Ziehier de combofix log. En wat zegt dit? 'k Heb er geen idee van. Wat is de volgende stap?
ComboFix 11-12-03.01 - Patrick 03/12/2011 20:05:06.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.32.1043.18.511.283 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Patrick.PATRICK-H20DJRL\Bureaublad\ComboFix.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: PC Cleaners *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB}
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-11-03 to 2011-12-03 ))))))))))))))))))))))))))))))
.
.
2011-12-03 15:45 . 2011-12-03 15:45 -------- d-----w- c:\program files\Microsoft.NET
2011-12-03 15:37 . 2011-12-03 15:37 -------- d-----w- c:\program files\OSDSoft
2011-12-03 15:37 . 2011-12-03 15:37 -------- d-----w- c:\program files\Common Files\OSDSoft
2011-12-02 10:42 . 2011-12-02 10:42 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\NeroDigital(TM)
2011-12-01 19:34 . 2011-12-01 19:34 -------- dc----w- C:\$AVG
2011-12-01 17:17 . 2011-12-01 17:17 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\AVG2012
2011-12-01 17:09 . 2011-12-03 12:35 -------- d-----w- c:\windows\system32\drivers\AVG
2011-12-01 17:09 . 2011-12-01 17:22 -------- dc----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG2012
2011-12-01 17:07 . 2011-12-01 17:07 -------- d-----w- c:\program files\AVG
2011-12-01 16:58 . 2011-12-01 16:58 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\Common Files
2011-12-01 16:56 . 2011-12-03 12:35 -------- dc----w- c:\documents and settings\All Users.WINDOWS\Application Data\MFAData
2011-12-01 16:54 . 2011-12-03 18:43 -------- d--h--r- c:\documents and settings\Patrick.PATRICK-H20DJRL\Onlangs geopend
2011-11-30 15:39 . 2011-11-30 15:39 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\Uniblue
2011-11-30 15:39 . 2011-11-30 15:39 -------- d-----w- c:\program files\Uniblue
2011-11-30 11:08 . 2011-11-30 11:08 -------- d-----w- c:\program files\microsoft frontpage
2011-11-29 15:51 . 2011-11-29 15:51 -------- d-----w- c:\windows\system32\wbem\Repository
2011-11-29 13:17 . 2011-11-29 13:17 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\Genie-Soft
2011-11-25 11:58 . 2011-11-25 11:58 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\.swt
2011-11-25 11:58 . 2011-12-01 16:54 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\Azureus
2011-11-25 11:55 . 2011-11-25 11:57 -------- d-----w- c:\program files\Vuze
2011-11-25 11:55 . 2011-11-25 12:24 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\Local Settings\Application Data\Conduit
2011-11-25 11:39 . 2011-11-25 11:39 -------- dc----w- c:\documents and settings\All Users.WINDOWS\Application Data\Premium
2011-11-25 11:39 . 2011-11-25 11:43 -------- dc----w- c:\documents and settings\All Users.WINDOWS\Application Data\InstallMate
2011-11-22 19:01 . 2011-11-22 19:23 -------- d-----w- c:\program files\Unlocker
2011-11-21 12:32 . 2011-11-21 12:32 -------- d-----w- c:\program files\CCleaner
2011-11-21 10:16 . 2011-11-21 10:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PC1Data
2011-11-19 08:14 . 2011-11-19 08:14 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-13 19:12 . 2011-12-01 16:51 -------- d-----w- c:\program files\CPUID
2011-11-08 09:15 . 2011-11-10 16:33 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-11-08 09:15 . 2011-11-10 16:33 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-11-08 09:15 . 2011-11-10 16:33 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-11-08 09:15 . 2011-11-10 16:33 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-11-08 09:15 . 2011-11-10 16:33 1989592 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-11-08 09:15 . 2011-11-10 16:33 801752 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-11-08 09:15 . 2011-09-29 00:26 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-11-08 09:15 . 2011-09-29 00:26 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-11-07 11:36 . 2011-11-07 11:36 -------- d-----w- c:\documents and settings\Patrick.PATRICK-H20DJRL\DoctorWeb
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:16 . 2003-05-22 19:30 5359888 ----a-w- c:\windows\uninst.exe
2011-10-10 14:22 . 2004-03-02 11:18 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 05:23 . 2011-10-07 05:23 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 05:21 . 2011-10-04 05:21 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-10-03 03:06 . 2010-05-13 10:48 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-28 07:06 . 2002-09-23 14:11 602624 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 614912 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-09-07 12:00 23040 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-09-07 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-13 05:30 . 2011-09-13 05:30 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-06 14:09 . 2001-09-07 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 16:33 . 2011-11-08 09:15 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedUpMyPC"="c:\progra~1\Uniblue\SPEEDU~1\launcher.exe" [2011-10-19 67960]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-24 2415456]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"c:\\Program Files\\InterVideo\\WinRip\\WinRip.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/07/2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13/09/2011 6:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/10/2011 6:23 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/07/2011 1:14 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/08/2011 6:09 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/07/2011 1:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/07/2011 1:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [4/10/2011 6:21 16720]
R3 ham50;Creatix V.90 HAM Data Fax Modem;c:\windows\system32\drivers\CTXH51.sys [7/11/2001 12:47 454815]
S2 Ca533av;Cam 3200, WDM Video Capture;c:\windows\system32\drivers\CA533AV.SYS [26/11/2003 15:45 515803]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 6:25 4433248]
S3 Camdrv30;Philips ToUcam XS;c:\windows\system32\drivers\camdrv30.sys [3/05/2003 17:55 171264]
S3 SampleScanner;USB Flatbed Scanner Driver;c:\windows\system32\DRIVERS\ArtecGT.sys --> c:\windows\system32\DRIVERS\ArtecGT.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - CLR_OPTIMIZATION_V4.0.30319_32
.
Inhoud van de 'Gedeelde Taken' map
.
2011-12-03 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-11-30 14:28]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://mail.yahoo.com/?.intl=us
mSearch Bar =
uInternet Settings,ProxyOverride = <local>
IE: Word Explorer starten
IE: Zoek op het web
IE: {{ECC5777A-6E88-BFCE-13CE-81F134789E7B}
TCP: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {660B74E4-4E01-43DE-BB13-2BA2D643C05A} - hxxps://internetbanking.argenta.be/multisecure/smartstart/Win32/SmartStartCtl.cab
FF - ProfilePath - c:\documents and settings\Patrick.PATRICK-H20DJRL\Application Data\Mozilla\Firefox\Profiles\tip6m0mw.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
.
- - - - ORPHANS VERWIJDERD - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-12-03 20:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
.
- - - - - - - > 'explorer.exe'(3752)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Voltooingstijd: 2011-12-03 20:24:03
ComboFix-quarantined-files.txt 2011-12-03 19:23
.
Pre-Run: 35.433.582.592 bytes beschikbaar
Post-Run: 35.604.545.536 bytes beschikbaar
.
- - End Of File - - 24B26A7E84C3ACFBE23894228F150178