Så gjorde jeg som anbefalet og der kom følgende ud af det?
Bullguard meddeler at der er 4 filer i karnatæne, tror du jeg skal slette dem?
skal jeg så fortsætte med flg.:
Start OTL og klik på CleanUp
Det vil fjerne OTL
-------------------------
ComboFix 11-02-12.02 - Hjørdis 13-02-2011 17:22:08.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.45.1030.18.4091.2409 [GMT 1:00]
Kører fra: c:\users\Hjørdis\Desktop\ComboFix.exe
AV: BullGuard Antivirus *Enabled/Updated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: BullGuard Firewall *Enabled* {68747E43-7A47-EA26-053F-CB84640E3E67}
SP: BullGuard Antispyware *Enabled/Updated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-01-13 til 2011-02-13 )))))))))))))))))))))))))))))))))))
.
2011-02-13 16:30 . 2011-02-13 16:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-13 08:38 . 2011-01-13 01:20 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5D8FB7BD-306B-418D-A9DA-CAD96A487EA7}\mpengine.dll
2011-02-13 05:24 . 2011-02-13 05:23 115696 ----a-w- c:\windows\system32\BdInstHk.dll
2011-02-12 10:02 . 2011-02-12 10:02 -------- d-----w- c:\users\Hjørdis\AppData\Roaming\Nokia Ovi Suite
2011-02-12 09:22 . 2011-02-12 09:22 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-02-11 06:32 . 2011-02-11 06:32 -------- d-----w- c:\program files (x86)\ESET
2011-02-10 16:26 . 2011-02-10 16:26 -------- d-----w- C:\_OTL
2011-02-10 08:55 . 2011-02-10 08:55 -------- d-----w- c:\program files (x86)\Common Files\Nokia
2011-02-10 08:54 . 2008-08-28 10:44 25600 ----a-w- c:\windows\system32\drivers\pccsmcfdx64.sys
2011-02-10 08:54 . 2011-02-10 08:54 -------- d-----w- c:\program files (x86)\PC Connectivity Solution
2011-02-09 13:21 . 2011-01-13 01:20 7844688 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:15 . 2010-11-30 09:43 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F68C7A79-68C5-47DB-8913-2A877EBF5E65}\gapaengine.dll
2011-02-09 13:06 . 2011-02-09 13:06 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-02-09 13:04 . 2011-02-09 13:06 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-09 13:03 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2011-02-09 11:32 . 2011-02-09 11:32 -------- d-----w- c:\users\Hjørdis\AppData\Roaming\Malwarebytes
2011-02-09 11:32 . 2011-02-09 11:32 -------- d-----w- c:\programdata\Malwarebytes
2011-02-09 11:32 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-02-09 11:31 . 2011-02-09 11:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-02-09 11:31 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-07 10:01 . 2011-02-07 10:01 -------- d-----w- c:\users\Hjørdis\AppData\Local\Nokia
2011-02-07 09:57 . 2011-02-07 09:57 -------- d-----w- c:\programdata\NokiaInstallerCache
2011-02-07 06:55 . 2011-02-12 09:58 -------- d-----w- c:\users\Hjørdis\AppData\Roaming\PC Suite
2011-02-07 06:55 . 2011-02-12 10:02 -------- d-----w- c:\users\Hjørdis\AppData\Roaming\Nokia
2011-02-07 06:55 . 2011-02-07 06:55 -------- d-----w- c:\programdata\PC Suite
2011-02-07 06:54 . 2011-02-10 08:54 -------- dc----w- c:\windows\system32\DRVSTORE
2011-02-07 06:53 . 2010-07-30 13:18 57856 ----a-w- c:\windows\system32\nmwcdclsX64.dll
2011-02-07 06:53 . 2011-02-10 08:53 -------- d-----w- c:\program files (x86)\Nokia
2011-02-07 06:51 . 2011-02-07 06:51 -------- d-----w- c:\programdata\Installations
2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2011-01-21 07:44 . 2011-01-21 07:44 -------- d-----w- c:\users\Hjørdis\AppData\Roaming\Software Inspection Library
2011-01-21 07:28 . 2011-01-21 07:27 98184 ----a-w- c:\windows\SysWow64\BgGamingMonitor.dll
2011-01-21 07:28 . 2011-01-21 07:27 108424 ----a-w- c:\windows\system32\BgGamingMonitor.dll
2011-01-21 07:28 . 2011-01-21 07:27 174472 ----a-w- c:\windows\system32\BGLsp.dll
2011-01-21 07:28 . 2011-01-21 07:27 150920 ----a-w- c:\windows\SysWow64\BGLsp.dll
2011-01-21 07:28 . 2011-02-13 05:23 255560 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2011-01-21 07:28 . 2011-02-13 05:23 25160 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-12 09:21 . 2010-07-24 14:40 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2010-07-24 11:49 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-21 07:27 . 2010-07-08 14:00 424040 ----a-r- c:\windows\system32\drivers\AfwCore.sys
2011-01-21 07:27 . 2010-07-08 14:00 39528 ----a-r- c:\windows\system32\drivers\Afw.sys
2010-12-15 16:01 . 2010-07-08 13:59 63712 ----a-w- c:\windows\system32\drivers\BdSpy.sys
2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\SysWow64\GPhotos.scr
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
.
((((((((((((((((((((((((((((( SnapShot@2011-02-09_19.04.49 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-13 23:48 . 2009-07-14 01:41 97280 c:\windows\system32\wscsvc.dll
+ 2011-02-10 07:31 . 2010-12-21 06:16 97280 c:\windows\system32\wscsvc.dll
+ 2011-02-10 07:32 . 2010-12-21 06:16 62976 c:\windows\system32\wscapi.dll
+ 2011-02-10 07:31 . 2010-12-21 06:15 15360 c:\windows\system32\slwga.dll
+ 2010-03-21 23:45 . 2011-02-13 12:29 81934 c:\windows\system32\perfc006.dat
- 2010-03-21 23:45 . 2011-02-09 13:06 81934 c:\windows\system32\perfc006.dat
- 2010-12-15 06:14 . 2010-11-04 06:32 97280 c:\windows\system32\mshtmled.dll
+ 2011-02-10 07:32 . 2010-12-18 06:12 97280 c:\windows\system32\mshtmled.dll
+ 2011-02-10 07:32 . 2010-12-18 06:08 12288 c:\windows\system32\msfeedssync.exe
- 2010-12-15 06:14 . 2010-11-04 06:28 12288 c:\windows\system32\msfeedssync.exe
+ 2011-02-10 07:32 . 2010-12-18 06:12 82944 c:\windows\system32\msfeedsbs.dll
- 2010-12-15 06:14 . 2010-11-04 06:32 82944 c:\windows\system32\msfeedsbs.dll
+ 2011-02-10 07:32 . 2010-12-18 06:11 57856 c:\windows\system32\licmgr10.dll
- 2010-12-15 06:14 . 2010-11-04 06:31 57856 c:\windows\system32\licmgr10.dll
+ 2009-07-14 05:30 . 2011-02-12 09:55 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2011-02-09 14:18 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2010-07-26 11:24 . 2010-07-26 11:24 12800 c:\windows\system32\DriverStore\FileRepository\nmwcdnsucx64.inf_amd64_neutral_1e268d3f068feca3\nmwcdnsucx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 57856 c:\windows\system32\DriverStore\FileRepository\ccdcmbx64.inf_amd64_neutral_593f819a73da02eb\nmwcdclsx64.dll
+ 2010-07-30 13:17 . 2010-07-30 13:17 19456 c:\windows\system32\DriverStore\FileRepository\ccdcmbx64.inf_amd64_neutral_593f819a73da02eb\ccdcmbx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 26624 c:\windows\system32\DriverStore\FileRepository\ccdcmbox64.inf_amd64_neutral_227463b79a06c6e4\ccdcmbox64.sys
+ 2009-07-14 00:06 . 2009-07-14 00:06 32768 c:\windows\system32\drivers\usbser.sys
+ 2010-07-30 13:17 . 2010-07-30 13:17 19456 c:\windows\system32\drivers\ccdcmbx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 26624 c:\windows\system32\drivers\ccdcmbox64.sys
+ 2010-07-25 00:14 . 2011-02-13 07:11 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-07-25 00:14 . 2011-02-09 13:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-07-25 00:14 . 2011-02-09 13:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-02-11 05:14 . 2011-02-13 07:11 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-02-09 13:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-02-13 07:11 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-15 06:14 . 2010-10-20 05:20 46080 c:\windows\system32\atmlib.dll
+ 2011-02-10 07:31 . 2011-01-07 08:06 46080 c:\windows\system32\atmlib.dll
+ 2010-07-30 13:18 . 2010-07-30 13:18 9216 c:\windows\system32\DriverStore\FileRepository\ccdcmbmx64.inf_amd64_neutral_65d0cd3fafbebc98\usbser_lowerfltx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 9216 c:\windows\system32\DriverStore\FileRepository\ccdcmbjx64.inf_amd64_neutral_b3384c2f6b784066\usbser_lowerfltjx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 9216 c:\windows\system32\drivers\usbser_lowerfltx64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 9216 c:\windows\system32\drivers\usbser_lowerfltjx64.sys
+ 2011-02-10 07:31 . 2010-12-21 06:16 214016 c:\windows\system32\winsrv.dll
- 2009-07-13 23:38 . 2009-07-14 01:41 214016 c:\windows\system32\winsrv.dll
+ 2011-02-10 07:32 . 2010-12-21 06:16 442880 c:\windows\system32\winhttp.dll
+ 2011-02-10 07:32 . 2010-12-21 06:16 258048 c:\windows\system32\WebClnt.dll
- 2010-07-25 06:51 . 2010-03-08 21:59 612352 c:\windows\system32\vbscript.dll
+ 2011-02-10 07:31 . 2011-01-05 06:20 612352 c:\windows\system32\vbscript.dll
+ 2011-02-10 07:32 . 2010-12-21 06:15 264192 c:\windows\system32\upnp.dll
- 2009-07-14 02:36 . 2011-02-09 13:06 621012 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-02-13 12:29 621012 c:\windows\system32\perfh009.dat
+ 2010-03-21 23:45 . 2011-02-13 12:29 475458 c:\windows\system32\perfh006.dat
- 2010-03-21 23:45 . 2011-02-09 13:06 475458 c:\windows\system32\perfh006.dat
- 2009-07-14 02:36 . 2011-02-09 13:06 108232 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-02-13 12:29 108232 c:\windows\system32\perfc009.dat
+ 2010-07-30 13:18 . 2010-07-30 13:18 639488 c:\windows\system32\nmwcdcoclsx64.dll
- 2010-12-15 06:14 . 2010-11-04 06:32 703488 c:\windows\system32\msfeeds.dll
+ 2011-02-10 07:32 . 2010-12-18 06:12 703488 c:\windows\system32\msfeeds.dll
+ 2011-02-10 07:32 . 2010-12-18 06:11 714752 c:\windows\system32\kerberos.dll
+ 2011-02-10 07:31 . 2011-01-05 06:16 852480 c:\windows\system32\jscript.dll
- 2010-07-25 06:52 . 2009-12-02 09:15 852480 c:\windows\system32\jscript.dll
- 2010-12-15 06:14 . 2010-11-04 06:31 256000 c:\windows\system32\iepeers.dll
+ 2011-02-10 07:32 . 2010-12-18 06:11 256000 c:\windows\system32\iepeers.dll
+ 2011-02-10 07:32 . 2010-12-18 06:11 445952 c:\windows\system32\iedkcs32.dll
- 2010-12-15 06:14 . 2010-11-04 06:31 445952 c:\windows\system32\iedkcs32.dll
+ 2009-07-14 04:45 . 2011-02-11 05:46 351472 c:\windows\system32\FNTCACHE.DAT
- 2009-07-14 04:45 . 2010-12-22 06:10 351472 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 05:30 . 2011-02-12 09:55 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-02-09 14:18 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-02-10 09:01 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:30 . 2011-02-09 14:18 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2010-07-26 11:24 . 2010-07-26 11:24 171008 c:\windows\system32\DriverStore\FileRepository\nmwcdnsux64.inf_amd64_neutral_7d58adc19ac7b04c\nmwcdnsux64.sys
+ 2010-07-30 13:18 . 2010-07-30 13:18 639488 c:\windows\system32\DriverStore\FileRepository\ccdcmbx64.inf_amd64_neutral_593f819a73da02eb\nmwcdcoclsx64.dll
+ 2010-07-30 13:19 . 2010-07-30 13:19 142848 c:\windows\system32\DriverStore\FileRepository\ccdcmbx64.inf_amd64_neutral_593f819a73da02eb\ccdcmbwux64.dll
+ 2011-02-10 07:31 . 2011-01-26 06:53 265088 c:\windows\system32\drivers\dxgmms1.sys
+ 2011-02-10 07:31 . 2011-01-26 06:53 982912 c:\windows\system32\drivers\dxgkrnl.sys
- 2011-01-12 06:53 . 2010-11-02 05:21 982912 c:\windows\system32\drivers\dxgkrnl.sys
+ 2011-02-10 07:32 . 2010-12-21 06:10 100864 c:\windows\system32\davclnt.dll
- 2009-07-14 05:12 . 2011-02-09 13:38 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12 . 2011-02-13 07:11 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-01-12 06:53 . 2010-11-02 04:59 144384 c:\windows\system32\cdd.dll
+ 2011-02-10 07:31 . 2011-01-26 06:31 144384 c:\windows\system32\cdd.dll
+ 2010-07-30 13:19 . 2010-07-30 13:19 142848 c:\windows\system32\ccdcmbwux64.dll
+ 2011-02-10 07:31 . 2011-01-07 05:49 366080 c:\windows\system32\atmfd.dll
+ 2011-02-10 07:32 . 2010-12-21 06:16 1197056 c:\windows\system32\wininet.dll
+ 2011-02-10 07:32 . 2011-01-05 04:00 3127808 c:\windows\system32\win32k.sys
+ 2011-02-10 07:32 . 2010-12-21 06:15 1498112 c:\windows\system32\urlmon.dll
+ 2011-02-10 07:31 . 2010-10-27 05:18 5510528 c:\windows\system32\ntoskrnl.exe
+ 2011-02-10 07:31 . 2010-10-27 05:16 1739176 c:\windows\system32\ntdll.dll
+ 2011-02-10 07:32 . 2010-12-21 06:13 2003968 c:\windows\system32\msxml6.dll
+ 2011-02-10 07:32 . 2010-12-21 06:13 1880576 c:\windows\system32\msxml3.dll
+ 2011-02-10 07:32 . 2010-12-18 06:12 1026560 c:\windows\system32\mstime.dll
- 2010-12-15 06:14 . 2010-11-04 06:32 1026560 c:\windows\system32\mstime.dll
+ 2011-02-10 07:32 . 2010-12-18 06:12 9302528 c:\windows\system32\mshtml.dll
- 2010-12-15 06:14 . 2010-11-04 06:31 2447872 c:\windows\system32\iertutil.dll
+ 2011-02-10 07:32 . 2010-12-18 06:11 2447872 c:\windows\system32\iertutil.dll
+ 2010-02-26 13:18 . 2010-02-26 13:18 1721576 c:\windows\system32\DriverStore\FileRepository\ccdcmbx64.inf_amd64_neutral_593f819a73da02eb\wdfcoinstaller01009.dll
+ 2010-07-25 07:33 . 2011-02-11 05:16 39403464 c:\windows\system32\MRT.exe
+ 2011-02-10 07:31 . 2010-12-21 06:11 12369408 c:\windows\system32\ieframe.dll
- 2010-12-15 06:14 . 2010-11-04 06:31 12369408 c:\windows\system32\ieframe.dll
.
-- Snapshot sat til dags dato --
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-11 05:41 120104 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-28 39408]
"ccleaner"="c:\program files\CCleaner\CCleaner64.exe" [2010-11-02 2968376]
"NokiaOviSuite2"="c:\program files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-01-31 703360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files (x86)\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
LUMIX Simple Viewer.lnk - c:\program files (x86)\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2010-8-22 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\System32\BgGamingMonitor.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 135664]
R3 BgRaSvc;BgRaSvc;c:\program files\BullGuard Ltd\BullGuard\Support\BgRaSvc.exe [2011-01-28 160088]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 114304]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-09-11 305448]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-06-18 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-05 216064]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SoundMovieServer;SoundMovieServer;c:\windows\SysWOW64\snmvtsvc.exe [2008-11-11 200704]
R3 STSService;STSService;c:\program files (x86)\SoundTaxi Media Suite\STSService.exe [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-26 1255736]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-10-11 52856]
S1 AFW;Agnitum Firewall Driver;c:\windows\system32\DRIVERS\afw.sys [2011-01-21 39528]
S1 BdSpy;BdSpy;c:\windows\system32\DRIVERS\BdSpy.sys [2010-12-15 63712]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
S1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\DRIVERS\NSKernel.sys [2011-02-13 255560]
S1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\DRIVERS\NSNetmon.sys [2011-02-13 25160]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 BsBhvScan;BullGuard Behavioural Detection;c:\program files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [2011-02-13 367960]
S2 BsBrowser;BullGuard antiphishing service;c:\windows\System32\SvcHost.exe [2009-07-14 27136]
S2 BsFileScan;BullGuard on-access service;c:\windows\System32\SvcHost.exe [2009-07-14 27136]
S2 BsFire;BullGuard firewall service;c:\windows\System32\SvcHost.exe [2009-07-14 27136]
S2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\System32\SvcHost.exe [2009-07-14 27136]
S2 BsMain;BullGuard main service;c:\windows\System32\SvcHost.exe [2009-07-14 27136]
S2 BsUpdate;BullGuard update service;c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [2011-01-28 384856]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-09-30 844320]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 IAANTMON;Intel(R) Matrix Storage Event Monitor;c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-24 62720]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-06-18 144640]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 afwcore;afwcore;c:\windows\system32\DRIVERS\afwcore.sys [2011-01-21 424040]
S3 BsScanner;BullGuard scanning service;c:\program files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [2011-02-13 295256]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-20 317480]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
S3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2008-11-11 33264]
.
Indhold af mappen 'Planlagte Opgaver'
2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 11:31]
2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 11:31]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-11 05:44 137512 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 16395880]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-06 8060960]
"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-09-30 823840]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2011-02-13 1695576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\BgGamingMonitor.dll
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://search.babylon.com/home?AF=15627uLocal Page = c:\windows\system32\blank.htm
mStart Page = about:blank
mLocal Page = c:\windows\system32\blank.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: danid.dk
Trusted Zone: danskebank.dk
DPF: Garmin Communicator Plug-In -
hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CABDPF: {07D09E9E-C667-45DD-B035-217BC2A61A3B} -
hxxps://www.lsb.dk/package/sdc/external/activex/ActiveXSikkerhedssoftware-prod-1.30.cab.
- - - - TOMME GENVEJE FJERNET - - - -
Toolbar-Locked - (no file)
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\program files (x86)\Canon\IJPLM\IJPLMSVC.EXE
c:\program files (x86)\PC Connectivity Solution\ServiceLayer.exe
c:\program files\BullGuard Ltd\BullGuard\files32\spamfilter\LittleHook.exe
c:\program files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files (x86)\Common Files\Nokia\NoA\nokiaaserver.exe
.
**************************************************************************
.
Gennemført tid: 2011-02-13 18:16:41 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-02-13 17:16
ComboFix2.txt 2011-02-09 19:13
Pre-Kørsel: 220.914.151.424 byte ledig
Post-Kørsel: 220.645.330.944 byte ledig
- - End Of File - - 576D321A23053EE1042A86E6D08B37AF