ComboFix 12-12-17.02 - Marije 17-12-2012 22:15:10.1.1 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.1979.676
Gestart vanuit: c:\users\Marije\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Marije\HijackThis.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-11-17 to 2012-12-17 ))))))))))))))))))))))))))))))
.
.
2012-12-17 21:27 . 2012-12-17 21:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-12-17 18:01 . 2012-12-17 18:01 ——– d—–w- c:\users\Marije\AppData\Local\Diagnostics
2012-12-17 15:07 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DC0B835C-E2A2-45E4-A9A0-D240E4DDE6DD}\mpengine.dll
2012-12-17 11:41 . 2012-12-17 11:41 ——– d—–w- c:\users\Marije\AppData\Local\Macromedia
2012-12-17 11:40 . 2012-12-17 11:40 ——– d—–w- c:\users\Marije\AppData\Local\Mozilla
2012-12-17 11:40 . 2012-12-17 11:40 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service
2012-12-16 20:28 . 2010-01-10 17:40 118784 —-a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2012-12-16 20:28 . 2010-01-10 17:40 1071088 —-a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-12-16 20:27 . 2012-12-17 17:32 ——– d—–w- c:\program files (x86)\SpywareBlaster
2012-12-16 20:05 . 2012-10-30 22:51 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-16 20:05 . 2012-10-30 22:51 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-16 20:05 . 2012-10-15 16:59 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-16 20:05 . 2012-10-30 22:51 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-16 20:05 . 2012-10-30 22:51 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-16 20:05 . 2012-10-30 22:51 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-16 20:04 . 2012-10-30 22:51 41224 —-a-w- c:\windows\avastSS.scr
2012-12-16 20:03 . 2012-10-30 22:50 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-16 19:46 . 2012-10-30 22:50 285328 —-a-w- c:\windows\system32\aswBoot.exe
2012-12-16 19:44 . 2012-12-16 20:03 ——– d—–w- c:\programdata\AVAST Software
2012-12-16 19:44 . 2012-12-16 20:03 ——– d—–w- c:\program files\AVAST Software
2012-12-16 19:27 . 2012-06-05 07:37 256904 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys
2012-12-16 18:59 . 2012-12-17 10:08 ——– d—–w- c:\program files\CCleaner
2012-12-16 18:36 . 2012-12-16 18:36 ——– d—–w- c:\program files (x86)\Common Files\Java
2012-12-16 18:36 . 2012-12-16 18:35 95184 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-12-16 18:35 . 2012-12-16 18:35 ——– d—–w- c:\program files (x86)\Java
2012-12-16 11:31 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-12-14 14:44 . 2012-12-14 14:47 ——– d—–w- c:\windows\system32\MpEngineStore
2012-12-13 10:50 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2012-12-13 10:50 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-12-13 10:50 . 2012-11-22 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys
2012-12-13 10:50 . 2012-11-05 21:35 46080 —-a-w- c:\windows\system32\atmlib.dll
2012-12-13 10:50 . 2012-11-05 20:41 367616 —-a-w- c:\windows\system32\atmfd.dll
2012-12-13 10:50 . 2012-11-05 20:32 295424 —-a-w- c:\windows\SysWow64\atmfd.dll
2012-12-13 10:50 . 2012-11-05 20:32 34304 —-a-w- c:\windows\SysWow64\atmlib.dll
2012-12-13 10:48 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll
2012-12-13 10:48 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll
2012-12-10 17:52 . 2012-12-10 17:52 ——– d—–w- c:\users\Marije\AppData\Local\CRE
2012-12-10 17:52 . 2012-12-10 17:52 ——– d—–w- c:\windows\SysWow64\searchplugins
2012-12-10 17:52 . 2012-12-10 17:52 ——– d—–w- c:\windows\SysWow64\Extensions
2012-12-10 17:50 . 2012-12-16 19:38 ——– d—–w- c:\program files (x86)\TornTV.com
2012-12-10 17:48 . 2012-12-16 18:49 ——– d—–w- c:\users\Marije\AppData\Roaming\uTorrent
2012-11-29 08:18 . 2012-11-29 08:16 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3E07BC78-C9C9-4294-B8EA-23A8AC369F24}\gapaengine.dll
2012-11-25 15:29 . 2012-11-25 15:29 ——– d—–w- c:\program files\Microsoft Silverlight
2012-11-25 15:29 . 2012-11-25 15:29 ——– d—–w- c:\program files (x86)\Microsoft Silverlight
2012-11-24 12:46 . 2012-11-24 12:46 ——– d—–w- c:\program files (x86)\Teach2000
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-16 18:35 . 2012-10-04 20:53 859072 —-a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-12-16 18:35 . 2012-10-04 20:53 779704 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-12-14 14:42 . 2012-10-05 08:08 67413224 —-a-w- c:\windows\system32\MRT.exe
2012-12-14 14:20 . 2012-10-05 11:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-14 14:20 . 2012-10-05 11:34 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-17 03:31 . 2012-11-08 11:14 741480 ——w- c:\windows\system32\HPDiscoPMa011.dll
2012-10-16 08:38 . 2012-11-29 08:09 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-29 08:09 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-29 08:09 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 18:17 . 2012-11-16 14:35 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-16 14:35 226816 —-a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-16 14:35 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-16 14:35 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-06 09:43 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll
2012-10-06 09:43 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll
2012-10-05 10:38 . 2012-10-05 10:38 560184 —-a-w- c:\windows\system32\drivers\sptd.sys
2012-10-05 08:45 . 2010-06-24 09:33 19720 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-10-04 19:02 . 2012-10-04 19:02 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-10-04 19:02 . 2012-10-04 19:02 161792 —-a-w- c:\windows\SysWow64\msls31.dll
2012-10-04 19:02 . 2012-10-04 19:02 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-10-04 19:02 . 2012-10-04 19:02 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll
2012-10-04 19:02 . 2012-10-04 19:02 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-10-04 19:02 . 2012-10-04 19:02 74752 —-a-w- c:\windows\SysWow64\iesetup.dll
2012-10-04 19:02 . 2012-10-04 19:02 63488 —-a-w- c:\windows\SysWow64\tdc.ocx
2012-10-04 19:02 . 2012-10-04 19:02 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll
2012-10-04 19:02 . 2012-10-04 19:02 367104 —-a-w- c:\windows\SysWow64\html.iec
2012-10-04 19:02 . 2012-10-04 19:02 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll
2012-10-04 19:02 . 2012-10-04 19:02 35840 —-a-w- c:\windows\SysWow64\imgutil.dll
2012-10-04 19:02 . 2012-10-04 19:02 152064 —-a-w- c:\windows\SysWow64\wextract.exe
2012-10-04 19:02 . 2012-10-04 19:02 150528 —-a-w- c:\windows\SysWow64\iexpress.exe
2012-10-04 19:02 . 2012-10-04 19:02 11776 —-a-w- c:\windows\SysWow64\mshta.exe
2012-10-04 19:02 . 2012-10-04 19:02 101888 —-a-w- c:\windows\SysWow64\admparse.dll
2012-10-04 19:02 . 2012-10-04 19:02 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-10-04 19:02 . 2012-10-04 19:02 65024 —-a-w- c:\windows\system32\pngfilt.dll
2012-10-04 19:02 . 2012-10-04 19:02 49664 —-a-w- c:\windows\system32\imgutil.dll
2012-10-04 19:02 . 2012-10-04 19:02 267776 —-a-w- c:\windows\system32\ieaksie.dll
2012-10-04 19:02 . 2012-10-04 19:02 222208 —-a-w- c:\windows\system32\msls31.dll
2012-10-04 19:02 . 2012-10-04 19:02 197120 —-a-w- c:\windows\system32\msrating.dll
2012-10-04 19:02 . 2012-10-04 19:02 163840 —-a-w- c:\windows\system32\ieakui.dll
2012-10-04 19:02 . 2012-10-04 19:02 149504 —-a-w- c:\windows\system32\occache.dll
2012-10-04 19:02 . 2012-10-04 19:02 12288 —-a-w- c:\windows\system32\mshta.exe
2012-10-04 19:02 . 2012-10-04 19:02 114176 —-a-w- c:\windows\system32\admparse.dll
2012-10-04 19:02 . 2012-10-04 19:02 145920 —-a-w- c:\windows\system32\iepeers.dll
2012-10-04 19:02 . 2012-10-04 19:02 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-10-04 19:02 . 2012-10-04 19:02 89088 —-a-w- c:\windows\system32\ie4uinit.exe
2012-10-04 19:02 . 2012-10-04 19:02 85504 —-a-w- c:\windows\system32\iesetup.dll
2012-10-04 19:02 . 2012-10-04 19:02 82432 —-a-w- c:\windows\system32\icardie.dll
2012-10-04 19:02 . 2012-10-04 19:02 76800 —-a-w- c:\windows\system32\tdc.ocx
2012-10-04 19:02 . 2012-10-04 19:02 55296 —-a-w- c:\windows\system32\msfeedsbs.dll
2012-10-04 19:02 . 2012-10-04 19:02 534528 —-a-w- c:\windows\system32\ieapfltr.dll
2012-10-04 19:02 . 2012-10-04 19:02 48640 —-a-w- c:\windows\system32\mshtmler.dll
2012-10-04 19:02 . 2012-10-04 19:02 452608 —-a-w- c:\windows\system32\dxtmsft.dll
2012-10-04 19:02 . 2012-10-04 19:02 448512 —-a-w- c:\windows\system32\html.iec
2012-10-04 19:02 . 2012-10-04 19:02 403248 —-a-w- c:\windows\system32\iedkcs32.dll
2012-10-04 19:02 . 2012-10-04 19:02 39936 —-a-w- c:\windows\system32\iernonce.dll
2012-10-04 19:02 . 2012-10-04 19:02 3695416 —-a-w- c:\windows\system32\ieapfltr.dat
2012-10-04 19:02 . 2012-10-04 19:02 282112 —-a-w- c:\windows\system32\dxtrans.dll
2012-10-04 19:02 . 2012-10-04 19:02 160256 —-a-w- c:\windows\system32\ieakeng.dll
2012-10-04 19:02 . 2012-10-04 19:02 135168 —-a-w- c:\windows\system32\IEAdvpack.dll
2012-10-04 19:02 . 2012-10-04 19:02 111616 —-a-w- c:\windows\system32\iesysprep.dll
2012-10-04 19:02 . 2012-10-04 19:02 10752 —-a-w- c:\windows\system32\msfeedssync.exe
2012-10-04 19:02 . 2012-10-04 19:02 30720 —-a-w- c:\windows\system32\licmgr10.dll
2012-10-04 19:02 . 2012-10-04 19:02 249344 —-a-w- c:\windows\system32\webcheck.dll
2012-10-04 19:02 . 2012-10-04 19:02 165888 —-a-w- c:\windows\system32\iexpress.exe
2012-10-04 19:02 . 2012-10-04 19:02 160256 —-a-w- c:\windows\system32\wextract.exe
2012-10-04 19:02 . 2012-10-04 19:02 103936 —-a-w- c:\windows\system32\inseng.dll
2012-10-04 18:10 . 2010-07-08 05:14 29480 —-a-w- c:\windows\SysWow64\msxml3a.dll
2012-10-04 18:10 . 2009-07-21 11:22 505128 —-a-w- c:\windows\SysWow64\msvcp71.dll
2012-10-04 18:10 . 2009-07-21 11:22 353576 —-a-w- c:\windows\SysWow64\msvcr71.dll
2012-10-04 16:40 . 2012-12-13 10:49 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2012-10-04 15:29 . 2010-03-27 17:32 588472 —-a-w- c:\windows\SysWow64\ezsvc7x.dll
2012-10-03 17:56 . 2012-11-16 14:35 1914248 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-10-03 17:44 . 2012-11-16 14:35 303104 —-a-w- c:\windows\system32\nlasvc.dll
2012-10-03 17:44 . 2012-11-16 14:35 70656 —-a-w- c:\windows\system32\nlaapi.dll
2012-10-03 17:44 . 2012-11-16 14:35 246272 —-a-w- c:\windows\system32\netcorehc.dll
2012-10-03 17:44 . 2012-11-16 14:35 18944 —-a-w- c:\windows\system32\netevent.dll
2012-10-03 17:44 . 2012-11-16 14:35 216576 —-a-w- c:\windows\system32\ncsi.dll
2012-10-03 17:42 . 2012-11-16 14:35 569344 —-a-w- c:\windows\system32\iphlpsvc.dll
2012-10-03 16:42 . 2012-11-16 14:35 175104 —-a-w- c:\windows\SysWow64\netcorehc.dll
2012-10-03 16:42 . 2012-11-16 14:35 18944 —-a-w- c:\windows\SysWow64\netevent.dll
2012-10-03 16:42 . 2012-11-16 14:35 156672 —-a-w- c:\windows\SysWow64\ncsi.dll
2012-10-03 16:07 . 2012-11-16 14:35 45568 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-09-29 18:54 . 2012-10-04 20:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-25 22:47 . 2012-11-16 14:35 78336 —-a-w- c:\windows\SysWow64\synceng.dll
2012-09-25 22:46 . 2012-11-16 14:35 95744 —-a-w- c:\windows\system32\synceng.dll
2012-09-20 18:00 . 2012-10-04 18:19 127488 —-a-w- c:\windows\system32\ff_vfw.dll
2012-09-18 22:58 . 2012-10-04 15:46 9308616 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{568F8B50-BAFC-4492-8B4D-2EF5E309D195}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
“WirelessAssistant”=“c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe”
“SwitchBoard”=“c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe”
“AdobeCS6ServiceManager”=“c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe”
“RemoteControl9”=“c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe”
“PDVD9LanguageShortcut”=“c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe”
“BDRegion”=“c:\program files (x86)\Cyberlink\Shared files\brs.exe”
“IAStorIcon”=“c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe”
“Adobe ARM”=“c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
“HP Software Update”=“c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe”
“SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe”
“avast”=“c:\program files\AVAST Software\Avast\avastUI.exe”
.
“ConsentPromptBehaviorAdmin”= 5 (0x5)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
.
“LoadAppInit_DLLs”=1 (0x1)
.
“aux1”=wdmaud.drv
.
@=“Service”
.
“SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe”
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys
S1 aswSnx;aswSnx;
S1 aswSP;aswSP;
S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control ;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\000.fcl
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe
S2 aswFsBlk;aswFsBlk;
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe
S2 HPWMISVC;HPWMISVC;c:\program files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technologie;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys
.
.
— Andere Services/Drivers In Geheugen —
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
2010-02-22 09:38 451872 —-a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhoud van de ‘Gedeelde Taken’ map
.
2012-12-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
.
2012-12-14 c:\windows\Tasks\HPCeeScheduleForMarije.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
.
.
——— X64 Entries ———–
.
.
@=“{472083B0-C522-11CF-8763-00608CC02F24}”
2012-10-30 22:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
“RTHDVCPL”=“c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe”
“RtkOSD”=“c:\program files (x86)\Realtek\Audio\OSD\RtVOsd64.exe”
“HP Quick Launch”=“c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe”
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”
“MSC”=“c:\program files\Microsoft Security Client\msseces.exe”
“AdobeAAMUpdater-1.0”=“c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe”
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe”
“IgfxTray”=“c:\windows\system32\igfxtray.exe”
“HotKeysCmds”=“c:\windows\system32\hkcmd.exe”
“Persistence”=“c:\windows\system32\igfxpers.exe”
.
——- Bijkomende Scan ——-
.
uStart Page = hxxp://www.nu.nl/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Verzenden naar OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\Marije\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
TCP: DhcpNameServer = 212.54.35.25 212.54.40.25
FF - ProfilePath - c:\users\Marije\AppData\Roaming\Mozilla\Firefox\Profiles\nh0fvlhj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.nu.nl/
FF - ExtSQL: 2012-12-16 21:12; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - ORPHANS VERWIJDERD - - - -
.
Wow6432Node-HKLM-Run- - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
“ImagePath”=“\??\c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\000.fcl”
.
——————— VERGRENDELDE REGISTER SLEUTELS ———————
.
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=“@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101”
.
“Enabled”=dword:00000001
.
@=“c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
@Denied: (A 2) (Everyone)
@=“IFlashBroker5”
.
@=“{00020424-0000-0000-C000-000000000046}”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=“@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101”
.
“Enabled”=dword:00000001
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx”
“ThreadingModel”=“Apartment”
.
@=“0”
.
@=“ShockwaveFlash.ShockwaveFlash.11”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“ShockwaveFlash.ShockwaveFlash”
.
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx”
“ThreadingModel”=“Apartment”
.
@=“FlashFactory.FlashFactory.1”
.
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1”
.
@=“{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
@=“1.0”
.
@=“FlashFactory.FlashFactory”
.
@Denied: (A 2) (Everyone)
@=“IFlashBroker5”
.
@=“{00020424-0000-0000-C000-000000000046}”
.
@=“{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
@Denied: (Full) (Everyone)
.
———————— Andere Aktieve Processen ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
.
**************************************************************************
.
Voltooingstijd: 2012-12-17 22:37:20 - machine werd herstart
ComboFix-quarantined-files.txt 2012-12-17 21:37
.
Pre-Run: 32.461.582.336 bytes beschikbaar
Post-Run: 32.435.527.680 bytes beschikbaar
.
- - End Of File - - 104795AAA5F35180378C83CB6049801A