okay, sorry er ikke den skarpeste kniv i skuffen når det kommer til computerer (:
ComboFix 09-03-15.01 - Maja 2009-03-16 22:25:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.511.199 [GMT 1:00]
Kører fra: c:\documents and settings\Maja\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Maja\Skrivebord\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *enabled*
* Dannede nyt systemgendannelsespunkt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
FILE ::
c:\docume~1\maja\skrive~1\GMVEGA~1.EXE
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-02-16 til 2009-03-16 )))))))))))))))))))))))))))))))))))
.
2009-03-15 15:16 . 2009-03-15 15:16 <DIR> d-------- c:\documents and settings\Maja\Application Data\Malwarebytes
2009-03-15 15:15 . 2009-03-15 15:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-15 15:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-15 15:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-14 15:06 . 2009-03-14 16:45 <DIR> d----c--- C:\Lop SD
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\documents and settings\Maja\Application Data\AdobeUM
2009-03-10 19:33 . 2009-03-10 19:33 <DIR> d-------- c:\documents and settings\Maja\Application Data\AdobeAUM
2009-03-10 19:01 . 2009-03-10 19:01 <DIR> d-------- c:\documents and settings\Maja\Application Data\Windows Search
2009-03-10 18:57 . 2009-03-10 18:57 <DIR> d-------- c:\documents and settings\Gæst\Application Data\Windows Desktop Search
2009-03-09 21:09 . 2009-03-09 21:09 <DIR> d-------- c:\programmer\iPod
2009-03-09 21:08 . 2009-03-09 21:10 <DIR> d-------- c:\programmer\iTunes
2009-03-09 21:08 . 2009-03-09 21:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-09 21:05 . 2009-03-09 21:05 <DIR> d-------- c:\programmer\Bonjour
2009-03-09 16:35 . 2009-03-09 16:35 <DIR> d-------- c:\programmer\Microsoft Silverlight
2009-03-09 16:34 . 2009-03-09 16:34 <DIR> d-------- c:\programmer\Microsoft
2009-03-09 16:32 . 2009-03-09 16:32 <DIR> d-------- c:\documents and settings\Maja\Application Data\Windows Desktop Search
2009-03-09 16:31 . 2009-03-09 16:31 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-03-09 16:31 . 2009-03-09 16:32 <DIR> d-------- c:\programmer\Windows Desktop Search
2009-03-09 16:30 . 2008-03-07 18:02 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
2009-03-09 16:30 . 2008-03-07 18:02 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
2009-03-09 16:30 . 2008-03-07 18:02 29,696 -----c--- c:\windows\system32\dllcache\mimefilt.dll
2009-03-09 16:11 . 2009-01-09 20:19 1,089,883 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-09 15:47 . 2009-03-09 15:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-03-09 15:27 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-03-09 15:11 . 2009-03-09 15:27 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-09 15:11 . 2009-03-09 15:11 <DIR> d-------- c:\programmer\Reference Assemblies
2009-03-09 15:11 . 2009-03-09 15:11 <DIR> d-------- c:\programmer\MSBuild
2009-03-09 15:09 . 2009-03-09 15:10 <DIR> d----c--- C:\ec40bb0dc8a32bfc8bdc146ecb
2009-03-09 15:09 . 2008-07-06 13:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-09 15:09 . 2008-07-06 13:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-09 15:09 . 2008-07-06 11:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-09 15:09 . 2008-07-06 13:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-09 15:09 . 2008-07-06 13:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-09 15:09 . 2008-07-06 13:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-09 15:09 . 2008-07-06 13:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-09 12:15 . 2009-03-09 12:15 <DIR> d-------- c:\windows\system32\da
2009-03-09 12:15 . 2009-03-09 12:15 <DIR> d-------- c:\windows\system32\bits
2009-03-09 12:15 . 2009-03-09 12:15 <DIR> d-------- c:\windows\l2schemas
2009-03-09 12:07 . 2009-03-09 12:16 <DIR> d-------- c:\windows\ServicePackFiles
2009-03-08 20:46 . 2004-07-17 11:36 184,101 -----c--- c:\windows\system32\dllcache\compact.wmz
2009-03-08 20:46 . 2004-07-17 22:55 129,045 --------- c:\windows\system32\drivers\cxthsfs2.cty
2009-03-08 20:46 . 2001-10-09 13:00 9,585 -----c--- c:\windows\system32\dllcache\controls.css
2009-03-08 20:46 . 2001-10-09 13:00 999 -----c--- c:\windows\system32\dllcache\bktrh.gif
2009-03-08 20:46 . 2001-10-09 13:00 773 -----c--- c:\windows\system32\dllcache\cnth.gif
2009-03-08 20:46 . 2001-10-09 13:00 773 -----c--- c:\windows\system32\dllcache\cnt.gif
2009-03-08 20:46 . 2001-10-09 13:00 772 -----c--- c:\windows\system32\dllcache\cntd.gif
2009-03-08 20:46 . 2001-10-09 13:00 760 -----c--- c:\windows\system32\dllcache\cloapph.gif
2009-03-08 20:46 . 2001-10-09 13:00 717 -----c--- c:\windows\system32\dllcache\cloapp.gif
2009-03-08 19:49 . 2008-06-14 18:35 272,256 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-03-08 19:46 . 2009-02-09 15:07 1,846,784 -----c--- c:\windows\system32\dllcache\win32k.sys
2009-03-08 19:45 . 2008-08-14 14:25 2,191,744 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-08 19:45 . 2008-08-14 14:25 2,147,840 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-08 19:45 . 2008-08-14 14:25 2,068,608 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-08 19:45 . 2008-08-14 14:25 2,026,496 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-08 19:36 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-08 19:36 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2009-03-08 19:35 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-03-08 19:35 . 2008-12-11 11:57 333,952 -----c--- c:\windows\system32\dllcache\srv.sys
2009-03-08 19:35 . 2008-05-01 15:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-03-08 19:33 . 2008-12-21 00:03 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-03-08 19:32 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-03-08 19:32 . 2008-10-15 17:37 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-03-08 14:35 . 2009-03-08 14:35 <DIR> d-------- c:\programmer\Symantec
2009-03-08 14:35 . 2009-03-08 14:43 <DIR> d-------- c:\programmer\Fælles filer\Symantec Shared
2009-03-08 14:35 . 2009-03-08 14:35 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-08 14:35 . 2009-03-08 14:35 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-03-08 14:35 . 2009-03-08 14:35 35,888 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-03-08 14:35 . 2009-03-08 14:35 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-08 14:35 . 2009-03-08 14:35 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-03-08 14:34 . 2009-03-08 14:34 <DIR> d-------- c:\windows\system32\drivers\NIS
2009-03-08 14:34 . 2009-03-08 14:34 <DIR> d-------- c:\programmer\Windows Sidebar
2009-03-08 14:34 . 2009-03-08 14:35 <DIR> d-------- c:\programmer\Norton Internet Security
2009-03-08 14:34 . 2009-03-08 14:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-03-08 14:26 . 2009-03-08 14:33 <DIR> d-------- c:\programmer\NortonInstaller
2009-03-08 14:26 . 2009-03-08 14:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-05 21:33 . 2009-03-16 22:22 <DIR> d-------- c:\windows\system32\CatRoot2
2009-03-01 20:59 . 2009-03-01 20:59 <DIR> d-------- c:\programmer\ReflexiveArcade
2009-03-01 20:51 . 2009-03-08 15:12 <DIR> d-------- C:\Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 15:27 --------- d-----w c:\programmer\Nokia
2009-03-12 16:57 --------- d-----w c:\programmer\MSN Messenger
2009-03-12 16:57 --------- d-----w c:\programmer\Messenger Plus! Live
2009-03-09 20:09 --------- d-----w c:\programmer\Fælles filer\Apple
2009-03-09 17:49 --------- d-----w c:\programmer\Fælles filer\Nokia
2009-03-09 15:29 --------- d-----w c:\programmer\Windows Media Connect 2
2009-03-09 10:14 --------- d-----w c:\programmer\Avanquest update
2009-02-22 19:54 --------- d-----w c:\programmer\QuickTime
2009-02-22 19:50 --------- d-----w c:\programmer\Apple Software Update
2009-01-27 19:15 --------- d-----w c:\programmer\SIW
2009-01-16 15:39 --------- d-----w c:\programmer\Google
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\programmer\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\programmer\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-11-16 344064]
"SunJavaUpdateSched"="c:\programmer\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"LogitechCommunicationsManager"="c:\programmer\Fælles filer\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 505368]
"NeroFilterCheck"="c:\programmer\Fælles filer\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\programmer\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - c:\programmer\IBM\Bluetooth Software\BTTray.exe [2004-01-20 507965]
Windows Search.lnk - c:\programmer\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MPEG"= JPEGCODE.DLL
"msacm.dvacm"= c:\progra~1\FLLESF~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Digimax Viewer 2.1.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Digimax Viewer 2.1.lnk
backup=c:\windows\pss\Digimax Viewer 2.1.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2005-06-06 22:46 57344 c:\programmer\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 01:38 34672 c:\programmer\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
--a------ 2004-01-14 02:10 409600 c:\programmer\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2009-01-06 13:06 290088 c:\programmer\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-05-17 09:53 780312 c:\programmer\Logitech\QuickCam10\QuickCam10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a--c--- 2007-06-16 00:15 366400 c:\programmer\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2009-01-05 16:18 413696 c:\programmer\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
--------- 2008-07-02 16:16 393216 c:\programmer\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2004-09-23 11:41 860160 c:\programmer\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 08:11 1388544 c:\programmer\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
-----c--- 2003-11-18 17:20 45056 c:\programmer\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
"c:\\Programmer\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Programmer\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Programmer\\MSN Messenger\\msnmsgr.exe"=
"c:\\Programmer\\MSN Messenger\\livecall.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-06-04 90408]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-06-04 15016]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-06-04 122024]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-06-04 115368]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-06-04 25768]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-06-04 111784]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-06-04 117544]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1000000.07D\SYMEFA.SYS [2009-03-08 309296]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1000000.07D\BHDrvx86.sys [2009-03-08 254512]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1000000.07D\ccHPx86.sys [2009-03-08 362544]
S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090310.003\IDSxpx86.sys [2009-02-06 276344]
S2 Norton Internet Security;Norton Internet Security;c:\programmer\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [2009-03-08 115560]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\programmer\Fælles filer\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-07 101936]
--- Andre Services/Drivers i Hukommelsen ---
*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - Beep
*Deregistered* - BHDrvx86
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - BTKRNL
*Deregistered* - btwdins
*Deregistered* - ccHP
*Deregistered* - Cdfs
*Deregistered* - cnmpar21
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - IBMPMSVC
*Deregistered* - IDSxpx86
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - Irmon
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - LVCOMSer
*Deregistered* - LVPr2Mon
*Deregistered* - LVPrcSrv
*Deregistered* - LVSrvLauncher
*Deregistered* - LVUSBSta
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NMIndexingService
*Deregistered* - Norton Internet Security
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PCIIde
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RegSrvc
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - S24EventMonitor
*Deregistered* - s24trans
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SoundMAX Agent Service (default)
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - SYMDNS
*Deregistered* - SymEFA
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SymIMMP
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - wscsvc
*Deregistered* - WSearch
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WUSB54Gv4SVC
*Deregistered* - WZCSVC
.
Indhold af mappen 'Planlagte Opgaver'
2009-03-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-08-25 c:\windows\Tasks\defrag.job
- c:\windows\system32\defrag.exe [2008-04-14 17:05]
2009-03-15 c:\windows\Tasks\Diskoprydning.job
- c:\windows\system32\cleanmgr.exe [2008-04-14 17:05]
2009-03-15 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-16 c:\windows\Tasks\Søg efter opdateringer til Windows Live Toolbar.job
- c:\programmer\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]
.
- - - - TOMME GENVEJE FJERNET - - - -
MSConfigStartUp-PCSuiteTrayApplication - c:\programmer\Nokia\Nokia PC Suite 6\LaunchApplication.exe
.
------- Yderligere scanning -------
.
uDefault_Search_URL =
hxxp://www.google.com/ieuInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &Windows Live Search - c:\programmer\Windows Live Toolbar\msntb.dll/search.htm
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\programmer\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Trusted Zone: facebook.com\www
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-16 22:33:28
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\programmer\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\programmer\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(1280)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(7840)
c:\programmer\Fælles filer\Logishrd\LVMVFM\LVPrcInj.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\S24EvMon.exe
c:\programmer\Fælles filer\logishrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\ati2evxx.exe
c:\programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\IBM\Bluetooth Software\bin\btwdins.exe
c:\programmer\Fælles filer\logishrd\LVCOMSER\LVComSer.exe
c:\programmer\Fælles filer\logishrd\LVCOMSER\LVComSer.exe
c:\windows\system32\RegSrvc.exe
c:\programmer\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\searchindexer.exe
c:\programmer\Fælles filer\Ahead\Lib\NMIndexStoreSvr.exe
c:\programmer\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
c:\programmer\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\programmer\iPod\bin\iPodService.exe
c:\programmer\Fælles filer\Ahead\Lib\NMIndexingService.exe
.
**************************************************************************
.
Gennemført tid: 2009-03-16 22:41:29 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-03-16 21:39:44
Pre-Kørsel: 13.238.255.616 byte ledig
Post-Kørsel: 14,332,768,256 byte ledig
402 --- E O F --- 2009-03-14 14:30:25