ComboFix 10-02-11.04 - Niklas 2010-02-12 17:42:44.1.1 - x86Microsoft Windows XP Home Edition 5.1.2600.3.1252.46.1053.18.2047.1575 [GMT 1:00]Körs från: d
documents and settings\Niklas\Mina dokument\Hämtade filer\ComboFix.exeAV: F-Secure Client Security 8.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}FW: F-Secure Client Security 8.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4} * Resident AV is activeVARNINIG -ÅTERSTÄLLNINGSKONSOLEN (THE RECOVERY CONSOLE) ÄR INTE INSTALLERAD PÅ DEN HÄR DATORN !!.(((((((((((((((((((((((( Filer Skapade från 2010-01-12 till 2010-02-12 )))))))))))))))))))))))))))))).2010-02-11 16:14 . 2010-01-07 15:07 38224 ----a-w- c
windows\system32\drivers\mbamswissarmy.sys2010-0
2-11 16:14 . 2010-02-11 16:14 -------- d-----w- c
program\Malwarebytes' Anti-Malware2010-02-11 16:14 . 2010-01-07 15:07 19160 ----a-w- c
windows\system32\drivers\mbam.sys2010-02-11 02:03 . 2010-02-11 02:03 -------- d-sh--w- c
documents and settings\Default User\IETldCache2010-02-08 21:22 . 2010-02-08 21:32 -------- d-----w- c
program\Spybot - Search & Destroy2010-02-05 15:11 . 2010-02-05 15:12 -------- d-----w- c
program\CCleaner2010-02-05 13:55 . 2010-02-05 13:55 -------- d-----w- c
program\Prio2010-02-03 15:53 . 2010-02-11 02:22 -------- d-----w- c
documents and settings\Niklas\Application Data\uTorrent2010-01-31 16:10 . 2010-01-31 16:10 52224 ----a-w- c
documents and settings\Niklas\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS
\SD10005.dll2010-01-31 16:10 . 2010-02-06 09:30 117760 ----a-w- c
documents and settings\Niklas\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS
\UIREPAIR.DLL2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c
documents and settings\All Users\Application Data\SUPERAntiSpyware.com2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c
program\SUPERAntiSpyware2010-01-31 16:07 . 2010-01-31 16:07 -------- d-----w- c
documents and settings\Niklas\Application Data\SUPERAntiSpyware.com2010-01-31 16:06 . 2010-01-31 16:06 -------- d-----w- c
program\Delade filer\Wise Installation Wizard2010-01-31 10:49 . 2010-01-31 10:49 -------- d-----w- c
documents and settings\Niklas\Application Data\Malwarebytes2010-01-31 10:49 . 2010-01-31 10:49 -------- d-----w- c
documents and settings\All Users\Application Data\Malwarebytes2010-01-30 12:52 . 2010-02-09 05:08 -------- d-----w- c
documents and settings\All Users\Application Data\Spybot - Search & Destroy2010-01-29 20:25 . 2010-01-29 20:25 102400 --sha-r- c
windows\system32\dmremote4.dll2010-01-24 10:11 . 2010-01-24 10:11 -------- d-----w- c
documents and settings\LocalService\Skrivbord2010-01-24 09:48 . 2010-02-01 18:41 -------- dc-h--w- c
documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}2010-0
1-24 09:48 . 2009-12-07 14:10 2953352 -c--a-w- c
documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-Aw
areInstallation.exe2010-01-24 09:46 . 2010-02-01 18:40 -------- d-----w- c
program\Lavasoft2010-01-24 09:46 . 2010-02-01 18:40 -------- d-----w- c
documents and settings\All Users\Application Data\Lavasoft.(((((((((((((((((((((((((((((((((((
((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))
)).2010-02-12 16:39 . 2009-09-23 09:05 -------- d-----w- c
documents and settings\Niklas\Application Data\WTablet2010-02-12 16:37 . 2009-09-10 11:07 -------- d-----w- c
documents and settings\LocalService\Application Data\WTablet2010-02-12 16:36 . 2009-08-14 10:04 -------- d-----w- c
documents and settings\Niklas\Application Data\vlc2010-02-12 07:51 . 2009-08-11 22:42 -------- d-----w- c
documents and settings\Niklas\Application Data\U32010-02-12 05:50 . 2009-08-11 23:09 -------- d-----w- c
program\F-Secure2010-02-11 02:22 . 2009-08-14 10:22 -------- d-----w- c
documents and settings\Niklas\Application Data\BitTorrent2010-02-11 02:05 . 2009-09-30 16:54 -------- d-----w- c
documents and settings\All Users\Application Data\Microsoft Help2010-02-10 22:43 . 2009-08-17 18:51 -------- d-----w- c
documents and settings\Niklas\Application Data\dvdcss2010-02-05 15:07 . 2009-12-29 13:05 -------- d-----w- c
program\Delade filer\Apple2010-01-24 14:20 . 2009-10-08 10:46 -------- d-----w- c
program\RegCure2010-01-21 11:33 . 2009-08-12 15:32 -------- d-----w- c
program\Microsoft Silverlight2010-01-16 13:33 . 2009-12-29 13:12 -------- d-----w- c
documents and settings\Niklas\Application Data\Apple Computer2009-12-31 16:50 . 2004-08-04 12:00 353792 ----a-w- c
windows\system32\drivers\srv.sys2009-12-29 14:33 . 2009-09-30 17:05 -------- d-----w- c
program\Microsoft Works2009-12-29 13:15 . 2009-08-15 15:41 -------- d-----w- c
documents and settings\Niklas\Application Data\Spotify2009-12-29 13:11 . 2009-12-29 13:09 -------- d-----w- c
program\iTunes2009-12-29 13:11 . 2009-12-29 13:09 -------- d-----w- c
documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}2009-1
2-29 13:10 . 2009-12-29 13:10 -------- d-----w- c
program\iPod2009-12-29 13:09 . 2009-12-29 13:07 -------- d-----w- c
documents and settings\All Users\Application Data\Apple Computer2009-12-29 13:09 . 2009-12-29 13:09 -------- d-----w- c
program\Bonjour2009-12-29 13:09 . 2009-12-29 13:07 -------- d-----w- c
program\QuickTime2009-12-29 13:07 . 2009-12-29 13:06 -------- d-----w- c
program\Apple Software Update2009-12-29 13:05 . 2009-12-29 13:05 -------- d-----w- c
documents and settings\All Users\Application Data\Apple2009-12-21 19:09 . 2004-08-04 12:00 916480 ----a-w- c
windows\system32\wininet.dll2009-12-21 09:36 . 2009-09-01 19:06 -------- d-----w- c
documents and settings\All Users\Application Data\FLEXnet2009-12-20 22:02 . 2009-12-20 22:02 -------- d-----w- c
program\Delade filer\en-US2009-12-20 22:01 . 2009-12-20 22:01 -------- d-----w- c
program\Delade filer\ja-JP2009-12-20 22:00 . 2009-08-18 16:14 -------- d-----w- c
program\Delade filer\Autodesk Shared2009-12-20 22:00 . 2009-08-18 17:21 -------- d-----w- c
documents and settings\All Users\Application Data\Autodesk2009-12-20 21:54 . 2009-08-18 16:05 -------- d-----w- c
program\Autodesk2009-12-18 15:54 . 2009-11-27 19:14 -------- d-----w- c
program\hl2009-12-17 07:42 . 2009-08-11 21:37 343552 ----a-w- c
windows\system32\mspaint.exe2009-12-14 07:10 . 2004-08-04 12:00 33280 ----a-w- c
windows\system32\csrsrv.dll2009-12-12 06:36 . 2004-08-04 12:00 94678 ----a-w- c
windows\system32\perfc01D.dat2009-12-12 06:36 . 2004-08-04 12:00 474574 ----a-w- c
windows\system32\perfh01D.dat2009-12-09 10:11 . 2004-08-04 01:24 2066816 ----a-w- c
windows\system32
tkrnlpa.exe2009-12-09 10:11 . 2004-08-04 12:00 2189952 ----a-w- c
windows\system32
toskrnl.exe2009-12-04 18:22 . 2004-08-04 12:00 455424 ----a-w- c
windows\system32\drivers\mrxsmb.sys2009-11-27 17:14 . 2004-08-04 12:00 1293824 ----a-w- c
windows\system32\quartz.dll2009-11-27 17:14 . 2004-08-04 01:33 17920 ----a-w- c
windows\system32\msyuv.dll2009-11-27 16:10 . 2004-08-04 12:00 85504 ----a-w- c
windows\system32\avifil32.dll2009-11-27 16:10 . 2004-08-04 12:00 28672 ----a-w- c
windows\system32\msvidc32.dll2009-11-27 16:10 . 2004-08-04 12:00 11264 ----a-w- c
windows\system32\msrle32.dll2009-11-27 16:10 . 2004-08-04 01:33 48128 ----a-w- c
windows\system32\iyuv_32.dll2009-11-27 16:10 . 2001-09-06 20:33 8704 ----a-w- c
windows\system32\tsbyuv.dll2009-11-21 16:03 . 2004-08-04 12:00 471552 ----a-w- c
windows\AppPatch\aclayers.dll2009-05-14 20:02 . 2009-05-14 20:02 3392872 ----a-w- c
program\Delade filer\adlmint_libFNP.dll2009-05-14 20:02 . 2009-05-14 20:02 3298152 ----a-w- c
program\Delade filer\adlmint.dll.(((((((((((((((((((((((((((((((
((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))..
*Not* Tomma poster & legitima standardposter visas inte. REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Win
dows\CurrentVersion\Run]"msnmsgr"="c
program\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]"MSMSGS"="c
program\Messenger\msmsgs.exe" [2008-04-14 1695232]"SUPERAntiSpyware"="c
program\SUPERAntiSpywar
e\SUPERAntiSpyware.exe" [2010-01-05 2002160]"SpybotSD TeaTimer"="c
program\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi
ndows\CurrentVersion\Run]"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]"SunJavaUpdateSched"="c
program\Java\jre1.5.0\b
in\jusched.exe" [2009-08-11 36972]"SynTPLpr"="c
program\Synaptics\SynTP\SynTPLpr.
exe" [2005-03-18 98393]"SynTPEnh"="c
program\Synaptics\SynTP\SynTPEnh.
exe" [2005-03-18 688217]"NvCplDaemon"="c
windows\system32\NvCpl.dll" [2005-07-01 7118848]"nwiz"="nwiz.exe" [2005-07-01 1519616]"F-Secure Manager"="c
program\F-Secure\Common\FSM32.EXE" [2008-10-09 182936]"F-Secure TNB"="c
program\F-Secure\FSGUI\TNBUtil.exe" [2008-10-09 1182304]"InstantOn"="c
program\CyberLink\PowerCinema Linux\ion_install.exe" [2005-05-11 93640]"SoundMan"="SOUNDMAN.EXE" [2009-08-11 90112]"AlcWzrd"="ALCWZRD.EXE" [2009-08-11 2803712]"DAEMON Tools"="c
program\DAEMON Tools\daemon.exe" [2005-11-08 128920]"Adobe Reader Speed Launcher"="c
program\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]"AdobeCS4ServiceManager"="c
program\Delade filer\Adobe\CS4ServiceManager\CS4ServiceManager.e
xe" [2008-08-14 611712]"GrooveMonitor"="c
program\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]"QuickTime Task"="c
program\QuickTime\QTTask.exe" [2009-11-10 417792]"iTunesHelper"="c
program\iTunes\iTunesHelper.
exe" [2009-11-12 141600]c
documents and settings\Niklas\Start-meny\Program\Autostart\Telia Mobilt bredband.lnk - c
program\Telia\Telia_Mobilt_bredband\Telia_Mobilt
_bredband.exe [2009-5-14 2050048]c
documents and settings\All Users\Start-meny\Program\Autostart\Windows Desktop Search.lnk - c
program\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784][hkey_local_machine\software\microsoft\win
dows\currentversion\explorer\ShellExecuteHooks]"{5
6F9679E-7826-4C84-81F3-532071A8BCC5}"= "c
program\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400][HKEY_LOCAL_MACHINE\software\microsoft\win
dows nt\currentversion\winlogon
otify\!SASWinLogon]2009-09-03 13:21 548352 ----a-w- c
program\SUPERAntiSpyware\SASWINLO.dll[HKLM\~\ser
vices\sharedaccess\parameters\firewallpolicy\stan
dardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\fir
ewallpolicy\standardprofile\AuthorizedApplication
s\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\
Network Diagnostic\\xpnetdiag.exe"="c
\Program\\BitTorrent\\
bittorrent.exe"="c
\Program\\Spotify\\spotify.exe"="c
\
Program\\Delade filer\\Adobe\\CS4ServiceManager\\CS4ServiceManage
r.exe"="c
\Program\\Microsoft Office\\Office12\\OUTLOOK.EXE"="c
\Program\\Microsoft Office\\Office12\\GROOVE.EXE"="c
\Program\\Microsoft Office\\Office12\\ONENOTE.EXE"="c
\Program\\Windows Live\\Messenger\\msnmsgr.exe"="c
\Program\\Messenger
\\msmsgs.exe"="c
\Program\\Bonjour\\mDNSResponder.exe"
;="c
\Program\\iTunes\\iTunes.exe"=[HKLM\~\services\
sharedaccess\parameters\firewallpolicy\standardpr
ofile\GloballyOpenPorts\List]"5353:TCP"= 5353:TCP:Adobe CSI CS4R0 fsbts;fsbts;c
windows\system32\drivers\fsbts.sys [2009-08-12 33920]R0 FSFW;F-Secure Firewall Driver;c
windows\system32\drivers\fsdfw.sys [2009-08-12 79872]R1 F-Secure HIPS;F-Secure HIPS Driver;c
program\F-Secure\HIPS\drivers\fshs.sys [2009-08-12 66720]R1 prio;Prio;c
windows\system32\drivers\prio.sys [2009-09-12 51448]R1 SASDIFSV;SASDIFSV;c
program\SUPERAntiSpyware\sasdi
fsv.sys [2010-01-05 9968]R1 SASKUTIL;SASKUTIL;c
program\SUPERAntiSpyware\SASKU
TIL.SYS [2010-01-05 74480]R2 TabletServicePen;TabletServicePen;c
windows\system
32\Pen_Tablet.exe [2009-09-07 2749736]R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c
program\F-Secure\Anti-Virus\minifilte
r\fsgk.sys [2009-08-12 107104]R3 FSORSPClient;F-Secure ORSP Client;c
program\F-Secure\ORSP Client\fsorsp.exe [2009-08-12 55904]R3 GTUHSBUS;GT UHS BUS;c
windows\system32\drivers\gtuhsbus.sys [2009-02-04 63360]R3 GTUHSNDISIPXP;GT UHS IP NDIS;c
windows\system32\drivers\gtuhs51.sys [2009-02-04 105856]R3 GTUHSSER;GT UHS SER;c
windows\system32\drivers\gtuhsser.sys [2009-02-04 8064]S0 sptd;sptd;c
windows\system32\drivers\sptd.sys [2009-08-15 722416]S3 SASENUM;SASENUM;c
program\SUPERAntiSpyware\SASENUM
.SYS [2010-01-05 7408]S3 wacmoumonitor;Wacom Mode Helper;c
windows\system32\drivers\wacmoumonitor.sys [2009-09-07 15656]S4 F-Secure Filter;F-Secure File System Filter;c
program\F-Secure\Anti-Virus\win2k\fsfilte
r.sys [2009-08-12 39776]S4 F-Secure Recognizer;F-Secure File System Recognizer;c
program\F-Secure\Anti-Virus\win2k\fsr
ec.sys [2009-08-12 25184].Innehållet i mappen 'Schemalagda aktiviteter':2010-02-12 c
windows\Tasks\RegCure Program Check.job- c
program\RegCure\RegCure.exe [2007-08-02 10:47]2010-02-11 c
windows\Tasks\RegCure.job- c
program\RegCure\RegCure.exe [2007-08-02 10:47]2010-02-12 c
windows\Tasks\User_Feed_Synchronization-{60A1D85
5-5A76-43B9-BC63-90C246284B64}.job- c
windows\system32\msfeedssync.exe [2009-03-08 02:31]..------- Extra genomsökning -------.uInternet Settings,ProxyOverride = *.localIE: E&xportera till Microsoft Excel - c
program\MI1933~1\Office12\EXCEL.EXE/3000LSP: c
program\F-Secure\FSPS\program\FSLSP.DLLFF - ProfilePath - c
documents and settings\Niklas\Application Data\Mozilla\Firefox\Profiles\58r3wf7s.default\FF - plugin: c
program\Java\jre1.5.0\bin\NPJava11.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPJava12.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPJava13.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPJava14.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPJava32.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPJPI150.dllFF - plugin: c
program\Java\jre1.5.0\bin\NPOJI610.dllFF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c
windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\---- FIREFOX POLICY ----c
program\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");.- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-E
BB7F4A000DA} - (no file)AddRemove-uTorrent - j
utorrent\uTorrent.exe***************************
***********************************************ca
tchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2010-02-12 17:50Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0************************************************
**************************.--------------------- LÅSTA REGISTERNYCKLAR ---------------------[HKEY_USERS\S-1-5-21-5159678
99-57989841-725345543-1005\Software\SecuROM\Licen
se information*]"datasecu"=hex:7d,46,98,21,d2,9b,cf,67
,ea,a2,25,8f,d0,5d,81,78,8a,3a,1d,65,5e, 18,8a,44,84,78,b4,3a,a1,dd,21,dd,37,9a,b5,58,ee,d
9,fb,3c,c4,42,81,e5,60,6c,\"rkeysecu"=hex:0f,fd,de,
2d,9d,a4,40,47,ce,d7,91,d6,db,c1,e1,f9.----------
----------- DLLer som "laddats" under processer som körs ---------------------- - - - - - - > 'winlogon.exe'
80
c
program\SUPERAntiSpyware\SA
SWINLO.dllc
program\Delade filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll- - - - - - - > 'lsass.exe'
864)c
program\F-Secure\FSPS\progra
m\FSLSP.DLL.Sluttid: 2010-02-12 17:54:58ComboFix-quarantined-files.txt 2010-02-12 16:54Före genomsökningen: 6 555 267 072 byte ledigtEfter genomsökningen: 6 580 432 896 byte ledigt- - End Of File - - F3B0241290D57A6218408A57DE6FAE94här är den loggen: