Juisterr zei:
Download ComboFix van één van deze locaties:
Link 1
Link 2
* BELANGRIJK !!! Sla ComboFix.exe op je Bureaublad op.
>>Hier<< kunt u lezen hoe u Combofix dient te gebruiken.
1. Schakel alle antivirus- en antispywareprogramma's uit, want anders kunnen ze misschien conflicteren met ComboFix.
* (
hier of
hier
2. Het kan voorkomen dat de computer meerdere malen opnieuw gestart moet worden, dit is normaal.
3. Dubbelklik op "
Combofix.exe" om de tool te starten.
4. Klik niet in het scherm van Combofix als deze actief is, hierdoor kan de 'tool' vastlopen.
* Noot !!! Als er een error wordt getoond met de melding "Illegal operation attempted on a registery key that has been marked for deletion." herstart dan de computer.
5. Wanneer ComboFix klaar is, zal het het een logbestand voor je maken. Post de inhoud van dit logbestand (te vinden als C:\ComboFix.txt) in je volgende bericht.
Hier is de gevraagde combofix log:
ComboFix 12-08-04.02 - Kevin&Lynn 04/08/2012 21:27:06.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.4023.2471 [GMT 2:00]
Gestart vanuit: c:\users\Kevin&Lynn\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\BrowserCompanion
c:\program files (x86)\BrowserCompanion\blabbers-ff-full.xpi
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-07-04 to 2012-08-04 ))))))))))))))))))))))))))))))
.
.
2012-08-04 19:34 . 2012-08-04 19:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-08-04 19:34 . 2012-08-04 19:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-04 19:32 . 2012-08-04 19:32 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E658DB08-F96E-4783-B574-A53A7053A4FB}\offreg.dll
2012-08-04 19:18 . 2012-08-04 19:18 -------- d-----w- c:\program files\Synaptics
2012-08-04 08:33 . 2012-07-16 00:40 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E658DB08-F96E-4783-B574-A53A7053A4FB}\mpengine.dll
2012-08-03 14:49 . 2012-08-03 14:49 -------- d-----w- c:\users\Kevin&Lynn\AppData\Roaming\SUPERAntiSpywa re.com
2012-08-03 14:49 . 2012-08-03 14:49 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-08-03 14:49 . 2012-08-03 14:49 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-08-03 14:38 . 2012-08-03 14:38 -------- d-----w- c:\windows\nl
2012-08-03 14:37 . 2012-08-03 14:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2012-08-03 14:35 . 2012-08-03 14:35 -------- d-----w- c:\program files\Windows Live
2012-08-03 14:35 . 2012-08-03 14:35 -------- d-----w- c:\windows\PCHEALTH
2012-08-02 06:32 . 2012-08-02 06:32 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\ElevatedDiagnost ics
2012-08-02 06:24 . 2012-08-02 06:24 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\805f87091cd70770b\DSETUP.dll
2012-08-02 06:24 . 2012-08-02 06:24 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\805f87091cd70770b\DXSETUP.exe
2012-08-02 06:24 . 2012-08-02 06:24 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\805f87091cd70770b\dsetup32.dll
2012-08-02 06:24 . 2012-08-02 06:24 94040 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\7d7416f31cd70770a\DSETUP.dll
2012-08-02 06:24 . 2012-08-02 06:24 525656 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\7d7416f31cd70770a\DXSETUP.exe
2012-08-02 06:24 . 2012-08-02 06:24 1691480 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\7d7416f31cd70770a\dsetup32.dll
2012-07-27 11:48 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-27 11:29 . 2012-07-27 11:29 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-07-27 10:38 . 2012-07-27 10:37 268720 ----a-w- c:\windows\system32\javaws.exe
2012-07-27 10:37 . 2012-07-27 10:37 189360 ----a-w- c:\windows\system32\javaw.exe
2012-07-27 10:37 . 2012-07-27 10:37 188840 ----a-w- c:\windows\system32\java.exe
2012-07-27 07:20 . 2012-08-04 19:20 -------- d-----w- c:\programdata\Kaspersky Lab
2012-07-27 07:20 . 2012-07-27 07:20 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2012-07-27 07:20 . 2012-07-27 07:20 615728 ----a-w- c:\windows\system32\drivers\klif.sys
2012-07-27 07:06 . 2009-12-30 09:21 31800 ----a-w- c:\windows\system32\drivers\revoflt.sys
2012-07-25 23:02 . 2012-07-25 23:02 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\VS Revo Group
2012-07-25 23:02 . 2012-07-25 23:02 -------- d-----w- c:\program files\VS Revo Group
2012-07-25 22:33 . 2012-07-25 22:33 -------- d-----w- c:\users\Kevin&Lynn\AppData\Roaming\Apple Computer
2012-07-25 20:28 . 2012-07-25 20:28 -------- d-----w- c:\programdata\Innovative Solutions
2012-07-25 14:56 . 2012-07-27 13:55 -------- d-----w- C:\kleaner.tmp
2012-07-21 13:16 . 2012-07-21 13:16 -------- d-----w- C:\Temp
2012-07-21 13:12 . 2012-07-21 13:12 -------- d-----w- c:\users\Kevin&Lynn\AppData\Roaming\Samsung
2012-07-21 13:08 . 2012-07-21 13:10 -------- d-----w- c:\program files (x86)\Samsung
2012-07-21 13:08 . 2012-07-21 13:09 -------- d-----w- c:\programdata\Samsung
2012-07-21 13:04 . 2012-07-21 13:07 -------- d-----w- C:\4a49beb7bc07b9ea91fac1
2012-07-21 10:34 . 2012-07-27 11:29 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-07-20 07:57 . 2012-07-20 07:57 -------- d-----w- c:\users\Kevin&Lynn\.thumbnails
2012-07-19 08:41 . 2012-07-19 08:41 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\fontconfig
2012-07-19 08:41 . 2012-07-20 07:58 -------- d-----w- c:\users\Kevin&Lynn\.gimp-2.8
2012-07-19 08:41 . 2012-07-19 08:41 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\gegl-0.2
2012-07-19 07:43 . 2012-07-27 06:59 -------- d-----w- c:\program files\GIMP 2
2012-07-06 11:56 . 2012-07-06 11:56 -------- d-----w- c:\users\Kevin&Lynn\AppData\Roaming\liQeNSoft
2012-07-06 11:56 . 2012-07-27 06:59 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\liQeNSoft
2012-07-06 10:08 . 2012-07-06 10:08 -------- d-----w- c:\users\Kevin&Lynn\AppData\Local\Microsoft Corporation
2012-07-06 10:07 . 2012-07-06 11:01 -------- d-----w- c:\program files (x86)\Microsoft Windows 7 Upgrade Advisor
2012-07-06 10:06 . 2012-07-06 10:06 -------- d-----w- c:\program files (x86)\MSECache
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2012-08-03 14:34 . 2011-03-28 16:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\pp crlconfig600.dll
2012-07-27 11:39 . 2012-03-03 07:32 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-07-27 10:37 . 2012-03-07 16:33 955840 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-07-27 10:37 . 2012-03-07 16:33 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-27 09:58 . 2012-04-01 10:51 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-27 09:58 . 2012-03-03 07:18 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-27 02:14 . 2012-06-27 02:14 4472832 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-06-02 22:19 . 2012-06-25 04:17 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-25 04:17 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-25 04:17 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-25 04:17 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-25 04:17 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-25 04:17 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-25 04:17 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-25 04:16 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-25 04:16 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2012-03-02 19:33 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-05-24 08:47 . 2012-06-07 18:58 24448 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-05-15 04:01 . 2012-06-13 21:18 1188864 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 03:59 . 2012-06-13 21:18 64512 ----a-w- c:\windows\system32\jsproxy.dll
2012-05-15 03:03 . 2012-06-13 21:18 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2012-05-07 09:50 . 2010-05-18 00:20 6656 ----a-w- c:\windows\system32\bcmwlrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ windows\currentversion\explorer\shelliconoverlayid entifiers\KAVOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2011-07-20 13:29 180624 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\shellex.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 5661056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Windows\CurrentVersion\Run]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ windows nt\currentversion\drivers32]
"mixer6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework6 4\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-01 2348352]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 cxbu0x64;OMNIKEY 1021;c:\windows\system32\DRIVERS\cxbu0x64.sys [2011-09-06 177920]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\ DrvAgent64.SYS [2012-04-07 21712]
R3 mdf16;mdf16; [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-08 113120]
R3 mvd23;mvd23; [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revofl t.sys [2009-12-30 31800]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-10-03 258560]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VS TAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VS TDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVER S\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsus bflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-03 1255736]
R3 WISOVD;WISOVD; [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPl ayerUpdateService.exe [2012-07-27 250056]
S0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\DRIVERS\CSCrySec.sys [2009-12-14 85048]
S1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\DRIVERS\CSVirtualDiskDr v.sys [2009-12-14 66104]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-10 29488]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-05-26 913792]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileReposi tory\stwrt64.inf_amd64_neutral_70dacb64382a61a7\AE STSr64.exe [2009-03-03 89600]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz13 5_x64.sys [2011-09-21 21992]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520]
S3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\w indows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-24 29288]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2012-01-31 173656]
S3 johci;JMicron 1394 Filter Driver;c:\windows\system32\DRIVERS\johci.sys [2011-11-30 26200]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 22544]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\ active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhoud van de 'Gedeelde Taken' map
.
2012-07-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [2012-04-01 09:58]
.
2012-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1308235410-1409386186-2256102856-1001Core.job
- c:\users\Kevin&Lynn\AppData\Local\Facebook\Update\ FacebookUpdate.exe [2012-05-01 19:03]
.
2012-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1308235410-1409386186-2256102856-1001UA.job
- c:\users\Kevin&Lynn\AppData\Local\Facebook\Update\ FacebookUpdate.exe [2012-05-01 19:03]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1308235410-1409386186-2256102856-1001Core.job
- c:\users\Kevin&Lynn\AppData\Local\Google\Update\Go ogleUpdate.exe [2012-03-25 16:56]
.
2012-03-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1308235410-1409386186-2256102856-1001UA.job
- c:\users\Kevin&Lynn\AppData\Local\Google\Update\Go ogleUpdate.exe [2012-03-25 16:56]
.
2012-08-03 c:\windows\Tasks\HPCeeScheduleForKevin&Lynn.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\KA VOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2011-07-20 13:29 231824 ----a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\shellex.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://everyoneweb.com/dezeekust/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Toevoegen aan Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
TCP: DhcpNameServer = 195.130.130.5 195.130.131.5
TCP: Interfaces\{BF1148F7-0950-449B-8F2D-18F15F6CBDB0}: NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{BF1148F7-0950-449B-8F2D-18F15F6CBDB0}\4554C454E4544584F4D4543505F445: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Kevin&Lynn\AppData\Roaming\Mozilla\Firefo x\Profiles\pbpwu01u.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/firefox
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B6069f77a-22e7-4ae3-96e3-13da50de06d5%7D&mid=89b2f0915aa247d1873d06a57e8466 f0-15f27b73aa27b229708d769009a3b5ab287dc199&ds=ts023& v=10.0.0.7&lang=nl&pr=sa&d=2012-03-02%2020%3A39%3A01&sap=ku&q=
.
- - - - ORPHANS VERWIJDERD - - - -
.
Wow6432Node-HKCU-Run-fsm - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Mac rome d\\Flash\\FlashUtil32_11_3_300_268_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash Ut il32_11_3_300_268_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash 32 _11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash 32 _11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash 32 _11_3_300_268.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash 32 _11_3_300_268.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\In terface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PC W\Security]
@Denied: (Full) (Everyone)
.
Voltooingstijd: 2012-08-04 21:37:36
ComboFix-quarantined-files.txt 2012-08-04 19:37
.
Pre-Run: 372.507.471.872 bytes beschikbaar
Post-Run: 372.151.603.200 bytes beschikbaar
.
- - End Of File - - 13E0D0281CD91161E6136EA3A293CD52
Mvg,
Kevin
__________________