Goedemorgen Huib,
de scan heeft er vreselijk lang over gedaan, hierbij het combofix logje
ik ga nu proberen om een hijack logje te maken, hijack weigerde dit
dus ik ga kijken of dit me nu gaat lukken…
iig alvast bedankt en een fijne dag
gr irmz irene
ComboFix 12-10-26.05 - Anca 28-10-2012 22:40:02.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3691.2263
Gestart vanuit: c:\users\Anca\Downloads\ComboFix.exe
SP: SPYWAREfighter *Enabled/Updated* {4E92AA92-C88D-5FC6-69DE-FCC188839428}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Anca\AppData\Roaming\1FE0.exe
c:\users\Anca\AppData\Roaming\5FA2.exe
c:\users\Anca\AppData\Roaming\9629.exe
c:\users\Anca\AppData\Roaming\9648.exe
c:\users\Anca\AppData\Roaming\AA52.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-09-28 to 2012-10-28 ))))))))))))))))))))))))))))))
.
.
2012-10-28 23:04 . 2012-10-28 23:04 ——– d—–w- c:\users\Gast\AppData\Local\temp
2012-10-28 23:04 . 2012-10-28 23:04 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-10-27 14:51 . 2012-10-28 21:20 ——– d—–w- c:\program files (x86)\Emsisoft Anti-Malware
2012-10-26 10:57 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1F379AEB-4B12-4445-9ADE-C6D3695986D2}\mpengine.dll
2012-10-10 14:36 . 2012-09-14 19:19 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-10 14:36 . 2012-09-14 18:28 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-10-10 14:36 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll
2012-10-10 14:36 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll
2012-10-10 14:36 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll
2012-10-10 14:36 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll
2012-10-10 14:36 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 14:36 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-10 14:36 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-10 14:36 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-04 15:34 . 2012-10-04 15:35 ——– d—–w- c:\users\Anca\AppData\Local\Facebook
2012-09-30 21:26 . 2009-07-14 01:41 230400 —-a-w- c:\windows\system32\Spool\prtprocs\x64\hpzppw71.dll
2012-09-29 13:53 . 2012-09-29 13:53 ——– d—–w- c:\program files\CCleaner
2012-09-29 12:46 . 2012-06-05 07:37 256904 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-23 10:17 . 2012-09-27 20:29 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-10-11 17:31 . 2012-09-27 20:27 65309168 —-a-w- c:\windows\system32\MRT.exe
2012-09-29 17:54 . 2012-09-27 18:33 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-27 20:27 . 2012-09-27 20:27 95208 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-27 20:26 . 2012-05-21 07:04 821736 —-a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-27 20:26 . 2012-05-21 07:04 746984 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-02 08:46 . 2012-09-02 08:46 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2012-09-02 08:46 . 2012-09-02 08:46 856712 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-08-24 11:15 . 2012-09-25 14:55 17810944 —-a-w- c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-25 14:55 10925568 —-a-w- c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-25 14:55 2312704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-25 14:55 1346048 —-a-w- c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-25 14:55 1392128 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-25 14:55 1494528 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-25 14:55 237056 —-a-w- c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-25 14:55 85504 —-a-w- c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-25 14:55 173056 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-25 14:55 816640 —-a-w- c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-25 14:55 599040 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-25 14:55 2144768 —-a-w- c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-25 14:55 729088 —-a-w- c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-25 14:56 96768 —-a-w- c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-25 14:56 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-25 14:55 248320 —-a-w- c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-25 14:55 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-25 14:55 1129472 —-a-w- c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-25 14:55 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-25 14:55 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-25 14:55 420864 —-a-w- c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-25 14:56 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-12 17:27 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-12 17:28 950128 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-12 17:27 376688 —-a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-12 17:27 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-21 21:01 . 2012-09-27 16:02 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-08-20 17:38 . 2012-10-10 14:37 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2012-08-02 17:58 . 2012-09-12 17:28 574464 —-a-w- c:\windows\system32\d3d10level9.dll
2012-08-02 16:57 . 2012-09-12 17:28 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“Skype”=“c:\program files (x86)\Skype\Phone\Skype.exe”
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe”
“Facebook Update”=“c:\users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe”
.
“StartCCC”=“c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe”
“HPQuickWebProxy”=“c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe”
“HP Quick Launch”=“c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe”
“Adobe Reader Speed Launcher”=“c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
“Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
“Easybits Recovery”=“c:\program files (x86)\EasyBits For Kids\ezRecover.exe”
“HPOSD”=“c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe”
“SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe”
“emsisoft anti-malware”=“c:\program files (x86)\Emsisoft Anti-Malware\a2guard.exe”
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe
.
“ConsentPromptBehaviorAdmin”= 5 (0x5)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
“HideFastUserSwitching”= 0 (0x0)
.
“EnableShellExecuteHooks”= 1 (0x1)
.
.
“LoadAppInit_DLLs”=0 (0x0)
.
Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe
R3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys
R3 AVFSFilter;AVFSFilter;c:\windows\system32\DRIVERS\avfsfilter.sys
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys
S2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys
S3 btwampfl;btwampfl;c:\windows\system32\DRIVERS\btwampfl.sys
S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys
.
.
Inhoud van de ‘Gedeelde Taken’ map
.
2012-10-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-139012978-1220910512-2524659261-1001Core.job
- c:\users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
2012-10-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-139012978-1220910512-2524659261-1001UA.job
- c:\users\Anca\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
2012-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-139012978-1220910512-2524659261-1001Core.job
- c:\users\Anca\AppData\Local\Google\Update\GoogleUpdate.exe
.
2012-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-139012978-1220910512-2524659261-1001UA.job
- c:\users\Anca\AppData\Local\Google\Update\GoogleUpdate.exe
.
2012-10-24 c:\windows\Tasks\HPCeeScheduleForAnca.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
.
.
——— X64 Entries ———–
.
.
“RTHDVCPL”=“c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe”
“SetDefault”=“c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe”
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Afbeelding verzenden naar &Bluetooth-apparaat… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Pagina verzenden naar &Bluetooth-apparaat… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.2.254
FF - ProfilePath - c:\users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\
FF - ExtSQL: 2012-09-27 18:08; crossriderapp5060@crossrider.com; c:\users\Anca\AppData\Roaming\Mozilla\Firefox\Profiles\v8056ts0.default\extensions\crossriderapp5060@crossrider.com
FF - ExtSQL: 2012-10-28 15:19; {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
.
- - - - ORPHANS VERWIJDERD - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=“@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe,-101”
.
“Enabled”=dword:00000001
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx”
“ThreadingModel”=“Apartment”
.
@=“0”
.
@=“ShockwaveFlash.ShockwaveFlash.10”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“ShockwaveFlash.ShockwaveFlash”
.
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx”
“ThreadingModel”=“Apartment”
.
@=“FlashFactory.FlashFactory.1”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“FlashFactory.FlashFactory”
.
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
.
@=“{00020424-0000-0000-C000-000000000046}”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
@Denied: (Full) (Everyone)
.
Voltooingstijd: 2012-10-29 00:08:56
ComboFix-quarantined-files.txt 2012-10-28 23:08
.
Pre-Run: 436.119.924.736 bytes beschikbaar
Post-Run: 440.522.219.520 bytes beschikbaar
.
- - End Of File - - DBD2AC0C0D705DC215A7D2D554AEB9C9