ComboFix 08-09-13.05 - Jesper 2008-09-14 15:14:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.1555 [GMT 2:00]
Running from: C:\Documents and Settings\Jesper\Skrivebord\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-14 14:58 . 2008-09-14 14:58 <DIR> d-------- C:\Programmer\Yahoo!
2008-09-14 14:58 . 2008-09-14 14:58 <DIR> d-------- C:\Programmer\CCleaner
2008-09-14 14:54 . 2008-09-14 14:54 960 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2008-09-14 13:22 . 2008-09-14 14:55 <DIR> d-------- C:\Programmer\nLite
2008-09-14 13:07 . 2008-09-14 13:09 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-09-14 13:07 . 2008-09-14 13:07 <DIR> d-------- C:\Documents and Settings\Jesper\Application Data\Malwarebytes
2008-09-14 13:07 . 2008-09-14 13:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-14 13:07 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-14 13:07 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-14 12:47 . 2008-09-14 12:47 <DIR> d-------- C:\WINDOWS\nview
2008-09-14 12:47 . 2008-05-16 14:01 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-09-14 12:47 . 2008-09-14 15:06 186,188 --a------ C:\WINDOWS\system32\nvapps.xml
2008-09-14 12:47 . 2008-05-16 14:01 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-09-14 12:46 . 2008-05-16 11:48 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-09-14 12:34 . 2008-09-14 12:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-14 10:32 . 2008-09-14 10:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Disk Cleaner
2008-09-13 13:05 . 2008-09-14 01:34 <DIR> d-------- C:\Documents and Settings\Jesper\Contacts
2008-09-12 18:45 . 2008-09-12 18:45 <DIR> d-------- C:\WINDOWS\VentriloMix
2008-09-12 18:45 . 2008-09-12 18:45 <DIR> d-------- C:\Programmer\VentriloMix
2008-09-12 15:42 . 2008-09-12 15:42 <DIR> d-------- C:\Programmer\SystemRequirementsLab
2008-09-12 15:42 . 2008-09-12 15:42 <DIR> d-------- C:\Documents and Settings\Jesper\Application Data\SystemRequirementsLab
2008-09-12 14:00 . 2008-04-14 18:05 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-12 13:54 . 2008-09-12 13:54 <DIR> d-------- C:\WINDOWS\system32\da
2008-09-12 13:54 . 2008-09-12 13:54 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-12 13:39 . 2008-09-12 13:39 <DIR> d-------- C:\Programmer\MSXML 4.0
2008-09-12 13:36 . 2008-04-11 21:05 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-12 13:36 . 2008-05-01 16:36 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-12 13:36 . 2008-06-14 19:35 272,256 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-12 13:36 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-12 13:22 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-09-12 13:22 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-09-12 13:22 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-12 13:22 . 2007-07-30 19:18 20,824 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-09-11 22:12 . 2008-09-11 22:13 <DIR> d-------- C:\WINDOWS\NV22483980.TMP
2008-09-11 22:11 . 2008-09-11 22:11 <DIR> d-------- C:\Programmer\Nvidia
2008-09-11 16:06 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-09-11 16:04 . 2008-09-11 16:04 <DIR> d-------- C:\directx
2008-09-10 23:04 . 2008-09-10 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-09-10 21:05 . 2008-09-10 21:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-09-10 20:48 . 2008-09-12 13:54 <DIR> d-------- C:\WINDOWS\system32\da-dk
2008-09-10 20:43 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-08-24 15:09 . 2008-08-24 15:09 21,840 --a------ C:\WINDOWS\system32\SIntfNT.dll
2008-08-24 15:09 . 2008-08-24 15:09 17,212 --a------ C:\WINDOWS\system32\SIntf32.dll
2008-08-24 15:09 . 2008-08-24 15:09 12,067 --a------ C:\WINDOWS\system32\SIntf16.dll
2008-08-24 14:25 . 2008-08-24 14:25 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-08-24 14:25 . 2008-08-24 15:09 30,068 --a------ C:\WINDOWS\DIIUnin.dat
2008-08-24 14:25 . 2008-08-24 14:25 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-08-24 14:04 . 2008-08-24 14:04 86,528 --a------ C:\WINDOWS\bnetunin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 13:13 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-09-14 12:55 --------- d-----w C:\Programmer\PokerStars
2008-09-13 10:33 --------- d-----w C:\Programmer\mIRC
2008-09-13 10:31 --------- d-----w C:\Documents and Settings\Jesper\Application Data\Skype
2008-09-13 08:57 --------- d-----w C:\Documents and Settings\Jesper\Application Data\skypePM
2008-09-12 13:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-09-12 13:52 --------- d-----w C:\Programmer\DivX
2008-09-12 12:01 --------- d-----w C:\Programmer\MSN Messenger
2008-09-10 19:02 --------- d-----w C:\Programmer\Elaborate Bytes
2008-09-10 18:49 --------- d-----w C:\Programmer\Fælles filer\Teleca Shared
2008-08-03 05:58 --------- d-----w C:\Programmer\Java
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:33 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:48 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-02-21 07:03 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-14_13.44.15.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-14 12:09:54 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\ace728a080313d45bbb1be9162963af6\AspNetMMCExt.ni.dll
+ 2008-09-14 12:09:55 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\e22e4a61e7fd4f4ea0a09b8664d7e36b\CustomMarshalers.ni.dll
+ 2008-09-14 12:09:54 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\329eff639eb9d14988c0afc4596f234e\dfsvc.ni.exe
+ 2008-09-14 12:09:56 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\
092d7ec91901084cba492ff3643b9911\Microsoft.Build.Engine.ni.dll
+ 2008-09-14 12:09:56 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\5f2d656f41e7b64fb991856119081c72\Microsoft.Build.Framework.ni.dll
+ 2008-09-14 12:09:59 1,691,648 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\76349116f13d6843bffc5dc6c871550b\Microsoft.Build.Tasks.ni.dll
+ 2008-09-14 12:10:00 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\14e6b36c0081534f848bdd0582011861\Microsoft.Build.Utilities.ni.dll
+ 2008-09-14 12:10:02 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\9c7117bf770af846898bf7062b21609d\Microsoft.VisualBasic.ni.dll
+ 2008-09-14 12:10:06 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\2b6063d6a1f84c47877e7957662afd82\System.Web.Mobile.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"razer"="C:\Programmer\Razer\Copperhead\razerhid.exe" [2005-09-06 155648]
"WinampAgent"="C:\Programmer\Winamp\winampa.exe" [2006-11-21 35328]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - C:\Programmer\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programmer\\MSN Messenger\\livecall.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26049:TCP"= 26049:TCP:BitComet 26049 TCP
"26049:UDP"= 26049:UDP:BitComet 26049 UDP
S3 PPDrv;Protector Plus Driver (UnRegistered);C:\Programmer\Protector Plus\PPDrv.sys [ ]
S3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 19020]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jesper\Application Data\Mozilla\Firefox\Profiles\mv9iin1v.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.dk/firefox.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-14 15:15:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-14 15:15:40
ComboFix-quarantined-files.txt 2008-09-14 13:15:38
ComboFix2.txt 2008-09-14 11:44:34
Pre-Run: 2,840,403,968 byte ledig
Post-Run: 2,830,495,744 byte ledig
150 --- E O F --- 2008-09-12 23:46:29