dank heren voor de snelle service. het duurde wat langer, want na de run moest ik mijn bureaublad herstellen.
ComboFix 08-11-12.01 - keesmees 2008-11-14 11:59:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1464
Gestart vanuit: c:\documents and settings\keesmees\Bureaublad\ComboFix.exe
* Nieuw herstelpunt werd aangemaakt
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\ntnet.drv
c:\windows\system32\sysaudio.sys
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-10-14 to 2008-11-14 ))))))))))))))))))))))))))))))
.
2008-11-12 08:15 . 2008-09-04 18:17 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-12 08:15 . 2008-10-24 12:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-09 11:58 . 2008-11-14 08:29 d——– c:\windows\system32\drivers\Avg
2008-11-09 11:58 . 2008-11-09 11:58 d——– c:\program files\AVG
2008-11-09 11:58 . 2008-11-09 11:58 d——– c:\documents and settings\All Users\Application Data\avg8
2008-11-09 11:58 . 2008-11-09 11:58 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-11-09 11:58 . 2008-11-09 11:58 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2008-11-09 11:58 . 2008-11-09 11:58 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-11-09 11:55 . 2008-11-09 11:58 8,192 –a—— c:\documents and settings\KEEZZZ~3
2008-11-09 11:13 . 2008-11-09 11:13 262,144 –a—— c:\documents and settings\KEEZZZ~2
2008-11-09 11:10 . 2008-11-09 11:10 262,144 –a—— c:\documents and settings\KEEZZZ~1
2008-10-24 08:07 . 2008-10-15 17:37 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-10-15 09:08 . 2008-08-14 14:27 2,193,536 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 09:08 . 2008-08-14 14:27 2,149,888 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 09:08 . 2008-08-14 14:27 2,070,400 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 09:08 . 2008-08-14 14:27 2,028,544 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 09:08 . 2008-09-15 16:28 1,846,528 —–c— c:\windows\system32\dllcache\win32k.sys
2008-10-15 09:08 . 2008-09-08 11:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 11:04 92,555,296 –sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-13 19:41 1,078,628 –sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-12 08:57 ——— d—–w c:\documents and settings\keesmees\Application Data\ZoomBrowser EX
2008-11-12 08:54 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-12 08:54 ——— d—–w c:\program files\SpywareBlaster
2008-11-09 15:39 ——— d—–w c:\program files\Common Files\Adobe
2008-10-30 20:23 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-10-22 06:10 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-11 08:22 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-09-21 09:48 ——— d—–w c:\documents and settings\keesmees\Application Data\CameraWindowDC
2008-09-21 09:45 ——— d—–w c:\documents and settings\keesmees\Application Data\CANON INC
2008-09-21 09:34 ——— d—–w c:\program files\Canon
2008-09-21 09:32 ——— d—–w c:\documents and settings\All Users\Application Data\ZoomBrowser
2008-09-21 09:29 ——— d—–w c:\program files\Common Files\Canon
2008-09-15 15:28 1,846,528 —-a-w c:\windows\system32\win32k.sys
2008-09-10 01:16 1,307,648 ——w c:\windows\system32\msxml6.dll
2008-09-04 17:17 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-08-26 08:27 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 13:27 2,193,536 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:27 2,070,400 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-05-12 11:47 29,472 —-a-w c:\documents and settings\keesmees\Application Data\GDIPFONTCACHEV1.DAT
2008-03-18 14:37 932 —ha-w c:\documents and settings\keesmees\Application Data\hpothb07.dat
2008-02-25 12:54 488 —ha-w c:\documents and settings\keesmees\hpothb07.dat
2007-07-04 10:41 164 —ha-w c:\documents and settings\All Users\hpothb07.dat
2005-02-02 15:43 0 —ha-w c:\documents and settings\fotomap\hpothb07.dat
2008-05-27 13:14 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012008052720080528\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
“CTFMON.EXE”=“c:\windows\system32\ctfmon.exe”
“MSMSGS”=“c:\program files\Messenger\msmsgs.exe”
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll”
“zBrowser Launcher”=“c:\program files\Logitech\iTouch\iTouch.exe”
“ZoneAlarm Client”=“c:\program files\Zone Labs\ZoneAlarm\zlclient.exe”
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll”
“NeroCheck”=“c:\windows\system32\\NeroCheck.exe”
“Adobe Photo Downloader”=“c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe”
“AVG8_TRAY”=“c:\progra~1\AVG\AVG8\avgtray.exe”
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
“Logitech Utility”=“Logi_MwX.Exe”
“CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE”
c:\documents and settings\keesmees\Menu Start\Programma's\Opstarten\
WordWeb.lnk - c:\program files\WordWeb\wweb32.exe
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE
“AppInit_DLLs”=avgrsstx.dll
“aux”= sysaudio.sys
path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
–a—— 2008-06-07 14:26 217088 c:\documents and settings\All Users\Bureaublad\Kaspersky Lab Tool\is-5G2HQ\is-5G2HQ.exe
–a—— 2008-04-14 18:03 1695232 c:\program files\Messenger\msmsgs.exe
–a—— 2004-10-29 16:50 4620288 c:\windows\system32\nvcpl.dll
–a—— 2005-07-07 18:53 98304 c:\program files\QuickTime\qttask.exe
–a—— 2008-01-15 23:54 37376 c:\program files\Winamp\winampa.exe
–a—— 2004-10-29 16:50 921600 c:\windows\system32\nwiz.exe
–a—— 2003-12-19 10:53 65024 c:\windows\SOUNDMAN.EXE
“MSMSGS”=“c:\program files\Messenger\msmsgs.exe” /background
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe”
“mmtask”=c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
“MMTray”=c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
“Adobe Photo Downloader”=“c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe”
“DisableMonitoring”=dword:00000001
“EnableFirewall”= 0 (0x0)
“c:\\WINDOWS\\system32\\sessmgr.exe”=
“c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Program Files\\AVG\\AVG8\\avgupd.exe”=
“c:\\Program Files\\AVG\\AVG8\\avgemc.exe”=
“%windir%\\system32\\sessmgr.exe”=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys
R3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\Drivers\LCcFltr.Sys
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys
*Newly Created Service* - PROCEXP90
.
Inhoud van de ‘Gedeelde Taken’ map
2008-02-07 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1194453305.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
.
——- Bijkomende Scan ——-
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab
c:\windows\Downloaded Program Files\ewidoOnlineScan.dll
O16 -: {1D185838-009D-47C8-824B-B65B4854430E} - hxxp://quickfix2.chello.nl/quickfix2/asp/chelloInstall.CAB
c:\windows\Downloaded Program Files\chelloInstall.INF
c:\windows\Downloaded Program Files\chelloInstall.dll
O16 -: {C58EFA10-2CC0-4C50-8C77-B326555EC1B7} - hxxp://quickfix2.chello.nl/quickfix2/asp/LaunchApp.CAB
c:\windows\Downloaded Program Files\LaunchApp.INF
c:\windows\Downloaded Program Files\LaunchApp.dll
O16 -: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} - hxxp://www.cyclomedia.nl/download/components/CycloScopeLite.cab
c:\windows\Downloaded Program Files\CycloScopeLite0.inf
c:\windows\system32\ir50_32.dll
c:\windows\Downloaded Program Files\NetConnectorLite.dll
c:\windows\Downloaded Program Files\CM_RowsetTransform.dll
c:\windows\Downloaded Program Files\CM_RecordingLocationDBC.dll
c:\windows\Downloaded Program Files\CM_RecordingLocationDAL2.dll
c:\windows\Downloaded Program Files\CM_RecordingLocationService2.dll
c:\windows\Downloaded Program Files\CM_ImageDirectoryDBC.dll
c:\windows\Downloaded Program Files\CM_ImageDirectoryDAL2.dll
c:\windows\Downloaded Program Files\CM_ImageDirectoryService2.dll
c:\windows\Downloaded Program Files\CM_AuthorizationProxy2.dll
c:\windows\Downloaded Program Files\CM_ADOConnector.dll
c:\windows\Downloaded Program Files\CycloFocus.dll
c:\windows\Downloaded Program Files\Ms_dcp1x.dll
c:\windows\Downloaded Program Files\HvPix1x.dll
c:\windows\Downloaded Program Files\CycloScopeLite0.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-14 12:03:10
Windows 5.1.2600 Service Pack 3 NTFS
scannen van verborgen processen …
scannen van verborgen autostart items …
scannen van verborgen bestanden …
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
Voltooingstijd: 2008-11-14 12:06:04
ComboFix-quarantined-files.txt 2008-11-14 11:05:55
Pre-Run: 89,347,481,600 bytes beschikbaar
Post-Run: 89,392,689,152 bytes beschikbaar
WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Home Edition” /fastdetect /NoExecute=OptIn
197 — E O F — 2008-11-12 09:05:09