ComboFix 08-10-05.08 - Christer 2008-10-06 15:43:50.11 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1044.18.519 [GMT 2:00] Running from: C:\Documents and Settings\Christer\Skrivebord\ComboFix.exe * Created a new restore point [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR] . ((((((((((((((((((((((((( Files Created from 2008-09-06 to 2008-10-06 ))))))))))))))))))))))))))))))) . 2008-09-24 21:13 . 2008-09-24 21:13 d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-09-24 20:55 . 2008-10-06 15:01 dr-h----- C:\Documents and Settings\Christer\Siste 2008-09-20 22:37 . 2008-09-20 22:37 d-------- C:\Documents and Settings\Christer\Programdata\Ashampoo 2008-09-20 22:33 . 2008-09-20 22:33 d-------- C:\Documents and Settings\All Users\Programdata\ashampoo 2008-09-19 16:45 . 2008-09-19 16:55 d-------- C:\Nexon 2008-09-19 16:45 . 2008-09-19 16:45 d-------- C:\Documents and Settings\All Users\Programdata\NexonUS 2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\WINDOWS\system32\ws341274.ocx 2008-09-16 17:27 . 2008-09-16 17:30 565 --ah----- C:\os501435.bin 2008-09-16 17:21 . 2008-09-16 17:21 d-------- C:\WINDOWS\Vbox 2008-09-16 17:21 . 2008-09-16 19:34 d-------- C:\DfW5Trial 2008-09-15 18:21 . 2008-09-15 18:21 d--h----- C:\WINDOWS\PIF 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\no 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\system32\bits 2008-09-12 22:46 . 2008-09-12 22:46 d-------- C:\WINDOWS\l2schemas 2008-09-12 22:42 . 2008-09-12 22:46 d-------- C:\WINDOWS\ServicePackFiles 2008-09-12 22:34 . 2008-09-12 22:34 d-------- C:\WINDOWS\EHome 2008-09-12 17:25 . 2004-08-04 00:54 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys 2008-09-12 16:31 . 2008-09-12 16:33 d-------- C:\Programfiler\CamStudio 2008-09-11 17:08 . 2008-09-11 17:10 d-------- C:\Programfiler\Malwarebytes' Anti-Malware 2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\Christer\Programdata\Malwarebytes 2008-09-11 17:08 . 2008-09-11 17:08 d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes 2008-09-11 17:08 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-09-11 17:08 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-09-10 22:13 . 2008-09-10 22:13 118 --a------ C:\WINDOWS\system32\MRT.INI 2008-09-09 21:02 . 2008-09-09 21:02 d-------- C:\Programfiler\Lavasoft 2008-09-09 21:02 . 2008-09-09 21:03 d-------- C:\Documents and Settings\All Users\Programdata\Lavasoft 2008-09-09 20:54 . 2008-09-09 20:54 268 --ah----- C:\sqmdata02.sqm 2008-09-09 20:54 . 2008-09-09 20:54 244 --ah----- C:\sqmnoopt02.sqm 2008-09-09 20:48 . 2008-09-09 20:48 268 --ah----- C:\sqmdata01.sqm 2008-09-09 20:48 . 2008-09-09 20:48 244 --ah----- C:\sqmnoopt01.sqm 2008-09-09 20:38 . 2008-09-09 20:38 d-------- C:\Documents and Settings\Reidun\Programdata\Nero 2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Programfiler\NCH Software 2008-09-08 17:24 . 2008-09-08 17:24 d-------- C:\Documents and Settings\All Users\Programdata\NCH Software 2008-09-06 16:36 . 2008-09-22 18:30 d-------- C:\Documents and Settings\Christer\Programdata\BitTorrent 2008-09-06 16:35 . 2008-09-18 14:25 d-------- C:\Programfiler\DNA 2008-09-06 16:35 . 2008-09-06 16:35 d-------- C:\Programfiler\BitTorrent 2008-09-06 16:35 . 2008-10-06 15:44 d-------- C:\Documents and Settings\Christer\Programdata\DNA 2008-09-06 16:15 . 2008-09-15 20:14 d-------- C:\Programfiler\Ahead 2008-09-06 15:37 . 2008-09-06 16:40 d-------- C:\Programfiler\FrostWire 2008-09-06 15:37 . 2008-09-06 16:41 d-------- C:\Documents and Settings\Christer\Programdata\FrostWire . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-06 13:09 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-10-06 13:00 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-10-06 12:35 --------- d-----w C:\Programfiler\LogMeIn 2008-10-05 08:19 --------- d-----w C:\Programfiler\Dl_cats 2008-09-22 16:42 --------- d-----w C:\Documents and Settings\All Users\Programdata\DVD Shrink 2008-09-10 20:11 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2008-09-09 14:03 --------- d-----w C:\Documents and Settings\Christer\Programdata\dvdcss 2008-09-06 14:17 --------- d-----w C:\Programfiler\Fellesfiler\Nero 2008-09-02 12:56 --------- d-----w C:\Programfiler\Microsoft Silverlight 2008-09-02 12:44 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-09-01 18:44 --------- d-----w C:\Programfiler\Cyanide 2008-09-01 18:41 --------- d-----w C:\Programfiler\Screamer Radio 2008-09-01 18:40 --------- d-----w C:\Programfiler\Yahoo! 2008-09-01 18:32 --------- d-----w C:\Programfiler\OpenOffice.org 2.3 2008-09-01 18:30 --------- d-----w C:\Documents and Settings\Christer\Programdata\OpenOffice.org2 2008-09-01 18:21 --------- d-----w C:\Programfiler\JLC's Software 2008-09-01 18:19 --------- d-----w C:\Programfiler\Gekko Mahjongg (Xmas edition) 2008-09-01 18:19 --------- d-----w C:\Programfiler\EA SPORTS 2008-09-01 18:18 --------- d-----w C:\Programfiler\AviSynth 2.5 2008-09-01 15:30 --------- d-----w C:\Documents and Settings\Tore\Programdata\OpenOffice.org2 2008-08-30 09:32 --------- d-----w C:\Programfiler\LimeWire 2008-08-30 09:32 --------- d-----w C:\Documents and Settings\Christer\Programdata\LimeWire 2008-08-30 09:15 --------- d-----w C:\Programfiler\Java 2008-08-29 17:04 --------- d-----w C:\Documents and Settings\Christer\Programdata\Azureus 2008-08-29 16:48 --------- d-----w C:\Documents and Settings\All Users\Programdata\Azureus 2008-08-27 19:24 --------- d-----w C:\Documents and Settings\Christer\Programdata\Xilisoft Corporation 2008-08-25 18:18 --------- d-----w C:\Programfiler\GeoGebra 2008-08-25 18:16 --------- d--h--w C:\Programfiler\Zero G Registry 2008-08-25 15:06 --------- d-----w C:\Programfiler\Handbrake 2008-08-25 15:05 --------- d-----w C:\Programfiler\NCH Swift Sound 2008-08-25 15:04 --------- d-----w C:\Programfiler\Elaborate Bytes 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe 2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll 2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll 2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll 2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll 2008-07-07 20:29 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll 2007-12-17 08:35 60,968 ----a-w C:\Documents and Settings\Christer\GoToAssistDownloadHelper.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360] "MsnMsgr"="C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "swg"="C:\Programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-02 68856] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872] "BitTorrent DNA"="C:\Programfiler\DNA\btdna.exe" [2008-09-18 289088] "WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "ATIPTA"="C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064] "DVDLauncher"="C:\Programfiler\filer\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "DMXLauncher"="C:\Programfiler\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016] "ISUSPM Startup"="C:\PROGRA~1\FELLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632] "dlccmon.exe"="C:\Programfiler\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984] "ecc"="C:\Programfiler\Telenor\ecc\ecc.exe" [2005-12-14 286720] "LogMeIn GUI"="C:\Programfiler\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048] "CamMonitor"="C:\Programfiler\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112] "Share-to-Web Namespace Daemon"="C:\Programfiler\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941] "ccApp"="C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe" [2007-01-09 115816] "osCheck"="C:\Programfiler\Norton Internet Security\osCheck.exe" [2006-10-16 26248] "NBKeyScan"="C:\Programfiler\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160] "Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "AppleSyncNotifier"="C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040] "QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-05-27 413696] "iTunesHelper"="C:\Programfiler\iTunes\iTunesHelper.exe" [2008-07-30 289064] "Symantec PIF AlertEng"="C:\Programfiler\Fellesfiler\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 C:\WINDOWS\stsystra.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360] C:\Documents and Settings\Tore\Start-meny\Programmer\Oppstart\ OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] C:\Documents and Settings\Christer\Start-meny\Programmer\Oppstart\ OneNote 2007 Screen Clipper og Launcher.lnk - C:\Programfiler\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2007-12-17 10:35 10792 C:\Programfiler\Citrix\GoToAssist\480\g2awinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "MSACM.CEGSM"= mobilev.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programfiler\\BitTorrent\\bittorrent.exe"= "C:\\Programfiler\\EA GAMES\\Battlefield 2\\BF2.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programfiler\\Messenger\\msmsgs.exe"= "C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Programfiler\\Bonjour\\mDNSResponder.exe"= "C:\\Programfiler\\iTunes\\iTunes.exe"= "C:\\Programfiler\\DNA\\btdna.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "C:\\Documents and Settings\\All Users\\Programdata\\NexonUS\\NGM\\NGM.exe"= R2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;C:\Programfiler\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-10-16 198336] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Programfiler\LogMeIn\x86\RaInfo.sys [2008-02-28 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848] S3 GoToAssist;GoToAssist;C:\Programfiler\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ] S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2008-07-22 32000] S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys [ ] S3 w550mdfl;Sony Ericsson W550 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w550mdfl.sys [ ] S3 w550mdm;Sony Ericsson W550 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w550mdm.sys [ ] S3 w550mgmt;Sony Ericsson W550 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w550mgmt.sys [ ] S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w550obex.sys [ ] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder 2008-09-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programfiler\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57] 2008-09-19 C:\WINDOWS\Tasks\Norton Internet Security Online - Kjør fullstendig systemsøk - Christer.job - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2006-10-16 17:17] . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.online.no/ R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore R1 -: HKCU-Internet Settings,ProxyOverride = *.local R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O16 -: {358DFA15-D48C-4296-8D16-7405F918333B} - hxxps://fronter.com/fredrikstadgs/links/fronter_oes2.cab C:\WINDOWS\Downloaded Program Files\fronter_oes2.inf C:\WINDOWS\Downloaded Program Files\Fronter_oes_prj.ocx C:\WINDOWS\Downloaded Program Files\fronter_oes2.exe C:\WINDOWS\Downloaded Program Files\fronter_oes2.dll O16 -: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} - hxxp://www.mpw.no/TvNorge/KooPlayer.ocx C:\WINDOWS\Downloaded Program Files\KooPlayer.ocx . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-06 15:45:54 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-10-06 15:47:12 ComboFix-quarantined-files.txt 2008-10-06 13:47:06 ComboFix2.txt 2008-10-06 13:22:48 ComboFix3.txt 2008-10-05 07:48:55 Pre-Run: 99 295 334 400 byte ledig Post-Run: 99,277,877,248 byte ledig 224 --- E O F --- 2008-09-16 12:39:04