her er de så
Logfile of HijackThis v1.99.1
Scan saved at 21:51:52, on 17-09-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\Programmer\SPYWAREfighter\spftray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\BullGuard Software\BullGuard\bullguard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
C:\Programmer\SPYWAREfighter\spfprc.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\BonoDK\Skrivebord\Ny mappe\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ekstrabladet.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Programmer\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Zboard] C:\Programmer\Ideazon\ZEngine\Zboard.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Automatisk EPSON Stylus CX3600 Series på mystra] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P47 "Automatisk EPSON Stylus CX3600 Series på mystra" /O14 "\\MYSTRA\EPSON" /M "Stylus CX3600"
O4 - HKLM\..\Run: [spywarefighterguard] C:\Programmer\SPYWAREfighter\spftray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ErrorSmart] C:\Programmer\ErrorSmart\ErrorSmart.exe
O4 - HKCU\..\Run: [BullGuard] "C:\Programmer\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AntiSpyware] C:\Programmer\AntiSpywareApp\AntiSpyware.exe -boot
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) -
http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CABO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cabO16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exeO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FLLESF~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Programmer\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programmer\Fælles filer\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Programmer\SPYWAREfighter\spfprc.exe
ComboFix 07-09-17.2 - "BonoDK" 2007-09-17 21:53:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.2244 [GMT 2:00]
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 )))))))))))))))))))))))))))))))
.
2007-09-17 21:52 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-17 21:28 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-17 20:39 <DIR> d-------- C:\Programmer\CCleaner
2007-09-17 19:12 <DIR> d-------- C:\Programmer\Sierra Entertainment
2007-09-17 18:20 <DIR> d-------- C:\Programmer\ErrorSmart
2007-09-16 16:14 <DIR> d-------- C:\Programmer\AntiSpywareApp
2007-09-16 16:14 <DIR> d-------- C:\DOCUME~1\BonoDK\APPLIC~1\AntiSpyware
2007-09-16 15:59 <DIR> d-------- C:\DOCUME~1\BonoDK\APPLIC~1\ErrorSmart
2007-09-16 15:24 <DIR> d-------- C:\WINDOWS\nview
2007-09-14 21:08 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-09-14 21:08 <DIR> d-------- C:\DOCUME~1\BonoDK\APPLIC~1\SUPERAntiSpyware.com
2007-09-14 21:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-14 15:33 <DIR> d-------- C:\WINDOWS\system32\C2MP
2007-09-13 17:13 94,480 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-13 17:13 <DIR> d-------- C:\DOCUME~1\BonoDK\APPLIC~1\HouseCall 6.6
2007-09-10 21:31 22,328 --a------ C:\DOCUME~1\BonoDK\APPLIC~1\PnkBstrK.sys
2007-09-10 21:27 <DIR> d-------- C:\Programmer\id Software
2007-09-04 14:20 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
2007-09-04 13:17 <DIR> d-------- C:\Programmer\SexMessenger
2007-08-26 18:31 <DIR> d-------- C:\Programmer\SystemRequirementsLab
2007-08-25 15:20 <DIR> d-------- C:\DOCUME~1\BonoDK\.housecall6.6
2007-08-24 23:57 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2007-08-24 23:57 <DIR> d-------- C:\Programmer\AGEIA Technologies
2007-08-22 12:51 <DIR> d-------- C:\Programmer\SPYWAREfighter
2007-08-22 12:51 <DIR> d-------- C:\Programmer\F‘lles filer\Application
2007-08-22 03:57 <DIR> d-------- C:\DOCUME~1\BonoDK\APPLIC~1\Bioshock
2007-08-17 18:22 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-17 21:45 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BullGuard
2007-09-17 19:12 --------- d--h----- C:\Programmer\InstallShield Installation Information
2007-09-17 19:03 22328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-09-17 19:02 103736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-09-17 17:02 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\Azureus
2007-09-16 01:15 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\BullGuard
2007-09-11 20:08 12528 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-11 20:02 --------- d-------- C:\Programmer\Ubisoft
2007-09-11 13:12 66872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-09-09 15:59 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\Skype
2007-09-09 15:28 51024 --a------ C:\WINDOWS\system32\drivers\BdFileSpy.sys
2007-09-09 15:28 14152 --a------ C:\WINDOWS\system32\client_cc.dll
2007-09-05 16:10 --------- d-------- C:\Programmer\Joost
2007-09-04 22:24 --------- d-------- C:\Programmer\Azureus
2007-09-04 14:20 --------- d-------- C:\Programmer\Logitech
2007-09-02 19:04 --------- d-------- C:\Programmer\Electronic Arts
2007-08-26 18:31 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\SystemRequirementsLab
2007-08-20 14:44 --------- d-------- C:\Programmer\Skype
2007-08-17 16:23 8478720 --a------ C:\WINDOWS\system32\nvcpl.dll
2007-08-17 16:23 81920 --a------ C:\WINDOWS\system32\nvwddi.dll
2007-08-17 16:23 81920 --a------ C:\WINDOWS\system32\nvmctray.dll
2007-08-17 16:23 753664 --a------ C:\WINDOWS\system32\nvcplui.exe
2007-08-17 16:23 6842208 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-08-17 16:23 6746112 --a------ C:\WINDOWS\system32\nvoglnt.dll
2007-08-17 16:23 6344704 --a------ C:\WINDOWS\system32\nvdisps.dll
2007-08-17 16:23 5860736 --a------ C:\WINDOWS\system32\nv4_disp.dll
2007-08-17 16:23 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-08-17 16:23 45056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2007-08-17 16:23 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-08-17 16:23 425984 --a------ C:\WINDOWS\system32\keystone.exe
2007-08-17 16:23 36864 --a------ C:\WINDOWS\system32\nvcodins.dll
2007-08-17 16:23 36864 --a------ C:\WINDOWS\system32\nvcod.dll
2007-08-17 16:23 360448 --a------ C:\WINDOWS\system32\nvapi.dll
2007-08-17 16:23 3551232 --a------ C:\WINDOWS\system32\nvvitvs.dll
2007-08-17 16:23 3334144 --a------ C:\WINDOWS\system32\nvgames.dll
2007-08-17 16:23 307200 --a------ C:\WINDOWS\system32\nvexpbar.dll
2007-08-17 16:23 286720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2007-08-17 16:23 2371584 --a------ C:\WINDOWS\system32\nvwss.dll
2007-08-17 16:23 229376 --a------ C:\WINDOWS\system32\nvmccs.dll
2007-08-17 16:23 188416 --a------ C:\WINDOWS\system32\nvmccss.dll
2007-08-17 16:23 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-08-17 16:23 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-08-17 16:23 155716 --a------ C:\WINDOWS\system32\nvsvc32.exe
2007-08-17 16:23 1478656 --a------ C:\WINDOWS\system32\nview.dll
2007-08-17 16:23 147456 --a------ C:\WINDOWS\system32\nvcolor.exe
2007-08-17 16:23 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-08-17 16:23 1150976 --a------ C:\WINDOWS\system32\nvmobls.dll
2007-08-17 16:23 1073152 --a------ C:\WINDOWS\system32\nvcpluir.dll
2007-08-17 16:23 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-08-09 17:41 315392 --a------ C:\WINDOWS\HideWin.exe
2007-08-09 17:41 --------- d-------- C:\Programmer\Realtek
2007-08-07 15:08 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\Vso
2007-08-04 01:04 --------- d-------- C:\Programmer\DivX
2007-08-01 12:56 --------- d-------- C:\Programmer\GPLGS
2007-08-01 12:56 --------- d-------- C:\Programmer\Acro Software
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-29 09:27 --------- d-------- C:\Programmer\EA GAMES
2007-07-27 01:06 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-27 01:06 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-24 19:43 --------- d-------- C:\Programmer\Teamspeak2_RC2
2007-07-24 19:43 --------- d-------- C:\DOCUME~1\BonoDK\APPLIC~1\teamspeak2
2007-07-24 11:51 6062 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2007-07-20 00:39 2142488 --a------ C:\WINDOWS\system32\drivers\LVMVdrv.sys
2007-07-20 00:37 2109592 --a------ C:\WINDOWS\system32\drivers\Lvckap.sys
2007-07-19 23:51 85302 --a------ C:\WINDOWS\system32\drivers\LVFeL002.cfg
2007-07-19 23:51 69592 --a------ C:\WINDOWS\system32\drivers\LVFaL000.cfg
2007-07-19 23:51 227172 --a------ C:\WINDOWS\system32\drivers\LVFeL000.cfg
2007-07-19 23:51 146680 --a------ C:\WINDOWS\system32\drivers\LVFeL001.cfg
2007-07-19 02:44 465432 --a------ C:\WINDOWS\system32\LVUI2RC.dll
2007-07-19 02:44 41752 --a------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2007-07-19 02:43 490008 --a------ C:\WINDOWS\system32\LVUI2.dll
2007-07-19 02:40 416280 --a------ C:\WINDOWS\system32\LVCodec2.dll
2007-07-18 22:26 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-07-18 19:26 4547584 --a------ C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-07-18 17:42 25624 --a------ C:\WINDOWS\system32\drivers\LVPr2Mon.sys
2007-07-17 13:15 14152 --a------ C:\WINDOWS\system32\lccl.dll
2007-07-12 22:33 87552 --a------ C:\WINDOWS\system32\cpwmon2k.dll
2007-07-08 21:29 108144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-07-05 16:08 16380416 --a------ C:\WINDOWS\RTHDCPL.exe
2007-06-29 00:43 5455872 --a------ C:\WINDOWS\system32\nvdispsr.dll
2007-06-29 00:43 458752 --a------ C:\WINDOWS\system32\nvmccssr.dll
2007-06-29 00:43 3600384 --a------ C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43 3072000 --a------ C:\WINDOWS\system32\nvgamesr.dll
2007-06-29 00:43 2854912 --a------ C:\WINDOWS\system32\nvmoblsr.dll
2007-06-29 00:43 2416640 --a------ C:\WINDOWS\system32\nvwssr.dll
2007-06-28 16:44 2165760 --a------ C:\WINDOWS\MicCal.exe
2007-06-28 13:58 87608 --a------ C:\DOCUME~1\BonoDK\APPLIC~1\ezpinst.exe
2007-06-28 13:58 47360 --a------ C:\DOCUME~1\BonoDK\APPLIC~1\pcouffin.sys
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 08:59 70400 --a------ C:\WINDOWS\system32\PhysXLoader.dll
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\Skype
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-08-09 11:06]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Programmer\Google\Gmail Notifier\gnotify.exe" [2005-07-15 23:48]
"Zboard"="C:\Programmer\Ideazon\ZEngine\Zboard.exe" [2006-03-17 16:49]
"LogitechCommunicationsManager"="C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" []
"Automatisk EPSON Stylus CX3600 Series på mystra"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.exe" [2004-03-04 05:00]
"spywarefighterguard"="C:\Programmer\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-08-17 16:23]
"nwiz"="nwiz.exe" [2007-08-17 16:23 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-08-17 16:23]
"ErrorSmart"="C:\Programmer\ErrorSmart\ErrorSmart.exe" [2007-09-10 15:39]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-08-09 11:06]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 14:00]
"AntiSpyware"="C:\Programmer\AntiSpywareApp\AntiSpyware.exe" [2007-08-30 13:08]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^BonoDK^Menuen Start^Programmer^Start^Xfire.lnk]
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiSpyware]
C:\Programmer\AntiSpywareApp\AntiSpyware.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
"C:\Programmer\Electronic Arts\EA Link\Core.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3600 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ErrorSmart]
C:\Programmer\ErrorSmart\ErrorSmart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Programmer\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
"C:\Programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Programmer\Logitech\QuickCam\Quickcam.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Programmer\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
C:\WINDOWS\system32\nvraidservice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
SkyTel.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spywarefighterguard]
C:\Programmer\SPYWAREfighter\spftray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"D:\CS\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
"C:\Programmer\VERITAS Software\Update Manager\sgtray.exe" /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Programmer\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys
R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys
R1 VFILT;BullGuard Firewall Kernel Driver;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\FiltNt.sys
R2 BdFileSpy;BullGuard File Monitor Driver;\??\C:\WINDOWS\system32\drivers\BdFileSpy.sys
R2 BsFileScan;BullGuard File Scan Service;C:\WINDOWS\System32\svchost.exe -k BullGuard
R2 BsFwall;BullGuard Firewall Service;C:\WINDOWS\System32\svchost.exe -k BullGuardFw
R3 Alpham;Ideazon Merc Composite Keyboard Driver;C:\WINDOWS\system32\DRIVERS\Alpham.sys
R3 PROTECT.DLL;BullGuard Firewall Protection Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\Protect.dll
R3 Reconn;BullGuard Email Monitor;\??\C:\Programmer\BullGuard Software\BullGuard\reconn.sys
R3 SpyFighter;SpyFighter Guard Device;\??\C:\Programmer\SPYWAREfighter\spyfighter.sys
R3 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Programmer\SPYWAREfighter\spfprc.exe"
S3 ADBLOCK.DLL;BullGuard Firewall Adware Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\AdBlock.dll
S3 Alpham1;Ideazon ZBoard USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham1.sys
S3 Alpham2;Ideazon ZBoard MM USB Human Interface Device;C:\WINDOWS\system32\DRIVERS\Alpham2.sys
S3 HTMLFILT.DLL;BullGuard Firewall HTML Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll
S3 HTTPFILT.DLL;BullGuard Firewall HTTP Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll
S3 st3tgbus;st3tgbus;C:\WINDOWS\system32\DRIVERS\st3tgbus.sys
S3 st3tiger;st3tiger;C:\WINDOWS\system32\DRIVERS\st3tiger.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard BgMainSvc BsFileScan BsMailProxy
BullGuardFw BsFwall
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-09-17 19:45:16 C:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job"
- C:\Programmer\AntiSpywareApp\AntiSpyware.exe
"2007-09-17 19:45:43 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Programmer\ErrorSmart\ErrorSmart.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-17 21:54:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-17 21:54:55
.
--- E O F ---
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 09/14/2007 at 09:29 PM
Application Version : 3.7.1018
Core Rules Database Version : 3306
Trace Rules Database Version: 1312
Scan type : Complete Scan
Total Scan Time : 00:18:38
Memory items scanned : 505
Memory threats detected : 0
Registry items scanned : 6460
Registry threats detected : 0
File items scanned : 30894
File threats detected : 1
Adware.Tracking Cookie
C:\Documents and Settings\BonoDK\Cookies\bonodk@atdmt[1].txt