ComboFix 10-01-02.05 - Fam. Tanggaard Bille 03-01-2010 20:58:33.6.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.45.1030.18.766.246 [GMT 1:00]
Running from: c:\users\Fam. Tanggaard Bille\Desktop\banan.exe
AV: F-Secure Client Security 7.10 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Client Security 7.10 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: F-Secure Client Security 7.10 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Filer skabt fra 2009-12-03 til 2010-01-03 )))))))))))))))))))))))))))))))))))
.
2010-01-03 20:10 . 2010-01-03 20:10 -------- d-----w- c:\users\Fam. Tanggaard Bille\AppData\Local\temp
2010-01-03 20:10 . 2010-01-03 20:10 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-03 20:10 . 2010-01-03 20:10 -------- d-----w- c:\users\FAM~1~TAN\AppData\Local\temp
2010-01-03 20:10 . 2010-01-03 20:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-24 13:32 . 2009-12-24 13:51 -------- d-----w- C:\ComboFix
2009-12-13 12:54 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-13 12:54 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-13 12:54 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-13 12:50 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-13 09:11 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-13 09:04 . 2004-03-29 15:23 90112 ----a-w- c:\windows\unvise32.exe
2009-12-07 08:41 . 2009-12-07 08:41 -------- d-----w- c:\users\Fam. Tanggaard Bille\AppData\Local\Citrix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 10:36 . 2007-09-14 04:32 13730 ----a-w- c:\users\Fam. Tanggaard Bille\AppData\Roaming\nvModes.dat
2010-01-02 15:55 . 2007-06-12 22:31 84790 ----a-w- c:\windows\system32\perfc006.dat
2010-01-02 15:55 . 2007-06-12 22:31 483230 ----a-w- c:\windows\system32\perfh006.dat
2009-12-24 10:43 . 2008-08-28 05:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 09:17 . 2007-09-18 20:28 680 ----a-w- c:\users\Fam. Tanggaard Bille\AppData\Local\d3d9caps.dat
2009-12-22 06:56 . 2007-10-15 18:59 -------- d-----w- c:\program files\Java
2009-12-13 13:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-13 08:56 . 2009-09-27 14:03 -------- d-----w- c:\program files\Silke
2009-12-07 08:42 . 2009-12-07 08:42 73728 ----a-r- c:\users\Fam. Tanggaard Bille\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\ARPICON.exe
2009-12-07 08:42 . 2009-12-07 08:42 73728 ----a-r- c:\users\Fam. Tanggaard Bille\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\liteico.exe.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
2009-12-03 15:14 . 2008-08-28 05:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2008-08-28 05:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-24 13:33 . 2009-06-09 19:18 0 ----a-w- c:\users\Fam. Tanggaard Bille\temp.dat
2009-11-21 06:40 . 2009-12-13 12:58 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-13 12:58 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-13 12:58 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-13 12:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-02 19:42 . 2009-10-02 17:33 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 12:45 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-29 09:17 . 2009-11-26 07:34 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-11 03:17 . 2008-11-25 20:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-01 12:35 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:08 . 2009-11-01 12:35 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:07 . 2009-11-01 12:35 4096 ----a-w- c:\windows\system32\oleaccrc.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2007-01-08 151552]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-21 659456]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2007-08-27 182952]
"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2007-08-27 895600]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-06 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-06 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-06 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9f,c9,00,f8,97,2d,ca,01
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\F-Secure\HIPS\fshs.sys [02-04-2008 16:30 70768]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [02-04-2008 16:31 34736]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [02-04-2008 16:31 69136]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\F-Secure\Anti-Virus\minifilter\fsvista.sys [02-04-2008 16:29 12912]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [08-05-2009 17:49 1153368]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [02-04-2008 16:29 62064]
S3 FontCache;Tjenesten Windows-skrifttypecache;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [27-08-2008 21:10 21504]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [02-04-2008 16:29 39792]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [02-04-2008 16:29 25200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Indhold af mappen 'Planlagte Opgaver'
2010-01-03 c:\windows\Tasks\User_Feed_Synchronization-{42C083EB-7F72-4279-B191-150D09048E0B}.job
- c:\windows\system32\msfeedssync.exe [2009-12-13 04:59]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7uDefault_Search_URL =
hxxp://www.google.com/iemStart Page =
hxxp://da.intl.acer.yahoo.comuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabFF - ProfilePath - c:\users\Fam. Tanggaard Bille\AppData\Roaming\Mozilla\Firefox\Profiles\smukbc82.default\
FF - prefs.js: browser.startup.homepage -
www.tv2.dkFF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\AppData\Roaming\Mozilla\Firefox\Profiles\smukbc82.default\extensions\turntoolviewer@turntool.com\plugins\nptnt.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\AppData\Roaming\Mozilla\plugins\npicaN.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\Desktop\programmer\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\users\Fam. Tanggaard Bille\Desktop\programmer\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLITIKKER ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-03 21:10
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'Explorer.exe'(5052)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Gennemført tid: 2010-01-03 21:21:41
ComboFix-quarantined-files.txt 2010-01-03 20:21
ComboFix2.txt 2009-12-24 13:50
ComboFix3.txt 2009-10-31 11:40
ComboFix4.txt 2009-10-20 17:49
ComboFix5.txt 2010-01-03 19:55
Pre-Run: 22.820.413.440 byte ledig
Post-Kørsel: 22.811.234.304 byte ledig
- - End Of File - - 4C66D604B129A016DF045ADB45480260