2007-01-31, 20:40
#37
ok här är den:
"Andreas" - 07-01-31 20:36:43 Service Pack 2
ComboFix 07.01.31 - Running from: "C:\Documents and Settings\Andreas\Skrivbord"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\SVKP.sys
C:\WINDOWS\system32\drivers\npf.sys
((((((((((((((((((((((((((((((( Files Created from 2006-12-31 to 2007-01-31 ))))))))))))))))))))))))))))))))))
2007-01-31 20:07 <KAT> d-------- C:\WINDOWS\LastGood
2007-01-31 20:07 <KAT> d-------- C:\WINDOWS\BDOSCAN8
2007-01-31 17:02 <KAT> d-------- C:\DOCUME~1\Marcus\Application Data\Skype
2007-01-28 19:05 <KAT> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-01-25 18:16 <KAT> d-------- C:\Dev-Cpp
2007-01-25 00:03 <KAT> d-------- C:\DOCUME~1\Thomas\.freemind
2007-01-25 00:03 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-22 17:05 33,952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-01-22 17:05 <KAT> d-------- C:\Program\Mount&Blade
2007-01-19 20:46 <KAT> d---s---- C:\DOCUME~1\ANN-CH~1\UserData
2007-01-19 20:33 <KAT> d-------- C:\Program\FreeMind
2007-01-19 20:33 <KAT> d-------- C:\DOCUME~1\ANN-CH~1\.freemind
2007-01-19 20:29 <KAT> d-------- C:\Program\Photo Story 3 for Windows
2007-01-19 20:26 <KAT> d-------- C:\Program\Audacity1
2007-01-19 20:24 <KAT> d-------- C:\Program\PhotoFiltre
2007-01-17 15:20 61,088 --a------ C:\WINDOWS\system\TX_HTML.DLL
2007-01-17 15:20 57,984 --a------ C:\WINDOWS\system\QPRO200.DLL
2007-01-17 15:20 53,376 --a------ C:\WINDOWS\system\TXTLS16.DLL
2007-01-17 15:20 50,160 --a------ C:\WINDOWS\system\Ic16.dll
2007-01-17 15:20 44,208 --a------ C:\WINDOWS\system\TX_RTF.DLL
2007-01-17 15:20 398,416 --a------ C:\WINDOWS\system\Vbrun300.dll
2007-01-17 15:20 321,488 --a------ C:\WINDOWS\system\TX16.DLL
2007-01-17 15:20 30,608 --a------ C:\WINDOWS\system\WNDTLS16.DLL
2007-01-17 15:20 26,768 --a------ C:\WINDOWS\system\Ctl3d.dll
2007-01-17 15:20 <KAT> d-------- C:\Program\TOLKEN99
2007-01-16 19:24 36,864 --------- C:\WINDOWS\system32\wbsys.dll
2007-01-16 19:24 20,480 --a------ C:\WINDOWS\system32\wbload.dll
2007-01-16 19:24 <KAT> d-------- C:\Program\Stardock
2007-01-15 22:44 <KAT> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Google
2007-01-15 22:43 <KAT> dr------- C:\DOCUME~1\LOCALS~1\Favoriter
2007-01-15 18:53 <KAT> d-------- C:\WINDOWS\Sys
2007-01-14 20:02 <KAT> d-------- C:\Program\Mozilla Thunderbird
2007-01-14 20:02 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Thunderbird
2007-01-14 20:02 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Talkback
2007-01-12 19:22 <KAT> d-------- C:\Program\HGI
2007-01-12 17:44 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Dev-Cpp
2007-01-05 09:45 319,488 -ra------ C:\WINDOWS\system32\MafiaSetup.exe
2007-01-02 10:29 <KAT> d-------- C:\Program\Delade filer\Skype
2007-01-02 10:29 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Skype
2007-01-02 10:29 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Skype
2007-01-02 10:28 <KAT> d-------- C:\Program\Skype
2007-01-01 19:47 <KAT> d-------- C:\DOCUME~1\Thomas\Application Data\Souptoys
2006-12-31 09:07 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2007-01-31 20:10 -------- d-------- C:\Program\steam
2007-01-30 17:04 -------- d-------- C:\Program\satellitetvforpc
2007-01-30 17:04 -------- d-------- C:\Program\project64 1.6
2007-01-21 12:15 -------- d-------- C:\Program\msn messenger
2007-01-20 13:42 -------- d-------- C:\Program\game cam v1.4
2007-01-17 15:15 -------- d-------- C:\DOCUME~1\Andreas\Application Data\utorrent
2007-01-16 19:22 -------- d-------- C:\Program\torrent master
2007-01-14 20:02 -------- d-------- C:\DOCUME~1\Andreas\Application Data\mozilla
2007-01-11 17:39 -------- d-------- C:\Program\windows live safety center
2007-01-09 18:23 -------- d-------- C:\Program\fairuse wizard 2
2007-01-05 16:47 -------- d-------- C:\Program\super internet tv
2007-01-05 09:50 -------- d-------- C:\Program\creative
2006-12-31 09:16 -------- d-------- C:\Program\bearshare
2006-12-30 21:43 -------- d---s---- C:\DOCUME~1\Andreas\Application Data\microsoft
2006-12-30 21:41 82380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2006-12-27 12:33 -------- d-------- C:\Program\utero digital media
2006-12-27 11:54 -------- d--h----- C:\Program\installshield installation information
2006-12-25 20:11 43602 --a------ C:\WINDOWS\system32\xvid-uninstall.exe
2006-12-25 20:11 -------- d-------- C:\Program\avisynth 2.5
2006-12-25 11:06 -------- d-------- C:\Program\pc vga camera
2006-12-25 11:06 -------- d-------- C:\Program\Delade filer\pccamera
2006-12-25 10:50 -------- d-------- C:\Program\backburner 2
2006-12-23 09:40 -------- d-------- C:\DOCUME~1\Andreas\Application Data\adobeum
2006-12-22 19:08 -------- d-------- C:\Program\souptoys
2006-12-17 20:27 -------- d-------- C:\Program\scripts
2006-12-17 20:27 -------- d-------- C:\Program\samurize
2006-12-17 20:27 -------- d-------- C:\Program\plugins
2006-12-17 20:27 -------- d-------- C:\Program\pedevice
2006-12-17 20:27 -------- d-------- C:\Program\icons
2006-12-17 20:27 -------- d-------- C:\Program\bitcomet
2006-12-17 20:27 -------- d-------- C:\Program\audacity
2006-12-17 20:27 -------- d-------- C:\DOCUME~1\Andreas\Application Data\shareaza
2006-12-17 10:06 -------- d-------- C:\Program\skins
2006-12-17 10:06 -------- d-------- C:\Program\lang
2006-12-15 18:15 73216 --a------ C:\WINDOWS\st6unst.exe
2006-12-15 18:15 286720 --------- C:\WINDOWS\setup1.exe
2006-12-14 17:39 -------- d-------- C:\Program\k-litepro
2006-12-10 18:26 -------- d-------- C:\Program\messenger plus! live
2006-12-08 13:50 217088 --a------ C:\WINDOWS\system32\xvidvfw.dll
2006-12-08 13:47 1159168 --a------ C:\WINDOWS\system32\xvidcore.dll
2006-12-07 06:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-06 18:31 -------- d-------- C:\Program\xrools
2006-11-24 17:20 43520 --a------ C:\WINDOWS\system32\cmdlineext03.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-03 21:42 8464 --a------ C:\WINDOWS\system32\sporder.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.ex e"
"SweetIM"="C:\\Program\\Macrogaming\\SweetIM\\Swee tIM.exe"
"msnmsgr"="~\"C:\\Program\\MSN Messenger\\msnmsgr.exe\" /background"
"Steam"="\"c:\\program\\steam\\steam.exe\" -silent"
"updateMgr"="\"C:\\Program\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run]
"F-Secure Manager"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\FSGUI\\FSSW.EXE\" /reboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SsAAD.exe"="C:\\Program\\Sony\\SONICS~1\\SsAAD.ex e"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72, 6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b ,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnph ost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2\{85f8ef57-d847-11da-a90a-0013d3c2832e}]
Shell\AutoRun\command N:\setupSNK.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1167516373.job
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 07-01-31 20:39:43
"Andreas" - 07-01-31 20:36:43 Service Pack 2
ComboFix 07.01.31 - Running from: "C:\Documents and Settings\Andreas\Skrivbord"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\SVKP.sys
C:\WINDOWS\system32\drivers\npf.sys
((((((((((((((((((((((((((((((( Files Created from 2006-12-31 to 2007-01-31 ))))))))))))))))))))))))))))))))))
2007-01-31 20:07 <KAT> d-------- C:\WINDOWS\LastGood
2007-01-31 20:07 <KAT> d-------- C:\WINDOWS\BDOSCAN8
2007-01-31 17:02 <KAT> d-------- C:\DOCUME~1\Marcus\Application Data\Skype
2007-01-28 19:05 <KAT> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-01-25 18:16 <KAT> d-------- C:\Dev-Cpp
2007-01-25 00:03 <KAT> d-------- C:\DOCUME~1\Thomas\.freemind
2007-01-25 00:03 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-22 17:05 33,952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-01-22 17:05 <KAT> d-------- C:\Program\Mount&Blade
2007-01-19 20:46 <KAT> d---s---- C:\DOCUME~1\ANN-CH~1\UserData
2007-01-19 20:33 <KAT> d-------- C:\Program\FreeMind
2007-01-19 20:33 <KAT> d-------- C:\DOCUME~1\ANN-CH~1\.freemind
2007-01-19 20:29 <KAT> d-------- C:\Program\Photo Story 3 for Windows
2007-01-19 20:26 <KAT> d-------- C:\Program\Audacity1
2007-01-19 20:24 <KAT> d-------- C:\Program\PhotoFiltre
2007-01-17 15:20 61,088 --a------ C:\WINDOWS\system\TX_HTML.DLL
2007-01-17 15:20 57,984 --a------ C:\WINDOWS\system\QPRO200.DLL
2007-01-17 15:20 53,376 --a------ C:\WINDOWS\system\TXTLS16.DLL
2007-01-17 15:20 50,160 --a------ C:\WINDOWS\system\Ic16.dll
2007-01-17 15:20 44,208 --a------ C:\WINDOWS\system\TX_RTF.DLL
2007-01-17 15:20 398,416 --a------ C:\WINDOWS\system\Vbrun300.dll
2007-01-17 15:20 321,488 --a------ C:\WINDOWS\system\TX16.DLL
2007-01-17 15:20 30,608 --a------ C:\WINDOWS\system\WNDTLS16.DLL
2007-01-17 15:20 26,768 --a------ C:\WINDOWS\system\Ctl3d.dll
2007-01-17 15:20 <KAT> d-------- C:\Program\TOLKEN99
2007-01-16 19:24 36,864 --------- C:\WINDOWS\system32\wbsys.dll
2007-01-16 19:24 20,480 --a------ C:\WINDOWS\system32\wbload.dll
2007-01-16 19:24 <KAT> d-------- C:\Program\Stardock
2007-01-15 22:44 <KAT> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Google
2007-01-15 22:43 <KAT> dr------- C:\DOCUME~1\LOCALS~1\Favoriter
2007-01-15 18:53 <KAT> d-------- C:\WINDOWS\Sys
2007-01-14 20:02 <KAT> d-------- C:\Program\Mozilla Thunderbird
2007-01-14 20:02 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Thunderbird
2007-01-14 20:02 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Talkback
2007-01-12 19:22 <KAT> d-------- C:\Program\HGI
2007-01-12 17:44 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Dev-Cpp
2007-01-05 09:45 319,488 -ra------ C:\WINDOWS\system32\MafiaSetup.exe
2007-01-02 10:29 <KAT> d-------- C:\Program\Delade filer\Skype
2007-01-02 10:29 <KAT> d-------- C:\DOCUME~1\Andreas\Application Data\Skype
2007-01-02 10:29 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Skype
2007-01-02 10:28 <KAT> d-------- C:\Program\Skype
2007-01-01 19:47 <KAT> d-------- C:\DOCUME~1\Thomas\Application Data\Souptoys
2006-12-31 09:07 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2007-01-31 20:10 -------- d-------- C:\Program\steam
2007-01-30 17:04 -------- d-------- C:\Program\satellitetvforpc
2007-01-30 17:04 -------- d-------- C:\Program\project64 1.6
2007-01-21 12:15 -------- d-------- C:\Program\msn messenger
2007-01-20 13:42 -------- d-------- C:\Program\game cam v1.4
2007-01-17 15:15 -------- d-------- C:\DOCUME~1\Andreas\Application Data\utorrent
2007-01-16 19:22 -------- d-------- C:\Program\torrent master
2007-01-14 20:02 -------- d-------- C:\DOCUME~1\Andreas\Application Data\mozilla
2007-01-11 17:39 -------- d-------- C:\Program\windows live safety center
2007-01-09 18:23 -------- d-------- C:\Program\fairuse wizard 2
2007-01-05 16:47 -------- d-------- C:\Program\super internet tv
2007-01-05 09:50 -------- d-------- C:\Program\creative
2006-12-31 09:16 -------- d-------- C:\Program\bearshare
2006-12-30 21:43 -------- d---s---- C:\DOCUME~1\Andreas\Application Data\microsoft
2006-12-30 21:41 82380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2006-12-27 12:33 -------- d-------- C:\Program\utero digital media
2006-12-27 11:54 -------- d--h----- C:\Program\installshield installation information
2006-12-25 20:11 43602 --a------ C:\WINDOWS\system32\xvid-uninstall.exe
2006-12-25 20:11 -------- d-------- C:\Program\avisynth 2.5
2006-12-25 11:06 -------- d-------- C:\Program\pc vga camera
2006-12-25 11:06 -------- d-------- C:\Program\Delade filer\pccamera
2006-12-25 10:50 -------- d-------- C:\Program\backburner 2
2006-12-23 09:40 -------- d-------- C:\DOCUME~1\Andreas\Application Data\adobeum
2006-12-22 19:08 -------- d-------- C:\Program\souptoys
2006-12-17 20:27 -------- d-------- C:\Program\scripts
2006-12-17 20:27 -------- d-------- C:\Program\samurize
2006-12-17 20:27 -------- d-------- C:\Program\plugins
2006-12-17 20:27 -------- d-------- C:\Program\pedevice
2006-12-17 20:27 -------- d-------- C:\Program\icons
2006-12-17 20:27 -------- d-------- C:\Program\bitcomet
2006-12-17 20:27 -------- d-------- C:\Program\audacity
2006-12-17 20:27 -------- d-------- C:\DOCUME~1\Andreas\Application Data\shareaza
2006-12-17 10:06 -------- d-------- C:\Program\skins
2006-12-17 10:06 -------- d-------- C:\Program\lang
2006-12-15 18:15 73216 --a------ C:\WINDOWS\st6unst.exe
2006-12-15 18:15 286720 --------- C:\WINDOWS\setup1.exe
2006-12-14 17:39 -------- d-------- C:\Program\k-litepro
2006-12-10 18:26 -------- d-------- C:\Program\messenger plus! live
2006-12-08 13:50 217088 --a------ C:\WINDOWS\system32\xvidvfw.dll
2006-12-08 13:47 1159168 --a------ C:\WINDOWS\system32\xvidcore.dll
2006-12-07 06:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-06 18:31 -------- d-------- C:\Program\xrools
2006-11-24 17:20 43520 --a------ C:\WINDOWS\system32\cmdlineext03.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-03 21:42 8464 --a------ C:\WINDOWS\system32\sporder.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.ex e"
"SweetIM"="C:\\Program\\Macrogaming\\SweetIM\\Swee tIM.exe"
"msnmsgr"="~\"C:\\Program\\MSN Messenger\\msnmsgr.exe\" /background"
"Steam"="\"c:\\program\\steam\\steam.exe\" -silent"
"updateMgr"="\"C:\\Program\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run]
"F-Secure Manager"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program\\Telia\\Telias Sakerhetstjanster\\FSGUI\\FSSW.EXE\" /reboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SsAAD.exe"="C:\\Program\\Sony\\SONICS~1\\SsAAD.ex e"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72, 6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b ,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnph ost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2\{85f8ef57-d847-11da-a90a-0013d3c2832e}]
Shell\AutoRun\command N:\setupSNK.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1167516373.job
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 07-01-31 20:39:43