Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 12-05-20.10 - Sluysen 21/05/2012 15:05:48.1.4 - x64
- Microsoft Windows 7 Professional 6.1.7600.0.1252.32.1043.18.3953.2288 [GMT 2:00]
- Gestart vanuit: c:\users\Sluysen\Desktop\ComboFix.exe
- AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
- SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\programdata\xml2DA5.tmp
- c:\programdata\xml2F1D.tmp
- c:\programdata\xml2FD9.tmp
- c:\programdata\xml43A8.tmp
- c:\programdata\xml7BF.tmp
- c:\programdata\xml97EC.tmp
- c:\programdata\xml9899.tmp
- c:\programdata\xmlF843.tmp
- c:\users\Sluysen\AppData\Local\assembly\tmp
- c:\users\Sluysen\AppData\Roaming\7za.exe
- c:\users\Sluysen\AppData\Roaming\a.7z
- c:\users\Sluysen\AppData\Roaming\Google\Update\1
- c:\users\Sluysen\AppData\Roaming\Google\Update\1\SD\m.txt
- c:\users\Sluysen\AppData\Roaming\Google\Update\1\SD\s.txt
- .
- .
- (((((((((((((((((((( Bestanden Gemaakt van 2012-04-21 to 2012-05-21 ))))))))))))))))))))))))))))))
- .
- .
- 2012-05-21 13:15 . 2012-05-21 13:15 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2012-05-21 13:15 . 2012-05-21 13:15 -------- d-----w- c:\users\Administrator\AppData\Local\temp
- 2012-05-21 10:51 . 2012-05-21 10:51 -------- d-----w- c:\users\Sluysen\AppData\Local\adaware
- 2012-05-21 10:51 . 2012-05-21 10:51 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection
- 2012-05-21 10:51 . 2011-12-19 10:44 60536 ----a-w- c:\windows\system32\drivers\sbhips.sys
- 2012-05-21 10:50 . 2011-09-29 10:16 119416 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
- 2012-05-21 10:50 . 2011-12-19 10:44 256632 ----a-w- c:\windows\system32\drivers\SbFw.sys
- 2012-05-21 10:50 . 2011-12-19 11:21 45936 ----a-w- c:\windows\system32\sbbd.exe
- 2012-05-21 10:50 . 2011-10-26 12:23 57976 ----a-w- c:\windows\system32\drivers\sbredrv.sys
- 2012-05-21 10:50 . 2012-05-21 10:50 -------- d-----w- c:\programdata\Lavasoft
- 2012-05-21 10:50 . 2012-05-21 10:58 -------- d-----w- c:\program files (x86)\Ad-Aware Antivirus
- 2012-05-21 10:49 . 2012-05-21 12:24 -------- d-----w- c:\users\Sluysen\AppData\Roaming\Ad-Aware Antivirus
- 2012-05-21 09:02 . 2012-05-21 09:02 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
- 2012-05-21 08:37 . 2012-05-21 08:37 -------- d-----w- c:\program files (x86)\Cyanide
- 2012-05-18 09:44 . 2012-05-08 17:02 8955792 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EA5D368F-DB80-465B-8AC3-1664EADF5294}\mpengine.dll
- 2012-05-13 22:14 . 2012-05-13 22:14 -------- d-----w- c:\program files (x86)\EA GAMES
- 2012-05-13 22:12 . 2004-09-30 14:24 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
- 2012-05-13 22:12 . 2004-09-30 14:20 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
- 2012-05-13 22:12 . 2004-09-30 14:20 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
- 2012-05-13 22:12 . 2004-09-30 14:19 172032 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
- 2012-05-13 22:12 . 2004-09-30 14:39 733184 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
- 2012-05-13 22:12 . 2012-05-13 22:12 180356 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
- 2012-05-13 22:12 . 2012-05-13 22:12 303236 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
- 2012-05-12 13:48 . 2012-05-12 13:48 -------- d-----w- c:\users\Sluysen\AppData\Local\Facebook
- 2012-05-11 17:10 . 2012-05-11 17:10 -------- d-----w- c:\program files\Microsoft Silverlight
- 2012-05-11 17:10 . 2012-05-11 17:10 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
- 2012-05-10 09:26 . 2012-03-03 06:29 1541120 ----a-w- c:\windows\system32\DWrite.dll
- 2012-05-10 09:26 . 2012-03-03 05:40 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
- 2012-05-10 09:26 . 2012-03-03 06:29 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
- 2012-05-10 09:26 . 2012-03-03 06:29 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
- 2012-05-10 09:26 . 2012-03-03 05:40 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll
- 2012-05-10 09:26 . 2012-03-03 05:40 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
- 2012-05-10 09:26 . 2012-03-03 06:29 197120 ----a-w- c:\windows\system32\d3d10_1.dll
- 2012-05-10 09:26 . 2012-03-03 06:29 902656 ----a-w- c:\windows\system32\d2d1.dll
- 2012-05-10 09:26 . 2012-03-03 05:40 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
- 2012-05-10 09:26 . 2012-03-03 05:40 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
- 2012-05-10 09:25 . 2012-04-02 05:34 5504880 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2012-05-10 09:25 . 2012-04-02 03:01 3143680 ----a-w- c:\windows\system32\win32k.sys
- 2012-05-10 09:25 . 2012-04-02 04:46 3902320 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
- 2012-05-10 09:25 . 2012-04-02 04:46 3958128 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
- 2012-05-10 09:25 . 2012-03-17 07:55 75632 ----a-w- c:\windows\system32\drivers\partmgr.sys
- 2012-05-10 09:25 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys
- 2012-05-10 09:25 . 2012-04-02 05:26 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
- 2012-05-10 09:25 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
- 2012-05-10 09:25 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
- 2012-05-10 09:25 . 2012-04-02 05:24 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
- 2012-05-10 09:25 . 2012-04-02 05:24 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
- 2012-05-09 14:25 . 2012-05-09 14:25 -------- d-----w- c:\program files (x86)\Maxis
- 2012-05-03 21:24 . 2012-04-30 19:05 31344 ----a-w- c:\windows\system32\drivers\VMparport.sys
- 2012-05-03 21:24 . 2012-04-30 19:05 63088 ----a-w- c:\windows\system32\drivers\vmx86.sys
- 2012-05-03 21:23 . 2012-04-30 19:04 354416 ----a-w- c:\windows\SysWow64\vmnetdhcp.exe
- 2012-05-03 21:23 . 2012-04-30 19:04 433264 ----a-w- c:\windows\SysWow64\vmnat.exe
- 2012-05-03 21:23 . 2012-04-30 19:03 30320 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
- 2012-05-03 21:23 . 2012-04-30 19:05 942192 ----a-w- c:\windows\system32\vnetlib64.dll
- 2012-05-03 21:23 . 2012-04-30 19:04 32880 ----a-w- c:\windows\system32\drivers\VMkbd.sys
- 2012-05-03 21:23 . 2011-08-29 21:11 39024 ----a-w- c:\windows\system32\drivers\hcmon.sys
- 2012-05-03 21:22 . 2012-05-03 21:22 -------- d-----w- c:\program files (x86)\Common Files\VMware
- 2012-05-03 21:21 . 2012-05-03 21:21 -------- d-----w- c:\program files\Common Files\VMware
- 2012-05-01 11:43 . 2012-05-01 11:43 -------- d-----w- c:\programdata\Media Center Programs
- 2012-05-01 11:14 . 2012-05-01 11:14 -------- d-----w- c:\program files (x86)\Sierra Entertainment
- 2012-04-30 16:26 . 2012-04-30 16:26 252016 ----a-w- c:\windows\SysWow64\vmnc.dll
- 2012-04-30 15:22 . 2012-04-30 15:22 62064 ----a-w- c:\windows\system32\vmnetbridge.dll
- 2012-04-30 15:22 . 2012-04-30 15:22 48752 ----a-w- c:\windows\system32\vnetinst.dll
- 2012-04-30 15:22 . 2012-04-30 15:22 45680 ----a-w- c:\windows\system32\drivers\vmnetbridge.sys
- 2012-04-30 15:22 . 2012-04-30 15:22 24176 ----a-w- c:\windows\system32\drivers\vmnet.sys
- 2012-04-30 15:22 . 2012-04-30 15:22 20080 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
- 2012-04-24 10:06 . 2012-04-24 10:06 -------- d-----w- c:\windows\SysWow64\BestPractices
- 2012-04-24 10:06 . 2012-04-24 10:06 -------- d-----w- c:\windows\system32\BestPractices
- 2012-04-24 10:06 . 2012-04-24 10:06 -------- d-----w- C:\inetpub
- 2012-04-24 09:52 . 2012-04-26 07:09 -------- d-----w- c:\program files (x86)\PHP
- 2012-04-23 09:52 . 2012-04-23 09:52 -------- d-----w- c:\users\Sluysen\AppData\Local\Tukui
- 2012-04-23 09:49 . 2012-04-23 09:49 -------- d-----w- c:\program files (x86)\Tukui Update Utility
- .
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2012-05-05 16:20 . 2012-04-03 09:50 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
- 2012-05-05 16:20 . 2011-07-25 21:58 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2012-05-05 16:20 . 2012-04-03 10:20 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
- 2012-03-16 22:45 . 2012-02-29 10:46 214816 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
- 2012-03-16 22:45 . 2012-02-29 10:44 214816 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
- 2012-03-14 21:11 . 2011-09-26 16:44 2255840 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
- 2012-03-07 19:01 . 2012-02-29 10:43 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
- 2012-03-06 23:15 . 2011-07-23 12:38 41184 ----a-w- c:\windows\avastSS.scr
- 2012-03-06 23:15 . 2011-07-23 12:38 201352 ----a-w- c:\windows\SysWow64\aswBoot.exe
- 2012-03-06 23:15 . 2011-07-23 12:39 258520 ----a-w- c:\windows\system32\aswBoot.exe
- 2012-03-06 23:04 . 2011-07-23 12:39 819032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
- 2012-03-06 23:04 . 2011-07-23 12:39 337240 ----a-w- c:\windows\system32\drivers\aswSP.sys
- 2012-03-06 23:02 . 2012-04-07 08:48 53080 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
- 2012-03-06 23:01 . 2011-07-23 12:39 59224 ----a-w- c:\windows\system32\drivers\aswTdi.sys
- 2012-03-06 23:01 . 2011-07-23 12:39 69976 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
- 2012-03-06 23:01 . 2011-07-23 12:39 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
- 2012-03-01 06:54 . 2012-04-11 19:33 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
- 2012-03-01 06:45 . 2012-04-11 19:33 220672 ----a-w- c:\windows\system32\wintrust.dll
- 2012-03-01 06:40 . 2012-04-11 19:33 80896 ----a-w- c:\windows\system32\imagehlp.dll
- 2012-03-01 06:35 . 2012-04-11 19:33 5120 ----a-w- c:\windows\system32\wmi.dll
- 2012-03-01 05:49 . 2012-04-11 19:33 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
- 2012-03-01 05:45 . 2012-04-11 19:33 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
- 2012-03-01 05:40 . 2012-04-11 19:33 5120 ----a-w- c:\windows\SysWow64\wmi.dll
- 2012-02-28 06:56 . 2012-04-11 19:37 2311168 ----a-w- c:\windows\system32\jscript9.dll
- 2012-02-28 06:49 . 2012-04-11 19:37 1390080 ----a-w- c:\windows\system32\wininet.dll
- 2012-02-28 06:48 . 2012-04-11 19:37 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
- 2012-02-28 06:42 . 2012-04-11 19:37 2382848 ----a-w- c:\windows\system32\mshtml.tlb
- 2012-02-28 01:18 . 2012-04-11 19:37 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll
- 2012-02-28 01:11 . 2012-04-11 19:37 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
- 2012-02-28 01:11 . 2012-04-11 19:37 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
- 2012-02-28 01:03 . 2012-04-11 19:37 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
- 2012-02-23 08:18 . 2011-07-23 11:46 279656 ------w- c:\windows\system32\MpSigStub.exe
- 2010-08-03 10:11 819200 --sha-w- c:\windows\SysWOW64\xvidcore.dll
- 2010-08-03 10:11 180224 --sha-w- c:\windows\SysWOW64\xvidvfw.dll
- .
- .
- ------- Sigcheck -------
- Note: Unsigned files aren't necessarily malware.
- .
- [7] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
- [-] 2009-07-14 . 50BEA589F7D7958BDD2528A8F69D05CC . 329216 . . [6.1.7600.16385] .. c:\windows\system32\services.exe
- .
- ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 94208 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 94208 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 94208 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Facebook Update"="c:\users\Sluysen\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-05-12 137536]
- "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-02-27 1242448]
- "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
- "NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-21 106496]
- "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
- "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
- "QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
- "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
- .
- c:\users\Sluysen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- CurseClientStartup.ccip [2012-4-3 0]
- Dropbox.lnk - c:\users\Sluysen\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-4 27087944]
- .
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- Monitor Apache Servers.lnk - c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe [2010-10-18 41051]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
- @="Ad-Aware Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
- @="Service"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
- @="Driver"
- .
- R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2011-10-26 57976]
- R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2011-12-19 3289032]
- R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
- R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [x]
- R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
- R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x]
- R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
- R3 MicrosoftDynamicsNavWS;Microsoft Dynamics NAV Business Web Services;c:\program files (x86)\Microsoft Dynamics NAV\60\Service\Microsoft.Dynamics.Nav.Server.exe [2010-12-11 141184]
- R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-17 129976]
- R3 netr28ux;Stuurprogramma voor RT2870 USB draadloze LAN-kaart voor Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
- R3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys [x]
- R3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys [x]
- R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
- R3 SBFWIMCL;GFI Software Firewall NDIS IM Filter Service;c:\windows\system32\DRIVERS\sbfwim.sys [x]
- R3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [x]
- R3 sbwtis;sbwtis;c:\windows\system32\DRIVERS\sbwtis.sys [x]
- R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
- R3 tizekdrv;tizekdrv;c:\users\Sluysen\AppData\Roaming\TZAC\tizek64.sys [2012-02-29 241848]
- R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
- R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
- R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
- R3 WSDPrintDevice;WSD-ondersteuning voor afdrukken via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x]
- R3 xhc200w;xhc200w;c:\swsetup\SP48109\32\xhc200w.sys [2010-02-02 25232]
- R3 zghsdiag;ZTE General Handset Diagnostic Port;c:\windows\system32\DRIVERS\zghsdiag.sys [x]
- R3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\DRIVERS\zghsmdm.sys [x]
- R3 zghsnmea;ZTE General Handset NMEA Port;c:\windows\system32\DRIVERS\zghsnmea.sys [x]
- R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
- R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
- R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
- S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x]
- S1 aswSnx;aswSnx; [x]
- S1 aswSP;aswSP; [x]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
- S1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [x]
- S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
- S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-05-03 1226096]
- S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-01 89600]
- S2 Apache2.2;Apache2.2;c:\program files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe [2010-10-18 20549]
- S2 aswFsBlk;aswFsBlk; [x]
- S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
- S2 ET Master Server Proxy;ET Master Server Proxy Service;c:\program files (x86)\Rudi Visser\ET Master Server Proxy Service\ETMSProxy.exe [2012-01-21 9728]
- S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
- S2 MicrosoftDynamicsNavServer;Microsoft Dynamics NAV Server;c:\program files (x86)\Microsoft Dynamics NAV\60\Service\Microsoft.Dynamics.Nav.Server.exe [2010-12-11 141184]
- S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x]
- S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [x]
- S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-29 846448]
- S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
- S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x]
- S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
- S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
- S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
- S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
- S3 rismcx64;RICOH Smart Card Reader;c:\windows\system32\DRIVERS\rismcx64.sys [x]
- S3 SBFWIMCLMP;GFI Software Firewall NDIS IM Filter Miniport;c:\windows\system32\DRIVERS\SBFWIM.sys [x]
- .
- .
- --- Andere Services/Drivers In Geheugen ---
- .
- *NewlyCreated* - SBWTIS
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
- iissvcs REG_MULTI_SZ w3svc was
- apphost REG_MULTI_SZ apphostsvc
- .
- Inhoud van de 'Gedeelde Taken' map
- .
- 2012-05-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 16:20]
- .
- 2012-05-20 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3201013571-1090400088-3516429029-1000Core.job
- - c:\users\Sluysen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-12 13:48]
- .
- 2012-05-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3201013571-1090400088-3516429029-1000UA.job
- - c:\users\Sluysen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-05-12 13:48]
- .
- 2012-05-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201013571-1090400088-3516429029-1000Core.job
- - c:\users\Sluysen\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-23 11:32]
- .
- 2012-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3201013571-1090400088-3516429029-1000UA.job
- - c:\users\Sluysen\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-23 11:32]
- .
- .
- --------- x86-64 -----------
- .
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
- @="{472083B0-C522-11CF-8763-00608CC02F24}"
- [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
- 2012-03-06 23:15 135408 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 97792 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 97792 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 97792 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2011-02-18 05:12 97792 ----a-w- c:\users\Sluysen\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-24 16405608]
- "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-09-07 489472]
- "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
- "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-10-10 1861416]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Bijkomende Scan -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- mLocal Page = c:\windows\SysWOW64\blank.htm
- IE: &Verzenden naar OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
- IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
- IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
- LSP: mswsock.dll
- LSP: %SystemRoot%\system32\vsocklib.dll
- Trusted Zone: clonewarsadventures.com
- Trusted Zone: freerealms.com
- Trusted Zone: soe.com
- Trusted Zone: sony.com
- TCP: DhcpNameServer = 195.130.131.5 192.168.0.1
- FF - ProfilePath - c:\users\Sluysen\AppData\Roaming\Mozilla\Firefox\Profiles\m58wssa1.default\
- FF - prefs.js: browser.startup.homepage - hxxp://localhost/
- .
- .
- ------- Bestandsassociaties -------
- .
- txtfile="c:\program files (x86)\Notepad++\notepad++.exe" %1
- .txt=Word.Document.12
- .
- - - - - ORPHANS VERWIJDERD - - - -
- .
- Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
- Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
- SafeBoot-SolutoService
- BHO-{3706EE7C-3CAD-445D-8A43-03EBC3B75908} - (no file)
- AddRemove-{33A22B2D-55BA-4508-B767-BF2E9C21A73F} - c:\program files (x86)\InstallShield Installation Information\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}\setup.exe
- AddRemove-UnityWebPlayer - c:\users\Sluysen\AppData\Local\Unity\WebPlayer\Uninstall.exe
- .
- .
- .
- --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
- .
- [HKEY_USERS\S-1-5-21-3201013571-1090400088-3516429029-1000\Software\SecuROM\License information*]
- "datasecu"=hex:14,f1,a1,57,33,ff,2e,3a,1d,ca,dd,64,c3,ba,26,38,6f,c5,d0,bb,4d,
- 85,5b,d2,dd,f6,44,0c,27,bb,40,e7,fa,dc,e9,6e,e3,95,6c,c0,e0,f2,81,67,10,fc,\
- "rkeysecu"=hex:19,6c,3d,24,4e,5e,f2,99,71,b2,fd,a1,1b,af,59,dd
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
- @Denied: (A 2) (Everyone)
- @="FlashBroker"
- "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
- "Enabled"=dword:00000001
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Shockwave Flash Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
- @="0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
- @="ShockwaveFlash.ShockwaveFlash.11"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="ShockwaveFlash.ShockwaveFlash"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
- @Denied: (A 2) (Everyone)
- @="Macromedia Flash Factory Object"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
- "ThreadingModel"="Apartment"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
- @="FlashFactory.FlashFactory.1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
- @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
- @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
- @="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
- @="FlashFactory.FlashFactory"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
- @Denied: (A 2) (Everyone)
- @="IFlashBroker4"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
- @="{00020424-0000-0000-C000-000000000046}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
- @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
- "Version"="1.0"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
- @Denied: (A) (Everyone)
- "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
- @Denied: (A) (Everyone)
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
- "Key"="ActionsPane3"
- "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- "MSCurrentCountry"=dword:000000b5
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
- @Denied: (A) (Users)
- @Denied: (A) (Everyone)
- @Allowed: (B 1 2 3 4 5) (S-1-5-20)
- "BlindDial"=dword:00000000
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Andere Aktieve Processen ------------------------
- .
- c:\program files\AVAST Software\Avast\AvastSvc.exe
- c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
- c:\windows\SysWOW64\PnkBstrB.exe
- c:\windows\SysWOW64\vmnat.exe
- c:\program files (x86)\VMware\VMware Player\vmware-authd.exe
- c:\windows\SysWOW64\vmnetdhcp.exe
- c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
- c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
- .
- **************************************************************************
- .
- Voltooingstijd: 2012-05-21 15:27:13 - machine werd herstart
- ComboFix-quarantined-files.txt 2012-05-21 13:27
- .
- Pre-Run: 8.278.675.456 bytes beschikbaar
- Post-Run: 7.831.359.488 bytes beschikbaar
- .
- - - End Of File - - 0FA3264BAB33DB1D6567DC56EE07AD45
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement