Gesloten
32
ComboFix 11-10-19.04 - Ikke 19-10-2011 18:13:58.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.3071.2441 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Ikke\Bureaublad\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Besmet exemplaar van c:\windows\system32\userinit.exe werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - c:\windows\ERDNT\cache\userinit.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-09-19 to 2011-10-19 ))))))))))))))))))))))))))))))
.
.
2011-10-18 15:57 . 2008-04-14 20:32 81920 ------w- c:\windows\system32\ieencode.dll
2011-10-16 17:13 . 2011-10-16 17:13 -------- d--h--w- c:\windows\PIF
2011-09-28 17:47 . 2011-09-28 17:48 -------- d-----w- c:\program files\uTorrent Turbo Booster
2011-09-28 17:45 . 2011-09-28 17:45 -------- d-----w- c:\program files\uTorrent
2011-09-28 17:44 . 2011-09-28 17:44 -------- d-----w- c:\documents and settings\Ikke\Local Settings\Application Data\uTorrent
2011-09-28 15:09 . 2011-09-28 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-28 15:03 . 2011-09-28 15:03 -------- d-----w- c:\program files\Uniblue
2011-09-28 15:03 . 2011-09-28 15:03 -------- d-----w- c:\documents and settings\Ikke\Local Settings\Application Data\PackageAware
2011-09-24 10:34 . 2011-09-24 10:34 -------- d-----w- c:\documents and settings\Ikke\Application Data\SUPERAntiSpyware.com
2011-09-24 10:33 . 2011-10-18 15:47 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-09-24 10:33 . 2011-09-24 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-09-21 16:25 . 2011-09-21 16:25 -------- d-----w- c:\documents and settings\Ikke\Application Data\DScaler4
2011-09-21 16:25 . 2011-09-21 16:25 -------- d-----w- c:\program files\DScaler
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 16:05 . 2011-05-21 05:42 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 09:41 . 2008-07-29 17:59 614912 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2003-06-02 08:49 23040 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2003-06-02 08:49 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2002-09-23 13:11 602624 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 20:45 . 2011-07-15 19:29 41184 ----a-w- c:\windows\avastSS.scr
2011-09-06 20:45 . 2011-07-15 19:29 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-09-06 20:38 . 2011-07-15 19:29 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-06 20:37 . 2011-07-15 19:29 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-09-06 20:36 . 2011-07-15 19:29 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-09-06 20:36 . 2011-07-15 19:29 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-09-06 20:36 . 2011-07-15 19:29 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-09-06 20:36 . 2011-07-15 19:29 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-09-06 20:36 . 2011-07-15 19:29 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-09-06 20:33 . 2011-07-15 19:29 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-09-06 14:09 . 2003-06-02 08:49 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-08-31 15:00 . 2010-11-21 11:49 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-26 13:37 . 2011-08-26 13:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-08-26 13:37 . 2010-05-05 15:28 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-22 23:41 . 2006-06-23 12:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2003-06-02 08:48 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:41 . 2003-06-02 08:48 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:58 . 2007-01-21 13:54 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2003-06-02 08:48 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-09 18:10 . 2011-08-09 18:10 53248 ----a-r- c:\documents and settings\Ikke\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-08-09 18:10 . 2011-02-20 19:15 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-08-03 11:49 . 2011-09-16 16:55 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:49 . 2011-09-16 16:54 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:49 . 2011-09-16 16:54 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:49 . 2010-04-03 20:55 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49 . 2010-04-03 20:55 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:49 . 2010-04-03 20:55 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:49 . 2010-04-03 20:55 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:49 . 2010-04-03 20:55 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:49 . 2010-04-03 17:23 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-03 11:49 . 2010-04-03 17:23 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2010-04-03 17:23 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:49 . 2010-04-03 17:22 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2007-06-28 22:43 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2003-10-07 08:14 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2003-10-07 08:14 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-08-03 11:49 . 2003-10-07 08:14 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-09-30 12:28 . 2011-04-30 05:41 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-17_15.52.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 20:30 . 2008-04-14 20:30 57344 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 57344 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2011-10-19 16:26 . 2011-10-19 16:26 16384 c:\windows\Temp\Perflib_Perfdata_1f0.dat
+ 2011-10-18 15:57 . 2008-04-14 16:37 40448 c:\windows\system32\ReinstallBackups\0041\DriverFiles\i386\intelppm.sys
+ 2011-10-18 15:57 . 2008-04-14 16:37 40448 c:\windows\system32\ReinstallBackups\0036\DriverFiles\i386\intelppm.sys
+ 2011-10-18 15:57 . 2008-04-14 16:37 40448 c:\windows\system32\ReinstallBackups\0012\DriverFiles\i386\intelppm.sys
+ 2011-10-18 15:57 . 2008-04-14 16:37 40448 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\intelppm.sys
+ 2003-06-02 08:49 . 2011-10-17 16:50 91260 c:\windows\system32\perfc013.dat
+ 2003-06-02 08:49 . 2011-10-17 16:50 71858 c:\windows\system32\perfc009.dat
+ 2011-10-18 15:57 . 2008-04-14 20:32 20480 c:\windows\system32\dllcache\wmpui.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 73728 c:\windows\system32\dllcache\wmplayer.exe
+ 2011-10-18 15:57 . 2008-04-14 20:32 20480 c:\windows\system32\dllcache\wmpcore.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 20480 c:\windows\system32\dllcache\wmpcd.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 98304 c:\windows\system32\dllcache\wmpband.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 23552 c:\windows\system32\dllcache\wmdmps.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 27136 c:\windows\system32\dllcache\wmdmlog.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 10240 c:\windows\system32\dllcache\npwmsdrm.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 52736 c:\windows\system32\dllcache\mspmsnsv.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 87040 c:\windows\system32\dllcache\drmstor.dll
- 2003-06-02 09:05 . 2008-09-18 17:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2003-06-02 09:05 . 2011-10-18 16:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-10-18 16:05 . 2011-10-18 16:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012011101820111019\index.dat
- 2003-06-02 09:05 . 2008-09-18 17:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2003-06-02 09:05 . 2011-10-18 16:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2011-10-18 16:04 . 2011-10-18 16:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2003-06-02 09:02 . 2008-09-18 17:32 76487 c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
+ 2003-06-02 09:02 . 2011-10-17 16:51 76487 c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
+ 2011-10-18 16:32 . 2011-10-18 16:32 22016 c:\windows\Installer\19e5aa.msi
- 2004-08-04 00:03 . 2008-04-14 17:03 7680 c:\windows\system32\spdwnwxp.exe
+ 2004-08-04 00:03 . 2008-04-14 20:33 7680 c:\windows\system32\spdwnwxp.exe
+ 2011-10-18 15:57 . 2008-04-14 20:31 4126 c:\windows\system32\dllcache\msdxmlc.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 4639 c:\windows\system32\dllcache\mplayer2.exe
+ 2011-10-18 15:57 . 2008-04-14 20:32 6656 c:\windows\system32\dllcache\laprxy.dll
+ 2011-10-18 15:57 . 2008-04-14 20:02 8192 c:\windows\system32\dllcache\asferror.dll
+ 2003-06-02 09:10 . 2008-04-14 20:02 8192 c:\windows\system32\asferror.dll
+ 2003-06-02 09:02 . 2011-10-17 16:51 2934 c:\windows\PCHealth\HelpCtr\PackageStore\SkuStore.bin
- 2008-09-18 15:48 . 2008-04-14 16:40 135680 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_nl_71cbebcb\rtcres.dll
+ 2008-04-14 20:10 . 2008-04-14 20:10 135680 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_nl_71cbebcb\rtcres.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 992768 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 992768 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 852992 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 852992 c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 343040 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 343040 c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2007-01-21 14:58 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
+ 2007-01-21 14:58 . 2008-04-14 20:32 121856 c:\windows\system32\xmllite.dll
- 2003-06-02 09:10 . 2004-08-04 00:03 102400 c:\windows\system32\wmpshell.dll
+ 2003-06-02 09:10 . 2008-04-14 20:32 102400 c:\windows\system32\wmpshell.dll
- 2008-09-18 17:45 . 2004-08-04 00:03 221184 c:\windows\system32\wmpns.dll
+ 2008-09-18 17:45 . 2008-04-14 20:32 221184 c:\windows\system32\wmpns.dll
+ 2003-06-02 09:10 . 2008-04-14 20:32 114688 c:\windows\system32\wmpasf.dll
- 2003-06-02 09:10 . 2004-08-04 00:03 114688 c:\windows\system32\wmpasf.dll
- 2003-06-02 09:10 . 2004-08-04 00:02 189952 c:\windows\system32\wmerror.dll
+ 2003-06-02 09:10 . 2008-04-14 20:06 189952 c:\windows\system32\wmerror.dll
- 2009-04-06 19:31 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2009-04-06 19:31 . 2008-04-14 20:32 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2010-08-30 20:26 . 2008-04-14 20:32 543232 c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
+ 2010-08-30 20:26 . 2008-04-14 20:32 728576 c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
+ 2011-10-18 15:57 . 2008-04-13 16:36 144384 c:\windows\system32\ReinstallBackups\0042\DriverFiles\hdaudbus.sys
+ 2003-06-02 08:49 . 2011-10-17 16:50 508344 c:\windows\system32\perfh013.dat
+ 2003-06-02 08:49 . 2011-10-17 16:50 440598 c:\windows\system32\perfh009.dat
+ 2011-10-18 15:57 . 2008-04-14 20:32 809984 c:\windows\system32\dllcache\wmvdmod.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 303616 c:\windows\system32\dllcache\wmstream.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 897024 c:\windows\system32\dllcache\wmspdmoe.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 115200 c:\windows\system32\dllcache\wmsdmoe.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 759296 c:\windows\system32\dllcache\wmsdmod.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 102400 c:\windows\system32\dllcache\wmpshell.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 221184 c:\windows\system32\dllcache\wmpns.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 114688 c:\windows\system32\dllcache\wmpasf.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 151552 c:\windows\system32\dllcache\wmidx.dll
+ 2011-10-18 15:58 . 2008-04-14 20:06 189952 c:\windows\system32\dllcache\wmerror.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 670720 c:\windows\system32\dllcache\wmadmoe.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 408064 c:\windows\system32\dllcache\wmadmod.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 208896 c:\windows\system32\dllcache\unregmp2.exe
+ 2011-10-18 15:57 . 2008-04-14 20:32 155136 c:\windows\system32\dllcache\shmedia.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 774144 c:\windows\system32\dllcache\setup_wm.exe
+ 2011-10-18 15:57 . 2008-04-14 20:33 226816 c:\windows\system32\dllcache\npdrmv2.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 246272 c:\windows\system32\dllcache\mswmdm.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 356352 c:\windows\system32\dllcache\msscp.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 201728 c:\windows\system32\dllcache\mspmsp.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 259072 c:\windows\system32\dllcache\msnetobj.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 368640 c:\windows\system32\dllcache\mpvis.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 124416 c:\windows\system32\dllcache\mplay32.exe
+ 2011-10-18 15:57 . 2008-04-14 20:32 240640 c:\windows\system32\dllcache\mpg4dmod.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 384512 c:\windows\system32\dllcache\mp4sdmod.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 310272 c:\windows\system32\dllcache\mp43dmod.dll
+ 2011-10-18 15:58 . 2008-04-14 20:33 786432 c:\windows\system32\dllcache\migrate.exe
+ 2011-10-18 15:57 . 2008-04-14 20:33 695808 c:\windows\system32\dllcache\drmv2clt.dll
+ 2011-10-18 15:57 . 2008-04-14 20:33 299520 c:\windows\system32\dllcache\drmclien.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 294912 c:\windows\system32\dllcache\dlimport.exe
+ 2011-10-18 15:57 . 2008-04-14 20:32 159232 c:\windows\system32\dllcache\cewmdm.dll
+ 2011-10-18 15:57 . 2008-04-14 20:32 286720 c:\windows\system32\dllcache\blackbox.dll
- 2003-06-02 09:10 . 2004-08-04 00:03 208896 c:\windows\inf\unregmp2.exe
+ 2003-06-02 09:10 . 2008-04-14 20:33 208896 c:\windows\inf\unregmp2.exe
- 2008-09-18 15:48 . 2008-04-14 17:00 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
+ 2008-04-14 20:30 . 2008-04-14 20:30 1011774 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
- 2008-09-18 15:48 . 2008-04-14 17:00 1011774 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2003-06-02 09:10 . 2008-04-14 20:08 2965504 c:\windows\system32\wmploc.dll
- 2003-06-02 09:10 . 2004-08-04 00:02 2965504 c:\windows\system32\wmploc.dll
- 2008-09-18 15:49 . 2009-07-31 09:05 1372672 c:\windows\system32\msxml6.dll
+ 2008-09-18 15:49 . 2009-07-31 08:05 1372672 c:\windows\system32\msxml6.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 1001472 c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2011-10-18 15:58 . 2008-04-14 20:32 1119744 c:\windows\system32\dllcache\wmsdmoe2.dll
+ 2011-10-18 15:57 . 2008-04-14 20:08 2965504 c:\windows\system32\dllcache\wmploc.dll
- 2008-09-18 15:49 . 2009-07-31 09:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2008-09-18 15:49 . 2009-07-31 08:05 1372672 c:\windows\system32\dllcache\msxml6.dll
.
-- Snapshot teruggezet naar huidige datum --
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-10-18 4615552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"36X Raid Configurer"="c:\windows\system32\JMRaidSetup.exe" [2006-11-16 1953792]
"Ai Remote Help"="c:\program files\ASUS\AI Remote\AiRc.exe" [2007-01-19 3347456]
"AsusServiceProvider"="c:\program files\ASUS\AASP\1.00.23\aaCenter.exe" [2007-01-05 597504]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.23\AsRunHelp.exe" [2006-12-29 363008]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-01-11 1423360]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1386776]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-10-09 1036288]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Ikke\Menu Start\Programma's\Opstarten\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Security Toolbar Service"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\ASUS\\ASUSUpdate\\Update.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Ikke\\Mijn documenten\\Downloads\\tinyumbrella-4.30.03.exe"=
"c:\\Documents and Settings\\Ikke\\Mijn documenten\\Downloads\\tinyumbrella-4.30.03(2).exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:Shareaza
"6346:UDP"= 6346:UDP:Shareaza
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [22-4-2007 15:11 716272]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [15-7-2011 21:29 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [15-7-2011 21:29 320856]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22-7-2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12-7-2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12-8-2011 1:38 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15-7-2011 21:29 20568]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [20-2-2011 21:15 12184]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [16-9-2011 18:55 2255464]
R2 PrivateDiskDriver;Private Encrypted Virtual Disk Driver;c:\windows\system32\drivers\PrivateDisk.sys [4-4-2009 20:06 42579]
R2 PrivateDiskService;Private Encrypted Virtual Disk;c:\program files\SINOSUN\TPM Secure Tools\Common\PrivateDisk.exe [4-4-2009 20:07 6656]
R2 SinoTCS;Trusted Platform Core Service (SINOSUN);c:\program files\SINOSUN\TPM Secure Tools\TSS\SinoTCS.exe [4-4-2009 20:07 720960]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;c:\windows\system32\drivers\PhTVTune.sys [31-7-2003 11:04 24704]
R3 SinoTPM;Driver For SINOSUN Trusted Platform Module;c:\windows\system32\drivers\SinoTpm.sys [4-4-2009 20:06 34048]
S2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21-5-2011 9:17 136176]
S2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe --> c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [?]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\drivers\ADM851X.sys [29-7-2010 15:10 26190]
S3 Amps2prt;Trust Ami PS/2 Port Mouse Driver (6);c:\windows\system32\drivers\Amps2prt.sys [19-10-2001 13:57 9056]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [?]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe --> c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [?]
S3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [21-5-2011 9:17 136176]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [3-12-2007 0:52 47360]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\DRIVERS\TMPassthru.sys --> c:\windows\system32\DRIVERS\TMPassthru.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscsi.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S4 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe --> c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [?]
.
Inhoud van de 'Gedeelde Taken' map
.
2011-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-21 07:17]
.
2011-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-21 07:17]
.
.
------- Bijkomende Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Download with &Shareaza - c:\program files\Shareaza\Plugins\RazaWebHook.dll/3000
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Search Using Copernic Agent - c:\program files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
TCP: DhcpNameServer = 62.179.104.196 213.46.228.196
DPF: DirectAnimation Java Classes - file://c" onclick="window.open(this.href);return false;:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c" onclick="window.open(this.href);return false;:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Ikke\Application Data\Mozilla\Firefox\Profiles\ygt4py6z.default\
FF - prefs.js: browser.search.selectedEngine - Google (Language: nl)
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net" onclick="window.open(this.href);return false;
Rootkit scan 2011-10-19 19:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
.
C:\## aswSnx private storage
.
Scan succesvol afgerond
verborgen bestanden: 1
.
**************************************************************************
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
.
- - - - - - - > 'winlogon.exe'(536)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'explorer.exe'(3244)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Voltooingstijd: 2011-10-19 19:07:31 - machine werd herstart
ComboFix-quarantined-files.txt 2011-10-19 17:07
ComboFix2.txt 2011-10-17 15:57
ComboFix3.txt 2010-12-06 20:19
.
Pre-Run: 43.402.248.192 bytes beschikbaar
Post-Run: 43.268.599.808 bytes beschikbaar
.
Current=3 Default=3 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 049A6E734CC55833AABA7F8B31CAA6B0
35
Hoi,

1. Download CCleaner Slim

Installeer CCleaner en start CCleaner op.
  • Klik in de linkse kolom op Cleaner.
  • Klik achtereenvolgens op Analyseren en Opschonen.
  • Klik vervolgens in de linkse kolom op Register en klik op Scan naar problemen.
  • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen en OK.
  • Dan krijg je de vraag om een back-up te maken, klik op JA. en kies dan Herstel alle geselecteerde fouten.
  • Sluit hierna CCleaner af.

2. Download Defraggler
Zorg er wel voor dat je tijdens de installatie het vinkje weg haalt bij "Install optional Yahoo! Toolbar"
Klik bij Schijf op de schijf waar je Windows op hebt geïnstalleerd.
Kies vervolgens voor Defragmenteer
Zeker de eerste keer zal dit proces tijd vergen!

Is er nu verbetering merkbaar?
Member of UNITE Unified Network of Instructors and Trained Eliminators (Unite Against Malware)
41
Hoi,

De volgende programma's en bijbehorende log bestanden mag je verwijderen.
  • DDS
  • aswMBR
  • ComboFix via de onderstaande instructies.
Verwijderen ComboFix, kopiëer het onderstaande commando met (Ctrl + C):
Combofix /Uninstall (let op!!! de spatie voor /Uninstall)

Klik Start -> Uitvoeren, en plak (Ctrl + V) het commando, toets vervolgens Ctrl + Shift + Enter. Afbeelding
Aangezien de problemen zijn verholpen adviseer ik u nog wel even het onderstaande uit te voeren.

1.) Systeemherstelpunten verwijderen
Als de computer geïnfecteerd is geweest met een malware infectie is het raadzaam om alle aanwezige systeemherstelpunten te verwijderen, want hier kunnen namelijk besmette herstelpunten tussen zitten.
  • Hoe u de herstelpunten verwijderd leest u hier
  • Hoe u zelf snel een nieuw systeemherstelpunt aan kunt maken leest u hier
2.) Installeren van essentiële updates.
Hoe u uw besturingssysteem en overige software up to date houdt kunt u hier lezen.
Door middel van het programma Secunia PSI wordt u automatisch gewaarschuwd indien er updates voor de geïnstalleerde software beschikbaar is, meer informatie leest u hier

3.) Pas op voor 'Phishing' berichten.
Phishing is een vorm van internet oplichting (fraude), met valse e-mailberichten en websites die er vertrouwd uitzien wordt er getracht 'logingegevens' en andere persoonlijke informatie te achterhalen.
Dit gebeurt vaak op hele slinkse manieren, zoals bijvoorbeeld e-mailberichten waarin u gevraagd wordt uw inloggegevens te verifiëren, in deze gevallen wordt u vaak naar een valse (clone) website gestuurd, zodra u uw gegevens hier hebt ingevoerd zijn deze in de handen van de kwaadwillende met alle gevolgen van dien.
Meer informatie leest u hier

4.) Gebruikersaccounts
Met dit account heeft u dus het volledige beheer van de computer in handen, het is dan ook niet aan te raden om dit account als primair account voor het dagelijkse gebruik in te stellen.
Meer informatie hierover leest u hier

5.) Risico's bij het downloaden
Peer to Peer (P2P) netwerken en ook Usenet (nieuwsgroepen) zijn een grote bron op het internet wat betreft het verspreiden van malware, het aanbieden van 'gevaarlijke' software (malware) gebeurt vrijwel anoniem waardoor dit een veel gebruikte methode is voor het verspreiden van malware.
Meer informatie hierover leest u hier

6.) Preventie informatie & het gebruik van beveiligings software.
Hier en hier staat informatie hoe u een infectie kunt voorkomen, lees dit eens op uw gemak door.

Meer informatie over het gebruik van "beveiligings software" en "valse (nep) software" (rogueware) leest u hier
Member of UNITE Unified Network of Instructors and Trained Eliminators (Unite Against Malware)
42
Hoi,

Eerst even dit; zet net mijn pc aan, start firefox op zit net op een website dmv een inlog
en BAM, zwart scherm....
Foutmelding die ik niet kon lezen omdat xp alweer aan het opstarten was.
Het was wel een meldscherm vanuit dos zo te zien omdat het een eenvoudig blauw scherm was met de melding hersteld van een ernstige fout.
De bijbehorende data voor het foutenrapport aan microsoft heb ik hieronder geplakt;

C:\DOCUME~1\Ikke\LOCALS~1\Temp\WER9583.dir00\Mini102811-01.dmp
C:\DOCUME~1\Ikke\LOCALS~1\Temp\WER9583.dir00\sysdata.xml

Ben benieuwd wat het kan zijn....

grt
Blokkendoos.
43
Hoi,

Even verder kijken wat de oorzaak kan zijn.

Download en installeer BlueScreenView
Na de installatie zal BlueScreenView starten.
Selecteer 1 bestand uit de lijst onder Dump File en druk op Ctrl+A
Klik vervolgens op File en daarna op Save Selected Items (Ctrl+S)
Sla het bestand op je bureaublad op. Open vervolgens dat bestand, en post de inhoud in je volgende post.
Member of UNITE Unified Network of Instructors and Trained Eliminators (Unite Against Malware)
44
Hoi,
hierbij het bestand;

==================================================
Dump File : Mini102811-01.dmp
Crash Time : 28-10-2011 15:20:20
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000005
Parameter 2 : 0xb80f83d1
Parameter 3 : 0xaa8196a8
Parameter 4 : 0x00000000
Caused By Driver : CLASSPNP.SYS
Caused By Address : CLASSPNP.SYS+3d1
File Description : SCSI Class System Dll
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Crash Address : CLASSPNP.SYS+3d1
Stack Address 1 : disk.sys+17d7
Stack Address 2 : CLASSPNP.SYS+13ed
Stack Address 3 : ntoskrnl.exe+1819f
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini102811-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
Dump File Size : 98.304
==================================================
Gesloten

Terug naar “Hulp bij malware problemen, adware, ongewenste software en een trage computer”