Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Pop-ups


  • This topic is locked This topic is locked

#1
digicraft63

digicraft63

    Member

  • Member
  • PipPip
  • 20 posts
I have had problems with pop-ups telling me to scan my computer for virus and download antivirus programs. It also is popping up ads for various gambling sites.

I have done the "You Must Read This Before Posting A Hijackthis Log" proceedure

The problem seams to have gone but I am posting the logs anyway just to make shure. If any of your geek busters have the time to browse them. Thank you!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:01:25, on 2008-04-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\Program\Delade filer\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program\AVG\AVG8\avgwdsvc.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\runservice.exe
C:\Program\AVG\AVG8\avgrsx.exe
C:\Program\Alias\Maya7.0\docs\wrapper.exe
C:\Program\Alias\Maya7.0\docs\jre\bin\java.exe
C:\Program\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\M-Audio USB Quattro\Install\QuatInst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Allume\StuffIt\MXTask.exe
C:\Program\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program\Allume\StuffIt\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\Winamp\winampa.exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\Program\SyncroSoft\Pos\H2O\cledx.exe
C:\Program\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program\QuickTime\QTTask.exe
C:\Program\Genie-Soft\GBMPro8\GBMAgent.exe
C:\Program\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program\Personal\bin\Personal.exe
C:\Program\Windows Desktop Search\WindowsSearch.exe
C:\Program\WinZip\WZQKPICK.EXE
C:\Program\SolidWorks\swScheduler\swBOEngine.exe
C:\Program\Bullet Proof FTP Server\bpftpserver.exe
C:\Program\M-Audio USB Quattro\QuatTask.exe
C:\Program\Java\jre1.6.0_05\bin\javaw.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program\Winamp\winamp.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\system32\inetsrv\DavCData.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.svd.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 195.100.127.152 www.solnachiefs.se
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program\Delade filer\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program\AVG\AVG8\avgtoolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\Windows Live Toolbar\msntb.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program\Free Download Manager\iefdm2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program\Delade filer\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {cbf6f119-ea59-4612-96c3-efd538c88c0a} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [TomcatStartup] C:\Program\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient] C:\Program\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [H2O] C:\Program\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program\Delade filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program\Delade filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GBMPro8Agent] C:\Program\Genie-Soft\GBMPro8\GBMAgent.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BVRPLiveUpdate] C:\Program\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\DOCUME~1\ALLUSE~1\APPLIC~1\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\Program\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program\Delade filer\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: .lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Genväg till bpftpserver.lnk = C:\Program\Bullet Proof FTP Server\bpftpserver.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: M-Audio Quattro Control Panel Launcher.lnk = C:\Program\M-Audio USB Quattro\QuatTask.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Maya 6 helpserver.lnk = C:\Program\Alias\Maya6.0\docs\helpserver.jar (User 'SYSTEM')
O4 - S-1-5-18 Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: .lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe (User 'Default user')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Genväg till bpftpserver.lnk = C:\Program\Bullet Proof FTP Server\bpftpserver.exe (User 'Default user')
O4 - .DEFAULT Startup: M-Audio Quattro Control Panel Launcher.lnk = C:\Program\M-Audio USB Quattro\QuatTask.exe (User 'Default user')
O4 - .DEFAULT Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe (User 'Default user')
O4 - .DEFAULT Startup: Maya 6 helpserver.lnk = C:\Program\Alias\Maya6.0\docs\helpserver.jar (User 'Default user')
O4 - .DEFAULT Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe (User 'Default user')
O4 - Startup: .lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Genväg till bpftpserver.lnk = C:\Program\Bullet Proof FTP Server\bpftpserver.exe
O4 - Startup: M-Audio Quattro Control Panel Launcher.lnk = C:\Program\M-Audio USB Quattro\QuatTask.exe
O4 - Startup: MagicDisc.lnk = C:\Program\MagicDisc\MagicDisc.exe
O4 - Startup: Maya 6 helpserver.lnk = C:\Program\Alias\Maya6.0\docs\helpserver.jar
O4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program\SolidWorks\swScheduler\swBOEngine.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program\Altova\XMLSpy2008\spy.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program\Altova\XMLSpy2008\spy.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - http://www.kaspersky.../kavwebscan.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....rl/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec....rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....ta/SymAData.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com...obat/nos/gp.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - http://www.symantec..../ActiveData.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zon...er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9D7BA76-D4FC-4DA1-87BB-B81E7918E7BC}: NameServer = 81.26.228.3,81.26.227.3
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Active Common Service - Unknown owner - C:\WINDOWS\system32\commserv.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program\Delade filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program\Delade filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program\Norton Internet Security\isPwdSvc.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program\Delade filer\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program\Alias\Maya7.0\docs\wrapper.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program\Delade filer\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Quattro Installer (QuattroInstallerService) - M-Audio - C:\Program\M-Audio USB Quattro\Install\QuatInst.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program\WinPcap\rpcapd.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program\Delade filer\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: StuffIt Task Manager - Allume Systems, Inc. - C:\Program\Allume\StuffIt\MXTask.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 19029 bytes



;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-04-27 09:36:10
PROTECTIONS: 1
MALWARE: 20
SUSPECTS: 1
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
Norton Internet Security 2007 Yes Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00000431 adware/ist.istbar Adware No 1 Yes No hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\istsvc
00013869 adware/cydoor Adware No 0 Yes No c:\windows\cdmxtras
00020302 adware/ncase Adware No 0 Yes No c:\windows\180axau.dat
00020302 adware/ncase Adware No 0 Yes No c:\windows\180ax.log
00029258 application/altnet HackTools No 0 Yes No hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}
00029258 application/altnet HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}
00029258 application/altnet HackTools No 0 Yes No HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
00029424 adware/cws.searchmeup Adware No 1 Yes No c:\documents and settings\hasse\favoriter\gambling
00029767 adware/delfinmedia Adware No 1 Yes No c:\keys.ini
00039204 adware/cws Adware No 0 Yes No c:\documents and settings\hasse\favoriter\adult
00041446 application/myway HackTools No 0 Yes No hkey_classes_root\clsid\{66fc8717-efa7-4546-8c4a-e224f3a80c76}
00041446 application/myway HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC}
00041446 application/myway HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
00041446 application/myway HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}
00095746 adware/startpage.lh Adware No 0 Yes No c:\documents and settings\hasse\favoriter\adult\single girls.url
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Hasse\Cookies\hasse@doubleclick[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Hasse\Cookies\hasse@mediaplex[1].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Hasse\Cookies\hasse@adtech[1].txt
00171475 adware/perfect-search Adware No 0 Yes No c:\documents and settings\hasse\favoriter\adult\escorts.url
00205140 Cookie/Research-int TrackingCookie No 0 Yes No C:\Documents and Settings\Hasse\Cookies\hasse@research-int[1].txt
00274954 adware/adrotator Adware No 0 Yes No hkey_local_machine\software\microsoft\rotator
00335507 Adware/AdRotator Adware No 0 Yes No C:\System Volume Information\_restore{29C8A49B-EA53-4143-A114-91505153B18A}\RP859\A0224774.exe
01048936 Generic Malware Virus/Trojan No 0 Yes No C:\Program\GameSpy Arcade\Services\_common\PortraitLoader.dll
01692698 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Hasse\Application Data\Macromedia\Shockwave Player\xtras\download\TheGrooveAlliance\3DGrooveXtrav181\Groove.x32
02517863 Adware/SaveNow Adware No 0 Yes No C:\Documents and Settings\Hasse\Mina dokument\Mina mottagna filer\BitLord_1.1.exe
02918586 Generic Malware Virus/Trojan No 0 Yes No C:\Program\radiojazz\tbrad1.dll
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location
;===============================================================================
=================================================================================
===================
No C:\PROGRAM\BULLET PROOF FTP SERVER\BPFTPSERVER.EXE
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================


Malwarebytes' Anti-Malware 1.11
Databasversion: 684

Skanningstyp: Snabb skanning
Antal skannade objekt: 55523
Förfluten tid: 25 minute(s), 10 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 4
Infekterade registernycklar: 17
Infekterade registervärden: 2
Infekterade registerdataposter: 2
Infekterade mappar: 0
Infekterade filer: 10

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
C:\WINDOWS\system32\mlJAtqOi.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\xybsrlfm.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\opnkkLdA.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\hbreapmk.dll (Trojan.Vundo) -> Unloaded module successfully.

Infekterade registernycklar:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5255cafb-d06b-4a36-8248-85991e4a0211} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{5255cafb-d06b-4a36-8248-85991e4a0211} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnkklda (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{45f079d0-420a-45c6-81cf-8a6928e7883f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45f079d0-420a-45c6-81cf-8a6928e7883f} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Infekterade registervärden:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{a6c54318-5ac7-477d-b0a7-49af5189300c} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM2bc0d81b (Trojan.Agent) -> Delete on reboot.

Infekterade registerdataposter:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljatqoi -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljatqoi -> Quarantined and deleted successfully.

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\WINDOWS\system32\mlJAtqOi.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\iOqtAJlm.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iOqtAJlm.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xybsrlfm.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\mflrsbyx.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnkkLdA.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\hbreapmk.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\srxnujvp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\foadmqjp.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\casino.ico (Malware.Trace) -> Quarantined and deleted successfully.


SUPERAntiSpyware Scan Log
Generated 04/26/2008 at 08:34 PM

Application Version : 3.6.1000

Core Rules Database Version : 3448
Trace Rules Database Version: 1440

Scan type : Quick Scan
Total Scan Time : 02:46:50

Memory items scanned : 648
Memory threats detected : 0
Registry items scanned : 1243
Registry threats detected : 7
File items scanned : 108075
File threats detected : 10

Adware.Tracking Cookie
C:\Documents and Settings\Hasse\Cookies\hasse@mediaplex[1].txt
C:\Documents and Settings\Hasse\Cookies\[email protected][1].txt
C:\Documents and Settings\Hasse\Cookies\hasse@adtech[1].txt
C:\Documents and Settings\Hasse\Cookies\hasse@adnetserver[1].txt
C:\Documents and Settings\Hasse\Cookies\[email protected][2].txt
C:\Documents and Settings\Hasse\Cookies\[email protected][2].txt

Adware.BusMaster/SafeSurfing
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\InprocServer32
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\InprocServer32#ThreadingModel
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\ProgID
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\Programmable
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\TypeLib
HKCR\CLSID\{4865F155-CE00-4E93-A414-147844D7C81A}\VersionIndependentProgID

Adware.TrustInCash
C:\WINDOWS\ADULT.ICO
C:\WINDOWS\SPYWAREREMOVAL.ICO

Adware.Unknown Origin
C:\WINDOWS\SHOPPING.ICO

Adware.eZula/BannerRotator
C:\WINDOWS\SYSTEM32\BRROT-UNINST.EXE
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Download OTMoveIt2 at http://download.blee...r/OTMoveIt2.exe
* Save it to your desktop.
* Double-click OTMoveIt2.exe to run it. (Vista users, right click on OTMoveIt2.exe and select Run as an Administrator).
* Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\istsvc
hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}
HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}
HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
hkey_local_machine\software\microsoft\rotator
hkey_classes_root\clsid\{66fc8717-efa7-4546-8c4a-e224f3a80c76}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC}
HKEY_LOCAL_MACHINE\software\classes\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}
c:\windows\cdmxtras
c:\windows\180axau.dat
c:\windows\180ax.log
c:\documents and settings\hasse\favoriter\gambling
c:\keys.ini
c:\documents and settings\hasse\favoriter\adult\
C:\Documents and Settings\Hasse\Mina dokument\Mina mottagna filer\BitLord_1.1.exe

* Return to OTMoveIt2. Right click in the Paste List of Files/Folders to Move window (under the Yellow bar) and choose Paste.
* Click the red Moveit! button.
* A log of files and folders moved will be created in the C:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
* Close OTMoveIt2.

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

1. Download combofix at http://www.techsuppo...Bs/ComboFix.exe or http://download.blee...Bs/ComboFix.exe
2. Double-click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not click on combofix's window while it's running. That may cause it to stall.
  • 0

#3
digicraft63

digicraft63

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thanks!
Looks like you found some additional problems. Here are the logs:

OTMomeIT:

< hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\istsvc >
Registry key hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\istsvc\\ deleted successfully.
< hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec} >
Registry key hkey_classes_root\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}\\ not found.
< HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC} >
Registry key HKEY_LOCAL_MACHINE\software\classes\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}\\ deleted successfully.
< HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496} >
Registry key HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}\\ deleted successfully.
< hkey_local_machine\software\microsoft\rotator >
Registry key hkey_local_machine\software\microsoft\rotator\\ deleted successfully.
< hkey_classes_root\clsid\{66fc8717-efa7-4546-8c4a-e224f3a80c76} >
Registry key hkey_classes_root\clsid\{66fc8717-efa7-4546-8c4a-e224f3a80c76}\\ not found.
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC} >
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC}\\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\classes\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76} >
Registry key HKEY_LOCAL_MACHINE\software\classes\CLSID\{66FC8717-EFA7-4546-8C4A-E224F3A80C76}\\ deleted successfully.
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} >
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}\\ deleted successfully.
c:\windows\cdmxtras moved successfully.
c:\windows\180axau.dat moved successfully.
c:\windows\180ax.log moved successfully.
c:\documents and settings\hasse\favoriter\gambling moved successfully.
c:\keys.ini moved successfully.
c:\documents and settings\hasse\favoriter\adult\Teens moved successfully.
c:\documents and settings\hasse\favoriter\adult\Lesbians moved successfully.
c:\documents and settings\hasse\favoriter\adult\Gay moved successfully.
c:\documents and settings\hasse\favoriter\adult moved successfully.
C:\Documents and Settings\Hasse\Mina dokument\Mina mottagna filer\BitLord_1.1.exe moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04272008_195331

ComboFix 08-04-26.5 - Hasse 2008-04-27 22:13:46.2 - NTFSx86
Running from: F:\Programs & Installs 06-10-19\Geeks\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Hasse\Application Data\macromedia\Flash Player\#SharedObjects\HFK4CHL6\iforex.com
C:\Documents and Settings\Hasse\Application Data\macromedia\Flash Player\#SharedObjects\HFK4CHL6\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Hasse\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Hasse\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\foadmqjp.dll
C:\WINDOWS\system32\iOqtAJlm.ini
C:\WINDOWS\system32\opnkkLdA.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.

2008-04-27 20:30 . 2008-04-27 20:31 <KAT> d--h----- C:\$AVG8.VAULT$
2008-04-27 12:00 . 2008-04-27 12:00 <KAT> d-------- C:\Program\Trend Micro
2008-04-27 10:11 . 2008-04-27 10:46 <KAT> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-27 10:11 . 2008-04-27 10:11 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-27 10:11 . 2008-04-27 10:11 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-27 10:11 . 2008-04-27 10:11 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-27 10:10 . 2008-04-27 10:10 <KAT> d-------- C:\Program\AVG
2008-04-27 10:10 . 2008-04-27 10:49 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\AVGTOOLBAR
2008-04-27 10:10 . 2008-04-27 10:10 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-26 22:47 . 2008-04-26 22:48 <KAT> d-------- C:\Program\Panda Security
2008-04-26 15:12 . 2008-04-26 15:12 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Malwarebytes
2008-04-26 15:11 . 2008-04-26 15:12 <KAT> d-------- C:\Program\Malwarebytes' Anti-Malware
2008-04-26 15:11 . 2008-04-26 15:11 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-26 12:14 . 2008-04-26 12:14 <KAT> d-------- C:\Documents and Settings\hans.olsson.HASSES-SNABBA\Application Data\Genie-soft
2008-04-25 11:09 . 2008-04-26 11:10 1,505,491 ---hs---- C:\WINDOWS\system32\swknllwv.ini
2008-04-25 11:05 . 2008-04-26 14:47 109,756 --a------ C:\WINDOWS\BM2bc0d81b.xml
2008-04-25 00:09 . 2008-04-25 15:14 18 --a------ C:\WINDOWS\avi2divx.INI
2008-04-24 23:15 . 2008-04-25 14:25 <KAT> d-------- C:\ConverterOutput
2008-04-24 23:14 . 2008-04-24 23:14 <KAT> d-------- C:\WINDOWS\system32\codec
2008-04-24 23:14 . 2008-04-24 23:14 <KAT> d-------- C:\Program\avi2divx
2008-04-24 22:59 . 2008-04-26 17:19 272,384 --------- C:\WINDOWS\system32\mlJAtqOi.dll
2008-04-24 22:45 . 2008-04-24 22:45 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Yahoo!
2008-04-24 22:45 . 2008-04-24 22:45 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-24 22:41 . 2008-04-24 22:42 <KAT> d-------- C:\Program\Yahoo!
2008-04-24 09:09 . 2008-04-24 11:34 <KAT> d-------- C:\divx
2008-04-22 22:55 . 2008-04-22 22:55 <KAT> d-------- C:\PoBB Möja DVD
2008-04-12 19:42 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-04-12 19:42 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-04-12 19:42 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-04-12 19:42 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-04-12 19:42 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-04-12 19:42 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2008-04-12 19:42 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-04-12 19:42 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2008-04-11 23:53 . 2008-04-11 23:53 63,488 --a------ C:\WINDOWS\xobglu16.dll
2008-04-11 23:53 . 2008-04-11 23:53 23,552 --a------ C:\WINDOWS\xobglu32.dll
2008-03-31 23:25 . 2008-03-31 23:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 23:25 . 2008-03-31 23:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 23:25 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 23:25 . 2008-03-31 23:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-28 15:29 . 2008-03-28 15:29 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-28 15:12 . 2008-03-28 15:43 <KAT> d-------- C:\Program\DVDFab Platinum 4
2008-03-28 15:12 . 2008-04-22 21:03 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Vso
2008-03-28 15:12 . 2008-03-28 15:12 87,608 --------- C:\Documents and Settings\Hasse\Application Data\inst.exe
2008-03-28 15:12 . 2008-03-28 15:12 47,360 --------- C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-28 15:12 . 2008-03-28 15:12 47,360 --------- C:\Documents and Settings\Hasse\Application Data\pcouffin.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 19:07 --------- d-----w C:\Program\Delade filer\Symantec Shared
2008-04-27 18:41 2,161 --sha-w C:\WINDOWS\system32\mmf.sys
2008-04-26 20:24 --------- d-----w C:\Program\SUPERAntiSpyware
2008-04-26 15:42 --------- d-----w C:\Program\Delade filer\Wise Installation Wizard
2008-04-26 15:42 --------- d-----w C:\Documents and Settings\Hasse\Application Data\SUPERAntiSpyware.com
2008-04-24 20:45 --------- d-----w C:\Documents and Settings\Hasse\Application Data\uTorrent
2008-04-24 20:43 --------- d-----w C:\Program\DivX
2008-04-22 19:03 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Vso
2008-04-12 20:24 --------- d-----w C:\Program\Steam
2008-04-12 17:42 --------- d-----w C:\Program\Delade filer\Ahead
2008-04-12 17:42 --------- d-----w C:\Program\Ahead
2008-04-08 13:56 --------- d-----w C:\Program\FirstClass
2008-04-05 11:22 --------- d-----w C:\Documents and Settings\Hasse\Application Data\dvdcss
2008-04-03 19:09 --------- d-----w C:\Program\Bullet Proof FTP Server
2008-03-28 13:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-25 08:16 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Ahead
2008-03-24 23:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 22:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-23 22:21 --------- d-----w C:\Program\Nero
2008-03-23 15:25 --------- d-----w C:\Documents and Settings\Hasse\Application Data\DivX
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 17:50 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Free Download Manager
2008-03-20 17:38 --------- d-----w C:\Documents and Settings\Hasse\Application Data\vlc
2008-03-20 16:58 --------- d-----w C:\Program\VideoLAN
2008-03-20 08:10 1,845,248 ------w C:\WINDOWS\system32\win32k.sys
2008-03-19 03:43 --------- d-----w C:\Program\Gene6 FTP Server
2008-03-18 15:20 --------- d-----w C:\Program\FLV Player
2008-03-15 12:46 --------- d-----w C:\Program\Finale 2007
2008-03-14 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-11 13:03 --------- d-----w C:\Program\radiojazz
2008-03-10 09:48 --------- d-----w C:\Program\Java
2008-03-07 13:03 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
2008-03-07 13:03 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
2008-03-07 12:40 13,035 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-03-07 12:40 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-03-07 12:39 39,984 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-03-07 12:39 37,936 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-03-07 12:39 35,120 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-03-07 12:39 27,696 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-03-07 12:39 191,536 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-03-07 12:39 145,968 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-03-07 12:39 12,848 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-03-06 20:32 706 ------w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ------w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ------w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-03 15:30 --------- d-----w C:\Program\Avanquest update
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-28 21:57 --------- d-----w C:\Program\M-Audio USB Quattro
2008-02-28 21:56 9,216 ------w C:\WINDOWS\system32\drivers\m763001b.sys
2008-02-28 21:56 82,944 ------w C:\WINDOWS\system32\usbns4x4.dll
2008-02-28 21:56 724,992 ------w C:\WINDOWS\iun6002.exe
2008-02-28 21:56 6,656 ------w C:\WINDOWS\system32\drivers\m763001d.sys
2008-02-28 21:56 41,856 ------w C:\WINDOWS\system32\drivers\MA763001.sys
2008-02-28 21:56 22,368 ------w C:\WINDOWS\system32\drivers\usbns4x4.sys
2008-02-28 00:48 --------- d-----w C:\Program\SmartMusic 9
2008-02-27 23:03 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Move Networks
2008-02-27 20:57 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Allume Systems
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-01-17 23:20 428 ------w C:\Documents and Settings\Hasse\scriptsOrganizer.dat
2007-08-30 06:57 80,512 ------w C:\Documents and Settings\Hasse\Application Data\GDIPFONTCACHEV1.DAT
2007-02-27 17:03 49 ------w C:\Documents and Settings\Hasse\Application Data\internaldb41.dat
2007-01-08 20:28 20,480 ------w C:\Documents and Settings\Hasse\Application Data\internaldb4827.dat
2006-12-27 20:23 6,144 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3134.dat
2006-12-27 20:23 379 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb41.dat
2006-12-27 20:23 20,480 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3043.dat
2006-12-27 20:23 151 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4082.dat
2006-12-27 20:23 13,046 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4226.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb6621.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4022.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3474.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb2347.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb2126.dat
2006-12-19 21:36 344 ------w C:\Documents and Settings\andré.HASSES-SNABBA\Application Data\internaldb1942.dat
2006-12-19 21:34 344 ------w C:\Documents and Settings\hans.olsson.HASSES-SNABBA\Application Data\internaldb41.dat
2006-11-16 15:44 0 ------w C:\Documents and Settings\Hasse\Application Data\internaldb5436.dat
2006-11-04 14:36 9,216 ------w C:\Documents and Settings\Hasse\Application Data\internaldb8467.dat
2006-11-04 14:36 0 ------w C:\Documents and Settings\Hasse\Application Data\internaldb6334.dat
2004-09-09 19:26 417,792 ------w C:\Documents and Settings\Hasse\GL4JavbJauGljJNI14.dll
2004-03-14 15:53 560 ------w C:\Program\Global.sw
2005-07-14 18:31 27,648 --sh--w C:\WINDOWS\system32\AVSredirect.dll
2004-10-23 11:46 2,161 --sh--w C:\WINDOWS\system32\mmf(2)(2).sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-27 10:10 2050816 --a------ C:\Program\AVG\AVG8\avgtoolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\Program\AVG\AVG8\avgtoolbar.dll" [2008-04-27 10:10 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\Program\AVG\AVG8\avgtoolbar.dll [2008-04-27 10:10 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:34 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program\Delade filer\Ahead\Lib\NMBgMonitor.exe" [ ]
"MSMSGS"="C:\Program\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup"="C:\Program\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 20:28 155648]
"StatusClient"="C:\Program\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 17:51 36864]
"TkBellExe"="C:\Program\Delade filer\Real\Update_OB\realsched.exe" [2004-12-19 02:16 180269]
"iTunesHelper"="C:\Program\iTunes\iTunesHelper.exe" [2005-12-20 21:54 278528]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 16:29 7561216]
"nwiz"="nwiz.exe" [2006-03-09 16:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 16:29 86016]
"WinampAgent"="C:\Program\Winamp\winampa.exe" [2006-11-21 19:38 35328]
"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"osCheck"="C:\Program\Norton Internet Security\osCheck.exe" [2007-01-14 01:11 771704]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"H2O"="C:\Program\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 01:00 385024]
"Symantec PIF AlertEng"="C:\Program\Delade filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Adobe Photo Downloader"="C:\Program\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"Acrobat Assistant 8.0"="C:\Program\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"QuickTime Task"="C:\Program\QuickTime\QTTask.exe" [2007-06-29 07:24 286720]
"GBMPro8Agent"="C:\Program\Genie-Soft\GBMPro8\GBMAgent.exe" [2007-07-11 07:23 214512]
"Adobe Reader Speed Launcher"="C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BVRPLiveUpdate"="C:\Program\Avanquest update\Engine\Setup.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"AVG8_TRAY"="C:\Program\AVG\AVG8\avgtray.exe" [2008-04-27 10:10 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 10:34 15360]

C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\
.lnk - C:\Program\SolidWorks\swScheduler\swBOEngine.exe [2007-09-09 07:51:40 488728]
Adobe Gamma.lnk - C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2004-02-26 18:36:06 110592]
Genv„g till bpftpserver.lnk - C:\Program\Bullet Proof FTP Server\bpftpserver.exe [2008-03-17 01:17:11 481280]
M-Audio Quattro Control Panel Launcher.lnk - C:\Program\M-Audio USB Quattro\QuatTask.exe [2003-07-10 02:23:58 69632]
MagicDisc.lnk - C:\Program\MagicDisc\MagicDisc.exe [2007-05-13 18:45:36 534016]
Maya 6 helpserver.lnk - C:\Program\Alias\Maya6.0\docs\helpserver.jar [2004-10-25 15:29:33 1517402]
SolidWorks Task Scheduler Engine.lnk - C:\Program\SolidWorks\swScheduler\swBOEngine.exe [2007-09-09 07:51:40 488728]

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
InterVideo WinCinema Manager.lnk - C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe [2004-02-26 04:32:56 110592]
Microsoft Office.lnk - C:\Program\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-07-30 10:12:38 722728]
Windows Desktop Search.lnk - C:\Program\Windows Desktop Search\WindowsSearch.exe [2007-02-05 16:40:46 118784]
WinZip Quick Pick.lnk - C:\Program\WinZip\WZQKPICK.EXE [2004-02-27 00:06:22 106560]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program\SUPERAntiSpyware\SASWINLO.DLL 2008-04-26 22:24 294912 C:\Program\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbns4x4.dll
"VIDC.DVSD"= pdvcodec.dll
"SENTINEL"= snti386.dll
"vidc.iv50"= C:\PROGRA~1\REPLAY~1\ir50_32.dll
"midi3"= usbns4x4.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"C:\\Program\\Kazaa\\kazaa.exe"=
"C:\\Program\\iTunes\\iTunes.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Programs & Installs 06-10-19\\utorrent.exe"=
"C:\\Program\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program\\Autodesk\\Backburner\\server.exe"=
"C:\\Program\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program\\MSN Messenger\\livecall.exe"=
"C:\\Program\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"C:\\Program\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)

R0 viaraid;viaraid;C:\WINDOWS\system32\DRIVERS\viaraid.sys [2003-10-21 08:03]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-27 10:11]
R2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;"C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-01-18 12:26]
R2 avg8emc;AVG8 E-mail Scanner;C:\Program\AVG\AVG8\avgemc.exe [2008-04-27 10:10]
R2 avg8wd;AVG8 WatchDog;C:\Program\AVG\AVG8\avgwdsvc.exe [2008-04-27 10:10]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-27 10:11]
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2004-03-10 22:07]
R2 QuattroInstallerService;Quattro Installer;C:\Program\M-Audio USB Quattro\Install\QuatInst.exe [2008-02-28 23:56]
R2 SMTPSVC;SMTP (Simple Mail Transfer Protocol);C:\WINDOWS\System32\inetsrv\inetinfo.exe [2004-08-04 10:34]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
S2 Active Common Service;Active Common Service;C:\WINDOWS\system32\commserv.exe []
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys [2006-11-29 07:46]
S3 Fast54xic;Fast54xic;C:\WINDOWS\system32\drivers\qv2kux.sys [2001-08-17 21:53]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-01-18 23:55]
S3 LMASFltr;LMASFltr;C:\WINDOWS\system32\drivers\LMASFltr.sys []
S3 m763001b;M-Audio Quattro Base Driver;C:\WINDOWS\system32\drivers\m763001b.sys [2008-02-28 23:56]
S3 m763001d;M-Audio Quattro Legacy Driver;C:\WINDOWS\system32\drivers\m763001d.sys [2008-02-28 23:56]
S3 ma763001;M-Audio Quattro;C:\WINDOWS\system32\drivers\MA763001.sys [2008-02-28 23:56]
S3 MMAUSB;M Audio USB ASIO Driver;C:\WINDOWS\system32\Drivers\MMAUSB.SYS []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 19:31]
S3 phil2vid;Philips USB VGA-kamera;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 23:04]
S3 USBNS4X4;M-Audio USB Quattro Midi;C:\WINDOWS\system32\drivers\usbns4x4.sys [2008-02-28 23:56]

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
C:\WINDOWS\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 05:15:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program\Apple Software Update\SoftwareUpdate.exe
"2008-04-02 09:26:17 C:\WINDOWS\Tasks\GBM - 232 Gb BackUp-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-03 04:41:22 C:\WINDOWS\Tasks\GBM - 80 Gb Vault-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-01 06:17:56 C:\WINDOWS\Tasks\GBM - BackUp System C disk-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-27 20:34:15 C:\WINDOWS\Tasks\Kontrollera uppdateringar för Windows Live Toolbar.job"
- C:\Program\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-22 05:10:11 C:\WINDOWS\Tasks\Norton Internet Security - Sök igenom datorn - Hasse.job"
- C:\Program\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 22:26:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 25

**************************************************************************
.
Completion time: 2008-04-27 22:56:50
ComboFix-quarantined-files.txt 2008-04-27 20:56:31

Pre-Run: 18,615,590,912 byte ledigt
Post-Run: 18,607,263,744 byte ledigt

324 --- E O F --- 2008-04-09 01:07:00
  • 0

#4
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Open up your Notepad editor (Start->Run, type in notepad and click OK). Copy and paste the text into the quotebox below:

Driver::
Active Common Service
File::
C:\WINDOWS\system32\swknllwv.ini
C:\WINDOWS\BM2bc0d81b.xml
C:\WINDOWS\system32\mlJAtqOi.dll

Save this as CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note: Do not click on combofix's window while it's running. That may cause it to stall.

How is the computer running so far?
  • 0

#5
digicraft63

digicraft63

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thanks again!

My computer is running pretty good, exept for that it is very slow to start up.

Here is the log:

ComboFix 08-04-26.5 - Hasse 2008-04-28 17:20:09.4 - NTFSx86
Running from: F:\Programs & Installs 06-10-19\Geeks\ComboFix.exe
Command switches used :: F:\Programs & Installs 06-10-19\Geeks\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM2bc0d81b.xml
C:\WINDOWS\system32\mlJAtqOi.dll
C:\WINDOWS\system32\swknllwv.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Gäst.HASSES-SNABBA\Lokala inställningar\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Hasse\Application Data\inst.exe
C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\.lnk
C:\WINDOWS\BM2bc0d81b.xml
C:\WINDOWS\system32\swknllwv.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ACTIVE_COMMON_SERVICE
-------\Service_Active Common Service


((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.

2008-04-27 20:30 . 2008-04-28 11:05 <KAT> d--h----- C:\$AVG8.VAULT$
2008-04-27 12:00 . 2008-04-27 12:00 <KAT> d-------- C:\Program\Trend Micro
2008-04-27 10:11 . 2008-04-28 08:23 <KAT> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-27 10:11 . 2008-04-27 10:11 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-27 10:11 . 2008-04-27 10:11 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-27 10:11 . 2008-04-27 10:11 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-27 10:10 . 2008-04-27 10:10 <KAT> d-------- C:\Program\AVG
2008-04-27 10:10 . 2008-04-27 10:49 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\AVGTOOLBAR
2008-04-27 10:10 . 2008-04-27 10:10 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-26 22:47 . 2008-04-26 22:48 <KAT> d-------- C:\Program\Panda Security
2008-04-26 15:12 . 2008-04-26 15:12 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Malwarebytes
2008-04-26 15:11 . 2008-04-26 15:12 <KAT> d-------- C:\Program\Malwarebytes' Anti-Malware
2008-04-26 15:11 . 2008-04-26 15:11 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-26 12:14 . 2008-04-26 12:14 <KAT> d-------- C:\Documents and Settings\hans.olsson.HASSES-SNABBA\Application Data\Genie-soft
2008-04-25 00:09 . 2008-04-25 15:14 18 --a------ C:\WINDOWS\avi2divx.INI
2008-04-24 23:15 . 2008-04-25 14:25 <KAT> d-------- C:\ConverterOutput
2008-04-24 23:14 . 2008-04-24 23:14 <KAT> d-------- C:\WINDOWS\system32\codec
2008-04-24 23:14 . 2008-04-24 23:14 <KAT> d-------- C:\Program\avi2divx
2008-04-24 22:45 . 2008-04-24 22:45 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Yahoo!
2008-04-24 22:45 . 2008-04-24 22:45 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-24 22:41 . 2008-04-24 22:42 <KAT> d-------- C:\Program\Yahoo!
2008-04-24 09:09 . 2008-04-24 11:34 <KAT> d-------- C:\divx
2008-04-22 22:55 . 2008-04-22 22:55 <KAT> d-------- C:\PoBB Möja DVD
2008-04-12 19:42 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-04-12 19:42 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-04-12 19:42 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-04-12 19:42 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-04-12 19:42 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-04-12 19:42 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2008-04-12 19:42 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-04-12 19:42 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2008-04-11 23:53 . 2008-04-11 23:53 63,488 --a------ C:\WINDOWS\xobglu16.dll
2008-04-11 23:53 . 2008-04-11 23:53 23,552 --a------ C:\WINDOWS\xobglu32.dll
2008-03-31 23:25 . 2008-03-31 23:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 23:25 . 2008-03-31 23:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 23:25 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 23:25 . 2008-03-31 23:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-28 15:29 . 2008-03-28 15:29 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-28 15:12 . 2008-03-28 15:43 <KAT> d-------- C:\Program\DVDFab Platinum 4
2008-03-28 15:12 . 2008-04-22 21:03 <KAT> d-------- C:\Documents and Settings\Hasse\Application Data\Vso
2008-03-28 15:12 . 2008-03-28 15:12 47,360 --------- C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-28 15:12 . 2008-03-28 15:12 47,360 --------- C:\Documents and Settings\Hasse\Application Data\pcouffin.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 13:26 --------- d-----w C:\Program\Delade filer\Symantec Shared
2008-04-28 06:27 --------- d-----w C:\Program\GameSpy Arcade
2008-04-28 05:57 --------- d-----w C:\Program\Bullet Proof FTP Server
2008-04-28 00:16 2,161 --sha-w C:\WINDOWS\system32\mmf.sys
2008-04-26 20:24 --------- d-----w C:\Program\SUPERAntiSpyware
2008-04-26 15:42 --------- d-----w C:\Program\Delade filer\Wise Installation Wizard
2008-04-26 15:42 --------- d-----w C:\Documents and Settings\Hasse\Application Data\SUPERAntiSpyware.com
2008-04-24 20:45 --------- d-----w C:\Documents and Settings\Hasse\Application Data\uTorrent
2008-04-24 20:43 --------- d-----w C:\Program\DivX
2008-04-22 19:03 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Vso
2008-04-12 20:24 --------- d-----w C:\Program\Steam
2008-04-12 17:42 --------- d-----w C:\Program\Delade filer\Ahead
2008-04-12 17:42 --------- d-----w C:\Program\Ahead
2008-04-08 13:56 --------- d-----w C:\Program\FirstClass
2008-04-05 11:22 --------- d-----w C:\Documents and Settings\Hasse\Application Data\dvdcss
2008-03-28 13:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-25 08:16 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Ahead
2008-03-24 23:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 22:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-23 22:21 --------- d-----w C:\Program\Nero
2008-03-23 15:25 --------- d-----w C:\Documents and Settings\Hasse\Application Data\DivX
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-20 17:50 --------- d-----w C:\Documents and Settings\Hasse\Application Data\Free Download Manager
2008-03-20 17:38 --------- d-----w C:\Documents and Settings\Hasse\Application Data\vlc
2008-03-20 16:58 --------- d-----w C:\Program\VideoLAN
2008-03-20 08:10 1,845,248 ------w C:\WINDOWS\system32\win32k.sys
2008-03-19 03:43 --------- d-----w C:\Program\Gene6 FTP Server
2008-03-18 15:20 --------- d-----w C:\Program\FLV Player
2008-03-15 12:46 --------- d-----w C:\Program\Finale 2007
2008-03-14 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-11 13:03 --------- d-----w C:\Program\radiojazz
2008-03-10 09:48 --------- d-----w C:\Program\Java
2008-03-07 13:03 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
2008-03-07 13:03 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
2008-03-07 12:40 13,035 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-03-07 12:40 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-03-07 12:39 39,984 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-03-07 12:39 37,936 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-03-07 12:39 35,120 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-03-07 12:39 27,696 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-03-07 12:39 191,536 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-03-07 12:39 145,968 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-03-07 12:39 12,848 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-03-06 20:32 706 ------w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ------w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ------w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-03 15:30 --------- d-----w C:\Program\Avanquest update
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-28 21:57 --------- d-----w C:\Program\M-Audio USB Quattro
2008-02-28 21:56 9,216 ------w C:\WINDOWS\system32\drivers\m763001b.sys
2008-02-28 21:56 82,944 ------w C:\WINDOWS\system32\usbns4x4.dll
2008-02-28 21:56 724,992 ------w C:\WINDOWS\iun6002.exe
2008-02-28 21:56 6,656 ------w C:\WINDOWS\system32\drivers\m763001d.sys
2008-02-28 21:56 41,856 ------w C:\WINDOWS\system32\drivers\MA763001.sys
2008-02-28 21:56 22,368 ------w C:\WINDOWS\system32\drivers\usbns4x4.sys
2008-02-28 00:48 --------- d-----w C:\Program\SmartMusic 9
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-01-17 23:20 428 ------w C:\Documents and Settings\Hasse\scriptsOrganizer.dat
2007-08-30 06:57 80,512 ------w C:\Documents and Settings\Hasse\Application Data\GDIPFONTCACHEV1.DAT
2007-02-27 17:03 49 ------w C:\Documents and Settings\Hasse\Application Data\internaldb41.dat
2007-01-08 20:28 20,480 ------w C:\Documents and Settings\Hasse\Application Data\internaldb4827.dat
2006-12-27 20:23 6,144 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3134.dat
2006-12-27 20:23 379 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb41.dat
2006-12-27 20:23 20,480 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3043.dat
2006-12-27 20:23 151 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4082.dat
2006-12-27 20:23 13,046 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4226.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb6621.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb4022.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb3474.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb2347.dat
2006-12-27 20:23 0 ------w C:\Documents and Settings\hasse olsson\Application Data\internaldb2126.dat
2006-12-19 21:36 344 ------w C:\Documents and Settings\andré.HASSES-SNABBA\Application Data\internaldb1942.dat
2006-12-19 21:34 344 ------w C:\Documents and Settings\hans.olsson.HASSES-SNABBA\Application Data\internaldb41.dat
2006-11-16 15:44 0 ------w C:\Documents and Settings\Hasse\Application Data\internaldb5436.dat
2006-11-04 14:36 9,216 ------w C:\Documents and Settings\Hasse\Application Data\internaldb8467.dat
2006-11-04 14:36 0 ------w C:\Documents and Settings\Hasse\Application Data\internaldb6334.dat
2004-09-09 19:26 417,792 ------w C:\Documents and Settings\Hasse\GL4JavbJauGljJNI14.dll
2004-03-14 15:53 560 ------w C:\Program\Global.sw
2005-07-14 18:31 27,648 --sh--w C:\WINDOWS\system32\AVSredirect.dll
2004-10-23 11:46 2,161 --sh--w C:\WINDOWS\system32\mmf(2)(2).sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-27_22.56.08.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-27 18:41:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 00:15:29 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-27 18:46:21 229,150 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-04-28 00:20:28 229,152 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-27 10:10 2050816 --a------ C:\Program\AVG\AVG8\avgtoolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\Program\AVG\AVG8\avgtoolbar.dll" [2008-04-27 10:10 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\Program\AVG\AVG8\avgtoolbar.dll [2008-04-27 10:10 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:34 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program\Delade filer\Ahead\Lib\NMBgMonitor.exe" [ ]
"MSMSGS"="C:\Program\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup"="C:\Program\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 20:28 155648]
"StatusClient"="C:\Program\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 17:51 36864]
"TkBellExe"="C:\Program\Delade filer\Real\Update_OB\realsched.exe" [2004-12-19 02:16 180269]
"iTunesHelper"="C:\Program\iTunes\iTunesHelper.exe" [2005-12-20 21:54 278528]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 16:29 7561216]
"nwiz"="nwiz.exe" [2006-03-09 16:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 16:29 86016]
"WinampAgent"="C:\Program\Winamp\winampa.exe" [2006-11-21 19:38 35328]
"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"osCheck"="C:\Program\Norton Internet Security\osCheck.exe" [2007-01-14 01:11 771704]
"SunJavaUpdateSched"="C:\Program\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"H2O"="C:\Program\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 01:00 385024]
"Symantec PIF AlertEng"="C:\Program\Delade filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"Adobe Photo Downloader"="C:\Program\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"Acrobat Assistant 8.0"="C:\Program\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"QuickTime Task"="C:\Program\QuickTime\QTTask.exe" [2007-06-29 07:24 286720]
"GBMPro8Agent"="C:\Program\Genie-Soft\GBMPro8\GBMAgent.exe" [2007-07-11 07:23 214512]
"Adobe Reader Speed Launcher"="C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BVRPLiveUpdate"="C:\Program\Avanquest update\Engine\Setup.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"AVG8_TRAY"="C:\Program\AVG\AVG8\avgtray.exe" [2008-04-27 10:10 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 10:34 15360]

C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\
Adobe Gamma.lnk - C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2004-02-26 18:36:06 110592]
Genv„g till bpftpserver.lnk - C:\Program\Bullet Proof FTP Server\bpftpserver.exe [2008-03-17 01:17:11 481280]
M-Audio Quattro Control Panel Launcher.lnk - C:\Program\M-Audio USB Quattro\QuatTask.exe [2003-07-10 02:23:58 69632]
MagicDisc.lnk - C:\Program\MagicDisc\MagicDisc.exe [2007-05-13 18:45:36 534016]
Maya 6 helpserver.lnk - C:\Program\Alias\Maya6.0\docs\helpserver.jar [2004-10-25 15:29:33 1517402]
SolidWorks Task Scheduler Engine.lnk - C:\Program\SolidWorks\swScheduler\swBOEngine.exe [2007-09-09 07:51:40 488728]

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
InterVideo WinCinema Manager.lnk - C:\Program\InterVideo\Common\Bin\WinCinemaMgr.exe [2004-02-26 04:32:56 110592]
Microsoft Office.lnk - C:\Program\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-07-30 10:12:38 722728]
Windows Desktop Search.lnk - C:\Program\Windows Desktop Search\WindowsSearch.exe [2007-02-05 16:40:46 118784]
WinZip Quick Pick.lnk - C:\Program\WinZip\WZQKPICK.EXE [2004-02-27 00:06:22 106560]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program\SUPERAntiSpyware\SASWINLO.DLL 2008-04-26 22:24 294912 C:\Program\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= usbns4x4.dll
"VIDC.DVSD"= pdvcodec.dll
"SENTINEL"= snti386.dll
"vidc.iv50"= C:\PROGRA~1\REPLAY~1\ir50_32.dll
"midi3"= usbns4x4.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"C:\\Program\\Kazaa\\kazaa.exe"=
"C:\\Program\\iTunes\\iTunes.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Programs & Installs 06-10-19\\utorrent.exe"=
"C:\\Program\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program\\Autodesk\\Backburner\\server.exe"=
"C:\\Program\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program\\MSN Messenger\\livecall.exe"=
"C:\\Program\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"C:\\Program\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)

R0 viaraid;viaraid;C:\WINDOWS\system32\DRIVERS\viaraid.sys [2003-10-21 08:03]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-27 10:11]
R2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;"C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-01-18 12:26]
R2 avg8emc;AVG8 E-mail Scanner;C:\Program\AVG\AVG8\avgemc.exe [2008-04-27 10:10]
R2 avg8wd;AVG8 WatchDog;C:\Program\AVG\AVG8\avgwdsvc.exe [2008-04-27 10:10]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-27 10:11]
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2004-03-10 22:07]
R2 QuattroInstallerService;Quattro Installer;C:\Program\M-Audio USB Quattro\Install\QuatInst.exe [2008-02-28 23:56]
R2 SMTPSVC;SMTP (Simple Mail Transfer Protocol);C:\WINDOWS\System32\inetsrv\inetinfo.exe [2004-08-04 10:34]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys [2006-11-29 07:46]
S3 Fast54xic;Fast54xic;C:\WINDOWS\system32\drivers\qv2kux.sys [2001-08-17 21:53]
S3 ggflt;SEMC USB Flash Driver Filter;C:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-01-18 23:55]
S3 LMASFltr;LMASFltr;C:\WINDOWS\system32\drivers\LMASFltr.sys []
S3 m763001b;M-Audio Quattro Base Driver;C:\WINDOWS\system32\drivers\m763001b.sys [2008-02-28 23:56]
S3 m763001d;M-Audio Quattro Legacy Driver;C:\WINDOWS\system32\drivers\m763001d.sys [2008-02-28 23:56]
S3 ma763001;M-Audio Quattro;C:\WINDOWS\system32\drivers\MA763001.sys [2008-02-28 23:56]
S3 MMAUSB;M Audio USB ASIO Driver;C:\WINDOWS\system32\Drivers\MMAUSB.SYS []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 19:31]
S3 phil2vid;Philips USB VGA-kamera;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 23:04]
S3 USBNS4X4;M-Audio USB Quattro Midi;C:\WINDOWS\system32\drivers\usbns4x4.sys [2008-02-28 23:56]

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
C:\WINDOWS\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 05:15:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program\Apple Software Update\SoftwareUpdate.exe
"2008-04-02 09:26:17 C:\WINDOWS\Tasks\GBM - 232 Gb BackUp-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-03 04:41:22 C:\WINDOWS\Tasks\GBM - 80 Gb Vault-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-01 06:17:56 C:\WINDOWS\Tasks\GBM - BackUp System C disk-Full.job"
- C:\Program\Genie-Soft\GBMPro8\GBM8.exe
"2008-04-28 15:33:30 C:\WINDOWS\Tasks\Kontrollera uppdateringar för Windows Live Toolbar.job"
- C:\Program\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-22 05:10:11 C:\WINDOWS\Tasks\Norton Internet Security - Sök igenom datorn - Hasse.job"
- C:\Program\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 17:30:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 25

**************************************************************************
.
Completion time: 2008-04-28 17:56:29
ComboFix-quarantined-files.txt 2008-04-28 15:56:17
ComboFix2.txt 2008-04-27 20:56:51

Pre-Run: 18,461,274,112 byte ledigt
Post-Run: 18,457,042,944 byte ledigt

330 --- E O F --- 2008-04-09 01:07:00
  • 0

#6
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Go to Start->Run and type in msconfig and hit OK. Go to the Startup tab and uncheck the following entries:

"TkBellExe"
"iTunesHelper"
"WinampAgent"
"SunJavaUpdateSched"
"Adobe Photo Downloader"
"Acrobat Assistant 8.0"
"QuickTime Task"
"Adobe Reader Speed Launcher"
"BVRPLiveUpdate"
"NeroFilterCheck"


This will disable them from startup and hopefully give you a faster loading time.

You might also want to delete the following shortcuts so they don't launch at startup:

C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\Adobe Gamma.lnk
C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\Genv„g till bpftpserver.lnk
C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\MagicDisc.lnk
C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\Maya 6 helpserver.lnk
C:\Documents and Settings\Hasse\Start-meny\Program\Autostart\SolidWorks Task Scheduler Engine.lnk
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\InterVideo WinCinema Manager.lnk
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Microsoft Office.lnk
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Personal.lnk
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\Windows Desktop Search.lnk
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\WinZip Quick Pick.lnk


Restart the computer and see if there's an improvement.
  • 0

#7
digicraft63

digicraft63

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Hello!
In the msconfig I presume that you mean the tab Autostart instead of "Startup tab", couse that tab could not be found?
Under that tab the only services/apps that resembles the ones in your list was:

"iTunesHelper"
"NeroFilterCheck" = "NeroCheck"?
"WinampAgent" = "Winampa"?

Didn´t find any who resembles:

"SunJavaUpdateSched"
"Adobe Photo Downloader"
"Acrobat Assistant 8.0"
"QuickTime Task"
"Adobe Reader Speed Launcher"
"BVRPLiveUpdate"

So far, the computer startup time is about 10 min. It is also very slow in displaying the shortcuts on the desktop. Maby I am having to many. It launces a program very slow after a reboot. It takes so long time to display the the apps welcome sign it makes you unshure wether you have dubble clicked the app icon properly.

Looks like there still is a lot of unnessisary things going on in the background during startup.
  • 0

#8
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
A slow computer does not mean there is malware present. I don't see anything in your Hijack This log to indicate that your problem is malware related. I will post the following info to get you started in the right direction, but if you need further help with this you will have to post a new topic in the proper Operating System Forum. I'm closing this topic.

Here are some routine maintenance practices that you should do on a regular basis to keep your machine running efficiently:

Disk Cleanup:

http://www.theelderg...nup_utility.htm

Defrag your HD:

http://artsweb.bham....rag-win2kxp.htm

Run chkdsk:

To use Chkdsk, click Start and My Computer. Right-click the hard drive you want to check, and click Properties. Select the Tools tab and click Check Now. Check both boxes. Click Start. You'll get a message that the computer must be rebooted to run a complete check. Click Yes and reboot. Chkdsk will take awhile, so run it when you don't need to use the computer for something else.

Remove unnecessary startups

This should be done through the System Configuration Utility. Go to Start > Run and type in msconfig.
Click OK or hit the Enter key.

Click on the "Startup" tab and remove the check by the items that you have determined are unnecessary. Click "Apply" then "Close"

You will be prompted to restart. Go ahead and restart.

Upon restart you will be confronted with a dialogue box warning about running in selective startup. Just ignore that message and put a check in the box by "Don't show me this message or launch the System Configuration Utility when Windows starts" and click "OK". You will not be bothered by the message again.

Keep in mind that some entries will be re-enabled in the startups each time you use that particular program. Therefore, you will have to find the option in that programs preferences that says something like "Load with Windows" or "Run when Windows Starts" and disable that option.

Go here for info on msconfig:

http://www.pacs-port...artup_index.htm

You can look up the startups at the following links to help determine what is needed and what is not:

http://computercops....tartupList.html

http://www.bleepingc...r.com/startups/

http://www.answersth...es/tasklist.htm

http://www.windowsst...start=50&end=75

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, have followed the steps above, and still suspect you may be infected, please contact a staff member with the address of the thread to have it reopened.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP