This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Keylogged, I think..

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.. I'm new to the forums :).

About an hour ago I started getting emails from Steam, that someone is trying to change my password.. I immediately changed my steam account password and email/msn etcetc.

My best guess sofar is a keylogger.. kind of scared about it as I use this computer for everything. Gaming, browsing and bank stuff etc. Anyways, here's my HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:12:50, on 2009-09-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program\COMODO\COMODO Internet Security\cfp.exe
C:\Program\Logitech\Gaming Software\LWEMon.exe
C:\Program\Windows Live\Messenger\msnmsgr.exe
C:\program\steam\steam.exe
C:\Program\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\Program\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program\DNA\btdna.exe
C:\Program\Logitech\SetPoint\SetPoint.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
C:\Program\Xfire\Xfire.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Windows Live\Contacts\wlcomm.exe
C:\Program\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Launch LgDeviceAgent] "C:\Program\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Windows Services] services.exe
O4 - HKLM\..\Run: [egui] "C:\Program\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [winlog.exe] C:\Documents and Settings\Mataza\Application Data\Microsoft\winlog.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [IDMan] C:\Program\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program\DNA\btdna.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: WinCE3.exe
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra 'Tools' menuitem: &Inställningar i Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1248549978984
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O17 - HKLM\System\CCS\Services\Tcpip\..\{844DDB6E-7A82-44EA-AD66-590D7F0C1E62}: NameServer = 195.67.199.27,195.67.199.28
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\HmelyoffLabs\VHToolkit\Skype4COM.dll
O20 - AppInit_DLLs: C:\Program\Google\GOOGLE~2\GOEC62~1.DLL C:\WINDOWS\system32\guard32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop-hanteraren 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program\Delade filer\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Ventrilo - Unknown owner - C:\Documents and Settings\Mataza\Skrivbord\ventriloserver\ventrilo_svc.exe

–
End of file - 10011 bytes
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?


Should you wish to clean this computer, please proceed with the following instructions.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Please make an uninstall list
  • Start HijackThis
  • Click the Config button
  • Click the Misc Tools button
  • Click the Open Uninstall Manager button.
  • Click the Save list button and save it to your desktop.
When you press Save, a notepad will open with the contents. Copy/paste the contents of the notepad file in your next reply.

Please post back with
  • combofix log
  • uninstall list
  • new HJT log take after all other steps
How is the computer at the moment?

Thanks
ComboFix 09-09-09.04 - Mataza 2009-09-10 8:56.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2047.1077 [GMT 2:00]
Körs från: c:\documents and settings\Mataza\Mina dokument\Downloads\Programs\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
c:\windows\Installer\WMEncoder.msi
c:\windows\service.exe
c:\windows\system.exe
c:\windows\system32\pagefileconfig.vbs
c:\windows\system32\plugin.dat

.
(((((((((((((((((((((((( Filer Skapade från 2009-08-10 till 2009-09-10 ))))))))))))))))))))))))))))))
.

2009-09-09 15:42 . 2009-09-09 15:47 ——– d—–w- c:\program\Diablo II
2009-09-09 14:41 . 2009-09-09 14:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Last.fm
2009-09-09 14:40 . 2009-09-09 14:40 ——– d—–w- c:\program\Last.fm
2009-09-09 09:50 . 2009-09-09 09:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\ImgBurn
2009-09-09 08:54 . 2009-09-09 08:54 ——– d—–w- c:\program\ImgBurn
2009-09-09 08:53 . 2009-09-09 08:53 ——– d—–w- C:\X360HP Temp
2009-09-09 08:48 . 2009-09-09 08:50 ——– d—–w- c:\program\Xbox 360 Hack Pack RC1
2009-09-08 22:24 . 2009-09-08 22:24 ——– d—–w- c:\program\Microsoft
2009-09-08 22:05 . 2009-09-08 22:24 ——– d—–w- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-09-08 22:05 . 2009-09-08 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-09-08 22:04 . 2009-09-08 22:04 ——– d—–w- c:\documents and settings\Mataza\Contacts
2009-09-08 21:34 . 2009-09-08 22:06 ——– d—–w- c:\program\MSN Messenger
2009-09-08 21:28 . 2009-09-08 21:32 ——– d—–w- c:\program\Messengern
2009-09-08 14:00 . 2009-09-08 14:00 ——– d—–w- c:\program\Delade filer\Adobe AIR
2009-09-07 14:51 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Construction Set Demo
2009-09-07 04:45 . 2009-09-07 04:45 ——– d–h–w- c:\windows\PIF
2009-09-06 05:57 . 2009-09-06 05:57 ——– d—–w- c:\program\Delade filer\NSV
2009-09-06 02:51 . 2009-09-06 03:57 ——– d—–w- c:\program\Need for Speed Most Wanted
2009-09-05 05:11 . 2009-09-05 05:11 ——– d—–w- c:\program\Delade filer\Logitech
2009-09-05 02:18 . 2009-09-05 02:22 ——– d—–w- c:\program\Euro Truck Simulator
2009-09-04 20:15 . 2009-09-04 20:15 ——– d—–w- c:\program\Microsoft Games
2009-09-04 00:49 . 2009-09-04 16:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-09-04 00:49 . 2009-09-04 00:48 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-09-04 00:49 . 2009-09-04 00:48 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-04 00:49 . 2009-09-04 00:48 179792 —-a-w- c:\windows\system32\guard32.dll
2009-09-04 00:49 . 2009-09-04 00:48 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-04 00:48 . 2009-09-04 00:48 ——– d—–w- c:\program\COMODO
2009-09-03 18:07 . 2009-09-03 18:07 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-09-02 16:55 . 2009-09-05 00:15 ——– d—–w- c:\program\PokerStars
2009-09-02 16:53 . 2009-09-08 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\TeamViewer
2009-09-02 16:53 . 2009-09-02 16:53 ——– d—–w- c:\program\TeamViewer
2009-09-02 16:52 . 2009-09-02 16:52 ——– d—–w- c:\documents and settings\Mataza\temp
2009-09-02 13:53 . 2009-09-07 14:32 ——– d—–w- c:\program\AionEU
2009-09-02 13:53 . 2009-09-02 13:53 ——– d—–w- c:\program\NCsoft
2009-08-31 20:37 . 2009-08-31 20:37 ——– d—–w- c:\program\Microsoft Silverlight
2009-08-30 22:18 . 2009-08-30 23:23 ——– d—–w- c:\documents and settings\Mataza\Application Data\NoNameScript
2009-08-29 23:42 . 2009-08-29 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Creative
2009-08-28 23:58 . 2009-08-28 23:58 ——– d—–w- c:\program\Audacity
2009-08-28 23:50 . 1999-09-17 08:56 118784 —-a-w- c:\windows\system32\mp3dec.dll
2009-08-27 13:02 . 2009-08-27 14:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\HLSW
2009-08-27 13:02 . 2009-08-27 13:03 ——– d-s—w- c:\program\HLSW
2009-08-25 18:37 . 2009-08-25 19:01 ——– d—–w- c:\documents and settings\Mataza\Application Data\Download Manager
2009-08-25 17:23 . 2009-08-25 17:23 ——– d—–w- c:\program\RealVNC
2009-08-24 12:25 . 2005-01-03 06:43 4682 —-a-w- c:\windows\system32\npptNT2.sys
2009-08-24 10:01 . 2009-08-24 10:01 ——– d—–w- C:\AeriaGames
2009-08-24 10:00 . 2009-08-24 10:00 ——– d—–w- c:\documents and settings\Mataza\Application Data\InstallShield
2009-08-24 09:17 . 2009-09-10 07:03 ——– d—–w- c:\program\DNA
2009-08-24 09:17 . 2009-09-10 07:03 ——– d—–w- c:\documents and settings\Mataza\Application Data\DNA
2009-08-23 16:35 . 2009-08-23 16:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\SmartFTP
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client 3.0 Setup Files
2009-08-23 08:17 . 2009-08-23 08:17 ——– d—–w- c:\program\OpenAL
2009-08-23 08:17 . 2009-08-23 09:05 ——– d—–w- c:\documents and settings\Mataza\Application Data\flightgear.org
2009-08-23 08:15 . 2009-08-23 08:17 ——– d—–w- c:\program\FlightGear
2009-08-23 08:15 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Building Game
2009-08-22 12:31 . 2009-08-22 12:31 ——– d—–w- c:\program\AMX Mod X
2009-08-22 12:04 . 2009-08-22 12:23 ——– d—–w- C:\hlds
2009-08-22 08:09 . 2009-08-22 08:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Octoshape
2009-08-22 06:03 . 2009-08-22 06:10 ——– d—–w- c:\program\Apophysis 2.0
2009-08-21 14:59 . 2009-08-21 15:00 ——– d—–w- c:\program\SystemRequirementsLab
2009-08-21 14:59 . 2009-08-21 14:59 ——– d—–w- c:\documents and settings\Mataza\Application Data\SystemRequirementsLab
2009-08-21 14:32 . 2009-08-21 14:32 ——– d—–w- c:\program\HD Tune Pro
2009-08-21 05:00 . 2003-06-25 14:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2009-08-20 02:39 . 2009-08-20 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-20 02:39 . 2009-08-20 02:40 ——– d—–w- c:\program\Spybot - Search & Destroy
2009-08-19 01:37 . 2009-08-19 01:37 135168 –sh–r- c:\windows\servicesss.exe
2009-08-19 01:18 . 2009-08-19 01:18 221184 —-a-w- c:\windows\test.exe
2009-08-19 01:05 . 2009-08-19 01:05 221184 —-a-w- c:\windows\servaaa.exe
2009-08-18 23:54 . 2009-08-19 00:51 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:35 . 2009-08-18 22:08 ——– d—–w- c:\program\BulletProof FTP Server v2.3
2009-08-18 19:44 . 2009-08-18 19:44 135168 –sh–r- c:\windows\servicess.exe
2009-08-18 03:11 . 2009-08-18 03:11 ——– d—–w- c:\program\Delade filer\DirectX
2009-08-18 03:11 . 2009-08-18 04:28 96 —ha-w- c:\windows\system32\HsInfo.dat
2009-08-17 16:08 . 2009-08-17 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-17 16:05 . 2009-08-17 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment.temp
2009-08-17 15:55 . 2009-08-17 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-08-17 15:50 . 2009-08-17 15:50 ——– d—–w- c:\program\Gravity
2009-08-17 14:37 . 2009-08-17 15:06 ——– d—–w- C:\WoW PTR
2009-08-17 14:00 . 2009-08-18 22:25 ——– d—–w- c:\program\Entropia Universe
2009-08-17 14:00 . 2009-08-17 14:00 ——– d—–w- c:\windows\Entropia Universe
2009-08-17 01:09 . 2009-08-17 01:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Apple Computer
2009-08-16 20:26 . 2009-08-16 20:26 ——– d—–w- c:\program\MSXML 6.0
2009-08-16 20:14 . 2008-03-05 14:03 238088 —-a-w- c:\windows\system32\xactengine3_0.dll
2009-08-16 20:14 . 2008-03-05 14:00 25608 —-a-w- c:\windows\system32\X3DAudio1_3.dll
2009-08-16 20:14 . 2008-03-05 13:56 1420824 —-a-w- c:\windows\system32\D3DCompiler_37.dll
2009-08-16 20:14 . 2008-02-05 21:07 462864 —-a-w- c:\windows\system32\d3dx10_37.dll
2009-08-16 20:14 . 2008-03-05 13:56 3786760 —-a-w- c:\windows\system32\D3DX9_37.dll
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\windows\system32\Futuremark
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\program\Delade filer\Futuremark Shared
2009-08-16 19:31 . 2008-09-17 13:14 27672 —-a-r- c:\windows\system32\drivers\Entech.sys
2009-08-16 15:57 . 2009-08-31 18:24 ——– d—–w- c:\documents and settings\Mataza\Application Data\mIRC
2009-08-16 15:57 . 2009-08-31 17:57 ——– d—–w- c:\program\mIRC
2009-08-14 22:59 . 2009-08-14 22:59 85504 —-a-w- c:\windows\system\werqwrqwr.exe
2009-08-14 19:00 . 2009-08-14 19:00 ——– d—–w- c:\program\DFX
2009-08-14 03:53 . 2008-04-14 16:04 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-14 03:38 . 2009-07-10 13:31 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-14 03:37 . 2009-07-03 17:00 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-14 03:37 . 2009-07-03 17:00 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\program\ESET
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\Mataza\Application Data\id Software
2009-08-13 21:15 . 2009-08-14 13:18 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\All Users\Application Data\id Software
2009-08-13 14:10 . 2009-09-04 19:56 ——– d—–w- c:\documents and settings\Mataza\Application Data\IDM
2009-08-13 14:10 . 2009-09-10 07:04 ——– d—–w- c:\documents and settings\Mataza\Application Data\DMCache
2009-08-13 14:10 . 2009-08-30 23:20 ——– d—–w- c:\program\Internet Download Manager
2009-08-13 01:13 . 2009-08-13 01:14 ——– d—–w- c:\program\CleanUp!
2009-08-13 00:39 . 2009-08-13 13:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-12 16:52 . 2003-04-24 12:00 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-12 16:52 . 2003-04-24 12:00 4224 —-a-w- c:\windows\system32\drivers\beep.sys
2009-08-12 15:46 . 2009-08-12 15:46 ——– d—–w- c:\program\HmelyoffLabs
2009-08-11 20:01 . 2009-08-16 20:05 221184 —-a-w- c:\windows\srv.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 07:04 . 2009-08-01 20:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Xfire
2009-09-10 07:03 . 2009-07-25 20:44 ——– d—–w- c:\program\Steam
2009-09-09 15:47 . 2009-08-06 06:26 ——– d—–w- c:\program\Delade filer\Blizzard Entertainment
2009-09-09 14:17 . 2009-07-26 00:36 ——– d—–w- c:\documents and settings\Mataza\Application Data\vlc
2009-09-09 07:20 . 2009-07-30 03:58 ——– d—–w- c:\documents and settings\Mataza\Application Data\uTorrent
2009-09-09 06:31 . 2009-08-01 20:14 ——– d—–w- c:\program\Xfire
2009-09-08 22:23 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live
2009-09-08 14:02 . 2009-07-30 18:46 ——– d—–w- c:\program\Delade filer\Adobe
2009-09-07 14:32 . 2009-07-25 18:12 ——– d–h–w- c:\program\InstallShield Installation Information
2009-09-07 14:26 . 2009-07-28 23:22 139584 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-07 14:26 . 2009-07-28 23:21 189104 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-07 03:58 . 2009-07-25 22:20 ——– d—–w- c:\program\GTA San Andreas
2009-09-05 05:11 . 2009-07-25 20:43 ——– d—–w- c:\program\Logitech
2009-09-04 22:34 . 2009-07-30 18:29 ——– d—–w- c:\program\Google
2009-09-04 01:22 . 2009-07-27 17:01 ——– d—–w- c:\program\Cheat Engine
2009-08-31 02:38 . 2009-07-28 16:08 ——– d—–w- c:\documents and settings\Mataza\Application Data\dvdcss
2009-08-30 23:23 . 2009-07-25 21:18 ——– d—–w- c:\documents and settings\Mataza\Application Data\Spotify
2009-08-29 23:42 . 2009-07-25 21:49 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-08-29 23:42 . 2009-07-25 21:49 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-08-23 02:50 . 2003-04-24 12:00 78906 —-a-w- c:\windows\system32\perfc01D.dat
2009-08-23 02:50 . 2003-04-24 12:00 434880 —-a-w- c:\windows\system32\perfh01D.dat
2009-08-21 16:21 . 2009-07-29 20:38 ——– d—–w- c:\program\AMD
2009-08-19 00:51 . 2009-08-18 23:54 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:36 . 2009-08-03 03:47 ——– d—–w- c:\program\BulletProof FTP Client v2.6
2009-08-17 15:50 . 2009-07-25 18:12 ——– d—–w- c:\program\Delade filer\InstallShield
2009-08-16 20:29 . 2009-08-16 20:15 ——– d—–w- c:\program\Guitar Hero World Tour
2009-08-16 20:28 . 2009-07-28 23:06 ——– d—–w- c:\program\Activision
2009-08-14 13:18 . 2009-07-28 23:22 139152 —-a-w- c:\documents and settings\Mataza\Application Data\PnkBstrK.sys
2009-08-14 13:18 . 2009-07-28 23:21 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-08-10 16:33 . 2009-08-10 16:33 711162 —-a-w- c:\windows\WhatYouSay Uninstaller.exe
2009-08-10 16:33 . 2009-08-10 16:33 ——– d—–w- c:\program\WhatYouSay
2009-08-10 10:24 . 2009-08-10 10:24 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-10 10:24 . 2009-08-10 10:24 ——– d—–w- c:\program\Java
2009-08-10 10:22 . 2009-08-10 10:22 ——– d—–w- c:\program\ModernRcon
2009-08-09 21:31 . 2009-08-09 21:31 ——– d—–w- c:\program\CoD RconTool
2009-08-08 19:58 . 2009-08-08 19:58 ——– d—–w- c:\program\ZModeler
2009-08-08 16:12 . 2009-08-08 16:12 ——– d—–w- c:\program\MTA San Andreas
2009-08-08 13:17 . 2009-08-08 13:17 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-08-08 06:04 . 2009-08-08 06:04 811008 —-a-w- c:\windows\system32\asdf.exe
2009-08-06 06:30 . 2009-08-06 06:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-08-05 09:01 . 2004-08-03 23:33 205312 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 06:46 . 2009-07-25 21:06 ——– d—–w- c:\program\Winamp
2009-08-03 05:44 . 2009-08-01 19:04 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\program\QuickTime
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\program\Apple Software Update
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-02 18:50 . 2009-07-28 19:47 ——– d—–w- c:\documents and settings\Mataza\Application Data\Ventrilo
2009-08-02 18:48 . 2009-08-02 18:48 ——– d—–w- c:\program\Ventrilo
2009-08-02 18:48 . 2009-07-29 20:38 ——– d—–w- c:\program\Delade filer\Wise Installation Wizard
2009-08-02 02:03 . 2009-08-02 02:03 ——– d—–w- c:\program\AeriaGames
2009-08-01 22:51 . 2009-08-01 22:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony Creative Software
2009-08-01 20:12 . 2009-08-01 20:12 ——– d—–w- c:\documents and settings\Mataza\Application Data\Publish Providers
2009-08-01 20:12 . 2009-08-01 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\program\Sony
2009-08-01 19:52 . 2009-08-01 19:52 ——– d—–w- c:\program\Windows Media Components
2009-08-01 16:25 . 2009-08-01 16:23 ——– d—–w- c:\program\Driving Simulator 2009
2009-08-01 02:22 . 2009-07-25 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\program\Delade filer\DFX
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-07-30 21:04 . 2009-07-30 21:04 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-30 18:47 . 2009-07-30 18:47 ——– d—–w- c:\program\Delade filer\Macrovision Shared
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\program\FlashFXP
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\documents and settings\All Users\Application Data\FlashFXP
2009-07-30 03:59 . 2009-07-30 03:59 ——– d—–w- c:\program\uTorrent
2009-07-28 19:47 . 2009-07-28 19:47 129536 —-a-w- c:\windows\inout2.dll
2009-07-28 18:22 . 2009-07-28 18:22 ——– d—–w- c:\program\Realtek
2009-07-27 16:58 . 2009-07-27 16:58 ——– d—–w- c:\program\FlashMute
2009-07-26 15:32 . 2009-07-26 15:32 ——– d—–w- c:\program\EA GAMES
2009-07-26 14:44 . 2009-07-26 14:44 48448 —-a-w- c:\windows\system32\sirenacm.dll
2009-07-25 23:15 . 2009-07-25 23:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Notepad++
2009-07-25 23:14 . 2009-07-25 23:14 ——– d—–w- c:\program\Notepad++
2009-07-25 22:47 . 2009-07-25 22:46 ——– d—–w- c:\program\Heroes of Newerth
2009-07-25 22:19 . 2009-07-25 22:19 ——– d—–w- c:\program\D-Tools
2009-07-25 22:00 . 2009-07-25 22:00 ——– d—–w- c:\program\Alcohol Soft
2009-07-25 21:51 . 2009-07-25 21:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Winamp
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\VideoLAN
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\Creative
2009-07-25 21:18 . 2009-07-25 21:18 ——– d—–w- c:\program\Spotify
2009-07-25 21:08 . 2009-07-25 21:08 ——– d—–w- c:\program\Messenger Plus! Live
2009-07-25 20:45 . 2009-07-25 20:45 ——– d—–w- c:\documents and settings\Mataza\Application Data\Logitech
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\program\Delade filer\Logishrd
2009-07-25 20:43 . 2009-07-25 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-25 20:33 . 2009-07-25 20:07 ——– d—–w- c:\documents and settings\Mataza\Application Data\DAEMON Tools Lite
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\Mataza\Application Data\ATI
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-07-25 20:31 . 2009-07-25 20:31 0 —-a-w- c:\windows\ativpsrm.bin
2009-07-25 20:31 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Lite
2009-07-25 20:29 . 2009-07-25 18:12 ——– d—–w- c:\program\ATI Technologies
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live SkyDrive
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\MSBuild
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Reference Assemblies
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Toolbar
2009-07-25 20:07 . 2009-07-25 20:07 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-03 09:34 . 2009-08-03 09:34 122880 —-a-w- c:\program\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2009-09-08 3883856]
"Steam"="c:\program\steam\steam.exe" [2009-08-12 1217784]
"MSMSGS"="c:\program\Messengern\msmsgs.exe" [2002-01-08 1462544]
"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"IDMan"="c:\program\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
"BitTorrent DNA"="c:\program\DNA\btdna.exe" [2009-08-24 318272]
"Google Update"="c:\documents and settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-30 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-27 61440]
"Launch LgDeviceAgent"="c:\program\Logitech\GamePanel Software\LgDevAgt.exe" [2009-05-04 354312]
"Launch LCDMon"="c:\program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-05-04 1572872]
"Launch LGDCore"="c:\program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-05-04 2817544]
"egui"="c:\program\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"amd_dc_opt"="c:\program\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"COMODO Internet Security"="c:\program\COMODO\COMODO Internet Security\cfp.exe" [2009-09-04 1796368]
"Start WingMan Profiler"="c:\program\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-07-20 18670592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Mataza\Start-meny\Program\Autostart\
Xfire.lnk - c:\program\Xfire\Xfire.exe [2009-9-3 3111824]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Logitech SetPoint.lnk - c:\program\Logitech\SetPoint\SetPoint.exe [2009-7-25 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 22:30 72208 —-a-w- c:\program\Delade filer\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Mataza^Start-meny^Program^Autostart^WinCE3.exe]
path=c:\documents and settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
backup=c:\windows\pss\WinCE3.exeStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Spotify\\spotify.exe"=
"c:\\Program\\EA GAMES\\Battlefield 2\\BF2.exe"=
"h:\\Pr0gz\\FlashFXP\\FlashFXP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program\\uTorrent\\uTorrent.exe"=
"c:\\Program\\FlashFXP\\FlashFXP.exe"=
"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program\\Ventrilo\\Ventrilo.exe"=
"c:\\Program\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program\\BulletProof FTP Server v2.3\\bpftpserver.exe"=
"c:\\Program\\Steam\\steamapps\\common\\tom clancy's h.a.w.x - demo\\HAWX.exe"=
"c:\\Program\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program\\DNA\\btdna.exe"=
"c:\\Program\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-09-04 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-09-04 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-05-14 94360]
R2 ekrn;ESET Service;c:\program\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-07-25 10384]
R3 skfilt;skfilt;c:\windows\system32\drivers\skfilt.sys [2009-07-25 1670016]
S2 gupdate;Google Update Service (gupdate);c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-07-28 1684736]
S3 cpuz130;cpuz130;\??\c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 GoogleDesktopManager-060409-093314;Google Desktop-hanteraren 5.9.906.4286;c:\program\Google\Google Desktop Search\GoogleDesktop.exe [2009-08-03 30192]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Innehållet i mappen 'Schemalagda aktiviteter':

2009-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]
.
.
——- Extra genomsökning ——-
.
uStart Page = about:blank
IE: Download all links with IDM - c:\program\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program\Internet Download Manager\IEExt.htm
TCP: {1A919DF9-BFBA-4078-9221-9D6808B8AF4C} = 195.67.199.27
TCP: {844DDB6E-7A82-44EA-AD66-590D7F0C1E62} = 195.67.199.27,195.67.199.28
FF - ProfilePath - c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/
FF - component: c:\documents and settings\Mataza\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICY —-
c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

HKCU-Run-winlog.exe - c:\documents and settings\Mataza\Application Data\Microsoft\winlog.exe
HKCU-Run-PlayNC Launcher - (no file)
HKLM-Run-AMD_Display - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-10 09:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1281626c-6790-4833-af2f-4b0a316f2318}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fc
"Therad"=dword:0000001d

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):9b,5b,d2,49,4f,d4,88,76,9a,f7,d8,76,ce,ff,8c,31,c3,7a,ec,94,fe,
92,99,d6,fb,d5,9e,03,7b,4d,e5,37,70,e9,70,76,38,5a,96,b9,00,00,00,00,00,00,\
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\program\delade filer\logishrd\bluetooth\LBTWlgn.dll
c:\program\delade filer\logishrd\bluetooth\LBTServ.dll
c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(712)
c:\program\SmartFTP Client\en-US\sfShellTools.dll.mui
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Andra processer som körs ————————
.
c:\windows\system32\ati2evxx.exe
c:\program\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\system32\ati2evxx.exe
c:\program\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program\Logitech\GamePanel Software\Applets\LCDClock.exe
c:\program\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Sluttid: 2009-09-10 9:08 - datorn startades om.
ComboFix-quarantined-files.txt 2009-09-10 07:08

Före genomsökningen: 84 990 902 272 byte ledigt
Efter genomsökningen: 97 060 761 600 byte ledigt

WindowsXP-KB310994-SP2-Pro-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

411

HJT uninstall list thing

Adobe AIR
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI en
Adobe Flash CS4 Professional
Adobe Flash CS4 STI-en
Adobe Flash Media Encoder 2.5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Importer
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 9.1 - Svenska
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
AMD Power Monitor
America's Army 3
AMX Mod X Installer 1.8.1
Apophysis 2.0
Apple Software Update
ATI - Hjälp för avinstallation av program
ATI Catalyst Control Center
ATI Display Driver
Audacity 1.2.6
Battlefield 2™
Battlefield 2: Special Forces
Bridge Building Game
BulletProof FTP Client (remove only)
BulletProof FTP Server (remove only)
Call of Duty® 4 - Modern Warfare™
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
Catalyst Control Center - Branding
CDDRV_Installer
Cheat Engine 5.5
CleanUp!
CoD RconTool
COMODO Internet Security
Connect
Counter-Strike
Counter-Strike: Source
DAEMON Tools
DAEMON Tools Toolbar
DFX for Winamp
Diablo II
Driving Simulator 2009 Version 1.12
Drum Controller Standard Tuning Kit
Dual-Core Optimizer
Dungeon Siege
Entropia Universe
Euro Truck Simulator
FlashFXP v3
FlightGear v1.9.1
Fraps (remove only)
Futuremark SystemInfo
Garry's Mod
Google Desktop
Google Gears
Google Update Helper
GTA San Andreas
Guild Wars
Guitar Hero World Tour
Half-Life 2
Half-Life Dedicated Server Update Tool
HD Tune Pro 3.50
Heroes of Newerth
HijackThis 2.0.2
HLSW v1.3.2.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
ImgBurn
Insurgency
Internet Download Manager
Java™ 6 Update 15
KhalInstallWrapper
kuler
Last.fm 1.5.4.24567
Logitech GamePanel Software 3.02.173
Logitech Gaming Software 5.04
Logitech SetPoint
Messenger Plus! Live
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - SVE
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - SVE
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 Language Pack - sve
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Choice Guard
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIRC
ModernRcon v0.8
Mozilla Firefox (3.5.2)
MSVCRT
MSXML 6.0 Parser
MTA: Race for San Andreas - Server 1.1.1
MTA:SA Race 1.1.2
NCsoft Launcher
Need for Speed™ Most Wanted
Notepad++
NVIDIA Drivers
OpenAL
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
PokerStars
Project Torque
PunkBuster Services
Quake Live Mozilla Plugin
QuickTime
Realtek AC'97 Audio
Realtek High Definition Audio Driver
Requiem
Segoe UI
Shaiya(US)
SmartFTP Client
SmartFTP Client 3.0 Setup Files (remove only)
Snabbkorrigering för Windows XP (KB952287)
Snabbkorrigering för Windows XP (KB961118)
Spotify
Språkpaket för Microsoft .NET Framework 3.5 - Swedish
Spybot - Search & Destroy
Steam
Suite Shared Configuration CS4
System Requirements Lab
Säkerhetsuppdatering för Windows Internet Explorer 8 (KB969897)
Säkerhetsuppdatering för Windows Internet Explorer 8 (KB972260)
Säkerhetsuppdatering för Windows Media Encoder (KB954156)
Säkerhetsuppdatering för Windows Media Player (KB952069)
Säkerhetsuppdatering för Windows Media Player (KB973540)
Säkerhetsuppdatering för Windows XP (KB923561)
Säkerhetsuppdatering för Windows XP (KB923789)
Säkerhetsuppdatering för Windows XP (KB938464-v2)
Säkerhetsuppdatering för Windows XP (KB941569)
Säkerhetsuppdatering för Windows XP (KB946648)
Säkerhetsuppdatering för Windows XP (KB950762)
Säkerhetsuppdatering för Windows XP (KB950974)
Säkerhetsuppdatering för Windows XP (KB951066)
Säkerhetsuppdatering för Windows XP (KB951376-v2)
Säkerhetsuppdatering för Windows XP (KB951748)
Säkerhetsuppdatering för Windows XP (KB952004)
Säkerhetsuppdatering för Windows XP (KB952954)
Säkerhetsuppdatering för Windows XP (KB954459)
Säkerhetsuppdatering för Windows XP (KB954600)
Säkerhetsuppdatering för Windows XP (KB955069)
Säkerhetsuppdatering för Windows XP (KB956572)
Säkerhetsuppdatering för Windows XP (KB956744)
Säkerhetsuppdatering för Windows XP (KB956802)
Säkerhetsuppdatering för Windows XP (KB956803)
Säkerhetsuppdatering för Windows XP (KB957097)
Säkerhetsuppdatering för Windows XP (KB958644)
Säkerhetsuppdatering för Windows XP (KB958687)
Säkerhetsuppdatering för Windows XP (KB959426)
Säkerhetsuppdatering för Windows XP (KB960225)
Säkerhetsuppdatering för Windows XP (KB960803)
Säkerhetsuppdatering för Windows XP (KB960859)
Säkerhetsuppdatering för Windows XP (KB961371)
Säkerhetsuppdatering för Windows XP (KB961501)
Säkerhetsuppdatering för Windows XP (KB968537)
Säkerhetsuppdatering för Windows XP (KB969897)
Säkerhetsuppdatering för Windows XP (KB970238)
Säkerhetsuppdatering för Windows XP (KB971557)
Säkerhetsuppdatering för Windows XP (KB971633)
Säkerhetsuppdatering för Windows XP (KB971657)
Säkerhetsuppdatering för Windows XP (KB973346)
Säkerhetsuppdatering för Windows XP (KB973354)
Säkerhetsuppdatering för Windows XP (KB973507)
Säkerhetsuppdatering för Windows XP (KB973869)
TeamViewer 4
Tom Clancy's H.A.W.X - Demo
Tweak UI
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Uppdatering för Windows Internet Explorer 8 (KB972636)
Uppdatering för Windows XP (KB951978)
Uppdatering för Windows XP (KB955839)
Uppdatering för Windows XP (KB961503)
Uppdatering för Windows XP (KB967715)
Uppdatering för Windows XP (KB968389)
Uppdatering för Windows XP (KB973815)
Vegas Pro 9.0
Ventrilo Client
VentriloMIX
VH Toolkit [removed]
WhatYouSay
Winamp
Winamp Essentials Pack
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
WinRAR archiver
Virtual DJ - Atomix Productions
VLC media player 1.0.0
VNC Free Edition 4.1.3
World of Warcraft
WVS 0.30.14 for Winamp
Xbox 360 Hack Pack RC1
Xfire (remove only)
XML Paper Specification Shared Components Language Pack 1.0
ZModeler (remove only)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:13:06, on 2009-09-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program\COMODO\COMODO Internet Security\cfp.exe
C:\program\steam\steam.exe
C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program\DNA\btdna.exe
C:\Program\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Launch LgDeviceAgent] "C:\Program\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Program\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messengern\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [IDMan] C:\Program\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program\DNA\btdna.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program\Xfire\Xfire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra 'Tools' menuitem: &Inst;ällningar i Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messengern\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messengern\MSMSGS.EXE
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1248549978984
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O17 - HKLM\System\CCS\Services\Tcpip\..\{844DDB6E-7A82-44EA-AD66-590D7F0C1E62}: NameServer = 195.67.199.27,195.67.199.28
O17 - HKLM\System\CS1\Services\Tcpip\..\{1A919DF9-BFBA-4078-9221-9D6808B8AF4C}: NameServer = 195.67.199.27
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\HmelyoffLabs\VHToolkit\Skype4COM.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop-hanteraren 5.9.906.4286 (GoogleDesktopManager-060409-093314) - Google - C:\Program\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program\Delade filer\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Ventrilo - Unknown owner - C:\Documents and Settings\Mataza\Skrivbord\ventriloserver\ventrilo_svc.exe (file missing)

–
End of file - 9151 bytes

There we go..

And the computer SEEMS to be fine at the moment, but Ive had experience with keyloggers before so I'm pretty careful to not save passwords etc during this.

Really, thanks for helping out :)
Hi Mataza,

I see evidence of some P2P programs such as uTorrent, and DNA, but it looks like you may have uninstalled them. Is that the case?

We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Keylogged_I_think_t106777.html

Collect::[4]
c:\windows\system\werqwrqwr.exe
c:\windows\servicess.exe
c:\windows\servaaa.exe
c:\windows\servicesss.exe
c:\windows\test.exe
c:\windows\srv.exe

REGLOCKDEL::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1281626c-6790-4833-af2f-4b0a316f2318}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • combofix log
  • MBAM log
How is the computer?

Thanks
ComboFix 09-09-09.07 - Mataza 2009-09-10 16:05.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2047.1172 [GMT 2:00]
Körs från: c:\documents and settings\Mataza\Mina dokument\Downloads\Programs\ComboFix.exe
Använda kommandoväxlar :: c:\documents and settings\Mataza\Skrivbord\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

file zipped: c:\windows\servaaa.exe
file zipped: c:\windows\servicess.exe
file zipped: c:\windows\servicesss.exe
file zipped: c:\windows\srv.exe
file zipped: c:\windows\system\werqwrqwr.exe
file zipped: c:\windows\test.exe
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\servaaa.exe
c:\windows\servicess.exe
c:\windows\servicesss.exe
c:\windows\srv.exe
c:\windows\system\werqwrqwr.exe
c:\windows\test.exe

.
(((((((((((((((((((((((( Filer Skapade från 2009-08-10 till 2009-09-10 ))))))))))))))))))))))))))))))
.

2009-09-10 12:02 . 2009-09-10 12:40 ——– d—–w- c:\program\AionEUz
2009-09-09 15:42 . 2009-09-10 11:42 ——– d—–w- c:\program\Diablo II
2009-09-09 14:41 . 2009-09-09 14:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Last.fm
2009-09-09 14:40 . 2009-09-09 14:40 ——– d—–w- c:\program\Last.fm
2009-09-09 09:50 . 2009-09-09 09:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\ImgBurn
2009-09-09 08:54 . 2009-09-09 08:54 ——– d—–w- c:\program\ImgBurn
2009-09-09 08:53 . 2009-09-09 08:53 ——– d—–w- C:\X360HP Temp
2009-09-09 08:48 . 2009-09-09 08:50 ——– d—–w- c:\program\Xbox 360 Hack Pack RC1
2009-09-08 22:24 . 2009-09-08 22:24 ——– d—–w- c:\program\Microsoft
2009-09-08 22:05 . 2009-09-08 22:24 ——– d—–w- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-09-08 22:05 . 2009-09-08 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-09-08 22:04 . 2009-09-08 22:04 ——– d—–w- c:\documents and settings\Mataza\Contacts
2009-09-08 21:34 . 2009-09-08 22:06 ——– d—–w- c:\program\MSN Messenger
2009-09-08 21:28 . 2009-09-08 21:32 ——– d—–w- c:\program\Messengern
2009-09-08 14:00 . 2009-09-08 14:00 ——– d—–w- c:\program\Delade filer\Adobe AIR
2009-09-07 14:51 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Construction Set Demo
2009-09-07 04:45 . 2009-09-07 04:45 ——– d–h–w- c:\windows\PIF
2009-09-06 05:57 . 2009-09-06 05:57 ——– d—–w- c:\program\Delade filer\NSV
2009-09-06 02:51 . 2009-09-06 03:57 ——– d—–w- c:\program\Need for Speed Most Wanted
2009-09-05 05:11 . 2009-09-05 05:11 ——– d—–w- c:\program\Delade filer\Logitech
2009-09-05 02:18 . 2009-09-05 02:22 ——– d—–w- c:\program\Euro Truck Simulator
2009-09-04 20:15 . 2009-09-04 20:15 ——– d—–w- c:\program\Microsoft Games
2009-09-04 00:49 . 2009-09-04 16:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-09-04 00:49 . 2009-09-04 00:48 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-09-04 00:49 . 2009-09-04 00:48 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-04 00:49 . 2009-09-04 00:48 179792 —-a-w- c:\windows\system32\guard32.dll
2009-09-04 00:49 . 2009-09-04 00:48 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-04 00:48 . 2009-09-04 00:48 ——– d—–w- c:\program\COMODO
2009-09-03 18:07 . 2009-09-03 18:07 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-09-02 16:55 . 2009-09-05 00:15 ——– d—–w- c:\program\PokerStars
2009-09-02 16:53 . 2009-09-08 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\TeamViewer
2009-09-02 16:53 . 2009-09-02 16:53 ——– d—–w- c:\program\TeamViewer
2009-09-02 16:52 . 2009-09-02 16:52 ——– d—–w- c:\documents and settings\Mataza\temp
2009-09-02 13:53 . 2009-09-07 14:32 ——– d—–w- c:\program\AionEU
2009-09-02 13:53 . 2009-09-02 13:53 ——– d—–w- c:\program\NCsoft
2009-08-31 20:37 . 2009-08-31 20:37 ——– d—–w- c:\program\Microsoft Silverlight
2009-08-30 22:18 . 2009-08-30 23:23 ——– d—–w- c:\documents and settings\Mataza\Application Data\NoNameScript
2009-08-29 23:42 . 2009-08-29 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Creative
2009-08-28 23:58 . 2009-08-28 23:58 ——– d—–w- c:\program\Audacity
2009-08-28 23:50 . 1999-09-17 08:56 118784 —-a-w- c:\windows\system32\mp3dec.dll
2009-08-27 13:02 . 2009-08-27 14:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\HLSW
2009-08-27 13:02 . 2009-08-27 13:03 ——– d-s—w- c:\program\HLSW
2009-08-25 18:37 . 2009-08-25 19:01 ——– d—–w- c:\documents and settings\Mataza\Application Data\Download Manager
2009-08-25 17:23 . 2009-08-25 17:23 ——– d—–w- c:\program\RealVNC
2009-08-24 12:25 . 2005-01-03 06:43 4682 —-a-w- c:\windows\system32\npptNT2.sys
2009-08-24 10:01 . 2009-08-24 10:01 ——– d—–w- C:\AeriaGames
2009-08-24 10:00 . 2009-08-24 10:00 ——– d—–w- c:\documents and settings\Mataza\Application Data\InstallShield
2009-08-24 09:17 . 2009-09-10 14:03 ——– d—–w- c:\documents and settings\Mataza\Application Data\DNA
2009-08-24 09:17 . 2009-09-10 13:13 ——– d—–w- c:\program\DNA
2009-08-23 16:35 . 2009-08-23 16:35 ——– d—–w- c:\documents and settings\Mataza\Application Data\SmartFTP
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client
2009-08-23 16:34 . 2009-08-23 16:34 ——– d—–w- c:\program\SmartFTP Client 3.0 Setup Files
2009-08-23 08:17 . 2009-08-23 08:17 ——– d—–w- c:\program\OpenAL
2009-08-23 08:17 . 2009-08-23 09:05 ——– d—–w- c:\documents and settings\Mataza\Application Data\flightgear.org
2009-08-23 08:15 . 2009-08-23 08:17 ——– d—–w- c:\program\FlightGear
2009-08-23 08:15 . 2009-09-07 15:00 ——– d—–w- c:\program\Bridge Building Game
2009-08-22 12:31 . 2009-08-22 12:31 ——– d—–w- c:\program\AMX Mod X
2009-08-22 12:04 . 2009-08-22 12:23 ——– d—–w- C:\hlds
2009-08-22 08:09 . 2009-08-22 08:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Octoshape
2009-08-22 06:03 . 2009-08-22 06:10 ——– d—–w- c:\program\Apophysis 2.0
2009-08-21 14:59 . 2009-08-21 15:00 ——– d—–w- c:\program\SystemRequirementsLab
2009-08-21 14:59 . 2009-08-21 14:59 ——– d—–w- c:\documents and settings\Mataza\Application Data\SystemRequirementsLab
2009-08-21 14:32 . 2009-08-21 14:32 ——– d—–w- c:\program\HD Tune Pro
2009-08-21 05:00 . 2003-06-25 14:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2009-08-20 02:39 . 2009-08-20 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-20 02:39 . 2009-08-20 02:40 ——– d—–w- c:\program\Spybot - Search & Destroy
2009-08-18 23:54 . 2009-08-19 00:51 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:35 . 2009-08-18 22:08 ——– d—–w- c:\program\BulletProof FTP Server v2.3
2009-08-18 03:11 . 2009-08-18 03:11 ——– d—–w- c:\program\Delade filer\DirectX
2009-08-18 03:11 . 2009-08-18 04:28 96 —ha-w- c:\windows\system32\HsInfo.dat
2009-08-17 16:08 . 2009-08-17 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-17 16:05 . 2009-08-17 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment.temp
2009-08-17 15:55 . 2009-08-17 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-08-17 15:50 . 2009-08-17 15:50 ——– d—–w- c:\program\Gravity
2009-08-17 14:37 . 2009-08-17 15:06 ——– d—–w- C:\WoW PTR
2009-08-17 14:00 . 2009-08-18 22:25 ——– d—–w- c:\program\Entropia Universe
2009-08-17 14:00 . 2009-08-17 14:00 ——– d—–w- c:\windows\Entropia Universe
2009-08-17 01:09 . 2009-08-17 01:09 ——– d—–w- c:\documents and settings\Mataza\Application Data\Apple Computer
2009-08-16 20:26 . 2009-08-16 20:26 ——– d—–w- c:\program\MSXML 6.0
2009-08-16 20:14 . 2008-03-05 14:03 238088 —-a-w- c:\windows\system32\xactengine3_0.dll
2009-08-16 20:14 . 2008-03-05 14:00 25608 —-a-w- c:\windows\system32\X3DAudio1_3.dll
2009-08-16 20:14 . 2008-03-05 13:56 1420824 —-a-w- c:\windows\system32\D3DCompiler_37.dll
2009-08-16 20:14 . 2008-02-05 21:07 462864 —-a-w- c:\windows\system32\d3dx10_37.dll
2009-08-16 20:14 . 2008-03-05 13:56 3786760 —-a-w- c:\windows\system32\D3DX9_37.dll
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\windows\system32\Futuremark
2009-08-16 19:31 . 2009-08-16 19:31 ——– d—–w- c:\program\Delade filer\Futuremark Shared
2009-08-16 19:31 . 2008-09-17 13:14 27672 —-a-r- c:\windows\system32\drivers\Entech.sys
2009-08-16 15:57 . 2009-08-31 18:24 ——– d—–w- c:\documents and settings\Mataza\Application Data\mIRC
2009-08-16 15:57 . 2009-08-31 17:57 ——– d—–w- c:\program\mIRC
2009-08-14 19:00 . 2009-08-14 19:00 ——– d—–w- c:\program\DFX
2009-08-14 03:53 . 2008-04-14 16:04 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-14 03:38 . 2009-07-10 13:31 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\program\ESET
2009-08-14 03:34 . 2009-08-14 03:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\Mataza\Application Data\id Software
2009-08-13 21:15 . 2009-08-14 13:18 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-08-13 21:15 . 2009-08-13 21:15 ——– d—–w- c:\documents and settings\All Users\Application Data\id Software
2009-08-13 14:10 . 2009-09-04 19:56 ——– d—–w- c:\documents and settings\Mataza\Application Data\IDM
2009-08-13 14:10 . 2009-09-10 14:11 ——– d—–w- c:\documents and settings\Mataza\Application Data\DMCache
2009-08-13 14:10 . 2009-08-30 23:20 ——– d—–w- c:\program\Internet Download Manager
2009-08-13 01:13 . 2009-08-13 01:14 ——– d—–w- c:\program\CleanUp!
2009-08-13 00:39 . 2009-08-13 13:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-12 16:52 . 2003-04-24 12:00 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-12 16:52 . 2003-04-24 12:00 4224 ——w- c:\windows\system32\drivers\beep.sys
2009-08-12 15:46 . 2009-08-12 15:46 ——– d—–w- c:\program\HmelyoffLabs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 13:16 . 2009-08-01 20:14 ——– d—–w- c:\program\Xfire
2009-09-10 13:13 . 2009-07-25 20:44 ——– d—–w- c:\program\Steam
2009-09-10 12:02 . 2009-07-25 18:12 ——– d–h–w- c:\program\InstallShield Installation Information
2009-09-10 07:04 . 2009-08-01 20:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Xfire
2009-09-09 15:47 . 2009-08-06 06:26 ——– d—–w- c:\program\Delade filer\Blizzard Entertainment
2009-09-09 14:17 . 2009-07-26 00:36 ——– d—–w- c:\documents and settings\Mataza\Application Data\vlc
2009-09-09 07:20 . 2009-07-30 03:58 ——– d—–w- c:\documents and settings\Mataza\Application Data\uTorrent
2009-09-08 22:23 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live
2009-09-08 14:02 . 2009-07-30 18:46 ——– d—–w- c:\program\Delade filer\Adobe
2009-09-07 14:26 . 2009-07-28 23:22 139584 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-07 14:26 . 2009-07-28 23:21 189104 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-07 03:58 . 2009-07-25 22:20 ——– d—–w- c:\program\GTA San Andreas
2009-09-05 05:11 . 2009-07-25 20:43 ——– d—–w- c:\program\Logitech
2009-09-04 22:34 . 2009-07-30 18:29 ——– d—–w- c:\program\Google
2009-09-04 01:22 . 2009-07-27 17:01 ——– d—–w- c:\program\Cheat Engine
2009-08-31 02:38 . 2009-07-28 16:08 ——– d—–w- c:\documents and settings\Mataza\Application Data\dvdcss
2009-08-30 23:23 . 2009-07-25 21:18 ——– d—–w- c:\documents and settings\Mataza\Application Data\Spotify
2009-08-29 23:42 . 2009-07-25 21:49 413696 —-a-w- c:\windows\system32\wrap_oal.dll
2009-08-29 23:42 . 2009-07-25 21:49 110592 —-a-w- c:\windows\system32\OpenAL32.dll
2009-08-23 02:50 . 2003-04-24 12:00 78906 —-a-w- c:\windows\system32\perfc01D.dat
2009-08-23 02:50 . 2003-04-24 12:00 434880 —-a-w- c:\windows\system32\perfh01D.dat
2009-08-21 16:21 . 2009-07-29 20:38 ——– d—–w- c:\program\AMD
2009-08-19 00:51 . 2009-08-18 23:54 ——– d—–w- c:\program\VirtualDJ
2009-08-18 21:36 . 2009-08-03 03:47 ——– d—–w- c:\program\BulletProof FTP Client v2.6
2009-08-17 15:50 . 2009-07-25 18:12 ——– d—–w- c:\program\Delade filer\InstallShield
2009-08-16 20:29 . 2009-08-16 20:15 ——– d—–w- c:\program\Guitar Hero World Tour
2009-08-16 20:28 . 2009-07-28 23:06 ——– d—–w- c:\program\Activision
2009-08-14 13:18 . 2009-07-28 23:22 139152 —-a-w- c:\documents and settings\Mataza\Application Data\PnkBstrK.sys
2009-08-14 13:18 . 2009-07-28 23:21 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-08-10 16:33 . 2009-08-10 16:33 711162 —-a-w- c:\windows\WhatYouSay Uninstaller.exe
2009-08-10 16:33 . 2009-08-10 16:33 ——– d—–w- c:\program\WhatYouSay
2009-08-10 10:24 . 2009-08-10 10:24 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-10 10:24 . 2009-08-10 10:24 ——– d—–w- c:\program\Java
2009-08-10 10:22 . 2009-08-10 10:22 ——– d—–w- c:\program\ModernRcon
2009-08-09 21:31 . 2009-08-09 21:31 ——– d—–w- c:\program\CoD RconTool
2009-08-08 19:58 . 2009-08-08 19:58 ——– d—–w- c:\program\ZModeler
2009-08-08 16:12 . 2009-08-08 16:12 ——– d—–w- c:\program\MTA San Andreas
2009-08-08 13:17 . 2009-08-08 13:17 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-08-08 06:04 . 2009-08-08 06:04 811008 —-a-w- c:\windows\system32\asdf.exe
2009-08-06 06:30 . 2009-08-06 06:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-08-05 09:01 . 2004-08-03 23:33 205312 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 06:46 . 2009-07-25 21:06 ——– d—–w- c:\program\Winamp
2009-08-03 05:44 . 2009-08-01 19:04 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\program\QuickTime
2009-08-03 01:27 . 2009-08-03 01:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\program\Apple Software Update
2009-08-03 01:26 . 2009-08-03 01:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-02 18:50 . 2009-07-28 19:47 ——– d—–w- c:\documents and settings\Mataza\Application Data\Ventrilo
2009-08-02 18:48 . 2009-08-02 18:48 ——– d—–w- c:\program\Ventrilo
2009-08-02 18:48 . 2009-07-29 20:38 ——– d—–w- c:\program\Delade filer\Wise Installation Wizard
2009-08-02 02:03 . 2009-08-02 02:03 ——– d—–w- c:\program\AeriaGames
2009-08-01 22:51 . 2009-08-01 22:51 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony Creative Software
2009-08-01 20:12 . 2009-08-01 20:12 ——– d—–w- c:\documents and settings\Mataza\Application Data\Publish Providers
2009-08-01 20:12 . 2009-08-01 20:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2009-08-01 20:02 . 2009-08-01 20:02 ——– d—–w- c:\program\Sony
2009-08-01 19:52 . 2009-08-01 19:52 ——– d—–w- c:\program\Windows Media Components
2009-08-01 16:25 . 2009-08-01 16:23 ——– d—–w- c:\program\Driving Simulator 2009
2009-08-01 02:22 . 2009-07-25 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\program\Delade filer\DFX
2009-07-31 17:41 . 2009-07-31 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-07-30 21:04 . 2009-07-30 21:04 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-30 18:47 . 2009-07-30 18:47 ——– d—–w- c:\program\Delade filer\Macrovision Shared
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\program\FlashFXP
2009-07-30 18:16 . 2009-07-30 18:16 ——– d—–w- c:\documents and settings\All Users\Application Data\FlashFXP
2009-07-30 03:59 . 2009-07-30 03:59 ——– d—–w- c:\program\uTorrent
2009-07-28 19:47 . 2009-07-28 19:47 129536 —-a-w- c:\windows\inout2.dll
2009-07-28 18:22 . 2009-07-28 18:22 ——– d—–w- c:\program\Realtek
2009-07-27 16:58 . 2009-07-27 16:58 ——– d—–w- c:\program\FlashMute
2009-07-26 15:32 . 2009-07-26 15:32 ——– d—–w- c:\program\EA GAMES
2009-07-26 14:44 . 2009-07-26 14:44 48448 —-a-w- c:\windows\system32\sirenacm.dll
2009-07-25 23:15 . 2009-07-25 23:14 ——– d—–w- c:\documents and settings\Mataza\Application Data\Notepad++
2009-07-25 23:14 . 2009-07-25 23:14 ——– d—–w- c:\program\Notepad++
2009-07-25 22:47 . 2009-07-25 22:46 ——– d—–w- c:\program\Heroes of Newerth
2009-07-25 22:19 . 2009-07-25 22:19 ——– d—–w- c:\program\D-Tools
2009-07-25 22:00 . 2009-07-25 22:00 ——– d—–w- c:\program\Alcohol Soft
2009-07-25 21:51 . 2009-07-25 21:06 ——– d—–w- c:\documents and settings\Mataza\Application Data\Winamp
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\VideoLAN
2009-07-25 21:49 . 2009-07-25 21:49 ——– d—–w- c:\program\Creative
2009-07-25 21:18 . 2009-07-25 21:18 ——– d—–w- c:\program\Spotify
2009-07-25 21:08 . 2009-07-25 21:08 ——– d—–w- c:\program\Messenger Plus! Live
2009-07-25 20:45 . 2009-07-25 20:45 ——– d—–w- c:\documents and settings\Mataza\Application Data\Logitech
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-07-25 20:44 . 2009-07-25 20:44 ——– d—–w- c:\program\Delade filer\Logishrd
2009-07-25 20:43 . 2009-07-25 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-25 20:33 . 2009-07-25 20:07 ——– d—–w- c:\documents and settings\Mataza\Application Data\DAEMON Tools Lite
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\Mataza\Application Data\ATI
2009-07-25 20:32 . 2009-07-25 20:32 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-07-25 20:31 . 2009-07-25 20:31 0 —-a-w- c:\windows\ativpsrm.bin
2009-07-25 20:31 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Lite
2009-07-25 20:29 . 2009-07-25 18:12 ——– d—–w- c:\program\ATI Technologies
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Windows Live SkyDrive
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\MSBuild
2009-07-25 20:21 . 2009-07-25 20:21 ——– d—–w- c:\program\Reference Assemblies
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-07-25 20:09 . 2009-07-25 20:09 ——– d—–w- c:\program\DAEMON Tools Toolbar
2009-07-25 20:07 . 2009-07-25 20:07 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-03 09:34 . 2009-08-03 09:34 122880 —-a-w- c:\program\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-10_07.04.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-03 23:34 . 2008-04-14 16:04 37888 c:\windows\system32\url.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 39424 c:\windows\system32\pngfilt.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 96768 c:\windows\system32\occache.dll
+ 2004-08-03 23:31 . 2008-04-14 15:35 56832 c:\windows\system32\mshtmler.dll
+ 2004-08-03 23:34 . 2008-04-14 16:05 29184 c:\windows\system32\mshta.exe
- 2009-03-08 02:31 . 2009-07-03 17:00 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-08-14 03:43 . 2009-03-08 02:31 55296 c:\windows\system32\msfeedsbs.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 22016 c:\windows\system32\licmgr10.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 15872 c:\windows\system32\jsproxy.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 96768 c:\windows\system32\inseng.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 35840 c:\windows\system32\imgutil.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 62976 c:\windows\system32\iesetup.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 48640 c:\windows\system32\iernonce.dll
- 2009-04-29 04:46 . 2009-04-29 04:46 81920 c:\windows\system32\ieencode.dll
+ 2009-04-29 04:46 . 2008-04-14 16:04 81920 c:\windows\system32\ieencode.dll
+ 2004-08-03 23:34 . 2008-04-14 16:05 34304 c:\windows\system32\ie4uinit.exe
+ 2004-08-03 23:33 . 2008-04-14 16:04 35328 c:\windows\system32\corpol.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 61440 c:\windows\system32\admparse.dll
+ 2004-08-03 23:34 . 2008-04-14 16:04 666624 c:\windows\system32\wininet.dll
+ 2004-08-03 23:34 . 2008-04-14 16:04 278016 c:\windows\system32\webcheck.dll
+ 2004-08-03 23:34 . 2008-05-09 10:56 430080 c:\windows\system32\vbscript.dll
+ 2004-08-03 23:34 . 2008-04-14 16:04 619520 c:\windows\system32\urlmon.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 532480 c:\windows\system32\mstime.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 146432 c:\windows\system32\msrating.dll
+ 2003-04-24 12:00 . 2003-04-24 12:00 146432 c:\windows\system32\msls31.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 449024 c:\windows\system32\mshtmled.dll
+ 2009-08-14 03:43 . 2009-03-08 02:32 594432 c:\windows\system32\msfeeds.dll
- 2009-03-08 02:32 . 2009-07-03 17:00 594432 c:\windows\system32\msfeeds.dll
+ 2004-08-03 23:33 . 2008-05-09 10:56 512000 c:\windows\system32\jscript.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 251904 c:\windows\system32\iepeers.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 323584 c:\windows\system32\iedkcs32.dll
+ 2003-04-24 12:00 . 2003-04-24 12:00 225280 c:\windows\system32\ieakui.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 219136 c:\windows\system32\ieaksie.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 143360 c:\windows\system32\ieakeng.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 205312 c:\windows\system32\dxtrans.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 357888 c:\windows\system32\dxtmsft.dll
+ 2008-05-09 10:56 . 2008-05-09 10:56 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2003-04-24 12:00 . 2003-04-24 12:00 146432 c:\windows\system32\dllcache\msls31.dll
+ 2008-05-09 10:56 . 2008-05-09 10:56 512000 c:\windows\system32\dllcache\jscript.dll
+ 2003-04-24 12:00 . 2003-04-24 12:00 225280 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 100864 c:\windows\system32\advpack.dll
+ 2004-08-03 23:33 . 2008-04-14 16:04 3066880 c:\windows\system32\mshtml.dll
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program\Windows Live\Messenger\msnmsgr.exe" [2009-09-08 3883856]
"Steam"="c:\program\steam\steam.exe" [2009-08-12 1217784]
"MSMSGS"="c:\program\Messengern\msmsgs.exe" [2002-01-08 1462544]
"SpybotSD TeaTimer"="c:\program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"IDMan"="c:\program\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
"BitTorrent DNA"="c:\program\DNA\btdna.exe" [2009-08-24 318272]
"Google Update"="c:\documents and settings\Mataza\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-30 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-27 61440]
"Launch LgDeviceAgent"="c:\program\Logitech\GamePanel Software\LgDevAgt.exe" [2009-05-04 354312]
"Launch LCDMon"="c:\program\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-05-04 1572872]
"Launch LGDCore"="c:\program\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-05-04 2817544]
"egui"="c:\program\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"amd_dc_opt"="c:\program\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"COMODO Internet Security"="c:\program\COMODO\COMODO Internet Security\cfp.exe" [2009-09-04 1796368]
"Start WingMan Profiler"="c:\program\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-07-20 18670592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Mataza\Start-meny\Program\Autostart\
Xfire.lnk - c:\program\Xfire\Xfire.exe [2009-9-3 3111824]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Logitech SetPoint.lnk - c:\program\Logitech\SetPoint\SetPoint.exe [2009-7-25 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 22:30 72208 —-a-w- c:\program\Delade filer\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Mataza^Start-meny^Program^Autostart^WinCE3.exe]
path=c:\documents and settings\Mataza\Start-meny\Program\Autostart\WinCE3.exe
backup=c:\windows\pss\WinCE3.exeStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program\\Spotify\\spotify.exe"=
"c:\\Program\\EA GAMES\\Battlefield 2\\BF2.exe"=
"h:\\Pr0gz\\FlashFXP\\FlashFXP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program\\uTorrent\\uTorrent.exe"=
"c:\\Program\\FlashFXP\\FlashFXP.exe"=
"c:\\Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program\\Ventrilo\\Ventrilo.exe"=
"c:\\Program\\Steam\\steamapps\\common\\america's army 3\\Binaries\\AA3Game.exe"=
"c:\\Program\\BulletProof FTP Server v2.3\\bpftpserver.exe"=
"c:\\Program\\Steam\\steamapps\\common\\tom clancy's h.a.w.x - demo\\HAWX.exe"=
"c:\\Program\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program\\DNA\\btdna.exe"=
"c:\\Program\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-09-04 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-09-04 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-05-14 94360]
R2 ekrn;ESET Service;c:\program\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-07-25 10384]
R3 skfilt;skfilt;c:\windows\system32\drivers\skfilt.sys [2009-07-25 1670016]
S2 gupdate;Google Update Service (gupdate);c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-07-28 1684736]
S3 cpuz130;cpuz130;\??\c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\Mataza\LOKALA~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 GoogleDesktopManager-060409-093314;Google Desktop-hanteraren 5.9.906.4286;c:\program\Google\Google Desktop Search\GoogleDesktop.exe [2009-08-03 30192]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
.
Innehållet i mappen 'Schemalagda aktiviteter':

2009-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program\Google\Update\GoogleUpdate.exe [2009-07-30 18:29]
.
.
——- Extra genomsökning ——-
.
uStart Page = about:blank
IE: Download all links with IDM - c:\program\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program\Internet Download Manager\IEExt.htm
TCP: {1A919DF9-BFBA-4078-9221-9D6808B8AF4C} = 195.67.199.27
TCP: {844DDB6E-7A82-44EA-AD66-590D7F0C1E62} = 195.67.199.27,195.67.199.28
FF - ProfilePath - c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/
FF - component: c:\documents and settings\Mataza\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\Firefox\Profiles\lmlpmd31.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\documents and settings\Mataza\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICY —-
c:\program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-10 16:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
c:\program\delade filer\logishrd\bluetooth\LBTWlgn.dll
c:\program\delade filer\logishrd\bluetooth\LBTServ.dll
c:\program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Sluttid: 2009-09-10 16:12
ComboFix-quarantined-files.txt 2009-09-10 14:12
ComboFix2.txt 2009-09-10 07:08

Före genomsökningen: 83 640 549 376 byte ledigt
Efter genomsökningen: 83 614 507 008 byte ledigt

411
Uppladdningen lyckades.

Malwarebytes' Anti-Malware 1.40
Database version: 2772
Windows 5.1.2600 Service Pack 3

2009-09-10 16:19:32
mbam-log-2009-09-10 (16-19-32).txt

Scan type: Quick Scan
Objects scanned: 97960
Time elapsed: 2 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Seems like that was some good results, I guess?
Hi, Mataza

Seems like that was some good results, I guess?

So far so good. :)


I see evidence of some P2P programs such as uTorrent, and DNA, but it looks like you may have uninstalled them. Is that the case?

If you have indeed uninstalled these programs you can delete these folders

c:\documents and settings\Mataza\Application Data\DNA
c:\documents and settings\Mataza\Application Data\uTorrent
c:\program\uTorrent
c:\program\DNA


Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please post back with
  • Kaspersky log
  • DDS.txt taken after all other steps are completed
Any problems?

Thanks
Hello. uTorrent is gone and Java wasn't out of date. I tried running the Kapersky thing, but after 13hours it only scanned 3%.. Would've taken me a week or more to get it fully scanned with Kapersky. Anyways, here's DDS reports etc. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 9:51:23,37 on 2009-09-12 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.46.1053.18.2047.1377 [GMT 2:00] AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\WINDOWS\Explorer.EXE C:\Program\Windows Live\Messenger\msnmsgr.exe svchost.exe C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program\Bonjour\mDNSResponder.exe C:\Program\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program\Internet Download Manager\IEMonitor.exe C:\Program\Windows Live\Contacts\wlcomm.exe C:\Program\Mozilla Firefox\firefox.exe C:\Documents and Settings\Mataza\Skrivbord\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Settings,ProxyOverride = *.local BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program\internet download manager\IDMIECC.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program\delade filer\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program\google\google gears\internet explorer\0.5.32.0\gears.dll BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\program\flashfxp\IEFlash.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [msnmsgr] "c:\program\windows live\messenger\msnmsgr.exe" /background uRun: [IDMan] c:\program\internet download manager\IDMan.exe /onboot dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: Download all links with IDM - c:\program\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program\internet download manager\IEExt.htm IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program\pokerstars\PokerStarsUpdate.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messengern\MSMSGS.EXE IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0401 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0404 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0405 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0406 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0407 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0408 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0409 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang040b IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang040c IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang040d IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang040e IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0410 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0411 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0412 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0413 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0414 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0415 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0416 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0419 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang041b IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang041d IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang041f IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0424 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0804 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0816 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\Lang0c0a IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program\google\google gears\internet explorer\0.5.32.0\gears.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program\spybot~1\SDHelper.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248549978984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab TCP: {1A919DF9-BFBA-4078-9221-9D6808B8AF4C} = 195.67.199.27 TCP: {844DDB6E-7A82-44EA-AD66-590D7F0C1E62} = 195.67.199.27,195.67.199.28 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program\hmelyofflabs\vhtoolkit\Skype4COM.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: LBTWlgn - c:\program\delade filer\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mataza\applic~1\mozilla\firefox\profiles\lmlpmd31.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.se/ FF - component: c:\documents and settings\mataza\application data\idm\idmmzcc3\components\idmmzcc.dll FF - component: c:\program\google\google gears\firefox\lib\ff35\gears.dll FF - component: c:\program\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll FF - plugin: c:\documents and settings\mataza\application data\mozilla\firefox\profiles\lmlpmd31.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npjustintvpublish.dll FF - plugin: c:\documents and settings\mataza\application data\mozilla\firefox\profiles\lmlpmd31.default\extensions\[removed]\plugins\npDyyno.dll FF - plugin: c:\documents and settings\mataza\application data\mozilla\plugins\npoctoshape.dll FF - plugin: c:\documents and settings\mataza\lokala instã¤llningar\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program\google\update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B"); c:\program\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se"); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask"); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-9-4 132168] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-9-4 25160] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program\comodo\comodo internet security\cmdagent.exe [2009-9-4 715392] R2 ekrn;ESET Service;c:\program\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840] R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-7-25 10384] R3 skfilt;skfilt;c:\windows\system32\drivers\skfilt.sys [2009-7-25 1670016] S2 gupdate;Google Update Service (gupdate);c:\program\google\update\GoogleUpdate.exe [2009-7-30 133104] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-7-28 1684736] S3 cpuz130;cpuz130;\??\c:\docume~1\mataza\lokala~1\temp\cpuz130\cpuz_x32.sys –> c:\docume~1\mataza\lokala~1\temp\cpuz130\cpuz_x32.sys [?] S3 GoogleDesktopManager-060409-093314;Google Desktop-hanteraren 5.9.906.4286;c:\program\google\google desktop search\GoogleDesktop.exe [2009-8-3 30192] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?] =============== Created Last 30 ================ 2009-09-11 18:44 –d—– c:\docume~1\alluse~1\applic~1\Test Drive Unlimited 2009-09-11 18:43 107,888 a——- c:\windows\system32\CmdLineExt.dll 2009-09-11 18:13 –d—– c:\program\Atari 2009-09-11 12:09 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-09-11 12:09 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-09-11 12:08 –d—– c:\program\iPod 2009-09-11 12:08 –d—– c:\program\iTunes 2009-09-11 12:08 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-09-11 12:07 –d—– c:\program\Bonjour 2009-09-11 12:02 –d—– c:\program\delade filer\Apple 2009-09-11 11:56 –d—– c:\program\iPodRip 2009-09-10 16:16 –d—– c:\docume~1\mataza\applic~1\Malwarebytes 2009-09-10 16:15 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 16:15 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-09-10 16:15 –d—– c:\program\Malwarebytes' Anti-Malware 2009-09-10 16:15 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-09-10 15:08 970 a——- c:\windows\Active Setup Log.BAK 2009-09-10 14:02 –d—– c:\program\AionEUz 2009-09-10 08:53 a-dshr– C:\cmdcons 2009-09-10 08:52 230,912 a——- c:\windows\PEV.exe 2009-09-10 08:52 161,792 a——- c:\windows\SWREG.exe 2009-09-10 08:52 98,816 a——- c:\windows\sed.exe 2009-09-09 17:42 –d—– c:\program\Diablo II 2009-09-09 16:41 –d—– c:\docume~1\alluse~1\applic~1\Last.fm 2009-09-09 16:40 –d—– c:\program\Last.fm 2009-09-09 10:53 –d—– C:\X360HP Temp 2009-09-09 10:48 –d—– c:\program\Xbox 360 Hack Pack RC1 2009-09-09 00:24 –d—– c:\program\Microsoft 2009-09-09 00:05 –d—– c:\docume~1\alluse~1\applic~1\WindowsLiveInstaller 2009-09-09 00:04 –d—– c:\documents and settings\mataza\Contacts 2009-09-08 23:34 –d—– c:\program\MSN Messenger 2009-09-08 23:34 –d—– c:\windows\system32\appmgmt 2009-09-08 23:28 –d—– c:\program\Messengern 2009-09-08 16:00 –d—– c:\program\delade filer\Adobe AIR 2009-09-07 16:51 –d—– c:\program\Bridge Construction Set Demo 2009-09-07 06:45 –d-h— c:\windows\PIF 2009-09-06 07:57 –d—– c:\program\delade filer\NSV 2009-09-06 06:30 3,407,412 a——- c:\windows\system32\GameMon.des 2009-09-06 04:51 –d—– c:\program\Need for Speed Most Wanted 2009-09-05 07:11 –d—– c:\program\delade filer\Logitech 2009-09-05 04:18 –d—– c:\program\Euro Truck Simulator 2009-09-05 01:54 94,208 a——- c:\windows\system32\QuickTimeVR.qtx 2009-09-05 01:54 69,632 a——- c:\windows\system32\QuickTime.qts 2009-09-04 22:15 –d—– c:\program\Microsoft Games 2009-09-04 02:49 –d—– c:\docume~1\alluse~1\applic~1\Comodo 2009-09-04 02:49 179,792 a——- c:\windows\system32\guard32.dll 2009-09-04 02:49 132,168 a——- c:\windows\system32\drivers\cmdguard.sys 2009-09-04 02:49 25,160 a——- c:\windows\system32\drivers\cmdhlp.sys 2009-09-04 02:48 –d—– c:\program\COMODO 2009-09-03 20:07 41,872 a——- c:\windows\system32\xfcodec.dll 2009-09-02 18:55 –d—– c:\program\PokerStars 2009-09-02 18:53 –d—– c:\docume~1\mataza\applic~1\TeamViewer 2009-09-02 18:53 –d—– c:\program\TeamViewer 2009-09-02 18:52 –d—– c:\documents and settings\mataza\temp 2009-09-02 15:53 –d—– c:\program\AionEU 2009-09-02 15:53 –d—– c:\program\NCsoft 2009-08-31 00:18 –d—– c:\docume~1\mataza\applic~1\NoNameScript 2009-08-29 01:58 –d—– c:\program\Audacity 2009-08-29 01:50 118,784 a——- c:\windows\system32\mp3dec.dll 2009-08-29 01:50 40,960 a——- c:\windows\system32\MDec.ocx 2009-08-27 15:02 –ds—- c:\program\HLSW 2009-08-27 15:02 –d—– c:\docume~1\mataza\applic~1\HLSW 2009-08-25 19:23 –d—– c:\program\RealVNC 2009-08-24 14:25 5,174 a——- c:\windows\system32\nppt9x.vxd 2009-08-24 14:25 4,682 a——- c:\windows\system32\npptNT2.sys 2009-08-24 12:01 –d—– C:\AeriaGames 2009-08-24 11:17 –d—– c:\program\DNA 2009-08-24 11:17 –d—– c:\docume~1\mataza\applic~1\DNA 2009-08-23 18:34 –d—– c:\program\SmartFTP Client 2009-08-23 18:34 –d—– c:\program\SmartFTP Client 3.0 Setup Files 2009-08-23 10:17 –d—– c:\program\OpenAL 2009-08-23 10:17 –d—– c:\docume~1\mataza\applic~1\flightgear.org 2009-08-23 10:15 –d—– c:\program\FlightGear 2009-08-23 10:15 –d—– c:\program\Bridge Building Game 2009-08-22 14:31 –d—– c:\program\AMX Mod X 2009-08-22 14:04 –d—– C:\hlds 2009-08-22 10:09 –d—– c:\docume~1\mataza\applic~1\Octoshape 2009-08-22 08:03 –d—– c:\program\Apophysis 2.0 2009-08-21 16:59 –d—– c:\program\SystemRequirementsLab 2009-08-21 16:32 –d—– c:\program\HD Tune Pro 2009-08-21 11:35 –d—– c:\windows\pss 2009-08-21 10:51 211 a——- C:\boot ini backup 2009-08-21 07:00 266,360 a——- c:\windows\system32\TweakUI.exe 2009-08-21 07:00 160,217 a——- c:\windows\system32\PowerToysLicense.rtf 2009-08-20 04:39 –d—– c:\program\Spybot - Search & Destroy 2009-08-20 04:39 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-08-19 01:54 –d—– c:\program\VirtualDJ 2009-08-18 23:35 –d—– c:\program\BulletProof FTP Server v2.3 2009-08-18 05:11 –d—– c:\program\delade filer\DirectX 2009-08-18 05:11 96 a—h— c:\windows\system32\HsInfo.dat 2009-08-17 18:08 –d—– c:\docume~1\alluse~1\applic~1\Blizzard Entertainment 2009-08-17 18:05 –d—– c:\docume~1\alluse~1\applic~1\Blizzard Entertainment.temp 2009-08-17 17:50 73,728 a——- c:\windows\system32\ISUSPM.cpl 2009-08-17 17:50 –d—– c:\program\Gravity 2009-08-17 16:37 –d—– C:\WoW PTR 2009-08-17 16:00 –d—– c:\windows\Entropia Universe 2009-08-17 16:00 –d—– c:\program\Entropia Universe 2009-08-16 22:26 –d—– c:\program\MSXML 6.0 2009-08-16 22:15 –d—– c:\program\Guitar Hero World Tour 2009-08-16 22:14 238,088 a——- c:\windows\system32\xactengine3_0.dll 2009-08-16 22:14 25,608 a——- c:\windows\system32\X3DAudio1_3.dll 2009-08-16 22:14 1,420,824 a——- c:\windows\system32\D3DCompiler_37.dll 2009-08-16 22:14 462,864 a——- c:\windows\system32\d3dx10_37.dll 2009-08-16 22:14 3,786,760 a——- c:\windows\system32\D3DX9_37.dll 2009-08-16 21:31 27,672 a—-r– c:\windows\system32\drivers\Entech.sys 2009-08-16 21:31 –d—– c:\windows\system32\Futuremark 2009-08-16 21:31 –d—– c:\program\delade filer\Futuremark Shared 2009-08-16 17:57 –d—– c:\docume~1\mataza\applic~1\mIRC 2009-08-16 17:57 –d—– c:\program\mIRC 2009-08-14 21:00 –d—– c:\program\DFX 2009-08-14 05:53 221,184 a——- c:\windows\system32\wmpns.dll 2009-08-14 05:38 1,315,328 -c—— c:\windows\system32\dllcache\msoe.dll 2009-08-14 05:38 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx 2009-08-14 05:37 1,089,883 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-08-14 05:34 –d—– c:\program\ESET 2009-08-13 23:15 –d—– c:\docume~1\mataza\applic~1\id Software 2009-08-13 23:15 794,408 a——- c:\windows\system32\pbsvc.exe 2009-08-13 23:15 –d—– c:\docume~1\alluse~1\applic~1\id Software 2009-08-13 16:10 –d—– c:\docume~1\mataza\applic~1\IDM 2009-08-13 16:10 –d—– c:\docume~1\mataza\applic~1\DMCache 2009-08-13 16:10 –d—– c:\program\Internet Download Manager ==================== Find3M ==================== 2009-09-11 16:40 189,104 a——- c:\windows\system32\PnkBstrB.exe 2009-09-11 15:31 139,584 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-08-30 01:42 413,696 a——- c:\windows\system32\wrap_oal.dll 2009-08-30 01:42 110,592 a——- c:\windows\system32\OpenAL32.dll 2009-08-23 04:50 434,880 a——- c:\windows\system32\perfh01D.dat 2009-08-23 04:50 78,906 a——- c:\windows\system32\perfc01D.dat 2009-08-14 15:18 139,152 a——- c:\docume~1\mataza\applic~1\PnkBstrK.sys 2009-08-14 15:18 75,064 a——- c:\windows\system32\PnkBstrA.exe 2009-08-10 18:33 711,162 a——- c:\windows\WhatYouSay Uninstaller.exe 2009-08-10 12:24 411,368 a——- c:\windows\system32\deploytk.dll 2009-08-08 08:04 811,008 a——- c:\windows\system32\asdf.exe 2009-08-05 11:01 205,312 a——- c:\windows\system32\mswebdvd.dll 2009-07-28 21:47 129,536 a——- c:\windows\inout2.dll 2009-07-26 16:44 48,448 a——- c:\windows\system32\sirenacm.dll 2009-07-25 22:44 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2009-07-25 22:44 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2009-07-25 22:44 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf 2009-07-25 22:07 721,904 a——- c:\windows\system32\drivers\sptd.sys 2009-07-25 21:44 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-07-25 20:19 10,528,768 a——- c:\windows\system32\RTLCPL.exe 2009-07-25 20:19 4,027,456 a——- c:\windows\system32\drivers\alcxwdm.sys 2009-07-25 20:19 217,088 a——- c:\windows\alcrmv.exe 2009-07-25 20:19 315,392 a——- c:\windows\alcupd.exe 2009-07-25 20:19 49,152 a——- c:\windows\system32\ChCfg.exe 2009-07-25 20:03 21,700 a——- c:\windows\system32\emptyregdb.dat 2009-07-20 19:08 5,795,328 a——- c:\windows\system32\drivers\RtkHDAud.sys 2009-07-20 11:12 18,670,592 a——- c:\windows\RTHDCPL.EXE 2009-07-17 21:04 58,880 a——- c:\windows\system32\atl.dll 2009-07-12 12:21 233,472 a——- c:\windows\system32\wmpdxm.dll 2009-07-08 11:29 41,472 a——- c:\windows\system32\RtkCoInstXP.dll 2009-06-25 10:27 730,624 a——- c:\windows\system32\lsasrv.dll 2009-06-25 10:27 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 10:27 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 10:27 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 10:27 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 10:27 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-24 10:43 831,488 a——- c:\windows\RtlExUpd.dll 2009-06-22 17:39 1,482,752 a——- c:\windows\RtlUpd.exe 2009-06-16 16:40 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 16:40 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-15 12:45 76,800 a——- c:\windows\system32\telnet.exe 2009-06-15 12:45 80,896 a——- c:\windows\system32\tlntsess.exe ============= FINISH: 9:51:49,50 =============== (Dont know if you need this one) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 2009-07-25 20:08:20 System Uptime: 2009-09-12 09:43:53 (0 hours ago) Motherboard: MSI | | MS-7250 Processor: AMD Athlon™ 64 X2 Dual Core Processor 4600+ | CPU 1 | 2412/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 298 GiB total, 79,421 GiB free. D: is CDROM () E: is CDROM (UDF) F: is CDROM () G: is CDROM () H: is FIXED (NTFS) - 932 GiB total, 313,383 GiB free. I: is CDROM () J: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318} Description: PS/2 Keyboard Device ID: ACPI\PNP0303\4&2B0A5BEB&0 Manufacturer: Logitech Name: PS/2 Keyboard PNP Device ID: ACPI\PNP0303\4&2B0A5BEB&0 Service: i8042prt Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: NVIDIA nForce Networking Controller Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0373\4&D8AC490&0&00 Manufacturer: NVIDIA Name: NVIDIA nForce Networking Controller PNP Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0373\4&D8AC490&0&00 Service: NVENETFD Class GUID: Description: Device ID: DISPLAY\NTATIVRV01\5&28084EF1&0&80000008&07&00 Manufacturer: Name: PNP Device ID: DISPLAY\NTATIVRV01\5&28084EF1&0&80000008&07&00 Service: Class GUID: Description: Device ID: ACPI\AWY0001\2&DABA3FF&0 Manufacturer: Name: PNP Device ID: ACPI\AWY0001\2&DABA3FF&0 Service: ==== System Restore Points =================== RP1: 2009-09-11 18:33:36 - Systemkontrollpunkt ==== Installed Programs ====================== Activision® Adobe AIR Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Drive CS4 Adobe Dynamiclink Support Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash CS4 Adobe Flash CS4 Extension - Flash Lite STI en Adobe Flash CS4 Professional Adobe Flash CS4 STI-en Adobe Flash Media Encoder 2.5 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Fonts All Adobe Linguistics CS4 Adobe Media Encoder CS4 Adobe Media Encoder CS4 Importer Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Support Adobe Reader 9.1 - Svenska Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Type Support CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Aion AMD Power Monitor America's Army 3 AMX Mod X Installer 1.8.1 Apophysis 2.0 Apple Application Support Apple Mobile Device Support Apple Software Update ATI - Hjälp för avinstallation av program ATI Catalyst Control Center ATI Display Driver µTorrent Audacity 1.2.6 Battlefield 2™ Battlefield 2: Special Forces Bonjour Bridge Building Game BulletProof FTP Client (remove only) BulletProof FTP Server (remove only) Call of Duty® 4 - Modern Warfare™ Call of Duty® 4 - Modern Warfare™ 1.6 Patch Call of Duty® 4 - Modern Warfare™ 1.7 Patch Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CDDRV_Installer Cheat Engine 5.5 CleanUp! CoD RconTool COMODO Internet Security Connect Counter-Strike Counter-Strike: Source DAEMON Tools DAEMON Tools Toolbar DFX for Winamp Diablo II DNA Driving Simulator 2009 Version 1.12 Drum Controller Standard Tuning Kit Dual-Core Optimizer Dungeon Siege Entropia Universe ESET NOD32 Antivirus Euro Truck Simulator FlashFXP v3 FlashMute FlightGear v1.9.1 Fraps (remove only) Futuremark SystemInfo Garry's Mod Google Chrome Google Desktop Google Gears Google Update Helper GTA San Andreas Guild Wars Guitar Hero World Tour Half-Life 2 Half-Life Dedicated Server Update Tool HD Tune Pro 3.50 Heroes of Newerth HijackThis 2.0.2 HLSW v1.3.2.1 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB954550-v5) ImgBurn Insurgency Internet Download Manager iPodRip iTunes Java™ 6 Update 15 KhalInstallWrapper kuler Last.fm 1.5.4.24567 Logitech GamePanel Software 3.02.173 Logitech Gaming Software 5.04 Logitech SetPoint Malwarebytes' Anti-Malware Messenger Plus! Live Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - SVE Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - SVE Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 Language Pack - sve Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 mIRC ModernRcon v0.8 Mozilla Firefox (3.5.3) MSVCRT MSXML 6.0 Parser MTA: Race for San Andreas - Server 1.1.1 MTA:SA Race 1.1.2 NCsoft Launcher Need for Speed™ Most Wanted NNScript Notepad++ NVIDIA Drivers Octoshape Streaming Services OpenAL PDF Settings CS4 Photoshop Camera Raw Pixel Bender Toolkit PokerStars Project Torque PunkBuster Services Quake Live Mozilla Plugin QuickTime Realtek AC'97 Audio Realtek High Definition Audio Driver Requiem Segoe UI Shaiya(US) Skins SmartFTP Client SmartFTP Client 3.0 Setup Files (remove only) Snabbkorrigering för Windows XP (KB952287) Snabbkorrigering för Windows XP (KB961118) Säkerhetsuppdatering för Windows Media Encoder (KB954156) Säkerhetsuppdatering för Windows Media Player (KB952069) Säkerhetsuppdatering för Windows Media Player (KB973540) Säkerhetsuppdatering för Windows XP (KB923561) Säkerhetsuppdatering för Windows XP (KB923789) Säkerhetsuppdatering för Windows XP (KB938464-v2) Säkerhetsuppdatering för Windows XP (KB941569) Säkerhetsuppdatering för Windows XP (KB946648) Säkerhetsuppdatering för Windows XP (KB950762) Säkerhetsuppdatering för Windows XP (KB950974) Säkerhetsuppdatering för Windows XP (KB951066) Säkerhetsuppdatering för Windows XP (KB951376-v2) Säkerhetsuppdatering för Windows XP (KB951748) Säkerhetsuppdatering för Windows XP (KB952004) Säkerhetsuppdatering för Windows XP (KB952954) Säkerhetsuppdatering för Windows XP (KB954459) Säkerhetsuppdatering för Windows XP (KB954600) Säkerhetsuppdatering för Windows XP (KB955069) Säkerhetsuppdatering för Windows XP (KB956572) Säkerhetsuppdatering för Windows XP (KB956744) Säkerhetsuppdatering för Windows XP (KB956802) Säkerhetsuppdatering för Windows XP (KB956803) Säkerhetsuppdatering för Windows XP (KB957097) Säkerhetsuppdatering för Windows XP (KB958644) Säkerhetsuppdatering för Windows XP (KB958687) Säkerhetsuppdatering för Windows XP (KB959426) Säkerhetsuppdatering för Windows XP (KB960225) Säkerhetsuppdatering för Windows XP (KB960803) Säkerhetsuppdatering för Windows XP (KB960859) Säkerhetsuppdatering för Windows XP (KB961371) Säkerhetsuppdatering för Windows XP (KB961501) Säkerhetsuppdatering för Windows XP (KB968537) Säkerhetsuppdatering för Windows XP (KB969897) Säkerhetsuppdatering för Windows XP (KB970238) Säkerhetsuppdatering för Windows XP (KB971557) Säkerhetsuppdatering för Windows XP (KB971633) Säkerhetsuppdatering för Windows XP (KB971657) Säkerhetsuppdatering för Windows XP (KB973346) Säkerhetsuppdatering för Windows XP (KB973354) Säkerhetsuppdatering för Windows XP (KB973507) Säkerhetsuppdatering för Windows XP (KB973869) Spotify Språkpaket för Microsoft .NET Framework 3.5 - Swedish Spybot - Search & Destroy Steam Suite Shared Configuration CS4 System Requirements Lab TeamViewer 4 Test Drive Unlimited Tom Clancy's H.A.W.X - Demo Tweak UI Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Uppdatering för Windows XP (KB951978) Uppdatering för Windows XP (KB955839) Uppdatering för Windows XP (KB961503) Uppdatering för Windows XP (KB967715) Uppdatering för Windows XP (KB968389) Uppdatering för Windows XP (KB973815) WebFldrs XP Vegas Pro 9.0 Ventrilo Client VentriloMIX VH Toolkit [removed] WhatYouSay Winamp Winamp Essentials Pack Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinRAR archiver Virtual DJ - Atomix Productions VLC media player 1.0.1 VNC Free Edition 4.1.3 World of Warcraft WVS 0.30.14 for Winamp Xbox 360 Hack Pack RC1 Xfire (remove only) XML Paper Specification Shared Components Language Pack 1.0 XML Paper Specification Shared Components Pack 1.0 ZModeler (remove only) ==== Event Viewer Messages From Past Week ======== 2009-09-10 09:00:47, information: Windows File Protection [64002] - Ett försök gjordes att ersätta den skyddade systemfilen c:\windows\system32\pagefileconfig.vbs. Filen återställdes till sin ursprungliga version för att systemstabiliteten ska behållas. Systemfilens version: 0.0.0.1. ==== End Of File ===========================
Hi Mataza,

Given the amount of data you have on your computer any scan is going to take considerable time. I'n not sure why Kaspersky was taking that long as it would seem it scanned about 30gb. What's on your H:\ drive?

Antivirus scanners look in places our tools don't, so in order to give my best opinion on whether or not you are clean I will need to see the reults of an online scan.

Try this one and scan your C:\ drive.

Please go to the F-secure online scanner.
You will need to use Internet Explorer versions 6.0 or 7.0 or Mozilla Firefox 3.0. Enable java script and for Internet Explorer enable ActiveX.
Click the "Start" button.
The online scanner will load, and a separate scanner window will open giving you the option of a:
  • Quick Scan
  • Full Scan
  • My Scan (a custom scan of folders that you select)
Select "Quick Scan"
Choose Your language from the drop down box in the upper right
Check The box "I have read and accepted the license terms" in the lower right
Click "Start"
The necessary files will be downloaded and scanning will begin.
Upon completion you will be able to select files to remove , do not remove anything
View the full scan log
Scan again or Close the scanner.

Please post the log for review.
On my H:\ drive I have loads and loads of music/movie backups etc. heres the report thingie. Scanning Report Sunday, September 13, 2009 03:29:56 - 03:35:47 Computer name: DATORN Scanning type: Quick scan Target: System 12 malware found TrackingCookie.2o7 (spyware) * System (Not cleaned) TrackingCookie.Advertising (spyware) * System (Not cleaned) TrackingCookie.Atdmt (spyware) * System (Not cleaned) TrackingCookie.Adform (spyware) * System (Not cleaned) TrackingCookie.Doubleclick (spyware) * System (Not cleaned) TrackingCookie.Revsci (spyware) * System (Not cleaned) TrackingCookie.Xiti (spyware) * System (Not cleaned) TrackingCookie.Webtrends (spyware) * System (Not cleaned) Trojan.Generic.1718016 (spyware) * System (Not cleaned) TrackingCookie.Tradedoubler (spyware) * System (Not cleaned) TrackingCookie.Atwola (spyware) * System (Not cleaned) TrackingCookie.Yieldmanager (spyware) * System (Not cleaned) Statistics Scanned: * Files: 3449 * System: 3449 * Not scanned: 0 Actions: * Disinfected: 0 * Renamed: 0 * Deleted: 0 * Not cleaned: 12 * Submitted: 0 Options Scanning engines:
Hi Mataza,

We'll clean out your temporary files, and you should be good to go.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

If no problems, we'll clean up our tools.

From your desktop, please delete
  • any notepads/logs that we created
  • DDS.scr

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

I suggest you keep MBAM. Keep MBAM updated and use it regularly. You can also keep TFC if you wish.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have those already.

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI