ComboFix 07-10-02.2 - moheka 2007-10-02 17:54:08.1 - NTFSx86
Microsoft© Windows VistaT Home Premium 6.0.6000.0.1252.1.1030.18.1346 [GMT 2:00]
Running from: C:\Users\moheka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\617RW2FC\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-02 to 2007-10-02 )))))))))))))))))))))))))))))))
.
2007-10-02 17:52 51,200 --a------ C:\Windows\NirCmd.exe
2007-10-02 16:50 <DIR> d-------- C:\Program Files\RegCleaner
2007-09-16 21:32 <DIR> d-------- C:\N360_BACKUP
2007-09-16 18:08 <DIR> d-------- C:\Users\moheka\AppData\Roaming\Symantec
2007-09-07 08:25 <DIR> d-------- C:\Users\moheka\AppData\Roaming\Politiken
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-02 17:49 --------- d-------- C:\Users\moheka\AppData\Roaming\Skype
2007-10-02 17:36 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-16 08:40 --------- d-------- C:\Program Files\Windows Mail
2007-08-31 09:38 --------- d-------- C:\Program Files\Polob32
2007-08-31 09:25 174 --ahs---- C:\Program Files\desktop.ini
2007-08-31 09:20 --------- d-------- C:\Program Files\Windows Calendar
2007-08-31 09:19 8192 --a------ C:\Windows\System32\riched32.dll
2007-08-31 09:19 77824 --a------ C:\Windows\System32\rascfg.dll
2007-08-31 09:19 70144 --a------ C:\Windows\system32\drivers\pacer.sys
2007-08-31 09:19 694784 --a------ C:\Windows\System32\localspl.dll
2007-08-31 09:19 61952 --a------ C:\Windows\system32\drivers\wanarp.sys
2007-08-31 09:19 619008 --a------ C:\Windows\system32\drivers\dxgkrnl.sys
2007-08-31 09:19 52736 --a------ C:\Windows\System32\rasdiag.dll
2007-08-31 09:19 48640 --a------ C:\Windows\system32\drivers\ndproxy.sys
2007-08-31 09:19 384000 --a------ C:\Windows\System32\netcfgx.dll
2007-08-31 09:19 36864 --a------ C:\Windows\System32\cdd.dll
2007-08-31 09:19 33280 --a------ C:\Windows\System32\traffic.dll
2007-08-31 09:19 32768 --a------ C:\Windows\System32\rasmxs.dll
2007-08-31 09:19 286208 --a------ C:\Windows\System32\ipnathlp.dll
2007-08-31 09:19 22016 --a------ C:\Windows\System32\rasser.dll
2007-08-31 09:19 20480 --a------ C:\Windows\system32\drivers\ndistapi.sys
2007-08-31 09:19 15360 --a------ C:\Windows\System32\pacerprf.dll
2007-08-31 09:19 13824 --a------ C:\Windows\System32\wshqos.dll
2007-08-31 09:19 13824 --a------ C:\Windows\System32\icsunattend.exe
2007-08-31 09:19 134656 --a------ C:\Windows\System32\dps.dll
2007-08-31 09:17 88576 --a------ C:\Windows\System32\avifil32.dll
2007-08-31 09:17 82944 --a------ C:\Windows\System32\mciavi32.dll
2007-08-31 09:17 8138240 --a------ C:\Windows\System32\ssBranded.scr
2007-08-31 09:17 712192 --a------ C:\Windows\System32\WindowsCodecs.dll
2007-08-31 09:17 704000 --a------ C:\Windows\System32\PhotoScreensaver.scr
2007-08-31 09:17 69632 --a------ C:\Windows\System32\sendmail.dll
2007-08-31 09:17 65024 --a------ C:\Windows\System32\avicap32.dll
2007-08-31 09:17 61440 --a------ C:\Windows\System32\ntprint.exe
2007-08-31 09:17 3504824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-08-31 09:17 3470008 --a------ C:\Windows\System32\ntoskrnl.exe
2007-08-31 09:17 31232 --a------ C:\Windows\System32\msvidc32.dll
2007-08-31 09:17 269824 --a------ C:\Windows\System32\schannel.dll
2007-08-31 09:17 220160 --a------ C:\Windows\System32\ntprint.dll
2007-08-31 09:17 1984512 --a------ C:\Windows\System32\authui.dll
2007-08-31 09:17 12800 --a------ C:\Windows\System32\msrle32.dll
2007-08-31 09:17 123904 --a------ C:\Windows\System32\msvfw32.dll
2007-08-31 09:17 120320 --a------ C:\Windows\System32\dhcpcsvc6.dll
2007-08-31 09:17 10240 --a------ C:\Windows\System32\dhcpcmonitor.dll
2007-08-31 09:16 750080 --a------ C:\Windows\System32\qmgr.dll
2007-08-24 08:00 53080 --a------ C:\Windows\System32\wuauclt.exe
2007-08-24 08:00 43352 --a------ C:\Windows\System32\wups2.dll
2007-08-24 08:00 1712984 --a------ C:\Windows\System32\wuaueng.dll
2007-08-24 08:00 1524224 --a------ C:\Windows\System32\wucltux.dll
2007-08-24 07:59 80896 --a------ C:\Windows\System32\wudriver.dll
2007-08-24 07:59 549720 --a------ C:\Windows\System32\wuapi.dll
2007-08-24 07:59 33624 --a------ C:\Windows\System32\wups.dll
2007-08-24 07:58 31232 --a------ C:\Windows\System32\wuapp.exe
2007-08-24 07:58 163000 --a------ C:\Windows\System32\wuwebv.dll
2007-08-18 15:40 --------- d-------- C:\Users\moheka\AppData\Roaming\Roxio
2007-08-16 08:23 8147968 --a------ C:\Windows\System32\wmploc.DLL
2007-08-16 08:23 7680 --a------ C:\Windows\System32\spwmp.dll
2007-08-16 08:23 4096 --a------ C:\Windows\System32\dxmasf.dll
2007-08-16 08:22 1191936 --a------ C:\Windows\System32\msxml3.dll
2007-08-16 08:21 1335296 --a------ C:\Windows\System32\msxml6.dll
2007-08-16 08:19 56320 --a------ C:\Windows\System32\iesetup.dll
2007-08-16 08:19 52736 --a------ C:\Windows\AppPatch\iebrshim.dll
2007-08-16 08:19 26624 --a------ C:\Windows\System32\ieUnatt.exe
2007-07-12 07:56 86016 --a------ C:\Windows\System32\icfupgd.dll
2007-07-12 07:56 61952 --a------ C:\Windows\System32\cmifw.dll
2007-07-12 07:56 396800 --a------ C:\Windows\System32\MPSSVC.dll
2007-07-12 07:56 392192 --a------ C:\Windows\System32\FirewallAPI.dll
2007-07-12 07:56 374456 --a------ C:\Windows\System32\mcupdate_GenuineIntel.dll
2007-07-12 07:56 178688 --a------ C:\Windows\System32\iphlpsvc.dll
2007-07-12 07:56 16896 --a------ C:\Windows\System32\wfapigp.dll
2007-07-12 07:55 537600 --a------ C:\Windows\AppPatch\AcLayers.dll
2007-07-12 07:55 449536 --a------ C:\Windows\AppPatch\AcSpecfc.dll
2007-07-12 07:55 4247552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2007-07-12 07:55 2144256 --a------ C:\Windows\AppPatch\AcGenral.dll
2007-07-12 07:55 173056 --a------ C:\Windows\AppPatch\AcXtrnal.dll
2007-07-12 07:55 1686528 --a------ C:\Windows\System32\gameux.dll
2007-07-12 07:54 57856 --a------ C:\Windows\System32\SLUINotify.dll
2007-07-12 07:54 566784 --a------ C:\Windows\System32\SLCommDlg.dll
2007-07-12 07:54 39936 --a------ C:\Windows\System32\slcinst.dll
2007-07-12 07:54 351232 --a------ C:\Windows\System32\SLUI.exe
2007-07-12 07:54 33280 --a------ C:\Windows\System32\slwmi.dll
2007-07-12 07:54 268288 --a------ C:\Windows\System32\mcbuilder.exe
2007-07-12 07:54 2605568 --a------ C:\Windows\System32\SLsvc.exe
2007-07-12 07:54 223232 --a------ C:\Windows\System32\SLC.dll
2007-07-12 07:54 186368 --a------ C:\Windows\System32\SLLUA.exe
2007-04-28 15:19:27 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-28 15:43]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 08:02]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-12-02 17:32]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 11:58]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-12-04 13:39]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 10:56]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 10:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-02-04 10:15]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-02-27 11:26]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-02-27 11:26]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-02-27 11:26]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 14:35]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-03-30 13:34]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
@=C:\Program Files\Internet Explorer\iexplore.exe
http://www.symantec.com/techsupp/servlet/ProductMessages?module=2007&error=0&language=da&product=SymNRT&version=2008.0.1.19&build=Symantec&a=00000082.00000045.00000119&b=00000082.00000046.000000b5&c=00000082.00000049.000000d3
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Launcher"=%WINDIR%\SMINST\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys
R3 btwaudio;Bluetooth-audioenhed;C:\Windows\system32\drivers\btwaudio.sys
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys
R3 HBtnKey;HBtnKey;C:\Windows\system32\DRIVERS\cpqbttn.sys
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys
S2 Automatisk LiveUpdate-planlægning;Automatisk LiveUpdate-planlægning;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
S3 BCM43XV;Driver til Broadcom Extensible 802.11-netværkskort;C:\Windows\system32\DRIVERS\bcmwl6.sys
S3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys
S3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys
S3 viaagp;VIA AGP Bus Filter;C:\Windows\system32\drivers\viaagp.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a9c46c11-f5c2-11db-a8c8-806e6f6e6963}]
AutoRun\command- F:\CDStart.Exe
Install\Command- F:\Stub.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-02 17:56:27
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-02 17:57:45
.
--- E O F ---