Bedankt, Michiel2.
Hier is de combofix log:
[hjt]
combofix 12-08-17.01 - felix 17-08-2012 15:02:57.3.8 - x64
microsoft windows 7 home premium 6.1.7601.1.1252.31.1043.18.8174.6176
[gmt 2:00]
gestart vanuit:
c:\users\felix\desktop\combofix.exe
av: bullguard antivirus *disabled/outdated*
{c3ccac61-52f7-a056-1860-6406566e2578}
fw: bullguard firewall *disabled*
{fbf72d44-1898-a10e-333f-cd33a8bd6203}
sp: bullguard antispyware *disabled/outdated*
{78ad4d85-74cd-afd8-22d0-5f742de96fc5}
sp: windows defender *disabled/updated*
{d68ddc3a-831f-4fae-9e44-da132c1acf46}
* nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((((((((((((((((( andere verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\felix\appdata\local\temp\{9ba7505c-d18e-47e5-ab94-c17673e762b3}\fpb.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2220.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2231.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2243.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2274.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2295.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2314.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2354.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2385.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem23a6.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem23b8.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem23e8.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem23fa.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem24d6.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem24f8.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem26ce.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem270e.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2720.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2770.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2791.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem27b2.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem27c4.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem27f4.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2854.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2886.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2972.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2a3f.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2a9e.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2b0d.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2b9c.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2bcd.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2bfd.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2c1f.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2c4f.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2c80.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2ca1.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2d01.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2d32.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2d72.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2da3.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2de3.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2e24.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2e64.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2ed4.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2f15.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2f36.tmp
c:\users\felix\appdata\local\temp\xtmp1mc3ve\dem2f57.tmp
c:\users\felix\appdata\local\temp\ytmp7mc8aa\taa3443.tmp
.
.
(((((((((((((((((((( bestanden gemaakt van 2012-07-17 to 2012-08-17 ))))))))))))))))))))))))))))))
.
.
2012-08-17 13:07 . 2012-08-17 13:07 -------- d-----w- c:\users\updatususer\appdata\local\temp
2012-08-17 13:07 . 2012-08-17 13:07 -------- d-----w- c:\users\public\appdata\local\temp
2012-08-17 13:07 . 2012-08-17 13:07 -------- d-----w- c:\users\default\appdata\local\temp
2012-08-15 14:07 . 2012-05-05 08:36 503808 ----a-w-
c:\windows\system32\srcore.dll
2012-08-15 14:07 . 2012-05-05 07:46 43008 ----a-w-
c:\windows\syswow64\srclient.dll
2012-08-15 14:07 . 2012-02-11 06:43 751104 ----a-w-
c:\windows\system32\win32spl.dll
2012-08-15 14:07 . 2012-02-11 06:36 559104 ----a-w-
c:\windows\system32\spoolsv.exe
2012-08-15 14:07 . 2012-02-11 06:36 67072 ----a-w-
c:\windows\splwow64.exe
2012-08-15 14:07 . 2012-02-11 05:43 492032 ----a-w-
c:\windows\syswow64\win32spl.dll
2012-08-15 14:07 . 2012-07-04 22:16 73216 ----a-w-
c:\windows\system32\netapi32.dll
2012-08-15 14:07 . 2012-07-04 22:13 59392 ----a-w-
c:\windows\system32\browcli.dll
2012-08-15 14:07 . 2012-07-04 22:13 136704 ----a-w-
c:\windows\system32\browser.dll
2012-08-15 14:07 . 2012-07-04 21:14 41984 ----a-w-
c:\windows\syswow64\browcli.dll
2012-08-15 14:07 . 2012-07-18 18:15 3148800 ----a-w-
c:\windows\system32\win32k.sys
2012-08-15 14:07 . 2012-05-14 05:26 956928 ----a-w-
c:\windows\system32\localspl.dll
2012-08-11 11:25 . 2012-08-15 22:00 -------- d-----w- c:\tmp
2012-08-11 10:40 . 2012-08-11 10:40 -------- d-----w- c:\program files (x86)\blender foundation
2012-08-08 23:21 . 2012-08-08 23:21 -------- d-----w- c:\program files (x86)\rtw - multicampaign
2012-08-08 20:06 . 2012-08-08 20:06 63840 ----a-w-
c:\windows\system32\bglsp.dll
2012-08-08 20:06 . 2012-08-08 20:06 54624 ----a-w-
c:\windows\syswow64\bglsp.dll
2012-08-08 19:54 . 2012-08-08 19:54 -------- d-----w- c:\program files\activision
2012-08-08 19:44 . 2012-08-08 19:44 282756 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\setup.dll
2012-08-08 19:44 . 2012-08-08 19:44 163972 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\igdi.dll
2012-08-08 19:44 . 2005-03-24 03:18 692224 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ikernel.dll
2012-08-08 19:44 . 2002-12-05 12:10 155648 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2012-08-08 19:44 . 2002-12-02 13:22 5632 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\dotnetinstaller.exe
2012-08-08 19:44 . 2002-12-02 11:33 57344 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2012-08-08 19:44 . 2002-12-02 11:33 237568 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2012-08-08 18:49 . 2012-08-08 18:50 -------- d-----w- c:\program files (x86)\gamespy arcade
2012-08-08 18:42 . 2012-08-08 22:08 -------- d-----w- c:\program files (x86)\the creative assembly
2012-08-08 18:41 . 2005-04-03 21:02 753664 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\ikernel.dll
2012-08-08 18:41 . 2005-04-03 21:02 69714 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\ctor.dll
2012-08-08 18:41 . 2005-04-03 21:01 274432 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\iscript.dll
2012-08-08 18:41 . 2005-04-03 21:00 184320 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\iuser.dll
2012-08-08 18:41 . 2005-04-03 21:00 63488 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\isbew64.exe
2012-08-08 18:41 . 2005-04-03 20:59 5632 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\dotnetinstaller.exe
2012-08-08 18:41 . 2012-08-08 18:41 200836 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\igdi.dll
2012-08-08 18:41 . 2012-08-08 18:41 331908 ----a-w-
c:\program files (x86)\common files\installshield\professional\runtime\11\00\intel32\setup.dll
2012-08-05 02:25 . 2012-08-05 02:25 -------- d-----w- c:\users\felix\appdata\local\facebook
2012-08-02 19:34 . 2012-08-09 18:33 -------- d-----w- c:\users\felix\appdata\local\albelli fotoboeken
2012-07-31 21:03 . 2012-07-31 21:03 -------- d-----w- c:\programdata\manycam
2012-07-25 16:34 . 2012-07-25 16:54 -------- d-----w- c:\users\felix\appdata\local\hema fotoalbum
2012-07-24 01:03 . 2010-02-23 08:16 294912 ----a-w-
c:\windows\system32\browserchoice.exe
2012-07-23 21:29 . 2012-06-06 06:06 2004480 ----a-w-
c:\windows\system32\msxml6.dll
2012-07-23 21:29 . 2012-06-06 06:06 1881600 ----a-w-
c:\windows\system32\msxml3.dll
2012-07-23 21:29 . 2012-06-06 05:05 1390080 ----a-w-
c:\windows\syswow64\msxml6.dll
2012-07-23 21:29 . 2012-06-06 05:05 1236992 ----a-w-
c:\windows\syswow64\msxml3.dll
2012-07-23 21:29 . 2010-06-26 03:55 2048 ----a-w-
c:\windows\system32\msxml3r.dll
2012-07-23 21:29 . 2010-06-26 03:24 2048 ----a-w-
c:\windows\syswow64\msxml3r.dll
2012-07-23 21:29 . 2012-06-09 05:43 14172672 ----a-w-
c:\windows\system32\shell32.dll
2012-07-22 00:40 . 2012-07-22 00:40 -------- d-----w- c:\users\felix\appdata\roaming\utherverse
2012-07-22 00:16 . 2012-07-22 00:16 -------- d-----w- c:\program files (x86)\utherverse digital inc
2012-07-21 13:49 . 2012-07-21 13:49 -------- d-----w- c:\users\felix\appdata\local\macromedia
.
.
.
((((((((((((((((((((((((((((((((((((((( find3m rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 16:22 . 2011-02-10 20:56 62134624 ----a-w-
c:\windows\system32\mrt.exe
2012-08-15 15:19 . 2012-04-20 15:35 70344 ----a-w- c:\windows\syswow64\flashplayercplapp.cpl
2012-08-15 15:19 . 2012-04-20 15:35 426184 ----a-w-
c:\windows\syswow64\flashplayerapp.exe
2012-07-03 11:46 . 2012-04-18 15:09 24904 ----a-w-
c:\windows\system32\drivers\mbam.sys
2012-06-20 08:34 . 2012-03-08 08:41 38528 ----a-r-
c:\windows\system32\drivers\afw.sys
2012-06-20 08:34 . 2012-03-08 08:41 445568 ----a-r-
c:\windows\system32\drivers\afwcore.sys
2012-06-06 06:49 . 2012-06-06 06:49 1070152 ----a-w-
c:\windows\syswow64\mscomctl.ocx
2012-06-02 22:19 . 2012-06-21 09:22 38424 ----a-w-
c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 09:22 2428952 ----a-w-
c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 09:22 57880 ----a-w-
c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 09:22 44056 ----a-w-
c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 09:22 701976 ----a-w-
c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 09:22 2622464 ----a-w-
c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 09:22 99840 ----a-w-
c:\windows\system32\wudriver.dll
2012-06-02 13:19 . 2012-06-21 09:21 186752 ----a-w-
c:\windows\system32\wuwebv.dll
2012-06-02 13:15 . 2012-06-21 09:21 36864 ----a-w-
c:\windows\system32\wuapp.exe
2012-05-31 10:25 . 2010-11-21 03:27 279656 ------w-
c:\windows\system32\mpsigstub.exe
.
.
((((((((((((((((((((((((((((((((((((( reg opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
regedit4
.
[hkey_current_user\software\microsoft\windows\currentversion\run]
"manycam"=
c:\program files (x86)\manycam\bin\manycam.exe [2012-06-28 2160024]
"facebook update"=
c:\users\felix\appdata\local\facebook\update\facebookupdate.exe [2012-08-05 138096]
.
[hkey_local_machine\software\wow6432node\microsoft\windows\currentversion\run]
"adobe arm"=
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe [2012-01-03 843712]
"sunjavaupdatesched"=
c:\program files (x86)\common files\java\java update\jusched.exe [2012-01-18 254696]
"tkbellexe"=
c:\program files (x86)\real\realplayer\update\realsched.exe [2012-02-16 296056]
"logmein hamachi ui"=
c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe [2012-06-27 1996200]
.
[hkey_local_machine\software\microsoft\windows\currentversion\policies\system]
"consentpromptbehavioradmin"= 5 (0x5)
"consentpromptbehavioruser"= 3 (0x3)
"enableuiadesktoptoggle"= 0 (0x0)
.
[hkey_local_machine\software\wow6432node\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=
c:\windows\system32\bggamingmonitor.dll
.
[hkey_local_machine\system\currentcontrolset\control\lsa]
security packages reg_multi_sz kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[hkey_local_machine\system\currentcontrolset\control\safeboot\minimal\bsmain]
@="service"
.
[hkey_local_machine\system\currentcontrolset\control\safeboot\minimal\bsscanner]
@="service"
.
r2 clr_optimization_v4.0.30319_64;microsoft .net framework ngen v4.0.30319_x64;
c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
r2 gupdate;google updateservice (gupdate);
c:\program files (x86)\google\update\googleupdate.exe [2011-08-25 136176]
r2 skypeupdate;skype updater;
c:\program files (x86)\skype\updater\updater.exe [2012-04-05 158856]
r3 adobeflashplayerupdatesvc;adobe flash player update service;
c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe [2012-08-15 250056]
r3 gupdatem;google update-service (gupdatem);
c:\program files (x86)\google\update\googleupdate.exe [2011-08-25 136176]
r3 lvpepf64;volume adapter;
c:\windows\system32\drivers\lv302a64.sys [2008-07-26 15768]
r3 lvrs64;logitech rightsound filter driver;
c:\windows\system32\drivers\lvrs64.sys [2008-07-26 790424]
r3 lvusbs64;logitech usb monitor filter;
c:\windows\system32\drivers\lvusbs64.sys [2008-07-26 50072]
r3 osppsvc;office software protection platform;
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe [2010-01-09 4925184]
r3 rtl8192su;
%rtl8192su.devicedesc.dispname%;c:\windows\system32\drivers\rtl8192su.sys [2010-02-06 690208]
r3 tsusbflt;tsusbflt;
c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
r3 tsusbgd;remote desktop generic usb device;
c:\windows\system32\drivers\tsusbgd.sys [2010-11-21 31232]
r3 usbaapl64;apple mobile usb driver;
c:\windows\system32\drivers\usbaapl64.sys [2011-08-02 51712]
r3 watadminsvc;windows activation technologies-service;
c:\windows\system32\wat\watadminsvc.exe [2011-08-26 1255736]
r3 wsvd;wsvd;
c:\windows\system32\drivers\wsvd.sys [2010-09-23 129008]
r4 iastordatamgrsvc;intel(r) rapid storage technology;
c:\program files (x86)\intel\intel(r) rapid storage technology\iastordatamgrsvc.exe [2011-04-30 13592]
r4 nvupdatusservice;nvidia update service daemon;
c:\program files (x86)\nvidia corporation\nvidia updatus\daemonu.exe [2011-08-03 2255464]
r4 stereo service;nvidia stereoscopic 3d driver service;
c:\program files (x86)\nvidia corporation\3d vision\nvscpapisvr.exe [2011-08-03 379496]
r4 teamviewer7;teamviewer 7;
c:\program files (x86)\teamviewer\version7\teamviewer_service.exe [2011-12-14 2984832]
r4 uns;intel(r) management and security application user notification service;
c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe [2011-03-11 2656280]
r4 wlcrasvc;windows live mesh remote connections service;
c:\program files\windows live\mesh\wlcrasvc.exe [2010-09-23 57184]
s0 nvpciflt;nvpciflt;
c:\windows\system32\drivers\nvpciflt.sys [2011-06-01 27240]
s1 afw;agnitum firewall driver;
c:\windows\system32\drivers\afw.sys [2012-06-20 38528]
s1 bdspy;bdspy;
c:\windows\system32\drivers\bdspy.sys [2012-03-08 66272]
s1 novashieldfilterdriver;novashieldfilterdriver;
c:\windows\system32\drivers\nskernel.sys [2012-03-08 256072]
s1 novashieldtdidriver;novashieldtdidriver;
c:\windows\system32\drivers\nsnetmon.sys [2012-03-08 25160]
s1 vwififlt;virtual wifi filter driver;
c:\windows\system32\drivers\vwififlt.sys [2009-07-14 59904]
s2 adobearmservice;adobe acrobat update service;
c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe [2012-04-03 63928]
s2 bsbackup;bullguard backup service;
c:\windows\system32\svchost.exe [2009-07-14 27136]
s2 bsbhvscan;bullguard behavioural detection;
c:\program files\bullguard ltd\bullguard\bullguardbhvscanner.exe [2012-06-16 368480]
s2 bsfilescan;bullguard on-access service;
c:\windows\system32\svchost.exe [2009-07-14 27136]
s2 bsfire;bullguard firewall service;
c:\windows\system32\svchost.exe [2009-07-14 27136]
s2 bsmailproxy;bullguard e-mail monitoring service;
c:\windows\system32\svchost.exe [2009-07-14 27136]
s2 bsmain;bullguard main service;
c:\windows\system32\svchost.exe [2009-07-14 27136]
s2 bsscanner;bullguard scanning service;
c:\program files\bullguard ltd\bullguard\bullguardscanner.exe [2012-06-16 199520]
s2 bsupdate;bullguard update service;
c:\program files\bullguard ltd\bullguard\bullguardupdate.exe [2012-06-20 379744]
s2 hamachi2svc;logmein hamachi tunneling engine;
c:\program files (x86)\logmein hamachi\hamachi-2.exe [2012-06-27 2369960]
s3 afwcore;afwcore;
c:\windows\system32\drivers\afwcore.sys [2012-06-20 445568]
s3 asmthub3;asmedia usb3 hub service;
c:\windows\system32\drivers\asmthub3.sys [2011-03-04 126952]
s3 asmtxhci;asmedia xhci service;
c:\windows\system32\drivers\asmtxhci.sys [2011-03-04 390632]
s3 manycam;manycam virtual webcam;
c:\windows\system32\drivers\mcvidrv_x64.sys [2012-01-11 34304]
s3 mcaudrv_simple;manycam virtual microphone;
c:\windows\system32\drivers\mcaudrv_x64.sys [2012-02-22 28160]
s3 meix64;intel(r) management engine interface;
c:\windows\system32\drivers\hecix64.sys [2011-03-11 56344]
s3 monitorfunction;driver for monitor;
c:\windows\system32\drivers\tvmonitor.sys [2011-11-11 16376]
s3 netr28ux;sweex wireless usb adapter driver;
c:\windows\system32\drivers\netr28ux.sys [2010-07-27 1241952]
s3 nvhda;service for nvidia high definition audio driver;
c:\windows\system32\drivers\nvhda64v.sys [2011-05-10 174184]
s3 rtl8167;realtek 8167 nt driver;
c:\windows\system32\drivers\rt64win7.sys [2011-02-16 428136]
s3 screambaudiosvc;screambee audio;
c:\windows\system32\drivers\screamingbaudio64.sys [2009-12-01 38992]
.
.
inhoud van de 'gedeelde taken' map
.
2012-08-16
c:\windows\tasks\adobe flash player updater.job
-
c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe [2012-04-20 15:19]
.
2012-08-14
c:\windows\tasks\facebookupdatetaskusers-1-5-21-3784602626-3873933597-2567512194-1001core.job
-
c:\users\felix\appdata\local\facebook\update\facebookupdate.exe [2012-08-05 02:25]
.
2012-08-16
c:\windows\tasks\facebookupdatetaskusers-1-5-21-3784602626-3873933597-2567512194-1001ua.job
-
c:\users\felix\appdata\local\facebook\update\facebookupdate.exe [2012-08-05 02:25]
.
2012-08-17
c:\windows\tasks\googleupdatetaskmachinecore.job
-
c:\program files (x86)\google\update\googleupdate.exe [2011-08-25 14:15]
.
2012-08-17
c:\windows\tasks\googleupdatetaskmachineua1cd6f1b9c22a58c.job
-
c:\program files (x86)\google\update\googleupdate.exe [2011-08-25 14:15]
.
2012-08-15
c:\windows\tasks\googleupdatetaskusers-1-5-21-3784602626-3873933597-2567512194-1001core1cd63ace5abf508.job
-
c:\users\felix\appdata\local\google\update\googleupdate.exe [2012-04-14 17:43]
.
2012-08-16
c:\windows\tasks\googleupdatetaskusers-1-5-21-3784602626-3873933597-2567512194-1001ua.job
-
c:\users\felix\appdata\local\google\update\googleupdate.exe [2012-04-14 17:43]
.
.
--------- x64 entries -----------
.
.
[hkey_local_machine\software\microsoft\windows\currentversion\run]
"bullguard"=
c:\program files\bullguard ltd\bullguard\bullguard.exe [2012-08-08 1863008]
"rthdvcpl"=
c:\program files\realtek\audio\hda\ravcpl64.exe [2011-01-13 11774568]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"
{1984dd45-52cf-49cd-ab77-18f378fea264}"=
c:\program files (x86)\stardock\fences\fencesmenu64.dll [2010-06-22 253288]
.
[hkey_local_machine\software\microsoft\windows nt\currentversion\windows]
"loadappinit_dlls"=0x1
"appinit_dlls"=
c:\windows\system32\bggamingmonitor.dll
.
------- bijkomende scan -------
.
ulocal page =
c:\windows\system32\blank.htm
ustart page = hxxp://www.google.nl/
mlocal page =
c:\windows\syswow64\blank.htm
uinternet settings,proxyoverride = *.local
ie: {
{0b65dcc9-1740-43dc-b19c-4f309fb6a6ca} -
[noparse]http://rover.ebay.com/rover/1/1346-72745-17534-1/4[/noparse]
lsp:
c:\windows\system32\bglsp.dll
tcp: dhcpnameserver = 192.168.0.1
tcp: interfaces\
{b2a0ec69-8ac3-43f2-a3c7-71d30759053b}: nameserver = 62.133.126.28
.
- - - - orphans verwijderd - - - -
.
wow6432node-hkcu-run-clownfish - (no file)
hklm_wow6432node-activesetup-
{2d46b6dc-2207-486b-b523-a557e6d54b47} - start
addremove-adobe shockwave player -
c:\windows\system32\adobe\shockwave 11\uninstaller.exe
addremove-cruise ship tycoon -
c:\progra~2\activi~1\cruise~1\unwise.exe
addremove-ilivid -
c:\program files (x86)\ilivid\uninstall.exe
.
.
.
--------------------- vergrendelde register sleutels ---------------------
.
[hkey_users\.default\software\microsoft\windows\currentversion\explorer\fileexts\.htm\userchoice]
@denied: (2) (localsystem)
"progid"="chromehtml"
.
[hkey_users\.default\software\microsoft\windows\currentversion\explorer\fileexts\.html\userchoice]
@denied: (2) (localsystem)
"progid"="chromehtml"
.
[hkey_users\.default\software\microsoft\windows\currentversion\explorer\fileexts\.shtml\userchoice]
@denied: (2) (localsystem)
"progid"="chromehtml"
.
[hkey_users\.default\software\microsoft\windows\currentversion\explorer\fileexts\.xht\userchoice]
@denied: (2) (localsystem)
"progid"="chromehtml"
.
[hkey_users\.default\software\microsoft\windows\currentversion\explorer\fileexts\.xhtml\userchoice]
@denied: (2) (localsystem)
"progid"="chromehtml"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{a483c63a-cdbc-426e-bf93-872502e8144e}]
@denied: (a 2) (everyone)
@="flashbroker"
"localizedstring"="@
c:\\windows\\syswow64\\macromed\\flash\\flashutil32_11_3_300_271_activex.exe,-101"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{a483c63a-cdbc-426e-bf93-872502e8144e}\elevation]
"enabled"=dword:00000001
.
[hkey_local_machine\software\classes\wow6432node\clsid\{a483c63a-cdbc-426e-bf93-872502e8144e}\localserver32]
@=
c:\\windows\\syswow64\\macromed\\flash\\flashutil32_11_3_300_271_activex.exe
.
[hkey_local_machine\software\classes\wow6432node\clsid\{a483c63a-cdbc-426e-bf93-872502e8144e}\typelib]
@="
{fab3e735-69c7-453b-a446-b6823c6df1c9}"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}]
@denied: (a 2) (everyone)
@="shockwave flash object"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\inprocserver32]
@=
c:\\windows\\syswow64\\macromed\\flash\\flash32_11_3_300_271.ocx
"threadingmodel"="apartment"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\miscstatus]
@="0"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\progid]
@="shockwaveflash.shockwaveflash.11"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\toolboxbitmap32]
@=
c:\\windows\\syswow64\\macromed\\flash\\flash32_11_3_300_271.ocx, 1"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\typelib]
@="
{d27cdb6b-ae6d-11cf-96b8-444553540000}"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\version]
@="1.0"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb6e-ae6d-11cf-96b8-444553540000}\versionindependentprogid]
@="shockwaveflash.shockwaveflash"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}]
@denied: (a 2) (everyone)
@="macromedia flash factory object"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\inprocserver32]
@=
c:\\windows\\syswow64\\macromed\\flash\\flash32_11_3_300_271.ocx
"threadingmodel"="apartment"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\progid]
@="flashfactory.flashfactory.1"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\toolboxbitmap32]
@=
c:\\windows\\syswow64\\macromed\\flash\\flash32_11_3_300_271.ocx, 1"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\typelib]
@="
{d27cdb6b-ae6d-11cf-96b8-444553540000}"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\version]
@="1.0"
.
[hkey_local_machine\software\classes\wow6432node\clsid\{d27cdb70-ae6d-11cf-96b8-444553540000}\versionindependentprogid]
@="flashfactory.flashfactory"
.
[hkey_local_machine\software\classes\wow6432node\interface\{e3f2c3cb-5eb8-4a04-b22c-7e3b4b6af30f}]
@denied: (a 2) (everyone)
@="iflashbroker4"
.
[hkey_local_machine\software\classes\wow6432node\interface\{e3f2c3cb-5eb8-4a04-b22c-7e3b4b6af30f}\proxystubclsid32]
@="
{00020424-0000-0000-c000-000000000046}"
.
[hkey_local_machine\software\classes\wow6432node\interface\{e3f2c3cb-5eb8-4a04-b22c-7e3b4b6af30f}\typelib]
@="
{fab3e735-69c7-453b-a446-b6823c6df1c9}"
"version"="1.0"
.
[hkey_local_machine\software\wow6432node\microsoft\office\common\smart tag\actions\{b7eff951-e52f-45cc-9ef7-57124f2177cc}]
@denied: (a) (everyone)
"solution"="
{15727de6-f92d-4e46-acb4-0e2c58b31a18}"
.
[hkey_local_machine\software\wow6432node\microsoft\schema library\actionspane3]
@denied: (a) (everyone)
.
[hkey_local_machine\software\wow6432node\microsoft\schema library\actionspane3\0]
"key"="actionspane3"
"location"="c:\\program files (x86)\\common files\\microsoft shared\\vsto\\actionspane3.xsd"
.
[hkey_local_machine\system\controlset001\control\class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\allusersettings]
@denied: (a) (users)
@denied: (a) (everyone)
@allowed: (b 1 2 3 4 5) (s-1-5-20)
"blinddial"=dword:00000000
.
[hkey_local_machine\system\controlset001\control\pcw\security]
@denied: (full) (everyone)
.
------------------------ andere aktieve processen ------------------------
.
c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
c:\windows\syswow64\pnkbstra.exe
c:\windows\syswow64\pnkbstrb.exe
.
**************************************************************************
.
voltooingstijd: 2012-08-17 15:13:43 - machine werd herstart
combofix-quarantined-files.txt 2012-08-17 13:13
.
pre-run: 1.302.869.463.040 bytes beschikbaar
post-run: 1.303.512.281.088 bytes beschikbaar
.
- - end of file - - 603582c3e21fe23579d58a49c9627449
[/hjt]