ComboFix 07-12-07.3 - Morten F I 2007-12-07 22:06:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.1446 [GMT 1:00]
Running from: C:\Documents and Settings\Morten F I\Skrivebord\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Programmer\download plugin
C:\Programmer\download plugin\DlPlugin-MSIE_1.5.0.0\axdlplug.inf
C:\Programmer\SecCenter
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\adiifjrm.dll
C:\WINDOWS\system32\agroeedr.dll
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\bfxsnecd.dll
C:\WINDOWS\system32\bucehwia.dll
C:\WINDOWS\system32\ddabb.dll
C:\WINDOWS\system32\humhhjte.dll
C:\WINDOWS\system32\jalbwsns.ini
C:\WINDOWS\system32\lipolbfa.dll
C:\WINDOWS\system32\lwvqhjhr.dll
C:\WINDOWS\system32\mljhhig.dll
C:\WINDOWS\system32\ngxvclsk.dll
C:\WINDOWS\system32\ntmxpxau.dll
C:\WINDOWS\system32\onsrvxdb.dll
C:\WINDOWS\system32\rrnyyaju.dll
C:\WINDOWS\system32\snswblaj.dll
C:\WINDOWS\system32\tmp30.tmp
C:\WINDOWS\system32\tmp31.tmp
C:\WINDOWS\system32\tmp32.tmp
C:\WINDOWS\system32\tmp33.tmp
C:\WINDOWS\system32\tqpnogvb.dll
C:\WINDOWS\system32\vikarpqg.dll
C:\WINDOWS\system32\wmljyekj.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\nm
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.
2007-12-07 21:44 . 2007-12-07 21:44 74,304 --a------ C:\WINDOWS\system32\cbqpnnao.exe
2007-12-07 01:02 . 2007-12-07 01:02 7,076 --a------ C:\WINDOWS\system32\vnxnngga.dll
2007-12-06 00:58 . 2007-12-07 00:01 1,961,968 ---hs---- C:\WINDOWS\system32\kdodiftc.ini
2007-12-06 00:13 . 2007-12-06 00:24 1,452,192 ---hs---- C:\WINDOWS\system32\esqocsdn.ini
2007-12-05 13:42 . 2007-12-06 00:01 872,579 ---hs---- C:\WINDOWS\system32\hjdcsofs.ini
2007-12-05 00:09 . 2007-12-05 13:33 796,793 ---hs---- C:\WINDOWS\system32\pfyvicky.ini
2007-12-04 13:41 . 2007-12-05 00:00 793,326 ---hs---- C:\WINDOWS\system32\qyydttcn.ini
2007-12-03 12:28 . 2007-12-04 13:32 803,700 ---hs---- C:\WINDOWS\system32\pylfsaxw.ini
2007-12-02 12:07 . 2007-12-03 12:23 792,312 ---hs---- C:\WINDOWS\system32\djsmdpee.ini
2007-12-01 23:24 . 2007-12-01 23:24 102,912 --a------ C:\WINDOWS\system32\drvfeh.dll
2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-22 16:32 . 2007-11-22 16:32 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-11-22 16:17 . 2007-11-22 16:33 <DIR> d-------- C:\WINDOWS\system32\da-dk
2007-11-15 22:58 . 2007-11-15 22:58 <DIR> d-------- C:\Documents and Settings\Morten F I\Application Data\Microsoft Games
2007-11-12 18:29 . 2007-11-12 18:29 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2007-11-12 18:29 . 2007-11-12 18:29 22,328 --a------ C:\Documents and Settings\Morten F I\Application Data\PnkBstrK.sys
2007-11-12 15:34 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-12 15:34 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-11-11 18:50 . 2007-11-11 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-11-11 18:39 . 2007-11-11 18:39 <DIR> d-------- C:\Programmer\Windows Live
2007-11-11 18:35 . 2007-11-11 19:05 <DIR> d-------- C:\Programmer\MSN Messenger
2007-11-11 18:15 . 2007-11-11 18:29 <DIR> d-------- C:\Programmer\Messenger Plus! Live
2007-11-11 18:04 . 2004-08-26 17:53 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-11-11 18:04 . 2004-08-26 17:53 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2007-11-11 18:04 . 2004-08-26 17:49 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-11-11 18:04 . 2004-08-26 17:49 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-11-11 16:20 . 2007-11-11 16:20 <DIR> d-------- C:\Programmer\Microsoft CAPICOM 2.1.0.2
2007-11-11 15:48 . <DIR> C:\Programmer\Fælles filer\WindowsLiveInstaller
2007-11-11 15:47 . 2007-11-11 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-11 04:31 . 2007-11-11 04:31 <DIR> d-------- C:\Documents and Settings\Morten F I\Application Data\Sierra Entertainment
2007-11-11 02:29 . 2007-11-18 19:22 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2007-11-11 02:29 . 2007-11-18 19:22 <DIR> d-------- C:\Programmer\AGEIA Technologies
2007-11-10 21:54 . 2007-11-10 21:54 <DIR> d-------- C:\Documents and Settings\Morten F I\Application Data\Turbine
2007-11-10 21:44 . 2007-11-10 21:44 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 21:12 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-12-07 20:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-07 13:12 --------- d-----w C:\Documents and Settings\Morten F I\Application Data\Azureus
2007-12-05 23:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-05 23:06 --------- d-----w C:\Programmer\Fælles filer\Symantec Shared
2007-12-05 13:16 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-05 13:16 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-05 13:16 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-05 13:16 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-05 13:16 --------- d-----w C:\Programmer\Symantec
2007-11-27 19:47 --------- d-----w C:\Programmer\Winamp
2007-11-18 19:09 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-11-18 18:22 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2007-11-17 22:02 --------- d-----w C:\Programmer\Norton AntiVirus
2007-11-12 17:29 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-11-12 17:29 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-12 17:29 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-02 16:38 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-31 22:35 --------- d-----w C:\Programmer\CloneCD
2007-10-31 21:36 81,920 ----a-w C:\Documents and Settings\Morten F I\Application Data\ezpinst.exe
2007-10-31 21:36 47,360 ----a-w C:\Documents and Settings\Morten F I\Application Data\pcouffin.sys
2007-10-31 21:36 --------- d-----w C:\Documents and Settings\Morten F I\Application Data\Vso
2007-10-31 21:32 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-10-30 20:13 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2007-10-30 20:13 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2007-10-30 20:08 --------- d-----w C:\Programmer\DAEMON Tools Pro
2007-10-30 19:58 --------- d-----w C:\Documents and Settings\Morten F I\Application Data\DAEMON Tools Pro
2007-10-30 19:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-10-30 18:55 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-30 18:55 39,856 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 18:55 37,936 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 18:55 35,120 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 18:55 27,696 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 18:55 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-30 18:55 191,536 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 18:55 145,968 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 18:55 12,848 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-30 18:24 12,963 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-30 18:24 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-29 20:56 --------- d-----w C:\Programmer\Azureus
2007-10-27 18:31 --------- d-----w C:\Programmer\HLSW
2007-10-24 22:15 --------- d-----w C:\Programmer\Java
2007-10-09 20:18 --------- d-----w C:\Programmer\ATI Driver
2007-10-05 18:36 315,392 ----a-w C:\WINDOWS\HideWin.exe
2007-09-23 17:20 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-09-23 17:20 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-09-13 08:45 70,944 ----a-w C:\WINDOWS\system32\PhysXLoader.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 16:53]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"SystemTray"="SysTray.Exe" [2001-10-09 14:00 C:\WINDOWS\system32\systray.exe]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"osCheck"="C:\Programmer\Norton AntiVirus\osCheck.exe" [2006-09-05 20:22]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"ISUSScheduler"="C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" []
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" []
"LogitechQuickCamRibbon"="C:\Programmer\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06]
"StartCCC"="C:\Programmer\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 15:08 C:\WINDOWS\RTHDCPL.exe]
"CloneCDElbyCDFL"="C:\Programmer\CloneCD\ElbyCheck.exe" [2002-11-02 07:33]
"Symantec PIF AlertEng"="C:\Programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-26 16:53]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwim32]
winwim32.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-06-29 19:05:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Morten F I.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-07 22:12:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 22:13:35 - machine was rebooted
.
--- E O F ---