xylox
2008-05-12, 00:03
Hi my connection keeps disconnecting, im having problems with, smitfraud, zlob downloader, starware and many others.
Im not really an expert but if anyone can help please do heres a combo fix log:
ComboFix 08-05-09.1 - shade 2008-05-11 22:19:46.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.175 [GMT 2:00]
Running from: C:\Documents and Settings\shade\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\shade\Skrivebord\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\ksol.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-04-30 16:53 . 2008-04-30 16:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-30 00:57 . 2008-04-30 00:57 <DIR> d-------- C:\Programmer\Fælles filer\Control Panels
2008-04-30 00:42 . 2008-04-30 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-04-29 22:28 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-04-29 22:28 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-04-29 21:40 . 2008-04-29 21:40 <DIR> d-------- C:\Programmer\Bonjour
2008-04-29 21:03 . 2008-04-29 21:03 <DIR> d-------- C:\Programmer\Fælles filer\Macrovision Shared
2008-04-28 01:51 . 2008-04-28 01:51 <DIR> d-------- C:\Programmer\MSXML 6.0
2008-04-28 01:51 . 2008-04-28 01:51 <DIR> d-------- C:\Programmer\Microsoft Silverlight
2008-04-28 01:51 . 2008-04-28 01:51 3,252 --a------ C:\WINDOWS\SECB3.PNF
2008-04-28 01:46 . 2008-04-28 01:46 3,068 --a------ C:\WINDOWS\SEC75.PNF
2008-04-28 01:42 . 2008-04-28 01:44 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-04-26 21:17 . 2008-04-26 21:17 <DIR> d-------- C:\Programmer\DAEMON Tools Lite
2008-04-26 18:25 . 2008-04-26 18:25 <DIR> d-------- C:\Documents and Settings\shade\Application Data\DAEMON Tools
2008-04-26 18:25 . 2008-04-26 18:25 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-23 20:26 . 2008-04-23 20:26 <DIR> d-------- C:\Documents and Settings\shade\.thumbnails
2008-04-20 20:05 . 2008-04-20 20:05 <DIR> d-------- C:\Documents and Settings\shade\Application Data\TrueCrypt
2008-04-14 18:30 . 2008-04-14 18:30 <DIR> d-------- C:\unisecur
2008-04-13 23:44 . 2008-04-13 23:44 <DIR> d-------- C:\Documents and Settings\shade\Application Data\Wireshark
2008-04-13 21:39 . 2008-04-13 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 17:15 --------- d-----w C:\Programmer\Steam
2008-05-07 19:22 --------- d-----w C:\Documents and Settings\shade\Application Data\Warez
2008-05-06 06:40 --------- d-----w C:\Programmer\Windows Live Toolbar
2008-04-29 23:13 --------- d-----w C:\Programmer\Fælles filer\Adobe
2008-04-29 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-21 14:45 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-04-21 14:45 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-04-21 14:45 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-04-08 18:08 --------- d-----w C:\Programmer\Windows Live
2008-04-08 10:15 --------- d-----w C:\Programmer\MediaEntertainmentCodec
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-19 23:02 --------- d-----w C:\Documents and Settings\shade\Application Data\Apple Computer
2008-03-19 23:00 --------- d-----w C:\Programmer\QuickTime
2008-03-19 22:57 --------- d-----w C:\Programmer\Fælles filer\Apple
2008-03-01 16:28 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:54 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:54 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:37 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:37 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:37 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 22:23 30,615 ----a-w C:\Documents and Settings\shade\x.exe
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}]
C:\Programmer\RXToolBar\sfcont.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 05:00 15360]
"Steam"="C:\Programmer\Steam\Steam.exe" [2007-01-09 09:58 1269760]
"msnmsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-02 22:05 68856]
"DAEMON Tools Lite"="C:\Programmer\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-07 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-07 19:32 126976]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43 688218]
"PCMService"="C:\Programmer\Arcade\PCMService.exe" [2005-03-09 18:59 49152]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-27 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00 455168]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 18:04 188416]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-24 09:13 2880512]
"LManager"="C:\Programmer\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:20 319488]
"eRecoveryService"="C:\Windows\System32\Check.exe" [2005-03-23 10:01 245760]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03 36975]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"Acrobat Assistant 8.0"="D:\mastersuite collections\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\FÆLLES~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 05:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmer\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\shade\\Dokumenter\\BitTorrent\\bittorrent.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-03-24 16:54]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R3 int15.sys;int15.sys;C:\Programmer\acer\eRecovery\int15.sys [2005-01-13 14:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00900934-072e-11dd-b372-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{151532fa-dc81-11dc-b31f-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{151532fc-dc81-11dc-b31f-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a5a17ca-dc12-11dc-b31e-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1aa18de6-a033-11dc-b2c3-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2833e114-c1cc-11dc-b303-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a33900-dc05-11dc-b31d-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{393fe432-e25f-11dc-b327-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bc28e78-c608-11dc-b304-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faeb05ac-dbfd-11dc-b31b-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faeb05ae-dbfd-11dc-b31b-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-07 18:02:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-11 22:23:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
Completion time: 2008-05-11 22:28:06
ComboFix-quarantined-files.txt 2008-05-11 20:27:01
ComboFix2.txt 2008-05-11 17:22:34
Pre-Run: 4,871,499,776 byte ledig
Post-Run: 4,872,593,408 byte ledig
161 --- E O F --- 2008-05-06 06:39:47€
Im not really an expert but if anyone can help please do heres a combo fix log:
ComboFix 08-05-09.1 - shade 2008-05-11 22:19:46.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.175 [GMT 2:00]
Running from: C:\Documents and Settings\shade\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\shade\Skrivebord\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\ksol.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-04-30 16:53 . 2008-04-30 16:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-30 00:57 . 2008-04-30 00:57 <DIR> d-------- C:\Programmer\Fælles filer\Control Panels
2008-04-30 00:42 . 2008-04-30 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-04-29 22:28 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-04-29 22:28 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-04-29 21:40 . 2008-04-29 21:40 <DIR> d-------- C:\Programmer\Bonjour
2008-04-29 21:03 . 2008-04-29 21:03 <DIR> d-------- C:\Programmer\Fælles filer\Macrovision Shared
2008-04-28 01:51 . 2008-04-28 01:51 <DIR> d-------- C:\Programmer\MSXML 6.0
2008-04-28 01:51 . 2008-04-28 01:51 <DIR> d-------- C:\Programmer\Microsoft Silverlight
2008-04-28 01:51 . 2008-04-28 01:51 3,252 --a------ C:\WINDOWS\SECB3.PNF
2008-04-28 01:46 . 2008-04-28 01:46 3,068 --a------ C:\WINDOWS\SEC75.PNF
2008-04-28 01:42 . 2008-04-28 01:44 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-04-26 21:17 . 2008-04-26 21:17 <DIR> d-------- C:\Programmer\DAEMON Tools Lite
2008-04-26 18:25 . 2008-04-26 18:25 <DIR> d-------- C:\Documents and Settings\shade\Application Data\DAEMON Tools
2008-04-26 18:25 . 2008-04-26 18:25 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-23 20:26 . 2008-04-23 20:26 <DIR> d-------- C:\Documents and Settings\shade\.thumbnails
2008-04-20 20:05 . 2008-04-20 20:05 <DIR> d-------- C:\Documents and Settings\shade\Application Data\TrueCrypt
2008-04-14 18:30 . 2008-04-14 18:30 <DIR> d-------- C:\unisecur
2008-04-13 23:44 . 2008-04-13 23:44 <DIR> d-------- C:\Documents and Settings\shade\Application Data\Wireshark
2008-04-13 21:39 . 2008-04-13 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 17:15 --------- d-----w C:\Programmer\Steam
2008-05-07 19:22 --------- d-----w C:\Documents and Settings\shade\Application Data\Warez
2008-05-06 06:40 --------- d-----w C:\Programmer\Windows Live Toolbar
2008-04-29 23:13 --------- d-----w C:\Programmer\Fælles filer\Adobe
2008-04-29 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-21 14:45 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-04-21 14:45 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-04-21 14:45 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-04-08 18:08 --------- d-----w C:\Programmer\Windows Live
2008-04-08 10:15 --------- d-----w C:\Programmer\MediaEntertainmentCodec
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-19 23:02 --------- d-----w C:\Documents and Settings\shade\Application Data\Apple Computer
2008-03-19 23:00 --------- d-----w C:\Programmer\QuickTime
2008-03-19 22:57 --------- d-----w C:\Programmer\Fælles filer\Apple
2008-03-01 16:28 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:54 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:54 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:37 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:37 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:37 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 22:23 30,615 ----a-w C:\Documents and Settings\shade\x.exe
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}]
C:\Programmer\RXToolBar\sfcont.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 05:00 15360]
"Steam"="C:\Programmer\Steam\Steam.exe" [2007-01-09 09:58 1269760]
"msnmsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-02 22:05 68856]
"DAEMON Tools Lite"="C:\Programmer\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-07 19:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-07 19:32 126976]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44 98394]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43 688218]
"PCMService"="C:\Programmer\Arcade\PCMService.exe" [2005-03-09 18:59 49152]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-27 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00 455168]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 18:04 188416]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-24 09:13 2880512]
"LManager"="C:\Programmer\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:20 319488]
"eRecoveryService"="C:\Windows\System32\Check.exe" [2005-03-23 10:01 245760]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03 36975]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"Acrobat Assistant 8.0"="D:\mastersuite collections\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\FÆLLES~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 05:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmer\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\shade\\Dokumenter\\BitTorrent\\bittorrent.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-03-24 16:54]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R3 int15.sys;int15.sys;C:\Programmer\acer\eRecovery\int15.sys [2005-01-13 14:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00900934-072e-11dd-b372-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{151532fa-dc81-11dc-b31f-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{151532fc-dc81-11dc-b31f-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a5a17ca-dc12-11dc-b31e-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1aa18de6-a033-11dc-b2c3-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2833e114-c1cc-11dc-b303-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a33900-dc05-11dc-b31d-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{393fe432-e25f-11dc-b327-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bc28e78-c608-11dc-b304-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faeb05ac-dbfd-11dc-b31b-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faeb05ae-dbfd-11dc-b31b-00c09fc4c12c}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-07 18:02:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-11 22:23:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
Completion time: 2008-05-11 22:28:06
ComboFix-quarantined-files.txt 2008-05-11 20:27:01
ComboFix2.txt 2008-05-11 17:22:34
Pre-Run: 4,871,499,776 byte ledig
Post-Run: 4,872,593,408 byte ledig
161 --- E O F --- 2008-05-06 06:39:47€