xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Combofix.txt
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
ComboFix 11-01-26.01 - Jacob 27-01-2011 10:25:19.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.45.1030.18.2006.1315 [GMT 1:00]
Kører fra: c:\documents and settings\Jacob\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Jacob\Skrivebord\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents
C:\Install.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\nsprs.dll
c:\windows\system32\prsgrc.dll
c:\windows\system32\serauth1.dll
c:\windows\system32\serauth2.dll
c:\windows\system32\ssprs.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-12-27 til 2011-01-27 )))))))))))))))))))))))))))))))))))
.
2011-01-26 22:21 . 2011-01-26 22:21 -------- d-----w- c:\documents and settings\Jacob\Application Data\Malwarebytes
2011-01-26 22:21 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-26 22:21 . 2011-01-26 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-26 22:21 . 2011-01-26 22:21 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-01-26 22:21 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-21 23:04 . 2011-01-21 23:04 -------- d-----w- c:\documents and settings\NetworkService\Application Data\TuneUp Software
2011-01-20 22:54 . 2010-12-14 13:43 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-01-20 22:54 . 2010-12-14 13:39 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2011-01-20 22:54 . 2011-01-20 22:54 -------- d-----w- c:\documents and settings\Jacob\Application Data\TuneUp Software
2011-01-20 22:53 . 2011-01-20 22:54 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-01-20 22:53 . 2011-01-20 22:53 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-01-19 10:03 . 2011-01-19 10:03 -------- d-----w- c:\programmer\Microsoft.NET
2011-01-19 10:03 . 2011-01-19 10:03 -------- d-----w- c:\documents and settings\All Users\Microsoft
2011-01-19 09:58 . 2011-01-19 09:58 -------- d-----w- c:\programmer\Microsoft Analysis Services
2011-01-19 09:58 . 2011-01-19 10:05 -------- d-----w- c:\windows\SHELLNEW
2011-01-19 09:56 . 2011-01-19 09:56 -------- d-----r- C:\MSOCache
2011-01-19 08:54 . 2011-01-19 08:54 -------- d-----w- c:\documents and settings\Jacob\Lokale indstillinger\Application Data\VS Revo Group
2011-01-17 19:57 . 1999-03-23 07:12 304128 ----a-w- c:\windows\unin040c.exe
2011-01-17 19:57 . 2011-01-17 19:57 -------- d-----w- c:\documents and settings\Jacob\WINDOWS
2011-01-15 20:57 . 2005-11-10 18:21 1499136 ------w- c:\programmer\Mozilla Firefox\plugins\npdjvu.dll
2011-01-15 20:57 . 2011-01-15 20:57 -------- d-----w- c:\programmer\LizardTech
2011-01-15 20:51 . 2011-01-15 20:51 -------- d-----w- c:\documents and settings\Jacob\Application Data\UDC Profiles
2011-01-15 20:45 . 2011-01-15 20:45 -------- d-----w- c:\documents and settings\Jacob\Application Data\MathWorks
2011-01-13 13:41 . 2011-01-13 13:41 -------- d-----w- c:\programmer\iPod
2011-01-13 13:41 . 2011-01-13 13:42 -------- d-----w- c:\programmer\iTunes
2011-01-12 11:53 . 2011-01-12 11:53 -------- d-----w- c:\windows\Microsoft Shared
2011-01-12 11:26 . 2011-01-12 11:26 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonIJScan
2011-01-12 11:26 . 2011-01-12 11:26 -------- d-----w- c:\documents and settings\Jacob\Application Data\Canon
2011-01-12 10:36 . 2011-01-12 10:36 -------- d-----w- c:\documents and settings\Jacob\Application Data\Addinsoft
2011-01-12 10:36 . 2011-01-12 10:36 -------- d-----w- C:\Addinsoft
2011-01-12 10:27 . 2011-01-19 10:15 -------- d-----w- c:\programmer\Addinsoft
2010-12-30 13:00 . 2010-12-30 13:00 -------- d-----w- c:\programmer\MATLAB
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-13 08:47 . 2010-09-07 22:34 38848 ----a-w- c:\windows\avastSS.scr
2011-01-13 08:47 . 2010-09-07 22:34 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-01-13 08:41 . 2010-09-07 22:34 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-13 08:40 . 2010-09-07 22:34 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-13 08:40 . 2010-09-07 22:34 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-01-13 08:39 . 2010-09-07 22:34 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-01-13 08:37 . 2010-09-07 22:34 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-13 08:37 . 2010-09-07 22:34 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-01-13 08:37 . 2010-09-07 22:34 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-16 15:45 . 2010-12-03 08:58 71253 ----a-w- c:\windows\Huawei ModemsUninstall.exe
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:15 . 2010-09-07 18:02 81920 ------w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-10-13 13:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2010-09-08 11:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-09 14:52 . 2008-04-14 07:05 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:23 . 2008-04-14 07:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:23 . 2008-04-14 07:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:23 . 2008-04-14 07:05 43520 ------w- c:\windows\system32\licmgr10.dll
2010-11-03 12:25 . 2008-04-14 06:39 385024 ------w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2008-04-13 09:57 40960 ------w- c:\windows\system32\drivers\ndproxy.sys
.
------- Sigcheck -------
- 2010-09-07 . 451EECBE879612ACC4AA953B1501FA66 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ------w- c:\documents and settings\Jacob\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ------w- c:\documents and settings\Jacob\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ------w- c:\documents and settings\Jacob\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programmer\Analog Devices\Core\smax4pnp.exe" [2008-04-24 1036288]
"TpShocks"="TpShocks.exe" [2009-12-11 337256]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2010-08-24 517480]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2009-12-01 256576]
"TPHOTKEY"="c:\programmer\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-12-21 69568]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-01-13 3396624]
"TVT Scheduler Proxy"="c:\programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-14 487424]
"ACTray"="c:\programmer\ThinkPad\ConnectUtilities\ACTray.exe" [2010-04-22 431464]
"ACWLIcon"="c:\programmer\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2010-04-22 181608]
"cssauth"="c:\programmer\Lenovo\Client Security Solution\cssauth.exe" [2008-06-13 3073336]
"PSQLLauncher"="c:\programmer\ThinkVantage Fingerprint Software\launcher.exe" [2009-12-01 55048]
"AwaySch"="c:\programmer\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-05 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-05 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-05 142360]
"TPFNF7"="c:\programmer\Lenovo\NPDIRECT\TPFNF7SP.exe" [2010-03-26 62312]
"TPKMAPHELPER"="c:\programmer\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"AMSG"="c:\programmer\ThinkVantage\AMSG\Amsg.exe" [2009-09-03 436800]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programmer\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmer\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ------w- c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2009-12-01 11:41 100104 ------w- c:\programmer\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\programmer\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^BTTray.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Windows Search.lnk]
path=c:\documents and settings\All Users\Menuen Start\Programmer\Start\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jacob^Menuen Start^Programmer^Start^Dropbox.lnk]
path=c:\documents and settings\Jacob\Menuen Start\Programmer\Start\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-07-27 02:10 1983816 ----a-w- c:\programmer\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-18 01:40 767312 ----a-w- c:\programmer\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16 421160 ----a-w- c:\programmer\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\programmer\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
2010-10-22 15:47 524288 ----a-w- c:\programmer\Fælles filer\Spigot\Search Settings\SearchSettings.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\SPSSInc\\PASWStatistics18\\paswstat.com"=
"c:\\Programmer\\SPSSInc\\PASWStatistics18\\WinWrapIDE.exe"=
"c:\\Programmer\\SPSSInc\\PASWStatistics18\\paswstat.exe"=
"c:\\Programmer\\Raptr\\raptr.exe"=
"c:\\Programmer\\Raptr\\raptr_im.exe"=
"c:\\Documents and Settings\\Jacob\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programmer\\Reference Manager 12\\WebPublisher\\thirdparty\\Apache2\\bin\\RMWP_Apache_Admin.exe"=
"c:\\Programmer\\Reference Manager 12\\WebPublisher\\thirdparty\\Apache2\\bin\\RMWP_Apache.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\Programmer\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
R0 DozeHDD;DozeHDD;c:\windows\system32\drivers\DOZEHDD.SYS [07-09-2010 21:11 24304]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [09-10-2009 11:10 20520]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [07-09-2010 23:34 294608]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [07-09-2010 23:25 13480]
R1 SASDIFSV;SASDIFSV;c:\programmer\SUPERAntiSpyware\sasdifsv.sys [17-02-2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\programmer\SUPERAntiSpyware\SASKUTIL.SYS [10-05-2010 19:41 67656]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [09-05-2008 04:50 46144]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07-09-2010 23:34 17744]
R2 DozeSvc;Lenovo Doze Mode Service;c:\programmer\ThinkPad\Utilities\DOZESVC.EXE [07-09-2010 21:11 132456]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\programmer\ThinkPad\Utilities\PWMDBSVC.exe [07-09-2010 21:11 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\programmer\ThinkVantage Fingerprint Software\smihlp.sys [13-03-2009 12:47 12560]
R2 TPHKSVC;Vis på skærm;c:\programmer\Lenovo\HOTKEY\TPHKSVC.exe [07-09-2010 23:25 63928]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\programmer\Lenovo\Rescue and Recovery\rrpservice.exe [14-05-2008 15:25 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\programmer\Lenovo\Rescue and Recovery\UpdateMonitor.exe [09-05-2008 04:50 360448]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [22-02-2008 15:54 37312]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\programmer\Lenovo\HOTKEY\micmute.exe [07-09-2010 23:25 45496]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;"c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe" --> c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [03-12-2010 09:58 112640]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [03-12-2010 09:58 102656]
S3 osppsvc;Office Software Protection Platform;c:\programmer\Fælles filer\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09-01-2010 21:37 4640000]
S3 RMWPService;RMWPService;c:\programmer\Reference Manager 12\WebPublisher\thirdparty\Apache2\bin\RMWP_Apache_Admin.exe [28-01-2004 18:25 20537]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys --> c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [04-11-2010 03:33 41984]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Indhold af mappen 'Planlagte Opgaver'
2011-01-27 c:\windows\Tasks\GlaryInitialize.job
- c:\programmer\Glary Utilities\initialize.exe [2010-09-19 08:32]
2011-01-02 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\programmer\PC-Doctor\uaclauncher.exe [2010-12-13 21:55]
2011-01-27 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2010-09-07 23:28]
2011-01-27 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\programmer\PC-Doctor\pcdrcui.exe [2010-12-13 21:55]
.
.
------- Yderligere scanning -------
.
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: S&end til OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Send til &Bluetooth-enhed... - c:\programmer\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send til Bluetooth - c:\programmer\ThinkPad\Bluetooth Software\btsendto_ie.htm
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\programmer\Fælles filer\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\documents and settings\Jacob\Application Data\Mozilla\Firefox\Profiles\8kmcmly1.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmer\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmer\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programmer\Java\jre6\lib\deploy\jqs\ff
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: EBrary Reader Plugin: reader_plugin@ebrary.com - %profile%\extensions\reader_plugin@ebrary.com
FF - Ext: German Dictionary: de-DE@dictionaries.addons.mozilla.org - %profile%\extensions\de-DE@dictionaries.addons.mozilla.org
.
- - - - TOMME GENVEJE FJERNET - - - -
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
Notify-ACNotify - ACNotify.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-27 10:33
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{21651cc0-9e82-45f8-91c9-370706a3216c}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014f
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,d1,12,be,bf,7e,b1,e4,71,e8,6c,f3,47,17,bd,3c,08,83,e0,8b,c5,07,bb,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):36,4a,4f,05,43,7d,15,95,bf,36,52,f5,06,c4,1c,27,98,ce,be,cf,5c,
df,f6,a9,4e,69,20,c7,64,ef,ff,66,d6,83,fe,c4,cf,f2,8b,9a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
- - - - - - - > 'winlogon.exe'(1156)
c:\windows\system32\tvt_gina.dll
c:\programmer\ThinkPad\ConnectUtilities\ACGina.dll
c:\programmer\ThinkPad\ConnectUtilities\ACHelper.dll
c:\programmer\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\programmer\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\programmer\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\programmer\ThinkPad\ConnectUtilities\ACON.dll
c:\programmer\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\programmer\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\programmer\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\programmer\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll
c:\programmer\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\programmer\Lenovo\HOTKEY\tpwrpc.dll
c:\programmer\ThinkPad\ConnectUtilities\Res\DK\ACGinaRes.dll
c:\programmer\SUPERAntiSpyware\SASWINLO.DLL
c:\programmer\ThinkPad\ConnectUtilities\ACNotify.dll
c:\programmer\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\programmer\ThinkVantage Fingerprint Software\homefus2.dll
c:\programmer\ThinkVantage Fingerprint Software\infql2.dll
c:\programmer\ThinkVantage Fingerprint Software\homepass.dll
c:\programmer\ThinkVantage Fingerprint Software\bio.dll
c:\programmer\ThinkVantage Fingerprint Software\qlbase.dll
- - - - - - - > 'lsass.exe'(1212)
c:\programmer\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\programmer\ThinkVantage Fingerprint Software\homefus2.dll
c:\programmer\ThinkVantage Fingerprint Software\infql2.dll
- - - - - - - > 'explorer.exe'(1452)
c:\documents and settings\Jacob\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ImgUtil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\programmer\Intel\WiFi\bin\S24EvMon.exe
c:\programmer\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\IPSSVC.EXE
c:\programmer\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\system32\acs.exe
c:\programmer\ThinkPad\ConnectUtilities\AcSvc.exe
c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmer\Intel\WiFi\bin\EvtEng.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\Intel\WirelessCommon\RegSrvc.exe
c:\programmer\Lenovo\System Update\SUService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\programmer\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TpKmpSVC.exe
c:\programmer\Lenovo\Client Security Solution\tvttcsd.exe
c:\programmer\Lenovo\Rescue and Recovery\rrservice.exe
c:\programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
c:\windows\system32\SearchIndexer.exe
c:\programmer\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\TpShocks.exe
c:\programmer\Synaptics\SynTP\SynTPEnh.exe
c:\windows\system32\rundll32.exe
c:\programmer\Synaptics\SynTP\SynTPLpr.exe
c:\windows\system32\igfxext.exe
c:\programmer\Lenovo\HOTKEY\TPONSCR.exe
c:\windows\system32\igfxsrvc.exe
c:\programmer\Lenovo\Zoom\TpScrex.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2011-01-27 10:38:34 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-01-27 09:38
Pre-Kørsel: 29.147.529.216 byte ledig
Post-Kørsel: 29.064.085.504 byte ledig
WindowsXP-KB310994-SP2-Home-BootDisk-DAN.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 260AB3E6C20BC478F91142267F0506A9