Combofix of securityscan?
Hierbij de log van Combofix, de site van Securityscan kan ik niet benaderen. Zijn er nog andere mogelijkheden?
ComboFix 14-01-01.01 - Verkleij 01-01-2014 18:31:59.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3069.1670
Gestart vanuit: c:\users\Verkleij\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2013-12-01 to 2014-01-01 ))))))))))))))))))))))))))))))
.
.
2014-01-01 17:40 . 2014-01-01 17:40 ——– d—–w- c:\users\Gast\AppData\Local\temp
2014-01-01 17:40 . 2014-01-01 17:40 ——– d—–w- c:\users\Default\AppData\Local\temp
2014-01-01 17:40 . 2014-01-01 17:40 ——– d—–w- c:\users\cinor 8\AppData\Local\temp
2014-01-01 17:40 . 2014-01-01 17:40 ——– d—–w- c:\users\cinor 8 oud\AppData\Local\temp
2014-01-01 17:39 . 2014-01-01 17:39 0 —ha-w- c:\users\Verkleij\BITA546.tmp
2014-01-01 17:25 . 2013-12-04 02:57 7760024 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C03BFCA7-4E71-4B31-8798-B67567AB26B9}\mpengine.dll
2013-12-31 18:32 . 2014-01-01 17:40 ——– d—–w- c:\users\Verkleij\AppData\Local\Temp
2013-12-31 18:08 . 2014-01-01 08:56 ——– d—–w- C:\zoek_backup
2013-12-31 14:30 . 2013-12-31 14:30 ——– d—–w- C:\FRST
2013-12-31 13:17 . 2013-12-31 13:16 719224 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2E7E153-F8A8-4822-9F12-0853C0B4D996}\gapaengine.dll
2013-12-31 13:16 . 2013-12-04 02:57 7760024 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-30 19:22 . 2013-12-30 19:22 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-12-30 18:17 . 2013-12-30 18:17 ——– d—–w- C:\rsit
2013-12-30 18:17 . 2013-12-30 18:17 ——– d—–w- c:\program files\trend micro
2013-12-30 13:49 . 2013-12-30 13:49 ——– d—–w- c:\program files\ESET
2013-12-30 13:33 . 2013-12-30 13:33 ——– d—–w- c:\users\Verkleij\AppData\Roaming\Malwarebytes
2013-12-30 13:32 . 2013-12-30 13:32 ——– d—–w- c:\programdata\Malwarebytes
2013-12-30 13:32 . 2013-12-30 13:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-12-30 13:32 . 2013-04-04 13:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-12-30 13:24 . 2013-12-30 13:26 ——– d—–w- C:\AdwCleaner
2013-12-28 17:54 . 2013-12-28 17:54 ——– d—–w- c:\windows\Migration
2013-12-28 17:53 . 2013-10-30 00:35 2050560 —-a-w- c:\windows\system32\win32k.sys
2013-12-28 17:53 . 2013-10-30 02:12 335360 —-a-w- c:\windows\system32\SysFxUI.dll
2013-12-28 17:53 . 2013-10-30 01:43 130048 —-a-w- c:\windows\system32\drivers\drmk.sys
2013-12-28 17:53 . 2013-10-30 00:43 167936 —-a-w- c:\windows\system32\drivers\portcls.sys
2013-12-28 17:52 . 2013-10-11 02:08 131072 —-a-w- c:\windows\system32\wshom.ocx
2013-12-28 17:52 . 2013-10-11 00:35 155648 —-a-w- c:\windows\system32\wscript.exe
2013-12-28 17:52 . 2013-10-11 02:08 36864 —-a-w- c:\windows\system32\wshcon.dll
2013-12-28 17:52 . 2013-10-11 02:08 172032 —-a-w- c:\windows\system32\scrrun.dll
2013-12-28 17:52 . 2013-10-11 00:35 135168 —-a-w- c:\windows\system32\cscript.exe
2013-12-28 17:52 . 2013-10-22 07:19 158208 —-a-w- c:\windows\system32\imagehlp.dll
2013-12-28 15:43 . 2013-12-28 15:43 ——– d—–w- c:\programdata\LightScribe
2013-12-10 15:54 . 2013-12-10 15:55 ——– d—–w- c:\program files\Mozilla Firefox(114)
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-28 19:38 . 2012-04-15 12:45 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-28 19:38 . 2012-04-15 12:45 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-19 10:21 . 2009-10-03 15:02 230048 ——w- c:\windows\system32\MpSigStub.exe
2013-10-30 02:13 . 2008-01-21 02:23 1304064 —-a-w- c:\windows\system32\WMALFXGFXDSP.dll
2013-10-11 02:08 . 2013-11-14 11:00 444928 —-a-w- c:\windows\system32\IKEEXT.DLL
2013-10-11 02:07 . 2013-11-14 11:00 596480 —-a-w- c:\windows\system32\FWPUCLNT.DLL
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“LightScribe Control Panel”=“c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe”
“Skype”=“c:\program files\Skype\Phone\Skype.exe”
“ehTray.exe”=“c:\windows\ehome\ehTray.exe”
.
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll”
“SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe”
“HP Health Check Scheduler”=“c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe”
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
“SmartMenu”=“c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe”
“APSDaemon”=“c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe”
“MSC”=“c:\program files\Microsoft Security Client\msseces.exe”
“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe”
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe”
“SysTrayApp”=“c:\program files\IDT\WDM\sttray.exe”
.
“EnableUIADesktopToggle”= 0 (0x0)
.
“AppInit_DLLs”=c:\windows\System32\acaptuser32.dll
.
@=“Service”
.
@=“”
.
@=“Service”
.
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnk.CommonStartup
backupExtension=.CommonStartup
.
2010-09-22 17:11 640440 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
2011-09-07 13:53 40376 —-a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
2009-03-23 17:00 1983816 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
2009-03-17 16:40 767312 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
2008-09-25 17:42 189736 ——w- c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
2008-09-26 01:36 1148200 ——w- c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe
.
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
2008-10-09 05:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
2008-12-08 13:50 54576 —-a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
2008-04-15 13:51 488752 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
2008-06-09 09:16 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
2009-10-03 10:40 13826664 —-a-w- c:\windows\System32\nvcpl.dll
.
2008-08-01 15:14 202032 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
2008-09-23 10:03 912688 —-a-w- c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
.
2010-10-29 13:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
2011-10-14 03:36 2299176 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
2009-07-21 21:33 458844 —-a-w- c:\program files\IDT\WDM\sttray.exe
.
2008-09-25 17:41 1152296 ——w- c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
.
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
2008-06-09 09:14 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhoud van de ‘Gedeelde Taken’ map
.
2014-01-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
.
2012-06-06 c:\windows\Tasks\HPCeeScheduleForcinor 8 oud.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe
.
.
——- Bijkomende Scan ——-
.
uStart Page = about:blank
IE: Converteren naar Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Doel van koppeling converteren naar Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Doel van koppeling toevoegen aan bestaande PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Toevoegen aan bestaande PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Verkleij\AppData\Roaming\Mozilla\Firefox\Profiles\fpz3hy76.default-1384266771836\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-01-01 18:40
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen …
.
scannen van verborgen autostart items …
.
scannen van verborgen bestanden …
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
“ImagePath”=“\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl”
.
Voltooingstijd: 2014-01-01 18:42:25
ComboFix-quarantined-files.txt 2014-01-01 17:42
ComboFix2.txt 2013-12-31 11:51
.
Pre-Run: 206.735.740.928 bytes beschikbaar
Post-Run: 206.704.631.808 bytes beschikbaar
.
- - End Of File - - 9F9CE841F617826BF71F6D421CA87819
5C86ADEC17B739C437E145E3B3FC2E6D
Hallo
Wil je nog even voor de zekerheid het volgende laten controleren:
Ga hiervoor naar de site Virustotal
c:\users\Verkleij\BITA546.tmp
Wacht het resultaat af, sla dit op en plak dit in je volgende post.
Klik op re-analyse als het bestand al eens eerder gescand werd.
Download: http://www.bleepingcomputer.com/download/securitycheck/ en sla het op je Bureaublad op.
Start Security Check.
Volg de Instructies in het scherm.
Aan het eind verschijnt een log (checkup.txt) plaats de inhoud ervan in je volgende antwoord.
File c:\users\Verkleij\BITA546.tmp is onvindbaar.
Securityscan uitgevoerdm zie logje:
Results of screen317's Security Check version 0.99.78
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
(On Access scanning disabled!)
Error obtaining update status for antivirus!
`````````Anti-malware/Other Utilities Check:`````````
CCleaner
Java(TM) 6 Update 24
Java(TM) 6 Update 7
Java version out of Date!
Adobe Flash Player 11.9.900.170
Adobe Reader 9 Adobe Reader out of Date!
Adobe Reader 10.1.3 Adobe Reader out of Date!
Mozilla Firefox (26.0)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
Hallo,
Voer zoek.exe nogmaals uit met de volgende code;
c:\users\Verkleij\BITA546.tmp;vs
Plaats hier het logje.
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
(On Access scanning disabled!)
Error obtaining update status for antivirus! Is deze niet up-to-date of werkt hij niet?
Java(TM) 6 Update 24
Java(TM) 6 Update 7
Java version out of Date! Verwijder al deze java's en download de nieuwste.
Update ook de volgende twee programma's.
Adobe Reader 9 Adobe Reader out of Date!
Adobe Reader 10.1.3 Adobe Reader out of Date!
Hierbij het logje:
Zoek.exe v5.0.0.0 Updated 28-December-2013
Tool run by Verkleij on wo 01-01-2014 at 19:33:05,37.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Verkleij\Desktop\zoek.exe
==== Older Logs ======================
C:\zoek-results2013-12-31-183452.log 46809 bytes
C:\zoek-results2014-01-01-085623.log 1492 bytes
==== C:\zoek_backup content ======================
C:\zoek_backup (files=117 folders=35 159493382 bytes)
==== EOF on wo 01-01-2014 at 19:33:59,08 ======================
Microsoft Security Essentials staat uit i.v.m. de combofix, heb hem nu weer aangezet.
Heb tevens de nieuwste Java geinstaleerd.
De acrobat reader is niet te updaten i.v.m. een of andere patch die niet klopt.
Gr.
Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.
Weet je zeker dat je deze post als spam wil rapporteren aan de beheerder?
Deze post wordt als spam gerapporteerd aan de beheerder van het forum. Bedankt!
Weet u zeker dat u dit topic wil verwijderen?