tuergopt program not found-skipping autocheck

  • mar

    hoi

    Ik werd door de hardware naar u gestuurd.

    Ik heb het stappenplan opgevolgd en nu 2 log mee gestuurd.

    Malwarebytes Anti-Malware (-evaluatieversie-) 1.65.1.1000

    www.malwarebytes.org

    Databaseversie: v2012.10.23.07

    Windows 7 Service Pack 1 x64 NTFS

    Internet Explorer 9.0.8112.16421

    hansenmarjo :: HANSENMARJO-PC

    Realtime bescherming: Ingeschakeld

    23-10-2012 21:37:55

    mbam-log-2012-10-23 (21-37-55).txt

    Scantype: Snelle scan

    Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scanopties: P2P

    Objecten gescand: 198126

    Verstreken tijd: 2 minuut/minuten, 48 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 1

    HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerwaarden gedetecteerd: 1

    HKCU\Software\InstalledBrowserExtensions\215 Apps|4479 (PUP.CrossFire.SA) -> Data: Giant Savings -> Succesvol in quarantaine geplaatst en verwijderd.

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 21:45:49, on 23-10-2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v9.00 (9.00.8112.16450)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    C:\Windows\SysWOW64\schtasks.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe

    C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe

    C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

    C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    C:\Windows\SysWOW64\ACEngSvr.exe

    C:\Windows\AsScrPro.exe

    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    D:\DAEMON Tools Lite\DTLite.exe

    C:\Program Files (x86)\Spotnet\Spotnet.exe

    C:\Program Files (x86)\Spotnet\SABnzbd.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    D:\downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files (x86)\Giant Savings\Giant Savings.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)

    O4 - HKLM\..\Run: “C:\Program Files (x86)\ASUS\APRP\APRP.EXE”

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: “C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\RunOnce: “C:\Program Files (x86)\TuneUp Utilities 2013\TUMessages.exe” /RegDefrag_Success

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)

    O4 - Global Startup: FancyStart daemon.lnk = ?

    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra ‘Tools’ menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: Accelerated graphics

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O20 - AppInit_DLLs: c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll

    O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    O23 - Service: Browser Manager - Unknown owner - C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    End of file - 12601 bytes

    bedankt alvast

  • Jos H

    hoi Mar

    Malwarebytes heeft al iets gevonden en uitgeschakeld.

    Wacht nu maar op het advies van Huib (fazantje) of Ben

  • fazantje

    Hoi Mar,

    Verwijder als 1e google chrome.

    Waarom? Lees hier.

    Deze kun je later weer installeren.

    Download AdwCleaner by Xplode naar je Bureaublad.

    Sluit alle openstaande vensters.

    Vista en Windows 7 gebruikers: Rechtsklik op AdwCleaner en selecteer als Administrator uitvoeren…

    Voor XP: Gewoon dubbelklikken op AdwCleaner.

    Klik vervolgens op Verwijderen.

    Klik bij AdwCleaner – Informatie op OK

    Klik bij AdwCleaner – Herstarten Noodzakelijk op OK

    Dat tijdens de aktie de snelkoppelingen verdwijnen, is normaal.

    Nadat de PC opnieuw is opgestart, opent een logfile.

    Post dit logje samen met een nieuw HijackThis logje in je volgende bericht.

    Succes,

    Huib;)

  • mar

    Hoi

    Ik heb grome eraf gehaald en er daarna weer opgezet want al mijn adressen waren weg en ik had deze niet in explore staan.

    bedankt alvast

    # AdwCleaner v2.005 - Verslag gemaakt op 24/10/2012 om 09:39:11

    # Geactualiseerd op 14/10/2012 door Xplode

    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

    # Gebruiker : hansenmarjo - HANSENMARJO-PC

    # Opstarten Modus : Normale modus

    # Gelanceerd vanaf : C:\Users\hansenmarjo\Desktop\adwcleaner.exe

    # Optie

    ***** *****

    Aanwezig : Browser Manager

    ***** *****

    File Aanwezig : C:\user.js

    Map Aanwezig : C:\Program Files (x86)\Giant Savings

    Map Aanwezig : C:\ProgramData\Babylon

    Map Aanwezig : C:\ProgramData\Browser Manager

    Map Aanwezig : C:\Users\hansenmarjo\AppData\Local\Giant Savings

    Map Aanwezig : C:\Users\hansenmarjo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj

    Map Aanwezig : C:\Users\hansenmarjo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph

    Map Aanwezig : C:\Users\hansenmarjo\AppData\LocalLow\BabylonToolbar

    Map Aanwezig : C:\Users\hansenmarjo\AppData\Roaming\Babylon

    ***** *****

    Data Aanwezig : HKLM\..\Windows = c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll

    Sleutel Aanwezig : HKCU\Software\AppDataLow\Software\Crossrider

    Sleutel Aanwezig : HKCU\Software\AppDataLow\Software\Giant Savings

    Sleutel Aanwezig : HKCU\Software\BrowserMngr

    Sleutel Aanwezig : HKCU\Software\Cr_Installer

    Sleutel Aanwezig : HKCU\Software\DataMngr

    Sleutel Aanwezig : HKCU\Software\DataMngr_Toolbar

    Sleutel Aanwezig : HKCU\Software\InstalledBrowserExtensions

    Sleutel Aanwezig : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings

    Sleutel Aanwezig : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKCU\Software\Softonic

    Sleutel Aanwezig : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Sleutel Aanwezig : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}

    Sleutel Aanwezig : HKLM\Software\Babylon

    Sleutel Aanwezig : HKLM\Software\BrowserMngr

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.BHO

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.BHO.1

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.FBApi

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.FBApi.1

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.Sandbox

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\CrossriderApp0004479.Sandbox.1

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044444479}

    Sleutel Aanwezig : HKLM\Software\Conduit

    Sleutel Aanwezig : HKLM\Software\DataMngr

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220022442279}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33333333-3333-3333-3333-330033443379}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{55555555-5555-5555-5555-550055445579}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66666666-6666-6666-6666-660066446679}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77777777-7777-7777-7777-770077447779}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndkhncnongaclekkbelchmeafffimifj

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011441179}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}

    Sleutel Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055445579}

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066446679}

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077447779}

    Sleutel Aanwezig : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

    Sleutel Aanwezig : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    Sleutel Aanwezig : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Sleutel Aanwezig : HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Sleutel Aanwezig : HKU\S-1-5-21-2259818667-322241977-2532615236-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Sleutel Aanwezig : HKU\S-1-5-21-2259818667-322241977-2532615236-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}

    Waarde Aanwezig : HKCU\Software\Mozilla\Firefox\Extensions

    Waarde Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar

    Waarde Aanwezig : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar

    ***** *****

    -\\ Internet Explorer v9.0.8112.16421

    = hxxp://search.babylon.com/?affID=110195&tt=3612_4&babsrc=NT_ss&mntrId=008edbb0000000000000e006e677de1b

    -\\ Google Chrome v

    File : C:\Users\hansenmarjo\AppData\Local\Google\Chrome\User Data\Default\Preferences

    De file bevat geen enkele ongeoorloofde invoer.

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner.txt - ##########

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 9:40:46, on 24-10-2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v9.00 (9.00.8112.16450)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

    C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    C:\Windows\SysWOW64\ACEngSvr.exe

    C:\Windows\AsScrPro.exe

    C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe

    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

    C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    D:\downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe,

    O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files (x86)\Giant Savings\Giant Savings.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)

    O4 - HKLM\..\Run: “C:\Program Files (x86)\ASUS\APRP\APRP.EXE”

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - HKCU\..\Run: “C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe” /background

    O4 - HKCU\..\RunOnce: “C:\Program Files (x86)\TuneUp Utilities 2013\TUMessages.exe” /RegDefrag_Success

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)

    O4 - Global Startup: FancyStart daemon.lnk = ?

    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra ‘Tools’ menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: Accelerated graphics

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O20 - AppInit_DLLs: c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll

    O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    O23 - Service: Browser Manager - Unknown owner - C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    End of file - 12384 bytes

  • Ben

    Hallo,

    Je heb bij AdwCleaner niet voor verwijderen gekozen doe dat als nog:

    Start AdwCleaner:

    Klik vervolgens op Verwijderen.

    Plaats dat logje en een nieuw HijackThis logje.

    Gr.Ben

    Antivirusprikbord.nl

  • mar

    hoi

    Helaas progamma Adwcleaner loopt vast.

    Moet ik eerst op zoeken klikken en dan op verwijderen en hoelang duurt het verwijder progamma

    gr mar

  • fazantje

    Hoi Mar,

    Verwijder ADWcleaner, het kan zijn dat de besmetting het verwijderen blokkeert.

    Schakel nu eerst jou virusscanner uit.

    Download Combofix hier en plaats het jou bureaublad.

    Indien je Combofix al eerder hebt gebruikt, gelieve die versie te verwijderen en Combofix opnieuw te downloaden via bovenstaande link,

    want Combofix wordt dagelijks geupdate.

    OPMERKING: indien je, tijdens of na het downloaden van Combofix of tijdens het gebruik van Combofix een melding krijgt

    van je Antivirus- of een andere realtime scanner, schakel dan deze scanner uit en download Combofix opnieuw.

    Sommige scanners zien bepaalde componenten die Combofix gebruikt als verdacht en gaan deze blokkeren of verwijderen!

    Dubbelklik op Combofix.exe

    Volg de instructies, aanvaard de disclaimer.

    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.

    De scan kan, afhankelijk van de besmetting 40 tot wel 100 minuten duren, dus denk niet van hij zit vast.

    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.

    Plaats deze log in je volgende post samen met een nieuw HijackThis log.

    Succes,

    Huib;)

  • mar

    hoi

    Op onze pc staat het ook. Ik ben nu met mijn laptop bezig en doe dezelfde handelingen maar op laptop lijkt het verdwenen te zijn op de pc nog niet

    gr mar

  • Ben

    Hallo,

    Plaats ter controle per pc de logjes.

    En geef aan welke de laptop is en welke de vaste.

    Gr.Ben

    Antivirusprikbord.nl

  • mar

    hoi

    Dit s het log van de laptop

    ComboFix 12-10-23.02 - hansenmarjo 24-10-2012 12:25:23.1.4 - x64

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.6048.4283

    Gestart vanuit: c:\users\hansenmarjo\Desktop\ComboFix.exe

    AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}

    SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}

    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\programdata\FullRemove.exe

    c:\windows\SysWow64\pt

    c:\windows\SysWow64\pt\AuthFWSnapIn.Resources.dll

    c:\windows\SysWow64\pt\AuthFWWizFwk.Resources.dll

    .

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2012-09-24 to 2012-10-24 ))))))))))))))))))))))))))))))

    .

    .

    2012-10-24 11:16 . 2012-10-24 11:16 ——– d—–w- c:\users\Default\AppData\Local\temp

    2012-10-24 08:12 . 2012-10-08 12:28 34656 —-a-w- c:\windows\system32\TURegOpt.exe

    2012-10-24 08:12 . 2012-10-08 12:28 25952 —-a-w- c:\windows\system32\authuitu.dll

    2012-10-24 08:12 . 2012-10-08 12:28 21344 —-a-w- c:\windows\SysWow64\authuitu.dll

    2012-10-24 08:12 . 2012-10-24 08:13 ——– d—–w- c:\program files (x86)\TuneUp Utilities 2013

    2012-10-23 20:59 . 2012-10-23 21:00 ——– d—–w- c:\users\hansenmarjo\AppData\Local\Deployment

    2012-10-23 20:59 . 2012-10-23 20:59 ——– d—–w- c:\users\hansenmarjo\AppData\Local\Apps

    2012-10-23 13:06 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7247D9B5-65FB-4900-9914-184ED107FE31}\mpengine.dll

    2012-10-21 16:02 . 2012-10-04 11:47 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54A5A44C-25CD-4905-9191-ABBCD8839B56}\gapaengine.dll

    2012-10-21 16:02 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

    2012-10-18 08:03 . 2012-10-18 08:03 ——– d—–w- c:\users\hansenmarjo\AppData\Roaming\SunRay Games

    2012-10-18 07:42 . 2012-10-18 07:42 ——– d—–w- c:\users\hansenmarjo\AppData\Roaming\SMIGames

    2012-10-10 19:47 . 2012-10-10 19:47 ——– d—–w- c:\users\hansenmarjo\AppData\Roaming\DreamTaleGame

    2012-10-10 07:59 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll

    2012-10-10 07:59 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll

    2012-10-10 07:59 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll

    2012-10-10 07:59 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll

    2012-10-10 07:59 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll

    2012-10-10 07:59 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll

    2012-10-10 07:57 . 2012-09-14 19:19 2048 —-a-w- c:\windows\system32\tzres.dll

    2012-10-10 07:57 . 2012-09-14 18:28 2048 —-a-w- c:\windows\SysWow64\tzres.dll

    2012-10-04 11:47 . 2012-10-04 11:47 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

    2012-10-04 11:43 . 2012-10-04 11:43 ——– d—–w- c:\programdata\Intenium

    2012-09-26 08:50 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe

    .

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-10-24 10:07 . 2012-08-20 12:28 387 —-a-w- c:\users\hansenmarjo\AppData\Roaming\sp_data.sys

    2012-10-24 09:59 . 2012-08-21 06:07 45056 —-a-w- c:\windows\SysWow64\acovcnt.exe

    2012-10-10 07:55 . 2012-08-21 11:30 65309168 —-a-w- c:\windows\system32\MRT.exe

    2012-09-29 17:54 . 2012-09-16 21:06 25928 —-a-w- c:\windows\system32\drivers\mbam.sys

    2012-08-30 20:03 . 2012-08-30 20:03 228768 —-a-w- c:\windows\system32\drivers\MpFilter.sys

    2012-08-30 20:03 . 2012-03-20 18:44 128456 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys

    2012-08-27 23:49 . 2012-09-14 19:52 9310152 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A1BE10EB-9298-4EED-9960-4B53B21F0C22}\mpengine.dll

    2012-08-24 11:15 . 2012-09-22 18:23 17810944 —-a-w- c:\windows\system32\mshtml.dll

    2012-08-24 10:39 . 2012-09-22 18:23 10925568 —-a-w- c:\windows\system32\ieframe.dll

    2012-08-24 10:31 . 2012-09-22 18:23 2312704 —-a-w- c:\windows\system32\jscript9.dll

    2012-08-24 10:22 . 2012-09-22 18:23 1346048 —-a-w- c:\windows\system32\urlmon.dll

    2012-08-24 10:21 . 2012-09-22 18:23 1392128 —-a-w- c:\windows\system32\wininet.dll

    2012-08-24 10:20 . 2012-09-22 18:23 1494528 —-a-w- c:\windows\system32\inetcpl.cpl

    2012-08-24 10:18 . 2012-09-22 18:23 237056 —-a-w- c:\windows\system32\url.dll

    2012-08-24 10:17 . 2012-09-22 18:23 85504 —-a-w- c:\windows\system32\jsproxy.dll

    2012-08-24 10:14 . 2012-09-22 18:23 173056 —-a-w- c:\windows\system32\ieUnatt.exe

    2012-08-24 10:14 . 2012-09-22 18:23 816640 —-a-w- c:\windows\system32\jscript.dll

    2012-08-24 10:13 . 2012-09-22 18:23 599040 —-a-w- c:\windows\system32\vbscript.dll

    2012-08-24 10:12 . 2012-09-22 18:23 2144768 —-a-w- c:\windows\system32\iertutil.dll

    2012-08-24 10:11 . 2012-09-22 18:23 729088 —-a-w- c:\windows\system32\msfeeds.dll

    2012-08-24 10:10 . 2012-09-22 18:23 96768 —-a-w- c:\windows\system32\mshtmled.dll

    2012-08-24 10:09 . 2012-09-22 18:23 2382848 —-a-w- c:\windows\system32\mshtml.tlb

    2012-08-24 10:04 . 2012-09-22 18:23 248320 —-a-w- c:\windows\system32\ieui.dll

    2012-08-24 06:59 . 2012-09-22 18:23 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll

    2012-08-24 06:51 . 2012-09-22 18:23 1129472 —-a-w- c:\windows\SysWow64\wininet.dll

    2012-08-24 06:51 . 2012-09-22 18:23 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl

    2012-08-24 06:47 . 2012-09-22 18:23 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe

    2012-08-24 06:47 . 2012-09-22 18:23 420864 —-a-w- c:\windows\SysWow64\vbscript.dll

    2012-08-24 06:43 . 2012-09-22 18:23 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb

    2012-08-22 18:12 . 2012-09-12 20:27 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys

    2012-08-22 18:12 . 2012-09-12 20:28 950128 —-a-w- c:\windows\system32\drivers\ndis.sys

    2012-08-22 18:12 . 2012-09-12 20:27 376688 —-a-w- c:\windows\system32\drivers\netio.sys

    2012-08-22 18:12 . 2012-09-12 20:27 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS

    2012-08-21 09:12 . 2012-09-02 06:59 285328 —-a-w- c:\windows\system32\aswBoot.exe

    2012-08-20 17:38 . 2012-10-10 07:58 44032 —-a-w- c:\windows\apppatch\acwow64.dll

    2012-08-20 12:28 . 2011-03-29 02:36 19720 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

    2012-08-02 17:58 . 2012-09-12 20:28 574464 —-a-w- c:\windows\system32\d3d10level9.dll

    2012-08-02 16:57 . 2012-09-12 20:28 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    .

    2012-07-29 11:41 488840 —-a-w- c:\program files (x86)\Giant Savings\Giant Savings.dll

    .

    “Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe”

    .

    “ASUSPRP”=“c:\program files (x86)\ASUS\APRP\APRP.EXE”

    “ASUSWebStorage”=“c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe”

    “SonicMasterTray”=“c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe”

    “ATKOSD2”=“c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe”

    “ATKMEDIA”=“c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe”

    “HControlUser”=“c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe”

    “Wireless Console 3”=“c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe”

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    FancyStart daemon.lnk - c:\windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe

    .

    “ConsentPromptBehaviorAdmin”= 0 (0x0)

    “ConsentPromptBehaviorUser”= 3 (0x3)

    “EnableLUA”= 0 (0x0)

    “EnableUIADesktopToggle”= 0 (0x0)

    “PromptOnSecureDesktop”= 0 (0x0)

    .

    “LoadAppInit_DLLs”=1 (0x1)

    “AppInit_DLLs”=c:\progra~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll

    .

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    @=“”

    .

    @=“Service”

    .

    “Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    .

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

    R2 gupdate;Google Update-service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe

    R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS

    R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE

    R3 gupdatem;Google Update-service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe

    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE

    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys

    R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe

    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE

    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys

    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys

    R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe

    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe

    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys

    S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe

    S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys

    S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    S2 MBAMScheduler;MBAMScheduler;d:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    S2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe

    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys

    S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys

    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys

    S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys

    S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys

    S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys

    S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

    S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys

    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys

    .

    .

    Inhoud van de ‘Gedeelde Taken’ map

    .

    2012-10-24 c:\windows\Tasks\AutoKMS.job

    - c:\autokms\AutoKMS.exe

    .

    2012-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe

    .

    2012-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe

    .

    .

    ——— X64 Entries ———–

    .

    .

    @=“{6D4133E5-0742-4ADC-8A8C-9303440F7190}”

    2011-05-25 07:09 227840 —-a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll

    .

    @=“{64174815-8D98-4CE6-8646-4C039977D808}”

    2011-05-25 07:09 227840 —-a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll

    .

    “IgfxTray”=“c:\windows\system32\igfxtray.exe”

    “HotKeysCmds”=“c:\windows\system32\hkcmd.exe”

    “AmIcoSinglun64”=“c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe”

    “RtHDVBg”=“c:\program files\Realtek\Audio\HDA\RAVBg64.exe”

    “BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe”

    “MSC”=“c:\program files\Microsoft Security Client\msseces.exe”

    .

    ——- Bijkomende Scan ——-

    .

    uLocal Page = c:\windows\system32\blank.htm

    uStart Page = hxxp://www.google.nl/

    mStart Page = hxxp://asus.msn.com

    IE: &Verzenden naar OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.1.1

    .

    - - - - ORPHANS VERWIJDERD - - - -

    .

    Toolbar-Locked - (no file)

    Toolbar-Locked - (no file)

    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

    HKLM-Run-SynAsusAcpi - c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe

    AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr

    .

    .

    .

    ——————— VERGRENDELDE REGISTER SLEUTELS ———————

    .

    @Denied: (A 2) (Everyone)

    @=“FlashBroker”

    “LocalizedString”=“@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101”

    .

    “Enabled”=dword:00000001

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    .

    @Denied: (A 2) (Everyone)

    @=“Shockwave Flash Object”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx”

    “ThreadingModel”=“Apartment”

    .

    @=“0”

    .

    @=“ShockwaveFlash.ShockwaveFlash.10”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1”

    .

    @=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”

    .

    @=“1.0”

    .

    @=“ShockwaveFlash.ShockwaveFlash”

    .

    @Denied: (A 2) (Everyone)

    @=“Macromedia Flash Factory Object”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx”

    “ThreadingModel”=“Apartment”

    .

    @=“FlashFactory.FlashFactory.1”

    .

    @=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1”

    .

    @=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”

    .

    @=“1.0”

    .

    @=“FlashFactory.FlashFactory”

    .

    @Denied: (A 2) (Everyone)

    @=“IFlashBroker4”

    .

    @=“{00020424-0000-0000-C000-000000000046}”

    .

    @=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”

    “Version”=“1.0”

    .

    @Denied: (Full) (Everyone)

    .

    Voltooingstijd: 2012-10-24 13:21:22

    ComboFix-quarantined-files.txt 2012-10-24 11:21

    .

    Pre-Run: 143.365.251.072 bytes beschikbaar

    Post-Run: 142.981.820.416 bytes beschikbaar

    .

    - - End Of File - - 9D3EC049E026BFA062D5DE7BD32681F2

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 13:23:57, on 24-10-2012

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v9.00 (9.00.8112.16450)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe

    C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe

    d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe

    C:\Windows\AsScrPro.exe

    C:\Windows\SysWOW64\ACEngSvr.exe

    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe

    C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    D:\downloads\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: CrossriderApp0004479 - {11111111-1111-1111-1111-110011441179} - C:\Program Files (x86)\Giant Savings\Giant Savings.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll” (file missing)

    O3 - Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)

    O4 - HKLM\..\Run: “C:\Program Files (x86)\ASUS\APRP\APRP.EXE”

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

    O4 - HKLM\..\Run: C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

    O4 - HKCU\..\Run: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

    O4 - Global Startup: FancyStart daemon.lnk = ?

    O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000

    O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra ‘Tools’ menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

    O11 - Options group: Accelerated graphics

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O20 - AppInit_DLLs: c:\PROGRA~3\BROWSE~1\23787~1.43\{16CDF~1\browsemngr.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

    O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe

    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: MBAMScheduler - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - d:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    End of file - 11172 bytes

    bedankt alvast

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.