ComboFix 10-04-02.01 - Brian 03-04-2010 16:52:07.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.1790.1002 [GMT 2:00] Gestart vanuit: c:\users\Brian\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Productregistratie.lnk . (((((((((((((((((((( Bestanden Gemaakt van 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))) . 2010-04-03 14:58 . 2010-04-03 14:58 -------- d-----w- c:\users\Brian\AppData\Local\temp 2010-04-03 14:58 . 2010-04-03 14:58 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-04-03 14:44 . 2010-04-03 14:44 -------- d-----w- c:\users\Brian\AppData\Roaming\Malwarebytes 2010-04-03 14:44 . 2010-03-29 13:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-03 14:44 . 2010-04-03 14:44 -------- d-----w- c:\programdata\Malwarebytes 2010-04-03 14:44 . 2010-03-29 13:24 20824 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-04-03 14:33 . 2010-04-03 14:33 -------- d-----w- c:\program files\Windows Portable Devices 2010-04-03 14:29 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2010-04-03 14:29 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll 2010-04-03 14:29 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll 2010-04-03 14:29 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll 2010-04-03 14:29 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll 2010-04-03 14:29 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll 2010-04-03 14:29 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll 2010-04-03 14:29 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2010-04-03 14:29 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2010-04-03 14:29 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll 2010-04-03 14:29 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll 2010-04-03 14:29 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll 2010-04-03 14:27 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll 2010-04-03 14:27 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-04-03 14:27 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-04-03 14:20 . 2010-04-03 14:20 -------- d-----w- c:\program files\Common Files\Logitech 2010-04-03 14:20 . 2010-04-03 14:20 -------- d-----w- c:\users\Brian\AppData\Local\Downloaded Installations 2010-04-03 14:19 . 2010-04-03 14:19 -------- d-----w- c:\users\Brian\AppData\Roaming\Logitech 2010-04-03 14:19 . 2010-04-03 14:19 53248 ----a-r- c:\users\Brian\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2010-04-03 14:19 . 2010-04-03 14:19 -------- d-----w- c:\users\Brian\AppData\Roaming\Leadertech 2010-04-03 14:17 . 2008-05-02 00:38 301656 ----a-w- c:\windows\system32\BtCoreIf.dll 2010-04-03 14:17 . 2008-05-02 00:40 84496 ----a-w- c:\windows\system32\KemXML.dll 2010-04-03 14:17 . 2008-05-02 00:40 117264 ----a-w- c:\windows\system32\KemWnd.dll 2010-04-03 14:17 . 2008-05-02 00:39 145936 ----a-w- c:\windows\system32\KemUtil.dll 2010-04-03 14:17 . 2008-05-02 00:39 170512 ----a-w- c:\windows\system32\kemutb.dll 2010-04-03 14:17 . 2010-04-03 14:19 -------- d-----w- c:\program files\Common Files\Logishrd 2010-04-03 14:17 . 2010-04-03 14:17 -------- d-----w- c:\programdata\Logitech 2010-04-03 14:17 . 2010-04-03 14:17 -------- d-----w- c:\users\Brian\AppData\Roaming\InstallShield 2010-04-03 14:17 . 2010-04-03 14:17 -------- d-----w- c:\programdata\LogiShrd 2010-04-03 12:45 . 2010-04-03 12:45 -------- d-----w- c:\windows\system32\ca-ES 2010-04-03 12:45 . 2010-04-03 12:45 -------- d-----w- c:\windows\system32\eu-ES 2010-04-03 12:45 . 2010-04-03 12:45 -------- d-----w- c:\windows\system32\vi-VN 2010-04-03 12:30 . 2010-04-03 12:30 -------- d-----w- c:\windows\system32\EventProviders 2010-04-03 12:27 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll 2010-04-03 12:27 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll 2010-04-03 12:27 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe 2010-04-03 12:27 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll 2010-04-03 12:27 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe 2010-04-03 12:27 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll 2010-04-03 12:27 . 2009-04-11 06:28 1480704 ----a-w- c:\windows\system32\mssrch.dll 2010-04-03 12:27 . 2009-04-11 06:28 1576960 ----a-w- c:\windows\system32\tquery.dll 2010-04-03 12:27 . 2009-04-11 02:52 684032 ----a-w- c:\windows\system32\drivers\spsys.sys 2010-04-03 12:25 . 2009-04-11 06:28 867328 ----a-w- c:\windows\system32\wmpmde.dll 2010-04-03 12:24 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll 2010-04-03 12:24 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll 2010-04-03 12:24 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll 2010-04-03 12:24 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll 2010-04-03 12:24 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll 2010-04-03 12:24 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll 2010-04-03 12:24 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll 2010-04-03 12:24 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll 2010-04-03 12:24 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll 2010-04-03 12:24 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe 2010-04-03 12:23 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll 2010-04-03 11:54 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll 2010-04-03 00:42 . 2010-04-03 12:09 -------- d-----w- c:\programdata\Messenger Plus! 2010-04-02 21:58 . 2010-04-03 00:09 -------- d-----w- c:\programdata\WLInstaller 2010-04-02 21:53 . 2009-03-08 11:33 18944 ----a-w- c:\windows\system32\corpol.dll 2010-04-02 21:38 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll 2010-04-02 21:37 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll 2010-04-02 21:37 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll 2010-04-02 21:37 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys 2010-04-02 21:37 . 2010-04-02 21:37 -------- d-----w- c:\program files\MSXML 4.0 2010-04-02 21:34 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe 2010-04-02 21:34 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe 2010-04-02 21:34 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2010-04-02 21:34 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll 2010-04-02 21:34 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-04-02 21:34 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-04-02 21:34 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll 2010-04-02 21:34 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-04-02 21:34 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-04-02 21:33 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll 2010-04-02 21:33 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll 2010-04-02 21:33 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\wlanhlp.dll 2010-04-02 21:33 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll 2010-04-02 21:33 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll 2010-04-02 21:33 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll 2010-04-02 21:33 . 2008-02-29 06:35 6656 ----a-w- c:\windows\system32\kbd106n.dll 2010-04-02 21:33 . 2009-12-08 20:01 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-04-02 21:33 . 2009-12-08 20:01 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-04-02 21:31 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2010-04-02 21:31 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll 2010-04-02 21:31 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe 2010-04-02 21:31 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll 2010-04-02 21:31 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll 2010-04-02 21:31 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe 2010-04-02 21:31 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe 2010-04-02 21:31 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll 2010-04-02 21:29 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll 2010-04-02 21:29 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-04-02 21:29 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll 2010-04-02 21:29 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2010-04-02 21:29 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe 2010-04-02 21:29 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll 2010-04-02 21:29 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2010-04-02 21:29 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll 2010-04-02 21:21 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-04-02 21:21 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-04-02 21:11 . 2009-11-24 22:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2010-04-02 21:11 . 2009-11-24 22:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2010-04-02 21:11 . 2009-11-24 22:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2010-04-02 21:11 . 2009-11-24 22:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2010-04-02 21:11 . 2009-11-24 22:47 97480 ----a-w- c:\windows\system32\AvastSS.scr 2010-04-02 21:11 . 2009-11-24 22:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe 2010-04-02 21:11 . 2009-11-24 22:49 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-04-02 21:10 . 2010-04-02 21:10 -------- d-----w- c:\program files\Alwil Software 2010-04-02 21:08 . 2010-04-02 22:37 -------- d-----w- c:\users\Brian\AppData\Local\Adobe 2010-04-02 21:05 . 2008-03-28 08:07 20992 ----a-w- c:\users\Brian\AppData\Roaming\Convivea\Bit_Che\languages\compare.exe 2010-04-02 21:05 . 2010-04-02 21:05 -------- d-----w- c:\users\Brian\AppData\Roaming\Convivea 2010-04-02 21:05 . 2008-03-28 08:04 58368 ----a-w- c:\users\Brian\AppData\Roaming\Convivea\Bit_Che\scripts\special.exe 2010-04-02 21:05 . 2008-03-28 08:02 60928 ----a-w- c:\users\Brian\AppData\Roaming\Convivea\Bit_Che\scripts\update.exe 2010-04-02 21:05 . 2008-03-28 08:01 59904 ----a-w- c:\users\Brian\AppData\Roaming\Convivea\Bit_Che\scripts\x.exe 2010-04-02 21:05 . 2003-08-19 03:06 80896 ----a-w- c:\users\Brian\AppData\Roaming\Convivea\Bit_Che\scripts\x.dll 2010-04-02 21:04 . 2010-04-02 21:04 -------- d-----w- c:\users\Brian\AppData\Roaming\vlc 2010-04-02 20:38 . 2010-04-03 14:26 -------- d-----w- c:\users\Brian\AppData\Roaming\uTorrent 2010-04-02 20:37 . 2010-04-02 20:37 -------- d-----w- c:\users\Brian\AppData\Roaming\Stardock 2010-04-02 20:26 . 2010-04-02 20:26 -------- d-----w- c:\windows\Acer_Wide . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-03 14:40 . 2008-01-21 06:47 667114 ----a-w- c:\windows\system32\perfh013.dat 2010-04-03 14:40 . 2008-01-21 06:47 126648 ----a-w- c:\windows\system32\perfc013.dat 2010-04-03 14:33 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2010-04-03 14:33 . 2010-04-03 14:33 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-04-03 14:21 . 2010-04-03 14:21 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2010-04-03 14:21 . 2010-04-03 14:21 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf 2010-04-03 14:17 . 2008-05-08 18:14 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-04-03 12:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar 2010-04-03 12:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery 2010-04-03 12:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal 2010-04-03 12:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration 2010-04-03 12:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar 2010-04-03 12:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-04-03 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender 2010-04-03 12:43 . 2008-05-08 18:23 -------- d-----w- c:\programdata\NVIDIA 2010-04-02 23:35 . 2010-04-02 21:58 -------- d-----w- c:\program files\Windows Live 2010-04-02 23:35 . 2010-04-02 21:58 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller 2010-04-02 23:13 . 2010-04-02 23:13 -------- dc-h--w- c:\programdata\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B} 2010-04-02 22:55 . 2010-04-02 22:39 -------- d-----w- c:\program files\NVIDIA Corporation 2010-04-02 22:54 . 2010-04-02 22:44 34895 ----a-w- c:\programdata\nvModes.dat 2010-04-02 22:39 . 2008-05-08 19:05 -------- d-----w- c:\program files\Microsoft Works 2010-04-02 22:38 . 2010-04-02 22:38 -------- d-----w- c:\program files\Microsoft Silverlight 2010-04-02 22:32 . 2010-04-02 20:21 69840 ----a-w- c:\users\Brian\AppData\Local\GDIPFONTCACHEV1.DAT 2010-04-02 20:56 . 2008-05-08 19:03 -------- d-----w- c:\programdata\Microsoft Help 2010-04-02 20:45 . 2008-05-08 18:36 -------- d-----w- c:\programdata\McAfee 2010-04-02 20:33 . 2008-05-08 19:13 -------- d-----w- c:\program files\Yahoo! 2010-04-02 20:29 . 2008-05-08 18:38 -------- d-----w- c:\programdata\SiteAdvisor 2010-04-02 20:21 . 2008-05-08 18:33 -------- d-----w- c:\program files\Acer 2010-02-23 06:39 . 2010-04-02 21:54 916480 ----a-w- c:\windows\system32\wininet.dll 2010-02-23 06:33 . 2010-04-02 21:54 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-02-23 06:33 . 2010-04-02 21:54 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-02-23 04:55 . 2010-04-02 21:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2010-02-12 10:48 . 2010-04-02 22:57 293376 ----a-w- c:\windows\system32\browserchoice.exe 2010-01-23 09:26 . 2010-04-02 21:30 2048 ----a-w- c:\windows\system32\tzres.dll 2010-01-06 15:38 . 2010-04-03 14:27 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-01-06 15:38 . 2010-04-03 14:27 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll 2010-01-06 15:38 . 2010-04-03 14:27 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-01-06 15:38 . 2010-04-03 14:27 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2010-04-03 5724184] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 319488] "EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 319488] "eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896] "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040] "WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "Skytel"="Skytel.exe" [2007-11-20 1826816] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - d:\program files\SetPoint\SetPoint.exe [2010-4-3 805392] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "d:\program files\Fences\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):d5,8f,cd,4e,2c,d3,ca,01 R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072] S1 aswSP;avast! Self Protection; [x] S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 269448] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560] S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328] S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384] S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-04-25 24576] S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-04-22 43552] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.nl/ mStart Page = hxxp://nl.intl.acer.yahoo.com LSP: %SYSTEMROOT%\system32\nvLsp.dll . - - - - ORPHANS VERWIJDERD - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKLM-Run-eRecoveryService - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-03 16:58 Windows 6.0.6002 Service Pack 2 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . Voltooingstijd: 2010-04-03 17:00:58 ComboFix-quarantined-files.txt 2010-04-03 15:00 Pre-Run: 127.559.606.272 bytes beschikbaar Post-Run: 127.143.452.672 bytes beschikbaar - - End Of File - - C981122BBEDAAE73A5FB98BCD8ACF4C1