Page 1 of 2 12 LastLast
Results 1 to 10 of 18

Thread: Smitfraud-C.CoreService

  1. #1
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Smitfraud-C.CoreService

    Since a few days I have a problem with my PC.

    Spybot detects Smitfraud-C.CoreService and can not delete this.

    I created a HJT log file and a Kaspersky report. Please help me, I am out of idea's how to solve this problem.

    Thanks in advance,
    Andre
    PS the kaspersky report is not included (to less space)

    HJT log file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:15:03, on 16-2-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
    C:\Program Files\UltraMon\UltraMon.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
    C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
    C:\Program Files\UltraMon\UltraMonTaskbar.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\PROGRA~1\MICROS~3\rapimgr.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O1 - Hosts: HP0017A47BC3AB
    O1 - Hosts: HP0017A47BC3AB HP0017A47BC3AB
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
    O4 - HKLM\..\Run: [TrojanScanner] "C:\Program Files\Trojan Remover\Trjscan.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
    O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
    O4 - Global Startup: HP Photosmart Premier Snelstart.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: &Google Zoeken - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Woord vertalen in het Nederlands - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Verbindingshelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Verbindingshelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V020...5031/CTPID.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

    --
    End of file - 13325 bytes

  2. #2
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Kaspersky report

    Scan Statistics:
    Total number of scanned objects: 285993
    Number of viruses found: 13
    Number of infected objects: 41
    Number of suspicious objects: 0
    Duration of the scan process: 03:55:24

    Infected Object Name / Virus Name / Last Action
    C:\1b9be945d94d2d93c5df095f\%temp%dd_msxml_retMSI.txt Object is locked skipped
    C:\95293d6b741f950bd9c02f1d2715\%temp%dd_msxml_retMSI.txt Object is locked skipped
    C:\b55a8713437ddfb7dd8b2954e011\msxml4-KB927978-enu.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Adobe\Catalogusmappen\Mijn catalogus\backupCt.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Adobe\Catalogusmappen\Mijn catalogus\collstatus.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Adobe\Catalogusmappen\Mijn catalogus\tagstatus.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Creative\CADI\Preset\PCI_BUS1102-5-2C1102-DF00.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-16_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30A1656B.exe Infected: Backdoor.Win32.VB.aym skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\468601F6.exe Infected: Backdoor.Win32.Hupigon.evc skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51981C4C.exe Infected: Backdoor.Win32.Rbot.bll skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\4619FC79.TMP Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\652D2A7C.TMP Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Config\desktop2.idf Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Fonts\SwUniNew.tff Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Softwrap\STREAMCASTNE5221016A\Morpheus.sw2 Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Softwrap\STREAMCASTNE884A\Morpheus.sw2 Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\TempSBE\MSDVRMM_1625688142_327680_65371 Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\TempSBE\MSDVRMM_1625688142_393216_65367 Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\TempSBE\SBE1.tmp Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\TempSBE\SBE2.tmp Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\{0B854DB4-D33A-4BD5-95DE-066D9C2FD34D}.TmpSBE Object is locked skipped
    C:\Documents and Settings\All Users\Documenten\Tv-opnamen\TempRec\{C2F3A5C1-D368-4E72-9D4B-20045050F83D}.TmpSBE Object is locked skipped
    C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/service.exe Infected: Backdoor.Win32.Iroffer.1302 skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/system.exe Infected: Backdoor.Win32.ServU-based skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/lsass.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/05 Jul 2007 19:05 to 'Hans'/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/service.exe Infected: Backdoor.Win32.Iroffer.1302 skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/system.exe Infected: Backdoor.Win32.ServU-based skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach/lsass.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe/Attach Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar/Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch/NL_V3.8 Beta_6_setup.exe Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst/Persoonlijke mappen/Verzonden items/08 Jul 2007 13:08 to 'hans.liebrand@gmail.com':FW: /Newsprogje.3.8.NL.Newzleech.Dutch+SuperSearch.rar Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst Mail MS Mail: infected - 12 skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\$_hpcst$.hpc Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\ApplicationHistory\CLI.EXE.c88dbd71.ini.inuse Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Temp\Perflib_Perfdata_adc.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Temp\Perflib_Perfdata_f0c.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Temp\~DFE1B0.tmp Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\HP_Administrator.WOONKAMER\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar/AVG Internet Security 7.5 Professional Edition W Keygen/AVG Internet Security Keygen.exe Infected: Backdoor.Win32.Rbot.gku skipped
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar RAR: infected - 1 skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence)\Spy Sweeper 5.5.7Build103(with 1 year licence)\sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar/Spy Sweeper 5.5.7Build103(with 1 year licence)/sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar RAR: infected - 1 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar/install.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/winmgnt.exe Infected: Backdoor.Win32.ServU-based skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/Servicerun.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe Rsrc-Package: infected - 10 skipped
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080216-122821.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDDBG.log

  3. #3
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default last part kaspersky report

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar/AVG Internet Security 7.5 Professional Edition W Keygen/AVG Internet Security Keygen.exe Infected: Backdoor.Win32.Rbot.gku skipped
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar RAR: infected - 1 skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence)\Spy Sweeper 5.5.7Build103(with 1 year licence)\sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar/Spy Sweeper 5.5.7Build103(with 1 year licence)/sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar RAR: infected - 1 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar/install.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/winmgnt.exe Infected: Backdoor.Win32.ServU-based skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/Servicerun.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe Rsrc-Package: infected - 10 skipped
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080216-122821.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
    C:\Program Files\Creative\ShareDLL\CADI\CTPLang.dat Object is locked skipped
    C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
    C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
    C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
    C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
    C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
    C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
    C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
    C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
    C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
    C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
    C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
    C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
    C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
    C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
    C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
    C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
    C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
    C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
    C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
    C:\Program Files\TC UP\PLUGINS\Tools\FtpPasswordRipper\Windows_Commander_FTP_Password_RIPPER.exe Infected: not-a-virus:PSWTool.Win32.Delf.f skipped
    C:\Program Files\TC UP\PLUGINS\Tools\Revelation\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    C:\Program Files\TC UP\PLUGINS\Tools\Revelation\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114391.exe Infected: Backdoor.Win32.Rbot.gku skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114393.exe/data0000.cab/update.exe Infected: Trojan.Win32.Agent.efb skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114393.exe/data0000.cab Infected: Trojan.Win32.Agent.efb skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114393.exe Rsrc-Package: infected - 2 skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114393.exe UPX: infected - 2 skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP375\A0114393.exe PE_Patch.UPX: infected - 2 skipped
    C:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP380\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\Prefetch\layout.ini Object is locked skipped
    C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{5945DD64-597C-4FD6-8526-E857C7E5B991}.crmlog Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
    C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
    C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
    C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
    C:\WINDOWS\system32\drivers\etc\Hosts.bak Object is locked skipped
    C:\WINDOWS\system32\drivers\rasl2tpp.sys Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\Temp\JET775.tmp Object is locked skipped
    C:\WINDOWS\Temp\JET811.tmp Object is locked skipped
    C:\WINDOWS\Temp\Perflib_Perfdata_6e4.dat Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    D:\System Volume Information\_restore{DFB1D6B4-B48A-447C-9289-6356097299FF}\RP380\change.log Object is locked skipped

    Scan process completed.

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Andre Wevers

    First of all, you should really think what you download:

    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar/AVG Internet Security 7.5 Professional Edition W Keygen/AVG Internet Security Keygen.exe Infected: Backdoor.Win32.Rbot.gku skipped
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar RAR: infected - 1 skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence)\Spy Sweeper 5.5.7Build103(with 1 year licence)\sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar/Spy Sweeper 5.5.7Build103(with 1 year licence)/sspsetup1_1.exe Infected: Trojan-Dropper.Win32.Pakes skipped
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar RAR: infected - 1 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar/install.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe/data.rar Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/home.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/winmgnt.exe Infected: Backdoor.Win32.ServU-based skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar/Servicerun.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe/data.rar Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab/ftp2.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab/crack.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe/data0000.cab Infected: not-a-virus:RiskTool.Win32.HideRun skipped
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED\sdsetup.exe Rsrc-Package: infected - 10 skipped

    Downloading pirated software is not only illegal but can cause some serious malware troubles,

    1. Download combofix from any of these links and save it to Desktop:
    Link 1
    Link 2
    Link 3

    **Note: It is important that it is saved directly to your desktop**

    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    If you have problems with Combofix usage, see here

    Post:

    - a fresh HijackThis log
    - combofix report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Combofix report (1)

    Thanks for helping me!

    Yes, I learned my lesson regarding the downloads!

    Belo the Combofix report (I will also create a new HijackThis report)

    ComboFix 08-02-21 - HP_Administrator 2008-02-21 11:13:46.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.1364 [GMT 1:00]
    Gestart vanuit: C:\temp\ComboFix.exe
    * Nieuw herstelpunt werd aangemaakt
    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\HP_Administrator\Application Data\inst.exe
    C:\temp\tn3
    C:\WINDOWS\bhookpl.dll
    D:\Autorun.inf
    C:\WINDOWS\system32\drivers\core.cache.dsk . . . . konden niet verwijderd worden

    .
    (((((((((((((((((((( Bestanden Gemaakt van 2008-01-21 to 2008-02-21 ))))))))))))))))))))))))))))))
    .

    2008-02-21 11:18 . 2008-02-21 11:18 <DIR> d-------- C:\temp\tn3
    2008-02-21 11:11 . 2008-02-21 11:11 1,598,301 --a------ C:\temp\ComboFix.exe
    2008-02-17 11:28 . 2008-02-17 11:28 4,340 --a------ C:\WINDOWS\system32\tmp.reg
    2008-02-17 08:38 . 2008-02-17 09:28 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-02-17 08:38 . 2008-02-17 08:38 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\SUPERAntiSpyware.com
    2008-02-17 08:38 . 2008-02-17 08:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-02-16 21:14 . 2008-02-16 21:14 <DIR> d-------- C:\Program Files\Trend Micro
    2008-02-16 21:06 . 2008-02-21 11:17 83,666 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk
    2008-02-16 15:36 . 2008-02-16 15:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
    2008-02-16 13:11 . 2008-02-16 13:11 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-02-16 13:11 . 2008-02-16 13:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-02-16 12:55 . 2008-02-16 12:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-02-16 12:17 . 2008-02-16 12:17 <DIR> d-------- C:\Documents and Settings\Administrator\Bureaublad
    2008-02-16 11:10 . 2008-02-16 11:10 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Simply Super Software
    2008-02-16 11:10 . 2008-02-16 11:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
    2008-02-16 10:56 . 2008-02-17 08:20 <DIR> d-------- C:\Program Files\Trojan Remover
    2008-02-16 10:56 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
    2008-02-16 10:56 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
    2008-02-16 10:56 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
    2008-02-16 10:56 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
    2008-02-16 10:56 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
    2008-02-16 10:04 . 2008-02-16 10:04 164 --a------ C:\install.dat
    2008-02-16 08:59 . 2008-02-16 08:59 100 --a------ C:\WINDOWS\system32\ikhcore.cfg
    2008-02-16 08:19 . 2008-02-16 19:46 <DIR> d-------- C:\virus
    2008-02-15 17:33 . 2008-02-15 17:36 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Registry Booster
    2008-02-15 11:07 . 2008-02-15 11:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-02-15 11:07 . 2008-02-15 11:07 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-02-15 11:04 . 2008-02-15 12:30 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
    2008-02-13 21:47 . 2008-02-13 21:47 <DIR> d-------- C:\Program Files\Belastingdienst
    2008-02-13 12:08 . 2008-02-13 12:09 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-02-12 21:31 . 2008-02-12 23:07 <DIR> d-------- C:\Program Files\XoftSpySE
    2008-02-11 20:08 . 2008-02-11 20:08 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Systweak
    2008-02-11 17:59 . 2008-02-11 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
    2008-02-11 17:53 . 2008-02-11 17:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-02-11 17:10 . 2008-02-11 17:10 86,144 --a------ C:\WINDOWS\system32\drivers\rasl2tpp.sys
    2008-02-10 15:34 . 2008-02-10 15:42 <DIR> d-------- C:\Program Files\Super Internet TV
    2008-02-10 15:13 . 2008-02-10 15:13 <DIR> d--h----- C:\Documents and Settings\HP_Administrator.WOONKAMER\Sjablonen
    2008-02-10 15:13 . 2008-02-10 15:13 <DIR> d--h----- C:\Documents and Settings\HP_Administrator.WOONKAMER\Netwerkprinteromgeving
    2008-02-10 12:44 . 2008-02-10 12:44 <DIR> d-------- C:\Program Files\Diskeeper Corporation
    2008-02-10 12:01 . 2008-02-10 12:02 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
    2008-02-10 12:01 . 2008-02-10 12:01 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\TuneUp Software
    2008-02-10 12:01 . 2008-02-10 12:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2008-02-10 12:01 . 2008-02-10 12:01 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-02-10 12:01 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-02-03 20:02 . 2008-02-03 20:02 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\XemiComputers
    2008-02-03 20:02 . 2008-02-03 20:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\XemiComputers
    2008-02-03 19:48 . 2008-02-03 19:48 <DIR> d-------- C:\Program Files\Osirius
    2008-01-30 20:22 . 2008-01-30 20:22 <DIR> d-------- C:\Program Files\Easy Computing
    2008-01-28 20:41 . 2008-01-28 20:41 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Sonic
    2008-01-28 20:41 . 2008-01-28 20:41 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Leadertech
    2008-01-28 20:12 . 2008-01-28 20:12 <DIR> d-------- C:\Program Files\Dr.Hardware 2008 english
    2008-01-28 20:12 . 2005-12-01 10:49 23,600 --a------ C:\WINDOWS\system32\drivers\drhard.sys
    2008-01-28 20:12 . 2005-12-01 14:38 20,651 --a------ C:\WINDOWS\system32\drivers\DRHARD.VXD
    2008-01-28 20:12 . 2005-12-01 14:38 20,651 --a------ C:\WINDOWS\system32\DRHARD.VXD
    2008-01-26 17:02 . 2008-01-26 17:03 <DIR> d-------- C:\Program Files\Mijn kat en ik
    2008-01-26 16:48 . 2008-01-26 17:03 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\cerasus.media
    2008-01-26 16:47 . 2008-01-26 16:48 <DIR> d-------- C:\Program Files\Mijn hond en ik
    2008-01-26 16:05 . 2008-01-26 16:05 <DIR> d-------- C:\Program Files\Groep 3 en 4
    2008-01-26 15:25 . 2008-01-26 15:25 85 --a------ C:\WINDOWS\ClonyDrives.ini
    2008-01-26 14:50 . 2008-01-26 14:50 <DIR> d-------- C:\bin
    2008-01-26 14:48 . 2008-01-26 14:49 <DIR> d-------- C:\Program Files\Common Files\HP
    2008-01-26 14:44 . 2008-01-26 14:45 819 --a------ C:\WINDOWS\hpntwksetup.ini
    2008-01-26 14:41 . 2008-01-26 15:02 119,636 --a------ C:\WINDOWS\hpoins11.dat
    2008-01-26 14:38 . 2006-05-05 22:20 11,634 --a------ C:\WINDOWS\hpomdl11.dat

    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-21 10:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-02-17 07:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-02-16 19:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-02-16 14:40 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\uTorrent
    2008-02-16 14:37 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-02-16 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-02-11 17:05 --------- d-----w C:\Program Files\Windows Sidebar
    2008-02-11 16:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-02-11 16:53 --------- d-----w C:\Program Files\Lavasoft
    2008-02-10 18:27 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\GrabIt
    2008-01-27 09:38 --------- d-----w C:\Program Files\MediaMonkey
    2008-01-26 15:50 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\cerasus.media
    2008-01-26 15:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-26 13:50 --------- d-----w C:\Program Files\Common Files\Sonic Shared
    2008-01-26 13:46 --------- d-----w C:\Program Files\HP
    2008-01-24 18:32 --------- d-----w C:\Program Files\P2000 Kaart
    2008-01-15 08:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-01-15 04:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-01-12 17:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-01-12 10:13 --------- d-----w C:\Program Files\Microsoft Office Outlook Connector
    2008-01-12 10:12 --------- d-----w C:\Program Files\MSECache
    2008-01-11 16:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Barbie Modeshow
    2008-01-11 15:46 --------- d-----w C:\Program Files\DigiKidz
    2008-01-07 21:40 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DAEMON Tools Pro
    2008-01-07 20:36 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DAEMON Tools
    2008-01-07 20:25 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
    2008-01-06 18:26 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Creative
    2008-01-06 10:29 --------- d-----w C:\Program Files\DivX
    2008-01-06 10:10 --------- d-----w C:\Program Files\GrabIt
    2008-01-05 17:56 --------- d-----w C:\Program Files\Picasa2
    2008-01-04 18:28 --------- d-----w C:\Program Files\DVD Decrypter
    2008-01-04 09:55 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Sync App Settings
    2007-12-24 08:44 --------- d--h--w C:\Program Files\Creative Installation Information
    2007-12-24 06:19 --------- d-----w C:\Program Files\Backup&Synchronize
    2007-12-23 20:34 --------- d-----w C:\Program Files\Yamicsoft
    2007-12-23 19:46 --------- d-----w C:\Program Files\Allway Sync
    2007-12-23 19:41 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\HP
    2007-12-23 17:51 --------- d-----w C:\Program Files\FTDv3.8
    2007-12-23 14:28 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Symantec
    2007-12-23 14:21 --------- d-----w C:\Program Files\Norton 360
    2007-12-23 13:49 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Lavasoft
    2007-12-23 13:20 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\LaCie
    2007-12-23 12:08 --------- d-----w C:\Program Files\Your Uninstaller 2006
    2007-12-23 12:08 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\URSoft
    2007-12-23 10:25 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DivX
    2007-12-23 09:30 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\VanDale
    2007-12-23 08:16 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\HPQ
    2007-12-23 07:51 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Realtime Soft
    2007-12-23 07:50 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\ATI
    2007-12-22 16:31 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\SiteAdvisor
    2007-12-21 19:35 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\uTorrent
    2007-11-25 11:08 487 ----a-w C:\Documents and Settings\HP_Administrator\CR-DX8MP.reg
    2007-11-04 17:55 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
    2007-02-15 11:32 7,089,294 ----a-w C:\Program Files\PCI_Install_5663(installshield 12_1.06)_20070215.rar
    2007-02-15 11:31 3,640,770 ----a-w C:\Program Files\PCI_Install_5663(installshield 12_1.06)_20070214.rar
    2007-02-13 20:48 975 ----a-w C:\Program Files\setup.ini
    2007-02-13 20:48 473 ----a-w C:\Program Files\layout.bin
    2007-02-13 20:48 36,486 ----a-w C:\Program Files\data1.hdr
    2007-02-13 20:48 3,327,097 ----a-w C:\Program Files\data1.cab
    2007-02-13 20:48 223,478 ----a-w C:\Program Files\setup.inx
    2007-02-13 20:48 112,544 ----a-w C:\Program Files\data2.cab
    2007-01-20 01:46 455,600 ----a-w C:\Program Files\setup.exe
    2007-01-20 01:43 492,032 ----a-w C:\Program Files\ISSetup.dll
    2006-12-13 18:28 852 ----a-w C:\Program Files\setup.iss
    2006-10-12 19:56 53,320 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
    2006-05-17 22:21 373,680 ----a-w C:\Program Files\_setup.dll
    2006-05-17 01:44 64,392 ----a-w C:\Program Files\setup.isn
    2006-04-16 13:27 0 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
    2006-04-16 19:22 64 --sha-r C:\WINDOWS\6EE73A0C9CC02D24.bin
    2006-11-04 01:13 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .

  6. #6
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Combofix report (2)

    REGEDIT4
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-02 13:00 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 15:52 68856]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-27 18:25 1211176]
    "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 11:29 220544]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 22:53 204288]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-18 05:40 64512]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
    "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 22:14 237568]
    "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-05-16 16:58 213936]
    "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]
    "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44 61440]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 10:12 90112]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-20 11:38 98304]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
    "RCSystem"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 17:07 49152]
    "CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 00:00 45056]
    "VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-28 08:56 122880]
    "CTHelper"="CTHELPER.EXE" [2006-08-17 04:32 17920 C:\WINDOWS\CTHELPER.EXE]
    "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]
    "UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" [2007-04-01 06:47 299520]
    "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 16:58 213936]
    "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-11-25 13:33 735824]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe" [2007-09-12 18:27 492912]

    C:\Documents and Settings\HP_Administrator.WOONKAMER\Menu Start\Programma's\Opstarten\
    Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 00:14:44 27136]

    C:\Documents and Settings\HP_Administrator\Menu Start\Programma's\Opstarten\
    OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

    C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
    HP Photosmart Premier Snelstart.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    R1 rasl2tpp;rasl2tpp;C:\WINDOWS\system32\drivers\rasl2tpp.sys [2008-02-11 17:10]
    R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 13:00]
    R2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2006-09-24 21:22]
    R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 21:57]
    R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-08-17 04:16]
    R3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys [2006-09-24 21:23]
    S3 drhard;DRHARD;C:\WINDOWS\system32\DRIVERS\DRHARD.SYS [2005-12-01 10:49]
    S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 18:44]
    S3 WN5401;Liteon Wireless LAN PCI 802.11 a/b/g adapter WN5401A;C:\WINDOWS\system32\DRIVERS\wn5401.sys [2005-01-07 01:08]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bb11dae-d253-11dc-8973-0013d3fa2457}]
    \Shell\AutoRun\command - F:\WD_Windows_Tools\setup.exe

    *Newly Created Service* - COMHOST
    .
    Inhoud van de 'Gedeelde Taken' map
    "2008-02-14 12:35:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-02-15 16:18:56 C:\WINDOWS\Tasks\Easy Onderhoud.job"
    - C:\Program Files\TuneUp Utilities 2008\OneClick.exe
    "2008-02-21 10:30:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{2C90D5DA-6FB8-4CA8-A312-D528B005DCA9}.job"
    - C:\WINDOWS\system32\msfeedssync.exe
    "2008-02-21 10:17:51 C:\WINDOWS\Tasks\XoftSpySE 2.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    "2008-02-19 05:51:36 C:\WINDOWS\Tasks\XoftSpySE.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-21 11:21:02
    Windows 5.1.2600 Service Pack 2 NTFS

    scannen van verborgen processen ...

    scannen van verborgen autostart items ...

    scannen van verborgen bestanden ...

    Scan succesvol afgerond
    verborgen bestanden: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    .
    **************************************************************************
    .
    Voltooingstijd: 2008-02-21 11:34:01 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-02-21 10:33:58
    .
    2008-02-13 11:11:05 --- E O F ---

  7. #7
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default a fresh hijackThis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:42:24, on 21-2-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
    O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
    O4 - HKLM\..\Run: [TrojanScanner] "C:\Program Files\Trojan Remover\Trjscan.exe"
    O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
    O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
    O4 - Global Startup: HP Photosmart Premier Snelstart.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: &Google Zoeken - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Woord vertalen in het Nederlands - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Mobiele favorieten maken - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Verbindingshelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Verbindingshelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V020...5031/CTPID.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

    --
    End of file - 12262 bytes

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Combofix is running from temp folder, please move it to Desktop next:

    Gestart vanuit: C:\temp\ComboFix.exe

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Driver::
    rasl2tpp
    
    File::
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar
    C:\WINDOWS\system32\drivers\rasl2tpp.sys
    
    Folder::
    C:\Downloads\Spyware Doctor 5.5.0.178 - Final UPDATED
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence)
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Combofix report (part 1)

    ComboFix 08-02-21 - HP_Administrator 2008-02-21 12:04:34.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.1493 [GMT 1:00]
    Gestart vanuit: C:\Documents and Settings\HP_Administrator.WOONKAMER\Bureaublad\ComboFix.exe
    Command switches used :: C:\Documents and Settings\HP_Administrator.WOONKAMER\Bureaublad\CFScript.txt
    * Nieuw herstelpunt werd aangemaakt

    FILE ::
    C:\Downloads\AVG Internet Security 7.5 Professional Edition W Keygen.rar
    C:\Downloads\Spy Sweeper 5.5.7Build103(with 1 year licence).rar
    C:\WINDOWS\system32\drivers\rasl2tpp.sys
    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\temp\tn3
    C:\WINDOWS\system32\drivers\core.cache.dsk
    C:\WINDOWS\system32\drivers\rasl2tpp.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_RASL2TPP
    -------\rasl2tpp


    (((((((((((((((((((( Bestanden Gemaakt van 2008-01-21 to 2008-02-21 ))))))))))))))))))))))))))))))
    .

    2008-02-21 11:11 . 2008-02-21 11:11 1,598,301 --a------ C:\temp\ComboFix.exe
    2008-02-17 11:28 . 2008-02-17 11:28 4,340 --a------ C:\WINDOWS\system32\tmp.reg
    2008-02-17 08:38 . 2008-02-17 09:28 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-02-17 08:38 . 2008-02-17 08:38 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\SUPERAntiSpyware.com
    2008-02-17 08:38 . 2008-02-17 08:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-02-16 21:14 . 2008-02-16 21:14 <DIR> d-------- C:\Program Files\Trend Micro
    2008-02-16 15:36 . 2008-02-16 15:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
    2008-02-16 13:11 . 2008-02-16 13:11 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-02-16 13:11 . 2008-02-16 13:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-02-16 12:55 . 2008-02-16 12:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-02-16 12:17 . 2008-02-16 12:17 <DIR> d-------- C:\Documents and Settings\Administrator\Bureaublad
    2008-02-16 11:10 . 2008-02-16 11:10 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Simply Super Software
    2008-02-16 11:10 . 2008-02-16 11:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
    2008-02-16 10:56 . 2008-02-17 08:20 <DIR> d-------- C:\Program Files\Trojan Remover
    2008-02-16 10:56 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
    2008-02-16 10:56 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
    2008-02-16 10:56 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
    2008-02-16 10:56 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
    2008-02-16 10:56 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
    2008-02-16 10:04 . 2008-02-16 10:04 164 --a------ C:\install.dat
    2008-02-16 08:59 . 2008-02-16 08:59 100 --a------ C:\WINDOWS\system32\ikhcore.cfg
    2008-02-16 08:19 . 2008-02-16 19:46 <DIR> d-------- C:\virus
    2008-02-15 17:33 . 2008-02-15 17:36 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Registry Booster
    2008-02-15 11:07 . 2008-02-15 11:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-02-15 11:07 . 2008-02-15 11:07 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-02-15 11:04 . 2008-02-15 12:30 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
    2008-02-13 21:47 . 2008-02-13 21:47 <DIR> d-------- C:\Program Files\Belastingdienst
    2008-02-13 12:08 . 2008-02-13 12:09 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-02-12 21:31 . 2008-02-12 23:07 <DIR> d-------- C:\Program Files\XoftSpySE
    2008-02-11 20:08 . 2008-02-11 20:08 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Systweak
    2008-02-11 17:59 . 2008-02-11 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
    2008-02-11 17:53 . 2008-02-11 17:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-02-10 15:34 . 2008-02-10 15:42 <DIR> d-------- C:\Program Files\Super Internet TV
    2008-02-10 15:13 . 2008-02-10 15:13 <DIR> d--h----- C:\Documents and Settings\HP_Administrator.WOONKAMER\Sjablonen
    2008-02-10 15:13 . 2008-02-10 15:13 <DIR> d--h----- C:\Documents and Settings\HP_Administrator.WOONKAMER\Netwerkprinteromgeving
    2008-02-10 12:44 . 2008-02-10 12:44 <DIR> d-------- C:\Program Files\Diskeeper Corporation
    2008-02-10 12:01 . 2008-02-10 12:02 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
    2008-02-10 12:01 . 2008-02-10 12:01 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\TuneUp Software
    2008-02-10 12:01 . 2008-02-10 12:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2008-02-10 12:01 . 2008-02-10 12:01 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-02-10 12:01 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-02-03 20:02 . 2008-02-03 20:02 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\XemiComputers
    2008-02-03 20:02 . 2008-02-03 20:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\XemiComputers
    2008-02-03 19:48 . 2008-02-03 19:48 <DIR> d-------- C:\Program Files\Osirius
    2008-01-30 20:22 . 2008-01-30 20:22 <DIR> d-------- C:\Program Files\Easy Computing
    2008-01-28 20:41 . 2008-01-28 20:41 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Sonic
    2008-01-28 20:41 . 2008-01-28 20:41 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Leadertech
    2008-01-28 20:12 . 2008-01-28 20:12 <DIR> d-------- C:\Program Files\Dr.Hardware 2008 english
    2008-01-28 20:12 . 2005-12-01 10:49 23,600 --a------ C:\WINDOWS\system32\drivers\drhard.sys
    2008-01-28 20:12 . 2005-12-01 14:38 20,651 --a------ C:\WINDOWS\system32\drivers\DRHARD.VXD
    2008-01-28 20:12 . 2005-12-01 14:38 20,651 --a------ C:\WINDOWS\system32\DRHARD.VXD
    2008-01-26 17:02 . 2008-01-26 17:03 <DIR> d-------- C:\Program Files\Mijn kat en ik
    2008-01-26 16:48 . 2008-01-26 17:03 <DIR> d-------- C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\cerasus.media
    2008-01-26 16:47 . 2008-01-26 16:48 <DIR> d-------- C:\Program Files\Mijn hond en ik
    2008-01-26 16:05 . 2008-01-26 16:05 <DIR> d-------- C:\Program Files\Groep 3 en 4
    2008-01-26 15:25 . 2008-01-26 15:25 85 --a------ C:\WINDOWS\ClonyDrives.ini
    2008-01-26 14:50 . 2008-01-26 14:50 <DIR> d-------- C:\bin
    2008-01-26 14:48 . 2008-01-26 14:49 <DIR> d-------- C:\Program Files\Common Files\HP
    2008-01-26 14:44 . 2008-01-26 14:45 819 --a------ C:\WINDOWS\hpntwksetup.ini
    2008-01-26 14:41 . 2008-01-26 15:02 119,636 --a------ C:\WINDOWS\hpoins11.dat
    2008-01-26 14:38 . 2006-05-05 22:20 11,634 --a------ C:\WINDOWS\hpomdl11.dat

    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-21 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-02-17 07:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-02-16 19:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-02-16 14:40 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\uTorrent
    2008-02-16 14:37 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-02-16 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-02-11 17:05 --------- d-----w C:\Program Files\Windows Sidebar
    2008-02-11 16:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-02-11 16:53 --------- d-----w C:\Program Files\Lavasoft
    2008-02-10 18:27 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\GrabIt
    2008-01-27 09:38 --------- d-----w C:\Program Files\MediaMonkey
    2008-01-26 15:50 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\cerasus.media
    2008-01-26 15:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-26 13:50 --------- d-----w C:\Program Files\Common Files\Sonic Shared
    2008-01-26 13:46 --------- d-----w C:\Program Files\HP
    2008-01-24 18:32 --------- d-----w C:\Program Files\P2000 Kaart
    2008-01-15 08:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-01-15 04:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-01-12 17:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-01-12 10:13 --------- d-----w C:\Program Files\Microsoft Office Outlook Connector
    2008-01-12 10:12 --------- d-----w C:\Program Files\MSECache
    2008-01-11 16:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Barbie Modeshow
    2008-01-11 15:46 --------- d-----w C:\Program Files\DigiKidz
    2008-01-07 21:40 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DAEMON Tools Pro
    2008-01-07 20:36 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DAEMON Tools
    2008-01-07 20:25 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
    2008-01-06 18:26 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Creative
    2008-01-06 10:29 --------- d-----w C:\Program Files\DivX
    2008-01-06 10:10 --------- d-----w C:\Program Files\GrabIt
    2008-01-05 17:56 --------- d-----w C:\Program Files\Picasa2
    2008-01-04 18:28 --------- d-----w C:\Program Files\DVD Decrypter
    2008-01-04 09:55 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Sync App Settings
    2007-12-24 08:44 --------- d--h--w C:\Program Files\Creative Installation Information
    2007-12-24 06:19 --------- d-----w C:\Program Files\Backup&Synchronize
    2007-12-23 20:34 --------- d-----w C:\Program Files\Yamicsoft
    2007-12-23 19:46 --------- d-----w C:\Program Files\Allway Sync
    2007-12-23 19:41 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\HP
    2007-12-23 17:51 --------- d-----w C:\Program Files\FTDv3.8
    2007-12-23 14:28 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Symantec
    2007-12-23 14:21 --------- d-----w C:\Program Files\Norton 360
    2007-12-23 13:49 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Lavasoft
    2007-12-23 13:20 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\LaCie
    2007-12-23 12:08 --------- d-----w C:\Program Files\Your Uninstaller 2006
    2007-12-23 12:08 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\URSoft
    2007-12-23 10:25 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\DivX
    2007-12-23 09:30 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\VanDale
    2007-12-23 08:16 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\HPQ
    2007-12-23 07:51 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\Realtime Soft
    2007-12-23 07:50 --------- d-----w C:\Documents and Settings\HP_Administrator.WOONKAMER\Application Data\ATI
    2007-12-22 16:31 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\SiteAdvisor
    2007-12-21 19:35 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\uTorrent
    2007-11-25 11:08 487 ----a-w C:\Documents and Settings\HP_Administrator\CR-DX8MP.reg
    2007-11-04 17:55 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
    2007-02-15 11:32 7,089,294 ----a-w C:\Program Files\PCI_Install_5663(installshield 12_1.06)_20070215.rar
    2007-02-15 11:31 3,640,770 ----a-w C:\Program Files\PCI_Install_5663(installshield 12_1.06)_20070214.rar
    2007-02-13 20:48 975 ----a-w C:\Program Files\setup.ini
    2007-02-13 20:48 473 ----a-w C:\Program Files\layout.bin
    2007-02-13 20:48 36,486 ----a-w C:\Program Files\data1.hdr
    2007-02-13 20:48 3,327,097 ----a-w C:\Program Files\data1.cab
    2007-02-13 20:48 223,478 ----a-w C:\Program Files\setup.inx
    2007-02-13 20:48 112,544 ----a-w C:\Program Files\data2.cab
    2007-01-20 01:46 455,600 ----a-w C:\Program Files\setup.exe
    2007-01-20 01:43 492,032 ----a-w C:\Program Files\ISSetup.dll
    2006-12-13 18:28 852 ----a-w C:\Program Files\setup.iss
    2006-10-12 19:56 53,320 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
    2006-05-17 22:21 373,680 ----a-w C:\Program Files\_setup.dll
    2006-05-17 01:44 64,392 ----a-w C:\Program Files\setup.isn
    2006-04-16 13:27 0 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
    2006-04-16 19:22 64 --sha-r C:\WINDOWS\6EE73A0C9CC02D24.bin
    2006-11-04 01:13 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .

  10. #10
    Junior Member
    Join Date
    Feb 2008
    Posts
    12

    Default Combofix report (part 2)

    REGEDIT4
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-02 13:00 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 15:52 68856]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-27 18:25 1211176]
    "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 11:29 220544]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 22:53 204288]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-18 05:40 64512]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
    "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 22:14 237568]
    "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-05-16 16:58 213936]
    "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]
    "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44 61440]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 10:12 90112]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-20 11:38 98304]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
    "RCSystem"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 17:07 49152]
    "CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 00:00 45056]
    "VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-28 08:56 122880]
    "CTHelper"="CTHELPER.EXE" [2006-08-17 04:32 17920 C:\WINDOWS\CTHELPER.EXE]
    "UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]
    "UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" [2007-04-01 06:47 299520]
    "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 16:58 213936]
    "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-11-25 13:33 735824]
    "ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe" [2007-09-12 18:27 492912]

    C:\Documents and Settings\HP_Administrator.WOONKAMER\Menu Start\Programma's\Opstarten\
    Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 00:14:44 27136]

    C:\Documents and Settings\HP_Administrator\Menu Start\Programma's\Opstarten\
    OneNote 2007 Schermopname en Snel starten.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]

    C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
    HP Photosmart Premier Snelstart.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 13:00]
    R2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2006-09-24 21:22]
    R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-03 21:57]
    R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-08-17 04:16]
    R3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys [2006-09-24 21:23]
    S3 drhard;DRHARD;C:\WINDOWS\system32\DRIVERS\DRHARD.SYS [2005-12-01 10:49]
    S3 WN5301;LIteon Wireless PCI Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wn5301.sys [2005-10-05 18:44]
    S3 WN5401;Liteon Wireless LAN PCI 802.11 a/b/g adapter WN5401A;C:\WINDOWS\system32\DRIVERS\wn5401.sys [2005-01-07 01:08]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bb11dae-d253-11dc-8973-0013d3fa2457}]
    \Shell\AutoRun\command - F:\WD_Windows_Tools\setup.exe

    *Newly Created Service* - COMHOST
    .
    Inhoud van de 'Gedeelde Taken' map
    "2008-02-14 12:35:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-02-15 16:18:56 C:\WINDOWS\Tasks\Easy Onderhoud.job"
    - C:\Program Files\TuneUp Utilities 2008\OneClick.exe
    "2008-02-21 11:20:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{2C90D5DA-6FB8-4CA8-A312-D528B005DCA9}.job"
    - C:\WINDOWS\system32\msfeedssync.exe
    "2008-02-21 11:08:04 C:\WINDOWS\Tasks\XoftSpySE 2.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    "2008-02-19 05:51:36 C:\WINDOWS\Tasks\XoftSpySE.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-21 12:09:12
    Windows 5.1.2600 Service Pack 2 NTFS

    scannen van verborgen processen ...

    scannen van verborgen autostart items ...

    scannen van verborgen bestanden ...

    Scan succesvol afgerond
    verborgen bestanden: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    .
    **************************************************************************
    .
    Voltooingstijd: 2008-02-21 12:22:51 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-02-21 11:22:49
    ComboFix2.txt 2008-02-21 10:34:01
    .
    2008-02-13 11:11:05 --- E O F ---

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •