This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer infested with virus/Trojan - Even format didn

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been trying to fix this for days. Kaspersky keeps giving me messages about random trojans and/or random name.exe files (like Rootkit.Win32.Pakes.gb)
I noticed my MBAM keeps trying to remove a ndisio.sys: (C:\WINDOWS\system32\drivers\ndisio.sys (Backdoor.Bot) -> Delete on reboot.)
But it keeps coming back (the file is also in a hidden map called "AVENGER", which i've never seen before)

I've tried multiple things like sdblaster, MBAM, kaspersky, nod32, ad-aware. Nothing seems to help.

Here's a hijackthislog

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:39:17, on 3-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Greatis\REGRUN~1\WatchDog.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Michal\xls.exe \s,
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [RegRun WinBait] C:\WINDOWS\winbait.exe
O4 - HKLM\..\Run: [@RegRunOnSecure] C:\PROGRA~1\Greatis\REGRUN~1\OnSecure.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Regrun2] C:\PROGRA~1\Greatis\REGRUN~1\WatchDog.exe
O4 - HKCU\..\Run: [Registry] "C:\Program Files\Greatis\RegRunSuite\lsoon.exe" -1 30 "C:\Program Files\Greatis\RegRunSuite\rescue.exe" /a "c:\backreg\rstore.ini"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 5161 bytes
Hello and Welcome to the forum.

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

Also please describe how your computer behaves at the moment.
I went to hell to get here. This morning my computer wouldn't boot. Then after finally getting it to boot, the internet wouldn't work. I had to remove my network adapter from my hardware screen.

Computer behaviour: Upon logging in to windows I get the "welcome" screen, I hear the login windows sound..my screen goes black…I wait a while, then my screen comes back..I hear the windows "logoff" sound..THEN I hear another "LOGIN" sound. After this last login sound I can finally choose the user I want to login with.
The computer is also slow with installing things: Windows SP3 took over 1.5 hours to install.
I can NOT install a virusscanner at the moment. I get random reboots and BSOD's
Also a format did not help ( I tried a format before this. The virus/trojans quickly came back)

I quickly ran combofix and here's also another hijackthislog:

ComboFix 09-02-02.04 - Administrator 2009-02-04 11:06:18.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1815 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Administrator\Bureaublad\ComboFix.exe
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
.
—- Voorgaande Run ——-
.
c:\documents and settings\Administrator\reader_s.exe
c:\documents and settings\Michal\reader_s.exe
c:\windows\system32\klogon.dll
c:\windows\system32\nxkukde.dll
c:\windows\system32\nxkukde32.dll

c:\windows\system32\userinit.exe . . . est infectee!!

c:\windows\system32\svchost.exe . . . est infectee!!

c:\windows\system32\spoolsv.exe . . . est infectee!!

c:\windows\explorer.exe . . . est infectee!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FCI
——-\Legacy_ICF
——-\Legacy_FCI
——-\Legacy_ICF


(((((((((((((((((((( Bestanden Gemaakt van 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))))
.

2009-02-04 10:36 . 2009-02-04 10:46 94,208 –a—— c:\windows\DUMP3d66.tmp
2009-02-04 10:36 . 2009-02-04 10:38 90,112 –a—— c:\windows\DUMP3a3a.tmp
2009-02-04 10:26 . 2009-02-04 11:20 174,112 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-04 10:39 103,424 –a—— C:\byptemd.exe
2009-02-04 10:26 . 2009-02-04 10:39 40,448 –a—— C:\txxsv.exe
2009-02-04 10:26 . 2009-02-04 10:39 22,016 –a—— C:\ophluxmi.exe
2009-02-04 10:26 . 2009-02-04 10:39 22,016 –a—— C:\ddcyusuf.exe
2009-02-04 10:26 . 2009-02-04 11:20 8,992 –ahs—- c:\windows\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-04 11:03 2,996 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-04 11:03 1,868 –ahs—- c:\windows\system32\drivers\fidbox2.idx
2009-02-04 10:26 . 2009-02-04 10:39 2 –a—— C:\-1997125074
2009-02-04 10:24 . 2009-02-04 10:39 32,768 –a—— c:\windows\system32\drivers\ati5gkxx.sys
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— c:\windows\system32\dllcache\ndis.sys
2009-02-04 07:14 . 2009-02-04 07:14 0 –a—— c:\windows\system32\1D.tmp
2009-02-04 07:13 . 2009-02-04 07:13 32,768 –ah—– c:\documents and settings\Michal\rjrgu.exe
2009-02-04 01:14 . 2009-02-04 01:14 d——– c:\documents and settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 00:55 . 2009-02-04 00:55 32,768 –ah—– c:\documents and settings\Michal\qqe.exe
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— c:\windows\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— c:\windows\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\program files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– c:\documents and settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— c:\windows\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— c:\windows\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— c:\windows\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– c:\windows\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— c:\windows\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— c:\windows\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— c:\windows\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— c:\windows\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— c:\windows\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— c:\windows\system32\vidcap.ax
2009-02-04 00:17 . 2009-02-04 10:22 138,080 –a—— c:\windows\system32\drivers\etherobc.sys
2009-02-03 23:49 . 2009-02-03 23:49 d——– c:\windows\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— c:\windows\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— c:\windows\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– c:\windows\EHome
2009-02-03 22:08 . 2009-02-03 22:08 (2) -rahs-ot- c:\windows\winstart.bat
2009-02-03 22:07 . 2009-02-03 22:07 d——– c:\documents and settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– c:\program files\Greatis
2009-02-03 22:06 . 2003-09-06 15:55 57,556 –a—— c:\windows\guard.bmp
2009-02-03 22:05 . 2009-02-03 22:12 d——– c:\program files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— c:\windows\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– c:\documents and settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- c:\documents and settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-04 11:05 d——– c:\documents and settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-04 10:57 d——– c:\documents and settings\Administrator
2009-02-03 21:14 . 2009-02-03 21:14 0 –a—— c:\windows\system32\30.tmp
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– c:\documents and settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– c:\documents and settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-03 20:27 d——– c:\program files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-03 20:28 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– c:\program files\Trend Micro
2009-02-03 19:52 . 2009-02-03 19:52 d——– c:\program files\Kaspersky Lab
2009-02-03 19:52 . 2009-02-04 01:09 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:48 . 2009-02-03 19:48 158,890 –a—— c:\windows\system32\2A.tmp
2009-02-03 19:47 . 2009-02-03 19:47 d——– c:\documents and settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm
2009-02-03 19:42 . 2009-02-03 19:42 d——– C:\Halu
2009-02-03 19:32 . 2008-04-13 23:15 172,416 –a—— c:\windows\system32\drivers\kmixer.sys
2009-02-03 19:32 . 2008-04-13 21:09 142,592 –a—— c:\windows\system32\drivers\aec.sys
2009-02-03 19:32 . 2008-04-13 23:47 83,072 –a—— c:\windows\system32\drivers\wdmaud.sys
2009-02-03 19:32 . 2008-04-13 23:45 60,800 –a—— c:\windows\system32\drivers\sysaudio.sys
2009-02-03 19:32 . 2008-04-13 23:15 56,576 –a—— c:\windows\system32\drivers\swmidi.sys
2009-02-03 19:32 . 2008-04-13 23:15 52,864 –a—— c:\windows\system32\drivers\DMusic.sys
2009-02-03 19:32 . 2008-04-13 23:09 7,552 –a—— c:\windows\system32\drivers\MSKSSRV.sys
2009-02-03 19:32 . 2008-04-13 23:15 6,272 –a—— c:\windows\system32\drivers\splitter.sys
2009-02-03 19:32 . 2008-04-13 23:09 5,376 –a—— c:\windows\system32\drivers\MSPCLOCK.sys
2009-02-03 19:32 . 2008-04-13 23:09 4,992 –a—— c:\windows\system32\drivers\MSPQM.sys
2009-02-03 19:32 . 2009-02-03 19:32 4,444 –a—— c:\windows\system32\pid.PNF
2009-02-03 19:32 . 2008-04-13 23:15 2,944 –a—— c:\windows\system32\drivers\drmkaud.sys
2009-02-03 19:31 . 2008-04-13 22:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-02-03 19:31 . 2008-04-14 20:33 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-02-03 19:31 . 2008-04-13 22:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-02-03 19:31 . 2008-04-13 23:15 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:31 . 2008-04-14 21:04 58,112 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-03 19:31 . 2008-04-14 21:32 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-03 19:31 . 2008-04-14 20:32 4,096 –a—— c:\windows\system32\ksuser.dll
2009-02-03 19:31 . 2001-08-17 20:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-03 19:30 . 2008-04-14 20:32 76,288 –a—— c:\windows\system32\usbui.dll
2009-02-03 19:28 . 2009-02-03 19:28 512,096 –a—— c:\windows\system32\drivers\_mon.s00
2009-02-03 19:28 . 2009-02-03 19:28 298,104 –a—— c:\windows\system32\_mon.d00
2009-02-03 19:28 . 2009-02-03 19:28 15,424 –a—— c:\windows\system32\drivers\_od32drv.s00
2009-02-03 19:23 . 2009-02-03 19:23 0 –a—— c:\windows\ativpsrm.bin
2009-02-03 19:21 . 2009-02-03 19:21 268 –ah—– C:\sqmdata01.sqm
2009-02-03 19:21 . 2009-02-03 19:21 244 –ah—– C:\sqmnoopt01.sqm
2009-02-03 19:18 . 2009-02-03 19:18 d——– c:\program files\GrabIt
2009-02-03 19:17 . 2009-02-03 23:09 d——– c:\program files\ATI Technologies
2009-02-03 19:17 . 2009-02-03 19:17 d——– C:\ATI
2009-02-03 19:17 . 2009-01-13 21:05 614,400 ——— c:\windows\system32\ati2sgag.exe
2009-02-03 19:06 . 2009-02-03 19:06 d——– c:\program files\PowerQuest
2009-02-03 19:05 . 2009-02-03 19:05 268 –ah—– C:\sqmdata00.sqm
2009-02-03 19:05 . 2009-02-03 19:05 244 –ah—– C:\sqmnoopt00.sqm
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\program files\Webteh
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\documents and settings\Michal\Application Data\BSplayer Pro
2009-02-03 19:03 . 2009-02-03 19:05 d——– c:\documents and settings\Michal\Application Data\BSplayer
2009-02-03 18:57 . 2009-02-04 10:39 130 –a—— c:\windows\adobe.bat
2009-02-03 18:57 . 2009-02-03 19:01 5 –a—— c:\windows\_id.dat
2009-02-03 18:56 . 2009-02-04 07:49 d——– c:\program files\Mozilla Thunderbird
2009-02-03 18:56 . 2009-02-03 18:56 d——– c:\documents and settings\Michal\Application Data\Thunderbird
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\drivers\bthport.sys
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\dllcache\bthport.sys
2009-02-03 18:55 . 2008-08-14 14:27 2,193,536 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,149,888 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,070,400 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,028,544 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 18:55 . 2008-09-15 16:28 1,846,528 ——— c:\windows\system32\dllcache\win32k.sys

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 09:27 94,208 —-a-w c:\windows\DUMP32d7.tmp
2009-02-04 09:22 182,656 —-a-w c:\windows\system32\drivers\ndis.sys
2009-02-03 18:54 94,208 —-a-w c:\windows\DUMP324b.tmp
2009-02-03 17:43 335,872 —-a-w c:\windows\HideWin.exe
2009-01-14 07:14 3,455,488 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.

——- Sigcheck ——-

2008-04-14 22:33 31744 7cbb1b22e73bd2e21b2c2f9fffdddb85 c:\windows\ServicePackFiles\i386\svchost.exe
2009-02-04 10:39 31744 44059c41f74387a6b58c6210c49c0539 c:\windows\system32\svchost.exe

2008-04-14 00:50 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys

2008-04-14 22:33 1054720 18fcb0e958953b03354e15b236945971 c:\windows\explorer.exe
2008-04-14 22:33 1054720 7cab377bb15acdbdb8519521496fc400 c:\windows\ServicePackFiles\i386\explorer.exe

2008-04-14 22:32 32768 b2b1bf07061b49d7268da5f0351d3ff8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 22:32 32768 1f82c9516eb017b1a36253ad46cfc945 c:\windows\system32\ctfmon.exe

2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 22:33 75264 3c2a848256cf5b73dc92314436ea2566 c:\windows\system32\spoolsv.exe

2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 22:33 43520 46e0a9c8fdb6b9b5036274730012214a c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5gkxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msuebwpx.sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2009-01-26 15:31 2144088 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R0 ati5gkxx;ati5gkxx;c:\windows\system32\drivers\ati5gkxx.sys [2009-02-04 32768]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S1 etherobc;etherobc;c:\windows\system32\drivers\etherobc.sys [2009-02-04 138080]
S3 xgbuvhxe;xgbuvhxe;\??\c:\windows\System32\Drivers\xgbuvhxe.sys –> c:\windows\System32\Drivers\xgbuvhxe.sys [?]

NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
Tapisrv
Themes
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN
wscsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
- - - - ORPHANS VERWIJDERD - - - -

HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKCU-Run-reader_s - c:\documents and settings\Michal\reader_s.exe
HKCU-Run-services - c:\windows\services.exe
HKLM-Run-reader_s - c:\windows\System32\reader_s.exe
HKU-Default-Run-rs32net - c:\windows\System32\rs32net.exe
HKU-Default-Run-reader_s - c:\documents and settings\Administrator\reader_s.exe
HKCU-Explorer_Run-services - c:\windows\services.exe
Notify-crypt - (no file)
Notify-nxkukde - (no file)
SafeBoot-ati6imxx.sys
SafeBoot-zrnxjnlu.sys


.
——- Bijkomende Scan ——-
.
FF - ProfilePath - c:\documents and settings\Michal\Application Data\Mozilla\Firefox\Profiles\znsybfek.default\
FF - prefs.js: browser.startup.homepage - www.startpagina.nl
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 11:20:09
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwOpenFile

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
——————— DLLs Geladen Onder Lopende Processen ———————

- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\Ati2evxx.dll
.
———————— Andere Aktieve Processen ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
.
**************************************************************************
.
Voltooingstijd: 2009-02-04 11:21:12 - machine werd herstart [Michal]
ComboFix-quarantined-files.txt 2009-02-04 10:21:10
ComboFix2.txt 2009-02-03 23:54:07

Pre-Run: 46.957.944.832 bytes beschikbaar
Post-Run: 46,894,338,048 bytes beschikbaar

321 — E O F — 2009-02-04 00:36:01


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:56, on 4-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [NvSvc] C:\WINDOWS\system32\nvsvc32.exe
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [hdlnbsqt.exe] C:\WINDOWS\hdlnbsqt.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

–
End of file - 4914 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\byptemd.exe
C:\txxsv.exe
C:\ophluxmi.exe
C:\ddcyusuf.exe
c:\windows\DUMP3d66.tmp
c:\windows\DUMP3a3a.tmp
c:\windows\system32\1D.tmp
c:\documents and settings\Michal\qqe.exe
c:\windows\winstart.bat
c:\windows\system32\30.tmp
c:\windows\system32\2A.tmp
C:\WINDOWS\SYSTEM32\crypts.dll
C:\WINDOWS\system32\cisvc.exe

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"=""

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I'd also like you to do this:

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Problems encountered:
- After combofix had completed, it gave me a "xor exe couldn't initialize" error. It gave me a log after it had rebooted TWICE
- SDFix could NOT be run. I got a BSOD twice trying to run it
- Computer rebooting at random times
- Computer still doing weird startup routine -> Welcome screen, it goes black, I hear logon sound, I hear logoff sound, welcome screen comes back and THEN I can choose the account I want to log on with.
- I don't know why kaspersky is still in there. I uninstalled it (but then it also rebooted, crashed and I couldn't reinstall another virusscanner)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:12, on 2009-02-04
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\kzt4.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\TEMP\VRT7.tmp
C:\WINDOWS\system32\svchost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [vybxbhuw.exe] C:\WINDOWS\vybxbhuw.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprhtqqp.exe] C:\WINDOWS\fprhtqqp.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprauipn.exe] C:\WINDOWS\fprauipn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tjbewwgs.exe] C:\WINDOWS\tjbewwgs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jrfusein.exe] C:\WINDOWS\jrfusein.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [zzjsircn.exe] C:\WINDOWS\zzjsircn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fpramqnr.exe] C:\WINDOWS\fpramqnr.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprwkiqd.exe] C:\WINDOWS\fprwkiqd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [dbxqrwli.exe] C:\WINDOWS\dbxqrwli.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnkbxxc.exe] C:\WINDOWS\phnkbxxc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tjbsuqpo.exe] C:\WINDOWS\tjbsuqpo.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprdwtwe.exe] C:\WINDOWS\fprdwtwe.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rvhiuvju.exe] C:\WINDOWS\rvhiuvju.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprwkcer.exe] C:\WINDOWS\fprwkcer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rvhirvff.exe] C:\WINDOWS\rvhirvff.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [vxvnwpoh.exe] C:\WINDOWS\vxvnwpoh.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rvhiumba.exe] C:\WINDOWS\rvhiumba.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rvhylfje.exe] C:\WINDOWS\rvhylfje.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [dbxqhkbt.exe] C:\WINDOWS\dbxqhkbt.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [zzjwblzz.exe] C:\WINDOWS\zzjwblzz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnyzelk.exe] C:\WINDOWS\phnyzelk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [hdaqkrmv.exe] C:\WINDOWS\hdaqkrmv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprewolo.exe] C:\WINDOWS\fprewolo.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fprampto.exe] C:\WINDOWS\fprampto.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tjbvjeef.exe] C:\WINDOWS\tjbvjeef.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [xlpxczxp.exe] C:\WINDOWS\xlpxczxp.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnfxuet.exe] C:\WINDOWS\phnfxuet.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnkbuqy.exe] C:\WINDOWS\phnkbuqy.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnfvrcj.exe] C:\WINDOWS\phnfvrcj.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [xlhnjslk.exe] C:\WINDOWS\xlhnjslk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tjbeolwa.exe] C:\WINDOWS\tjbeolwa.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnuwefu.exe] C:\WINDOWS\phnuwefu.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [zzjwlrxf.exe] C:\WINDOWS\zzjwlrxf.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnyztsb.exe] C:\WINDOWS\phnyztsb.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: crypt - C:\WINDOWS\
O20 - Winlogon Notify: nxkukde - C:\WINDOWS\SYSTEM32\nxkukde32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

–
End of file - 6946 bytes



ComboFix 09-02-03.01 - Michal 2009-02-04 16:52:38.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1600 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\Michal\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: C:\Documents and Settings\Michal\Bureaublad\CFScript.txt

FILE ::
C:\byptemd.exe
C:\ddcyusuf.exe
c:\documents and settings\Michal\qqe.exe
C:\ophluxmi.exe
C:\txxsv.exe
c:\windows\DUMP3a3a.tmp
c:\windows\DUMP3d66.tmp
c:\windows\system32\1D.tmp
c:\windows\system32\2A.tmp
c:\windows\system32\30.tmp
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\SYSTEM32\crypts.dll
c:\windows\winstart.bat
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\byptemd.exe
C:\ddcyusuf.exe
c:\documents and settings\Michal\qqe.exe
C:\Documents and Settings\Michal\reader_s.exe
C:\ophluxmi.exe
C:\txxsv.exe
c:\windows\DUMP3a3a.tmp
c:\windows\DUMP3d66.tmp
c:\windows\system32\1D.tmp
c:\windows\system32\2A.tmp
C:\WINDOWS\system32\3.tmp
c:\windows\system32\30.tmp
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\6.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\drivers\ntndis.exe
C:\WINDOWS\system32\drivers\ntndis.sys
C:\WINDOWS\system32\nxkukde.dll
C:\WINDOWS\system32\reader_s.exe
C:\WINDOWS\system32\tjlzakww.dll
c:\windows\winstart.bat

C:\WINDOWS\system32\userinit.exe . . . est infectee!!

C:\WINDOWS\system32\svchost.exe . . . est infectee!!

C:\WINDOWS\system32\spoolsv.exe . . . est infectee!!

C:\WINDOWS\explorer.exe . . . est infectee!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FCI
——-\Legacy_ICF
——-\Service_FCI
——-\Service_Passthru


(((((((((((((((((((( Bestanden Gemaakt van 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))))
.

2009-02-04 15:06 . 2009-02-04 15:06 0 –a—— C:\WINDOWS\system32\2.tmp
2009-02-04 15:04 . 2009-02-04 15:04 3,584 –a—— C:\WINDOWS\phnuwefu.exe
2009-02-04 15:03 . 2009-02-04 15:03 29,184 –a—— C:\WINDOWS\system32\24.tmp
2009-02-04 15:03 . 2009-02-04 15:03 3,584 –a—— C:\WINDOWS\tjbeolwa.exe
2009-02-04 15:03 . 2009-02-04 15:03 0 –a—— C:\WINDOWS\system32\28.tmp
2009-02-04 15:00 . 2009-02-04 15:00 3,584 –a—— C:\WINDOWS\xlhnjslk.exe
2009-02-04 14:34 . 2009-02-04 14:34 7,052 –a—— C:\WINDOWS\system32\25.tmp
2009-02-04 14:34 . 2009-02-04 14:34 3,584 –a—— C:\WINDOWS\phnfvrcj.exe
2009-02-04 14:33 . 2009-02-04 14:34 29,184 –a—— C:\WINDOWS\system32\1F.tmp
2009-02-04 14:32 . 2009-02-04 14:32 3,584 –a—— C:\WINDOWS\phnkbuqy.exe
2009-02-04 14:28 . 2009-02-04 14:28 29,184 –a—— C:\WINDOWS\system32\1E.tmp
2009-02-04 14:28 . 2009-02-04 14:28 3,584 –a—— C:\WINDOWS\phnfxuet.exe
2009-02-04 14:28 . 2009-02-04 14:28 0 –a—— C:\WINDOWS\system32\21.tmp
2009-02-04 14:26 . 2009-02-04 14:26 3,584 –a—— C:\WINDOWS\xlpxczxp.exe
2009-02-04 14:26 . 2009-02-04 14:26 0 –a—— C:\WINDOWS\system32\11.tmp
2009-02-04 14:23 . 2009-02-04 14:23 29,184 –a—— C:\WINDOWS\system32\1C.tmp
2009-02-04 14:23 . 2009-02-04 14:23 12,612 –a—— C:\WINDOWS\system32\20.tmp
2009-02-04 14:23 . 2009-02-04 14:23 3,584 –a—— C:\WINDOWS\tjbvjeef.exe
2009-02-04 14:22 . 2009-02-04 14:22 0 –a—— C:\WINDOWS\system32\16.tmp
2009-02-04 14:21 . 2009-02-04 14:21 3,584 –a—— C:\WINDOWS\fprampto.exe
2009-02-04 14:20 . 2009-02-04 14:20 3,584 –a—— C:\WINDOWS\fprewolo.exe
2009-02-04 14:20 . 2009-02-04 14:20 0 –a—— C:\WINDOWS\system32\19.tmp
2009-02-04 14:18 . 2009-02-04 14:18 3,584 –a—— C:\WINDOWS\hdaqkrmv.exe
2009-02-04 13:50 . 2009-02-04 13:50 3,584 –a—— C:\WINDOWS\zzjwblzz.exe
2009-02-04 13:50 . 2009-02-04 13:50 3,584 –a—— C:\WINDOWS\phnyzelk.exe
2009-02-04 13:50 . 2009-02-04 13:50 0 –a—— C:\WINDOWS\system32\1A.tmp
2009-02-04 13:48 . 2009-02-04 13:48 3,584 –a—— C:\WINDOWS\dbxqhkbt.exe
2009-02-04 13:48 . 2009-02-04 13:48 0 –a—— C:\WINDOWS\system32\18.tmp
2009-02-04 13:47 . 2009-02-04 13:47 3,584 –a—— C:\WINDOWS\rvhylfje.exe
2009-02-04 13:43 . 2009-02-04 13:43 3,584 –a—— C:\WINDOWS\rvhiumba.exe
2009-02-04 13:43 . 2009-02-04 13:43 0 –a—— C:\WINDOWS\system32\17.tmp
2009-02-04 13:42 . 2009-02-04 13:42 3,584 –a—— C:\WINDOWS\vxvnwpoh.exe
2009-02-04 13:39 . 2009-02-04 13:39 3,584 –a—— C:\WINDOWS\rvhirvff.exe
2009-02-04 13:39 . 2009-02-04 13:39 0 –a—— C:\WINDOWS\system32\7.tmp
2009-02-04 13:38 . 2009-02-04 13:38 0 –a—— C:\WINDOWS\system32\F.tmp
2009-02-04 13:37 . 2009-02-04 13:37 3,584 –a—— C:\WINDOWS\fprwkcer.exe
2009-02-04 13:36 . 2009-02-04 13:36 3,584 –a—— C:\WINDOWS\rvhiuvju.exe
2009-02-04 13:36 . 2009-02-04 13:36 0 –a—— C:\WINDOWS\system32\14.tmp
2009-02-04 13:34 . 2009-02-04 13:34 3,584 –a—— C:\WINDOWS\fprdwtwe.exe
2009-02-04 13:33 . 2009-02-04 13:33 3,584 –a—— C:\WINDOWS\tjbsuqpo.exe
2009-02-04 13:33 . 2009-02-04 13:33 0 –a—— C:\WINDOWS\system32\12.tmp
2009-02-04 13:31 . 2009-02-04 13:31 3,584 –a—— C:\WINDOWS\phnkbxxc.exe
2009-02-04 13:28 . 2009-02-04 13:28 3,584 –a—— C:\WINDOWS\dbxqrwli.exe
2009-02-04 13:26 . 2009-02-04 13:26 3,584 –a—— C:\WINDOWS\fprwkiqd.exe
2009-02-04 13:26 . 2009-02-04 13:26 0 –a—— C:\WINDOWS\system32\D.tmp
2009-02-04 13:25 . 2009-02-04 13:25 3,584 –a—— C:\WINDOWS\fpramqnr.exe
2009-02-04 13:25 . 2009-02-04 13:25 0 –a—— C:\WINDOWS\system32\C.tmp
2009-02-04 13:24 . 2009-02-04 13:24 0 –a—— C:\WINDOWS\system32\8.tmp
2009-02-04 13:23 . 2009-02-04 13:23 3,584 –a—— C:\WINDOWS\zzjsircn.exe
2009-02-04 13:22 . 2009-02-04 13:22 3,584 –a—— C:\WINDOWS\jrfusein.exe
2009-02-04 13:22 . 2009-02-04 13:22 0 –a—— C:\WINDOWS\system32\A.tmp
2009-02-04 13:20 . 2009-02-04 13:20 3,584 –a—— C:\WINDOWS\tjbewwgs.exe
2009-02-04 13:17 . 2009-02-04 13:17 3,584 –a—— C:\WINDOWS\fprauipn.exe
2009-02-04 13:16 . 2009-02-04 13:16 3,584 –a—— C:\WINDOWS\fprhtqqp.exe
2009-02-04 13:15 . 2009-02-04 13:46 53,248 –a—— C:\WINDOWS\system32\drivers\ndisio.sys
2009-02-04 13:13 . 2009-02-04 13:13 3,584 –a—— C:\WINDOWS\vybxbhuw.exe
2009-02-04 13:13 . 2009-02-04 13:13 244 –ah—– C:\sqmnoopt05.sqm
2009-02-04 13:13 . 2009-02-04 13:13 232 –ah—– C:\sqmdata05.sqm
2009-02-04 13:13 . 2009-02-04 13:13 0 –a—— C:\WINDOWS\system32\10.tmp
2009-02-04 11:30 . 2009-02-04 11:30 84,992 –a—— C:\mdmcqfv.exe
2009-02-04 10:26 . 2009-02-04 17:00 458,784 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-04 16:59 26,656 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-04 16:59 6,380 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-04 16:59 3,548 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2009-02-04 10:26 . 2009-02-04 11:31 2 –a—— C:\-1997125074
2009-02-04 10:24 . 2009-02-04 17:00 32,768 –a—— C:\WINDOWS\system32\drivers\ati5gkxx.sys
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— C:\WINDOWS\system32\dllcache\ndis.sys
2009-02-04 07:13 . 2009-02-04 07:13 32,768 –ah—– C:\Documents and Settings\Michal\rjrgu.exe
2009-02-04 01:14 . 2009-02-04 01:14 d——– C:\Documents and Settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– C:\Program Files\Common Files\Symantec Shared
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— C:\WINDOWS\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— C:\WINDOWS\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– C:\WINDOWS\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– C:\WINDOWS\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– C:\WINDOWS\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– C:\WINDOWS\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– C:\Program Files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– C:\Documents and Settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— C:\WINDOWS\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— C:\WINDOWS\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— C:\WINDOWS\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– C:\WINDOWS\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— C:\WINDOWS\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— C:\WINDOWS\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— C:\WINDOWS\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— C:\WINDOWS\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— C:\WINDOWS\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— C:\WINDOWS\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— C:\WINDOWS\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— C:\WINDOWS\system32\vidcap.ax
2009-02-04 00:17 . 2009-02-04 15:04 138,176 –a—— C:\WINDOWS\system32\drivers\etherobc.sys
2009-02-03 23:49 . 2009-02-03 23:49 d——– C:\WINDOWS\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— C:\WINDOWS\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— C:\WINDOWS\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– C:\WINDOWS\EHome
2009-02-03 22:07 . 2009-02-03 22:07 d——– C:\Documents and Settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– C:\Program Files\Greatis
2009-02-03 22:06 . 2003-09-06 15:55 57,556 –a—— C:\WINDOWS\guard.bmp
2009-02-03 22:05 . 2009-02-03 22:12 d——– C:\Program Files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— C:\WINDOWS\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– C:\Documents and Settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– C:\Documents and Settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– C:\Documents and Settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– C:\Documents and Settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- C:\Documents and Settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– C:\Documents and Settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-04 11:05 d——– C:\Documents and Settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-04 10:57 d——– C:\Documents and Settings\Administrator
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– C:\Documents and Settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– C:\Documents and Settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-03 20:27 d——– C:\Program Files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-03 20:28 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– C:\Program Files\Trend Micro
2009-02-03 19:52 . 2009-02-03 19:52 d——– C:\Program Files\Kaspersky Lab
2009-02-03 19:52 . 2009-02-04 01:09 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:47 . 2009-02-03 19:47 d——– C:\Documents and Settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
This time please post the full scan results from Combofix.

Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop CiSvc Hit enter.

sc delete CiSvc Hit enter.


sc stop ICF Hit enter.

sc delete ICF Hit enter.


Next:

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Documents and Settings\Michal\rjrgu.exe
C:\-1997125074
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\phnuwefu.exe
C:\WINDOWS\system32\24.tmp
C:\WINDOWS\tjbeolwa.exe
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\xlhnjslk.exe
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\phnfvrcj.exe
C:\WINDOWS\system32\1F.tmp
C:\WINDOWS\phnkbuqy.exe
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\phnfxuet.exe
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\xlpxczxp.exe
C:\WINDOWS\system32\11.tmp
C:\WINDOWS\system32\1C.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\tjbvjeef.exe
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\fprampto.exe
C:\WINDOWS\fprewolo.exe
C:\WINDOWS\system32\19.tmp
C:\WINDOWS\hdaqkrmv.exe
C:\WINDOWS\zzjwblzz.exe
C:\WINDOWS\phnyzelk.exe
C:\WINDOWS\system32\1A.tmp
C:\WINDOWS\dbxqhkbt.exe
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\rvhylfje.exe
C:\WINDOWS\rvhiumba.exe
C:\WINDOWS\system32\17.tmp
C:\WINDOWS\vxvnwpoh.exe
C:\WINDOWS\rvhirvff.exe
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\F.tmp
C:\WINDOWS\fprwkcer.exe
C:\WINDOWS\rvhiuvju.exe
C:\WINDOWS\system32\14.tmp
C:\WINDOWS\fprdwtwe.exe
C:\WINDOWS\tjbsuqpo.exe
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\phnkbxxc.exe
C:\WINDOWS\dbxqrwli.exe
C:\WINDOWS\fprwkiqd.exe
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\fpramqnr.exe
C:\WINDOWS\system32\C.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\zzjsircn.exe
C:\WINDOWS\jrfusein.exe
C:\WINDOWS\system32\A.tmp
C:\WINDOWS\tjbewwgs.exe
C:\WINDOWS\fprauipn.exe
C:\WINDOWS\fprhtqqp.exe
C:\WINDOWS\system32\drivers\ndisio.sys
C:\WINDOWS\vybxbhuw.exe
C:\sqmnoopt05.sqm
C:\sqmdata05.sqm
C:\WINDOWS\system32\10.tmp
C:\mdmcqfv.exe
C:\WINDOWS\system32\drivers\etherobc.sys

Driver::
etherobc

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I'm sorry for the Combofix log being incomplete, but that's all I got. My computer automatically rebooted before combofix could finish the whole log. I got a whole log this time.

Computer behaviour:
- Still the same startup routine: Welcome screen, login sound, screen goes black -> Screen comes back, logoff sound…login sound and I can choose the account I want to login with.
- My internet stopped working. It said my network adapter/card was missing some registry values, so it wasn't working correctly. Had to remove the adapter from my hardware screen and reboot, it's working now.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:08, on 4-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\znc4.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [zzjwlrxf.exe] C:\WINDOWS\zzjwlrxf.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnyztsb.exe] C:\WINDOWS\phnyztsb.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: nxkukde - C:\WINDOWS\SYSTEM32\nxkukde.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

–
End of file - 4187 bytes



ComboFix 09-02-03.01 - Michal 2009-02-04 18:01:54.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1573 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Michal\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: c:\documents and settings\Michal\Bureaublad\CFScript.txt

FILE ::
C:\-1997125074
c:\documents and settings\Michal\rjrgu.exe
C:\mdmcqfv.exe
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
c:\windows\dbxqhkbt.exe
c:\windows\dbxqrwli.exe
c:\windows\fprampto.exe
c:\windows\fpramqnr.exe
c:\windows\fprauipn.exe
c:\windows\fprdwtwe.exe
c:\windows\fprewolo.exe
c:\windows\fprhtqqp.exe
c:\windows\fprwkcer.exe
c:\windows\fprwkiqd.exe
c:\windows\hdaqkrmv.exe
c:\windows\jrfusein.exe
c:\windows\phnfvrcj.exe
c:\windows\phnfxuet.exe
c:\windows\phnkbuqy.exe
c:\windows\phnkbxxc.exe
c:\windows\phnuwefu.exe
c:\windows\phnyzelk.exe
c:\windows\rvhirvff.exe
c:\windows\rvhiumba.exe
c:\windows\rvhiuvju.exe
c:\windows\rvhylfje.exe
c:\windows\system32\10.tmp
c:\windows\system32\11.tmp
c:\windows\system32\12.tmp
c:\windows\system32\14.tmp
c:\windows\system32\16.tmp
c:\windows\system32\17.tmp
c:\windows\system32\18.tmp
c:\windows\system32\19.tmp
c:\windows\system32\1A.tmp
c:\windows\system32\1C.tmp
c:\windows\system32\1E.tmp
c:\windows\system32\1F.tmp
c:\windows\system32\2.tmp
c:\windows\system32\20.tmp
c:\windows\system32\21.tmp
c:\windows\system32\24.tmp
c:\windows\system32\25.tmp
c:\windows\system32\28.tmp
c:\windows\system32\7.tmp
c:\windows\system32\8.tmp
c:\windows\system32\A.tmp
c:\windows\system32\C.tmp
c:\windows\system32\D.tmp
c:\windows\system32\drivers\etherobc.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\F.tmp
c:\windows\tjbeolwa.exe
c:\windows\tjbewwgs.exe
c:\windows\tjbsuqpo.exe
c:\windows\tjbvjeef.exe
c:\windows\vxvnwpoh.exe
c:\windows\vybxbhuw.exe
c:\windows\xlhnjslk.exe
c:\windows\xlpxczxp.exe
c:\windows\zzjsircn.exe
c:\windows\zzjwblzz.exe
.
ADS - svchost.exe: deleted 46592 bytes in 1 streams.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\-1997125074
c:\documents and settings\Michal\rjrgu.exe
C:\mdmcqfv.exe
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
c:\windows\dbxqhkbt.exe
c:\windows\dbxqrwli.exe
c:\windows\fprampto.exe
c:\windows\fpramqnr.exe
c:\windows\fprauipn.exe
c:\windows\fprdwtwe.exe
c:\windows\fprewolo.exe
c:\windows\fprhtqqp.exe
c:\windows\fprwkcer.exe
c:\windows\fprwkiqd.exe
c:\windows\hdaqkrmv.exe
c:\windows\jrfusein.exe
c:\windows\phnfvrcj.exe
c:\windows\phnfxuet.exe
c:\windows\phnkbuqy.exe
c:\windows\phnkbxxc.exe
c:\windows\phnuwefu.exe
c:\windows\phnyzelk.exe
c:\windows\rvhirvff.exe
c:\windows\rvhiumba.exe
c:\windows\rvhiuvju.exe
c:\windows\rvhylfje.exe
c:\windows\system32\10.tmp
c:\windows\system32\11.tmp
c:\windows\system32\12.tmp
c:\windows\system32\14.tmp
c:\windows\system32\16.tmp
c:\windows\system32\17.tmp
c:\windows\system32\18.tmp
c:\windows\system32\19.tmp
c:\windows\system32\1A.tmp
c:\windows\system32\1C.tmp
c:\windows\system32\1E.tmp
c:\windows\system32\1F.tmp
c:\windows\system32\2.tmp
c:\windows\system32\20.tmp
c:\windows\system32\21.tmp
c:\windows\system32\24.tmp
c:\windows\system32\25.tmp
c:\windows\system32\28.tmp
c:\windows\system32\7.tmp
c:\windows\system32\8.tmp
c:\windows\system32\A.tmp
c:\windows\system32\C.tmp
c:\windows\system32\D.tmp
c:\windows\system32\drivers\etherobc.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\F.tmp
c:\windows\system32\nxkukde.dll
c:\windows\system32\nxkukde32.dll
c:\windows\tjbeolwa.exe
c:\windows\tjbewwgs.exe
c:\windows\tjbsuqpo.exe
c:\windows\tjbvjeef.exe
c:\windows\vxvnwpoh.exe
c:\windows\vybxbhuw.exe
c:\windows\xlhnjslk.exe
c:\windows\xlpxczxp.exe
c:\windows\zzjsircn.exe
c:\windows\zzjwblzz.exe
.
—- Voorgaande Run ——-
.
C:\byptemd.exe
C:\ddcyusuf.exe
c:\documents and settings\Michal\qqe.exe
c:\documents and settings\Michal\reader_s.exe
C:\ophluxmi.exe
C:\txxsv.exe
c:\windows\DUMP3a3a.tmp
c:\windows\DUMP3d66.tmp
c:\windows\system32\1D.tmp
c:\windows\system32\2A.tmp
c:\windows\system32\3.tmp
c:\windows\system32\30.tmp
c:\windows\system32\4.tmp
c:\windows\system32\6.tmp
c:\windows\system32\9.tmp
c:\windows\system32\B.tmp
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\nxkukde.dll
c:\windows\system32\reader_s.exe
c:\windows\system32\tjlzakww.dll
c:\windows\winstart.bat

c:\windows\system32\userinit.exe . . . est infectee!!

c:\windows\system32\svchost.exe . . . est infectee!!

c:\windows\system32\spoolsv.exe . . . est infectee!!

c:\windows\explorer.exe . . . est infectee!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FCI
——-\Legacy_ICF
——-\Service_FCI
——-\Service_Passthru
——-\Service_etherobc
——-\Service_Passthru


(((((((((((((((((((( Bestanden Gemaakt van 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))))
.

2009-02-04 17:12 . 2009-02-04 17:12 11,776 –ah—– c:\documents and settings\Michal\hhumc.exe
2009-02-04 17:10 . 2009-02-04 17:10 3,584 –a—— c:\windows\phnyztsb.exe
2009-02-04 17:07 . 2009-02-04 17:07 d——– c:\windows\ERUNT
2009-02-04 17:04 . 2009-02-04 17:09 d——– C:\SDFix
2009-02-04 17:04 . 2009-02-04 17:04 33,920 –a—— c:\windows\system32\drivers\ixgituaw.sys
2009-02-04 17:04 . 2009-02-04 17:04 32,768 –ah—– c:\documents and settings\Michal\rnley.exe
2009-02-04 17:03 . 2009-02-04 17:03 32,768 –ah—– c:\documents and settings\Michal\yij.exe
2009-02-04 17:01 . 2009-01-14 04:37 96,256 –a—— c:\windows\system32\_ati2cqa.dll
2009-02-04 17:01 . 2009-02-04 17:01 3,584 –a—— c:\windows\zzjwlrxf.exe
2009-02-04 10:36 . 2009-02-04 17:08 90,112 –a—— c:\windows\DUMP59e7.tmp
2009-02-04 10:36 . 2009-02-04 17:09 90,112 –a—— c:\windows\DUMP2dc6.tmp
2009-02-04 10:26 . 2009-02-04 18:09 587,808 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-04 18:09 34,592 –ahs—- c:\windows\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-04 18:08 7,892 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-04 18:08 4,268 –ahs—- c:\windows\system32\drivers\fidbox2.idx
2009-02-04 10:24 . 2009-02-04 17:12 32,768 –a—— c:\windows\system32\drivers\ati5gkxx.sys
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— c:\windows\system32\dllcache\ndis.sys
2009-02-04 01:14 . 2009-02-04 01:14 d——– c:\documents and settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— c:\windows\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— c:\windows\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\program files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– c:\documents and settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— c:\windows\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— c:\windows\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— c:\windows\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– c:\windows\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— c:\windows\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— c:\windows\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— c:\windows\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— c:\windows\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— c:\windows\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— c:\windows\system32\vidcap.ax
2009-02-03 23:49 . 2009-02-03 23:49 d——– c:\windows\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— c:\windows\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— c:\windows\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– c:\windows\EHome
2009-02-03 22:07 . 2009-02-03 22:07 d——– c:\documents and settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– c:\program files\Greatis
2009-02-03 22:06 . 2003-09-06 15:55 57,556 –a—— c:\windows\guard.bmp
2009-02-03 22:05 . 2009-02-03 22:12 d——– c:\program files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— c:\windows\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– c:\documents and settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- c:\documents and settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-04 11:05 d——– c:\documents and settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-04 10:57 d——– c:\documents and settings\Administrator
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– c:\documents and settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– c:\documents and settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\program files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– c:\program files\Trend Micro
2009-02-03 19:52 . 2009-02-03 19:52 d——– c:\program files\Kaspersky Lab
2009-02-03 19:52 . 2009-02-04 01:09 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:47 . 2009-02-03 19:47 d——– c:\documents and settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm
2009-02-03 19:42 . 2009-02-03 19:42 d——– C:\Halu
2009-02-03 19:32 . 2008-04-13 23:15 172,416 –a—— c:\windows\system32\drivers\kmixer.sys
2009-02-03 19:32 . 2008-04-13 21:09 142,592 –a—— c:\windows\system32\drivers\aec.sys
2009-02-03 19:32 . 2008-04-13 23:47 83,072 –a—— c:\windows\system32\drivers\wdmaud.sys
2009-02-03 19:32 . 2008-04-13 23:45 60,800 –a—— c:\windows\system32\drivers\sysaudio.sys
2009-02-03 19:32 . 2008-04-13 23:15 56,576 –a—— c:\windows\system32\drivers\swmidi.sys
2009-02-03 19:32 . 2008-04-13 23:15 52,864 –a—— c:\windows\system32\drivers\DMusic.sys
2009-02-03 19:32 . 2008-04-13 23:09 7,552 –a—— c:\windows\system32\drivers\MSKSSRV.sys
2009-02-03 19:32 . 2008-04-13 23:15 6,272 –a—— c:\windows\system32\drivers\splitter.sys
2009-02-03 19:32 . 2008-04-13 23:09 5,376 –a—— c:\windows\system32\drivers\MSPCLOCK.sys
2009-02-03 19:32 . 2008-04-13 23:09 4,992 –a—— c:\windows\system32\drivers\MSPQM.sys
2009-02-03 19:32 . 2009-02-03 19:32 4,444 –a—— c:\windows\system32\pid.PNF
2009-02-03 19:32 . 2008-04-13 23:15 2,944 –a—— c:\windows\system32\drivers\drmkaud.sys
2009-02-03 19:31 . 2008-04-13 22:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-02-03 19:31 . 2008-04-14 20:33 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-02-03 19:31 . 2008-04-13 22:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-02-03 19:31 . 2008-04-13 23:15 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:31 . 2008-04-14 21:04 58,112 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-03 19:31 . 2008-04-14 21:32 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-03 19:31 . 2008-04-14 20:32 4,096 –a—— c:\windows\system32\ksuser.dll
2009-02-03 19:31 . 2001-08-17 20:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-03 19:30 . 2008-04-14 20:32 76,288 –a—— c:\windows\system32\usbui.dll
2009-02-03 19:28 . 2009-02-03 19:28 512,096 –a—— c:\windows\system32\drivers\_mon.s00
2009-02-03 19:28 . 2009-02-03 19:28 298,104 –a—— c:\windows\system32\_mon.d00
2009-02-03 19:28 . 2009-02-03 19:28 15,424 –a—— c:\windows\system32\drivers\_od32drv.s00
2009-02-03 19:23 . 2009-02-03 19:23 0 –a—— c:\windows\ativpsrm.bin
2009-02-03 19:21 . 2009-02-03 19:21 268 –ah—– C:\sqmdata01.sqm
2009-02-03 19:21 . 2009-02-03 19:21 244 –ah—– C:\sqmnoopt01.sqm
2009-02-03 19:18 . 2009-02-03 19:18 d——– c:\program files\GrabIt
2009-02-03 19:17 . 2009-02-03 23:09 d——– c:\program files\ATI Technologies
2009-02-03 19:17 . 2009-02-03 19:17 d——– C:\ATI
2009-02-03 19:17 . 2009-01-13 21:05 614,400 ——— c:\windows\system32\ati2sgag.exe
2009-02-03 19:06 . 2009-02-03 19:06 d——– c:\program files\PowerQuest
2009-02-03 19:05 . 2009-02-03 19:05 268 –ah—– C:\sqmdata00.sqm
2009-02-03 19:05 . 2009-02-03 19:05 244 –ah—– C:\sqmnoopt00.sqm
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\program files\Webteh
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\documents and settings\Michal\Application Data\BSplayer Pro
2009-02-03 19:03 . 2009-02-03 19:05 d——– c:\documents and settings\Michal\Application Data\BSplayer
2009-02-03 18:57 . 2009-02-04 15:03 124 –a—— c:\windows\adobe.bat
2009-02-03 18:57 . 2009-02-03 19:01 5 –a—— c:\windows\_id.dat
2009-02-03 18:56 . 2009-02-04 16:36 d——– c:\program files\Mozilla Thunderbird
2009-02-03 18:56 . 2009-02-03 18:56 d——– c:\documents and settings\Michal\Application Data\Thunderbird
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\drivers\bthport.sys
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\dllcache\bthport.sys
2009-02-03 18:55 . 2008-08-14 14:27 2,193,536 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,149,888 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,070,400 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,028,544 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 18:55 . 2008-09-15 16:28 1,846,528 ——— c:\windows\system32\dllcache\win32k.sys
2009-02-03 18:55 . 2009-02-04 17:12 66,560 —h—– c:\windows\system32\secupdat.dat
2009-02-03 18:55 . 2009-02-03 18:55 1,172 –a—— c:\windows\mozver.dat
2009-02-03 18:54 . 2009-02-03 18:54 d——– c:\program files\QuickPar

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 09:27 94,208 —-a-w c:\windows\DUMP32d7.tmp
2009-02-04 09:22 182,656 —-a-w c:\windows\system32\drivers\ndis.sys
2009-02-03 18:54 94,208 —-a-w c:\windows\DUMP324b.tmp
2009-02-03 17:43 335,872 —-a-w c:\windows\HideWin.exe
2009-01-14 07:14 3,455,488 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.

——- Sigcheck ——-

2008-04-14 22:33 31744 7cbb1b22e73bd2e21b2c2f9fffdddb85 c:\windows\ServicePackFiles\i386\svchost.exe
2009-02-04 17:12 31744 44059c41f74387a6b58c6210c49c0539 c:\windows\system32\svchost.exe

2008-04-14 00:50 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys

2008-04-14 22:33 1054720 18fcb0e958953b03354e15b236945971 c:\windows\explorer.exe
2008-04-14 22:33 1054720 7cab377bb15acdbdb8519521496fc400 c:\windows\ServicePackFiles\i386\explorer.exe

2008-04-14 22:32 32768 b2b1bf07061b49d7268da5f0351d3ff8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 22:32 32768 1f82c9516eb017b1a36253ad46cfc945 c:\windows\system32\ctfmon.exe

2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 22:33 75264 3c2a848256cf5b73dc92314436ea2566 c:\windows\system32\spoolsv.exe

2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 22:33 43520 46e0a9c8fdb6b9b5036274730012214a c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-04_11.20.40.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2009-02-04 16:09:14 4,395,008 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2009-02-04 16:09:14 16,384 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-02-04 16:07:16 495,616 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2009-02-04 16:07:16 16,384 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-10-16 13:06:48 268,648 ——w c:\windows\SoftwareDistribution\SelfUpdate\Registered\mucltui.dll
+ 2009-01-14 03:37:08 96,256 —-a-w c:\windows\system32\_ati2cqa.dll
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-04 17:09:24 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 17:09:24 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 15:38:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012009020420090205\index.dat
- 2009-02-04 10:19:41 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-04 17:09:24 81,920 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"services"="c:\windows\services.exe" [BU]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reader_s"="c:\windows\System32\reader_s.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"zzjwlrxf.exe"="c:\windows\zzjwlrxf.exe" [2009-02-04 3584]
"phnyztsb.exe"="c:\windows\phnyztsb.exe" [2009-02-04 3584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5gkxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ixgituaw.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msuebwpx.sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R0 ati5gkxx;ati5gkxx;c:\windows\system32\drivers\ati5gkxx.sys [2009-02-04 32768]
R0 ixgituaw;ixgituaw;c:\windows\system32\drivers\ixgituaw.sys [2009-02-04 33920]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S3 xgbuvhxe;xgbuvhxe;\??\c:\windows\System32\Drivers\xgbuvhxe.sys –> c:\windows\System32\Drivers\xgbuvhxe.sys [?]

NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
Tapisrv
Themes
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN
wscsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
- - - - ORPHANS VERWIJDERD - - - -

HKU-Default-Run-vybxbhuw.exe - c:\windows\vybxbhuw.exe
HKU-Default-Run-fprhtqqp.exe - c:\windows\fprhtqqp.exe
HKU-Default-Run-fprauipn.exe - c:\windows\fprauipn.exe
HKU-Default-Run-tjbewwgs.exe - c:\windows\tjbewwgs.exe
HKU-Default-Run-jrfusein.exe - c:\windows\jrfusein.exe
HKU-Default-Run-zzjsircn.exe - c:\windows\zzjsircn.exe
HKU-Default-Run-fpramqnr.exe - c:\windows\fpramqnr.exe
HKU-Default-Run-fprwkiqd.exe - c:\windows\fprwkiqd.exe
HKU-Default-Run-dbxqrwli.exe - c:\windows\dbxqrwli.exe
HKU-Default-Run-phnkbxxc.exe - c:\windows\phnkbxxc.exe
HKU-Default-Run-tjbsuqpo.exe - c:\windows\tjbsuqpo.exe
HKU-Default-Run-fprdwtwe.exe - c:\windows\fprdwtwe.exe
HKU-Default-Run-rvhiuvju.exe - c:\windows\rvhiuvju.exe
HKU-Default-Run-fprwkcer.exe - c:\windows\fprwkcer.exe
HKU-Default-Run-rvhirvff.exe - c:\windows\rvhirvff.exe
HKU-Default-Run-vxvnwpoh.exe - c:\windows\vxvnwpoh.exe
HKU-Default-Run-rvhiumba.exe - c:\windows\rvhiumba.exe
HKU-Default-Run-rvhylfje.exe - c:\windows\rvhylfje.exe
HKU-Default-Run-dbxqhkbt.exe - c:\windows\dbxqhkbt.exe
HKU-Default-Run-zzjwblzz.exe - c:\windows\zzjwblzz.exe
HKU-Default-Run-phnyzelk.exe - c:\windows\phnyzelk.exe
HKU-Default-Run-hdaqkrmv.exe - c:\windows\hdaqkrmv.exe
HKU-Default-Run-fprewolo.exe - c:\windows\fprewolo.exe
HKU-Default-Run-fprampto.exe - c:\windows\fprampto.exe
HKU-Default-Run-tjbvjeef.exe - c:\windows\tjbvjeef.exe
HKU-Default-Run-xlpxczxp.exe - c:\windows\xlpxczxp.exe
HKU-Default-Run-phnfxuet.exe - c:\windows\phnfxuet.exe
HKU-Default-Run-phnkbuqy.exe - c:\windows\phnkbuqy.exe
HKU-Default-Run-phnfvrcj.exe - c:\windows\phnfvrcj.exe
HKU-Default-Run-xlhnjslk.exe - c:\windows\xlhnjslk.exe
HKU-Default-Run-tjbeolwa.exe - c:\windows\tjbeolwa.exe
HKU-Default-Run-phnuwefu.exe - c:\windows\phnuwefu.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe


.
——- Bijkomende Scan ——-
.
FF - ProfilePath - c:\documents and settings\Michal\Application Data\Mozilla\Firefox\Profiles\znsybfek.default\
FF - prefs.js: browser.startup.homepage - www.startpagina.nl
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 18:09:51
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwOpenFile

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
——————— DLLs Geladen Onder Lopende Processen ———————

- - - - - - - > 'winlogon.exe'(456)
c:\windows\system32\Ati2evxx.dll
.
———————— Andere Aktieve Processen ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
.
**************************************************************************
.
Voltooingstijd: 2009-02-04 18:10:46 - machine werd herstart [Michal]
ComboFix-quarantined-files.txt 2009-02-04 17:10:44
ComboFix2.txt 2009-02-04 10:21:13
ComboFix3.txt 2009-02-03 23:54:07

Pre-Run: 46,872,158,208 bytes beschikbaar
Post-Run: 46,865,780,736 bytes beschikbaar

516 — E O F — 2009-02-04 00:36:01
It is getting beter.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\documents and settings\Michal\hhumc.exe
c:\windows\phnyztsb.exe
c:\windows\zzjwlrxf.exe
c:\windows\DUMP59e7.tmp
c:\windows\DUMP2dc6.tmp
c:\windows\guard.bmp
c:\windows\services.exe
c:\windows\system32\drivers\ixgituaw.sys
c:\windows\System32\Drivers\xgbuvhxe.sys

Driver::
ixgituaw
xgbuvhxe

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
services"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"zzjwlrxf.exe"=-
"phnyztsb.exe"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ixgituaw.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msuebwpx.sys]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
First of all, i'd like to thank you for all the help!

Computer behaviour: I lost internet AGAIN after Combofix had done it's work, so I had to remove the network adapter from my hardware screen again.
The computer still has the same startup routine: Welcome screen, goes black, logon sound, screen comes back, logoff sound…then I can choose the account I want to log in with:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:07:26, on 4-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\3.tmp
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\vdd8.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,C:\Documents and Settings\Michal\ueh.exe \s
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bndggard.exe] C:\WINDOWS\bndggard.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: nxkukde - C:\WINDOWS\SYSTEM32\nxkukde.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

–
End of file - 4279 bytes



ComboFix 09-02-03.01 - Michal 2009-02-04 18:51:52.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1657 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Michal\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: c:\documents and settings\Michal\Bureaublad\CFScript.txt

FILE ::
c:\documents and settings\Michal\hhumc.exe
c:\windows\DUMP2dc6.tmp
c:\windows\DUMP59e7.tmp
c:\windows\guard.bmp
c:\windows\phnyztsb.exe
c:\windows\services.exe
c:\windows\system32\drivers\ixgituaw.sys
c:\windows\System32\Drivers\xgbuvhxe.sys
c:\windows\zzjwlrxf.exe
.
ADS - svchost.exe: deleted 46592 bytes in 1 streams.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Michal\hhumc.exe
c:\windows\DUMP2dc6.tmp
c:\windows\DUMP59e7.tmp
c:\windows\guard.bmp
c:\windows\phnyztsb.exe
c:\windows\system32\B.tmp
c:\windows\system32\drivers\ixgituaw.sys
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\nxkukde.dll
c:\windows\zzjwlrxf.exe
c:\windows\system32\drivers\str.sys . . . . konden niet verwijderd worden

c:\windows\system32\userinit.exe . . . est infectee!!

c:\windows\system32\svchost.exe . . . est infectee!!

c:\windows\system32\spoolsv.exe . . . est infectee!!

c:\windows\explorer.exe . . . est infectee!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IXGITUAW
——-\Legacy_SYNSEND
——-\Service_ICF
——-\Service_ixgituaw
——-\Service_Passthru
——-\Service_synsend
——-\Service_xgbuvhxe


(((((((((((((((((((( Bestanden Gemaakt van 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))))
.

2009-02-04 18:14 . 2009-02-04 18:14 53,248 –a—— c:\windows\system32\drivers\ndisio.sys
2009-02-04 18:14 . 2009-02-04 18:14 32,768 –ah—– c:\documents and settings\Michal\shvlfn.exe
2009-02-04 18:14 . 2009-02-04 18:14 1,748 –a—— c:\windows\system32\netsf.inf
2009-02-04 18:14 . 2009-02-04 18:14 695 –a—— c:\windows\system32\netsf_m.inf
2009-02-04 17:07 . 2009-02-04 17:07 d——– c:\windows\ERUNT
2009-02-04 17:04 . 2009-02-04 17:09 d——– C:\SDFix
2009-02-04 17:04 . 2009-02-04 17:04 32,768 –ah—– c:\documents and settings\Michal\rnley.exe
2009-02-04 17:03 . 2009-02-04 17:03 32,768 –ah—– c:\documents and settings\Michal\yij.exe
2009-02-04 17:01 . 2009-01-14 04:37 96,256 –a—— c:\windows\system32\_ati2cqa.dll
2009-02-04 10:26 . 2009-02-04 18:59 702,496 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-04 19:00 35,104 –ahs—- c:\windows\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-04 18:58 9,260 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-04 18:58 4,340 –ahs—- c:\windows\system32\drivers\fidbox2.idx
2009-02-04 10:24 . 2009-02-04 18:13 32,768 –a—— c:\windows\system32\drivers\ati5gkxx.sys
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— c:\windows\system32\dllcache\ndis.sys
2009-02-04 01:14 . 2009-02-04 01:14 d——– c:\documents and settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— c:\windows\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— c:\windows\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\program files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– c:\documents and settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— c:\windows\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— c:\windows\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— c:\windows\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– c:\windows\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— c:\windows\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— c:\windows\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— c:\windows\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— c:\windows\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— c:\windows\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— c:\windows\system32\vidcap.ax
2009-02-03 23:49 . 2009-02-03 23:49 d——– c:\windows\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— c:\windows\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— c:\windows\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– c:\windows\EHome
2009-02-03 22:07 . 2009-02-03 22:07 d——– c:\documents and settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– c:\program files\Greatis
2009-02-03 22:05 . 2009-02-03 22:12 d——– c:\program files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— c:\windows\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– c:\documents and settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- c:\documents and settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-04 11:05 d——– c:\documents and settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-04 10:57 d——– c:\documents and settings\Administrator
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– c:\documents and settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– c:\documents and settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\program files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– c:\program files\Trend Micro
2009-02-03 19:52 . 2009-02-03 19:52 d——– c:\program files\Kaspersky Lab
2009-02-03 19:52 . 2009-02-04 01:09 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:47 . 2009-02-03 19:47 d——– c:\documents and settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm
2009-02-03 19:42 . 2009-02-03 19:42 d——– C:\Halu
2009-02-03 19:32 . 2008-04-13 23:15 172,416 –a—— c:\windows\system32\drivers\kmixer.sys
2009-02-03 19:32 . 2008-04-13 21:09 142,592 –a—— c:\windows\system32\drivers\aec.sys
2009-02-03 19:32 . 2008-04-13 23:47 83,072 –a—— c:\windows\system32\drivers\wdmaud.sys
2009-02-03 19:32 . 2008-04-13 23:45 60,800 –a—— c:\windows\system32\drivers\sysaudio.sys
2009-02-03 19:32 . 2008-04-13 23:15 56,576 –a—— c:\windows\system32\drivers\swmidi.sys
2009-02-03 19:32 . 2008-04-13 23:15 52,864 –a—— c:\windows\system32\drivers\DMusic.sys
2009-02-03 19:32 . 2008-04-13 23:09 7,552 –a—— c:\windows\system32\drivers\MSKSSRV.sys
2009-02-03 19:32 . 2008-04-13 23:15 6,272 –a—— c:\windows\system32\drivers\splitter.sys
2009-02-03 19:32 . 2008-04-13 23:09 5,376 –a—— c:\windows\system32\drivers\MSPCLOCK.sys
2009-02-03 19:32 . 2008-04-13 23:09 4,992 –a—— c:\windows\system32\drivers\MSPQM.sys
2009-02-03 19:32 . 2009-02-03 19:32 4,444 –a—— c:\windows\system32\pid.PNF
2009-02-03 19:32 . 2008-04-13 23:15 2,944 –a—— c:\windows\system32\drivers\drmkaud.sys
2009-02-03 19:31 . 2008-04-13 22:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-02-03 19:31 . 2008-04-14 20:33 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-02-03 19:31 . 2008-04-13 22:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-02-03 19:31 . 2008-04-13 23:15 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:31 . 2008-04-14 21:04 58,112 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-03 19:31 . 2008-04-14 21:32 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-03 19:31 . 2008-04-14 20:32 4,096 –a—— c:\windows\system32\ksuser.dll
2009-02-03 19:31 . 2001-08-17 20:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-03 19:30 . 2008-04-14 20:32 76,288 –a—— c:\windows\system32\usbui.dll
2009-02-03 19:28 . 2009-02-03 19:28 512,096 –a—— c:\windows\system32\drivers\_mon.s00
2009-02-03 19:28 . 2009-02-03 19:28 298,104 –a—— c:\windows\system32\_mon.d00
2009-02-03 19:28 . 2009-02-03 19:28 15,424 –a—— c:\windows\system32\drivers\_od32drv.s00
2009-02-03 19:23 . 2009-02-03 19:23 0 –a—— c:\windows\ativpsrm.bin
2009-02-03 19:21 . 2009-02-03 19:21 268 –ah—– C:\sqmdata01.sqm
2009-02-03 19:21 . 2009-02-03 19:21 244 –ah—– C:\sqmnoopt01.sqm
2009-02-03 19:18 . 2009-02-03 19:18 d——– c:\program files\GrabIt
2009-02-03 19:17 . 2009-02-03 23:09 d——– c:\program files\ATI Technologies
2009-02-03 19:17 . 2009-02-03 19:17 d——– C:\ATI
2009-02-03 19:17 . 2009-01-13 21:05 614,400 ——— c:\windows\system32\ati2sgag.exe
2009-02-03 19:06 . 2009-02-03 19:06 d——– c:\program files\PowerQuest
2009-02-03 19:05 . 2009-02-03 19:05 268 –ah—– C:\sqmdata00.sqm
2009-02-03 19:05 . 2009-02-03 19:05 244 –ah—– C:\sqmnoopt00.sqm
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\program files\Webteh
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\documents and settings\Michal\Application Data\BSplayer Pro
2009-02-03 19:03 . 2009-02-03 19:05 d——– c:\documents and settings\Michal\Application Data\BSplayer
2009-02-03 18:57 . 2009-02-04 15:03 124 –a—— c:\windows\adobe.bat
2009-02-03 18:57 . 2009-02-03 19:01 5 –a—— c:\windows\_id.dat
2009-02-03 18:56 . 2009-02-04 16:36 d——– c:\program files\Mozilla Thunderbird
2009-02-03 18:56 . 2009-02-03 18:56 d——– c:\documents and settings\Michal\Application Data\Thunderbird
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\drivers\bthport.sys
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\dllcache\bthport.sys
2009-02-03 18:55 . 2008-08-14 14:27 2,193,536 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,149,888 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,070,400 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,028,544 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 18:55 . 2008-09-15 16:28 1,846,528 ——— c:\windows\system32\dllcache\win32k.sys
2009-02-03 18:55 . 2009-02-04 18:14 66,560 —h—– c:\windows\system32\secupdat.dat
2009-02-03 18:55 . 2009-02-03 18:55 1,172 –a—— c:\windows\mozver.dat
2009-02-03 18:54 . 2009-02-03 18:54 d——– c:\program files\QuickPar
2009-02-03 18:54 . 2008-12-13 07:39 3,593,216 –a—— c:\windows\system32\dllcache\mshtml.dll
2009-02-03 18:54 . 2008-04-11 20:06 691,712 ——— c:\windows\system32\dllcache\inetcomm.dll
2009-02-03 18:54 . 2008-10-24 12:21 455,296 ——— c:\windows\system32\dllcache\mrxsmb.sys

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 09:27 94,208 —-a-w c:\windows\DUMP32d7.tmp
2009-02-04 09:22 182,656 —-a-w c:\windows\system32\drivers\ndis.sys
2009-02-03 18:54 94,208 —-a-w c:\windows\DUMP324b.tmp
2009-02-03 17:43 335,872 —-a-w c:\windows\HideWin.exe
2009-01-14 07:14 3,455,488 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.

——- Sigcheck ——-

2008-04-14 22:33 31744 7cbb1b22e73bd2e21b2c2f9fffdddb85 c:\windows\ServicePackFiles\i386\svchost.exe
2009-02-04 18:13 31744 44059c41f74387a6b58c6210c49c0539 c:\windows\system32\svchost.exe

2008-04-14 00:50 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys

2008-04-14 22:33 1054720 18fcb0e958953b03354e15b236945971 c:\windows\explorer.exe
2008-04-14 22:33 1054720 7cab377bb15acdbdb8519521496fc400 c:\windows\ServicePackFiles\i386\explorer.exe

2008-04-14 22:32 32768 b2b1bf07061b49d7268da5f0351d3ff8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 22:32 32768 1f82c9516eb017b1a36253ad46cfc945 c:\windows\system32\ctfmon.exe

2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 22:33 75264 3c2a848256cf5b73dc92314436ea2566 c:\windows\system32\spoolsv.exe

2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 22:33 43520 46e0a9c8fdb6b9b5036274730012214a c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-04_11.20.40.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2009-02-04 16:09:14 4,395,008 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2009-02-04 16:09:14 16,384 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-02-04 16:07:16 495,616 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2009-02-04 16:07:16 16,384 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-10-16 13:06:48 268,648 ——w c:\windows\SoftwareDistribution\SelfUpdate\Registered\mucltui.dll
+ 2009-01-14 03:37:08 96,256 —-a-w c:\windows\system32\_ati2cqa.dll
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-04 17:59:39 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 17:59:39 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 17:13:38 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012009020420090205\index.dat
- 2009-02-04 10:19:41 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-04 17:59:39 81,920 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"services"="c:\windows\services.exe" [BU]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reader_s"="c:\windows\System32\reader_s.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5gkxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R0 ati5gkxx;ati5gkxx;c:\windows\system32\drivers\ati5gkxx.sys [2009-02-04 32768]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]

NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
Tapisrv
Themes
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN
wscsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
.
——- Bijkomende Scan ——-
.
FF - ProfilePath - c:\documents and settings\Michal\Application Data\Mozilla\Firefox\Profiles\znsybfek.default\
FF - prefs.js: browser.startup.homepage - www.startpagina.nl
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 19:00:03
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwOpenFile

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …


c:\windows\system32\drivers\str.sys 0 bytes
c:\windows\system32\drivers\ybsoptagjgb.sys 30848 bytes executable

Scan succesvol afgerond
verborgen bestanden: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fbmffn]
"ImagePath"="\??\c:\windows\system32\drivers\ybsoptagjgb.sys"
.
——————— DLLs Geladen Onder Lopende Processen ———————

- - - - - - - > 'winlogon.exe'(452)
c:\windows\system32\Ati2evxx.dll
.
———————— Andere Aktieve Processen ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
.
**************************************************************************
.
Voltooingstijd: 2009-02-04 19:01:03 - machine werd herstart [Michal]
ComboFix-quarantined-files.txt 2009-02-04 18:00:59
ComboFix2.txt 2009-02-04 17:10:47
ComboFix3.txt 2009-02-04 10:21:13
ComboFix4.txt 2009-02-03 23:54:07

Pre-Run: 46.857.187.328 bytes beschikbaar
Post-Run: 46,848,655,360 bytes beschikbaar

346 — E O F — 2009-02-04 00:36:01
Download to your Desktop FixPolicies.exe, a self-extracting ZIP archive from here: http://downloads.malwareremoval.com/BillCa…FixPolicies.exe
  • Double-click FixPolicies.exe.
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box will briefly appear and then close. This will enable your Control Panel and stop the Administrative warnings, at least until the malware infection resets the registry policy keys again. You can run this as many times as you like.

Next:

Please follow this very carefully.
We need to replace some infected windows files.

If you are ask to replace the existing file, select yes.

Copy svchost.exe from this location c:\windows\ServicePackFiles\i386\svchost.exe
To: c:\windows\system32\

Copy explorer.exe from this location: c:\windows\ServicePackFiles\i386\explorer.exe
TO: c:\windows\

Copy spoolsv.exe from this location: c:\windows\ServicePackFiles\i386\spoolsv.exe
To: c:\windows\system32\

Copy userinit.exe from this location: c:\windows\ServicePackFiles\i386\userinit.exe
To: c:\windows\system32\


Next:

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\documents and settings\Michal\shvlfn.exe
c:\documents and settings\Michal\rnley.exe
c:\documents and settings\Michal\yij.exe
c:\windows\DUMP32d7.tmp
c:\windows\DUMP324b.tmp
c:\windows\services.exe
c:\documents and settings\Michal\reader_s.exe
c:\windows\System32\reader_s.exe
C:\WINDOWS\system32\3.tmp
C:\WINDOWS\TEMP\vdd8.tmp
C:\WINDOWS\system32\4.tmp
c:\windows\system32\drivers\Partizan.sys
c:\windows\system32\drivers\ybsoptagjgb.sys

Driver::
Partizan
ybsoptagjgb

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"services"=-
"reader_s"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reader_s"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"=-

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I was able to copy userinit and spoolsv by ending their proces in my taskmanager and then copying them, but couldn't replace explorer and svhost because they were in use and I couldn't end the processes.
I tried this in normal and safe mode. I also used that fixpolicies a few times (assuming it would let me replace the file, not sure what else it does)

So I got to replace two files, and couldn't replace two other files. I'll post logs of this proces, just to be sure:

Additional info: Using msconfig to restore files from my windows XP CD did _NOT_ work. My MSconfig file is missing, so I can't open it because I get an error saying windows can't find msconfig.


ComboFix 09-02-03.01 - Michal 2009-02-05 7:32:32.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1559 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Michal\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: c:\documents and settings\Michal\Bureaublad\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

FILE ::
c:\documents and settings\Michal\reader_s.exe
c:\documents and settings\Michal\rnley.exe
c:\documents and settings\Michal\shvlfn.exe
c:\documents and settings\Michal\yij.exe
c:\windows\DUMP324b.tmp
c:\windows\DUMP32d7.tmp
c:\windows\services.exe
c:\windows\system32\3.tmp
c:\windows\system32\4.tmp
c:\windows\system32\drivers\Partizan.sys
c:\windows\system32\drivers\ybsoptagjgb.sys
c:\windows\System32\reader_s.exe
c:\windows\TEMP\vdd8.tmp
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Michal\rnley.exe
c:\documents and settings\Michal\shvlfn.exe
c:\documents and settings\Michal\yij.exe
c:\windows\DUMP324b.tmp
c:\windows\DUMP32d7.tmp
c:\windows\system32\3.tmp
c:\windows\system32\4.tmp
c:\windows\system32\B.tmp
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys

c:\windows\system32\userinit.exe . . . est infectee!!

c:\windows\system32\svchost.exe . . . est infectee!!

c:\windows\system32\spoolsv.exe . . . est infectee!!

c:\windows\explorer.exe . . . est infectee!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PARTIZAN
——-\Service_Partizan
——-\Service_Passthru


(((((((((((((((((((( Bestanden Gemaakt van 2009-01-05 to 2009-02-05 ))))))))))))))))))))))))))))))
.

2009-02-05 07:24 . 2009-02-05 07:24 32,768 –ah—– c:\documents and settings\Administrator\bcgolvf.exe
2009-02-05 07:24 . 2009-02-05 07:24 44 –a—— c:\windows\system32\C.tmp
2009-02-05 07:23 . 2009-02-05 07:33 53,248 –a—— c:\windows\system32\drivers\ndisio.sys
2009-02-05 07:23 . 2009-02-05 07:23 32,768 –ah—– c:\documents and settings\Administrator\joaq.exe
2009-02-05 07:17 . 2009-02-05 07:17 44 –a—— c:\windows\system32\5.tmp
2009-02-05 07:00 . 2009-02-05 07:00 44 –a—— c:\windows\system32\D.tmp
2009-02-05 06:59 . 2009-02-05 06:59 44 –a—— c:\windows\system32\A.tmp
2009-02-05 06:58 . 2009-02-05 06:58 44 –a—— c:\windows\system32\2.tmp
2009-02-05 00:15 . 2009-02-05 00:15 32,768 –ah—– c:\documents and settings\Michal\igsigua.exe
2009-02-05 00:14 . 2009-02-05 00:14 32,768 –ah—– c:\documents and settings\Michal\uap.exe
2009-02-04 23:51 . 2009-02-04 23:51 32,768 –ah—– c:\documents and settings\Michal\qrfkw.exe
2009-02-04 23:31 . 2009-02-04 23:31 32,768 –ah—– c:\documents and settings\Michal\lvhmkd.exe
2009-02-04 23:27 . 2009-02-04 23:27 32,768 –ah—– c:\documents and settings\Michal\vujg.exe
2009-02-04 23:15 . 2009-02-04 23:35 d——– c:\program files\Lavasoft
2009-02-04 23:15 . 2009-02-04 23:35 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-04 23:07 . 2009-02-04 23:07 88 –a—— c:\windows\system32\20.tmp
2009-02-04 20:13 . 2009-02-04 20:13 d——– c:\program files\Kaspersky Lab
2009-02-04 20:13 . 2009-02-04 20:28 101,287 –a—— c:\windows\system32\drivers\klin.dat
2009-02-04 20:13 . 2009-02-04 20:28 89,601 –a—— c:\windows\system32\drivers\klick.dat
2009-02-04 19:56 . 2009-02-04 19:56 0 –a—— c:\windows\system32\17.tmp
2009-02-04 19:04 . 2009-02-04 19:04 32,768 –ah—– c:\documents and settings\Michal\ueh.exe
2009-02-04 17:07 . 2009-02-04 17:07 d——– c:\windows\ERUNT
2009-02-04 17:04 . 2009-02-04 21:58 d——– C:\SDFix
2009-02-04 17:01 . 2009-01-14 04:37 96,256 –a—— c:\windows\system32\_ati2cqa.dll
2009-02-04 10:36 . 2009-02-04 21:59 90,112 –a—— c:\windows\DUMP2cfb.tmp
2009-02-04 10:26 . 2009-02-05 07:39 2,030,368 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-05 07:39 71,200 –ahs—- c:\windows\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-05 07:39 28,220 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-05 07:39 7,748 –ahs—- c:\windows\system32\drivers\fidbox2.idx
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— c:\windows\system32\dllcache\ndis.sys
2009-02-04 01:14 . 2009-02-04 01:14 d——– c:\documents and settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— c:\windows\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— c:\windows\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\program files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– c:\documents and settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— c:\windows\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— c:\windows\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— c:\windows\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– c:\windows\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— c:\windows\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— c:\windows\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— c:\windows\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— c:\windows\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— c:\windows\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— c:\windows\system32\vidcap.ax
2009-02-03 23:49 . 2009-02-03 23:49 d——– c:\windows\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— c:\windows\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— c:\windows\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– c:\windows\EHome
2009-02-03 22:07 . 2009-02-03 22:07 d——– c:\documents and settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– c:\program files\Greatis
2009-02-03 22:05 . 2009-02-03 22:12 d——– c:\program files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— c:\windows\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– c:\documents and settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- c:\documents and settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-05 07:24 d——– c:\documents and settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-05 07:24 d——– c:\documents and settings\Administrator
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– c:\documents and settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– c:\documents and settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-04 23:09 d——– c:\program files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-04 23:11 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– c:\program files\Trend Micro
2009-02-03 19:52 . 2009-02-05 07:30 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:47 . 2009-02-03 19:47 d——– c:\documents and settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm
2009-02-03 19:32 . 2008-04-13 23:15 172,416 –a—— c:\windows\system32\drivers\kmixer.sys
2009-02-03 19:32 . 2008-04-13 21:09 142,592 –a—— c:\windows\system32\drivers\aec.sys
2009-02-03 19:32 . 2008-04-13 23:47 83,072 –a—— c:\windows\system32\drivers\wdmaud.sys
2009-02-03 19:32 . 2008-04-13 23:45 60,800 –a—— c:\windows\system32\drivers\sysaudio.sys
2009-02-03 19:32 . 2008-04-13 23:15 56,576 –a—— c:\windows\system32\drivers\swmidi.sys
2009-02-03 19:32 . 2008-04-13 23:15 52,864 –a—— c:\windows\system32\drivers\DMusic.sys
2009-02-03 19:32 . 2008-04-13 23:09 7,552 –a—— c:\windows\system32\drivers\MSKSSRV.sys
2009-02-03 19:32 . 2008-04-13 23:15 6,272 –a—— c:\windows\system32\drivers\splitter.sys
2009-02-03 19:32 . 2008-04-13 23:09 5,376 –a—— c:\windows\system32\drivers\MSPCLOCK.sys
2009-02-03 19:32 . 2008-04-13 23:09 4,992 –a—— c:\windows\system32\drivers\MSPQM.sys
2009-02-03 19:32 . 2009-02-03 19:32 4,444 –a—— c:\windows\system32\pid.PNF
2009-02-03 19:32 . 2008-04-13 23:15 2,944 –a—— c:\windows\system32\drivers\drmkaud.sys
2009-02-03 19:31 . 2008-04-13 22:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-02-03 19:31 . 2008-04-14 20:33 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-02-03 19:31 . 2008-04-13 22:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-02-03 19:31 . 2008-04-13 23:15 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:31 . 2008-04-14 21:04 58,112 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-03 19:31 . 2008-04-14 21:32 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-03 19:31 . 2008-04-14 20:32 4,096 –a—— c:\windows\system32\ksuser.dll
2009-02-03 19:31 . 2001-08-17 20:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-03 19:30 . 2008-04-14 20:32 76,288 –a—— c:\windows\system32\usbui.dll
2009-02-03 19:28 . 2009-02-03 19:28 512,096 –a—— c:\windows\system32\drivers\_mon.s00
2009-02-03 19:28 . 2009-02-03 19:28 298,104 –a—— c:\windows\system32\_mon.d00
2009-02-03 19:28 . 2009-02-03 19:28 15,424 –a—— c:\windows\system32\drivers\_od32drv.s00
2009-02-03 19:23 . 2009-02-03 19:23 0 –a—— c:\windows\ativpsrm.bin
2009-02-03 19:21 . 2009-02-03 19:21 268 –ah—– C:\sqmdata01.sqm
2009-02-03 19:21 . 2009-02-03 19:21 244 –ah—– C:\sqmnoopt01.sqm
2009-02-03 19:18 . 2009-02-03 19:18 d——– c:\program files\GrabIt
2009-02-03 19:17 . 2009-02-03 23:09 d——– c:\program files\ATI Technologies
2009-02-03 19:17 . 2009-02-03 19:17 d——– C:\ATI
2009-02-03 19:17 . 2009-01-13 21:05 614,400 ——— c:\windows\system32\ati2sgag.exe
2009-02-03 19:06 . 2009-02-03 19:06 d——– c:\program files\PowerQuest
2009-02-03 19:05 . 2009-02-03 19:05 268 –ah—– C:\sqmdata00.sqm
2009-02-03 19:05 . 2009-02-03 19:05 244 –ah—– C:\sqmnoopt00.sqm
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\program files\Webteh
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\documents and settings\Michal\Application Data\BSplayer Pro
2009-02-03 19:03 . 2009-02-03 19:05 d——– c:\documents and settings\Michal\Application Data\BSplayer
2009-02-03 18:57 . 2009-02-04 15:03 124 –a—— c:\windows\adobe.bat
2009-02-03 18:57 . 2009-02-03 19:01 5 –a—— c:\windows\_id.dat
2009-02-03 18:56 . 2009-02-05 07:00 d——– c:\program files\Mozilla Thunderbird
2009-02-03 18:56 . 2009-02-03 18:56 d——– c:\documents and settings\Michal\Application Data\Thunderbird

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 09:22 182,656 —-a-w c:\windows\system32\drivers\ndis.sys
2009-02-03 17:43 335,872 —-a-w c:\windows\HideWin.exe
2009-01-14 07:14 3,455,488 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.

——- Sigcheck ——-

2008-04-14 22:33 31744 7cbb1b22e73bd2e21b2c2f9fffdddb85 c:\windows\ServicePackFiles\i386\svchost.exe
2009-02-05 00:15 31744 44059c41f74387a6b58c6210c49c0539 c:\windows\system32\svchost.exe

2008-04-14 00:50 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys

2008-04-14 22:33 1054720 18fcb0e958953b03354e15b236945971 c:\windows\explorer.exe
2008-04-14 22:33 1054720 7cab377bb15acdbdb8519521496fc400 c:\windows\ServicePackFiles\i386\explorer.exe

2008-04-14 22:32 32768 b2b1bf07061b49d7268da5f0351d3ff8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 22:32 32768 1f82c9516eb017b1a36253ad46cfc945 c:\windows\system32\ctfmon.exe

2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\system32\spoolsv.exe

2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot_2009-02-04_23.51.28.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-04 22:50:49 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-05 06:39:51 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 22:50:49 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-05 06:39:51 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
- 2009-02-04 21:52:28 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012009020420090205\index.dat
+ 2009-02-04 22:50:49 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012009020420090205\index.dat
- 2009-02-04 22:50:49 98,304 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-05 06:39:51 98,304 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-04 22:31:32 66,560 —h–w c:\windows\system32\secupdat.dat
+ 2009-02-05 06:24:42 66,560 —h–w c:\windows\system32\secupdat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 221248]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\birddgnn.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\llwflzir.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qyituqjg.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

S0 birddgnn;birddgnn;c:\windows\system32\Drivers\birddgnn.sys –> c:\windows\system32\Drivers\birddgnn.sys [?]
S0 llwflzir;llwflzir;c:\windows\system32\Drivers\llwflzir.sys –> c:\windows\system32\Drivers\llwflzir.sys [?]
S0 qyituqjg;qyituqjg;c:\windows\system32\Drivers\qyituqjg.sys –> c:\windows\system32\Drivers\qyituqjg.sys [?]
S1 ethcproe;ethcproe;c:\windows\system32\drivers\ethcproe.sys –> c:\windows\system32\drivers\ethcproe.sys [?]
S2 fbmffn;fbmffn;\??\c:\windows\system32\drivers\ybsoptagjgb.sys –> c:\windows\system32\drivers\ybsoptagjgb.sys [?]
S3 coqhifkb;coqhifkb;\??\c:\windows\System32\Drivers\coqhifkb.sys –> c:\windows\System32\Drivers\coqhifkb.sys [?]
S3 gsyhcthf;gsyhcthf;\??\c:\windows\System32\Drivers\gsyhcthf.sys –> c:\windows\System32\Drivers\gsyhcthf.sys [?]
S3 otkunxas;otkunxas;\??\c:\windows\System32\Drivers\otkunxas.sys –> c:\windows\System32\Drivers\otkunxas.sys [?]
S3 qoqxyawv;qoqxyawv;\??\c:\windows\System32\Drivers\qoqxyawv.sys –> c:\windows\System32\Drivers\qoqxyawv.sys [?]
S3 vigcwilv;vigcwilv;\??\c:\windows\System32\Drivers\vigcwilv.sys –> c:\windows\System32\Drivers\vigcwilv.sys [?]
S3 yoeguanj;yoeguanj;\??\c:\windows\System32\Drivers\yoeguanj.sys –> c:\windows\System32\Drivers\yoeguanj.sys [?]

NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
Tapisrv
Themes
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN
wscsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
.
——- Bijkomende Scan ——-
.
FF - ProfilePath - c:\documents and settings\Michal\Application Data\Mozilla\Firefox\Profiles\znsybfek.default\
FF - prefs.js: browser.startup.homepage - www.startpagina.nl
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-05 07:40:19
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwOpenFile

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
——————— DLLs Geladen Onder Lopende Processen ———————

- - - - - - - > 'winlogon.exe'(452)
c:\windows\system32\Ati2evxx.dll
.
———————— Andere Aktieve Processen ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
.
**************************************************************************
.
Voltooingstijd: 2009-02-05 7:41:16 - machine werd herstart
ComboFix-quarantined-files.txt 2009-02-05 06:41:13
ComboFix2.txt 2009-02-04 23:26:39
ComboFix3.txt 2009-02-04 23:07:55
ComboFix4.txt 2009-02-04 22:51:59
ComboFix5.txt 2009-02-05 06:32:10

Pre-Run: 46.503.645.184 bytes beschikbaar
Post-Run: 46,494,806,016 bytes beschikbaar

345 — E O F — 2009-02-04 00:36:01




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:58, on 5-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\TEMP\VRT3.tmp
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)

–
End of file - 3733 bytes
Because I need the computer for uni-work by this weekend, i'm gonna try a last (fast) remedy. I'm going to do a full format of my whole hdd and hope it fixes it. If it doesn't, i'll post logs here again…. I Greatly appreciate the help so far!
That really is the only way to go as those Windows files that are infected would require a Windows CD to try and replace them. I don't know where you got infected but it's a bad one. Be sure to get your anti-virus / anti-spyware installed and running before you surf the net.
Yes, I also tried replacing those files by using my windows cd (or even copying the essential files from the cd to my hdd), but it didn't work. I kept getting the "insert correct cd" error, even after using all the known fixes to bypass that. I did a full format (and deleted all the partitions) of my hdd, while only burning a few - for me - essential files on a dvd. After the full format I reinstalled windows. I immediately installed SP3 ( which I had also burned, together with a firewall (comodo) and my antivirus (kaspersky)), after which I also installed the firewall and antivirus. Then I plugged myself back into the network (I was afraid I might get infected through the network, because I know the other pc on this network isn't entirely clean) and the first thing I did was download all essential windows updates. The system seems to be working fine again. Would you advise running another hijackthis/combofix and posting logs, just to be sure everything is gone? Another thing: the windows sfc (atleast, it looks like it) sometimes keeps popping up while installing new drivers etc. It keeps telling me to insert the windows cd to place back the "changed" windows files. Is this safe? If so; can I disable it? P.S. I am very thankfull for the help you have provided me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI