<<<<<<<<<<<<<<<<<<< combofix log >>>>>>>>>>>>>>>>><<
ComboFix 07-10-07.2 - Christina 2007-10-07 15:40:03.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.126 [GMT 2:00]
Running from: C:\Documents and Settings\Christina\Skrivebord\hjackthis\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\install.dat
C:\Documents and Settings\Christina\Application Data\Microsoft\20509.dat
C:\Documents and Settings\Christina\Application Data\Microsoft\20509.dat
C:\Documents and Settings\Christina\Application Data\Microsoft\20509.dat
C:\WINDOWS\system32\dlh9jkd1q8.exe
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\vx.tll
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\wpcjmd.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_ICF
-------\LEGACY_POOF
-------\kprof
-------\poof
((((((((((((((((((((((((( Files Created from 2007-09-07 to 2007-10-07 )))))))))))))))))))))))))))))))
.
2007-10-07 15:39 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-07 15:34 401,720 --a------ C:\Programmer\HJTrenamed.exe
2007-10-07 15:28 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-07 15:28 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-10-07 14:44 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-10-07 10:53 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2007-10-01 23:35 <DIR> d-------- C:\Programmer\Windows Defender
2007-10-01 23:07 <DIR> d--hs---- C:\FOUND.001
2007-10-01 22:46 <DIR> d-------- C:\Programmer\SymNetDrv
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-07 15:34 6930 --a------ C:\Programmer\hijackthis.log
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
C:\Programmer\Fælles filer\IRAABOUT.DLL
C:\Programmer\Fælles filer\IRAWEBTR.DLL
C:\Programmer\Fælles filer\IRASRIAL.DLL
C:\Programmer\Fælles filer\IRAREG.DLL
C:\Programmer\Fælles filer\IRAMDMTR.DLL
C:\Programmer\Fælles filer\IRALPTTR.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"SiSPower"="SiSPower.dll" [2005-02-25 04:35 C:\WINDOWS\system32\SiSPower.dll]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 03:13 C:\WINDOWS\SOUNDMAN.EXE]
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 05:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-27 05:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00]
"LManager"="C:\Programmer\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 16:41]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-10-01 22:46]
"Windows Defender"="C:\Programmer\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 05:00]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
"newrs32"="C:\WINDOWS\system32\edconss.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FÆLLES~1\MICROS~1\DW\dwtrig20.exe" -t
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2005-01-04 16:52:52]
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56]
Symantec WinFax Starter Port.lnk - C:\Programmer\Microsoft Office\Office\1030\OLFSNT40.EXE [1999-04-16 11:55:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"NDYMRkAqS"= {320D180F-98A7-B2A5-88B7-DA4E629C8ED9} - C:\WINDOWS\system32\prl.dll [2004-08-27 05:00 32768]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R2 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R2 osaio;osaio;\??\C:\WINDOWS\system32\drivers\osaio.sys
R2 osanbm;osanbm;\??\C:\WINDOWS\system32\drivers\osanbm.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys
S2 windev-1c4a-7500;windev-1c4a-7500;\??\C:\WINDOWS\system32\windev-1c4a-7500.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-09-29 06:12:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Christina.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
"2007-10-07 13:47:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programmer\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-07 15:43:05
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-07 15:47:55 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-07 15:47
.
--- E O F ---