ComboFix 08-01-07.5 - Jesper 2008-01-09 17:41:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.531 [GMT 1:00]
Running from: C:\Documents and Settings\Jesper\Skrivebord\Eksperten\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-09 to 2008-01-09 )))))))))))))))))))))))))))))))
.
2008-01-09 17:40 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-09 17:35 . 2008-01-09 17:35 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-08 20:25 . 2008-01-08 20:25 <DIR> d-------- C:\Documents and Settings\Administrator.JEVER.000\Application Data\SUPERAntiSpyware.com
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> d-------- C:\Documents and Settings\Administrator.JEVER.000\Skrivebord
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> d--h----- C:\Documents and Settings\Administrator.JEVER.000\Skabeloner
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> d--h----- C:\Documents and Settings\Administrator.JEVER.000\Printere
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> dr------- C:\Documents and Settings\Administrator.JEVER.000\Menuen Start
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> d--h----- C:\Documents and Settings\Administrator.JEVER.000\Lokale indstillinger
2008-01-08 20:20 . 2004-09-10 11:34 <DIR> dr------- C:\Documents and Settings\Administrator.JEVER.000\Foretrukne
2008-01-08 20:20 . 2004-09-10 11:34 <DIR> dr------- C:\Documents and Settings\Administrator.JEVER.000\Dokumenter
2008-01-08 20:20 . 2006-09-08 10:04 <DIR> d-------- C:\Documents and Settings\Administrator.JEVER.000\Bluetooth Software
2008-01-08 20:20 . 2006-09-08 10:19 <DIR> d-------- C:\Documents and Settings\Administrator.JEVER.000\Application Data\Symantec
2008-01-08 20:20 . 2006-09-08 10:14 <DIR> d-------- C:\Documents and Settings\Administrator.JEVER.000\Application Data\IBM
2008-01-08 20:20 . 2004-09-10 11:19 <DIR> d--h----- C:\Documents and Settings\Administrator.JEVER.000\Andre computere
2008-01-08 20:12 . 2008-01-08 20:12 <DIR> d-------- C:\Documents and Settings\Jesper\Application Data\SUPERAntiSpyware.com
2008-01-08 20:12 . 2008-01-08 20:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-08 20:11 . 2008-01-08 20:11 <DIR> d-------- C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-05 15:45 . 2008-01-07 20:47 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-05 15:45 . 2008-01-05 15:45 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-05 02:17 . 2008-01-05 02:18 632 --a------ C:\WINDOWS\Sofplat.INI
2008-01-02 23:30 . 2008-01-02 23:30 8,192 --ahs---- C:\WINDOWS\Thumbs.db
2007-12-25 10:53 . 2007-11-29 21:31 782,336 -ra------ C:\WINDOWS\system32\tmp5761.tmp
2007-12-25 10:53 . 2007-11-29 21:31 782,336 -ra------ C:\WINDOWS\system32\tmp5760.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 17:04 --------- d-----w C:\Documents and Settings\Jesper\Application Data\uTorrent
2008-01-08 17:03 --------- d-----w C:\Documents and Settings\Jesper\Application Data\Metacafe
2008-01-08 17:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Metacafe
2008-01-05 23:00 5,427 ----a-w C:\WINDOWS\system32\EGATHDRV.SYS
2008-01-05 13:50 --------- d-----w C:\Documents and Settings\Jesper\Application Data\LimeWire
2007-12-25 09:53 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-12-25 09:53 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-12-25 09:53 --------- d-----w C:\Programmer\OpenAL
2007-12-06 17:51 --------- d-----w C:\Programmer\Real
2007-12-06 17:51 --------- d-----w C:\Programmer\Fælles filer\xing shared
2007-12-06 17:51 --------- d-----w C:\Programmer\Fælles filer\Real
2007-12-04 16:32 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-12-04 16:25 --------- d-----w C:\Programmer\EA SPORTS
2007-11-14 16:20 --------- d-----w C:\Programmer\utorrent
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 17:17 --------- d-----w C:\Documents and Settings\Jesper\Application Data\Software Defender
2007-10-30 23:26 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:44 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:44 1,291,776 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-25 16:43 8,472,064 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-20 05:01 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-20 05:01 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-10 23:52 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:52 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:52 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:52 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:52 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:52 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:52 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:52 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:52 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:52 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:52 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:52 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:52 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:52 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:52 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:52 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:52 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:52 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:52 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:52 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:52 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 23:52 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 10:58 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 05:46 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-01-28 19:40 81,920 ----a-w C:\Documents and Settings\Jesper\Application Data\ezpinst.exe
2007-01-28 19:40 47,360 ----a-w C:\Documents and Settings\Jesper\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 16:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\lib\NMBgMonitor.exe" [2006-03-01 19:43 90112]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 14:50 88204 C:\WINDOWS\AGRSMMSG.exe]
"nod32kui"="C:\jesper\Programmer\Eset\nod32kui.exe" [2007-02-20 18:11 921600]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 15:26 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 15:22 77824]
"Genvej til egenskabsside for High Definition Audio"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"PMHandler"="C:\WINDOWS\system32\PMHandler.exe" [2006-05-20 09:28 24576]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2005-10-28 17:58 761945]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 15:25 98304]
"cssauthe"="C:\Programmer\IBM ThinkVantage\Client Security Solution\cssauthe.exe" [2005-12-21 18:08 1988144]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-14 23:10 1236992]
"ACWLIcon"="C:\Programmer\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 12:59 98304]
"ACTray"="C:\Programmer\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 13:09 409600]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-27 16:00 158720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpeedStartup"="C:\jesper\Programmer\Speed Startup\speedstartup.exe" [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\jesper\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\jesper\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Jesper\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2006-02-28 00:21 49152 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-12-20 20:46 24576 C:\WINDOWS\system32\tphklock.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Ashampoo Magical Defrag.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Ashampoo Magical Defrag.lnk
backup=C:\WINDOWS\pss\Ashampoo Magical Defrag.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^BTTray.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Metacafe.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Metacafe.lnk
backup=C:\WINDOWS\pss\Metacafe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jesper^Menuen Start^Programmer^Start^Metacafe.lnk]
path=C:\Documents and Settings\Jesper\Menuen Start\Programmer\Start\Metacafe.lnk
backup=C:\WINDOWS\pss\Metacafe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cFosSpeed]
-ra------ 2006-05-19 14:14 782336 C:\Jesper\Programmer\cFosSpeed.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 14:47 57344 C:\jesper\programmer\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-11-12 11:48 157592 C:\jesper\Programmer\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DailyDonkeyBot]
C:\Documents and Settings\Jesper\Skrivebord\BETTINGS\Lay2Lose\DailyDonkeyBot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-07-10 08:18 270648 C:\jesper\Programmer\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
--a------ 2005-12-07 01:00 106496 C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 11:55 5674352 C:\Programmer\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPass]
--a------ 2006-02-28 00:20 2076672 C:\Program Files\Softex\OmniPass\scureapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2005-10-28 20:08 335872 C:\Programmer\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 05:24 286720 C:\Programmer\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedStartup]
C:\jesper\Programmer\Speed Startup\speedstartup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-04-13 03:48 36975 C:\Programmer\Java\jre1.5.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2007-04-23 15:46 1318128 C:\jesper\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\suScheduler]
--a------ 2005-08-01 17:32 40960 C:\Programmer\ThinkVantage\SystemUpdate\UCLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-12-06 18:51 185632 C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPHOTKEY]
--a------ 2005-12-20 20:47 94208 C:\Programmer\Lenovo\HOTKEY\TPHKMGR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPWAUDAP]
--a------ 2005-12-10 08:29 24064 C:\Programmer\Lenovo\HOTKEY\TpWAudAp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-11-21 18:38 35328 C:\jesper\Programmer\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate"=3 (0x3)
"Automatisk LiveUpdate-planlægning"=2 (0x2)
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 09:27]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2006-01-13 00:33]
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys [2005-12-21 14:09]
R2 ibmfilter;ibmfilter;C:\WINDOWS\system32\drivers\ibmfilter.sys [2005-12-21 17:14]
R2 smi2;smi2;C:\Programmer\SMI2\smi2.sys [2005-12-21 16:45]
S0 ANCSQ;ANCSQ;C:\WINDOWS\system32\drivers\ANCSQ.sys []
S3 CH341SER;CH341SER;C:\WINDOWS\system32\Drivers\CH341SER.SYS [2005-02-26 17:00]
S4 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 23:07]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 05:13:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-09 17:46:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Programmer\ThinkPad\ConnectUtilities\AcSvcStub.dll
-> C:\Programmer\ThinkPad\ConnectUtilities\AcLocSettings.dll
-> C:\Programmer\ThinkPad\ConnectUtilities\ACHelper.dll
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
-> C:\WINDOWS\system32\tphklock.dll
.
Completion time: 2008-01-09 17:46:47
.
2007-12-13 02:05:12 --- E O F ---