ComboFix 08-10-05.08 - Christer 2008-10-06 15:43:50.11 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1044.18.519 [GMT 2:00]
Running from: C:\Documents and Settings\Christer\Skrivebord\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((( Files Created from 2008-09-06 to 2008-10-06 )))))))))))))))))))))))))))))))
.
2008-09-24 21:13 . 2008-09-24 21:13
d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard
2008-09-24 20:55 . 2008-10-06 15:01 dr-h----- C:\Documents and Settings\Christer\Siste
2008-09-20 22:37 . 2008-09-20 22:37 d-------- C:\Documents and Settings\Christer\Programdata\Ashampoo
2008-09-20 22:33 . 2008-09-20 22:33 d-------- C:\Documents and Settings\All Users\Programdata\ashampoo
2008-09-19 16:45 . 2008-09-19 16:55 d-------- C:\Nexon
2008-09-19 16:45 . 2008-09-19 16:45 d-------- C:\Documents and Settings\All Users\Programdata\NexonUS
2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\WINDOWS\system32\ws341274.ocx
2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\os501435.bin
2008-09-16 17:21 . 2008-09-16 17:21 d-------- C:\WINDOWS\Vbox
2008-09-16 17:21 . 2008-09-16 19:34 d-------- C:\DfW5Trial
2008-09-15 18:21 . 2008-09-15 18:21 d--h----- C:\WINDOWS\PIF
2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\no
2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\bits
2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\l2schemas
2008-09-12 22:42 . 2008-09-12 22:46 d-------- C:\WINDOWS\ServicePackFiles
2008-09-12 22:34 . 2008-09-12 22:34 d-------- C:\WINDOWS\EHome
2008-09-12 17:25 . 2004-08-04 00:54 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-09-12 16:31 . 2008-09-12 16:33 d-------- C:\Programfiler\CamStudio
2008-09-11 17:08 . 2008-09-11 17:10 d-------- C:\Programfiler\Malwarebytes' Anti-Malware
2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\Christer\Programdata\Malwarebytes
2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes
2008-09-11 17:08 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-11 17:08 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-10 22:13 . 2008-09-10 22:13 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-09-09 21:02 . 2008-09-09 21:02 d-------- C:\Programfiler\Lavasoft
2008-09-09 21:02 . 2008-09-09 21:03 d-------- C:\Documents and Settings\All Users\Programdata\Lavasoft
2008-09-09 20:54 . 2008-09-09 20:54 268 --ah----- C:\sqmdata02.sqm
2008-09-09 20:54 . 2008-09-09 20:54 244 --ah----- C:\sqmnoopt02.sqm
2008-09-09 20:48 . 2008-09-09 20:48 268 --ah----- C:\sqmdata01.sqm
2008-09-09 20:48 . 2008-09-09 20:48 244 --ah----- C:\sqmnoopt01.sqm
2008-09-09 20:38 . 2008-09-09 20:38 d-------- C:\Documents and Settings\Reidun\Programdata\Nero
2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Programfiler\NCH Software
2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Documents and Settings\All Users\Programdata\NCH Software
2008-09-06 16:36 . 2008-09-22 18:30 d-------- C:\Documents and Settings\Christer\Programdata\BitTorrent
2008-09-06 16:35 . 2008-09-18 14:25 d-------- C:\Programfiler\DNA
2008-09-06 16:35 . 2008-09-06 16:35 d-------- C:\Programfiler\BitTorrent
2008-09-06 16:35 . 2008-10-06 15:44 d-------- C:\Documents and Settings\Christer\Programdata\DNA
2008-09-06 16:15 . 2008-09-15 20:14 d-------- C:\Programfiler\Ahead
2008-09-06 15:37 . 2008-09-06 16:40 d-------- C:\Programfiler\FrostWire
2008-09-06 15:37 . 2008-09-06 16:41 d-------- C:\Documents and Settings\Christer\Programdata\FrostWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 13:09 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared
2008-10-06 13:00 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec
2008-10-06 12:35 --------- d-----w C:\Programfiler\LogMeIn
2008-10-05 08:19 --------- d-----w C:\Programfiler\Dl_cats
2008-09-22 16:42 --------- d-----w C:\Documents and Settings\All Users\Programdata\DVD Shrink
2008-09-10 20:11 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help
2008-09-09 14:03 --------- d-----w C:\Documents and Settings\Christer\Programdata\dvdcss
2008-09-06 14:17 --------- d-----w C:\Programfiler\Fellesfiler\Nero
2008-09-02 12:56 --------- d-----w C:\Programfiler\Microsoft Silverlight
2008-09-02 12:44 --------- d--h--w C:\Programfiler\InstallShield Installation Information
2008-09-01 18:44 --------- d-----w C:\Programfiler\Cyanide
2008-09-01 18:41 --------- d-----w C:\Programfiler\Screamer Radio
2008-09-01 18:40 --------- d-----w C:\Programfiler\Yahoo!
2008-09-01 18:32 --------- d-----w C:\Programfiler\OpenOffice.org 2.3
2008-09-01 18:30 --------- d-----w C:\Documents and Settings\Christer\Programdata\OpenOffice.org2
2008-09-01 18:21 --------- d-----w C:\Programfiler\JLC's Software
2008-09-01 18:19 --------- d-----w C:\Programfiler\Gekko Mahjongg (Xmas edition)
2008-09-01 18:19 --------- d-----w C:\Programfiler\EA SPORTS
2008-09-01 18:18 --------- d-----w C:\Programfiler\AviSynth 2.5
2008-09-01 15:30 --------- d-----w C:\Documents and Settings\Tore\Programdata\OpenOffice.org2
2008-08-30 09:32 --------- d-----w C:\Programfiler\LimeWire
2008-08-30 09:32 --------- d-----w C:\Documents and Settings\Christer\Programdata\LimeWire
2008-08-30 09:15 --------- d-----w C:\Programfiler\Java
2008-08-29 17:04 --------- d-----w C:\Documents and Settings\Christer\Programdata\Azureus
2008-08-29 16:48 --------- d-----w C:\Documents and Settings\All Users\Programdata\Azureus
2008-08-27 19:24 --------- d-----w C:\Documents and Settings\Christer\Programdata\Xilisoft Corporation
2008-08-25 18:18 --------- d-----w C:\Programfiler\GeoGebra
2008-08-25 18:16 --------- d--h--w C:\Programfiler\Zero G Registry
2008-08-25 15:06 --------- d-----w C:\Programfiler\Handbrake
2008-08-25 15:05 --------- d-----w C:\Programfiler\NCH Swift Sound
2008-08-25 15:04 --------- d-----w C:\Programfiler\Elaborate Bytes
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:29 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2007-12-17 08:35 60,968 ----a-w C:\Documents and Settings\Christer\GoToAssistDownloadHelper.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-02 68856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
"BitTorrent DNA"="C:\Programfiler\DNA\btdna.exe" [2008-09-18 289088]
"WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DVDLauncher"="C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"DMXLauncher"="C:\Programfiler\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"ISUSPM Startup"="C:\PROGRA~1\FELLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632]
"dlccmon.exe"="C:\Programfiler\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984]
"ecc"="C:\Programfiler\Telenor\ecc\ecc.exe" [2005-12-14 286720]
"LogMeIn GUI"="C:\Programfiler\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"CamMonitor"="C:\Programfiler\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112]
"Share-to-Web Namespace Daemon"="C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"ccApp"="C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="C:\Programfiler\Norton Internet Security\osCheck.exe" [2006-10-16 26248]
"NBKeyScan"="C:\Programfiler\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Programfiler\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Symantec PIF AlertEng"="C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\Tore\Start-meny\Programmer\Oppstart\
OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
C:\Documents and Settings\Christer\Start-meny\Programmer\Oppstart\
OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2007-12-17 10:35 10792 C:\Programfiler\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programfiler\\BitTorrent\\bittorrent.exe"=
"C:\\Programfiler\\EA GAMES\\Battlefield 2\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programfiler\\Messenger\\msmsgs.exe"=
"C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Programfiler\\Bonjour\\mDNSResponder.exe"=
"C:\\Programfiler\\iTunes\\iTunes.exe"=
"C:\\Programfiler\\DNA\\btdna.exe"=
"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Programdata\\NexonUS\\NGM\\NGM.exe"=
R2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-10-16 198336]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Programfiler\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848]
S3 GoToAssist;GoToAssist;C:\Programfiler\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2008-07-22 32000]
S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys [ ]
S3 w550mdfl;Sony Ericsson W550 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w550mdfl.sys [ ]
S3 w550mdm;Sony Ericsson W550 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w550mdm.sys [ ]
S3 w550mgmt;Sony Ericsson W550 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w550mgmt.sys [ ]
S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w550obex.sys [ ]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2008-09-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Programfiler\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-09-19 C:\WINDOWS\Tasks\Norton Internet Security Online - Kjør fullstendig systemsøk - Christer.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2006-10-16 17:17]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.online.no/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: {358DFA15-D48C-4296-8D16-7405F918333B} - hxxps://fronter.com/fredrikstadgs/links/fronter_oes2.cab
C:\WINDOWS\Downloaded Program Files\fronter_oes2.inf
C:\WINDOWS\Downloaded Program Files\Fronter_oes_prj.ocx
C:\WINDOWS\Downloaded Program Files\fronter_oes2.exe
C:\WINDOWS\Downloaded Program Files\fronter_oes2.dll
O16 -: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} - hxxp://www.mpw.no/TvNorge/KooPlayer.ocx
C:\WINDOWS\Downloaded Program Files\KooPlayer.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 15:45:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-06 15:47:12
ComboFix-quarantined-files.txt 2008-10-06 13:47:06
ComboFix2.txt 2008-10-06 13:22:48
ComboFix3.txt 2008-10-05 07:48:55
Pre-Run: 99 295 334 400 byte ledig
Post-Run: 99,277,877,248 byte ledig
224 --- E O F --- 2008-09-16 12:39:04