Nogle der vil kigge på disse log filer.?
Logfile of HijackThis v1.99.1Scan saved at 18:53: VIRUS ALERT!, on 29-07-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Java\j2re1.4.2_05\bin\jusched.exe
C:\Programmer\Logitech\SetPoint\LBTWiz.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Programmer\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe
C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe
C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\D-Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\Programmer\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Brother\Brmfcmon\BrMfcmon.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmer\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Programmer\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Michael\Skrivebord\sypware\alternativ.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QXK Olive - {2881DA20-2EAD-4741-8AF3-4798FADD0428} - C:\WINDOWS\nfavxwdbpbd.dll
O2 - BHO: (no name) - {5351010D-585C-45D6-89DD-9E358BC93B73} - C:\WINDOWS\system32\urqQijIY.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {E8AC85E8-4634-426D-942B-1F6069723DC7} - C:\WINDOWS\system32\wvUnMccD.dll
O3 - Toolbar: fdkowvbp - {65FDCE92-5922-48F2-A5E7-A1981975D160} - C:\WINDOWS\fdkowvbp.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Programmer\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Programmer\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [BrMfcWnd] C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Programmer\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programmer\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [antivirus-2008pro.exe] C:\Programmer\Antivirus 2008 PRO\antivirus-2008pro.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmer\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send til &Bluetooth-enhed... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} (ActiveX sikkerhedssoftware Control) - https://www.sparnord.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programmer\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: LBTWlgn - c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O20 - Winlogon Notify: wvUnMccD - C:\WINDOWS\SYSTEM32\wvUnMccD.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: eqvwamkl - {D66656F6-73A5-485A-A69F-E6E56751B489} - C:\WINDOWS\eqvwamkl.dll
O21 - SSODL: wnslvxtf - {1AD1B15A-58B2-4351-AA2D-4F9C0734E36E} - C:\WINDOWS\wnslvxtf.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
ComboFix 08-07-28.6 - Michael 2008-07-29 18:56:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1030.18.308 [GMT 2:00]
Running from: C:\Documents and Settings\Michael\Skrivebord\sypware\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Michael\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk
C:\Documents and Settings\Michael\Foretrukne\Error Cleaner.url
C:\Documents and Settings\Michael\Foretrukne\Privacy Protector.url
C:\Documents and Settings\Michael\Foretrukne\Spyware&Malware Protection.url
C:\Documents and Settings\Michael\Menuen Start\Programmer\Antivirus 2008 PRO
C:\Documents and Settings\Michael\Menuen Start\Programmer\Antivirus 2008 PRO\antivirus-2008pro.lnk
C:\Documents and Settings\Michael\Skrivebord\antivirus-2008pro.lnk
C:\Documents and Settings\Michael\Skrivebord\Error Cleaner.url
C:\Documents and Settings\Michael\Skrivebord\Privacy Protector.url
C:\Documents and Settings\Michael\Skrivebord\Spyware&Malware Protection.url
C:\Programmer\Antivirus 2008 PRO
C:\Programmer\Antivirus 2008 PRO\antivirus-2008pro.exe
C:\Programmer\Antivirus 2008 PRO\vscan.tsi
C:\Programmer\Antivirus 2008 PRO\zlib.dll
C:\WINDOWS\eprn.exe
C:\WINDOWS\eqvwamkl.dll
C:\WINDOWS\fdkowvbp.dll
C:\WINDOWS\grswptdl.exe
C:\WINDOWS\nfavxwdbpbd.dll
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
c:\windows\system32\Drivers\Winqv84.sys
C:\WINDOWS\system32\ljJDWPfd.dll
C:\WINDOWS\system32\WinCtrl32.dl_
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\wvUnMccD.dll
C:\WINDOWS\system32\YIjiQqru.ini
C:\WINDOWS\system32\YIjiQqru.ini2
C:\WINDOWS\wnslvxtf.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINQV84
-------\Service_Winqv84
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))
.
2008-07-29 18:06 . 2008-07-29 18:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-07-29 18:05 . 2008-07-01 16:31 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord
2008-07-29 18:05 . 2008-07-01 16:25 <DIR> d--h----- C:\Documents and Settings\Administrator\Skabeloner
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> d--h----- C:\Documents and Settings\Administrator\Printere
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> dr------- C:\Documents and Settings\Administrator\Menuen Start
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale indstillinger
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> d-------- C:\Documents and Settings\Administrator\Foretrukne
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenter
2008-07-29 18:05 . 2008-07-01 18:20 <DIR> d--h----- C:\Documents and Settings\Administrator\Andre computere
2008-07-29 18:05 . 2008-07-29 18:05 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-29 18:01 . 2008-07-29 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-29 18:00 . 2008-07-29 18:00 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2008-07-29 18:00 . 2008-07-29 18:00 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com
2008-07-29 17:55 . 2008-07-29 17:55 <DIR> d-------- C:\Programmer\CCleaner
2008-07-28 22:28 . 2008-07-29 18:52 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\TmpRecentIcons
2008-07-28 22:23 . 2008-07-28 22:23 876 --a------ C:\WINDOWS\$_hpcst$.hpc
2008-07-25 22:47 . 2006-02-21 15:49 1,929,216 --a------ C:\WINDOWS\system32\cdintf250.dll
2008-07-25 22:46 . 2008-07-25 22:53 <DIR> d-------- C:\Programmer\Mamut
2008-07-25 22:44 . 2008-07-25 22:44 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-10 12:53 . 2008-04-14 17:37 32,000 --a------ C:\WINDOWS\system32\drivers\wceusbsh.sys
2008-07-10 12:53 . 2008-04-14 17:37 32,000 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-07-10 00:42 . 2008-07-10 00:42 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-07-08 23:00 . 2003-12-19 19:48 89,184 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-07-08 23:00 . 2003-12-23 15:40 57,344 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-07-08 22:59 . <DIR> C:\Programmer\Fælles filer\Ahead
2008-07-08 22:59 . 2008-07-08 22:59 <DIR> d-------- C:\Programmer\Ahead
2008-07-08 22:59 . 2001-07-06 13:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-07-08 22:59 . 2001-07-06 11:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-07-08 22:59 . 2001-07-06 17:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-07-08 22:59 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-07-08 22:59 . 2001-06-26 07:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-07-08 17:41 . 2008-07-09 06:17 45,161 --a------ C:\WINDOWS\diagerr.xml
2008-07-08 17:41 . 2008-07-09 06:17 1,905 --a------ C:\WINDOWS\diagwrn.xml
2008-07-05 16:19 . 2008-07-28 22:32 <DIR> d-------- C:\Programmer\Panda Security
2008-07-05 14:19 . 2008-07-05 14:19 1,072 --a------ C:\EBJKeystore.store
2008-07-05 14:19 . 2008-07-05 14:19 1,056 --a------ C:\EBJKeystore.store.backup
2008-07-04 03:00 . 2008-07-04 03:00 <DIR> d-------- C:\Programmer\MSXML 4.0
2008-07-04 00:46 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-04 00:46 . 2008-07-25 22:52 636 --a------ C:\WINDOWS\ODBC.INI
2008-07-04 00:44 . 2008-07-04 00:44 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-04 00:43 . 2008-07-04 00:43 <DIR> d-------- C:\Programmer\Microsoft.NET
2008-07-04 00:42 . 2008-07-04 00:42 <DIR> dr-h----- C:\MSOCache
2008-07-04 00:37 . 2008-07-04 00:37 <DIR> d-------- C:\Programmer\D-Tools
2008-07-03 14:47 . 2008-07-03 14:47 <DIR> d-------- C:\WINDOWS\MVUNINST
2008-07-03 14:47 . 2008-07-03 14:48 <DIR> d-------- C:\Programmer\SureThing
2008-07-03 14:47 . <DIR> C:\Programmer\Fælles filer\SureThing Shared
2008-07-03 14:47 . 2002-01-05 02:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-07-02 22:53 . 2008-07-02 22:53 <DIR> d-------- C:\Programmer\TDC
2008-07-02 22:53 . <DIR> C:\Programmer\Fælles filer\Wise Installation Wizard
2008-07-02 22:53 . 2008-07-02 22:53 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Cryptomathic
2008-07-02 22:51 . 2008-07-02 22:51 <DIR> d-------- C:\Programmer\Realtek AC97
2008-07-02 22:51 . 2006-05-19 08:01 18,796,544 --a------ C:\WINDOWS\system32\alsndmgr.cpl
2008-07-02 22:51 . 2006-05-11 07:18 10,527,232 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-07-02 22:51 . 2006-05-19 15:44 3,965,056 --a------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-07-02 22:51 . 2006-03-02 07:22 577,536 --a------ C:\WINDOWS\soundman.exe
2008-07-02 22:51 . 2006-03-20 11:48 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-07-02 22:51 . 2005-11-18 11:20 217,088 --a------ C:\WINDOWS\Alcrmv.exe
2008-07-02 22:51 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-07-02 22:51 . 2006-01-10 13:38 135,168 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-07-02 22:51 . 2005-07-15 16:48 40,960 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-07-02 22:49 . 2008-07-02 22:49 <DIR> d-------- C:\Programmer\S3
2008-07-02 22:25 . 2008-07-02 22:25 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-02 22:24 . <DIR> C:\Programmer\Fælles filer\Adobe AIR
2008-07-02 22:23 . <DIR> C:\Programmer\Fælles filer\Adobe
2008-07-02 22:19 . 2008-07-02 22:49 <DIR> d-------- C:\Programmer\NOS
2008-07-02 22:19 . 2008-07-02 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-07-02 22:12 . 2008-07-10 13:33 425 --a------ C:\WINDOWS\BRWMARK.INI
2008-07-02 22:12 . 2008-07-10 13:33 27 --a------ C:\WINDOWS\BRPP2KA.INI
2008-07-02 22:11 . 2007-02-01 13:19 1,520,640 --a------ C:\WINDOWS\system32\BrWia07a.dll
2008-07-02 22:11 . 2006-12-28 13:39 176,128 --------- C:\WINDOWS\system32\BroSNMP.dll
2008-07-02 22:11 . 2007-01-25 17:16 94,208 -r------- C:\WINDOWS\system32\BrDctF2.dll
2008-07-02 22:11 . 2007-01-26 14:06 45,568 --a------ C:\WINDOWS\system32\BrUsi07a.dll
2008-07-02 22:11 . 2004-10-15 12:50 15,295 --a------ C:\WINDOWS\system32\drivers\BrScnUsb.sys
2008-07-02 22:11 . 2007-01-15 21:54 12,288 -r------- C:\WINDOWS\system32\BrDctF2S.dll
2008-07-02 22:11 . 2007-01-15 16:27 12,288 -r------- C:\WINDOWS\system32\BrDctF2L.dll
2008-07-02 22:10 . 2008-07-02 22:10 <DIR> d-------- C:\Brother
2008-07-02 22:10 . 2001-11-15 01:00 6,224 --------- C:\WINDOWS\CVRPAGE.bmp
2008-07-02 22:09 . 2008-07-02 22:09 <DIR> d-------- C:\Programmer\Nuance
2008-07-02 22:09 . 2008-07-02 22:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-07-02 22:09 . 2006-10-24 16:13 31,326 --a------ C:\WINDOWS\maxlink.ini
2008-07-02 22:08 . 2008-07-02 22:08 <DIR> d-------- C:\Programmer\ScanSoft
2008-07-02 22:08 . <DIR> C:\Programmer\Fælles filer\ScanSoft Shared
2008-07-02 22:08 . 2008-07-02 22:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-07-02 21:59 . 2008-07-02 21:59 <DIR> d-------- C:\Programmer\Windows Media Connect 2
2008-07-02 21:58 . 2008-07-02 21:58 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-07-02 21:58 . 2008-07-02 22:01 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-02 21:53 . <DIR> C:\Programmer\Fælles filer\Nokia
2008-07-02 21:53 . 2008-07-02 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nokia
2008-07-02 21:52 . 2008-07-02 21:52 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-07-02 21:51 . <DIR> C:\Programmer\Fælles filer\PCSuite
2008-07-02 21:49 . 2008-07-03 17:58 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Brother
2008-07-02 21:40 . 2008-07-02 22:11 50 --a------ C:\WINDOWS\system32\bridf07a.dat
2008-07-02 21:39 . 2008-07-02 21:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Brother
2008-07-02 21:39 . 2007-01-18 13:51 163,840 --------- C:\WINDOWS\system32\NSSearch.dll
2008-07-02 21:39 . 2007-02-15 13:54 131,072 --------- C:\WINDOWS\brunin03.dll
2008-07-02 21:39 . 2002-11-26 13:43 106,496 --------- C:\WINDOWS\system32\BrMuSNMP.dll
2008-07-02 21:39 . 2007-02-06 19:50 61,952 --------- C:\WINDOWS\system32\BrNetSti.dll
2008-07-02 21:39 . 2007-01-26 16:31 53,760 --a------ C:\WINDOWS\system32\brinsstr.dll
2008-07-02 21:39 . 2006-12-26 19:39 37,376 --------- C:\WINDOWS\system32\Brnsplg.dll
2008-07-02 21:39 . 2007-01-26 15:06 34,816 --------- C:\WINDOWS\system32\BrWiaNCp.dll
2008-07-02 21:39 . 2007-01-26 15:05 18,944 --------- C:\WINDOWS\system32\BrnStiCp.cpl
2008-07-02 21:39 . 2006-11-20 20:48 9,728 --------- C:\WINDOWS\system32\BrSti07a.dll
2008-07-02 21:36 . <DIR> C:\Programmer\Fælles filer\Brother
2008-07-02 21:35 . 2008-07-02 22:11 <DIR> d-------- C:\Programmer\Brother
2008-07-02 21:34 . 2008-07-02 21:34 <DIR> d-------- C:\Documents and Settings\Michael\Bluetooth Software
2008-07-02 21:33 . 2008-07-02 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-07-02 21:32 . 2008-07-02 21:32 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Logitech
2008-07-02 21:32 . 2008-07-02 21:32 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Logitech
2008-07-02 21:32 . 2005-10-05 12:00 47,104 --a------ C:\WINDOWS\system32\drivers\vserial.sys
2008-07-02 21:32 . 2005-10-05 12:00 18,167 --a------ C:\WINDOWS\system32\drivers\vsb.sys
2008-07-02 21:31 . 2008-07-02 21:31 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-07-02 21:31 . 2008-07-02 21:31 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-07-02 21:30 . <DIR> C:\Programmer\Fælles filer\Logishrd
2008-07-02 21:30 . 2008-07-19 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-07-02 21:29 . 2008-04-13 20:45 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-07-02 21:28 . 2008-07-02 21:28 <DIR> d-------- C:\Programmer\WIDCOMM
2008-07-02 21:28 . 2008-07-02 21:32 <DIR> d-------- C:\Programmer\Logitech
2008-07-02 21:28 . 2008-07-02 21:28 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\InstallShield
2008-07-02 21:28 . 2006-12-04 14:33 863,402 --a------ C:\WINDOWS\system32\drivers\btkrnl.sys
2008-07-02 21:28 . 2006-12-04 14:33 329,901 --a------ C:\WINDOWS\system32\drivers\btaudio.sys
2008-07-02 21:28 . 2006-12-04 14:33 106,557 --a------ C:\WINDOWS\system32\btw_ci.dll
2008-07-02 21:28 . 2006-12-04 14:33 67,672 --a------ C:\WINDOWS\system32\drivers\btwusb.sys
2008-07-02 21:28 . 2006-12-04 14:33 47,907 --a------ C:\WINDOWS\system32\drivers\btwhid.sys
2008-07-02 21:28 . 2006-12-04 14:33 30,459 --a------ C:\WINDOWS\system32\drivers\btport.sys
2008-07-02 21:28 . 2006-12-04 14:33 30,285 --a------ C:\WINDOWS\system32\drivers\btwmodem.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 20:51 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-07-02 20:08 --------- d-----w C:\Programmer\Fælles filer\InstallShield
2008-07-01 14:37 --------- d-----w C:\Programmer\D-Link
2008-07-01 14:32 --------- d-----w C:\Programmer\microsoft frontpage
2008-07-01 14:31 --------- d-----w C:\Programmer\Java
2008-07-01 14:31 --------- d-----w C:\Programmer\Fælles filer\Java
2008-07-01 14:28 --------- d-----w C:\Programmer\Onlinetjenester
2008-07-01 14:27 --------- d-----w C:\Programmer\Fælles filer\Tjenester
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:35 272,256 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Programmer\Java\j2re1.4.2_05\bin\jusched.exe" [2008-07-01 16:31 32881]
"Easy Synchronization"="C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe" [2005-10-05 12:00 53248]
"NSLauncher"="C:\Programmer\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-10-01 12:29 3104768]
"PaperPort PTD"="C:\Programmer\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 21:12 30248]
"IndexSearch"="C:\Programmer\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 21:10 46632]
"PPort11reminder"="C:\Programmer\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 13:46 255528]
"BrMfcWnd"="C:\Programmer\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 14:51 663552]
"ControlCenter3"="C:\Programmer\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 15:58 65536]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"DAEMON Tools-1033"="C:\Programmer\D-Tools\daemon.exe" [2003-10-02 02:20 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe]
"VTTimer"="VTTimer.exe" [2006-09-21 16:36 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2007-02-06 07:30 176128 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-03-02 07:22 577536 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 18:05 15360]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-29 22:37:20 561213]
Logitech SetPoint.lnk - C:\Programmer\Logitech\SetPoint\SetPoint.exe [2008-07-02 21:30:55 805392]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{FE24CD78-7C63-465D-8787-4EDF7FC79895}"= "C:\Programmer\Logitech\Easy Synchronization\shellexecutehook.dll" [2005-10-05 12:00 69632]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programmer\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
R0 pnpshark;pnpshark;C:\WINDOWS\system32\DRIVERS\pnpshark.sys [2003-10-02 03:16]
R0 st3shark;st3shark;C:\WINDOWS\system32\DRIVERS\st3shark.sys [2003-09-27 14:37]
.
- - - - ORPHANS REMOVED - - - -
BHO-{5351010D-585C-45D6-89DD-9E358BC93B73} - C:\WINDOWS\system32\urqQijIY.dll
Toolbar-{65FDCE92-5922-48F2-A5E7-A1981975D160} - C:\WINDOWS\fdkowvbp.dll
HKLM-Run-SSBkgdUpdate - C:\Programmer\Fælles filer\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
HKLM-Run-Bluetooth Connection Assistant - LBTWIZ.EXE
Notify-LBTWlgn - c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll
.
------- Supplementary Scan -------
.
O16 -: {07D09E9E-C667-45DD-B035-217BC2A61A3B} - hxxps://www.sparnord.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.20.cab
C:\WINDOWS\Downloaded Program Files\comp.inf
C:\WINDOWS\Downloaded Program Files\EBJSecurity_3.dll
C:\WINDOWS\Downloaded Program Files\ActiveXSikkerhedssoftware.ocx
O16 -: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} - hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-29 19:04:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-29 19:07:19 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-07-29 17:07:14
Pre-Run: 74,930,380,800 byte ledig
Post-Run: 74,863,939,584 byte ledig
263 --- E O F --- 2008-07-17 22:32:33
Nede i hjørnet ved uret, står der en tekst, hvor der står VIRUS ALERT?