ComboFix 07-10-29.1** - Finn 2007-10-31 6:53:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.78 [GMT 1:00]
Running from: C:\Documents and Settings\Finn\Lokale indstillinger\Temporary Internet Files\Content.IE5\LR5I6EZX\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-31 )))))))))))))))))))))))))))))))
.
2007-10-31 06:51 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-30 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-30 20:23 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-10-30 20:23 <DIR> d-------- C:\Programmer\Fælles filer\Wise Installation Wizard
2007-10-30 20:23 <DIR> d-------- C:\Documents and Settings\Finn\Application Data\SUPERAntiSpyware.com
2007-10-30 20:01 <DIR> d-------- C:\Programmer\CCleaner
2007-10-11 08:34 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-09-27 20:22 <DIR> d-------- C:\Programmer\TrackMania Nations ESWC
2007-09-04 21:44 <DIR> d-------- C:\Documents and Settings\Finn\Phone Browser
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-30 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-30 15:55 --------- d-----w C:\Programmer\XoftSpySE
2007-10-07 14:51 --------- d-----w C:\Programmer\Norton Utilities
2007-10-06 07:04 --------- d-----w C:\Programmer\Google
2007-09-13 21:20 --------- d-----w C:\Programmer\MSN Messenger
2007-09-10 18:51 --------- d-----w C:\Programmer\Avast antivirus
2007-09-07 15:32 --------- d-----w C:\Documents and Settings\Finn\Application Data\Skype
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-09 13:19 582,656 ----a-w C:\WINDOWS\system32\rpcrt4.dll
2007-01-07 15:08 1,035,271 ----a-w C:\Programmer\wrar362.exe
2007-01-07 13:09 18,046,088 ----a-w C:\Programmer\tdcnetsupport.exe
2006-02-06 21:12 17,952,344 ----a-w C:\Programmer\nuvi350_270.exe
2005-12-15 09:58 44,640 ----a-w C:\Documents and Settings\Finn\Application Data\GDIPFONTCACHEV1.DAT
2004-02-21 11:16 560 ----a-w C:\Documents and Settings\Finn\PCDOC.BAT
2004-01-16 18:51 6,660,608 ----a-w C:\Programmer\avg6562fu_free.exe
2003-07-10 16:54 10,504,000 ----a-w C:\Programmer\stjerne.xxx.txt
2003-07-08 21:38 297,528 ----a-w C:\Programmer\dxwebsetup.exe
2003-06-17 20:30 3,750,576 ----a-w C:\Programmer\zaSetup_37_143.exe
2003-05-13 17:07 1,438,467 ----a-w C:\Programmer\dwyco297.exe
2003-04-16 21:06 16,434,414 ----a-w C:\Programmer\JMeeting.exe
2003-04-13 16:32 13,263,480 ----a-w C:\Programmer\AcroReader51_DAN_full.exe
2003-04-13 15:46 9,440,776 ----a-w C:\Programmer\AcroReader51_DAN.exe
2002-04-26 11:23 49,152 ----a-w C:\Programmer\PopupKiller.exe
2001-09-15 20:56 258,048 ----a-w C:\Programmer\SETUP1.EXE
2000-07-14 22:00 73,216 ----a-w C:\Programmer\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 09:04]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-24 09:04]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2004-07-01 12:33]
"nwiz"="nwiz.exe" [2004-03-24 09:04 C:\WINDOWS\system32\nwiz.exe]
"LVCOMS"="C:\Programmer\Fælles filer\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 16:54]
"LogitechVideoTray"="C:\Programmer\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"LogitechVideoRepair"="C:\Programmer\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LogitechImageStudioTray"="C:\Programmer\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 17:31]
"LogitechGalleryRepair"="C:\Programmer\Logitech\ImageStudio\ISStart.exe" [2002-12-10 17:32]
"C-Media Mixer"="Mixer.exe" [2002-10-15 17:00 C:\WINDOWS\mixer.exe]
"avast!"="C:\PROGRA~1\AVASTA~1\ashDisp.exe" [2007-09-06 11:06]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" [2006-05-03 22:20]
"PCSuiteTrayApplication"="C:\Programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCamRT.exe"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 01:53]
"Eyeball Chat"="C:\Programmer\Eyeball\Eyeball Chat\EyeballChat.exe" [2002-10-11 14:52]
"Yahoo! Pager"="C:\Programmer\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 13:08]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
S3 Amps2prt;Addison Technology PS/2 Port Mouse Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys
S3 NtApm;NT Apm/Ældre grænsefladedriver;C:\WINDOWS\system32\DRIVERS\NtApm.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-31 03:07:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
"2007-06-12 20:26:49 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Programmer\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-31 06:57:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ServiceDll"="%SystemRoot%\System32\browser.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\C:]
.
Completion time: 2007-10-31 6:58:53
.
--- E O F ---