ComboFix 07-10-21.1** - S›ren 2007-10-21 13:25:58.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.991 [GMT 2:00]
Running from: D:\Dokumenter S›ren\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-21 13:01 <DIR> d-------- C:\Programmer\backups
2007-10-21 12:20 401,720 --a------ C:\Programmer\HJTrenamed.exe
2007-10-21 09:07 <DIR> C:\Documents and Settings\Søren\Recent
2007-10-21 09:05 <DIR> d-------- C:\Programmer\CCleaner
2007-10-11 01:07 <DIR> d-------- C:\Programmer\MSXML 6.0
2007-10-10 07:02 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-05 22:35 <DIR> d-------- C:\Documents and Settings\Trine\Contacts
2007-09-26 04:52 <DIR> d-------- C:\Programmer\Remove Empty Directories
2007-09-22 06:56 <DIR> d-------- C:\Programmer\Haltonware
2007-09-21 14:26 <DIR> d-------- C:\Documents and Settings\Lene\Application Data\Xara
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 11:20 12,432 ----a-w C:\Programmer\hijackthis.log
2007-10-21 11:15 12,513,280 ----a-w C:\Documents and Settings\Søren\ntuser.dat
2007-10-21 10:40 --------- d-----w C:\Programmer\K-Lite
2007-10-21 07:11 --------- d-----w C:\Programmer\SUPERAntiSpyware
2007-10-21 07:05 --------- d-----w C:\Programmer\Yahoo!
2007-10-20 07:07 --------- d-----w C:\Programmer\eMule
2007-10-16 11:11 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-09 21:07 --------- d-----w C:\Programmer\Fælles filer\Microsoft Shared
2007-10-09 21:07 --------- d-----w C:\Programmer\Fælles filer\Adobe
2007-10-09 08:13 --------- d-----w C:\Programmer\iTunes
2007-10-09 08:13 --------- d-----w C:\Programmer\iPod
2007-10-09 08:11 --------- d-----w C:\Programmer\Apple Software Update
2007-10-09 08:09 --------- d-----w C:\Programmer\Fælles filer
2007-10-07 07:20 --------- d-----w C:\Programmer\Picasa2
2007-10-06 10:11 --------- d-----w C:\Programmer\Java
2007-09-22 04:56 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-09-11 13:59 --------- d-----w C:\Programmer\Pegasus Imaging
2007-09-09 07:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-09-09 07:30 --------- d-----w C:\Programmer\Fælles filer\Macrovision Shared
2007-09-07 13:30 --------- d-----w C:\Programmer\Fælles filer\Canon
2007-09-07 11:05 --------- d-----w C:\Programmer\QuickTime
2007-09-06 13:33 --------- d-----w C:\Programmer\Google
2007-09-06 11:56 646,592 ----a-w C:\WINDOWS\system32\ad2mcmpgdec.dll
2007-09-06 11:56 440,256 ----a-w C:\WINDOWS\system32\ad2mpegin.dll
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-03 04:04 --------- d-----w C:\Programmer\SpywareBlaster
2007-08-28 09:28 --------- d-----w C:\Programmer\FirstClass
2007-08-22 15:48 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-08-22 15:48 249,856 ------w C:\WINDOWS\Setup1.exe
2007-08-22 15:48 --------- d-----w C:\Programmer\Power DVD Player
2007-08-22 15:48 --------- d-----w C:\Programmer\CodecInstaller
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 17:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:12 2,874,926 ----a-w C:\Programmer\FLV PlayerRCATSetup.exe
2007-04-17 05:11 25,980,320 ----a-w C:\Programmer\FLV PlayerRCSetup.exe
2006-09-11 16:13 5,348 ----a-w C:\Programmer\IkeCrash.log
2006-09-11 16:13 4,772 ----a-w C:\Programmer\Ike.log
2006-09-11 16:13 21 ----a-w C:\Programmer\unlocked_missions.xml
2006-09-11 16:13 19 ----a-w C:\Programmer\unlocked_heroes.xml
2006-09-11 16:13 14 ----a-w C:\Programmer\best_times.xml
2005-05-11 22:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2001-11-10 00:58 8,495 ----a-w C:\Programmer\SetupReg.exe
2001-11-10 00:58 329 ----a-w C:\Programmer\setup.bat
2001-11-10 00:49 113,480,648 ----a-w C:\Programmer\rsb.uha
2001-11-10 00:23 5,757,681 ----a-w C:\Programmer\GhostRecon.exe
2001-11-10 00:23 15,873,229 ----a-w C:\Programmer\myth.pak
2001-10-01 14:51 5,427,265 ----a-w C:\Programmer\igor.exe
2001-09-28 19:16 19,748 ----a-w C:\Programmer\ReadMe.txt
2001-09-28 14:16 10,134 ----a-w C:\Programmer\ubicom.ico
2001-09-20 15:42 3,434 ----a-w C:\Programmer\IgorHelp.txt
2001-09-18 18:24 98,304 ----a-r C:\Programmer\eax.dll
2001-09-18 18:24 413,766 ----a-r C:\Programmer\ScriptEd.dll
2001-09-18 18:24 31,678 ----a-r C:\Programmer\IgorScripting.txt
2001-09-18 18:24 24,708 ----a-r C:\Programmer\ike.sdf
2001-09-18 14:07 766 ----a-w C:\Programmer\RSEblack.ico
2001-09-18 14:07 7,078 ----a-w C:\Programmer\Ghost.ico
2001-08-10 07:27 163,088 ----a-r C:\Programmer\dbghelp.dll
2001-02-24 15:43 56,832 ----a-w C:\Programmer\mythxuha.exe
2000-08-06 22:11 20,992 ----a-w C:\Programmer\mythxpak.exe
1998-09-01 13:28 297,984 ----a-w C:\Programmer\myth.acm
2006-01-19 17:55:40 56 --sh--r C:\WINDOWS\system32\F6A1580A5C.sys
2006-01-19 17:55:45 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 07:29]
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" []
"LogitechQuickCamRibbon"="C:\Programmer\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 10:53]
"SPAMfighter Agent"="C:\Programmer\SPAMfighter\SFAgent.exe" [2007-06-25 15:03]
"hcenter"="C:\Programmer\Support.com\bin\tgcmd.exe" [2005-04-08 12:38]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 14:47]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" []
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-06-29 06:24]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Programmer\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 21:46]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 02:53]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-29 08:51]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-07-25 17:27]
"Power DVD Player"="C:\Programmer\Power DVD Player\PowerDVDPlayer.exe" [2007-08-20 10:35]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Picasa Media Detector"=C:\Programmer\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL 2007-07-25 17:27 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Harman Kardon TC 30 Remote.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Harman Kardon TC 30 Remote.lnk
backup=C:\WINDOWS\pss\Harman Kardon TC 30 Remote.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Image Zone Hurtig start.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\HP Image Zone Hurtig start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Hurtig start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Hurtig søgning.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Microsoft Hurtig søgning.lnk
backup=C:\WINDOWS\pss\Microsoft Hurtig søgning.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Søren^Menuen Start^Programmer^Start^Picture Motion Browser Media Check Tool.lnk]
path=C:\Documents and Settings\Søren\Menuen Start\Programmer\Start\Picture Motion Browser Media Check Tool.lnk
backup=C:\WINDOWS\pss\Picture Motion Browser Media Check Tool.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Programmer\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Programmer\Logitech\QuickCam10\QuickCam10.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
"C:\Programmer\Fælles filer\Logitech\LComMgr\LVComSX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Programmer\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Programmer\Google\Gmail Notifier\gnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"PixVue"=2 (0x2)
"iPod Service"=3 (0x3)
"AdobeActiveFileMonitor5.0"=2 (0x2)
R0 viaagp1;VIA AGP Filter;C:\WINDOWS\system32\DRIVERS\viaagp1.sys
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
S0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys
S3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5455027a-822a-11db-91b7-005070c841f4}]
AutoRun\command - L:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-10-21 07:26:26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{4EA74684-89A0-4E29-B18D-713D2D49354E}.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-21 13:28:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-21 13:29:01
C:\ComboFix-quarantined-files.txt ... 2007-07-16 22:54
C:\ComboFix2.txt ... 2007-10-21 13:10
C:\ComboFix3.txt ... 2007-07-16 22:54
.
--- E O F ---