den er gal igen min bb crasher. har kørt hjt og combofix her er loggen for combofix
ComboFix 11-01-19.03 - cabr 20-01-2011 10:47:03.4.2 - x86 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.45.1030.18.3069.2464 [GMT 1:00]
Kører fra: c:\users\cabr\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Dannede nyt systemgendannelsespunkt
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-12-20 til 2011-01-20 )))))))))))))))))))))))))))))))))))
.
2011-01-20 09:50 . 2011-01-20 09:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-19 20:22 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6E20665B-7EDD-4981-B98D-C88FDD65CC2A}\mpengine.dll
2011-01-19 19:20 . 2011-01-19 19:20 71880 ----a-w- c:\windows\system32\PxSecure.dll
2011-01-19 19:20 . 2011-01-19 19:22 26096 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2011-01-19 19:20 . 2011-01-19 19:20 76696 ----a-w- c:\windows\system32\drivers\pxrts.sys
2011-01-19 19:20 . 2011-01-19 19:20 32008 ----a-w- c:\windows\system32\drivers\pxscan.sys
2011-01-19 19:20 . 2011-01-19 19:20 -------- d-----w- c:\program files\Prevx
2011-01-19 19:20 . 2011-01-19 19:22 -------- d-----w- c:\programdata\PrevxCSI
2011-01-18 14:10 . 2011-01-18 14:10 -------- d-----w- c:\program files\CCleaner
2011-01-18 11:12 . 2011-01-18 11:12 -------- d-----w- c:\program files\Loaris
2011-01-17 21:29 . 2011-01-17 21:29 -------- d-----w- c:\users\cabr\AppData\Roaming\Malwarebytes
2011-01-17 21:29 . 2011-01-17 21:29 -------- d-----w- c:\programdata\Malwarebytes
2011-01-17 21:29 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-17 21:29 . 2011-01-17 21:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-17 21:29 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-17 14:19 . 2011-01-17 14:19 -------- d-----w- c:\users\cabr\AppData\Roaming\Software Inspection Library
2011-01-17 10:46 . 2011-01-17 10:46 -------- d-----w- c:\program files\Enigma Software Group
2011-01-17 10:46 . 2011-01-18 14:22 -------- d-----w- c:\windows\41EBC322660F4D16A0DF53147210CBDB.TMP
2011-01-17 10:46 . 2011-01-17 10:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-01-17 08:29 . 2011-01-17 08:43 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-01-15 21:21 . 2011-01-15 21:21 -------- d-----w- c:\users\cabr\AppData\Roaming\CheckPoint
2011-01-15 21:20 . 2010-05-15 15:30 461400 ----a-w- c:\windows\system32\drivers\vsdatant.sys
2011-01-15 21:20 . 2011-01-15 21:20 -------- d-----w- c:\program files\Zone Labs
2011-01-15 20:33 . 2011-01-20 09:35 -------- d-----w- c:\windows\Internet Logs
2011-01-15 20:33 . 2011-01-15 20:33 -------- d-----w- c:\programdata\CheckPoint
2011-01-15 09:04 . 2011-01-15 09:04 -------- d-sh--w- c:\programdata\PIXXUIS
2011-01-15 09:04 . 2011-01-16 21:37 -------- d-sh--w- c:\programdata\1e95a2
2011-01-13 14:50 . 2011-01-13 14:50 -------- d-----w- c:\users\cabr\AppData\Local\Canon Easy-PhotoPrint EX
2011-01-13 14:50 . 2011-01-13 14:50 -------- d--h--w- c:\programdata\CanonIJEPPEX
2011-01-13 14:47 . 2011-01-14 21:55 -------- d-----w- c:\programdata\CanonIJPLM
2011-01-13 14:46 . 2011-01-13 14:46 -------- d--h--w- c:\programdata\CanonIJSolutionMenuEX
2011-01-13 14:46 . 2011-01-13 14:46 -------- d--h--w- c:\programdata\CanonEPP
2011-01-13 14:46 . 2011-01-13 14:46 -------- d--h--w- c:\programdata\CanonIJMyPrinter
2011-01-13 14:42 . 2011-01-13 14:42 -------- d-----w- c:\programdata\CanonIJMSetup
2011-01-13 14:41 . 2011-01-13 14:41 -------- d-----w- c:\program files\Common Files\CANON
2011-01-13 14:41 . 2011-01-13 14:41 -------- d-----w- c:\programdata\CanonIJWSpt
2011-01-13 14:32 . 2011-01-13 14:48 -------- d-----w- c:\program files\Canon
2011-01-13 14:31 . 2011-01-13 14:31 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-01-13 14:31 . 2011-01-13 14:31 -------- d--h--w- c:\programdata\CanonBJ
2011-01-13 14:31 . 2010-08-25 04:00 73216 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAA.DLL
2011-01-13 14:31 . 2010-08-25 04:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAA.DLL
2011-01-13 14:30 . 2010-08-25 04:00 290816 ----a-w- c:\windows\system32\CNMLMAA.DLL
2011-01-13 14:30 . 2010-03-18 18:25 307200 ----a-w- c:\windows\system32\CNC280L.dll
2011-01-13 14:30 . 2010-03-18 16:12 1335296 ----a-w- c:\windows\system32\CNC280C.dll
2011-01-13 14:30 . 2010-03-18 16:12 114688 ----a-w- c:\windows\system32\CNC280I.dll
2011-01-13 14:30 . 2010-03-18 16:11 106496 ----a-w- c:\windows\system32\CNC280U.dll
2011-01-12 15:29 . 2011-01-12 15:29 -------- d-----w- c:\users\cabr\.oces2
2011-01-11 16:22 . 2011-01-11 16:22 -------- d-----w- c:\users\cabr\AppData\Local\Conduit
2011-01-11 16:22 . 2011-01-11 16:22 -------- d-----w- c:\program files\Productivity_2.2
2011-01-11 14:32 . 2011-01-11 15:02 -------- d-----w- c:\program files\Xvid
2011-01-11 14:32 . 2009-06-07 15:25 77824 ----a-w- c:\windows\system32\xvid.ax
2011-01-11 14:32 . 2009-06-07 15:24 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2011-01-11 14:32 . 2009-06-07 15:16 819200 ----a-w- c:\windows\system32\xvidcore.dll
2011-01-10 21:35 . 2011-01-15 08:52 47360 ----a-w- c:\users\cabr\AppData\Roaming\pcouffin.sys
2011-01-10 21:35 . 2011-01-10 21:35 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2011-01-10 21:35 . 2011-01-15 08:52 -------- d-----w- c:\users\cabr\AppData\Roaming\Vso
2011-01-10 10:32 . 2011-01-10 10:32 -------- d-----w- c:\programdata\Goland
2011-01-10 09:53 . 2008-02-28 12:26 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2011-01-09 14:00 . 2011-01-09 14:00 -------- d-----w- c:\program files\Smart Projects
2011-01-07 15:05 . 2011-01-07 15:32 -------- d-----w- C:\mymovie
2010-12-27 15:59 . 2010-12-28 14:32 -------- d-----w- c:\users\cabr\AppData\Local\Apple Computer
2010-12-27 15:59 . 2010-12-27 21:27 -------- d-----w- c:\users\cabr\AppData\Roaming\Apple Computer
2010-12-27 15:58 . 2010-12-27 15:59 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-12-27 15:57 . 2010-12-27 15:57 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2010-12-22 16:53 . 2010-12-22 17:07 1409 ----a-w- c:\windows\QTFont.for
2010-12-22 16:51 . 2010-12-22 17:06 -------- d-----w- c:\programdata\QuickTime
2010-12-22 16:40 . 2010-12-22 17:07 -------- d-----w- c:\program files\Ubisoft
2010-12-22 16:39 . 2004-10-22 01:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:58 . 2010-11-18 18:58 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\tmpidcrl.dll
2010-11-18 18:58 . 2009-08-18 10:30 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2010-11-18 18:58 . 2009-08-18 10:24 17816 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2010-11-12 17:53 . 2010-07-27 06:46 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-04 05:52 . 2010-12-15 06:03 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48 . 2010-12-15 06:03 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41 . 2010-12-15 06:03 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08 . 2010-12-15 06:03 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41 . 2010-12-15 05:22 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40 . 2010-12-15 05:22 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40 . 2010-12-15 05:22 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39 . 2010-12-15 05:22 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-15 05:22 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34 . 2010-12-15 05:22 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-27 04:32 . 2010-12-15 05:24 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-01-19_20.01.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2011-01-19 20:21 53296 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-02 07:11 . 2011-01-19 20:21 14552 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2582585493-2844099296-214694576-1000_UserData.bin
- 2010-01-01 09:27 . 2011-01-17 20:50 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-01 09:27 . 2011-01-19 20:26 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-01 09:27 . 2011-01-17 20:50 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-01 09:27 . 2011-01-19 20:26 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:41 . 2011-01-17 20:50 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2011-01-19 20:26 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:34 . 2011-01-19 20:21 79056 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-01-01 10:09 . 2011-01-15 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-01 10:09 . 2011-01-19 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-01 10:09 . 2011-01-15 21:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-01 10:09 . 2011-01-19 21:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-01-20 08:36 . 2011-01-20 08:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-01-18 22:08 . 2011-01-19 07:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-01-20 08:36 . 2011-01-20 08:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-01-18 22:08 . 2011-01-19 07:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-06 08:47 . 2010-10-19 09:41 222080 c:\windows\System32\MpSigStub.exe
+ 2010-08-17 06:17 . 2011-01-19 20:26 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-08-17 06:17 . 2011-01-15 19:55 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:47 . 2011-01-15 21:35 272264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 04:47 . 2011-01-19 21:58 272264 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2010-08-13 20:36 . 2011-01-15 21:35 273032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2582585493-2844099296-214694576-1000-8192.dat
+ 2010-08-13 20:36 . 2011-01-19 21:58 273032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2582585493-2844099296-214694576-1000-8192.dat
- 2009-07-14 02:03 . 2011-01-16 20:50 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:03 . 2011-01-19 21:52 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-07-14 04:34 . 2011-01-13 07:36 4661362 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:34 . 2011-01-19 20:21 4661362 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e84cc2c1-b722-48fc-a39c-edb8b525c777}"= "c:\program files\Productivity_2.2\prxtbProd.dll" [2011-01-03 175400]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
[HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}]
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2010-12-01 10:27 2735200 ----a-w- c:\program files\ZoneAlarm_Security\tbZone.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-21 10:17 1233288 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e84cc2c1-b722-48fc-a39c-edb8b525c777}]
2011-01-03 09:16 175400 ----a-w- c:\program files\Productivity_2.2\prxtbProd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-21 1233288]
"{e84cc2c1-b722-48fc-a39c-edb8b525c777}"= "c:\program files\Productivity_2.2\prxtbProd.dll" [2011-01-03 175400]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}]
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-21 1233288]
"{E84CC2C1-B722-48FC-A39C-EDB8B525C777}"= "c:\program files\Productivity_2.2\prxtbProd.dll" [2011-01-03 175400]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{e84cc2c1-b722-48fc-a39c-edb8b525c777}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"TouchFreeze"="c:\program files\TouchFreeze\TouchFreeze.exe" [2005-04-29 45056]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-03-03 155648]
"Raptr"="c:\progra~1\Raptr\raptrstub.exe" [2011-01-11 53160]
"Steam"="c:\program files\Steam\Steam.exe" [2010-11-17 1242448]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-09-02 672632]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-05 39408]
"RESTART_STICKY_NOTES"="c:\windows\system32\StikyNot.exe" [2009-07-14 354304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"KMCONFIG"="c:\program files\Keyboard & Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"NBAgent"="c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-03-26 1234216]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-11-16 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-11-05 738808]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
R1 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-01-19 76696]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2011-01-19 6416120]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 135664]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2010-11-05 26872]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2010-11-05 488952]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Keyboard & Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
R3 BthAvrcp;Bluetooth AVRCP-profil;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [2007-03-29 17024]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-02 1343400]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-01-19 32008]
S3 netw5v32;Kortdriver til Intel(R) trådløs WiFi 5000 Series-forbindelse til Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-01-19 26096]
.
Indhold af mappen 'Planlagte Opgaver'
2011-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 21:44]
2011-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 21:44]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/mStart Page =
hxxp://www.bigseekpro.com/burn4free/{9C89FB15-D4F2-4CAD-B5DA-C56843A7D09D}uInternet Settings,ProxyOverride = <local>
Trusted Zone: danid.dk
Trusted Zone: nordea.dk\www.netbank
Trusted Zone: danid.dk
TCP: {B67C8737-2923-4EB7-8402-1357056CE4F3} = 208.67.222.222,208.67.220.220
TCP: 752425D233430383 = 208.67.222.222,208.67.220.220
.
- - - - TOMME GENVEJE FJERNET - - - -
HKLM-RunOnce-<NO NAME> - (no file)
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Gennemført tid: 2011-01-20 10:52:39
ComboFix-quarantined-files.txt 2011-01-20 09:52
ComboFix2.txt 2011-01-20 08:27
ComboFix3.txt 2011-01-20 08:02
ComboFix4.txt 2011-01-19 20:03
Pre-Kørsel: 86.622.810.112 byte ledig
Post-Kørsel: 86.556.553.216 byte ledig
- - End Of File - - 6399DA29D0F303C45C009041777AE330
jeg har også loggen for hjt