Hi,
hereby the following logfile:
- ComboFix
- Kaspersky
- HaijackThis
ComboFix 08-01-23.1C - Jur 2008-01-27 9:36:09.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.546 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\Jur\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jur\Bureaublad\CFScript.txt
* Nieuw herstelpunt werd aangemaakt
WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
FILE
C:\WINDOWS\system32\vtstt.exe
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\vtstt.exe
.
(((((((((((((((((((( Bestanden Gemaakt van 2007-12-27 to 2008-01-27 ))))))))))))))))))))))))))))))
.
2008-01-25 10:10 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 23:32 . 2008-01-25 11:28 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-24 23:31 . 2008-01-24 23:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-23 23:07 . 2008-01-25 11:29 <DIR> d-------- C:\Program Files\Shareaza
2008-01-23 22:14 . 2008-01-23 22:14 145 --a------ C:\WINDOWS\system32\winver.bat
2007-12-30 17:45 . 2007-12-30 17:45 193 --a------ C:\WINDOWS\hppsapp.INI
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 09:04 561,152 ----a-w C:\WINDOWS\system32\LVCOMSX.EXE
2008-01-23 19:01 --------- d-----w C:\Program Files\Trojan Remover
2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2006-11-07 21:24 463 ----a-w C:\Program Files\CONFIG.DAT
2005-05-11 21:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2002-01-04 15:16 3,306,069 ----a-w C:\Program Files\cap2.exe
2001-11-15 14:07 66 ----a-w C:\Program Files\cap2home.url
.
Code:
<pre>
----a-w 45,056 2008-01-24 10:55:50 C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-26_20.34.57.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 19:25:59 679,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-27 08:35:46 679,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-26 19:25:59 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-27 08:35:46 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-26 19:25:59 679,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-27 08:35:46 679,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-26 19:25:59 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-27 08:35:46 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-26 19:25:59 6,221,824 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-27 08:35:47 6,221,824 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-26 19:26:00 122,880 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-27 08:35:47 122,880 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-26 08:15:29 65,034 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-27 08:19:56 65,034 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-26 08:15:29 84,342 ----a-w C:\WINDOWS\system32\perfc013.dat
+ 2008-01-27 08:19:56 84,342 ----a-w C:\WINDOWS\system32\perfc013.dat
- 2008-01-26 08:15:29 407,078 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-27 08:19:56 407,078 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-26 08:15:29 472,104 ----a-w C:\WINDOWS\system32\perfh013.dat
+ 2008-01-27 08:19:56 472,104 ----a-w C:\WINDOWS\system32\perfh013.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\JPEG]
@={40DAD1B9-DDCF-4A31-A5D3-A03BC8881370}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"InternetCalls"="C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2008-01-24 10:03 415232]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 12:34 544768 C:\WINDOWS\sm56hlpr.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2008-01-24 10:03 385536]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-01-24 10:03 1115136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2008-01-24 10:03 418304]
"RTHDCPL"="RTHDCPL.EXE" []
"Comodo Firewall"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-02-07 09:03 1115728]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2008-01-24 10:03 1255936]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2008-01-24 10:04 827904]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2008-01-24 10:04 561152]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2008-01-24 10:04 822272]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2008-01-24 10:04 557056]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-01-24 10:04 495104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 11:19 219136]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2006-02-27 15:00]
R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys [2006-02-20 16:01]
R0 SiSRaid2;SiSRaid2;C:\WINDOWS\system32\drivers\SiSRaid2.sys [2005-01-11 16:58]
R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys [2005-04-08 10:43]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2325a216-9b69-11dc-833e-00c0a8be5a87}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-27 09:40:05
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
Voltooingstijd: 2008-01-27 9:40:31
ComboFix-quarantined-files.txt 2008-01-27 08:40:29
ComboFix2.txt 2008-01-26 19:35:12
.
2007-12-14 08:58:10 --- E O F ---
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, January 29, 2008 4:38:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/01/2008
Kaspersky Anti-Virus database records: 535777
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 86671
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:09:24
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\Jur\Application Data\Microsoft\Sjablonen\Normal.dot Object is locked skipped
C:\Documents and Settings\Jur\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Jur\Bureaublad\Steam advise 2.doc Object is locked skipped
C:\Documents and Settings\Jur\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Geschiedenis\History.IE5\MSHist012008012920080130\index.dat Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temp\~DF123.tmp Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temp\~DF37C5.tmp Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temp\~DF504E.tmp Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temp\~DFD1C5.tmp Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temp\~WRF0000.tmp Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Jur\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jur\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jur\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe Object is locked skipped
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Object is locked skipped
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000348.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000349.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000350.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000351.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000352.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000353.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000354.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000355.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000356.exe Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\A0000357.EXE Object is locked skipped
C:\System Volume Information\_restore{28D617AA-B4F3-4060-9BC2-85D787C0CC48}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.