ComboFix 08-07-07.3 - Administrator 2008-07-08 16:25:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.111 [GMT 2:00]
Gestart vanuit: C:\Documents and Settings\Administrator\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Bureaublad\WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\Adssite Advanced Toolbar
C:\Documents and Settings\Administrator\Application Data\Adssite Advanced Toolbar\advertbuttons.xml
C:\Documents and Settings\Administrator\Application Data\Adssite Advanced Toolbar\selected.xml
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#SharedObjects\TBBVXGZJ\iforex.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#SharedObjects\TBBVXGZJ\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Administrator\spooldr.ini
C:\Program Files\Adssite Advanced Toolbar
C:\WINDOWS\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
-------\Legacy_WCVS
-------\Service_wcvs
(((((((((((((((((((( Bestanden Gemaakt van 2008-06-08 to 2008-07-08 ))))))))))))))))))))))))))))))
.
2008-07-08 09:54 . 2008-07-08 09:54 <DIR> d-------- C:\WINDOWS\system32\nl-nl
2008-06-24 21:02 . 2008-06-24 21:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-15 00:26 . 2008-06-15 00:26 <DIR> d-------- C:\Documents and Settings\LocalService\Menu Start
2008-06-13 04:00 . 2008-06-13 04:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-11 04:07 . 2008-06-14 20:00 272,640 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 04:07 . 2008-06-14 20:00 272,640 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 18:23 . 2008-07-08 10:50 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-08 17:09 . 2008-07-06 09:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-08 17:08 . 2008-07-08 16:27 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-08 17:08 . 2008-06-13 04:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-08 17:08 . 2008-06-21 09:34 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-08 17:08 . 2008-06-21 09:37 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-08 17:08 . 2008-06-21 09:35 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-08 17:07 . 2008-06-08 17:07 <DIR> d-------- C:\Program Files\AVG
2008-06-08 17:07 . 2008-06-08 17:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-08 15:58 . 2008-06-08 15:58 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-06-08 15:56 . 2001-03-08 19:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-06 12:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-04 13:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-04 13:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-07-04 08:43 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-06-24 19:20 --------- d-----w C:\Program Files\Unlocker
2008-06-24 19:20 --------- d-----w C:\Program Files\SpamPal
2008-06-24 18:21 --------- d-----w C:\Program Files\Java
2008-06-24 18:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-24 18:07 --------- d-----w C:\Program Files\Google
2008-06-24 15:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SpamPal
2008-06-01 18:03 --------- d-----w C:\Program Files\LimeWire
2008-05-26 13:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BearShare
2008-05-18 14:14 --------- d-----w C:\Program Files\Windows Live
2008-05-17 20:40 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-17 20:39 --------- d-----w C:\Program Files\Windows Live Favorites
2008-05-17 19:56 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-17 17:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:16 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2007-09-27 11:55 19,504 -c--a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2D040A2B-DF0A-4C40-A801-85FEEB442076}]
2004-08-04 03:03 97024 --a------ C:\WINDOWS\system32\ersv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-18 04:45 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDog305"="C:\WINDOWS\VM305_STI.EXE" [2005-08-05 09:15 61440]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-27 17:57 29744]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-06 09:40 1232152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 03:03 15360]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-18 04:45:30 125624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=C:\\WINDOWS\\system32\\svchost
"C:\\WINDOWS\\system32\\spoolsv.exe"=C:\\WINDOWS\\system32\\spoolsv.exe
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-21 09:35]
R0 ebtdbhfx;ebtdbhfx;C:\WINDOWS\system32\drivers\lwmpvyob.dat []
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-21 09:34]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-06 09:39]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-21 09:37]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps snelle ethernet-adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-04 00:31]
R3 ctlsb16;Creative SB16/AWE32/AWE64-stuurprogramma (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2001-08-17 22:19]
R3 ZSMC0305;A4 TECH PC Camera V;C:\WINDOWS\system32\Drivers\usbVM305.sys [2006-05-08 04:24]
S2 EKEOKPPY;EKEOKPPY;C:\WINDOWS\system32\ekeokppy.wef []
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-04-27 17:57]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac1abc82-a5a2-11dc-9832-000cf62ba562}]
\Shell\Auto\command - G:\svchost.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL svchost.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bda2d041-68ff-11dc-9756-000cf62ba562}]
\Shell\Auto\command - svchost.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL svchost.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da4d1c65-776b-11dc-97b5-000cf62ba562}]
\Shell\Auto\command - G:\svchost.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL svchost.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da4d1c66-776b-11dc-97b5-000cf62ba562}]
\Shell\AutoRun\command - D:\setupSNK.exe
.
Inhoud van de 'Gedeelde Taken' map
"2008-07-08 13:51:20 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-07-04 19:35:55 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MalwareProMFC - C:\Program Files\MalwarePro\MalwarePro.exe
HKLM-Run-Salestart(1) - C:\Program Files\Common Files\NoCompromaat\mc.exe dm=http://nocompromaat.com ad=http://nocompromaat.com
HKLM-Run-Stupid Data Dart Wave - C:\Documents and Settings\All Users\Application Data\flag ace stupid data\axis help.exe
HKLM-Run-UnlockerAssistant - C:\Program Files\Unlocker\UnlockerAssistant.exe
HKLM-Run-SBI - C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZBYFUBQI\install_sbd_nl[1].exe
HKLM-Run-BMN - C:\Program Files\Common Files\AntiVirusScherm\bm.exe dm=http://antivirusscherm.com ad=http://antivirusscherm.com
HKLM-Run-UADCcw - C:\Program Files\AdvancedCleaner Free\UADCcw.exe
HKU-Default-Run-Windows Certificate Verification Service - C:\WINDOWS\wcvs.exe
MSConfigStartUp-Magentic - C:\PROGRA~1\Magentic\bin\Magentic.exe
MSConfigStartUp-MsnMsgr - ~C:\Program Files\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-SweetIM - C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-WinampAgent - C:\Program Files\Winamp\winampa.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 16:38:49
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ebtdbhfx]
"ImagePath"="system32\drivers\lwmpvyob.dat"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EKEOKPPY]
"ImagePath"="\??\C:\WINDOWS\system32\ekeokppy.wef"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Voltooingstijd: 2008-07-08 16:46:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-08 14:46:31
Pre-Run: 27,132,968,960 bytes beschikbaar
Post-Run: 27,612,848,128 bytes beschikbaar
WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
179 --- E O F --- 2008-07-08 08:14:55