ComboFix 10-04-07.04 - Ilse 08-04-2010 15:11:59.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3038.2287 [GMT 2:00]
Kører fra: F:\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3406256479-142805783-62209338-500
c:\$recycle.bin\S-1-5-21-734878722-964706295-3213630054-500
c:\windows\system32\AutoRun.inf
c:\windows\system32\oem9.inf
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-03-08 til 2010-04-08 )))))))))))))))))))))))))))))))))))
.
2010-04-08 13:33 . 2010-04-08 13:36 -------- d-----w- c:\users\Ilse\AppData\Local\temp
2010-04-08 13:33 . 2010-04-08 13:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-08 06:13 . 2010-04-08 06:13 -------- d-----w- c:\program files\CCleaner
2010-04-07 20:12 . 2010-04-07 20:12 -------- d-----w- c:\users\Ilse\AppData\Roaming\Malwarebytes
2010-04-07 20:11 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-07 20:11 . 2010-04-07 20:11 -------- d-----w- c:\programdata\Malwarebytes
2010-04-07 20:11 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-07 20:11 . 2010-04-07 21:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-07 13:52 . 2010-04-07 13:52 -------- d-----w- c:\users\Ilse\AppData\Local\ewcemnrbx
2010-03-28 20:29 . 2010-03-28 20:29 -------- d-----w- c:\users\Ilse\AppData\Roaming\Template
2010-03-11 06:01 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 06:01 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-03-11 06:01 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-10 20:40 . 2010-03-10 20:40 -------- d-----w- c:\program files\Microsoft Security Essentials
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 13:40 . 2010-01-09 17:29 -------- d-----w- c:\users\Ilse\AppData\Roaming\LimeWire
2010-04-08 13:39 . 2009-09-15 13:28 -------- d-----w- c:\users\Ilse\AppData\Roaming\Skype
2010-04-08 13:16 . 2009-02-17 09:07 589296 ----a-w- c:\windows\system32\perfh01D.dat
2010-04-08 13:16 . 2009-02-17 09:07 117296 ----a-w- c:\windows\system32\perfc01D.dat
2010-04-08 13:16 . 2009-02-17 09:01 76390 ----a-w- c:\windows\system32\perfc014.dat
2010-04-08 13:16 . 2009-02-17 09:01 443832 ----a-w- c:\windows\system32\perfh014.dat
2010-04-08 13:16 . 2009-02-17 08:56 80612 ----a-w- c:\windows\system32\perfc00B.dat
2010-04-08 13:16 . 2009-02-17 08:56 427118 ----a-w- c:\windows\system32\perfh00B.dat
2010-04-08 13:16 . 2009-02-17 08:50 77202 ----a-w- c:\windows\system32\perfc006.dat
2010-04-08 13:16 . 2009-02-17 08:50 463344 ----a-w- c:\windows\system32\perfh006.dat
2010-04-08 10:56 . 2009-09-15 13:31 -------- d-----w- c:\users\Ilse\AppData\Roaming\skypePM
2010-04-07 21:46 . 2009-09-17 16:49 6836 ----a-w- c:\users\Ilse\AppData\Local\d3d9caps.dat
2010-03-28 20:29 . 2010-03-28 20:29 0 ----a-w- c:\users\Ilse\AppData\Roaming\wklnhst.dat
2010-03-11 06:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-11 06:07 . 2009-09-04 12:30 -------- d-----w- c:\programdata\Microsoft Help
2010-03-10 20:08 . 2009-11-09 09:11 -------- d-----w- c:\programdata\avg9
2010-03-04 20:15 . 2010-03-04 20:15 -------- d-----w- c:\programdata\Birdstep Technology
2010-03-04 20:15 . 2010-03-04 20:15 -------- d-----w- c:\users\Ilse\AppData\Roaming\Birdstep Technology
2010-03-04 20:13 . 2009-09-04 13:17 71279 ----a-w- c:\windows\Huawei ModemsUninstall.exe
2010-03-04 20:13 . 2010-03-04 20:13 -------- d-----w- c:\program files\Connect it
2010-03-04 20:13 . 2009-02-17 08:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-03 09:54 . 2009-02-17 09:49 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
2010-02-25 17:53 . 2010-02-25 17:53 -------- d-----w- c:\program files\Mouse Driver
2010-02-25 05:26 . 2009-09-04 12:41 75832 ----a-w- c:\users\Ilse\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-11-07 08:27 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-30 18:57 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-30 18:57 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-30 18:57 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-30 18:57 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-19 13:21 . 2009-02-17 09:03 -------- d-----w- c:\programdata\WildTangent
2010-02-19 13:21 . 2009-02-17 09:03 -------- d-----w- c:\program files\HP Games
2010-02-12 10:32 . 2010-03-09 02:00 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-02-09 16:43 . 2010-02-09 16:43 87040 --sha-r- c:\users\Ilse\AppData\Roaming\WMADMOE2.dll
2010-01-25 12:00 . 2010-02-23 21:24 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-23 21:24 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-23 21:24 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-23 21:24 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-23 21:24 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-23 21:24 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-23 21:24 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-23 21:24 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-23 21:24 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-23 21:24 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-04 39408]
"wuqsurqn"="c:\users\Ilse\AppData\Local\ewcemnrbx\svnutgstssd.exe" [2010-04-07 275200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-29 1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-05-09 206120]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-15 218408]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-19 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-25 149280]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-10-26 450659]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2008-05-30 212992]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
c:\users\Ilse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]
Screen Clipper and Launcher til OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Opdateringsagent.lnk - c:\program files\Connect it\Connect it\AutoUpdateSrv.exe [2010-3-4 667648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):67,24,26,49,86,9e,ca,01
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe [2008-06-27 77824]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
2010-04-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 13:28]
2010-04-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 13:28]
2010-04-08 c:\windows\Tasks\User_Feed_Synchronization-{E7900C73-839E-430F-84A7-879F08B4BFFF}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.ni.dk/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=91&bd=Pavilion&pf=cnnbuInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: &AOL Toolbar-søgning - c:\programdata\AOL\ieToolbar\resources\da-DK\local\search.html
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.
.
------- Fil Associationer -------
.
.
- - - - TOMME GENVEJE FJERNET - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-Wdf01000.sys
AddRemove-HijackThis - F:\HijackThis.exe
**************************************************************************
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer:
**************************************************************************
.
------------------------ Andre kørende processer ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\WLANExt.exe
c:\program files\Mouse Driver\KMWDSrv.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\SMINST\BLService.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Mouse Driver\KMConfig.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Mouse Driver\KMProcess.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Microsoft Security Essentials\MpCmdRun.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Gennemført tid: 2010-04-08 15:43:19 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-04-08 13:43
Pre-Kørsel: 223.509.630.976 byte ledig
Post-Kørsel: 224.088.756.224 byte ledig
- - End Of File - - A417230AF35E380D7638296606F55658