timoootn
-
Items
7 -
Registratiedatum
-
Laatst bezocht
Inhoudstype
Profielen
Forums
Store
Berichten die geplaatst zijn door timoootn
-
-
ComboFix 12-03-28.01 - Timo 28/03/2012 13:01:09.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3070.1702 [GMT 2:00]
Gestart vanuit: c:\users\Timo\Downloads\ComboFix.exe
gebruikte Opdracht switches :: c:\users\Timo\Desktop\CFScript.txt
AV: BullGuard Antivirus *Disabled/Outdated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Disabled/Outdated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\chrome\bittorrentbar_nl.jar
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\ConduitAutoCompleteSearch.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\ConduitAutoCompleteSearch.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\ConduitToolbar.idl
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\ConduitToolbar.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\ConduitToolbar.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\RadioWMPCore.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\RadioWMPCore.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\components\RadioWMPCoreGecko19.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\alertSettingsComponent.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\appContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\engineContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\engineSettings.json
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\fbAlert.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\getAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\postAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\toolbarContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\defaults\unsharedAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\lib\xpcom.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\META-INF\manifest.mf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\META-INF\zigbert.rsa
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\META-INF\zigbert.sf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\searchplugin\conduit.gif
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\searchplugin\conduit.ico
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\searchplugin\conduit.PNG
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\searchplugin\conduit.src
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\searchplugin\conduit.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\setup.ini
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}\version.txt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\chrome\softonic_english.jar
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\ConduitAutoCompleteSearch.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\ConduitAutoCompleteSearch.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\ConduitToolbar.idl
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\ConduitToolbar.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\ConduitToolbar.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\FFExternalAlert.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\FFExternalAlert.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\RadioWMPCore.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components\RadioWMPCore.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\defaults\default_radio_skin.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\defaults\fbAlert.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\lib\xpcom.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\META-INF\manifest.mf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\META-INF\zigbert.rsa
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\META-INF\zigbert.sf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin\conduit.gif
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin\conduit.ico
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin\conduit.PNG
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin\conduit.src
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin\conduit.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\setup.ini
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\version.txt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome\content\dealply.xul
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome\content\images\dealplyIcon32.png
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\defaults\preferences\defaults.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome\bs_player.jar
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.idl
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\FFExternalAlert.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\FFExternalAlert.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\default_radio_skin.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\fbAlert.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\lib\xpcom.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\manifest.mf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.rsa
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.sf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.gif
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.ico
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.PNG
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.src
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\version.txt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\engineSettings.json
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\fbAlert.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\DualPackage\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\install.rdf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\lib\xpcom.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\META-INF\manifest.mf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\searchplugin\conduit.src
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\setup.ini
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\engine@conduit.com\version.txt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\chrome.manifest
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\components\FFHst.dll
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\components\FFHst.xpt
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\defaults\preferences\instlPref.js
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\facemoods.jar
c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\extensions\ffxtlbr@Facemoods.com\install.rdf
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-02-28 to 2012-03-28 ))))))))))))))))))))))))))))))
.
.
2012-03-28 11:07 . 2012-03-28 11:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-24 17:38 . 2012-03-24 17:38 -------- d-----w- c:\windows\CheckSur
2012-03-22 19:29 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-22 19:29 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-22 19:29 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-22 19:29 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-22 19:29 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-21 18:09 . 2012-03-21 18:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-03-21 18:09 . 2012-03-21 18:09 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-03-21 18:09 . 2012-03-21 18:09 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-03-21 18:09 . 2012-03-21 18:09 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-03-21 18:09 . 2012-03-21 18:09 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-03-21 18:09 . 2012-03-21 18:09 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-03-21 18:09 . 2012-03-21 18:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-03-19 18:13 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-19 18:13 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-19 18:13 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2012-03-19 18:13 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2012-03-19 18:13 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-03-19 18:13 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-03-19 18:13 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-03-19 18:13 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-03-19 18:13 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-19 18:13 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-03-19 18:13 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-03-19 18:12 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-03-19 18:12 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-03-19 18:12 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2012-03-19 18:12 . 2011-09-20 21:02 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-19 18:02 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-19 18:02 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\ca-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\eu-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\vi-VN
2012-03-19 11:03 . 2012-03-19 11:03 -------- d-----w- c:\windows\system32\SPReview
2012-03-19 10:46 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2012-03-19 10:46 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2012-03-19 10:34 . 2009-04-10 22:32 141288 ----a-w- c:\windows\system32\drivers\ecache.sys
2012-03-19 10:33 . 2009-04-10 22:28 48128 ----a-w- c:\windows\system32\l2nacp.dll
2012-03-19 10:29 . 2012-03-19 10:29 -------- d-----w- c:\windows\system32\EventProviders
2012-03-19 09:46 . 2012-03-19 09:46 -------- d-----w- c:\users\Timo\Octopus
2012-03-19 09:21 . 2012-03-19 09:21 -------- d-----w- c:\program files\CCleaner
2012-03-17 11:38 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2012-03-17 11:38 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2012-03-17 11:38 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-03-17 11:38 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2012-03-17 11:38 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2012-03-17 11:38 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-03-17 11:38 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-03-17 11:38 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-03-17 11:36 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-03-17 11:35 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2012-03-17 11:23 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2012-03-17 11:23 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-03-17 11:23 . 2009-04-11 06:28 63488 ----a-w- c:\windows\system32\tscupgrd.exe
2012-03-17 11:21 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-03-17 11:07 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-03-17 11:07 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-03-17 11:07 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-03-17 11:07 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-03-17 11:07 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-03-14 17:56 . 2012-03-14 17:56 -------- d-----w- C:\PerfLogs
2012-03-14 17:21 . 2008-01-18 22:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2012-03-14 17:21 . 2008-01-18 22:33 193024 ----a-w- c:\windows\system32\recdisc.exe
2012-03-14 17:20 . 2008-01-18 22:36 28160 ----a-w- c:\windows\system32\sxproxy.dll
2012-03-14 17:13 . 2008-01-18 22:35 8203264 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll
2012-03-14 17:12 . 2008-01-18 22:36 403968 ----a-w- c:\windows\system32\p2pcollab.dll
2012-03-14 17:11 . 2008-01-18 22:33 218112 ----a-w- c:\windows\system32\WindowsAnytimeUpgrade.exe
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\users\Timo\AppData\Roaming\Malwarebytes
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\programdata\Malwarebytes
2012-03-14 16:08 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-14 16:06 . 2012-03-17 11:14 -------- d-----w- C:\backups
2012-03-13 20:04 . 2012-03-13 20:05 -------- d-----w- c:\users\Timo\AppData\Roaming\kodak
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-28 09:23 . 2010-07-17 15:49 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2012-03-28 09:23 . 2010-07-18 19:37 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-03-21 18:09 . 2012-03-21 18:09 4096 ----a-w- c:\windows\system32\drivers\nl-NL\dxgkrnl.sys.mui
2012-03-20 18:24 . 2010-07-17 15:58 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2012-03-14 17:46 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-03-14 17:46 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-03-07 20:37 . 2012-01-15 08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 19:52 . 2012-02-15 19:52 3332784 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2012-02-15 19:52 . 2012-02-15 19:52 316888 ----a-w- c:\windows\system32\appdrvrem01.exe
2012-02-09 12:41 . 2011-09-22 10:32 20040 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2012-02-09 12:41 . 2012-02-09 12:41 53088 ----a-w- c:\windows\system32\BGLsp.dll
2012-02-09 12:41 . 2011-09-22 10:32 216136 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2012-02-09 12:40 . 2011-09-22 10:32 308296 ----a-w- c:\windows\system32\drivers\Trufos.sys
2012-01-26 23:21 . 2010-09-13 17:57 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-06 04:19 . 2012-02-08 16:44 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C5868349-8000-4DF4-8B04-1B98BC3EB318}\mpengine.dll
2010-10-12 14:33 . 2010-10-12 14:33 124344 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-10-12 16:15 . 2010-10-12 16:15 13240 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-10-12 14:37 . 2010-10-12 14:37 70592 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-10-12 14:35 . 2010-10-12 14:35 91576 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-10-12 14:34 . 2010-10-12 14:34 22464 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-10-12 14:32 . 2010-10-12 14:32 255416 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-10-12 14:35 . 2010-10-12 14:35 31672 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-10-12 14:34 . 2010-10-12 14:34 40384 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2010-07-14 10:42 . 2010-07-14 10:42 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-10-12 14:37 . 2010-10-12 14:37 24000 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" [2012-03-23 1710944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 13:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-21 23:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2011-08-17 07:29 4527424 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExpressFiles]
2012-01-07 14:09 326776 ----a-w- c:\program files\ExpressFiles\ExpressFiles.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-11-03 21:20 137536 ----atw- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-10 22:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2009-12-08 06:51 774144 ------w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2945745822-2279633797-4175448609-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
.
2012-03-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000Core.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-03-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000UA.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 195.130.131.133 195.130.130.5
FF - ProfilePath - c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=109130&babsrc=adbartrp&mntrId=a06a49e7000000000000001f3b994f33&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: vShare Plugin: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: BullGuard Safe Browsing: antiphishing@bullguard - c:\program files\BullGuard Ltd\BullGuard Antivirus\Antiphishing\FF\antiphishing@bullguard
FF - user.js: extensions.BabylonToolbar_i.id - a06a49e7000000000000001f3b994f33
FF - user.js: extensions.BabylonToolbar_i.hardId - a06a49e7000000000000001f3b994f33
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15346
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:09
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109130
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-03-28 13:07
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-03-28 13:09:26
ComboFix-quarantined-files.txt 2012-03-28 11:09
ComboFix2.txt 2012-03-28 09:19
.
Pre-Run: 47.837.986.816 bytes beschikbaar
Post-Run: 47.811.514.368 bytes beschikbaar
.
- - End Of File - - 9CEF0469A6B270C124F394E0E86BB38A
-
Beste,
dit is het logje van combo fix.
Na mijn pc te hebben heropgestart komt dat kadertje er alvast niet meer op.
Ik heb na de scan ook mijn antivirus terug ingeschakeld.
Is alles nu opgelost?
Logje:
ComboFix 12-03-28.01 - Timo 28/03/2012 11:10:09.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3070.1953 [GMT 2:00]
Gestart vanuit: c:\users\Timo\Downloads\ComboFix.exe
AV: BullGuard Antivirus *Disabled/Outdated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Disabled/Outdated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Voorgaande Run -------
.
c:\programdata\hpe7667.dll
c:\users\Timo\AppData\Roaming\iSecurity.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-02-28 to 2012-03-28 ))))))))))))))))))))))))))))))
.
.
2012-03-24 17:38 . 2012-03-24 17:38 -------- d-----w- c:\windows\CheckSur
2012-03-22 19:29 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-22 19:29 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-22 19:29 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-22 19:29 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-22 19:29 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-21 18:09 . 2012-03-21 18:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-03-21 18:09 . 2012-03-21 18:09 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-03-21 18:09 . 2012-03-21 18:09 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-03-21 18:09 . 2012-03-21 18:09 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-03-21 18:09 . 2012-03-21 18:09 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-03-21 18:09 . 2012-03-21 18:09 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-03-21 18:09 . 2012-03-21 18:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-03-19 18:13 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-19 18:13 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-19 18:13 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2012-03-19 18:13 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2012-03-19 18:13 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-03-19 18:13 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-03-19 18:13 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-03-19 18:13 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-03-19 18:13 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-19 18:13 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-03-19 18:13 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-03-19 18:12 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-03-19 18:12 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-03-19 18:12 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2012-03-19 18:12 . 2011-09-20 21:02 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-19 18:02 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-19 18:02 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\ca-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\eu-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\vi-VN
2012-03-19 11:03 . 2012-03-19 11:03 -------- d-----w- c:\windows\system32\SPReview
2012-03-19 10:46 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2012-03-19 10:46 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2012-03-19 10:34 . 2009-04-10 22:32 141288 ----a-w- c:\windows\system32\drivers\ecache.sys
2012-03-19 10:33 . 2009-04-10 22:28 48128 ----a-w- c:\windows\system32\l2nacp.dll
2012-03-19 10:29 . 2012-03-19 10:29 -------- d-----w- c:\windows\system32\EventProviders
2012-03-19 09:46 . 2012-03-19 09:46 -------- d-----w- c:\users\Timo\Octopus
2012-03-19 09:21 . 2012-03-19 09:21 -------- d-----w- c:\program files\CCleaner
2012-03-17 11:38 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2012-03-17 11:38 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2012-03-17 11:38 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-03-17 11:38 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2012-03-17 11:38 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2012-03-17 11:38 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-03-17 11:38 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-03-17 11:38 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-03-17 11:36 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-03-17 11:35 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2012-03-17 11:23 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2012-03-17 11:23 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-03-17 11:23 . 2009-04-11 06:28 63488 ----a-w- c:\windows\system32\tscupgrd.exe
2012-03-17 11:21 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-03-17 11:07 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-03-17 11:07 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-03-17 11:07 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-03-17 11:07 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-03-17 11:07 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-03-14 17:56 . 2012-03-14 17:56 -------- d-----w- C:\PerfLogs
2012-03-14 17:21 . 2008-01-18 22:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2012-03-14 17:21 . 2008-01-18 22:33 193024 ----a-w- c:\windows\system32\recdisc.exe
2012-03-14 17:20 . 2008-01-18 22:36 28160 ----a-w- c:\windows\system32\sxproxy.dll
2012-03-14 17:13 . 2008-01-18 22:35 8203264 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll
2012-03-14 17:12 . 2008-01-18 22:36 403968 ----a-w- c:\windows\system32\p2pcollab.dll
2012-03-14 17:11 . 2008-01-18 22:33 218112 ----a-w- c:\windows\system32\WindowsAnytimeUpgrade.exe
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\users\Timo\AppData\Roaming\Malwarebytes
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\programdata\Malwarebytes
2012-03-14 16:08 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-14 16:06 . 2012-03-17 11:14 -------- d-----w- C:\backups
2012-03-13 20:04 . 2012-03-13 20:05 -------- d-----w- c:\users\Timo\AppData\Roaming\kodak
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-28 08:09 . 2010-07-17 15:49 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2012-03-28 08:09 . 2010-07-18 19:37 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-03-21 18:09 . 2012-03-21 18:09 4096 ----a-w- c:\windows\system32\drivers\nl-NL\dxgkrnl.sys.mui
2012-03-20 18:24 . 2010-07-17 15:58 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2012-03-14 17:46 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-03-14 17:46 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-03-07 20:37 . 2012-01-15 08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 19:52 . 2012-02-15 19:52 3332784 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2012-02-15 19:52 . 2012-02-15 19:52 316888 ----a-w- c:\windows\system32\appdrvrem01.exe
2012-02-09 12:41 . 2011-09-22 10:32 20040 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2012-02-09 12:41 . 2012-02-09 12:41 53088 ----a-w- c:\windows\system32\BGLsp.dll
2012-02-09 12:41 . 2011-09-22 10:32 216136 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2012-02-09 12:40 . 2011-09-22 10:32 308296 ----a-w- c:\windows\system32\drivers\Trufos.sys
2012-01-26 23:21 . 2010-09-13 17:57 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-06 04:19 . 2012-02-08 16:44 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C5868349-8000-4DF4-8B04-1B98BC3EB318}\mpengine.dll
2010-10-12 14:33 . 2010-10-12 14:33 124344 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-10-12 16:15 . 2010-10-12 16:15 13240 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-10-12 14:37 . 2010-10-12 14:37 70592 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-10-12 14:35 . 2010-10-12 14:35 91576 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-10-12 14:34 . 2010-10-12 14:34 22464 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-10-12 14:32 . 2010-10-12 14:32 255416 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-10-12 14:35 . 2010-10-12 14:35 31672 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-10-12 14:34 . 2010-10-12 14:34 40384 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2010-07-14 10:42 . 2010-07-14 10:42 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-10-12 14:37 . 2010-10-12 14:37 24000 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" [2012-03-23 1710944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 13:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-21 23:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2011-08-17 07:29 4527424 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExpressFiles]
2012-01-07 14:09 326776 ----a-w- c:\program files\ExpressFiles\ExpressFiles.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-11-03 21:20 137536 ----atw- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-10 22:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2009-12-08 06:51 774144 ------w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2011-08-01 12:35 114992 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2945745822-2279633797-4175448609-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
.
2012-03-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000Core.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-03-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000UA.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Zoek op het web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 195.130.131.133 195.130.130.5
FF - ProfilePath - c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=109130&babsrc=adbartrp&mntrId=a06a49e7000000000000001f3b994f33&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Facemoods: ffxtlbr@Facemoods.com - %profile%\extensions\ffxtlbr@Facemoods.com
FF - Ext: vShare Plugin: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: BittorrentBar_NL Community Toolbar: {2d8d9acc-f6d7-4362-8876-a275ca929591} - %profile%\extensions\{2d8d9acc-f6d7-4362-8876-a275ca929591}
FF - Ext: Softonic English Toolbar: {930f1200-f5f1-4870-bac6-e233ec8e7023} - %profile%\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}
FF - Ext: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
FF - Ext: DealPly: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} - %profile%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: BullGuard Safe Browsing: antiphishing@bullguard - c:\program files\BullGuard Ltd\BullGuard Antivirus\Antiphishing\FF\antiphishing@bullguard
FF - user.js: extensions.BabylonToolbar_i.id - a06a49e7000000000000001f3b994f33
FF - user.js: extensions.BabylonToolbar_i.hardId - a06a49e7000000000000001f3b994f33
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15346
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1715:09
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109130
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS VERWIJDERD - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{2D8D9ACC-F6D7-4362-8876-A275CA929591} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe
MSConfigStartUp-Internet Security - c:\users\Timo\AppData\Roaming\isecurity.exe
AddRemove-{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3} - c:\program files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe
AddRemove-FoxTab MP3 Converter - c:\program files\FoxTabMP3Converter\Uninstall\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-03-28 11:17
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-03-28 11:19:43
ComboFix-quarantined-files.txt 2012-03-28 09:19
.
Pre-Run: 45.342.736.384 bytes beschikbaar
Post-Run: 45.286.002.688 bytes beschikbaar
.
- - End Of File - - FFB71AF7B1CB9469E08D710C82A4C8E5
-
Beste,
Ik heb bovenstaande gedaan maar dat kadertje met die melding blijft nog altijd komen als ik mijn pc opstart. Ook merk ik dat mijn pc opvallend trager gaat, weet jij hier iets op?
Timoootn
-
Beste,
Ik heb gedaan wat u in vorig bericht gevraagd hebt. Mogen deze twee programma'tjes (Malwarebytes en Hijack) dan terug worden verwijderd of niet?
Ik heb ook nog een ander probleempje:Telkens ik mijn pc opstart, komt volgend kadertje: "Kan het bestand C/Users/Timo/Locals-1/Temp/msiaesfut.exe , dat in het register staat vermeld niet laden of starten. Controleer of dit bestand bestaat op de computer of verwijdr de verwijzing naar dit bestand uit het register. "
Log Malware:
Malwarebytes Anti-Malware 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Databaseversie: v2012.03.14.02
Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
Timo :: PC_VAN_TIMO [administrator]
17/03/2012 12:19:49
mbam-log-2012-03-17 (12-19-49).txt
Scantype: Snelle scan
Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scanopties: P2P
Objecten gescand: 176352
Verstreken tijd: 24 minuut/minuten, 1 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
(einde)
Log Hijack
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:35:02, on 17/03/2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\HijackThis.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\wsqmcons.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F3 - REG:win.ini: load=C:\Users\Timo\LOCALS~1\Temp\msiaesfut.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [bullGuard] "C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" -boot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: Zoek op het web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\Antiphishing\IE\BGAntiphishingIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BullGuard behavioural detection service (BsBhvScan) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardBhvScanner.exe
O23 - Service: BullGuard scanning service (BsScanner) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardScanner.exe
O23 - Service: BullGuard update service (BsUpdate) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardUpdate.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 7764 bytes
-
Beste,
Alvast bedankt voor de grote hulp. Ik kan nu mijn pc al opstarten in normale modus. Hieronder vind je de inhoud van het logje en nieuwe HijackThis log.
Moet ik verder nog iets doen of is het virus helemaal verwijderd? Ik zal ook de service packs installeren.
Malwarebytes Anti-Malware 1.60.1.1000
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Databaseversie: v2012.03.14.02
Windows Vista x86 NTFS (Veilige modus/netwerkmogelijkheden)
Internet Explorer 7.0.6000.16982
Timo :: PC_VAN_TIMO [administrator]
14/03/2012 17:10:45
mbam-log-2012-03-14 (17-10-45).txt
Scantype: Snelle scan
Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scanopties: P2P
Objecten gescand: 174917
Verstreken tijd: 4 minuut/minuten, 24 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerdata gedetecteerd: 1
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Trojan.Ransom.BP) -> Slecht: (C:\Users\Timo\LOCALS~1\Temp\msiaesfut.exe) Goed: () -> Zal worden verwijderd tijdens het herstarten.
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 2
C:\Users\Timo\Local Settings\temp\msiaesfut.exe (Trojan.Ransom.BP) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Timo\AppData\Local\temp\msiaesfut.exe (Trojan.Ransom.BP) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
Hijackthis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:31:11, on 14/03/2012
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F3 - REG:win.ini: load=C:\Users\Timo\LOCALS~1\Temp\msiaesfut.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [bullGuard] "C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" -boot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: Zoek op het web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\Antiphishing\IE\BGAntiphishingIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BullGuard behavioural detection service (BsBhvScan) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardBhvScanner.exe
O23 - Service: BullGuard scanning service (BsScanner) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardScanner.exe
O23 - Service: BullGuard update service (BsUpdate) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardUpdate.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 8572 bytes
-
Ben je ondertussen al verder geraakt met het verwijderen van de Bundespolizei ?Start Hijackthis op. Selecteer “Scan”. Selecteer alleen de items die hieronder zijn genoemd:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Policies\Explorer\Run: [27521] C:\PROGRA~2\LOCALS~1\Temp\msxrqk.cmd
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll (file missing)
Klik op 'Fix checked' om de items te verwijderen.
Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\Program Files\Trend Micro\HiJackThis of C:\Program Files (x86)\Trend Micro\HiJackThis.
Download MBAM (Malwarebytes Anti-Malware)
Dubbelklik op mbam-setup.exe om het programma te installeren.
Zorg ervoor dat er een vinkje geplaatst is voor Update Malwarebytes' Anti-Malware en Start Malwarebytes' Anti-Malware, Klik daarna op "Voltooien".
Indien een update gevonden werd, zal die gedownload en geïnstalleerd worden.
Wanneer het programma volledig up to date is, selecteer dan in het tabblad Scanner : "Snelle Scan", daarna klik op Scan.
Het scannen kan een tijdje duren, dus wees geduldig.
Wanneer de scan voltooid is, klik op OK, daarna "Bekijk Resultaten" om de resultaten te zien.
Zorg ervoor dat daar alles aangevinkt is, daarna klik op: Verwijder geselecteerde.
Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten. (Zie verder).
Indien er de rootkit (TDSS) aanwezig is, zal MBAM vragen te herstarten. Doe dit dan ook.
MBAM zal na de herstart opnieuw scannen en de rootkit verwijderen.
Het log wordt automatisch bewaard door MBAM en kan je terugvinden door op de "Logs" tab te klikken in het programma.
Indien MBAM moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven waar je OK moet klikken. Daarna zal het vragen om de computer opnieuw op te starten... dus sta toe dat MBAM de computer opnieuw opstart.
Plak de inhoud van het logje in je volgende bericht, samen met een nieuw HijackThis log.
BESTE,
Ik heb het zelfde probleem. Kunt u mij helpen? Hieronder vind U al mijn logje.
Alvast bedankt
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:32:27, on 13/03/2012
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\explorer.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, nieuws en entertainment vind je op MSN.nl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {2d8d9acc-f6d7-4362-8876-a275ca929591} - (no file)
F3 - REG:win.ini: load=C:\Users\Timo\LOCALS~1\Temp\msiaesfut.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [bullGuard] "C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" -boot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: Zoek op het web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\Antiphishing\IE\BGAntiphishingIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BullGuard behavioural detection service (BsBhvScan) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardBhvScanner.exe
O23 - Service: BullGuard scanning service (BsScanner) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardScanner.exe
O23 - Service: BullGuard update service (BsUpdate) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard Antivirus\BullGuardUpdate.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 8788 bytes
Bundespolizei...
in Archief Bestrijding malware & virussen
Geplaatst:
ComboFix 12-03-28.01 - Timo 02/04/2012 12:37:06.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3070.1919 [GMT 2:00]
Gestart vanuit: c:\users\Timo\Downloads\ComboFix.exe
gebruikte Opdracht switches :: c:\users\Timo\Desktop\CFScript.txt
AV: BullGuard Antivirus *Disabled/Outdated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
SP: BullGuard Antispyware *Disabled/Outdated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
.
- VERMINDERDE FUNCTIONALITEIT MODUS -
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-03-02 to 2012-04-02 ))))))))))))))))))))))))))))))
.
.
2012-04-02 10:38 . 2012-04-02 10:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-24 17:38 . 2012-03-24 17:38 -------- d-----w- c:\windows\CheckSur
2012-03-22 19:29 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-22 19:29 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-22 19:29 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-22 19:29 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-22 19:29 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-21 18:09 . 2012-03-21 18:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-03-21 18:09 . 2012-03-21 18:09 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-03-21 18:09 . 2012-03-21 18:09 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-03-21 18:09 . 2012-03-21 18:09 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-03-21 18:09 . 2012-03-21 18:09 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-03-21 18:09 . 2012-03-21 18:09 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-03-21 18:09 . 2012-03-21 18:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-03-19 18:13 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-19 18:13 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-19 18:13 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2012-03-19 18:13 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2012-03-19 18:13 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-03-19 18:13 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-03-19 18:13 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-03-19 18:13 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-03-19 18:13 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-19 18:13 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-03-19 18:13 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2012-03-19 18:12 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-03-19 18:12 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-03-19 18:12 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2012-03-19 18:12 . 2011-09-20 21:02 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-19 18:02 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-19 18:02 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\ca-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\eu-ES
2012-03-19 11:09 . 2012-03-19 11:09 -------- d-----w- c:\windows\system32\vi-VN
2012-03-19 11:03 . 2012-03-19 11:03 -------- d-----w- c:\windows\system32\SPReview
2012-03-19 10:46 . 2009-04-10 22:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2012-03-19 10:46 . 2009-04-10 22:27 57856 ----a-w- c:\windows\system32\compcln.exe
2012-03-19 10:34 . 2009-04-10 22:32 141288 ----a-w- c:\windows\system32\drivers\ecache.sys
2012-03-19 10:33 . 2009-04-10 22:28 48128 ----a-w- c:\windows\system32\l2nacp.dll
2012-03-19 10:29 . 2012-03-19 10:29 -------- d-----w- c:\windows\system32\EventProviders
2012-03-19 09:46 . 2012-03-19 09:46 -------- d-----w- c:\users\Timo\Octopus
2012-03-19 09:21 . 2012-03-19 09:21 -------- d-----w- c:\program files\CCleaner
2012-03-17 11:38 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2012-03-17 11:38 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2012-03-17 11:38 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-03-17 11:38 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2012-03-17 11:38 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2012-03-17 11:38 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2012-03-17 11:38 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2012-03-17 11:38 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2012-03-17 11:36 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-03-17 11:35 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2012-03-17 11:23 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2012-03-17 11:23 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2012-03-17 11:23 . 2009-04-11 06:28 63488 ----a-w- c:\windows\system32\tscupgrd.exe
2012-03-17 11:21 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-03-17 11:07 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-03-17 11:07 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-03-17 11:07 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-03-17 11:07 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-03-17 11:07 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-03-14 17:56 . 2012-03-14 17:56 -------- d-----w- C:\PerfLogs
2012-03-14 17:21 . 2008-01-18 22:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2012-03-14 17:21 . 2008-01-18 22:33 193024 ----a-w- c:\windows\system32\recdisc.exe
2012-03-14 17:20 . 2008-01-18 22:36 28160 ----a-w- c:\windows\system32\sxproxy.dll
2012-03-14 17:13 . 2008-01-18 22:35 8203264 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\mshwusa.dll
2012-03-14 17:12 . 2008-01-18 22:36 403968 ----a-w- c:\windows\system32\p2pcollab.dll
2012-03-14 17:11 . 2008-01-18 22:33 218112 ----a-w- c:\windows\system32\WindowsAnytimeUpgrade.exe
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\users\Timo\AppData\Roaming\Malwarebytes
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-14 16:08 . 2012-03-14 16:08 -------- d-----w- c:\programdata\Malwarebytes
2012-03-14 16:08 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-14 16:06 . 2012-03-17 11:14 -------- d-----w- C:\backups
2012-03-13 20:04 . 2012-03-13 20:05 -------- d-----w- c:\users\Timo\AppData\Roaming\kodak
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-02 08:24 . 2010-07-17 15:49 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2012-04-02 08:24 . 2010-07-18 19:37 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-03-21 18:09 . 2012-03-21 18:09 4096 ----a-w- c:\windows\system32\drivers\nl-NL\dxgkrnl.sys.mui
2012-03-20 18:24 . 2010-07-17 15:58 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2012-03-14 17:46 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-03-14 17:46 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-03-07 20:37 . 2012-01-15 08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-15 19:52 . 2012-02-15 19:52 3332784 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2012-02-15 19:52 . 2012-02-15 19:52 316888 ----a-w- c:\windows\system32\appdrvrem01.exe
2012-02-09 12:41 . 2011-09-22 10:32 20040 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2012-02-09 12:41 . 2012-02-09 12:41 53088 ----a-w- c:\windows\system32\BGLsp.dll
2012-02-09 12:41 . 2011-09-22 10:32 216136 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2012-02-09 12:40 . 2011-09-22 10:32 308296 ----a-w- c:\windows\system32\drivers\Trufos.sys
2012-01-26 23:21 . 2010-09-13 17:57 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-06 04:19 . 2012-02-08 16:44 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C5868349-8000-4DF4-8B04-1B98BC3EB318}\mpengine.dll
2010-10-12 14:33 . 2010-10-12 14:33 124344 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-10-12 16:15 . 2010-10-12 16:15 13240 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-10-12 14:37 . 2010-10-12 14:37 70592 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-10-12 14:35 . 2010-10-12 14:35 91576 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-10-12 14:34 . 2010-10-12 14:34 22464 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-10-12 14:32 . 2010-10-12 14:32 255416 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-10-12 14:35 . 2010-10-12 14:35 31672 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-10-12 14:34 . 2010-10-12 14:34 40384 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2010-07-14 10:42 . 2010-07-14 10:42 898480 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-10-12 14:37 . 2010-10-12 14:37 24000 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-03-31 16:54 . 2012-03-31 16:54 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-10-12 304568]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard Antivirus\BullGuard.exe" [2012-03-28 1711456]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 13:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-21 23:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2011-08-17 07:29 4527424 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExpressFiles]
2012-01-07 14:09 326776 ----a-w- c:\program files\ExpressFiles\ExpressFiles.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-11-03 21:20 137536 ----atw- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-10 22:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2009-12-08 06:51 774144 ------w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2945745822-2279633797-4175448609-1000]
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
.
2012-03-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000Core.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-04-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2945745822-2279633797-4175448609-1000UA.job
- c:\users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-03 21:20]
.
2012-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
2012-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-18 19:43]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 195.130.131.133 195.130.130.5
FF - ProfilePath - c:\users\Timo\AppData\Roaming\Mozilla\Firefox\Profiles\7ctg4dpj.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - Google
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-04-02 12:38
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-04-02 12:40:36
ComboFix-quarantined-files.txt 2012-04-02 10:40
ComboFix2.txt 2012-03-28 11:09
ComboFix3.txt 2012-03-28 09:19
.
Pre-Run: 45.474.066.432 bytes beschikbaar
Post-Run: 45.456.437.248 bytes beschikbaar
.
- - End Of File - - 666B93DD7A9D6D36F8A498B41BC85020