Så lykkedes det:
ComboFix 10-06-28.01 - Ulla Inger Johansen 29-06-2010 18:43:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1014.412 [GMT 2:00]
Kører fra: c:\documents and settings\Ulla Inger Johansen\Skrivebord\ComboFix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Ulla Inger Johansen\Skrivebord\ComboFix\CFScript.txt
AV: TDC Sikkerhedspakke 9.01 *On-access scanning enabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: TDC Sikkerhedspakke 9.01 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Ijl11.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-05-28 til 2010-06-29 )))))))))))))))))))))))))))))))))))
.
2010-06-29 07:10 . 2010-06-29 07:10 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\Application Data\Malwarebytes
2010-06-29 07:09 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-29 07:09 . 2010-06-29 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-29 07:09 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-29 07:09 . 2010-06-29 07:09 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2010-06-22 21:52 . 2010-06-22 21:52 -------- d-----w- c:\programmer\iPod
2010-06-22 21:40 . 2010-06-22 21:40 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-16 08:40 . 2010-06-16 08:40 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sonic
2010-06-16 08:39 . 2010-06-16 08:39 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\Application Data\Leadertech
2010-06-16 08:36 . 2010-06-16 08:36 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-12 17:03 . 2010-06-12 17:04 0 ----a-w- c:\documents and settings\Ulla Inger Johansen\temp.dat
2010-06-12 17:03 . 2010-06-12 17:03 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\.oces
2010-06-11 10:45 . 2010-06-11 10:45 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\Lokale indstillinger\Application Data\MetaGeek,_LLC
2010-06-11 10:42 . 2010-06-11 10:42 45126 ----a-r- c:\documents and settings\Ulla Inger Johansen\Application Data\Microsoft\Installer\{882C685B-3735-452E-9B77-D562A6A6AFE3}\_C0EDDA7A92A80D14F7FA33.exe
2010-06-11 10:42 . 2010-06-11 10:42 45126 ----a-r- c:\documents and settings\Ulla Inger Johansen\Application Data\Microsoft\Installer\{882C685B-3735-452E-9B77-D562A6A6AFE3}\_6FEFF9B68218417F98F549.exe
2010-06-11 10:42 . 2010-06-11 10:42 -------- d-----w- c:\programmer\MetaGeek
2010-06-09 19:45 . 2010-05-06 10:34 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-02 16:01 . 2010-06-08 14:30 -------- d-----w- c:\programmer\Norton Security Scan
2010-06-02 08:32 . 2010-06-02 08:32 -------- d-----w- c:\documents and settings\NetworkService\Lokale indstillinger\Application Data\Zynga
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 19:32 . 2009-01-07 11:07 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
2010-06-25 18:20 . 2010-01-27 07:48 -------- d-----w- c:\programmer\CCleaner
2010-06-22 22:30 . 2006-02-18 04:32 514158 ----a-w- c:\windows\system32\perfh006.dat
2010-06-22 22:30 . 2006-02-18 04:32 105218 ----a-w- c:\windows\system32\perfc006.dat
2010-06-22 21:53 . 2010-05-12 07:14 -------- d-----w- c:\programmer\iTunes
2010-06-22 21:51 . 2009-11-03 15:47 -------- d-----w- c:\programmer\Fælles filer\Apple
2010-06-16 08:46 . 2009-07-02 20:24 -------- d-----w- c:\documents and settings\Ulla Inger Johansen\Application Data\U3
2010-06-16 08:39 . 2010-05-12 07:02 -------- d-----w- c:\programmer\Safari
2010-06-10 13:51 . 2009-01-07 11:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-08 16:44 . 2009-01-07 13:22 -------- d-----w- c:\programmer\Nokia
2010-06-08 14:30 . 2009-11-09 11:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-06-08 14:29 . 2009-01-07 11:01 -------- d-----w- c:\programmer\Fælles filer\Symantec Shared
2010-06-06 07:39 . 2010-01-13 21:29 -------- d-----w- c:\programmer\Microsoft Silverlight
2010-06-02 16:00 . 2009-11-09 11:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-05-30 13:01 . 2010-04-02 13:01 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-29 07:15 . 2010-05-29 07:15 503808 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-77b341e8-n\msvcp71.dll
2010-05-29 07:15 . 2010-05-29 07:15 61440 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2d5bf094-n\decora-sse.dll
2010-05-29 07:15 . 2010-05-29 07:15 499712 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-77b341e8-n\jmc.dll
2010-05-29 07:15 . 2010-05-29 07:15 348160 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-77b341e8-n\msvcr71.dll
2010-05-29 07:15 . 2010-05-29 07:15 12800 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2d5bf094-n\decora-d3d.dll
2010-05-14 19:27 . 2009-01-09 20:22 -------- d-----w- c:\programmer\Google
2010-05-12 07:15 . 2010-05-12 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-12 07:10 . 2010-05-12 07:10 -------- d-----w- c:\programmer\QuickTime
2010-05-12 07:00 . 2010-05-12 07:00 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-05-11 17:16 . 2009-01-07 10:56 -------- d-----w- c:\programmer\Java
2010-05-08 17:50 . 2009-01-07 13:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-08 17:50 . 2010-05-08 17:50 -------- d-----w- c:\programmer\PC Connectivity Solution
2010-05-08 17:45 . 2010-05-08 17:45 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{73C0DA51-DB32-4F66-970B-7298F3CAF37F}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-08 17:45 . 2010-05-08 17:45 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{73C0DA51-DB32-4F66-970B-7298F3CAF37F}\Installer\CommonCustomActions\Sleep.exe
2010-05-08 17:45 . 2010-05-08 17:45 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{73C0DA51-DB32-4F66-970B-7298F3CAF37F}\Installer\CommonCustomActions\vcredistExec.exe
2010-05-08 17:44 . 2010-05-08 17:47 35762752 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{73C0DA51-DB32-4F66-970B-7298F3CAF37F}\NokiaSoftwareUpdaterSetup_da[1].exe
2010-05-06 10:34 . 2006-02-18 04:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:09 . 2006-02-18 04:31 1851264 ------w- c:\windows\system32\win32k.sys
2010-04-20 05:31 . 2006-02-18 04:31 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-13 07:02 . 2010-04-08 08:28 922400 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\JRERunOnce.exe
2010-04-12 15:29 . 2010-05-11 17:17 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-08 08:47 . 2010-04-08 08:47 503808 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76cf89e7-n\msvcp71.dll
2010-04-08 08:47 . 2010-04-08 08:47 499712 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76cf89e7-n\jmc.dll
2010-04-08 08:47 . 2010-04-08 08:47 348160 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76cf89e7-n\msvcr71.dll
2010-04-08 08:47 . 2010-04-08 08:47 61440 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1cc74d18-n\decora-sse.dll
2010-04-08 08:47 . 2010-04-08 08:47 12800 ----a-w- c:\documents and settings\Ulla Inger Johansen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1cc74d18-n\decora-d3d.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-23 39408]
"Google Update"="c:\documents and settings\Ulla Inger Johansen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe" [2009-10-15 133104]
"WMPNSCFG"="c:\programmer\Windows Media Player\WMPNSCFG.exe" [2006-11-15 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"SynTPLpr"="c:\programmer\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
"SynTPEnh"="c:\programmer\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"TPKMAPHELPER"="c:\programmer\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 856064]
"TpShocks"="TpShocks.exe" [2006-03-15 106496]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"TP4EX"="tp4ex.exe" [2005-10-17 65536]
"SoundMAXPnP"="c:\programmer\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-07-25 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-07-25 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-07-25 118784]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"ISUSPM Startup"="c:\progra~1\FLLESF~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"AwaySch"="c:\programmer\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
"DiskeeperSystray"="c:\programmer\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"ACTray"="c:\programmer\ThinkPad\ConnectUtilities\ACTray.exe" [2007-02-19 409600]
"ACWLIcon"="c:\programmer\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-02-19 110592]
"cssauth"="c:\programmer\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 2341632]
"F-Secure Manager"="c:\programmer\TDCSikkerhedspakke\Common\FSM32.EXE" [2009-08-05 199264]
"F-Secure TNB"="c:\programmer\TDCSikkerhedspakke\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" [2010-03-17 421888]
"AppleSyncNotifier"="c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe" [2010-06-15 141624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
BTTray.lnk - c:\programmer\ThinkPad\Bluetooth Software\BTTray.exe [2006-5-31 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-1-7 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
2006-08-16 17:07 49152 ------w- c:\programmer\Lenovo\AwayTask\AwayNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 14:45 28672 ------w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 11:16 24576 ------w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [07-01-2009 17:04 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [07-01-2009 16:30 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\programmer\TDCSikkerhedspakke\HIPS\drivers\fshs.sys [07-01-2009 16:29 68064]
R2 PrivateDisk;PrivateDisk;c:\programmer\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [13-03-2006 17:05 58368]
R2 smi2;smi2;c:\programmer\SMI2\smi2.sys [14-07-2006 16:55 3968]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\programmer\TDCSikkerhedspakke\Anti-Virus\minifilter\fsgk.sys [07-01-2009 16:28 113864]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [28-01-2010 10:29 135664]
S3 FSORSPClient;F-Secure ORSP Client;c:\programmer\TDCSikkerhedspakke\ORSP Client\fsorsp.exe [07-01-2009 16:29 55992]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [06-04-2009 09:13 13224]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl.sys --> c:\windows\system32\Drivers\usbaapl.sys [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\programmer\TDCSikkerhedspakke\Anti-Virus\win2k\fsfilter.sys [07-01-2009 16:28 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\programmer\TDCSikkerhedspakke\Anti-Virus\win2k\fsrec.sys [07-01-2009 16:28 25184]
.
Indhold af mappen 'Planlagte Opgaver'
2010-06-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-28 08:29]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-01-28 08:29]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3015256264-2327457422-3953637553-1008Core.job
- c:\documents and settings\Ulla Inger Johansen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-10-15 18:28]
2010-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3015256264-2327457422-3953637553-1008UA.job
- c:\documents and settings\Ulla Inger Johansen\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-10-15 18:28]
2010-06-29 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-01-07 16:13]
2010-06-28 c:\windows\Tasks\User_Feed_Synchronization-{E55C760B-E855-40F8-AB9E-052B7290A59F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/ig?hl=da&source=iglkuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
LSP: c:\programmer\TDCSikkerhedspakke\FSPS\program\FSLSP.DLL
Trusted Zone: danid.dk
Trusted Zone: danid.dk
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} -
hxxp://kitchenplanner.ikea.com/DK/Core/Player/2020PlayerAX_Win32.cabDPF: {25C29129-E95F-4564-BFE3-000000007100} -
hxxp://www.123hjemmeside.dk/builder/pages/KvikVideo-7-1-0-0.CABDPF: {4445EA6A-9008-40D5-9160-035FDE5214C4} -
hxxp://www.123hjemmeside.dk/builder/pages/Mpu-dk-1-0-0-8.cabDPF: {4F2A3649-7A9F-4950-9C31-409FAC6FC7C8} -
hxxps://danid.dk/csp/authenticode/csp.exeDPF: {8C379EAB-FB26-4B71-BB5C-05B4C96E4851} -
hxxp://www.123hjemmeside.dk/builder/pages/KvikFoto-1-0-6.CAB.
- - - - TOMME GENVEJE FJERNET - - - -
Toolbar-Locked - (no file)
Notify-ACNotify - ACNotify.dll
Notify-NavLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-29 18:52
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(1000)
c:\programmer\ThinkPad\ConnectUtilities\ACNotify.dll
c:\programmer\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\programmer\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\programmer\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\tphklock.dll
c:\programmer\tdcsikkerhedspakke\hips\fshook32.dll
c:\programmer\Lenovo\AwayTask\AwayNotify.dll
- - - - - - - > 'lsass.exe'(1056)
c:\programmer\TDCSikkerhedspakke\FSPS\program\FSLSP.DLL
c:\programmer\tdcsikkerhedspakke\hips\fshook32.dll
- - - - - - - > 'explorer.exe'(3364)
c:\windows\system32\PROCHLP.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\IPSSVC.EXE
c:\programmer\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\system32\acs.exe
c:\programmer\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\programmer\Diskeeper Corporation\Diskeeper\DkService.exe
c:\programmer\TDCSikkerhedspakke\Anti-Virus\fsgk32st.exe
c:\programmer\TDCSikkerhedspakke\Common\FSMA32.EXE
c:\programmer\TDCSikkerhedspakke\Anti-Virus\FSGK32.EXE
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\programmer\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmer\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\programmer\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.EXE
c:\windows\system32\TpKmpSVC.exe
c:\programmer\Lenovo\Client Security Solution\tvttcsd.exe
c:\programmer\Lenovo\Rescue and Recovery\rrservice.exe
c:\programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
c:\programmer\Lenovo\Rescue and Recovery\ADM\IUService.exe
c:\programmer\ThinkPad\ConnectUtilities\AcSvc.exe
c:\programmer\lenovo\system update\suservice.exe
c:\programmer\Windows Media Player\WMPNetwk.exe
c:\programmer\Fælles filer\Lenovo\Logger\logmon.exe
c:\programmer\TDCSikkerhedspakke\Anti-Virus\fssm32.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\programmer\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\TpShocks.exe
c:\programmer\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\programmer\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\progra~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
c:\programmer\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\programmer\TDCSikkerhedspakke\Common\FSLAUNCHER0.EXE
.
**************************************************************************
.
Gennemført tid: 2010-06-29 18:59:23 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2010-06-29 16:59
Pre-Kørsel: 4.816.961.536 byte ledig
Post-Kørsel: 4.784.861.184 byte ledig
- - End Of File - - 72C03799567AE5F0C89F7B39DAC31F8E