nou toch gelukt met die combo loggie, nou kijk maar is of dat wat of er nog tussen zit wat er niet thuishoort
en die avast he is dat avast internet security of gewoon de avast free met windows firewal
ComboFix 11-07-08.03 - willem 09-07-2011 15:44:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.3070.2523
Gestart vanuit: c:\documents and settings\willem\Bureaublad\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\willem\Application Data\PriceGong
c:\documents and settings\willem\Application Data\PriceGong\Data\1.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\a.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\b.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\c.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\d.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\e.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\f.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\g.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\h.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\i.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\J.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\k.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\l.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\m.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\n.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\o.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\p.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\q.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\r.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\s.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\t.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\u.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\v.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\w.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\x.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\y.xml
c:\documents and settings\willem\Application Data\PriceGong\Data\z.xml
c:\windows\IsUn0413.exe
c:\windows\vb.ini
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-06-09 to 2011-07-09 ))))))))))))))))))))))))))))))
.
.
2011-07-09 08:44 . 2011-07-09 08:44 ——– d—–w- c:\program files\Lavalys
2011-07-08 19:07 . 2011-07-08 19:07 388096 —-a-r- c:\documents and settings\willem\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-08 19:07 . 2011-07-08 19:07 ——– d—–w- c:\program files\Trend Micro
2011-07-08 18:35 . 2011-07-09 13:00 ——– d–h–r- c:\documents and settings\willem\Onlangs geopend
2011-07-05 19:26 . 2011-07-09 12:45 ——– d—–w- c:\documents and settings\willem\Local Settings\Application Data\Google
2011-07-05 19:26 . 2011-07-09 12:45 ——– d—–w- c:\documents and settings\willem\Local Settings\Application Data\Deployment
2011-07-05 17:37 . 2011-07-05 17:37 ——– d—–w- c:\program files\CCleaner
2011-07-05 12:36 . 2009-06-30 08:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2011-07-02 12:26 . 2011-07-02 12:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-07-02 06:22 . 2011-07-02 06:22 ——– d—–w- C:\found.000
2011-06-30 17:54 . 2011-06-30 17:54 ——– d—–w- c:\documents and settings\willem\Local Settings\Application Data\WinAVI
2011-06-30 17:54 . 2011-06-30 17:54 ——– d—–w- c:\windows\WinAVI Video Converter 9.0
2011-06-29 18:33 . 2011-06-29 18:33 ——– d—–w- c:\documents and settings\willem\Local Settings\Application Data\Microsoft_Corporation
2011-06-29 17:55 . 2011-06-29 17:55 ——– d—–w- c:\windows\system32\winrm
2011-06-29 17:55 . 2011-06-29 17:55 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-06-29 17:55 . 2006-06-29 11:07 14048 ——w- c:\windows\system32\spmsg2.dll
2011-06-28 16:31 . 2011-06-28 16:31 ——– d—–w- c:\program files\Common Files\Java
2011-06-24 15:04 . 2011-06-24 15:04 ——– d—–w- c:\program files\7-Zip
2011-06-17 11:45 . 2011-06-17 11:45 ——– d—–w- c:\program files\Belastingdienst
2011-06-16 10:35 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-14 19:25 . 2004-12-02 23:26 188416 ——w- c:\windows\system32\PDRVINST.DLL
2011-06-14 19:25 . 2003-07-02 23:08 65536 ——w- c:\windows\system32\BRWEBUP.EXE
2011-06-14 19:25 . 2002-10-30 23:09 81920 ——w- c:\windows\system32\BrWebIns.dll
2011-06-14 19:25 . 2000-01-28 10:19 331776 ——w- c:\program files\Common Files\InstallShield\WebUpdate\WebUpdate.exe
2011-06-14 19:25 . 2000-01-28 10:19 24576 ——w- c:\program files\Common Files\InstallShield\WebUpdate\RasThunk.dll
2011-06-14 19:25 . 2000-01-28 10:19 132096 ——w- c:\program files\Common Files\InstallShield\WebUpdate\ISiteLite.dll
2011-06-14 19:25 . 2000-01-28 10:19 513536 ——w- c:\program files\Common Files\InstallShield\WebUpdate\IFTW.EXE
2011-06-14 19:25 . 2011-06-14 19:25 ——– d—–w- C:\Brother
2011-06-14 19:25 . 2005-04-07 23:01 122880 ——w- c:\windows\system32\BrfxD05a.dll
2011-06-14 19:25 . 2011-06-14 19:26 ——– d—–w- c:\program files\Brother
2011-06-14 19:24 . 2002-12-05 12:10 155648 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-06-14 19:24 . 2011-06-14 19:24 163972 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-06-14 19:24 . 2002-12-05 12:12 692224 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-06-14 19:24 . 2002-12-02 13:22 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-06-14 19:24 . 2002-12-02 11:33 57344 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-06-14 19:24 . 2002-12-02 11:33 237568 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-06-14 19:24 . 2011-06-14 19:24 282756 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-06-14 13:31 . 2011-06-14 13:31 ——– d—–w- c:\documents and settings\Administrator
2011-06-13 12:45 . 2008-06-24 11:45 1414440 —-a-w- c:\windows\system32\ShellManager310E2D762.dll
2011-06-13 12:16 . 2011-06-13 12:20 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2011-06-13 09:57 . 2011-06-13 09:57 ——– d—–w- c:\program files\DVDVideoSoft
2011-06-13 09:16 . 2011-06-13 09:58 ——– d—–w- c:\documents and settings\willem\Application Data\DVDVideoSoftIEHelpers
2011-06-13 09:16 . 2011-06-13 09:58 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2011-06-11 09:49 . 2011-06-11 09:49 ——– d—–w- c:\documents and settings\willem\Application Data\SUPERAntiSpyware.com
2011-06-11 09:49 . 2011-07-02 10:24 ——– d—–w- c:\program files\SUPERAntiSpyware
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-16 11:16 . 2011-05-28 18:59 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-01 13:07 . 2011-06-01 13:07 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-29 07:11 . 2011-05-30 12:01 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 07:11 . 2011-05-30 12:01 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-16 07:45 . 2011-05-16 07:45 7040 —-a-w- c:\windows\system32\sabprocenum.sys
2011-05-04 02:52 . 2011-05-29 17:25 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2011-05-29 17:25 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31 . 2011-05-28 15:26 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-03 23:03 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-03 21:15 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:05 . 2004-08-03 23:03 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:05 . 2004-08-03 23:03 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 16:05 . 2004-08-03 23:03 43520 ——w- c:\windows\system32\licmgr10.dll
2011-04-25 12:01 . 2004-08-03 22:55 385024 ——w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-03 21:15 105472 —-a-w- c:\windows\system32\drivers\mup.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe”
“IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe”
.
“RTHDCPL”=“RTHDCPL.EXE”
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll”
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll”
“SSBkgdUpdate”=“c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe”
“IndexSearch”=“c:\program files\ScanSoft\PaperPort\IndexSearch.exe”
“PaperPort PTD”=“c:\program files\ScanSoft\PaperPort\pptd40nt.exe”
“SetDefPrt”=“c:\program files\Brother\Brmfl05a\BrStDvPt.exe”
“ControlCenter2.0”=“c:\program files\Brother\ControlCenter2\brctrcen.exe”
“SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe”
.
“AvgUninstallURL”=“start http://www.avg.com/nl.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMkNNWC1SWFBXQS1QM05aSC05RDIwQy0zN1RT&inst=NzctNjcwNzczNDAzLVNQMSsxLVNQMVRCKzEtU1AxUzIrMS1TVUQrMS1EMzgxTCs2LVMxSSsxLVNVMysxLVRVRyszLUxTRCsyLUREVCswLUkxMCsx&prod=55&ver=10.0.1388”
.
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE”
.
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “c:\program files\SUPERAntiSpyware\SASSEH.DLL”
.
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
path=c:\documents and settings\willem\Menu Start\Programma's\Opstarten\OpenOffice.org 3.3 .lnk
backup=c:\windows\pss\OpenOffice.org 3.3 .lnkStartup
.
2011-06-06 10:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
2011-06-06 10:55 35736 —-a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
2001-09-24 07:39 98304 —-a-w- c:\program files\Common Files\Logitech\QCDriver\LVComS.exe
.
2011-05-29 07:11 449584 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
2008-06-08 07:31 2221352 —-a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
2008-06-19 07:53 570664 —-a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
2010-11-04 06:51 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
“%windir%\\system32\\sessmgr.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe”=
“c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=
“c:\\Program Files\\uTorrent\\uTorrent.exe”=
.
“3389:TCP”= 3389:TCP:Remote Desktop
“65533:TCP”= 65533:TCP:Services
“52344:TCP”= 52344:TCP:Services
“5985:TCP”= 5985:TCP:*isabled:Windows Remote Management
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS
R3 QCEmerald;Logitech QuickCam Web(PID_0850);c:\windows\system32\drivers\lvce.sys
R3 xcpip;Stuurprogramma voor TCP/IP-protocol;c:\windows\system32\drivers\xcpip.sys –> c:\windows\system32\drivers\xcpip.sys
R3 xpsec;IPSEC-stuurprogramma;c:\windows\system32\drivers\xpsec.sys –> c:\windows\system32\drivers\xpsec.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
.
WINRM REG_MULTI_SZ WINRM
.
Inhoud van de ‘Gedeelde Taken’ map
.
2011-07-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1767777339-725345543-1003Core.job
- c:\documents and settings\willem\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
2011-07-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-1767777339-725345543-1003UA.job
- c:\documents and settings\willem\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.startpagina.nl/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\documents and settings\willem\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS VERWIJDERD - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-Advanced SystemCare 4 - c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
MSConfigStartUp-SDTray - c:\program files\Spybot - Search & Destroy 2\SDTray.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-09 15:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen …
.
scannen van verborgen autostart items …
.
scannen van verborgen bestanden …
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
“3140110900063D11C8EF10054038389C”=“C?\\WINDOWS\\system32\\FM20ENU.DLL”
.
——————— DLLs Geladen Onder Lopende Processen ———————
.
- - - - - - - > ‘winlogon.exe’(784)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\documents and settings\willem\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\documents and settings\willem\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
c:\documents and settings\willem\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
c:\documents and settings\willem\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
.
Voltooingstijd: 2011-07-09 15:47:06
ComboFix-quarantined-files.txt 2011-07-09 13:47
.
Pre-Run: 246.249.689.088 bytes beschikbaar
Post-Run: 246.358.953.984 bytes beschikbaar
.
WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
UnsupportedDebug=“do not select this” /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Professional” /noexecute=optin /fastdetect
.
- - End Of File - - 63E04EBF10D526EC979DD35743889C5A