ComboFix 10-02-07.01 - Michael 07-02-2010 19:21:03.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.3326.2264 [GMT 1:00]
Gestart vanuit: c:\users\Michael\Downloads\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\SIntf16.dll
Besmet exemplaar van c:\windows\system32\drivers\atapi.sys werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - Kitty ate it :p
.
(((((((((((((((((((( Bestanden Gemaakt van 2010-01-07 to 2010-02-07 ))))))))))))))))))))))))))))))
.
2010-02-07 18:32 . 2010-02-07 18:33 -------- d-----w- c:\users\Michael\AppData\Local\temp
2010-02-07 18:32 . 2010-02-07 18:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-07 12:16 . 2010-02-07 12:16 -------- d-----w- c:\program files\Trend Micro
2010-02-07 10:38 . 2010-02-07 11:03 -------- d-----w- c:\programdata\OnlineArmor
2010-02-07 10:38 . 2010-02-07 10:38 -------- d-----w- c:\users\Michael\AppData\Roaming\OnlineArmor
2010-02-07 10:36 . 2009-12-05 06:28 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-07 10:36 . 2009-12-05 06:28 30800 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-07 10:36 . 2009-12-05 06:27 223312 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-07 10:36 . 2010-02-07 10:36 -------- d-----w- c:\program files\Tall Emu
2010-02-07 08:15 . 2010-02-07 08:15 -------- d-----w- c:\users\Michael\AppData\Roaming\Malwarebytes
2010-02-07 08:15 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 08:15 . 2010-02-07 08:15 -------- d-----w- c:\programdata\Malwarebytes
2010-02-07 08:15 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-07 08:15 . 2010-02-07 08:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-06 20:36 . 2010-02-06 20:45 -------- d-----w- c:\users\Michael\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2010-02-06 19:03 . 2010-02-06 19:20 -------- d-----w- c:\users\Michael\AppData\Roaming\My Battle for Middle-earth Files
2010-02-01 12:26 . 2010-02-01 12:26 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-30 17:43 . 2010-01-30 17:43 -------- d-----w- c:\programdata\EA Logs
2010-01-27 16:59 . 2010-01-27 16:59 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-01-27 15:39 . 2010-01-14 10:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 11:03 . 2010-01-12 11:03 68200 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 11:03 . 2010-01-12 11:03 4321384 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-01-12 11:03 . 2010-01-12 11:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 11:03 . 2010-01-12 11:03 4061800 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 11:03 . 2010-01-12 11:03 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 11:03 . 2010-01-12 11:03 182888 ----a-w- c:\windows\system32\nvcod189.dll
2010-01-12 11:03 . 2010-01-12 11:03 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-12 11:03 . 2010-01-12 11:03 14924392 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-12 11:03 . 2010-01-12 11:03 11639400 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 11:03 . 2010-01-12 11:03 11586280 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-11 21:18 . 2010-01-11 21:18 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-11 21:18 . 2010-01-11 21:18 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-11 21:18 . 2010-01-11 21:18 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-11 21:18 . 2010-01-11 21:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 18:21 . 2008-01-21 06:47 736756 ----a-w- c:\windows\system32\perfh013.dat
2010-02-07 18:21 . 2008-01-21 06:47 153004 ----a-w- c:\windows\system32\perfc013.dat
2010-02-07 18:15 . 2009-06-26 10:57 35085 ----a-w- c:\programdata\nvModes.dat
2010-02-07 17:34 . 2009-06-24 08:20 -------- d-----w- c:\program files\Steam
2010-02-07 09:21 . 2009-01-24 16:43 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-06 18:51 . 2009-01-24 06:45 -------- d-----w- c:\program files\Electronic Arts
2010-02-05 06:15 . 2009-01-21 15:49 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-05 05:59 . 2009-01-21 15:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-01 12:26 . 2009-01-21 15:10 -------- d-----w- c:\programdata\NVIDIA
2010-02-01 12:19 . 2009-12-04 13:05 -------- d-----w- c:\programdata\BioWare
2010-02-01 10:12 . 2009-09-24 18:56 -------- d-----w- c:\program files\Common Files\BioWare
2010-02-01 10:11 . 2009-01-23 23:16 -------- d-----w- c:\programdata\Media Center Programs
2010-02-01 06:15 . 2009-01-25 16:04 -------- d-----w- c:\program files\Activision
2010-02-01 06:13 . 2009-03-22 08:45 -------- d-----w- c:\program files\Sega
2010-01-31 06:03 . 2009-02-01 18:25 1 ----a-w- c:\users\Michael\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-27 15:28 . 2009-01-21 14:49 -------- d-----w- c:\programdata\McAfee
2010-01-27 15:22 . 2009-04-08 12:23 -------- d-----w- c:\program files\Ubisoft
2010-01-27 07:49 . 2009-05-08 06:45 -------- d-----w- c:\programdata\Electronic Arts
2010-01-27 07:49 . 2009-12-04 12:57 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-27 07:49 . 2009-12-04 12:57 38784 ----a-w- c:\users\Michael\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-27 07:49 . 2009-12-04 12:57 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-25 13:01 . 2009-01-21 14:48 53464 ----a-w- c:\users\Michael\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-25 05:03 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2010-01-24 19:49 . 2009-04-28 11:47 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-24 19:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-12 11:03 . 2010-01-12 11:03 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-01-12 11:03 . 2009-09-27 22:12 592488 ----a-w- c:\windows\system32\nvudisp.exe
2010-01-12 11:03 . 2009-01-21 14:53 592488 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-01-12 11:03 . 2008-07-26 04:48 9388648 ----a-w- c:\windows\system32\nvd3dum.dll
2010-01-12 11:03 . 2008-07-26 04:48 1280616 ----a-w- c:\windows\system32\nvapi.dll
2010-01-02 06:38 . 2010-01-24 19:41 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-24 19:41 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-24 19:41 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-24 19:41 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-20 15:20 . 2009-01-24 16:45 -------- d-----w- c:\programdata\Lavasoft
2009-12-20 09:53 . 2009-12-20 09:53 234016 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-12-14 07:33 . 2009-12-14 07:33 970504 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-03 08:27 . 2009-12-03 08:27 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2009-12-03 08:27 . 2009-11-12 06:24 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-11-30 17:02 . 2009-11-30 17:02 171144 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-30 17:02 . 2009-11-30 17:02 72840 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-12 07:42 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-10 11:35 . 2009-10-14 19:50 38 ----a-w- c:\users\Michael\jagex_runescape_preferences.dat
2009-11-10 11:30 . 2009-10-14 19:52 63 ----a-w- c:\users\Michael\jagex_runescape_preferences2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2010-01-26 1724728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SMCWCU"="c:\program files\SMC\SMCWPCIT-G\SMCWCU.exe" [2006-03-14 303104]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-12-05 6622920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-12-05 923336]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-01-29 10:51 4911104 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):59,54,f9,78,fc,62,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2713266562-1326134346-4058669467-1000]
"EnableNotificationsRef"=dword:00000003
R1 OADevice;OADriver;c:\windows\System32\drivers\OADriver.sys [7-2-2010 11:36 223312]
R1 OAmon;OAmon;c:\windows\System32\drivers\OAmon.sys [7-2-2010 11:36 24656]
R2 DAUpdaterSvc;Dragon Age: Origins Updater;c:\program files\Steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [31-1-2010 9:55 25832]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7-2-2010 9:15 236368]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [7-2-2010 11:36 1282248]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [24-1-2009 17:43 809296]
R2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [7-2-2010 11:36 3291336]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [7-2-2010 9:15 19160]
R3 OAnet;OnlineArmor Service;c:\windows\System32\drivers\OAnet.sys [7-2-2010 11:36 30800]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21-1-2008 3:23 21504]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18-6-2009 18:48 42480]
S3 RTL8187B;Wireless Network USB Adapter 54g WL-168v1.004;c:\windows\System32\drivers\RTL8187B.sys [21-1-2009 18:50 286208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Inhoud van de 'Gedeelde Taken' map
2010-02-07 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Michael.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-02-07 15:07]
2010-02-07 c:\windows\Tasks\Malwarebytes' Scheduled Update for Michael.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-02-07 15:07]
.
.
------- Bijkomende Scan -------
.
uStart Page =
hxxp://www.google.nl/Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\sdthlznz.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.nl/FF - component: c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\sdthlznz.default\extensions\{ca8b7b3d-b6e6-438f-b935-601b3de48d66}\platform\WINNT_x86-msvc\components\FFThrottle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS VERWIJDERD - - - -
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-mcmscsvc
SafeBoot-MCODS
SafeBoot-SRService
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-07 19:32
Windows 6.0.6002 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_USERS\S-1-5-21-2713266562-1326134346-4058669467-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:91,b2,66,14,c4,c0,b8,48,51,47,68,44,86,6e,0d,ee,e4,fe,2b,bb,75,5d,e3,
e8,7c,e1,09,eb,56,69,84,90,2f,21,1f,ec,a7,56,c7,06,6a,b0,43,3c,34,96,bb,8a,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
[HKEY_USERS\S-1-5-21-2713266562-1326134346-4058669467-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:f2,b7,a4,b2,31,e5,b9,5b,07,a0,14,76,7e,3d,67,48,6d,01,f7,a5,fb,
70,62,b3,70,b0,7a,66,01,f2,a0,c3,9b,3d,27,b2,03,0e,6c,75,9b,88,5e,fb,d9,5c,\
"rkeysecu"=hex:de,ca,3c,78,81,dd,51,8b,8c,2c,53,f4,3f,88,22,26
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Voltooingstijd: 2010-02-07 19:37:22
ComboFix-quarantined-files.txt 2010-02-07 18:37
Pre-Run: 628.991.590.400 bytes beschikbaar
Post-Run: 648.003.878.912 bytes beschikbaar
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 50A362BEC25619063E7DCA35BBAB332B