Her er de så. Og tak fir hjælpen og din tid.
Malwarebytes' Anti-Malware 1.41
Database version: 3012
Windows 5.1.2600 Service Pack 3
22-10-2009 19:22:22
mbam-log-2009-10-22 (19-22-22).txt
Skan type: Hurtig skanning
Objekter skannet: 106336
Tid tilbagelagt: 7 minute(s), 13 second(s)
Inficerede Hukommelses Processer: 7
Inficerede Hukommelses Moduler: 1
Inficerede Registeringsdatabase Nøgler: 2
Inficerede Registeringsdatabase Værdier: 12
Inficerede Registeringsdatabase Filer: 4
Inficerede Mapper: 4
Inficerede Filer: 49
Inficerede Hukommelses Processer:
C:\WINDOWS\Temp\_ex-08.exe (Trojan.Dropper) -> Unloaded process successfully.
C:\Documents and Settings\Reception1\Application Data\seres.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Documents and Settings\Reception1\Application Data\svcst.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\WINDOWS\system32\qtplugin.exe (Rootkit.Agent) -> Unloaded process successfully.
C:\WINDOWS\Temp\wpv651255703227.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\Reception1\restorer64_a.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\WINDOWS\system32\restorer64_a.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Inficerede Hukommelses Moduler:
C:\WINDOWS\system32\cpcp.cpo (Trojan.Agent) -> Delete on reboot.
Inficerede Registeringsdatabase Nøgler:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusPro_2010 (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusPro_2010 (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
Inficerede Registeringsdatabase Værdier:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\promoreg (Trojan.Dropper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mserv (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysgif32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registrymonitor1 (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RList (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\restorer64_a (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\restorer64_a (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Inficerede Registeringsdatabase Filer:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe cpcp.cpo bef0regiiav) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Inficerede Mapper:
C:\Programmer\AntivirusPro_2010 (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\data (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\Microsoft.VC80.CRT (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Menuen Start\Programmer\AntivirusPro_2010 (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
Inficerede Filer:
C:\WINDOWS\Temp\_ex-08.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Application Data\seres.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Application Data\svcst.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\wpv581255562528.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN10.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN11.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN12.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN13.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN14.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN15.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN16.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN185.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN2.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN4.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN5.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN6.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN7.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN8.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BN9.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BNA.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BNB.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BNC.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BND.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BNE.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Lokale indstillinger\Temp\BNF.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\AntivirusPro_2010.cfg (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\AntivirusPro_2010.exe (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\AVEngn.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\htmlayout.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\pthreadVC2.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\wscui.cpl (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\data\daily.cvd (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Programmer\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Menuen Start\Programmer\AntivirusPro_2010\AntivirusPro_2010.lnk (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Menuen Start\Programmer\AntivirusPro_2010\Uninstall.lnk (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cpcp.cpo (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Reception1\Application Data\lizkavd.exe (Rogue.AntiVirusPro) -> Delete on reboot.
C:\WINDOWS\Temp\wpv651255703227.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qtplugin.exe (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\Temp\wpv881255137485.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Skrivebord\AntivirusPro_2010.lnk (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk (Rogue.AntiVirusPro2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Reception1\restorer64_a.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\restorer64_a.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
------------------------------------------------------------
DDS (Ver_09-10-13.01) - NTFSx86
Run by Reception1 at 19:23:01,64 on 22-10-2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1015.392 [GMT 2:00]
AV: Trend Micro Client-Server Security Agent AntiVirus *On-access scanning enabled* (Updated) {9562DEF8-B4C4-4848-946E-F4F43834FB9F}
AV: avast! antivirus 4.8.1356 [VPS 091021-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Trend Micro Client-Server Security Agent Firewall *disabled* {9562DEF8-B4C4-4848-946E-F4F43834FB9F}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.exe
svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programmer\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Programmer\SetWeb\SetWeb.exe
C:\Programmer\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\OpenOffice.org 3\program\soffice.bin
svchost
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Programmer\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\TEMP\OECA52.EXE
C:\Programmer\Malwarebytes' Anti-Malware\mbam.exe
C:\Programmer\Java\jre6\bin\jucheck.exe
C:\Documents and Settings\Reception1\Skrivebord\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = dk.msn.com//
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\programmer\canon\easy-webprint\Toolband.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\programmer\windows live\messenger\msnmsgr.exe" /background
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [OfficeScanNT Monitor] "c:\programmer\trend micro\client server security agent\pccntmon.exe" -HideWindow
mRun: [Easy-PrintToolBox] c:\programmer\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
mRun: [SunJavaUpdateSched] "c:\programmer\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SpyHunter Security Suite] c:\programmer\enigma software group\spyhunter\SpyHunter3.exe
mRun: [Regedit32] c:\windows\system32\regedit.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\programmer\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\recept~1\menuen~1\progra~1\start\openof~1.lnk - c:\programmer\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\documents and settings\reception1\menuen start\programmer\start\zavupd32.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\adober~1.lnk - c:\programmer\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\adober~2.lnk - c:\programmer\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\setweb.lnk - c:\programmer\setweb\SetWeb.exe
IE: Easy-WebPrint Add To Print List - c:\programmer\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\programmer\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\programmer\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\programmer\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programmer\messenger\msmsgs.exe
Trusted Zone: danid.dk
DPF: {00134F72-5284-44F7-95A8-52A619F70751} -
hxxps://192.168.18.11:4343/officescan/console/ClientInstall/WinNTChk.cabDPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} -
hxxps://192.168.18.11:4343/officescan/console/ClientInstall/setup.cabDPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} -
hxxps://192.168.18.11:4343/officescan/console/ClientInstall/RemoveCtrl.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {9BBB3919-F518-4D06-8209-299FC243FC30} -
hxxps://192.168.18.11:4343/SMB/console/html/root/AtxEnc.cabDPF: {9DF01F00-08E7-4DBE-9070-94841463B3FE} -
hxxps://danid.dk/csp/authenticode/csp.exeDPF: {C07E5288-22FB-11D7-962E-0004AC77C761} -
hxxps://activex.dataloen.dk/controls/Dataloen3341.CABDPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cabDPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} -
hxxps://udstedelse.certifikat.tdc.dk/csp/authenticode/digitalsignatur-csp.exeDPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabNotify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-10-22 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-22 20560]
R2 TmFilter;Trend Micro Filter;c:\programmer\trend micro\client server security agent\tmxpflt.sys [2008-8-16 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\programmer\trend micro\client server security agent\tmpreflt.sys [2008-8-16 36368]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-6-18 30720]
R3 cxbu0wdm;CardMan 3x21;c:\windows\system32\drivers\cxbu0wdm.sys [2008-11-5 52026]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-10-22 38224]
=============== Created Last 30 ================
2009-10-22 19:13 <DIR> --d----- c:\docume~1\recept~1\applic~1\Malwarebytes
2009-10-22 19:13 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-22 19:13 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-10-22 19:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-22 19:13 <DIR> --d----- c:\programmer\Malwarebytes' Anti-Malware
2009-10-22 18:23 <DIR> --d----- c:\programmer\Enigma Software Group
2009-10-22 16:54 27,408 a------- c:\windows\system32\drivers\aavmker4.sys
2009-10-21 15:59 19,168 a------- c:\windows\system32\ruco.dll
2009-10-21 15:59 18,006 a------- c:\windows\system32\vykeneh.com
2009-10-21 15:59 17,084 a------- c:\windows\system32\ulubafe.ban
2009-10-21 15:59 14,574 a------- c:\windows\sidyqyboc.ban
2009-10-21 15:59 11,706 a------- c:\windows\system32\iryxojufu.com
2009-10-21 15:59 11,148 a------- c:\windows\system32\otaqokihe.vbs
2009-10-21 15:59 10,007 a------- c:\windows\ejovasadyd.vbs
2009-10-21 15:59 16,290 a------- c:\windows\socegaji.sys
2009-10-21 15:59 14,573 a------- c:\windows\genygy.lib
2009-10-21 15:59 14,421 a------- c:\docume~1\recept~1\applic~1\iqefut.vbs
2009-10-21 15:59 14,308 a------- c:\programmer\fælles filer\ipig.dll
2009-10-21 15:59 14,185 a------- c:\docume~1\recept~1\applic~1\habadyt.com
2009-10-21 15:59 14,136 a------- c:\windows\emutosaru.bin
2009-10-21 15:59 12,771 a------- c:\docume~1\recept~1\applic~1\apuhiqud.bat
2009-10-21 15:55 42,368 ac------ c:\windows\system32\dllcache\agp440.sys
2009-10-21 15:55 27,136 -------- c:\windows\system32\cpcp.cpo
2009-10-15 09:08 208,744 a------- c:\windows\system32\muweb.dll
2009-10-15 09:08 268,648 a------- c:\windows\system32\mucltui.dll
2009-10-15 09:08 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-10-14 10:24 <DIR> --d----- c:\documents and settings\reception1\Tracing
2009-10-14 10:24 <DIR> --d----- c:\programmer\Microsoft
2009-10-14 10:24 <DIR> --d----- c:\programmer\Windows Live SkyDrive
2009-10-14 10:16 <DIR> --d----- c:\programmer\fælles filer\Windows Live
2009-10-01 13:36 2,674,149 a------- C:\Kontoudtog til Revisor.pdf
2009-09-30 14:43 278,528 a------- c:\windows\system32\DSJPG.dll
2009-09-30 14:43 260,096 a------- c:\windows\system32\TMDGUI20.dll
2009-09-30 14:42 279,552 a------- c:\windows\system32\DSJPG_12Bit.dll
==================== Find3M ====================
2009-10-22 19:14 324,960 a------- c:\windows\system32\perfh006.dat
2009-10-22 19:14 47,276 a------- c:\windows\system32\perfc006.dat
2009-10-21 15:59 18,879 a------- c:\programmer\fælles filer\ryrewut.db
2009-10-21 15:59 16,487 a------- c:\programmer\fælles filer\dogyzip.ban
2009-10-21 15:59 16,445 a------- c:\programmer\fælles filer\zobawot.db
2009-10-20 14:39 0 a------- c:\documents and settings\reception1\temp.dat
2009-09-30 14:45 282,112 a------- c:\windows\MiniWeb.exe
2009-09-30 14:43 144,896 a------- c:\windows\system32\dsxml.dll
2009-09-30 14:43 155,648 a------- c:\windows\system32\dsibapi.dll
2009-09-30 14:42 287,232 a------- c:\windows\system32\DSPNG.dll
2009-09-30 14:42 109,568 a------- c:\windows\system32\dszlib.dll
2009-09-30 14:42 101,888 a------- c:\windows\system32\ToolBox20.dll
2009-09-11 16:19 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-04 23:04 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-29 09:28 832,512 a------- c:\windows\system32\wininet.dll
2009-08-29 09:28 78,336 a------- c:\windows\system32\ieencode.dll
2009-08-29 09:28 17,408 -------- c:\windows\system32\corpol.dll
2009-08-26 10:02 247,326 a------- c:\windows\system32\strmdll.dll
2009-08-05 11:00 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-04 19:29 2,147,840 a------- c:\windows\system32\ntoskrnl.exe
2009-08-04 19:29 2,026,496 a------- c:\windows\system32\ntkrnlpa.exe
2009-08-04 11:45 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
============= FINISH: 19:23:32,82 ===============