Ga naar inhoud

2012

Lid
  • Items

    3
  • Registratiedatum

  • Laatst bezocht

Berichten die geplaatst zijn door 2012

  1. he bedankt voor je reaktie maar de eerste 2 die R0 die waren al weg vreemd

    ---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:26 ----------

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:25:45 PM, on 9/13/2009

    Platform: Windows Vista SP1 (WinNT 6.00.1905)

    MSIE: Internet Explorer v8.00 (8.00.6001.18813)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\system32\taskeng.exe

    C:\Windows\RtHDVCpl.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

    C:\Windows\System32\wpcumi.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Windows\WindowsMobile\wmdcBase.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\Program Files\RocketDock\RocketDock.exe

    C:\Program Files\MagicTune Premium\GammaTray.exe

    C:\Program Files\Windows Media Player\wmplayer.exe

    C:\Program Files\MagicTune Premium\MagicTune.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Program Files\Skype\Plugin Manager\SkypePM.exe

    C:\Program Files\FTDv3.8\KoalaFTDSearch.exe

    C:\Program Files\FTDv3.8\ftdv3.exe

    C:\Windows\system32\mfpmp.exe

    C:\Program Files\DFX\WMP\Apps\dfxgApp.exe

    C:\Program Files\Poker Heaven\poker.exe

    C:\Program Files\Poker Heaven\browserhost.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

    O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe

    O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

    O4 - Global Startup: GammaTray.lnk = ?

    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe

    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE

    O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe

    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

    --

    End of file - 7462 bytes

    ---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:28 ----------

    Malwarebytes' Anti-Malware 1.41

    Database versie: 2791

    Windows 6.0.6001 Service Pack 1

    9/13/2009 11:28:31 PM

    mbam-log-2009-09-13 (23-28-31).txt

    Scan type: Snelle Scan

    Objecten gescand: 83884

    Verstreken tijd: 3 minute(s), 43 second(s)

    Geheugenprocessen geïnfecteerd: 0

    Geheugenmodulen geïnfecteerd: 0

    Registersleutels geïnfecteerd: 0

    Registerwaarden geïnfecteerd: 0

    Registerdata bestanden geïnfecteerd: 0

    Mappen geïnfecteerd: 0

    Bestanden geïnfecteerd: 0

    Geheugenprocessen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Geheugenmodulen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registersleutels geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registerwaarden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Registerdata bestanden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Mappen geïnfecteerd:

    (Geen kwaadaardige items gevonden)

    Bestanden geïnfecteerd:

    (Geen kwaadaardige items gevonden)

  2. ComboFix 09-09-12.A0 - Tim 09/13/2009 6:17.2.2 - NTFSx86

    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1470.661 [GMT -7:00]

    Running from: c:\users\Tim\Downloads\ComboFix.exe

    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    .

    ((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))

    .

    2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Tim\AppData\Local\temp

    2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Public\AppData\Local\temp

    2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Default\AppData\Local\temp

    2009-09-13 09:43 . 2008-03-02 10:28 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys

    2009-09-13 09:43 . 2009-09-13 09:44 -------- d-----w- c:\program files\Trend Micro

    2009-09-12 13:39 . 2009-09-12 13:39 -------- d-----w- c:\programdata\vsosdk

    2009-09-12 12:56 . 2009-09-12 13:50 -------- d-----w- c:\users\Tim\AppData\Roaming\Vso

    2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

    2009-09-12 12:56 . 2007-03-19 03:37 65602 ----a-w- c:\windows\system32\cook3260.dll

    2009-09-12 12:56 . 2006-09-29 18:26 176165 ----a-w- c:\windows\system32\drv23260.dll

    2009-09-12 12:56 . 2006-09-29 18:25 208935 ----a-w- c:\windows\system32\drv33260.dll

    2009-09-12 12:56 . 2006-09-29 18:24 217127 ----a-w- c:\windows\system32\drv43260.dll

    2009-09-12 12:56 . 2004-05-04 18:53 1645320 ----a-w- c:\windows\gdiplus.dll

    2009-09-12 12:56 . 2009-09-12 12:56 -------- d-----w- c:\program files\VSO

    2009-09-12 09:59 . 2009-09-12 12:00 -------- d-----w- c:\users\Tim\AppData\Roaming\Any Video Converter Professional

    2009-09-12 09:59 . 2009-09-12 10:01 -------- d-----w- c:\program files\Any Video Converter Professional

    2009-09-11 09:42 . 2009-09-11 09:42 680 ----a-w- c:\users\Tim\AppData\Local\d3d9caps.dat

    2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Toolbar

    2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Lite

    2009-09-10 13:05 . 2009-09-10 13:06 -------- d-----w- c:\program files\QuickTime

    2009-09-10 13:05 . 2009-09-10 13:05 -------- d-----w- c:\programdata\Apple Computer

    2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Common Files\Apple

    2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\users\Tim\AppData\Local\Apple

    2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Apple Software Update

    2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\programdata\Apple

    2009-09-10 10:28 . 2009-09-10 10:28 -------- d-----w- c:\windows\system32\EventProviders

    2009-09-09 14:13 . 2009-09-09 14:15 -------- d-----w- C:\Betsson

    2009-09-09 12:51 . 2009-09-09 12:51 -------- d-----w- c:\programdata\Azureus

    2009-09-09 12:51 . 2009-09-12 09:57 -------- d-----w- c:\users\Tim\AppData\Roaming\Azureus

    2009-09-09 12:50 . 2009-09-09 12:51 -------- d-----w- c:\program files\Vuze

    2009-09-09 08:05 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll

    2009-09-09 08:05 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll

    2009-09-09 08:05 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll

    2009-09-09 08:05 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys

    2009-09-09 08:05 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll

    2009-09-09 08:05 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll

    2009-09-09 08:05 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll

    2009-09-09 08:05 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe

    2009-09-08 16:53 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys

    2009-09-08 16:53 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll

    2009-09-08 16:53 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE

    2009-09-08 16:53 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll

    2009-09-08 16:53 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE

    2009-09-08 16:53 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE

    2009-09-08 16:53 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE

    2009-09-08 16:53 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE

    2009-09-08 16:53 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE

    2009-09-08 16:53 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe

    2009-09-08 16:52 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll

    2009-09-08 16:52 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll

    2009-09-08 16:52 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll

    2009-09-08 16:52 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll

    2009-09-08 16:52 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll

    2009-09-08 16:08 . 2009-09-08 16:08 -------- d-----w- C:\SAV32CLI

    2009-09-08 15:11 . 2009-09-08 17:48 -------- d-----w- C:\SDFix

    2009-09-08 13:29 . 2009-09-08 13:54 -------- d-----w- c:\windows\BDOSCAN8

    2009-09-08 11:42 . 2009-09-08 11:42 -------- d-----w- c:\programdata\F-Secure

    2009-09-07 20:05 . 2009-09-07 20:05 -------- d-----w- c:\program files\Java

    2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\users\Tim\AppData\Roaming\IrfanView

    2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\program files\IrfanView

    2009-09-07 16:52 . 2004-08-04 14:00 506368 ----a-w- c:\windows\system32\msxml.dll

    2009-09-07 12:42 . 2009-09-11 21:51 -------- d-----w- c:\users\Tim\AppData\Roaming\Skype

    2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\programdata\Skype

    2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Common Files\Skype

    2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Skype

    2009-09-06 15:40 . 2009-09-06 15:40 -------- d-----w- c:\program files\Common Files\xing shared

    2009-09-06 14:25 . 2009-09-12 17:06 -------- d-----w- c:\program files\Everest Poker

    2009-09-06 13:58 . 2009-09-06 14:13 -------- d-----w- c:\users\Tim\AppData\Local\P5

    2009-09-06 13:48 . 2009-09-09 14:11 -------- d-----w- c:\program files\A-Winning-Hand

    2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\users\Tim\AppData\Roaming\VistaCodecs

    2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\program files\VistaCodecPack

    2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\programdata\VistaCodecs

    2009-09-06 12:57 . 2009-09-06 14:32 -------- d-----w- C:\Poker

    2009-09-06 12:54 . 2009-09-12 13:48 -------- d-----w- c:\programdata\Boss Media

    2009-09-06 11:53 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll

    2009-09-06 04:04 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll

    2009-09-06 04:04 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll

    2009-09-06 04:02 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll

    2009-09-06 04:02 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll

    2009-09-06 04:02 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll

    2009-09-06 04:02 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL

    2009-09-06 04:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll

    2009-09-06 03:50 . 2009-09-06 03:50 -------- d-----w- c:\program files\MSXML 4.0

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2009-09-13 10:06 . 2009-05-25 22:55 12 ----a-w- c:\windows\bthservsdp.dat

    2009-09-13 09:43 . 2009-05-13 02:25 -------- d--h--w- c:\program files\InstallShield Installation Information

    2009-09-12 16:28 . 2009-05-25 10:47 -------- d-----w- c:\program files\POKER

    2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\users\Tim\AppData\Roaming\pcouffin.sys

    2009-09-11 11:59 . 2009-05-12 19:39 -------- d-----w- c:\programdata\NVIDIA

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar

    2009-09-11 11:51 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery

    2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender

    2009-09-11 09:20 . 2009-05-25 06:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

    2009-09-10 21:54 . 2009-05-25 06:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

    2009-09-10 21:53 . 2009-05-25 06:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

    2009-09-09 14:17 . 2009-05-25 10:40 -------- d-----w- c:\program files\Poker Heaven

    2009-09-08 14:36 . 2009-05-26 04:42 -------- d-----w- c:\programdata\Soulseek

    2009-09-08 14:36 . 2009-05-25 10:08 -------- d-----w- c:\users\Tim\AppData\Roaming\vlc

    2009-09-07 20:06 . 2009-05-12 18:37 411368 ----a-w- c:\windows\system32\deploytk.dll

    2009-09-07 00:32 . 2009-05-25 06:20 -------- d-----w- c:\programdata\Avira

    2009-09-06 16:57 . 2009-05-28 00:24 -------- d-----w- c:\program files\Betsson

    2009-09-06 15:41 . 2009-05-25 10:10 -------- d-----w- c:\program files\Common Files\Real

    2009-09-06 13:59 . 2009-05-25 11:22 -------- d-----w- c:\users\Tim\AppData\Roaming\Microgaming

    2009-09-06 04:09 . 2009-05-30 08:29 -------- d-----w- c:\program files\Google

    2009-09-06 04:00 . 2009-05-27 13:32 -------- d-----w- c:\programdata\Electronic Arts

    2009-09-06 03:58 . 2009-05-25 05:51 -------- d-----w- c:\programdata\LogiShrd

    2009-09-06 03:58 . 2009-05-25 05:50 -------- d-----w- c:\program files\Common Files\Logishrd

    2009-09-06 03:49 . 2009-05-25 08:57 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys

    2009-08-28 12:39 . 2009-09-06 04:03 28672 ----a-w- c:\windows\system32\Apphlpdm.dll

    2009-08-28 10:15 . 2009-09-06 04:03 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

    2009-08-04 16:48 . 2009-08-04 16:48 2744800 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys

    2009-08-04 16:17 . 2009-08-04 16:17 1265696 ----a-w- c:\windows\system32\RtkPgExt.dll

    2009-08-04 16:17 . 2009-05-13 02:25 52256 ----a-w- c:\windows\system32\RtkCoInst.dll

    2009-08-04 16:17 . 2009-08-04 16:17 326176 ----a-w- c:\windows\system32\RtkApoApi.dll

    2009-08-04 16:17 . 2009-05-13 02:25 2898464 ----a-w- c:\windows\system32\RtkAPO.dll

    2009-07-21 21:52 . 2009-09-06 04:03 915456 ----a-w- c:\windows\system32\wininet.dll

    2009-07-21 21:47 . 2009-09-06 04:03 109056 ----a-w- c:\windows\system32\iesysprep.dll

    2009-07-21 21:47 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\iesetup.dll

    2009-07-21 21:01 . 2009-07-21 21:01 266240 ----a-w- c:\windows\system32\FMAPO.dll

    2009-07-21 20:13 . 2009-09-06 04:03 133632 ----a-w- c:\windows\system32\ieUnatt.exe

    2009-07-20 19:26 . 2009-05-25 05:50 84496 ----a-w- c:\windows\system32\KemXML.dll

    2009-07-20 19:26 . 2009-05-25 05:50 117264 ----a-w- c:\windows\system32\KemWnd.dll

    2009-07-20 19:26 . 2009-05-25 05:50 145936 ----a-w- c:\windows\system32\KemUtil.dll

    2009-07-20 19:26 . 2009-05-25 05:50 170512 ----a-w- c:\windows\system32\kemutb.dll

    2009-07-20 19:25 . 2009-05-25 05:50 301656 ----a-w- c:\windows\system32\BtCoreIf.dll

    2009-07-17 14:35 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\atl.dll

    2009-06-17 16:56 . 2009-06-17 16:56 28560 ----a-w- c:\windows\system32\drivers\LUsbFilt.sys

    2009-06-17 16:56 . 2009-06-17 16:56 37392 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys

    2009-06-17 16:56 . 2009-06-17 16:56 35472 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys

    2009-06-17 16:55 . 2009-06-17 16:55 20240 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys

    2009-06-17 16:55 . 2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe

    2009-06-15 15:24 . 2009-09-06 04:03 156672 ----a-w- c:\windows\system32\t2embed.dll

    2009-06-15 15:20 . 2009-09-06 04:03 72704 ----a-w- c:\windows\system32\fontsub.dll

    2009-06-15 15:20 . 2009-09-06 04:03 10240 ----a-w- c:\windows\system32\dciman32.dll

    .

    ------- Sigcheck -------

    [7] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll

    [-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll

    [-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll

    .

    ((((((((((((((((((((((((((((( SnapShot@2009-09-13_10.02.01 )))))))))))))))))))))))))))))))))))))))))

    .

    - 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    + 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

    - 2009-05-13 01:34 . 2009-09-13 09:29 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    + 2009-05-13 01:34 . 2009-09-13 13:09 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

    - 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    + 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

    + 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2006-11-02 10:33 . 2009-09-13 13:11 595446 c:\windows\System32\perfh009.dat

    - 2006-11-02 10:33 . 2009-09-13 09:31 595446 c:\windows\System32\perfh009.dat

    - 2006-11-02 10:33 . 2009-09-13 09:31 101144 c:\windows\System32\perfc009.dat

    + 2006-11-02 10:33 . 2009-09-13 13:11 101144 c:\windows\System32\perfc009.dat

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

    "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]

    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]

    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-05-25 209153]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

    "MagicTuneEngine"="c:\program files\MagicTune Premium\MagicTuneEngine.exe" [2009-02-28 69632]

    "WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]

    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-07 149280]

    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-06 198160]

    "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

    "TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088]

    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2009-06-17 55824]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2009-5-29 36864]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "EnableLUA"= 0 (0x0)

    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

    2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

    @="Service"

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]

    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

    backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup

    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]

    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk

    backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup

    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

    "VistaSp2"=hex(B):76,83,2d,99,6e,32,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1625430939-434094062-2039484060-1000]

    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

    "{E7A0DE10-0AAC-4D47-A6A6-85DA84EE592E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)

    "TCP Query User{8641B803-3AAE-4A39-8D19-7A80255E1A28}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar

    "UDP Query User{C1BF1F0C-85B7-4144-8E3B-15AB73E87AC4}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar

    "TCP Query User{D92F81F6-AAF7-4086-A2D1-67AE1B0230B3}c:\\program files\\soulseekns\\slsk.exe"= UDP:c:\program files\soulseekns\slsk.exe:SoulSeek

    "UDP Query User{573FEA67-D015-46C3-83C8-0212631D7E5F}c:\\program files\\soulseekns\\slsk.exe"= TCP:c:\program files\soulseekns\slsk.exe:SoulSeek

    "TCP Query User{C7F2A80C-8052-4CCE-82CC-A177927B5DCA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

    "UDP Query User{FE35F96B-7C19-40AB-88EF-E8B2261BA86C}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

    "TCP Query User{3452DD1D-75B1-498D-99A7-155A77F3BCCF}c:\\program files\\magictune premium\\magictune.exe"= UDP:c:\program files\magictune premium\magictune.exe:MagicTune

    "UDP Query User{BD43CA06-4386-4293-813C-1E8023476CED}c:\\program files\\magictune premium\\magictune.exe"= TCP:c:\program files\magictune premium\magictune.exe:MagicTune

    "TCP Query User{9C9AD9EF-3BFB-440D-9471-943A74F700E1}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= UDP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary

    "UDP Query User{45F6A493-9AF8-42B6-A68C-968604630DF0}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= TCP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary

    "TCP Query User{5488F78E-58D8-4E43-9181-17684ADB63DA}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus

    "UDP Query User{C4ED2645-2AF1-4E58-8655-096FDF675744}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus

    "{4EFAEA45-D0CA-4514-90F3-35BBC7832F2E}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype

    "{8B623564-7EDC-47A8-AE6E-416F86659A74}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype

    R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [6/1/2009 4:02 AM 20392]

    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]

    R1 SAS***IL;SAS***IL;c:\program files\SUPERAntiSpyware\SAS***IL.SYS [4/28/2009 11:33 AM 72944]

    R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [5/25/2009 1:57 AM 194817]

    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/25/2009 1:57 AM 108289]

    R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [5/25/2009 1:57 AM 434945]

    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/24/2009 11:21 PM 269648]

    R2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [9/13/2009 2:43 AM 582992]

    R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [5/24/2009 11:21 PM 19160]

    R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [2/26/2008 5:17 PM 493568]

    R3 TMPassthruMP;TMPassthruMP;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]

    S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2/22/2007 7:53 PM 2217416]

    S2 gupdate1c9e100d4e6a22b;Google Update Service (gupdate1c9e100d4e6a22b);c:\program files\Google\Update\GoogleUpdate.exe [5/30/2009 1:30 AM 133104]

    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]

    S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    WindowsMobile REG_MULTI_SZ wcescomm rapimgr

    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

    bthsvcs REG_MULTI_SZ BthServ

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

    "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

    .

    Contents of the 'Scheduled Tasks' folder

    2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]

    2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]

    2009-09-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000Core.job

    - c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]

    2009-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000UA.job

    - c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]

    2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Tim.job

    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]

    2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Update for Tim.job

    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]

    2009-09-13 c:\windows\Tasks\User_Feed_Synchronization-{627C8EAA-BB82-4C9A-83B7-A17FA49E136D}.job

    - c:\windows\system32\msfeedssync.exe [2009-09-06 20:13]

    .

    .

    ------- Supplementary Scan -------

    .

    uStart Page = hxxp://www.google.nl/

    LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll

    FF - ProfilePath - c:\users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\i49klk1y.default\

    FF - prefs.js: browser.search.selectedEngine -

    FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll

    FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll

    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll

    FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll

    FF - plugin: c:\users\Tim\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll

    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

    Rootkit scan 2009-09-13 06:27

    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    **************************************************************************

    .

    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'lsass.exe'(936)

    c:\windows\system32\relog_ap.dll

    .

    Completion time: 2009-09-13 6:29

    ComboFix-quarantined-files.txt 2009-09-13 13:29

    ComboFix2.txt 2009-09-13 10:04

    Pre-Run: 5,452,574,720 bytes free

    Post-Run: 5,393,772,544 bytes free

    305 --- E O F --- 2009-09-11 11:35

    ---------- Post toegevoegd om 13:35 ---------- Vorige post was om 13:33 ----------

    En wat ook zo raar was is dat ik gister een online scan met f-secure wou doen en avira premium zegt bij het downloaden van de f-secure files dat er een script virus in zit heel raar al eerder ermee gescaned en geen problemen meer mensen daar last van...? mvg tim

  3. kan iemand mijn logs van hijack this and combifix even checken verstuur soms spam naar mensen had last van hidden files en trage computer heb met mbam superantispyware en avira premium al aardig wat verwijdert heb alleen nog last van die spam....mvg tim

    ---------- Post toegevoegd om 13:14 ---------- Vorige post was om 13:13 ----------

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 2:47:19 AM, on 9/13/2009

    Platform: Windows Vista SP1 (WinNT 6.00.1905)

    MSIE: Internet Explorer v8.00 (8.00.6001.18813)

    Boot mode: Normal

    Running processes:

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Windows\RtHDVCpl.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

    C:\Windows\System32\wpcumi.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Windows\WindowsMobile\wmdcBase.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\Program Files\RocketDock\RocketDock.exe

    C:\Program Files\MagicTune Premium\GammaTray.exe

    C:\Program Files\MagicTune Premium\MagicTune.exe

    C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe

    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

    O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe

    O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

    O4 - Global Startup: GammaTray.lnk = ?

    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

    O9 - Extra button: Eurolinx - {00000000-0000-0000-0000-000000000000} - (no file) (HKCU)

    O13 - Gopher Prefix:

    O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe

    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe

    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE

    O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe

    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

    --

    End of file - 7728 bytes

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.