ComboFix 07-12-21.4 - Rikke 2007-12-22 19:45:29.10 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1030.18.244 [GMT 1:00]
Running from: C:\Documents and Settings\Rikke\Skrivebord\Spywarefri\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.
2007-12-22 19:28 . 2006-10-08 17:49 194 --ah----- C:\boot.ini
2007-12-22 18:58 . 2007-12-22 18:58 <DIR> d-------- C:\Documents and Settings\Rikke\DoctorWeb
2007-12-22 15:48 . 2007-12-22 15:44 118,784 --a------ C:\WINDOWS\system32\ruu.exe
2007-12-22 15:46 . 2007-12-22 15:44 118,784 --a------ C:\WINDOWS\system32\mcqfwcciog.exe
2007-12-22 15:44 . 2007-12-22 15:44 118,784 --a------ C:\WINDOWS\system32\hnjobcxhxjh.exe
2007-12-17 20:58 . 2007-12-17 20:58 <DIR> d-------- C:\Programmer\Submachine4_at
2007-12-10 22:11 . 2007-12-10 22:11 <DIR> d-------- C:\Programmer\Amazonia_at
2007-12-03 16:30 . 2007-12-03 16:30 <DIR> d-------- C:\Programmer\LawOrderVengefulHeart_at
2007-12-03 07:25 . 2007-12-03 07:25 <DIR> d-------- C:\Programmer\LawandOrderDarkObsession_at
2007-12-02 20:07 . 2007-12-02 20:07 <DIR> d-------- C:\TMOTM
2007-12-02 20:07 . 2007-12-02 20:07 <DIR> d-------- C:\Programmer\MysteryoftheMummy_at
2007-12-01 15:39 . 2007-12-01 15:40 <DIR> d-------- C:\Programmer\DreamChronicles_at
2007-11-30 22:13 . 2007-11-30 22:13 <DIR> d-------- C:\Documents and Settings\Rikke\Application Data\Big Fish Games
2007-11-30 22:12 . 2007-11-30 22:12 <DIR> d-------- C:\Programmer\Azada_at
2007-11-30 12:14 . 2007-11-30 12:14 <DIR> d-------- C:\Programmer\MahjonggArtifacts2_at
2007-11-30 11:22 . 2007-11-30 11:22 <DIR> d-------- C:\Programmer\FatalHearts_at
2007-11-25 14:54 . 2007-11-25 14:55 <DIR> d-------- C:\Documents and Settings\Rikke\Application Data\AdobeAUM
2007-11-24 09:11 . 2007-11-24 09:11 <DIR> d-------- C:\Programmer\HeroesofHellas_at
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 18:31 3,214 ----a-w C:\WINDOWS\system32\tmp.reg
2007-11-21 18:23 --------- d-----w C:\Documents and Settings\Rikke\Application Data\Jane s Hotel
2007-11-21 18:22 --------- d-----w C:\Programmer\JanesHotel_at
2007-11-18 12:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-17 21:32 --------- d-----w C:\Programmer\CCleaner
2007-11-17 21:25 --------- d-----w C:\Programmer\Fælles filer\Java
2007-11-15 16:13 --------- d-----w C:\Programmer\Carlo Gavazzi
2007-11-13 18:22 --------- d-----w C:\Programmer\TrojanHunter 5.0
2007-11-09 14:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-09 14:51 --------- d-----w C:\Programmer\SUPERAntiSpyware
2007-11-09 14:51 --------- d-----w C:\Documents and Settings\Rikke\Application Data\SUPERAntiSpyware.com
2007-11-08 19:31 --------- d-----w C:\Programmer\Trend Micro
2007-10-22 17:51 50,896 ----a-w C:\WINDOWS\system32\drivers\BdFileSpy.sys
2007-10-22 17:51 14,152 ----a-w C:\WINDOWS\system32\client_cc.dll
2007-10-17 09:52 774,144 ----a-w C:\Programmer\RngInterstitial.dll
2007-10-03 22:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2007-01-09 11:25 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2003-08-27 14:52 461 ----a-w C:\Programmer\INSTALL.LOG
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-09 11:00]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-10-22 18:51]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-21 17:16]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINDOWS\system32\CTHELPER.EXE]
"Jet Detection"="C:\Programmer\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
"Lexmark 5200 series"="C:\Programmer\Lexmark 5200 series\lxbtbmgr.exe" [2004-02-24 18:10]
"hcenter"="C:\Programmer\Support.com\bin\tgcmd.exe" [2005-04-08 12:38]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-10-22 18:51]
"LXBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll" [2004-02-23 14:47]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2001-10-09 11:00]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"hnjobcxhxjh"="C:\WINDOWS\System32\hnjobcxhxjh.exe" [2007-12-22 15:44]
"THGuard"="C:\Programmer\TrojanHunter 5.0\THGuard.exe" [2007-09-09 09:31]
"ruu"="C:\WINDOWS\System32\ruu.exe" [2007-12-22 15:44]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"hnjobcxhxjh"="C:\WINDOWS\System32\hnjobcxhxjh.exe" [2007-12-22 15:44]
"ruu"="C:\WINDOWS\System32\ruu.exe" [2007-12-22 15:44]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-09 11:00]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56]
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ErrorSafe]
C:\Programmer\Error Safe Free\ers.exe /min
R1 ewido security suite driver;ewido security suite driver;C:\Programmer\ewido\security suite\guard.sys [2004-11-22 15:15]
R1 VFILT;BullGuard Firewall Kernel Driver;C:\Programmer\BullGuard Software\BullGuard\FwEngine\FiltNt.sys [2006-10-04 10:24]
R2 BdFileSpy;BullGuard File Monitor Driver;C:\WINDOWS\System32\drivers\BdFileSpy.sys [2007-10-22 18:51]
R2 BsFileScan;BullGuard File Scan Service;C:\WINDOWS\System32\svchost.exe -k BullGuard []
R2 BsFwall;BullGuard Firewall Service;C:\WINDOWS\System32\svchost.exe -k BullGuardFw []
R3 FA312;Driver til NETGEAR FA330/FA312/FA311 Fast Ethernet-netværkskort;C:\WINDOWS\System32\DRIVERS\FA312nd5.sys [2001-08-17 20:12]
R3 Reconn;BullGuard Email Monitor;C:\Programmer\BullGuard Software\BullGuard\reconn.sys [2007-04-18 08:44]
S2 lwiiqe8aumozt;Print Spooler Service;C:\WINDOWS\System32\hnjobcxhxjh.exe /service []
S3 ADBLOCK.DLL;BullGuard Firewall Adware Plugin;C:\Programmer\BullGuard Software\BullGuard\FwEngine\AdBlock.dll [2006-10-04 10:24]
S3 HTMLFILT.DLL;BullGuard Firewall HTML Plugin;C:\Programmer\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll [2006-10-04 10:24]
S3 HTTPFILT.DLL;BullGuard Firewall HTTP Plugin;C:\Programmer\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll [2006-10-04 10:24]
S3 PROTECT.DLL;BullGuard Firewall Protection Plugin;C:\Programmer\BullGuard Software\BullGuard\FwEngine\Protect.dll [2006-10-04 10:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy
BullGuardFw REG_MULTI_SZ BsFwall
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-22 19:47:04
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-22 19:47:37
C:\ComboFix3.txt ... 2007-11-26 23:09
C:\ComboFix2.txt ... 2007-11-28 16:34
.
2007-12-15 10:31:44 --- E O F ---