Hier de log van ComboFix:
ComboFix 10-01-11.04 - Thirza 12-01-2010 18:03:17.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1918.1416 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Thirza\Bureaublad\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\183736.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\prsgrc.dll
.
(((((((((((((((((((( Bestanden Gemaakt van 2009-12-12 to 2010-01-12 ))))))))))))))))))))))))))))))
.
2010-01-10 15:04 . 2010-01-11 20:04 -------- d-----w- c:\program files\a-squared Free
2010-01-10 14:00 . 2010-01-11 10:14 52224 ----a-w- c:\documents and settings\Thirza\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-10 14:00 . 2010-01-11 10:14 117760 ----a-w- c:\documents and settings\Thirza\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-10 13:58 . 2010-01-10 13:58 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-10 13:57 . 2010-01-10 13:57 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-10 13:57 . 2010-01-10 13:57 -------- d-----w- c:\documents and settings\Thirza\Application Data\SUPERAntiSpyware.com
2010-01-10 13:56 . 2010-01-10 13:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-10 12:25 . 2010-01-10 12:25 -------- d-----w- c:\documents and settings\Thirza\Application Data\Malwarebytes
2010-01-10 12:25 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-10 12:25 . 2010-01-10 12:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-10 12:25 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 12:25 . 2010-01-10 12:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-10 11:38 . 2010-01-10 11:38 -------- d-----w- c:\documents and settings\Thirza\Application Data\Leadertech
2010-01-08 12:14 . 2010-01-08 12:14 -------- d-----w- c:\program files\Common Files\SPSS
2010-01-08 12:14 . 2010-01-08 12:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SPSS
2010-01-08 12:14 . 2010-01-08 12:14 -------- d-----w- c:\program files\SPSSInc
2010-01-08 12:13 . 2010-01-08 12:13 1025 ----a-w- c:\windows\system32\sysprs7.dll
2009-12-22 11:59 . 2009-12-22 11:58 4043544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 11:59 . 2009-12-18 15:13 294656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-20 20:27 . 2009-12-20 20:32 -------- d-----w- c:\documents and settings\Thirza\Application Data\WinFF
2009-12-20 20:27 . 2009-12-20 20:27 -------- d-----w- c:\program files\WinFF
2009-12-20 18:08 . 2009-12-22 20:51 -------- d-----w- c:\documents and settings\Thirza\Local Settings\Application Data\WMTools Downloaded Files
2009-12-20 17:25 . 2009-12-20 17:25 -------- d-----w- c:\program files\DVDVideoSoft
2009-12-20 17:25 . 2009-12-20 17:25 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 11:31 . 2009-07-27 20:55 -------- d-----w- c:\documents and settings\Thirza\Application Data\uTorrent
2010-01-08 15:10 . 2009-07-12 16:05 20968 ----a-w- c:\documents and settings\Thirza\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-03 16:22 . 2009-07-24 14:35 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-23 22:02 . 2009-07-24 15:14 -------- d-----w- c:\documents and settings\Thirza\Application Data\Skype
2009-12-23 21:41 . 2009-07-24 15:15 -------- d-----w- c:\documents and settings\Thirza\Application Data\skypePM
2009-12-22 11:58 . 2009-11-12 17:19 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-11 18:37 . 2004-08-04 10:00 90988 ----a-w- c:\windows\system32\perfc013.dat
2009-12-11 18:37 . 2004-08-04 10:00 509478 ----a-w- c:\windows\system32\perfh013.dat
2009-11-11 18:32 . 2009-07-12 19:45 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-03 10:03 . 2009-07-12 19:45 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-03 10:03 . 2009-07-12 19:45 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-03 10:03 . 2009-07-12 19:45 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-29 17:46 . 2009-10-29 17:46 74072 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-10-29 13:21 . 2009-10-29 13:21 17480 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-10-29 07:44 . 2006-03-04 03:35 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:40 . 2004-08-04 10:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:40 . 2004-08-04 10:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-19 13:32 . 2009-10-19 13:18 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"btk"="c:\windows\system32\btk.exe \u" [X]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programma's\Opstarten\
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2009-9-25 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-03 10:03 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\BitTorrent\\uTorrent.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.com"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12-7-2009 20:45 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12-7-2009 20:45 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5-1-2010 7:56 9968]
R1 SAS***IL;SAS***IL;c:\program files\SUPERAntiSpyware\SAS***IL.SYS [5-1-2010 7:56 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [10-1-2010 16:04 1858144]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3-11-2009 11:03 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3-11-2009 11:03 285392]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5-1-2010 7:56 7408]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://student.fss.uu.nl/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS VERWIJDERD - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 18:07
Windows 5.1.2600 Service Pack 3 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–}|ÿÿÿÿÀ•}|ù•9~*]
"3140111900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Voltooingstijd: 2010-01-12 18:08:09
ComboFix-quarantined-files.txt 2010-01-12 17:08
Pre-Run: 33.154.084.864 bytes beschikbaar
Post-Run: 33.197.477.888 bytes beschikbaar
WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - F5F7C568E1858E4E5D398DC1539DCAF2