Hej,
Nu opfører den sig pænere. AVG fandt pludselig en SHeur.LBW og "klarede" den. Jeg gjorde som du foreslog - ser det bedre ud nu?
HiJack-log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:29:39, on 04-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\ATKKBService.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\HP\KBD\KBD.EXE
C:\Programmer\Fælles filer\Cloanto\Software Manager\softmngr.exe
C:\Programmer\Print Server\PTP\PSDiagnostic.exe
C:\Programmer\SPAMfighter\SFAgent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe
C:\Programmer\RegSweep\RegSweep.exe
C:\Garmin\gStart.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Skype\Plugin Manager\skypePM.exe
C:\ProcesXp\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=DA_DK&c=Q105&bd=pavilion&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar6.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [CloantoSoftwareManager] "C:\Programmer\Fælles filer\Cloanto\Software Manager\softmngr.exe" /s
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Programmer\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Programmer\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RegSweep] C:\Programmer\RegSweep\RegSweep.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKCU\..\Run: [gStart] C:\Garmin\gStart.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmer\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://intranet.eucnvs.dkO15 - Trusted Zone: *.eucnvs.dk
O15 - Trusted Zone:
http://*.eucnvs.dkO15 - Trusted Zone: *.selvhenter.dk
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://creative.com/su/ocx/15015/CTSUEng.cabO16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -
http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.6.0.cabO16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exeO16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInContactFinderControl.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cabO16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cabO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -
http://launch.gamespyarcade.com/software/launch/alaunch.cabO16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) -
http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cabO16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -
http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cabO16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) -
http://www.systemrequirementslab.com/sysreqlab.cabO16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) -
http://gameadvisor.futuremark.com/global/msc311.cabO16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) -
https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exeO16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IP-Uploader Control) -
http://asp03.photoprintit.de/microsite/10021/defaults/activex/ImageUploader3.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://creative.com/su/ocx/15016/CTPID.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 9617 bytes
COMBOFIX-LOG:
ComboFix 07-08-30.3 - "Anders" 2007-09-04 19:11:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.2568 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Gitte\MENUEN~1\PROGRA~1\Start\system.exe
C:\WINDOWS\system32\printer.exe
D:\Autorun.inf
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))
2007-09-04 19:11 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-03 17:52 <DIR> d-------- C:\ProcesXp
2007-09-03 17:45 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-03 17:37 341 --a------ C:\restore.vbs
2007-09-03 14:45 3,630 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-03 14:45 <DIR> d-------- C:\SmitfraudFix
2007-09-03 14:40 <DIR> d-------- C:\DOCUME~1\Anders\.housecall6.6
2007-09-03 14:36 115 --a------ C:\restore.reg
2007-09-03 14:24 <DIR> d-------- C:\DOCUME~1\Gitte\APPLIC~1\RegSweep
2007-09-03 13:59 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-03 13:32 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menuen Start
2007-09-03 13:32 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Foretrukne
2007-09-03 13:32 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Dokumenter
2007-09-03 13:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Skabeloner
2007-09-03 13:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Printere
2007-09-03 13:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Lokale indstillinger
2007-09-03 13:32 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Andre computere
2007-09-03 13:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-09-03 13:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Skrivebord
2007-09-03 13:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-09-03 13:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-09-03 13:32 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
2007-09-03 11:47 <DIR> d-------- C:\Programmer\RegSweep
2007-09-03 11:47 <DIR> d-------- C:\DOCUME~1\Anders\APPLIC~1\RegSweep
2007-09-03 11:25 <DIR> d-------- C:\Programmer\Lavasoft
2007-09-03 11:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-03 10:48 39,424 --a------ C:\WINDOWS\system32\vtr.dll
2007-09-02 01:06 <DIR> d--h----- C:\WINDOWS\PIF
2007-08-30 21:10 <DIR> d-------- C:\Programmer\typo3
2007-08-29 22:58 64,783 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-08-29 22:56 6,116 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-08-29 22:55 <DIR> d-------- C:\WINDOWS\BricoPacks
2007-08-13 22:43 <DIR> d-------- C:\Programmer\Skype
2007-08-13 22:43 <DIR> d-------- C:\Programmer\F‘lles filer\Skype
2007-08-07 13:58 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-06 12:41 <DIR> d-------- C:\DOCUME~1\Anders\APPLIC~1\Opera
2007-08-06 12:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
2007-08-06 10:42 <DIR> d-------- C:\Programmer\Picture Ripper 4
2007-08-06 10:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-04 19:07 --------- d-------- C:\DOCUME~1\Anders\APPLIC~1\Skype
2007-09-03 17:19 --------- d-------- C:\DOCUME~1\Anders\APPLIC~1\uTorrent
2007-09-03 14:08 --------- d-------- C:\Programmer\Windows Live Safety Center
2007-09-03 10:55 --------- d-------- C:\DOCUME~1\Anders\APPLIC~1\Azureus
2007-08-30 21:52 --------- d-------- C:\Programmer\JPEGCrops
2007-08-29 22:58 219136 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-08-29 22:58 219136 --a------ C:\WINDOWS\system32\dllcache\uxtheme.dll
2007-08-26 14:45 --------- d-------- C:\DOCUME~1\Anders\APPLIC~1\Canon
2007-08-19 19:56 --------- d-------- C:\Programmer\Azureus
2007-08-13 22:43 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-08-06 22:27 66872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-08-06 22:27 22328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-08-06 22:26 103736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 68440 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 08:58 3856384 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 01:31 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-11 14:37 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-07-04 13:57 --------- d-------- C:\Programmer\Google
2007-06-27 16:05 814592 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 16:05 671232 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 16:05 62464 --a------ C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 16:05 6058496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 16:05 52224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 16:05 477696 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 16:05 459264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 16:05 44544 --a------ C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 16:05 393728 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 16:05 27648 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 16:05 267776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 16:05 193024 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 16:05 163840 --a------ C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 16:05 1225728 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 16:04 384512 --a------ C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 16:04 383488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 16:04 230400 --a------ C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 16:04 153088 --a------ C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 16:04 132608 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 16:04 124928 --a------ C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 15:34 317952 --a------ C:\WINDOWS\system32\dllcache\unregmp2.exe
2007-06-27 10:27 63488 --a------ C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27 13824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 10:25 625152 --a------ C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 09:00 161792 --a------ C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 15:22 976384 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 15:22 1034240 --a------ C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 --a------ C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-05 10:34 1184664 --a------ C:\WINDOWS\system32\FreeImage.dll
2006-06-16 12:40 1 --------- C:\DOCUME~1\Anders\SI.bin
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\Skype
--------- C:\Programmer\Fælles filer\LogiShrd
--------- C:\Programmer\Fælles filer
2004-08-27 12:00:00 60,416 --sha-w C:\WINDOWS\BricoPacks\SysFiles\80_msimn.exe
2005-07-13 12:08:41 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 22:43]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 23:54]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-08-16 12:29]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
"CloantoSoftwareManager"="C:\Programmer\Fælles filer\Cloanto\Software Manager\softmngr.exe" []
"PrintServer Diagnostic"="C:\Programmer\Print Server\PTP\PSDiagnostic.exe" [2004-11-24 17:09]
"SPAMfighter Agent"="C:\Programmer\SPAMfighter\SFAgent.exe" [2007-06-05 10:34]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2007-04-27 09:41]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26]
"RegSweep"="C:\Programmer\RegSweep\RegSweep.exe" [2007-08-13 21:45]
"!AVG Anti-Spyware"="C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"ASUS SmartDoctor"="C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe" [2006-05-15 12:31]
"gStart"="C:\Garmin\gStart.exe" [2007-03-04 23:08]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" []
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2007-08-06 12:43]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
R2 DgiVecp;Team MFP Comm Driver;C:\WINDOWS\system32\Drivers\DgiVecp.sys
R3 Cap7134;Philips Cap7134 Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys
R3 PhTVTune;Philips WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys
S2 713xTVCard;SAA7134 TV Card;C:\WINDOWS\system32\DRIVERS\SAA713x.sys
S3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys
S3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
Contents of the 'Scheduled Tasks' folder
2007-06-22 08:57:42 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programmer\Apple Software Update\SoftwareUpdate.exe
2007-09-04 17:25:43 C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job - C:\Programmer\RegSweep\RegSweep.exe
2007-09-04 17:10:25 C:\WINDOWS\Tasks\User_Feed_Synchronization-{0E5812F7-7981-43F9-BDA9-47F53D42E9C7}.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-04 19:24:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\aawservice]
"ImagePath"="\"C:\Programmer\Lavasoft\Ad-Aware 2007\aawservice.exe\""
Completion time: 2007-09-04 19:27:35 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-04 19:27
--- E O F ---
Anders