Den er her:
ComboFix 08-10-22.05 - Martin Hagge 2008-10-23 13:50:16.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.328 [GMT 2:00]
Running from: C:\Documents and Settings\Martin Hagge\Skrivebord\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-20 12:29 . 2008-10-20 12:29 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-10-20 12:29 . 2008-10-20 12:29 <DIR> d-------- C:\Documents and Settings\Martin Hagge\Application Data\Malwarebytes
2008-10-20 12:29 . 2008-10-20 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-20 12:29 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-20 12:29 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-16 03:09 . 2008-10-16 03:10 1,393 --a------ C:\WINDOWS\imsins.BAK
2008-10-16 00:41 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-16 00:40 . 2008-08-14 15:25 2,147,840 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-16 00:40 . 2008-08-14 15:25 2,068,608 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-16 00:40 . 2008-09-15 17:27 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-16 00:39 . 2008-08-14 15:25 2,191,744 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-16 00:39 . 2008-08-14 15:25 2,026,496 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-09 02:13 . 2008-10-09 02:13 <DIR> d-------- C:\Programmer\CCleaner
2008-10-08 17:54 . 2008-10-08 17:54 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-08 17:53 . 2008-10-08 17:53 <DIR> d-------- C:\Programmer\Skype
2008-10-08 17:53 . 2008-10-08 17:53 <DIR> d-------- C:\Programmer\Fælles filer\Skype
2008-10-08 17:53 . 2008-10-21 21:53 <DIR> d-------- C:\Documents and Settings\Martin Hagge\Application Data\Skype
2008-10-06 08:56 . 2008-10-06 08:56 <DIR> d-------- C:\Programmer\Trend Micro
2008-10-05 23:49 . 2008-10-05 23:49 1,720,086 --a------ C:\WINDOWS\system32\TmpA394125
2008-10-03 21:31 . 2008-04-14 03:54 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-21 19:53 --------- d-----w C:\Documents and Settings\Martin Hagge\Application Data\skypePM
2008-10-21 19:43 --------- d-----w C:\Programmer\Microsoft Silverlight
2008-10-21 19:39 --------- d-----w C:\Programmer\Yahoo!
2008-10-16 01:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-08 15:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-10-06 06:47 --------- d-----w C:\Programmer\Google
2008-10-05 21:48 --------- d-----w C:\Programmer\Advanced Poker Calculator
2008-10-05 21:11 --------- d-----w C:\Programmer\DAEMON Tools Lite
2008-09-23 20:55 --------- d-----w C:\Documents and Settings\Martin Hagge\Application Data\dvdcss
2008-09-21 21:14 --------- d-----w C:\Documents and Settings\Martin Hagge\Application Data\vlc
2008-09-17 10:47 --------- d-----w C:\Programmer\Electronic Arts
2008-09-17 08:44 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-17 00:27 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-09-15 15:27 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-04 19:12 --------- d-----w C:\Programmer\Messenger Plus! Live
2008-08-26 19:39 --------- d-----w C:\Programmer\Image-Line
2008-08-26 08:27 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-26 08:27 826,368 ----a-w C:\WINDOWS\system32\SET8F3.tmp
2008-08-26 08:27 233,472 ----a-w C:\WINDOWS\system32\SET8F4.tmp
2008-08-26 08:27 1,159,680 ----a-w C:\WINDOWS\system32\SET8F5.tmp
2008-08-14 13:25 2,191,744 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:25 2,068,608 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-03-17 00:39 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-10-10_14.23.29.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-14 13:25:42 2,147,840 ------w C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 13:25:45 2,068,608 ------w C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 13:25:41 2,026,496 ------w C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 13:25:45 2,191,744 ------w C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
+ 2008-06-23 16:33:50 124,928 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\advpack.dll
+ 2008-06-23 16:33:50 347,136 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\dxtmsft.dll
+ 2008-06-23 16:33:50 214,528 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\dxtrans.dll
+ 2008-06-23 16:33:50 133,120 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\extmgr.dll
+ 2008-06-23 16:33:50 63,488 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\icardie.dll
+ 2008-06-23 09:19:04 70,656 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ie4uinit.exe
+ 2008-06-23 16:33:50 153,088 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieakeng.dll
+ 2008-06-23 16:33:50 230,400 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieaksie.dll
+ 2008-06-21 05:23:54 161,792 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieakui.dll
+ 2008-06-23 16:33:50 383,488 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieapfltr.dll
+ 2008-06-23 16:33:50 384,512 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\iedkcs32.dll
+ 2008-06-23 16:33:51 6,066,176 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieframe.dll
+ 2008-06-23 16:33:51 44,544 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\iernonce.dll
+ 2008-06-23 16:33:52 267,776 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\iertutil.dll
+ 2008-06-23 09:20:26 13,824 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\ieudinit.exe
+ 2008-06-23 09:19:22 625,664 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
+ 2008-06-23 16:33:52 27,648 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\jsproxy.dll
+ 2008-06-23 16:33:52 459,264 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\msfeeds.dll
+ 2008-06-23 16:33:52 52,224 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\msfeedsbs.dll
+ 2008-06-24 08:33:54 3,592,192 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\mshtml.dll
+ 2008-06-23 16:33:53 477,696 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\mshtmled.dll
+ 2008-06-23 16:33:53 193,024 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\msrating.dll
+ 2008-06-23 16:33:53 671,232 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\mstime.dll
+ 2008-06-23 16:33:53 102,912 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\occache.dll
+ 2008-06-23 16:33:53 44,544 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\pngfilt.dll
+ 2007-03-06 01:11:00 214,752 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:12:08 383,200 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\updspapi.dll
+ 2008-06-23 16:33:53 105,984 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\url.dll
+ 2008-06-23 16:33:53 1,159,680 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\urlmon.dll
+ 2008-06-23 16:33:54 233,472 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\webcheck.dll
+ 2008-06-23 16:33:54 826,368 -c----w C:\WINDOWS\ie7updates\KB956390-IE7\wininet.dll
- 2008-09-16 08:30:05 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-10-16 01:42:19 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-09-16 08:30:06 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-10-16 01:42:20 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-09-16 08:30:05 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-10-16 01:42:19 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-09-16 08:30:05 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-10-16 01:42:19 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-09-16 08:30:06 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-10-16 01:42:19 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-09-16 08:30:06 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-10-16 01:42:20 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-09-16 08:30:07 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-10-16 01:42:20 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-09-16 08:30:06 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-10-16 01:42:19 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-09-16 08:30:06 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-10-16 01:42:19 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-09-16 08:30:06 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-10-16 01:42:19 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-09-16 08:30:06 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-10-16 01:42:20 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-09-16 08:30:05 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-10-16 01:42:19 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-06-23 16:33:50 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-08-26 08:27:23 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2008-06-23 16:33:50 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-08-26 08:27:23 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll
- 2008-06-20 11:40:08 138,496 -c----w C:\WINDOWS\system32\dllcache\afd.sys
+ 2008-08-14 10:04:36 138,496 -c----w C:\WINDOWS\system32\dllcache\afd.sys
- 2008-06-23 16:33:50 347,136 -c----w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-08-26 08:27:23 347,136 -c----w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-06-23 16:33:50 214,528 -c----w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-08-26 08:27:23 214,528 -c----w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-06-23 16:33:50 133,120 -c----w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-08-26 08:27:23 133,120 -c----w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-06-23 16:33:50 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-08-26 08:27:23 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll
- 2008-06-23 09:19:04 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-08-25 08:36:50 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-06-23 16:33:50 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-08-26 08:27:23 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-06-23 16:33:50 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-08-26 08:27:23 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-06-21 05:23:54 161,792 -c----w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-08-23 05:54:51 161,792 -c----w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-06-23 16:33:50 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-08-26 08:27:24 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-06-23 16:33:50 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-08-26 08:27:24 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-06-23 16:33:51 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-10-03 17:12:34 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-06-23 16:33:51 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-08-26 08:27:25 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-06-23 16:33:52 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-08-26 08:27:25 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-06-23 09:20:26 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-06-23 09:19:22 625,664 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-08-23 05:56:15 635,848 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-06-23 16:33:52 27,648 -c----w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-08-26 08:27:26 27,648 -c----w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-06-23 16:33:52 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-08-26 08:27:26 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-06-23 16:33:52 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-08-26 08:27:26 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-06-24 08:33:54 3,592,192 -c----w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-08-27 09:27:28 3,593,216 -c----w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-06-23 16:33:53 477,696 -c----w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-08-26 08:27:27 477,696 -c----w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-06-23 16:33:53 193,024 -c----w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-08-26 08:27:27 193,024 -c----w C:\WINDOWS\system32\dllcache\msrating.dll
- 2008-06-23 16:33:53 671,232 -c----w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-08-26 08:27:27 671,232 -c----w C:\WINDOWS\system32\dllcache\mstime.dll
- 2008-06-23 16:33:53 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-08-26 08:27:27 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll
- 2008-06-23 16:33:53 44,544 -c----w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-08-26 08:27:27 44,544 -c----w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2008-06-23 16:33:53 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-08-26 08:27:27 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll
- 2008-06-23 16:33:53 1,159,680 -c----w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-08-26 08:27:27 1,159,680 -c----w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-06-23 16:33:54 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-08-26 08:27:27 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-06-23 16:33:54 826,368 -c----w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-08-26 08:27:28 826,368 -c----w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-06-20 11:40:08 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
+ 2008-08-14 10:04:36 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
- 2008-06-23 16:33:50 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-08-26 08:27:23 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-06-23 16:33:50 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-08-26 08:27:23 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-06-23 16:33:50 133,120 ------w C:\WINDOWS\system32\extmgr.dll
+ 2008-08-26 08:27:23 133,120 ------w C:\WINDOWS\system32\extmgr.dll
- 2008-08-14 00:19:56 269,392 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-16 11:40:55 269,392 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-06-23 16:33:50 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-08-26 08:27:23 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2008-06-23 09:19:04 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-08-25 08:36:50 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
- 2008-06-23 16:33:50 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
+ 2008-08-26 08:27:23 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
- 2008-06-23 16:33:50 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
+ 2008-08-26 08:27:23 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
- 2008-06-21 05:23:54 161,792 ------w C:\WINDOWS\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ------w C:\WINDOWS\system32\ieakui.dll
- 2008-06-23 16:33:50 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-08-26 08:27:24 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-06-23 16:33:50 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-08-26 08:27:24 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
- 2008-06-23 16:33:51 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-10-03 17:12:34 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2008-06-23 16:33:51 44,544 ------w C:\WINDOWS\system32\iernonce.dll
+ 2008-08-26 08:27:25 44,544 ------w C:\WINDOWS\system32\iernonce.dll
- 2008-06-23 16:33:52 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-08-26 08:27:25 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2008-06-23 09:20:26 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2008-06-23 16:33:52 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
+ 2008-08-26 08:27:26 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
- 2008-08-26 20:28:12 16,208,504 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-10-07 19:19:40 16,721,856 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-06-23 16:33:52 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-08-26 08:27:26 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-06-23 16:33:52 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-08-26 08:27:26 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-06-24 08:33:54 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-08-27 09:27:28 3,593,216 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-06-23 16:33:53 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-08-26 08:27:27 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2008-06-23 16:33:53 193,024 ------w C:\WINDOWS\system32\msrating.dll
+ 2008-08-26 08:27:27 193,024 ------w C:\WINDOWS\system32\msrating.dll
- 2008-06-23 16:33:53 671,232 ------w C:\WINDOWS\system32\mstime.dll
+ 2008-08-26 08:27:27 671,232 ------w C:\WINDOWS\system32\mstime.dll
- 2008-06-23 16:33:53 102,912 ------w C:\WINDOWS\system32\occache.dll
+ 2008-08-26 08:27:27 102,912 ------w C:\WINDOWS\system32\occache.dll
- 2008-06-23 16:33:53 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-08-26 08:27:27 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-11-30 12:39:13 17,784 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:31 17,784 ------w C:\WINDOWS\system32\spmsg.dll
- 2008-06-23 16:33:53 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-08-26 08:27:27 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2008-06-23 16:33:53 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-08-26 08:27:27 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2008-06-23 16:33:54 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-08-26 08:27:27 233,472 ------w C:\WINDOWS\system32\webcheck.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="C:\Programmer\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-12 65536]
"msnmsgr"="C:\Programmer\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-11 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"PC Suite Tray"="C:\Programmer\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 1079296]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 1232896]
"updateMgr"="C:\Programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Uniblue RegistryBooster2"="C:\Programmer\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-08-16 1877272]
"Uniblue SpyEraser"="C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe" [2008-04-02 1424648]
"Uniblue RegistryBooster 2"="C:\Programmer\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-08-16 1877272]
"DAEMON Tools Lite"="C:\Programmer\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"WMPNSCFG"="C:\Programmer\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Programmer\Apoint2K\Apoint.exe" [2004-03-24 196608]
"CeEKEY"="C:\Programmer\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]
"TPNF"="C:\Programmer\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 53248]
"HWSetup"="C:\Programmer\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"SVPWUTIL"="C:\Programmer\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"SmoothView"="C:\Programmer\TOSHIBA\TOSHIBA-zoomfunktion\SmoothView.exe" [2005-05-12 118784]
"PadTouch"="C:\Programmer\TOSHIBA\Touch and Launch\PadExe.exe" [2005-08-30 1077328]
"Tvs"="C:\Programmer\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"Windows Media Connect 2"="C:\Programmer\Windows Media Connect 2\WMCCFG.exe" [2006-10-18 8704]
"GrooveMonitor"="C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="C:\Programmer\Fælles filer\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ControlCenter2.0"="C:\Programmer\Brother\ControlCenter2\brctrcen.exe" [2005-07-22 933888]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2008-03-07 385024]
"NSLauncher"="C:\Programmer\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
"Zooming"="ZoomingHook.exe" [2005-06-06 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-08-11 C:\WINDOWS\system32\TPSMain.exe]
"TFncKy"="TFncKy.exe" [BU]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 C:\WINDOWS\agrsmmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="C:\Programmer\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 1232896]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Bluetooth Manager.lnk - C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-03-22 483328]
Giganews Accelerator.lnk - C:\Programmer\Giganews Accelerator\GiganewsAccelerator.exe [2007-12-18 757760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-03-07 01:57 229376 C:\Programmer\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Programmer\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Programmer\\Fælles filer\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Programmer\\Windows Media Player\\wmplayer.exe"=
"C:\\Programmer\\InterPoker\\UA.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41952:TCP"= 41952:TCP:MediaServer.exe
.
Contents of the 'Scheduled Tasks' folder
2008-03-06 C:\WINDOWS\Tasks\Registreringspåmindelse 2.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2008-04-14 18:05]
2008-08-09 C:\WINDOWS\Tasks\Uniblue SpyEraser.job
- C:\Programmer\Uniblue\SpyEraser\SpyEraser.exe [2008-04-02 09:50]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Martin Hagge\Application Data\Mozilla\Firefox\Profiles\2poykota.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.dk/FF -: plugin - C:\Programmer\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\Programmer\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\Programmer\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - C:\Programmer\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-23 13:54:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-23 13:56:12
ComboFix-quarantined-files.txt 2008-10-23 11:55:59
ComboFix2.txt 2008-10-10 12:24:17
Pre-Run: 26.509.352.960 byte ledig
Post-Run: 26,575,286,272 byte ledig
345 --- E O F --- 2008-10-21 01:01:17