ComboFix 07-08-09.3 - "henrik lai jensen" 2007-08-12 23:41:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.154 [GMT 2:00]
* Created a new restore point
Rootkit driver xpdt is present. ... attempting disinfection xpdt ...... driver unloaded successfully.((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\HENRIK~1\APPLIC~1\..\err.log
C:\WINDOWS\system32\xpdt.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NTIO256
-------\ntio256
((((((((((((((((((((((((( Files Created from 2007-07-12 to 2007-08-12 )))))))))))))))))))))))))))))))
2007-08-12 23:36 51,200 --a------ C:\WINDOWS\nircmd.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-07 23:49 --------- d-------- C:\Programmer\SUPERAntiSpyware
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-27 14:04 1852 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-07-15 01:19 2322688 --a------ C:\WINDOWS\system32\TUKernel.exe
2007-07-14 00:21 --------- d-------- C:\Programmer\Google
2007-07-11 21:31 69784 --a------ C:\WINDOWS\system32\perfc006.dat
2007-07-11 21:31 409696 --a------ C:\WINDOWS\system32\perfh006.dat
2007-07-08 21:53 1740 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-07-07 13:51 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\Google
2007-07-05 22:27 --------- d-------- C:\Programmer\X-Cleaner
2007-07-01 22:04 --------- d-------- C:\Programmer\Banner Maker Pro for Flash
2007-06-28 21:35 455238 --a------ C:\uninstall.exe
2007-06-28 21:35 2125824 --a------ C:\Antenna.exe
2007-06-27 20:44 --------- d-------- C:\Programmer\Via-net ApS
2007-06-26 22:03 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\KompoZer
2007-06-26 21:41 --------- d-------- C:\Programmer\Nvu
2007-06-26 20:57 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-25 21:54 --------- d--h----- C:\Programmer\InstallShield Installation Information
2007-06-25 21:54 --------- d-------- C:\Programmer\Xara
2007-06-25 21:13 --------- d-------- C:\Programmer\Banner Maker Pro 6
2007-06-24 03:01 --------- d-------- C:\Programmer\MSXML 4.0
2007-06-20 21:30 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\LGSync
2007-06-20 21:27 --------- d-------- C:\Programmer\LG Electronics
2007-06-20 21:25 --------- d-------- C:\Programmer\LGE GSM PC Sync
2007-06-17 15:36 1956 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-17 00:01 --------- d-------- C:\Programmer\Selteco
2007-06-16 23:55 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\Likno
2007-06-13 22:12 --------- d-------- C:\Programmer\Web Button Menu Maker
2007-06-13 21:54 --------- d-------- C:\Programmer\LiknoWebButtonMakerFree
2007-06-07 06:23 1040384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-06-07 06:22 196608 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-06-02 14:55 1536 --a------ C:\cwainda.exe
2007-05-16 17:14 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 17:14 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 17:14 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 17:14 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 17:14 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 17:14 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\System
--------- C:\Programmer\Fælles filer\NSV
--------- C:\Programmer\Fælles filer\InstallShield
--------- C:\Programmer\Fælles filer
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Huskesedel.txt [2007-07-19 06:00:18]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL 2007-08-07 23:48 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winxwp32]
winxwp32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^henrik lai jensen^Menuen Start^Programmer^Start^huskesedel.txt]
path=C:\Documents and Settings\henrik lai jensen\Menuen Start\Programmer\Start\huskesedel.txt
backup=C:\WINDOWS\pss\huskesedel.txtStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApachInc]
rundll32.exe "C:\WINDOWS\system32\xgievutk.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipmon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\novsvida.exe]
C:\Documents and Settings\All Users\Application Data\novsvida.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
rundll32.exe "C:\WINDOWS\system32\myeolxwp.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundService]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT
R1 SASDIFSV;SASDIFSV;\??\C:\Programmer\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Programmer\SUPERAntiSpyware\SASKUTIL.sys
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 3dfxvs;3dfxvs;C:\WINDOWS\system32\DRIVERS\3dfxvsm.sys
S3 SASENUM;SASENUM;\??\C:\Programmer\SUPERAntiSpyware\SASENUM.SYS
S3 TSP;TSP;\??\C:\WINDOWS\system32\drivers\klif.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2007-08-10 15:33:04 C:\WINDOWS\Tasks\1-Click Maintenance.job
2007-05-15 19:59:40 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programmer\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-08-12 23:48:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4]
Completion time: 2007-08-12 23:51:23 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-12 23:50
--- E O F ---