First log
Here we go... have to make two replies, cause the text was too long... First log first:
"siri" - 2007-07-27 11:01:08 [GMT 2:00] - ComboFix 07-07-24 - Service Pack 2 NTFS
ADS removed - system32: Prosessen får ikke tilgang til filen fordi den brukes av en annen prosess.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\siri\MINEDO~1.\mbols~1
C:\DOCUME~1\siri\MINEDO~1.\mbols~1\ping.exe
C:\WINDOWS\racle~1
C:\WINDOWS\racle~1\?ervices.exe
C:\WINDOWS\system32\mrcdigz.dll
C:\WINDOWS\system32\rundll.exe
C:\WINDOWS\system32\wcpsvcc32.exe
C:\WINDOWS\system32\x64
C:\WINDOWS\wr.txt
((((((((((((((((((((((((( Files Created from 2007-06-27 to 2007-07-27 )))))))))))))))))))))))))))))))
2007-07-27 11:00 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-26 20:04 <DIR> d-------- C:\Programfiler\Trend Micro
2007-07-26 16:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Spybot - Search & Destroy
2007-07-26 13:26 <DIR> d-------- C:\IDE
2007-07-23 12:59 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Start-meny
2007-07-23 12:53 19,000 --a------ C:\WINDOWS\system32\drivers\nvcw32mf.sys
2007-07-23 12:52 <DIR> d-------- C:\Norman
2007-07-23 12:37 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-07-20 21:41 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\WinRAR
2007-07-19 21:47 <DIR> d-------- C:\Programfiler\Windows Live Safety Center
2007-07-19 18:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\FLEXnet
2007-07-19 17:15 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Azureus
2007-07-19 17:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Azureus
2007-07-18 20:39 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-07-18 16:53 <DIR> d-------- C:\Programfiler\Fellesfiler\Macromedia Shared
2007-07-18 16:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Macrovision
2007-07-17 22:09 <DIR> d-------- C:\Programfiler\Shockwave.com
2007-07-17 22:09 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\PlayFirst
2007-07-17 22:02 <DIR> d-------- C:\Programfiler\Onlinebandit-no
2007-07-17 20:10 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Sonic
2007-07-17 20:10 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Leadertech
2007-07-17 18:29 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\SPAMfighter
2007-07-17 18:28 <DIR> d-------- C:\Programfiler\SPAMfighter
2007-07-17 18:28 <DIR> d-------- C:\Programfiler\Fellesfiler\Application
2007-07-17 18:28 <DIR> d-------- C:\Programfiler\Fellesfiler\Ankiro
2007-07-17 11:58 <DIR> d-------- C:\Programfiler\poEdit
2007-07-17 10:27 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\XLAB ISL Plugins
2007-07-17 10:26 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\XLAB ISL Light Client3
2007-07-17 09:55 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Windows Desktop Search
2007-07-17 09:52 <DIR> d-------- C:\Programfiler\Windows Desktop Search
2007-07-16 22:32 <DIR> d-------- C:\Programfiler\Skype
2007-07-16 22:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Skype
2007-07-16 22:32 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Skype
2007-07-16 22:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Skype
2007-07-16 22:21 <DIR> d-------- C:\Musikk
2007-07-16 22:20 <DIR> d-------- C:\Videoer
2007-07-16 21:40 <DIR> d-------- C:\Programfiler\MSXML 6.0
2007-07-16 21:40 <DIR> d-------- C:\Programfiler\Microsoft CAPICOM 2.1.0.2
2007-07-16 21:34 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-07-16 21:33 <DIR> d-------- C:\Programfiler\Reference Assemblies
2007-07-16 21:32 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-07-16 21:32 <DIR> d-------- C:\b9fba9cf63f1bc46379d
2007-07-16 21:30 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-07-16 21:30 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-07-16 21:29 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-07-16 20:41 <DIR> d-------- C:\Programfiler\Microsoft Virtual PC
2007-07-16 20:37 <DIR> d-------- C:\DOCUME~1\siri\Contacts
2007-07-16 20:34 <DIR> d-------- C:\Programfiler\MSN Messenger
2007-07-16 20:26 <DIR> d-------- C:\Programfiler\XLAB ISL Boot
2007-07-16 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-16 20:19 208,248 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-16 20:12 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-07-16 20:12 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-07-16 20:12 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2007-07-16 20:12 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2007-07-16 20:12 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-07-16 20:11 91,177 -ra------ C:\WINDOWS\system32\drivers\P1131Vid.sys
2007-07-16 20:11 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-07-16 20:11 81,920 -ra------ C:\WINDOWS\CtDrvIns.exe
2007-07-16 20:11 69,632 -ra------ C:\WINDOWS\system32\P1131Sti.dll
2007-07-16 20:11 65,536 -ra------ C:\WINDOWS\system32\CtCamMgr.dll
2007-07-16 20:11 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-07-16 20:11 49,152 -ra------ C:\WINDOWS\system32\P1131Hwx.dll
2007-07-16 20:11 36,864 -ra------ C:\WINDOWS\system32\P1131Pin.dll
2007-07-16 20:11 20,480 -ra------ C:\WINDOWS\system32\P1131Srv.exe
2007-07-16 20:11 20,480 -ra------ C:\WINDOWS\P1131Cfg.exe
2007-07-16 20:11 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-07-16 20:11 126,976 -ra------ C:\WINDOWS\system32\P1131Vfw.dll
2007-07-16 20:06 <DIR> d-------- C:\Programfiler\Creative
2007-07-16 19:52 61,598 --a------ C:\WINDOWS\system32\EBPMON2.DLL
2007-07-16 19:52 57,344 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2007-07-16 19:52 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2007-07-16 19:52 145 --a------ C:\WINDOWS\system32\EBPPORT.DAT
2007-07-16 19:52 <DIR> d-------- C:\Programfiler\EPSON
2007-07-16 19:52 <DIR> d-------- C:\EPSON
2007-07-16 19:46 30,512 --a------ C:\WINDOWS\system32\mdimon.dll
2007-07-16 19:43 <DIR> d-------- C:\Programfiler\MSBuild
2007-07-16 19:43 <DIR> d-------- C:\Programfiler\Microsoft Works
2007-07-16 19:41 <DIR> d-------- C:\Programfiler\Microsoft.NET
2007-07-16 19:38 <DIR> d-------- C:\Programfiler\Zoom Player
2007-07-16 19:38 <DIR> d-------- C:\Programfiler\ws_ftp32
2007-07-16 19:38 <DIR> d-------- C:\Programfiler\Microsoft Visual Studio 8
2007-07-16 19:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-07-16 19:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Microsoft Help
2007-07-16 19:35 <DIR> dr-h----- C:\MSOCache
2007-07-16 19:34 <DIR> d-------- C:\Programfiler\kodak
2007-07-16 19:32 <DIR> d-------- C:\office
2007-07-16 19:28 <DIR> d-------- C:\Programfiler\clue
2007-07-16 19:14 <DIR> d-------- C:\DOCUME~1\siri\PROGRA~1\Google
2007-07-16 19:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\PROGRA~1\Google
2007-07-16 19:13 <DIR> d-------- C:\Programfiler\Google
2007-07-16 19:11 <DIR> d-------- C:\WINDOWS\Cache
2007-07-16 18:57 <DIR> d-------- C:\Programfiler\MSXML 4.0
2007-07-16 18:56 <DIR> d-------- C:\DOCUME~1\siri\hob_jportal
2007-07-16 18:48 <DIR> dr------- C:\DOCUME~1\siri\Favoritter
2007-07-16 18:46 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-07-16 18:46 <DIR> d-------- C:\Programfiler\TotalCmd
2007-07-16 18:43 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-16 18:43 <DIR> d-------- C:\Programfiler\Windows Live Toolbar
2007-07-16 18:42 3,407,872 --ah----- C:\DOCUME~1\siri\NTUSER.DAT
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-17 07:52:43 88,126 ----a-w C:\WINDOWS\system32\perfc014.dat
2007-07-17 07:52:43 462,998 ----a-w C:\WINDOWS\system32\perfh014.dat
2007-07-16 16:43:30 50 ----a-w C:\WINDOWS\system32\drivers\LENOVO_9265_7HG.MRK
2007-06-27 10:12:30 17,280 ----a-w C:\WINDOWS\system32\drivers\psadd.sys
2007-05-16 15:19:43 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Snarvei til egenskapsside for High Definition Audio"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe]
"Mouse Suite 98 Daemon"="ICO.EXE" [2005-04-13 14:34 C:\WINDOWS\system32\ico.exe]
"SoundMAXPnP"="C:\Programfiler\Analog Devices\Core\smax4pnp.exe" [2006-12-18 15:34]
"SoundMAX"="C:\Programfiler\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 07:12]
"AMSG"="C:\Programfiler\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 08:23]
"LPManager"="C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-03-22 18:10]
"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"ISUSPM Startup"="C:\PROGRA~1\FELLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"AwaySch"="C:\Programfiler\Lenovo\AwayTask\AwaySch.EXE" [2006-04-18 19:05]
"TVT Scheduler Proxy"="C:\Programfiler\Fellesfiler\Lenovo\Scheduler\scheduler_proxy.exe" [2006-03-28 04:01]
"DiskeeperSystray"="C:\Programfiler\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 16:24]
"Picasa Media Detector"="C:\Programfiler\Picasa2\PicasaMediaDetector.exe" [2005-10-28 20:08]
"cssauth"="C:\Programfiler\Lenovo\Client Security Solution\cssauth.exe" [2006-05-12 20:15]
"Adobe Photo Downloader"="C:\Programfiler\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SPAMfighter Agent"="C:\Programfiler\SPAMfighter\SFAgent.exe" [2007-07-04 14:22]
"Norman ZANDA"="C:\Norman\Npm\bin\ZLH.exe" [2007-04-27 14:02]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 18:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00]
"Rcwl"="C:\DOCUME~1\siri\MINEDO~1\MBOLS~1\ping.exe" []
"Kjo"="C:\WINDOWS\?racle\?ervices.exe" []
"WMPNSCFG"="C:\Programfiler\Windows Media Player\WMPNSCFG.exe" [2006-11-15 10:46]
C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\
PC-s›k i Windows.lnk - C:\Programfiler\Windows Desktop Search\WindowsSearch.exe [2007-02-05 15:40:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Programfiler\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
C:\Programfiler\Lenovo\AwayTask\AwayNotify.dll 2006-04-18 19:05 49152 C:\Programfiler\Lenovo\AwayTask\AwayNotify.dll
R1 DLACDBHM;DLACDBHM;C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
R1 DLARTL_N;DLARTL_N;C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
R1 vmm;Virtual Machine Monitor;\??\C:\WINDOWS\system32\Drivers\vmm.sys
R2 DLABOIOM;DLABOIOM;C:\WINDOWS\system32\DLA\DLABOIOM.SYS
R2 DLADResN;DLADResN;C:\WINDOWS\system32\DLA\DLADResN.SYS
R2 DLAIFS_M;DLAIFS_M;C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
R2 DLAOPIOM;DLAOPIOM;C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
R2 DLAPoolM;DLAPoolM;C:\WINDOWS\system32\DLA\DLAPoolM.SYS
R2 DLAUDF_M;DLAUDF_M;C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
R2 DLAUDFAM;DLAUDFAM;C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
R2 DRVNDDM;DRVNDDM;C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
R2 EGATHDRV;IBM eGatherer;\??\C:\WINDOWS\SYSTEM32\EGATHDRV.SYS
R2 eLoggerSvc6;Norman eLogger service 6;C:\Norman\Npm\bin\ELOGSVC.EXE
R2 Ndiskio;Ndiskio;\??\C:\Norman\Nse\bin\NDISKIO.SYS
R2 pmem;pmem;\??\C:\WINDOWS\System32\drivers\pmemnt.sys
R2 PROCDD;IPS Helper Driver;C:\WINDOWS\system32\DRIVERS\PROCDD.SYS
R2 smi2;smi2;\??\C:\Programfiler\SMI2\smi2.sys
R2 tvtfilter;tvtfilter;\??\C:\WINDOWS\system32\drivers\tvtfilter.sys
R2 WSearch;Windows Search;C:\WINDOWS\system32\SearchIndexer.exe /Embedding
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service;C:\WINDOWS\system32\drivers\ADIHdAud.sys
R3 HidUsb;Microsoft HID-klassedriver;C:\WINDOWS\system32\DRIVERS\hidusb.sys
R3 Iviaspi;IVI ASPI Shell;C:\WINDOWS\system32\drivers\iviaspi.sys
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys
R3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Norman\Nvc\BIN\NVCSCHED.EXE
R3 P1131VID;Creative WebCam NX Pro (WDM);C:\WINDOWS\system32\DRIVERS\P1131Vid.sys
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
R3 TVTPktFilter;TVT Packet Filter Service;C:\WINDOWS\system32\DRIVERS\tvtpktfilter.sys
R3 usbehci;Miniportdriver for Microsoft USB 2.0 forbedret vertskontroller;C:\WINDOWS\system32\DRIVERS\usbehci.sys
R3 usbhub;USB2 aktivert hub;C:\WINDOWS\system32\DRIVERS\usbhub.sys
R3 usbuhci;Miniportdriver for Microsoft USB universell vertskontroller;C:\WINDOWS\system32\DRIVERS\usbuhci.sys
R3 VPCNetS2;Virtual Machine Network Services Driver;C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys
S3 E100B;Intel(R) PRO-kortdriver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 G400;G400;C:\WINDOWS\system32\DRIVERS\G400m.sys
S3 HdAudAddService;Microsoft UAA-funksjonsdriver for High Definition Audio-tjenesten;C:\WINDOWS\system32\drivers\HdAudio.sys
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 odserv;Microsoft Office Diagnostics Service;"C:\Programfiler\Fellesfiler\Microsoft Shared\OFFICE12\ODSERV.EXE"
S3 psadd;IBM PSA Access Driver;\??\C:\WINDOWS\system32\Drivers\psadd.sys
S3 USBSTOR;USB-masselagringsenhet;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S4 agpCPQ;Compaq AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
S4 iaStor;Intel AHCI Controller;C:\WINDOWS\system32\DRIVERS\iaStor.sys
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
S4 viaagp;VIA AGP-bussfilter;C:\WINDOWS\system32\DRIVERS\viaagp.sys
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{30694BC6-D358-E7AA-6E3C-B1F92934E8AB}
C:\WINDOWS\system32:win32.exe
Contents of the 'Scheduled Tasks' folder
2007-07-26 20:34:01 C:\WINDOWS\tasks\Se etter oppdateringer for Windows Live Toolbar.job
2007-07-26 12:36:18 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-27 11:06:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000051f
scanning hidden files ...
C:\WINDOWS\system32:win32.exe 189776 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\viaagp]
"ImagePath"="\SystemRoot\system32\DRIVERS\viaagp.sys"
Completion time: 2007-07-27 11:07:19
C:\ComboFix-quarantined-files.txt ... 2007-07-27 11:06
--- E O F ---