Hoi Maxstar,
Mijn probleem met combofix is verholpen, maar nu is mijn pc wederom besmet met het buma virus. Ik begrijp eigenlijk niet hoe dit mogelijk is geweest. Zat het virus en/of rootkit na de vorige keer nog op de pc? Ik ben zelfs voor betere beveiliging overgestapt naar Avast, maar dit heeft helaas niet mogen baten.
Voor de verwijdering heb ik weer het stappenplan gevolgd. Daarna ook meteen een aswMBR en Combofix scan uitgevoerd.
Hier de logs van Mbam, Emsisoft, DDS, aswMBR en Combofix.
mbam-log
Scantype: Snelle scan
Ingeschakelde scanopties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scanopties: P2P
Objecten gescand: 193856
Verstreken tijd: 13 minuut/minuten, 59 seconde(n)
Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Registerwaarden gedetecteerd: 1
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Hijack.Shell.Gen) -> Data: C:\Users\ AppData\Roaming\flint4ytw.exe -> Succesvol in quarantaine geplaatst en verwijderd.
Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)
Bestanden gedetecteerd: 1
C:\Users\ \AppData\Local\temp\wpbt0.dll (Exploit.Drop) -> Succesvol in quarantaine geplaatst en verwijderd.
(einde)
Emsisoft Emergency Kit - Versie 1.0
Scaninstellingen:
Scantype: Diepe Scan
Objecten: Geheugen, Sporen, Cookies, C:\, D:\
Scan archieven: Aan
Heuristieken: Uit
ADS Scan: Aan
Scan gestart: 12-3-2012 21:09:16
C:\Kaspersky Rescue Disk 10.0\bases_rd\kjim.kdl Ontdekt: Virus.Win32.Malware!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/ER.class Ontdekt: JAVA.Agent!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/Inc.class Ontdekt: Exploit.Java.Blacole!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/a.class Ontdekt: Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/b.class Ontdekt: Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/c.class Ontdekt: Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/t.class Ontdekt: Exploit.Java.CVE-2010!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/Field.class Ontdekt: JAVA.Agent!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/Inc.class Ontdekt: Exploit.Java.CVE!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/m.class Ontdekt: Exploit.Java.CVE-2011-3544!IK
Gescand
Bestanden: 337549
Sporen: 405504
Cookies: 7
Processen: 61
Gevonden
Bestanden: 10
Sporen: 0
Cookies: 0
Processen: 0
Registersleutels: 0
Scan Geëindigd: 13-3-2012 4:43:43
Scantijd: 7:34:27
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/Inc.class Verwijderd Exploit.Java.CVE!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/t.class Verwijderd Exploit.Java.CVE-2010!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/a.class Verwijderd Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/b.class Verwijderd Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/c.class Verwijderd Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/m.class Verwijderd Exploit.Java.CVE-2011-3544!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/Inc.class Verwijderd Exploit.Java.Blacole!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\4a6c36e7-409be0f6/ER.class Verwijderd JAVA.Agent!IK
C:\Users\ \AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\4ac0c886-185a29df/Field.class Verwijderd JAVA.Agent!IK
C:\Kaspersky Rescue Disk 10.0\bases_rd\kjim.kdl Verwijderd Virus.Win32.Malware!IK
Verwijderd
Bestanden: 10
Sporen: 0
Cookies: 0
DDS
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\alg.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conime.exe
.
============== Pseudo HJT Report ===============
.
mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopuURLSearchHooks: H - No File
uWinlogon: Userinit=c:\users\ \appdata\roaming\flint4ytw.exe,c:\windows\system32\userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Aanmelden - Help: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Search Assistant BHO: {9cb65201-89c4-402c-ba80-02d8c59f9b1d} - Ask Search Assistant BHO
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: Ask Toolbar: {fe063db9-4ec0-403e-8dd8-394c54984b2c} -
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {87775FDB-6972-41F9-AE51-8326E38CB206} - No File
uRun: [2X9I7BYX2HVCZF8VFHSCXXYSYXRRGAK] 2f0071000000
uRun: [K3aRyluP6SiCkoR] c:\users\ \appdata\roaming\flint4ytw.exe
uRunServices: [PlayerPlayer] c:\users\~1\appdata\local\temp\0.6116133340978206.exe
uRunServices: [0.6116133340978206] c:\users\\appdata\local\temp\0.6116133340978206.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SBRegRebootCleaner] "c:\program files\gfi software\vipre\SBRC.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} -
hxxp://dl.pplive.com/PluginSetup.cabTCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{DF559764-E4CE-49BA-A800-BDDA662DEDA6} : DhcpNameServer = 10.0.0.138
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\\appdata\roaming\mozilla\firefox\profiles\eals0j79.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft silverlight\5.0.61118.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-3-9 24408]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-3-9 610648]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-3-9 337112]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-3-9 20696]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-3-9 57688]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-3-9 44768]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\Ndisrd.sys [2009-8-28 22016]
S2 gupdate;Google Updateservice (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-18 135664]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-11-15 54632]
S3 fsssvc;De service Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 gupdatem;Google Update-service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-18 135664]
S3 Ndisrd;WinpkFilter Service;c:\windows\system32\drivers\Ndisrd.sys [2009-8-28 22016]
S3 SBFWIMCL;GFI Software Firewall NDIS IM Filter Service;c:\windows\system32\drivers\SbFwIm.sys [2012-2-2 94584]
S3 SBFWIMCLMP;GFI Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [2012-2-2 94584]
.
=============== Created Last 30 ================
.
2012-03-13 19:14:01 476904 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2012-03-13 14:07:43 6552120 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{8111a7a2-c1b9-4e26-b61e-25e9bd12d27a}\mpengine.dll
2012-03-09 19:17:18 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-09 19:17:18 24408 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-03-09 19:17:17 57688 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-03-09 19:14:16 41184 ----a-w- c:\windows\avastSS.scr
2012-03-09 19:10:32 -------- d-----w- c:\program files\AVAST Software
2012-03-09 18:27:13 -------- d-----w- c:\users\\appdata\local\temp
2012-03-09 18:25:24 -------- d-sh--w- C:\$RECYCLE.BIN
2012-03-09 18:03:17 -------- d-----w- C:\ComboFix
2012-03-06 15:48:37 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-03-06 15:48:37 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-03-06 15:44:09 -------- d-----w- c:\program files\iPod
2012-03-06 15:44:02 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-03-06 15:44:02 -------- d-----w- c:\program files\iTunes
2012-03-02 16:59:06 -------- d-----w- C:\TDSSStarter
2012-03-02 16:44:41 98816 ----a-w- c:\windows\sed.exe
2012-03-02 16:44:41 518144 ----a-w- c:\windows\SWREG.exe
2012-03-02 16:44:41 256000 ----a-w- c:\windows\PEV.exe
2012-03-02 16:44:41 208896 ----a-w- c:\windows\MBR.exe
2012-03-02 07:03:05 -------- d-----w- c:\users\ \appdata\roaming\Malwarebytes
2012-03-02 07:02:57 -------- d-----w- c:\programdata\Malwarebytes
2012-03-02 07:02:55 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-02 07:02:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 04:38:24 388096 ----a-r- c:\users\\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-03-02 04:38:21 -------- d-----w- c:\program files\Trend Micro
2012-03-01 18:06:44 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-02-29 21:36:25 -------- d-----w- c:\users\\appdata\roaming\CBS Interactive
2012-02-28 21:48:41 -------- d-----w- c:\programdata\CPA_VA
2012-02-28 21:21:05 -------- d-----w- c:\programdata\Comodo
2012-02-28 21:20:39 -------- d-----w- c:\program files\Comodo
2012-02-28 21:20:28 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2012-02-28 11:58:26 -------- d-----w- c:\users\\appdata\roaming\Wyroygz
2012-02-28 11:58:26 -------- d-----w- c:\users\\appdata\roaming\Cukara
2012-02-16 18:41:57 -------- d-----w- c:\program files\Conduit
2012-02-16 18:41:14 -------- d-----w- c:\users\\appdata\local\Conduit
.
==================== Find3M ====================
.
2012-03-13 19:11:50 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-28 15:25:01 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-23 08:18:36 237072 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 1:51:24,05 ===============
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-14 02:12:58
-----------------------------
02:12:58.404 OS Version: Windows 6.0.6000
02:12:58.405 Number of processors: 2 586 0xF0D
02:12:58.407 ComputerName: UserName:
02:12:59.919 Initialize success
02:13:00.151 AVAST engine defs: 12031301
02:13:05.925 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
02:13:05.929 Disk 0 Vendor: FUJITSU_ 8918 Size: 114473MB BusType: 3
02:13:05.936 Disk 0 MBR read successfully
02:13:05.941 Disk 0 MBR scan
02:13:05.947 Disk 0 unknown MBR code
02:13:05.953 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 107403 MB offset 63
02:13:05.976 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 7067 MB offset 219961980
02:13:05.986 Disk 0 scanning sectors +234436545
02:13:06.047 Disk 0 scanning C:\Windows\system32\drivers
02:13:15.355 Service scanning
02:13:16.448 Service .tdx \? **LOCKED** 123
02:13:36.393 Modules scanning
02:13:43.899 Disk 0 trace - called modules:
02:13:44.291 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
02:13:44.300 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85be6a08]
02:13:44.309 3 ntkrnlpa.exe[824b07e2] -> nt!IofCallDriver -> [0x8516a770]
02:13:44.319 5 acpi.sys[8066932a] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84c11030]
02:13:45.402 AVAST engine scan C:\Windows
02:13:49.013 AVAST engine scan C:\Windows\system32
02:16:08.042 AVAST engine scan C:\Windows\system32\drivers
02:16:24.880 AVAST engine scan C:\Users\
02:18:28.019 Disk 0 MBR has been saved successfully to "C:\Users\ \Desktop\MBR.dat"
02:18:28.035 The log file has been saved successfully to "C:\Users\ \Desktop\aswMBR2.txt"
ComboFix
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\dmc\Desktop_1.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\dmc\Desktop_2.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom\Usb 2.0 Driver\S-1-5-31-1286970278978-5713669491-166975984-320\dmc\Desktop_1.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom\Usb 2.0 Driver\S-1-5-31-1286970278978-5713669491-166975984-320\dmc\Desktop_2.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom\Usb 2.0 Driver\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr\Desktop_1.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\Rotinom\Usb 2.0 Driver\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr\Desktop_2.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr\Desktop_1.ini
c:\users\ \AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320\tlsr\Desktop_2.ini
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-02-14 to 2012-03-14 ))))))))))))))))))))))))))))))
.
.
2012-03-13 19:15 . 2012-03-13 19:15 -------- d-----w- c:\program files\Common Files\Java
2012-03-13 19:14 . 2012-03-13 19:12 476904 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2012-03-13 19:11 . 2012-03-13 19:11 -------- d-----w- c:\program files\Java
2012-03-13 14:07 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8111A7A2-C1B9-4E26-B61E-25E9BD12D27A}\mpengine.dll
2012-03-09 19:17 . 2012-02-23 16:12 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-09 19:17 . 2012-02-23 16:10 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-09 19:17 . 2012-02-23 16:10 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-09 19:17 . 2012-02-23 16:10 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-09 19:17 . 2012-02-23 16:12 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-09 19:17 . 2012-02-23 16:11 24408 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-03-09 19:17 . 2012-02-23 16:10 57688 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-03-09 19:14 . 2012-02-23 16:23 41184 ----a-w- c:\windows\avastSS.scr
2012-03-09 19:14 . 2012-02-23 16:23 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-09 19:10 . 2012-03-09 19:10 -------- d-----w- c:\program files\AVAST Software
2012-03-06 15:48 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-03-06 15:48 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-03-06 15:44 . 2012-03-06 15:44 -------- d-----w- c:\program files\iPod
2012-03-06 15:44 . 2012-03-06 15:48 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-03-06 15:44 . 2012-03-06 15:48 -------- d-----w- c:\program files\iTunes
2012-03-06 15:40 . 2012-03-06 15:40 -------- d-----w- c:\program files\Apple Software Update
2012-03-02 16:59 . 2012-03-02 17:01 -------- d-----w- C:\TDSSStarter
2012-03-02 07:03 . 2012-03-02 07:03 -------- d-----w- c:\users\ \AppData\Roaming\Malwarebytes
2012-03-02 07:02 . 2012-03-02 07:02 -------- d-----w- c:\programdata\Malwarebytes
2012-03-02 07:02 . 2012-03-02 07:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 07:02 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-02 04:38 . 2012-03-02 04:38 388096 ----a-r- c:\users\ AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-02 04:38 . 2012-03-02 04:38 -------- d-----w- c:\program files\Trend Micro
2012-03-01 16:33 . 2012-03-01 16:36 -------- d-----w- c:\users\ \AppData\Roaming\ImgBurn
2012-02-29 21:36 . 2012-02-29 21:36 -------- d-----w- c:\users\ \AppData\Roaming\CBS Interactive
2012-02-28 21:48 . 2012-03-01 18:17 -------- d-----w- c:\programdata\CPA_VA
2012-02-28 21:21 . 2012-02-28 21:48 -------- d-----w- c:\programdata\Comodo
2012-02-28 21:20 . 2012-03-01 15:27 -------- d-----w- c:\program files\Comodo
2012-02-28 21:20 . 2012-02-28 21:20 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2012-02-28 11:58 . 2012-02-28 20:17 -------- d-----w- c:\users\ \AppData\Roaming\Cukara
2012-02-28 11:58 . 2012-02-28 20:08 -------- d-----w- c:\users\ \AppData\Roaming\Wyroygz
2012-02-16 18:41 . 2012-02-16 18:41 -------- d-----w- c:\program files\Conduit
2012-02-16 18:41 . 2012-03-12 19:50 -------- d-----w- c:\users\ \AppData\Local\Conduit
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-13 19:11 . 2010-11-28 22:59 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-28 15:25 . 2011-08-25 18:40 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-23 08:18 . 2009-10-03 09:12 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-28 20:32 . 2012-02-12 22:15 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-02-23 16:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"2X9I7BYX2HVCZF8VFHSCXXYSYXRRGAK"="2f0071000000" [X]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"PlayerPlayer"="c:\users\ ~1\AppData\Local\Temp\0.6116133340978206.exe" [BU]
"0.6116133340978206"="c:\users\ \AppData\Local\Temp\0.6116133340978206.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 4390912]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
c:\program files\SUPERAntiSpyware\SASWINLO.DLL [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 01:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 14:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2007-03-12 09:54 50696 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 21:11 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
c:\program files\MSN Messenger\msnmsgr.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2007-02-13 09:38 159744 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-04-23 16:11 176128 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
c:\program files\QuickTime\QTTask.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Andere Services/Drivers In Geheugen ---
.
*Deregistered* - aswMBR
.
Inhoud van de 'Gedeelde Taken' map
.
2012-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-18 13:25]
.
2012-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-18 13:25]
.
.
------- Bijkomende Scan -------
.
mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 10.0.0.138
DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} -
hxxp://dl.pplive.com/PluginSetup.cabFF - ProfilePath - c:\users\ \AppData\Roaming\Mozilla\Firefox\Profiles\eals0j79.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS VERWIJDERD - - - -
.
URLSearchHooks-{87775fdb-6972-41f9-ae51-8326e38cb206} - (no file)
WebBrowser-{87775FDB-6972-41F9-AE51-8326E38CB206} - (no file)
HKCU-Run-K3aRyluP6SiCkoR - c:\users\ \AppData\Roaming\flint4ytw.exe
HKLM-Run-SBRegRebootCleaner - c:\program files\GFI Software\VIPRE\SBRC.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-03-14 02:39
Windows 6.0.6000 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
.
C:\avast! sandbox
.
Scan succesvol afgerond
verborgen bestanden: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\.tdx]
"ImagePath"="\?"
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2012-03-14 02:43:51
ComboFix-quarantined-files.txt 2012-03-14 01:43
ComboFix2.txt 2012-03-09 18:27
.
Pre-Run: 3.754.053.632 bytes beschikbaar
Post-Run: 3.620.409.344 bytes beschikbaar
.
- - End Of File - - E6CDA4E8B8DA0CEE9DEDD1A941B7C543