Succes, disabled antivir before running but not windows defender, don't know it that's a problem.
ComboFix 11-05-21.03 - Jan 22/05/2011 15:24:08.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.32.1043.18.3062.2181 [GMT 2:00]
Gestart vanuit: c:\users\Jan\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DaemonTools_WhenUSave_Installer
c:\program files\DaemonTools_WhenUSave_Installer\vvsn.cfg
G:\install.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2011-04-22 to 2011-05-22 ))))))))))))))))))))))))))))))
.
.
2011-05-22 13:32 . 2011-05-22 13:32 -------- d-----w- c:\users\Jan\AppData\Local\temp
2011-05-20 15:48 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\93828962.sys
2011-05-20 15:48 . 2009-10-09 21:31 311312 ----a-w- c:\windows\system32\drivers\9382896.sys
2011-05-20 15:48 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\93828961.sys
2011-05-20 08:09 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C65C1C2B-5CDC-4CE0-A25B-F79C441F1EA6}\mpengine.dll
2011-05-19 15:58 . 2011-05-19 15:58 -------- d-----w- C:\_OTL
2011-05-16 13:37 . 2011-05-16 13:37 -------- d-----w- c:\users\Jan\AppData\Roaming\Media Player Classic
2011-05-16 13:08 . 2011-05-16 13:08 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 13:07 . 2011-05-15 13:07 -------- d-----w- c:\users\Jan\AppData\Local\Apps
2011-05-11 07:35 . 2011-04-07 12:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-05-09 13:33 . 2011-05-18 20:29 -------- d-----w- c:\users\Jan\AppData\Local\Adobe
2011-04-27 13:14 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 13:14 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 13:14 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-26 13:00 . 2011-04-26 13:00 -------- d-----w- c:\users\Jan\AppData\Roaming\Reviversoft
2011-04-26 12:59 . 2011-03-16 11:28 16704 ----a-w- c:\windows\system32\roboot.exe
2011-04-26 11:28 . 2011-04-26 11:28 -------- d-----w- c:\programdata\Media Get LLC
2011-04-25 22:20 . 2011-04-25 22:20 -------- d-----w- C:\Temp
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-22 12:58 . 2010-04-19 22:03 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-04-06 12:51 . 2011-04-06 12:51 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-06 12:51 . 2011-04-06 12:51 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-06 12:51 . 2011-04-06 12:51 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-06 12:51 . 2011-04-06 12:51 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-06 12:51 . 2011-04-06 12:51 161792 ----a-w- c:\windows\system32\msls31.dll
2011-04-06 12:51 . 2011-04-06 12:51 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-04-06 12:51 . 2011-04-06 12:51 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-04-06 12:51 . 2011-04-06 12:51 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-04-06 12:51 . 2011-04-06 12:51 367104 ----a-w- c:\windows\system32\html.iec
2011-04-06 12:51 . 2011-04-06 12:51 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-06 12:51 . 2011-04-06 12:51 152064 ----a-w- c:\windows\system32\wextract.exe
2011-04-06 12:51 . 2011-04-06 12:51 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-06 12:51 . 2011-04-06 12:51 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-06 12:51 . 2011-04-06 12:51 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-04-06 12:51 . 2011-04-06 12:51 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-06 12:51 . 2011-04-06 12:51 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-06 12:51 . 2011-04-06 12:51 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-04-06 12:51 . 2011-04-06 12:51 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-06 12:51 . 2011-04-06 12:51 11776 ----a-w- c:\windows\system32\mshta.exe
2011-04-06 12:51 . 2011-04-06 12:51 101888 ----a-w- c:\windows\system32\admparse.dll
2011-04-06 12:51 . 2011-04-06 12:51 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-03-16 11:38 . 2010-04-14 10:31 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-10 17:03 . 2011-04-16 08:41 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03 . 2011-04-16 08:41 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42 . 2011-04-16 08:41 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40 . 2011-04-27 13:14 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 13:14 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 13:14 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 13:14 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:25 . 2011-04-16 08:41 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44 . 2011-04-16 08:41 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 14:13 . 2011-03-23 12:47 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 12:47 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 12:47 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-02-22 13:24 . 2011-04-16 08:41 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-22 13:24 . 2011-04-16 08:41 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-22 13:23 . 2011-04-16 08:41 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-22 13:23 . 2011-04-16 08:41 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-08 894512]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-21 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-21 8534560]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-21 88608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-02 281768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
setup_9.0.0.722_20.05.2011_18-09.lnk - c:\users\Jan\Desktop\Virus Removal Tool\setup_9.0.0.722_20.05.2011_18-09\startup.exe [2011-5-20 72208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TotalMedia BackUp & Recorder Monitor.lnk - c:\program files\ArcSoft\TotalMedia Extreme\BackUp & Recorder\uBBMonitor.exe [2006-3-11 270336]
WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WiFiStation.exe [2008-8-5 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R1 CXAVSAUD;Conexant 2388x Audio Capture;c:\windows\system32\DRIVERS\cxavsaud_IBV32.sys [2006-11-02 10368]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9ccd8f50d9593;Google Updateservice (gupdate1c9ccd8f50d9593);c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 133104]
R3 gupdatem;Google Update-service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 133104]
R3 netr73;Hercules Wireless USB Dongle Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2007-01-31 256000]
R3 PCIUtil;PCI Utility;c:\users\Jan\AppData\Local\Temp\PCIUtil.sys [x]
R3 utyymtcw;AVZ Kernel Driver;c:\windows\system32\Drivers\utyymtcw.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 93828962;93828962 Boot Guard Driver;c:\windows\system32\DRIVERS\93828962.sys [2009-10-22 37392]
S1 93828961;93828961;c:\windows\system32\DRIVERS\93828961.sys [2009-09-25 128016]
S1 setup_9.0.0.722_20.05.2011_18-09drv;setup_9.0.0.722_20.05.2011_18-09drv;c:\windows\system32\DRIVERS\9382896.sys [2009-10-09 311312]
S1 udfpt;udfpt; [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-01-08 46592]
.
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - NORMANDY
*Deregistered* - Normandy
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
.
2011-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 16:53]
.
2011-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 16:53]
.
2011-05-22 c:\windows\Tasks\Uitgebreide garantie.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2006-03-11 16:38]
.
.
------- Bijkomende Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
.
- - - - ORPHANS VERWIJDERD - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
AddRemove-Picasa2 - c:\program files\Picasa2\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-22 15:32
Windows 6.0.6002 Service Pack 2 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden:
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-1783622925-2638716330-3058166797-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E559F8D7-0E5D-6498-F750-9B456D0CAA50}*]
"bbonieihmnclcjpeaadihnljobdolabofgcp"=hex:61,61,00,00
"abonieihmnclcjpeaaciepoaenpakljhkl"=hex:61,61,00,00
.
Voltooingstijd: 2011-05-22 15:34:39
ComboFix-quarantined-files.txt 2011-05-22 13:34
.
Pre-Run: 3.300.446.208 bytes beschikbaar
Post-Run: 3.339.653.120 bytes beschikbaar
.
- - End Of File - - 4F5AA8AC685AB90E1DBFE62957D40037