Hier alvast het logje van Combofix, het logje van Hyacthis lukt niet, iets met administrator, pas lukte het wel, probeer het morgen nog eens.
Hij doet het weer oké, liep vmi wel even vast naar zwart scherm, maar na opnieuw starten deed hij het weer.
De laatste maanden kwam er met opstarten elke keer een pop up in beeld van PSSW Core oid, had volgens mij met de printer te maken.
Deze was erg harnekkig en moest elke keer weggeklikt worden.
Deze is na de herstelde besmetting verdwenen
Groetjes Roosje
ComboFix 10-11-07.A2 - Adrie 09-11-2010 10:57:06.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.2301.1283
Gestart vanuit: H:\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Aanwezig AV is actief
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
(((((((((((((((((((( Bestanden Gemaakt van 2010-10-09 to 2010-11-09 ))))))))))))))))))))))))))))))
.
2010-11-09 10:06 . 2010-11-09 10:08 ——– d—–w- c:\users\Adrie\AppData\Local\temp
2010-11-09 10:06 . 2010-11-09 10:06 ——– d—–w- c:\users\ReleaseEngineer.MACROVISION\AppData\Local\temp
2010-11-09 10:06 . 2010-11-09 10:06 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-11-09 10:06 . 2010-11-09 10:06 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-11-09 09:52 . 2010-11-09 09:53 ——– d—–w- C:\32788R22FWJFW
2010-11-06 19:22 . 2010-11-06 19:22 ——– d—–w- C:\found.003
2010-11-06 05:09 . 2010-11-07 20:43 ——– d—–w- c:\program files\Panda Security
2010-11-05 22:14 . 2010-11-05 22:14 ——– d—–w- c:\users\Adrie\Nieuwe map (1)
2010-11-05 22:14 . 2010-11-05 22:14 ——– d—–w- c:\users\Adrie\Nieuwe map
2010-10-31 08:33 . 2010-10-31 08:33 ——– d—–w- c:\users\Adrie\AppData\Roaming\MAGIX
2010-10-31 08:31 . 2007-04-27 09:43 120200 —-a-w- c:\windows\system32\DLLDEV32i.dll
2010-10-31 08:30 . 2010-10-31 08:30 ——– d—–w- c:\program files\Common Files\MAGIX Services
2010-10-28 04:58 . 2010-08-26 16:34 1696256 —-a-w- c:\windows\system32\gameux.dll
2010-10-28 04:57 . 2010-08-26 16:33 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2010-10-28 04:57 . 2010-08-26 14:23 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-10-21 19:02 . 2010-10-21 19:02 ——– d—–w- c:\program files\Nebo Fotoservice
2010-10-13 17:12 . 2010-10-13 17:12 94040 —-a-w- c:\program files\Common Files\Windows Live\.cache\dfb25bd31cb6af91e\DSETUP.dll
2010-10-13 17:12 . 2010-10-13 17:12 525656 —-a-w- c:\program files\Common Files\Windows Live\.cache\dfb25bd31cb6af91e\DXSETUP.exe
2010-10-13 17:12 . 2010-10-13 17:12 1691480 —-a-w- c:\program files\Common Files\Windows Live\.cache\dfb25bd31cb6af91e\dsetup32.dll
2010-10-13 17:12 . 2010-10-13 17:12 94040 —-a-w- c:\program files\Common Files\Windows Live\.cache\d5fadef31cb6af91d\DSETUP.dll
2010-10-13 17:12 . 2010-10-13 17:12 525656 —-a-w- c:\program files\Common Files\Windows Live\.cache\d5fadef31cb6af91d\DXSETUP.exe
2010-10-13 17:12 . 2010-10-13 17:12 1691480 —-a-w- c:\program files\Common Files\Windows Live\.cache\d5fadef31cb6af91d\dsetup32.dll
2010-10-13 17:02 . 2010-10-13 17:02 ——– d—–w- c:\users\Adrie\AppData\Local\Windows Live
2010-10-13 05:35 . 2010-09-13 13:56 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2010-10-13 05:35 . 2010-09-13 13:56 168960 —-a-w- c:\program files\Windows Media Player\wmplayer.exe
2010-10-13 05:35 . 2010-09-06 16:20 125952 —-a-w- c:\windows\system32\srvsvc.dll
2010-10-13 05:35 . 2010-09-06 13:45 304128 —-a-w- c:\windows\system32\drivers\srv.sys
2010-10-13 05:35 . 2010-09-06 13:45 145408 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-10-13 05:35 . 2010-09-06 13:45 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-13 05:35 . 2010-09-06 16:19 17920 —-a-w- c:\windows\system32\netevent.dll
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 16:33 . 2010-10-28 04:57 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2010-08-26 16:33 . 2010-10-28 04:57 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2010-08-26 16:33 . 2010-10-28 04:57 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2010-08-26 16:33 . 2010-10-28 04:57 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2010-08-17 14:11 . 2010-09-15 05:57 128000 —-a-w- c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
“ehTray.exe”=“c:\windows\ehome\ehTray.exe”
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe”
“SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe”
“mcagent_exe”=“c:\program files\McAfee.com\Agent\mcagent.exe”
“EnableUIADesktopToggle”= 0 (0x0)
“AppInit_DLLs”=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
@=“”
@=“”
@=“Service”
2010-04-16 20:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
2009-04-11 06:28 2153472 —-a-w- c:\windows\System32\oobefldr.dll
R0 lhxqgxm;lhxqgxm;c:\windows\System32\drivers\gobxi.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe
R3 uxddrv;Dynamically loaded UxdDrv;e:\diagnose\WSTENG32\2PART\uxddrv86.sys
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
S0 DiskSec;Magix Volume Filter Driver;
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys
S3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de ‘Gedeelde Taken’ map
2010-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe
2010-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe
2010-09-07 c:\windows\Tasks\Install.job
- c:\windows\System32\Macromed\Shockwave 10\nssstub.exe
2010-04-08 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe
2010-07-31 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe
2010-11-09 c:\windows\Tasks\PCCT - MAGIX AG.job
- c:\program files\MAGIX\PC_Check_Tuning_2010_Download-versie\MxTray.exe
2010-11-08 c:\windows\Tasks\User_Feed_Synchronization-{66509024-ED84-400E-AB8C-AB50DB202535}.job
- c:\windows\system32\msfeedssync.exe
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://prijsvragen.startpagina.nl/prikbord/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Formulieren opslaan - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Invul Formulieren - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Menu aanpassen - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RoboForm Werkbalk - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Trusted Zone: sgcambium.net
Trusted Zone: sgcambium.net\.www
DPF: {63D6DD13-C913-466D-9444-9357561E4D94} - hxxp://www.mijnalbum.nl/v3/skinsrc/core/system/ma5.8.3/uploadtoepassing.cab
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
.
- - - - ORPHANS VERWIJDERD - - - -
HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\DTLite.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-09 11:08
Windows 6.0.6002 Service Pack 2 NTFS
scannen van verborgen processen …
scannen van verborgen autostart items …
scannen van verborgen bestanden …
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
Voltooingstijd: 2010-11-09 11:10:52
ComboFix-quarantined-files.txt 2010-11-09 10:10
ComboFix2.txt 2010-05-26 17:50
Pre-Run: 205.766.688.768 bytes beschikbaar
Post-Run: 205.807.087.616 bytes beschikbaar
- - End Of File - - F965DF8F98467BBFCD94D48E780CDCAA