ComboFix 08-02.05.3 - Jan Thulstrup 2008-02-08 14:19:12.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.57 [GMT 1:00]
Running from: C:\Documents and Settings\Jan Thulstrup\Skrivebord\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 10:43 . 2008-02-08 10:43 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-02-07 21:47 . 2008-02-07 21:47 <DIR> d-------- C:\Programmer\CCleaner
2008-01-31 20:08 . 2008-01-31 20:08 <DIR> d-------- C:\Programmer\DNA
2008-01-31 13:36 . 2008-01-31 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-31 13:35 . 2008-01-31 13:35 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2008-01-17 16:30 . 2008-01-17 16:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\espionServerData
2008-01-17 16:25 . 2008-01-17 16:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-17 12:21 . 2008-01-17 12:21 <DIR> d-------- C:\Programmer\Fælles filer\Macrovision Shared
2008-01-17 12:09 . 2008-01-17 12:08 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-17 12:09 . 2008-01-17 12:08 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-01-17 12:09 . 2008-01-17 12:08 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-11 20:53 . 2008-01-11 20:53 <DIR> d-------- C:\Programmer\XnView
2008-01-11 09:58 . 2004-08-27 02:53 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-01-11 09:58 . 2001-10-04 17:07 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-01-10 13:09 . 2008-01-10 13:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\muvee Technologies
2008-01-10 13:06 . 2008-01-14 17:16 20 ---h----- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-01-10 12:38 . 2006-10-25 14:14 5,709,824 -ra------ C:\WINDOWS\system32\NkNEFPlugin.dll
2008-01-10 12:38 . 2003-03-19 13:28 2,179,072 --a------ C:\WINDOWS\system32\mfc71d.dll
2008-01-10 12:38 . 2003-03-19 12:04 765,952 --a------ C:\WINDOWS\system32\msvcp71d.dll
2008-01-10 12:38 . 2003-03-19 12:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll
2008-01-10 12:37 . 2005-12-05 13:21 495,616 -ra------ C:\WINDOWS\system32\DRAGNKL1.dll
2008-01-10 12:37 . 2006-08-10 15:35 180,224 -ra------ C:\WINDOWS\system32\Strato4.dll
2008-01-10 12:37 . 2005-12-05 16:13 180,224 -ra------ C:\WINDOWS\system32\picn1120.dll
2008-01-10 12:37 . 2005-12-05 16:13 155,648 -ra------ C:\WINDOWS\system32\picn1020.dll
2008-01-10 12:37 . 2005-12-05 17:24 110,592 -ra------ C:\WINDOWS\system32\RCSigProc.dll
2008-01-10 12:37 . 2005-12-05 17:24 76,800 -ra------ C:\WINDOWS\system32\RedEye.dll
2008-01-10 12:37 . 2005-12-05 16:13 48,128 -ra------ C:\WINDOWS\system32\picn20.dll
2008-01-10 12:36 . 2008-01-10 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ultima_T15
2008-01-10 12:36 . 2008-01-10 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EnterNHelp
2008-01-10 12:36 . 2008-01-14 17:20 0 ---h----- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-01-10 12:35 . 2008-01-10 12:35 <DIR> d-------- C:\Programmer\Fælles filer\Nikon
2008-01-10 12:35 . 2001-10-09 10:02 434,176 --a------ C:\WINDOWS\system32\DC120V15_32.DLL
2008-01-10 12:35 . 2002-09-11 11:00 181,248 --a------ C:\WINDOWS\system32\LFPNG12N.DLL
2008-01-10 12:35 . 2002-09-11 10:50 60,416 --a------ C:\WINDOWS\system32\LFPCT12N.DLL
2008-01-10 12:35 . 2002-09-11 10:50 36,864 --a------ C:\WINDOWS\system32\LFPSD12N.DLL
2008-01-10 12:35 . 2002-09-11 10:49 30,720 --a------ C:\WINDOWS\system32\LFBMP12N.DLL
2008-01-10 12:35 . 2002-09-11 10:50 26,112 --a------ C:\WINDOWS\system32\LFPCX12N.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 11:08 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-12 08:51 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-12 08:51 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-12 08:51 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-12 08:51 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-14 07:28 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 02:53 15360]
"NBJ"="C:\Programmer\Ahead\Nero BackItUp\NBJ.exe" [2005-08-09 14:28 1961984]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 09:01 68856]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"BitTorrent DNA"="C:\Programmer\DNA\btdna.exe" [2008-01-31 20:08 286528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hcenter"="C:\Programmer\Support.com\bin\tgcmd.exe" [2005-04-08 12:38 1757184]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" [2007-03-01 12:04 52840]
"OpwareSE2"="C:\Programmer\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 11:00 49152]
"Windows Defender"="C:\Programmer\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"Symantec PIF AlertEng"="C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-27 02:53 110592 C:\WINDOWS\system32\bthprops.cpl]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Adobe Photo Downloader"="C:\Programmer\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 00:43 67488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-27 02:53 15360]
"Picasa Media Detector"="C:\Programmer\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoTrayItemsDisplay"= 00000000
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="kdreg.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12Voip]
C:\Programmer\12Voip.com\12Voip\12Voip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Programmer\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Programmer\Messenger\MSMSGS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPAMfighter Agent]
--a------ 2007-10-25 15:29 308880 C:\Programmer\SPAMfighter\SFAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-16 09:01 68856 C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipDiscount]
C:\Programmer\VoipDiscount.com\VoipDiscount\VoipDiscount.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
C:\Programmer\VoipStunt.com\VoipStunt\VoipStunt.exe
R0 viaagp;VIA AGP-busfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-04 08:07]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Programmer\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 00:45]
R2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:46]
R2 SPAMfighter Update Service;SPAMfighter Update Service;C:\Programmer\SPAMfighter\sfus.exe [2007-10-25 15:29]
R2 WinDriver;WinDriver;C:\WINDOWS\system32\drivers\WINDRVR.SYS [2002-07-01 11:07]
S2 Winkwio;Winkwio;C:\WINDOWS\System32\Winkwio.exe []
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 12:05:40 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programmer\Windows Defender\MpCmdRun.exe
"2008-02-01 20:02:16 C:\WINDOWS\Tasks\Norton AntiVirus - Kør fuld systemskanning - Jan Thulstrup.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-08 14:24:32
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-08 14:26:33
ComboFix-quarantined-files.txt 2008-02-08 13:26:22
.
2007-12-14 14:47:35 --- E O F ---