F-arn, nu har jeg prøvet det du henviste til også kommer følgende logfil frem;
ComboFix 09-10-30.01 - Fam. Tanggaard Bille 31-10-2009 12:25.4.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.45.1030.18.766.290 [GMT 1:00]
Kører fra: c:\users\Fam. Tanggaard Bille\Desktop\ComboFix.exe
AV: F-Secure Client Security 7.10 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Client Security 7.10 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: F-Secure Client Security 7.10 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-09-28 til 2009-10-31 )))))))))))))))))))))))))))))))))))
.
2009-10-31 11:36 . 2009-10-31 11:37 -------- d-----w- c:\users\Fam. Tanggaard Bille\AppData\Local\temp
2009-10-31 11:36 . 2009-10-31 11:36 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-31 11:36 . 2009-10-31 11:36 -------- d-----w- c:\users\FAM~1~TAN\AppData\Local\temp
2009-10-31 11:36 . 2009-10-31 11:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-31 11:25 . 2009-04-11 06:32 19944 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-10-31 11:25 . 2007-08-09 17:12 110624 ----a-w- c:\windows\system32\drivers\nvstor32.sys
2009-10-31 11:25 . 2007-01-05 19:59 35920 ----a-w- c:\windows\system32\drivers\nvstor.sys
2009-10-30 15:02 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-30 15:02 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-20 15:22 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-20 15:22 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-20 15:21 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-20 15:20 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-20 15:02 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-20 14:49 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-02 17:33 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 10:55 . 2007-06-12 22:31 84790 ----a-w- c:\windows\system32\perfc006.dat
2009-10-31 10:55 . 2007-06-12 22:31 483230 ----a-w- c:\windows\system32\perfh006.dat
2009-10-25 18:49 . 2007-09-14 04:32 13730 ----a-w- c:\users\Fam. Tanggaard Bille\AppData\Roaming\nvModes.dat
2009-10-20 16:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-20 16:06 . 2007-06-12 13:02 -------- d-----w- c:\program files\Microsoft Works
2009-09-27 16:30 . 2008-08-28 05:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-27 14:07 . 2009-09-27 14:03 -------- d-----w- c:\program files\Silke
2009-09-24 17:04 . 2009-09-24 17:04 -------- d-----w- c:\program files\Common Files\e-Safekey
2009-09-24 17:04 . 2006-12-09 13:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-23 18:03 . 2009-09-23 18:03 -------- d-----w- c:\programdata\e-Safekey
2009-09-22 18:36 . 2009-05-06 19:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-18 19:37 . 2009-09-18 19:37 -------- d-----w- c:\programdata\McAfee
2009-09-16 17:29 . 2009-09-16 17:29 -------- d-----w- c:\programdata\McAfee Security Scan
2009-09-10 12:54 . 2008-08-28 05:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2008-08-28 05:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 12:49 . 2009-05-05 20:23 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 19:30 . 2007-09-14 04:32 69272 ----a-w- c:\users\Fam. Tanggaard Bille\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-08 19:17 . 2009-06-09 19:18 0 ----a-w- c:\users\Fam. Tanggaard Bille\temp.dat
2009-09-04 20:07 . 2007-09-18 20:28 680 ----a-w- c:\users\Fam. Tanggaard Bille\AppData\Local\d3d9caps.dat
2009-09-04 19:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-09-04 19:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-09-04 19:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-09-04 19:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-04 19:39 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-09-04 19:31 . 2008-07-14 06:58 -------- d-----w- c:\program files\Common Files\Logitech
2009-09-03 19:03 . 2007-06-12 13:00 -------- d-----w- c:\programdata\Microsoft Help
2009-09-03 18:46 . 2007-09-20 18:43 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-29 00:27 . 2009-09-03 18:29 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-03 18:29 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:22 . 2009-10-20 16:10 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-20 16:10 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-20 16:10 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-20 16:10 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-20 13:09 . 2009-08-20 13:09 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:27 . 2009-09-08 19:03 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-08 19:02 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-08 19:03 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-08 19:03 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-08 19:02 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-08 19:03 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-08 19:03 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-08 19:03 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-08 19:03 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-08 19:03 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-08 19:03 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-03 13:07 . 2009-08-03 13:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 13:07 . 2009-08-03 13:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 13:07 . 2009-08-03 13:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-10-20_17.44.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-30 14:21 . 2009-10-01 11:55 92160 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22933_none_8444da075fea9e51\iecompat.dll
+ 2009-10-30 14:21 . 2009-10-01 03:59 92160 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18842_none_83af6d0646d60121\iecompat.dll
+ 2007-06-12 12:37 . 2009-10-31 09:30 67184 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-10-31 10:48 68946 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-09-14 04:29 . 2009-10-31 10:48 16090 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-653627467-3041025058-2117155716-1000_UserData.bin
- 2007-09-14 04:29 . 2009-10-20 17:05 16090 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-653627467-3041025058-2117155716-1000_UserData.bin
- 2007-09-14 04:31 . 2009-10-20 17:24 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-09-14 04:31 . 2009-10-31 09:54 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-09-14 04:31 . 2009-10-31 09:54 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-14 04:31 . 2009-10-20 17:24 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-14 04:31 . 2009-10-20 17:24 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-09-14 04:31 . 2009-10-31 09:54 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-20 17:46 . 2009-10-20 17:46 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f7cfb619815540da7efa7d0ce6cd581c\System.Windows.Presentation.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\94a159c32cf1d5ff553e2c12861c7e9f\System.Web.DynamicData.Design.ni.dll
+ 2009-10-30 15:02 . 2009-09-10 15:10 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\spwmp.dll
+ 2009-10-30 15:02 . 2009-09-10 15:10 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\dxmasf.dll
+ 2009-08-13 06:32 . 2009-07-15 12:39 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\spwmp.dll
+ 2009-08-13 06:32 . 2009-07-15 12:39 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\dxmasf.dll
+ 2009-10-30 15:02 . 2009-09-10 20:45 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\spwmp.dll
+ 2009-10-30 15:02 . 2009-09-10 20:45 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\dxmasf.dll
+ 2009-08-13 06:32 . 2009-07-14 12:58 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\spwmp.dll
+ 2009-08-13 06:32 . 2009-07-14 12:59 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\dxmasf.dll
+ 2009-10-30 15:02 . 2009-09-10 17:30 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\spwmp.dll
+ 2009-10-30 15:02 . 2009-09-10 17:31 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\dxmasf.dll
+ 2009-10-30 15:02 . 2009-09-10 17:39 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\spwmp.dll
+ 2009-10-30 15:02 . 2009-09-10 17:40 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\dxmasf.dll
+ 2007-10-15 21:12 . 2009-10-30 15:12 3674 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2007-10-15 21:12 . 2009-10-20 16:53 3674 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-10-20 16:56 . 2009-10-20 16:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-31 10:45 . 2009-10-31 10:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-10-20 16:56 . 2009-10-20 16:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-31 10:45 . 2009-10-31 10:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-21 17:38 . 2009-06-06 12:55 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.22886_none_66022984264aac18\jscript.dll
+ 2009-10-21 17:38 . 2009-06-06 05:01 726528 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_8.0.6001.18795_none_656cbc830d360ee8\jscript.dll
+ 2009-10-30 15:02 . 2009-09-10 15:10 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.22223_none_b05140d2ecdc475e\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 14:58 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.18111_none_afd0735fd3b858f5\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 15:23 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.22520_none_ae67ce0cefb8a635\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 15:21 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.18330_none_add35f6fd6a32535\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 15:14 311296 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.21125_none_ac866714f28dca12\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 15:29 311296 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.16926_none_abfdf271d96f105d\unregmp2.exe
+ 2009-10-30 15:02 . 2009-09-10 15:10 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 15:10 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmplayer.exe
+ 2009-10-30 15:02 . 2009-09-10 15:10 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmpconfig.exe
+ 2009-08-13 06:32 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 14:58 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmplayer.exe
+ 2009-08-13 06:32 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmpconfig.exe
+ 2009-10-30 15:02 . 2009-09-10 15:23 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 15:23 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmplayer.exe
+ 2009-10-30 15:02 . 2009-09-10 15:23 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmpconfig.exe
+ 2009-08-13 06:32 . 2009-07-14 10:58 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 15:21 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmplayer.exe
+ 2009-08-13 06:32 . 2009-07-14 10:59 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmpconfig.exe
+ 2009-10-30 15:02 . 2009-09-10 15:14 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 15:14 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmplayer.exe
+ 2009-10-30 15:02 . 2009-09-10 15:14 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmpconfig.exe
+ 2009-10-30 15:02 . 2009-09-10 15:29 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmpshare.exe
+ 2009-10-30 15:02 . 2009-09-10 15:29 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmplayer.exe
+ 2009-10-30 15:02 . 2009-09-10 15:29 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmpconfig.exe
+ 2006-11-02 10:33 . 2009-10-31 10:55 598562 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-20 14:35 598562 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-10-31 10:55 108736 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-10-20 14:35 108736 c:\windows\System32\perfc009.dat
- 2009-10-20 16:07 . 2009-03-08 11:33 726528 c:\windows\System32\jscript.dll
+ 2009-10-21 17:38 . 2009-06-06 05:01 726528 c:\windows\System32\jscript.dll
- 2009-05-05 17:44 . 2009-10-20 17:24 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-05-05 17:44 . 2009-10-31 09:54 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-10-20 17:47 . 2009-10-20 17:47 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\8f9e7faa17ad97b10b90647dc804bd02\WindowsFormsIntegration.ni.dll
+ 2009-10-20 17:47 . 2009-10-20 17:47 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\a7b063c683276e3a82a58ba41c52df12\UIAutomationClient.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 235520 c:\windows\assembly\NativeImages_v2.0.50727_32\TaskScheduler\254b382cfc56f408ee61524805812f29\TaskScheduler.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\0eae6266b8c2becb2131349055187233\System.Xml.Linq.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\9ab2b63a74f18bded73c752dfad29b7b\System.Web.Routing.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c6abb45c13e5b9122696522bec0d2ecf\System.Web.Extensions.Design.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\eaa2ae0c44f344b227b2c382c846f7a4\System.Web.Entity.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\5c0af069194b9d1f5d6ee63dbb90ee8d\System.Web.Entity.Design.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\03efddc7dbc191f65c0b343666f27026\System.Web.DynamicData.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\f064a5d32c3dbf54f7e6923b3cba5f35\System.Web.Abstractions.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\23ca5e14f05c37fb49bc0df6521a314e\System.Net.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\072654567a9c8a9788fc1dc3c36ecfc7\System.Management.Instrumentation.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\34472e4436b3e385c07ee148575e09f6\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\e7535982e4bf2036e9e7269641b7be96\System.Data.Services.Client.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\d8591d22020c2da6180edf325b1a5d06\System.Data.Services.Design.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 232448 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\723e877d7b2a6ef55f2ae48ce7c1ee09\sysglobl.ni.dll
+ 2009-10-30 15:02 . 2009-09-10 15:10 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.22223_none_b05140d2ecdc475e\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 14:58 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.18111_none_afd0735fd3b858f5\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 15:23 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.22520_none_ae67ce0cefb8a635\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 15:21 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.18330_none_add35f6fd6a32535\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 15:14 1418240 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.21125_none_ac866714f28dca12\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 15:29 1418240 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.16926_none_abfdf271d96f105d\setup_wm.exe
+ 2009-10-30 15:02 . 2009-09-10 15:11 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmploc.DLL
+ 2009-10-30 15:02 . 2009-09-10 14:59 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmploc.DLL
+ 2009-10-30 15:01 . 2009-09-10 15:24 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmploc.DLL
+ 2009-10-30 15:01 . 2009-09-10 15:21 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmploc.DLL
+ 2009-10-30 15:00 . 2009-09-10 15:14 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmploc.DLL
+ 2009-10-30 14:59 . 2009-09-10 15:29 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmploc.DLL
- 2006-11-02 10:22 . 2009-10-20 16:59 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-10-31 10:43 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 12:45 . 2009-09-04 19:52 4208533 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2006-11-02 12:45 . 2009-10-31 10:46 4208533 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2009-10-20 17:47 . 2009-10-20 17:47 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\2105c56c3fe48843fcb0b488cbe3a9d4\UIAutomationClientsideProviders.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\6cd20be7cbc4f149f2cb27342632f52e\System.WorkflowServices.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\40409c8e5284e8a59e3ea9d2969be855\System.Web.Mobile.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\84f6711a2dcbe862949b0d01ac8568ba\System.Web.Extensions.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\a9bb974635790a38d3530b441a9c93cc\System.Speech.ni.dll
+ 2009-10-20 17:46 . 2009-10-20 17:46 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\1c98099c39a6925b6292b7f00c3010a5\System.ServiceModel.Web.ni.dll
+ 2009-10-20 17:45 . 2009-10-20 17:45 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\96217e2185e9b019a4a8d78e43be3124\System.Data.Services.ni.dll
+ 2009-10-30 15:02 . 2009-09-10 17:10 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmp.dll
+ 2009-10-30 15:02 . 2009-09-10 16:49 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmp.dll
+ 2009-10-30 15:02 . 2009-09-10 20:46 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmp.dll
+ 2009-10-30 15:02 . 2009-09-10 17:33 10626048 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmp.dll
+ 2009-10-30 15:03 . 2009-09-10 17:31 10622464 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmp.dll
+ 2009-10-30 15:03 . 2009-09-10 17:40 10622464 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmp.dll
+ 2009-10-30 15:02 . 2009-09-10 16:49 10627584 c:\windows\System32\wmp.dll
+ 2009-05-06 16:23 . 2009-10-29 13:04 227135372 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot sat til dags dato --
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2007-01-08 151552]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-21 659456]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2007-08-27 182952]
"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2007-08-27 895600]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-06 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-06 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-06 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9f,c9,00,f8,97,2d,ca,01
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\F-Secure\HIPS\fshs.sys [02-04-2008 16:30 70768]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [02-04-2008 16:31 34736]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [02-04-2008 16:31 69136]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\F-Secure\Anti-Virus\minifilter\fsvista.sys [02-04-2008 16:29 12912]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [08-05-2009 17:49 1153368]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [02-04-2008 16:29 62064]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30-03-2009 15:28 1533808]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [02-04-2008 16:29 39792]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [02-04-2008 16:29 25200]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Indhold af mappen 'Planlagte Opgaver'
2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{42C083EB-7F72-4279-B191-150D09048E0B}.job
- c:\windows\system32\msfeedssync.exe [2009-10-20 03:41]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7uDefault_Search_URL =
hxxp://www.google.com/iemStart Page =
hxxp://da.intl.acer.yahoo.comuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabFF - ProfilePath - c:\users\Fam. Tanggaard Bille\AppData\Roaming\Mozilla\Firefox\Profiles\smukbc82.default\
FF - prefs.js: browser.startup.homepage -
www.tv2.dkFF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\AppData\Roaming\Mozilla\Firefox\Profiles\smukbc82.default\extensions\turntoolviewer@turntool.com\plugins\nptnt.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\Desktop\programmer\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\Desktop\programmer\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLITIKKER ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-31 12:37
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Gennemført tid: 2009-10-31 12:40
ComboFix-quarantined-files.txt 2009-10-31 11:40
ComboFix2.txt 2009-10-20 17:49
ComboFix3.txt 2009-05-12 15:37
Pre-Kørsel: 24.512.643.072 byte ledig
Post-Kørsel: 24.377.110.528 byte ledig
- - End Of File - - D5919B77FA774C59A3649F5E41A92AD7