ComboFix 09-12-02.03 - Bjarne Lyngbo 02/12/2009 17:38.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1789.1462 [GMT 1:00]
Kører fra: c:\documents and settings\Bjarne Lyngbo\Skrivebord\ComboFix.exe
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
ADS - WINDOWS: deleted 48 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\95091086.ini
c:\documents and settings\Bjarne Lyngbo\Application Data\.#
c:\documents and settings\Bjarne Lyngbo\Application Data\inst.exe
c:\programmer\MajorShare\SYSInfo.ocx
C:\test.txt
c:\windows\system32\advapi32new.dll
c:\windows\system32\apphelpnew.dll
c:\windows\system32\crypt32new.dll
c:\windows\system32\d3d10core.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\kernel32new.dll
c:\windows\system32\msvcrtnew.dll
c:\windows\system32\ntdsapinew.dll
c:\windows\system32\powrprofnew.dll
c:\windows\system32\secur32new.dll
c:\windows\system32\user32new.dll
c:\windows\system32\winstanew.dll
Inficeret kopi af c:\windows\system32\DRIVERS\atapi.sys blev fundet og desinficeret
Genskabt kopi fra - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((((((( Filer skabt fra 2009-11-02 til 2009-12-02 )))))))))))))))))))))))))))))))))))
.
2009-12-02 15:31 . 2009-12-02 15:31 -------- d-----w- C:\Converted
2009-12-02 15:29 . 2009-05-28 13:57 245760 ----a-w- c:\windows\system32\snmvtsvc.exe
2009-12-02 15:29 . 2009-05-28 12:15 10936 ----a-w- c:\windows\system32\SndTVideo.dll
2009-12-02 15:29 . 2009-05-28 12:15 3768 ----a-w- c:\windows\system32\SndTVideo.sys
2009-12-02 15:29 . 2009-05-28 12:15 23096 ----a-w- c:\windows\system32\SndTAudio.sys
2009-12-02 15:29 . 2009-05-28 12:15 23096 ----a-w- c:\windows\system32\drivers\SndTAudio.sys
2009-12-02 15:29 . 2009-12-02 15:30 -------- d-----w- c:\programmer\SoundTaxi
2009-12-02 15:15 . 2009-12-02 15:15 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Malwarebytes
2009-12-02 15:15 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 15:14 . 2009-12-02 15:15 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2009-12-02 15:14 . 2009-12-02 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-02 15:14 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-02 14:03 . 2009-12-02 14:03 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-02 13:55 . 2009-12-02 13:56 -------- d-----w- C:\0 - DivX Serier OK
2009-12-02 13:54 . 2009-12-02 13:54 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\GlobalSCAPE
2009-12-02 13:54 . 2009-12-02 13:54 -------- d-----w- c:\programmer\Hide and Secret 3 - Pharaohs Quest
2009-12-02 13:54 . 2009-12-02 13:54 -------- d-----w- c:\programmer\Lost City of Z - Special Edition
2009-12-02 13:53 . 2009-12-02 13:53 -------- d-----w- c:\programmer\Romance of Rome
2009-12-02 13:53 . 2009-12-02 13:53 -------- d-----w- c:\programmer\The Tudors
2009-12-02 13:53 . 2009-12-02 13:53 -------- d-----w- c:\programmer\Company
2009-12-02 13:53 . 2009-12-02 13:53 -------- d-----w- c:\programmer\Princess Isabella - A Witch's Curse
2009-12-02 13:53 . 2009-12-02 13:54 -------- d-----w- c:\programmer\Reincarnations - Awakening
2009-12-02 13:19 . 2009-12-02 13:19 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\DoctorWeb
2009-12-02 12:35 . 2009-12-02 13:54 -------- d-----w- C:\Spyware Doctor
2009-11-28 10:43 . 2009-11-28 10:43 -------- d-----w- c:\programmer\Runtime Software
2009-11-26 21:03 . 2009-11-26 21:04 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\FirstColony
2009-11-26 19:27 . 2009-11-26 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\ScreenSeven
2009-11-26 18:48 . 2009-12-02 13:56 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Azgard
2009-11-25 07:31 . 2009-11-25 07:31 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Alawar
2009-11-24 23:31 . 2009-11-24 23:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Elaborate Bytes
2009-11-24 23:30 . 2009-11-24 23:30 -------- d-----w- c:\programmer\Elaborate Bytes
2009-11-24 20:04 . 2009-11-24 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SOS
2009-11-24 15:09 . 2009-11-24 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\EscapeTheMuseum2
2009-11-24 12:01 . 2009-12-02 13:55 -------- d-----w- C:\0 - DivX Film OK
2009-11-23 21:26 . 2009-11-30 01:58 -------- d-----w- C:\0 - DVD Film OK
2009-11-23 19:13 . 2009-11-23 19:13 -------- d-----w- C:\temp_dvd
2009-11-23 19:13 . 2009-11-23 19:13 -------- d-----w- c:\programmer\Dvd-cloner
2009-11-23 18:32 . 2009-11-23 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-11-23 18:09 . 2009-11-23 22:31 -------- d-----w- c:\programmer\Norton 360
2009-11-23 18:09 . 2009-11-23 22:27 -------- d-----w- c:\programmer\Symantec
2009-11-23 18:09 . 2009-11-23 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-23 17:33 . 1998-06-18 10:58 94208 ----a-w- c:\windows\system32\msstkprp.dll
2009-11-23 17:32 . 2009-11-23 17:32 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\WINDOWS
2009-11-23 17:32 . 2009-11-23 17:32 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Application Data\Help
2009-11-23 17:30 . 2000-02-24 16:07 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2009-11-23 17:30 . 2000-02-24 16:07 252176 ----a-w- c:\windows\system32\MSRD2X35.DLL
2009-11-23 17:30 . 2000-02-24 16:07 24848 ----a-w- c:\windows\system32\MSJTER35.DLL
2009-11-23 17:30 . 2000-02-24 16:07 123664 ----a-w- c:\windows\system32\MSJINT35.DLL
2009-11-23 17:30 . 2000-02-24 16:07 1046288 ----a-w- c:\windows\system32\MSJET35.DLL
2009-11-23 17:30 . 2009-11-23 22:44 -------- d-----w- c:\programmer\Fælles filer\Symantec Shared
2009-11-22 10:05 . 2009-11-22 10:05 -------- d-----w- c:\documents and settings\All Users\Application Data\IntDreams
2009-11-21 12:38 . 2009-11-21 12:38 -------- d-----w- c:\programmer\Fælles filer\PCSuite
2009-11-21 12:37 . 2009-11-21 12:37 -------- d-----w- c:\programmer\PC Connectivity Solution
2009-11-21 12:36 . 2009-11-21 12:35 33652688 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_dan.exe
2009-11-21 12:36 . 2009-11-21 12:36 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2009-11-21 12:36 . 2009-11-21 12:36 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2009-11-21 12:36 . 2009-11-21 12:36 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-11-21 12:36 . 2009-11-21 12:36 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-17 18:38 . 2009-11-17 18:38 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Friday's games
2009-11-17 17:40 . 2009-11-17 17:41 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\TimeMachine
2009-11-17 13:01 . 2009-11-17 13:00 24414896 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\NokiaSoftwareUpdaterSetup_1.8.10DK.exe
2009-11-17 12:56 . 2009-11-17 12:56 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\msxml6Exec.exe
2009-11-17 12:56 . 2009-11-17 12:56 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\Sleep.exe
2009-11-17 12:56 . 2009-11-17 12:56 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\vcredistExec.exe
2009-11-17 12:53 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-11-17 12:51 . 2009-11-17 12:52 33848696 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_dan_web[1].exe
2009-11-17 11:42 . 2009-11-17 12:25 -------- d-----w- C:\SIM Edit Tool
2009-11-15 19:28 . 2009-11-15 19:28 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Application Data\Identities
2009-11-15 18:35 . 2009-11-23 15:36 -------- d-----w- c:\programmer\News Group File Grabber
2009-11-15 16:04 . 2009-11-27 10:53 -------- d-----w- c:\windows\system32\NtmsData
2009-11-15 05:24 . 2009-11-15 05:24 -------- d-----w- c:\documents and settings\All Users\Application Data\WildWestQuest2
2009-11-14 20:16 . 2009-11-14 20:17 -------- d-----w- c:\programmer\I-Fluid
2009-11-14 20:14 . 2009-11-14 20:14 -------- d-----w- c:\windows\Season of Mystery The Cherry Blossom Murders
2009-11-14 20:14 . 2009-11-14 20:14 -------- d-----w- c:\programmer\Season of Mystery The Cherry Blossom Murders
2009-11-14 16:31 . 2009-11-14 17:42 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\uspy
2009-11-14 15:12 . 2009-11-14 15:12 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\GOA
2009-11-14 15:12 . 2009-11-14 15:12 -------- d-----w- c:\documents and settings\All Users\Application Data\GOA
2009-11-14 14:42 . 2009-11-18 20:32 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\ForgottenRiddles2
2009-11-13 14:03 . 2009-11-13 14:03 -------- d-----w- c:\programmer\WinAVIVideoConverter
2009-11-13 12:51 . 2009-11-13 13:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Islands
2009-11-13 07:50 . 2009-11-13 07:50 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Playrix Entertainment
2009-11-12 23:42 . 2009-12-02 12:28 -------- d-----w- c:\programmer\JDownloader
2009-11-12 00:26 . 2009-11-12 00:26 -------- d-----w- c:\programmer\Samorost2
2009-11-11 18:31 . 2009-12-02 13:56 -------- d-----w- C:\games
2009-11-11 14:19 . 2009-11-11 14:48 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\EcoRescue
2009-11-09 22:14 . 2009-11-09 22:14 -------- d-----w- c:\programmer\Avenue Flo
2009-11-09 22:14 . 2009-11-09 22:14 -------- d-----w- c:\windows\Avenue Flo
2009-11-09 15:01 . 2009-11-09 15:01 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\ElementalsTheMagicKey
2009-11-09 10:39 . 2009-11-09 10:39 -------- d-----w- c:\programmer\Zip and Split
2009-11-07 10:51 . 2009-11-07 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-11-07 10:51 . 2009-11-07 10:51 -------- d-----w- c:\programmer\DVD Shrink
2009-11-06 15:10 . 2009-11-06 15:10 -------- d-----w- c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\myBabylon_English
2009-11-04 20:13 . 2009-11-04 20:13 152576 ----a-w- c:\documents and settings\Bjarne Lyngbo\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 16:43 . 2009-10-29 20:46 -------- d-----w- c:\programmer\MajorShare
2009-12-02 16:42 . 2008-04-15 12:00 83590 ----a-w- c:\windows\system32\perfc006.dat
2009-12-02 16:42 . 2008-04-15 12:00 458944 ----a-w- c:\windows\system32\perfh006.dat
2009-12-02 13:56 . 2009-06-10 22:40 -------- d-----w- c:\programmer\Foxit Reader
2009-12-02 13:56 . 2009-06-09 17:53 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Azureus
2009-12-02 13:56 . 2009-07-12 11:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Gamers Digital
2009-12-02 13:55 . 2009-06-07 15:39 -------- d--h--w- c:\programmer\InstallShield Installation Information
2009-12-02 13:55 . 2009-06-14 12:13 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\dvdcss
2009-12-02 13:54 . 2009-06-23 09:58 -------- d-----w- c:\programmer\Cute FTP 8 Pro
2009-12-02 13:54 . 2009-10-18 17:25 -------- d-----w- c:\programmer\Games
2009-12-02 13:31 . 2009-06-12 18:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-02 12:29 . 2009-07-30 09:50 -------- d-----w- c:\programmer\Google
2009-11-27 10:54 . 2009-06-09 13:05 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Vso
2009-11-26 22:48 . 2009-07-12 11:19 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Gamers Digital
2009-11-23 17:24 . 2009-06-14 10:06 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-11-23 16:46 . 2009-09-27 07:11 -------- d-----w- c:\programmer\Avast 4
2009-11-23 16:44 . 2009-09-14 14:41 -------- d-----w- c:\programmer\AL Zip 7,0
2009-11-23 16:44 . 2009-09-14 14:41 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\ESTsoft
2009-11-23 15:41 . 2009-06-09 13:05 -------- d-----w- c:\programmer\VSO
2009-11-23 15:40 . 2009-09-23 08:23 -------- d-----w- c:\programmer\Unity
2009-11-23 15:40 . 2009-07-06 19:40 -------- d-----w- c:\programmer\Tipard MPEG TS Converter
2009-11-23 15:39 . 2009-09-19 18:36 -------- d-----w- c:\programmer\SUPERAntiSpyware
2009-11-23 15:39 . 2009-06-10 11:53 -------- d-----w- c:\programmer\Fælles filer\Wise Installation Wizard
2009-11-23 15:29 . 2009-07-16 18:50 -------- d-----w- c:\programmer\Conceiva Download Studio
2009-11-23 15:25 . 2009-06-10 11:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-23 15:22 . 2009-09-19 18:37 117760 ----a-w- c:\documents and settings\Bjarne Lyngbo\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-22 12:08 . 2009-06-09 17:53 -------- d-----w- c:\programmer\Azureus
2009-11-21 12:38 . 2009-08-27 09:26 -------- d-----w- c:\programmer\Fælles filer\Nokia
2009-11-21 12:38 . 2009-08-27 09:25 -------- d-----w- c:\programmer\Nokia
2009-11-21 12:35 . 2009-08-27 09:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-20 15:28 . 2009-09-22 19:55 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Merscom
2009-11-20 15:28 . 2009-09-22 19:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom
2009-11-19 11:21 . 2009-06-14 13:01 -------- d-----w- c:\programmer\ImTOO DVD Copy Express
2009-11-17 13:11 . 2009-08-27 09:27 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\PC Suite
2009-11-13 22:13 . 2009-07-01 01:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Sandlot Games
2009-11-12 00:37 . 2009-07-28 11:09 -------- d-----w- c:\documents and settings\All Users\Application Data\JollyBear
2009-11-12 00:35 . 2009-07-28 11:48 -------- d-----w- c:\programmer\LeeGTs Games
2009-11-11 18:31 . 2009-07-18 06:28 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\PlayFirst
2009-11-11 18:31 . 2009-07-18 06:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-11-09 14:27 . 2009-08-18 06:23 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\blg
2009-11-09 14:27 . 2009-08-18 06:23 -------- d-----w- c:\documents and settings\All Users\Application Data\blg
2009-11-05 11:34 . 2009-07-20 13:17 0 -c--a-w- c:\documents and settings\Bjarne Lyngbo\temp.dat
2009-11-04 20:26 . 2009-06-08 10:18 -------- d-----w- c:\programmer\Java
2009-10-29 19:45 . 2009-10-29 19:45 -------- d--h--r- c:\documents and settings\Bjarne Lyngbo\Application Data\SecuROM
2009-10-29 10:49 . 2009-10-29 10:49 0 ----a-w- c:\documents and settings\Bjarne Lyngbo\Application Data\mgsnhDemo_32.dll
2009-10-29 10:49 . 2009-10-29 10:49 0 ----a-w- c:\documents and settings\Bjarne Lyngbo\Application Data\mgsnhDemo_32.dll
2009-10-29 10:10 . 2009-10-29 10:10 -------- d-----w- c:\programmer\Magitech
2009-10-27 16:52 . 2009-10-27 16:52 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Sierra Entertainment
2009-10-24 23:13 . 2009-10-24 23:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Gogii
2009-10-24 20:40 . 2009-10-24 20:40 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Enki Games
2009-10-24 20:15 . 2009-10-24 20:15 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\TitanicMystery
2009-10-24 16:07 . 2009-09-05 19:11 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Big Fish Games
2009-10-21 13:38 . 2009-10-21 13:34 -------- d-----w- c:\programmer\Easy CD-DA Extractor 12
2009-10-21 13:35 . 2009-10-21 13:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-10-21 12:56 . 2009-10-21 12:56 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Apple Computer
2009-10-18 17:16 . 2009-10-18 17:15 -------- d-----w- c:\programmer\Boulder Match 4
2009-10-18 16:20 . 2009-09-08 19:54 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Flood Light Games
2009-10-18 16:20 . 2009-09-08 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Flood Light Games
2009-10-17 00:23 . 2009-10-17 00:22 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\GTM_Bodie
2009-10-16 23:59 . 2009-10-16 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\MythPeople
2009-10-15 08:29 . 2009-10-15 08:29 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Little Games Company
2009-10-15 08:29 . 2009-10-15 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Little Games Company
2009-10-14 03:57 . 2009-10-14 03:57 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\MBT
2009-10-11 03:17 . 2009-06-08 10:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-07 08:41 . 2009-10-04 13:50 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Freezetag
2009-10-06 21:13 . 2009-09-14 18:39 -------- d-----w- c:\programmer\Adrianne Stone Hidden Relics
2009-10-06 10:52 . 2009-08-27 09:25 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-10-06 06:57 . 2009-10-06 06:57 -------- d-----w- c:\documents and settings\Bjarne Lyngbo\Application Data\Total Eclipse
2009-10-04 20:58 . 2009-10-04 20:58 24576 ----a-r- c:\documents and settings\Bjarne Lyngbo\Application Data\Microsoft\Installer\{EDA2E9CA-8B7E-4BC0-9B0F-34B299555BF3}\IconEDA2E9CA.exe
2009-10-04 20:58 . 2009-10-04 20:58 -------- d-----w- c:\programmer\EVE Interactive
2009-09-23 08:10 . 2009-06-09 18:02 7154255 ----a-w- c:\documents and settings\Bjarne Lyngbo\Application Data\Azureus\plugins\azemp\azmplay.exe
2009-09-20 20:28 . 2009-09-20 20:28 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-09-20 20:28 . 2009-09-20 20:28 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-09-04 16:44 . 2009-10-29 19:01 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 16:44 . 2009-10-29 19:01 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 16:44 . 2009-07-18 16:22 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 16:29 . 2009-10-29 19:01 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 16:29 . 2009-10-29 19:01 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 16:29 . 2009-10-29 19:01 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 16:29 . 2009-10-29 19:01 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 16:29 . 2009-10-29 19:01 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2008-03-09 05:25 . 2009-07-07 17:12 236 -c-ha-w- c:\programmer\Fælles filer\dx.reg
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\programmer\Fælles filer\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"TkBellExe"="c:\programmer\Fælles filer\Real\Update_OB\realsched.exe" [2009-06-09 185896]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2009-05-26 413696]
"Malwarebytes Anti-Malware (reboot)"="c:\programmer\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Image Zone Hurtig start.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Image Zone Hurtig start.lnk
backup=c:\windows\pss\HP Image Zone Hurtig start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Photosmart Premier Hurtig start.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\HP Photosmart Premier Hurtig start.lnk
backup=c:\windows\pss\HP Photosmart Premier Hurtig start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"odserv"=3 (0x3)
"ose"=3 (0x3)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"rpcapd"=3 (0x3)
"NVSvc"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"ERSvc"=2 (0x2)
"CiSvc"=3 (0x3)
"aawservice"=2 (0x2)
"wuauserv"=2 (0x2)
"IJPLMSVC"=2 (0x2)
"BITS"=3 (0x3)
"ASKUpgrade"=2 (0x2)
"ASKService"=2 (0x2)
"organiserservice"=2 (0x2)
"NMIndexingService"=3 (0x3)
"Crypkey License"=2 (0x2)
"iWinTrusted"=2 (0x2)
"ServiceLayer"=3 (0x3)
"gupdate"=2 (0x2)
"avast! Mail Scanner"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Azureus\\Azureus.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Nye Programmer\\eMule\\emule.exe"=
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [02/12/2009 16:29 23096]
S3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [02/12/2009 16:29 245760]
S4 gupdate;Google Update Service (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [06/10/2009 16:53 133104]
S4 iWinTrusted;iWinTrusted;c:\programmer\iWin Games\iWinTrusted.exe --> c:\programmer\iWin Games\iWinTrusted.exe [?]
S4 organiserservice;organiser database;c:\vivida~1\ORGANI~1.EXE -zglaxservice organiserservice --> c:\vivida~1\ORGANI~1.EXE -zglaxservice organiserservice [?]
.
Indhold af mappen 'Planlagte Opgaver'
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/ig?hl=da&source=iglkTrusted Zone: danid.dk
TCP: {A4C25A26-BDC3-4FAC-8D01-8A7E580EDE7B} = 208.67.222.222,208.67.220.220
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab.
- - - - TOMME GENVEJE FJERNET - - - -
AddRemove-Alexandra Fortune in Mystery of the Lunar Archipelago - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Amazing Heists Dillinger_is1 - c:\games\Forgotten Riddles
AddRemove-Ancient Quest Of Saqqarah_is1 - c:\games\Forgotten Riddles
AddRemove-Aquapolis_is1 - c:\games\Forgotten Riddles
AddRemove-Avalon_is1 - c:\games\Forgotten Riddles
AddRemove-Aveyond Lord of Twilight_is1 - c:\games\Forgotten Riddles
AddRemove-Babylonia_is1 - c:\games\Forgotten Riddles
AddRemove-Be A King_is1 - c:\games\Forgotten Riddles
AddRemove-Bounty Special Edition_is1 - c:\games\Forgotten Riddles
AddRemove-Brickshooter Egypt_is1 - c:\games\Forgotten Riddles
AddRemove-Build-a-lot 4 Power Source_is1 - c:\games\Forgotten Riddles
AddRemove-CanonMyPrinter - c:\programmer\Canon\MyPrinter\uninst.exe uninst.ini
AddRemove-Digital Signatur - c:\documents and settings\All Users\Application Data\{D166A25B-41F0-45EA-B10E-DE7D7B5C3455}\csp.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-Easy-PhotoPrint - c:\programmer\Canon Pixma IP 4300\Easy-PhotoPrint\uninst.exe uninst.ini
AddRemove-Easy-PrintToolBox - c:\programmer\Canon\Easy-PrintToolBox\uninst.exe uninst.ini
AddRemove-Engineer2_is1 - c:\games\Forgotten Riddles
AddRemove-Faerie Solitaire_is1 - c:\games\Forgotten Riddles
AddRemove-Fortune Tiles Gold_is1 - c:\games\Forgotten Riddles
AddRemove-HdO Adventure Secrets of the Vatican_is1 - c:\games\Forgotten Riddles
AddRemove-Hidden Wonders Of The Depths_is1 - c:\games\Forgotten Riddles
AddRemove-Holly 2 Magic Land_is1 - c:\games\Forgotten Riddles
AddRemove-Hotel Mogul_is1 - c:\games\Forgotten Riddles
AddRemove-Insider Tales The Stolen Venus_is1 - c:\games\Forgotten Riddles
AddRemove-Jewel Quest Mysteries 2 Trail of the Midnight Heart_is1 - c:\games\Forgotten Riddles
AddRemove-Jewel Quest Mysteries Trail of the Midnight Heart 1.00 - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-LEFT BEHIND: Tribulation Forces_is1 - c:\games\Forgotten Riddles
AddRemove-Lost Realms Legacy of the Sun Princess_is1 - c:\games\Forgotten Riddles
AddRemove-Magic Ball 4_is1 - c:\games\Forgotten Riddles
AddRemove-Mahjongg Ancient Mayas_is1 - c:\games\Forgotten Riddles
AddRemove-MediaNavigation.CDLabelPrint - c:\programmer\Canon Pixma IP 4300\CD-LabelPrint\Uninstal.exe Canon.CDLabelPrint.Application
AddRemove-Monkey Money Slots 1.00 - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Moxxie's Tabloid Adventures - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Mr Jones' Grave Yard Shift_is1 - c:\games\Forgotten Riddles
AddRemove-Mysterious City Vegas_is1 - c:\games\Forgotten Riddles
AddRemove-Mystery Stories Berlin Nights_is1 - c:\games\Forgotten Riddles
AddRemove-Mystic Emporium_is1 - c:\games\Forgotten Riddles
AddRemove-MysticDiaryLostBrother 1.00 - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-Pahelika Secret Legends_is1 - c:\games\Forgotten Riddles
AddRemove-Plants vs Zombies_is1 - c:\games\Forgotten Riddles
AddRemove-Pocahontas Princess of the Powhatan_is1 - c:\games\Forgotten Riddles
AddRemove-Pure Hidden_is1 - c:\games\Forgotten Riddles
AddRemove-Rangy Lil's Wild West Adventure 1.00 - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-RealJukebox 1.0 - c:\programmer\Fælles filer\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\programmer\Fælles filer\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-Relic Hunt - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Righteous Kill Revenge of the Poet Killer_is1 - c:\games\Forgotten Riddles
AddRemove-Robbie Unforgettable Adventures_is1 - c:\games\Forgotten Riddles
AddRemove-Season Match 2_is1 - c:\games\Forgotten Riddles
AddRemove-Slingo Mystery Whos Gold_is1 - c:\games\Forgotten Riddles
AddRemove-Sprilland Ritchie Adventures In Time 1.00 - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Sprouts Adventure_is1 - c:\games\Forgotten Riddles
AddRemove-The Color of Murder_is1 - c:\games\Forgotten Riddles
AddRemove-The Legend of Crystal Valley_is1 - c:\games\Forgotten Riddles
AddRemove-The Mystery of the Mary Celeste_is1 - c:\games\Forgotten Riddles
AddRemove-The Village Mage Spellbinder_is1 - c:\games\Forgotten Riddles
AddRemove-Vertigo - c:\documents and settings\Bjarne Lyngbo\Lokale indstillinger\Temp\Uninstall.exe
AddRemove-Wonderland Adventures Mysteries of Fire Island_is1 - c:\games\Forgotten Riddles
AddRemove-World Mosaics 2_is1 - c:\games\Forgotten Riddles
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-02 17:45
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\programmer\Cyberlink Power DVD\000.fcl"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_USERS\S-1-5-21-1343024091-436374069-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1343024091-436374069-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:aa,f1,de,a4,49,e3,2d,ca,75,fa,4a,e9,a9,93,2e,25,4f,68,da,74,97,
19,2e,be,79,80,60,d1,b7,75,05,5a,dc,c5,96,ef,40,59,af,0a,1d,c3,21,bb,06,de,\
"rkeysecu"=hex:c8,72,e3,38,70,93,7a,c3,19,f8,69,d9,6f,6f,d7,54
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'explorer.exe'(368)
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2009-12-02 17:49 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2009-12-02 16:49
Pre-Kørsel: 30,429,818,880 byte ledig
Post-Kørsel: 31,479,808,000 byte ledig
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 008F33365A38CF6FB37ADE9F1C8E97C5