Here's the log
ComboFix 08-07-21.2 - Jeroen 2008-07-24 1:03:46.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.28 [GMT 2:00]
Gestart vanuit: C:\Documents and Settings\Jeroen\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jeroen\Bureaublad\CFScript.txt
* Nieuw herstelpunt werd aangemaakt
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM2f3386f4.xml
C:\WINDOWS\system32\ajiswtbg.ini
C:\WINDOWS\system32\avhyvcsp.ini
C:\WINDOWS\system32\bqpkspyy.ini
C:\WINDOWS\system32\canqgssa.ini
C:\WINDOWS\system32\ctxvouox.ini
C:\WINDOWS\system32\dbemxqeq.exe
C:\WINDOWS\system32\emlgwunl.ini
C:\WINDOWS\system32\flerfjhr.ini
C:\WINDOWS\system32\grfwcsra.ini
C:\WINDOWS\system32\kdvnlbwb.ini
C:\WINDOWS\system32\lsexccss.ini
C:\WINDOWS\system32\mhngmlml.ini
C:\WINDOWS\system32\orgeirkr.ini
C:\WINDOWS\system32\oyrgrspw.ini
C:\WINDOWS\system32\ppnst.dll
C:\WINDOWS\system32\qkqbttdr.ini
C:\WINDOWS\system32\qvvccavn.ini
C:\WINDOWS\system32\svheekgr.ini
C:\WINDOWS\system32\tttmlvde.ini
C:\WINDOWS\system32\tyfiytsf.ini
C:\WINDOWS\system32\uacrmgcn.ini
C:\WINDOWS\system32\uiadhlay.ini
C:\WINDOWS\system32\uvmfkrkj.ini
C:\WINDOWS\system32\vunttaad.ini
C:\WINDOWS\system32\wnctbcno.ini
C:\WINDOWS\system32\wwvyoind.ini
C:\WINDOWS\system32\xbpxbaxk.ini
C:\WINDOWS\system32\xhveipbq.ini
C:\WINDOWS\system32\xjlskrop.ini
C:\WINDOWS\system32\xvpgstvn.ini
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))))))
.
2008-07-23 02:36 . 2008-07-23 02:36 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-23 02:35 . 2008-07-23 02:52 <DIR> d-------- C:\SDFix
2008-07-23 01:17 . 2008-07-23 01:17 <DIR> d-------- C:\Deckard
2008-07-22 16:08 . 2008-07-24 01:01 <DIR> dr-h----- C:\Documents and Settings\Jeroen\Onlangs geopend
2008-07-01 01:04 . 2008-07-01 01:04 <DIR> d-------- C:\Program Files\Belarc
2008-07-01 01:04 . 2008-02-27 13:49 3,840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2008-07-01 00:22 . 2008-07-01 00:22 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-01 00:22 . 2008-07-01 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-01 00:21 . 2008-07-01 00:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-01 00:09 . 2008-07-01 00:10 <DIR> d-------- C:\Program Files\CCleaner
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-07-23 12:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-19 11:32 --------- d-----w C:\Program Files\Ruff-Rose
2008-07-15 12:00 --------- d-----w C:\Program Files\Google
2008-07-13 21:35 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-13 20:45 --------- d-----w C:\Program Files\AruaROSE
2008-07-01 08:59 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-30 22:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-31 12:32 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-05-29 10:34 --------- d-----w C:\Documents and Settings\Jeroen\Application Data\AdobeUM
2008-05-26 15:43 --------- d-----w C:\Program Files\PokerStars
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-23_14.09.00.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-03-21 10:30 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.E XE" [2004-08-04 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT \TINTSETP.EXE" [2004-08-04 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TIN TSETP.EXE" [2004-08-04 14:00 455168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-09-12 12:28 70800]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-09-15 13:25 74264]
"PCMService"="c:\Apps\Powercinema\PCMService.e xe" [2005-01-28 11:10 110740]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-08-29 14:17 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-08-29 14:20 77824]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 16:41 57344]
"VTTimer"="VTTimer.exe" [2004-03-26 14:07 49152 C:\WINDOWS\system32\VTTimer.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 15:47 67072 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV53 2AV.SYS [2003-09-16 05:41]
.
Inhoud van de 'Gedeelde Taken' map
"2007-07-03 21:50:11 C:\WINDOWS\Tasks\Herinnering voor registratie 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-07-10 21:50:13 C:\WINDOWS\Tasks\Herinnering voor registratie 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2008-07-18 18:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Mijn computer scannen.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2007-06-27 10:16:37 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NetService - C:\WINDOWS\system32\ppnst.dll
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-24 01:09:04
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\system32\LVComS.exe
.
************************************************** ************************
.
Voltooingstijd: 2008-07-24 1:16:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-23 23:16:28
ComboFix2.txt 2008-07-23 12:10:32
Pre-Run: 62,770,892,800 bytes beschikbaar
Post-Run: 62,705,979,392 bytes beschikbaar
161 --- E O F --- 2008-03-11 21:57:01