ComboFix 08-10-08.02 - HP_Ejer 2008-10-15 18:25:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.1594 [GMT 2:00]
Running from: C:\Documents and Settings\HP_Ejer\Skrivebord\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
.
2008-10-15 10:39 . 2008-10-15 10:44 24 --a------ C:\Documents and Settings\HP_Ejer\jagex_runescape_preferences.dat
2008-10-13 10:57 . 2008-10-13 10:57 3,867 --a------ C:\AsAddon
2008-10-12 15:18 . 2008-10-12 15:29 <DIR> d-------- C:\Programmer\BearShare Applications
2008-10-12 15:09 . 2008-10-12 17:22 <DIR> d-------- C:\Documents and Settings\All Users\Incomplete
2008-10-12 15:08 . 2008-10-12 15:08 <DIR> d-------- C:\Programmer\P2P_Energy
2008-10-12 15:08 . 2008-10-12 15:08 <DIR> d-------- C:\Programmer\Conduit
2008-10-12 15:08 . 2008-10-12 15:08 <DIR> d-------- C:\Documents and Settings\HP_Ejer\Incomplete
2008-10-12 15:08 . 2008-10-12 15:18 <DIR> d-------- C:\Documents and Settings\HP_Ejer\Application Data\LimeWire Music
2008-10-12 15:07 . 2008-10-12 15:08 <DIR> d-------- C:\Programmer\LimeWire Music
2008-10-09 13:57 . 2008-10-09 13:57 <DIR> d-------- C:\Programmer\RAPTOR-GAMING
2008-10-09 13:57 . 2006-10-04 14:31 18,620,416 --a------ C:\WINDOWS\system32\XControlPad.dll
2008-10-09 13:57 . 2006-09-21 10:38 2,576,384 --a------ C:\WINDOWS\system32\XWheel.dll
2008-10-09 13:57 . 2006-09-21 10:38 593,920 --a------ C:\WINDOWS\system32\XIndicator.dll
2008-10-09 13:57 . 2006-10-04 11:27 413,696 --a------ C:\WINDOWS\system32\XDPI.dll
2008-10-09 13:57 . 2006-10-04 14:20 26,240 --a------ C:\WINDOWS\system32\drivers\GMFilter.sys
2008-10-09 13:57 . 2004-11-25 15:44 1,701 --a------ C:\WINDOWS\system32\drivers\GMFilter.inf
2008-10-08 16:57 . 2008-10-08 16:58 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-10-08 16:57 . 2008-10-08 16:57 <DIR> d-------- C:\Documents and Settings\HP_Ejer\Application Data\Malwarebytes
2008-10-08 16:57 . 2008-10-08 16:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-08 16:57 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-08 16:57 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-08 12:43 . 2008-10-08 12:43 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-10-08 08:51 . 2008-10-08 08:51 <DIR> d-------- C:\Programmer\Lavasoft
2008-10-08 08:51 . 2008-10-08 08:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-07 22:34 . 2008-10-08 09:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-17 11:43 . 2008-09-17 11:43 <DIR> d-------- C:\WINDOWS\system32\da
2008-09-17 11:43 . 2008-09-17 11:43 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-17 11:43 . 2008-09-17 11:43 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-17 11:40 . 2008-09-17 11:40 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-17 11:33 . 2008-09-17 11:33 <DIR> d-------- C:\WINDOWS\EHome
2008-09-16 17:34 . 2008-09-16 17:34 <DIR> d-------- C:\Programmer\DivX
2008-09-16 08:15 . 2004-08-03 22:29 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2008-09-16 08:15 . 2004-08-03 22:29 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 19:39 --------- d-----w C:\Documents and Settings\HP_Ejer\Application Data\LimeWire
2008-10-12 16:54 --------- d-----w C:\Programmer\LimeWire
2008-10-12 16:54 --------- d-----w C:\Programmer\Incomplete
2008-10-09 11:57 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-10-08 06:51 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-09-12 20:16 --------- d-----w C:\Documents and Settings\HP_Ejer\Application Data\BitTorrent
2008-09-02 12:27 --------- d-----w C:\Programmer\VstPlugins
2008-09-02 08:07 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-02 08:01 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-02 08:01 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-09-02 08:01 --------- d-----w C:\Programmer\AVG
2008-09-02 08:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-02 07:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-09-02 07:36 --------- d-----w C:\Programmer\Spybot - Search & Destroy
2008-09-02 07:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-01 11:47 --------- d-----w C:\Programmer\Sun
2008-09-01 11:47 --------- d-----w C:\Programmer\Java
2008-08-30 11:06 --------- d-----w C:\Programmer\Battlezone II
2008-08-26 19:06 --------- d-----w C:\Programmer\ASTRA32
2008-08-26 16:54 --------- d-----w C:\Programmer\Ligos
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 586,752 ----a-w C:\WINDOWS\WLXPGSS.SCR
2007-01-09 21:01 204,800 ----a-w C:\Programmer\GCFScape.exe
2007-01-07 13:50 0 ----a-w C:\Documents and Settings\HP_Ejer\Application Data\wklnhst.dat
2006-05-24 14:35 15,062 ----a-w C:\Programmer\provider.txt
2004-06-07 08:26 315,392 ----a-w C:\Programmer\Code Calculator 5.4.exe
2004-05-22 08:42 69,632 ----a-w C:\Programmer\calc.dll
2004-04-28 09:31 326 ----a-w C:\Programmer\GID1.txt
2002-09-11 14:26 63,730 ----a-w C:\Programmer\viewsonicinstruct_xp.pdf
1999-07-13 12:46 209,408 ----a-w C:\Programmer\tabctl32.ocx
2006-02-06 10:22 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( snapshot@2008-10-09_ 8.35.38.64 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-15 08:39:35 315,392 ----a-w C:\WINDOWS\.jagex_cache_32\runescape\jogl.dll
+ 2008-10-15 08:39:35 20,480 ----a-w C:\WINDOWS\.jagex_cache_32\runescape\jogl_awt.dll
+ 2008-10-15 08:51:36 53,248 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-09-15 06:47 1784856 --a------ C:\Programmer\P2P_Energy\tbP2P_.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
2008-07-07 11:27 398776 --a------ C:\Programmer\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "C:\Programmer\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "C:\Programmer\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Programmer\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\programmer\valve\steam\steam.exe" [2008-10-05 1410296]
"CTSyncU.exe"="C:\Programmer\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"msnmsgr"="C:\Programmer\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SWHelper"="C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" [2008-10-15 53248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD08"="c:\Programmer\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2005-05-05 278528]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 61440]
"CTCheck"="C:\Programmer\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 81920]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2005-01-03 98304]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-30 1234712]
"RAPTOR-GAMING M3"="C:\Programmer\RAPTOR-GAMING\RAPTOR-ADJUST M3 V1\Panel.exe" [2006-10-05 73728]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
VPN Client.lnk - C:\WINDOWS\Installer\{24C67B54-0718-445E-B663-3138D9246BD1}\Icon3E5562ED7.ico [2006-05-15 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Adobe Reader Hurtigstart.lnk
backup=C:\WINDOWS\pss\Adobe Reader Hurtigstart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Ejer^Menuen Start^Programmer^Start^Xfire.lnk]
path=C:\Documents and Settings\HP_Ejer\Menuen Start\Programmer\Start\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Programmer\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JustVoip]
--a------ 2008-01-02 16:38 8770864 C:\Programmer\JustVoip.com\JustVoip\JustVoip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 18:05 1695232 C:\Programmer\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Programmer\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 02:41 8523776 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-01-03 06:34 98304 C:\Programmer\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-01-03 06:07 36972 C:\Programmer\Java\jre1.5.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 22:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\source sdk base 2007\\hl2.exe"=
"C:\\Programmer\\BitTorrent\\bittorrent.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\garrysmod\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\source sdk base\\hl2.exe"=
"C:\\Programmer\\Valve\\Steam\\steam.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\half-life\\hl.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\synergy\\hl2.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\counter-strike source\\hl2.exe"=
"C:\\Programmer\\Valve\\Steam\\SteamApps\\sejadam\\deathmatch classic\\hl.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-02 97928]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Programmer\ASTRA32\ASTRA32.sys [2007-02-22 30864]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-02 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-02 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-02 76040]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2006-10-04 26240]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8R0 -: HKCU-Main,Start Page =
hxxp://www.google.dk/webhp?sourceid=navclient&ie=UTF-8O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O16 -: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabC:\WINDOWS\Downloaded Program Files\e-Safekey.inf
C:\WINDOWS\Downloaded Program Files\e-Safekey.dll
O16 -: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} -
hxxp://asp10.photoprintit.de/microsite/4066/defaults/activex/IPSUploader.cabC:\WINDOWS\Downloaded Program Files\IPSUploader.inf
C:\WINDOWS\Downloaded Program Files\ImageUploader_3.ocx
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\IPSUploader.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-15 18:31:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Programmer\TortoiseSVN\iconv\_tbl_simple.so
-> C:\Programmer\TortoiseSVN\iconv\windows-1252.so
-> C:\Programmer\TortoiseSVN\iconv\utf-8.so
.
Completion time: 2008-10-15 18:35:31
ComboFix-quarantined-files.txt 2008-10-15 16:35:27
ComboFix2.txt 2008-10-12 10:49:54
ComboFix3.txt 2008-10-09 06:36:06
Pre-Run: 62.108.868.608 byte ledig
Post-Run: 62,095,826,944 byte ledig
281 --- E O F --- 2008-09-17 18:50:43