log van combofix:
ComboFix 08-03-03.6 - Michiel 2008-03-03 10:08:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.31.1043.18.576 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\Michiel\Bureaublad\ComboFix.exe
* Nieuw herstelpunt werd aangemaakt
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-02-03 to 2008-03-03 ))))))))))))))))))))))))))))))
.
2008-02-28 20:24 . 2008-02-28 20:24 <DIR> d-------- C:\Graphics
2008-02-28 20:24 . 2005-06-14 01:51 233,984 --------- C:\WINDOWS\system32\mwgfx24.dll
2008-02-28 20:24 . 2005-07-12 11:17 162,304 --------- C:\WINDOWS\system32\mwgfx.dll
2008-02-28 20:24 . 2005-06-04 12:45 103,424 --------- C:\WINDOWS\system32\mwdds.dll
2008-02-28 20:24 . 2004-05-14 10:13 56,832 --------- C:\WINDOWS\system32\mwace.dll
2008-02-28 19:36 . 2008-02-28 19:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-27 21:22 . 2008-02-27 21:38 <DIR> d-------- C:\HaxFix
2008-02-27 21:22 . 2008-02-27 21:37 449,390 --a------ C:\HaxFix.exe
2008-02-25 16:34 . 2008-02-25 16:34 <DIR> d-------- C:\Documents and Settings\Mapa\Application Data\Printer Info Cache
2008-02-25 16:34 . 2008-02-25 16:34 <DIR> d-------- C:\Documents and Settings\Mapa\Application Data\Image Zone Express
2008-02-23 21:18 . 2008-02-23 21:03 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-23 21:18 . 2008-02-23 21:18 2,555 --a------ C:\WINDOWS\unins000.dat
2008-02-23 16:35 . 2008-02-23 16:34 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 16:34 . 2008-02-23 16:35 <DIR> d-------- C:\Documents and Settings\Michiel\.housecall6.6
2008-02-18 21:41 . 2008-02-18 21:41 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2008-02-18 21:41 . 2007-09-07 14:55 27,672 --a------ C:\WINDOWS\system32\drivers\Entech.sys
2008-02-18 21:41 . 2007-09-07 14:55 12,744 --a------ C:\WINDOWS\system32\drivers\Entech64.sys
2008-02-18 21:41 . 2007-09-07 14:55 6,173 --a------ C:\WINDOWS\system32\drivers\Entech.vxd
2008-02-18 21:41 . 2001-11-19 20:05 3,972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2008-02-18 21:40 . 2008-02-18 21:40 <DIR> d-------- C:\Program Files\Futuremark
2008-02-17 14:39 . 2000-01-14 17:14 45,568 --a------ C:\WINDOWS\UniFish3.exe
2008-02-10 16:52 . 2008-02-10 16:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Magix
2008-02-08 16:58 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-02-08 16:58 . 2001-05-16 17:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-02-08 16:58 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-02-08 16:55 . 2008-02-10 16:53 <DIR> d-------- C:\WINDOWS\system32\MAGIX
2008-02-08 16:55 . 2007-04-17 17:05 667,648 --a------ C:\WINDOWS\system32\mgxoschk.dll
2008-02-08 16:55 . 2007-04-27 10:43 120,200 --a------ C:\WINDOWS\system32\DLLDEV32i.dll
2008-02-08 16:55 . 2008-02-08 16:57 5,937 --a------ C:\WINDOWS\mgxoschk.ini
2008-02-05 16:43 . 2008-02-05 16:43 <DIR> d-------- C:\Documents and Settings\Michiel\WINDOWS
2008-02-05 12:54 . 2008-02-05 12:54 <DIR> d-------- C:\Documents and Settings\Michiel\Application Data\WeatherWatcher
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-03 09:02 --------- d-----w C:\Program Files\Hitman Pro
2008-02-28 18:07 --------- d-----w C:\Documents and Settings\Michiel\Application Data\AVG7
2008-02-24 10:29 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-02-24 07:02 --------- d-----w C:\Program Files\Spyware Doctor
2008-02-23 21:24 --------- d---a-w C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2008-02-23 20:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-23 20:07 --------- d-----w C:\Program Files\ESET
2008-02-23 20:05 --------- d-----w C:\Program Files\SpywareBlaster
2008-02-23 20:03 2,560 ----a-w C:\WINDOWS\system32\drivers\mchInjDrv.sys
2008-02-23 15:48 --------- d-----w C:\Documents and Settings\Michiel\Application Data\uTorrent
2008-02-23 15:46 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
2008-02-23 14:31 --------- d-----w C:\Program Files\Google
2008-02-18 20:42 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-02-18 20:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-14 16:40 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-09 14:58 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Test Drive Unlimited
2008-02-05 15:29 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-02-05 11:55 --------- d-----w C:\Program Files\Weather Watcher
2008-02-05 10:27 --------- d-----w C:\Documents and Settings\Michiel\Application Data\LimeWire
2008-02-04 11:56 --------- d-----w C:\Documents and Settings\Michiel\Application Data\Winamp
2008-01-20 19:42 --------- d-----w C:\Program Files\AdVantage
2008-01-20 18:53 --------- d-----w C:\Documents and Settings\Michiel\Application Data\Lavasoft
2008-01-20 18:50 --------- d-----w C:\Program Files\Lavasoft
2008-01-20 18:48 74,240 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-20 18:48 56,832 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-30 15:54 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-12-21 03:09 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-21 03:08 272,384 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-21 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-21 02:59 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-21 02:59 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-21 02:59 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-21 02:59 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-21 02:58 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-21 02:57 512,000 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-21 02:56 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-21 02:53 9,826,304 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-21 02:47 3,120,640 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-21 02:36 1,661,696 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-21 02:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-21 02:20 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-21 02:18 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-21 02:15 159,744 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-21 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-20 20:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-12-11 18:26 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-07 02:18 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:42 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-01-11 08:08 577536 C:\WINDOWS\soundman.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-20 18:15 579072]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 09:33 892928]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Hitman Pro Expiration Helper"="C:\Program Files\Hitman Pro\xphelper.exe" [2007-01-30 14:41 596760]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-23 17:15 219136]
C:\DOCUME~1\ALLUSE~1\MENUST~1\PROGRA~1\OPSTAR~1\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-07 18:17:52 67128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"D:\\Games\\Test Drive\\TestDriveUnlimited.exe"=
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"D:\\Games\\Stranglehold\\Binaries\\Retail-Stranglehold.exe"=
"D:\\Games\\Freeciv\\Freeciv-2.0.9-gtk2\\civserver.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\DAP\\DAP.exe"=
"D:\\Games\\Postal Share The pain\\System\\Postal2.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Games\\Kane and Lynch Dead Men\\kaneandlynch.exe"=
"C:\\Documents and Settings\\Mapa\\Local Settings\\Temp\\ImInstaller\\IncrediMail\\incredimail_install[1].exe"=
"C:\\Program Files\\Hitman Pro\\wget.exe"=
R1 mchInjDrv;madCodeHook DLL injection driver;C:\WINDOWS\system32\Drivers\mchInjDrv.sys [2008-02-23 21:03]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-03 10:10:36
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
Voltooingstijd: 2008-03-03 10:10:57
.
2008-02-29 10:47:01 --- E O F ---