Hallo,
Hier het logje van combofix
ComboFix 12-09-15.02 - suzanneenchris 16-09-2012 14:01:15.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1790.1384
Gestart vanuit: c:\documents and settings\suzanneenchris\Bureaublad\proggies\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\msadoex.dll
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Gast\Application Data\PriceGong
c:\documents and settings\Gast\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Gast\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Gast\Application Data\PriceGong\Data\z.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\1.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\371.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\4489.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\450.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\a.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\b.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\c.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\d.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\e.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\f.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\g.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\h.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\i.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\j.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\k.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\l.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\m.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\n.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\o.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\p.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\q.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\r.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\s.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\t.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\u.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\v.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\w.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\x.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\y.txt
c:\documents and settings\suzanneenchris\Application Data\PriceGong\Data\z.txt
c:\documents and settings\suzanneenchris\Application Data\Toolbar4
c:\documents and settings\suzanneenchris\Application Data\win
c:\documents and settings\suzanneenchris\lame_enc_en.dll
c:\documents and settings\suzanneenchris\lametritonus_en.dll
c:\documents and settings\suzanneenchris\WINDOWS
c:\windows\config.txt
c:\windows\IsUn0413.exe
c:\windows\iun6002.exe
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\roboot.exe
c:\windows\system32\SET10CE.tmp
c:\windows\system32\SET10E1.tmp
c:\windows\system32\SET10E2.tmp
c:\windows\system32\SET10EC.tmp
c:\windows\system32\SET10FF.tmp
c:\windows\system32\SET1104.tmp
c:\windows\system32\SET1110.tmp
c:\windows\system32\SET112B.tmp
c:\windows\system32\SET1140.tmp
c:\windows\system32\SET1156.tmp
c:\windows\system32\SET116C.tmp
c:\windows\system32\SET1173.tmp
c:\windows\system32\SET1174.tmp
c:\windows\system32\SET1175.tmp
c:\windows\system32\SET1177.tmp
c:\windows\system32\SET118C.tmp
c:\windows\system32\SET11B2.tmp
c:\windows\system32\SET11C6.tmp
c:\windows\system32\SET11CF.tmp
c:\windows\system32\SET1222.tmp
c:\windows\system32\SET1226.tmp
c:\windows\system32\SET122E.tmp
c:\windows\system32\SET1276.tmp
c:\windows\system32\SET14F.tmp
c:\windows\system32\SET150.tmp
c:\windows\system32\SET152.tmp
c:\windows\system32\SET154.tmp
c:\windows\system32\SET156.tmp
c:\windows\system32\SET15D.tmp
c:\windows\system32\SET15E.tmp
c:\windows\system32\SET161.tmp
c:\windows\system32\SET170.tmp
c:\windows\system32\SET176.tmp
c:\windows\system32\SET177.tmp
c:\windows\system32\SET179.tmp
c:\windows\system32\SET17A.tmp
c:\windows\system32\SET17B.tmp
c:\windows\system32\SET17C.tmp
c:\windows\system32\SET17D.tmp
c:\windows\system32\SET17F.tmp
c:\windows\system32\SET180.tmp
c:\windows\system32\SET181.tmp
c:\windows\system32\SET184.tmp
c:\windows\system32\SET18B.tmp
c:\windows\system32\SET18C.tmp
c:\windows\system32\SET190.tmp
c:\windows\system32\SET192.tmp
c:\windows\system32\SET193.tmp
c:\windows\system32\SET199.tmp
c:\windows\system32\SET19B.tmp
c:\windows\system32\SET19C.tmp
c:\windows\system32\SET19D.tmp
c:\windows\system32\SET19E.tmp
c:\windows\system32\SET19F.tmp
c:\windows\system32\SET1A4.tmp
c:\windows\system32\SET1A5.tmp
c:\windows\system32\SET1A6.tmp
c:\windows\system32\SET1A7.tmp
c:\windows\system32\SET1A8.tmp
c:\windows\system32\SET1AE.tmp
c:\windows\system32\SET1B3.tmp
c:\windows\system32\SET1B4.tmp
c:\windows\system32\SET1B7.tmp
c:\windows\system32\SET1BA.tmp
c:\windows\system32\SET1BB.tmp
c:\windows\system32\SET1C2.tmp
c:\windows\system32\SET1C3.tmp
c:\windows\system32\SET1C5.tmp
c:\windows\system32\SET1C8.tmp
c:\windows\system32\SET1C9.tmp
c:\windows\system32\SET1D2.tmp
c:\windows\system32\SET1D3.tmp
c:\windows\system32\SET1D6.tmp
c:\windows\system32\SET1D8.tmp
c:\windows\system32\SET1D9.tmp
c:\windows\system32\SET1DA.tmp
c:\windows\system32\SET1DB.tmp
c:\windows\system32\SET1DC.tmp
c:\windows\system32\SET1E2.tmp
c:\windows\system32\SET1EF.tmp
c:\windows\system32\SET1F4.tmp
c:\windows\system32\SET1F6.tmp
c:\windows\system32\SET1F8.tmp
c:\windows\system32\SET1FA.tmp
c:\windows\system32\SET1FB.tmp
c:\windows\system32\SET1FD.tmp
c:\windows\system32\SET1FE.tmp
c:\windows\system32\SET202.tmp
c:\windows\system32\SET203.tmp
c:\windows\system32\SET208.tmp
c:\windows\system32\SET20E.tmp
c:\windows\system32\SET20F.tmp
c:\windows\system32\SET210.tmp
c:\windows\system32\SET218.tmp
c:\windows\system32\SET21E.tmp
c:\windows\system32\SET221.tmp
c:\windows\system32\SET223.tmp
c:\windows\system32\SET229.tmp
c:\windows\system32\SET235.tmp
c:\windows\system32\SET237.tmp
c:\windows\system32\SET239.tmp
c:\windows\system32\SET23A.tmp
c:\windows\system32\SET23B.tmp
c:\windows\system32\SET247.tmp
c:\windows\system32\SET249.tmp
c:\windows\system32\SET24A.tmp
c:\windows\system32\SET24D.tmp
c:\windows\system32\SET24F.tmp
c:\windows\system32\SET252.tmp
c:\windows\system32\SET261.tmp
c:\windows\system32\SET264.tmp
c:\windows\system32\SET265.tmp
c:\windows\system32\SET26C.tmp
c:\windows\system32\SET26D.tmp
c:\windows\system32\SET270.tmp
c:\windows\system32\SET271.tmp
c:\windows\system32\SET272.tmp
c:\windows\system32\SET273.tmp
c:\windows\system32\SET274.tmp
c:\windows\system32\SET276.tmp
c:\windows\system32\SET277.tmp
c:\windows\system32\SET278.tmp
c:\windows\system32\SET27A.tmp
c:\windows\system32\SET27B.tmp
c:\windows\system32\SET27C.tmp
c:\windows\system32\SET27E.tmp
c:\windows\system32\SET281.tmp
c:\windows\system32\SET286.tmp
c:\windows\system32\SET287.tmp
c:\windows\system32\SET288.tmp
c:\windows\system32\SET28D.tmp
c:\windows\system32\SET28E.tmp
c:\windows\system32\SET28F.tmp
c:\windows\system32\SET291.tmp
c:\windows\system32\SET294.tmp
c:\windows\system32\SET296.tmp
c:\windows\system32\SET297.tmp
c:\windows\system32\SET29A.tmp
c:\windows\system32\SET29E.tmp
c:\windows\system32\SET2A1.tmp
c:\windows\system32\SET2A2.tmp
c:\windows\system32\SET2A4.tmp
c:\windows\system32\SET2B5.tmp
c:\windows\system32\SET2B7.tmp
c:\windows\system32\SET2B8.tmp
c:\windows\system32\SET2BB.tmp
c:\windows\system32\SET2BC.tmp
c:\windows\system32\SET2C7.tmp
c:\windows\system32\SET2CA.tmp
c:\windows\system32\SET2CC.tmp
c:\windows\system32\SET2CD.tmp
c:\windows\system32\SET2D9.tmp
c:\windows\system32\SET2DA.tmp
c:\windows\system32\SET2DB.tmp
c:\windows\system32\SET2DC.tmp
c:\windows\system32\SET2DD.tmp
c:\windows\system32\SET2DE.tmp
c:\windows\system32\SET2E0.tmp
c:\windows\system32\SET2E2.tmp
c:\windows\system32\SET2E5.tmp
c:\windows\system32\SET2EF.tmp
c:\windows\system32\SET2F1.tmp
c:\windows\system32\SET2F3.tmp
c:\windows\system32\SET2F4.tmp
c:\windows\system32\SET2F5.tmp
c:\windows\system32\SET2FD.tmp
c:\windows\system32\SET2FF.tmp
c:\windows\system32\SET300.tmp
c:\windows\system32\SET307.tmp
c:\windows\system32\SET312.tmp
c:\windows\system32\SET315.tmp
c:\windows\system32\SET316.tmp
c:\windows\system32\SET317.tmp
c:\windows\system32\SET31B.tmp
c:\windows\system32\SET323.tmp
c:\windows\system32\SET327.tmp
c:\windows\system32\SET32B.tmp
c:\windows\system32\SET32E.tmp
c:\windows\system32\SET335.tmp
c:\windows\system32\SET348.tmp
c:\windows\system32\SET34D.tmp
c:\windows\system32\SET34F.tmp
c:\windows\system32\SET351.tmp
c:\windows\system32\SET357.tmp
c:\windows\system32\SET35B.tmp
c:\windows\system32\SET367.tmp
c:\windows\system32\SET369.tmp
c:\windows\system32\SET370.tmp
c:\windows\system32\SET372.tmp
c:\windows\system32\SET373.tmp
c:\windows\system32\SET379.tmp
c:\windows\system32\SET38E.tmp
c:\windows\system32\SET390.tmp
c:\windows\system32\SET392.tmp
c:\windows\system32\SET39A.tmp
c:\windows\system32\SET39E.tmp
c:\windows\system32\SET3A9.tmp
c:\windows\system32\SET3BC.tmp
c:\windows\system32\SET3DE.tmp
c:\windows\system32\SET3DF.tmp
c:\windows\system32\SET3E2.tmp
c:\windows\system32\SET3E9.tmp
c:\windows\system32\SET3ED.tmp
c:\windows\system32\SET3F0.tmp
c:\windows\system32\SET3F1.tmp
c:\windows\system32\SET3F2.tmp
c:\windows\system32\SET3F4.tmp
c:\windows\system32\SET3F5.tmp
c:\windows\system32\SET3F6.tmp
c:\windows\system32\SET3F7.tmp
c:\windows\system32\SET3F9.tmp
c:\windows\system32\SET3FB.tmp
c:\windows\system32\SET3FC.tmp
c:\windows\system32\SET3FD.tmp
c:\windows\system32\SET400.tmp
c:\windows\system32\SET402.tmp
c:\windows\system32\SET407.tmp
c:\windows\system32\SET408.tmp
c:\windows\system32\SET410.tmp
c:\windows\system32\SET416.tmp
c:\windows\system32\SET41B.tmp
c:\windows\system32\SET41F.tmp
c:\windows\system32\SET422.tmp
c:\windows\system32\SET424.tmp
c:\windows\system32\SET428.tmp
c:\windows\system32\SET42A.tmp
c:\windows\system32\SET42B.tmp
c:\windows\system32\SET42C.tmp
c:\windows\system32\SET430.tmp
c:\windows\system32\SET431.tmp
c:\windows\system32\SET435.tmp
c:\windows\system32\SET436.tmp
c:\windows\system32\SET440.tmp
c:\windows\system32\SET443.tmp
c:\windows\system32\SET447.tmp
c:\windows\system32\SET449.tmp
c:\windows\system32\SET44B.tmp
c:\windows\system32\SET5A.tmp
c:\windows\system32\SET5C.tmp
c:\windows\system32\SET6A.tmp
c:\windows\system32\SET8B.tmp
c:\windows\system32\SETEA6.tmp
c:\windows\system32\SETEAB.tmp
c:\windows\system32\SETEBD.tmp
c:\windows\system32\SETEE5.tmp
c:\windows\system32\SETF6E.tmp
c:\windows\system32\Thumbs.db
c:\windows\unin0413.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-08-16 to 2012-09-16 ))))))))))))))))))))))))))))))
.
.
2012-09-16 08:52 . 2012-09-16 08:52 ——– d—–w- c:\program files\CrystalDiskInfo
2012-09-15 06:51 . 2012-09-16 08:42 ——– d–h–r- c:\documents and settings\suzanneenchris\Onlangs geopend
2012-09-13 14:15 . 2012-09-13 14:15 ——– d—–w- c:\documents and settings\suzanneenchris\Application Data\Freeze Tag
2012-09-12 19:27 . 2012-09-12 19:27 ——– d—–w- c:\documents and settings\suzanneenchris\Application Data\GameDevo
2012-09-12 14:02 . 2012-09-12 14:02 ——– d—–w- c:\program files\MSXML 4.0
2012-09-12 13:56 . 2012-01-09 15:28 8192 —-a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2012-09-12 13:56 . 2012-01-09 15:28 8192 —-a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2012-09-12 13:56 . 2012-01-09 15:28 23168 —-a-w- c:\windows\system32\drivers\ccdcmbo.sys
2012-09-12 13:55 . 2012-01-09 15:28 18176 —-a-w- c:\windows\system32\drivers\ccdcmb.sys
2012-09-12 08:57 . 2012-09-12 08:57 ——– d—–w- c:\windows\system32\wbem\Repository
2012-09-12 08:57 . 2012-09-16 08:28 ——– d—–w- c:\program files\Microsoft Security Client
2012-09-08 22:49 . 2008-04-14 15:34 32000 -c–a-w- c:\windows\system32\dllcache\wceusbsh.sys
2012-09-08 22:49 . 2008-04-14 15:34 32000 —-a-w- c:\windows\system32\drivers\wceusbsh.sys
2012-09-08 22:46 . 2012-09-08 22:46 147456 –sha-r- c:\windows\system32\pwdrvioc.dll
2012-09-08 22:46 . 2012-09-08 22:46 147456 –sha-r- c:\windows\system32\d3dx9_30S.dll
2012-09-08 07:50 . 2012-08-23 07:15 7022536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B3CA1F54-75E2-4313-8395-C10440280BE6}\mpengine.dll
2012-09-08 00:20 . 2012-09-08 00:20 ——– d–h–r- c:\documents and settings\Gast\Onlangs geopend
2012-09-07 03:19 . 2012-08-23 07:15 7022536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-26 21:15 . 2012-08-26 21:15 ——– d—–w- c:\documents and settings\suzanneenchris\Local Settings\Application Data\BVRP Software
2012-08-25 09:27 . 2012-06-27 13:18 19072 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-08-25 09:26 . 2012-08-25 09:26 ——– d—–w- c:\program files\PC Connectivity Solution
2012-08-21 10:52 . 2012-08-21 10:52 ——– d—–w- c:\program files\Pando Networks
2012-08-18 11:44 . 2012-08-18 11:44 ——– d—–w- c:\documents and settings\Gast\Application Data\Softonic
2012-08-18 11:03 . 2012-09-08 00:06 ——– d—–w- c:\documents and settings\Gast\Local Settings\Application Data\Spotify
2012-08-18 11:02 . 2012-09-08 00:06 ——– d—–w- c:\documents and settings\Gast\Application Data\Spotify
2012-08-18 10:57 . 2012-08-24 06:24 ——– d—–w- c:\program files\Yontoo
2012-08-18 10:57 . 2012-08-18 10:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Tarma Installer
2012-08-18 10:56 . 2012-08-20 08:35 167 —-a-w- C:\user.js
2012-08-18 10:56 . 2012-08-18 10:56 ——– d—–w- c:\program files\Photo!
2012-08-17 21:00 . 2012-09-15 12:28 ——– d—–w- c:\documents and settings\suzanneenchris\Local Settings\Application Data\Spotify
2012-08-17 20:59 . 2012-09-15 12:28 ——– d—–w- c:\documents and settings\suzanneenchris\Application Data\Spotify
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-08 07:21 . 2012-03-31 01:10 696520 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-08 07:21 . 2011-07-17 08:52 73416 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 15:04 . 2011-04-27 12:19 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 18:24 . 2012-06-27 12:38 477168 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-08-28 18:24 . 2011-04-30 13:34 473072 -c–a-w- c:\windows\system32\deployJava1.dll
2012-08-28 16:39 . 2012-06-27 12:38 73728 —-a-w- c:\windows\system32\javacpl.cpl
2007-03-12 16:59 . 2007-03-12 16:59 299008 -c–a-w- c:\program files\navigram_register.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“RTHDCPL”=“RTHDCPL.EXE”
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll”
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll”
“A8GSdsApp”=“e:\ik\A8GSdsApp\AGSeiApp.exe”
“BluetoothAuthenticationAgent”=“bthprops.cpl”
“MSC”=“c:\program files\Microsoft Security Client\msseces.exe”
“SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe”
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
.
“CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE”
“DWQueuedReporting”=“c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe”
.
@=“Service”
.
@=“Driver”
.
2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
2009-04-24 03:21 203928 -c–a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
.
2009-11-01 17:30 2508104 -c–a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
2009-09-03 16:43 767312 -c–a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
2008-02-25 11:29 1626112 ——w- c:\windows\system32\nwiz.exe
.
“%windir%\\system32\\sessmgr.exe”=
“%windir%\\Network Diagnostic\\xpnetdiag.exe”=
“e:\\Microsoft Office\\Office12\\OUTLOOK.EXE”=
“c:\\Program Files\\Bonjour\\mDNSResponder.exe”=
“c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe”=
“c:\\Program Files\\utorrent\\uTorrent.exe”=
“c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=
“c:\\Documents and Settings\\suzanneenchris\\Application Data\\Spotify\\spotify.exe”=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys
S1 lcxdpazj;lcxdpazj;\??\c:\windows\system32\drivers\lcxdpazj.sys –> c:\windows\system32\drivers\lcxdpazj.sys
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\program files\VMLaunch\BuddyVM.sys –> c:\program files\VMLaunch\BuddyVM.sys
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys
S3 e.dentifier2;SmartCard Reader ABN AMRO e.dentifier2;c:\windows\system32\drivers\aabed2.sys
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys
.
Inhoud van de ‘Gedeelde Taken’ map
.
2012-09-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
.
2012-09-08 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe
.
2012-09-16 c:\windows\Tasks\User_Feed_Synchronization-{33FC4C53-B05F-4A01-BB75-92ECC69D5A92}.job
- c:\windows\system32\msfeedssync.exe
.
2012-09-16 c:\windows\Tasks\User_Feed_Synchronization-{BA22967F-1414-42CD-B789-3DDD77ACE2E3}.job
- c:\windows\system32\msfeedssync.exe
.
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.google.nl/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 192.168.2.254
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS VERWIJDERD - - - -
.
Toolbar-Locked - (no file)
MSConfigStartUp-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
MSConfigStartUp-iTunesHelper - e:\i\iTunesHelper.exe
MSConfigStartUp-Sony Ericsson PC Companion - c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
MSConfigStartUp-Sony PC Companion - c:\program files\Sony\Sony PC Companion\PCCompanion.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-16 14:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen …
.
scannen van verborgen autostart items …
.
scannen van verborgen bestanden …
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=“@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101”
.
“Enabled”=dword:00000001
.
@=“c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
@Denied: (A 2) (Everyone)
@=“IFlashBroker5”
.
@=“{00020424-0000-0000-C000-000000000046}”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
Voltooingstijd: 2012-09-16 14:09:36
ComboFix-quarantined-files.txt 2012-09-16 12:09
.
Pre-Run: 25.990.045.696 bytes beschikbaar
Post-Run: 25.992.658.944 bytes beschikbaar
.
WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
UnsupportedDebug=“do not select this” /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=“Microsoft Windows XP Home Edition” /fastdetect /NoExecute=OptIn
.
- - End Of File - - C508BB9F06DB9B8BDB8085E4D7A1978F