ComboFix 10-01-04.01 - Chrétienne 10-01-2010 9:36.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3070.2119 [GMT 1:00]
Gestart vanuit: c:\users\Chrétienne\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1796560525-4208644463-2362124044-500
Besmet exemplaar van c:\windows\system32\DRIVERS\iaStor.sys werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - Kitty ate it
.
(((((((((((((((((((( Bestanden Gemaakt van 2009-12-10 to 2010-01-10 ))))))))))))))))))))))))))))))
.
2010-01-10 08:47 . 2010-01-10 08:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-09 16:22 . 2010-01-09 16:22 -------- d-----w- c:\program files\ESET
2010-01-09 12:35 . 2010-01-09 12:35 -------- d-----w- c:\programdata\Kaspersky Lab
2010-01-09 10:38 . 2010-01-09 10:38 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-09 10:38 . 2010-01-09 10:38 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-09 10:37 . 2010-01-09 10:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-09 08:57 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 08:57 . 2010-01-09 08:57 -------- d-----w- c:\programdata\Malwarebytes
2010-01-09 08:57 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-09 08:57 . 2010-01-09 08:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-08 19:39 . 2010-01-08 19:40 -------- d-----w- c:\program files\GIMP-2.0
2010-01-08 09:58 . 2010-01-08 09:58 -------- d-----w- c:\program files\eMule
2010-01-07 20:55 . 2009-12-02 13:19 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-07 19:51 . 2010-01-07 19:51 -------- dc----w- c:\windows\system32\DRVSTORE
2010-01-07 19:51 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-07 19:51 . 2010-01-07 19:51 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-07 19:51 . 2010-01-07 19:51 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-07 19:51 . 2010-01-07 19:51 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-07 19:46 . 2010-01-07 19:46 -------- d-----w- c:\program files\Lavasoft
2010-01-05 19:11 . 2010-01-05 19:11 -------- d-----w- c:\program files\Common Files\Oberon Media
2010-01-05 19:11 . 2010-01-05 19:46 -------- d-----w- c:\program files\Spelletjes.nl
2010-01-04 17:00 . 2010-01-04 17:18 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2010-01-04 16:50 . 2009-08-05 15:57 35680 ----a-w- c:\windows\system32\drivers\fses.sys
2010-01-04 16:50 . 2009-08-05 15:57 71040 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2010-01-04 15:07 . 2010-01-04 15:08 -------- d-----w- C:\sysmon
2010-01-02 12:00 . 2010-01-04 15:52 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-02 12:00 . 2010-01-04 15:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-28 18:58 . 2009-12-28 19:03 -------- d-----w- c:\program files\Super Mario Blue Twilight DX
2009-12-25 08:14 . 2009-12-25 08:14 970504 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-24 14:37 . 2009-12-24 14:37 -------- d-----w- c:\program files\GameTop.com
2009-12-20 10:46 . 2010-01-10 08:47 12 ----a-w- c:\windows\bthservsdp.dat
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 08:48 . 2009-10-13 00:27 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-01-10 08:41 . 2008-04-16 11:26 677096 ----a-w- c:\windows\system32\perfh013.dat
2010-01-10 08:41 . 2008-04-16 11:26 131312 ----a-w- c:\windows\system32\perfc013.dat
2010-01-08 09:58 . 2009-10-24 15:43 -------- d-----w- c:\programdata\eMule
2010-01-07 19:51 . 2010-01-07 19:46 -------- d-----w- c:\programdata\Lavasoft
2010-01-07 19:51 . 2010-01-07 19:51 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-07 19:51 . 2010-01-07 19:51 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-01-07 19:51 . 2010-01-07 19:51 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-07 19:50 . 2010-01-07 19:50 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-07 19:50 . 2010-01-07 19:50 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-07 19:50 . 2010-01-07 19:50 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-07 19:50 . 2010-01-07 19:50 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-01-07 19:50 . 2010-01-07 19:50 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-07 19:50 . 2010-01-07 19:50 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-07 19:50 . 2010-01-07 19:50 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-07 19:47 . 2010-01-07 19:47 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-04 17:16 . 2009-10-22 16:42 -------- d-----w- c:\program files\Internetbeveiling
2010-01-04 17:12 . 2009-10-22 16:42 -------- d-----w- c:\programdata\fssg
2010-01-04 16:49 . 2009-10-22 16:40 -------- d-----w- c:\programdata\f-secure
2009-12-10 02:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-07 14:10 . 2010-01-07 19:47 2953352 -c--a-w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-11-24 17:39 . 2009-11-24 17:36 -------- d-----w- c:\programdata\Zylom
2009-11-24 17:38 . 2009-11-24 17:36 -------- d-----w- c:\program files\Zylom Games
2009-11-21 06:40 . 2009-12-30 16:45 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-30 16:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-30 16:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-30 16:45 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-20 14:53 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2009-11-19 06:22 . 2009-11-19 06:22 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-19 06:22 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-19 06:22 . 2009-11-19 06:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-12 19:24 . 2009-11-12 19:24 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-09 12:31 . 2009-12-10 02:02 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-10 02:02 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-10 02:02 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-11-02 19:42 . 2009-10-22 17:33 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-25 19:29 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-23 14:01 . 2009-11-24 17:36 102400 ----a-w- c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-10-13 00:23 . 2009-10-13 00:23 33136 ----a-w- c:\windows\ASScrPro.exe
2009-10-13 00:23 . 2009-10-13 00:23 4814371 ----a-w- c:\windows\ASUS Camera ScreenSaver.exe
2009-10-13 00:23 . 2009-10-13 00:23 37232 ----a-w- c:\windows\ASScrProlog.exe
2009-10-13 00:23 . 2009-10-13 00:23 274800 ----a-w- c:\windows\ASUS Camera ScreenSaver Uninstaller.exe
2009-10-13 00:23 . 2009-10-13 00:23 503808 ----a-w- c:\windows\Asus_Camera_ScreenSaver.scr
2009-10-13 00:23 . 2009-10-13 00:23 606848 ----a-w- c:\windows\flashax.exe
2009-10-13 00:23 . 2009-10-13 00:23 12288 ----a-w- c:\windows\impborl.dll
2009-10-12 23:49 . 2009-10-12 23:49 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-10-12 23:49 . 2009-10-12 23:49 315392 ----a-w- c:\windows\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Manager"="c:\program files\Internetbeveiling\Common\FSM32.EXE" [2009-08-05 199264]
"F-Secure TNB"="c:\program files\Internetbeveiling\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):03,7b,c8,64,16,5a,ca,01
R0 fsbts;fsbts;c:\windows\System32\drivers\fsbts.sys [4-1-2010 18:00 33920]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [7-1-2010 20:51 64288]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Internetbeveiling\HIPS\drivers\fshs.sys [4-1-2010 17:49 68064]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [4-1-2010 17:50 35680]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [4-1-2010 17:50 71040]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\Internetbeveiling\Anti-Virus\minifilter\fsvista.sys [4-1-2010 17:48 12384]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5-1-2010 7:56 9968]
R1 SAS***IL;SAS***IL;c:\program files\SUPERAntiSpyware\SAS***IL.SYS [5-1-2010 7:56 74480]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2-12-2009 14:19 1181328]
R2 ***laby;***laby;c:\windows\System32\drivers\***laby.sys [13-10-2009 1:17 15416]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [27-6-2007 14:00 46592]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Internetbeveiling\Anti-Virus\minifilter\fsgk.sys [4-1-2010 17:48 107104]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5-1-2010 7:56 7408]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21-1-2008 3:23 21504]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\Internetbeveiling\ORSP Client\fsorsp.exe [4-1-2010 17:49 55936]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Internetbeveiling\Anti-Virus\win2k\fsfilter.sys [4-1-2010 17:48 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Internetbeveiling\Anti-Virus\win2k\fsrec.sys [4-1-2010 17:48 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Inhoud van de 'Gedeelde Taken' map
2010-01-09 c:\windows\Tasks\User_Feed_Synchronization-{D246F031-BBE3-401F-8154-5AA7E8AEF314}.job
- c:\windows\system32\msfeedssync.exe [2009-12-30 04:59]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://www.google.nl/
LSP: c:\program files\Internetbeveiling\FSPS\program\FSLSP.DLL
FF - ProfilePath - c:\users\Chrétienne\AppData\Roaming\Mozilla\Firefox\Profiles\u344cx1h.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.nl/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-10 09:50
Windows 6.0.6002 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\program files\internetbeveiling\hips\fshook32.dll
- - - - - - - > 'lsass.exe'(760)
c:\program files\internetbeveiling\hips\fshook32.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\windows\system32\WLANExt.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATKOSD2\ATKOSD2.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\ASUS CopyProtect\ASPG.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Internetbeveiling\Anti-Virus\fsgk32st.exe
c:\program files\Internetbeveiling\Anti-Virus\FSGK32.EXE
c:\program files\Internetbeveiling\Common\FSMA32.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Internetbeveiling\Anti-Virus\fssm32.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Voltooingstijd: 2010-01-10 09:59:00 - machine werd herstart
ComboFix-quarantined-files.txt 2010-01-10 08:58
Pre-Run: 81.656.823.808 bytes beschikbaar
Post-Run: 81.620.365.312 bytes beschikbaar
- - End Of File - - 85DA23DDF984CB8AC5ACE0F42A9EFE9E
Nou volgens mij heb ik nog nooit zoveel programma's op dit gebied gerund. Zou het er nu niet eens uit zijn?
