ComboFix 08-12-01.01 - Common 2008-12-02 10:54:53.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.311 [GMT 1:00]
Running from: c:\documents and settings\COMMON\Desktop\Ny mappe\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\COMMON\Application Data\HbTools
c:\documents and settings\COMMON\Application Data\HbTools\v3.0\HbTools\static\2\btntrans.idx
c:\documents and settings\COMMON\My Documents\My Music\My Music.url
c:\documents and settings\COMMON\My Documents\My Videos\My Video.url
c:\program files\TinyProxy
c:\program files\TinyProxy\tinyproxy.exe
c:\program files\UAV
c:\program files\UAV\UAV.cpl
c:\program files\UAV\uav.ooo
c:\program files\UAV\UAV1.dat
c:\program files\UAV\Uninstall.exe
c:\windows\Downloaded Program Files\setup.inf
c:\windows\fmark2.dat
c:\windows\system32\601325
c:\windows\system32\601325\601325.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 )))))))))))))))))))))))))))))))
.
2008-11-26 19:42 . 2008-11-26 19:42 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-26 19:42 . 2008-11-26 19:42 <DIR> d-------- c:\documents and settings\COMMON\Application Data\Malwarebytes
2008-11-26 19:42 . 2008-11-26 19:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-26 19:42 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-26 19:42 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-26 17:49 . 2008-11-26 19:13 <DIR> d-------- c:\program files\Enigma Software Group
2008-11-26 11:58 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-26 11:54 . 2008-08-14 11:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-26 11:54 . 2008-08-14 11:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-26 11:54 . 2008-08-14 10:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-26 11:54 . 2008-08-14 10:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-26 11:54 . 2008-09-15 13:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-11-26 11:54 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-26 11:51 . 2008-09-04 18:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-26 11:51 . 2008-10-15 17:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-26 11:36 . 2008-11-26 19:06 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-26 10:21 . 2008-11-26 10:21 <DIR> d--hs---- C:\C01A79303A8DDB48
2008-11-25 13:22 . 2008-11-25 13:28 4,337 ---h----- c:\windows\f49f4d98.dat
2008-11-25 13:20 . 2008-11-26 12:59 1 ---h----- c:\windows\f49f4daa.dat
2008-11-06 15:43 . 2008-11-06 18:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Corel
2008-11-06 15:38 . 2008-11-06 15:40 <DIR> d-------- c:\program files\Common Files\Corel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 18:38 --------- d-----w c:\program files\CCleaner
2008-11-20 10:16 --------- d-----w c:\documents and settings\All Users\Application Data\pdf995
2008-11-06 17:25 --------- d-----w c:\documents and settings\COMMON\Application Data\Corel
2008-11-06 14:38 --------- d-----w c:\program files\Corel
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-11 14:14 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-11 14:08 108 ----a-w C:\HiroConfig.dat
2008-10-11 11:16 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-11 10:33 --------- d-----w c:\documents and settings\All Users\Application Data\Hiro-Media
2008-02-19 14:30 25,992 -c--a-w c:\documents and settings\COMMON\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-12-11 3022848]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Mediafour Mac Volume Notifications"="c:\program files\Common Files\Mediafour\MACVNTFY.EXE" [2002-12-17 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-06-21 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-08-15 271672]
"iPrint Tray"="c:\windows\system32\iprntctl.exe" [2006-10-18 40960]
"iPrint Event Monitor"="c:\windows\system32\iprntlgn.exe" [2006-10-18 45056]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2007-10-30 16200]
"nwiz"="nwiz.exe" [2003-12-11 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 c:\windows\system32\nwtray.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Getting Started with MacDrive 5.lnk - c:\program files\Mediafour\MacDrive5\MDGSTART.EXE [2002-10-08 65536]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MacDrive-iTunes compatibility]
2003-11-07 10:24 61440 c:\program files\Common Files\Mediafour\MacDriveiTunesPatch.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SAS Institute\\SAS\\V8\\sas.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Novell\\GroupWise\\grpwise.exe"=
"c:\\Novell\\GroupWise\\notify.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 MDPMGRNT;MDPMGRNT;c:\windows\system32\drivers\MDPMGRNT.sys [2003-11-05 26272]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-08 78416]
S1 nipplpt2;Novell iCapture Lpt Redirector 2;c:\windows\system32\drivers\nipplpt.sys [2007-09-06 34671]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-08 20560]
S2 C01A79303A8DDB48;C01A79303A8DDB48;\??\c:\c01a79303a8ddb48\C01A79303A8DDB48 []
S2 Logical Disk Manager (dmserver) ;Logical Disk Manager (dmserver) ;c:\program files\tinyproxy\tinyproxy.exe []
S3 MDFSYSNT;MDFSYSNT;c:\windows\system32\drivers\MDFSYSNT.sys [2003-10-07 223264]
S3 sasrfcService;sasrfc Service;c:\program files\SAS Institute\SAS\V8\access\sasexe\sasrfc.exe [2004-12-21 41984]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf850640-29b0-11da-9e8c-000feafec372}]
\Shell\AutoRun\command - setupSNK.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{C39E6B6E-7E2A-43FF-8EC4-6731ED3B9D47} - (no file)
ShellIconOverlayIdentifiers-Mediafour Mac Volume Icons - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\COMMON\Application Data\Mozilla\Firefox\Profiles\te6krw7s.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:da-DK:official.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-02 11:04:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\C01A79303A8DDB48]
"ImagePath"="\??\c:\c01a79303a8ddb48\C01A79303A8DDB48"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(232)
c:\program files\Common Files\Mediafour\MacDriveiTunesPatch.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Trend Micro\HijackThis\HijackThis.exe
.
**************************************************************************
.
Completion time: 2008-12-02 11:09:27 - machine was rebooted [COMMON]
ComboFix-quarantined-files.txt 2008-12-02 10:09:24
Pre-Run: 19,225,628,672 bytes free
Post-Run: 19,230,027,776 bytes free
160 --- E O F --- 2008-11-26 11:51:36