ComboFix 09-08-06.01 - Tar 06-08-2009 23:46.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.2045.754 [GMT 2:00] Gestart vanuit: c:\users\Tar\Desktop\ComboFix.exe SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . (((((((((((((((((((( Bestanden Gemaakt van 2009-07-06 to 2009-08-06 )))))))))))))))))))))))))))))) . 2009-08-06 21:53 . 2009-08-06 21:53 -------- d-----w- c:\users\Tar\AppData\Local\temp 2009-08-06 21:53 . 2009-08-06 21:53 -------- d-----w- c:\users\Public\AppData\Local\temp 2009-08-06 21:53 . 2009-08-06 21:53 -------- d-----w- c:\users\Gast\AppData\Local\temp 2009-08-06 21:53 . 2009-08-06 21:53 -------- d-----w- c:\users\eric\AppData\Local\temp 2009-08-06 21:53 . 2009-08-06 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-08-05 18:10 . 2009-08-05 18:10 -------- d-----w- c:\program files\Trend Micro 2009-08-05 15:39 . 2009-08-05 15:39 117760 ----a-w- c:\users\Tar\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-08-05 15:02 . 2009-08-05 15:02 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2009-08-05 15:01 . 2009-08-05 15:38 -------- d-----w- c:\users\Tar\AppData\Roaming\SUPERAntiSpyware.com 2009-08-05 14:34 . 2009-08-05 14:57 -------- d-----w- C:\MGtools 2009-08-05 13:16 . 2009-08-05 13:16 -------- d-----w- C:\NVIDIA 2009-08-05 11:38 . 2009-08-05 11:38 -------- d-----w- c:\program files\CCleaner 2009-08-04 23:32 . 2008-04-07 04:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll 2009-08-04 21:11 . 2009-08-04 21:11 -------- d-----w- c:\users\Tar\AppData\Roaming\Malwarebytes 2009-08-04 21:11 . 2009-08-04 21:11 -------- d-----w- c:\programdata\Malwarebytes 2009-08-04 20:06 . 2009-08-04 20:07 -------- d-----w- c:\users\Tar\AppData\Roaming\U3 2009-08-04 19:09 . 2009-08-04 19:09 -------- d-----w- c:\program files\NT Registry Optimizer 2009-08-03 19:28 . 2009-08-03 22:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2009-08-03 18:29 . 2009-08-03 18:29 -------- d-----w- c:\program files\Realtek 2009-08-03 18:28 . 2006-09-12 12:34 499712 ----a-w- c:\windows\RtlExUpd.dll 2009-07-29 13:35 . 2009-07-29 13:37 -------- d-----w- c:\windows\system32\ca-ES 2009-07-29 13:35 . 2009-07-29 13:36 -------- d-----w- c:\windows\system32\eu-ES 2009-07-29 13:35 . 2009-07-29 13:36 -------- d-----w- c:\windows\system32\vi-VN 2009-07-28 22:35 . 2009-07-28 22:35 -------- d-----w- c:\windows\system32\EventProviders 2009-07-28 22:26 . 2009-04-11 06:28 928768 ----a-w- c:\windows\system32\scavenge.dll 2009-07-28 22:25 . 2009-04-11 06:32 1083880 ----a-w- c:\windows\system32\drivers\ntfs.sys 2009-07-28 22:24 . 2009-04-11 06:28 343040 ----a-w- c:\windows\system32\wmicmiplugin.dll 2009-07-28 22:23 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\wlanhlp.dll 2009-07-28 22:22 . 2009-04-11 04:46 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys 2009-07-28 22:21 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll 2009-07-28 22:21 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll 2009-07-28 22:21 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe 2009-07-28 22:18 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll 2009-07-28 21:28 . 2009-07-28 21:28 -------- d-----w- c:\users\Tar\AppData\Local\Apple 2009-07-28 20:07 . 2003-08-29 16:47 7040 ----a-w- c:\windows\system32\drivers\flash.sys 2009-07-28 15:48 . 2009-07-28 15:48 -------- d--h--w- c:\windows\Icons 2009-07-28 15:45 . 2009-07-28 15:45 6483968 ----a-w- c:\programdata\TuneUp Software\TuneUp Utilities\WinStyler\LogonScreens\Redwood.tls.dll 2009-07-28 15:25 . 2009-07-28 15:25 604488 ----a-w- c:\windows\system32\TUProgSt.exe 2009-07-28 15:25 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll 2009-07-28 15:25 . 2009-07-15 09:48 17224 ----a-w- c:\windows\system32\authuitu.dll 2009-07-28 15:25 . 2009-07-28 15:25 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2009-07-28 15:25 . 2009-07-28 15:25 -------- d-----w- c:\users\Tar\AppData\Roaming\TuneUp Software 2009-07-28 15:24 . 2009-07-28 15:25 -------- d-----w- c:\program files\TuneUp Utilities 2009 2009-07-28 15:24 . 2009-07-28 15:24 -------- d-----w- c:\programdata\TuneUp Software 2009-07-28 15:22 . 2009-07-28 15:22 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357} 2009-07-28 14:05 . 2006-09-05 10:28 38480 ------w- c:\windows\system32\IJRMF.exe 2009-07-22 22:33 . 2009-07-22 22:33 -------- d-----w- c:\program files\Belarc 2009-07-22 19:56 . 2009-07-22 19:56 -------- d-----w- c:\programdata\YAMAHA 2009-07-22 18:51 . 2009-07-22 18:51 -------- d-----w- C:\ASK Video 2009-07-21 18:12 . 2008-08-26 11:21 33736 ----a-w- c:\windows\system32\drivers\ymidusbw.sys 2009-07-21 18:09 . 2009-07-21 18:09 -------- d-----w- c:\program files\YAMAHA 2009-07-20 19:07 . 2009-07-20 20:45 34 ----a-w- c:\users\Tar\jagex_runescape_preferences.dat 2009-07-19 13:20 . 2009-07-19 13:21 -------- d-----w- c:\users\Tar\AppData\Local\Apple Computer 2009-07-19 12:25 . 2009-07-19 12:25 -------- d--h--w- c:\users\Tar\AppData\Local\acer eNM 2009-07-18 22:00 . 2009-07-18 22:00 -------- d-----w- c:\users\Tar\AppData\Roaming\IObit 2009-07-18 22:00 . 2009-07-18 22:00 -------- d-----w- c:\program files\IObit 2009-07-18 21:21 . 2009-07-18 21:21 -------- d-----w- c:\users\Tar\AppData\Local\Thinstall 2009-07-18 20:03 . 2009-07-19 17:47 -------- d-----w- c:\users\Tar\AppData\Local\Adobe 2009-07-17 14:39 . 2009-07-17 14:39 -------- d-----w- C:\Hotspot Shield 2009-07-17 14:38 . 2009-07-17 14:39 -------- d-----w- c:\program files\Hotspot Shield 2009-07-16 10:54 . 2009-07-16 10:54 -------- d-----w- c:\program files\iPod 2009-07-15 13:22 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll 2009-07-15 13:22 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll 2009-07-15 13:22 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll 2009-07-15 13:22 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll 2009-07-15 13:22 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll 2009-07-15 13:22 . 2009-04-11 06:28 34304 ----a-w- c:\windows\system32\atmlib.dll 2009-07-15 00:01 . 2009-07-15 00:01 25472 ----a-w- c:\windows\system32\drivers\tap0901.sys 2009-07-13 14:22 . 2009-07-13 14:22 -------- d-----w- c:\users\Tar\AppData\Local\Mozilla . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-06 21:06 . 2009-01-21 19:29 -------- d-----w- c:\programdata\Google Updater 2009-08-06 21:04 . 2009-05-08 14:45 210388 ----a-w- c:\programdata\nvModes.dat 2009-08-05 15:36 . 2008-06-03 12:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-08-05 13:29 . 2007-03-07 15:32 -------- d-----w- c:\programdata\NVIDIA 2009-08-05 12:04 . 2008-10-08 14:59 -------- d-----w- c:\users\Tar\AppData\Roaming\uTorrent 2009-08-05 12:03 . 2007-03-07 15:25 -------- d-----w- c:\programdata\Microsoft Help 2009-08-05 10:58 . 2008-02-02 20:37 -------- d-----w- c:\program files\Common Files\Merge Modules 2009-08-05 10:23 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild 2009-08-05 09:32 . 2007-03-07 15:01 62865 ----a-w- c:\users\Tar\AppData\Roaming\nvModes.dat 2009-08-04 20:22 . 2006-12-14 03:17 809272 ----a-w- c:\windows\system32\perfh013.dat 2009-08-04 20:22 . 2006-12-14 03:17 181062 ----a-w- c:\windows\system32\perfc013.dat 2009-08-04 18:34 . 2007-03-07 15:00 68240 ----a-w- c:\users\Tar\AppData\Local\GDIPFONTCACHEV1.DAT 2009-08-03 23:10 . 2008-05-09 13:58 -------- d-----w- c:\users\Tar\AppData\Roaming\MySQL 2009-08-03 19:17 . 2007-08-05 21:14 -------- d-----w- c:\program files\McAfee 2009-08-03 19:16 . 2008-06-21 16:02 -------- d-----w- c:\program files\Microsoft Silverlight 2009-08-03 18:29 . 2006-12-02 18:50 319984 ----a-w- c:\windows\DIFxAPI.dll 2009-08-03 18:29 . 2006-12-02 18:49 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-29 13:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar 2009-07-29 13:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar 2009-07-29 13:37 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-07-29 13:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery 2009-07-29 13:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender 2009-07-29 13:35 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2009-07-29 12:36 . 2009-01-16 22:30 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont 2009-07-28 20:59 . 2009-05-24 19:26 18368 ----a-w- c:\programdata\Microsoft\VSA\9.0\1033\ResourceCache.dll 2009-07-28 20:59 . 2009-05-24 19:25 1680064 ----a-w- c:\programdata\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll 2009-07-28 20:39 . 2008-07-04 22:01 -------- d-----w- c:\programdata\Apple Computer 2009-07-28 15:14 . 2008-07-04 21:57 -------- d-----w- c:\programdata\Apple 2009-07-28 14:38 . 2008-05-30 14:24 -------- d-----w- c:\program files\eclipse 2009-07-28 14:22 . 2006-12-13 18:34 -------- d-----w- c:\program files\NewTech Infosystems 2009-07-28 14:20 . 2006-12-13 18:34 -------- d-----w- c:\program files\Common Files\NewTech Infosystems 2009-07-28 14:19 . 2006-12-13 18:31 -------- d-----w- c:\program files\CyberLink 2009-07-28 14:10 . 2007-03-07 16:41 -------- d-----w- c:\program files\Java 2009-07-28 14:01 . 2009-01-08 19:54 -------- d-----w- c:\program files\Common Files\Logitech 2009-07-28 13:53 . 2009-01-08 19:54 -------- d-----w- c:\program files\Logitech 2009-07-21 21:52 . 2009-07-28 20:46 915456 ----a-w- c:\windows\system32\wininet.dll 2009-07-21 21:47 . 2009-07-28 20:46 109056 ----a-w- c:\windows\system32\iesysprep.dll 2009-07-21 21:47 . 2009-07-28 20:46 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-07-21 20:13 . 2009-07-28 20:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-07-19 18:48 . 2009-05-16 19:05 -------- d-----w- c:\program files\Puran Defrag 2009-07-18 22:50 . 2008-02-27 20:04 -------- d-----w- c:\programdata\WLInstaller 2009-07-18 22:50 . 2007-11-08 15:03 -------- d-----w- c:\programdata\FLEXnet 2009-07-16 11:58 . 2009-06-14 18:50 22528 ----a-w- c:\windows\system32\drivers\nhcDriver.sys 2009-07-16 10:55 . 2009-06-03 20:07 -------- d-----w- c:\program files\iTunes 2009-07-16 10:54 . 2008-07-04 21:57 -------- d-----w- c:\program files\Common Files\Apple 2009-07-16 08:05 . 2009-05-16 19:05 229376 ----a-w- c:\windows\system32\PuranDefragS.exe 2009-07-16 08:05 . 2009-05-16 19:05 229376 ----a-w- c:\windows\system32\PuranDC.exe 2009-07-16 08:05 . 2009-05-16 19:05 107008 ----a-w- c:\windows\system32\PuranDefragBT.exe 2009-07-16 08:05 . 2009-05-16 19:05 1110016 ----a-w- c:\windows\system32\PuranFD.exe 2009-07-10 09:29 . 2007-06-24 10:54 -------- d-----w- c:\programdata\McAfee 2009-07-07 19:23 . 2009-07-07 19:23 488960 ----a-w- c:\users\Tar\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv302-0811070-0-main.dll 2009-07-07 19:23 . 2009-07-07 19:23 319488 ----a-w- c:\users\Tar\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe 2009-07-06 09:54 . 2009-05-16 19:05 208896 ----a-w- c:\windows\system32\PuranDefrag.dll 2009-07-02 08:08 . 2009-07-01 18:46 -------- d-----w- c:\program files\Common Files\Acer 2009-07-02 02:34 . 2009-07-02 02:34 33840 ----a-w- c:\windows\system32\drivers\hssdrv.sys 2009-07-01 19:14 . 2008-10-12 19:21 -------- d-----w- c:\program files\DivX 2009-07-01 19:13 . 2009-07-01 19:13 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-06-28 12:20 . 2009-06-28 12:20 91 ----a-w- c:\users\Tar\AppData\Local\fusioncache.dat 2009-06-28 12:19 . 2008-06-03 12:26 -------- d-----w- c:\program files\TI Education 2009-06-28 12:19 . 2008-06-03 12:26 -------- d-----w- c:\program files\Common Files\TI Shared 2009-06-28 12:19 . 2009-06-28 12:19 -------- d-----w- c:\program files\Common Files\SpellEx 2009-06-25 19:10 . 2007-08-23 19:21 -------- d-----w- c:\users\Tar\AppData\Roaming\Canon 2009-06-23 18:46 . 2009-06-23 18:46 -------- d-----w- c:\programdata\Minnetonka Audio Software 2009-06-18 19:25 . 2008-11-23 09:58 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-18 19:09 . 2009-06-18 19:09 3584 ----a-r- c:\users\Tar\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2009-06-18 19:09 . 2009-06-18 19:09 -------- d-----w- c:\program files\Windows Installer Clean Up 2009-06-18 19:08 . 2007-03-07 15:52 -------- d-----w- c:\program files\MSECache 2009-06-14 18:50 . 2009-06-14 18:50 -------- d-----w- c:\program files\Notebook Hardware Control 2009-06-14 14:54 . 2008-11-16 15:57 -------- d-----w- c:\users\Tar\AppData\Roaming\Vso 2009-05-30 14:13 . 2009-05-30 14:13 279172 ----a-w- c:\programdata\eSellerate\eWebClient.dll 2009-05-29 11:36 . 2009-05-29 11:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2009-05-29 11:36 . 2009-05-29 11:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll 2009-05-24 08:26 . 2008-03-07 15:53 680 ----a-w- c:\users\Tar\AppData\Local\d3d9caps.dat 2009-05-16 16:18 . 2009-05-16 16:18 66904 ----a-r- c:\users\Tar\AppData\Roaming\Microsoft\Installer\{D4A2957D-5113-4722-A0A3-E7D0BF85D5D4}\ARPPRODUCTICON.exe 2002-07-31 17:55 . 2007-10-03 17:49 520 --sh--w- c:\windows\WSYS049.SYS 2007-09-29 19:39 . 2007-12-11 22:20 80 --sha-r- c:\windows\System32\A7E9485A94.dll 2006-05-03 10:06 . 2009-04-05 15:13 163328 --sh--r- c:\windows\System32\flvDX.dll 2007-02-21 11:47 . 2009-04-05 15:13 31232 --sh--r- c:\windows\System32\msfDX.dll 2008-03-16 13:30 . 2009-04-05 15:13 216064 --sh--r- c:\windows\System32\nbDX.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] 2009-07-17 14:38 218160 ----a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856] "Google Update"="c:\users\Tar\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-12-12 133104] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104] "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768] "LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-01-10 200704] "LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664] "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016] "OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304] "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-08 645328] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-18 148888] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13605408] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 92704] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304] c:\users\eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Schermopname en Snel starten.lnk.disabled [2008-5-24 1119] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-13 528384] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-8 805392] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "MaxRecentDocs"= 11 (0xb) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\eNetHook.dll c:\windows\System32\eNetHook.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot "WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.exe "Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):f6,79,10,66,52,14,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-144886689-3844884146-1124540986-1000] "EnableNotificationsRef"=dword:00000002 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-144886689-3844884146-1124540986-1002] "EnableNotifications"=dword:00000001 "EnableNotificationsRef"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{66FCBB55-81DF-47B0-BCD5-BA03387BDA58}"= UDP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite "{C6818DF6-D2B6-4AE2-8082-5B221017FB10}"= TCP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite "{FEE6F50A-CA25-4205-BC9C-967A78D61733}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{756CD7DB-3BBF-4E96-B9B3-C24F78B6A2AE}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{AEC87814-5A3C-498A-9618-606FC7FBFB4F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{A2610B0B-9ABA-479F-A907-6337CAEA05FA}"= UDP:1187:woonkamer-xp "{1815C41C-767B-4820-9464-B73DBE4E1A80}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{A2F01597-A554-4E3E-AC95-41DB408F36EC}"= TCP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{DD2560E9-1AD0-4E5C-A758-1411E644EF2D}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{B149D83F-913A-4055-AE10-C2868A455E40}"= TCP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "TCP Query User{C6481E2F-A712-40FC-997B-1FA15A3BAF85}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{FC5C88B7-A98C-4F3E-883C-DEC47D334B0A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "{7EFBFE9A-6008-4DF0-A8F3-478FE2ABF230}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{42F03376-CE69-4B0D-828E-2F3D1392799E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{0C4EB289-21CF-4A3E-8588-0167E85BB3A7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent "UDP Query User{99EDE1B8-F06B-426F-BC37-8192062CADDB}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent "{50A032BC-759E-458D-9341-CEB51D69E51B}"= UDP:c:\program files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor "{84683CE4-180A-4C0B-9788-BF3B181D980D}"= TCP:c:\program files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor "{EAF63F68-37E3-4A58-97E2-B5613E1E4786}"= UDP:c:\program files\Autodesk\Backburner\manager.exe:backburner 2.3 manager "{84BC2293-2DC9-4C7D-8479-1F9B5F3ED1CA}"= TCP:c:\program files\Autodesk\Backburner\manager.exe:backburner 2.3 manager "{5BCA7CF0-3ADE-4D77-8412-766073C62F59}"= UDP:c:\program files\Autodesk\Backburner\server.exe:backburner 2.3 server "{9C907333-B331-4108-862A-BCD229DC546B}"= TCP:c:\program files\Autodesk\Backburner\server.exe:backburner 2.3 server "{AE59B844-4AAC-4CFE-BE06-E635930000F6}"= UDP:c:\program files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit "{D0E305DD-F0D9-4F40-8BA6-CCE7DCBF9D42}"= TCP:c:\program files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit "{9BE369F1-5CFF-47F3-B91B-13D43E9DCD21}"= UDP:c:\program files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor "{5D8DE77C-9615-491F-90C6-2EAEEF80FA85}"= TCP:c:\program files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor "{5896E048-492D-4B34-843E-E2D44EA0B80F}"= UDP:c:\program files\Autodesk\Backburner\manager.exe:backburner 2.3 manager "{2E7D2B47-2563-4005-AC20-0521A85D4230}"= TCP:c:\program files\Autodesk\Backburner\manager.exe:backburner 2.3 manager "{60F27DFC-3641-4E39-9F9A-4447AB9381D3}"= UDP:c:\program files\Autodesk\Backburner\server.exe:backburner 2.3 server "{231FB590-67E2-4EEE-BF52-B519F0D8B728}"= TCP:c:\program files\Autodesk\Backburner\server.exe:backburner 2.3 server "{5B9A025F-7162-4D64-AA80-5F9A673F5E74}"= UDP:c:\program files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit "{76C196E6-DE3C-4A59-8D60-B46532B17883}"= TCP:c:\program files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit "{ECA273E8-90D7-4EC3-BB6F-CD788B33A0C1}"= UDP:5353:Adobe CSI CS4 "{8912FD94-3853-4F07-93B3-60576EB3EFA6}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{9E0439EE-4142-49E4-9ED0-383C9FC6C3E6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{842E4603-8D1A-4BEE-9181-34D58B5EA12F}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{1C3F9B79-5A37-45DD-A6BE-0B15773EE41F}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{4FB08617-729C-4691-84EE-BBC125A653C4}"= UDP:3703:Adobe Version Cue CS4 Server "{FB7B7632-D1BF-4D5F-B728-73EE6DBB497C}"= UDP:3704:Adobe Version Cue CS4 Server "{C3C7700D-7BE1-4032-A0C8-09BE9EDB9967}"= UDP:51000:Adobe Version Cue CS4 Server "{01A17B42-CA90-439D-987E-2F170D06454B}"= UDP:51001:Adobe Version Cue CS4 Server "{0CF6A718-92BC-4EA5-B0F8-4710DB358007}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server "{6852116F-3232-4D85-BCCE-E89D16201B3C}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server "{BE1003EE-78D0-4886-B661-A74EC27C4526}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{6B042CD3-6A5C-453C-8A2D-45C519271AA6}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{8305FA02-DF19-42A8-AC14-5A486563A731}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync "{91B8FE41-2CF3-4C97-87F8-B5485952E579}"= inRosettaStoneLtdServices.exe:Rosetta Stone Online Component (inbound) "{FF5244B4-AD7D-4C1A-AB56-A4523D654AD9}"= RosettaStoneVersion3.exe:Rosetta Stone V3 Application (inbound) "{D55E2683-CE38-45BA-BCE6-C965CC0F165C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{08E66EB8-DCBE-4C24-8884-7210F7B19E8D}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\Phase1AuthenticationSets\Anonymous] "Version"= 2.0 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\Phase1AuthenticationSets\Anonymous\0000] "Method"= Anonymous [HKLM\~\services\sharedaccess\parameters\firewallpolicy\Phase1AuthenticationSets\ComputerKerberos] "Version"= 2.0 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\Phase1AuthenticationSets\ComputerKerberos\0000] "Method"= MachineKerb [HKLM\~\services\sharedaccess\parameters\firewallpolicy\Phase2AuthenticationSets\EmptySet] "Version"= 2.0 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [28-7-2009 17:25 604488] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30-3-2009 16:28 1533808] R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\System32\drivers\hssdrv.sys [2-7-2009 4:34 33840] R3 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3-10-2008 18:20 203280] R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [11-1-2009 21:56 3668480] R3 tap0901;TAP-Win32 Adapter V9;c:\windows\System32\drivers\tap0901.sys [15-7-2009 2:01 25472] R3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [17-3-2007 21:37 118784] S2 0018371226590775mcinstcleanup;McAfee Application Installer Cleanup (0018371226590775); [x] S3 flash;flash;c:\windows\System32\drivers\flash.sys [28-7-2009 22:07 7040] S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [15-7-2009 2:02 57640] S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [17-3-2007 19:33 80744] S3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\System32\drivers\ymidusbw.sys [21-7-2009 20:12 33736] S4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15-8-2008 6:46 288112] S4 HssSrv;Hotspot Shield Routing Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [15-6-2009 23:21 331312] S4 PuranDefrag;PuranDefrag;c:\windows\System32\PuranDefragS.exe [16-5-2009 21:05 229376] --- Andere Services/Drivers In Geheugen --- *NewlyCreated* - BONJOUR_SERVICE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Inhoud van de 'Gedeelde Taken' map 2009-08-06 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54] 2009-08-06 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-21 19:19] 2009-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-144886689-3844884146-1124540986-1000Core.job - c:\users\Tar\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-12 21:02] 2009-08-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-144886689-3844884146-1124540986-1000UA.job - c:\users\Tar\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-12 21:02] 2007-08-05 c:\windows\Tasks\McDefragTask.job - c:\program files\mcafee\mqc\QcConsol.exe [2009-03-29 08:53] 2009-03-01 c:\windows\Tasks\McQcTask.job - c:\program files\mcafee\mqc\QcConsol.exe [2009-03-29 08:53] . - - - - ORPHANS VERWIJDERD - - - - ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file) . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.dufpy.com mWindow Title = %USERNAME% op %COMPUTERNAME% uInternet Settings,ProxyOverride = *.local IE: Converteren naar Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Doel van koppeling converteren naar Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Doel van koppeling toevoegen aan bestaande PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Toevoegen aan bestaande PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html Trusted Zone: runescape.com FF - ProfilePath - c:\users\Tar\AppData\Roaming\Mozilla\Firefox\Profiles\nppfxhku.default\ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-06 23:53 Windows 6.0.6002 Service Pack 2 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . --------------------- DLLs Geladen Onder Lopende Processen --------------------- - - - - - - - > 'Explorer.exe'(1640) c:\program files\McAfee\SiteAdvisor\saHook.dll c:\windows\system32\MsnChatHook.dll c:\windows\system32\ShowErrMsg.dll c:\windows\system32\sysenv.dll c:\windows\system32\BatchCrypto.dll c:\windows\system32\CryptoAPI.dll c:\windows\system32\keyManager.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\acer\Empowering Technology\EPOWER\SysHook.dll c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll . Voltooingstijd: 2009-08-06 23:57 ComboFix-quarantined-files.txt 2009-08-06 21:57 ComboFix2.txt 2009-08-05 14:02 ComboFix3.txt 2009-07-01 18:33 Pre-Run: 13.439.922.176 bytes beschikbaar Post-Run: 13.409.476.608 bytes beschikbaar 436 --- E O F --- 2009-08-05 12:24