Combofix log
ComboFix 09-06-22.0E - Admin 23-06-2009 21:11.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.45.1030.18.2046.844 [GMT 2:00]
Kører fra: c:\users\Michael\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3522495347-3552900226-3149808774-500
c:\$recycle.bin\S-1-5-21-4272318485-1682127081-3642472035-500
c:\$recycle.bin\S-1-5-21-3522495347-3552900226-3149808774-500\desktop.ini
c:\$recycle.bin\S-1-5-21-4272318485-1682127081-3642472035-500\desktop.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\KBL.LOG
D:\Desktop.ini
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-05-23 til 2009-06-23 )))))))))))))))))))))))))))))))))))
.
2009-06-23 19:08 . 2009-06-23 19:08 -------- d-----w- c:\programdata\HPSSUPPLY
2009-06-23 18:51 . 2007-05-02 10:03 267864 ----a-w- c:\windows\system32\hpzids01.dll
2009-06-23 18:51 . 2007-03-15 13:32 118272 ----a-w- c:\windows\system32\hpz3l5ha.dll
2009-06-23 18:47 . 2009-06-23 19:01 -------- d-----w- c:\windows\LastGood
2009-06-23 08:00 . 2009-06-23 08:00 -------- d-----w- c:\windows\system32\Adobe
2009-06-20 18:28 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-06-20 18:28 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-20 18:28 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-20 18:28 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-06-20 18:28 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-06-20 18:28 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-20 18:28 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-06-20 16:27 . 2008-02-23 04:38 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-06-20 16:27 . 2008-02-23 02:41 22528 ----a-w- c:\windows\system32\netiougc.exe
2009-06-20 16:26 . 2009-02-15 22:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2009-06-20 16:26 . 2009-02-15 22:10 69000 ----a-w- c:\windows\system32\zlcomm.dll
2009-06-20 16:25 . 2009-02-15 22:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-06-20 16:25 . 2009-06-20 16:25 -------- d-----w- c:\program files\Zone Labs
2009-06-20 16:25 . 2009-06-20 16:26 -------- d-----w- c:\windows\system32\ZoneLabs
2009-06-20 16:25 . 2009-02-15 22:11 293528 ----a-w- c:\windows\system32\drivers\vsdatant.sys
2009-06-20 16:24 . 2009-06-20 16:24 -------- d-----w- c:\programdata\CheckPoint
2009-06-20 15:58 . 2009-06-20 15:58 -------- d-----w- C:\PerfLogs
2009-06-20 14:59 . 2009-05-09 05:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-06-20 14:58 . 2009-05-09 05:50 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-20 14:38 . 2008-01-19 07:36 1541120 ----a-w- c:\windows\system32\onex.dll
2009-06-20 14:38 . 2008-01-19 07:33 2623488 ----a-w- c:\windows\system32\SLsvc.exe
2009-06-20 14:38 . 2008-01-19 07:42 51768 ----a-w- c:\windows\system32\PSHED.DLL
2009-06-20 14:38 . 2008-01-19 07:29 705536 ----a-w- c:\windows\system32\imagesp1.dll
2009-06-20 14:38 . 2008-01-19 04:10 681984 ----a-w- c:\windows\system32\drivers\spsys.sys
2009-06-20 14:38 . 2008-01-19 07:36 1107968 ----a-w- c:\windows\system32\pidgenx.dll
2009-06-20 14:38 . 2008-01-19 07:33 2091520 ----a-w- c:\windows\system32\dfsr.exe
2009-06-20 14:38 . 2008-01-19 07:36 116736 ----a-w- c:\windows\system32\sstpsvc.dll
2009-06-20 14:38 . 2008-01-19 07:35 2061824 ----a-w- c:\windows\system32\mstscax.dll
2009-06-20 14:36 . 2008-01-19 07:36 225792 ----a-w- c:\windows\system32\SLC.dll
2009-06-20 14:35 . 2008-01-19 07:42 192056 ----a-w- c:\windows\system32\drivers\fltMgr.sys
2009-06-20 14:34 . 2008-01-19 07:33 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-06-20 14:33 . 2008-01-19 07:37 56320 ----a-w- c:\windows\system32\wscmisetup.dll
2009-06-20 14:32 . 2008-01-19 07:35 450560 ----a-w- c:\windows\system32\msxbde40.dll
2009-06-20 14:31 . 2008-01-19 07:33 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2009-06-20 14:31 . 2006-11-02 09:46 151552 ----a-w- c:\windows\system32\WpdMtp.dll
2009-06-20 14:30 . 2008-01-19 07:34 102400 ----a-w- c:\windows\system32\wbem\mofinstall.dll
2009-06-20 14:30 . 2008-01-19 07:36 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-06-20 14:30 . 2008-01-19 07:36 742912 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-06-20 14:30 . 2008-01-19 07:36 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-06-20 14:30 . 2008-01-19 07:36 357888 ----a-w- c:\windows\system32\wbemcomn.dll
2009-06-20 14:30 . 2008-01-19 07:36 264704 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-06-20 14:30 . 2008-01-19 07:34 191488 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-06-20 14:30 . 2008-01-19 07:34 263168 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-06-20 14:29 . 2008-01-19 07:36 129536 ----a-w- c:\windows\system32\sqmapi.dll
2009-06-20 14:29 . 2008-01-19 07:36 704512 ----a-w- c:\windows\system32\SmiEngine.dll
2009-06-20 14:29 . 2008-01-19 07:36 139264 ----a-w- c:\windows\system32\SmiInstaller.dll
2009-06-20 14:29 . 2008-01-19 07:36 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-06-20 14:29 . 2008-01-19 07:33 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-06-20 14:27 . 2008-01-19 07:34 246784 ----a-w- c:\windows\system32\drvstore.dll
2009-06-20 14:27 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll
2009-06-20 14:27 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll
2009-06-20 14:27 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll
2009-06-20 13:08 . 2009-06-23 07:40 680 ----a-w- c:\users\Michael\AppData\Local\d3d9caps.dat
2009-06-20 11:16 . 2009-06-20 11:16 212480 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-06-20 11:16 . 2009-06-20 11:16 269312 ----a-w- c:\windows\system32\es.dll
2009-06-20 11:15 . 2009-06-20 11:15 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-06-20 11:13 . 2009-06-20 11:13 2048 ----a-w- c:\windows\system32\tzres.dll
2009-06-20 11:09 . 2009-06-20 11:09 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-20 11:05 . 2009-06-20 11:05 2927104 ----a-w- c:\windows\explorer.exe
2009-06-20 10:07 . 2009-06-20 10:07 -------- d-----w- c:\program files\Microsoft Silverlight
2009-06-19 22:01 . 2009-06-19 22:01 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-06-19 22:01 . 2009-06-19 22:01 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-06-19 22:01 . 2009-06-19 22:01 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-06-19 22:01 . 2009-06-19 22:01 272896 ----a-w- c:\windows\system32\polstore.dll
2009-06-19 22:00 . 2009-06-19 22:00 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-06-19 22:00 . 2009-06-19 22:00 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-06-19 22:00 . 2009-06-19 22:00 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-06-19 21:56 . 2009-06-19 21:56 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-19 21:56 . 2009-06-19 21:56 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-19 21:54 . 2009-06-19 21:54 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-06-19 21:49 . 2009-06-19 21:49 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-06-19 21:49 . 2009-06-19 21:49 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-06-19 21:43 . 2009-06-19 21:43 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-06-19 20:56 . 2009-06-19 20:56 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2009-06-19 20:56 . 2009-06-19 20:56 38912 ----a-w- c:\windows\system32\xolehlp.dll
2009-06-19 20:13 . 2009-06-19 20:13 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-06-19 20:12 . 2009-06-19 20:12 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-06-19 20:12 . 2009-06-19 20:12 1695744 ----a-w- c:\windows\system32\gameux.dll
2009-06-19 19:55 . 2009-06-19 19:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-06-19 19:55 . 2009-06-19 19:55 1191936 ----a-w- c:\windows\system32\msxml3.dll
2009-06-19 19:38 . 2009-06-19 19:38 -------- d--h--r- c:\users\Michael\AppData\Roaming\SecuROM
2009-06-19 19:37 . 2009-06-19 19:37 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-06-19 19:36 . 2009-06-19 19:36 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-06-19 19:36 . 2009-06-19 19:36 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-06-19 19:33 . 2009-06-19 19:09 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-19 19:33 . 2009-06-19 19:33 10134 ----a-r- c:\users\Admin\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-19 19:33 . 2009-06-19 19:33 -------- d-----w- c:\program files\Microsoft WSE
2009-06-19 19:33 . 2009-06-19 19:33 -------- d-----w- c:\users\Michael\AppData\Local\Microsoft Help
2009-06-19 19:33 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-06-19 19:11 . 2009-06-19 19:11 1793536 ----a-w- c:\windows\system32\NlsLexicons0045.dll
2009-06-19 19:11 . 2009-06-19 19:11 1808896 ----a-w- c:\windows\system32\NlsLexicons0046.dll
2009-06-19 19:11 . 2009-06-19 19:11 1411072 ----a-w- c:\windows\system32\NlsLexicons0047.dll
2009-06-19 19:11 . 2009-06-19 19:11 1558016 ----a-w- c:\windows\system32\NlsLexicons0049.dll
2009-06-19 19:11 . 2009-06-19 19:11 1236992 ----a-w- c:\windows\system32\NlsLexicons0020.dll
2009-06-19 19:11 . 2009-06-19 19:11 1782272 ----a-w- c:\windows\system32\NlsLexicons0039.dll
2009-06-19 19:10 . 2009-06-19 19:10 2136064 ----a-w- c:\windows\system32\NlsLexicons0021.dll
2009-06-19 19:10 . 2009-06-19 19:10 5499904 ----a-w- c:\windows\system32\NlsLexicons0022.dll
2009-06-19 19:10 . 2009-06-19 19:10 7964672 ----a-w- c:\windows\system32\NlsLexicons0024.dll
2009-06-19 19:10 . 2009-06-19 19:10 5791232 ----a-w- c:\windows\system32\NlsLexicons0026.dll
2009-06-19 19:10 . 2009-06-19 19:10 6224896 ----a-w- c:\windows\system32\NlsLexicons0027.dll
2009-06-19 19:10 . 2009-06-19 19:10 4175872 ----a-w- c:\windows\system32\NlsLexicons0010.dll
2009-06-19 19:10 . 2009-06-19 19:10 2466816 ----a-w- c:\windows\system32\NlsLexicons0011.dll
2009-06-19 19:10 . 2009-06-19 19:10 4981248 ----a-w- c:\windows\system32\NlsLexicons0013.dll
2009-06-19 19:10 . 2009-06-19 19:10 3331072 ----a-w- c:\windows\system32\NlsLexicons0018.dll
2009-06-19 19:10 . 2009-06-19 19:10 6781440 ----a-w- c:\windows\system32\NlsLexicons0019.dll
2009-06-19 19:09 . 2009-06-19 19:09 11722752 ----a-w- c:\windows\system32\NlsLexicons0001.dll
2009-06-19 19:09 . 2009-06-19 19:09 4164096 ----a-w- c:\windows\system32\NlsLexicons0002.dll
2009-06-19 19:09 . 2009-06-19 19:09 1452544 ----a-w- c:\windows\system32\NlsLexicons0003.dll
2009-06-19 19:09 . 2009-06-19 19:09 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-06-19 19:09 . 2009-06-19 19:09 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-06-19 19:09 . 2009-06-19 19:09 3419136 ----a-w- c:\windows\system32\NlsLexicons004a.dll
2009-06-19 19:09 . 2009-06-19 19:09 1702912 ----a-w- c:\windows\system32\NlsLexicons004b.dll
2009-06-19 19:09 . 2009-06-19 19:09 4093440 ----a-w- c:\windows\system32\NlsLexicons004c.dll
2009-06-19 19:09 . 2009-06-19 19:09 1972736 ----a-w- c:\windows\system32\NlsLexicons004e.dll
2009-06-19 19:08 . 2009-06-19 19:08 4045824 ----a-w- c:\windows\system32\NlsLexicons003e.dll
2009-06-19 19:08 . 2009-06-19 19:08 4096 ----a-w- c:\windows\system32\NlsLexicons002a.dll
2009-06-19 19:08 . 2009-06-19 19:08 6014976 ----a-w- c:\windows\system32\NlsLexicons001a.dll
2009-06-19 19:08 . 2009-06-19 19:08 6585856 ----a-w- c:\windows\system32\NlsLexicons001b.dll
2009-06-19 19:08 . 2009-06-19 19:08 6346240 ----a-w- c:\windows\system32\NlsLexicons001d.dll
2009-06-19 19:08 . 2009-06-19 19:08 9892864 ----a-w- c:\windows\system32\NlsLexicons000a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 19:16 . 2008-02-26 02:01 589296 ----a-w- c:\windows\system32\perfh01D.dat
2009-06-23 19:16 . 2008-02-26 02:01 117296 ----a-w- c:\windows\system32\perfc01D.dat
2009-06-23 19:16 . 2008-02-26 01:47 77202 ----a-w- c:\windows\system32\perfc006.dat
2009-06-23 19:16 . 2008-02-26 01:47 463344 ----a-w- c:\windows\system32\perfh006.dat
2009-06-23 19:09 . 2009-06-23 18:54 164170 ----a-w- c:\windows\hpoins21.dat
2009-06-23 19:08 . 2008-03-22 02:55 -------- d-----w- c:\program files\HP
2009-06-23 19:08 . 2008-02-26 03:24 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-23 19:06 . 2009-06-23 18:52 -------- d-----w- c:\programdata\HP
2009-06-23 19:05 . 2009-06-23 19:05 -------- d-----w- c:\programdata\HP Product Assistant
2009-06-23 19:04 . 2009-06-23 19:04 -------- d-----w- c:\program files\Common Files\HP
2009-06-23 19:02 . 2009-06-23 19:02 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-23 18:53 . 2008-02-26 04:20 -------- d-----w- c:\programdata\Hewlett-Packard
2009-06-23 18:47 . 2009-06-23 18:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-06-23 18:42 . 2009-06-20 16:25 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-06-23 07:41 . 2009-06-20 10:40 42237 ----a-w- c:\programdata\nvModes.dat
2009-06-21 13:47 . 2009-06-21 13:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-20 16:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-20 16:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-20 15:58 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-20 15:34 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-06-20 15:34 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-06-20 10:02 . 2008-03-22 03:04 -------- d-----w- c:\programdata\NVIDIA
2009-06-20 09:52 . 2008-03-22 02:49 -------- d-----w- c:\program files\CONEXANT
2009-06-19 21:46 . 2009-06-18 20:53 27525 ----a-w- c:\users\Michael\AppData\Roaming\nvModes.dat
2009-06-19 19:22 . 2008-02-26 03:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-19 19:06 . 2009-06-19 19:06 2643456 ----a-w- c:\windows\system32\NlsData000c.dll
2009-06-19 19:06 . 2009-06-19 19:06 2342912 ----a-w- c:\windows\system32\NlsData000d.dll
2009-06-19 19:06 . 2009-06-19 19:06 1965056 ----a-w- c:\windows\system32\NlsData000f.dll
2009-06-19 19:06 . 2009-06-19 19:06 4495360 ----a-w- c:\windows\system32\NlsData0414.dll
2009-06-19 19:06 . 2009-06-19 19:06 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2009-06-19 19:06 . 2009-06-19 19:06 4495360 ----a-w- c:\windows\system32\NlsData0416.dll
2009-06-19 19:06 . 2009-06-19 19:06 4495360 ----a-w- c:\windows\system32\NlsData0816.dll
2009-06-19 19:06 . 2009-06-19 19:06 1965056 ----a-w- c:\windows\system32\NlsData081a.dll
2009-06-19 19:06 . 2009-06-19 19:06 6917120 ----a-w- c:\windows\system32\NlsLexicons0c1a.dll
2009-06-19 19:06 . 2009-06-19 19:06 1965056 ----a-w- c:\windows\system32\NlsData0c1a.dll
2009-06-18 20:50 . 2008-02-26 03:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-18 20:44 . 2008-02-26 03:30 -------- d-----w- c:\programdata\Symantec
2009-06-18 20:23 . 2008-03-22 02:57 -------- d-----w- c:\program files\HPQ
2009-06-18 20:21 . 2009-06-18 20:21 0 --sha-r- c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv6700 Notebook PC_Y5335KV_0U_QCNF8113YBK_E459053-DH5_4A_I30D0_SQuanta_V85.24_F.2A_T080222_WV3-0_L406_M2047_J250_7AMD_8F82_91.90_#080225_N10DE0450;168C001C_(KW098EA#UUW)_XMOBILE_CN10_Z.MRK
2009-06-18 20:12 . 2009-06-18 20:12 -------- d-sh--we c:\programdata\Templates
2009-06-18 20:12 . 2009-06-18 20:12 -------- d-sh--we c:\programdata\Start Menu
2009-06-18 20:12 . 2009-06-18 20:12 -------- d-sh--we c:\programdata\Favorites
2009-06-18 20:12 . 2009-06-18 20:12 -------- d-sh--we c:\programdata\Documents
2009-06-18 20:12 . 2009-06-18 20:12 -------- d-sh--we c:\programdata\Desktop
2008-04-28 13:45 . 2009-06-19 06:08 32 --sha-w- c:\windows\SMINST\HPCD.SYS
2008-02-26 02:57 . 2008-02-26 02:37 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-19 1947928]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-19 68592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6D5471FF-DE17-4FA1-AA9D-12F8EFB527DB}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{E091E6C3-58B6-4902-9868-3223AF0A2E5F}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{6207A3F2-DBAF-42F8-9339-F9B3AE19F971}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{23836983-E25E-437A-BEE4-AA4FBDADC3AC}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{0D96BA6C-DDB9-4435-9A93-40F201BFCAF3}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{0D9E220F-E0D2-4D57-B6B2-1EE1031AEFBB}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{8E1ED444-55E9-4F0B-BAB9-0DE7AE1F659E}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{16EB2A39-014C-44CF-A208-B1BC5E8B9D31}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{8D2E314D-0940-4135-A6D4-63856E765A4A}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{EA93E459-F5DA-45B1-8977-45D1297AA823}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{07F14F51-F28D-4E0E-BA5F-9BB059C42BD2}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{409D4E2A-43F7-44E4-B0B1-6249DB376932}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{44B7886D-4B8C-437C-ADE6-F5A19C399F67}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{D2050C38-8F88-46C5-A33E-8958B906C734}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{1ADE1934-8A94-4529-9389-43E4B19759A3}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{A9E313CC-8EFA-43EF-8A1A-F8123EC38D11}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{3C2C7086-F6BD-4112-8952-AAD4CA878805}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{7553D91D-C47A-4021-8ED8-41DFF6B874FA}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{02FF8ECC-4DF9-45A1-A332-C16AE341C7B7}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{D807E81E-5BB6-4D5F-B785-65DE64D63C8C}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{81A591B0-E1B5-4D91-AEEA-FBA6861A8B78}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{A03D867C-5F10-4EDA-A349-4942E4F56D11}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{5AD9D142-F022-48A3-856F-6861397E6636}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{38D0519B-8CC1-41F4-B0E1-F07F6DB36C21}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
"{82819F22-080E-4196-A463-096264046A14}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{EF8143D0-4C78-413B-B986-BC32F01BD17B}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{B7D1FD14-3116-4FB0-8F0E-4FDEE12058FA}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{3DAD68F0-1FBF-448C-B04F-F357E4CCA171}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{DF8508C7-90DB-4550-8F85-5712719F8DB2}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{FAA60483-64D8-4DBC-BB54-EFF86FE608C5}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{08125376-3473-407F-97BD-07F1633E0118}"= Disabled:UDP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
"{9ADD1D83-1004-456E-8BFA-DB8CC14F0734}"= Disabled:TCP:c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [18-06-2009 22:38 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [18-06-2009 22:38 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18-06-2009 22:38 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18-06-2009 22:38 298776]
S3 V0260VID;Live! Cam Vista IM;c:\windows\System32\drivers\V0260Vid.sys [19-06-2009 16:45 162176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Indhold af mappen 'Planlagte Opgaver'
2009-06-23 c:\windows\Tasks\User_Feed_Synchronization-{909104A9-63CD-476A-92C1-738A4471C219}.job
- c:\windows\system32\msfeedssync.exe [2009-06-20 11:31]
.
- - - - TOMME GENVEJE FJERNET - - - -
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptopmStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptopTrusted Zone: danid.dk
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.portalbank.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cabDPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} -
hxxps://danid.dk/csp/authenticode/csp.exe.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-23 21:19
Windows 6.0.6001 Service Pack 1 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_USERS\S-1-5-21-4272318485-1682127081-3642472035-1001\Software\SecuROM\License information*]
"datasecu"=hex:b1,8a,50,f3,97,db,37,e0,6b,a5,43,81,e0,0e,36,81,38,fa,63,07,26,
67,bf,06,3f,3c,28,c8,97,d3,23,06,ef,5a,1d,18,12,05,b3,85,cd,a1,84,bf,43,a4,\
"rkeysecu"=hex:6d,50,d2,fa,e7,9f,ec,db,f9,8e,f5,7b,28,1a,4a,d5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Gennemført tid: 2009-06-23 21:21
ComboFix-quarantined-files.txt 2009-06-23 19:21
Pre-Kørsel: 170.029.785.088 byte ledig
Post-Kørsel: 170.278.965.248 byte ledig
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
339 --- E O F --- 2009-06-22 17:29