ComboFix 07-07-30.2 - "Jesper" 2007-08-01 0:13:08.1 [GMT 2:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.Sand
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 )))))))))))))))))))))))))))))))
2007-07-31 15:31 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-07-31 15:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-31 15:26 <DIR> d-------- C:\Programmer\Apple Software Update
2007-07-31 15:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-31 15:21 <DIR> d-------- C:\Programmer\QuickTime
2007-07-28 23:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-28 23:10 <DIR> d-------- C:\Programmer\NoAdware5.0
2007-07-28 22:20 <DIR> d-------- C:\Programmer\xp-AntiSpy
2007-07-27 23:53 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-07-27 23:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-27 23:09 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-27 22:50 <DIR> d-------- C:\Programmer\BillP Studios
2007-07-27 22:50 <DIR> d-------- C:\DOCUME~1\Jesper\APPLIC~1\WinPatrol
2007-07-26 17:51 <DIR> d-------- C:\Programmer\BPK
2007-07-26 00:10 372,736 --a------ C:\WINDOWS\system32\IJL11.DLL
2007-07-26 00:10 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-26 00:08 <DIR> d-------- C:\div
2007-07-16 14:53 <DIR> d-------- C:\Programmer\IrfanView
2007-07-06 14:26 128 --a------ C:\WINDOWS\STAMP1.DAT
2007-07-06 14:24 403,216 --a------ C:\WINDOWS\system32\MSREPL35.DLL
2007-07-06 14:24 37,136 --a------ C:\WINDOWS\system32\MSJINT35.DLL
2007-07-06 14:24 368,912 --a------ C:\WINDOWS\system32\VBAR332.DLL
2007-07-06 14:24 251,664 --a------ C:\WINDOWS\system32\MSRD2X35.DLL
2007-07-06 14:24 24,336 --a------ C:\WINDOWS\system32\MSJTER35.DLL
2007-07-06 14:24 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2007-07-06 14:24 1,039,360 --a------ C:\WINDOWS\system32\MSJET35.DLL
2007-07-06 14:24 <DIR> d-------- C:\Programmer\Det levende Danmarkskort
2007-07-06 14:17 299,520 --a------ C:\WINDOWS\uninst.exe
2007-07-06 14:17 <DIR> d-------- C:\ANDRT98A
2007-07-06 14:16 246,784 --a------ C:\WINDOWS\UNINST16.EXE
2007-07-06 14:16 246,784 --a------ C:\WINDOWS\UN160406.EXE
2007-07-06 14:16 20,976 --a------ C:\WINDOWS\system\CTL3D.DLL
2007-07-06 14:16 <DIR> d-------- C:\DOCUME~1\Jesper\WINDOWS
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-28 23:49 --------- d-------- C:\Programmer\Lavasoft
2007-07-27 02:07 --------- d-------- C:\Programmer\FastStone Image Viewer
2007-07-06 14:28 --------- d-------- C:\DOCUME~1\Jesper\APPLIC~1\Help
2007-07-06 01:23 --------- d-------- C:\DOCUME~1\Jesper\APPLIC~1\AdobeUM
2007-06-17 00:11 51200 --a------ C:\WINDOWS\nircmd.exe
2007-05-16 17:14 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\System
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hcenter"="C:\Programmer\Support.com\bin\tgcmd.exe" [2005-04-08 12:38]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Cmaudio"="cmicnfg.cpl" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-05 15:31]
"610v4"="C:\Programmer\610v4qxE-tavirp\csrss.exe" [2006-02-27 00:10]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-07-31 15:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53]
"610v4"="C:\Programmer\610v4qxE-tavirp\csrss.exe" [2006-02-27 00:10]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
hp psc 1000 series.lnk - C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18]
hpoddt01.exe.lnk - C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
R3 ms_mpu401;Microsoft MPU-401 MIDI UART-driver;C:\WINDOWS\system32\drivers\msmpu401.sys
S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys
S3 SABProcEnum;SABProcEnum;\??\C:\Programmer\Internet Explorer\SABProcEnum.sys
S3 sermouse;Seriel musedriver;C:\WINDOWS\system32\DRIVERS\sermouse.sys
S3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys
S3 SiS7018;Service for SiS7018 Driver (WDM);C:\WINDOWS\system32\drivers\sis7018.sys
S3 TVICHW32;TVICHW32;\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc
Contents of the 'Scheduled Tasks' folder
2007-04-29 21:57:45 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1157657095.job - C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
2007-07-30 23:25:00 C:\WINDOWS\Tasks\WebReg 20061007012506.job - C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-08-01 00:16:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aawservice]
"ImagePath"="\"C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe\""
Completion time: 2007-08-01 0:19:15
--- E O F ---