Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Trojan Bho.cvx


  • This topic is locked This topic is locked
7 replies to this topic

#1 F16GEA

F16GEA

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 16 December 2007 - 05:56 PM

Hi there.
As said I've already been fighting this battle for a couple of days now (See also: My BHO.CVX topic in "Am I infected? What to do?"). One of the tools used (KillBox) has managed to remove one of the 2 infected files but the original one is still there.

I've done the preparation for HJT as described less point 3 and 8. Point 3 simply didn't work. The computer seemed to not react properly on it as it took ages without anything really happening (However, I ran ATF Cleaner while getting help through the other topic. Perhaps this did the job?). Point 8: Well, don't ask why.

Anyway, it was my AVG that first discovered the problem by giving me this popup:
Threat detected. dmusico.dll
Trojan identified as BHO.CVX


Later on I also got this popup:
Threat detected. d3dpmesho.dll
Virus identified as Packed.morphine.d


The latter of the two has, as said, been succesfully deleted by KillBox.
Both those 2 dll files located at C:\WINDOWS\System32\

Another file, which none of the Anti Virus programmes picked up, d3dpmesho.dll.bak was also found in the same folder and I made KillBox erase it as I assumed was coonected to d3dpmesho.dll

Anyway, here's the log from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:35:02, on 16-12-2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Saitek\Software\Profiler.exe
C:\Programmer\Saitek\Software\SaiSmart.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
G:\Programmer\Daemon\DAEMON Tools\daemon.exe
C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\VIA\RAID\raid_tool.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jetfighters.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - g:\programmer\AdobeWriter\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {AA15CEBF-12A5-447A-8C30-729824F2A9D8} - c:\windows\system32\d3dpmesho.dll (file missing)
O2 - BHO: (no name) - {C330E39F-852B-43DD-9510-C66ADD0E82BE} - C:\WINDOWS\System32\dmusico.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Profiler] C:\Programmer\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Programmer\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\System32\rpcc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "G:\Programmer\Daemon\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Programmer\Acrobat\Reader\reader_sl.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmer\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MS-FRO~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {31150A86-0BBA-409F-BEB4-F3922D10BF34} (Gif89 Class) - http://www.f-f-f.dk/webcam/xplug.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe
O20 - Winlogon Notify: !SASWinLogon - G:\Programmer\SUPERAntispyware\SASWINLO.dll
O20 - Winlogon Notify: wgvlxfkx - d3dpmesho.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7762 bytes



Hope you guys can help.
Best regards
F16GEA

Edited by F16GEA, 16 December 2007 - 08:21 PM.


BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 08:24 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum F16GEA
My name is Richie and i'll be helping you to fix your problems.

Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.



If you have previously downloaded ComboFix,please delete that version now.
Warning
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert,not for private use.
Using this tool incorrectly could render your system/pc inoperable.

Now download Combofix and save to your desktop:
Note
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 F16GEA

F16GEA
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 09:57 AM

Hey Richie.
Thanks for your help. I did as you said, however it seems like the infected file is still there. After that I ran Combofix and was about to save the txt file, AVG gave me the popup that I always get (dmusico.dll / Trojan BHO.CVX)
Anyway, here are the reports:
SDFix:

SDFix: Version 1.118

Run by Stephen on 17-12-2007 at 15:35

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found





Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-17 15:39:58
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

IPC error: 2 Den angivne fil blev ikke fundet.
scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:c3d08f62
"s2"=dword:227a5a3b
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="G:\Programmer\Daemon\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:c0,8c,7b,e0,56,79,b5,fc,75,82,d7,34,e8,a1,81,ea,2b,fb,17,8e,ea,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,e7,c4,7f,c3,fc,a6,b0,65,fb,bb,f0,ae,39,e7,65,a5,f9,..
"khjeh"=hex:f0,31,1b,70,58,0f,ab,5a,e2,e8,01,20,c4,44,4b,76,f2,bc,89,16,1a,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:53,a6,a1,69,94,e4,cc,8b,e1,a2,2c,55,67,e1,a4,68,6a,27,5f,4d,ca,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="G:\Programmer\Daemon\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:c0,8c,7b,e0,56,79,b5,fc,75,82,d7,34,e8,a1,81,ea,2b,fb,17,8e,ea,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,e7,c4,7f,c3,fc,a6,b0,65,fb,bb,f0,ae,39,e7,65,a5,f9,..
"khjeh"=hex:f0,31,1b,70,58,0f,ab,5a,e2,e8,01,20,c4,44,4b,76,f2,bc,89,16,1a,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:53,a6,a1,69,94,e4,cc,8b,e1,a2,2c,55,67,e1,a4,68,6a,27,5f,4d,ca,..

scanning hidden registry entries ...

scanning hidden files ...

C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\mondo16@hotmail.com\DFSR\Staging\CS{93C99396-667D-648D-486B-1879B66E60DB}\01\59-{93C99396-667D-648D-486B-1879B66E60DB}-v1-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\01\10-{90B20D63-909A-2F48-C5B1-E7EB9985EA85}-v1-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\11\11-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v11-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\12\12-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v12-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\13\16-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v13-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 642 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\13\16-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v13-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 88 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\14\17-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v14-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5538 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\14\17-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v14-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 624 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\15\18-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v15-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1254 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\15\18-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v15-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\19\19-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v19-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2370 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\19\19-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v19-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 272 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\20\20-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v20-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\22\22-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v22-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1902 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\22\22-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v22-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 208 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\23\23-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v23-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1632 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\23\23-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v23-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 176 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\24\24-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v24-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6096 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\24\24-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v24-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 672 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\25\25-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v25-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\26\26-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v26-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1704 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\26\26-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v26-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 200 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\29\29-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v29-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 696 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\29\29-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v29-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\31\31-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v31-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 894 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\31\31-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v31-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 104 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\36\36-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v36-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\37\37-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v37-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 876 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\37\37-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v37-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 104 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\38\38-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v38-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3756 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\38\38-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v38-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\39\39-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v39-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2334 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\39\39-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v39-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 256 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\41\41-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v41-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4008 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\41\41-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v41-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 448 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\42\42-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v42-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3846 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\42\42-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v42-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 432 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\43\43-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v43-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4872 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\43\43-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v43-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 552 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\44\44-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v44-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5196 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\44\44-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v44-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 576 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\45\45-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v45-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 714 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\45\45-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v45-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\46\46-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v46-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v46-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4080 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\46\46-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v46-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v46-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 448 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\47\47-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v47-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3954 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\47\47-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v47-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 448 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\48\48-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v48-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3774 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\48\48-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v48-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\49\49-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v49-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4134 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\49\49-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v49-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\50\50-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v50-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4800 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\50\50-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v50-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 528 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\51\51-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v51-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4206 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\51\51-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v51-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\52\52-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v52-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4026 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\52\52-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v52-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\53\53-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v53-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1974 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\53\53-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v53-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 232 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\54\54-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v54-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4206 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\54\54-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v54-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 456 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\55\55-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v55-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3774 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\55\55-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v55-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\56\56-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v56-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3756 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\m_halfer@msn.com\DFSR\Staging\CS{90B20D63-909A-2F48-C5B1-E7EB9985EA85}\56\56-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v56-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 408 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\01\58-{607F04EC-5F70-1A46-2FA1-68CBEE455A96}-v1-{95B1BD6E-BE92-4AFD-B80D-A9EA0A5A7C74}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\12\1112-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1112-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 176 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\13\1113-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1113-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1113-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 144 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\14\1114-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1114-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1114-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 184 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\15\1115-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1115-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1115-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 560 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\16\1116-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1116-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 240 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\17\1117-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1117-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1117-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 232 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\18\1118-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1118-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 240 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\19\1119-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1119-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1119-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 192 bytes hidden from API
C:\Documents and Settings\Stephen\Lokale indstillinger\Application Data\Microsoft\Messenger\lowpass_stephen@hotmail.com\SharingMetadata\subria9h30@hotmail.com\DFSR\Staging\CS{607F04EC-5F70-1A46-2FA1-68CBEE455A96}\20\1120-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1120-{DE866CDA-760E-4CC5-A4D1-4F470D90BBD3}-v1120-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 144 bytes hidden from API

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 75


Remaining Services:
------------------



Authorized Application Key Export:

Remaining Files:
---------------


Files with Hidden Attributes:

Fri 4 Aug 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 14 Mar 2005 299,008 A..H. --- "C:\Programmer\Canon\MP Navigator 2.0\Maint.exe"
Mon 28 Feb 2005 61,440 A..H. --- "C:\Programmer\Canon\MP Navigator 2.0\uinstrsc.dll"
Sat 13 Nov 2004 37,376 ...H. --- "C:\Programmer\F‘lles filer\Adobe\ESD\DLMCleanup.exe"
Fri 4 Aug 2006 4,348 ...H. --- "C:\Documents and Settings\Stephen\Dokumenter\Musik\Sikkerhedskopiering af licenser\drmv1key.bak"
Sun 18 Nov 2007 20 A..H. --- "C:\Documents and Settings\Stephen\Dokumenter\Musik\Sikkerhedskopiering af licenser\drmv1lic.bak"
Fri 4 Aug 2006 400 A.SH. --- "C:\Documents and Settings\Stephen\Dokumenter\Musik\Sikkerhedskopiering af licenser\drmv2key.bak"

Finished!


Combofix:

ComboFix 07-12-16.4 - Stephen 2007-12-17 15:45:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1030.18.666 [GMT 1:00]
Running from: C:\Documents and Settings\Stephen\Skrivebord\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-17 to 2007-12-17 )))))))))))))))))))))))))))))))
.

2007-12-17 15:35 . 2007-12-17 15:35 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-16 23:34 . 2007-12-16 23:34 <DIR> d-------- C:\Programmer\Trend Micro
2007-12-16 17:05 . 2007-12-16 17:22 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-12-16 17:05 . 2007-12-16 17:05 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2007-12-16 17:05 . 2007-12-16 17:05 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2007-12-16 17:05 . 2007-12-16 17:05 1,406 --a------ C:\WINDOWS\system32\Help.ico
2007-12-16 17:00 . 2007-12-16 17:32 <DIR> d-------- C:\Documents and Settings\Stephen\.housecall6.6
2007-12-16 14:59 . 2007-12-16 16:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-15 13:20 . 2007-12-15 13:42 <DIR> d-------- C:\Programmer\EsetOnlineScanner
2007-12-15 12:45 . 2007-12-15 13:52 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-12-14 20:44 . 2007-12-14 20:44 <DIR> d-------- C:\Documents and Settings\Stephen\Application Data\SUPERAntiSpyware.com
2007-12-14 20:44 . 2007-12-14 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-14 20:43 . 2007-12-14 20:43 <DIR> d-------- C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-14 20:06 . 2007-12-14 20:06 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-12-14 20:06 . 2007-12-14 20:06 741,632 --a------ C:\WINDOWS\system32\wgzqsmpc.dat
2007-12-14 20:06 . 2007-12-14 20:06 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-12-14 20:06 . 2007-12-14 20:06 42,240 --a------ C:\WINDOWS\system32\zuzcgpxs.dat
2007-12-14 20:06 . 2007-12-14 20:06 36,096 --a------ C:\WINDOWS\system32\jmtzofve.dat
2007-12-14 20:06 . 2007-12-14 20:06 35,072 --a------ C:\WINDOWS\system32\tqtrwisg.dat
2007-12-13 01:10 . 2007-12-13 01:10 119,552 --a------ C:\WINDOWS\system32\jzsyexfj.dat
2007-12-13 01:03 . 2004-07-09 04:27 84,992 --a------ C:\WINDOWS\system32\dmusico.dll
2007-12-13 01:03 . 19,456 C:\WINDOWS\system32\drivers\pwspmpvj.dat
2007-12-12 11:51 . 2007-12-13 01:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-12 11:51 . 2007-12-12 11:51 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-23 23:00 . 2007-10-04 17:14 136,260 --a------ C:\WINDOWS\system32\nvapps.nvb
2007-11-23 22:53 . 2007-11-23 22:53 <DIR> d-------- C:\Programmer\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 07:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-14 22:50 17,761,229 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_14_20_55_16_full.dmp.zip
2007-12-14 19:52 17,674,395 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_14_20_50_55_full.dmp.zip
2007-12-13 00:58 --------- d-----w C:\Documents and Settings\Stephen\Application Data\AVG7
2007-11-25 14:07 --------- d-----w C:\Documents and Settings\Stephen\Application Data\ZoomBrowser EX
2007-11-25 14:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14 5,509,120 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-10-04 16:14 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-10-04 16:14 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll
2007-10-04 16:14 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll
2007-10-04 16:14 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll
2007-10-04 16:14 3,629,056 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-10-04 16:14 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14 3,166,208 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll
2007-10-04 16:14 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll
2007-10-04 16:14 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll
2007-10-04 16:14 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll
2007-10-04 16:14 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll
2007-10-04 16:14 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll
2007-10-04 16:14 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
2007-10-04 16:14 2,441,216 ----a-w C:\WINDOWS\system32\nvwssr.dll
2007-10-04 16:14 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll
2007-10-04 16:14 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll
2007-10-04 16:14 163,840 ----a-w C:\WINDOWS\system32\nvwrszhc.dll
2007-10-04 16:14 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14 126,976 ----a-w C:\WINDOWS\system32\nvrszht.dll
2007-10-04 16:14 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll
2007-10-04 16:14 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14 1,073,152 ----a-w C:\WINDOWS\system32\nvcpluir.dll
2006-07-21 15:49 61 --sh--w C:\WINDOWS\cnerolf.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA15CEBF-12A5-447A-8C30-729824F2A9D8}]
c:\windows\system32\d3dpmesho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C330E39F-852B-43DD-9510-C66ADD0E82BE}]
2004-07-09 04:27 84992 --a------ C:\WINDOWS\System32\dmusico.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-09 13:13]
"DAEMON Tools"="G:\Programmer\Daemon\DAEMON Tools\daemon.exe" [2006-11-12 11:48]
"ASUS SmartDoctor"="C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe" [2006-04-18 15:37]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-27 11:45]
"WorksFUD"="C:\Programmer\Microsoft Works\wkfud.exe" [2000-07-12 12:59]
"Microsoft Works Portfolio"="C:\Programmer\Microsoft Works\WksSb.exe" [2000-07-12 14:14]
"Microsoft Works Update Detection"="C:\Programmer\Microsoft Works\WkDetect.exe" [2000-09-12 19:24]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 09:53 C:\WINDOWS\SOUNDMAN.EXE]
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"Profiler"="C:\Programmer\Saitek\Software\Profiler.exe" [2004-07-26 12:04]
"SaiSmart"="C:\Programmer\Saitek\Software\SaiSmart.exe" [2004-07-26 12:04]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-10-25 18:58]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"NvCplDaemon"="RUNDLL32.exe" [2001-10-09 13:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"ZoneAlarm Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"NvMediaCenter"="RUNDLL32.exe" [2001-10-09 13:00 C:\WINDOWS\system32\rundll32.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-09-09 13:13]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-27 11:45]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Acrobat Assistant.lnk - G:\Programmer\AdobeWriter\Distillr\AcroTray.exe [2006-11-26 20:30:10]
Adobe Reader Speed Launch.lnk - G:\Programmer\Acrobat\Reader\reader_sl.exe [2005-09-23 21:05:26]
P†mindelser i Microsoft Works Kalender.lnk - C:\Programmer\F‘lles filer\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38]
VIA RAID TOOL.lnk - C:\Programmer\VIA\RAID\raid_tool.exe [2006-07-21 15:40:53]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= G:\Programmer\SUPERAntispyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
G:\Programmer\SUPERAntispyware\SASWINLO.dll 2007-04-19 13:41 294912 G:\Programmer\SUPERAntispyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wgvlxfkx]
d3dpmesho.dll

R0 pvjahvfb;pvjahvfb;C:\WINDOWS\System32\drivers\pwspmpvj.dat
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\System32\drivers\sfsync03.sys
R0 viamraid;viamraid;C:\WINDOWS\System32\DRIVERS\viamraid.sys
R3 SaiH053c;SaiH053c;C:\WINDOWS\System32\DRIVERS\SaiH053c.sys
S2 vhwjgakc; til Terminal Server-enhedsomdirigeringHelper;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 SaiH075C;SaiH075C;C:\WINDOWS\System32\DRIVERS\SaiH075C.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vhwjgakc

*Newly Created Service* - ALG
*Newly Created Service* - CATCHME
*Newly Created Service* - IPNAT
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-17 15:46:57
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-17 15:47:42


Hijack this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:48:46, on 17-12-2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmer\Saitek\Software\Profiler.exe
C:\Programmer\Saitek\Software\SaiSmart.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
G:\Programmer\Daemon\DAEMON Tools\daemon.exe
C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe
G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
G:\Programmer\Acrobat\Reader\reader_sl.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\VIA\RAID\raid_tool.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jetfighters.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - g:\programmer\AdobeWriter\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {AA15CEBF-12A5-447A-8C30-729824F2A9D8} - c:\windows\system32\d3dpmesho.dll (file missing)
O2 - BHO: (no name) - {C330E39F-852B-43DD-9510-C66ADD0E82BE} - C:\WINDOWS\System32\dmusico.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Profiler] C:\Programmer\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Programmer\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "G:\Programmer\Daemon\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Programmer\Acrobat\Reader\reader_sl.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmer\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MS-FRO~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {31150A86-0BBA-409F-BEB4-F3922D10BF34} (Gif89 Class) - http://www.f-f-f.dk/webcam/xplug.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe
O20 - Winlogon Notify: !SASWinLogon - G:\Programmer\SUPERAntispyware\SASWINLO.dll
O20 - Winlogon Notify: wgvlxfkx - d3dpmesho.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7598 bytes


Looking forward to your next reply.
Best regards
F16GEA

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 03:15 PM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\wgzqsmpc.dat
C:\WINDOWS\system32\zuzcgpxs.dat
C:\WINDOWS\system32\jmtzofve.dat
C:\WINDOWS\system32\tqtrwisg.dat
C:\WINDOWS\system32\jzsyexfj.dat
C:\WINDOWS\system32\dmusico.dll
C:\WINDOWS\system32\drivers\pwspmpvj.dat
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA15CEBF-12A5-447A-8C30-729824F2A9D8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C330E39F-852B-43DD-9510-C66ADD0E82BE}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wgvlxfkx]
Driver::
pvjahvfb
vhwjgakc

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#5 F16GEA

F16GEA
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 03:52 PM

Hey Richie, or shall I say RULE BRITANNIA! It seems like you've managed to erase the infected files :thumbsup:
Anyway, here are the reports:

ComboFix log

ComboFix 07-12-16.4 - Stephen 2007-12-17 21:40:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1030.18.669 [GMT 1:00]
Running from: C:\Documents and Settings\Stephen\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Stephen\Skrivebord\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\dmusico.dll
C:\WINDOWS\system32\drivers\pwspmpvj.dat
C:\WINDOWS\system32\jmtzofve.dat
C:\WINDOWS\system32\jzsyexfj.dat
C:\WINDOWS\system32\tqtrwisg.dat
C:\WINDOWS\system32\wgzqsmpc.dat
C:\WINDOWS\system32\zuzcgpxs.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\dmusico.dll
C:\WINDOWS\system32\drivers\pwspmpvj.dat
C:\WINDOWS\system32\jmtzofve.dat
C:\WINDOWS\system32\jzsyexfj.dat
C:\WINDOWS\system32\tqtrwisg.dat
C:\WINDOWS\system32\wgzqsmpc.dat
C:\WINDOWS\system32\zuzcgpxs.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_PVJAHVFB
-------\LEGACY_VHWJGAKC
-------\pvjahvfb
-------\vhwjgakc


((((((((((((((((((((((((( Files Created from 2007-11-17 to 2007-12-17 )))))))))))))))))))))))))))))))
.

2007-12-17 15:35 . 2007-12-17 15:35 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-16 23:34 . 2007-12-16 23:34 <DIR> d-------- C:\Programmer\Trend Micro
2007-12-16 17:05 . 2007-12-16 17:22 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-12-16 17:05 . 2007-12-16 17:05 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2007-12-16 17:05 . 2007-12-16 17:05 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2007-12-16 17:05 . 2007-12-16 17:05 1,406 --a------ C:\WINDOWS\system32\Help.ico
2007-12-16 17:00 . 2007-12-16 17:32 <DIR> d-------- C:\Documents and Settings\Stephen\.housecall6.6
2007-12-16 14:59 . 2007-12-16 16:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-15 13:20 . 2007-12-15 13:42 <DIR> d-------- C:\Programmer\EsetOnlineScanner
2007-12-15 12:45 . 2007-12-15 13:52 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-12-14 20:44 . 2007-12-14 20:44 <DIR> d-------- C:\Documents and Settings\Stephen\Application Data\SUPERAntiSpyware.com
2007-12-14 20:44 . 2007-12-14 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-14 20:43 . <DIR> C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-14 20:06 . 2007-12-14 20:06 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-12-14 20:06 . 2007-12-14 20:06 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-12-12 11:51 . 2007-12-13 01:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-12 11:51 . 2007-12-12 11:51 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-23 23:00 . 2007-10-04 17:14 136,260 --a------ C:\WINDOWS\system32\nvapps.nvb
2007-11-23 22:53 . 2007-11-23 22:53 <DIR> d-------- C:\Programmer\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 07:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-14 22:50 17,761,229 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_14_20_55_16_full.dmp.zip
2007-12-14 19:52 17,674,395 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_12_14_20_50_55_full.dmp.zip
2007-12-13 00:58 --------- d-----w C:\Documents and Settings\Stephen\Application Data\AVG7
2007-11-25 14:07 --------- d-----w C:\Documents and Settings\Stephen\Application Data\ZoomBrowser EX
2007-11-25 14:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14 5,509,120 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-10-04 16:14 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-10-04 16:14 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll
2007-10-04 16:14 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll
2007-10-04 16:14 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll
2007-10-04 16:14 3,629,056 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-10-04 16:14 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14 3,166,208 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll
2007-10-04 16:14 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll
2007-10-04 16:14 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll
2007-10-04 16:14 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll
2007-10-04 16:14 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll
2007-10-04 16:14 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll
2007-10-04 16:14 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
2007-10-04 16:14 2,441,216 ----a-w C:\WINDOWS\system32\nvwssr.dll
2007-10-04 16:14 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll
2007-10-04 16:14 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll
2007-10-04 16:14 163,840 ----a-w C:\WINDOWS\system32\nvwrszhc.dll
2007-10-04 16:14 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14 126,976 ----a-w C:\WINDOWS\system32\nvrszht.dll
2007-10-04 16:14 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll
2007-10-04 16:14 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14 1,073,152 ----a-w C:\WINDOWS\system32\nvcpluir.dll
2006-07-21 15:49 61 --sh--w C:\WINDOWS\cnerolf.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-17_15.46.58,84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 09:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-09 13:13]
"DAEMON Tools"="G:\Programmer\Daemon\DAEMON Tools\daemon.exe" [2006-11-12 11:48]
"ASUS SmartDoctor"="C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe" [2006-04-18 15:37]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-10-27 11:45]
"WorksFUD"="C:\Programmer\Microsoft Works\wkfud.exe" [2000-07-12 12:59]
"Microsoft Works Portfolio"="C:\Programmer\Microsoft Works\WksSb.exe" [2000-07-12 14:14]
"Microsoft Works Update Detection"="C:\Programmer\Microsoft Works\WkDetect.exe" [2000-09-12 19:24]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 09:53 C:\WINDOWS\SOUNDMAN.EXE]
"Zone Labs Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"Profiler"="C:\Programmer\Saitek\Software\Profiler.exe" [2004-07-26 12:04]
"SaiSmart"="C:\Programmer\Saitek\Software\SaiSmart.exe" [2004-07-26 12:04]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-10-25 18:58]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"NvCplDaemon"="RUNDLL32.exe" [2001-10-09 13:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"ZoneAlarm Client"="C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"NvMediaCenter"="RUNDLL32.exe" [2001-10-09 13:00 C:\WINDOWS\system32\rundll32.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-09-09 13:13]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-27 11:45]

C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Acrobat Assistant.lnk - G:\Programmer\AdobeWriter\Distillr\AcroTray.exe [2006-11-26 20:30:10]
Adobe Reader Speed Launch.lnk - G:\Programmer\Acrobat\Reader\reader_sl.exe [2005-09-23 21:05:26]
P†mindelser i Microsoft Works Kalender.lnk - C:\Programmer\F‘lles filer\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38]
VIA RAID TOOL.lnk - C:\Programmer\VIA\RAID\raid_tool.exe [2006-07-21 15:40:53]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= G:\Programmer\SUPERAntispyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
G:\Programmer\SUPERAntispyware\SASWINLO.dll 2007-04-19 13:41 294912 G:\Programmer\SUPERAntispyware\SASWINLO.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vhwjgakc

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-17 21:44:36
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-17 21:46:37 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-17 15:47


And here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:47:53, on 17-12-2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Saitek\Software\Profiler.exe
C:\Programmer\Saitek\Software\SaiSmart.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
G:\Programmer\Daemon\DAEMON Tools\daemon.exe
C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
G:\Programmer\Acrobat\Reader\reader_sl.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programmer\Fælles filer\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programmer\VIA\RAID\raid_tool.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jetfighters.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - g:\programmer\AdobeWriter\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WorksFUD] C:\Programmer\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Profiler] C:\Programmer\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Programmer\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmer\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "G:\Programmer\Daemon\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Programmer\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = G:\Programmer\AdobeWriter\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Programmer\Acrobat\Reader\reader_sl.exe
O4 - Global Startup: Påmindelser i Microsoft Works Kalender.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Programmer\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MS-FRO~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {31150A86-0BBA-409F-BEB4-F3922D10BF34} (Gif89 Class) - http://www.f-f-f.dk/webcam/xplug.ocx
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe
O20 - Winlogon Notify: !SASWinLogon - G:\Programmer\SUPERAntispyware\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Programmer\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7284 bytes


/F16GEA

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 04:01 PM

Your log is clean :thumbsup: ,please do the following:

Click on Start/Run,copy and paste ComboFix /u into the 'Open:' space,then press Ok.

Posted Image

Please download OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Click on the 'Cleanup' button Posted Image
When you do this a text file named cleanup.txt will be downloaded from the internet.
If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so.
When the 'Confirm' box appears click 'Yes'.
Restart your pc when prompted.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:

Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

How to prevent Malware:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

So how did I get infected in the first place:
http://forums.spybot.info/showthread.php?t=279

Malware Cleanup Programs and Preventative Procedures:
http://russelltexas.com/malware/allclear.htm

You should now visit Windows Update and install all the latest critical/high priority updates including Service Pack 2.

Edited by RichieUK, 17 December 2007 - 04:02 PM.

Posted Image
Posted Image

#7 F16GEA

F16GEA
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 05:28 PM

Thanks for your help, chief!
I'll buy you a beer next time we meet :thumbsup:
Best regards
F16GEA

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:55 PM

Posted 17 December 2007 - 05:33 PM

You're most welcome F16GEA :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users