SuperAntiSpyware log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 04/10/2009 at 10:49 AM
Application Version : 4.0.1154
Core Rules Database Version : 3838
Trace Rules Database Version: 1794
Scan type : Complete Scan
Total Scan Time : 00:12:48
Memory items scanned : 431
Memory threats detected : 0
Registry items scanned : 4518
Registry threats detected : 0
File items scanned : 15297
File threats detected : 75
Adware.Tracking Cookie
C:\Documents and Settings\ZV\Cookies\zv@adserver.adreactor[1].txt
C:\Documents and Settings\ZV\Cookies\zv@postclicktracking[1].txt
C:\Documents and Settings\ZV\Cookies\zv@at.atwola[1].txt
C:\Documents and Settings\ZV\Cookies\zv@adopt.specificclick[2].txt
C:\Documents and Settings\ZV\Cookies\zv@adtech[1].txt
C:\Documents and Settings\ZV\Cookies\zv@chitika[1].txt
C:\Documents and Settings\ZV\Cookies\zv@specificclick[1].txt
C:\Documents and Settings\ZV\Cookies\zv@fastclick[1].txt
C:\Documents and Settings\ZV\Cookies\zv@ads.dvinfo[2].txt
C:\Documents and Settings\ZV\Cookies\zv@ero-advertising[1].txt
C:\Documents and Settings\ZV\Cookies\zv@media6degrees[1].txt
C:\Documents and Settings\ZV\Cookies\zv@atdmt[2].txt
C:\Documents and Settings\ZV\Cookies\zv@www.googleadservices[1].txt
C:\Documents and Settings\ZV\Cookies\zv@www.googleadservices[2].txt
C:\Documents and Settings\ZV\Cookies\zv@partypoker[2].txt
C:\Documents and Settings\ZV\Cookies\zv@eas.apm.emediate[2].txt
C:\Documents and Settings\ZV\Cookies\zv@collective-media[1].txt
C:\Documents and Settings\ZV\Cookies\zv@tribalfusion[1].txt
C:\Documents and Settings\ZV\Cookies\zv@ads.warcraftmovies[2].txt
C:\Documents and Settings\ZV\Cookies\zv@hitbox[1].txt
C:\Documents and Settings\ZV\Cookies\zv@elitebastards[2].txt
C:\Documents and Settings\ZV\Cookies\zv@serving-sys[1].txt
C:\Documents and Settings\ZV\Cookies\zv@list[1].txt
C:\Documents and Settings\ZV\Cookies\zv@advertising[1].txt
C:\Documents and Settings\ZV\Cookies\zv@trafficmp[1].txt
C:\Documents and Settings\ZV\Cookies\zv@247realmedia[1].txt
C:\Documents and Settings\ZV\Cookies\zv@smartadserver[1].txt
C:\Documents and Settings\ZV\Cookies\zv@pro-market[2].txt
C:\Documents and Settings\ZV\Cookies\zv@bs.serving-sys[2].txt
C:\Documents and Settings\ZV\Cookies\zv@msnportal.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@valueclick[1].txt
C:\Documents and Settings\ZV\Cookies\zv@findfiles[2].txt
C:\Documents and Settings\ZV\Cookies\zv@ads.ad4game[2].txt
C:\Documents and Settings\ZV\Cookies\zv@mediaplex[1].txt
C:\Documents and Settings\ZV\Cookies\zv@adserver.adtechus[1].txt
C:\Documents and Settings\ZV\Cookies\zv@zedo[2].txt
C:\Documents and Settings\ZV\Cookies\zv@ads.widgetbucks[1].txt
C:\Documents and Settings\ZV\Cookies\zv@nextag.co[1].txt
C:\Documents and Settings\ZV\Cookies\zv@doubleclick[1].txt
C:\Documents and Settings\ZV\Cookies\zv@adbureau[1].txt
C:\Documents and Settings\ZV\Cookies\zv@ads.incgamers[2].txt
C:\Documents and Settings\ZV\Cookies\zv@realmedia[1].txt
C:\Documents and Settings\ZV\Cookies\zv@danskebank.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@imrworldwide[2].txt
C:\Documents and Settings\ZV\Cookies\zv@burstnet[1].txt
C:\Documents and Settings\ZV\Cookies\zv@movia.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@aller.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@track.adform[2].txt
C:\Documents and Settings\ZV\Cookies\zv@adbrite[1].txt
C:\Documents and Settings\ZV\Cookies\zv@c7.zedo[2].txt
C:\Documents and Settings\ZV\Cookies\zv@adinterax[1].txt
C:\Documents and Settings\ZV\Cookies\zv@lenovo.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@bluestreak[2].txt
C:\Documents and Settings\ZV\Cookies\zv@tacoda[1].txt
C:\Documents and Settings\ZV\Cookies\zv@ad.yieldmanager[2].txt
C:\Documents and Settings\ZV\Cookies\zv@adopt.euroclick[1].txt
C:\Documents and Settings\ZV\Cookies\zv@e2.emediate[1].txt
C:\Documents and Settings\ZV\Cookies\zv@xiti[1].txt
C:\Documents and Settings\ZV\Cookies\zv@tradedoubler[1].txt
C:\Documents and Settings\ZV\Cookies\zv@indextools[2].txt
C:\Documents and Settings\ZV\Cookies\zv@ad.dragonstar.dmoglobal[2].txt
C:\Documents and Settings\ZV\Cookies\zv@adrevolver[2].txt
C:\Documents and Settings\ZV\Cookies\zv@ehg-techtarget.hitbox[1].txt
C:\Documents and Settings\ZV\Cookies\zv@ad1.emediate[2].txt
C:\Documents and Settings\ZV\Cookies\zv@eas4.emediate[1].txt
C:\Documents and Settings\ZV\Cookies\zv@statcounter[1].txt
C:\Documents and Settings\ZV\Cookies\zv@overture[2].txt
C:\Documents and Settings\ZV\Cookies\zv@horisont.adservinginternational[1].txt
C:\Documents and Settings\ZV\Cookies\zv@2o7[2].txt
C:\Documents and Settings\ZV\Cookies\zv@cgm.adbureau[2].txt
C:\Documents and Settings\ZV\Cookies\zv@homeentertainment.112.2o7[1].txt
C:\Documents and Settings\ZV\Cookies\zv@media.adrevolver[1].txt
C:\Documents and Settings\ZV\Cookies\zv@revsci[1].txt
Combofix log:
ComboFix 09-04-13.A2 - ZV 2009-04-13 12:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1030.18.3070.2605 [GMT 2:00]
Kører fra: c:\documents and settings\ZV\Skrivebord\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
* Dannede nyt systemgendannelsespunkt
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\28463
c:\windows\system32\28463\AKV.exe
c:\windows\system32\28463\IKSI.exe
c:\windows\system32\ftx32.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-03-13 til 2009-04-13 )))))))))))))))))))))))))))))))))))
.
2009-04-10 08:35 . 2009-04-10 08:35 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-10 08:35 . 2009-04-10 08:35 -------- d-----w c:\documents and settings\ZV\Application Data\SUPERAntiSpyware.com
2009-04-09 11:36 . 2009-04-09 11:36 -------- d-----w c:\documents and settings\ZV\Application Data\Malwarebytes
2009-04-09 11:36 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-09 11:36 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 11:36 . 2009-04-09 11:36 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-04 16:44 . 2009-04-04 16:44 1080 ----a-w c:\windows\system32\settingsbkup.sfm
2009-04-04 16:44 . 2009-04-04 16:44 1080 ----a-w c:\windows\system32\settings.sfm
2009-04-04 13:53 . 2009-04-04 13:53 -------- d-----w c:\documents and settings\All Users\Application Data\Azureus
2009-04-04 13:53 . 2009-04-04 14:19 -------- d-----w c:\documents and settings\ZV\Application Data\Azureus
2009-04-04 10:59 . 2009-04-04 14:08 -------- d-----w C:\Bryllup
2009-04-04 09:48 . 2009-04-11 16:01 30528 ----a-w c:\windows\system32\BMXCtrlState-{00000011-00000000-0000000A-00001102-00000004-20021102}.rfx
2009-04-04 09:48 . 2009-04-11 16:01 30528 ----a-w c:\windows\system32\BMXBkpCtrlState-{00000011-00000000-0000000A-00001102-00000004-20021102}.rfx
2009-04-04 09:48 . 2009-04-11 16:01 11564 ----a-w c:\windows\system32\DVCState-{00000011-00000000-0000000A-00001102-00000004-20021102}.rfx
2009-04-04 09:47 . 2009-04-13 10:41 4933105 ----a-w c:\windows\{00000011-00000000-0000000A-00001102-00000004-20021102}.BAK
2009-04-04 09:43 . 2009-04-13 10:41 4933105 ----a-w c:\windows\{00000011-00000000-0000000A-00001102-00000004-20021102}.CDF
2009-04-01 14:51 . 2009-04-01 14:51 -------- d-----w c:\documents and settings\ZV\Lokale indstillinger\Application Data\Identities
2009-04-01 09:24 . 2005-05-04 06:20 53248 ------w c:\windows\system32\wdmioctl.dll
2009-04-01 09:24 . 2001-09-11 12:20 1285632 ------w c:\windows\system32\SMMedia.dll
2009-04-01 09:24 . 2006-07-10 12:42 49152 ------w c:\windows\system32\DSndUp.exe
2009-04-01 09:24 . 2002-04-17 12:05 45056 ------w c:\windows\system32\CleanUp.exe
2009-04-01 07:59 . 2002-06-11 17:55 13780 ----a-w c:\windows\system32\drivers\pfc.sys
2009-04-01 07:58 . 2009-04-01 07:58 -------- d-----w c:\documents and settings\ZV\Application Data\Apple Computer
2009-03-31 11:59 . 2009-03-31 11:59 -------- d-----w c:\windows\system32\(null)
2009-03-31 11:59 . 2007-02-19 05:56 21376 ----a-w c:\windows\system32\drivers\psadd.sys
2009-03-31 11:16 . 2009-03-31 11:16 -------- d-----w C:\SWTOOLS
2009-03-30 14:47 . 2003-06-19 11:08 15872 ----a-w c:\windows\system32\KeyFilter.dll
2009-03-30 14:47 . 2003-06-19 11:05 90112 ----a-w c:\windows\system32\WinMMFix.dll
2009-03-30 14:47 . 2003-06-19 11:05 540672 ----a-w c:\windows\system32\Dsi.dll
2009-03-30 14:46 . 2001-02-01 13:10 45056 ----a-w c:\windows\system32\wnaspi32.dll
2009-03-30 14:46 . 2001-01-30 09:21 24683 ----a-w c:\windows\system32\plugincpl130_02.cpl
2009-03-30 14:46 . 2009-03-30 14:46 -------- d-----w C:\Program Files
2009-03-30 14:46 . 2009-03-30 14:46 -------- d-----w c:\documents and settings\ZV\WINDOWS
2009-03-28 22:05 . 2009-04-04 12:57 -------- d-----w c:\documents and settings\ZV\Application Data\OpenOffice.org2
2009-03-26 14:09 . 2009-03-26 14:09 -------- d-----w c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\Apple
2009-03-25 16:23 . 2009-03-25 16:23 -------- d-----w c:\documents and settings\All Users\Application Data\Grass Valley
2009-03-25 16:22 . 2009-04-13 10:29 0 ----a-w c:\windows\TempFile
2009-03-25 16:22 . 2005-07-28 07:18 685056 ----a-w c:\windows\system32\drivers\hardlock.sys
2009-03-25 16:22 . 2006-10-30 08:56 69632 ----a-w c:\windows\system32\cuvccodc.dll
2009-03-25 16:22 . 2006-10-30 08:56 258048 ----a-w c:\windows\system32\cllccodc.dll
2009-03-25 16:22 . 2006-09-21 15:22 65536 ----a-w c:\windows\system32\cdvhcodc.dll
2009-03-25 16:22 . 2006-09-21 15:22 69632 ----a-w c:\windows\system32\cdv5codc.dll
2009-03-25 16:22 . 2006-05-01 10:08 4096 ----a-w c:\windows\system32\paveno.dll
2009-03-25 16:22 . 2006-03-26 12:48 671815 ----a-w c:\windows\system32\csehqa.dll
2009-03-25 16:22 . 2005-06-08 10:13 835665 ----a-w c:\windows\system32\cseuvec.dll
2009-03-25 16:22 . 2004-09-09 14:36 122961 ----a-w c:\windows\system32\csellc.dll
2009-03-25 16:22 . 2002-12-02 09:42 49152 ----a-w c:\windows\system32\cvpcdvc.dll
2009-03-25 16:20 . 2009-03-25 16:20 -------- d-----w c:\documents and settings\ZV\Application Data\InstallShield
2009-03-25 16:19 . 2009-03-25 16:19 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-25 16:19 . 2009-03-25 16:19 -------- d-----w c:\documents and settings\ZV\Lokale indstillinger\Application Data\Apple
2009-03-25 16:19 . 2009-03-25 16:19 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-03-25 16:18 . 2009-03-25 16:18 -------- d-----w c:\documents and settings\ZV\Lokale indstillinger\Application Data\Apple Computer
2009-03-24 12:44 . 1998-10-29 15:45 306688 ----a-w c:\windows\IsUninst.exe
2009-03-21 18:07 . 2009-03-21 18:39 -------- d-----w c:\documents and settings\ZV\Application Data\Mumble
2009-03-20 16:54 . 2009-03-20 16:54 -------- d-----w c:\documents and settings\All Users\Application Data\e-Safekey
2009-03-20 08:41 . 2009-03-20 16:54 -------- d-----w C:\downloads
2009-03-20 08:41 . 2009-03-20 08:41 -------- d-----w c:\documents and settings\ZV\Application Data\GrabPro
2009-03-20 08:41 . 2009-03-21 12:31 -------- d-----w c:\documents and settings\ZV\Application Data\Orbit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-13 10:44 . 2009-01-04 10:48 -------- d-----w c:\programmer\Fælles filer\BitDefender
2009-04-13 10:43 . 2009-01-17 11:08 81984 ----a-w c:\windows\system32\bdod.bin
2009-04-13 10:32 . 2009-04-13 10:30 32768 --sha-w c:\windows\Temp\History\History.IE5\MSHist012009041320090414\index.dat
2009-04-13 10:30 . 2009-04-13 10:30 32768 --sha-w c:\windows\Temp\History\History.IE5\MSHist012009040620090413\index.dat
2009-04-13 10:30 . 2009-01-24 11:21 32768 --sha-w c:\windows\Temp\History\History.IE5\index.dat
2009-04-13 10:30 . 2009-01-24 11:21 16384 --sha-w c:\windows\Temp\Cookies\index.dat
2009-04-13 10:30 . 2009-01-24 11:21 32768 --sha-w c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
2009-04-13 10:29 . 2009-04-10 08:35 -------- d-----w c:\programmer\SUPERAntiSpyware
2009-04-10 08:35 . 2009-01-04 10:10 -------- d-----w c:\programmer\Fælles filer\Wise Installation Wizard
2009-04-09 11:36 . 2009-04-09 11:36 -------- d-----w c:\programmer\Malwarebytes' Anti-Malware
2009-04-09 10:18 . 2009-03-20 08:41 -------- d-----w c:\programmer\Orbitdownloader
2009-04-09 10:13 . 2009-04-09 10:13 -------- d-----w c:\programmer\Trend Micro
2009-04-09 09:41 . 2009-04-09 09:41 -------- d-----w c:\programmer\Windows Defender
2009-04-06 21:35 . 2009-01-04 10:26 -------- d-----w c:\programmer\WinTV
2009-04-04 14:02 . 2009-04-04 14:02 -------- d-----w c:\programmer\Runtime Software
2009-04-04 13:53 . 2009-04-04 13:52 -------- d-----w c:\programmer\Vuze
2009-04-04 13:52 . 2009-04-04 13:52 -------- d-----w c:\programmer\Fælles filer\i4j_jres
2009-04-04 09:58 . 2009-04-04 09:58 -------- d-----w c:\programmer\Fælles filer\Blizzard Entertainment
2009-04-04 09:43 . 2009-01-04 10:27 -------- d--h--w c:\programmer\InstallShield Installation Information
2009-04-04 09:43 . 2009-04-04 09:43 -------- d-----w c:\programmer\Fælles filer\Creative Labs Shared
2009-04-04 09:43 . 2009-01-04 10:50 -------- d-----w c:\programmer\Creative
2009-04-04 09:43 . 2009-01-04 10:49 444952 ----a-w c:\windows\system32\wrap_oal.dll
2009-04-04 09:43 . 2009-01-04 10:49 109080 ----a-w c:\windows\system32\OpenAL32.dll
2009-04-04 09:43 . 2009-01-04 10:49 -------- d-----w c:\documents and settings\ZV\Application Data\Creative
2009-04-04 09:40 . 2009-01-04 10:48 -------- d-----w c:\programmer\Winamp
2009-04-04 09:27 . 2009-03-30 14:46 -------- d-----w c:\programmer\Avid
2009-04-01 09:24 . 2001-10-09 11:00 68966 ----a-w c:\windows\system32\perfc006.dat
2009-04-01 09:24 . 2001-10-09 11:00 406966 ----a-w c:\windows\system32\perfh006.dat
2009-04-01 09:24 . 2009-04-01 09:24 -------- d-----w c:\programmer\Analog Devices
2009-04-01 07:56 . 2009-04-01 07:56 -------- d-----w c:\programmer\Smart Projects
2009-03-31 11:59 . 2009-03-31 11:59 -------- d-----w c:\programmer\Lenovo
2009-03-31 11:59 . 2009-03-31 11:59 -------- d-----w c:\programmer\Fælles filer\Lenovo
2009-03-30 14:47 . 2009-03-30 14:47 -------- d-----w c:\programmer\Fælles filer\Digidesign
2009-03-30 14:46 . 2009-03-30 14:46 -------- d-----w c:\programmer\Rainbow Technologies
2009-03-29 10:16 . 2009-01-04 10:57 17088 ----a-w c:\documents and settings\ZV\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2009-03-28 22:05 . 2009-03-28 22:04 -------- d-----w c:\programmer\OpenOffice.org 2.4
2009-03-25 16:22 . 2009-03-25 16:21 -------- d-----w c:\programmer\Fælles filer\Canopus Shared
2009-03-25 16:21 . 2009-03-25 16:21 -------- d-----w c:\programmer\Fælles filer\Snell & Wilcox Shared
2009-03-25 16:21 . 2009-03-25 16:21 -------- d-----w c:\programmer\Grass Valley
2009-03-25 16:21 . 2009-03-25 16:21 -------- d-----w c:\programmer\Fælles filer\Grass Valley
2009-03-25 16:19 . 2009-03-25 16:19 -------- d-----w c:\programmer\QuickTime
2009-03-25 16:19 . 2009-03-25 16:19 -------- d-----w c:\programmer\Apple Software Update
2009-03-24 12:45 . 2009-03-24 12:45 -------- d-----w c:\programmer\FinalData
2009-03-21 18:07 . 2009-03-21 18:06 -------- d-----w c:\programmer\Mumble
2009-03-09 00:57 . 2009-03-09 00:57 -------- d-----w c:\programmer\Fælles filer\TechSmith Shared
2009-03-09 00:57 . 2009-03-09 00:57 -------- d-----w c:\programmer\TechSmith
2009-03-04 12:47 . 2009-03-04 12:47 15896 ----a-w c:\windows\system32\drivers\pfmodnt.sys
2009-03-04 12:46 . 2009-03-04 12:46 189464 ----a-w c:\windows\system32\drivers\haP17v2k.sys
2009-03-04 12:46 . 2009-03-04 12:46 162840 ----a-w c:\windows\system32\drivers\haP16v2k.sys
2009-03-04 12:46 . 2009-03-04 12:46 798744 ----a-w c:\windows\system32\drivers\ha10kx2k.sys
2009-03-04 12:46 . 2009-03-04 12:46 92696 ----a-w c:\windows\system32\drivers\emupia2k.sys
2009-03-04 12:46 . 2009-03-04 12:46 157208 ----a-w c:\windows\system32\drivers\ctsfm2k.sys
2009-03-04 12:45 . 2009-03-04 12:45 14360 ----a-w c:\windows\system32\drivers\ctprxy2k.sys
2009-03-04 12:45 . 2009-03-04 12:45 127512 ----a-w c:\windows\system32\drivers\ctoss2k.sys
2009-03-04 12:45 . 2009-03-04 12:45 1395992 ----a-w c:\windows\system32\drivers\CTMMFILT.SYS
2009-03-04 12:45 . 2009-03-04 12:45 18840 ----a-w c:\windows\system32\drivers\CTGAME.SYS
2009-03-04 12:44 . 2009-03-04 12:44 347080 ----a-w c:\windows\system32\drivers\ctdvda2k.sys
2009-03-04 12:44 . 2009-03-04 12:44 528408 ----a-w c:\windows\system32\drivers\ctaud2k.sys
2009-03-04 12:44 . 2009-03-04 12:44 511000 ----a-w c:\windows\system32\drivers\ctac32k.sys
2009-03-04 12:44 . 2009-03-04 12:44 1366424 ----a-w c:\windows\system32\drivers\CT0531FL.SYS
2009-03-04 12:42 . 2009-03-04 12:42 100888 ----a-w c:\windows\system32\drivers\CTERFXFX.sys
2009-03-04 12:42 . 2009-03-04 12:42 566296 ----a-w c:\windows\system32\drivers\CTSBLFX.sys
2009-03-04 12:42 . 2009-03-04 12:42 555032 ----a-w c:\windows\system32\drivers\CTAUDFX.sys
2009-03-04 12:42 . 2009-03-04 12:42 99352 ----a-w c:\windows\system32\drivers\COMMONFX.sys
2009-03-04 10:47 . 2009-03-04 10:47 43520 ----a-w c:\windows\system32\CTBurst.dll
2009-03-04 10:47 . 2009-03-04 10:47 11776 ----a-w c:\windows\system32\inres.dll
2009-03-04 10:47 . 2009-03-04 10:47 11776 ----a-w c:\windows\INRES.DLL
2009-03-04 10:47 . 2008-06-27 16:27 182272 ----a-w c:\windows\system32\ctdvinst.dll
2009-03-04 10:47 . 2008-06-27 16:27 86528 ----a-w c:\windows\system32\ctcoinst.dll
2009-03-04 10:46 . 2009-03-04 10:46 10752 ----a-w c:\windows\system32\a3d.dll
2009-03-04 10:46 . 2009-03-04 10:46 11776 ----a-w c:\windows\system32\ac3api.dll
2009-03-04 10:45 . 2009-03-04 10:45 38400 ----a-w c:\windows\system32\readreg.exe
2009-03-04 10:45 . 2009-03-04 10:45 37888 ----a-w c:\windows\system32\psconv.exe
2009-03-04 10:45 . 2009-03-04 10:45 19456 ----a-w c:\windows\system32\CtHelper.exe
2009-03-04 10:45 . 2009-03-04 10:45 8704 ----a-w c:\windows\system32\ctagent.dll
2009-03-04 10:45 . 2009-03-04 10:45 45568 ----a-w c:\windows\system32\ctspkhlp.dll
2009-03-04 10:45 . 2009-03-04 10:45 56832 ----a-w c:\windows\system32\CTpcmcia.dll
2009-03-04 10:45 . 2009-03-04 10:45 12800 ----a-w c:\windows\system32\ctmmep.dll
2009-03-04 10:45 . 2009-03-04 10:45 9216 ----a-w c:\windows\system32\ctpres.dll
2009-03-04 10:45 . 2009-03-04 10:45 9216 ----a-w c:\windows\CTPRES.DLL
2009-03-04 10:45 . 2009-03-04 10:45 32768 ----a-w c:\windows\system32\ctthxcal.dll
2009-03-04 10:44 . 2009-03-04 10:44 41472 ----a-w c:\windows\system32\ctscal.dll
2009-03-04 10:44 . 2009-03-04 10:44 131072 ----a-w c:\windows\system32\ctdcifce.dll
2009-03-04 10:44 . 2009-03-04 10:44 330752 ----a-w c:\windows\system32\ctdc0001.dll
2009-03-04 10:44 . 2009-03-04 10:44 227840 ----a-w c:\windows\system32\ctdc0000.dll
2009-03-04 10:44 . 2009-03-04 10:44 10240 ----a-w c:\windows\system32\ctdcres.dll
2009-03-04 10:44 . 2009-03-04 10:44 10240 ----a-w c:\windows\CTDCRES.DLL
2009-03-04 10:33 . 2009-03-04 10:33 51787 ----a-w c:\windows\system32\ctdlang.dat
2009-03-04 10:33 . 2009-03-04 10:33 386852 ----a-w c:\windows\system32\ctdnlstr.dat
2009-03-04 10:33 . 2009-03-04 10:33 196096 ----a-w c:\windows\system32\ctemupia.dll
2009-03-04 10:30 . 2009-03-04 10:30 176128 ----a-w c:\windows\system32\ct_oal.dll
2009-03-04 10:30 . 2009-03-04 10:30 46592 ----a-w c:\windows\system32\ctasio.dll
2009-03-04 10:30 . 2009-03-04 10:30 49152 ----a-w c:\windows\system32\ctdproxy.dll
2009-03-04 10:29 . 2009-03-04 10:29 69632 ----a-w c:\windows\system32\ctosuser.dll
2009-03-04 10:29 . 2009-03-04 10:29 6144 ----a-w c:\windows\system32\sfman32.dll
2009-03-04 10:29 . 2009-03-04 10:29 125952 ----a-w c:\windows\system32\sfms32.dll
2009-03-04 10:28 . 2009-03-04 10:28 13312 ----a-w c:\windows\system32\regplib.exe
2009-03-04 10:28 . 2009-03-04 10:28 64512 ----a-w c:\windows\system32\piaproxy.dll
2009-03-04 10:28 . 2009-03-04 10:28 149838 ----a-w c:\windows\system32\ctbas2w.dat
2009-03-04 10:26 . 2009-03-04 10:26 274587 ----a-w c:\windows\system32\ctsbas2w.dat
2009-03-05 16:2009-04-09 23:23 08:04 . c:\programmer\mozilla firefox\components\FFComm.dll
.
------- Sigcheck -------
- 2008-04-14 07:06 14336 555F8F4CB284FE94059DCACF6074F9EC c:\windows\system32\svchost.exe
- 2008-04-14 07:06 14336 555F8F4CB284FE94059DCACF6074F9EC c:\windows\system32\dllcache\svchost.exe
- 2008-04-14 07:05 578560 A45B00E0410E44E7177A403ECAD4B12A c:\windows\system32\user32.dll
- 2008-04-14 07:05 578560 A45B00E0410E44E7177A403ECAD4B12A c:\windows\system32\dllcache\user32.dll
- 2008-04-14 07:05 82432 4C92DB1CD4ABC8A986896FCD3070B4CE c:\windows\system32\ws2_32.dll
- 2008-04-14 07:05 82432 4C92DB1CD4ABC8A986896FCD3070B4CE c:\windows\system32\dllcache\ws2_32.dll
- 2008-04-14 07:06 507904 E0339362391BF6AC04D1622EF8E3A61B c:\windows\system32\winlogon.exe
- 2008-04-14 07:06 507904 E0339362391BF6AC04D1622EF8E3A61B c:\windows\system32\dllcache\winlogon.exe
- 2008-04-13 10:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\dllcache\ndis.sys
- 2008-04-13 10:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\drivers\ndis.sys
- 2008-04-13 09:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\dllcache\ip6fw.sys
- 2008-04-13 09:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\drivers\ip6fw.sys
- 2008-08-14 18:27 2068608 879F6F04D5BBC90B261F8C25AB68539D c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
- 2008-04-14 07:18 2026496 A1BA9C3748329ACB5C5A0E39004042F8 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
- 2008-08-14 13:25 2068608 EDFAC73972E95151A1C95E4EB811545D c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2008-08-14 13:25 2026496 00315E597422FEFB19B6586323933CE2 c:\windows\system32\ntkrnlpa.exe
- 2008-08-14 13:25 2068608 EDFAC73972E95151A1C95E4EB811545D c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-08-14 18:27 2191744 F88F5258032106D211EC7B1167D4B434 c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
- 2008-04-14 06:44 2147840 1AAE08DE2AE92E1244E94C6BAD07E248 c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
- 2008-08-14 13:25 2191744 A9B263F4FCF70BFD47BC6C9D6476502F c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-08-14 13:25 2147840 0706E1752A43CE555D73D8931367756C c:\windows\system32\ntoskrnl.exe
- 2008-08-14 13:25 2191744 A9B263F4FCF70BFD47BC6C9D6476502F c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-04-14 07:05 1034752 1D9BD1CAA1E4CF63370F201DF742DC7D c:\windows\explorer.exe
- 2008-04-14 07:05 1034752 1D9BD1CAA1E4CF63370F201DF742DC7D c:\windows\system32\dllcache\explorer.exe
- 2008-04-14 07:06 108544 AB2B6ABF3FCDA803FF0E2251F9A5274E c:\windows\system32\services.exe
- 2008-04-14 07:06 108544 AB2B6ABF3FCDA803FF0E2251F9A5274E c:\windows\system32\dllcache\services.exe
- 2008-04-14 07:05 13312 AC9FCA8BCD685ABDB9928B1964B731A2 c:\windows\system32\lsass.exe
- 2008-04-14 07:05 13312 AC9FCA8BCD685ABDB9928B1964B731A2 c:\windows\system32\dllcache\lsass.exe
- 2008-04-14 07:05 15360 CB8D8AB9CED50556501014F97A9FA270 c:\windows\system32\ctfmon.exe
- 2008-04-14 07:05 15360 CB8D8AB9CED50556501014F97A9FA270 c:\windows\system32\dllcache\ctfmon.exe
- 2008-04-14 07:06 57856 E06D0A59737CF479466A86AB5E2A0B6B c:\windows\system32\spoolsv.exe
- 2008-04-14 07:06 57856 E06D0A59737CF479466A86AB5E2A0B6B c:\windows\system32\dllcache\spoolsv.exe
- 2008-04-14 07:06 26112 7B3770DB760FBBA068454EAFCAA89772 c:\windows\system32\userinit.exe
- 2008-04-14 07:06 26112 7B3770DB760FBBA068454EAFCAA89772 c:\windows\system32\dllcache\userinit.exe
- 2008-04-14 07:05 296448 14C8EC0AA06A33CCC5407E4324F91312 c:\windows\system32\termsrv.dll
- 2008-04-14 07:05 296448 14C8EC0AA06A33CCC5407E4324F91312 c:\windows\system32\dllcache\termsrv.dll
- 2008-04-14 07:05 1006080 99ED0BF23810EC30271A5B1A00968791 c:\windows\system32\kernel32.dll
- 2008-04-14 07:05 1006080 99ED0BF23810EC30271A5B1A00968791 c:\windows\system32\dllcache\kernel32.dll
- 2008-04-14 07:05 17408 71F270F3E6092CA48920FA3876ED86A2 c:\windows\system32\powrprof.dll
- 2008-04-14 07:05 17408 71F270F3E6092CA48920FA3876ED86A2 c:\windows\system32\dllcache\powrprof.dll
- 2008-04-14 07:05 110080 E8C6B982597CD2BA53D73A068CDF9D8C c:\windows\system32\imm32.dll
- 2008-04-14 07:05 110080 E8C6B982597CD2BA53D73A068CDF9D8C c:\windows\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\programmer\Fælles filer\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"SUPERAntiSpyware"="c:\programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-13 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\programmer\Fælles filer\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"RemoteControl"="c:\programmer\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2009-01-05 413696]
"NexusServer"="c:\programmer\Fælles filer\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" [2007-03-26 389120]
"TVT Scheduler Proxy"="c:\programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"SoundMAXPnP"="c:\programmer\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352]
"nwiz"="nwiz.exe" [2008-11-12 c:\windows\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2009-03-04 c:\windows\system32\CtHelper.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2009-04-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-04-13 12:29 356352 c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.CDVC"= cdvccodc.dll
"vidc.CDVH"= cdvhcodc.dll
"vidc.CUVC"= cuvccodc.dll
"vidc.CLLC"= cllccodc.dll
"vidc.CDV5"= cdv5codc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Games\\Guitar Hero III\\GH3.exe"=
"c:\\Programmer\\Ventrilo\\Ventrilo.exe"=
"e:\\Games\\World of Warcraft\\Launcher.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Orbitdownloader\\orbitdm.exe"=
"c:\\Programmer\\Orbitdownloader\\orbitnet.exe"=
"e:\\Games\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Programmer\\Vuze\\Azureus.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - SASDIFSV
.
Indhold af mappen 'Planlagte Opgaver'
2009-04-07 c:\windows\Tasks\!Chunks1e02.job
- c:\progra~1\WinTV\Scheduler\StayAwake.exe [2008-03-06 14:04]
2009-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-04-07 c:\windows\Tasks\Chunks1e02.job
- c:\progra~1\WinTV\WinTV2K.EXE [2006-03-29 17:28]
2009-04-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmer\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKLM-Run-WinampAgent - c:\programmer\Winamp\winampa.exe
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/IE: &Download by Orbit - c:\programmer\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\programmer\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\programmer\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\programmer\Orbitdownloader\orbitmxt.dll/202
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabFF - ProfilePath - c:\documents and settings\ZV\Application Data\Mozilla\Firefox\Profiles\xvmuzozk.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/FF - component: c:\programmer\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.0_02\bin\NPJava130_02.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.0_02\bin\NPOJI600.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-13 12:47
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2009-04-13 12:48
ComboFix-quarantined-files.txt 2009-04-13 10:48
Pre-Kørsel: 50.982.600.704 byte ledig
Post-Kørsel: 52,271,890,432 byte ledig
319 --- E O F --- 2009-04-09 12:06