Ik heb een Combofix log.Windows Defender staat aan bij C ,bij D staat hij af.Aanzetten lukt niet.Is dat omdat ik wat geknipt heb van D naar C.+Nu meldt Combofix dat ik geen Defender heb.Normaal heb je maar 1 Defender zou ik zeggen.
ComboFix 13-02-26.01 - Everaard 27/04/2013 21:40:26.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.32.1043.18.2046.1285 [GMT 2:00]
Gestart vanuit: c:\users\Everaard\Desktop\combofix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Everaard\AppData\Roaming\BabMaint.exe
c:\windows\system32\roboot.exe
D:\setup.exe
.
.
(((((((((((((((((((( Bestanden Gemaakt van 2013-03-27 to 2013-04-27 ))))))))))))))))))))))))))))))
.
.
2013-04-27 19:45 . 2013-04-27 19:45 -------- d-----w- c:\users\Everaard\AppData\Local\temp
2013-04-27 19:45 . 2013-04-27 19:45 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-04-27 19:45 . 2013-04-27 19:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-04-27 19:37 . 2013-04-27 19:37 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F691AB80-2DD3-4304-B878-BAC60ACF8CA7}\MpKsl890d7356.sys
2013-04-27 19:37 . 2013-04-27 19:37 -------- d-----w- c:\users\Everaard\AppData\Roaming\eIntaller
2013-04-27 16:05 . 2013-04-27 16:05 -------- d-----w- c:\program files\GPLGS
2013-04-27 16:05 . 2013-04-27 16:05 -------- d-----w- c:\program files\PDFCreator
2013-04-27 09:46 . 2013-04-27 09:46 -------- d-----w- c:\programdata\Microsoft SkyDrive
2013-04-26 21:30 . 2013-04-26 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-04-26 21:30 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-04-26 21:13 . 2013-04-26 21:21 -------- d-----w- c:\program files\RegistryFix8
2013-04-26 18:58 . 2013-04-10 03:08 6906960 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F691AB80-2DD3-4304-B878-BAC60ACF8CA7}\mpengine.dll
2013-04-25 21:24 . 2013-04-25 21:24 -------- d-----w- c:\program files\Magical Jelly Bean
2013-04-25 14:00 . 2013-04-10 03:08 6906960 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-25 12:47 . 2013-04-25 21:39 -------- d-----w- c:\users\Everaard\AppData\Local\ElevatedDiagnostics
2013-04-24 12:35 . 2013-04-24 12:45 -------- d-----w- c:\program files\Unlocker
2013-04-23 20:24 . 2013-04-23 20:22 706640 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CF2F035B-9AA0-4158-A7C9-7CB337754963}\gapaengine.dll
2013-04-23 20:24 . 2013-04-11 18:34 740840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-04-23 20:16 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-19 20:02 . 2013-04-19 20:07 -------- d-----w- c:\users\Everaard\AppData\Roaming\Nero
2013-04-19 19:56 . 2013-04-27 09:53 -------- d-----w- c:\programdata\Nero
2013-04-13 20:33 . 2013-04-13 20:33 -------- d-----w- c:\users\Everaard\AppData\Roaming\DSite
2013-04-12 20:32 . 2013-04-12 20:32 -------- d-----w- c:\programdata\IsolatedStorage
2013-04-12 09:57 . 2013-04-12 20:54 -------- d-----w- c:\users\Everaard\AppData\Roaming\Windows Live Writer
2013-04-12 09:57 . 2013-04-12 19:30 -------- d-----w- c:\users\Everaard\AppData\Local\Windows Live Writer
2013-04-12 09:44 . 2013-04-13 20:40 -------- d-----w- c:\program files\Microsoft
2013-04-12 09:44 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2013-04-12 09:44 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2013-04-12 09:42 . 2013-04-12 09:42 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\fc5efb351ce376109\MeshBetaRemover.exe
2013-04-12 09:42 . 2013-04-12 09:42 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\fb1addb61ce376108\DSETUP.dll
2013-04-12 09:42 . 2013-04-12 09:42 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\fb1addb61ce376108\DXSETUP.exe
2013-04-12 09:42 . 2013-04-12 09:42 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\fb1addb61ce376108\dsetup32.dll
2013-04-12 09:41 . 2013-04-12 09:41 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\f9136d5b1ce376107\DXSETUP.exe
2013-04-12 09:41 . 2013-04-12 09:41 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\f9136d5b1ce376107\DSETUP.dll
2013-04-12 09:41 . 2013-04-12 09:41 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\f9136d5b1ce376107\dsetup32.dll
2013-04-12 09:41 . 2013-04-12 09:41 6260088 ----a-w- c:\program files\Common Files\Windows Live\.cache\f62a73531ce376106\Silverlight.4.0.exe
2013-04-12 09:41 . 2013-04-12 09:57 -------- d-----w- c:\users\Everaard\AppData\Local\Windows Live
2013-04-11 19:36 . 2013-04-11 19:36 -------- d-----w- c:\programdata\NVIDIA
2013-04-11 19:20 . 2013-04-25 12:51 -------- d-----w- c:\programdata\VS Revo Group
2013-04-11 18:33 . 2013-04-11 18:33 -------- d-----w- c:\program files\Microsoft Security Client
2013-04-10 20:46 . 2013-04-10 20:46 34702 ----a-w- c:\windows\system32\drivers\fvstore.dat
2013-04-09 21:19 . 2013-04-15 21:32 -------- d-----w- c:\users\Everaard\AppData\Roaming\MusicBee
2013-04-09 19:50 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-09 19:50 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-09 19:50 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-09 19:50 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe
2013-04-09 19:50 . 2013-03-01 03:09 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-04-09 19:50 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-08 19:54 . 2013-04-08 19:54 -------- d-----w- c:\users\Everaard\AppData\Roaming\Thunderbird
2013-04-08 19:54 . 2013-04-08 19:54 -------- d-----w- c:\users\Everaard\AppData\Local\Thunderbird
2013-04-08 19:40 . 2013-04-14 12:19 -------- d-----w- c:\programdata\Microsoft Help
2013-04-08 19:21 . 2013-04-25 12:51 -------- d-----w- c:\programdata\COMODO
2013-04-08 19:16 . 2013-01-08 04:57 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9BBFFBE8-5247-4D0D-AA37-8C48BAAFF4EA}\mpengine.dll
2013-04-07 22:01 . 2013-04-07 22:01 -------- d-----w- c:\programdata\Malwarebytes
2013-04-07 19:15 . 2013-04-07 19:15 -------- d-----w- c:\program files\Enigma Software Group
2013-04-07 19:14 . 2013-04-07 19:45 -------- d-----w- c:\windows\D8167CA8236B4334B77DF388F494EE18.TMP
2013-04-01 14:10 . 2013-04-27 09:51 -------- d-----w- c:\windows\system32\catroot2
2013-04-01 12:56 . 2013-01-22 20:16 303616 ----a-w- C:\SetACL.exe
2013-03-30 17:26 . 2013-03-30 17:27 -------- d-----w- C:\Temp
2013-03-30 16:53 . 2013-03-30 16:53 -------- d-----w- c:\users\Everaard\AppData\Roaming\Aura Video Editor
2013-03-30 16:53 . 2013-03-30 17:00 -------- d-----w- c:\program files\Aura4You
.
.
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-17 06:56 . 2012-12-29 16:30 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-17 06:56 . 2012-12-29 16:30 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-02 10:33 . 2012-12-28 19:44 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-04-01 13:20 . 2013-01-18 20:33 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-03-13 08:50 . 2013-03-13 08:50 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-13 08:50 . 2013-03-13 08:50 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-03-13 08:49 . 2013-03-13 08:49 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-03-13 08:49 . 2013-03-13 08:49 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-03-13 08:49 . 2013-03-13 08:49 158720 ----a-w- c:\windows\system32\msls31.dll
2013-03-13 08:49 . 2013-03-13 08:49 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-03-13 08:49 . 2013-03-13 08:49 138752 ----a-w- c:\windows\system32\wextract.exe
2013-03-13 08:49 . 2013-03-13 08:49 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-03-13 08:49 . 2013-03-13 08:49 12800 ----a-w- c:\windows\system32\mshta.exe
2013-03-13 08:49 . 2013-03-13 08:49 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-03-13 08:49 . 2013-03-13 08:49 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-03-13 08:49 . 2013-03-13 08:49 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-03-13 08:49 . 2013-03-13 08:49 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-03-13 08:49 . 2013-03-13 08:49 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-03-13 08:49 . 2013-03-13 08:49 361984 ----a-w- c:\windows\system32\html.iec
2013-03-13 08:49 . 2013-03-13 08:49 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-03-13 08:49 . 2013-03-13 08:49 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-03-12 11:25 . 2012-12-29 21:20 773712 ----a-w- c:\windows\system32\msvcr100.dll
2013-03-12 11:25 . 2011-06-11 00:58 420944 ----a-w- c:\windows\system32\msvcp100.dll
2013-02-12 04:48 . 2013-03-12 20:07 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-12 20:07 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-12 03:32 . 2013-03-13 08:48 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-20 13:31 . 2013-01-18 21:00 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 216064 --sha-r- c:\windows\System32\nbDX.dll
2010-01-06 23:00 107520 --sha-r- c:\windows\System32\TAKDSDecoder.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-03-01 15:10 280224 ----a-w- c:\program files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-11-18 1657448]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-11-20 87144]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-20 12685928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
2009-11-20 19:33 87144 ----a-w- c:\windows\System32\nvhotkey.dll
.
R3 BthAvrcp;Bluetooth AVRCP-profiel;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 DellBIOS;DellBIOS;c:\windows\DellBIOS.Sys [x]
R3 netw5v32;Stuurprogramma voor Intel(R) Wireless WiFi Link 5000 Series-adapter 32-bits Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Netwerkinspectie;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 MpKsl890d7356;MpKsl890d7356;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F691AB80-2DD3-4304-B878-BAC60ACF8CA7}\MpKsl890d7356.sys [x]
S2 hasplms;Sentinel Local License Manager;c:\windows\system32\hasplms.exe -run [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 XpoLogCenter;XpoLogCenter;c:\progra~1\XPOLOG~1.4\XpoLog.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
.
.
--- Andere Services/Drivers In Geheugen ---
.
*NewlyCreated* - MPKSL890D7356
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
GPSvcGroup REG_MULTI_SZ GPSvc
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-12 09:47 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Inhoud van de 'Gedeelde Taken' map
.
2013-04-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-29 06:56]
.
2013-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-21 10:26]
.
2013-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-01-21 10:26]
.
.
------- Bijkomende Scan -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
Trusted Zone: dell.com
TCP: DhcpNameServer = 195.130.130.4 195.130.130.132 195.130.131.132
FF - ProfilePath - c:\users\Everaard\AppData\Roaming\Mozilla\Firefox\Profiles\0v6x55nh.default-1364069917402\
.
- - - - ORPHANS VERWIJDERD - - - -
.
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
AddRemove-{06C7286A-AD86-4BBA-9243-B5C02EDF4BC3}_is1 - c:\program files\Full Video Converter Free 10\unins000.exe
.
.
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:9b,0c,63,1d,5e,f6,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,3d,9b,8a,c8,6b,bf,4a,98,c6,d9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,3d,9b,8a,c8,6b,bf,4a,98,c6,d9,\
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.HTM"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.MHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.partial\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.PARTIAL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.URL"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.website\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.WEBSITE"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.XHT"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Voltooingstijd: 2013-04-27 21:46:41
ComboFix-quarantined-files.txt 2013-04-27 19:46
.
Pre-Run: 3.231.432.704 bytes beschikbaar
Post-Run: 3.397.365.760 bytes beschikbaar
.
- - End Of File - - FA923F141EF192FA3CAC6ADA1DC51CE0