ComboFix 09-03-15.01 - Asger Mortensen 2009-03-17 15:02:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.1023.737 [GMT 1:00]
Kører fra: c:\spy\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated)
FW: ESET Personal firewall *disabled*
* Dannede nyt systemgendannelsespunkt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-02-17 til 2009-03-17 )))))))))))))))))))))))))))))))))))
.
2009-03-15 20:18 . 2009-03-15 20:18 <DIR> d-------- c:\programmer\Malwarebytes' Anti-Malware
2009-03-15 20:18 . 2009-03-15 20:18 <DIR> d-------- c:\documents and settings\Asger Mortensen\Application Data\Malwarebytes
2009-03-15 20:18 . 2009-03-15 20:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-15 20:18 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-15 20:18 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-15 20:14 . 2009-03-15 20:14 <DIR> d-------- c:\programmer\CCleaner
2009-03-15 20:03 . 2009-03-17 15:01 <DIR> d-------- C:\spy
2009-03-15 19:51 . 2009-03-15 19:51 <DIR> d-------- c:\programmer\D-Link AirPlus
2009-03-15 13:24 . 2009-03-15 13:24 <DIR> d-------- C:\Intel
2009-03-15 13:05 . 2009-01-09 20:19 1,089,883 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-15 12:58 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-15 12:58 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-15 12:58 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-27 10:58 . 2009-02-27 10:58 244 --ah----- C:\sqmnoopt00.sqm
2009-02-27 10:58 . 2009-02-27 10:58 232 --ah----- C:\sqmdata00.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 18:51 --------- d--h--w c:\programmer\InstallShield Installation Information
2009-03-15 12:21 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2009-03-15 11:56 --------- d-----w c:\programmer\Microsoft Silverlight
2009-02-13 10:03 --------- d-----w c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-02-13 09:34 --------- d-----w c:\programmer\PicLensIE
2009-02-12 13:38 --------- dcsh--w c:\programmer\Fælles filer\WindowsLiveInstaller
2009-02-12 13:38 --------- d-----w c:\programmer\Windows Live
2009-02-12 13:37 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-02-12 13:33 --------- d-----w c:\programmer\MSN Toolbar
2009-02-12 13:28 --------- d-----w c:\documents and settings\All Users\Application Data\e-Safekey
2009-02-11 01:44 --------- d-----w c:\programmer\VideoLAN
2009-02-11 01:38 --------- d-----w c:\documents and settings\Asger Mortensen\Application Data\vlc
2009-02-10 02:04 --------- d-----w c:\programmer\MSBuild
2009-02-10 01:49 --------- d-----w c:\documents and settings\Asger Mortensen\Application Data\Windows Desktop Search
2009-02-10 01:48 --------- d-----w c:\programmer\Windows Desktop Search
2009-02-10 01:36 --------- d-----w c:\programmer\Windows Media Connect 2
2009-02-09 22:41 --------- d-----w c:\programmer\Fælles filer\InstallShield
2009-02-09 17:57 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-09 17:57 --------- d-----w c:\programmer\Uniblue
2009-02-09 17:57 --------- d-----w c:\documents and settings\Asger Mortensen\Application Data\uniblue
2009-02-09 16:37 --------- d-----w c:\programmer\Intel
2009-02-09 16:32 --------- dc-h--w c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-02-09 16:18 --------- d-----w c:\documents and settings\Asger Mortensen\Application Data\ESET
2009-02-09 16:15 --------- d-----w c:\programmer\ESET
2009-02-09 16:15 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-02-09 16:07 --------- dc-h--w c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-02-09 16:03 --------- d-----w c:\programmer\Reference Assemblies
2009-02-09 14:37 15,890 ----a-w c:\windows\system32\drivers\mdc8021x.sys
2009-02-09 14:36 --------- d-----w c:\programmer\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter
2009-02-09 14:10 --------- d-----w c:\programmer\IZArc
2009-02-09 14:08 --------- d-----w c:\programmer\DIFX
2009-02-09 14:07 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 13:36 --------- d-----w c:\programmer\microsoft frontpage
2009-02-09 13:33 --------- d-----w c:\programmer\Onlinetjenester
2009-02-09 13:32 --------- d-----w c:\programmer\Fælles filer\Tjenester
2008-12-20 23:03 826,368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\programmer\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ACU"="c:\programmer\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter\ACU.exe" [2005-07-22 397312]
"egui"="c:\programmer\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-03-12 c:\windows\system32\atiptaxx.exe]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
D-Link AirPlus.lnk - c:\programmer\D-Link AirPlus\AirPlus.exe [2009-02-18 262144]
Windows Search.lnk - c:\programmer\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmer\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
R2 ekrn;Eset Service;c:\programmer\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [2009-02-09 43392]
.
- - - - TOMME GENVEJE FJERNET - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uInternet Connection Wizard,ShellNext =
hxxp://izarc.org/donate.htmlDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-17 15:04:35
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2009-03-17 15:06:27
ComboFix-quarantined-files.txt 2009-03-17 14:06:25
Pre-Kørsel: 32.033.329.152 byte ledig
Post-Kørsel: 32,049,352,704 byte ledig
116 --- E O F --- 2009-03-15 12:12:04