undskyld ventetiden - påskefrokost 
Ja virtual earth og virtualclonedrive
"tommy olsen" - 07-04-06 13:08:09    Service Pack 2
ComboFix 07-04-05 - Running from: "D:\download\sikkerhed"
((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\84379234.DLL
(((((((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
-------\LEGACY_MCHINJDRV
-------\LEGACY_WINDOWS_LOG
(((((((((((((((((((((((((((((((   Files Created from 2007-03-06 to 2007-04-06  ))))))))))))))))))))))))))))))))))
2007-04-05 00:09   <DIR>   d--------   C:\Programmer\Virtual Earth 3D
2007-04-04 23:41   <DIR>   d--------   C:\Programmer\ScanSoft
2007-04-04 23:26   <DIR>   d--------   C:\Programmer\PC Connectivity Solution
2007-04-04 23:20   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
2007-04-04 21:04   2,297,552   --a------   C:\WINDOWS\system32\d3dx9_26.dll
2007-04-04 19:54   22,848   --a------   C:\WINDOWS\system32\drivers\LwUsbHid.sys
2007-04-04 16:30   <DIR>   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\Nokia Multimedia Player
2007-04-04 16:23   8,192   --a------   C:\WINDOWS\system32\wshirda.dll
2007-04-04 16:23   27,648   --a------   C:\WINDOWS\system32\irmon.dll
2007-04-04 16:23   153,088   --a------   C:\WINDOWS\system32\irftp.exe
2007-04-04 16:19   <DIR>   d--------   C:\DOCUME~1\NETWOR~1\Dokumenter
2007-04-04 11:44   1   --a------   C:\WINDOWS\system32\index.dat
2007-04-03 23:04   14,122   --a------   C:\WINDOWS\system32\B23FD116.exe
2007-04-02 21:01   <DIR>   d--------   C:\WINDOWS\SxsCaPendDel
2007-04-02 18:23   <DIR>   d--------   C:\Programmer\F‘lles filer\Ankiro
2007-04-02 18:22   <DIR>   d--------   C:\Programmer\SPAMfighter
2007-04-02 18:22   <DIR>   d--------   C:\Programmer\F‘lles filer\Application
2007-04-02 18:22   <DIR>   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\SPAMfighter
2007-03-11 20:06   <DIR>   d--------   C:\Programmer\CDBurnerXP Pro 3
2007-03-11 15:38   58,904   --a------   C:\WINDOWS\system32\sysfolderazipcnt.dll
2007-03-11 15:38   58,904   --a------   C:\WINDOWS\system32\azipcontmn.dll
2007-03-11 15:38   <DIR>   d--------   C:\Programmer\AlphaZIP
2007-03-10 21:14   <DIR>   d--------   C:\Programmer\Red Kawa
2007-03-10 21:10   <DIR>   d--------   C:\Programmer\Videora
2007-03-10 21:10   <DIR>   d--------   C:\Programmer\BitComet
2007-03-10 21:07   <DIR>   d--------   C:\Programmer\Boilsoft MP4 Converter
2007-03-10 20:55   81,920   --a------   C:\WINDOWS\system32\viscomwave.dll
2007-03-10 20:55   475,136   --a------   C:\WINDOWS\system32\SkinCrafter.dll
2007-03-10 20:55   139,264   --a------   C:\WINDOWS\system32\viscomqtde.dll
2007-03-10 20:55   <DIR>   d--------   C:\Programmer\Plato Video To iPod Converter
2007-03-07 22:18   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\APPLIC~1\Elaborate Bytes
2007-03-07 20:46   <DIR>   d--------   C:\Programmer\DVD Decrypter
2007-03-07 20:07   <DIR>   d--------   C:\Programmer\Elaborate Bytes
 
 
((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-06 12:04   --------   d--------   C:\Programmer\emule
2007-04-05 12:47   --------   d--------   C:\Programmer\superantispyware
2007-04-05 10:31   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\nokia
2007-04-04 23:28   --------   d--------   C:\Programmer\difx
2007-04-04 23:27   --------   d--------   C:\Programmer\nokia
2007-04-04 23:27   --------   d--------   C:\Programmer\F‘lles filer\pcsuite
2007-04-04 23:27   --------   d--------   C:\Programmer\F‘lles filer\nokia
2007-04-04 23:15   73258   --a------   C:\WINDOWS\system32\perfc006.dat
2007-04-04 23:15   415362   --a------   C:\WINDOWS\system32\perfh006.dat
2007-04-04 20:53   --------   d--------   C:\Programmer\electronic arts
2007-04-04 20:51   --------   d--------   C:\Programmer\maplom
2007-03-29 16:59   --------   d--------   C:\Programmer\spywareblaster
2007-03-13 21:48   --------   d--h-----   C:\Programmer\installshield installation information
2007-03-08 17:38   577536   --a------   C:\WINDOWS\system32\user32.dll
2007-03-08 17:38   40960   --a------   C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38   281600   --a------   C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:35   1843584   --a------   C:\WINDOWS\system32\win32k.sys
2007-03-04 20:32   --------   d--------   C:\Programmer\registrysmart
2007-03-04 17:44   --------   d--------   C:\Programmer\itunes
2007-03-04 17:44   --------   d--------   C:\Programmer\ipod
2007-03-04 17:43   --------   d--------   C:\Programmer\quicktime
2007-03-04 14:38   --------   d--------   C:\Programmer\wincustomize
2007-03-04 14:38   --------   d--------   C:\Programmer\F‘lles filer\stardock
2007-03-04 14:16   --------   d--------   C:\Programmer\chemix skole3_00
2007-03-03 01:18   --------   d--------   C:\Programmer\pro imaging powertoys
2007-03-03 01:18   --------   d--------   C:\Programmer\java
2007-03-03 01:18   --------   d--------   C:\Programmer\F‘lles filer\nikon
2007-03-03 00:53   --------   d--------   C:\Programmer\dvd shrink
2007-02-28 21:34   --------   d--------   C:\Programmer\diskeeper corporation
2007-02-27 22:10   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\leadertech
2007-02-24 14:19   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\desktop sidebar
2007-02-23 17:42   2156544   --a------   C:\WINDOWS\system32\kernel1.exe
2007-02-23 17:37   --------   d--------   C:\Programmer\tgtsoft
2007-02-22 10:15   90624   --a------   C:\WINDOWS\system32\nmwcdcls.dll
2007-02-21 22:37   --------   d---s----   C:\Programmer\xfire
2007-02-21 22:37   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\xfire
2007-02-21 22:02   --------   d--------   C:\Programmer\gamespy arcade
2007-02-21 19:41   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\reasonable software
2007-02-20 22:21   --------   d--------   C:\Programmer\reasonable noclone 4 home
2007-02-20 21:27   --------   d--------   C:\Programmer\desktop sidebar
2007-02-18 19:10   --------   d--------   C:\Programmer\winace
2007-02-11 17:51   1093632   --a------   C:\WINDOWS\system32\freeimage.dll
2007-02-08 21:14   --------   d--------   C:\DOCUME~1\TOMMYO~1\APPLIC~1\help
2007-02-06 22:24   --------   d--------   C:\Programmer\canon
2007-02-06 21:35   --------   d--------   C:\Programmer\copernic desktop search 2
2007-02-06 21:29   5   --a------   C:\WINDOWS\system32\netdetect.dat
2007-02-06 21:29   23   --a------   C:\WINDOWS\system32\userlst.dat
2007-02-06 21:29   --------   d--------   C:\Programmer\gallup interactive
2007-01-19 13:53   51056   --a------   C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01   17408   --a------   C:\WINDOWS\system32\corpol.dll
 
 
((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"d:\\progra~1\\valve\\steam\\steam.exe\" -silent"
"TuneUp MemOptimizer"="\"C:\\Programmer\\TuneUp Utilities 2006\\MemOptimizer.exe\" autostart"
"LClock"="C:\\Programmer\\LClock\\lclock.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"PcSync"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Programmer\\Fælles filer\\Ahead\\lib\\NMBgMonitor.exe\""
"swg"="C:\\Programmer\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"MsnMsgr"="\"C:\\Programmer\\MSN Messenger\\MsnMsgr.Exe\" /background"
"SUPERAntiSpyware"="C:\\Programmer\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"
"WMPNSCFG"="C:\\Programmer\\Windows Media Player\\WMPNSCFG.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NVIDIA nTune"="\"C:\\Programmer\\NVIDIA Corporation\\nTune\\\\nTune.exe\" clear"
"SunJavaUpdateSched"="\"C:\\Programmer\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"LClock"="C:\\Programmer\\LClock\\LClock.exe"
"WINCINEMAMGR"="C:\\Programmer\\InterVideo\\Common\\Bin\\WinCinemaMgr.exe"
"NWEReboot"=""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"DiskeeperSystray"="\"C:\\Programmer\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"LogonStudio"="\"C:\\Programmer\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
"QuickTime Task"="\"C:\\Programmer\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Programmer\\iTunes\\iTunesHelper.exe\""
"Maplom"="C:\\Programmer\\Maplom\\Maplom.exe"
"SPAMfighter Agent"="\"C:\\Programmer\\SPAMfighter\\SFAgent.exe\" update delay 60"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"PCSuiteTrayApplication"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -startup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"Nokia.PCSync"="C:\\Programmer\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
   Authentication Packages   REG_MULTI_SZ      msv1_0\0\0
   Security Packages   REG_MULTI_SZ      kerberos\0msv1_0\0schannel\0wdigest\0\0
   Notification Packages   REG_MULTI_SZ      scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService   REG_MULTI_SZ      Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService   REG_MULTI_SZ      DnsCache\0\0
rpcss   REG_MULTI_SZ      RpcSs\0\0
imgsvc   REG_MULTI_SZ      StiSvc\0\0
termsvcs   REG_MULTI_SZ      TermService\0\0
HTTPFilter   REG_MULTI_SZ      HTTPFilter\0\0
DcomLaunch   REG_MULTI_SZ      DcomLaunch\0TermService\0\0
WudfServiceGroup   REG_MULTI_SZ      WUDFSvc\0\0
bthsvcs   REG_MULTI_SZ      BthServ\0\0
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20060813-185839-259 
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe
backup-20060813-185838-582 
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A9B0DC39-901C-40B2-BA94-ADF1AA5E2F98}.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-06 13:10:32
C:\ComboFix-quarantined-files.txt ... 07-04-06 13:10