytes

    ComboFix 11-09-21.04 - Dario 22-09-2011 10:01:32.1.2 - x86

    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3071.1838

    Gestart vanuit: c:\users\Dario\Downloads\ComboFix.exe

    AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}

    SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}

    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\users\Dario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1 .lnk

    c:\windows\system32\delete.bat

    c:\windows\system32\install

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2011-08-22 to 2011-09-22 ))))))))))))))))))))))))))))))

    .

    .

    2011-09-22 08:07 . 2011-09-22 08:07 ——– d—–w- c:\users\Default\AppData\Local\temp

    2011-09-21 20:52 . 2011-09-21 20:52 ——– d—–w- c:\program files\Trend Micro

    2011-09-21 20:31 . 2011-09-21 20:31 ——– d—–w- c:\users\Dario\AppData\Roaming\Malwarebytes

    2011-09-21 20:31 . 2011-09-21 20:31 ——– d—–w- c:\programdata\Malwarebytes

    2011-09-21 20:31 . 2011-09-21 20:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware

    2011-09-21 20:31 . 2011-08-31 15:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys

    2011-09-21 20:04 . 2009-06-30 08:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys

    2011-09-21 20:04 . 2011-09-21 20:04 ——– d—–w- c:\program files\Panda Security

    2011-09-20 19:26 . 2011-08-12 02:44 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21578437-8A4A-40E0-8C40-63EEBC04E134}\mpengine.dll

    2011-09-14 08:52 . 2011-08-10 12:14 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat

    2011-09-13 18:51 . 2011-09-13 18:51 ——– d—–w- c:\windows\system32\Adobe

    2011-09-13 18:13 . 2011-09-13 18:13 ——– d—–w- c:\program files\ESET

    2011-09-12 21:33 . 2011-09-12 21:33 ——– d—–w- c:\program files\Apple Software Update

    2011-09-12 20:47 . 2011-09-12 20:47 ——– d—–w- c:\program files\Common Files\Java

    2011-09-12 20:47 . 2011-09-12 20:46 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

    2011-09-12 20:47 . 2011-09-12 20:46 472808 —-a-w- c:\windows\system32\deployJava1.dll

    2011-09-12 20:46 . 2011-09-12 20:46 ——– d—–w- c:\program files\Java

    2011-09-05 17:04 . 2011-09-05 17:04 183696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll

    2011-09-05 17:04 . 2011-09-05 17:04 183696 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll

    2011-09-03 11:27 . 2011-09-03 11:27 ——– d—–w- c:\programdata\WindowsSearch

    2011-08-24 11:27 . 2011-07-11 13:25 2048 —-a-w- c:\windows\system32\tzres.dll

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2011-09-13 18:40 . 2011-08-07 14:04 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2011-08-09 11:57 . 2011-08-09 11:57 163424 —-a-w- c:\windows\system32\drivers\eamonm.sys

    2011-08-04 07:20 . 2011-08-04 07:20 103112 —-a-w- c:\windows\system32\drivers\epfwwfpr.sys

    2011-08-04 07:20 . 2011-08-04 07:20 118104 —-a-w- c:\windows\system32\drivers\ehdrv.sys

    2011-07-23 11:04 . 2011-08-10 08:44 916480 —-a-w- c:\windows\system32\wininet.dll

    2011-07-23 11:00 . 2011-08-10 08:44 43520 —-a-w- c:\windows\system32\licmgr10.dll

    2011-07-23 10:59 . 2011-08-10 08:44 1469440 —-a-w- c:\windows\system32\inetcpl.cpl

    2011-07-23 10:59 . 2011-08-10 08:44 71680 —-a-w- c:\windows\system32\iesetup.dll

    2011-07-23 10:59 . 2011-08-10 08:44 109056 —-a-w- c:\windows\system32\iesysprep.dll

    2011-07-23 10:03 . 2011-08-10 08:44 385024 —-a-w- c:\windows\system32\html.iec

    2011-07-23 09:27 . 2011-08-10 08:44 133632 —-a-w- c:\windows\system32\ieUnatt.exe

    2011-07-23 09:25 . 2011-08-10 08:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb

    2011-07-06 15:31 . 2011-08-10 08:45 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys

    2011-07-05 16:37 . 2011-07-05 16:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx

    2011-07-05 16:37 . 2011-07-05 16:37 69632 —-a-w- c:\windows\system32\QuickTime.qts

    2011-09-06 14:34 . 2011-07-09 18:01 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    “Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe”

    “BitTorrent DNA”=“c:\users\Dario\Program Files\DNA\btdna.exe”

    “AutoStartNPSAgent”=“c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe”

    “WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe”

    .

    “RtHDVCpl”=“RtHDVCpl.exe”

    “Acer Empowering Technology Monitor”=“c:\acer\Empowering Technology\SysMonitor.exe”

    “eDataSecurity Loader”=“c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe”

    “PCMMediaSharing”=“c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe”

    “Skytel”=“Skytel.exe”

    “PlayMovie”=“c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe”

    “WarReg_PopUp”=“c:\acer\WR_PopUp\WarReg_PopUp.exe”

    “StartCCC”=“c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe”

    “Acer Tour Reminder”=“c:\acer\AcerTour\Reminder.exe”

    “GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe”

    “NBAgent”=“c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe”

    “AppleSyncNotifier”=“c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe”

    “iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe”

    “Windows Mobile-based device management”=“c:\windows\WindowsMobile\wmdSync.exe”

    “SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe”

    “Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “QuickTime Task”=“c:\program files\QuickTime\QTTask.exe”

    “egui”=“c:\program files\ESET\ESET NOD32 Antivirus\egui.exe”

    “Malwarebytes' Anti-Malware (reboot)”=“c:\program files\Malwarebytes' Anti-Malware\mbam.exe”

    .

    “Acer Tour Reminder”=“c:\acer\AcerTour\Reminder.exe”

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe

    Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    .

    “EnableUIADesktopToggle”= 0 (0x0)

    “EnableLinkedConnections”= 1 (0x1)

    .

    “DisableMonitoring”=dword:00000001

    .

    “DisableMonitoring”=dword:00000001

    .

    “DisableMonitoring”=dword:00000001

    .

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

    R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys

    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe

    S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys

    S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys

    S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl

    S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe

    S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys

    S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe

    S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys

    S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe

    S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe

    S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe

    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS

    S3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\system32\DRIVERS\RTL85n86.sys

    .

    .

    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    WindowsMobile REG_MULTI_SZ wcescomm rapimgr

    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

    .

    .

    ——- Bijkomende Scan ——-

    .

    uStart Page = hxxp://www.startpagina.nl/

    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7

    mStart Page = hxxp://nl.intl.acer.yahoo.com

    uInternet Settings,ProxyOverride = *.local

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.1.254

    FF - ProfilePath - c:\users\Dario\AppData\Roaming\Mozilla\Firefox\Profiles\0mo05nta.default\

    FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)

    FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/home

    FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=toolbar2&q=

    FF - prefs.js: network.proxy.type - 0

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

    HKCU-Run-RegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe

    HKLM-Run-IgfxTray - c:\windows\system32\igfxtray.exe

    HKLM-Run-HotKeysCmds - c:\windows\system32\hkcmd.exe

    HKLM-Run-Persistence - c:\windows\system32\igfxpers.exe

    HKLM-Run-Acer Tour - (no file)

    HKLM-Run-Apanel - c:\acersw\config\SetApanel.cmd

    HKLM-Run-eRecoveryService - (no file)

    HKLM-Run-NPSStartup - (no file)

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2011-09-22 10:07

    Windows 6.0.6002 Service Pack 2 NTFS

    .

    scannen van verborgen processen …

    .

    scannen van verborgen autostart items …

    .

    scannen van verborgen bestanden …

    .

    Scan succesvol afgerond

    verborgen bestanden: 0

    .

    **************************************************************************

    .

    “ImagePath”=“\??\c:\program files\Acer Arcade Live\Acer PlayMovie\000.fcl”

    .

    ——————— VERGRENDELDE REGISTER SLEUTELS ———————

    .

    “Name”=“ActiveSync”

    “DisplayName”=“Microsoft ActiveSync”

    “Param1”=“ActiveSync”

    “Type”=“wellknown”

    “Order”=dword:00000001

    “State”=dword:00000020

    .

    “Name”=“IESettings”

    “Type”=“IESettings”

    “Order”=dword:00000003

    “State”=dword:0000000b

    .

    “Name”=“MediaFiles”

    “Type”=“MediaFiles”

    “Order”=dword:00000002

    “State”=dword:0000000b

    .

    “Name”=“Outlook”

    “DisplayName”=“Microsoft Outlook”

    “Param1”=“Outlook”

    “Type”=“wellknown”

    “Order”=dword:00000000

    “State”=dword:00000020

    .

    @Denied: (A) (Users)

    @Denied: (A) (Everyone)

    @Allowed: (B 1 2 3 4 5) (S-1-5-20)

    “BlindDial”=dword:00000000

    .

    Voltooingstijd: 2011-09-22 10:09:46

    ComboFix-quarantined-files.txt 2011-09-22 08:09

    .

    Pre-Run: 112.525.611.008 bytes beschikbaar

    Post-Run: 112.630.378.496 bytes beschikbaar

    .

    - - End Of File - - ABC410839BF0B8BFDC35AD50E0736D43

    toolbars via IE uitgezet , hier de logjes.

    krijg nu wel waarschuwing van geblokkeerde opstartprogramma`s maar ik weet niet waar die voor zijn dus daar heb ik niets mee gedaan.

    hopenlijk zijn de logjes nu goed en is pc nu weer schoon.

  • fazantje

    Hoi Maria,

    Zou je een nieuw HijackThis logje willen plaatsen.

    Deze is van gisteren, zie:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:53:11, on 21-9-2011

    Groetjes Huib;)

  • maria

    ik had hem echt opnieuw aangeklikt , maar ik probeer het opnieuw. en als ik nu jullie prikbord open komt er dat ik beveiligde pagina`s ga weergeven.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 10:54:10, on 22-9-2011

    Platform: Windows Vista SP2 (WinNT 6.00.1906)

    MSIE: Internet Explorer v8.00 (8.00.6001.19120)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\RtHDVCpl.exe

    C:\Acer\Empowering Technology\SysMonitor.exe

    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe

    C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Windows\WindowsMobile\wmdSync.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Windows Sidebar\sidebar.exe

    C:\Users\Dario\Program Files\DNA\btdna.exe

    C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE

    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe

    C:\Program Files\eMule\emule.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nl.intl.acer.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll

    O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

    O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

    O4 - HKLM\..\Run: RtHDVCpl.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\SysMonitor.exe

    O4 - HKLM\..\Run: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

    O4 - HKLM\..\Run: C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe

    O4 - HKLM\..\Run: Skytel.exe

    O4 - HKLM\..\Run: “C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe”

    O4 - HKLM\..\Run: C:\Acer\WR_PopUp\WarReg_PopUp.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: C:\Acer\AcerTour\Reminder.exe

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe” /WinStart

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: %windir%\WindowsMobile\wmdSync.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\QTTask.exe” -atboottime

    O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe” /hide /waitservice

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: “C:\Users\Dario\Program Files\DNA\btdna.exe”

    O4 - HKCU\..\Run: C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-18\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘SYSTEEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\Acer\AcerTour\Reminder.exe (User ‘Default user’)

    O4 - Global Startup: Empowering Technology Launcher.lnk = ?

    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe

    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

    O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe

    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

    O23 - Service: Planner voor Automatische LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe

    End of file - 9537 bytes

    moest als administrator , dus nu een goede datum en tijd

  • fazantje

    Hoi Maria,

    Start HijackThis, klik op scan en vink daarna de volgende regel aan:

    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)

    Sluit alle vensters, behalve van hijackThis en klik op fix checked.

    Kijk uit met bittorrent.

    Combo kun je verwijderen.

    Verwijder Combofix volg de onderstaande instructies.

    Ga naar Start - Uitvoeren

    Kopieer en plak: Combofix /Uninstall in de startzoekbalk.

    Druk ENTER daarna op OK.

    Als het goed is krijg je dan een melding dat Combofix verwijderd werd.

    Laat Ccleaner standaard draaien.

    Eerst de cleaner en daarna het register.

    Let wel op bij het installeren van Ccleaner dat je het vinkje weg haalt bij google chrome, anders krijg je deze er gratis erbij.

    Succes,

    Huib;)

  • maria

    bedankt , dus ik begrijp dat nu alles goed is ? ik gebruik geen bittorent ,( vorige eigenaar , mjn zoon , wel) ik gebruik alleen e-mule en die heeft 4 minuten nodig om te starten wat op laptop niet zo is.weet je hoe dat komt ? en ccleaner doe ik altijd een maal per week.