Her så det nye log fra ComboFix
ComboFix 07-10-09.3 - Kent Falkenstr›m 2007-10-10 16:25:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.645 [GMT 2:00]
Running from: C:\Download\ComboFix\ComboFix.exe
Command switches used :: C:\Download\ComboFix\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-10 to 2007-10-10 )))))))))))))))))))))))))))))))
.
2007-10-09 23:11 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-09 21:03 401,720 --a------ C:\Programmer\HJTrenamed.exe
2007-10-09 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-09 18:26 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-10-08 16:10 <DIR> d-------- C:\Programmer\UltraVNC
2007-10-08 16:10 12,800 --a------ C:\WINDOWS\system32\vncdrv.dll
2007-10-08 16:10 6,016 --a------ C:\WINDOWS\system32\drivers\vnccom.SYS
2007-10-08 16:10 5,760 --a------ C:\WINDOWS\system32\vnchelp.dll
2007-10-08 16:10 4,736 --a------ C:\WINDOWS\system32\drivers\vncdrv.sys
2007-10-04 05:59 <DIR> d-------- C:\FAKTURA MAPPE
2007-09-30 13:20 <DIR> d-------- C:\Programmer\Nvu
2007-09-30 12:56 <DIR> d-------- C:\Programmer\BlueVoda Website Builder
2007-09-30 01:23 <DIR> d-------- C:\Programmer\Lavasoft
2007-09-30 01:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-19 16:20 <DIR> d-------- C:\Programmer\Joost
2007-09-16 18:00 <DIR> d-------- C:\divx
2007-09-16 17:38 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-09-16 17:38 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-09-16 17:38 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-09-16 17:38 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-09-16 17:38 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-09-15 15:17 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-09-15 15:17 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-09-14 14:47 <DIR> d-------- C:\Programmer\Windows Live Toolbar
2007-09-14 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-09-12 17:12 <DIR> d-------- C:\EVENT DVD APRIL 2007
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-10 04:18 5,767,168 ---ha-w C:\Documents and Settings\Kent Falkenstrøm\NTUSER.DAT
2007-10-09 19:04 7,720 ----a-w C:\Programmer\hijackthis.log
2007-10-09 16:26 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2007-09-22 13:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-22 10:27 --------- d-----w C:\Programmer\DVDlabPro1.53
2007-09-16 15:38 --------- d-----w C:\Programmer\DivX
2007-09-14 12:44 --------- d-----w C:\Programmer\MSN Messenger
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 144,704 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-08-15 22:30 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-08-15 22:30 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-08-15 22:30 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((( snapshot@2007-10-09_23.15.48,50 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 14,560 2007-03-06 01:10:55 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\spmsg.dll
----a-w 214,752 2007-03-06 01:11:00 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\spuninst.exe
----a-w 683,520 2007-08-21 06:17:41 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\sp2gdr\inetcomm.dll
----a-w 683,520 2007-08-21 06:26:05 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\sp2qfe\inetcomm.dll
----a-w 22,752 2007-03-06 01:10:53 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\update\spcustom.dll
----a-w 721,120 2007-03-06 01:11:17 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\update\update.exe
----a-w 383,200 2007-03-06 01:12:08 C:\WINDOWS\SoftwareDistribution\Download\3469968981637981346391b6df19c63e\update\updspapi.dll
----a-w 14,560 2007-03-06 01:10:55 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\spmsg.dll
----a-w 214,752 2007-03-06 01:11:00 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\spuninst.exe
----a-w 1,022,976 2007-08-22 13:14:05 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\browseui.dll
----a-w 151,552 2007-08-22 13:14:05 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\cdfview.dll
----a-w 1,056,256 2007-08-22 13:14:06 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\danim.dll
----a-w 357,888 2007-08-22 13:14:07 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\dxtmsft.dll
----a-w 205,312 2007-08-22 13:14:07 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\dxtrans.dll
----a-w 55,808 2007-08-22 13:14:07 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\extmgr.dll
----a-w 18,432 2007-08-21 10:30:45 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\iedw.exe
----a-w 251,392 2007-08-22 13:14:07 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\iepeers.dll
----a-w 96,768 2007-08-22 13:14:08 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\inseng.dll
----a-w 16,384 2007-08-22 13:14:08 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\jsproxy.dll
----a-w 3,079,168 2007-08-22 13:14:11 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\mshtml.dll
----a-w 449,024 2007-08-22 13:14:11 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\mshtmled.dll
----a-w 146,432 2007-08-22 13:14:12 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\msrating.dll
----a-w 532,480 2007-08-22 13:14:12 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\mstime.dll
----a-w 39,424 2007-08-22 13:14:13 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\pngfilt.dll
----a-w 1,494,528 2007-08-22 13:14:15 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\shdocvw.dll
----a-w 474,112 2007-08-22 13:14:16 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\shlwapi.dll
----a-w 118,272 2007-08-21 10:53:20 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\spru0406.dll
----a-w 617,472 2007-08-22 13:14:17 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\urlmon.dll
----a-w 660,480 2007-08-22 13:14:18 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2gdr\wininet.dll
----a-w 1,022,976 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\browseui.dll
----a-w 151,552 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\cdfview.dll
----a-w 1,056,256 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\danim.dll
----a-w 357,888 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\dxtmsft.dll
----a-w 205,824 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\dxtrans.dll
----a-w 55,808 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\extmgr.dll
----a-w 18,432 2007-08-21 10:19:39 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\iedw.exe
----a-w 251,904 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\iepeers.dll
----a-w 96,768 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\inseng.dll
----a-w 16,384 2007-08-22 12:57:23 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\jsproxy.dll
----a-w 3,085,824 2007-08-22 12:57:24 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\mshtml.dll
----a-w 449,024 2007-08-22 12:57:24 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\mshtmled.dll
----a-w 146,432 2007-08-22 12:57:24 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\msrating.dll
----a-w 532,480 2007-08-22 12:57:24 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\mstime.dll
----a-w 39,424 2007-08-22 12:57:24 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\pngfilt.dll
----a-w 1,498,112 2007-08-22 12:57:25 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\shdocvw.dll
----a-w 474,112 2007-08-22 12:57:25 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\shlwapi.dll
----a-w 359,936 2007-08-21 10:50:44 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\spru0406.dll
----a-w 620,032 2007-08-22 12:57:25 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\urlmon.dll
----a-w 667,136 2007-08-22 12:57:26 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\sp2qfe\wininet.dll
----a-w 22,752 2007-03-06 01:10:53 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\update\spcustom.dll
----a-w 721,120 2007-03-06 01:11:17 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\update\update.exe
----a-w 383,200 2007-03-06 01:12:08 C:\WINDOWS\SoftwareDistribution\Download\c066cf6e1b8ee6f0e19c3625c63520bd\update\updspapi.dll
----a-w 14,560 2005-10-12 23:10:49 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\spmsg.dll
----a-w 214,752 2005-10-12 23:10:49 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\spuninst.exe
----a-w 584,192 2007-07-09 13:11:49 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\SP2GDR\rpcrt4.dll
----a-w 118,272 2007-06-12 21:53:14 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\SP2GDR\spru0406.dll
----a-w 582,656 2007-07-09 13:19:29 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\SP2QFE\rpcrt4.dll
----a-w 359,936 2007-06-18 22:24:36 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\SP2QFE\spru0406.dll
----a-w 22,752 2005-10-12 23:10:48 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\update\spcustom.dll
----a-w 721,120 2005-10-12 23:10:51 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\update\update.exe
----a-w 383,200 2005-10-12 23:10:56 C:\WINDOWS\SoftwareDistribution\Download\e452665eb2abffc827e7c4aa87008129\update\updspapi.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-09-20 16:09]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-08 15:23]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Cisco Systems VPN Client.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Cisco Systems VPN Client.lnk
backup=C:\WINDOWS\pss\Cisco Systems VPN Client.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^SATARaid.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\SATARaid.lnk
backup=C:\WINDOWS\pss\SATARaid.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kent Falkenstrøm^Menuen Start^Programmer^Start^Adobe Gamma.lnk]
path=C:\Documents and Settings\Kent Falkenstrøm\Menuen Start\Programmer\Start\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kent Falkenstrøm^Menuen Start^Programmer^Start^SpywareGuard.lnk]
path=C:\Documents and Settings\Kent Falkenstrøm\Menuen Start\Programmer\Start\SpywareGuard.lnk
backup=C:\WINDOWS\pss\SpywareGuard.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSDVCRAgent]
C:\Programmer\ASUS\ASUS Digital VCR\Schedule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
C:\Programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZSKY150]
C:\Programmer\EZSKY150\EZSKY150.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
C:\Programmer\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
~"C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
"C:\Programmer\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Programmer\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDVR SchSvr]
"C:\Programmer\Fælles filer\InterVideo\SchSvr\SchSvr.exe"
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\si3112r.sys
R0 Si3124r5;SiI-3124 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3124r5.sys
R1 GhPciScan;GhostPciScanner;\??\C:\Programmer\Symantec\Norton Ghost 2003\ghpciscan.sys
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys
R2 nvTUNEP;nVidia WDM TVTuner;C:\WINDOWS\system32\DRIVERS\nvtunep.sys
R2 nvtvSND;nVidia WDM TVAudio Crossbar;C:\WINDOWS\system32\DRIVERS\nvtvsnd.sys
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS
R3 vncdrv;vncdrv;C:\WINDOWS\system32\DRIVERS\vncdrv.sys
S3 SE27bus;Sony Ericsson Device 039 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE27bus.sys
S3 SE27mdfl;Sony Ericsson Device 039 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys
S3 SE27mdm;Sony Ericsson Device 039 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE27mdm.sys
S3 SE27mgmt;Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys
S3 se27nd5;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS);C:\WINDOWS\system32\DRIVERS\se27nd5.sys
S3 SE27obex;Sony Ericsson Device 039 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE27obex.sys
S3 se27unic;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM);C:\WINDOWS\system32\DRIVERS\se27unic.sys
S3 SiSV;SiSV;C:\WINDOWS\system32\DRIVERS\SiSV.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 03:47:00 C:\WINDOWS\Tasks\Søg efter opdateringer til Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-10 16:27:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aawservice]
"ImagePath"="\"C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe\""
.
Completion time: 2007-10-10 16:27:56
C:\ComboFix-quarantined-files.txt ... 2007-10-10 16:27
C:\ComboFix2.txt ... 2007-10-09 23:16
.
--- E O F ---