Ok, hier de logfile can combofix:
ComboFix 12-05-01.02 - Bob 30-04-2012 19:03:36.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.512.117 [GMT 2:00]
Gestart vanuit: c:\documents and settings\Bob.BOB-A601S66XUVI\Bureaublad\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
c:\documents and settings\Bob.BOB-A601S66XUVI\Application Data\ACD Systems\ACDSee\ImageDB.ddf
c:\documents and settings\Bob.BOB-A601S66XUVI\Mijn documenten\DPE.DUS
c:\documents and settings\Bob.BOB-A601S66XUVI\WINDOWS
c:\windows\desktop
c:\windows\desktop\NeuroTran 2000.lnk
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.8-2.inf
c:\windows\IsUn0413.exe
c:\windows\system32\SET104.tmp
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2012-03-28 to 2012-04-30 ))))))))))))))))))))))))))))))
.
.
2012-04-09 18:21 . 2012-04-09 18:21 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2012-04-03 03:39 . 2012-04-09 18:21 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-09 18:21 . 2011-05-27 21:05 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2011-08-10 13:29 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-22 19:17 . 2003-04-08 12:00 96384 ----a-w- c:\windows\system32\drivers\sptddrv1.sys
2012-03-22 18:51 . 2009-06-12 19:49 87608 -c--a-w- c:\documents and settings\Bob.BOB-A601S66XUVI\Application Data\inst.exe
2012-03-22 18:51 . 2009-06-12 19:49 47360 -c--a-w- c:\documents and settings\Bob.BOB-A601S66XUVI\Application Data\pcouffin.sys
2012-03-01 11:00 . 2003-04-08 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:00 . 2003-04-08 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:00 . 2003-04-08 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2003-04-08 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2003-04-08 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-10-11 20:43 385024 ----a-w- c:\windows\system32\html.iec
2012-02-03 09:57 . 2003-04-08 12:00 1860224 ----a-w- c:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"timesync.exe"="c:\windows\system32\timesync.exe" [2010-05-04 32768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-12 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keep fast
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-14 23:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 17:02 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 17:03 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Norton AntiVirus Server"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2-1-2005 14:34 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2-1-2005 14:34 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10-11-2006 13:16 611064]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21-12-2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21-12-2010 13:47 94872]
R2 DbgMsg;Debug Message;c:\windows\system32\drivers\DbgMsg.sys [29-7-2006 13:59 18240]
R2 ddnt;ddnt;c:\windows\system32\drivers\ddnt.sys [27-11-2005 18:56 7072]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12-1-2011 16:41 810144]
R2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\system32\drivers\npf_devolo.sys [28-11-2008 14:34 35840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18-3-2010 14:16 130384]
S2 RGFILERW;RGFILERW;\??\c:\windows\system32\Drivers\RGFILERW.SYS --> c:\windows\system32\Drivers\RGFILERW.SYS [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3-4-2012 5:39 253088]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [25-3-2006 12:41 16512]
S3 MLFILEM;MLFILEM;\??\c:\windows\system32\drivers\MLFILEM.SYS --> c:\windows\system32\drivers\MLFILEM.SYS [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25-1-2007 19:31 42000]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12-6-2009 21:49 47360]
S3 PortlUSB;PortlUSB;c:\windows\system32\drivers\H10USB.sys [24-6-2004 6:52 7552]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys --> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18-3-2010 14:16 753504]
.
Inhoud van de 'Gedeelde Taken' map
.
2012-04-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 18:21]
.
2011-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
.
------- Bijkomende Scan -------
.
uStart Page =
hxxp://www.google.nl/uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://g.msn.nl/0SENLNL/SAOS01?FORM=TOOLBRIE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 212.54.40.25 212.54.35.25
.
- - - - ORPHANS VERWIJDERD - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-FreeRAM XP - c:\program files\FreeRAM XP Pro\FreeRAM XP Pro.exe
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-Zinio DLM - c:\program files\Zinio\ZinioDeliveryManager.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-30 19:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scannen van verborgen processen ...
.
scannen van verborgen autostart items ...
.
scannen van verborgen bestanden ...
.
Scan succesvol afgerond
verborgen bestanden: 0
.
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\S-1-5-21-1004336348-1965331169-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58DCB4E8-DEB6-64F7-3118-B1B9CBC0408A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1004336348-1965331169-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EEC65B83-D72A-B5E5-C1EC-D0B5B0224AA3}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iagcbhjdbinmcggjmh"=hex:6a,61,6a,70,6e,6e,70,69,6a,6c,65,6b,65,6d,6e,61,69,6a,
6c,69,00,e9
"hamdhfpmnpmhojag"=hex:6a,61,6a,70,6e,6e,70,69,6a,6c,65,6b,65,6d,6e,61,69,6a,
6c,69,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aif\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aif\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aifc\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aifc\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aiff\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .aiff\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .au\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .au\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .dat\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .dat\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .m1v\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .m1v\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .m2v\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .m2v\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mid\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mid\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .midi\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .midi\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mov\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mov\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mp3\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mp3\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpeg\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpeg\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpg\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpg\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpv\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .mpv\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .qt\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .qt\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .rmm\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .rmm\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .rt\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .rt\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .smi\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .smi\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .smil\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .smil\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .snd\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .snd\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .swf \shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .swf \shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .vob\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .vob\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wav\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wav\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wma\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wma\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wmv\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\ .wmv\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.ac3\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.ac3\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.avi\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.avi\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.mpg\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.mpg\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.plf\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.plf\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.ram\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.ram\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.rm\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.rm\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\.rmvb\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\.rmvb\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
[HKEY_LOCAL_MACHINE\software\Classes\BlazeDVD.Media\shell\X* :*]
@="X’:"
.
[HKEY_LOCAL_MACHINE\software\Classes\BlazeDVD.Media\shell\X* :*\command]
@="\"\\\\server\\ShareRW\\R&D\\BlazeDVD 3.0 release Setup\\BlazeDVD.exe\" \"%1\""
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
.
- - - - - - - > 'winlogon.exe'(740)
c:\windows\System32\NavLogon.dll
.
Voltooingstijd: 2012-04-30 19:17:51
ComboFix-quarantined-files.txt 2012-04-30 17:17
.
Pre-Run: 8.526.594.048 bytes beschikbaar
Post-Run: 8.881.131.520 bytes beschikbaar
.
WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 2956CAE5E895AE0F0105F518FA189031