Finally got the logs together.. the kaspersky scan took over 4 hours!
ComboFix 10-04-14.04 - gebruiker 15-04-2010 22:00:53.3.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.31.1043.18.1915.962 [GMT 2:00]
Gestart vanuit: c:\users\gebruiker\Desktop\ComboFix.exe
gebruikte Opdracht switches :: c:\users\gebruiker\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
file zipped: c:\programdata\476OWd0l.dat
file zipped: c:\programdata\Epk77023.exe
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\476OWd0l.dat
c:\programdata\Epk77023.exe
c:\users\gebruiker\AppData\Roaming\LimeWire
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xul-v2.0b2.4-do-not-remove
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\branding.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\classic.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\comm.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\en-US.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\limewire.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\pippki.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\chrome\toolkit.manifest
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility-msaa.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\accessibility.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\alerts.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\appstartup.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\autocomplete.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\caps.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\chardet.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\chrome.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\commandhandler.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\commandlines.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\composer.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_html.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_htmldoc.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xmldoc.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xslt.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\content_xtf.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\contentprefs.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\cookie.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\directory.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\docshell_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_canvas.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_core.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_css.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_events.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_html.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_json.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_loadsave.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_offline.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_range.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_sidebar.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_storage.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_stylesheets.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_svg.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_traversal.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_views.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xbl.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xpath.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\dom_xul.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\downloads.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\editor.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\embed_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\extensions.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\exthandler.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\exthelper.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\fastfind.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\FeedProcessor.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\feeds.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\find.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\gfx.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\htmlparser.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\imgicon.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\imglib2.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\inspector.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\intl.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\jar.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\jsconsole-clhandler.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\jsdservice.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_printing.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\layout_xul_tree.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\locale.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\loginmgr.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\lwbrk.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\mimetype.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\mozbrwsr.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\mozfind.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_about.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cache.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_cookie.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_dns.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_file.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_ftp.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_http.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_res.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_socket.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_strconv.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\necko_viewsource.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsAddonRepository.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBadCertHandler.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsBlocklistService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentDispatchChooser.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsContentPrefService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDefaultCLH.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDictionary.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsDownloadManagerUI.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsExtensionManager.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHandlerService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsHelperAppDlg.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLivemarkService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginInfo.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManager.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsLoginManagerPrompter.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsPostUpdateWin.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProgressDialog.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsProxyAutoConfig.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsResetPref.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTaggingService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsTryToClose.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsUpdateService.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsURLFormatter.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsWebHandlerApp.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXmlRpcClient.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\nsXULAppInstall.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\oji.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\parentalcontrols.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\places.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\plugin.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pluginGlue.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\pref.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\prefetch.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\profile.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\proxyObject.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\rdf.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\satchel.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\saxparser.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\shistory.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\spellchecker.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\storage-Legacy.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\storage.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\toolkitprofile.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\txEXSLTRegExFunctions.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\txmgr.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\txtsvc.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\uconv.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\unicharutil.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\update.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\uriloader.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\urlformatter.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\webBrowser_core.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\webbrowserpersist.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\webshell_idls.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\widget.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\windowds.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\windowwatcher.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xml-rpc.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_base.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_components.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_ds.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_io.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_system.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_thread.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpcom_xpti.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpconnect.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xpinstall.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xulapp_setup.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xuldoc.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xultmpl.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\xulutil.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\components\zipwriter.xpt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\crashreporter.ini
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\platform.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\autoconfig\prefcalls.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\pref\xulrunner.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userChrome-example.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\chrome\userContent-example.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\localstore.rdf
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userChrome-example.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\chrome\userContent-example.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\defaults\profile\US\localstore.rdf
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\dependentlibs.list
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.aff
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\dictionaries\en-US.dic
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.chk
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\freebl3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\all.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\security-prefs.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\greprefs\xpinstall.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcom.jar
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\javaxpcomglue.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\js3250.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\LICENSE
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\debug.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\DownloadUtils.jsm
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\ISO8601DateUtils.jsm
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\JSON.jsm
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\Microformats.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\PluralForm.jsm
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\utils.js
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\modules\XPCOMUtils.jsm
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\mozctl.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\mozctlx.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\MSVCP71.DLL
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\msvcr71.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\nspr4.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\nss3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\nssckbi.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\nssdbm3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\nssutil3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\platform.ini
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\plc4.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\plds4.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\plugins\npnul32.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\README.txt
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\arrow.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\arrowd.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\broken-image.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetalias.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\charsetData.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\contenteditable.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\designmode.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\mathml.dtd
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\dtd\xhtml11.dtd
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\EditorOverride.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Latin1.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Special.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\html40Symbols.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\htmlEntityVersions.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\mathml20.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\entityTables\transliterate.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfont.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontStandardSymbolsL.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXNonUnicode.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSTIXSize1.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontSymbol.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\fonts\mathfontUnicode.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\forms.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\grabber.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\hiddenWindow.html
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\html.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\html\folder.png
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\langGroups.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\language.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\loading-image.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\mathml.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\quirk.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\svg.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-after.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-column-before.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-after.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-add-row-before.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-column.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-active.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row-hover.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\table-remove-row.gif
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\ua.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\viewsource.css
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\res\wincharset.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\smime3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.chk
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\softokn3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\sqlite3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\ssl3.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\updater.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\version.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpcom.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpcshell.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpicleanup.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpidl.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpt_dump.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xpt_link.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xul.dll
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner-stub.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner.exe
c:\users\gebruiker\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\gebruiker\AppData\Roaming\LimeWire\createtimes.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\downloads.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\fileurns.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\gnutella.net
c:\users\gebruiker\AppData\Roaming\LimeWire\installation.props
c:\users\gebruiker\AppData\Roaming\LimeWire\library.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\library5.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\limewire.props
c:\users\gebruiker\AppData\Roaming\LimeWire\lock
c:\users\gebruiker\AppData\Roaming\LimeWire\mojito.props
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\.autoreg
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_001_
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_002_
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_003_
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\_CACHE_MAP_
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\28BC3FA7d01
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\7BD6A121d01
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\AE98BDEDd01
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\BAFF9A9Bd01
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\Cache\F9D3E29Fd01
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\cert8.db
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\compreg.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\cookies.sqlite
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\downloads.sqlite
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\extensions.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\extensions.ini
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\history.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\key3.db
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\permissions.sqlite
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite-journal
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\places.sqlite
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\pluginreg.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\prefs.js
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\secmod.db
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\XPC.mfl
c:\users\gebruiker\AppData\Roaming\LimeWire\mozilla-profile\xpti.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\player.props
c:\users\gebruiker\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\gebruiker\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\gebruiker\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\gebruiker\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\gebruiker\AppData\Roaming\LimeWire\questions.props
c:\users\gebruiker\AppData\Roaming\LimeWire\responses.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\simpp.xml
c:\users\gebruiker\AppData\Roaming\LimeWire\spam.dat
c:\users\gebruiker\AppData\Roaming\LimeWire\tables.props
c:\users\gebruiker\AppData\Roaming\LimeWire\ttdata.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\ttroot.cache
c:\users\gebruiker\AppData\Roaming\LimeWire\version.xml
c:\users\gebruiker\AppData\Roaming\LimeWire\versions.props
c:\users\gebruiker\AppData\Roaming\LimeWire\xml\data\audio.sxml3
c:\users\gebruiker\AppData\Roaming\LimeWire\xml\data\video.sxml3
c:\windows\Tasks\At25.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At48.job
Besmet exemplaar van c:\windows\system32\drivers\disk.sys werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - Kitty had a snack
Besmet exemplaar van c:\windows\system32\drivers\disk.sys werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - Kitty ate it
.
(((((((((((((((((((( Bestanden Gemaakt van 2010-03-15 to 2010-04-15 ))))))))))))))))))))))))))))))
.
2010-04-15 20:11 . 2010-04-15 20:13 -------- d-----w- c:\users\gebruiker\AppData\Local\temp
2010-04-15 20:11 . 2010-04-15 20:11 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-04-15 20:11 . 2010-04-15 20:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-15 17:45 . 2010-04-15 17:45 -------- d-----w- c:\program files\Windows Portable Devices
2010-04-15 17:19 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-04-15 17:19 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-04-15 17:19 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-04-15 17:17 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-04-15 17:17 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2010-04-15 17:17 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2010-04-15 17:17 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2010-04-15 17:17 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2010-04-15 17:17 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-04-15 17:17 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2010-04-15 17:17 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2010-04-15 17:17 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2010-04-15 17:17 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2010-04-15 17:17 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2010-04-15 17:17 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2010-04-15 17:15 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-04-15 17:15 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-04-15 17:15 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-04-11 20:08 . 2010-04-11 20:08 -------- d-----w- c:\program files\Trend Micro
2010-04-11 20:04 . 2010-04-11 20:05 -------- d-----w- c:\program files\ERUNT
2010-04-11 20:00 . 2010-04-11 20:04 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-11 20:00 . 2010-04-11 20:02 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-11 19:59 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-04-11 19:59 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-04-11 19:59 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-04-11 14:05 . 2010-04-11 14:05 -------- d-----w- c:\users\gebruiker\AppData\Roaming\Malwarebytes
2010-04-11 14:05 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-11 14:05 . 2010-04-11 14:05 -------- d-----w- c:\programdata\Malwarebytes
2010-04-11 14:05 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-11 14:05 . 2010-04-11 14:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-10 18:52 . 2010-04-10 18:53 -------- d-----w- c:\windows\system32\ca-ES
2010-04-10 18:52 . 2010-04-10 18:53 -------- d-----w- c:\windows\system32\eu-ES
2010-04-10 18:52 . 2010-04-10 18:53 -------- d-----w- c:\windows\system32\vi-VN
2010-04-10 10:57 . 2010-04-10 10:57 -------- d-----w- c:\windows\system32\EventProviders
2010-04-10 09:37 . 2010-04-10 09:37 -------- d-----w- C:\$AVG
2010-04-10 09:35 . 2010-04-10 09:35 -------- d-----w- c:\programdata\avg9
2010-03-18 09:29 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-15 20:13 . 2010-02-15 15:36 -------- d-----w- c:\program files\Common Files\Akamai
2010-04-15 20:05 . 2008-01-21 05:45 670308 ----a-w- c:\windows\system32\perfh013.dat
2010-04-15 20:05 . 2008-01-21 05:45 127900 ----a-w- c:\windows\system32\perfc013.dat
2010-04-15 20:00 . 2009-07-10 09:12 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2010-04-15 17:45 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-15 17:44 . 2010-04-15 17:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-04-15 17:16 . 2010-04-15 17:16 1685784 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-04-15 17:16 . 2010-04-15 17:16 1035032 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2010-04-10 18:54 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2010-04-10 18:54 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2010-04-10 18:54 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2010-04-10 18:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-10 18:54 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-10 18:53 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2010-04-10 18:50 . 2009-11-22 13:24 55352 ----a-w- c:\windows\system32\drivers\disk.sys
2010-04-10 09:37 . 2009-06-29 08:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-10 09:37 . 2009-06-29 08:47 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-10 09:37 . 2009-06-29 08:47 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-10 09:37 . 2009-06-29 08:47 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-10 09:35 . 2009-06-29 08:47 -------- d-----w- c:\program files\AVG
2010-04-08 17:16 . 2009-08-28 14:42 -------- d-----w- c:\programdata\LightScribe
2010-03-25 09:39 . 2010-01-17 19:30 -------- d-----w- c:\users\gebruiker\AppData\Roaming\Skype
2010-03-25 09:15 . 2010-01-17 19:32 -------- d-----w- c:\users\gebruiker\AppData\Roaming\skypePM
2010-03-14 15:34 . 2009-06-29 08:54 -------- d-----w- c:\programdata\Microsoft Help
2010-03-02 08:56 . 2010-02-15 16:18 -------- d-----w- c:\users\gebruiker\AppData\Roaming\Autodesk
2010-03-02 08:56 . 2010-02-15 16:18 -------- d-----w- c:\programdata\Autodesk
2010-02-24 14:31 . 2009-06-29 07:47 132448 ----a-w- c:\users\gebruiker\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-10-02 18:54 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-30 19:17 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-30 19:17 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-30 19:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-30 19:17 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-15 16:51 . 2010-02-15 16:51 36864 ----a-w- c:\users\gebruiker\AppData\Roaming\Autodesk\AutoCAD 2010\R18.0\enu\ContextualTabSelectorRules.dll
2010-02-15 16:39 . 2010-02-15 16:39 -------- d-----w- c:\programdata\FLEXnet
2010-02-15 16:21 . 2010-02-15 16:18 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-02-15 16:21 . 2010-02-15 16:18 -------- d-----w- c:\program files\AutoCAD 2010
2010-02-15 16:20 . 2010-02-15 16:20 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-25 12:00 . 2010-02-23 20:02 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-23 20:02 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-23 20:02 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-23 20:02 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-23 20:02 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-23 20:02 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-23 20:02 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-23 20:02 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-23 20:02 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-23 20:00 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-17 19:32 . 2010-01-17 19:32 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-16 13:13 . 2010-01-16 13:13 7406 ----a-r- c:\users\gebruiker\AppData\Roaming\Microsoft\Installer\{14B0B4D7-EDC0-4A3B-BFAB-31B974146807}\_6FEFF9B68218417F98F549.exe
2006-01-06 01:31 . 2009-09-03 16:23 6029312 ----a-w- c:\program files\speed.exe
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-03 39408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-09-12 6037504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-12 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-12 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-12 145944]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-09-26 417792]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10b.exe" [2009-02-03 240544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):63,8a,f2,fe,df,d8,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4002780628-4200678009-187139236-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1ca97ab71419670;Google Updateservice (gupdate1ca97ab71419670);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-17 133104]
R2 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-10 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-04-10 242696]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-10 308064]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
Akamai REG_MULTI_SZ Akamai
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Inhoud van de 'Gedeelde Taken' map
2010-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-17 19:29]
2010-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-17 19:29]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://intranet.cah.nl/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.
- - - - ORPHANS VERWIJDERD - - - -
HKU-Default-Run-Canaveral - c:\windows\system32\sshnas21.dll
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-15 22:13
Windows 6.0.6002 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,92,b2,09,b9,fc,d8,36,45,8f,1f,de,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,92,b2,09,b9,fc,d8,36,45,8f,1f,de,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\conime.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Voltooingstijd: 2010-04-15 22:21:08 - machine werd herstart
ComboFix-quarantined-files.txt 2010-04-15 20:21
ComboFix2.txt 2010-04-15 18:51
Pre-Run: 131.219.730.432 bytes beschikbaar
Post-Run: 131.194.212.352 bytes beschikbaar
- - End Of File - - F680F7F0E98BED83D8B3643CA56133B7
Upload was successvol