ComboFix 11-06-07.03 - Gebruiker 08/06/2011 14:53:42.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.1918.1389 [GMT 2:00] Gestart vanuit: c:\documents and settings\Gebruiker\Bureaublad\ComboFix.exe AV: ESET NOD32 antivirus system 2.70 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} AV: Lavasoft Ad-Watch Live! Antivirus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} * Aanwezig AV is actief . . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Documenten\Settings c:\documents and settings\Gebruiker\Application Data\Adobe\plugs c:\documents and settings\Gebruiker\Application Data\Adobe\shed c:\documents and settings\Gebruiker\bdzmeg.bak c:\documents and settings\Gebruiker\Bureaublad\Windows XP Recovery.lnk c:\documents and settings\Gebruiker\glmquw.bak c:\documents and settings\Gebruiker\kqdvi.bak c:\documents and settings\Gebruiker\Menu Start\Programma's\Windows XP Recovery c:\documents and settings\Gebruiker\Menu Start\Programma's\Windows XP Recovery\Uninstall Windows XP Recovery.lnk c:\documents and settings\Gebruiker\Menu Start\Programma's\Windows XP Recovery\Windows XP Recovery.lnk c:\documents and settings\Gebruiker\nklsuv.bak c:\documents and settings\Gebruiker\pcskyv.bak C:\LOG27B6.tmp C:\LOG456F.tmp C:\LOG4576.tmp c:\windows\SNMPAPI.DLL . Besmet exemplaar van c:\windows\system32\drivers\tcpip.sys werd aangetroffen en gedesinfecteerd Hersteld exemplaar van - Kitty had a snack :p . (((((((((((((((((((( Bestanden Gemaakt van 2011-05-08 to 2011-06-08 )))))))))))))))))))))))))))))) . . 2011-06-06 07:50 . 2011-06-06 07:50 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo! 2011-06-06 07:50 . 2011-06-06 07:50 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe 2011-06-06 07:47 . 2011-06-06 07:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\RCP 5 2011-06-06 07:27 . 2011-06-06 07:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2011-06-01 13:50 . 2011-06-08 13:08 -------- d--h--r- c:\documents and settings\Gebruiker\Onlangs geopend 2011-06-01 10:41 . 2011-06-01 13:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent 2011-06-01 10:23 . 2011-06-01 10:23 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-06-01 10:23 . 2011-06-01 10:23 -------- d-----w- c:\program files\Trend Micro 2011-06-01 10:22 . 2011-06-01 10:22 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE 2011-06-01 09:21 . 2011-06-01 10:03 -------- d-----w- C:\sh4ldr 2011-06-01 09:21 . 2011-06-01 09:21 -------- d-----w- c:\program files\Enigma Software Group 2011-06-01 09:21 . 2011-06-01 10:11 -------- d-----w- c:\windows\820C0EEB9B124AD5B39DD15ED1DBDD06.TMP 2011-06-01 09:20 . 2011-06-01 09:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2011-05-20 13:15 . 2010-11-29 09:42 35136 ----a-w- c:\program files\Mozilla Firefox\plugins\np_gp.dll 2011-05-20 13:15 . 2011-05-20 13:15 -------- d--h--w- c:\documents and settings\All Users\Application Data\NOS 2011-05-20 13:15 . 2011-05-20 13:15 -------- d-----w- c:\program files\NOS 2011-05-20 13:13 . 2011-04-14 16:57 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll 2011-05-20 13:13 . 2011-04-14 16:57 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll 2011-05-20 13:13 . 2011-04-14 16:57 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll 2011-05-20 13:13 . 2011-04-14 16:57 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll 2011-05-20 13:13 . 2011-04-14 16:57 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll 2011-05-20 13:13 . 2011-04-14 16:57 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll 2011-05-20 13:13 . 2010-01-01 08:00 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll 2011-05-20 13:13 . 2010-01-01 08:00 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-29 07:11 . 2010-08-02 14:36 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 07:11 . 2010-08-02 14:36 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-18 14:37 . 2011-03-11 09:12 0 ----a-w- c:\windows\system32\ConduitEngine.tmp 2011-04-18 10:23 . 2010-08-02 14:32 16432 ----a-w- c:\windows\system32\lsdelete.exe 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2011-04-14 16:57 . 2011-05-20 13:13 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2004-08-04 02:00 94784 --sh--w- c:\windows\twain.dll 2008-04-14 17:02 50688 --sh--w- c:\windows\twain_32.dll 2006-02-16 20:33 1216 --sh--w- c:\windows\Twunk_16.dll 2006-02-16 20:33 1216 --sh--w- c:\windows\Twunk_32.dll 2008-04-14 17:02 1028096 --sh--w- c:\windows\system32\mfc42.dll 2008-04-14 17:02 57344 --sh--w- c:\windows\system32\msvcirt.dll 2008-04-14 17:02 413696 --sha-w- c:\windows\system32\msvcp60.dll 2008-04-14 17:02 343040 --sha-w- c:\windows\system32\msvcrt.dll 2008-04-14 17:02 551936 --sh--w- c:\windows\system32\oleaut32.dll 2008-04-14 17:02 84992 --sh--w- c:\windows\system32\olepro32.dll 2008-04-14 17:03 12288 --sh--w- c:\windows\system32\regsvr32.exe . [code]
c:\program files\ATI Technologies\ATI Control Panel\atiptaxx .exe c:\program files\Common Files\InstallShield\UpdateService\issch .exe c:\program files\Compaq\SetRefresh\SetRefresh .exe c:\program files\HP\HP Software Update\HPWuSchd2 .exe c:\program files\HP\hpcoretech\hpcmpmgr .exe c:\program files\Java\jre6\bin\jusched .exe c:\program files\TomTom HOME 2\TomTomHOMERunner .exe c:\windows\system32\rundll32 .exe[/code] . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-12-10 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\ Snelkoppeling naar Startup.lnk - c:\batch\Startup.bat [2009-1-21 27] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Adobe Reader Snelle start.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\Adobe Reader Snelle start.lnk backup=c:\windows\pss\Adobe Reader Snelle start.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^HPAiODevice(hp officejet v series) - 1.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\HPAiODevice(hp officejet v series) - 1.lnk backup=c:\windows\pss\HPAiODevice(hp officejet v series) - 1.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Sonic CinePlayer Quick Launch.lnk] path=c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\Sonic CinePlayer Quick Launch.lnk backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Gebruiker^Menu Start^Programma's^Opstarten^LimeWire On Startup.lnk] path=c:\documents and settings\Gebruiker\Menu Start\Programma's\Opstarten\LimeWire On Startup.lnk backup=c:\windows\pss\LimeWire On Startup.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA] c:\program files\DNA\btdna.exe [N/A] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 17:02 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Free Codec] 2007-03-30 02:44 274432 ----a-w- c:\program files\DivX Free Codec\Divx Free Update.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA] 2005-09-28 03:10 122940 ----a-w- c:\windows\system32\DLA\DLACTRLW.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] 2004-07-27 14:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui] 2007-04-02 07:00 949376 ----a-w- c:\program files\ESET\nod32kui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\scheduler_monitor] 2007-06-15 08:17 27136 ----a-w- c:\program files\ReaConverter 5.5 Pro\init_scheduler.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2010-12-10 11:39 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= . R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [17/06/2009 15:01 20744] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/08/2010 14:38 64288] R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2/04/2007 9:00 15424] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/07/2010 10:55 2151128] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/08/2010 16:36 366640] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [3/06/2009 14:46 92008] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/08/2010 16:36 22712] S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2010 13:39 136176] S2 rbhfnfjc;IPX Traffic Filter Support;c:\windows\System32\svchost.exe -k netsvcs [4/08/2004 4:00 14336] S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [17/06/2009 15:02 29192] S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2010 13:39 136176] S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [17/06/2009 15:01 25480] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2/08/2010 16:36 39984] S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [4/08/2004 4:00 14336] S3 rcp_service;ReaConverter scheduler service;c:\program files\ReaConverter 5.5 Pro\rcp_scheduler.exe [30/11/2007 11:27 558592] S3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21/04/2007 15:54 52080] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs rbhfnfjc . Inhoud van de 'Gedeelde Taken' map . 2011-06-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 09:11] . 2011-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-10 11:39] . 2011-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-10 11:39] . 2011-04-08 c:\windows\Tasks\pixillionShakeIcon.job - c:\program files\NCH Software\Pixillion\pixillion.exe [2011-01-05 08:33] . 2010-12-23 c:\windows\Tasks\switchShakeIcon.job - c:\program files\NCH Swift Sound\Switch\switch.exe [2010-12-23 08:01] . . ------- Bijkomende Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride =