Så prøver vi denne her !!....
ComboFix 07-06-13.3 - C:\Documents and Settings\John Vamos\Skrivebord\ComboFix.exe
"John Vamos" - 2007-06-13 8:22:14 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\core
-------\nm
((((((((((((((((((((((((( Files Created from 2007-05-13 to 2007-06-13 )))))))))))))))))))))))))))))))
2007-06-13 08:21 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-09 16:16 2,485,766 --a------ C:\SmitfraudFix.exe
2007-06-09 16:16 <DIR> d-------- C:\SmitfraudFix
2007-06-09 16:12 3,778 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-09 16:10 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-09 16:10 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-06-09 16:10 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-06-09 13:57 <DIR> d-------- C:\Programmer\Windows Live
2007-06-08 12:19 <DIR> d-------- C:\WINDOWS\pss
2007-06-08 07:55 34,576 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-06-08 07:55 33,296 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-06-08 07:55 1,419,024 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-06-08 07:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
2007-06-07 08:00 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2007-06-07 07:58 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\Bitdefender
2007-06-07 07:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
2007-06-06 17:28 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-06-06 16:58 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\PhraseExpress
2007-06-06 16:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PhraseExpress
2007-06-06 05:26 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-06-05 07:19 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
2007-06-05 07:19 225,280 --a------ C:\WINDOWS\system32\ReWire.dll
2007-06-05 07:19 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\Propellerhead Software
2007-06-05 07:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Propellerhead Software
2007-06-05 07:11 <DIR> d-------- C:\Programmer\Propellerhead
2007-06-05 06:18 <DIR> d-------- C:\Programmer\MagicISO
2007-06-05 06:09 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\WinRAR
2007-06-05 05:55 86,056 --a------ C:\WINDOWS\system32\build_dol.exe
2007-06-05 03:55 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\uTorrent
2007-06-03 19:26 <DIR> d-------- C:\Program Files
2007-06-02 19:57 <DIR> d-------- C:\Garmin
2007-06-02 19:00 <DIR> d-------- C:\Programmer\DVD Shrink
2007-06-02 19:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-06-01 09:45 <DIR> d-------- C:\Programmer\LimeWire
2007-06-01 09:45 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\Incomplete
2007-06-01 09:35 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\.limewire
2007-05-27 09:37 <DIR> d-------- C:\DOCUME~1\JOHNVA~1\APPLIC~1\Elaborate Bytes
2007-05-27 09:33 <DIR> d-------- C:\Programmer\Elaborate Bytes
2007-05-24 15:19 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-05-24 15:19 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-05-18 03:54 <DIR> d-------- C:\Programmer\VirtualDJ
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-13 06:26:48 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\nView_Wallpaper
2007-06-10 06:41:06 -------- d-----w C:\Programmer\MUSICMATCH Jukebox
2007-06-09 14:26:54 48,284 ----a-w C:\WINDOWS\system32\perfc006.dat
2007-06-09 14:26:54 327,994 ----a-w C:\WINDOWS\system32\perfh006.dat
2007-06-09 11:57:21 -------- d-----w C:\Programmer\MSN Messenger
2007-06-09 11:57:21 -------- d-----w C:\Programmer\Messenger Plus! Live
2007-06-08 05:57:24 -------- d-----w C:\Programmer\Fælles filer\Microsoft Shared
2007-06-08 05:55:44 -------- d-----w C:\Programmer\Fælles filer\Logitech
2007-06-08 05:55:20 -------- d-----w C:\Programmer\Logitech
2007-06-07 05:55:06 -------- d-----w C:\Programmer\Fælles filer\Softwin
2007-06-07 05:54:04 -------- d-----w C:\Programmer\Fælles filer
2007-06-06 10:07:57 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\SolSuite
2007-06-06 03:47:37 -------- d-----w C:\Programmer\Ad-Aware SE Personal
2007-06-04 10:22:55 -------- d-----w C:\Programmer\DivX
2007-05-19 03:59:51 -------- d-----w C:\Programmer\Winamp
2007-05-18 06:55:50 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\Roxio
2007-05-10 10:47:05 -------- d--h--w C:\Programmer\InstallShield Installation Information
2007-05-10 10:46:11 -------- d-----w C:\Programmer\Veoh Networks
2007-05-06 22:42:47 -------- d-----w C:\Programmer\Fælles filer\NSV
2007-04-26 06:27:57 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\CyberLink
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:05:20 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
2007-04-22 09:16:53 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\Help
2007-04-22 07:15:34 -------- d-----w C:\Programmer\Diskeeper
2007-04-20 19:16:08 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\Creative
2007-04-17 07:03:42 -------- d-----w C:\Programmer\win commander
2007-04-15 22:38:48 -------- d-----w C:\DOCUME~1\JOHNVA~1\APPLIC~1\Ventrilo
2007-04-15 22:34:36 -------- d-----w C:\Programmer\Ventrilo
2007-04-15 22:34:15 -------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2007-04-11 18:21:20 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2007-04-07 03:11:37 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-04-06 13:51:11 0 --sha-r C:\MSDOS.SYS
2007-04-06 13:51:11 0 --sha-r C:\IO.SYS
2007-04-06 13:51:11 0 ----a-w C:\CONFIG.SYS
2007-04-06 13:51:11 0 ----a-w C:\AUTOEXEC.BAT
2007-04-06 13:48:02 21,644 ----a-w C:\WINDOWS\system32\emptyregdb.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Programmer\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 16:39]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-08-30 07:48 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2005-06-15 17:20 C:\WINDOWS\system32\nwiz.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-21 11:33]
"DiskeeperSystray"="C:\Programmer\Diskeeper\DkIcon.exe" [2005-07-26 17:52]
"ZoneAlarm Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"RemoteControl"="C:\Programmer\Power DVD\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"RoxWatchTray"="C:\Programmer\Fælles filer\Roxio Shared\SharedCOM8\RoxWatchTray.exe" []
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"zBrowser Launcher"="C:\Programmer\Logitech\Keyboard\iTouch\iTouch.exe" [2004-03-18 09:33]
"ISUSPM Startup"="C:\PROGRA~1\FLLESF~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 07:50]
"BDMCon"="C:\Programmer\Softwin\BitDefender10\bdmcon.exe" [2006-08-04 16:22]
"BDAgent"="C:\Programmer\Softwin\BitDefender10\bdagent.exe" [2006-06-20 14:35]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 C:\WINDOWS\KHALMNPR.Exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 17:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"CTSyncU.exe"="C:\Programmer\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 14:32]
"Veoh"="C:\Programmer\Veoh Networks\Veoh\VeohClient.exe" [2007-05-03 17:43]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-13 08:25:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-13 8:28:00 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-13 08:27
--- E O F ---