Ik kan je melden dat m'n PC merkelijk vlugger opstart (in ongev. 2.30 min. en ook vlugger alslaat bij het stoppen).
Hier de log van Combofix
ComboFix 09-04-22.A0 - Eigenaar 22/04/2009 10:45.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.32.1043.18.1023.309 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Eigenaar\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: c:\documents and settings\Eigenaar\Bureaublad\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Nieuw herstelpunt werd aangemaakt
FILE ::
c:\windows\system32\tmp4D68D.FOT
c:\windows\system32\tmp5148D.FOT
c:\windows\system32\tmp9F58D.FOT
c:\windows\system32\tmpAD58D.FOT
c:\windows\system32\tmpBA58D.FOT
c:\windows\system32\tmpD558D.FOT
c:\windows\system32\tmpFF48D.FOT
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Hitman Pro
c:\program files\Hitman Pro\blank.ini
c:\program files\Hitman Pro\Controls.ini
c:\program files\Hitman Pro\epcompilersigs.dat
c:\program files\Hitman Pro\eppackersigs.dat
c:\program files\Hitman Pro\hitmanpro2.sys
c:\program files\Hitman Pro\Language.ini
c:\program files\Hitman Pro\logs\buynow.gif
c:\program files\Hitman Pro\logs\Hitman_Pro_2005-05-29_16-58-26.htm
c:\program files\Hitman Pro\logs\Hitman_Pro_2005-05-29_17-00-40.htm
c:\program files\Hitman Pro\logs\Hitman_Pro_2008-04-14_00-31-27.htm
c:\program files\Hitman Pro\logs\Hitman_Pro_2008-04-14_00-36-19.htm
c:\program files\Hitman Pro\logs\Hitman_Pro_2008-04-14_09-57-40.htm
c:\program files\Hitman Pro\logs\hitmanpro.jpg
c:\program files\Hitman Pro\MRCAgent.exe
c:\program files\Hitman Pro\roamingsigs
c:\program files\Hitman Pro\sigcheck.exe
c:\program files\Hitman Pro\StriderCache.ini
c:\windows\system32\tmp4D68D.FOT
c:\windows\system32\tmp5148D.FOT
c:\windows\system32\tmp9F58D.FOT
c:\windows\system32\tmpAD58D.FOT
c:\windows\system32\tmpBA58D.FOT
c:\windows\system32\tmpD558D.FOT
c:\windows\system32\tmpFF48D.FOT
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CTREDRV.SYS
-------\Service_ctredrv.sys
(((((((((((((((((((( Bestanden Gemaakt van 2009-03-22 to 2009-04-22 ))))))))))))))))))))))))))))))
.
2009-04-19 16:05 . 2009-04-19 16:05 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Malwarebytes
2009-04-19 16:05 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-19 16:05 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-19 16:05 . 2009-04-21 13:37 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-19 16:05 . 2009-04-19 16:05 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-18 22:08 . 2009-04-18 22:08 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Audio Editor Deluxe
2009-04-18 22:07 . 2006-03-23 10:56 113486 ----a-w c:\windows\system32\NCTWMAProfiles.prx
2009-04-18 22:07 . 2005-05-18 09:52 1212416 ----a-w c:\windows\system32\NCTAudioInformation2.dll
2009-04-18 22:07 . 2005-05-17 10:37 1986560 ----a-w c:\windows\system32\NCTAudioFile2.dll
2009-04-18 22:07 . 2005-04-25 11:01 458752 ----a-w c:\windows\system32\NCTAudioRecord2.dll
2009-04-18 22:07 . 2005-04-25 11:01 458752 ----a-w c:\windows\system32\NCTAudioPlayer2.dll
2009-04-18 22:07 . 2005-04-15 10:08 880640 ----a-w c:\windows\system32\NCTAudioEditor2.dll
2009-04-18 22:07 . 2005-04-04 15:21 602112 ----a-w c:\windows\system32\NCTAudioTransform2.dll
2009-04-18 22:07 . 2005-03-29 05:57 2084864 ----a-w c:\windows\system32\NCTAudioDesign2.dll
2009-04-18 22:07 . 2005-03-28 13:56 417792 ----a-w c:\windows\system32\NCTAudioDisplay2.dll
2009-04-18 22:07 . 2005-03-28 13:54 479232 ----a-w c:\windows\system32\NCTAudioVisualization2.dll
2009-04-18 22:07 . 2005-02-24 09:51 348160 ----a-w c:\windows\system32\NCTWMAFile2.dll
2009-04-18 22:07 . 2004-11-04 11:31 835584 ----a-w c:\windows\system32\NCTAudioCDGrabber2.dll
2009-04-18 20:07 . 2009-04-18 20:07 -------- d-----w c:\program files\Trend Micro
2009-04-18 16:23 . 2009-04-18 16:23 67 ----a-w c:\windows\wininit.ini
2009-04-16 20:47 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 20:47 . 2009-03-06 14:23 285696 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 20:47 . 2009-02-09 11:27 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 20:47 . 2009-02-09 10:56 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 20:47 . 2009-02-09 10:56 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 20:47 . 2009-02-09 10:56 684544 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 20:47 . 2009-02-09 10:56 734208 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 20:47 . 2009-02-09 10:56 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 20:47 . 2009-02-09 10:56 735744 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 20:46 . 2009-03-27 06:59 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 20:46 . 2008-04-21 21:16 218624 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 21:09 . 2009-02-23 15:15 85281 ------w c:\windows\hpgins01.dat.temp
2009-04-14 21:09 . 2004-05-13 20:33 145 ------w c:\windows\hpgmdl01.dat.temp
2009-04-12 12:37 . 2009-04-12 12:37 -------- d-----w c:\documents and settings\All Users\Application Data\TERMINAL Studio
2009-04-08 17:00 . 2008-12-13 12:47 40496 ----a-w c:\windows\system32\drivers\hotcore3.sys
2009-04-08 16:57 . 2009-04-08 16:57 -------- d-----w c:\program files\Paragon Software
2009-04-07 22:08 . 2009-04-07 22:08 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Talkback
2009-04-05 16:45 . 2009-04-05 16:45 -------- d-----w c:\documents and settings\Eigenaar\Application Data\TERMINAL Studio
2009-04-05 16:43 . 2007-11-06 15:46 106496 ----a-w c:\windows\system32\Astro Gemini Screensaver Manager.scr
2009-04-05 16:43 . 2009-04-05 16:43 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Astro Gemini Software
2009-04-05 16:43 . 2009-04-05 16:43 -------- d-----w c:\program files\Astro Gemini Software
2009-04-05 16:43 . 2008-08-21 10:30 12636160 ----a-w c:\windows\system32\Dinosaurs 3D Screensaver.scr
2009-04-04 12:48 . 2009-04-04 12:56 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Jetbricks
2009-04-01 14:58 . 2009-04-01 14:58 -------- d-----w c:\documents and settings\Eigenaar\Local Settings\Application Data\FileMaker
2009-03-31 16:40 . 2009-03-31 16:40 -------- d-----w c:\documents and settings\All Users\Application Data\PCPitstop
2009-03-28 11:20 . 2009-03-28 11:20 -------- d-----w c:\documents and settings\All Users\Application Data\Gameeel
2009-03-23 15:15 . 2009-03-23 15:15 23 ----a-w c:\windows\SWFDecompiler.INI
2009-03-23 15:13 . 2009-03-27 22:53 -------- d-----w c:\program files\Common Files\SourceTec
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 08:54 . 2008-07-28 10:30 -------- d-----w c:\program files\SPAMfighter
2009-04-22 08:53 . 2005-04-29 17:48 -------- d-----w c:\program files\Mozilla Sunbird
2009-04-22 08:52 . 2009-01-23 19:48 132269 ----a-w C:\aaw7boot.log
2009-04-21 16:53 . 2009-04-21 16:53 26476 ----a-w C:\log21-04-09.txt
2009-04-21 16:36 . 2009-04-21 16:36 26476 ----a-w C:\log.txt
2009-04-21 15:18 . 2007-05-29 10:52 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-19 13:44 . 2009-03-16 11:58 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-17 22:31 . 2008-04-13 21:59 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-17 06:28 . 2004-08-04 12:00 580636 ----a-w c:\windows\system32\perfh013.dat
2009-04-17 06:28 . 2004-08-04 12:00 117582 ----a-w c:\windows\system32\perfc013.dat
2009-04-10 18:43 . 2008-05-26 17:40 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-05 20:36 . 2009-03-15 11:34 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Gold Casual Games
2009-04-05 20:36 . 2009-03-15 11:34 -------- d-----w c:\documents and settings\All Users\Application Data\Gold Casual Games
2009-04-01 16:48 . 2009-01-28 20:36 -------- d-----w c:\program files\DivX
2009-04-01 16:48 . 2009-01-03 13:56 -------- d-----w c:\program files\TweakRAM
2009-04-01 16:48 . 2008-11-25 21:56 -------- d-----w c:\program files\QuickTime
2009-04-01 16:48 . 2008-06-17 12:32 -------- d-----w c:\program files\FotoXpert
2009-04-01 16:48 . 2008-03-03 18:22 -------- d-----w c:\program files\Windows Live Toolbar
2009-04-01 16:48 . 2008-10-05 09:38 -------- d-----w c:\documents and settings\Eigenaar\Application Data\SpinTop
2009-03-31 14:00 . 2008-12-28 17:31 -------- d-----w c:\program files\WinUtilities
2009-03-31 13:15 . 2009-03-20 20:36 -------- d-----w c:\program files\Flexbyte Software
2009-03-31 09:55 . 2009-03-14 15:49 -------- d-----w c:\program files\JLC's Software
2009-03-28 07:12 . 2008-11-25 21:58 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Apple Computer
2009-03-24 14:16 . 2009-03-20 20:37 -------- d-----w c:\documents and settings\Eigenaar\Application Data\NetStat Agent
2009-03-24 14:15 . 2008-11-25 21:57 -------- d-----w c:\program files\Bonjour
2009-03-24 08:23 . 2005-04-02 07:13 -------- d-----w c:\program files\Google
2009-03-24 07:45 . 2009-01-15 21:12 -------- d-----w c:\documents and settings\All Users\Application Data\History Explorer
2009-03-20 14:28 . 2005-03-29 13:23 282440 ----a-w c:\documents and settings\Eigenaar\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-20 14:15 . 2009-03-20 14:15 -------- d-----w c:\program files\JRE
2009-03-20 14:15 . 2009-03-20 14:15 -------- d-----w c:\program files\OpenOffice.org 3
2009-03-19 09:06 . 2005-03-31 11:06 -------- d-----w c:\program files\Topcom
2009-03-18 23:48 . 2009-03-18 23:48 -------- d-----w c:\program files\Common Files\Bcgsoft
2009-03-18 00:17 . 2007-04-22 06:06 -------- d-----w c:\program files\Microsoft SQL Server
2009-03-17 22:41 . 2009-03-17 22:41 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Windows Search
2009-03-17 22:41 . 2009-03-17 22:41 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Windows Desktop Search
2009-03-17 22:40 . 2009-03-17 22:40 -------- d-----w c:\program files\Windows Desktop Search
2009-03-17 22:20 . 2009-03-17 22:20 -------- d-----w c:\program files\Microsoft Works
2009-03-17 22:19 . 2007-02-05 10:01 -------- d-----w c:\program files\Microsoft.NET
2009-03-17 21:53 . 2009-02-05 16:56 -------- d-----w c:\program files\MSBuild
2009-03-17 16:26 . 2008-12-26 14:00 -------- d-----w c:\program files\Premium Booster
2009-03-16 11:27 . 2007-04-22 06:13 -------- d-----w c:\program files\Microsoft Small Business
2009-03-14 15:49 . 2009-03-14 15:49 -------- d-----w c:\documents and settings\Eigenaar\Application Data\JLC's Software
2009-03-14 08:31 . 2009-03-14 08:31 -------- d-----w c:\program files\SystemRequirementsLab
2009-03-14 08:31 . 2009-03-14 08:31 -------- d-----w c:\documents and settings\Eigenaar\Application Data\SystemRequirementsLab
2009-03-12 16:46 . 2008-04-14 10:56 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-11 16:28 . 2005-03-29 13:11 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-11 16:22 . 2005-04-06 12:19 -------- d-----w c:\program files\Pinnacle
2009-03-11 16:07 . 2009-03-08 17:16 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Vso
2009-03-09 16:12 . 2009-03-09 10:37 -------- d-----w c:\documents and settings\Eigenaar\Application Data\AVGTOOLBAR
2009-03-09 10:38 . 2008-05-26 17:40 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-09 10:37 . 2008-05-26 17:40 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-03-09 10:37 . 2008-05-26 17:39 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-03-08 17:16 . 2009-03-08 17:16 81920 ----a-w c:\documents and settings\Eigenaar\Application Data\ezpinst.exe
2009-03-08 17:16 . 2009-03-08 17:16 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-08 17:16 . 2009-03-08 17:16 47360 ----a-w c:\documents and settings\Eigenaar\Application Data\pcouffin.sys
2009-03-07 23:20 . 2009-03-07 23:20 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Gamelab
2009-03-06 17:27 . 2009-01-23 17:48 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-03-06 17:27 . 2009-01-23 17:27 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-03-06 14:23 . 2004-08-04 12:00 285696 ----a-w c:\windows\system32\pdh.dll
2009-03-04 17:35 . 2008-11-25 20:51 -------- d-----w c:\program files\MultiStage Recovery
2009-03-03 00:16 . 2004-08-04 12:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 22:44 . 2009-03-02 22:44 -------- d-----w c:\program files\Quicksys
2009-03-01 10:05 . 2009-03-01 10:01 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Archibald's Adventures
2009-03-01 07:19 . 2008-11-19 00:01 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-27 22:37 . 2009-02-27 22:37 -------- d-----w c:\documents and settings\All Users\Application Data\Quicksys
2009-02-27 21:21 . 2009-02-27 21:21 -------- d-----w c:\documents and settings\Eigenaar\Application Data\OpenOffice.org
2009-02-27 21:17 . 2009-02-26 12:11 -------- d-----w c:\program files\OpenOffice.org 2.4
2009-02-27 21:04 . 2008-08-07 19:39 -------- d-----w c:\documents and settings\Eigenaar\Application Data\OpenOffice.org2
2009-02-27 20:24 . 2009-02-27 17:29 -------- d-----w c:\documents and settings\Eigenaar\Application Data\RegTool
2009-02-26 12:03 . 2009-02-26 12:03 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-26 12:03 . 2006-10-29 03:14 -------- d-----w c:\program files\Java
2009-02-23 15:15 . 2005-04-04 12:27 85281 ------w c:\windows\hpgins01.dat
2009-02-23 15:14 . 2009-02-23 15:14 -------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-02-23 15:14 . 2005-04-04 12:28 -------- d-----w c:\program files\HP
2009-02-23 15:06 . 2005-03-31 20:50 -------- d-----w c:\program files\Hewlett-Packard
2009-02-23 14:25 . 2005-04-04 12:32 -------- d-----w c:\program files\Readiris Pro 9
2009-02-21 14:14 . 2009-02-21 14:14 -------- d-----w c:\documents and settings\Eigenaar\Application Data\Sytexis Software
2009-02-20 17:18 . 2004-08-04 12:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:08 . 2004-08-04 12:00 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:27 . 2004-08-04 00:58 2028544 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:27 . 2004-08-04 12:00 2149888 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:27 . 2004-08-04 12:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:56 . 2004-08-04 12:00 734208 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:56 . 2004-08-04 12:00 684544 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:56 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:56 . 2004-08-04 12:00 735744 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-05 16:57 . 2009-02-05 16:57 432008 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll
2008-05-04 20:29 . 2008-05-04 20:29 9 ----a-w c:\documents and settings\Eigenaar\Application Data\mdb.bin
2008-04-03 18:09 . 2008-03-14 08:21 105272 ----a-w c:\documents and settings\Gast\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-11-03 16:51 . 2007-10-29 21:54 1452 ----a-w c:\documents and settings\Eigenaar\Emails.dat
2007-10-29 21:54 . 2007-10-29 21:54 10 ----a-w c:\documents and settings\Eigenaar\user.dat
2007-02-01 18:28 . 2005-04-23 16:08 56824 ----a-w c:\documents and settings\Eigenaar\Application Data\GDIPFONTCACHEV1.DAT
2005-03-31 18:05 . 2005-03-31 18:05 131 ----a-w c:\documents and settings\Eigenaar\Local Settings\Application Data\fusioncache.dat
2008-08-30 08:56 . 2008-08-30 08:56 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012008083020080831\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-21_15.28.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-22 08:53 . 2009-04-22 08:53 16384 c:\windows\Temp\usgthrsvc\Perflib_Perfdata_bf4.dat
+ 2009-04-22 08:29 . 2009-04-22 08:29 16384 c:\windows\Temp\Perflib_Perfdata_64c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TweakRAM"="c:\program files\TweakRAM\TweakRAM.exe" [2008-12-20 1189888]
"Wireless LAN Card Utilities"="c:\program files\ASUS\WLAN Card Utilities\Center.exe" [2006-09-18 1696768]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-29 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"QuickTime Task"="c:\program files\QUICKTIME\QTTask.exe" [2008-11-04 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-09 1932568]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-01-03 1385472]
c:\documents and settings\Eigenaar\Menu Start\Programma's\Opstarten\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
sunbird.exe.lnk - c:\program files\Mozilla Sunbird\sunbird.exe [2005-4-29 6354540]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-09 10:37 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Eigenaar^Menu Start^Programma's^Opstarten^Adobe Media Player.lnk]
backup=c:\windows\pss\Adobe Media Player.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"CloneCDTray"="c:\program files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" -hide
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"snpstd3"=c:\windows\vsnpstd3.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QUICKTIME\QTTASK.EXE" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R3 DCamUSBSTK017;STK017 Camera;c:\windows\system32\DRIVERS\STK017W2.sys [2003-11-17 99476]
R3 hitmanpro2;Hitman Pro 2 Driver; [x]
R3 USRPCI;USRobotics Wireless PCI Adapter Service; [x]
R3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.SYS [2004-04-21 16384]
S0 hotcore3;Hotcore helper;c:\windows\system32\DRIVERS\hotcore3.sys [2008-12-13 40496]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\DRIVERS\iteraid.sys [2004-06-01 24971]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-06 64160]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-09 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-10 108552]
S1 DCxxMJPG;Pinnacle DC10plus, Motion-JPEG VideoIO Board;c:\windows\system32\drivers\DCxxMJPG.sys [2002-06-04 132940]
S1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys [2008-12-26 95592]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-09 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-09 298264]
S2 History Explorer Service;History Explorer Service;h:\giveawayoftheday\History Explorer\HistoryExplorer.Service.exe [2009-01-06 51200]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
S2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\SPAMfighter\sfus.exe [2008-07-14 184968]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\system32\ASNDIS5.SYS [2002-09-09 16269]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
.
Inhoud van de 'Gedeelde Taken' map
2009-04-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:27]
2009-04-22 c:\windows\Tasks\Controleren op updates voor Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2009-04-22 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-07-19 16:02]
2009-04-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-29 13:38]
2009-04-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 16:20]
2009-03-15 c:\windows\Tasks\Wise Disk Cleaner 4.job
- h:\giveawayoftheday\Wise Disk Cleaner\WiseDiskCleaner.exe [2009-03-15 19:12]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.hln.be/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.be/ig?sourceid=navclient&hl=nl&ie=UTF-8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
Sign In
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\lob8pztu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.rocketdivision.com/search/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=nl-be&FORM=MICJE3&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOFF12.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-22 10:54
Windows 5.1.2600 Service Pack 3 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_USERS\S-1-5-21-343818398-842925246-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"3140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3600)
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\Audiodev.dll
c:\windows\system32\WMVCore.DLL
c:\windows\system32\WMASF.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\gearsec.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Voltooingstijd: 2009-04-22 11:03 - machine werd herstart
ComboFix-quarantined-files.txt 2009-04-22 09:03
ComboFix2.txt 2009-04-21 16:28
ComboFix3.txt 2009-04-21 15:30
Pre-Run: 10.671.685.632 bytes beschikbaar
Post-Run: 10.549.395.456 bytes beschikbaar
391 --- E O F --- 2009-04-22 08:02
Nogmaals veel dank, Mikel