"$-peter's private-$" - 07-04-20 19:12:33 Service Pack 2
ComboFix 07-04-20V - Running from: C:\Documents and Settings\$-peter's private-$\Skrivebord\
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Programmer\screensavers.com\Wallpaper\Gran Turismo 3 - City Limits.jpg
C:\Programmer\screensavers.com\Wallpaper\swpstart.exe
C:\Programmer\screensavers.com\Wallpaper\Need For Speed Underground.jpg
C:\Programmer\screensavers.com
((((((((((((((((((((((((((((((( Files Created from 2007-03-20 to 2007-04-20 ))))))))))))))))))))))))))))))))))
2007-04-19 23:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-04-19 23:06 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-04-19 23:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-19 23:06 <DIR> d-------- C:\DOCUME~1\$-PETE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-19 23:05 <DIR> d-------- C:\Programmer\Yahoo!
2007-04-19 23:05 <DIR> d-------- C:\Programmer\F‘lles filer\Wise Installation Wizard
2007-04-19 23:05 <DIR> d-------- C:\Programmer\CCleaner
2007-04-19 22:40 3,206 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-19 22:39 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-04-19 22:39 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-04-19 22:39 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-04-19 22:39 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-04-19 22:39 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-04-19 22:39 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-04-18 18:29 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-04-18 18:29 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menuen Start
2007-04-18 18:29 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Foretrukne
2007-04-18 18:29 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Dokumenter
2007-04-18 18:29 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skabeloner
2007-04-18 18:29 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Printere
2007-04-18 18:29 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale indstillinger
2007-04-18 18:29 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Andre computere
2007-04-18 18:29 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord
2007-04-18 18:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-04-05 13:22 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-03-23 12:53 <DIR> d-------- C:\Programmer\iPod
2007-03-23 12:52 <DIR> d-------- C:\Programmer\QuickTime
2007-03-23 12:51 <DIR> d-------- C:\Programmer\Apple Software Update
2007-03-22 14:08 <DIR> d-------- C:\Programmer\Enigma Software Group
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-17 15:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-15 12:23 497496 --a------ C:\WINDOWS\system32\xceedzip.dll
2007-03-15 12:19 526184 --a------ C:\WINDOWS\system32\xceedcry.dll
2007-03-08 17:38 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38 40960 --------- C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:35 1843584 --------- C:\WINDOWS\system32\win32k.sys
2007-03-07 18:13 51442 --a------ C:\WINDOWS\system32\perfc006.dat
2007-03-07 18:13 333704 --a------ C:\WINDOWS\system32\perfh006.dat
2007-03-07 18:02 2560 --a------ C:\WINDOWS\_msrstrt.exe
2007-03-05 19:47 374 --a------ C:\DOCUME~1\$-PETE~1\APPLIC~1\internaldb6334.dat
2007-03-05 19:32 538 --a------ C:\DOCUME~1\$-PETE~1\APPLIC~1\internaldb8467.dat
2007-03-05 19:32 18432 --a------ C:\DOCUME~1\$-PETE~1\APPLIC~1\internaldb41.dat
2007-03-04 20:46 69698 --a------ C:\WINDOWS\distro_uplayme_stub_973387.exe
2007-02-24 14:12 -------- d-------- C:\Programmer\stardock
2007-02-22 15:25 -------- d-------- C:\Programmer\jowood
2007-02-05 22:19 185344 --a------ C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"LaunchApp"="Alaunch"
"SynTPLpr"="C:\\Programmer\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Programmer\\Synaptics\\SynTP\\SynTPEnh.exe"
"SoundMan"="SOUNDMAN.EXE"
"AGRSMMSG"="AGRSMMSG.exe"
"SiSPower"="Rundll32.exe SiSPower.dll,ModeAgent"
"SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"SunJavaUpdateSched"="\"C:\\Programmer\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Programmer\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Programmer\\iTunes\\iTunesHelper.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Programmer\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Yodm3D"="C:\\Documents and Settings\\$-peter's private-$\\Skrivebord\\lll\\yodm3D\\Yodm3D.exe"
"WMPNSCFG"="C:\\Programmer\\Windows Media Player\\WMPNSCFG.exe"
"SUPERAntiSpyware"="C:\\Programmer\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-20 19:14:28
C:\ComboFix-quarantined-files.txt ... 07-04-20 19:14