ik heb een korte tijd een groot probleem.
ik heb een virus of zo op mijn computer.
ik heb geprobeerd mijn computer scannen;maar het kan het niet.
elke keer als ik de scan start,val het programma meteen uit.geen een van de virusscan kan gestard worden.
ik heb die gekregen met combofix
zeg het iets voor jou?
ik heb een virus of zo op mijn computer.
ik heb geprobeerd mijn computer scannen;maar het kan het niet.
elke keer als ik de scan start,val het programma meteen uit.geen een van de virusscan kan gestard worden.
ik heb die gekregen met combofix
zeg het iets voor jou?
Code:
xxxxxxxx - 11-09-30 23:45:16,18 Service Pack 3
ComboFix 06.10.19 - Running from: "E:\Papa\zzzSoftware\Zsoftware\Doc software\Computer Fixing & Utilities"
((((((((((((((((((((((((((((((( Files Created from 2011-08-30 to 2011-09-30 ))))))))))))))))))))))))))))))))))
2011-09-30 23:26 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2011-09-30 23:26 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2011-09-30 23:26 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2011-09-30 23:26 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2011-09-30 23:25 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2011-09-29 22:59 211,456 --a------ C:\WINDOWS\system32\drivers\ACPIWMI.dll
2011-09-29 22:59 204,800 --a------ C:\WINDOWS\system32\drivers\AsDMI.dll
2011-09-29 22:59 192,512 --a------ C:\WINDOWS\system32\drivers\UpdateHelper.dll
2011-09-29 22:59 11,832 --a------ C:\WINDOWS\system32\drivers\AsInsHelp64.sys
2011-09-29 22:59 10,216 --a------ C:\WINDOWS\system32\drivers\AsInsHelp32.sys
2011-09-29 22:58 24,576 -ra------ C:\WINDOWS\system32\AsIO.dll
2011-09-29 22:58 11,448 -ra------ C:\WINDOWS\system32\drivers\AsUpIO.sys
2011-09-29 22:58 11,296 -ra------ C:\WINDOWS\system32\drivers\AsIO.sys
2011-09-27 23:50 41,272 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-09-27 03:53 54,760 --a------ C:\WINDOWS\system32\drivers\fssfltr_tdi.sys
2011-09-20 19:26 15,232 --a------ C:\WINDOWS\system32\drivers\MPE.sys
2011-09-20 19:25 363,520 --a------ C:\WINDOWS\system32\PsisDecd.dll
2011-09-20 19:25 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-09-30 23:30 -------- d-------- C:\Program Files\Trojan Remover
2011-09-30 04:03 -------- d-------- C:\Program Files\Microsoft Works
2011-09-30 04:03 -------- d-------- C:\Program Files\Fichiers communs\Microsoft Shared
2011-09-30 04:03 -------- d-------- C:\Program Files\Emsisoft Anti-Malware
2011-09-30 04:02 -------- d-------- C:\Program Files\MSBuild
2011-09-30 04:02 -------- d-------- C:\Program Files\Microsoft Visual Studio
2011-09-30 03:56 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2011-09-30 00:33 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\Wise Disk Cleaner
2011-09-30 00:24 -------- d-------- C:\Program Files\Wise Disk Cleaner
2011-09-30 00:19 -------- d-------- C:\Program Files\Mozilla Firefox
2011-09-30 00:18 -------- d-------- C:\Program Files\BannerDesignStudio
2011-09-30 00:15 -------- d-------- C:\Program Files\3D-Album-CS
2011-09-30 00:15 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\3D-Album
2011-09-30 00:12 -------- d-------- C:\Program Files\Google
2011-09-30 00:11 -------- d-------- C:\Program Files\Opera
2011-09-30 00:10 -------- d--h----- C:\Program Files\InstallShield Installation Information
2011-09-30 00:10 -------- d-------- C:\Program Files\ASUS
2011-09-29 23:58 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\Skype
2011-09-29 23:57 -------- d-------- C:\Program Files\Fichiers communs
2011-09-29 22:58 -------- d-------- C:\Program Files\Fichiers communs\InstallShield
2011-09-29 10:33 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\cacaoweb
2011-09-29 01:42 -------- d-------- C:\Program Files\Avira
2011-09-28 01:53 -------- d-------- C:\Program Files\Fichiers communs\Corel
2011-09-28 01:53 -------- d-------- C:\Program Files\Corel
2011-09-27 22:38 -------- d-------- C:\Program Files\Fichiers communs\BitDefender
2011-09-27 22:05 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\HPAppData
2011-09-27 21:43 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\QuickScan
2011-09-27 18:22 -------- d-------- C:\Program Files\Windows Defender
2011-09-27 18:21 -------- d-------- C:\Program Files\SUPERAntiSpyware
2011-09-27 03:53 -------- d-------- C:\Program Files\Windows Live
2011-09-27 03:53 -------- d-------- C:\Program Files\Microsoft
2011-09-27 03:52 -------- d---s---- C:\Documents and Settings\idecomaison\Application Data\Microsoft
2011-09-27 03:52 -------- d-------- C:\Program Files\Windows Live SkyDrive
2011-09-27 03:15 -------- d-------- C:\Program Files\Internet Explorer
2011-09-27 03:15 -------- d-------- C:\Program Files\Fichiers communs\Windows Live
2011-09-27 02:34 -------- d-------- C:\Program Files\Bonjour
2011-09-27 02:33 53472 --a------ C:\WINDOWS\system32\wuauclt.exe
2011-09-27 02:30 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\SolidDocuments
2011-09-27 02:05 -------- d-------- C:\Program Files\Fichiers communs\System
2011-09-27 00:33 2880 --a------ C:\WINDOWS\system32\KGyGaAvL.sys
2011-09-26 22:27 -------- d-------- C:\Program Files\Norman
2011-09-26 21:26 -------- d-------- C:\Program Files\BitDefender
2011-09-26 21:21 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\Simply Super Software
2011-09-26 12:23 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\SUPERAntiSpyware.com
2011-09-26 00:41 -------- d-------- C:\Program Files\Microsoft Security Client
2011-09-25 20:47 -------- d-------- C:\Program Files\Grisoft
2011-09-21 22:44 23624 --a------ C:\WINDOWS\system32\drivers\hitmanpro35.sys
2011-09-17 02:14 -------- d-------- C:\Program Files\FunWebProducts
2011-09-13 01:15 -------- d-------- C:\Program Files\MyWebSearch
2011-09-09 11:12 606208 --a------ C:\WINDOWS\system32\crypt32.dll
2011-09-04 04:31 -------- d-------- C:\Program Files\ADLSoft UnCompressor
2011-09-04 03:58 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\Babylon
2011-08-13 23:28 -------- d-------- C:\Program Files\WinRAR
2011-08-13 14:12 -------- d-------- C:\Program Files\Zecter
2011-08-13 14:02 -------- d-------- C:\Program Files\ZHPDiag
2011-08-13 14:01 -------- d-------- C:\Program Files\Yahoo!
2011-08-13 13:57 -------- d-------- C:\Program Files\Portrait Professional 9 Trial
2011-08-13 13:54 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\Mediaparts Interactive
2011-08-13 13:51 -------- d-------- C:\Program Files\FLIP Flash Album Deluxe 2
2011-08-13 13:21 -------- d-------- C:\Documents and Settings\idecomaison\Application Data\ZumoDrive
2011-07-08 15:49 46080 --------- C:\WINDOWS\system32\tzchange.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"ObjectDock949"="C:\\Program Files\\Stardock\\ObjectDock\\ObjectDock.exe"
"cacaoweb"="\"C:\\Program Files\\cacaoweb\\cacaoweb.exe\" -noplayer"
"SUPERAntiSpyware"="C:\\Documents and Settings\\idecomaison\\Mes documents\\SUPERAntiSpyware.exe"
"Google Update"="\"C:\\Documents and Settings\\idecomaison\\Local Settings\\Application Data\\Google\\Update\\GoogleUpdate.exe\" /c"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"Norman ZANDA"="\"C:\\Program Files\\Norman\\Npm\\Bin\\ZLH.EXE\" /LOAD /SPLASH"
"BDAgent"="\"C:\\Program Files\\BitDefender\\BitDefender 2009\\bdagent.exe\""
"BitDefender Antiphishing Helper"="\"C:\\Program Files\\BitDefender\\BitDefender 2009\\IEShow.exe\""
"BCSSync"="\"C:\\Program Files\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices"
"ASUS Update Checker"="C:\\Program Files\\ASUS\\ASUSUpdate\\UpdateChecker\\UpdateChecker.exe"
"TrojanScanner"="C:\\Program Files\\Trojan Remover\\Trjscan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
@=""
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,68,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\FICHIE~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\FICHIE~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoNetHood"=dword:00000000
"NoNetworkConnections"=dword:00000000
"NoControlPanel"=dword:00000000
"NoAddPrinter"=dword:00000000
"NoDeletePrinter"=dword:00000000
"NoSMMyDocs"=dword:00000000
"NoRecentDocsMenu"=dword:00000000
"NoFind"=dword:00000000
"NoSMMyPictures"=dword:00000000
"NoStartMenuMyMusic"=dword:00000000
"NoStartMenuNetWorkPlaces"=dword:00000000
"StartMenuLogoff"=dword:00000000
"NoClose"=dword:00000000
"NoStartMenuMorePrograms"=dword:00000000
"NoStartMenuPinnedList"=dword:00000000
"NoStartMenuMFUprogramsList"=dword:00000000
"NoSetTaskbar"=dword:00000000
"LockTaskbar"=dword:00000000
"GreyMSIAds"=dword:00000000
"NoCommonGroups"=dword:00000000
"NoFavoritesMenu"=dword:00000000
"NoInstrumentation"=dword:00000000
"NoResolveTrack"=dword:00000000
"NoSMHelp"=dword:00000000
"NoUserNameInStartMenu"=dword:00000000
"NoSMConfigurePrograms"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"EnablELUA"=dword:00000000
"ConsentPromptBehaviorAdmin"=dword:00000002
"ValidateAdminCodeSignatures"=dword:00000000
"PromptOnSecureDesktop"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"=dword:00000001
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"uTorrent"="\"C:\\Program Files\\uTorrent\\uTorrent.exe\""
"cacaoweb"="\"C:\\Program Files\\cacaoweb\\cacaoweb.exe\" -noplayer"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RTHDCPL"="RTHDCPL.EXE"
"BCSSync"="\"C:\\Program Files\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Google Quick Search Box"="\"C:\\Program Files\\Google\\Quick Search Box\\GoogleQuickSearchBox.exe\" /autorun"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1070912147-1030409430-1536324635-1006Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1070912147-1030409430-1536324635-1006UA.job
Completion time: 11-09-30 23:50:09.42
C:\ComboFix.txt ... 11-09-30 23:50
Laatst bewerkt door een moderator: