combofix
ComboFix 14-01-16.03 - Arvid Beekman 21-01-2014 10:23:50.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.4095.2565 [GMT 1:00]
Gestart vanuit: c:\users\Arvid Beekman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MQNGC0Q1\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Arvid Beekman\AppData\Roaming\Microsoft\engine_ag.dll
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2013-12-21 to 2014-01-21 ))))))))))))))))))))))))))))))
.
.
2014-01-21 09:31 . 2014-01-21 09:31 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-01-21 09:31 . 2014-01-21 09:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-21 09:17 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29F7ACDE-00F0-47EF-94A6-8014049F8714}\mpengine.dll
2014-01-20 15:29 . 2014-01-20 15:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-20 15:29 . 2014-01-20 15:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-01-19 17:58 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-01-17 11:04 . 2012-06-01 05:36 192000 ----a-w- c:\windows\system32\iisRtl.dll
2014-01-17 11:04 . 2012-06-01 04:37 154624 ----a-w- c:\windows\SysWow64\iisRtl.dll
2014-01-17 11:04 . 2012-06-01 05:34 55296 ----a-w- c:\windows\system32\admwprox.dll
2014-01-17 11:04 . 2012-06-01 04:35 50688 ----a-w- c:\windows\SysWow64\admwprox.dll
2014-01-17 11:04 . 2012-06-01 05:39 14848 ----a-w- c:\windows\system32\wamregps.dll
2014-01-17 11:04 . 2012-06-01 05:35 60928 ----a-w- c:\windows\system32\ahadmin.dll
2014-01-17 11:04 . 2012-06-01 05:33 16896 ----a-w- c:\windows\system32\iisreset.exe
2014-01-17 11:04 . 2012-06-01 04:35 26624 ----a-w- c:\windows\SysWow64\ahadmin.dll
2014-01-17 11:04 . 2012-06-01 04:34 15360 ----a-w- c:\windows\SysWow64\iisreset.exe
2014-01-17 11:04 . 2012-06-01 05:36 11264 ----a-w- c:\windows\system32\iisrstap.dll
2014-01-17 11:04 . 2012-06-01 04:40 10752 ----a-w- c:\windows\SysWow64\wamregps.dll
2014-01-17 11:04 . 2012-06-01 04:37 8192 ----a-w- c:\windows\SysWow64\iisrstap.dll
2014-01-17 10:55 . 2013-12-01 13:10 257624 ----a-w- c:\windows\system32\unrar64.dll
2014-01-17 10:55 . 2013-12-01 13:10 218200 ----a-w- c:\windows\SysWow64\unrar.dll
2014-01-17 10:55 . 2014-01-17 10:55 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2014-01-16 14:30 . 2014-01-16 14:30 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\AnvSoft
2014-01-16 14:30 . 2014-01-16 14:30 -------- d-----w- c:\program files (x86)\AnvSoft
2014-01-16 10:03 . 2014-01-16 09:45 24064 ----a-w- c:\windows\zoek-delete.exe
2014-01-16 10:03 . 2014-01-21 09:31 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\Temp
2014-01-16 09:45 . 2014-01-16 09:57 -------- d-----w- C:\zoek_backup
2014-01-16 08:03 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-16 08:03 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-16 08:03 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-16 08:03 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-16 08:03 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-16 08:03 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-16 08:03 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-16 08:03 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2014-01-16 08:03 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-01-16 08:02 . 2014-01-16 08:02 -------- d-----w- C:\inetpub
2014-01-15 13:11 . 2014-01-15 13:11 -------- d-----w- C:\AMD
2014-01-15 12:43 . 2014-01-15 12:43 -------- d-----w- C:\rsit
2014-01-15 12:43 . 2014-01-15 12:43 -------- d-----w- c:\program files\trend micro
2014-01-15 09:24 . 2014-01-15 09:24 -------- d--h--w- c:\windows\AxInstSV
2014-01-15 09:09 . 2014-01-15 09:09 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\ElevatedDiagnostics
2014-01-11 10:45 . 2014-01-11 10:45 -------- d-----w- c:\windows\SysWow64\Adobe
2014-01-10 11:23 . 2014-01-10 11:23 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\Apowersoft
2014-01-09 12:32 . 2014-01-09 14:18 -------- d-----w- c:\users\Arvid Beekman\AppData\Roaming\Spotydl
2014-01-09 12:31 . 2014-01-09 12:32 -------- d-----w- c:\program files (x86)\Spotydl
2014-01-04 13:01 . 2014-01-04 13:01 -------- d-----w- c:\programdata\ASUS
2014-01-04 13:01 . 2014-01-04 13:01 -------- d-----w- c:\users\Arvid Beekman\AppData\Local\ASUS
2013-12-28 13:41 . 2013-12-28 13:41 -------- d-----w- c:\program files\iPod
2013-12-28 13:41 . 2013-12-28 13:43 -------- d-----w- c:\program files\iTunes
2013-12-28 13:41 . 2013-12-28 13:43 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-19 07:33 . 2013-10-14 17:10 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-01-16 08:13 . 2013-10-14 19:03 86054176 ----a-w- c:\windows\system32\MRT.exe
2013-11-23 18:26 . 2013-12-11 09:10 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-11 09:10 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-11-12 02:23 . 2013-12-11 09:10 2048 ----a-w- c:\windows\system32\tzres.dll
2013-11-12 02:07 . 2013-12-11 09:10 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-10-30 11:13 . 2013-11-21 19:29 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2013-10-30 11:07 . 2013-10-30 11:07 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2013-10-30 11:07 . 2013-10-30 11:07 330240 ----a-w- c:\windows\MASetupCaller.dll
2013-10-30 11:07 . 2013-10-30 11:07 30568 ----a-w- c:\windows\MusiccityDownload.exe
2013-10-30 11:06 . 2013-10-30 11:06 974848 ----a-w- c:\windows\SysWow64\cis-2.4.dll
2013-10-30 11:06 . 2013-10-30 11:06 81920 ----a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll
2013-10-30 11:06 . 2013-10-30 11:06 65536 ----a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll
2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\MTXSYNCICON.dll
2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\MK_Lyric.dll
2013-10-30 11:06 . 2013-10-30 11:06 57344 ----a-w- c:\windows\SysWow64\issacapi_se-2.3.dll
2013-10-30 11:06 . 2013-10-30 11:06 569344 ----a-w- c:\windows\SysWow64\muzdecode.ax
2013-10-30 11:06 . 2013-10-30 11:06 491520 ----a-w- c:\windows\SysWow64\muzapp.dll
2013-10-30 11:06 . 2013-10-30 11:06 49152 ----a-w- c:\windows\SysWow64\MaJGUILib.dll
2013-10-30 11:06 . 2013-10-30 11:06 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2013-10-30 11:06 . 2013-10-30 11:06 45056 ----a-w- c:\windows\SysWow64\MaXMLProto.dll
2013-10-30 11:06 . 2013-10-30 11:06 45056 ----a-w- c:\windows\SysWow64\MACXMLProto.dll
2013-10-30 11:06 . 2013-10-30 11:06 40960 ----a-w- c:\windows\SysWow64\MTTELECHIP.dll
2013-10-30 11:06 . 2013-10-30 11:06 352256 ----a-w- c:\windows\SysWow64\MSLUR71.dll
2013-10-30 11:06 . 2013-10-30 11:06 258048 ----a-w- c:\windows\SysWow64\muzoggsp.ax
2013-10-30 11:06 . 2013-10-30 11:06 245760 ----a-w- c:\windows\SysWow64\MSCLib.dll
2013-10-30 11:06 . 2013-10-30 11:06 24576 ----a-w- c:\windows\SysWow64\MASetupCleaner.exe
2013-10-30 11:06 . 2013-10-30 11:06 200704 ----a-w- c:\windows\SysWow64\muzwmts.dll
2013-10-30 11:06 . 2013-10-30 11:06 172032 ----a-w- c:\windows\SysWow64\muzapp.exe
2013-10-30 11:06 . 2013-10-30 11:06 155648 ----a-w- c:\windows\SysWow64\MSFLib.dll
2013-10-30 11:06 . 2013-10-30 11:06 143360 ----a-w- c:\windows\SysWow64\3DAudio.ax
2013-10-30 11:06 . 2013-10-30 11:06 135168 ----a-w- c:\windows\SysWow64\muzaf1.dll
2013-10-30 11:06 . 2013-10-30 11:06 131072 ----a-w- c:\windows\SysWow64\muzmpgsp.ax
2013-10-30 11:06 . 2013-10-30 11:06 122880 ----a-w- c:\windows\SysWow64\muzeffect.ax
2013-10-30 11:06 . 2013-10-30 11:06 118784 ----a-w- c:\windows\SysWow64\MaDRM.dll
2013-10-30 11:06 . 2013-10-30 11:06 110592 ----a-w- c:\windows\SysWow64\muzmp4sp.ax
2013-10-30 11:06 . 2013-11-21 19:29 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll
2013-10-30 08:59 . 2013-10-30 08:59 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-10-30 08:59 . 2013-10-30 08:59 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-10-30 08:59 . 2013-10-30 08:59 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2013-10-30 08:59 . 2013-10-30 08:59 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2013-10-30 08:59 . 2013-10-30 08:59 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2013-10-30 08:59 . 2013-10-30 08:59 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-10-30 08:59 . 2013-10-30 08:59 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2013-10-30 08:59 . 2013-10-30 08:59 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-10-30 08:59 . 2013-10-30 08:59 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-10-30 08:59 . 2013-10-30 08:59 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-10-30 08:59 . 2013-10-30 08:59 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2013-10-30 08:59 . 2013-10-30 08:59 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-10-30 08:59 . 2013-10-30 08:59 296960 ----a-w- c:\windows\system32\d3d10core.dll
2013-10-30 08:59 . 2013-10-30 08:59 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2013-10-30 08:59 . 2013-10-30 08:59 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-10-30 08:59 . 2013-10-30 08:59 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2013-10-30 08:59 . 2013-10-30 08:59 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-10-30 08:59 . 2013-10-30 08:59 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-10-30 08:59 . 2013-10-30 08:59 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2013-10-30 08:59 . 2013-10-30 08:59 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2013-10-30 08:59 . 2013-10-30 08:59 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-10-30 08:59 . 2013-10-30 08:59 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2013-10-30 08:59 . 2013-10-30 08:59 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2013-10-30 08:59 . 2013-10-30 08:59 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2013-10-30 08:59 . 2013-10-30 08:59 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-10-30 08:59 . 2013-10-30 08:59 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2013-10-30 08:59 . 2013-10-30 08:59 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-10-30 08:59 . 2013-10-30 08:59 1238528 ----a-w- c:\windows\system32\d3d10.dll
2013-10-30 08:59 . 2013-10-30 08:59 1175552 ----a-w- c:\windows\system32\FntCache.dll
2013-10-30 08:59 . 2013-10-30 08:59 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2013-10-30 02:32 . 2013-12-11 09:10 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-10-30 02:19 . 2013-12-11 09:10 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-10-28 16:44 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2013-10-28 16:44 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2013-10-26 08:26 . 2013-12-06 14:12 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{465ED3EC-3071-4C89-923D-033AF590D9C1}\gapaengine.dll
2013-10-26 08:26 . 2013-10-26 08:26 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-11-02 11:35 1727176 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"="c:\users\Arvid Beekman\Kies\Kies.exe" [2013-11-06 1564528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"="c:\users\Arvid Beekman\Kies\KiesTrayAgent.exe" [2013-11-06 311152]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-17 2245120]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2010-01-13 7109248]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2010-01-05 170624]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-11 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R4 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys;c:\program files\ATKGFNEX\ASMMAP64.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Inhoud van de 'Gedeelde Taken' map
.
2014-01-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-20 15:29]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-11-02 11:30 2331336 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
.
------- Bijkomende Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
https://www.google.nl/
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.254 195.121.1.34 195.121.1.66
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
.
- - - - ORPHANS VERWIJDERD - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-PC Cleaners - c:\programdata\pclunst.exe
AddRemove-UpdaterEX - c:\users\Arvid Beekman\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe
.
.
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_38_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_38.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Voltooingstijd: 2014-01-21 10:35:14
ComboFix-quarantined-files.txt 2014-01-21 09:35
ComboFix2.txt 2013-12-15 18:49
.
Pre-Run: 2.100.330.496 bytes beschikbaar
Post-Run: 2.284.457.984 bytes beschikbaar
.
- - End Of File - - CE46A40B831386729A9798F8CFF00963
5C616939100B85E558DA92B899A0FC36