ComboFix 10-01-01.02 - Daniel Küster 02-01-2010 14:04:43.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.45.1030.18.2047.1651 [GMT 1:00]
Kører fra: c:\documents and settings\Daniel Küster\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Daniel Küster\Skrivebord\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programmer\ecobar\tbHElper.dll
c:\windows\Install.txt
c:\windows\system32\Install.txt
Inficeret kopi af c:\windows\system32\DRIVERS\atapi.sys blev fundet og desinficeret
Genskabt kopi fra - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICF
-------\Service_BtwSrv
((((((((((((((((((((((((((((( Filer skabt fra 2009-12-02 til 2010-01-02 )))))))))))))))))))))))))))))))))))
.
2010-01-02 11:56 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 11:56 . 2010-01-02 11:57 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2010-01-02 11:56 . 2010-01-02 11:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-02 11:56 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 11:49 . 2010-01-02 11:49 -------- d-----w- c:\programmer\CCleaner
2010-01-02 10:47 . 2010-01-02 10:47 -------- d-----w- c:\programmer\Trend Micro
2010-01-02 10:28 . 2010-01-02 11:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-02 10:28 . 2010-01-02 10:28 -------- d-----w- c:\programmer\Spybot - Search & Destroy
2010-01-02 10:15 . 2010-01-02 13:07 -------- d-----w- c:\programmer\ecobar
2010-01-02 10:14 . 2010-01-02 10:14 165376 --sh--r- c:\windows\system32\wlcommn.exe
2009-12-29 19:37 . 2009-12-29 19:37 -------- d-sh--w- c:\windows\ftpcache
2009-12-29 19:37 . 2009-12-29 19:37 -------- d-----w- c:\programmer\Fælles filer\SynSpell
2009-12-29 19:37 . 2009-12-29 19:37 -------- d-----w- c:\programmer\TSW
2009-12-28 11:01 . 2009-12-28 11:02 -------- d-----w- c:\programmer\CesarFTP
2009-12-27 19:34 . 2009-12-27 19:34 -------- d-----w- c:\temp\author
2009-12-27 17:43 . 2009-12-30 16:52 -------- d-----w- C:\Temp
2009-12-22 13:04 . 2009-12-22 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\FarmFrenzy3
2009-12-20 10:11 . 2009-12-20 10:11 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-12-20 10:11 . 2009-12-20 10:11 -------- d-----w- c:\programmer\Logitech
2009-12-17 09:35 . 2009-12-17 09:35 -------- d-----w- c:\programmer\Cerberus
2009-12-17 09:34 . 2009-12-18 03:32 -------- d-----w- c:\windows\SxsCaPendDel
2009-12-16 09:37 . 2009-12-16 09:37 -------- d-----w- c:\documents and settings\All Users\Application Data\FreshGames
2009-12-15 21:44 . 2009-12-15 21:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Cerberus LLC
2009-12-15 21:44 . 2009-12-15 21:44 -------- d-----w- c:\programmer\Cerberus LLC
2009-12-15 08:32 . 2009-12-22 16:05 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-12-14 18:22 . 2006-12-30 22:16 313344 ----a-w- c:\windows\system32\avisynth.dll
2009-12-14 18:22 . 2005-04-04 13:52 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2009-12-14 18:22 . 2005-04-04 13:35 745472 ----a-w- c:\windows\system32\xvidcore.dll
2009-12-14 18:22 . 2004-05-26 08:37 719872 ----a-w- c:\windows\system32\devil.dll
2009-12-14 18:22 . 2002-01-05 01:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-12-14 18:22 . 2009-12-27 19:29 -------- d-----w- c:\programmer\DIKO
2009-12-14 16:42 . 2009-12-14 17:21 -------- d-----w- c:\programmer\PFConfig
2009-12-14 16:01 . 2009-12-14 16:01 -------- d-----w- c:\programmer\Flash Renamer 4.8
2009-12-14 09:03 . 2009-12-14 09:03 -------- d-----w- c:\documents and settings\All Users\Application Data\GoBit Games
2009-12-14 04:28 . 2009-12-14 04:28 -------- d-----w- c:\windows\kalender
2009-12-14 04:26 . 2009-12-14 04:26 -------- d-----w- c:\programmer\zepsoft
2009-12-14 04:26 . 2009-12-14 04:26 724992 ----a-w- c:\windows\iun6002.exe
2009-12-12 10:54 . 2003-03-29 15:45 89184 ----a-w- c:\windows\system32\drivers\imagedrv.sys
2009-12-12 10:54 . 2001-07-06 17:24 283920 ----a-w- c:\windows\system32\ImagXpr5.dll
2009-12-12 10:54 . 2001-07-06 13:41 569344 ----a-w- c:\windows\system32\imagr5.dll
2009-12-12 10:54 . 2001-07-06 11:44 544768 ----a-w- c:\windows\system32\imagx5.dll
2009-12-12 10:54 . 2001-06-26 07:15 38912 ----a-w- c:\windows\system32\picn20.dll
2009-12-12 10:54 . 2009-12-12 10:54 -------- d-----w- c:\programmer\Fælles filer\Ahead
2009-12-12 10:54 . 2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2009-12-12 10:54 . 2009-12-12 10:54 -------- d-----w- c:\programmer\Ahead
2009-12-12 10:40 . 2009-12-12 10:40 -------- d-----w- c:\programmer\GNU
2009-12-11 23:13 . 2009-12-11 23:13 -------- d-----w- c:\programmer\Fælles filer\Adobe
2009-12-11 22:24 . 2009-12-11 22:25 -------- d-----w- c:\programmer\OpenOffice.org 3
2009-12-10 21:27 . 2004-08-03 22:07 59264 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-12-10 21:27 . 2004-08-03 22:07 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-12-10 20:55 . 2009-12-10 20:55 -------- d--h--w- c:\windows\PIF
2009-12-10 20:12 . 2009-12-22 17:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-10 19:59 . 2004-08-03 22:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-12-09 16:21 . 2009-12-09 16:21 -------- d-----w- c:\documents and settings\All Users\Application Data\e-Safekey
2009-12-09 14:08 . 2009-12-09 14:09 -------- d-----w- c:\windows\system32\Adobe
2009-12-09 14:08 . 2009-12-09 14:08 -------- d-----w- c:\windows\Sun
2009-12-08 21:16 . 2009-12-08 21:16 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 21:16 . 2009-12-08 21:16 -------- d-----w- c:\programmer\Java
2009-12-08 21:16 . 2009-12-08 21:17 -------- d-----w- c:\programmer\LimeWire
2009-12-08 20:30 . 2009-12-08 20:30 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-08 20:26 . 2009-12-08 20:26 -------- d-----w- c:\programmer\Fælles filer\Skype
2009-12-08 20:26 . 2009-12-08 20:27 -------- d-----r- c:\programmer\Skype
2009-12-08 20:26 . 2009-12-08 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-08 20:24 . 2009-12-08 20:24 -------- d-----w- c:\programmer\Microsoft
2009-12-08 20:24 . 2009-12-08 20:24 -------- d-----w- c:\programmer\Windows Live SkyDrive
2009-12-08 20:24 . 2009-12-08 20:24 -------- d-----w- c:\programmer\Windows Live
2009-12-08 20:20 . 2009-12-08 20:20 -------- d-----w- c:\programmer\Fælles filer\Windows Live
2009-12-08 20:17 . 2009-12-08 20:17 -------- d-----w- c:\programmer\Qualcomm
2009-12-08 20:16 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2009-12-08 19:54 . 2009-12-08 19:54 -------- d-----w- c:\programmer\Z8Games
2009-12-08 19:33 . 2010-01-02 13:03 -------- d-----w- c:\programmer\Internet Download Manager
2009-12-08 19:30 . 2009-12-09 11:02 -------- d-----w- C:\$AVG
2009-12-08 19:29 . 2009-12-08 19:29 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-08 19:29 . 2009-12-08 19:29 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-08 19:29 . 2009-12-08 19:29 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-08 19:29 . 2009-12-08 19:29 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-08 19:29 . 2010-01-01 16:31 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-08 19:29 . 2009-12-08 19:29 -------- d-----w- c:\programmer\AVG
2009-12-08 19:29 . 2009-12-08 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-08 19:29 . 2009-12-08 19:29 -------- d-----w- c:\programmer\GRETECH
2009-12-08 14:27 . 2009-12-08 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\GameHouse
2009-12-08 14:27 . 2009-12-22 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2009-12-08 14:27 . 2009-10-26 14:45 102400 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-12-08 14:27 . 2006-09-26 11:03 161976 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2009-12-08 14:27 . 2009-12-28 11:23 -------- d-----w- c:\programmer\Zylom Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 13:03 . 2001-10-09 11:00 68966 ----a-w- c:\windows\system32\perfc006.dat
2010-01-02 13:03 . 2001-10-09 11:00 406966 ----a-w- c:\windows\system32\perfh006.dat
2010-01-02 10:19 . 2001-10-09 11:00 14336 ----a-w- c:\windows\system32\svchost.exe
2010-01-01 14:41 . 2009-12-07 16:58 -------- d-----w- c:\programmer\Steam
2009-12-30 16:52 . 2009-12-07 22:47 -------- d-----w- c:\programmer\microsoft frontpage
2009-12-20 10:11 . 2009-12-07 22:54 -------- d--h--w- c:\programmer\InstallShield Installation Information
2009-12-08 20:11 . 2009-12-08 20:10 -------- d-----w- c:\programmer\Winamp
2009-12-08 04:35 . 2009-12-07 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-12-07 23:40 . 2009-12-07 22:54 -------- d-----w- c:\programmer\Realtek
2009-12-07 23:39 . 2009-12-07 23:39 -------- d-----w- c:\programmer\Intel
2009-12-07 23:28 . 2009-12-07 23:28 -------- d-----w- c:\programmer\Fælles filer\InstallShield
2009-12-07 22:47 . 2009-12-07 22:47 70691 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-12-07 22:46 . 2009-12-07 22:46 -------- d-----w- c:\programmer\Fælles filer\Tjenester
2009-12-07 22:45 . 2009-12-07 22:45 21644 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-07 22:45 . 2009-12-07 22:45 -------- d-----w- c:\programmer\Onlinetjenester
2009-12-07 22:15 . 2009-12-07 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\PassMark
2009-12-07 21:24 . 2009-12-07 21:24 -------- d-----w- c:\programmer\AGEIA Technologies
2009-12-07 21:24 . 2009-12-07 21:24 -------- d-----w- c:\programmer\Fælles filer\Wise Installation Wizard
2009-12-07 17:53 . 2009-12-07 17:53 -------- d-----w- c:\programmer\Microsoft WSE
2009-12-07 17:31 . 2009-12-07 17:31 -------- d-----w- c:\programmer\BitTorrent
2009-12-07 17:29 . 2009-12-07 17:29 -------- d-----w- c:\programmer\Electronic Arts
2009-12-07 17:17 . 2009-12-07 17:17 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-12-07 17:17 . 2009-12-07 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-12-07 16:52 . 2009-12-07 16:52 0 ----a-w- c:\windows\nsreg.dat
2009-10-29 04:48 . 2009-10-29 04:48 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48 . 2009-10-29 04:48 348160 ----a-w- c:\windows\system32\msvcr71.dll
2004-06-29 18:14 . 2009-12-07 21:24 892696 ----a-w- c:\programmer\Royale Theme for Win XP.exe
.
------- Sigcheck -------
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\tcpip.sys
- 2004-08-03 . 7399D854596BFEFEED6B60879F28CE07 . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\tcpip.sys
- 2001-10-09 . E7774698BB0D14B0710A9A31E209F9B6 . 327168 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\programmer\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"SpybotSD TeaTimer"="c:\programmer\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-26 15360]
c:\documents and settings\Daniel Kster\Menuen Start\Programmer\Start\
Wallpaper Calendar.lnk - c:\programmer\zepsoft\Wallpaper Calendar\WallCal3.exe [2002-10-19 1227776]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
CesarFTP.lnk - c:\programmer\CesarFTP\CesarFTP.exe [2002-12-1 291328]
Logitech Desktop Messenger.lnk - c:\programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-12-20 67128]
Microsoft Office.lnk - c:\programmer\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-08 19:29 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Daniel Küster^Menuen Start^Programmer^Start^LimeWire On Startup.lnk]
path=c:\documents and settings\Daniel Küster\Menuen Start\Programmer\Start\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-12-07 17:09 1217808 ----a-w- c:\programmer\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-08 21:16 149280 ----a-w- c:\programmer\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Steam\\Steam.exe"=
"c:\\Programmer\\BitTorrent\\bittorrent.exe"=
"c:\\Programmer\\Steam\\steamapps\\snokey@galnet.dk\\counter-strike source\\hl2.exe"=
"c:\\Programmer\\AVG\\AVG9\\avgemc.exe"=
"c:\\Programmer\\AVG\\AVG9\\avgupd.exe"=
"c:\\Programmer\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Programmer\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmer\\Steam\\steamapps\\snokey@galnet.dk\\source dedicated server\\srcds.exe"=
"c:\\Programmer\\LimeWire\\LimeWire.exe"=
"c:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Programmer\\CesarFTP\\Server.exe"=
"c:\\WINDOWS\\system32\\wlcommn.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08-12-2009 20:29 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08-12-2009 20:29 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\programmer\AVG\AVG9\avgemc.exe [08-12-2009 20:29 906520]
R2 avg9wd;AVG Free WatchDog;c:\programmer\AVG\AVG9\avgwdsvc.exe [08-12-2009 20:29 285392]
S3 XDva317;XDva317;\??\c:\windows\system32\XDva317.sys --> c:\windows\system32\XDva317.sys [?]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} -
hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabFF - ProfilePath - c:\documents and settings\Daniel Küster\Application Data\Mozilla\Firefox\Profiles\p1zmdpaz.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/FF - component: c:\programmer\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\programmer\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\programmer\Mozilla Firefox\plugins\npzylomgamesplayer.dll
---- FIREFOX POLITIKKER ----
c:\programmer\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
- - - - TOMME GENVEJE FJERNET - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-nwiz - nwiz.exe
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - (no file)
MSConfigStartUp-NvCplDaemon - c:\windows\System32\NvCpl.dll
MSConfigStartUp-NvMediaCenter - c:\windows\System32\NvMcTray.dll
AddRemove-HijackThis - c:\programmer\Trend Micro\HijackThis\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-02 14:09
Windows 5.1.2600 Service Pack 2 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7b,a8,64,55,93,57,25,b7,4f,f0,c7,a3,15,45,6f,8f,7d,53,8f,f0,48,
d7,ae,26,2c,85,27,41,2d,cf,38,c0,ea,31,25,07,26,17,8a,8e,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{79f4b9ec-babb-49d7-a7eb-483ab40e24c0}]
@Denied: (Full) (Everyone)
"Model"=dword:00000001
"Therad"=dword:00000019
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\AVG\AVG9\avgchsvx.exe
c:\programmer\AVG\AVG9\avgrsx.exe
c:\programmer\AVG\AVG9\avgcsrvx.exe
c:\windows\RTHDCPL.EXE
c:\programmer\CesarFTP\server.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\windows\system32\spupdsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\spnpinst.exe
c:\programmer\AVG\AVG9\avgnsx.exe
c:\programmer\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\Sysocmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\programmer\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Gennemført tid: 2010-01-02 14:12:04 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-01-02 13:12
Pre-Kørsel: 81.431.425.024 byte ledig
Post-Kørsel: 81.328.492.544 byte ledig
- - End Of File - - 04A4323BA1B15C099293F182418959E8