en dan nog het logje van combofix
ComboFix 12-04-04.02 - Ricardo 04-04-2012 21:38:48.3.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.31.1043.18.6074.4408
Gestart vanuit: c:\users\Ricardo\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . konden niet verwijderd worden
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-03-04 to 2012-04-04 ))))))))))))))))))))))))))))))
.
.
2012-04-04 19:42 . 2012-04-04 19:42 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-04-04 19:42 . 2012-04-04 19:42 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-04 15:21 . 2012-04-04 15:21 ——– d—–w- c:\program files (x86)\Conduit
2012-04-04 04:04 . 2012-04-04 04:04 ——– d—–w- c:\program files (x86)\ESET
2012-04-03 03:59 . 2012-04-03 03:59 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-29 22:31 . 2012-03-29 22:31 ——– d—–w- c:\users\Ricardo\AppData\Roaming\QuickScan
2012-03-29 21:53 . 2012-03-29 21:53 ——– d—–w- c:\users\Ricardo\AppData\Local\KSafe
2012-03-26 18:22 . 2011-03-03 15:59 29288 —-a-w- c:\windows\system32\nvhdap64.dll
2012-03-26 18:22 . 2011-03-03 15:59 174184 —-a-w- c:\windows\system32\drivers\nvhda64v.sys
2012-03-26 18:22 . 2011-03-03 15:59 1359976 —-a-w- c:\windows\system32\nvhdagenco642040.dll
2012-03-26 18:21 . 2012-03-26 18:21 ——– d—–w- c:\programdata\NVIDIA Corporation
2012-03-26 18:20 . 2011-03-10 13:00 8124520 —-a-w- c:\windows\system32\nvwgf2umx.dll
2012-03-26 18:20 . 2011-03-10 13:00 6042008 —-a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-03-26 18:20 . 2011-03-10 13:00 20487272 —-a-w- c:\windows\system32\nvoglv64.dll
2012-03-26 18:20 . 2011-03-10 13:00 15061400 —-a-w- c:\windows\SysWow64\nvoglv32.dll
2012-03-26 18:20 . 2011-03-10 13:00 13014040 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-03-26 18:20 . 2011-03-10 13:00 12867992 —-a-w- c:\windows\system32\nvd3dumx.dll
2012-03-26 18:20 . 2011-03-10 13:00 10082712 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2012-03-26 18:20 . 2011-03-10 13:00 2214296 —-a-w- c:\windows\system32\nvapi64.dll
2012-03-26 18:20 . 2011-03-10 13:00 1979288 —-a-w- c:\windows\SysWow64\nvapi.dll
2012-03-26 18:16 . 2012-03-26 18:16 ——– d—–w- c:\users\Ricardo\AppData\Roaming\KSafe
2012-03-26 18:16 . 2012-03-26 18:16 ——– d—–w- c:\programdata\KSafe
2012-03-26 18:10 . 2012-03-26 18:10 ——– d—–w- C:\KSafeRecycle
2012-03-26 18:10 . 2012-03-26 18:10 ——– d—–w- c:\users\Ricardo\AppData\Roaming\kingsoft
2012-03-26 18:10 . 2012-03-29 22:13 ——– d—–w- c:\programdata\Kingsoft
2012-03-26 18:10 . 2012-03-26 18:10 ——– d—–w- c:\program files (x86)\Kingsoft
2012-03-26 17:30 . 2012-03-26 17:30 ——– d—–w- c:\program files (x86)\NVIDIA Corporation
2012-03-26 17:28 . 2011-03-10 13:00 1612184 —-a-w- c:\windows\system32\nvdispco642090.dll
2012-03-26 17:28 . 2011-03-10 13:00 1357720 —-a-w- c:\windows\system32\nvgenco642040.dll
2012-03-26 17:28 . 2011-03-10 13:00 67176 —-a-w- c:\windows\system32\OpenCL.dll
2012-03-26 17:28 . 2011-03-10 13:00 55704 —-a-w- c:\windows\SysWow64\OpenCL.dll
2012-03-26 17:28 . 2011-03-10 13:00 2895256 —-a-w- c:\windows\SysWow64\nvcuvid.dll
2012-03-26 17:28 . 2011-03-10 13:00 3113576 —-a-w- c:\windows\system32\nvcuvid.dll
2012-03-26 17:28 . 2011-03-10 13:00 2482280 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-03-26 17:28 . 2011-03-10 13:00 4941720 —-a-w- c:\windows\SysWow64\nvcuda.dll
2012-03-26 17:28 . 2011-03-10 13:00 2252904 —-a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-03-26 17:28 . 2011-03-10 13:00 6607976 —-a-w- c:\windows\system32\nvcuda.dll
2012-03-26 17:27 . 2011-03-10 13:00 13011560 —-a-w- c:\windows\SysWow64\nvcompiler.dll
2012-03-26 17:27 . 2011-03-10 13:00 18577816 —-a-w- c:\windows\system32\nvcompiler.dll
2012-03-26 17:27 . 2011-03-10 13:00 8984 —-a-w- c:\windows\system32\drivers\nvBridge.kmd
2012-03-18 20:07 . 2012-03-18 20:07 ——– d—–w- c:\program files (x86)\InstallShield Installation Information
2012-03-18 20:07 . 2012-03-18 20:07 ——– d—–w- c:\program files (x86)\My Company Name
2012-03-14 06:14 . 2011-11-19 15:20 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-03-14 06:14 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-14 06:14 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-14 05:58 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys
2012-03-14 05:57 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll
2012-03-14 05:57 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll
2012-03-14 05:57 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 05:57 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-14 05:57 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-14 05:57 . 2012-02-17 06:38 1112064 —-a-w- c:\windows\system32\rdpcorets.dll
2012-03-14 05:57 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll
2012-03-14 05:57 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-14 05:57 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 05:57 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-06 22:40 . 2012-03-06 22:40 162664 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-03 03:59 . 2011-06-21 20:39 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-14 03:27 . 2011-06-22 20:30 8669240 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-02-28 15:23 . 2011-09-17 14:13 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-02-10 06:25 . 2012-02-10 06:27 927800 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{819A1657-856E-4B73-961C-4B64A4402053}\gapaengine.dll
2012-02-05 12:05 . 2012-02-05 12:05 61440 —-a-w- c:\windows\SysWow64\drivers\jbna.sys
2012-02-05 11:58 . 2012-02-05 11:58 61440 —-a-w- c:\windows\SysWow64\drivers\muudei.sys
2012-02-05 11:47 . 2012-02-05 11:47 61440 —-a-w- c:\windows\SysWow64\drivers\ttkkco.sys
2012-01-31 15:48 . 2012-01-31 15:48 129024 —-a-w- c:\windows\RegBootClean64.exe
2012-01-31 12:44 . 2011-06-20 20:10 279656 ——w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-04_17.53.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-21 18:03 . 2012-04-04 17:55 48212 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-04 18:20 30514 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-06-21 18:03 . 2012-04-04 18:20 10940 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1910047367-3864795175-840720451-1000_UserData.bin
+ 2011-06-20 19:52 . 2012-04-04 19:14 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-06-20 19:52 . 2012-04-04 14:27 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-20 19:52 . 2012-04-04 19:14 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-06-20 19:52 . 2012-04-04 14:27 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-04 14:27 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-04 19:14 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-04 17:53 . 2012-04-04 17:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-04 19:43 . 2012-04-04 19:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-04-04 17:53 . 2012-04-04 17:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-04 19:43 . 2012-04-04 19:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-04-04 17:53 . 2009-04-30 14:00 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
+ 2012-04-04 19:44 . 2009-04-30 14:00 131608 c:\windows\Temp\logishrd\LVPrcInj02.dll
- 2012-04-04 17:53 . 2009-04-30 14:01 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
+ 2012-04-04 19:44 . 2009-04-30 14:01 109080 c:\windows\Temp\logishrd\LVPrcInj01.dll
- 2009-07-14 05:01 . 2012-04-04 17:52 389116 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-04-04 19:43 389116 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-06-21 19:57 . 2012-04-04 15:33 5748563 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1910047367-3864795175-840720451-1000-12288.dat
+ 2011-06-21 19:57 . 2012-04-04 19:43 5748563 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1910047367-3864795175-840720451-1000-12288.dat
+ 2011-06-21 19:57 . 2012-04-04 19:43 37644900 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1910047367-3864795175-840720451-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“IncrediMail”=“c:\program files (x86)\IncrediMail\bin\IncMail.exe”
“Messenger (Yahoo!)”=“c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe”
.
“LogitechQuickCamRibbon”=“c:\program files\Logitech\Logitech WebCam Software\LWS.exe”
“KSafeTray”=“c:\program files (x86)\Kingsoft\PCDoctor\KSafeTray.exe”
.
“ConsentPromptBehaviorAdmin”= 5 (0x5)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
.
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
@=“Service”
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
R3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys
R3 LVUVC64;Logitech QuickCam Pro 5000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys
R3 MSICDSetup;MSICDSetup;F:\CDriver64.sys
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
S2 KSafeSvc;KSafe service;c:\program files (x86)\Kingsoft\PCDoctor\KSafeSvc.exe
S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys
.
.
Inhoud van de ‘Gedeelde Taken’ map
.
2012-04-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
.
2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1910047367-3864795175-840720451-1000Core.job
- c:\users\Ricardo\AppData\Local\Google\Update\GoogleUpdate.exe
.
2012-04-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1910047367-3864795175-840720451-1000UA.job
- c:\users\Ricardo\AppData\Local\Google\Update\GoogleUpdate.exe
.
.
——— x86-64 ———–
.
.
“MSC”=“c:\program files\Microsoft Security Client\msseces.exe”
.
——- Bijkomende Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.zeelandnet.nl/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 212.115.192.100 62.238.255.69
.
- - - - ORPHANS VERWIJDERD - - - -
.
URLSearchHooks-{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - (no file)
WebBrowser-{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - (no file)
.
.
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=“@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101”
.
“Enabled”=dword:00000001
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx”
“ThreadingModel”=“Apartment”
.
@=“0”
.
@=“ShockwaveFlash.ShockwaveFlash.11”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“ShockwaveFlash.ShockwaveFlash”
.
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx”
“ThreadingModel”=“Apartment”
.
@=“FlashFactory.FlashFactory.1”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“FlashFactory.FlashFactory”
.
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
.
@=“{00020424-0000-0000-C000-000000000046}”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
@Denied: (Full) (Everyone)
.
———————— Andere Aktieve Processen ————————
.
c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
c:\program files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
.
**************************************************************************
.
Voltooingstijd: 2012-04-04 21:47:19 - machine werd herstart
ComboFix-quarantined-files.txt 2012-04-04 19:47
ComboFix2.txt 2012-04-04 17:56
ComboFix3.txt 2012-02-04 14:35
.
Pre-Run: 325.461.782.528 bytes beschikbaar
Post-Run: 325.441.318.912 bytes beschikbaar
.
- - End Of File - - 951A1D1312BDF8CE1C656AA231774ECF
groetjes ricardo