[size=9]
herttja - 06-11-29 7:47:57,09 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\herttja\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-10-29 to 2006-11-29 ))))))))))))))))))))))))))))))))))
2006-11-28 08:12 218,112 --a------ C:\HijackThis.exe
2006-11-28 08:12 <DIR> d-------- C:\HiJackThis logit
2006-11-22 13:17 <DIR> d-------- C:\Jalli
2006-11-20 14:44 <DIR> d-------- C:\Documents and Settings\herttja\Application Data\Sonic
2006-11-20 09:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2006-11-20 09:02 <DIR> d-------- C:\661117e5cca75f1f71523510d16f9c
2006-11-14 08:32 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2006-11-14 08:32 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2006-11-14 08:32 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2006-11-10 07:28 <DIR> d-------- C:\Documents and Settings\herttja\WINDOWS
2006-11-04 14:14 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-31 09:53 139,264 --a------ C:\WINDOWS\system32\igfxres.dll
2006-10-31 06:59 <DIR> d--hs---- C:\WINDOWS\ftpcache
2006-10-31 06:58 <DIR> d-------- C:\Documents and Settings\herttja\Application Data\U3
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-28 13:05 -------- d-------- C:\Documents and Settings\herttja\Application Data\AdobeUM
2006-11-27 14:55 264 --a------ C:\WINDOWS\system32\winsusrm.dll
2006-11-27 14:55 -------- d-------- C:\Program Files\EuroTranslator 7.2
2006-11-27 13:01 -------- d-------- C:\Program Files\Mozilla
Firefox
2006-11-27 06:56 5427 --a------ C:\WINDOWS\system32\EGATHDRV.SYS
2006-11-24 12:46 -------- d---s---- C:\Documents and Settings\herttja\Application Data\Microsoft
2006-11-20 09:01 -------- d-------- C:\Program Files\Internet Explorer
2006-10-26 07:07 -------- d-------- C:\Program Files\MSN
2006-10-24 07:11 -------- d-------- C:\Documents and Settings\herttja\Application Data\Mozilla
2006-10-24 07:08 -------- d-------- C:\Program Files\TrojanHunter 4.6
2006-10-24 06:29 -------- d-------- C:\Documents and Settings\herttja\Application Data\TrojanHunter
2006-10-24 06:27 -------- d-------- C:\Program Files\Autodesk
2006-10-24 06:26 -------- d-------- C:\Program Files\Common Files\Autodesk Shared
2006-10-24 06:26 -------- d-------- C:\Program Files\AutoCAD LT 2004
2006-10-17 14:37 -------- d-------- C:\Program Files\F-Secure
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Media Player Classic
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Macromedia
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Leadertech
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Help
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Google
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\F-Secure
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\EPSON
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Downloaded Installations
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Canon
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\BSplayer
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\AutoDWG
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Autodesk
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\ArcSoft
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Ahead
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\Adobe
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\ACDInTouch
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\ACD Systems
2006-10-17 14:21 -------- d-------- C:\Documents and Settings\herttja\Application Data\ABBYY
2006-10-17 14:11 -------- d-------- C:\Program Files\HDD Health
2006-10-16 11:45 -------- d-------- C:\Program Files\Save
2006-10-16 06:04 -------- d-------- C:\Program Files\Google
2006-10-13 14:35 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 14:35 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 14:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 12:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-04 08:34 -------- d-------- C:\Program Files\Index Dat Suite
2006-09-15 12:23 37027 --a------ C:\WINDOWS\atmoUn.exe
2006-09-13 07:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"Mouse Suite 98 Daemon"="ICO.EXE"
"AMSG"="C:\\Program Files\\ThinkVantage\\AMSG\\Amsg.exe"
"LPManager"="C:\\PROGRA~1\\THINKV~1\\PrdCtr\\LPMGR.exe"
"cssauth"="\"C:\\Program Files\\IBM ThinkVantage\\Client Security Solution\\cssauth.exe\" silent"
"PDService.exe"="\"C:\\Program Files\\IBM ThinkVantage\\SafeGuard PrivateDisk\\pdservice.exe\""
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"DiskeeperSystray"="\"C:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"suScheduler"="C:\\Program Files\\ThinkVantage\\SystemUpdate\\UCLauncher.exe /SCHEDULER"
"DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
"ISUSPM Startup"="c:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"F-Secure Manager"="\"C:\\Program Files\\F-Secure\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\F-Secure\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,12,03,00,00,23,00,00,00,dc,00,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 06-11-29 7:50:54.44
C:\ComboFix.txt ... 06-11-29 07:50
[/size]