ComboFix 10-03-29.04 - Brandon 01/04/2010 20:31:15.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.32.1043.18.447.147 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Brandon\Bureaublad\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ABP470N5
-------\Service_abp470n5
(((((((((((((((((((( Bestanden Gemaakt van 2010-03-01 to 2010-04-01 ))))))))))))))))))))))))))))))
.
2010-03-31 14:40 . 2010-03-31 14:40 -------- d-s---w- c:\documents and settings\Brandon\UserData
2010-03-30 12:50 . 2010-03-30 12:50 -------- d-----w- c:\windows\system32\Adobe
2010-03-25 11:14 . 2010-03-31 11:26 -------- d-----w- c:\documents and settings\Brandon\Application Data\dvdcss
2010-03-21 16:39 . 2010-03-21 16:39 -------- d-----w- c:\windows\Sun
2010-03-21 12:57 . 2010-03-21 12:57 -------- d-----w- c:\program files\Common Files\Java
2010-03-21 12:55 . 2010-03-21 12:55 503808 ----a-w- c:\documents and settings\Brandon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-74b07a74-n\msvcp71.dll
2010-03-21 12:55 . 2010-03-21 12:55 348160 ----a-w- c:\documents and settings\Brandon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-74b07a74-n\msvcr71.dll
2010-03-21 12:55 . 2010-03-21 12:55 499712 ----a-w- c:\documents and settings\Brandon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-74b07a74-n\jmc.dll
2010-03-21 12:55 . 2010-03-21 12:55 61440 ----a-w- c:\documents and settings\Brandon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5341ba5b-n\decora-sse.dll
2010-03-21 12:55 . 2010-03-21 12:55 12800 ----a-w- c:\documents and settings\Brandon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5341ba5b-n\decora-d3d.dll
2010-03-21 12:54 . 2010-03-21 12:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-21 12:53 . 2010-03-21 12:53 -------- d-----w- c:\program files\Java
2010-03-19 16:09 . 2001-08-17 20:47 12928 -c--a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-03-19 16:09 . 2001-08-17 20:47 12928 ----a-w- c:\windows\system32\drivers\Dot4Prt.sys
2010-03-19 16:08 . 2001-09-06 20:26 324608 -c--a-w- c:\windows\system32\dllcache\hpojwia.dll
2010-03-19 16:08 . 2001-09-06 20:26 324608 ----a-w- c:\windows\system32\hpojwia.dll
2010-03-19 16:08 . 2001-08-17 20:47 8704 -c--a-w- c:\windows\system32\dllcache\dot4scan.sys
2010-03-19 16:08 . 2001-08-17 20:47 8704 ----a-w- c:\windows\system32\drivers\Dot4scan.sys
2010-03-19 16:08 . 2001-09-06 18:40 23936 -c--a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-03-19 16:08 . 2001-09-06 18:40 23936 ----a-w- c:\windows\system32\drivers\Dot4usb.sys
2010-03-19 16:08 . 2008-04-13 18:39 206976 -c--a-w- c:\windows\system32\dllcache\dot4.sys
2010-03-19 16:08 . 2008-04-13 18:39 206976 ----a-w- c:\windows\system32\drivers\Dot4.sys
2010-03-19 16:03 . 2010-03-19 16:03 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-03-19 16:01 . 2010-03-19 16:12 -------- d-----w- c:\documents and settings\Brandon\Local Settings\Application Data\Adobe
2010-03-19 11:34 . 2009-08-13 15:24 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2010-03-18 22:06 . 2010-03-18 22:06 105731 ----a-w- c:\documents and settings\Brandon\Application Data\NoNameScript\nnuninstall.exe
2010-03-18 22:06 . 2010-04-01 14:13 -------- d-----w- c:\documents and settings\Brandon\Application Data\NoNameScript
2010-03-18 21:59 . 2010-03-18 21:59 -------- d-----w- c:\windows\system32\nl-nl
2010-03-18 21:59 . 2010-03-18 21:59 -------- d-----w- c:\windows\l2schemas
2010-03-18 21:59 . 2010-03-18 21:59 -------- d-----w- c:\windows\system32\nl
2010-03-18 21:59 . 2010-03-18 21:59 -------- d-----w- c:\windows\system32\bits
2010-03-18 21:48 . 2010-03-18 21:48 -------- d-----w- c:\windows\EHome
2010-03-18 19:41 . 2008-04-14 17:02 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-03-18 18:16 . 2010-03-18 18:16 -------- d-----w- c:\program files\Microsoft Silverlight
2010-03-18 18:07 . 2010-03-18 18:07 -------- d-----w- c:\program files\Windows Media Connect 2
2010-03-18 18:05 . 2010-03-18 18:06 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-03-18 18:05 . 2010-03-18 18:05 -------- d-----w- c:\windows\system32\LogFiles
2010-03-18 17:24 . 2010-03-19 16:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-18 17:22 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-03-18 17:12 . 2010-03-18 21:55 -------- d-----w- c:\windows\ServicePackFiles
2010-03-18 17:11 . 2010-03-18 17:11 -------- d-----w- c:\documents and settings\Brandon\Application Data\SmartFTP
2010-03-18 17:04 . 2010-03-18 17:04 -------- d-----w- c:\program files\SmartFTP Client
2010-03-18 17:03 . 2010-03-18 17:03 -------- d-----w- c:\program files\SmartFTP Client 3.0 Setup Files
2010-03-18 16:58 . 2004-08-03 21:29 63488 ------w- c:\windows\system32\drivers\atinxsxx.sys
2010-03-18 16:36 . 2008-06-14 17:36 272640 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-18 16:36 . 2008-06-14 17:36 272640 ------w- c:\windows\system32\drivers\bthport.sys
2010-03-18 16:36 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-18 16:36 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-18 16:34 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-18 16:33 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-18 16:32 . 2009-07-10 13:31 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-18 16:31 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-18 16:30 . 2008-10-15 16:37 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-18 16:29 . 2008-04-21 21:16 218624 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-03-17 18:26 . 2010-04-01 18:13 0 ----a-w- c:\documents and settings\Brandon\Local Settings\Application Data\prvlcl.dat
2010-03-17 17:09 . 2010-03-17 17:09 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-17 17:09 . 2010-03-17 17:09 28424 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-03-17 17:09 . 2010-03-17 17:09 333192 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-17 17:08 . 2010-03-17 17:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-17 17:07 . 2010-03-17 16:45 800536 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-03-17 17:07 . 2010-03-17 16:45 613656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-03-17 17:07 . 2010-03-17 16:45 1658136 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-03-17 17:07 . 2010-03-17 16:45 1007896 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-03-17 16:46 . 2010-03-17 16:50 -------- d-----w- C:\$AVG
2010-03-17 16:46 . 2010-03-17 17:09 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-17 16:46 . 2010-03-17 17:08 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-17 16:46 . 2010-03-17 17:08 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-17 16:46 . 2010-04-01 10:31 -------- d-----w- c:\windows\system32\drivers\Avg
2010-03-17 16:45 . 2010-03-17 16:45 -------- d-----w- c:\program files\AVG
2010-03-17 16:45 . 2010-03-17 16:45 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-03-17 16:10 . 2010-03-17 16:28 -------- d-----w- c:\documents and settings\Brandon\Local Settings\Application Data\Panda Software
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-01 18:24 . 2010-03-17 14:58 -------- d-----w- c:\documents and settings\Brandon\Application Data\uTorrent
2010-04-01 17:17 . 2010-03-17 14:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-01 15:42 . 2010-03-17 15:13 -------- d-----w- c:\documents and settings\Brandon\Application Data\vlc
2010-04-01 10:24 . 2010-03-18 22:05 -------- d-----w- c:\program files\mIRC
2010-03-28 09:40 . 2004-08-04 12:00 54668 ----a-w- c:\windows\system32\perfc013.dat
2010-03-28 09:40 . 2004-08-04 12:00 367616 ----a-w- c:\windows\system32\perfh013.dat
2010-03-24 17:12 . 2010-03-17 14:40 -------- d-----w- c:\program files\Firefox
2010-03-18 22:14 . 2010-03-17 14:24 44840 ----a-w- c:\documents and settings\Brandon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-18 22:05 . 2010-03-18 22:05 -------- d-----w- c:\documents and settings\Brandon\Application Data\mIRC
2010-03-18 22:02 . 2010-03-17 14:18 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-18 17:18 . 2010-03-17 14:42 -------- d-----w- c:\program files\Microsoft Works
2010-03-17 19:02 . 2010-03-17 14:57 -------- d-----w- c:\documents and settings\Brandon\Application Data\ISP Monitor
2010-03-17 17:06 . 2010-03-17 14:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-17 16:51 . 2010-03-17 14:25 13312 ----a-w- c:\documents and settings\Brandon\Local Settings\Application Data\hide.exe
2010-03-17 16:50 . 2010-03-17 15:51 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-03-17 16:06 . 2010-03-17 15:51 -------- d-----w- c:\documents and settings\Brandon\Application Data\DAEMON Tools Lite
2010-03-17 15:52 . 2010-03-17 15:52 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-17 15:51 . 2010-03-17 15:51 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-03-17 15:48 . 2010-03-17 15:00 -------- d-----w- c:\program files\uTorrent
2010-03-17 15:15 . 2010-03-17 15:15 -------- d-----w- c:\program files\Microsoft
2010-03-17 15:15 . 2010-03-17 15:14 -------- d-----w- c:\program files\Windows Live
2010-03-17 15:15 . 2010-03-17 15:15 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-03-17 15:13 . 2010-03-17 15:13 -------- d-----w- c:\program files\Common Files\Windows Live
2010-03-17 14:58 . 2010-03-17 14:57 -------- d-----w- c:\program files\VLC
2010-03-17 14:57 . 2010-03-17 14:57 -------- d-----w- c:\program files\ISP Monitor
2010-03-17 14:56 . 2010-03-17 14:57 737280 ----a-w- c:\windows\iun6002.exe
2010-03-17 14:41 . 2010-03-17 14:41 0 ----a-w- c:\windows\nsreg.dat
2010-03-17 14:29 . 2010-03-17 14:29 -------- d-----w- c:\program files\AMD
2010-03-17 14:23 . 2010-03-17 14:23 -------- d-----w- c:\program files\Realtek
2010-03-17 14:23 . 2010-03-17 14:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-17 14:18 . 2010-03-17 14:18 -------- d-----w- c:\program files\microsoft frontpage
2010-03-17 14:16 . 2010-03-17 14:16 21748 ----a-w- c:\windows\system32\emptyregdb.dat
2010-02-26 05:53 . 2004-08-04 12:00 670208 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 05:53 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-01-18 06:30 . 2010-01-18 06:30 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-01-18 06:30 . 2010-01-18 06:30 499712 ----a-w- c:\windows\system32\msvcp71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISPMonitor"="c:\program files\ISP Monitor\isp.exe" [2010-02-28 423536]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 16050176]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-09 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-09 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-3-18 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-17 17:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\OOBE\\msoobe.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [17/03/2010 17:02 28552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17/03/2010 17:52 691696]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [17/03/2010 18:46 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [17/03/2010 18:46 242696]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [17/03/2010 19:08 308064]
S2 ISPMonitorSrv;ISP Monitor;c:\program files\ISP Monitor\ISPMonitorSrv.exe [16/01/2010 21:18 36864]
.
.
------- Bijkomende Scan -------
.
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Brandon\Application Data\Mozilla\Firefox\Profiles\swjzbdn7.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
---- FIREFOX POLICIES ----
c:\program files\Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS VERWIJDERD - - - -
AddRemove-ActiveScan 2.0 - c:\program files\Panda Security\ActiveScan 2.0\as2uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2010-04-01 20:37
Windows 5.1.2600 Service Pack 3 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
GMER - Rootkit Detector and Remover
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x845741F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf761af28
\Driver\ACPI -> ACPI.sys @ 0xf7381cb8
\Driver\atapi -> atapi.sys @ 0xf733cb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xf722cbb0
PacketIndicateHandler -> NDIS.sys @ 0xf7239a21
SendHandler -> NDIS.sys @ 0xf721787b
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'explorer.exe'(2752)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Voltooingstijd: 2010-04-01 20:42:07 - machine werd herstart
ComboFix-quarantined-files.txt 2010-04-01 18:42
Pre-Run: 41 984 221 184 bytes beschikbaar
Post-Run: 42 247 892 992 bytes beschikbaar
WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - CE5A9753E07086FB32B0F5DF8FD166DB