and here is combofix logo.
ComboFix 08-02-21 - llll 2008-02-21 12:47:10.1 - NTFSx86
Gestart vanuit: C:\Documents and Settings\llll\Bureaublad\ComboFix.exe
* Nieuw herstelpunt werd aangemaakt[color=red][b]WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !![/b][/color]
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\ac
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Documents and Settings\llll\Application Data\storageprotector
C:\Documents and Settings\llll\Application Data\storageprotector\Logs\update.log
C:\Program Files\outlook
C:\setup.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bcbeg.ini
C:\WINDOWS\system32\bcbeg.ini2
C:\WINDOWS\system32\dyrsrkll.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\oiofgptp.ini
C:\WINDOWS\system32\scwcemwa.ini
C:\WINDOWS\Fonts\'
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-01-21 to 2008-02-21 ))))))))))))))))))))))))))))))
.
2008-02-20 18:17 . 2008-02-20 18:17 <DIR> d-------- C:\Program Files\MSN Messenger
2008-02-20 16:51 . 2008-02-20 16:51 <DIR> d-------- C:\VundoFix Backups
2008-02-20 11:45 . 2008-02-20 15:52 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-20 11:27 . 2008-02-20 11:26 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-20 11:25 . 2008-02-20 12:10 <DIR> d-------- C:\Documents and Settings\llll\.housecall6.6
2008-02-16 12:26 . 2008-02-19 13:07 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-16 12:26 . 2008-02-16 12:26 <DIR> d-------- C:\Documents and Settings\llll\Application Data\SUPERAntiSpyware.com
2008-02-16 12:26 . 2008-02-16 12:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-13 14:47 . 2008-02-13 14:47 832 --a------ C:\pos1AB.rar
2008-02-13 12:33 . 2008-02-13 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-13 09:48 . 2008-02-13 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-13 09:47 . 2008-02-20 15:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-12 20:55 . 2008-02-12 20:55 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-02-12 19:08 . 2008-02-13 08:56 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-02-12 19:08 . 2008-02-12 19:08 <DIR> d-------- C:\Program Files\MSECACHE
2008-02-12 16:33 . 2008-02-12 16:33 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-02-12 16:33 . 2008-02-12 16:33 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-02-12 16:31 . 2008-02-12 16:31 <DIR> d-------- C:\Documents and Settings\llll\Application Data\Sunbelt Software
2008-02-11 18:59 . 2008-02-13 12:27 <DIR> d-------- C:\Documents and Settings\LocalService\Bureaublad
2008-02-11 18:58 . 2008-02-12 17:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-11 18:51 . 2008-02-11 18:51 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-11 18:03 . 2008-02-12 17:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-11 17:41 . 2008-02-11 17:41 <DIR> d--h----- C:\kleaner.tmp
2008-02-11 17:12 . 2008-02-12 13:14 151 --a------ C:\WINDOWS\wininit.ini
2008-02-11 15:28 . 2008-02-11 15:28 <DIR> d-------- C:\Program Files\doc
2008-02-11 14:22 . 2008-02-11 14:22 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-02-04 13:33 . 2008-02-11 08:24 <DIR> d-------- C:\Program Files\AskPBar
2008-02-02 12:28 . 2007-10-11 00:53 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-02 12:28 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-02 12:28 . 2007-07-01 04:36 1,032,192 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-02 12:28 . 2007-10-11 00:53 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-02 12:28 . 2007-10-11 00:53 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-02 12:28 . 2007-10-11 00:53 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-02 12:28 . 2007-10-11 00:53 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-02 12:28 . 2007-10-11 00:53 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-02 12:28 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-02 12:17 . 2006-06-02 20:34 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 07:00 --------- d-----w C:\Documents and Settings\llll\Application Data\AVG7
2008-02-20 17:10 --------- d-----w C:\Program Files\Common Files\Real
2008-02-20 16:37 --------- d-----w C:\Program Files\Google
2008-02-13 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-13 08:59 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-12 18:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-11 16:34 --------- d-----w C:\Documents and Settings\llll\Application Data\LimeWire
2008-02-05 15:47 --------- d-----w C:\Documents and Settings\llll\Application Data\Paltalk
2008-02-03 14:41 --------- d-----w C:\Program Files\Paltalk Messenger
2008-01-14 20:13 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-13 09:30 --------- d-----w C:\Program Files\BitComet
2008-01-11 16:28 --------- d-----w C:\Program Files\BitDownload
2008-01-10 20:29 --------- d-----w C:\Documents and Settings\llll\Application Data\HP
2008-01-10 20:16 --------- d-----w C:\Program Files\Common Files\HP
2008-01-10 20:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-01-10 20:14 --------- d-----w C:\Program Files\HP
2008-01-10 20:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-01-08 02:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-06 23:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-06 18:41 --------- d-----w C:\Program Files\Hyves Kwekker
2007-12-26 22:42 --------- d-----w C:\Program Files\Trend Micro
2007-12-26 22:21 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-26 22:20 --------- d-----w C:\Program Files\Windows Live Favorites
2007-12-26 22:15 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-20 21:23 72,264 ----a-w C:\Program Files\setup.exe
2007-12-17 16:23 74,124 ----a-w C:\Program Files\release_notes_kav7.0mp1_en.html
2007-12-07 01:08 662,528 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:42 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
2007-08-02 15:53 536 ----a-w C:\Program Files\setup.reg
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6186eb50-f551-4589-b126-a7ab07e72057}]
C:\WINDOWS\system32\fodhwini.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-10-14 18:09 103712]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:03 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-10-14 18:09 103712]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-13 12:33 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-13 12:33 219136]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 14:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\auzuosyl]
auzuosyl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxxyyx]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^PalStart.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\PalStart.lnk
backup=C:\WINDOWS\pss\PalStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^VersionTrackerPro.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\VersionTrackerPro.lnk
backup=C:\WINDOWS\pss\VersionTrackerPro.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programma's^Opstarten^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-02-13 12:33 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 09:03 15360 C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-03-11 21:34 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IE Privacy Keeper]
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2003-07-13 01:49 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
C:\Program Files\outlook\outlook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BITS"=2 (0x2)
R3 SNCP106;PC Camera (6009 CIF);C:\WINDOWS\system32\DRIVERS\sncp106.sys [2002-12-27 17:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\CDStart.Exe
\Shell\Install\Command - E:\Stub.exe
.
Inhoud van de 'Gedeelde Taken' map
"2008-02-21 11:25:00 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 12:58:18
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
r Running Proce
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\SearchIndexer.exe
.
**************************************************************************
.
Voltooingstijd: 2008-02-21 13:04:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-21 12:04:24
.
2008-02-18 23:41:05 --- E O F ---