Done
Ove
ComboFix 07-07-30.2 - "Ny Ove" 2007-08-04 10:23:56.5 [GMT 2:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.Sand
Command switches used :: C:\Documents and Settings\Ny Ove\Skrivebord\CFScript.txt
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-07-04 to 2007-08-04 )))))))))))))))))))))))))))))))
2007-08-04 10:15 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-04 10:13 <DIR> d-------- C:\Programmer\Maxtor
2007-08-04 09:35 <DIR> d-------- C:\WINDOWS\LastGood
2007-08-04 09:17 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-08-04 09:17 27,648 --a------ C:\WINDOWS\system32\irmon.dll
2007-08-04 09:17 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2007-08-04 08:59 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-08-04 08:59 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-08-03 21:24 <DIR> d-------- C:\Programmer\SiSLan
2007-08-02 20:11 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-08-02 19:52 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-01 20:15 338,304 --a------ C:\WINDOWS\system32\_AxShlEx.dll
2007-08-01 19:21 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-01 18:56 <DIR> d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\gtk-2.0
2007-07-31 21:21 82,258 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-07-31 21:21 82,258 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-07-31 21:21 18,570,528 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-31 21:20 168,224 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-07-31 21:20 <DIR> d-------- C:\Programmer\Kaspersky Lab
2007-07-30 21:20 <DIR> d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\UseNeXT
2007-07-29 22:39 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-29 19:17 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SUPERAntiSpyware.com
2007-07-29 19:16 <DIR> d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-29 09:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2007-07-29 09:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Office Genuine Advantage
2007-07-29 07:38 <DIR> d-------- C:\DOCUME~1\NYOVE~1\DoctorWeb
2007-07-28 09:43 5,376 --a------ C:\WINDOWS\system32\antiwpa.dll
2007-07-27 15:04 921,872 --a------ C:\WINDOWS\system\MFC40.DLL
2007-07-27 15:04 326,656 --a------ C:\WINDOWS\system\Msvcrt40.dll
2007-07-27 15:03 283,648 --a------ C:\WINDOWS\uninst.exe
2007-07-27 15:03 <DIR> d-------- C:\DOCUME~1\NYOVE~1\WINDOWS
2007-07-22 09:23 <DIR> d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\Opera
2007-07-20 14:24 <DIR> d-------- C:\Programmer\gs
2007-07-14 08:56 <DIR> d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\ScanSoft
2007-07-11 19:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\espionServerData
2007-07-04 22:15 <DIR> d-------- C:\WINDOWS\system32\QuickTime
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-04 10:20 95080 --a------ C:\WINDOWS\system32\perfc006.dat
2007-08-04 10:20 472146 --a------ C:\WINDOWS\system32\perfh006.dat
2007-08-04 10:17 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\Skype
2007-08-04 10:14 256592 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-04 10:14 20804 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-04 10:13 --------- d--h----- C:\Programmer\InstallShield Installation Information
2007-08-04 09:29 23372 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-03 20:04 --------- d-------- C:\Programmer\Windows NT
2007-08-01 21:55 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\Vso
2007-08-01 20:04 --------- d-------- C:\Programmer\PCSVIEW
2007-08-01 20:03 --------- d-------- C:\Programmer\PCSPD
2007-07-31 20:52 --------- d-------- C:\Programmer\SmartFTP Client
2007-07-31 06:05 --------- d--h----- C:\Programmer\WindowsUpdate
2007-07-28 07:17 --------- d-------- C:\Programmer\TuneUp Utilities 2007
2007-07-22 09:01 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\XnView
2007-07-20 17:18 --------- d-------- C:\Programmer\PCSEL40
2007-07-17 23:19 --------- d-------- C:\Programmer\XnView
2007-07-13 22:50 0 --a------ C:\WINDOWS\brdfxspd.dat
2007-07-13 20:17 50 --a------ C:\WINDOWS\system32\BRIDF04A.dat
2007-07-13 19:59 --------- d-------- C:\Programmer\Brother
2007-07-02 18:41 10872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-29 17:55 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\WinRAR
2007-06-28 12:51 206088 --a------ C:\WINDOWS\system32\klogon(2).dll
2007-06-26 21:06 --------- d-------- C:\Programmer\WinTrade
2007-06-24 19:18 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\Genie-Soft
2007-06-20 19:41 --------- d-------- C:\Programmer\SmartFTP Client 2.0
2007-06-20 19:11 --------- d-------- C:\Programmer\Namo
2007-06-20 19:07 --------- d-------- C:\Programmer\Microsoft ActiveSync
2007-06-17 10:53 20640 --a------ C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-06-17 10:53 109568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2007-06-17 10:53 108544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2007-06-16 15:55 101440 --a------ C:\DOCUME~1\NYOVE~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-06-07 19:37 --------- d-------- C:\DOCUME~1\NYOVE~1\APPLIC~1\Cryptomathic
--------- C:\Programmer\Fælles filer\Wise Installation Wizard
--------- C:\Programmer\Fælles filer\System
--------- C:\Programmer\Fælles filer\PCschematic
--------- C:\Programmer\Fælles filer\Open Design Alliance
--------- C:\Programmer\Fælles filer\Nero
--------- C:\Programmer\Fælles filer\Autodesk Shared
--------- C:\Programmer\Fælles filer\Ahead
--------- C:\Programmer\Fælles filer
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"ControlCenter2.0"="C:\Programmer\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 10:34]
"Cmaudio"="cmicnfg.cpl" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-26 17:53 C:\WINDOWS\system32\bthprops.cpl]
"AVP"="C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [2007-03-09 20:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-26 17:53]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" [2007-06-08 15:18]
"MSMSGS"="C:\Programmer\Messenger\msmsgs.exe" [2004-10-13 18:24]
"TWALINK"="C:\Programmer\TEXTware\HotKey\TWALINK.EXE" [1998-11-10 16:47]
"Microsoft Office XP component"="C:\Programmer\Microsoft Office\Office10\MSOFFICE.EXE" [2001-02-13 10:58]
"H/PC Connection Agent"="C:\Programmer\Microsoft ActiveSync\wcescomm.exe" [2006-06-27 19:39]
"TuneUp MemOptimizer"="C:\Programmer\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-27 05:08]
"AlcoholAutomount"="C:\Programmer\Alcohol Soft\Alcohol 120\axcmd.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Skype"="C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
"Windows System Service"=WinInfo.exe
C:\Documents and Settings\All Users.WINDOWS\Menuen Start\Programmer\Start\
Adobe Acrobat Hurtigstart.lnk - C:\WINDOWS\Installer\{AC76BA86-1030-D700-7760-000000000002}\SC_Acrobat.exe [2006-01-14 11:01:51]
AutoCAD Startup Accelerator.lnk - C:\Programmer\F‘lles filer\Autodesk Shared\acstart16.exe [2004-02-25 02:35:22]
Cordless DUALphone opstart.lnk - C:\Programmer\Cordless USB Phone\Cordless DUALphone Suite.exe [2006-06-09 14:45:37]
Status Monitor.lnk - C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe [2006-12-14 14:00:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs
R2 ElbyCDIO;ElbyCDIO Driver;C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
R2 Hardlock;Hardlock;\??\C:\WINDOWS\system32\drivers\hardlock.sys
R2 Haspnt;Haspnt;\??\C:\WINDOWS\system32\drivers\Haspnt.sys
R2 Sentinel;Sentinel;C:\WINDOWS\system32\Drivers\SENTINEL.SYS
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys
R3 BthEnum;Driver til Bluetooth-anmodningsblok;C:\WINDOWS\system32\DRIVERS\BthEnum.sys
R3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys
R3 BTHUSB;USB-driver til Bluetooth-radio;C:\WINDOWS\system32\Drivers\BTHUSB.sys
R3 ElbyCDFL;ElbyCDFL;C:\WINDOWS\system32\Drivers\ElbyCDFL.sys
R3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART-driver;C:\WINDOWS\system32\drivers\msmpu401.sys
R3 Pcouffin;VSO Software pcouffin;C:\WINDOWS\system32\Drivers\Pcouffin.sys
R3 RFCOMM;Bluetooth-enhed (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
R3 StillCam;Driver til serielt digitalt kamera (stillbilleder);C:\WINDOWS\system32\DRIVERS\serscan.sys
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 BTHPORT;Bluetooth-portdriver;C:\WINDOWS\system32\Drivers\BTHport.sys
S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys
S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys
S3 CVirtA;Cisco Systems VPN Adapter;C:\WINDOWS\system32\DRIVERS\CVirtA.sys
S3 fixustor;fixustor;C:\WINDOWS\system32\drivers\fixustor.sys
S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
Contents of the 'Scheduled Tasks' folder
2007-07-27 15:15:01 C:\WINDOWS\Tasks\1-Klick-Wartung.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-08-04 10:28:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-04 10:31:26
C:\ComboFix-quarantined-files.txt ... 2007-08-04 10:30
C:\ComboFix2.txt ... 2007-08-03 14:33
C:\ComboFix3.txt ... 2007-08-02 18:25
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 15:22:06, on 4-08-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programmer\Fælles filer\Acronis\Schedule2\schedul2.exe
C:\Programmer\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Programmer\Fælles filer\Autodesk Shared\Service\AdskScSrv.exe
C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\TEXTware\HotKey\TWALINK.EXE
C:\Programmer\Microsoft Office\Office10\MSOFFICE.EXE
C:\Programmer\Microsoft ActiveSync\wcescomm.exe
C:\Programmer\TuneUp Utilities 2007\MemOptimizer.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Programmer\Cordless USB Phone\Cordless DUALphone Suite.exe
C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programmer\Skype\Plugin Manager\SkypePM.exe
C:\Programmer\Outlook Express\msimn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Ny Ove\Lokale indstillinger\Temporary Internet Files\Content.IE5\FCU1BFZ9\alternativ[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmer\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVP] "C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TWALINK] C:\Programmer\TEXTware\HotKey\TWALINK.EXE
O4 - HKCU\..\Run: [Microsoft Office XP component] C:\Programmer\Microsoft Office\Office10\MSOFFICE.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Programmer\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - Global Startup: Adobe Acrobat Hurtigstart.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = ?
O4 - Global Startup: Cordless DUALphone opstart.lnk = C:\Programmer\Cordless USB Phone\Cordless DUALphone Suite.exe
O4 - Global Startup: Status Monitor.lnk = C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O8 - Extra context menu item: Konverter hyperlinkdestination til Adobe PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter hyperlinkdestination til eksisterende PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter markering til Adobe PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter markering til eksisterende PDF-fil -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter til Adobe PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konverter til eksisterende PDF-fil -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konverter valgte hyperlinks til Adobe PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Konverter valgte hyperlinks til eksisterende PDF -
res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Tilføj til Kaspersky Anti-Banner - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Opret Foretrukken på den mobile enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -
http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cabO16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) -
https://www.basisbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.10.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exeO16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} -
http://www.turntool.com/ViewerInstall.exeO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/20040105/qtinstall.info.apple.com/mickey/dk/win/QuickTimeFullInstaller.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185606099420O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186074899265O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) -
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) -
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) -
https://opdatering.tdc.dk/csp/authenticode/tdccsp-0506.exeO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cabO16 - DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} (IlosoftImageUploadCtl Class) -
http://webc.surf-invest.dk/controls/IlosoftImageUpload.dllO16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programmer\Fælles filer\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Programmer\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programmer\Fælles filer\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Programmer\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programmer\Fælles filer\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\Programmer\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)