AAComboFix 07-08-09.3 - "henrik lai jensen" 2007-09-04 21:25:36.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.140 [GMT 2:00]
Command switches used :: C:\Documents and Settings\henrik lai jensen\Dokumenter\combofix\CFScript.txt
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\dat.txt
((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))
2007-09-04 17:30 266,240 --a------ C:\WINDOWS\msmdev.dll
2007-09-04 17:30 253,952 --a------ C:\WINDOWS\msmhost.dll
2007-09-04 17:30 208,896 --a------ C:\WINDOWS\nsduo.dll
2007-09-03 21:45 <DIR> d-------- C:\Programmer\backups
2007-09-03 17:26 <DIR> d-------- C:\Programmer\XoftSpySE
2007-09-02 20:30 401,720 --a------ C:\Programmer\HJTrenamed.exe
2007-08-17 01:14 3,224,336 --a------ C:\WINDOWS\system32\VFP500.DLL
2007-08-17 01:14 <DIR> d-------- C:\Programmer\Lets Play Darts
2007-08-17 00:42 4 --a------ C:\WINDOWS\system32\proc884495530.bin
2007-08-17 00:42 <DIR> d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\GanymedeNet
2007-08-14 22:20 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-08-13 00:39 <DIR> d-------- C:\Programmer\CCleaner
2007-08-12 23:36 51,200 --a------ C:\WINDOWS\nircmd.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-04 18:15 5912 --a------ C:\Programmer\hijackthis.log
2007-09-03 18:06 --------- d-------- C:\Programmer\SUPERAntiSpyware
2007-08-20 18:06 --------- d-------- C:\Programmer\Banner Maker Pro for Flash
2007-08-17 00:43 1740 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-07-30 19:19 92504 --a--c--- C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a--c--- C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a--c--- C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a--c--- C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a--c--- C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a--c--- C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a--c--- C:\WINDOWS\system32\dllcache\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-27 14:04 1852 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-07-19 08:58 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-15 01:19 2322688 --a------ C:\WINDOWS\system32\TUKernel.exe
2007-07-14 00:21 --------- d-------- C:\Programmer\Google
2007-07-13 01:31 765952 --a--c--- C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-11 21:31 69784 --a------ C:\WINDOWS\system32\perfc006.dat
2007-07-11 21:31 409696 --a------ C:\WINDOWS\system32\perfh006.dat
2007-07-07 13:51 --------- d-------- C:\DOCUME~1\HENRIK~1\APPLIC~1\Google
2007-07-05 22:27 --------- d-------- C:\Programmer\X-Cleaner
2007-06-27 16:05 823808 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 16:05 671232 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 16:05 6058496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 16:05 52224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 16:05 477696 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 16:05 459264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 16:05 44544 --a--c--- C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 16:05 27648 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 16:05 267776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 16:05 232960 --a--c--- C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 16:05 193024 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 16:05 1152000 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 16:05 105984 --a--c--- C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 16:05 102400 --a--c--- C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 16:04 384512 --a--c--- C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 16:04 383488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 16:04 230400 --a--c--- C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 16:04 153088 --a--c--- C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 16:04 132608 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 16:04 124928 --a--c--- C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 15:34 317952 --a--c--- C:\WINDOWS\system32\dllcache\unregmp2.exe
2007-06-27 10:27 63488 --a--c--- C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27 13824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 10:25 625152 --a--c--- C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 09:00 161792 --a--c--- C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:10 1104896 --a--c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a--c--- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-17 15:36 1956 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-13 15:22 1034240 --a--c--- C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 15:22 1034240 --a------ C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 --a--c--- C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-07 06:23 1040384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-06-07 06:22 196608 --a------ C:\WINDOWS\system32\ssleay32.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88418AA3-16F5-4FC2-A9D8-90B1266DF841}]
2007-09-04 12:00 208896 --a------ C:\WINDOWS\nsduo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-27 14:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"msmhost"= {31F3B6B5-3E55-4947-8475-D87FBC7E7E1E} - C:\WINDOWS\msmhost.dll [2007-09-04 12:00 253952]
"msmdev"= {D9801870-9F6D-4636-8479-4F05A341F200} - C:\WINDOWS\msmdev.dll [2007-09-04 12:00 266240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL 2007-08-07 23:48 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=hardlife.ini
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Huskesedel.txt]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Huskesedel.txt
backup=C:\WINDOWS\pss\Huskesedel.txtCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^henrik lai jensen^Menuen Start^Programmer^Start^huskesedel.txt]
path=C:\Documents and Settings\henrik lai jensen\Menuen Start\Programmer\Start\huskesedel.txt
backup=C:\WINDOWS\pss\huskesedel.txtStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipmon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\novsvida.exe]
C:\Documents and Settings\All Users\Application Data\novsvida.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundService]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT
R1 SASDIFSV;SASDIFSV;\??\C:\Programmer\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Programmer\SUPERAntiSpyware\SASKUTIL.sys
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 3dfxvs;3dfxvs;C:\WINDOWS\system32\DRIVERS\3dfxvsm.sys
S3 SASENUM;SASENUM;\??\C:\Programmer\SUPERAntiSpyware\SASENUM.SYS
S3 TSP;TSP;\??\C:\WINDOWS\system32\drivers\klif.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2007-08-17 15:29:44 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Programmer\TuneUp Utilities 2007\SystemOptimizer.exe
2007-05-15 19:59:40 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programmer\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-04 21:28:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Aavmker4]
Completion time: 2007-09-04 21:30:25
C:\ComboFix-quarantined-files.txt ... 2007-09-04 21:29
C:\ComboFix2.txt ... 2007-09-04 20:57
C:\ComboFix3.txt ... 2007-08-29 18:55
--- E O F ---