Allright, it did it's thing, here's the log:
ComboFix 10-07-21.02 - Adde 2010-07-22 14:07:17.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1033.18.2047.1286 [GMT 2:00]
Körs från: c:\users\Adde\Desktop\ComboFix.exe
* Skapade en ny återställningspunkt
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\settings.reg
c:\windows\system32\%appdata%
c:\windows\system32\msvcsv60.dll
.
(((((((((((((((((((((((( Filer Skapade från 2010-06-22 till 2010-07-22 ))))))))))))))))))))))))))))))
.
2010-07-22 12:13 . 2010-07-22 12:14 -------- d-----w- c:\users\Adde\AppData\Local\temp
2010-07-21 03:00 . 2010-07-21 03:00 -------- d-----w- c:\windows\system32\wbem\Logs
2010-07-21 02:57 . 2010-07-21 02:57 -------- d-----w- c:\users\Adde\AppData\Roaming\Malwarebytes
2010-07-21 02:57 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-21 02:57 . 2010-07-21 02:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-21 02:57 . 2010-07-21 02:57 -------- d-----w- c:\programdata\Malwarebytes
2010-07-21 02:57 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-20 19:59 . 2010-07-20 20:03 -------- d-----w- c:\program files\a-squared Free
2010-07-11 15:30 . 2010-07-11 15:30 -------- d-----w- c:\users\Adde\AppData\Roaming\XRay Engine
2010-07-04 07:35 . 2010-07-04 07:35 -------- d-----w- c:\program files\AC3Filter
2010-06-30 13:29 . 2010-06-30 13:29 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-06-30 07:13 . 2010-06-30 09:49 -------- d-----w- c:\users\Adde\AppData\Roaming\Xfire
2010-06-30 07:12 . 2010-06-30 07:15 -------- d-----w- c:\programdata\Xfire
2010-06-30 07:12 . 2010-06-30 07:13 -------- d-----w- c:\program files\Xfire
2010-06-29 21:27 . 2010-06-29 21:34 -------- d-----w- c:\users\Adde\AppData\Roaming\dp3d
2010-06-29 15:51 . 2010-07-06 22:38 16 ----a-w- c:\windows\msocreg32.dat
2010-06-29 10:31 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-06-26 01:01 . 2010-06-26 01:01 -------- d-----w- c:\program files\Microsoft.NET
2010-06-25 02:28 . 2010-06-25 02:28 -------- d-----w- c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-06-23 01:01 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 01:01 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 01:01 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 01:01 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 01:01 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-22 22:44 . 2010-06-22 22:44 -------- d-----w- C:\PFiles
2010-06-22 19:26 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-06-22 19:26 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-06-22 19:26 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 12:15 . 2010-03-13 20:31 -------- d-----w- c:\users\Adde\AppData\Roaming\uTorrent
2010-07-22 10:51 . 2010-03-15 01:22 -------- d-----w- c:\users\Adde\AppData\Roaming\vlc
2010-07-18 22:47 . 2010-05-10 18:41 -------- d-----w- c:\users\Adde\AppData\Roaming\Skype
2010-07-18 22:47 . 2010-05-10 18:43 -------- d-----w- c:\users\Adde\AppData\Roaming\skypePM
2010-07-07 17:28 . 2010-04-12 08:02 -------- d-----w- c:\users\Adde\AppData\Roaming\dvdcss
2010-06-28 20:57 . 2010-03-13 20:45 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-03-13 20:46 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-03-13 20:46 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-03-13 20:46 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-03-13 20:46 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-06-28 20:32 . 2010-03-13 20:46 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 08:40 . 2010-03-14 13:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-25 02:28 . 2010-03-13 21:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-24 22:26 . 2010-03-14 18:09 -------- d-----w- c:\program files\DivX
2010-06-20 14:24 . 2010-06-20 14:24 -------- d-----w- c:\programdata\Steam
2010-06-14 23:45 . 2010-06-14 23:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSBW_01_00_00.Wdf
2010-06-14 23:45 . 2010-06-14 23:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_lgSSQVGA_01_00_00.Wdf
2010-06-14 23:45 . 2010-06-14 23:45 -------- d-----w- c:\programdata\Logitech
2010-06-14 23:45 . 2010-06-14 23:45 -------- d-----w- c:\program files\Logitech
2010-06-05 00:29 . 2010-06-05 00:29 -------- d-----w- c:\users\Adde\AppData\Roaming\Octoshape
2010-06-04 18:59 . 2010-06-04 18:59 -------- d-----w- c:\users\Adde\AppData\Roaming\InstallShield Installation Information
2010-06-04 18:58 . 2010-06-04 18:59 331776 ----a-w- c:\users\Adde\AppData\Roaming\InstallShield Installation Information\{6530FDAA-5B1F-4830-95BB-650E9804D239}\setup.exe
2010-06-04 18:58 . 2010-06-04 18:59 2010726 ----a-w- c:\users\Adde\AppData\Roaming\InstallShield Installation Information\{6530FDAA-5B1F-4830-95BB-650E9804D239}\ISSetup.dll
2010-06-04 06:35 . 2010-05-15 11:13 -------- d-----w- c:\program files\uTorrent2
2010-06-04 06:35 . 2010-05-09 04:51 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-04 06:34 . 2009-07-13 23:40 409088 ----a-w- c:\windows\system32\systemcpl.dll
2010-06-04 06:34 . 2009-07-13 23:36 13824 ----a-w- c:\windows\system32\slwga.dll
2010-06-04 06:34 . 2009-07-13 23:24 811520 ----a-w- c:\windows\system32\user32.dll
2010-06-01 20:43 . 2010-03-29 11:07 -------- d-----w- c:\program files\Autodesk
2010-06-01 16:54 . 2010-03-13 20:32 -------- d-----w- c:\program files\uTorrent
2010-05-29 15:29 . 2010-05-29 15:29 -------- d-----w- c:\programdata\SEGA Corporation
2010-05-28 00:04 . 2010-05-28 00:04 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-05-27 07:24 . 2010-06-08 18:43 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-08 18:43 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 23:00 . 2010-05-26 23:00 -------- d-----w- c:\users\Adde\AppData\Roaming\bizarre creations
2010-05-22 23:57 . 2010-03-13 20:34 57560 ----a-w- c:\users\Adde\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-21 12:14 . 2010-02-10 05:47 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-21 05:18 . 2010-06-08 18:43 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-10 18:43 . 2010-05-10 18:43 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-05-06 00:06 . 2010-05-06 00:06 1879 ----a-w- c:\programdata\xml7DD8.tmp
2010-05-06 00:06 . 2010-05-06 00:06 13445 ----a-w- c:\programdata\xml7D1B.tmp
2010-05-06 00:06 . 2010-05-06 00:06 9521 ----a-w- c:\programdata\xml7B36.tmp
2010-05-01 14:49 . 2010-06-08 18:43 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 13:37 . 2010-04-29 13:37 230 ----a-w- c:\windows\ctrunonce.reg
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
------- Sigcheck -------
[-] 2010-06-04 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"uTorrent"="c:\program files\uTorrent2\uTorrent.exe" [2010-06-04 322352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-06-28 2837864]
"JulaPAN.exe"="JulaPAN.exe" [2010-03-13 495648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableThumbnails"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer6"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-21 23:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2009-06-03 22:55 25600 ----a-w- c:\windows\System32\Ctxfihlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e-kort]
2008-12-11 12:14 377856 ----a-w- c:\progra~1\ekort\ekort.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-03-13 20:34 135664 ----atw- c:\users\Adde\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2009-09-21 17:40 1681408 ----a-r- c:\program files\VIA\VIAudioi\VDeck\VDeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JulaPAN.exe]
2010-03-13 20:39 495648 ----a-w- c:\windows\System32\JulaPAN.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883840 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"uTorrent"="c:\program files\uTorrent2\uTorrent.exe"
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"Octoshape Streaming Services"="c:\users\Adde\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
R1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\system32\DRIVERS\Jula.sys [2010-03-13 48160]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-04-29 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2009-06-04 171032]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2009-06-04 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2009-06-04 1324056]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2009-06-04 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2009-06-04 72728]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2009-06-04 72728]
R3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\system32\DRIVERS\JulaWDM.sys [2010-03-13 35872]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
R3 MADFUMIDISPORT2010;Service for M-Audio MIDISPORT DFU;c:\windows\system32\DRIVERS\MAudioMIDISPORT_DFU.sys [2010-02-03 23304]
R3 MAUSBMIDISPORT;Service for M-Audio MIDISPORT;c:\windows\system32\DRIVERS\MAudioMIDISPORT.sys [2010-02-03 166920]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-02 1343400]
R4 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2010-04-15 1872320]
R4 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\spel\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-03-14 691696]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-04-07 172032]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-02-25 1047880]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-04-07 5430272]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-04-07 157184]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-25 10064]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Innehållet i mappen 'Schemalagda aktiviteter':
2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2843955662-4099961252-1379313863-1001Core.job
- c:\users\Adde\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-13 20:34]
2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2843955662-4099961252-1379313863-1001UA.job
- c:\users\Adde\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-13 20:34]
.
.
------- Extra genomsökning -------
.
Trusted Zone: com\
www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
.
.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,30,56,32,64,90,4c,e7,42,bf,45,2c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,30,56,32,64,90,4c,e7,42,bf,45,2c,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andra processer som körs ------------------------
.
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\atieclxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Sluttid: 2010-07-22 14:18:26 - datorn startades om.
ComboFix-quarantined-files.txt 2010-07-22 12:18
Före genomsökningen: 70*421*422*080 bytes free
Efter genomsökningen: 70*369*628*160 bytes free
- - End Of File - - C04BB425ECE12E02C4B05E4AF4479611