ComboFix 11-06-10.09 - Niels 11/06/2011 9:52.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3071.1836 [GMT 2:00] Gestart vanuit: c:\users\Niels\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\bf2_modtools\BF2_ModTools.exe c:\program files\AutocompletePro c:\program files\AutocompletePro\64\AutocompletePro64.dll c:\program files\AutocompletePro\chrome\autocompleteprochrome.crx c:\program files\AutocompletePro\ChromeSetSearchInBrowser.exe c:\program files\AutocompletePro\FireFoxExtension.exe c:\program files\AutocompletePro\InstTracker.exe c:\program files\AutocompletePro\support@predictad.com\chrome.manifest c:\program files\AutocompletePro\support@predictad.com\chrome\content\browserOverlay.xul c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.js c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.xul c:\program files\AutocompletePro\support@predictad.com\chrome\content\utils.js c:\program files\AutocompletePro\support@predictad.com\defaults\preferences\predictad.js c:\program files\AutocompletePro\support@predictad.com\install.rdf c:\program files\AutocompletePro\unins000.dat c:\program files\AutocompletePro\unins000.exe c:\program files\Hotspot Shield\hssie\HsSIe.dll c:\windows\system\MFC40.DLL c:\windows\system\MFC40.DLL\MFC40.DLL c:\windows\system\Mfc42.dll c:\windows\system\Mfc42.dll\Mfc42.dll c:\windows\system\MSVCIRT.DLL c:\windows\system\MSVCIRT.DLL\MSVCIRT.DLL c:\windows\system\Msvcrt.dll c:\windows\system\Msvcrt.dll\Msvcrt.dll c:\windows\system\MSVCRT40.DLL c:\windows\system\MSVCRT40.DLL\MSVCRT40.DLL c:\windows\system32\Drivers\qkjxx.sys c:\windows\system32\vb5ko.dll c:\windows\system32\vb5ko.dll\vb5ko.dll c:\windows\system32\videocore.dll c:\windows\TEMP\jna75409168969689725.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_gjmruwvv . . (((((((((((((((((((( Bestanden Gemaakt van 2011-05-11 to 2011-06-11 )))))))))))))))))))))))))))))) . . 2011-06-11 08:02 . 2011-06-11 08:02 -------- d-----w- c:\users\Niels\AppData\Local\temp 2011-06-11 08:02 . 2011-06-11 08:02 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-06-11 08:02 . 2011-06-11 08:02 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2011-06-11 07:46 . 2011-06-11 07:48 -------- d-----w- C:\32788R22FWJFW 2011-06-10 16:28 . 2011-06-10 16:28 -------- d-----w- c:\users\Niels\AppData\Local\4A0B~1 2011-06-10 16:28 . 2011-06-10 16:28 -------- d-----w- c:\users\Niels\AppData\Local\PS3 2011-06-10 15:29 . 2011-06-10 15:28 249856 ----a-w- c:\windows\rcptinf.exe 2011-06-10 15:12 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{77481251-653F-4CE8-A652-746C446CFCCB}\mpengine.dll 2011-06-08 20:12 . 2011-06-08 20:12 -------- d-----w- C:\Hotspot Shield 2011-06-08 20:11 . 2011-06-03 23:56 330600 ----a-w- c:\windows\system32\HMIPCore.dll 2011-06-08 20:11 . 2011-06-10 15:13 -------- d-----w- c:\program files\Hide My IP 2011-06-08 20:10 . 2011-06-08 20:12 -------- d-----w- c:\program files\Hotspot Shield 2011-06-05 10:00 . 2011-06-05 15:27 -------- d-----w- c:\users\Niels\AppData\Roaming\.minecraft 2011-06-05 09:57 . 2011-06-05 09:57 -------- d-----w- c:\users\Niels\AppData\Roaming\MinecraftTools 2011-06-04 20:40 . 2011-06-04 20:40 -------- d-----w- c:\users\Niels\.dvdcss 2011-06-04 20:32 . 2011-06-04 20:32 -------- d-----w- c:\programdata\PMS 2011-05-28 09:43 . 2011-06-04 20:27 -------- d-----w- c:\users\Niels\AppData\Roaming\TwonkyMedia 2011-05-28 09:42 . 2011-05-28 09:43 -------- d-----w- c:\program files\TwonkyMedia 2011-05-28 09:03 . 2011-05-28 09:03 -------- d-----w- c:\users\Niels\AppData\Roaming\Nero 2011-05-28 08:54 . 2011-05-28 08:54 -------- d-----w- c:\users\NeroMediaHomeUser.4 2011-05-28 08:54 . 2011-05-28 08:55 -------- d-----w- c:\program files\Nero 2011-05-23 18:18 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll 2011-05-23 18:18 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll 2011-05-23 18:10 . 2011-05-23 18:11 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2011-05-22 19:42 . 2011-05-22 19:42 -------- d-----w- c:\program files\Download Movie Subtitles 3.0 2011-05-22 17:51 . 2011-05-22 17:52 -------- d-----w- c:\program files\PdaNet for Android 2011-05-21 10:39 . 2011-05-21 10:39 -------- d-----w- c:\programdata\ATI 2011-05-21 10:12 . 2011-05-22 19:51 -------- d-----w- c:\windows\system32\RTCOM 2011-05-21 10:10 . 2011-05-21 10:13 -------- d--h--w- c:\program files\Temp 2011-05-21 10:10 . 2010-10-28 08:46 1251944 ----a-w- c:\windows\RtlExUpd.dll 2011-05-21 10:10 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll 2011-05-21 10:10 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll 2011-05-21 10:10 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll 2011-05-21 10:10 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll 2011-05-21 10:10 . 2005-11-13 21:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe 2011-05-21 10:10 . 2011-05-21 10:10 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll 2011-05-21 10:10 . 2011-05-21 10:10 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll 2011-05-21 10:03 . 2011-05-21 10:03 -------- d-----w- c:\program files\Driver-Soft 2011-05-21 09:56 . 2011-05-21 09:56 -------- d-----w- c:\programdata\Easy Driver Pro 2011-05-19 15:55 . 2007-05-30 14:31 311394 ----a-w- c:\windows\system32\PS2DMiniDrv.dll 2011-05-19 15:55 . 2006-06-16 12:19 303186 ----a-w- c:\windows\system32\MKCoInstaller.dll 2011-05-19 15:55 . 2006-06-16 11:50 12416 ----a-w- c:\windows\system32\drivers\GT680X.SYS 2011-05-18 16:35 . 2011-05-18 16:36 -------- d-----w- c:\program files\Common Files\DivX Shared 2011-05-18 16:35 . 2011-05-18 16:36 -------- d-----w- c:\program files\DivX 2011-05-18 16:35 . 2011-05-18 16:36 -------- d-----w- c:\programdata\DivX 2011-05-18 12:36 . 2011-05-18 12:36 -------- d-----w- c:\programdata\regid.1986-12.com.adobe 2011-05-18 12:35 . 2011-05-22 19:45 -------- d-----w- c:\program files\Movie Subtitles Searcher 2011-05-18 12:33 . 2011-05-18 12:33 -------- d-----w- c:\program files\Adobe Media Player 2011-05-18 12:31 . 2011-05-18 12:31 -------- d-----w- c:\program files\Common Files\Adobe AIR 2011-05-17 16:15 . 2011-05-17 16:15 -------- d-----w- c:\program files\StreamTransport 2011-05-17 16:15 . 2009-10-27 17:31 3982240 ----a-w- c:\windows\system32\Flash10d.ocx 2011-05-16 20:29 . 2011-06-03 18:14 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-16 19:53 . 2011-05-16 19:53 -------- d-----w- c:\users\Niels\AppData\Roaming\dvdcss 2011-05-16 15:01 . 2011-05-16 15:01 -------- d-----w- c:\program files\Prolific 2011-05-16 14:59 . 2007-02-12 15:55 75776 ----a-w- c:\windows\system32\drivers\ser2pl.sys 2011-05-16 14:59 . 2011-05-16 14:59 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll 2011-05-16 14:59 . 2011-05-16 14:59 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll 2011-05-16 14:59 . 2004-10-22 00:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll 2011-05-16 14:59 . 2004-10-22 00:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll 2011-05-16 14:59 . 2004-10-22 00:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll 2011-05-16 14:59 . 2004-10-22 00:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll 2011-05-16 14:59 . 2004-10-22 00:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe 2011-05-15 21:20 . 2011-05-15 21:20 -------- d-----w- c:\users\Niels\AppData\Roaming\f-secure 2011-05-15 21:20 . 2011-05-15 21:20 -------- d-----w- c:\programdata\F-Secure 2011-05-15 20:54 . 2011-05-15 20:54 388096 ----a-r- c:\users\Niels\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-05-15 20:54 . 2011-05-15 20:54 -------- d-----w- c:\program files\Trend Micro 2011-05-15 20:44 . 2011-05-15 20:44 -------- d-----w- c:\program files\Sothink Movie DVD Maker 2011-05-15 20:44 . 2009-03-17 15:38 70656 ----a-w- c:\windows\system32\RLAPEDec.ax 2011-05-15 20:41 . 2011-05-15 20:41 -------- d-----w- c:\program files\Sothink DVD Ripper 2011-05-15 13:14 . 2011-05-15 22:13 -------- d-----w- c:\users\andere 2011-05-14 23:04 . 2008-12-08 10:53 57344 ----a-w- c:\windows\system32\ff_vfw.dll 2011-05-14 23:04 . 2008-06-08 20:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll 2011-05-14 23:04 . 2011-05-15 20:45 -------- d-----w- c:\program files\ffdshow 2011-05-14 23:04 . 2011-05-14 23:04 -------- d-----w- c:\program files\Haali 2011-05-14 23:04 . 2011-05-15 20:44 -------- d-----w- c:\program files\AviSynth 2.5 2011-05-14 23:04 . 2011-05-14 23:04 -------- d-----w- c:\program files\Common Files\SourceTec 2011-05-14 23:04 . 2010-07-15 09:30 290816 ----a-w- c:\windows\system32\stFLVSource.ax 2011-05-14 23:04 . 2009-08-17 07:54 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll 2011-05-14 23:03 . 2011-05-14 23:03 -------- d-----w- c:\users\Niels\AppData\Roaming\AMozilla 2011-05-14 23:03 . 2011-05-14 23:03 -------- d-----w- c:\program files\SourceTec 2011-05-14 23:03 . 2009-08-17 07:54 438272 ----a-w- c:\windows\system32\Mpeg2DecFilter.ax 2011-05-14 23:03 . 2009-08-17 07:54 217088 ----a-w- c:\windows\system32\CoreFLACDecoder.ax 2011-05-12 16:24 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-29 07:11 . 2011-04-30 14:55 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 07:11 . 2011-04-30 14:55 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-08 16:00 . 2011-05-08 16:00 6656 ----a-w- c:\windows\system32\drivers\UMDF\nl-NL\WpdMtpDr.dll.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\umbus.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\gpr400.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3072 ----a-w- c:\windows\system32\drivers\nl-NL\serscan.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3072 ----a-w- c:\windows\system32\drivers\nl-NL\cxbp0wdm.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 2560 ----a-w- c:\windows\system32\drivers\nl-NL\wd.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\SCR111.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\scmstcs.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\pscr.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\grserial.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\stcusb.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3072 ----a-w- c:\windows\system32\drivers\nl-NL\cmbp0wdm.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\nl-NL\LMPRTPRC.DLL.mui 2011-05-08 16:00 . 2011-05-08 16:00 5120 ----a-w- c:\windows\system32\drivers\nl-NL\pcmcia.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 5632 ----a-w- c:\windows\system32\drivers\nl-NL\nv4_mini.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4608 ----a-w- c:\windows\system32\drivers\nl-NL\ntrigdigi.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 6656 ----a-w- c:\windows\system32\drivers\nl-NL\yk60x86.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 5632 ----a-w- c:\windows\system32\drivers\nl-NL\bcm4sbxp.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\parport.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\rndismpx.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\parvdm.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4608 ----a-w- c:\windows\system32\drivers\nl-NL\msdsm.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3584 ----a-w- c:\windows\system32\drivers\nl-NL\scsiport.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 2560 ----a-w- c:\windows\system32\drivers\nl-NL\amdide.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 9216 ----a-w- c:\windows\system32\drivers\nl-NL\afd.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 4096 ----a-w- c:\windows\system32\drivers\nl-NL\modem.sys.mui 2011-05-08 16:00 . 2011-05-08 16:00 3072 ----a-w- c:\windows\system32\drivers\nl-NL\srv.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 3584 ----a-w- c:\windows\system32\drivers\nl-NL\RNDISMP.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 3584 ----a-w- c:\windows\system32\drivers\nl-NL\pacer.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 3072 ----a-w- c:\windows\system32\drivers\nl-NL\qwavedrv.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 73728 ----a-w- c:\windows\system32\drivers\nl-NL\ntfs.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 3584 ----a-w- c:\windows\system32\drivers\nl-NL\nfsrdr.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 4096 ----a-w- c:\windows\system32\drivers\nl-NL\dxgkrnl.sys.mui 2011-05-08 15:59 . 2011-05-08 15:59 4096 ----a-w- c:\windows\system32\drivers\nl-NL\ipnat.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 5632 ----a-w- c:\windows\system32\drivers\nl-NL\fltmgr.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3072 ----a-w- c:\windows\system32\drivers\nl-NL\pnpmem.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 11264 ----a-w- c:\windows\system32\drivers\nl-NL\ltmdmnt.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 6656 ----a-w- c:\windows\system32\drivers\nl-NL\IPMIDrv.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 4608 ----a-w- c:\windows\system32\drivers\nl-NL\wacompen.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3584 ----a-w- c:\windows\system32\drivers\nl-NL\hidbth.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 11776 ----a-w- c:\windows\system32\drivers\nl-NL\serial.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3072 ----a-w- c:\windows\system32\drivers\nl-NL\Dot4usb.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 5120 ----a-w- c:\windows\system32\drivers\nl-NL\bthpan.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 2560 ----a-w- c:\windows\system32\drivers\nl-NL\BrParwdm.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 11264 ----a-w- c:\windows\system32\drivers\nl-NL\BrSerId.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3584 ----a-w- c:\windows\system32\drivers\nl-NL\atikmdag.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3584 ----a-w- c:\windows\system32\drivers\nl-NL\ati2mtag.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3584 ----a-w- c:\windows\system32\drivers\nl-NL\ati2mpad.sys.mui 2011-05-08 15:58 . 2011-05-08 15:58 3072 ----a-w- c:\windows\system32\drivers\nl-NL\UAGP35.SYS.mui 2011-05-08 15:58 . 2011-05-08 15:58 3072 ----a-w- c:\windows\system32\drivers\nl-NL\GAGP30KX.SYS.mui 2011-05-08 15:58 . 2011-05-08 15:58 12288 ----a-w- c:\windows\system32\drivers\nl-NL\ohci1394.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 40960 ----a-w- c:\windows\system32\drivers\nl-NL\http.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 7168 ----a-w- c:\windows\system32\drivers\nl-NL\luafv.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\wdf01000.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 23040 ----a-w- c:\windows\system32\drivers\nl-NL\e1e6032.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 19968 ----a-w- c:\windows\system32\drivers\nl-NL\E1G60I32.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 6144 ----a-w- c:\windows\system32\drivers\nl-NL\b57nd60x.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 5632 ----a-w- c:\windows\system32\drivers\nl-NL\tpm.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 5120 ----a-w- c:\windows\system32\drivers\nl-NL\e100b325.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 36864 ----a-w- c:\windows\system32\drivers\nl-NL\volsnap.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 6144 ----a-w- c:\windows\system32\drivers\nl-NL\sermouse.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 5120 ----a-w- c:\windows\system32\drivers\nl-NL\mouclass.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3584 ----a-w- c:\windows\system32\drivers\nl-NL\mouhid.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 27648 ----a-w- c:\windows\system32\drivers\nl-NL\mpio.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 15360 ----a-w- c:\windows\system32\drivers\nl-NL\fvevol.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 9216 ----a-w- c:\windows\system32\drivers\nl-NL\pci.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 5632 ----a-w- c:\windows\system32\drivers\nl-NL\kbdclass.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 4608 ----a-w- c:\windows\system32\drivers\nl-NL\isapnp.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3584 ----a-w- c:\windows\system32\drivers\nl-NL\mssmbios.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\VIAAGP.SYS.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\ULIAGPKX.SYS.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\SISAGP.SYS.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\NV_AGP.SYS.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\kbdhid.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\AMDAGP.SYS.mui 2011-05-08 15:57 . 2011-05-08 15:57 3072 ----a-w- c:\windows\system32\drivers\nl-NL\AGP440.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\viac7.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\processr.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\intelppm.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\crusoe.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\amdk8.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 21504 ----a-w- c:\windows\system32\drivers\nl-NL\amdk7.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 11776 ----a-w- c:\windows\system32\drivers\nl-NL\i8042prt.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 10752 ----a-w- c:\windows\system32\drivers\nl-NL\acpi.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 9216 ----a-w- c:\windows\system32\drivers\nl-NL\bthport.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 4096 ----a-w- c:\windows\system32\drivers\nl-NL\vmbus.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 4096 ----a-w- c:\windows\system32\drivers\nl-NL\hdaudbus.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 3584 ----a-w- c:\windows\system32\drivers\nl-NL\vmstorfl.sys.mui 2011-05-08 15:57 . 2011-05-08 15:57 24576 ----a-w- c:\windows\web\ts\bin\nl\TSPortalWebPart.resources.dll 2011-05-08 15:57 . 2011-05-08 15:57 10240 ----a-w- c:\windows\system32\drivers\nl-NL\battc.sys.mui 2011-05-02 16:51 . 2011-05-02 16:51 685816 ----a-w- c:\windows\system32\drivers\sptd.sys 2011-05-01 18:27 . 2011-05-01 18:27 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-05-01 10:28 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll 2011-05-01 10:28 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll 2011-04-30 23:57 . 2011-04-30 23:57 377344 ----a-w- c:\windows\system32\winhttp.dll 2011-04-30 23:55 . 2011-04-30 23:55 36864 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui 2011-04-30 20:35 . 2011-04-30 20:35 37888 ----a-w- c:\windows\system32\printcom.dll 2011-04-30 20:34 . 2011-04-30 20:34 14848 ----a-w- c:\windows\system32\wshrm.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920] "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472] "Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2008-10-01 3622184] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10r_ActiveX.exe" [2011-06-03 240288] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ChangeFilterMerit"="c:\program files\NewSoft\Presto! PVR\ChangeFilterMerit.exe" [2007-06-08 51280] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-12-23 9972328] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-19 336384] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] "Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2008-10-01 3622184] "ctra"="c:\windows\rcptinf.exe" [2011-06-10 249856] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Taskman"="" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3890213903-1528567892-1987025069-1000] "EnableNotifications"=dword:00000001 "EnableNotificationsRef"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-30 135664] R3 cpuz135;cpuz135;c:\users\Niels\AppData\Local\Temp\cpuz135\cpuz135_x32.sys [x] R3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;c:\users\Niels\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys [x] R3 RTL2832UBDA;REALTEK 2832U BDA Driver;c:\windows\system32\drivers\RTL2832UBDA.sys [2010-07-01 188392] R3 RTL2832UUSB;REALTEK 2832U USB Driver;c:\windows\system32\Drivers\RTL2832UUSB.sys [2010-07-01 32872] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-05-02 685816] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-04-20 176128] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] S2 PS3 Media Server;PS3 Media Server;c:\program files\PS3 Media Server\win32\service\wrapper.exe [2011-05-17 366872] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-04-20 7772160] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-04-20 243712] S3 HideMyIpSRV;HideMyIpSRV;c:\program files\Hide My IP\HideMyIpSrv.exe [2011-06-03 3249512] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712] S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSGB6.sys [2008-05-02 48128] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Inhoud van de 'Gedeelde Taken' map . 2011-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-30 14:39] . 2011-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-30 14:39] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.be/ IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html LSP: c:\windows\system32\HMIPCore.dll LSP: c:\windows\system32\wpclsp.dll TCP: DhcpNameServer = 195.130.131.132 195.130.130.4 . - - - - ORPHANS VERWIJDERD - - - - . AddRemove-AutocompletePro3_is1 - c:\program files\AutocompletePro\unins000.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-11 12:35 Windows 6.0.6002 Service Pack 2 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_USERS\S-1-5-21-3890213903-1528567892-1987025069-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*±ò›5] @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-3890213903-1528567892-1987025069-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*±ò›5\OpenWithList] "a"="vlc.exe" "MRUList"="a" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Andere Aktieve Processen ------------------------ . c:\windows\system32\atieclxx.exe c:\program files\Hotspot Shield\bin\openvpnas.exe c:\program files\Hotspot Shield\HssWPR\hsssrv.exe c:\windows\system32\java.exe c:\windows\system32\WUDFHost.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\conime.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\program files\Hotspot Shield\bin\openvpntray.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Internet Explorer\iexplore.exe c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\taskmgr.exe c:\users\andere\AppData\Local\Temp\6941.dir\InstallFlashPlayer.exe . ************************************************************************** . Voltooingstijd: 2011-06-11 12:38:20 - machine werd herstart ComboFix-quarantined-files.txt 2011-06-11 10:38 . Pre-Run: 28.858.421.248 bytes free Post-Run: 31.828.033.536 bytes free . - - End Of File - - 4D84234C8E704F77F45660D96D758A26