undskyld ventetiden - påskefrokost
Ja virtual earth og virtualclonedrive
"tommy olsen" - 07-04-06 13:08:09 Service Pack 2
ComboFix 07-04-05 - Running from: "D:\download\sikkerhed"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\84379234.DLL
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
-------\LEGACY_MCHINJDRV
-------\LEGACY_WINDOWS_LOG
((((((((((((((((((((((((((((((( Files Created from 2007-03-06 to 2007-04-06 ))))))))))))))))))))))))))))))))))
2007-04-05 00:09 <DIR> d-------- C:\Programmer\Virtual Earth 3D
2007-04-04 23:41 <DIR> d-------- C:\Programmer\ScanSoft
2007-04-04 23:26 <DIR> d-------- C:\Programmer\PC Connectivity Solution
2007-04-04 23:20 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
2007-04-04 21:04 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-04-04 19:54 22,848 --a------ C:\WINDOWS\system32\drivers\LwUsbHid.sys
2007-04-04 16:30 <DIR> d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\Nokia Multimedia Player
2007-04-04 16:23 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-04-04 16:23 27,648 --a------ C:\WINDOWS\system32\irmon.dll
2007-04-04 16:23 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2007-04-04 16:19 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Dokumenter
2007-04-04 11:44 1 --a------ C:\WINDOWS\system32\index.dat
2007-04-03 23:04 14,122 --a------ C:\WINDOWS\system32\B23FD116.exe
2007-04-02 21:01 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-04-02 18:23 <DIR> d-------- C:\Programmer\F‘lles filer\Ankiro
2007-04-02 18:22 <DIR> d-------- C:\Programmer\SPAMfighter
2007-04-02 18:22 <DIR> d-------- C:\Programmer\F‘lles filer\Application
2007-04-02 18:22 <DIR> d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\SPAMfighter
2007-03-11 20:06 <DIR> d-------- C:\Programmer\CDBurnerXP Pro 3
2007-03-11 15:38 58,904 --a------ C:\WINDOWS\system32\sysfolderazipcnt.dll
2007-03-11 15:38 58,904 --a------ C:\WINDOWS\system32\azipcontmn.dll
2007-03-11 15:38 <DIR> d-------- C:\Programmer\AlphaZIP
2007-03-10 21:14 <DIR> d-------- C:\Programmer\Red Kawa
2007-03-10 21:10 <DIR> d-------- C:\Programmer\Videora
2007-03-10 21:10 <DIR> d-------- C:\Programmer\BitComet
2007-03-10 21:07 <DIR> d-------- C:\Programmer\Boilsoft MP4 Converter
2007-03-10 20:55 81,920 --a------ C:\WINDOWS\system32\viscomwave.dll
2007-03-10 20:55 475,136 --a------ C:\WINDOWS\system32\SkinCrafter.dll
2007-03-10 20:55 139,264 --a------ C:\WINDOWS\system32\viscomqtde.dll
2007-03-10 20:55 <DIR> d-------- C:\Programmer\Plato Video To iPod Converter
2007-03-07 22:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Elaborate Bytes
2007-03-07 20:46 <DIR> d-------- C:\Programmer\DVD Decrypter
2007-03-07 20:07 <DIR> d-------- C:\Programmer\Elaborate Bytes
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-06 12:04 -------- d-------- C:\Programmer\emule
2007-04-05 12:47 -------- d-------- C:\Programmer\superantispyware
2007-04-05 10:31 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\nokia
2007-04-04 23:28 -------- d-------- C:\Programmer\difx
2007-04-04 23:27 -------- d-------- C:\Programmer\nokia
2007-04-04 23:27 -------- d-------- C:\Programmer\F‘lles filer\pcsuite
2007-04-04 23:27 -------- d-------- C:\Programmer\F‘lles filer\nokia
2007-04-04 23:15 73258 --a------ C:\WINDOWS\system32\perfc006.dat
2007-04-04 23:15 415362 --a------ C:\WINDOWS\system32\perfh006.dat
2007-04-04 20:53 -------- d-------- C:\Programmer\electronic arts
2007-04-04 20:51 -------- d-------- C:\Programmer\maplom
2007-03-29 16:59 -------- d-------- C:\Programmer\spywareblaster
2007-03-13 21:48 -------- d--h----- C:\Programmer\installshield installation information
2007-03-08 17:38 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:35 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-04 20:32 -------- d-------- C:\Programmer\registrysmart
2007-03-04 17:44 -------- d-------- C:\Programmer\itunes
2007-03-04 17:44 -------- d-------- C:\Programmer\ipod
2007-03-04 17:43 -------- d-------- C:\Programmer\quicktime
2007-03-04 14:38 -------- d-------- C:\Programmer\wincustomize
2007-03-04 14:38 -------- d-------- C:\Programmer\F‘lles filer\stardock
2007-03-04 14:16 -------- d-------- C:\Programmer\chemix skole3_00
2007-03-03 01:18 -------- d-------- C:\Programmer\pro imaging powertoys
2007-03-03 01:18 -------- d-------- C:\Programmer\java
2007-03-03 01:18 -------- d-------- C:\Programmer\F‘lles filer\nikon
2007-03-03 00:53 -------- d-------- C:\Programmer\dvd shrink
2007-02-28 21:34 -------- d-------- C:\Programmer\diskeeper corporation
2007-02-27 22:10 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\leadertech
2007-02-24 14:19 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\desktop sidebar
2007-02-23 17:42 2156544 --a------ C:\WINDOWS\system32\kernel1.exe
2007-02-23 17:37 -------- d-------- C:\Programmer\tgtsoft
2007-02-22 10:15 90624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-02-21 22:37 -------- d---s---- C:\Programmer\xfire
2007-02-21 22:37 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\xfire
2007-02-21 22:02 -------- d-------- C:\Programmer\gamespy arcade
2007-02-21 19:41 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\reasonable software
2007-02-20 22:21 -------- d-------- C:\Programmer\reasonable noclone 4 home
2007-02-20 21:27 -------- d-------- C:\Programmer\desktop sidebar
2007-02-18 19:10 -------- d-------- C:\Programmer\winace
2007-02-11 17:51 1093632 --a------ C:\WINDOWS\system32\freeimage.dll
2007-02-08 21:14 -------- d-------- C:\DOCUME~1\TOMMYO~1\APPLIC~1\help
2007-02-06 22:24 -------- d-------- C:\Programmer\canon
2007-02-06 21:35 -------- d-------- C:\Programmer\copernic desktop search 2
2007-02-06 21:29 5 --a------ C:\WINDOWS\system32\netdetect.dat
2007-02-06 21:29 23 --a------ C:\WINDOWS\system32\userlst.dat
2007-02-06 21:29 -------- d-------- C:\Programmer\gallup interactive
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"d:\\progra~1\\valve\\steam\\steam.exe\" -silent"
"TuneUp MemOptimizer"="\"C:\\Programmer\\TuneUp Utilities 2006\\MemOptimizer.exe\" autostart"
"LClock"="C:\\Programmer\\LClock\\lclock.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"PcSync"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Programmer\\Fælles filer\\Ahead\\lib\\NMBgMonitor.exe\""
"swg"="C:\\Programmer\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"MsnMsgr"="\"C:\\Programmer\\MSN Messenger\\MsnMsgr.Exe\" /background"
"SUPERAntiSpyware"="C:\\Programmer\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"
"WMPNSCFG"="C:\\Programmer\\Windows Media Player\\WMPNSCFG.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NVIDIA nTune"="\"C:\\Programmer\\NVIDIA Corporation\\nTune\\\\nTune.exe\" clear"
"SunJavaUpdateSched"="\"C:\\Programmer\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"LClock"="C:\\Programmer\\LClock\\LClock.exe"
"WINCINEMAMGR"="C:\\Programmer\\InterVideo\\Common\\Bin\\WinCinemaMgr.exe"
"NWEReboot"=""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"DiskeeperSystray"="\"C:\\Programmer\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"LogonStudio"="\"C:\\Programmer\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
"QuickTime Task"="\"C:\\Programmer\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Programmer\\iTunes\\iTunesHelper.exe\""
"Maplom"="C:\\Programmer\\Maplom\\Maplom.exe"
"SPAMfighter Agent"="\"C:\\Programmer\\SPAMfighter\\SFAgent.exe\" update delay 60"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"PCSuiteTrayApplication"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -startup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"Nokia.PCSync"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20060813-185839-259
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe
backup-20060813-185838-582
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A9B0DC39-901C-40B2-BA94-ADF1AA5E2F98}.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-06 13:10:32
C:\ComboFix-quarantined-files.txt ... 07-04-06 13:10