This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TR/Crypt.ZPACK.Gen infection

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Avira AntiVir detects the trojan TR/Crypt.ZPACK.Gen.

I did everything from the Are you Infected? page.

Can somebody help me to remove this virus.

Thanks in advance!!

Stefaan

MBAM-log
Malwarebytes' Anti-Malware 1.42
Database versie: 3454
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

30/12/2009 12:47:38
mbam-log-2009-12-30 (12-47-38).txt

Scan type: Snelle Scan
Objecten gescand: 101374
Verstreken tijd: 5 minute(s), 30 second(s)

Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 0
Registersleutels geïnfecteerd: 8
Registerwaarden geïnfecteerd: 3
Registerdata bestanden geïnfecteerd: 0
Mappen geïnfecteerd: 0
Bestanden geïnfecteerd: 0

Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Geheugenmodulen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Registersleutels geïnfecteerd:
HKEY_CLASSES_ROOT\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{96afbe69-c3b0-4b00-8578-d933d2896ee2} (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dup (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SPService (TrojanProxy.Agent) -> Quarantined and deleted successfully.

Registerwaarden geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96afbe69-c3b0-4b00-8578-d933d2896ee2} (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registrymonitor1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvc (TrojanProxy.Agent) -> Quarantined and deleted successfully.

Registerdata bestanden geïnfecteerd:
(Geen kwaadaardige items gevonden)

Mappen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Bestanden geïnfecteerd:
(Geen kwaadaardige items gevonden)

GMER-log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-30 17:24:08
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Dhaenens\AppData\Local\Temp\ugrdrpob.sys


—- System - GMER 1.0.15 —-

SSDT 9ED4C944 ZwCreateThread
SSDT 9ED4C930 ZwOpenProcess
SSDT 9ED4C935 ZwOpenThread
SSDT 9ED4C93F ZwTerminateProcess

—- Devices - GMER 1.0.15 —-

Device \Driver\iaStor \Device\Ide\iaStor0 [8A4E96C8] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [8A4E96C8] \SystemRoot\system32\DRIVERS\iaStor.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\drivers\iaStor.sys suspicious modification

—- EOF - GMER 1.0.15 —-

DDS-log
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 17:25:15,86 on wo 30/12/2009
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3069.1658 [GMT 1:00]

SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Program Files\ExtraFilm Designer BE NL\EFUploadSrv.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Windows\system32\nhsrvice.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dhaenens\Desktop\dds.scr
C:\Windows\system32\conime.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.be
uSEARCH PAGE =
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://nl.intl.acer.yahoo.com
mDefault_Page_URL = hxxp://nl.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
EB: Search panel: {c5e6f0d8-38ea-20c6-e33b-03f901a22038} - c:\windows\system32\euqgmiqgxl.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Acer Tour Reminder]
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
dRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
dRun: [RegistryMonitor1] "c:\windows\temp\cprd.tmp"
dRun: [cbssreg] c:\windows\temp\emwf.tmp
StartupFolder: c:\users\dhaenens\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{14fcfe7c-ab86-428a-9d2e-bfb6f5a7aa6e}\Icon3E5562ED7.ico
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xporteren naar Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\dhaenens\appdata\roaming\mozilla\firefox\profiles\n5nxuusp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www27.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - prefs.js: keyword.URL - hxxp://www27.yoog.com/search.php?q=
FF - component: c:\program files\common files\dvdvideosoft\dll\ffcontextmenuy\components\FFContextMenu.dll
FF - plugin: c:\program files\cambridgesoft\chemoffice2008\chem3d\npChem3DPlugin.dll
FF - plugin: c:\program files\cambridgesoft\chemoffice2008\chemdraw\NPCDP32.DLL
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\picasa3\npPicasa2.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\dhaenens\appdata\roaming\mozilla\firefox\profiles\n5nxuusp.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npSafeview3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www27.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: keyword.URL - hxxp://www27.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
user_pref(places.frecency.bookmarkVisitBonus,0);
user_pref(places.frecency.unvisitedBookmarkBonus,0);
user_pref(browser.startup.page,1);
user_pref(browser.download.lastDir,c:\\users\\dhaenens\\desktop\\);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\play movie\000.fcl [2008-4-12 13560]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-3 108289]
R2 EFUploadSrv;ExtraFilm upload service;c:\program files\extrafilm designer be nl\EFUploadSrv.exe [2008-11-27 1712128]
R2 HASP Loader;HASP Loader;c:\windows\system32\nhsrvice.exe -service –> c:\windows\system32\nhsrvice.exe -service [?]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-9-4 32256]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-9-4 179712]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-14 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-3 54632]
S3 fsssvc;De service Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]

=============== Created Last 30 ================

2009-12-30 12:40 –d—– c:\users\dhaenens\appdata\roaming\Malwarebytes
2009-12-30 12:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 12:40 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-30 12:40 –d—– c:\programdata\Malwarebytes
2009-12-30 12:40 –d—– c:\progra~2\Malwarebytes
2009-12-30 12:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-30 11:39 –d—– c:\program files\Trend Micro
2009-12-28 17:37 –d—– c:\programdata\ALM
2009-12-28 17:37 –d—– c:\progra~2\ALM
2009-12-28 17:20 –d—– c:\program files\common files\Macrovision Shared
2009-12-24 08:58 –d—– C:\Autoruns
2009-12-19 18:37 –d—– c:\programdata\Etiam
2009-12-19 18:37 –d—– c:\progra~2\Etiam
2009-12-09 23:22 24,064 a——- c:\windows\system32\nshhttp.dll
2009-12-09 23:22 411,648 a——- c:\windows\system32\drivers\http.sys
2009-12-09 23:22 30,720 a——- c:\windows\system32\httpapi.dll
2009-12-09 19:12 243,712 a——- c:\windows\system32\rastls.dll
2009-12-05 18:37 178,176 a——- c:\windows\system32\unrar.dll
2009-12-05 18:37 38 a——- c:\windows\avisplitter.ini
2009-12-05 18:37 839,680 a——- c:\windows\system32\lameACM.acm
2009-12-05 18:37 414 a——- c:\windows\system32\lame_acm.xml
2009-12-05 18:37 881,664 a——- c:\windows\system32\xvidcore.dll
2009-12-05 18:37 217,088 a——- c:\windows\system32\yv12vfw.dll
2009-12-05 18:37 205,824 a——- c:\windows\system32\xvidvfw.dll
2009-12-05 18:37 118,784 a——- c:\windows\system32\ac3acm.acm
2009-12-05 18:37 85,504 a——- c:\windows\system32\ff_vfw.dll
2009-12-05 18:37 547 a——- c:\windows\system32\ff_vfw.dll.manifest
2009-12-05 18:37 –d—– c:\program files\K-Lite Codec Pack

==================== Find3M ====================

2009-12-27 13:54 667,352 a——- c:\windows\system32\perfh013.dat
2009-12-27 13:54 126,854 a——- c:\windows\system32\perfc013.dat
2009-12-18 20:11 117,340 a——- c:\users\dhaenens\appdata\roaming\nvModes.dat
2009-12-07 20:42 56,816 a——- c:\windows\system32\drivers\avgntflt.sys
2009-11-21 07:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 07:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 07:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-21 05:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-17 21:48 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-17 21:48 86,016 a——- c:\windows\inf\infpub.dat
2009-11-17 21:48 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-17 21:48 143,360 a——- c:\windows\inf\infstor.dat
2009-11-17 21:48 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-17 21:47 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-29 10:17 2,048 a——- c:\windows\system32\tzres.dll
2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll
2009-10-08 22:08 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-10-08 22:08 234,496 a——- c:\windows\system32\oleacc.dll
2009-10-08 22:07 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-01-04 14:16 48 a—h— c:\programdata\ezsidmv.dat
2009-01-04 14:16 48 a—h— c:\progra~2\ezsidmv.dat
2008-07-08 06:50 68 a——- c:\users\dhaenens\appdata\roaming\wklnhst.dat
2008-06-16 09:45 174 a–sh— c:\program files\desktop.ini
2008-04-13 18:14 32 a——- c:\programdata\ezsid.dat
2008-04-13 18:14 32 a——- c:\progra~2\ezsid.dat
2006-11-02 17:08 336,440 a——- c:\windows\inf\perflib\0413\perfi.dat
2006-11-02 17:08 336,440 a——- c:\windows\inf\perflib\0413\perfh.dat
2006-11-02 17:08 41,976 a——- c:\windows\inf\perflib\0413\perfd.dat
2006-11-02 17:08 41,976 a——- c:\windows\inf\perflib\0413\perfc.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 17:27:00,27 ===============
Hi,

please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 10-01-01.02 - Dhaenens 02/01/2010 15:09:44.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3069.1849 [GMT 1:00]
Gestart vanuit: c:\users\Dhaenens\Desktop\virus\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\acer\Empowering Technology\eRecovery\Autorun\SW1\Tuner\Liteon\Resources\_desktop.ini
c:\drv\Tuner\Yuan\Resources\_desktop.ini
c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera
c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera \Uninstall.lnk

.
(((((((((((((((((((( Bestanden Gemaakt van 2009-12-02 to 2010-01-02 ))))))))))))))))))))))))))))))
.

2010-01-02 14:23 . 2010-01-02 14:27 ——– d—–w- c:\users\Dhaenens\AppData\Local\temp
2010-01-02 14:23 . 2010-01-02 14:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-02 12:48 . 2010-01-02 12:48 ——– d—–w- c:\programdata\McAfee
2009-12-31 12:47 . 2009-12-31 12:47 ——– d—–w- c:\programdata\McAfee Security Scan
2009-12-31 12:47 . 2009-12-31 12:47 ——– d—–w- c:\program files\McAfee Security Scan
2009-12-30 13:58 . 2009-12-30 13:58 ——– d—–w- c:\users\Dhaenens\AppData\Local\Adobe
2009-12-30 11:40 . 2009-12-30 11:40 ——– d—–w- c:\users\Dhaenens\AppData\Roaming\Malwarebytes
2009-12-30 11:40 . 2009-12-03 15:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 11:40 . 2009-12-30 11:40 ——– d—–w- c:\programdata\Malwarebytes
2009-12-30 11:40 . 2009-12-03 15:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 11:40 . 2009-12-30 11:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 11:37 . 2009-12-30 11:38 ——– d—–w- c:\program files\ERUNT
2009-12-30 10:39 . 2009-12-30 10:39 ——– d—–w- c:\program files\Trend Micro
2009-12-28 16:37 . 2009-12-28 16:37 ——– d—–w- c:\programdata\ALM
2009-12-28 16:20 . 2009-12-28 16:20 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-12-24 07:58 . 2009-12-24 08:02 ——– d—–w- C:\Autoruns
2009-12-19 17:37 . 2009-12-19 17:38 ——– d—–w- c:\programdata\Etiam
2009-12-09 22:22 . 2009-11-09 12:31 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-09 22:22 . 2009-11-09 12:30 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-12-09 22:22 . 2009-11-09 10:36 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-09 18:12 . 2009-10-07 11:36 243712 —-a-w- c:\windows\system32\rastls.dll
2009-12-05 17:37 . 2009-08-16 15:08 178176 —-a-w- c:\windows\system32\unrar.dll
2009-12-05 17:37 . 2009-05-29 21:37 205824 —-a-w- c:\windows\system32\xvidvfw.dll
2009-12-05 17:37 . 2009-05-29 21:31 881664 —-a-w- c:\windows\system32\xvidcore.dll
2009-12-05 17:37 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2009-12-05 17:37 . 2009-11-09 18:00 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-12-05 17:37 . 2009-12-05 17:38 ——– d—–w- c:\program files\K-Lite Codec Pack

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 14:25 . 2008-05-31 11:54 12 —-a-w- c:\windows\system32\haspaddr.dat
2010-01-01 18:22 . 2008-10-31 22:09 ——– d—–w- c:\programdata\Google Updater
2010-01-01 17:00 . 2007-09-03 16:17 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-31 14:40 . 2006-11-02 16:11 667352 —-a-w- c:\windows\system32\perfh013.dat
2009-12-31 14:40 . 2006-11-02 16:11 126854 —-a-w- c:\windows\system32\perfc013.dat
2009-12-31 14:02 . 2008-05-25 05:18 ——– d—–w- c:\users\Dhaenens\AppData\Roaming\uTorrent
2009-12-29 07:05 . 2008-04-12 15:03 ——– d—–w- c:\users\Dhaenens\AppData\Roaming\Thunderbird
2009-12-28 19:47 . 2007-09-03 14:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-28 16:36 . 2008-04-21 19:59 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-27 17:35 . 2008-09-02 18:28 ——– d—–w- c:\users\Dhaenens\AppData\Roaming\Juniper Networks
2009-12-24 08:29 . 2008-04-25 11:30 8268 —-a-w- c:\users\Dhaenens\AppData\Local\d3d9caps.dat
2009-12-23 18:36 . 2009-12-23 18:36 291696 —-a-w- c:\users\Dhaenens\AppData\Roaming\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTR_8.0.50727.762.exe
2009-12-19 09:31 . 2009-11-28 11:53 ——– d—–w- c:\programdata\SP
2009-12-18 19:11 . 2008-04-13 19:55 117340 —-a-w- c:\users\Dhaenens\AppData\Roaming\nvModes.dat
2009-12-14 09:00 . 2009-12-20 17:02 2747440 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20091220.004\CCERASER.DLL
2009-12-14 09:00 . 2009-12-14 09:00 2747440 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\CCERASER.DLL
2009-12-12 13:23 . 2009-12-12 13:23 484976 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbDBC1.tmp.exe
2009-12-10 17:31 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-09 22:23 . 2007-09-03 16:04 ——– d—–w- c:\programdata\Microsoft Help
2009-12-07 19:42 . 2009-05-03 14:14 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-21 06:40 . 2009-12-09 18:15 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 18:15 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 18:15 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 18:15 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 18:02 . 2009-11-15 17:36 ——– d—–w- c:\program files\FileZilla
2009-11-17 20:48 . 2009-11-17 20:48 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-17 20:48 . 2009-11-17 20:48 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-17 20:47 . 2009-11-17 20:47 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 20:39 . 2008-04-12 15:51 ——– d—–w- c:\program files\Java
2009-11-10 12:56 . 2009-11-10 12:52 ——– d—–w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-10 12:56 . 2009-11-10 12:52 ——– d—–w- c:\program files\iTunes
2009-11-10 12:53 . 2009-11-10 12:53 ——– d—–w- c:\program files\iPod
2009-11-10 12:52 . 2008-06-24 17:51 ——– d—–w- c:\program files\Common Files\Apple
2009-11-10 12:49 . 2009-11-10 12:48 ——– d—–w- c:\program files\QuickTime
2009-11-10 12:44 . 2009-11-10 12:44 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-02 19:42 . 2009-10-02 16:19 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-26 22:38 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-19 08:00 . 2009-12-20 17:02 259440 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20091220.004\ECMSVR32.DLL
2009-10-19 08:00 . 2009-10-19 08:00 259440 —-a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\ECMSVR32.DLL
2009-10-11 03:17 . 2008-12-14 14:21 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-17 20:37 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-17 20:37 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-17 20:37 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2008-02-07 19:46 . 2008-02-07 19:46 13624 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-07 19:46 . 2008-02-07 19:46 87360 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-07 19:46 . 2008-02-07 19:46 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-07 19:46 . 2008-02-07 19:46 21824 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-07 19:46 . 2008-02-07 19:46 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-07 19:46 . 2008-02-07 19:46 31544 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-07 19:46 . 2008-02-07 19:46 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-16 15:27 . 2007-03-16 15:27 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 15:27 . 2007-03-16 15:27 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 15:27 . 2007-03-16 15:27 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 10:47 . 2007-07-20 10:47 981170 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-07 19:46 . 2008-02-07 19:46 24384 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-31 39408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]

c:\users\Dhaenens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-4-19 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):14,6f,32,ec,7d,13,ca,01

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [12/04/2008 15:19 13560]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/05/2009 15:14 108289]
R2 EFUploadSrv;ExtraFilm upload service;c:\program files\ExtraFilm Designer BE NL\EFUploadSrv.exe [27/11/2008 15:17 1712128]
R2 HASP Loader;HASP Loader;c:\windows\system32\nhsrvice.exe -service –> c:\windows\system32\nhsrvice.exe -service [?]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [4/09/2007 0:01 32256]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [4/09/2007 0:01 179712]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [14/06/2008 9:29 21504]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [3/10/2009 12:15 54632]
S3 fsssvc;De service Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 21:48 704864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map

2010-01-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-18 08:42]

2010-01-01 c:\windows\Tasks\Norton Security Scan for Dhaenens.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-08-21 14:45]
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.google.be
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://nl.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xporteren; naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
FF - ProfilePath - c:\users\Dhaenens\AppData\Roaming\Mozilla\Firefox\Profiles\n5nxuusp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www27.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - prefs.js: keyword.URL - hxxp://www27.yoog.com/search.php?q=
FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF - plugin: c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Dhaenens\AppData\Roaming\Mozilla\Firefox\Profiles\n5nxuusp.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npSafeview3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www27.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: keyword.URL - hxxp://www27.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
user_pref(places.frecency.bookmarkVisitBonus,0);
user_pref(places.frecency.unvisitedBookmarkBonus,0);
user_pref(browser.startup.page,1);
user_pref(browser.download.lastDir,c:\\Users\\Dhaenens\\Desktop\\);
.
- - - - ORPHANS VERWIJDERD - - - -

HKCU-Run-Acer Tour Reminder - (no file)
AddRemove-program files - c:\progra~1\Prism3\UNWISE.EXE
AddRemove-unibetpoker (Poker) - c:\microgaming\Poker\unibetpokerMPP\install.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-02 15:26
Windows 6.0.6002 Service Pack 2 NTFS

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,51,e9,cb,2c,b1,58,44,be,1b,53,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,51,e9,cb,2c,b1,58,44,be,1b,53,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Geladen Onder Lopende Processen ———————

- - - - - - - > 'Explorer.exe'(3912)
c:\program files\WinSCP3\DragExt.dll
.
———————— Andere Aktieve Processen ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\windows\system32\nhsrvice.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Voltooingstijd: 2010-01-02 15:35:41 - machine werd herstart
ComboFix-quarantined-files.txt 2010-01-02 14:35

Pre-Run: 10.977.370.112 bytes beschikbaar
Post-Run: 11.127.328.768 bytes beschikbaar

- - End Of File - - FC126FD466186E163817B90D354E26C2
Hi,

Please do the following:

**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hello, Thanks for the reply but when executing the Kaspersky online scan, my CPU usage is almost 100% all the time, and the temperature is nearly 90°C… Is there an alternative? For example downloading a offline version of the scanner? My CPU is a Pentium Dual T2330 1.6 GHz (with a maximum temperature of 100°C). Yesterday my pc just shut down during the scanning process. Thanks!!
Hi,

Try this scanner instead:

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.


If you still have some overheating issues, try this tool:

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder. Click Next.
  • Hit OK at the prompt for scanning in Safe Mode.
  • It will then open a box. There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the top right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then choose the delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file, name it Kas.
  • Save it to your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Hello, I let it run and put my pc in a cold place. After 5 hours it finished: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, January 3, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, January 03, 2010 10:09:57 Records in database: 3369521 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 187992 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 04:54:07 No threats found. Scanned area is clean. Selected area has been scanned. Apparently no threats… I'll let you know if the notification returns. Thanks for the support!
Hi,

we can clean up our tools:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI