ComboFix 08-05-21.3 - Malene 2008-05-23 18:22:27.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1030.18.1071 [GMT 2:00]
Running from: C:\Users\Malene\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\ACER.exe
C:\Windows\System32\Desktop_.ini
C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-23 17:52 . 2008-05-23 17:52 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-05-23 17:52 . 2008-05-23 17:52 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-05-23 17:51 . 2008-05-23 17:51 <DIR> d-------- C:\Users\Malene\AppData\Roaming\SUPERAntiSpyware.com
2008-05-23 17:51 . 2008-05-23 17:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-23 17:50 . 2008-05-23 17:50 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-23 17:47 . 2008-05-23 17:47 <DIR> d-------- C:\Program Files\CCleaner
2008-05-23 16:03 . 2008-05-23 16:51 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-23 16:01 . 2008-05-23 16:01 10,520 --a------ C:\Windows\System32\avgrsstx.dll
2008-05-23 16:00 . 2008-05-23 16:02 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-05-23 16:00 . 2008-05-23 16:00 <DIR> d-------- C:\Users\All Users\avg8
2008-05-23 16:00 . 2008-05-23 16:00 <DIR> d-------- C:\ProgramData\avg8
2008-05-23 16:00 . 2008-05-23 16:00 <DIR> d-------- C:\Program Files\AVG
2008-05-23 16:00 . 2008-05-23 16:00 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-05-23 15:28 . 2008-05-23 15:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 14:53 . 2008-05-23 14:53 <DIR> d-------- C:\Users\All Users\CheckPoint
2008-05-23 14:53 . 2008-05-23 14:53 <DIR> d-------- C:\ProgramData\CheckPoint
2008-05-23 14:53 . 2008-05-23 14:53 <DIR> d-------- C:\Program Files\Zone Labs
2008-05-23 14:53 . 2008-03-03 15:05 1,086,952 --a------ C:\Windows\System32\zpeng24.dll
2008-05-23 14:53 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0014.TMP
2008-05-23 14:52 . 2008-05-23 14:53 <DIR> d-------- C:\Windows\System32\ZoneLabs
2008-05-23 14:52 . 2008-05-23 18:13 352,615 --ah----- C:\Windows\System32\drivers\vsconfig.xml
2008-05-23 14:52 . 2008-03-03 15:06 279,440 --------- C:\Windows\System32\drivers\vsdatant.sys
2008-05-23 14:51 . 2008-05-23 18:23 <DIR> d-------- C:\Windows\Internet Logs
2008-05-22 15:50 . 2008-05-22 15:50 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-22 15:44 . 2008-05-22 18:49 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-05-22 15:29 . 2008-05-22 15:29 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-05-22 15:28 . 2008-05-22 15:28 <DIR> d-------- C:\Users\Malene\AppData\Roaming\DAEMON Tools
2008-05-22 15:23 . 2008-05-22 15:23 <DIR> d-------- C:\Program Files\WinAce
2008-05-21 20:41 . 2008-05-22 18:56 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-05-21 20:41 . 2008-05-22 18:56 <DIR> d-------- C:\ProgramData\WLInstaller
2008-05-21 20:41 . 2008-05-21 20:52 <DIR> d-------- C:\Program Files\Windows Live
2008-05-21 20:41 . 2008-05-21 20:51 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-21 20:35 . 2008-05-21 20:35 <DIR> d-------- C:\Users\Malene\AppData\Roaming\Talkback
2008-05-20 23:23 . 2008-05-20 23:23 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-05-20 23:23 . 2008-05-20 23:23 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-05-20 23:21 . 2008-05-20 23:21 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-05-20 23:21 . 2008-05-20 23:21 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2008-05-20 23:11 . 2008-05-20 23:11 <DIR> d-------- C:\Users\Malene\Program Files
2008-05-20 23:10 . 2008-05-20 23:10 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-20 23:10 . 2008-05-20 23:10 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-05-20 23:10 . 2008-05-20 23:10 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-05-20 23:10 . 2008-05-20 23:10 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-05-20 23:10 . 2008-05-20 23:10 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-05-20 23:10 . 2008-05-20 23:10 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-05-20 23:10 . 2008-05-20 23:10 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-05-20 23:10 . 2008-05-20 23:10 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-05-20 23:10 . 2008-05-20 23:10 17,976 --a------ C:\Windows\System32\drivers\intelide.sys
2008-05-20 23:09 . 2008-05-20 23:09 806,400 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-05-20 23:09 . 2008-05-20 23:09 217,144 --a------ C:\Windows\System32\drivers\netio.sys
2008-05-20 23:09 . 2008-05-20 23:09 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-05-20 23:09 . 2008-05-20 23:09 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-05-20 23:09 . 2008-05-20 23:09 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-05-20 23:08 . 2008-05-20 23:08 1,327,104 --a------ C:\Windows\System32\quartz.dll
2008-05-20 23:06 . 2008-05-20 23:06 1,585,664 --a------ C:\Windows\System32\setupapi.dll
2008-05-20 23:03 . 2008-05-20 23:03 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-05-20 23:02 . 2008-05-20 23:02 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-05-20 23:02 . 2008-05-20 23:02 223,232 --a------ C:\Windows\System32\WMASF.DLL
2008-05-20 23:02 . 2008-05-20 23:02 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2008-05-20 23:02 . 2008-05-20 23:02 2,048 --a------ C:\Windows\System32\asferror.dll
2008-05-20 23:01 . 2008-05-20 23:01 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-20 23:01 . 2008-05-20 23:01 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-05-20 23:00 . 2008-05-20 23:00 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-05-20 22:59 . 2008-05-20 22:59 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-05-20 22:59 . 2008-05-20 22:59 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-05-20 22:50 . 2008-05-20 22:50 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2008-05-20 22:50 . 2008-05-20 22:50 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2008-05-20 22:50 . 2008-05-20 22:50 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2008-05-20 22:50 . 2008-05-20 22:50 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2008-05-20 22:49 . 2008-05-20 22:49 148,992 --a------ C:\Windows\System32\drivers\ks.sys
2008-05-20 22:44 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Searches
2008-05-20 22:44 . 2008-05-21 21:12 <DIR> dr------- C:\Users\Malene\Contacts
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Videos
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Saved Games
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Pictures
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Music
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> dr------- C:\Users\Malene\Links
2008-05-20 22:43 . 2008-05-23 18:20 <DIR> dr------- C:\Users\Malene\Downloads
2008-05-20 22:43 . 2008-05-23 17:49 <DIR> dr------- C:\Users\Malene\Documents
2008-05-20 22:43 . 2008-05-20 22:44 <DIR> d--h----- C:\Users\Malene\AppData
2008-05-20 22:43 . 2008-05-23 14:52 <DIR> d-------- C:\Users\Malene
2008-05-20 22:43 . 2008-05-20 22:43 2,048 --a------ C:\Windows\System32\tzres.dll
2008-05-20 22:40 . 2008-05-20 22:40 <DIR> d-------- C:\Users\Jordbae\AppData\Roaming\PeerNetworking
2008-05-20 10:37 . 2008-05-20 10:37 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2008-05-20 10:37 . 2008-05-20 10:37 750,080 --a------ C:\Windows\System32\qmgr.dll
2008-05-20 10:37 . 2008-05-20 10:37 8,888 --a------ C:\Windows\System32\RacUR.xml
2008-05-20 10:37 . 2008-05-20 10:37 150 --a------ C:\Windows\System32\RacUREx.xml
2008-05-20 10:35 . 2008-05-20 10:35 694,784 --a------ C:\Windows\System32\localspl.dll
2008-05-20 10:31 . 2008-05-20 10:31 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2008-05-20 10:31 . 2008-05-20 10:31 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2008-05-20 10:31 . 2008-05-20 10:31 2,048 --a------ C:\Windows\System32\msxml6r.dll
2008-05-20 10:31 . 2008-05-20 10:31 2,048 --a------ C:\Windows\System32\msxml3r.dll
2008-05-20 10:29 . 2008-05-20 10:29 2,605,568 --a------ C:\Windows\System32\SLsvc.exe
2008-05-20 10:29 . 2008-05-20 10:29 566,784 --a------ C:\Windows\System32\SLCommDlg.dll
2008-05-20 10:29 . 2008-05-20 10:29 351,232 --a------ C:\Windows\System32\SLUI.exe
2008-05-20 10:29 . 2008-05-20 10:29 268,288 --a------ C:\Windows\System32\mcbuilder.exe
2008-05-20 10:29 . 2008-05-20 10:29 223,232 --a------ C:\Windows\System32\SLC.dll
2008-05-20 10:29 . 2008-05-20 10:29 186,368 --a------ C:\Windows\System32\SLLUA.exe
2008-05-20 10:29 . 2008-05-20 10:29 57,856 --a------ C:\Windows\System32\SLUINotify.dll
2008-05-20 10:29 . 2008-05-20 10:29 39,936 --a------ C:\Windows\System32\slcinst.dll
2008-05-20 10:29 . 2008-05-20 10:29 33,280 --a------ C:\Windows\System32\slwmi.dll
2008-05-20 10:27 . 2008-05-20 10:27 205,824 --a------ C:\Windows\System32\msoeacct.dll
2008-05-20 10:27 . 2008-05-20 10:27 152,576 --a------ C:\Windows\System32\imagehlp.dll
2008-05-20 10:27 . 2008-05-20 10:27 87,040 --a------ C:\Windows\System32\msoert2.dll
2008-05-20 10:27 . 2008-05-20 10:27 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2008-05-20 10:27 . 2008-05-20 10:27 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
2008-05-20 10:27 . 2008-05-20 10:27 5,120 --a------ C:\Windows\System32\wmi.dll
2008-05-20 10:26 . 2007-09-07 21:20 196,608 --a------ C:\Windows\System32\SynCtrl.dll
2008-05-20 10:26 . 2007-09-07 21:56 192,816 --a------ C:\Windows\System32\drivers\SynTP.sys
2008-05-20 10:26 . 2007-09-07 21:19 163,840 --a------ C:\Windows\System32\SynCOM.dll
2008-05-20 10:26 . 2007-09-07 21:28 147,456 --a------ C:\Windows\System32\SynTPAPI.dll
2008-05-20 10:26 . 2007-09-07 21:56 110,592 --a------ C:\Windows\System32\SynTPCo4.dll
2008-05-20 10:26 . 2007-12-27 02:35 11,263 --ahs---- C:\Patch.rev
2008-05-20 01:27 . 2008-05-19 21:32 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-20 01:23 . 2007-11-06 09:30 15,656 --a------ C:\Windows\System32\drivers\int15_64.sys
2008-05-20 01:23 . 2007-11-30 15:51 15,392 --a------ C:\Windows\System32\drivers\int15.sys
2008-05-20 01:22 . 2007-07-17 19:33 368,640 --a------ C:\Windows\System32\CheckD2DSystem.exe
2008-05-20 01:22 . 2006-11-12 11:54 327,680 --a------ C:\Windows\System32\Remove_eRecovery.exe
2008-05-20 01:22 . 2006-11-10 17:27 16,384 --a------ C:\Windows\System32\LauncheRyAgentUser.exe
2008-05-20 01:22 . 2005-12-09 09:12 16,384 --a------ C:\Windows\System32\ClearEvent.exe
2008-05-20 01:22 . 2006-02-24 11:28 552 --a------ C:\Windows\System32\setup.iss
2008-05-20 01:20 . 2008-05-20 01:20 <DIR> d-------- C:\Program Files\Launch Manager
2008-05-20 01:20 . 2008-05-20 01:20 83 --a------ C:\Windows\LManager.UNI
2008-05-20 01:18 . 2008-05-20 01:18 92 --a------ C:\Windows\GridV.UNI
2008-05-20 01:17 . 2008-05-20 01:17 <DIR> d-------- C:\Program Files\CyberLink
2008-05-20 01:17 . 2007-03-14 21:02 29,744 --------- C:\Windows\System32\msxml3a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:05 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-23 12:49 --------- d-----w C:\ProgramData\Symantec
2008-05-22 16:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-22 13:51 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-22 01:07 --------- d-----w C:\Program Files\Windows Calendar
2008-05-21 19:58 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-21 19:58 --------- d-----w C:\Program Files\Windows Mail
2008-05-20 21:13 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-05-20 21:01 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-05-20 21:01 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-05-20 21:01 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-05-20 21:01 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-05-20 21:01 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-05-20 20:47 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-05-20 20:47 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-05-20 20:47 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-05-20 20:47 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-05-20 08:40 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-05-20 08:36 88,576 ----a-w C:\Windows\System32\avifil32.dll
2008-05-20 08:35 8,192 ----a-w C:\Windows\System32\riched32.dll
2008-05-20 08:31 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-05-19 23:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-19 23:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-19 23:04 --------- d-----w C:\Program Files\Broadcom
2008-05-19 22:57 --------- d-sh--w C:\ProgramData\Skrivebord
2008-05-19 22:57 --------- d-sh--w C:\ProgramData\Skabeloner
2008-05-19 22:57 --------- d-sh--w C:\ProgramData\Menuen Start
2008-05-19 22:57 --------- d-sh--w C:\ProgramData\Favoritter
2008-05-19 22:57 --------- d-sh--w C:\ProgramData\Dokumenter
2008-05-19 22:57 --------- d-sh--w C:\Program Files\Fælles filer
2008-05-19 22:49 174 --sha-w C:\Program Files\desktop.ini
2008-05-19 19:04 --------- d-----w C:\Program Files\Microsoft Games
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-05-20 23:00 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-29 02:29 4472832 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-07 21:56 1021224]
"Acer Tour"="" []
"PLFSetL"="C:\Windows\PLFSetL.exe" [2007-07-05 12:35 94208]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-08-28 22:43 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-08-28 22:43 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-08-28 22:43 137752]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 21:35 102400]
"Adobe Reader Speed Launcher"="c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 04:38 40048]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-10-17 20:59 858632]
"eRecoveryService"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 15:05 959976]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-23 16:00 1177368]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{644DD87E-2A9B-464F-801D-BCA7C790D92A}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{63B0B231-043D-44E6-B226-A5F18354970B}"= C:\Program Files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{A8BE105D-758D-44F9-A79E-C02A12B25B04}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{668CB4FF-38DE-438E-9AA9-004A1A05AE05}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{0B0F3044-F792-4547-B08B-568E4F697CF6}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{AD8D60DD-ECDE-45A8-BC8F-8670D09EE14E}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{EA5003B0-1EBF-458A-AB1D-1C3DF67998EB}C:\\users\\jordbae\\program files\\dna\\btdna.exe"= UDP:C:\users\jordbae\program files\dna\btdna.exe:btdna.exe
"UDP Query User{2CCB8BA6-F7DE-41C2-8764-964E16A49EFB}C:\\users\\jordbae\\program files\\dna\\btdna.exe"= TCP:C:\users\jordbae\program files\dna\btdna.exe:btdna.exe
"TCP Query User{F354E266-DBF3-403B-9C8D-9E5491941323}C:\\users\\malene\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\malene\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{69EE1F4E-2F62-4FD3-A94A-EEB1E5B21CFE}C:\\users\\malene\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\malene\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{F2E27DE8-A030-4BE4-B1B1-3BF2CC7F1578}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{354255E3-0641-4DAC-96F2-B87E48691E8A}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-23 16:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-23 16:00]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Starttjeneste;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 11:01]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 12:57]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-29 02:44]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-09 00:03]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-08-20 22:25]
S3 BCM43XV;Driver til Broadcom Extensible 802.11-netværkskort;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-26 14:41]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43847687-2803-11dd-93de-000000000000}]
\shell\AutoRun\command - F:\SETUP.EXE
\shell\configure\command - F:\SETUP.EXE
\shell\install\command - F:\SETUP.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e96e4687-25f4-11dd-bef2-806e6f6e6963}]
\shell\AutoRun\command - E:\autorun.exe
\shell\directx\command - E:\DirectX9\dxsetup.exe
\shell\setup\command - E:\setup.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-23 18:25:05
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\Iaanotif.exe\""
.
Completion time: 2008-05-23 18:25:51
ComboFix-quarantined-files.txt 2008-05-23 16:25:48
Pre-Run: 45,101,006,848 byte ledig
Post-Run: 45,127,737,344 byte ledig
286 --- E O F --- 2008-05-23 01:02:11