Beste Phoenix
ik heb vergeten te melden ComboFix
Logs van ComboFix
----------------------
ComboFix 11-10-20.05 - MKaya 20-10-2011 20:50:09.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.3070.1318 [GMT 2:00]
Gestart vanuit: c:\users\MKaya\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\MKaya\AppData\Local\promo.exe
c:\users\MKaya\AppData\Local\Setup.exe
C:\WINDOWSTemp
c:\windowstemp\dbisam.lck
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-09-20 to 2011-10-20 ))))))))))))))))))))))))))))))
.
.
2011-10-20 18:57 . 2011-10-20 18:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-20 18:12 . 2011-10-20 18:12 -------- d-----w- c:\programdata\Malwarebytes
2011-10-20 18:12 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-20 18:12 . 2011-10-20 18:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-20 16:49 . 2011-10-20 16:49 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6577DF10-B35F-40D3-9622-01AB35D8FA1C}\MpKslec9e954f.sys
2011-10-20 16:49 . 2011-10-20 16:49 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6577DF10-B35F-40D3-9622-01AB35D8FA1C}\offreg.dll
2011-10-20 16:49 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6577DF10-B35F-40D3-9622-01AB35D8FA1C}\mpengine.dll
2011-10-18 23:22 . 2011-10-18 23:22 -------- d-----w- c:\program files\FastStone Capture
2011-10-17 15:18 . 2011-10-17 15:22 -------- d-----w- c:\program files\TC UP
2011-10-15 20:30 . 2011-10-15 20:30 -------- d-----w- c:\windows\Davut Kaya Hatim
2011-10-14 22:10 . 2011-10-14 22:10 -------- dc-h--w- c:\programdata\{6C47B826-5902-49BB-BF6B-68F5716FD827}
2011-10-14 15:12 . 2011-10-14 15:15 -------- d-----w- c:\program files\PhotoScape
2011-10-14 15:06 . 2011-10-14 15:06 -------- d-----w- c:\windows\system32\quicktime
2011-10-14 15:06 . 2011-10-16 09:29 -------- d-----w- c:\program files\Videocharge Software
2011-10-14 13:38 . 2011-10-14 13:38 -------- d-----w- c:\programdata\Mr Retro
2011-10-13 18:40 . 2011-10-13 18:40 -------- d-----w- c:\programdata\Anvsoft
2011-10-13 18:39 . 2011-10-13 18:40 -------- d-----w- c:\program files\Wedding Album Maker Gold
2011-10-13 17:40 . 2011-10-13 17:40 102400 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy\{5326F70F-C5F6-4386-9EA9-0CA8FEAF50AF}-Splash.exe
2011-10-13 17:40 . 2011-10-13 17:40 102400 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy\{01B6551F-256D-42AD-9E67-A8F6D952750C}-Splash.exe
2011-10-13 15:20 . 2011-10-13 15:20 -------- dc-h--w- c:\programdata\{738BC746-5FBD-4969-B3F1-6A065E31C7BE}
2011-10-13 15:18 . 2011-10-13 15:18 -------- dc-h--w- c:\programdata\{DD44E1C4-AD22-4508-8355-744AA998F06D}
2011-10-13 15:18 . 2011-10-13 15:18 -------- dc-h--w- c:\programdata\{682FE305-7958-4875-9B95-34673E7151AD}
2011-10-13 15:18 . 2011-10-13 15:18 -------- dc-h--w- c:\programdata\{529BBEB3-0369-420C-BD9C-37553D289203}
2011-10-13 15:17 . 2011-10-13 15:18 -------- dc-h--w- c:\programdata\{E6AF2639-F710-4F5B-8830-95A396FB523F}
2011-10-13 15:17 . 2011-10-13 15:17 -------- dc-h--w- c:\programdata\{AB404F93-CDCE-40D9-8D4E-8606C84D368C}
2011-10-13 15:17 . 2011-10-13 15:17 -------- dc-h--w- c:\programdata\{8265C354-3D13-4FE5-95C7-65F277FF3041}
2011-10-13 15:17 . 2011-10-14 22:10 -------- d-----w- c:\program files\Common Files\Topaz Labs
2011-10-13 15:17 . 2011-10-14 22:10 -------- d-----w- c:\program files\Topaz Labs
2011-10-13 13:23 . 2011-10-13 13:25 -------- d-----w- c:\program files\DownVision
2011-10-12 23:51 . 2011-10-12 23:51 -------- d-----w- c:\program files\Common Files\DivX Shared
2011-10-12 23:50 . 2011-10-12 23:51 -------- d-----w- c:\program files\DivX
2011-10-12 23:50 . 2011-10-12 23:51 -------- d-----w- c:\programdata\DivX
2011-10-12 23:22 . 2011-10-12 23:23 -------- d-----w- c:\program files\Filter Forge Freepack 3 - Frames
2011-10-12 23:12 . 2006-11-10 16:41 1030144 ----a-w- c:\windows\system32\dbghelp-xfw.dll
2011-10-12 23:12 . 2011-10-12 23:12 -------- d-----w- c:\program files\Filter Forge Freepack 2 - Photo Effects
2011-10-12 23:01 . 2011-10-12 23:01 -------- d-----w- c:\program files\Imagenomic
2011-10-11 01:36 . 2010-11-30 09:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-10-11 01:35 . 2011-10-11 01:35 703824 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6EF62D24-2387-4D73-8FC5-1312B730412C}\gapaengine.dll
2011-10-10 17:52 . 2011-10-10 17:52 -------- d-----w- c:\program files\GetMiro Toolbar
2011-10-10 17:50 . 2011-10-10 17:50 -------- d-----w- c:\program files\Participatory Culture Foundation
2011-10-09 23:49 . 2011-10-10 19:42 -------- d-----w- C:\Gizli_Bilgiler
2011-10-09 23:39 . 2011-10-09 23:39 -------- d-----w- c:\programdata\Socusoft
2011-10-09 23:35 . 2011-10-09 23:35 -------- d-----w- c:\program files\DVD Photo Slideshow Professional
2011-10-09 23:13 . 2007-04-09 11:23 28552 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2011-10-09 23:13 . 2007-04-09 11:23 28040 ----a-w- c:\windows\system32\mdimon.dll
2011-10-09 23:12 . 2011-10-12 23:51 -------- d-----w- c:\program files\Mozilla Sunbird
2011-10-09 23:11 . 2011-10-11 01:02 -------- d-----w- c:\program files\Microsoft Works
2011-10-09 23:11 . 2011-10-09 23:12 -------- d-----w- c:\windows\SHELLNEW
2011-10-09 23:11 . 2011-10-13 10:47 -------- d-----w- c:\program files\Microsoft.NET
2011-10-09 23:03 . 2011-10-09 23:03 -------- d-----w- c:\program files\GRETECH
2011-10-09 22:59 . 2011-10-09 22:59 -------- d-----w- c:\program files\Common Files\Webroot Shared
2011-10-09 22:59 . 2011-10-09 22:59 -------- d-----w- c:\programdata\Webroot
2011-10-09 22:59 . 2011-10-09 22:59 -------- d-----w- c:\program files\Webroot
2011-10-09 22:58 . 2007-11-26 12:47 194888 ----a-w- c:\windows\Unwash6.exe
2011-10-09 22:47 . 2011-10-10 12:50 -------- d-----w- c:\program files\Common Files\Macromedia
2011-10-09 22:47 . 2011-10-10 12:50 -------- d-----w- c:\program files\Macromedia
2011-10-09 22:40 . 2011-10-09 22:40 -------- d-----w- c:\program files\TeamViewer
2011-10-09 22:37 . 2008-01-21 02:32 89600 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPLHN.DLL
2011-10-09 22:36 . 2011-10-09 22:36 -------- d-----w- c:\program files\Common Files\Bullzip
2011-10-09 22:36 . 2010-01-16 15:01 7680 ----a-w- c:\windows\system32\BioPdf.PdfWriter.Lib.dll
2011-10-09 22:36 . 2010-01-07 18:40 131072 ----a-w- c:\windows\system32\bzpdfc.dll
2011-10-09 22:36 . 2008-10-30 20:15 227840 ----a-w- c:\windows\system32\bzFlRdr.dll
2011-10-09 22:36 . 2008-07-09 21:19 103424 ----a-w- c:\windows\system32\bzDCT.dll
2011-10-09 22:36 . 2010-01-13 17:57 194560 ----a-w- c:\windows\system32\bzpdf.dll
2011-10-09 22:36 . 1999-05-06 21:00 140288 ----a-w- c:\windows\system32\comdlg32.OCX
2011-10-09 22:36 . 2011-10-09 22:36 -------- d-----w- c:\program files\Bullzip
2011-10-09 22:31 . 2011-10-09 22:32 -------- d-----w- c:\program files\The KMPlayer
2011-10-09 22:29 . 2011-10-14 12:13 -------- d-----w- c:\program files\JDownloader
2011-10-09 22:27 . 2007-04-12 12:19 129024 ----a-w- c:\windows\system32\AVERM.dll
2011-10-09 22:27 . 2006-09-26 11:57 28672 ----a-w- c:\windows\system32\AVEQT.dll
2011-10-09 22:27 . 2011-10-09 22:27 -------- d-----w- c:\program files\Ultra Video Joiner
2011-10-09 22:22 . 2011-10-09 22:22 -------- d-----w- c:\program files\Common Files\Java
2011-10-09 22:21 . 2011-10-09 22:21 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-09 22:21 . 2011-10-09 22:21 -------- d-----w- c:\program files\Java
2011-10-09 22:12 . 2011-10-09 22:12 -------- d-----w- c:\program files\uTorrent
2011-10-09 22:06 . 2011-10-09 22:07 -------- d-----w- c:\program files\FileZilla FTP Client
2011-10-09 21:07 . 2011-08-03 11:50 6613096 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-10-09 21:07 . 2011-08-03 11:50 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-10-09 21:07 . 2011-08-03 11:50 16595560 ----a-w- c:\windows\system32\nvoglv32.dll
2011-10-09 21:07 . 2011-08-03 11:50 10304104 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-10-09 21:06 . 2011-08-03 11:50 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-10-09 21:06 . 2011-08-03 11:50 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-10-09 21:06 . 2011-08-03 11:50 5404776 ----a-w- c:\windows\system32\nvcuda.dll
2011-10-09 21:06 . 2011-08-03 11:50 2391656 ----a-w- c:\windows\system32\nvcuvid.dll
2011-10-09 21:06 . 2011-08-03 11:50 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-10-09 21:06 . 2011-08-03 11:50 17193576 ----a-w- c:\windows\system32\nvcompiler.dll
2011-10-09 17:22 . 2011-10-09 17:22 -------- d-----w- c:\programdata\RoboForm
2011-10-09 17:21 . 2011-10-09 17:21 -------- d-----w- c:\program files\Siber Systems
2011-10-09 17:15 . 2011-10-09 17:15 -------- d-----w- c:\windows\Kuran Hatim 3.0
2011-10-09 17:14 . 2011-10-09 17:15 -------- d-----w- c:\program files\Hasenat
2011-10-09 16:53 . 2011-10-09 16:53 -------- d-----w- C:\NVIDIA
2011-10-09 16:46 . 2011-10-09 16:46 -------- d-----w- c:\users\UpdatusUser
2011-10-09 16:44 . 2011-10-09 16:44 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-10-09 16:40 . 2011-05-10 09:41 865896 ----a-w- c:\windows\system32\nvhdagenco322040.dll
2011-10-09 16:40 . 2011-04-08 05:14 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-10-09 16:40 . 2011-04-08 05:14 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-10-09 16:40 . 2011-10-09 22:02 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-09 15:13 . 2011-10-09 15:13 -------- d-----r- c:\program files\Skype
2011-10-09 15:13 . 2011-10-09 15:13 -------- d-----w- c:\programdata\Skype
2011-10-09 14:20 . 2011-10-09 14:20 -------- d-----w- c:\windows\PCHEALTH
2011-10-09 14:19 . 2011-10-09 14:22 -------- d-----w- c:\program files\Windows Live
2011-10-09 14:12 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-10-09 13:59 . 2011-10-09 13:59 -------- d-----w- c:\program files\Windows Portable Devices
2011-10-09 13:54 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-10-09 13:54 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-10-09 13:54 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-10-09 13:47 . 2009-11-08 08:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-10-09 13:47 . 2009-11-08 08:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-10-09 13:47 . 2009-11-08 08:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-10-09 13:47 . 2009-11-08 08:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-10-09 13:47 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-10-09 13:43 . 2011-01-20 16:08 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-10-09 13:42 . 2011-04-30 06:09 758784 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-10-09 13:40 . 2011-06-17 20:13 913296 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-10-09 13:40 . 2011-06-17 13:31 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-10-09 13:39 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-09 13:39 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-09 13:33 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-10-09 12:48 . 2011-10-09 12:48 -------- d-----w- c:\windows\system32\ca-ES
2011-10-09 12:48 . 2011-10-09 12:48 -------- d-----w- c:\windows\system32\eu-ES
2011-10-09 12:48 . 2011-10-09 12:48 -------- d-----w- c:\windows\system32\vi-VN
2011-10-09 12:44 . 2011-10-09 12:44 -------- d-----w- c:\windows\system32\SPReview
2011-10-09 12:20 . 2009-04-10 21:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2011-10-09 12:20 . 2009-04-10 21:27 57856 ----a-w- c:\windows\system32\compcln.exe
2011-10-09 12:13 . 2009-04-10 21:32 27112 ----a-w- c:\windows\system32\drivers\msahci.sys
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-18 22:53 . 2009-02-12 18:48 45056 ----a-w- c:\windows\system32\acovcnt.exe
2011-10-09 14:20 . 2011-03-28 16:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-03 11:50 . 2011-04-07 20:43 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:50 . 2011-04-07 20:43 66664 ----a-w- c:\windows\system32\nvshext.dll
2011-08-03 11:50 . 2011-04-07 20:43 599144 ----a-w- c:\windows\system32\nvvsvc.exe
2011-08-03 11:50 . 2011-04-07 20:43 309352 ----a-w- c:\windows\system32\nvhotkey.dll
2011-08-03 11:50 . 2011-04-07 20:43 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
2011-08-03 11:50 . 2011-04-07 20:43 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:50 . 2011-04-07 20:43 3730024 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:50 . 2011-04-07 20:43 2558568 ----a-w- c:\windows\system32\nvsvc.dll
2011-08-03 11:50 . 2008-07-25 08:30 2412136 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:50 . 2008-07-25 08:30 12636776 ----a-w- c:\windows\system32\nvd3dum.dll
2011-08-03 01:31 . 2011-08-03 01:31 311912 ----a-w- c:\windows\system32\nvStreaming.exe
2011-07-22 20:51 . 2011-07-22 20:51 94208 ----a-w- c:\windows\system32\dpl100.dll
2011-07-08 07:48 . 2011-10-14 16:07 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2009-02-12 17:55 157168 ----a-w- c:\programdata\Partner\partner.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-12 39408]
"TC UP"="c:\program files\TC UP\TC UP.exe" [2010-12-25 615936]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2008-04-03 87336]
"LanguageShortcut"="c:\program files\ASUSTek\ASUSDVD\Language\Language.exe" [2008-02-22 62760]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-12 6265376]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2009-02-12 3054136]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2009-02-12 47672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Skytel"="Skytel.exe" [2008-08-12 1833504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NoIE4StubProcessing"="c:\windows\system32\reg.exe DELETE HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" [X]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-4 113664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-04 98304]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-09 135664]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-04 118784]
R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-09 135664]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [2009-02-12 110576]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 MpKslec9e954f;MpKslec9e954f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6577DF10-B35F-40D3-9622-01AB35D8FA1C}\MpKslec9e954f.sys [2011-10-20 28752]
S1 VD_FileDisk;VD_FileDisk; [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [2010-10-04 64512]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-01-27 2253688]
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2007-11-26 598856]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
.
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - 10920836
*NewlyCreated* - ASWMBR
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSWISSARMY
*NewlyCreated* - MPKSLEC9E954F
*Deregistered* - 10920836
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-09 10:16]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-09 10:16]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://
www.google.nl/" onclick="window.open(this.href);return false;
mStart Page = hxxp://
www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS" onclick="window.open(this.href);return false;
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Formulieren Invullen - file://c" onclick="window.open(this.href);return false;:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Formulieren opslaan - file://c" onclick="window.open(this.href);return false;:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Menu aanpassen - file://c" onclick="window.open(this.href);return false;:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RoboForm Werkbalk - file://c" onclick="window.open(this.href);return false;:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
TCP: DhcpNameServer = 212.54.40.25 212.54.35.25
FF - ProfilePath - c:\users\MKaya\AppData\Roaming\Mozilla\Firefox\Profiles\ztueazy4.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.nl" onclick="window.open(this.href);return false;
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS VERWIJDERD - - - -
.
HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net" onclick="window.open(this.href);return false;
Rootkit scan 2011-10-20 20:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-3078239276-3349614612-1677412284-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-3078239276-3349614612-1677412284-1000)
@Denied: (2) (LocalSystem)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-3078239276-3349614612-1677412284-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-3078239276-3349614612-1677412284-1000)
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
Voltooingstijd: 2011-10-20 21:00:11
ComboFix-quarantined-files.txt 2011-10-20 19:00
.
Pre-Run: 79.362.523.136 bytes beschikbaar
Post-Run: 79.496.945.664 bytes beschikbaar
.
- - End Of File - - 807F158DC433BEAE42B890B6679FC9B0