ComboFix 07-10-06.3 - ole 2007-10-06 10:50:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.45.1030.18.533 [GMT 2:00]
Running from: C:\Documents and Settings\ole\Lokale indstillinger\Temporary Internet Files\Content.IE5\HHGY62IT\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\ole\Skrivebord\internet.lnk
.
((((((((((((((((((((((((( Files Created from 2007-09-06 to 2007-10-06 )))))))))))))))))))))))))))))))
.
2007-10-06 10:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-06 10:23 <DIR> d-------- C:\Programmer\Trend Micro
2007-10-06 10:16 <DIR> d-------- C:\WINDOWS\pss
2007-10-02 10:47 7,296 -ra------ C:\WINDOWS\system32\drivers\grmnusb.sys
2007-10-02 10:47 17,536 --a------ C:\WINDOWS\system32\drivers\grmn0200.sys
2007-10-02 10:47 17,024 -ra------ C:\WINDOWS\system32\drivers\grmngen.sys
2007-10-02 10:47 16,512 --a------ C:\WINDOWS\system32\drivers\grmn0400.sys
2007-10-02 10:47 11,776 --a------ C:\WINDOWS\system32\drivers\grmn1200.sys
2007-10-02 10:46 <DIR> d-------- C:\Garmin
2007-09-29 11:09 <DIR> d-------- C:\WINDOWS\ShellNew
2007-09-24 11:13 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-19 12:19 51,200 -r-hs---- C:\WINDOWS\system32\servicer.exe
2007-09-18 22:20 <DIR> d-------- C:\Programmer\Flight1 Downloader
2007-09-18 20:23 8,576 --a--c--- C:\WINDOWS\system32\dllcache\hidgame.sys
2007-09-18 20:23 8,576 --a------ C:\WINDOWS\system32\drivers\hidgame.sys
2007-09-07 09:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2007-09-07 09:43 <DIR> d-------- C:\Programmer\GT Interactive
2007-09-07 09:26 <DIR> d-------- C:\Documents and Settings\ole\Application Data\BitTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-06 10:11 --------- d-------- C:\Documents and Settings\ole\Application Data\Skype
2007-10-06 10:11 --------- d-------- C:\Documents and Settings\All Users\Application Data\BullGuard
2007-09-19 16:30 --------- d-------- C:\Programmer\GE2006
2007-09-18 15:59 --------- d-------- C:\Documents and Settings\ole\Application Data\BullGuard
2007-09-10 16:26 --------- d-------- C:\Programmer\Winamp
2007-09-07 18:27 51024 --a------ C:\WINDOWS\system32\drivers\BdFileSpy.sys
2007-09-07 18:27 14152 --a------ C:\WINDOWS\system32\client_cc.dll
2007-08-20 13:39 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-08-20 08:39 14152 --a------ C:\WINDOWS\system32\lccl.dll
2007-08-15 09:49 737280 --a------ C:\WINDOWS\iun6002.exe
2007-08-15 09:49 --------- d-------- C:\Programmer\OATmedia
2007-08-15 09:46 --------- d-------- C:\Programmer\Oat-Met
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
--------- C:\Programmer\Fælles filer\System
--------- C:\Programmer\Fælles filer\Microsoft Shared
--------- C:\Programmer\Fælles filer\Designer
--------- C:\Programmer\Fælles filer
2007-03-20 17:25:00 61 --sh--w C:\WINDOWS\cnerolf.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-08-20 08:39]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-18 16:56]
"nwiz"="nwiz.exe" [2006-05-18 16:56 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-05-18 16:56]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 16:21 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Programmer\Analog Devices\Core\smax4pnp.exe" [2005-05-20 03:11]
"SoundMAX"="C:\Programmer\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 16:35]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [2006-08-16 05:10]
"Microsoft Servicer"="servicer.exe" [2007-09-19 09:44 C:\WINDOWS\system32\servicer.exe]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-26 17:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53]
"BullGuard"="C:\Programmer\BullGuard Software\BullGuard\bullguard.exe" [2007-08-20 08:39]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
C:\Documents and Settings\ole\Menuen Start\Programmer\Start\
Monitor.lnk - C:\Programmer\802.11g Wireless LAN\Monitor.exe [2005-08-02 18:03:50]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Programmer\Winamp\winampa.exe
R1 VFILT;BullGuard Firewall Kernel Driver;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\FiltNt.sys
R2 BdFileSpy;BullGuard File Monitor Driver;\??\C:\WINDOWS\system32\drivers\BdFileSpy.sys
R2 BsFileScan;BullGuard File Scan Service;C:\WINDOWS\System32\svchost.exe -k BullGuard
R2 BsFwall;BullGuard Firewall Service;C:\WINDOWS\System32\svchost.exe -k BullGuardFw
R2 DgiVecp;DgiVecp;\??\C:\WINDOWS\system32\Drivers\DgiVecp.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 PROTECT.DLL;BullGuard Firewall Protection Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\Protect.dll
R3 Reconn;BullGuard Email Monitor;\??\C:\Programmer\BullGuard Software\BullGuard\reconn.sys
S3 ADBLOCK.DLL;BullGuard Firewall Adware Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\AdBlock.dll
S3 chanalog;CH Analog Devices;C:\WINDOWS\system32\DRIVERS\chanalog.sys
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys
S3 HTMLFILT.DLL;BullGuard Firewall HTML Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll
S3 HTTPFILT.DLL;BullGuard Firewall HTTP Plugin;\??\C:\Programmer\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard BgMainSvc BsFileScan BsMailProxy
BullGuardFw BsFwall
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-06 10:53:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-06 10:53:59
C:\ComboFix-quarantined-files.txt ... 2007-10-06 10:53
.
--- E O F ---