I'm sorry for the Combofix log being incomplete, but that's all I got. My computer automatically rebooted before combofix could finish the whole log. I got a whole log this time.
Computer behaviour:
- Still the same startup routine: Welcome screen, login sound, screen goes black -> Screen comes back, logoff sound…login sound and I can choose the account I want to login with.
- My internet stopped working. It said my network adapter/card was missing some registry values, so it wasn't working correctly. Had to remove the adapter from my hardware screen and reboot, it's working now.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:08, on 4-2-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\znc4.tmp
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Michal\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [zzjwlrxf.exe] C:\WINDOWS\zzjwlrxf.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [phnyztsb.exe] C:\WINDOWS\phnyztsb.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1233699131265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: nxkukde - C:\WINDOWS\SYSTEM32\nxkukde.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
–
End of file - 4187 bytes
ComboFix 09-02-03.01 - Michal 2009-02-04 18:01:54.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1043.18.2046.1573 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Michal\Bureaublad\ComboFix.exe
gebruikte Opdracht switches :: c:\documents and settings\Michal\Bureaublad\CFScript.txt
FILE ::
C:\-1997125074
c:\documents and settings\Michal\rjrgu.exe
C:\mdmcqfv.exe
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
c:\windows\dbxqhkbt.exe
c:\windows\dbxqrwli.exe
c:\windows\fprampto.exe
c:\windows\fpramqnr.exe
c:\windows\fprauipn.exe
c:\windows\fprdwtwe.exe
c:\windows\fprewolo.exe
c:\windows\fprhtqqp.exe
c:\windows\fprwkcer.exe
c:\windows\fprwkiqd.exe
c:\windows\hdaqkrmv.exe
c:\windows\jrfusein.exe
c:\windows\phnfvrcj.exe
c:\windows\phnfxuet.exe
c:\windows\phnkbuqy.exe
c:\windows\phnkbxxc.exe
c:\windows\phnuwefu.exe
c:\windows\phnyzelk.exe
c:\windows\rvhirvff.exe
c:\windows\rvhiumba.exe
c:\windows\rvhiuvju.exe
c:\windows\rvhylfje.exe
c:\windows\system32\10.tmp
c:\windows\system32\11.tmp
c:\windows\system32\12.tmp
c:\windows\system32\14.tmp
c:\windows\system32\16.tmp
c:\windows\system32\17.tmp
c:\windows\system32\18.tmp
c:\windows\system32\19.tmp
c:\windows\system32\1A.tmp
c:\windows\system32\1C.tmp
c:\windows\system32\1E.tmp
c:\windows\system32\1F.tmp
c:\windows\system32\2.tmp
c:\windows\system32\20.tmp
c:\windows\system32\21.tmp
c:\windows\system32\24.tmp
c:\windows\system32\25.tmp
c:\windows\system32\28.tmp
c:\windows\system32\7.tmp
c:\windows\system32\8.tmp
c:\windows\system32\A.tmp
c:\windows\system32\C.tmp
c:\windows\system32\D.tmp
c:\windows\system32\drivers\etherobc.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\F.tmp
c:\windows\tjbeolwa.exe
c:\windows\tjbewwgs.exe
c:\windows\tjbsuqpo.exe
c:\windows\tjbvjeef.exe
c:\windows\vxvnwpoh.exe
c:\windows\vybxbhuw.exe
c:\windows\xlhnjslk.exe
c:\windows\xlpxczxp.exe
c:\windows\zzjsircn.exe
c:\windows\zzjwblzz.exe
.
ADS - svchost.exe: deleted 46592 bytes in 1 streams.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-1997125074
c:\documents and settings\Michal\rjrgu.exe
C:\mdmcqfv.exe
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
c:\windows\dbxqhkbt.exe
c:\windows\dbxqrwli.exe
c:\windows\fprampto.exe
c:\windows\fpramqnr.exe
c:\windows\fprauipn.exe
c:\windows\fprdwtwe.exe
c:\windows\fprewolo.exe
c:\windows\fprhtqqp.exe
c:\windows\fprwkcer.exe
c:\windows\fprwkiqd.exe
c:\windows\hdaqkrmv.exe
c:\windows\jrfusein.exe
c:\windows\phnfvrcj.exe
c:\windows\phnfxuet.exe
c:\windows\phnkbuqy.exe
c:\windows\phnkbxxc.exe
c:\windows\phnuwefu.exe
c:\windows\phnyzelk.exe
c:\windows\rvhirvff.exe
c:\windows\rvhiumba.exe
c:\windows\rvhiuvju.exe
c:\windows\rvhylfje.exe
c:\windows\system32\10.tmp
c:\windows\system32\11.tmp
c:\windows\system32\12.tmp
c:\windows\system32\14.tmp
c:\windows\system32\16.tmp
c:\windows\system32\17.tmp
c:\windows\system32\18.tmp
c:\windows\system32\19.tmp
c:\windows\system32\1A.tmp
c:\windows\system32\1C.tmp
c:\windows\system32\1E.tmp
c:\windows\system32\1F.tmp
c:\windows\system32\2.tmp
c:\windows\system32\20.tmp
c:\windows\system32\21.tmp
c:\windows\system32\24.tmp
c:\windows\system32\25.tmp
c:\windows\system32\28.tmp
c:\windows\system32\7.tmp
c:\windows\system32\8.tmp
c:\windows\system32\A.tmp
c:\windows\system32\C.tmp
c:\windows\system32\D.tmp
c:\windows\system32\drivers\etherobc.sys
c:\windows\system32\drivers\ndisio.sys
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\F.tmp
c:\windows\system32\nxkukde.dll
c:\windows\system32\nxkukde32.dll
c:\windows\tjbeolwa.exe
c:\windows\tjbewwgs.exe
c:\windows\tjbsuqpo.exe
c:\windows\tjbvjeef.exe
c:\windows\vxvnwpoh.exe
c:\windows\vybxbhuw.exe
c:\windows\xlhnjslk.exe
c:\windows\xlpxczxp.exe
c:\windows\zzjsircn.exe
c:\windows\zzjwblzz.exe
.
—- Voorgaande Run ——-
.
C:\byptemd.exe
C:\ddcyusuf.exe
c:\documents and settings\Michal\qqe.exe
c:\documents and settings\Michal\reader_s.exe
C:\ophluxmi.exe
C:\txxsv.exe
c:\windows\DUMP3a3a.tmp
c:\windows\DUMP3d66.tmp
c:\windows\system32\1D.tmp
c:\windows\system32\2A.tmp
c:\windows\system32\3.tmp
c:\windows\system32\30.tmp
c:\windows\system32\4.tmp
c:\windows\system32\6.tmp
c:\windows\system32\9.tmp
c:\windows\system32\B.tmp
c:\windows\system32\drivers\ntndis.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\nxkukde.dll
c:\windows\system32\reader_s.exe
c:\windows\system32\tjlzakww.dll
c:\windows\winstart.bat
c:\windows\system32\userinit.exe . . . est infectee!!
c:\windows\system32\svchost.exe . . . est infectee!!
c:\windows\system32\spoolsv.exe . . . est infectee!!
c:\windows\explorer.exe . . . est infectee!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FCI
——-\Legacy_ICF
——-\Service_FCI
——-\Service_Passthru
——-\Service_etherobc
——-\Service_Passthru
(((((((((((((((((((( Bestanden Gemaakt van 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))))
.
2009-02-04 17:12 . 2009-02-04 17:12 11,776 –ah—– c:\documents and settings\Michal\hhumc.exe
2009-02-04 17:10 . 2009-02-04 17:10 3,584 –a—— c:\windows\phnyztsb.exe
2009-02-04 17:07 . 2009-02-04 17:07 d——– c:\windows\ERUNT
2009-02-04 17:04 . 2009-02-04 17:09 d——– C:\SDFix
2009-02-04 17:04 . 2009-02-04 17:04 33,920 –a—— c:\windows\system32\drivers\ixgituaw.sys
2009-02-04 17:04 . 2009-02-04 17:04 32,768 –ah—– c:\documents and settings\Michal\rnley.exe
2009-02-04 17:03 . 2009-02-04 17:03 32,768 –ah—– c:\documents and settings\Michal\yij.exe
2009-02-04 17:01 . 2009-01-14 04:37 96,256 –a—— c:\windows\system32\_ati2cqa.dll
2009-02-04 17:01 . 2009-02-04 17:01 3,584 –a—— c:\windows\zzjwlrxf.exe
2009-02-04 10:36 . 2009-02-04 17:08 90,112 –a—— c:\windows\DUMP59e7.tmp
2009-02-04 10:36 . 2009-02-04 17:09 90,112 –a—— c:\windows\DUMP2dc6.tmp
2009-02-04 10:26 . 2009-02-04 18:09 587,808 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-02-04 10:26 . 2009-02-04 18:09 34,592 –ahs—- c:\windows\system32\drivers\fidbox2.dat
2009-02-04 10:26 . 2009-02-04 18:08 7,892 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-02-04 10:26 . 2009-02-04 18:08 4,268 –ahs—- c:\windows\system32\drivers\fidbox2.idx
2009-02-04 10:24 . 2009-02-04 17:12 32,768 –a—— c:\windows\system32\drivers\ati5gkxx.sys
2009-02-04 10:22 . 2009-02-04 10:22 182,656 –a—— c:\windows\system32\dllcache\ndis.sys
2009-02-04 01:14 . 2009-02-04 01:14 d——– c:\documents and settings\Michal\Application Data\Symantec
2009-02-04 01:10 . 2009-02-04 10:19 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-02-04 01:09 . 2009-02-04 10:21 d——– c:\program files\Common Files\Symantec Shared
2009-02-04 00:41 . 2009-02-04 00:41 76 –a—— c:\windows\lsoon.ini
2009-02-04 00:40 . 2009-02-04 00:40 44 –a—— c:\windows\system32\Partizan.RRI
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\xircom
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\system32\restore
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\srchasst
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\windows\msagent
2009-02-04 00:39 . 2009-02-04 00:39 d——– c:\program files\microsoft frontpage
2009-02-04 00:35 . 2009-02-04 00:35 d——– c:\documents and settings\NetworkService\Menu Start
2009-02-04 00:30 . 2008-04-14 22:09 88,064 ——— c:\windows\system32\dllcache\msxml6r.dll
2009-02-04 00:28 . 2008-04-14 22:33 806,912 ——— c:\windows\system32\dllcache\migrate.exe
2009-02-04 00:26 . 2008-04-14 22:32 4,274,816 ——— c:\windows\system32\nv4_disp.dll
2009-02-04 00:25 . 2009-02-04 00:25 d——– c:\windows\system32\bits
2009-02-04 00:25 . 2008-04-14 22:33 148,480 ——— c:\windows\system32\wscui.cpl
2009-02-04 00:25 . 2008-04-14 22:33 94,276 ——— c:\windows\system32\slserv.exe
2009-02-04 00:25 . 2008-04-14 22:32 80,896 ——— c:\windows\system32\wscsvc.dll
2009-02-04 00:25 . 2008-04-14 22:32 57,856 ——— c:\windows\system32\twext.dll
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\system32\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 53,346 ——— c:\windows\slrundll.exe
2009-02-04 00:25 . 2008-04-14 22:33 31,232 ——— c:\windows\system32\wscntfy.exe
2009-02-04 00:25 . 2008-04-14 22:33 28,672 ——— c:\windows\system32\vidcap.ax
2009-02-03 23:49 . 2009-02-03 23:49 d——– c:\windows\ServicePackFiles
2009-02-03 23:45 . 2008-04-14 22:08 2,965,504 ——— c:\windows\system32\dllcache\wmploc.dll
2009-02-03 23:29 . 2008-04-13 22:04 1,897,408 ——— c:\windows\system32\drivers\nv4_mini.sys
2009-02-03 23:25 . 2009-02-04 00:27 d——– c:\windows\EHome
2009-02-03 22:07 . 2009-02-03 22:07 d——– c:\documents and settings\Michal\Application Data\Regrun
2009-02-03 22:07 . 2009-02-04 00:41 d——– C:\backreg
2009-02-03 22:06 . 2009-02-03 22:06 d——– c:\program files\Greatis
2009-02-03 22:06 . 2003-09-06 15:55 57,556 –a—— c:\windows\guard.bmp
2009-02-03 22:05 . 2009-02-03 22:12 d——– c:\program files\Prevx
2009-02-03 22:05 . 2009-02-03 22:05 65 –a—— c:\windows\wininit.ini
2009-02-03 21:30 . 2009-02-03 21:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 21:14 . 2009-02-03 18:34 d–h—– c:\documents and settings\Administrator\Sjablonen
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Onlangs geopend
2009-02-03 21:14 . 2009-02-03 17:21 d–h—– c:\documents and settings\Administrator\Netwerkprinteromgeving
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Mijn documenten
2009-02-03 21:14 . 2009-02-03 17:21 dr——- c:\documents and settings\Administrator\Menu Start
2009-02-03 21:14 . 2009-02-03 17:21 d——– c:\documents and settings\Administrator\Favorieten
2009-02-03 21:14 . 2009-02-04 11:05 d——– c:\documents and settings\Administrator\Bureaublad
2009-02-03 21:14 . 2009-02-04 10:57 d——– c:\documents and settings\Administrator
2009-02-03 21:09 . 2009-02-03 21:09 244 –ah—– C:\sqmnoopt04.sqm
2009-02-03 21:09 . 2009-02-03 21:09 232 –ah—– C:\sqmdata04.sqm
2009-02-03 20:58 . 2009-02-03 21:47 d——– c:\documents and settings\Michal\Application Data\GrabIt
2009-02-03 20:56 . 2009-02-03 20:56 32,768 –ah—– c:\documents and settings\Michal\xls.exe
2009-02-03 20:52 . 2009-02-03 20:52 244 –ah—– C:\sqmnoopt03.sqm
2009-02-03 20:52 . 2009-02-03 20:52 232 –ah—– C:\sqmdata03.sqm
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\program files\Spybot - Search & Destroy
2009-02-03 20:27 . 2009-02-04 17:03 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 20:03 . 2009-02-03 20:03 d——– c:\program files\Trend Micro
2009-02-03 19:52 . 2009-02-03 19:52 d——– c:\program files\Kaspersky Lab
2009-02-03 19:52 . 2009-02-04 01:09 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-03 19:47 . 2009-02-03 19:47 d——– c:\documents and settings\Michal\Contacts
2009-02-03 19:43 . 2009-02-03 19:43 268 –ah—– C:\sqmdata02.sqm
2009-02-03 19:43 . 2009-02-03 19:43 244 –ah—– C:\sqmnoopt02.sqm
2009-02-03 19:42 . 2009-02-03 19:42 d——– C:\Halu
2009-02-03 19:32 . 2008-04-13 23:15 172,416 –a—— c:\windows\system32\drivers\kmixer.sys
2009-02-03 19:32 . 2008-04-13 21:09 142,592 –a—— c:\windows\system32\drivers\aec.sys
2009-02-03 19:32 . 2008-04-13 23:47 83,072 –a—— c:\windows\system32\drivers\wdmaud.sys
2009-02-03 19:32 . 2008-04-13 23:45 60,800 –a—— c:\windows\system32\drivers\sysaudio.sys
2009-02-03 19:32 . 2008-04-13 23:15 56,576 –a—— c:\windows\system32\drivers\swmidi.sys
2009-02-03 19:32 . 2008-04-13 23:15 52,864 –a—— c:\windows\system32\drivers\DMusic.sys
2009-02-03 19:32 . 2008-04-13 23:09 7,552 –a—— c:\windows\system32\drivers\MSKSSRV.sys
2009-02-03 19:32 . 2008-04-13 23:15 6,272 –a—— c:\windows\system32\drivers\splitter.sys
2009-02-03 19:32 . 2008-04-13 23:09 5,376 –a—— c:\windows\system32\drivers\MSPCLOCK.sys
2009-02-03 19:32 . 2008-04-13 23:09 4,992 –a—— c:\windows\system32\drivers\MSPQM.sys
2009-02-03 19:32 . 2009-02-03 19:32 4,444 –a—— c:\windows\system32\pid.PNF
2009-02-03 19:32 . 2008-04-13 23:15 2,944 –a—— c:\windows\system32\drivers\drmkaud.sys
2009-02-03 19:31 . 2008-04-13 22:49 146,048 –a—— c:\windows\system32\drivers\portcls.sys
2009-02-03 19:31 . 2008-04-14 20:33 129,536 –a—— c:\windows\system32\ksproxy.ax
2009-02-03 19:31 . 2008-04-13 22:15 60,160 –a—— c:\windows\system32\drivers\drmk.sys
2009-02-03 19:31 . 2008-04-13 23:15 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-02-03 19:31 . 2008-04-14 21:04 58,112 –a—— c:\windows\system32\drivers\redbook.sys
2009-02-03 19:31 . 2008-04-14 21:32 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-03 19:31 . 2008-04-14 20:32 4,096 –a—— c:\windows\system32\ksuser.dll
2009-02-03 19:31 . 2001-08-17 20:59 3,072 –a—— c:\windows\system32\drivers\audstub.sys
2009-02-03 19:30 . 2008-04-14 20:32 76,288 –a—— c:\windows\system32\usbui.dll
2009-02-03 19:28 . 2009-02-03 19:28 512,096 –a—— c:\windows\system32\drivers\_mon.s00
2009-02-03 19:28 . 2009-02-03 19:28 298,104 –a—— c:\windows\system32\_mon.d00
2009-02-03 19:28 . 2009-02-03 19:28 15,424 –a—— c:\windows\system32\drivers\_od32drv.s00
2009-02-03 19:23 . 2009-02-03 19:23 0 –a—— c:\windows\ativpsrm.bin
2009-02-03 19:21 . 2009-02-03 19:21 268 –ah—– C:\sqmdata01.sqm
2009-02-03 19:21 . 2009-02-03 19:21 244 –ah—– C:\sqmnoopt01.sqm
2009-02-03 19:18 . 2009-02-03 19:18 d——– c:\program files\GrabIt
2009-02-03 19:17 . 2009-02-03 23:09 d——– c:\program files\ATI Technologies
2009-02-03 19:17 . 2009-02-03 19:17 d——– C:\ATI
2009-02-03 19:17 . 2009-01-13 21:05 614,400 ——— c:\windows\system32\ati2sgag.exe
2009-02-03 19:06 . 2009-02-03 19:06 d——– c:\program files\PowerQuest
2009-02-03 19:05 . 2009-02-03 19:05 268 –ah—– C:\sqmdata00.sqm
2009-02-03 19:05 . 2009-02-03 19:05 244 –ah—– C:\sqmnoopt00.sqm
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\program files\Webteh
2009-02-03 19:03 . 2009-02-03 19:03 d——– c:\documents and settings\Michal\Application Data\BSplayer Pro
2009-02-03 19:03 . 2009-02-03 19:05 d——– c:\documents and settings\Michal\Application Data\BSplayer
2009-02-03 18:57 . 2009-02-04 15:03 124 –a—— c:\windows\adobe.bat
2009-02-03 18:57 . 2009-02-03 19:01 5 –a—— c:\windows\_id.dat
2009-02-03 18:56 . 2009-02-04 16:36 d——– c:\program files\Mozilla Thunderbird
2009-02-03 18:56 . 2009-02-03 18:56 d——– c:\documents and settings\Michal\Application Data\Thunderbird
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\drivers\bthport.sys
2009-02-03 18:56 . 2008-06-14 18:36 272,640 ——— c:\windows\system32\dllcache\bthport.sys
2009-02-03 18:55 . 2008-08-14 14:27 2,193,536 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,149,888 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,070,400 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-03 18:55 . 2008-08-14 14:27 2,028,544 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 18:55 . 2008-09-15 16:28 1,846,528 ——— c:\windows\system32\dllcache\win32k.sys
2009-02-03 18:55 . 2009-02-04 17:12 66,560 —h—– c:\windows\system32\secupdat.dat
2009-02-03 18:55 . 2009-02-03 18:55 1,172 –a—— c:\windows\mozver.dat
2009-02-03 18:54 . 2009-02-03 18:54 d——– c:\program files\QuickPar
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 09:27 94,208 —-a-w c:\windows\DUMP32d7.tmp
2009-02-04 09:22 182,656 —-a-w c:\windows\system32\drivers\ndis.sys
2009-02-03 18:54 94,208 —-a-w c:\windows\DUMP324b.tmp
2009-02-03 17:43 335,872 —-a-w c:\windows\HideWin.exe
2009-01-14 07:14 3,455,488 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 03:43 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.
——- Sigcheck ——-
2008-04-14 22:33 31744 7cbb1b22e73bd2e21b2c2f9fffdddb85 c:\windows\ServicePackFiles\i386\svchost.exe
2009-02-04 17:12 31744 44059c41f74387a6b58c6210c49c0539 c:\windows\system32\svchost.exe
2008-04-14 00:50 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-04 10:22 213632 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
2008-04-14 22:33 1054720 18fcb0e958953b03354e15b236945971 c:\windows\explorer.exe
2008-04-14 22:33 1054720 7cab377bb15acdbdb8519521496fc400 c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-14 22:32 32768 b2b1bf07061b49d7268da5f0351d3ff8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 22:32 32768 1f82c9516eb017b1a36253ad46cfc945 c:\windows\system32\ctfmon.exe
2008-04-14 22:33 75264 e15f35169eb569625f79d4208a667fad c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 22:33 75264 3c2a848256cf5b73dc92314436ea2566 c:\windows\system32\spoolsv.exe
2008-04-14 22:33 43520 2df22736f15d6acfb7a5581f0fe2792b c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 22:33 43520 46e0a9c8fdb6b9b5036274730012214a c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-04_11.20.40.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2009-02-04 16:09:14 4,395,008 —-a-w c:\windows\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2009-02-04 16:09:14 16,384 —-a-w c:\windows\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-08-07 14:27:04 184,320 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-02-04 16:07:16 495,616 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2009-02-04 16:07:16 16,384 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
+ 2008-10-16 13:06:48 268,648 ——w c:\windows\SoftwareDistribution\SelfUpdate\Registered\mucltui.dll
+ 2009-01-14 03:37:08 96,256 —-a-w c:\windows\system32\_ati2cqa.dll
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-04 17:09:24 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 10:19:41 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 17:09:24 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\index.dat
+ 2009-02-04 15:38:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Geschiedenis\History.IE5\MSHist012009020420090205\index.dat
- 2009-02-04 10:19:41 49,152 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-04 17:09:24 81,920 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 32768]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"services"="c:\windows\services.exe" [BU]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reader_s"="c:\windows\System32\reader_s.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 32768]
"reader_s"="c:\documents and settings\Michal\reader_s.exe" [BU]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"zzjwlrxf.exe"="c:\windows\zzjwlrxf.exe" [2009-02-04 3584]
"phnyztsb.exe"="c:\windows\phnyztsb.exe" [2009-02-04 3584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5gkxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ixgituaw.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msuebwpx.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 ati5gkxx;ati5gkxx;c:\windows\system32\drivers\ati5gkxx.sys [2009-02-04 32768]
R0 ixgituaw;ixgituaw;c:\windows\system32\drivers\ixgituaw.sys [2009-02-04 33920]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S3 xgbuvhxe;xgbuvhxe;\??\c:\windows\System32\Drivers\xgbuvhxe.sys –> c:\windows\System32\Drivers\xgbuvhxe.sys [?]
NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
Tapisrv
Themes
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN
wscsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
- - - - ORPHANS VERWIJDERD - - - -
HKU-Default-Run-vybxbhuw.exe - c:\windows\vybxbhuw.exe
HKU-Default-Run-fprhtqqp.exe - c:\windows\fprhtqqp.exe
HKU-Default-Run-fprauipn.exe - c:\windows\fprauipn.exe
HKU-Default-Run-tjbewwgs.exe - c:\windows\tjbewwgs.exe
HKU-Default-Run-jrfusein.exe - c:\windows\jrfusein.exe
HKU-Default-Run-zzjsircn.exe - c:\windows\zzjsircn.exe
HKU-Default-Run-fpramqnr.exe - c:\windows\fpramqnr.exe
HKU-Default-Run-fprwkiqd.exe - c:\windows\fprwkiqd.exe
HKU-Default-Run-dbxqrwli.exe - c:\windows\dbxqrwli.exe
HKU-Default-Run-phnkbxxc.exe - c:\windows\phnkbxxc.exe
HKU-Default-Run-tjbsuqpo.exe - c:\windows\tjbsuqpo.exe
HKU-Default-Run-fprdwtwe.exe - c:\windows\fprdwtwe.exe
HKU-Default-Run-rvhiuvju.exe - c:\windows\rvhiuvju.exe
HKU-Default-Run-fprwkcer.exe - c:\windows\fprwkcer.exe
HKU-Default-Run-rvhirvff.exe - c:\windows\rvhirvff.exe
HKU-Default-Run-vxvnwpoh.exe - c:\windows\vxvnwpoh.exe
HKU-Default-Run-rvhiumba.exe - c:\windows\rvhiumba.exe
HKU-Default-Run-rvhylfje.exe - c:\windows\rvhylfje.exe
HKU-Default-Run-dbxqhkbt.exe - c:\windows\dbxqhkbt.exe
HKU-Default-Run-zzjwblzz.exe - c:\windows\zzjwblzz.exe
HKU-Default-Run-phnyzelk.exe - c:\windows\phnyzelk.exe
HKU-Default-Run-hdaqkrmv.exe - c:\windows\hdaqkrmv.exe
HKU-Default-Run-fprewolo.exe - c:\windows\fprewolo.exe
HKU-Default-Run-fprampto.exe - c:\windows\fprampto.exe
HKU-Default-Run-tjbvjeef.exe - c:\windows\tjbvjeef.exe
HKU-Default-Run-xlpxczxp.exe - c:\windows\xlpxczxp.exe
HKU-Default-Run-phnfxuet.exe - c:\windows\phnfxuet.exe
HKU-Default-Run-phnkbuqy.exe - c:\windows\phnkbuqy.exe
HKU-Default-Run-phnfvrcj.exe - c:\windows\phnfvrcj.exe
HKU-Default-Run-xlhnjslk.exe - c:\windows\xlhnjslk.exe
HKU-Default-Run-tjbeolwa.exe - c:\windows\tjbeolwa.exe
HKU-Default-Run-phnuwefu.exe - c:\windows\phnuwefu.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
——- Bijkomende Scan ——-
.
FF - ProfilePath - c:\documents and settings\Michal\Application Data\Mozilla\Firefox\Profiles\znsybfek.default\
FF - prefs.js: browser.startup.homepage - www.startpagina.nl
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-04 18:09:51
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scannen van verborgen processen …
scannen van verborgen autostart items …
scannen van verborgen bestanden …
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
——————— DLLs Geladen Onder Lopende Processen ———————
- - - - - - - > 'winlogon.exe'(456)
c:\windows\system32\Ati2evxx.dll
.
———————— Andere Aktieve Processen ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
.
**************************************************************************
.
Voltooingstijd: 2009-02-04 18:10:46 - machine werd herstart [Michal]
ComboFix-quarantined-files.txt 2009-02-04 17:10:44
ComboFix2.txt 2009-02-04 10:21:13
ComboFix3.txt 2009-02-03 23:54:07
Pre-Run: 46,872,158,208 bytes beschikbaar
Post-Run: 46,865,780,736 bytes beschikbaar
516 — E O F — 2009-02-04 00:36:01