2012
-
Items
3 -
Registratiedatum
-
Laatst bezocht
Inhoudstype
Profielen
Forums
Store
Berichten die geplaatst zijn door 2012
-
-
ComboFix 09-09-12.A0 - Tim 09/13/2009 6:17.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1470.661 [GMT -7:00]
Running from: c:\users\Tim\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))
.
2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Tim\AppData\Local\temp
2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-13 13:27 . 2009-09-13 13:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-13 09:43 . 2008-03-02 10:28 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys
2009-09-13 09:43 . 2009-09-13 09:44 -------- d-----w- c:\program files\Trend Micro
2009-09-12 13:39 . 2009-09-12 13:39 -------- d-----w- c:\programdata\vsosdk
2009-09-12 12:56 . 2009-09-12 13:50 -------- d-----w- c:\users\Tim\AppData\Roaming\Vso
2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-09-12 12:56 . 2007-03-19 03:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2009-09-12 12:56 . 2006-09-29 18:26 176165 ----a-w- c:\windows\system32\drv23260.dll
2009-09-12 12:56 . 2006-09-29 18:25 208935 ----a-w- c:\windows\system32\drv33260.dll
2009-09-12 12:56 . 2006-09-29 18:24 217127 ----a-w- c:\windows\system32\drv43260.dll
2009-09-12 12:56 . 2004-05-04 18:53 1645320 ----a-w- c:\windows\gdiplus.dll
2009-09-12 12:56 . 2009-09-12 12:56 -------- d-----w- c:\program files\VSO
2009-09-12 09:59 . 2009-09-12 12:00 -------- d-----w- c:\users\Tim\AppData\Roaming\Any Video Converter Professional
2009-09-12 09:59 . 2009-09-12 10:01 -------- d-----w- c:\program files\Any Video Converter Professional
2009-09-11 09:42 . 2009-09-11 09:42 680 ----a-w- c:\users\Tim\AppData\Local\d3d9caps.dat
2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-10 15:12 . 2009-09-10 15:12 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-09-10 13:05 . 2009-09-10 13:06 -------- d-----w- c:\program files\QuickTime
2009-09-10 13:05 . 2009-09-10 13:05 -------- d-----w- c:\programdata\Apple Computer
2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Common Files\Apple
2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\users\Tim\AppData\Local\Apple
2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\program files\Apple Software Update
2009-09-10 13:04 . 2009-09-10 13:04 -------- d-----w- c:\programdata\Apple
2009-09-10 10:28 . 2009-09-10 10:28 -------- d-----w- c:\windows\system32\EventProviders
2009-09-09 14:13 . 2009-09-09 14:15 -------- d-----w- C:\Betsson
2009-09-09 12:51 . 2009-09-09 12:51 -------- d-----w- c:\programdata\Azureus
2009-09-09 12:51 . 2009-09-12 09:57 -------- d-----w- c:\users\Tim\AppData\Roaming\Azureus
2009-09-09 12:50 . 2009-09-09 12:51 -------- d-----w- c:\program files\Vuze
2009-09-09 08:05 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-09 08:05 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 08:05 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-09 08:05 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-09 08:05 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-09 08:05 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-09 08:05 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-09 08:05 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-08 16:53 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-08 16:53 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-08 16:53 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-08 16:53 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-08 16:53 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-08 16:53 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-08 16:53 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-08 16:53 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-08 16:53 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-08 16:53 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-08 16:52 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-08 16:52 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-08 16:52 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-08 16:52 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-08 16:52 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-08 16:08 . 2009-09-08 16:08 -------- d-----w- C:\SAV32CLI
2009-09-08 15:11 . 2009-09-08 17:48 -------- d-----w- C:\SDFix
2009-09-08 13:29 . 2009-09-08 13:54 -------- d-----w- c:\windows\BDOSCAN8
2009-09-08 11:42 . 2009-09-08 11:42 -------- d-----w- c:\programdata\F-Secure
2009-09-07 20:05 . 2009-09-07 20:05 -------- d-----w- c:\program files\Java
2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\users\Tim\AppData\Roaming\IrfanView
2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\program files\IrfanView
2009-09-07 16:52 . 2004-08-04 14:00 506368 ----a-w- c:\windows\system32\msxml.dll
2009-09-07 12:42 . 2009-09-11 21:51 -------- d-----w- c:\users\Tim\AppData\Roaming\Skype
2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\programdata\Skype
2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Common Files\Skype
2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\program files\Skype
2009-09-06 15:40 . 2009-09-06 15:40 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-06 14:25 . 2009-09-12 17:06 -------- d-----w- c:\program files\Everest Poker
2009-09-06 13:58 . 2009-09-06 14:13 -------- d-----w- c:\users\Tim\AppData\Local\P5
2009-09-06 13:48 . 2009-09-09 14:11 -------- d-----w- c:\program files\A-Winning-Hand
2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\users\Tim\AppData\Roaming\VistaCodecs
2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\program files\VistaCodecPack
2009-09-06 13:15 . 2009-09-06 13:15 -------- d-----w- c:\programdata\VistaCodecs
2009-09-06 12:57 . 2009-09-06 14:32 -------- d-----w- C:\Poker
2009-09-06 12:54 . 2009-09-12 13:48 -------- d-----w- c:\programdata\Boss Media
2009-09-06 11:53 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-06 04:04 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-09-06 04:04 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-09-06 04:02 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-09-06 04:02 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-06 04:02 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-06 04:02 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-06 04:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-09-06 03:50 . 2009-09-06 03:50 -------- d-----w- c:\program files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 10:06 . 2009-05-25 22:55 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-13 09:43 . 2009-05-13 02:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-12 16:28 . 2009-05-25 10:47 -------- d-----w- c:\program files\POKER
2009-09-12 12:56 . 2009-09-12 12:56 47360 ----a-w- c:\users\Tim\AppData\Roaming\pcouffin.sys
2009-09-11 11:59 . 2009-05-12 19:39 -------- d-----w- c:\programdata\NVIDIA
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-11 11:51 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-11 11:51 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-11 09:20 . 2009-05-25 06:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 21:54 . 2009-05-25 06:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2009-05-25 06:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 14:17 . 2009-05-25 10:40 -------- d-----w- c:\program files\Poker Heaven
2009-09-08 14:36 . 2009-05-26 04:42 -------- d-----w- c:\programdata\Soulseek
2009-09-08 14:36 . 2009-05-25 10:08 -------- d-----w- c:\users\Tim\AppData\Roaming\vlc
2009-09-07 20:06 . 2009-05-12 18:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-07 00:32 . 2009-05-25 06:20 -------- d-----w- c:\programdata\Avira
2009-09-06 16:57 . 2009-05-28 00:24 -------- d-----w- c:\program files\Betsson
2009-09-06 15:41 . 2009-05-25 10:10 -------- d-----w- c:\program files\Common Files\Real
2009-09-06 13:59 . 2009-05-25 11:22 -------- d-----w- c:\users\Tim\AppData\Roaming\Microgaming
2009-09-06 04:09 . 2009-05-30 08:29 -------- d-----w- c:\program files\Google
2009-09-06 04:00 . 2009-05-27 13:32 -------- d-----w- c:\programdata\Electronic Arts
2009-09-06 03:58 . 2009-05-25 05:51 -------- d-----w- c:\programdata\LogiShrd
2009-09-06 03:58 . 2009-05-25 05:50 -------- d-----w- c:\program files\Common Files\Logishrd
2009-09-06 03:49 . 2009-05-25 08:57 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-28 12:39 . 2009-09-06 04:03 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-06 04:03 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-04 16:48 . 2009-08-04 16:48 2744800 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2009-08-04 16:17 . 2009-08-04 16:17 1265696 ----a-w- c:\windows\system32\RtkPgExt.dll
2009-08-04 16:17 . 2009-05-13 02:25 52256 ----a-w- c:\windows\system32\RtkCoInst.dll
2009-08-04 16:17 . 2009-08-04 16:17 326176 ----a-w- c:\windows\system32\RtkApoApi.dll
2009-08-04 16:17 . 2009-05-13 02:25 2898464 ----a-w- c:\windows\system32\RtkAPO.dll
2009-07-21 21:52 . 2009-09-06 04:03 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-09-06 04:03 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 21:01 . 2009-07-21 21:01 266240 ----a-w- c:\windows\system32\FMAPO.dll
2009-07-21 20:13 . 2009-09-06 04:03 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-20 19:26 . 2009-05-25 05:50 84496 ----a-w- c:\windows\system32\KemXML.dll
2009-07-20 19:26 . 2009-05-25 05:50 117264 ----a-w- c:\windows\system32\KemWnd.dll
2009-07-20 19:26 . 2009-05-25 05:50 145936 ----a-w- c:\windows\system32\KemUtil.dll
2009-07-20 19:26 . 2009-05-25 05:50 170512 ----a-w- c:\windows\system32\kemutb.dll
2009-07-20 19:25 . 2009-05-25 05:50 301656 ----a-w- c:\windows\system32\BtCoreIf.dll
2009-07-17 14:35 . 2009-09-06 04:03 71680 ----a-w- c:\windows\system32\atl.dll
2009-06-17 16:56 . 2009-06-17 16:56 28560 ----a-w- c:\windows\system32\drivers\LUsbFilt.sys
2009-06-17 16:56 . 2009-06-17 16:56 37392 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys
2009-06-17 16:56 . 2009-06-17 16:56 35472 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys
2009-06-17 16:55 . 2009-06-17 16:55 20240 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys
2009-06-17 16:55 . 2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
2009-06-15 15:24 . 2009-09-06 04:03 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-09-06 04:03 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-09-06 04:03 10240 ----a-w- c:\windows\system32\dciman32.dll
.
------- Sigcheck -------
[7] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll
[-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
[-] 2006-11-10 . 921D359C1168867B515C219ACCED9609 . 245248 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-13_10.02.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-05-13 01:34 . 2009-09-13 09:29 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-05-13 01:34 . 2009-09-13 13:09 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-05-13 01:34 . 2009-09-13 09:29 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-13 01:34 . 2009-09-13 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-13 09:26 . 2009-09-13 09:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-13 10:07 . 2009-09-13 10:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-09-13 13:11 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-13 09:31 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-13 09:31 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-09-13 13:11 101144 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-05-25 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"MagicTuneEngine"="c:\program files\MagicTune Premium\MagicTuneEngine.exe" [2009-02-28 69632]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-07 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-06 198160]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2009-06-17 55824]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2009-5-29 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:76,83,2d,99,6e,32,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1625430939-434094062-2039484060-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E7A0DE10-0AAC-4D47-A6A6-85DA84EE592E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{8641B803-3AAE-4A39-8D19-7A80255E1A28}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"UDP Query User{C1BF1F0C-85B7-4144-8E3B-15AB73E87AC4}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"TCP Query User{D92F81F6-AAF7-4086-A2D1-67AE1B0230B3}c:\\program files\\soulseekns\\slsk.exe"= UDP:c:\program files\soulseekns\slsk.exe:SoulSeek
"UDP Query User{573FEA67-D015-46C3-83C8-0212631D7E5F}c:\\program files\\soulseekns\\slsk.exe"= TCP:c:\program files\soulseekns\slsk.exe:SoulSeek
"TCP Query User{C7F2A80C-8052-4CCE-82CC-A177927B5DCA}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{FE35F96B-7C19-40AB-88EF-E8B2261BA86C}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{3452DD1D-75B1-498D-99A7-155A77F3BCCF}c:\\program files\\magictune premium\\magictune.exe"= UDP:c:\program files\magictune premium\magictune.exe:MagicTune
"UDP Query User{BD43CA06-4386-4293-813C-1E8023476CED}c:\\program files\\magictune premium\\magictune.exe"= TCP:c:\program files\magictune premium\magictune.exe:MagicTune
"TCP Query User{9C9AD9EF-3BFB-440D-9471-943A74F700E1}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= UDP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary
"UDP Query User{45F6A493-9AF8-42B6-A68C-968604630DF0}c:\\program files\\b2bpoker\\hollidaypoker\\jre\\bin\\javaw.exe"= TCP:c:\program files\b2bpoker\hollidaypoker\jre\bin\javaw.exe:Java 2 Platform Standard Edition binary
"TCP Query User{5488F78E-58D8-4E43-9181-17684ADB63DA}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{C4ED2645-2AF1-4E58-8655-096FDF675744}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{4EFAEA45-D0CA-4514-90F3-35BBC7832F2E}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{8B623564-7EDC-47A8-AE6E-416F86659A74}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [6/1/2009 4:02 AM 20392]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SAS***IL;SAS***IL;c:\program files\SUPERAntiSpyware\SAS***IL.SYS [4/28/2009 11:33 AM 72944]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [5/25/2009 1:57 AM 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/25/2009 1:57 AM 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [5/25/2009 1:57 AM 434945]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/24/2009 11:21 PM 269648]
R2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [9/13/2009 2:43 AM 582992]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [5/24/2009 11:21 PM 19160]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [2/26/2008 5:17 PM 493568]
R3 TMPassthruMP;TMPassthruMP;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2/22/2007 7:53 PM 2217416]
S2 gupdate1c9e100d4e6a22b;Google Update Service (gupdate1c9e100d4e6a22b);c:\program files\Google\Update\GoogleUpdate.exe [5/30/2009 1:30 AM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\System32\drivers\TMPassthru.sys [9/13/2009 2:43 AM 206608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]
2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 08:29]
2009-09-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000Core.job
- c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]
2009-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1625430939-434094062-2039484060-1000UA.job
- c:\users\Tim\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-25 06:14]
2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Tim.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]
2009-09-11 c:\windows\Tasks\Malwarebytes' Scheduled Update for Tim.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-05-25 21:53]
2009-09-13 c:\windows\Tasks\User_Feed_Synchronization-{627C8EAA-BB82-4C9A-83B7-A17FA49E136D}.job
- c:\windows\system32\msfeedssync.exe [2009-09-06 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.nl/
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\i49klk1y.default\
FF - prefs.js: browser.search.selectedEngine -
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\users\Tim\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-09-13 06:27
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\relog_ap.dll
.
Completion time: 2009-09-13 6:29
ComboFix-quarantined-files.txt 2009-09-13 13:29
ComboFix2.txt 2009-09-13 10:04
Pre-Run: 5,452,574,720 bytes free
Post-Run: 5,393,772,544 bytes free
305 --- E O F --- 2009-09-11 11:35
---------- Post toegevoegd om 13:35 ---------- Vorige post was om 13:33 ----------
En wat ook zo raar was is dat ik gister een online scan met f-secure wou doen en avira premium zegt bij het downloaden van de f-secure files dat er een script virus in zit heel raar al eerder ermee gescaned en geen problemen meer mensen daar last van...? mvg tim
-
kan iemand mijn logs van hijack this and combifix even checken verstuur soms spam naar mensen had last van hidden files en trage computer heb met mbam superantispyware en avira premium al aardig wat verwijdert heb alleen nog last van die spam....mvg tim
---------- Post toegevoegd om 13:14 ---------- Vorige post was om 13:13 ----------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:19 AM, on 9/13/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\MagicTune Premium\GammaTray.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: GammaTray.lnk = ?
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Eurolinx - {00000000-0000-0000-0000-000000000000} - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
--
End of file - 7728 bytes
combifix en hijack this logs nakijken
in Archief Windows Algemeen
Geplaatst:
he bedankt voor je reaktie maar de eerste 2 die R0 die waren al weg vreemd
---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:26 ----------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:45 PM, on 9/13/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\MagicTune Premium\GammaTray.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\FTDv3.8\KoalaFTDSearch.exe
C:\Program Files\FTDv3.8\ftdv3.exe
C:\Windows\system32\mfpmp.exe
C:\Program Files\DFX\WMP\Apps\dfxgApp.exe
C:\Program Files\Poker Heaven\poker.exe
C:\Program Files\Poker Heaven\browserhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MagicTuneEngine] C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - Global Startup: GammaTray.lnk = ?
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Google Update Service (gupdate1c9e100d4e6a22b) (gupdate1c9e100d4e6a22b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
--
End of file - 7462 bytes
---------- Post toegevoegd om 21:28 ---------- Vorige post was om 21:28 ----------
Malwarebytes' Anti-Malware 1.41
Database versie: 2791
Windows 6.0.6001 Service Pack 1
9/13/2009 11:28:31 PM
mbam-log-2009-09-13 (23-28-31).txt
Scan type: Snelle Scan
Objecten gescand: 83884
Verstreken tijd: 3 minute(s), 43 second(s)
Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 0
Registersleutels geïnfecteerd: 0
Registerwaarden geïnfecteerd: 0
Registerdata bestanden geïnfecteerd: 0
Mappen geïnfecteerd: 0
Bestanden geïnfecteerd: 0
Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige items gevonden)
Geheugenmodulen geïnfecteerd:
(Geen kwaadaardige items gevonden)
Registersleutels geïnfecteerd:
(Geen kwaadaardige items gevonden)
Registerwaarden geïnfecteerd:
(Geen kwaadaardige items gevonden)
Registerdata bestanden geïnfecteerd:
(Geen kwaadaardige items gevonden)
Mappen geïnfecteerd:
(Geen kwaadaardige items gevonden)
Bestanden geïnfecteerd:
(Geen kwaadaardige items gevonden)