ComboFix 07-11-01.1** - BKK 2007-11-01 19:45:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.1381 [GMT 1:00]Running from: C:\Documents and Settings\BKK\Skrivebord\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\BKK\Skrivebord\internet.lnk
.
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.
2007-11-01 19:44 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-31 22:38 <DIR> d-------- C:\Programmer\Registry Repair
2007-10-19 20:37 <DIR> d-------- C:\Documents and Settings\BKK\Application Data\Joost
2007-10-19 20:36 <DIR> d-------- C:\Programmer\Joost
2007-10-19 20:06 <DIR> d-------- C:\WINDOWS\temp2
2007-10-19 20:06 <DIR> d-------- C:\Program Files
2007-10-19 20:06 327,168 --a------ C:\WINDOWS\IsUn0406.exe
2007-10-19 20:05 <DIR> d-------- C:\WINDOWS\system32\Adobe
2007-10-16 19:25 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2007-10-16 19:25 19,424 --a------ C:\WINDOWS\system32\drivers\ggsemc.sys
2007-10-10 19:22 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-01 17:58 --------- d-----w C:\Programmer\SUPERAntiSpyware
2007-11-01 15:39 --------- d-----w C:\Documents and Settings\BKK\Application Data\AdobeUM
2007-11-01 15:33 --------- d-----w C:\Documents and Settings\BKK\Application Data\AVG7
2007-10-31 20:35 --------- d-----w C:\Programmer\Folder Guard Pro
2007-10-31 19:05 --------- d-----w C:\Programmer\SpywareGuard
2007-10-31 18:58 --------- d-----w C:\Programmer\MSN Messenger
2007-10-31 18:54 --------- d-----w C:\Programmer\Google
2007-10-31 18:54 --------- d-----w C:\Programmer\Fælles filer\LightScribe
2007-10-29 21:19 --------- d-----w C:\Documents and Settings\BKK\Application Data\Folder Guard
2007-10-28 18:12 --------- d-----w C:\Programmer\Java
2007-10-19 19:05 --------- d-----w C:\Programmer\Hewlett-Packard
2007-10-17 19:24 --------- d-----w C:\Programmer\Fælles filer\Teleca Shared
2007-10-16 18:40 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-10-16 18:40 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
2007-09-23 09:17 --------- d-----w C:\Programmer\Pinnacle
2007-09-23 09:05 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-09-23 09:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2007-09-18 19:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-09-02 13:02 --------- d-----w C:\Programmer\SpywareBlaster
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-22 18:59]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 08:25]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 08:22]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 08:26]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 08:34 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 08:29]
"nwiz"="nwiz.exe" [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 08:29]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2005-11-30 11:49]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" [2006-12-07 23:08]
"hpfsched"="C:\WINDOWS\hpfsched.exe" [1999-03-03 10:39]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-11 00:26]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-08-30 05:47]
"RegistryRepair"="C:\Programmer\Registry Repair\RegistryRepair.exe" [2006-02-13 06:21]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 16:53]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-27 20:25]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 11:08]
C:\Documents and Settings\BKK\Menuen Start\Programmer\Start\
SpywareGuard.lnk - C:\Programmer\SpywareGuard\sgmain.exe [2003-08-29 18:05:35]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
EdgeCLS11.00.lnk - C:\Programmer\EdgeCAM\Cam\edgecls.exe [2006-12-14 17:00:44]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL 2007-05-05 19:18 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FolderGuard]
C:\Programmer\Folder Guard Pro\FGH32.DLL 2006-04-19 23:00 94208 C:\Programmer\Folder Guard Pro\FGH32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExtraFilmHemmaAgent]
"C:\Programmer\ExtraFilm Hjemme\Agent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
"C:\Programmer\Lexmark X1100 Series\lxbkbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDrvCheck]
"C:\Programmer\Pinnacle\Instant PhotoAlbum\programs\PSDrvCheck.exe" -CheckReg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys
R1 ewido security suite driver;ewido security suite driver;\??\C:\Programmer\ewido\security suite\guard.sys
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys
R2 FGUARD32;FGUARD32;\??\C:\Programmer\Folder Guard Pro\FGUARD32.SYS
R2 PDRJNDL;PDRJNDL;\??\C:\Programmer\Dekart\Private Disk Light\PDRJNDL.SYS
R2 PRVDISK;PRVDISK;\??\C:\Programmer\Dekart\Private Disk Light\PRVDISK.SYS
S3 29a5472a-34d2-47dc-8861-c86c71dede5c;29a5472a-34d2-47dc-8861-c86c71dede5c;\??\D:\CDS300\cds300.dll
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-01 19:46:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-01 19:47:06
.
--- E O F ---