ComboFix 11-06-17.04 - Ruud 06/19/2011 16:48:34.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1014.317 [GMT 2:00] Gestart vanuit: c:\documents and settings\Ruud\Mijn documenten\Downloads\ComboFix.exe . . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Ruud\Application Data\Local c:\documents and settings\Ruud\Application Data\Local\Temp\DDM\Settings\FG_S04E14_ns.avi.ddr c:\documents and settings\Ruud\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\FG_S04E14_ns.avi(2).ddp c:\documents and settings\Ruud\Application Data\PriceGong c:\documents and settings\Ruud\Application Data\PriceGong\Data\1.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\a.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\b.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\c.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\d.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\e.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\f.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\g.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\h.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\i.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\J.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\k.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\l.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\m.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\mru.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\n.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\o.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\p.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\q.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\r.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\s.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\t.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\u.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\v.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\w.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\x.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\y.xml c:\documents and settings\Ruud\Application Data\PriceGong\Data\z.xml c:\documents and settings\Ruud\WINDOWS c:\firststeps\FirstSteps.exe c:\windows\IsUn0413.exe . . (((((((((((((((((((( Bestanden Gemaakt van 2011-05-19 to 2011-06-19 )))))))))))))))))))))))))))))) . . 2011-06-19 13:13 . 2011-06-19 13:14 -------- d-----w- C:\rsit 2011-06-19 12:45 . 2011-06-19 12:45 -------- d-----w- c:\documents and settings\Ruud\Application Data\Malwarebytes 2011-06-19 12:45 . 2011-05-29 07:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-06-19 12:45 . 2011-06-19 12:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-06-19 12:45 . 2011-06-19 12:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-06-19 12:45 . 2011-05-29 07:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-06-19 12:30 . 2011-06-19 12:30 388096 ----a-r- c:\documents and settings\Ruud\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-06-19 12:30 . 2011-06-19 13:18 -------- d-----w- c:\program files\Trend Micro 2011-06-19 09:51 . 2011-05-09 20:46 6962000 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{67D6DEE0-8D6E-4A2A-8C96-A0E2CED56DBE}\mpengine.dll 2011-06-19 09:49 . 2011-06-19 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2011-06-19 09:24 . 2011-06-19 09:24 -------- d-----w- c:\documents and settings\All Users\Application Data\boost_interprocess 2011-06-19 08:57 . 2011-06-19 08:57 -------- d-----w- c:\documents and settings\Ruud\AppData 2011-06-19 08:57 . 2011-06-19 08:57 -------- d-----w- c:\documents and settings\Ruud\Application Data\searchquband 2011-06-18 21:35 . 2011-06-18 21:36 -------- d-----w- c:\documents and settings\Ruud\Local Settings\Application Data\Ilivid Player 2011-06-18 21:35 . 2011-05-25 14:55 1524112 ------w- c:\windows\system32\bandoolmx.dll 2011-06-18 21:33 . 2011-06-19 08:57 -------- d-----w- c:\documents and settings\Ruud\Application Data\searchqutoolbar 2011-06-18 11:10 . 2011-06-18 11:10 -------- d-----w- c:\documents and settings\All Users\Application Data\RegTask 2011-05-24 10:04 . 2011-05-24 10:04 -------- d-----w- c:\documents and settings\Ruud\Local Settings\Application Data\AVG Security Toolbar . . . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-24 17:14 . 2010-12-08 09:05 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-05-02 15:31 . 2006-06-25 11:56 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-04-29 16:19 . 2006-06-25 14:49 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-25 16:05 . 2006-06-25 14:49 916480 ----a-w- c:\windows\system32\wininet.dll 2011-04-25 16:05 . 2006-06-25 14:49 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-04-25 16:05 . 2006-06-25 14:49 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-04-25 12:01 . 2006-06-25 14:49 385024 ----a-w- c:\windows\system32\html.iec 2011-04-21 13:37 . 2006-06-25 14:49 105472 ----a-w- c:\windows\system32\drivers\mup.sys 2011-04-11 07:04 . 2008-10-06 22:38 7071056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-04-14 16:57 . 2011-06-19 12:18 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "AvgUninstallURL"="start http:" [X] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "JavaQuickStarterService"=2 (0x2) "gusvc"=2 (0x2) "GoogleDesktopManager"=3 (0x3) "CVPND"=2 (0x2) . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"= "c:\\Program Files\\SopCast\\SopCast.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= . R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2/27/2006 4:00 PM 34880] R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2/20/2006 5:01 PM 29056] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/6/2006 3:42 PM 639224] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/19/2011 2:45 PM 366640] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/19/2011 2:45 PM 22712] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384] S3 APL531;Hercules Dualpix HD Webcam;c:\windows\system32\drivers\HDvid.sys [4/10/2007 9:33 PM 274816] S3 camfilt;camfilt;c:\windows\system32\drivers\camfilt.sys [4/10/2007 9:33 PM 22656] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/18/2011 2:21 AM 30192] S3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys --> c:\windows\system32\Drivers\ANDROIDUSB.sys [?] S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [3/10/2010 9:18 AM 24216] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/19/2011 2:45 PM 39984] S3 ovt530;Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [4/11/2007 10:49 PM 161792] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504] . Inhoud van de 'Gedeelde Taken' map . 2011-06-19 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20] . . ------- Bijkomende Scan ------- . mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 [removed] [removed] TCP: Interfaces\{47FE4466-2110-4B7E-BA08-FDD9B043BA3D}: NameServer = 192.168.1.254,195.241.77.55 FF - ProfilePath - c:\documents and settings\Ruud\Application Data\Mozilla\Firefox\Profiles\490zs88j.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4ddaca3e&v=7.005.030.004&i=26&tp=ab&iy=&ychte=nl&lng=nl&q= . - - - - ORPHANS VERWIJDERD - - - - . URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Toolbar-10 - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) Notify-iifefcca - iifefcca.dll AddRemove-Creative MediaSource CD-ROM Burner Plugin Unicode - c:\program files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe AddRemove-Creative MediaSource Net Content Plugin Unicode - c:\program files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe AddRemove-ZEN Plugin Unicode - c:\program files\Creative Installation Information\E-CENTER_PLUGIN_NOMADJUKEBOXTYPE2_U\Setup.exe AddRemove-Creative MediaSource Online Store Plugin - c:\program files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe AddRemove-Creative MediaSource Player Skin Pack Unicode - c:\program files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe AddRemove-Creative MediaSource Plugin for PlaysForSure Unicode - c:\program files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe AddRemove-Creative MediaSource Unicode - c:\program files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe AddRemove-Microsoft Interactive Training - c:\windows\IsUn0413.exe AddRemove-To-do List_is1 - c:\program files\HTP\To-do List\unins000.exe AddRemove-Xvid_is1 - c:\program files\Xvid\unins000.exe AddRemove-Yahoo! Toolbar - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-19 16:58 Windows 5.1.2600 Service Pack 3 NTFS . scannen van verborgen processen ... . scannen van verborgen autostart items ... . scannen van verborgen bestanden ... . Scan succesvol afgerond verborgen bestanden: 0 . ************************************************************************** . --------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- . [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\ . --------------------- DLLs Geladen Onder Lopende Processen --------------------- . - - - - - - - > 'explorer.exe'(2592) c:\program files\Windows Media Player\wmpband.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Andere Aktieve Processen ------------------------ . c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\o2flash.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Voltooingstijd: 2011-06-19 17:04:33 - machine werd herstart ComboFix-quarantined-files.txt 2011-06-19 15:04 . Pre-Run: 21,908,787,200 bytes beschikbaar Post-Run: 24,679,993,344 bytes beschikbaar . WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect . - - End Of File - - 8882D5EB5E86B2257BF2688CD955D971