Time for the next logs. ComboFix did NOT freeze this time. But I'd like to run a Memtest, which sort of program would I use for that?
Here is the ComboFix log:
ComboFix 12-07-07.04 - Korcas 07.07.2012 19:03:48.4.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.3327.2561 [GMT 2:00]
Running from: h:\dokumente und einstellungen\Korcas\Desktop\ComboFix.exe
Command switches used :: h:\dokumente und einstellungen\Korcas\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Files Created from 2012-06-07 to 2012-07-07 )))))))))))))))))))))))))))))))
.
.
2012-07-06 03:49 . 2012-07-06 03:49 -------- d-----w- H:\_OTM
2012-07-05 17:12 . 2012-07-05 17:12 -------- d-----w- h:\programme\ESET
2012-07-04 16:32 . 2012-07-04 16:32 -------- d-----w- h:\dokumente und einstellungen\Korcas\Anwendungsdaten\Malwarebytes
2012-07-04 16:32 . 2012-07-04 16:32 -------- d-----w- h:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2012-07-04 16:32 . 2012-04-04 13:56 22344 ----a-w- h:\windows\system32\drivers\mbam.sys
2012-07-03 05:16 . 2012-07-03 05:16 -------- d-----w- h:\windows\system32\wbem\Repository
2012-06-14 02:47 . 2012-05-11 14:40 521728 -c----w- h:\windows\system32\dllcache\jsdbgui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 16:21 . 2010-12-28 17:32 54232 ----a-w- h:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2012-02-25 08:54 18544 ----a-w- h:\windows\system32\drivers\aswKbd.sys
2012-07-03 16:21 . 2011-11-11 06:24 721000 ----a-w- h:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2011-11-11 06:24 202928 ----a-w- h:\windows\system32\drivers\aswNdis2.sys
2012-07-03 16:21 . 2010-12-28 17:32 21256 ----a-w- h:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2010-12-28 17:32 353688 ----a-w- h:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2010-12-28 17:32 35928 ----a-w- h:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2010-12-28 17:32 97608 ----a-w- h:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2010-12-28 17:32 89624 ----a-w- h:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2011-11-11 06:24 113776 ----a-w- h:\windows\system32\drivers\aswFW.sys
2012-07-03 16:21 . 2010-12-28 17:32 25256 ----a-w- h:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2010-12-28 17:32 41224 ----a-w- h:\windows\avastSS.scr
2012-07-03 16:21 . 2010-12-28 17:32 227648 ----a-w- h:\windows\system32\aswBoot.exe
2012-07-02 02:27 . 2012-04-01 15:06 426184 ----a-w- h:\windows\system32\FlashPlayerApp.exe
2012-07-02 02:27 . 2011-07-01 18:33 70344 ----a-w- h:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 13:19 . 2009-10-17 14:26 329240 ----a-w- h:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-10-17 14:26 210968 ----a-w- h:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-10-17 14:26 219160 ----a-w- h:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2008-10-16 12:08 15896 ----a-w- h:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 12:07 18456 ----a-w- h:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-10-17 14:26 53784 ----a-w- h:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-10-17 14:26 35864 ----a-w- h:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 12:09 45080 ----a-w- h:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 12:08 15896 ----a-w- h:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2007-07-27 12:00 97304 ----a-w- h:\windows\system32\cdm.dll
2012-06-02 13:19 . 2008-10-16 12:08 23576 ----a-w- h:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-10-17 14:26 577048 ----a-w- h:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-10-17 14:26 1933848 ----a-w- h:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2007-07-27 12:00 604160 ----a-w- h:\windows\system32\crypt32.dll
2012-05-16 15:07 . 2007-07-27 12:00 916992 ----a-w- h:\windows\system32\wininet.dll
2012-05-15 13:56 . 2007-07-27 12:00 1863296 ----a-w- h:\windows\system32\win32k.sys
2012-05-11 14:40 . 2007-07-27 12:00 43520 ----a-w- h:\windows\system32\licmgr10.dll
2012-05-11 14:40 . 2007-07-27 12:00 1469440 ------w- h:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2007-07-27 12:00 385024 ----a-w- h:\windows\system32\html.iec
2012-05-05 03:14 . 2007-07-27 12:00 2150912 ----a-w- h:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-04 00:50 2029056 ----a-w- h:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2009-10-17 14:24 139656 ----a-w- h:\windows\system32\drivers\rdpwd.sys
2002-11-19 23:01 . 2006-02-17 15:51 28672 ----a-w- h:\programme\opera\program\plugins\PlugDef.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-05_17.07.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-06 18:21 . 2012-07-06 18:21 16384 h:\windows\temp\Perflib_Perfdata_5f0.dat
- 2007-07-27 12:00 . 2012-07-05 16:54 67740 h:\windows\system32\perfc009.dat
+ 2007-07-27 12:00 . 2012-07-06 18:25 67740 h:\windows\system32\perfc009.dat
- 2007-07-27 12:00 . 2012-07-05 16:54 48036 h:\windows\system32\perfc007.dat
+ 2007-07-27 12:00 . 2012-07-06 18:25 48036 h:\windows\system32\perfc007.dat
+ 2007-07-27 12:00 . 2012-07-06 18:25 432784 h:\windows\system32\perfh009.dat
- 2007-07-27 12:00 . 2012-07-05 16:54 432784 h:\windows\system32\perfh009.dat
- 2007-07-27 12:00 . 2012-07-05 16:54 316246 h:\windows\system32\perfh007.dat
+ 2007-07-27 12:00 . 2012-07-06 18:25 316246 h:\windows\system32\perfh007.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- h:\programme\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="h:\programme\Vtune\TBPanel.exe" [2009-05-12 2158592]
"AdobeBridge"="I:\adobecs5.5\Adobe Bridge CS5.1\Bridge.exe" [2011-03-02 12008296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="h:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-27 208952]
"MSPY2002"="h:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2007-07-27 59392]
"PHIME2002ASync"="h:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2007-07-27 455168]
"PHIME2002A"="h:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2007-07-27 455168]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Adobe ARM"="h:\programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Trojancheck 6 Guard"="h:\programme\Trojancheck 6\tcguard.exe" [2002-11-14 590336]
"ISUSPM Startup"="h:\progra~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="h:\programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"AdobeAAMUpdater-1.0"="h:\programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"SwitchBoard"="h:\programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="h:\programme\Gemeinsame Dateien\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"Adobe Acrobat Speed Launcher"="I:\adobecs5.5\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="I:\adobecs5.5\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
"avast"="h:\programme\Alwil Software\Avast5\avastUI.exe" [2012-07-03 4273976]
"SunJavaUpdateSched"="h:\programme\Gemeinsame Dateien\Java\Java Update\jusched.exe" [2011-06-09 254696]
"NvMediaCenter"="NvMCTray.dll" [2011-05-21 111208]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2011-05-21 13895272]
"nwiz"="h:\programme\NVIDIA Corporation\nView\nwiz.exe" [2011-05-04 1632360]
"Malwarebytes' Anti-Malware"="I:\malwarebytes' anti-malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\H:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Gamma Loader.lnk]
path=h:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Adobe Gamma Loader.lnk
backup=h:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\H:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^HP Digital Imaging Monitor.lnk]
path=h:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\HP Digital Imaging Monitor.lnk
backup=h:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\H:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Microsoft Office.lnk]
path=h:\dokumente und einstellungen\All Users\Startmenü\Programme\Autostart\Microsoft Office.lnk
backup=h:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AshSnap]
2011-04-01 07:10 1528176 ----a-w- I:\ashampoo snap 4\ashsnap.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-28 22:15 136176 ----atw- h:\dokumente und einstellungen\Korcas\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-11-21 02:10 3293184 ----a-w- h:\programme\Google\Google Talk\googletalk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2010-11-22 13:20 2736128 ----a-w- h:\programme\Gemeinsame Dateien\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:22 1695232 ------w- h:\programme\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- I:\quicktime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 14:12 26192168 ----a-r- I:\skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"I:\\mIRC\\mirc.exe"=
"I:\\Trillian\\trillian.exe"=
"h:\\Programme\\Java\\jre6\\bin\\javaw.exe"=
"h:\\Programme\\VideoLAN\\VLC\\vlc.exe"=
"h:\\Dokumente und Einstellungen\\Korcas\\Lokale Einstellungen\\Anwendungsdaten\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"I:\\Skype\\Plugin Manager\\skypePM.exe"=
"I:\\Skype\\Phone\\Skype.exe"=
"h:\\Programme\\Opera\\opera.exe"=
"h:\\Programme\\Google\\Google Talk\\googletalk.exe"=
"I:\\AdobeCS5.5\\Adobe Flash Builder 4.5\\FlashBuilder.exe"=
"h:\\Programme\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"h:\\Programme\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"I:\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"I:\\Opera\\opera.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7935:TCP"= 7935:TCP:Adobe Flash Builder 4.5
.
R0 aswNdis;avast! Firewall NDIS Filter Service;h:\windows\system32\drivers\aswNdis.sys [11.11.2011 08:24 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;h:\windows\system32\drivers\aswNdis2.sys [11.11.2011 08:24 202928]
R1 aswFW;avast! TDI Firewall driver;h:\windows\system32\drivers\aswFW.sys [11.11.2011 08:24 113776]
R1 aswKbd;aswKbd;h:\windows\system32\drivers\aswKbd.sys [25.02.2012 10:54 18544]
R1 aswSnx;aswSnx;h:\windows\system32\drivers\aswSnx.sys [11.11.2011 08:24 721000]
R1 aswSP;aswSP;h:\windows\system32\drivers\aswSP.sys [28.12.2010 19:32 353688]
R1 ISODisk;ISODisk;h:\windows\system32\drivers\ISODisk.sys [25.06.2011 09:41 9600]
R2 aswFsBlk;aswFsBlk;h:\windows\system32\drivers\aswFsBlk.sys [28.12.2010 19:32 21256]
R2 avast! Firewall;avast! Firewall;h:\programme\Alwil Software\Avast5\afwServ.exe [11.11.2011 08:24 133912]
R2 MBAMService;MBAMService;I:\malwarebytes' anti-malware\mbamservice.exe [04.07.2012 18:32 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;h:\programme\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [06.03.2012 23:02 2214504]
R2 TabletServicePen;TabletServicePen;h:\windows\system32\Pen_Tablet.exe [18.10.2009 21:34 4497704]
R2 WTouchService;WTouch Service;h:\programme\WTouch\WTouchService.exe [18.10.2009 21:35 113448]
R3 MBAMProtector;MBAMProtector;h:\windows\system32\drivers\mbam.sys [04.07.2012 18:32 22344]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;h:\windows\system32\drivers\viahduaa.sys [20.12.2009 20:00 1381632]
R3 wacmoumonitor;Wacom Mode Helper;h:\windows\system32\drivers\wacmoumonitor.sys [18.10.2009 21:34 16168]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;h:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [01.04.2012 17:06 250056]
S3 appliandMP;appliandMP;h:\windows\system32\DRIVERS\appliand.sys --> h:\windows\system32\DRIVERS\appliand.sys [?]
S3 SwitchBoard;SwitchBoard;h:\programme\Gemeinsame Dateien\Adobe\SwitchBoard\SwitchBoard.exe [19.02.2010 13:37 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-11-22 13:18 451872 ----a-w- h:\programme\Gemeinsame Dateien\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-07 h:\windows\Tasks\AdobeAAMUpdater-1.0-GREYBOX-Korcas.job
- h:\programme\Gemeinsame Dateien\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-06-26 06:46]
.
2012-07-07 h:\windows\Tasks\avast! Emergency Update.job
- h:\programme\Alwil Software\Avast5\AvastEmUpdate.exe [2012-06-30 16:21]
.
2012-07-07 h:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1757981266-725345543-1003Core.job
- h:\dokumente und einstellungen\Korcas\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2010-04-28 22:15]
.
2012-07-07 h:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1757981266-725345543-1003UA.job
- h:\dokumente und einstellungen\Korcas\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe [2010-04-28 22:15]
.
.
------- Supplementary Scan -------
.
IE: An vorhandene PDF-Datei anfügen - h:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: In Adobe PDF konvertieren - h:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - h:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - h:\programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Adobe Reader Speed Launcher - I:\reader\Reader\Reader_sl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-07-07 19:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(5348)
h:\windows\system32\webcheck.dll
.
Completion time: 2012-07-07 19:09:06
ComboFix-quarantined-files.txt 2012-07-07 17:09
ComboFix2.txt 2012-07-06 18:24
ComboFix3.txt 2012-07-06 03:46
ComboFix4.txt 2012-07-05 17:10
.
Pre-Run: 8 Verzeichnis(se), 13.594.959.872 Bytes frei
Post-Run: 9 Verzeichnis(se), 14.461.534.208 Bytes frei
.
- - End Of File - - 456DFF7C11E471E7594F636EB88FCD1F