ComboFix 09-09-09.04 - Mataza 2009-09-10 8:56.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2047.1077 [GMT 2:00]
Körs från: c:\documents and settings\Mataza\Mina dokument\Downloads\Programs\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
c:\windows\Installer\WMEncoder.msi
c:\windows\service.exe
c:\windows\system.exe
c:\windows\system32\pagefileconfig.vbs
c:\windows\system32\plugin.dat
.
(((((((((((((((((((((((( Filer Skapade från 2009-08-10 till 2009-09-10 ))))))))))))))))))))))))))))))
.
2009-09-09 15:42 . 2009-09-09 15:47 ——– d—–w- c:\program\Diablo II
2009-09-09 14:41 . 2009-09-09 14:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Last.fm
2009-09-09 14:40 . 2009-09-09 14:40 ——– d—–w- c:\program\Last.fm
2009-09-09 09:50 . 2009-09-09 09:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\ImgBurn
2009-09-09 08:54 . 2009-09-09 08:54 ——– d—–w- c:\program\ImgBurn
2009-09-09 08:53 . 2009-09-09 08:53 ——– d—–w- C:\X360HP Temp
2009-09-09 08:48 . 2009-09-09 08:50 ——– d—–w- c:\program\Xbox 360 Hack Pack RC1
2009-09-08 22:24 . 2009-09-08 22:24 ——– d—–w- c:\program\Microsoft
2009-09-08 22:05 . 2009-09-08 22:24 ——– d—–w- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-09-08 22:05 . 2009-09-08 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-09-08 22:04 . 2009-09-08 22:04 ——– d—–w- c:\documents and settings\Mataza\Contacts
2009-09-08 21:34 . 2009-09-08 22:06 ——– d—–w- c:\program\MSN Messenger
2009-09-08 21:28 . 2009-09-08 21:32 ——– d—–w- c:\program\Messengern
2009-09-08 14:00 . 2009-09-08 14:00 ——– d—–w- c:\program\Delade filer\Adobe AIR
2009-09-07 14:51 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Construction Set Demo
2009-09-07 04:45 . 2009-09-07 04:45 ——– d–h–w- c:\windows\PIF
2009-09-06 05:57 . 2009-09-06 05:57 ——– d—–w- c:\program\Delade filer\NSV
2009-09-06 02:51 . 2009-09-06 03:57 ——– d—–w- c:\program\Need for Speed Most Wanted
2009-09-05 05:11 . 2009-09-05 05:11 ——– d—–w- c:\program\Delade filer\Logitech
2009-09-05 02:18 . 2009-09-05 02:22 ——– d—–w- c:\program\Euro Truck Simulator
2009-09-04 20:15 . 2009-09-04 20:15 ——– d—–w- c:\program\Microsoft Games
2009-09-04 00:49 . 2009-09-04 16:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-09-04 00:49 . 2009-09-04 00:48 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-09-04 00:49 . 2009-09-04 00:48 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-04 00:49 . 2009-09-04 00:48 179792 —-a-w- c:\windows\system32\guard32.dll
2009-09-04 00:49 . 2009-09-04 00:48 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-04 00:48 . 2009-09-04 00:48 ——– d—–w- c:\program\COMODO
2009-09-03 18:07 . 2009-09-03 18:07 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-09-02 16:55 . 2009-09-05 00:15 ——– d—–w- c:\program\PokerStars
2009-09-02 16:53 . 2009-09-08 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\TeamViewer
2009-09-02 16:53 . 2009-09-02 16:53 ——– d—–w- c:\program\TeamViewer
2009-09-02 16:52 . 2009-09-02 16:52 ——– d—–w- c:\documents and settings\Mataza\temp
2009-09-02 13:53 . 2009-09-07 14:32 ——– d—–w- c:\program\AionEU
2009-09-02 13:53 . 2009-09-02 13:53 ——– d—–w- c:\program\NCsoft
2009-08-31 20:37 . 2009-08-31 20:37 ——– d—–w- c:\program\Microsoft Silverlight
2009-08-30 22:18 . 2009-08-30 23:23 ——– d—–w- c:\documents and settings\Mataza\Application Data\NoNameScript
2009-08-29 23:42 . 2009-08-29 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Creative
2009-08-28 23:58 . 2009-08-28 23:58 ——– d—–w- c:\program\Audacity
2009-08-28 23:50 . 1999-09-17 08:56 118784 —-a-w- c:\windows\system32\mp3dec.dll
2009-08-27 13:02 . 2009-08-27 14:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\HLSW
2009-08-27 13:02 . 2009-08-27 13:03 ——– d-s—w- c:\program\HLSW
2009-08-25 18:37 . 2009-08-25 19:01 ——– d—–w- c:\documents and settings\Mataza\Application Data\Download Manager
2009-08-25 17:23 . 2009-08-25 17:23 ——– d—–w- c:\program\RealVNC
2009-08-24 12:25 . 2005-01-03 06:43 4682 —-a-w- c:\windows\system32\npptNT2.sys
2009-08-24 10:01 . 2009-08-24 10:01 ——– d—–w- C:\AeriaGames
2009-08-24 10:00 . 2009-08-24 10:00 ——– d—–w- c:\documents and settings\Mataza\Application Data\InstallShield
2009-08-24 09:17 . 2009-09-10 07:03 ——– d—–w- c:\program\DNA
2009-08-24 09:17 . 2009-09-10 07:03 ——– d—–w- c:\documents and settings\Mataza\Application Data\DNA
2009-08-23 16:35 . 2009-08-23 16:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\SmartFTP
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client 3.0 Setup Files
2009-08-23 08:17 . 2009-08-23 08:17 ——– d—–w- c:\program\OpenAL
2009-08-23 08:17 . 2009-08-23 09:05 ——– d—–w- c:\documents and settings\Mataza\Application Data\flightgear.org
2009-08-23 08:15 . 2009-08-23 08:17 ——– d—–w- c:\program\FlightGear
2009-08-23 08:15 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Building Game
2009-08-22 12:31 . 2009-08-22 12:31 ——– d—–w- c:\program\AMX Mod X
2009-08-22 12:04 . 2009-08-22 12:23 ——– d—–w- C:\hlds
2009-08-22 08:09 . 2009-08-22 08:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Octoshape
2009-08-22 06:03 . 2009-08-22 06:10 ——– d—–w- c:\program\Apophysis 2.0
2009-08-21 14:59 . 2009-08-21 15:00 ——– d—–w- c:\program\SystemRequirementsLab
2009-08-21 14:59 . 2009-08-21 14:59 ——– d—–w- c:\documents and settings\Mataza\Application Data\SystemRequirementsLab
2009-08-21 14:32 . 2009-08-21 14:32 ——– d—–w- c:\program\HD Tune Pro
2009-08-21 05:00 . 2003-06-25 14:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2009-08-20 02:39 . 2009-08-20 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-20 02:39 . 2009-08-20 02:40 ——– d—–w- c:\program\Spybot - Search & Destroy
2009-08-19 01:37 . 2009-08-19 01:37 135168 –sh–r- c:\windows\servicesss.exe
2009-08-19 01:18 . 2009-08-19 01:18 221184 —-a-w- c:\windows\test.exe
2009-08-19 01:05 . 2009-08-19 01:05 221184 —-a-w- c:\windows\servaaa.exe
2009-08-18 23:54 . 2009-08-19 00:51 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:35 . 2009-08-18 22:08 ——– d—–w- c:\program\BulletProof FTP Server v2.3
2009-08-18 19:44 . 2009-08-18 19:44 135168 –sh–r- c:\windows\servicess.exe
2009-08-18 03:11 . 2009-08-18 03:11 ——– d—–w- c:\program\Delade filer\DirectX
2009-08-18 03:11 . 2009-08-18 04:28 96 —ha-w- c:\windows\system32\HsInfo.dat
2009-08-17 16:08 . 2009-08-17 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-17 16:05 . 2009-08-17 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment.temp
2009-08-17 15:55 . 2009-08-17 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-08-17 15:50 . 2009-08-17 15:50 ——– d—–w- c:\program\Gravity
2009-08-17 14:37 . 2009-08-17 15:06 ——– d—–w- C:\WoW PTR
2009-08-17 14:00 . 2009-08-18 22:25 ——– d—–w- c:\program\Entropia Universe
2009-08-17 14:00 . 2009-08-17 14:00 ——– d—–w- c:\windows\Entropia Universe
2009-08-17 01:09 . 2009-08-17 01:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Apple Computer
2009-08-16 20:26 . 2009-08-16 20:26 ——– d—–w- c:\program\MSXML 6.0
2009-08-16 20:14 . 2008-03-05 14:03 238088 —-a-w- c:\windows\system32\xactengine3_0.dll
2009-08-16 20:14 . 2008-03-05 14:00 25608 —-a-w- c:\windows\system32\X3DAudio1_3.dll
2009-08-16 20:14 . 2008-03-05 13:56 1420824 —-a-w- c:\windows\system32\D3DCompiler_37.dll
2009-08-16 20:14 . 2008-02-05 21:07 462864 —-a-w- c:\windows\system32\d3dx10_37.dll
2009-08-16 20:14 . 2008-03-05 13:56 3786760 —-a-w- c:\windows\system32\D3DX9_37.dll
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\windows\system32\Futuremark
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\program\Delade filer\Futuremark Shared
2009-08-16 19:31 . 2008-09-17 13:14 27672 —-a-r- c:\windows\system32\drivers\Entech.sys
2009-08-16 15:57 . 2009-08-31 18:24 ——– d—–w- c:\documents and settings\Mataza\Application Data\mIRC
2009-08-16 15:57 . 2009-08-31 17:57 ——– d—–w- c:\program\mIRC
2009-08-14 22:59 . 2009-08-14 22:59 85504 —-a-w- c:\windows\system\werqwrqwr.exe
2009-08-14 19:00 . 2009-08-14 19:00 ——– d—–w- c:\program\DFX
2009-08-14 03:53 . 2008-04-14 16:04 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-14 03:38 . 2009-07-10 13:31 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-14 03:37 . 2009-07-03 17:00 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-14 03:37 . 2009-07-03 17:00 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\program\ESET
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\Mataza\Application Data\id Software
2009-08-13 21:15 . 2009-08-14 13:18 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\All Users\Application Data\id Software
2009-08-13 14:10 . 2009-09-04 19:56 ——– d—–w- c:\documents and settings\Mataza\Application Data\IDM
2009-08-13 14:10 . 2009-09-10 07:04 ——– d—–w- c:\documents and settings\Mataza\Application Data\DMCache
2009-08-13 14:10 . 2009-08-30 23:20 ——– d—–w- c:\program\Internet Download Manager
2009-08-13 01:13 . 2009-08-13 01:14 ——– d—–w- c:\program\CleanUp!
2009-08-13 00:39 . 2009-08-13 13:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-12 16:52 . 2003-04-24 12:00 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-12 16:52 . 2003-04-24 12:00 4224 —-a-w- c:\windows\system32\drivers\beep.sys
2009-08-12 15:46 . 2009-08-12 15:46 ——– d—–w- c:\program\HmelyoffLabs
2009-08-11 20:01 . 2009-08-16 20:05 221184 —-a-w- c:\windows\srv.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 07:04 . 2009-08-01 20:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Xfire
2009-09-10 07:03 . 2009-07-25 20:44 ——– d—–w- c:\program\Steam
2009-09-09 15:47 . 2009-08-06 06:26 ——– d—–w- c:\program\Delade filer\Blizzard Entertainment
2009-09-09 14:17 . 2009-07-26 00:36 ——– d—–w- c:\documents and settings\Mataza\Application Data\vlc
2009-09-09 07:20 . 2009-07-30 03:58 ——– d—–w- c:\documents and settings\Mataza\Application Data\uTorrent
2009-09-09 06:31 . 2009-08-01 20:14 ——– d—–w- c:\program\Xfire
2009-09-08 22:23 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live
2009-09-08 14:02 . 2009-07-30 18:46 ——– d—–w- c:\program\Delade filer\Adobe
2009-09-07 14:32 . 2009-07-25 18:12 ——– d–h–w- c:\program\InstallShield Installation Information
2009-09-07 14:26 . 2009-07-28 23:22 139584 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-07 14:26 . 2009-07-28 23:21 189104 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-07 03:58 . 2009-07-25 22:20 ——– d—–w- c:\program\GTA San Andreas
2009-09-05 05:11 . 2009-07-25 20:43 ——– d—–w- c:\program\Logitech
2009-09-04 22:34 . 2009-07-30 18:29 ——– d—–w- c:\program\Google
2009-09-04 01:22 . 2009-07-27 17:01 ——– d—–w- c:\program\Cheat Engine
2009-08-31 02:38 . 2009-07-28 16:08 ——– d—–w- c:\documents and settings\Mataza\Application Data\dvdcss
2009-08-30 23:23 . 2009-07-25 21:18 ——– d—–w- c:\documents and settings\Mataza\Application Data\Spotify
2009-08-29 23:42 . 2009-07-25 21:49 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-08-29 23:42 . 2009-07-25 21:49 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-08-23 02:50 . 2003-04-24 12:00 78906 —-a-w- c:\windows\system32\perfc01D.dat
2009-08-23 02:50 . 2003-04-24 12:00 434880 —-a-w- c:\windows\system32\perfh01D.dat
2009-08-21 16:21 . 2009-07-29 20:38 ——– d—–w- c:\program\AMD
2009-08-19 00:51 . 2009-08-18 23:54 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:36 . 2009-08-03 03:47 ——– d—–w- c:\program\BulletProof FTP Client v2.6
2009-08-17 15:50 . 2009-07-25 18:12 ——– d—–w- c:\program\Delade filer\InstallShield
2009-08-16 20:29 . 2009-08-16 20:15 ——– d—–w- c:\program\Guitar Hero World Tour
2009-08-16 20:28 . 2009-07-28 23:06 ——– d—–w- c:\program\Activision
2009-08-14 13:18 . 2009-07-28 23:22 139152 —-a-w- c:\documents and settings\Mataza\Application Data\PnkBstrK.sys
2009-08-14 13:18 . 2009-07-28 23:21 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-08-10 16:33 . 2009-08-10 16:33 711162 —-a-w- c:\windows\WhatYouSay Uninstaller.exe
2009-08-10 16:33 . 2009-08-10 16:33 ——– d—–w- c:\program\WhatYouSay
2009-08-10 10:24 . 2009-08-10 10:24 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-10 10:24 . 2009-08-10 10:24 ——– d—–w- c:\program\Java
2009-08-10 10:22 . 2009-08-10 10:22 ——– d—–w- c:\program\ModernRcon
2009-08-09 21:31 . 2009-08-09 21:31 ——– d—–w- c:\program\CoD RconTool
2009-08-08 19:58 . 2009-08-08 19:58 ——– d—–w- c:\program\ZModeler
2009-08-08 16:12 . 2009-08-08 16:12 ——– d—–w- c:\program\MTA San Andreas
2009-08-08 13:17 . 2009-08-08 13:17 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-08-08 06:04 . 2009-08-08 06:04 811008 —-a-w- c:\windows\system32\asdf.exe
2009-08-06 06:30 . 2009-08-06 06:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-08-05 09:01 . 2004-08-03 23:33 205312 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 06:46 . 2009-07-25 21:06 ——– d—–w- c:\program\Winamp
2009-08-03 05:44 . 2009-08-01 19:04 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\program\QuickTime
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\program\Apple Software Update
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-02 18:50 . 2009-07-28 19:47 ——– d—–w- c:\documents and settings\Mataza\Application Data\Ventrilo
2009-08-02 18:48 . 2009-08-02 18:48 ——– d—–w- c:\program\Ventrilo
2009-08-02 18:48 . 2009-07-29 20:38 ——– d—–w- c:\program\Delade filer\Wise Installation Wizard
2009-08-02 02:03 . 2009-08-02 02:03 ——– d—–w- c:\program\AeriaGames
2009-08-01 22:51 . 2009-08-01 22:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony Creative Software
2009-08-01 20:12 . 2009-08-01 20:12 ——– d—–w- c:\documents and settings\Mataza\Application Data\Publish Providers
2009-08-01 20:12 . 2009-08-01 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\program\Sony
2009-08-01 19:52 . 2009-08-01 19:52 ——– d—–w- c:\program\Windows Media Components
2009-08-01 16:25 . 2009-08-01 16:23 ——– d—–w- c:\program\Driving Simulator 2009
2009-08-01 02:22 . 2009-07-25 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\program\Delade filer\DFX
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-07-30 21:04 . 2009-07-30 21:04 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-30 18:47 . 2009-07-30 18:47 ——– d—–w- c:\program\Delade filer\Macrovision Shared
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\program\FlashFXP
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\documents and settings\All Users\Application Data\FlashFXP
2009-07-30 03:59 . 2009-07-30 03:59 ——– d—–w- c:\program\uTorrent
2009-07-28 19:47 . 2009-07-28 19:47 129536 —-a-w- c:\windows\inout2.dll
2009-07-28 18:22 . 2009-07-28 18:22 ——– d—–w- c:\program\Realtek
2009-07-27 16:58 . 2009-07-27 16:58 ——– d—–w- c:\program\FlashMute
2009-07-26 15:32 . 2009-07-26 15:32 ——– d—–w- c:\program\EA GAMES
2009-07-26 14:44 . 2009-07-26 14:44 48448 —-a-w- c:\windows\system32\sirenacm.dll
2009-07-25 23:15 . 2009-07-25 23:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Notepad++
2009-07-25 23:14 . 2009-07-25 23:14 ——– d—–w- c:\program\Notepad++
2009-07-25 22:47 . 2009-07-25 22:46 ——– d—–w- c:\program\Heroes of Newerth
2009-07-25 22:19 . 2009-07-25 22:19 ——– d—–w- c:\program\D-Tools
2009-07-25 22:00 . 2009-07-25 22:00 ——– d—–w- c:\program\Alcohol Soft
2009-07-25 21:51 . 2009-07-25 21:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Winamp
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\VideoLAN
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\Creative
2009-07-25 21:18 . 2009-07-25 21:18 ——– d—–w- c:\program\Spotify
2009-07-25 21:08 . 2009-07-25 21:08 ——– d—–w- c:\program\Messenger Plus! Live
2009-07-25 20:45 . 2009-07-25 20:45 ——– d—–w- c:\documents and settings\Mataza\Application Data\Logitech
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\program\Delade filer\Logishrd
2009-07-25 20:43 . 2009-07-25 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-25 20:33 . 2009-07-25 20:07 ——– d—–w- c:\documents and settings\Mataza\Application Data\DAEMON Tools Lite
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\Mataza\Application Data\ATI
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-07-25 20:31 . 2009-07-25 20:31 0 —-a-w- c:\windows\ativpsrm.bin
2009-07-25 20:31 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Lite
2009-07-25 20:29 . 2009-07-25 18:12 ——– d—–w- c:\program\ATI Technologies
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live SkyDrive
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\MSBuild
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Reference Assemblies
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Toolbar
2009-07-25 20:07 . 2009-07-25 20:07 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-03 09:34 . 2009-08-03 09:34 122880 —-a-w- c:\program\mozilla firefox\components\GoogleDesktopMozilla.dll
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2009-09-08 3883856]
"Steam"="c:\program\steam\steam.exe" [2009-08-12 1217784]
"MSMSGS"="c:\program\Messengern\msmsgs.exe" [2002-01-08 1462544]
"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"IDMan"="c:\program\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
"BitTorrent DNA"="c:\program\DNA\btdna.exe" [2009-08-24 318272]
"Google Update"="c:\documents and settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-30 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-27 61440]
"Launch LgDeviceAgent"="c:\program\Logitech\GamePanel Software\LgDevAgt.exe" [2009-05-04 354312]
"Launch LCDMon"="c:\program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-05-04 1572872]
"Launch LGDCore"="c:\program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-05-04 2817544]
"egui"="c:\program\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"amd_dc_opt"="c:\program\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"COMODO Internet Security"="c:\program\COMODO\COMODO Internet Security\cfp.exe" [2009-09-04 1796368]
"Start WingMan Profiler"="c:\program\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-07-20 18670592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Mataza\Start-meny\Program\Autostart\
Xfire.lnk - c:\program\Xfire\Xfire.exe [2009-9-3 3111824]
c:\documents and settings\All Users\Start-meny\Program\Autostart\
Logitech SetPoint.lnk - c:\program\Logitech\SetPoint\SetPoint.exe [2009-7-25 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 22:30 72208 —-a-w- c:\program\Delade filer\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Mataza^Start-meny^Program^Autostart^WinCE3.exe]
path=c:\documents and settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
backup=c:\windows\pss\WinCE3.exeStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Spotify\\spotify.exe"=
"c:\\Program\\EA GAMES\\Battlefield 2\\BF2.exe"=
"h:\\Pr0gz\\FlashFXP\\FlashFXP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program\\uTorrent\\uTorrent.exe"=
"c:\\Program\\FlashFXP\\FlashFXP.exe"=
"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program\\Ventrilo\\Ventrilo.exe"=
"c:\\Program\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program\\BulletProof FTP Server v2.3\\bpftpserver.exe"=
"c:\\Program\\Steam\\steamapps\\common\\tom clancy's h.a.w.x - demo\\HAWX.exe"=
"c:\\Program\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program\\DNA\\btdna.exe"=
"c:\\Program\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-09-04 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-09-04 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-05-14 94360]
R2 ekrn;ESET Service;c:\program\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-07-25 10384]
R3 skfilt;skfilt;c:\windows\system32\drivers\skfilt.sys [2009-07-25 1670016]
S2 gupdate;Google Update Service (gupdate);c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-07-28 1684736]
S3 cpuz130;cpuz130;\??\c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 GoogleDesktopManager-060409-093314;Google Desktop-hanteraren 5.9.906.4286;c:\program\Google\Google Desktop Search\GoogleDesktop.exe [2009-08-03 30192]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Innehållet i mappen 'Schemalagda aktiviteter':
2009-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]
.
.
——- Extra genomsökning ——-
.
uStart Page = about:blank
IE: Download all links with IDM - c:\program\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program\Internet Download Manager\IEExt.htm
TCP: {1A919DF9-BFBA-4078-9221-9D6808B8AF4C} = 195.67.199.27
TCP: {844DDB6E-7A82-44EA-AD66-590D7F0C1E62} = 195.67.199.27,195.67.199.28
FF - ProfilePath - c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/
FF - component: c:\documents and settings\Mataza\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICY —-
c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -
HKCU-Run-winlog.exe - c:\documents and settings\Mataza\Application Data\Microsoft\winlog.exe
HKCU-Run-PlayNC Launcher - (no file)
HKLM-Run-AMD_Display - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-10 09:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LÅSTA REGISTERNYCKLAR ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1281626c-6790-4833-af2f-4b0a316f2318}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fc
"Therad"=dword:0000001d
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):9b,5b,d2,49,4f,d4,88,76,9a,f7,d8,76,ce,ff,8c,31,c3,7a,ec,94,fe,
92,99,d6,fb,d5,9e,03,7b,4d,e5,37,70,e9,70,76,38,5a,96,b9,00,00,00,00,00,00,\
.
——————— DLLer som "laddats" under processer som körs ———————
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\program\delade filer\logishrd\bluetooth\LBTWlgn.dll
c:\program\delade filer\logishrd\bluetooth\LBTServ.dll
c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(712)
c:\program\SmartFTP Client\en-US\sfShellTools.dll.mui
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Andra processer som körs ————————
.
c:\windows\system32\ati2evxx.exe
c:\program\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\system32\ati2evxx.exe
c:\program\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program\Logitech\GamePanel Software\Applets\LCDClock.exe
c:\program\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Sluttid: 2009-09-10 9:08 - datorn startades om.
ComboFix-quarantined-files.txt 2009-09-10 07:08
Före genomsökningen: 84 990 902 272 byte ledigt
Efter genomsökningen: 97 060 761 600 byte ledigt
WindowsXP-KB310994-SP2-Pro-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
411
HJT uninstall list thing
Adobe AIR
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI en
Adobe Flash CS4 Professional
Adobe Flash CS4 STI-en
Adobe Flash Media Encoder 2.5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Importer
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 9.1 - Svenska
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
AMD Power Monitor
America's Army 3
AMX Mod X Installer 1.8.1
Apophysis 2.0
Apple Software Update
ATI - Hjälp för avinstallation av program
ATI Catalyst Control Center
ATI Display Driver
Audacity 1.2.6
Battlefield 2™
Battlefield 2: Special Forces
Bridge Building Game
BulletProof FTP Client (remove only)
BulletProof FTP Server (remove only)
Call of Duty® 4 - Modern Warfare™
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
Catalyst Control Center - Branding
CDDRV_Installer
Cheat Engine 5.5
CleanUp!
CoD RconTool
COMODO Internet Security
Connect
Counter-Strike
Counter-Strike: Source
DAEMON Tools
DAEMON Tools Toolbar
DFX for Winamp
Diablo II
Driving Simulator 2009 Version 1.12
Drum Controller Standard Tuning Kit
Dual-Core Optimizer
Dungeon Siege
Entropia Universe
Euro Truck Simulator
FlashFXP v3
FlightGear v1.9.1
Fraps (remove only)
Futuremark SystemInfo
Garry's Mod
Google Desktop
Google Gears
Google Update Helper
GTA San Andreas
Guild Wars
Guitar Hero World Tour
Half-Life 2
Half-Life Dedicated Server Update Tool
HD Tune Pro 3.50
Heroes of Newerth
HijackThis 2.0.2
HLSW v1.3.2.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
ImgBurn
Insurgency
Internet Download Manager
Java™ 6 Update 15
KhalInstallWrapper
kuler
Last.fm 1.5.4.24567
Logitech GamePanel Software 3.02.173
Logitech Gaming Software 5.04
Logitech SetPoint
Messenger Plus! Live
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - SVE
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - SVE
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - sve
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Choice Guard
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIRC
ModernRcon v0.8
Mozilla Firefox (3.5.2)
MSVCRT
MSXML 6.0 Parser
MTA: Race for San Andreas - Server 1.1.1
MTA:SA Race 1.1.2
NCsoft Launcher
Need for Speed™ Most Wanted
Notepad++
NVIDIA Drivers
OpenAL
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
PokerStars
Project Torque
PunkBuster Services
Quake Live Mozilla Plugin
QuickTime
Realtek AC'97 Audio
Realtek High Definition Audio Driver
Requiem
Segoe UI
Shaiya(US)
SmartFTP Client
SmartFTP Client 3.0 Setup Files (remove only)
Snabbkorrigering för Windows XP (KB952287)
Snabbkorrigering för Windows XP (KB961118)
Spotify
Språkpaket för Microsoft .NET Framework 3.5 - Swedish
Spybot - Search & Destroy
Steam
Suite Shared Configuration CS4
System Requirements Lab
Säkerhetsuppdatering för Windows Internet Explorer 8 (KB969897)
Säkerhetsuppdatering för Windows Internet Explorer 8 (KB972260)
Säkerhetsuppdatering för Windows Media Encoder (KB954156)
Säkerhetsuppdatering för Windows Media Player (KB952069)
Säkerhetsuppdatering för Windows Media Player (KB973540)
Säkerhetsuppdatering för Windows XP (KB923561)
Säkerhetsuppdatering för Windows XP (KB923789)
Säkerhetsuppdatering för Windows XP (KB938464-v2)
Säkerhetsuppdatering för Windows XP (KB941569)
Säkerhetsuppdatering för Windows XP (KB946648)
Säkerhetsuppdatering för Windows XP (KB950762)
Säkerhetsuppdatering för Windows XP (KB950974)
Säkerhetsuppdatering för Windows XP (KB951066)
Säkerhetsuppdatering för Windows XP (KB951376-v2)
Säkerhetsuppdatering för Windows XP (KB951748)
Säkerhetsuppdatering för Windows XP (KB952004)
Säkerhetsuppdatering för Windows XP (KB952954)
Säkerhetsuppdatering för Windows XP (KB954459)
Säkerhetsuppdatering för Windows XP (KB954600)
Säkerhetsuppdatering för Windows XP (KB955069)
Säkerhetsuppdatering för Windows XP (KB956572)
Säkerhetsuppdatering för Windows XP (KB956744)
Säkerhetsuppdatering för Windows XP (KB956802)
Säkerhetsuppdatering för Windows XP (KB956803)
Säkerhetsuppdatering för Windows XP (KB957097)
Säkerhetsuppdatering för Windows XP (KB958644)
Säkerhetsuppdatering för Windows XP (KB958687)
Säkerhetsuppdatering för Windows XP (KB959426)
Säkerhetsuppdatering för Windows XP (KB960225)
Säkerhetsuppdatering för Windows XP (KB960803)
Säkerhetsuppdatering för Windows XP (KB960859)
Säkerhetsuppdatering för Windows XP (KB961371)
Säkerhetsuppdatering för Windows XP (KB961501)
Säkerhetsuppdatering för Windows XP (KB968537)
Säkerhetsuppdatering för Windows XP (KB969897)
Säkerhetsuppdatering för Windows XP (KB970238)
Säkerhetsuppdatering för Windows XP (KB971557)
Säkerhetsuppdatering för Windows XP (KB971633)
Säkerhetsuppdatering för Windows XP (KB971657)
Säkerhetsuppdatering för Windows XP (KB973346)
Säkerhetsuppdatering för Windows XP (KB973354)
Säkerhetsuppdatering för Windows XP (KB973507)
Säkerhetsuppdatering för Windows XP (KB973869)
TeamViewer 4
Tom Clancy's H.A.W.X - Demo
Tweak UI
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Uppdatering för Windows Internet Explorer 8 (KB972636)
Uppdatering för Windows XP (KB951978)
Uppdatering för Windows XP (KB955839)
Uppdatering för Windows XP (KB961503)
Uppdatering för Windows XP (KB967715)
Uppdatering för Windows XP (KB968389)
Uppdatering för Windows XP (KB973815)
Vegas Pro 9.0
Ventrilo Client
VentriloMIX
VH Toolkit [removed]
WhatYouSay
Winamp
Winamp Essentials Pack
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
WinRAR archiver
Virtual DJ - Atomix Productions
VLC media player 1.0.0
VNC Free Edition 4.1.3
World of Warcraft
WVS 0.30.14 for Winamp
Xbox 360 Hack Pack RC1
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
ZModeler (remove only)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:13:06, on 2009-09-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program\COMODO\COMODO Internet Security\cfp.exe
C:\program\steam\steam.exe
C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program\DNA\btdna.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Launch LgDeviceAgent] "C:\Program\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Program\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messengern\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [IDMan] C:\Program\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program\DNA\btdna.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra 'Tools' menuitem: &Inst;ällningar i Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messengern\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messengern\MSMSGS.EXE
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) -
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1248549978984
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O17 - HKLM\System\CCS\Services\Tcpip\..\{844DDB6E-7A82-44EA-AD66-590D7F0C1E62}: NameServer = 195.67.199.27,195.67.199.28
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\HmelyoffLabs\VHToolkit\Skype4COM.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop-hanteraren 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program\Delade filer\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Ventrilo - Unknown owner - C:\Documents and Settings\Mataza\Skrivbord\ventriloserver\ventrilo_svc.exe (file missing)
–
End of file - 9151 bytes
There we go..
And the computer SEEMS to be fine at the moment, but Ive had experience with keyloggers before so I'm pretty careful to not save passwords etc during this.
Really, thanks for helping out
