ComboFix 09-02-24.01 - Niclas 2009-02-24 21:46:46.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1030.18.3069.1703 [GMT 1:00]
Kører fra: C:\Users\Niclas\Desktop\ComboFix.exe
Kommandoer benyttet :: C:\Users\Niclas\Desktop\cfscript.lnk
* Dannede nyt systemgendannelsespunkt
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\404Fix.exe
C:\Windows\system32\Agent.OMZ.Fix.exe
C:\Windows\system32\dumphive.exe
C:\Windows\system32\IEDFix.C.exe
C:\Windows\system32\IEDFix.exe
C:\Windows\system32\o4Patch.exe
C:\Windows\system32\Process.exe
C:\Windows\system32\SrchSTS.exe
C:\Windows\system32\tmp.reg
C:\Windows\system32\VACFix.exe
C:\Windows\system32\VCCLSID.exe
C:\Windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-01-24 til 2009-02-24 )))))))))))))))))))))))))))))))))))
.
2009-02-22 14:05 . 2009-02-22 14:05 691 --a------ C:\Users\Niclas\AppData\Roaming\GetValue.vbs
2009-02-22 14:05 . 2009-02-22 14:05 35 --a------ C:\Users\Niclas\AppData\Roaming\SetValue.bat
2009-02-22 14:01 . 2009-02-22 14:11 <DIR> d-------- C:\SmitfraudFix
2009-02-22 13:58 . 2009-02-22 13:58 1,662,588 --a------ C:\SmitfraudFix.exe
2009-02-20 20:28 . 2009-02-20 23:30 <DIR> d-------- C:\Lop SD
2009-02-20 18:10 . 2009-02-20 18:10 <DIR> d-------- C:\Windows\System32\Adobe
2009-02-18 20:52 . 2009-02-18 20:52 <DIR> d-------- C:\Users\Niclas\AppData\Roaming\BitTorrent
2009-02-17 20:13 . 2009-02-17 20:13 <DIR> d-------- C:\Program Files\Common Files\Skype
2009-02-16 22:44 . 2009-02-16 22:44 <DIR> d-------- C:\Users\Niclas\AppData\Roaming\Malwarebytes
2009-02-16 22:44 . 2009-02-16 22:44 <DIR> d-------- C:\ProgramData\Malwarebytes
2009-02-16 22:44 . 2009-02-16 22:44 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-16 22:44 . 2009-02-11 10:19 38,496 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2009-02-16 22:44 . 2009-02-11 10:19 15,504 --a------ C:\Windows\System32\drivers\mbam.sys
2009-02-16 20:05 . 2009-02-16 20:05 <DIR> d-------- C:\Program Files\CCleaner
2009-02-16 19:15 . 2009-02-16 19:07 15,688 --a------ C:\Windows\System32\lsdelete.exe
2009-02-16 19:07 . 2009-02-16 19:06 64,160 --a------ C:\Windows\System32\drivers\Lbd.sys
2009-02-16 19:04 . 2009-02-16 19:04 <DIR> d--h-c--- C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-16 19:03 . 2009-02-16 19:07 <DIR> d-------- C:\ProgramData\Lavasoft
2009-02-16 19:03 . 2009-02-16 19:03 <DIR> d-------- C:\Program Files\Lavasoft
2009-02-16 14:59 . 2009-02-21 12:21 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-16 14:07 . 2009-02-16 14:07 10,520 --a------ C:\Windows\System32\avgrsstx.dll.install_backup
2009-02-16 14:06 . 2009-02-22 13:01 <DIR> d-------- C:\ProgramData\avg8
2009-02-16 14:06 . 2009-02-16 14:06 <DIR> d-------- C:\Program Files\AVG
2009-02-16 12:41 . 2008-12-05 05:32 428,544 --a------ C:\Windows\System32\EncDec.dll
2009-02-16 12:41 . 2008-12-05 05:32 293,376 --a------ C:\Windows\System32\psisdecd.dll
2009-02-16 12:41 . 2008-12-05 05:31 217,088 --a------ C:\Windows\System32\psisrndr.ax
2009-02-16 12:41 . 2008-12-05 05:31 177,664 --a------ C:\Windows\System32\mpg2splt.ax
2009-02-16 12:41 . 2008-12-05 05:31 80,896 --a------ C:\Windows\System32\MSNP.ax
2009-02-15 18:39 . 2009-01-15 04:36 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2009-02-15 18:39 . 2009-01-15 07:11 827,392 --a------ C:\Windows\System32\wininet.dll
2009-02-05 18:11 . 2009-02-05 18:11 <DIR> d-------- C:\ProgramData\Office Genuine Advantage
2009-02-05 17:30 . 2008-06-20 02:14 781,344 --a------ C:\Windows\System32\PresentationNative_v0300.dll
2009-02-05 17:30 . 2008-06-20 02:14 622,080 --a------ C:\Windows\System32\icardagt.exe
2009-02-05 17:30 . 2008-06-20 02:14 326,160 --a------ C:\Windows\System32\PresentationHost.exe
2009-02-05 17:30 . 2008-06-20 02:14 105,016 --a------ C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-05 17:30 . 2008-06-20 02:14 97,800 --a------ C:\Windows\System32\infocardapi.dll
2009-02-05 17:30 . 2008-06-20 02:14 43,544 --a------ C:\Windows\System32\PresentationHostProxy.dll
2009-02-05 17:30 . 2008-06-20 02:14 37,384 --a------ C:\Windows\System32\infocardcpl.cpl
2009-02-05 17:30 . 2008-06-20 02:14 11,264 --a------ C:\Windows\System32\icardres.dll
2009-02-05 17:25 . 2008-07-27 19:03 282,112 --a------ C:\Windows\System32\mscoree.dll
2009-02-05 17:25 . 2008-07-27 19:03 158,720 --a------ C:\Windows\System32\mscorier.dll
2009-02-05 17:25 . 2008-07-27 19:03 96,760 --a------ C:\Windows\System32\dfshim.dll
2009-02-05 17:25 . 2008-07-27 19:03 83,968 --a------ C:\Windows\System32\mscories.dll
2009-02-05 17:25 . 2008-07-27 19:03 41,984 --a------ C:\Windows\System32\netfxperf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 20:56 --------- d-----w C:\Users\Niclas\AppData\Roaming\Skype
2009-02-24 19:33 --------- d---a-w C:\ProgramData\TEMP
2009-02-24 15:04 --------- d-----w C:\Users\Niclas\AppData\Roaming\skypePM
2009-02-22 15:31 --------- d-----w C:\Program Files\Steam
2009-02-21 13:22 --------- d-----w C:\Program Files\Common Files\Steam
2009-02-21 10:45 --------- d-----w C:\Program Files\McAfee
2009-02-18 17:08 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2009-02-17 19:13 --------- d-----r C:\Program Files\Skype
2009-02-17 19:12 --------- d-----w C:\ProgramData\Skype
2009-02-17 14:38 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2009-02-16 12:45 --------- d-----w C:\Program Files\Bonjour
2009-02-16 11:38 --------- d-----w C:\ProgramData\Microsoft Help
2009-02-16 11:38 --------- d-----w C:\Program Files\Windows Mail
2009-02-05 16:24 --------- d-----w C:\Users\Niclas\AppData\Roaming\LimeWire
2009-01-23 21:48 --------- d-----w C:\Program Files\directx
2009-01-19 19:24 --------- d-----w C:\Users\Niclas\AppData\Roaming\Turbine
2009-01-19 13:49 --------- d-----w C:\Program Files\SystemRequirementsLab
2009-01-13 19:15 --------- d-----w C:\Program Files\DivX
2009-01-02 14:46 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-12-31 16:04 691,560 ----a-w C:\Windows\System32\OGACheckControl.dll
2008-12-31 16:04 528,744 ----a-w C:\Windows\System32\OGAVerify.exe
2008-12-31 16:04 502,120 ----a-w C:\Windows\System32\OGAAddin.dll
2008-12-27 20:20 --------- d-----w C:\Users\Niclas\AppData\Roaming\dvdcss
2008-12-25 11:59 --------- d-----w C:\Users\Niclas\AppData\Roaming\DivX
2008-12-24 12:03 --------- d-----w C:\ProgramData\NVIDIA
2008-12-24 11:58 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-12-24 11:58 --------- d-----w C:\Program Files\AGEIA Technologies
2008-12-11 00:33 86,016 ----a-w C:\Windows\System32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w C:\Windows\System32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-09-08 18:23 3,739,136 ----a-w C:\Users\Niclas\WAR Europe Downloader.exe
2008-08-18 13:53 174 --sha-w C:\Program Files\desktop.ini
2008-08-10 12:46 56 ---ha-w C:\ProgramData\ezsidmv.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-02-17_17.15.24.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-17 19:13:26 364,726 ----a-r C:\Windows\Installer\{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}\SkypeIcon.exe
- 2009-02-17 16:09:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-24 11:32:17 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-17 16:09:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-24 11:32:17 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-17 16:12:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-24 11:33:15 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-24 11:33:15 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-02-17 16:13:08 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-24 20:58:30 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-24 20:58:30 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
+ 2009-01-16 16:19:40 202,168 ----a-w C:\Windows\System32\Adobe\Director\swdir.dll
+ 2009-01-16 16:19:58 67,000 ----a-w C:\Windows\System32\Adobe\Director\SwDnld.exe
- 2009-02-17 16:13:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-24 20:58:35 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-17 16:13:05 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-24 20:58:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-17 16:13:05 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-24 20:58:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-17 16:06:09 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-24 20:46:01 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-24 20:46:01 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2009-02-17 14:45:23 96,202 ----a-w C:\Windows\System32\perfc006.dat
+ 2009-02-24 11:38:35 96,202 ----a-w C:\Windows\System32\perfc006.dat
- 2009-02-17 14:45:23 116,946 ----a-w C:\Windows\System32\perfc009.dat
+ 2009-02-24 11:38:35 116,946 ----a-w C:\Windows\System32\perfc009.dat
- 2009-02-17 14:45:23 502,090 ----a-w C:\Windows\System32\perfh006.dat
+ 2009-02-24 11:38:35 502,090 ----a-w C:\Windows\System32\perfh006.dat
- 2009-02-17 14:45:23 625,384 ----a-w C:\Windows\System32\perfh009.dat
+ 2009-02-24 11:38:35 625,384 ----a-w C:\Windows\System32\perfh009.dat
- 2009-02-17 14:45:16 6,900 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2222424339-3459818889-2464454366-1000_UserData.bin
+ 2009-02-24 11:34:31 8,004 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2222424339-3459818889-2464454366-1000_UserData.bin
- 2009-02-17 14:45:14 60,924 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-24 11:34:30 61,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-17 14:45:11 44,948 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-24 11:34:29 46,762 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot sat til dags dato --
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 08:33 125952]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 10:34 5724184]
"Google Update"="C:\Users\Niclas\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-10-07 17:51 133104]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 08:33 202240]
"CurseClient"="C:\Program Files\Curse\CurseClient.exe" [BU]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2009-02-04 12:27 23975720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-04-10 01:42 77824]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 15:22 184320]
"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-11 01:00 90112]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 15:44 178712]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-12-06 11:15 1548288]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-10 01:55 1838592]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-12-14 14:25 244208]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 15:27 155648]
"Launch LCDMon"="C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-18 00:30 1687824]
"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-18 01:08 2094352]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 01:38 34672]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 19:12 111936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-11-04 10:30 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-11-20 13:20 290088]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-11-12 14:54 13675040]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-11-12 14:54 92704]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-16 19:06 509784]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-08 00:50 9728 C:\Windows\System32\HCIMNTR.DLL]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-07-02 15:18 23552 C:\Windows\System32\Ctxfihlp.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-13 11:43:38 715568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{01144B01-A2D4-419A-8808-4197F2A99891}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{01E78162-6A1D-43CC-A993-41D889DC45CD}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{BAF1E9F6-9C6F-428F-93DE-3541E77C9EDF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{ECE5BAE9-88A9-4051-8008-247B3F8A1F42}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{6D15D121-AAF7-40C8-A3B1-EEB1C9D49D29}"= UDP:C:\Program Files\Electronic Arts\EADM\Core.exe:EA Download Manager
"{584D8D03-2AF2-4ED6-B293-5EB844F566A2}"= TCP:C:\Program Files\Electronic Arts\EADM\Core.exe:EA Download Manager
"TCP Query User{6AFADBEF-47E7-4795-9826-C4E70C60BCEB}C:\\users\\niclas\\war europe downloader.exe"= UDP:C:\users\niclas\war europe downloader.exe:war europe downloader.exe
"UDP Query User{8C644EE3-6EE5-47B7-8750-E8DFA0BFBD66}C:\\users\\niclas\\war europe downloader.exe"= TCP:C:\users\niclas\war europe downloader.exe:war europe downloader.exe
"TCP Query User{27F05083-6855-4D71-833C-E3828141846C}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{8B7E9F6F-0A39-41F2-944E-16E58A8D447C}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{081A9358-E925-4559-B6B9-B2FB1DAEEE74}C:\\program files\\steam\\steamapps\\angora\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\angora\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{F36D4F45-56FE-4D35-B39A-A7FA59174DB7}C:\\program files\\steam\\steamapps\\angora\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\angora\counter-strike\hl.exe:Half-Life Launcher
"TCP Query User{3926CA42-B924-4B53-8C67-D3617868EFDE}C:\\users\\niclas\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\mtnimbty\\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe"= UDP:C:\users\niclas\appdata\local\microsoft\windows\temporary internet files\content.ie5\mtnimbty\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe:wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe
"UDP Query User{BD028BF4-9206-4E50-BE20-A2CDF710CCA9}C:\\users\\niclas\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\mtnimbty\\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe"= TCP:C:\users\niclas\appdata\local\microsoft\windows\temporary internet files\content.ie5\mtnimbty\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe:wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe
"{86F6E2E6-8EAD-41E5-84ED-948948BAE407}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{8BB74D3C-7D93-4362-B2F1-78643734609A}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"TCP Query User{605B08D8-CDEB-4593-8108-E05ADF5EE5D2}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:µTorrent
"UDP Query User{D805950B-4103-4B16-8D9F-4B74981F23CE}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:µTorrent
"TCP Query User{7F346A26-2AEE-470C-85A1-A10938FAEA21}C:\\users\\niclas\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\y2v75sf6\\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe"= UDP:C:\users\niclas\appdata\local\microsoft\windows\temporary internet files\content.ie5\y2v75sf6\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe:wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe
"UDP Query User{A37E710A-AB35-4A7F-A965-BFCED7F3D4FA}C:\\users\\niclas\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\y2v75sf6\\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe"= TCP:C:\users\niclas\appdata\local\microsoft\windows\temporary internet files\content.ie5\y2v75sf6\wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe:wow-2.4.3.8568-to-3.0.2.8916-engb-downloader[1].exe
"{37E38F86-201C-4AB8-A20D-52BE230B32AE}"= UDP:3724:Blizzard Downloader
"{2E47BA17-7FA2-4433-BBB4-CBCA89D25531}"= UDP:6112:Blizzard Downloader
"TCP Query User{BC47D3C7-BCE9-48D3-B957-52CDEF4FDCD0}C:\\users\\niclas\\program files\\dna\\btdna.exe"= UDP:C:\users\niclas\program files\dna\btdna.exe:btdna.exe
"UDP Query User{1B350384-E7BE-4105-9B65-5630EA6B6165}C:\\users\\niclas\\program files\\dna\\btdna.exe"= TCP:C:\users\niclas\program files\dna\btdna.exe:btdna.exe
"TCP Query User{6054F39D-A40B-4E5A-873C-8EA0DADAAE5A}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{50C9078E-D8DD-4FDE-9CF4-8E465A9BFE08}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{84C21360-05AD-4B2F-A12A-0E3B1AE097F8}C:\\program files\\steam\\steamapps\\angora\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{3BBD807C-6C38-43FF-8B38-DA81B0971865}C:\\program files\\steam\\steamapps\\angora\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\half-life 2 deathmatch\hl2.exe:hl2
"TCP Query User{77B9B230-5A59-4655-A8A6-A174AE71AA5A}C:\\program files\\steam\\steamapps\\angora\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\counter-strike source\hl2.exe:hl2
"UDP Query User{9AF546EE-3C41-44E4-B453-9F60A998E865}C:\\program files\\steam\\steamapps\\angora\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\counter-strike source\hl2.exe:hl2
"TCP Query User{2119A476-EA69-451B-9C4E-51EA968710B6}C:\\program files\\steam\\steamapps\\angora\\team fortress 2\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\team fortress 2\hl2.exe:hl2
"UDP Query User{B668439D-7635-44E8-AEBE-B8409629446F}C:\\program files\\steam\\steamapps\\angora\\team fortress 2\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\team fortress 2\hl2.exe:hl2
"{8C382DA4-EA46-4F16-881C-4C1536B19498}"= UDP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.4.3-to-3.0.2-enGB-Win-Final-downloader.exe:Blizzard Downloader
"{A9AFF543-2CDB-45D8-A9C6-BBBAFBE36511}"= TCP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.4.3-to-3.0.2-enGB-Win-Final-downloader.exe:Blizzard Downloader
"{1C241DDB-E4FE-4F35-ABC5-2800813F570E}"= UDP:C:\Program Files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{0AA91392-838D-40F8-BA88-DA7044555B8F}"= TCP:C:\Program Files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{5F66BD21-9ED9-46C1-9817-E051B0432943}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{C51779AE-01E2-4CFC-BD4E-680361EF685C}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{AA133A0B-61F6-415B-B388-8DA5F944B70A}C:\\program files\\tortun\\gui.exe"= UDP:C:\program files\tortun\gui.exe:gui
"UDP Query User{5B67FAFC-6FEB-49B6-8F0A-78A3E8855F67}C:\\program files\\tortun\\gui.exe"= TCP:C:\program files\tortun\gui.exe:gui
"{AD654001-4AED-4B38-93FF-CC0BF30A8CE6}"= UDP:C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{AE7CCBA0-36CE-41B0-971C-929D522399C6}"= TCP:C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{A2494ABF-B0E6-4CA2-8AF9-2DF34E769A87}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{ED6C6D13-67A7-4F57-8992-36830EC9DF20}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{8A415C7D-9911-4C05-947B-7E152C0DA1DE}"= UDP:C:\Program Files\Curse\CurseClient.exe:Curse Client
"{8722A722-31D2-4F2E-9E23-7FD972749004}"= TCP:C:\Program Files\Curse\CurseClient.exe:Curse Client
"TCP Query User{CBA1F336-A750-4F9A-AE0B-B47FADFCEED8}C:\\users\\niclas\\program files\\dna\\btdna.exe"= UDP:C:\users\niclas\program files\dna\btdna.exe:btdna.exe
"UDP Query User{301D681A-F4D0-46E1-90B0-4141B3CEAE5F}C:\\users\\niclas\\program files\\dna\\btdna.exe"= TCP:C:\users\niclas\program files\dna\btdna.exe:btdna.exe
"TCP Query User{BE05EF37-5011-4237-BCF3-1036FAAC32C5}C:\\program files\\curse\\curseclient.exe"= UDP:C:\program files\curse\curseclient.exe:CurseClient
"UDP Query User{1CB8D9F1-115A-4B8F-BDB5-5712C03675A2}C:\\program files\\curse\\curseclient.exe"= TCP:C:\program files\curse\curseclient.exe:CurseClient
"TCP Query User{4F516DD8-0B16-45A5-8857-1E4C5899B246}C:\\program files\\steam\\steamapps\\angora\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\angora\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{ECCDC802-9F73-4271-AF23-36A01A23C2B5}C:\\program files\\steam\\steamapps\\angora\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\angora\counter-strike\hl.exe:Half-Life Launcher
"TCP Query User{0D92C6CB-3007-4A6C-9C8C-3D1BE51AEB67}C:\\users\\niclas\\desktop\\[ pc games ] - age of empires ii(full)(2)\\empires2.exe"= UDP:C:\users\niclas\desktop\[ pc games ] - age of empires ii(full)(2)\empires2.exe:empires2.exe
"UDP Query User{17E97B21-351D-499E-838C-571E144581FC}C:\\users\\niclas\\desktop\\[ pc games ] - age of empires ii(full)(2)\\empires2.exe"= TCP:C:\users\niclas\desktop\[ pc games ] - age of empires ii(full)(2)\empires2.exe:empires2.exe
"TCP Query User{12FCD64A-BE6F-4D46-B628-6A0948478F18}C:\\users\\niclas\\desktop\\[ pc games ] - age of empires ii(full)(2)\\age2_x1.exe"= UDP:C:\users\niclas\desktop\[ pc games ] - age of empires ii(full)(2)\age2_x1.exe:age2_x1.exe
"UDP Query User{8D924025-E16D-432C-9C6B-CE0067DE3389}C:\\users\\niclas\\desktop\\[ pc games ] - age of empires ii(full)(2)\\age2_x1.exe"= TCP:C:\users\niclas\desktop\[ pc games ] - age of empires ii(full)(2)\age2_x1.exe:age2_x1.exe
"TCP Query User{84585480-E2C4-448D-BDF8-7E4ED6AE327C}C:\\windows\\system32\\dplaysvr.exe"= UDP:C:\windows\system32\dplaysvr.exe:Hjælpeprogram til Microsoft DirectPlay
"UDP Query User{6ACCE5A2-930A-43BC-A265-95B46BF43A94}C:\\windows\\system32\\dplaysvr.exe"= TCP:C:\windows\system32\dplaysvr.exe:Hjælpeprogram til Microsoft DirectPlay
"TCP Query User{A2404DC2-C632-47BB-AF43-7386A032E3CC}C:\\program files\\steam\\steamapps\\angora\\source sdk base\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\source sdk base\hl2.exe:hl2
"UDP Query User{0A4BD918-B41C-40E8-95A7-056F66B74A17}C:\\program files\\steam\\steamapps\\angora\\source sdk base\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\source sdk base\hl2.exe:hl2
"TCP Query User{3E354D3B-75C8-48B2-9B3A-B8F0990061FE}C:\\program files\\steam\\steamapps\\angora\\team fortress 2\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\team fortress 2\hl2.exe:hl2
"UDP Query User{C453A44F-8A6E-4CAD-9202-647998BB206F}C:\\program files\\steam\\steamapps\\angora\\team fortress 2\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\team fortress 2\hl2.exe:hl2
"TCP Query User{543F19F8-D071-4C11-8116-AF1FF9A9B0AF}C:\\program files\\steam\\steamapps\\angora\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{AE9256E4-7440-4B74-BE8A-0D3DA17B89F7}C:\\program files\\steam\\steamapps\\angora\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\half-life 2 deathmatch\hl2.exe:hl2
"TCP Query User{19A01615-14C4-4030-B7A5-15C432BD2522}C:\\program files\\steam\\steamapps\\angora\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\angora\counter-strike source\hl2.exe:hl2
"UDP Query User{8009E03D-FF95-4058-BCAF-E12C2C4428F8}C:\\program files\\steam\\steamapps\\angora\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\angora\counter-strike source\hl2.exe:hl2
"TCP Query User{3281AD30-1BC6-470D-A752-73383DEACB0E}C:\\users\\public\\games\\world of warcraft\\launcher.exe"= UDP:C:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{978D00CB-68BF-4984-BA43-5EB058F9A60B}C:\\users\\public\\games\\world of warcraft\\launcher.exe"= TCP:C:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2009-02-16 19:07:05 64160]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor;C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe [2008-04-10 01:47:13 358936]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 22:34:37 950096]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-02-17 15:11:22 1153368]
S2 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-12-14 14:25:22 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-12-14 14:25:20 166384]
S2 SessionLauncher;SessionLauncher;C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe --> C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-08-18 20:58:49 79360]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-12-14 14:25:12 1112560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\TrueCrypt\TrueCrypt.exe /q /a /e /m rm /v "data"
\shell\dismount\command - L:\TrueCrypt\TrueCrypt.exe /q /d
\shell\mount\command - L:\TrueCrypt\TrueCrypt.exe /q /a /e /m rm /v "data"
\shell\open\command - L:\TrueCrypt\TrueCrypt.exe /e /m rm /v "data"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6e904b8-a8c1-11dd-b8ee-001e4ce638c3}]
\shell\AutoRun\command - L:\TrueCrypt\TrueCrypt.exe /q /a /e /m rm /v "data"
\shell\dismount\command - L:\TrueCrypt\TrueCrypt.exe /q /d
\shell\mount\command - L:\TrueCrypt\TrueCrypt.exe /q /a /e /m rm /v "data"
\shell\open\command - L:\TrueCrypt\TrueCrypt.exe /e /m rm /v "data"
.
Indhold af mappen 'Planlagte Opgaver'
2009-02-23 C:\Windows\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-16 19:06]
2009-02-24 C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2222424339-3459818889-2464454366-1000.job
- C:\Users\Niclas\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-07 17:51]
2008-11-15 C:\Windows\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-04-10 C:\Windows\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
.
------- Yderligere scanning -------
.
uStart Page =
https://www.lectio.dk/lectio/61/SkemaGenerator.aspx?type=elev&id=1491250961IE: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} -
hxxp://www.srtest.com/srl_bin/sysreqlab_test.cabFF - ProfilePath - C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\dj9oqvvy.default\
FF - prefs.js: browser.startup.homepage -
hxxps://www.lectio.dk/lectio/61/SkemaGenerator.aspx?type=elev&id=1491250961 1 fil(er) flyttet.
1 fil(er) flyttet.
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: C:\Users\Niclas\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-24 21:58:36
Windows 6.0.6001 Service Pack 1 NTFS
scanner skjulte processer ...
[0] 0x1B120232
scanner skjulte autostarter ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2009-02-24 22:00:24
ComboFix-quarantined-files.txt 2009-02-24 21:00:21
ComboFix2.txt 2009-02-17 16:17:12
Pre-Kørsel: 157,517,234,176 byte ledig
Post-Kørsel: 156,757,737,472 byte ledig
341 --- E O F --- 2009-02-24 11:37:24