Superantispyware loggen slettede jeg, kan selvfølgelig køre den igen?
ComboFix 10-02-16.03 - far 17-02-2010 21:35:43.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.2038.904 [GMT 1:00]
Kører fra: c:\users\far\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1674595945-2017179872-3778674227-500
c:\$recycle.bin\S-1-5-21-2304783522-1850635467-2630122807-500
c:\$recycle.bin\S-1-5-21-3852295878-3484362443-4022584128-500
c:\$recycle.bin\S-1-5-21-999333346-789248744-1644448349-500
C:\LOG.TXT
c:\users\far\Documents\regdata.reg
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-01-17 til 2010-02-17 )))))))))))))))))))))))))))))))))))
.
2010-02-17 20:49 . 2010-02-17 20:49 -------- d-----w- c:\users\far\AppData\Local\temp
2010-02-17 20:49 . 2010-02-17 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-15 06:51 . 2010-02-15 06:51 52224 ----a-w- c:\users\far\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-15 06:51 . 2010-02-16 14:48 117760 ----a-w- c:\users\far\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-14 21:57 . 2010-02-14 21:57 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-02-14 21:57 . 2010-02-15 06:51 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-14 21:57 . 2010-02-14 21:57 -------- d-----w- c:\users\far\AppData\Roaming\SUPERAntiSpyware.com
2010-02-14 21:56 . 2010-02-14 21:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-14 19:50 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-14 19:50 . 2010-02-14 19:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-14 19:50 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 18:18 . 2009-11-20 08:42 -------- d-----w- c:\program files\BitComet
2010-02-10 18:22 . 2007-09-13 04:44 -------- d-----w- c:\program files\Google
2010-02-09 19:40 . 2009-02-17 21:00 -------- d-----w- c:\program files\Teamspeak2_RC2
2010-02-09 17:52 . 2007-11-20 14:55 -------- d-----w- c:\program files\Lavasoft
2010-02-09 17:52 . 2007-11-20 14:55 -------- d-----w- c:\programdata\Lavasoft
2010-01-30 16:08 . 2006-11-21 04:49 81790 ----a-w- c:\windows\system32\perfc006.dat
2010-01-30 16:08 . 2006-11-21 04:49 471658 ----a-w- c:\windows\system32\perfh006.dat
2010-01-30 12:42 . 2008-12-09 15:26 0 ----a-w- c:\users\far\temp.dat
2010-01-17 08:36 . 2007-08-25 12:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-16 14:02 . 2009-11-01 19:42 -------- d-----w- c:\program files\QuadWeb
2010-01-16 13:50 . 2008-12-23 20:38 -------- d-----w- c:\users\far\AppData\Roaming\Vso
2010-01-14 17:24 . 2007-10-22 17:53 -------- d-----w- c:\users\far\AppData\Roaming\Skype
2010-01-14 17:05 . 2007-11-25 14:53 -------- d-----w- c:\users\far\AppData\Roaming\skypePM
2010-01-10 20:45 . 2010-01-10 20:45 -------- d-----w- c:\program files\VSO
2010-01-10 13:56 . 2010-01-10 13:53 -------- d-----w- c:\program files\Aplus FLV to DIVX Converter
2010-01-10 13:42 . 2010-01-10 13:42 -------- d-----w- c:\program files\Emicsoft Studio
2010-01-02 19:35 . 2007-10-22 18:30 -------- d-----w- c:\users\far\AppData\Roaming\FileZilla
2009-12-30 20:43 . 2009-12-30 20:37 -------- d-----w- c:\program files\Unlocker
2009-12-30 18:16 . 2009-09-28 14:19 -------- d-----w- c:\users\far\AppData\Roaming\vlc
2009-12-30 18:09 . 2009-11-20 18:40 -------- d-----w- c:\program files\MpcStar
2009-12-27 13:17 . 2007-11-23 13:35 -------- d-----w- c:\users\far\AppData\Roaming\Apple Computer
2009-12-27 13:16 . 2009-12-27 13:15 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-27 13:16 . 2009-12-27 13:15 -------- d-----w- c:\program files\iTunes
2009-12-27 13:15 . 2009-12-27 13:15 -------- d-----w- c:\program files\iPod
2009-12-27 13:15 . 2009-12-27 13:07 -------- d-----w- c:\program files\Common Files\Apple
2009-12-27 13:14 . 2009-12-27 13:14 -------- d-----w- c:\program files\Bonjour
2009-12-27 13:14 . 2009-12-27 13:13 -------- d-----w- c:\program files\QuickTime
2009-12-23 11:41 . 2007-10-22 17:07 -------- d-----w- c:\users\far\AppData\Roaming\U3
2009-12-16 18:41 . 2007-08-25 09:17 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-11-24 23:54 . 2008-12-30 23:09 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2008-12-30 23:09 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-12-30 23:09 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-12-30 23:09 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2008-12-30 23:09 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-12-30 23:09 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-12-30 23:09 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-22 19:13 . 2009-05-28 18:45 16 ----a-w- c:\windows\popcinfo.dat
2009-11-22 14:58 . 2009-01-02 19:19 292120 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\YouTube.dll
2009-11-20 20:48 . 2009-11-20 20:48 476512 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\RadioRip.dll
2009-11-20 20:48 . 2009-11-20 20:48 169312 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgSoundclick.dll
2009-11-20 20:48 . 2009-11-20 20:48 128352 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgMyspace.dll
2009-11-20 20:48 . 2009-11-20 20:48 111968 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgPandora.dll
2009-11-20 20:48 . 2009-11-20 20:48 99680 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgIJigg.dll
2009-11-20 20:48 . 2009-11-20 20:48 230752 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgHypemachine.dll
2009-11-20 20:48 . 2009-11-20 20:48 132448 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgImeem.dll
2009-11-20 20:48 . 2009-11-20 20:48 111968 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgLastfm.dll
2009-11-20 20:48 . 2009-11-20 20:48 120160 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgGeneral.dll
2009-11-20 20:48 . 2009-11-20 20:48 87392 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgDefault.dll
2009-11-20 20:48 . 2009-11-20 20:48 140640 ----a-w- c:\programdata\RapidSolution\Tunebite_2009\RadioRip\PlgDeezer.dll
2009-11-20 08:42 . 2009-11-20 08:42 1032192 ----a-w- c:\users\far\AppData\Roaming\Mozilla\Firefox\Profiles\n5w7h1jq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-15 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2007-09-01 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-09-06 188416]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoThumbnail"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoNotification"= 0 (0x0)
"HideSCABattery"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2010-02-15 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2010-02-15 06:51 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTZDetec.exe]
2007-12-18 13:20 401408 ------w- c:\program files\Creative\Creative Media Lite\CTZDetec.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-10 19:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 15:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-04-11 13:32 56080 ----a-w- c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 20:17 52256 ----a-w- c:\program files\Home Cinema\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrOSD]
2006-12-26 09:23 180224 ----a-w- c:\program files\Launch Manager\OSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPass]
2007-09-04 10:45 2560000 ----a-w- c:\program files\Softex\OmniPass\scureapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2007-07-05 10:35 94208 ----a-w- c:\windows\PLFSetL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\toolbar_eula_launcher]
2007-02-09 13:54 16896 ----a-w- c:\program files\GoogleEULA\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tunebite]
2009-09-10 16:58 4678960 ----a-w- c:\program files\RapidSolution\Tunebite\Tunebite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2009-10-26 07:33 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wbutton]
2007-09-07 07:26 86016 ----a-w- c:\program files\Launch Manager\WButton.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9e,49,53,03,76,06,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2461692144-2294394301-1871040877-1000]
"EnableNotificationsRef"=dword:00000001
R0 Si3531;SiI-3531 SATA Controller;c:\windows\System32\drivers\Si3531.sys [05-02-2009 19:38 212520]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [31-12-2008 00:09 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [29-02-2008 16:03 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [29-02-2008 16:03 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [31-12-2008 00:09 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [31-12-2008 00:09 53328]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [11-08-2009 15:01 185640]
R3 RRNetCapMP;RRNetCapMP;c:\windows\System32\drivers\rrnetcap.sys [03-11-2009 16:47 27168]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [16-02-2006 16:51 4096]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\System32\drivers\teamviewervpn.sys [25-01-2008 10:12 25088]
R3 X10Hid;X10 Hid Device;c:\windows\System32\drivers\x10hid.sys [25-08-2007 11:18 13976]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31-07-2009 14:53 133104]
S2 IAANTMON;Intel(R) Matrix Storage Event Monitor;c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe --> c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [?]
S3 DrmRDriverV32;DrmRDriverV32;c:\windows\System32\drivers\DrmRDriverV32.sys [10-08-2008 15:24 23096]
S3 DrmRVideo32;DrmRVideo32;c:\windows\System32\drivers\DrmRVideo32.sys [10-08-2008 15:24 3768]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\System32\drivers\ggflt.sys [16-06-2009 19:57 13224]
S3 MovRVDrv32;MovRVDrv32;c:\windows\System32\drivers\MovRVDrv32.sys [10-08-2008 13:13 3768]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\System32\drivers\nmwcdnsu.sys [01-02-2008 15:17 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\System32\drivers\nmwcdnsuc.sys [01-02-2008 15:17 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [29-06-2007 01:01 42512]
S3 PhilCap;NXP service;c:\windows\System32\drivers\PhilCap.sys [25-08-2007 09:42 908896]
S3 RRNetCap;RRNetCap Service;c:\windows\System32\drivers\rrnetcap.sys [03-11-2009 16:47 27168]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [04-08-2008 15:12 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [04-08-2008 15:12 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [04-08-2008 15:12 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [04-08-2008 15:12 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [04-08-2008 15:12 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [04-08-2008 15:12 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [04-08-2008 15:12 110120]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\System32\drivers\usbaapl.sys [28-08-2009 19:42 40448]
S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [12-09-2007 12:14 118784]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - SASDIFSV
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 14:32 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Indhold af mappen 'Planlagte Opgaver'
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-31 13:53]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-31 13:53]
.
.
------- Yderligere scanning -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: bec.dk\web30.prod
Trusted Zone: danid.dk
Trusted Zone: nordjyskebank.dk
Trusted Zone: portalbank.dk\www
Trusted Zone: sparekassen-vendsyssel.dk\www
Trusted Zone: sparv.dk\www
Trusted Zone: tdc.dk\udstedelse.certifikat
Trusted Zone: testby.dk\www
Trusted Zone: danid.dk
DPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.sparekassen-vendsyssel.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cabFF - ProfilePath - c:\users\far\AppData\Roaming\Mozilla\Firefox\Profiles\n5w7h1jq.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - component: c:\program files\RapidSolution\Tunebite\plugins\GeckoBased\tunebite-firefox-surf-and-catch-extension@audials.com\components\TB_WebRipFFPlugin.dll
FF - component: c:\users\far\AppData\Roaming\Mozilla\Firefox\Profiles\n5w7h1jq.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\RapidSolution\Tunebite\plugins\GeckoBased\tunebite-firefox-surf-and-catch-extension@audials.com\plugins\np_TB_OgloPlugin.dll
FF - plugin: c:\users\far\AppData\Roaming\Mozilla\Firefox\Profiles\n5w7h1jq.default\extensions\turntoolviewer@turntool.com\plugins\nptnt.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLITIKKER ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.
- - - - TOMME GENVEJE FJERNET - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\far\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\octoshape\octoshape.exe**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-17 21:49
Windows 6.0.6002 Service Pack 2 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
"MSCurrentCountry"=dword:00000031
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Gennemført tid: 2010-02-17 21:54:44
ComboFix-quarantined-files.txt 2010-02-17 20:54
ComboFix2.txt 2009-01-01 16:15
Pre-Kørsel: 15.657.492.480 byte ledig
Post-Kørsel: 15.395.581.952 byte ledig
- - End Of File - - 9E5656A0FDD696736E1FC9CA27DA052F