ComboFix 07-11-19.4 - Grønskolling 2007-11-28 0:27:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.266 [GMT 1:00]Running from: C:\Documents and Settings\Grønskolling\Skrivebord\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Gr›nskolling\Application Data\Sskcwrd.dll
C:\Programmer\Fælles filer\WinSoftware
C:\Programmer\Fælles filer\WinSoftware\FCrXML.dll
C:\Programmer\Fælles filer\WinSoftware\PrCheck.dll
C:\Programmer\myglobalsearch
C:\Programmer\winupdates
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NWSAPAGENT
-------\NwSapAgent
((((((((((((((((((((((((( Files Created from 2007-10-27 to 2007-11-27 )))))))))))))))))))))))))))))))
.
2007-11-27 19:46 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-11-27 19:34 <DIR> d-------- C:\Programmer\RichVideoCodec
2007-11-26 14:05 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-11-26 13:43 <DIR> d-------- C:\Programmer\Participatory Culture Foundation
2007-11-19 22:38 <DIR> d-------- C:\Programmer\Veoh Networks
2007-11-15 21:30 <DIR> d-------- C:\Programmer\SystemRequirementsLab
2007-11-08 16:07 <DIR> d-------- C:\Programmer\ScanSoft
2007-11-08 16:03 <DIR> d-------- C:\WINDOWS\Lhsp
2007-11-07 19:08 <DIR> d-------- C:\Spiludvikling
2007-11-07 18:59 <DIR> d-------- C:\Programmer\Game_Maker7
2007-11-07 14:17 <DIR> d-------- C:\Nexuiz
2007-11-07 14:10 <DIR> d-------- C:\neverball-1.4.0
2007-11-07 14:01 <DIR> d-------- C:\Programmer\dangerdeep
2007-11-06 18:54 <DIR> d-------- C:\Programmer\TrackMania Nations ESWC
2007-11-05 22:41 <DIR> d-------- C:\FTP server upload
2007-11-04 15:46 <DIR> d-------- C:\Programmer\DSFP
2007-11-04 15:10 <DIR> d-------- C:\WINDOWS\system32\languages
2007-11-04 15:10 <DIR> d-------- C:\WINDOWS\system32\custom matrices
2007-11-04 15:10 405,504 --a------ C:\WINDOWS\system32\libmplayer.dll
2007-11-04 15:10 114,688 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll
2007-11-04 15:10 20,480 --a------ C:\WINDOWS\system32\makeAVIS.exe
2007-11-04 15:10 8,192 --a------ C:\WINDOWS\system32\FLT_ffdshow.dll
2007-11-04 14:01 <DIR> d-------- C:\Programmer\Gabest
2007-11-04 13:42 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-11-04 13:42 597,834 --a------ C:\WINDOWS\system32\AS-IFce1.ocx
2007-11-04 13:42 389,120 --a------ C:\WINDOWS\system32\actskn43.ocx
2007-11-04 13:41 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2007-11-04 13:41 1,140,472 --a------ C:\WINDOWS\system32\IGUltraGrid20.ocx
2007-11-04 13:41 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-11-04 13:41 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-11-04 13:01 <DIR> d-------- C:\Programmer\Webteh
2007-11-04 12:47 <DIR> d-------- C:\Undertekst
2007-11-04 12:21 <DIR> d-------- C:\WINDOWS\system32\quicktime
2007-11-04 12:21 <DIR> d-------- C:\Programmer\NimoCodec Pack
2007-11-03 14:23 <DIR> d-------- C:\Programmer\URUSoft
2007-10-31 19:51 921,088 --a------ C:\WINDOWS\MobileLock.exe
2007-10-31 19:51 501,248 --a------ C:\WINDOWS\MobileFavorites.exe
2007-10-31 19:51 341,504 --a------ C:\WINDOWS\udisk_dll.dll
2007-10-31 19:50 <DIR> d-------- C:\WINDOWS\FAQuickMenu
2007-10-31 18:50 <DIR> d-------- C:\Programmer\GIMP-2.0
2007-10-31 15:32 <DIR> d-------- C:\WINDOWS\FLV Player
2007-10-31 15:32 <DIR> d-------- C:\Programmer\FLV Player
2007-10-31 15:25 <DIR> d-------- C:\Programmer\Free FLV Converter
2007-10-31 15:25 208,500 --a------ C:\WINDOWS\system32\ReyXpBasics.tlb
2007-10-31 15:25 15,360 --a------ C:\WINDOWS\system32\inetfr.DLL
2007-10-31 15:05 <DIR> d-------- C:\Programmer\Joost
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 14:01 --------- d-----w C:\Programmer\Winamp
2007-11-19 21:39 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-11-15 20:40 --------- d-----w C:\Programmer\ATI Technologies
2007-11-08 15:27 --------- d-----w C:\Programmer\Duplicate Music Files Finder
2007-11-04 12:58 --------- d-----w C:\Programmer\Pcsx2
2007-11-04 12:57 --------- d-----w C:\Programmer\GameSpy Arcade
2007-11-04 11:40 --------- d-----w C:\Programmer\DivX
2007-11-02 20:03 1,823 ----a-w C:\WINDOWS\Fonts\lang_miss.txt
2007-10-31 16:04 --------- d-----w C:\Programmer\Google
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-21 19:12 --------- d-----w C:\Programmer\Red Storm Entertainment
2007-10-01 12:37 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2007-09-24 12:04 385,128 ----a-w C:\WINDOWS\RST_screensaver.scr
2007-09-24 12:04 29,696 -c--a-w C:\WINDOWS\mickey32.dll
2007-09-24 12:04 2,268,268 ----a-w C:\WINDOWS\RST_screensaver.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Programmer\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Programmer\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-10-23 09:37]
"SoundMAX"="C:\Programmer\Analog Devices\SoundMAX\SMax4.exe" [2003-10-14 14:44]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-02-24 21:10]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 11:50]
"AceGain LiveUpdate"="C:\Programmer\AceGain\LiveUpdate\LiveUpdate.exe" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 11:45 C:\WINDOWS\KHALMNPR.Exe]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2004-03-12 21:43]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"ATICCC"="C:\Programmer\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-09-01 15:57]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-27 01:53]
C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\
Wireless Configuration Utility HW.31.lnk - C:\Programmer\802.11 Wireless LAN\802.11b Pen Size Wireless USB 2.0 Adapter HW.31 V.1.00\WlanCU.exe [2004-06-28 17:11:52]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
WgaLogon.dll 2007-03-15 17:16 236928 C:\WINDOWS\system32\WgaLogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iexplore]
1rgYg.dll
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys
R2 SVKP;SVKP;\??\C:\WINDOWS\system32\SVKP.sys
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys
S4 SISNPF;SIS Netgroup Packet Filter;C:\WINDOWS\system32\drivers\SISNPF.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
\Shell\readit\command - notepad readme.doc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe
\Shell\readit\command - notepad readme.doc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44220b3a-921e-11d9-91ce-936d27d79455}]
\Shell\AutoRun\command - G:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44220b3b-921e-11d9-91ce-936d27d79455}]
\Shell\AutoRun\command - L:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44220b3c-921e-11d9-91ce-936d27d79455}]
\Shell\AutoRun\command - H:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf17c8a1-05f6-11db-939e-0040f4c782d1}]
\Shell\Auto\command - E:\setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-27 08:01:15 C:\WINDOWS\Tasks\Blur - Song 2.job"
- C:\Documents and Settings\Gr›nskolling\Dokumenter\Musik\CKY - 96 Quite Bitter Beings.mp3
"2007-11-22 22:10:37 C:\WINDOWS\Tasks\Kopi af Blur - Song 2.job"
- C:\Documents and Settings\Gr›nskolling\Dokumenter\Musik\Blur - Song 2.mp3
"2007-11-20 21:35:30 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Programmer\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-09-11 13:53:51 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Programmer\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-28 00:38:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-28 0:40:58 - machine was rebooted
.
--- E O F ---
Det ser ud til at ha virket, eller er der mere jeg skal gøre?