Check af log
Er der en der vil checke disse logs.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:08, on 04-09-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe
C:\Programmer\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\StartupMonitor.exe
C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\ClocX\ClocX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Programmer\Vista Start Menu\VistaStartMenu.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\FreeNote\FreeNote.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\Philips\VOIP321\VOIP321.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jan\Skrivebord\HiJackThis.exe
C:\WINDOWS\System32\HPZipm12.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - :C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Bredbandscenter] "C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe" /winstart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ClocX] C:\Programmer\ClocX\ClocX.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [VistaStartMenu] "C:\Programmer\Vista Start Menu\VistaStartMenu.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [FreeNote] C:\Programmer\FreeNote\FreeNote.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VOIP321.lnk = C:\Programmer\Philips\VOIP321\VOIP321.exe
O4 - Global Startup: ~Disabled
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.danicapension.dk
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187907598203
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220538399968
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netpension.danicapension.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F9F8BC4-8D36-4DCB-99B6-55B5EDB8263F}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Programmer\Bonjour\mDNSResponder.exe
O23 - Service: BredbandscenterDownloader - Glocalnet AB - C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programmer\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe
O24 - Desktop Component 0: (no name) - http://www.avast.com/eng/images/maincn_middle.gif
--
End of file - 10328 bytes
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 09/04/2008 at 08:54 PM
Application Version : 4.20.1046
Core Rules Database Version : 3556
Trace Rules Database Version: 1544
Scan type : Complete Scan
Total Scan Time : 00:41:20
Memory items scanned : 446
Memory threats detected : 0
Registry items scanned : 5897
Registry threats detected : 0
File items scanned : 31339
File threats detected : 14
Adware.Tracking Cookie
C:\Documents and Settings\Jan\Cookies\jan@adtech[3].txt
C:\Documents and Settings\Jan\Cookies\jan@advertising[3].txt
C:\Documents and Settings\Jan\Cookies\jan@track.adform[3].txt
C:\Documents and Settings\Jan\Cookies\jan@2o7[1].txt
C:\Documents and Settings\Jan\Cookies\jan@ad.zanox[2].txt
C:\Documents and Settings\Jan\Cookies\jan@adtech[2].txt
C:\Documents and Settings\Jan\Cookies\jan@advertising[2].txt
C:\Documents and Settings\Jan\Cookies\jan@atdmt[2].txt
C:\Documents and Settings\Jan\Cookies\jan@doubleclick[1].txt
C:\Documents and Settings\Jan\Cookies\jan@msnportal.112.2o7[1].txt
C:\Documents and Settings\Jan\Cookies\jan@stat.swedbank[1].txt
C:\Documents and Settings\Jan\Cookies\jan@track.adform[2].txt
C:\Documents and Settings\Jan\Cookies\jan@viasatsatelliteservices.112.2o7[1].txt
C:\Documents and Settings\Jan\Cookies\jan@www.googleadservices[1].txt
ComboFix 08-09-03.06 - Jan 2008-09-04 19:53:32.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.479 [GMT 2:00]
Running from: C:\Documents and Settings\Jan\Skrivebord\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((( Files Created from 2008-08-04 to 2008-09-04 )))))))))))))))))))))))))))))))
.
2008-09-04 17:19 . 2008-09-04 17:19 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-09-04 16:21 . 2008-07-18 22:09 29,896 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-01 00:19 . 2008-09-02 15:17 <DIR> d-------- C:\Programmer\FreeNote
2008-08-31 23:08 . 2008-04-14 18:05 116,224 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-08-31 23:08 . 2008-04-13 20:46 19,200 --a--c--- C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-08-31 23:08 . 2008-04-14 18:05 18,944 --a--c--- C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-08-31 23:08 . 2008-04-14 18:05 8,192 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
2008-08-31 23:07 . 2008-04-14 18:05 54,272 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-08-31 23:07 . 2008-04-14 17:37 32,000 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-08-31 23:07 . 2008-04-13 20:45 26,112 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-08-31 23:07 . 2008-04-13 20:45 17,152 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-08-31 23:07 . 2008-04-13 20:36 8,832 --a--c--- C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-08-31 23:07 . 2008-04-13 20:40 5,376 --a--c--- C:\WINDOWS\system32\dllcache\viaide.sys
2008-08-31 23:06 . 2008-04-13 20:40 149,376 --a--c--- C:\WINDOWS\system32\dllcache\tffsport.sys
2008-08-31 23:06 . 2008-04-14 18:06 82,944 --a--c--- C:\WINDOWS\system32\dllcache\tp4mon.exe
2008-08-31 23:06 . 2008-04-13 20:46 15,232 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-08-31 23:05 . 2008-04-13 20:40 43,904 --a--c--- C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-08-31 23:05 . 2008-04-13 20:36 16,000 --a--c--- C:\WINDOWS\system32\dllcache\smbbatt.sys
2008-08-31 23:05 . 2008-04-13 20:45 11,520 --a--c--- C:\WINDOWS\system32\dllcache\scsiscan.sys
2008-08-31 23:05 . 2008-04-13 20:46 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
2008-08-31 23:05 . 2008-04-13 20:40 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonyait.sys
2008-08-31 23:05 . 2008-04-13 20:36 6,912 --a--c--- C:\WINDOWS\system32\dllcache\smbclass.sys
2008-08-31 23:03 . 2008-04-14 17:44 2,068,480 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-31 23:03 . 2008-04-13 20:46 85,248 --a--c--- C:\WINDOWS\system32\dllcache\nabtsfec.sys
2008-08-31 23:03 . 2008-04-13 20:54 28,672 --a--c--- C:\WINDOWS\system32\dllcache\nscirda.sys
2008-08-31 23:03 . 2008-04-13 20:44 27,904 --a--c--- C:\WINDOWS\system32\dllcache\perm2.sys
2008-08-31 23:03 . 2008-04-13 20:46 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-08-31 23:02 . 2008-04-14 18:06 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-08-31 23:02 . 2008-04-13 20:46 51,200 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-08-31 23:02 . 2008-04-13 20:46 49,024 --a--c--- C:\WINDOWS\system32\dllcache\mstape.sys
2008-08-31 23:02 . 2008-04-13 20:41 26,112 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
2008-08-31 23:02 . 2008-04-13 20:54 22,016 --a--c--- C:\WINDOWS\system32\dllcache\msircomm.sys
2008-08-31 23:02 . 2008-04-13 20:46 15,232 --a--c--- C:\WINDOWS\system32\dllcache\mpe.sys
2008-08-31 23:02 . 2008-04-13 20:39 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-08-31 23:00 . 2008-04-14 18:05 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-08-31 23:00 . 2008-04-13 20:41 18,560 --a--c--- C:\WINDOWS\system32\dllcache\i2omp.sys
2008-08-31 23:00 . 2008-04-13 20:41 8,576 --a--c--- C:\WINDOWS\system32\dllcache\i2omgmt.sys
2008-08-31 22:59 . 2008-04-13 20:45 59,136 --a--c--- C:\WINDOWS\system32\dllcache\gckernel.sys
2008-08-31 22:59 . 2008-04-14 17:38 28,416 --a--c--- C:\WINDOWS\system32\dllcache\grserial.sys
2008-08-31 22:59 . 2008-04-13 20:36 20,352 --a--c--- C:\WINDOWS\system32\dllcache\hidbatt.sys
2008-08-31 22:59 . 2008-04-13 20:45 10,624 --a--c--- C:\WINDOWS\system32\dllcache\gameenum.sys
2008-08-31 22:58 . 2008-04-13 20:39 206,976 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-08-31 22:58 . 2008-04-14 18:06 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-08-31 22:58 . 2008-04-13 20:40 8,320 --a--c--- C:\WINDOWS\system32\dllcache\dlttape.sys
2008-08-31 22:57 . 2008-04-14 18:05 250,880 --a--c--- C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-08-31 22:57 . 2008-04-14 18:05 121,856 --a--c--- C:\WINDOWS\system32\dllcache\camext30.dll
2008-08-31 22:57 . 2008-04-13 20:46 17,024 --a--c--- C:\WINDOWS\system32\dllcache\ccdecode.sys
2008-08-31 22:57 . 2008-04-13 20:36 13,952 --a--c--- C:\WINDOWS\system32\dllcache\cmbatt.sys
2008-08-31 22:57 . 2008-04-13 20:36 10,240 --a--c--- C:\WINDOWS\system32\dllcache\compbatt.sys
2008-08-31 22:57 . 2008-04-13 20:40 8,192 --a--c--- C:\WINDOWS\system32\dllcache\changer.sys
2008-08-31 22:56 . 2008-04-13 20:46 38,912 --a--c--- C:\WINDOWS\system32\dllcache\avc.sys
2008-08-31 22:56 . 2008-04-14 18:06 18,432 --a--c--- C:\WINDOWS\system32\dllcache\bdaplgin.ax
2008-08-31 22:56 . 2008-04-13 20:36 14,208 --a--c--- C:\WINDOWS\system32\dllcache\battc.sys
2008-08-31 22:56 . 2008-04-13 20:46 13,696 --a--c--- C:\WINDOWS\system32\dllcache\avcstrm.sys
2008-08-31 22:56 . 2008-04-13 20:46 11,776 --a--c--- C:\WINDOWS\system32\dllcache\bdasup.sys
2008-08-31 22:55 . 2008-04-14 17:45 2,191,616 --a--c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-31 22:55 . 2008-04-13 20:46 48,128 --a--c--- C:\WINDOWS\system32\dllcache\61883.sys
2008-08-31 22:55 . 2008-04-13 20:40 12,288 --a--c--- C:\WINDOWS\system32\dllcache\4mmdat.sys
2008-08-31 11:12 . 2008-08-31 11:13 <DIR> d-------- C:\Programmer\ClocX
2008-08-31 10:54 . 2008-09-01 00:07 <DIR> d-------- C:\Programmer\KeyKeeper
2008-08-31 10:48 . 2008-08-31 10:48 <DIR> d-------- C:\Programmer\ABF software
2008-08-31 10:48 . 2008-08-31 10:48 97 --a------ C:\WINDOWS\CSS.key
2008-08-12 22:56 . 2008-08-12 22:56 <DIR> d-------- C:\WINDOWS\system32\da
2008-08-12 22:56 . 2008-08-12 22:56 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-12 22:03 . 2008-04-14 18:05 1,306,624 --------- C:\WINDOWS\system32\msxml6.dll
2008-08-09 13:25 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-08-09 13:25 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-08-09 13:25 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-08-09 13:25 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-08-09 13:25 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-08-09 13:25 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-08-09 13:25 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-08-09 13:25 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-08-07 08:03 . 2008-08-07 08:03 <DIR> d-------- C:\Programmer\iTunes
2008-08-07 08:03 . 2008-08-07 08:03 <DIR> d-------- C:\Programmer\iPod
2008-08-07 08:03 . 2008-08-07 08:04 <DIR> d-------- C:\Programmer\Apple Software Update
2008-08-07 08:02 . 2008-08-07 08:02 <DIR> d-------- C:\Programmer\Bonjour
2008-08-07 07:59 . 2008-08-07 07:59 <DIR> d-------- C:\Programmer\Safari
2008-08-07 07:58 . 2008-08-07 07:58 <DIR> d-------- C:\Programmer\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-04 17:49 --------- d-----w C:\Documents and Settings\Jan\Application Data\Skype
2008-09-04 17:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-04 17:30 --------- d-----w C:\Programmer\Spybot - Search & Destroy
2008-09-04 15:52 --------- d-----w C:\Documents and Settings\Jan\Application Data\Vista Start Menu
2008-09-04 15:13 --------- d-----w C:\Documents and Settings\Jan\Application Data\skypePM
2008-09-04 10:16 156,713 -c--a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-09-02 14:16 --------- d-----w C:\Programmer\SUPERAntiSpyware
2008-09-02 14:15 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-09-02 14:09 --------- d-----w C:\Documents and Settings\Jan\Application Data\MSN6
2008-08-25 22:39 --------- d-----w C:\Programmer\HP
2008-08-05 11:21 --------- d-----w C:\Documents and Settings\Jan\Application Data\Image Zone Express
2008-08-02 21:17 --------- d-----w C:\Programmer\Lavasoft
2008-08-02 21:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-24 09:19 --------- d-----w C:\Programmer\Yahoo!
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 12:37 --------- d-----w C:\Programmer\Hewlett-Packard
2008-07-18 12:22 --------- d-----w C:\Programmer\Fælles filer\HP
2008-07-18 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2008-07-18 09:58 --------- d-----w C:\Programmer\MultiKeyboard Driver
2008-07-15 18:07 --------- d-----w C:\Programmer\Skype
2008-07-15 18:07 --------- d-----w C:\Programmer\Fælles filer\Skype
2008-07-15 18:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-07-15 17:33 --------- d-----w C:\Programmer\Philips
2008-07-10 08:13 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:33 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:48 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2007-12-10 15:27 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-06 13:13 2,847,210 ----a-w C:\Programmer\everesthome151.zip
2003-01-13 10:30 278,528 -c----w C:\Programmer\internet explorer\plugins\PanoViewer.dll
1999-04-30 15:00 98,304 -c----w C:\Programmer\internet explorer\plugins\UPjpeg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Gadwin PrintScreen 2.6"="C:\Programmer\Gadwin Systems\PrintScreen\PrintScreen.exe" [2003-07-16 913408]
"VistaStartMenu"="C:\Programmer\Vista Start Menu\VistaStartMenu.exe" [2007-12-12 1704624]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"FreeNote"="C:\Programmer\FreeNote\FreeNote.exe" [2008-02-19 1040384]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
"Google Update"="C:\Documents and Settings\Jan\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FLMOFFICE4DMOUSE"="C:\Programmer\Trust\MI-7500X Wireless Laser Mouse\Mouse32a.exe" [2007-09-19 370176]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 7700480]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Bredbandscenter"="C:\Programmer\Glocalnet\Bredbandscenter\Launcher.exe" [2008-05-01 808104]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"ClocX"="C:\Programmer\ClocX\ClocX.exe" [2007-07-26 270336]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 C:\WINDOWS\StartupMonitor.exe]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 C:\WINDOWS\system32\ptipbmf.dll]
"nwiz"="nwiz.exe" [2006-10-22 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="C:\PROGRA~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
VOIP321.lnk - C:\Programmer\Philips\VOIP321\VOIP321.exe [2006-11-07 771072]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\~Disabled
Adobe Reader Speed Launch.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe [2008-01-11 39792]
Adobe Reader Synchronizer.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
Notification Packages REG_MULTI_SZ scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 12:22 7700480 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-25 02:11 132496 C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Programmer\\Glocalnet\\Bredbandscenter\\Bredbandscenter.exe"=
"C:\\Programmer\\Glocalnet\\Bredbandscenter\\BredbandscenterUpdater.exe"= C:\\Programmer\\Glocalnet\\Bredbandscenter\\BredbandCenterUpdater.exe
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 302000]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 72624]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 BredbandscenterDownloader;BredbandscenterDownloader;C:\Programmer\Glocalnet\Bredbandscenter\BredbandscenterUpdater.exe [2008-05-01 1055912]
R2 NMSAccessU;NMSAccessU;C:\Programmer\CDBurnerXP\NMSAccessU.exe [2007-05-04 71360]
R2 sbbotdi;sbbotdi;C:\PROGRA~1\SPEEDB~1\sbbotdi.sys [2007-07-17 35200]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Programmer\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 1234480]
S3 N100;Compaq Ethernet eller Fast Ethernet NIC-driver;C:\WINDOWS\system32\DRIVERS\n100325.sys [2001-10-04 129536]
S3 NetWlan5;Driver til symbolbaseret 802.11b Wireless LAN-netværkskort;C:\WINDOWS\system32\DRIVERS\NetWlan5.sys [2004-08-27 132695]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Ulead AutoDetector - :C:\Programmer\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
HKLM-Run-Ulead Photo Express Calendar Checker - :C:\Programmer\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
HKLM-Run-HP Software Update - :C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
HKLM-Run-AppleSyncNotifier - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
HKU-Default-Run-swg - C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-HP Software Update - :C:\Programmer\HP\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-MSMSGS - :C:\Programmer\Messenger\msmsgs.exe
MSConfigStartUp-NeroFilterCheck - :C:\WINDOWS\system32\NeroCheck.exe
MSConfigStartUp-QuickTime Task - :C:\Programmer\QuickTime\qttask.exe
MSConfigStartUp-swg - C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jan\Application Data\Mozilla\Firefox\Profiles\9bmcliqs.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.dk
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-04 20:02:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Programmer\Windows Defender\MsMpEng.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmer\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\Programmer\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\HP\Digital Imaging\bin\hpqste08.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-04 20:06:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-04 18:06:48
Pre-Run: 116,019,130,368 byte ledig
Post-Run: 116,170,178,560 byte ledig
281 --- E O F --- 2008-09-04 17:37:27
