okay... haha
ComboFix 11-02-26.01 - Lau 27-02-2011 8:28.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.45.1030.18.4095.2920 [GMT 1:00]
Kører fra: c:\users\Lau\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Lau\Desktop\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
FW: COMODO Firewall *Disabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Dannede nyt systemgendannelsespunkt
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files (x86)\vShare\
c:\program files (x86)\vShare\\configuration.xml
c:\program files (x86)\vShare\\configuration_ex.xml
c:\program files (x86)\vShare\\icon_logo.bmp
c:\program files (x86)\vShare\\images.bmp
c:\program files (x86)\vShare\\lip.exe
c:\program files (x86)\vShare\\newtab.htm
c:\program files (x86)\vShare\\radio\ajax.js
c:\program files (x86)\vShare\\radio\bg.gif
c:\program files (x86)\vShare\\radio\play.gif
c:\program files (x86)\vShare\\radio\play_hover.gif
c:\program files (x86)\vShare\\radio\radio.html
c:\program files (x86)\vShare\\radio\radio.js
c:\program files (x86)\vShare\\radio\sample_radio.jpg
c:\program files (x86)\vShare\\radio\stations.xml
c:\program files (x86)\vShare\\radio\stop.gif
c:\program files (x86)\vShare\\radio\stop_hover.gif
c:\program files (x86)\vShare\\radio\v_minus.gif
c:\program files (x86)\vShare\\radio\v_minus_1.gif
c:\program files (x86)\vShare\\radio\v_plus.gif
c:\program files (x86)\vShare\\radio\v_plus_1.gif
c:\program files (x86)\vShare\\radio\vol_line_emp.gif
c:\program files (x86)\vShare\\radio\vol_line_full.gif
c:\program files (x86)\vShare\\radio\vol_line_half.gif
c:\program files (x86)\vShare\\security_error.htm
c:\program files (x86)\vShare\\setup.bmp
c:\program files (x86)\vShare\\skin\bg.gif
c:\program files (x86)\vShare\\skin\e.gif
c:\program files (x86)\vShare\\skin\tt.gif
c:\program files (x86)\vShare\\TermsOfUse.rtf
c:\program files (x86)\vShare\\thisversion.txt
c:\program files (x86)\vShare\\Uninstall.exe
c:\program files (x86)\vShare\\UNWISE.EXE
c:\program files (x86)\vShare\\vshare_toolbar.dll
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-01-27 til 2011-02-27 )))))))))))))))))))))))))))))))))))
.
2011-02-27 06:33 . 2007-07-19 23:57 411496 ----a-w- c:\windows\system32\xactengine2_9.dll
2011-02-27 01:20 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-02-25 18:55 . 2011-02-11 07:30 7947600 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E17B6DE0-670E-474C-9DF6-6686D6883D28}\mpengine.dll
2011-02-23 22:52 . 2011-02-23 22:52 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-02-23 22:52 . 2011-02-23 22:52 -------- d-----w- c:\program files (x86)\Java
2011-02-23 22:45 . 2011-02-23 22:45 -------- d-----w- c:\users\Lau\AppData\Local\Secunia PSI
2011-02-23 22:45 . 2011-02-23 22:45 -------- d-----w- c:\program files (x86)\Secunia
2011-02-23 06:54 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2011-02-23 06:54 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2011-02-23 06:09 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-23 06:09 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-23 06:09 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-02-23 06:09 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-02-22 03:02 . 2011-02-22 03:02 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2011-02-22 02:43 . 2011-02-22 02:43 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-02-21 14:28 . 2011-02-21 14:28 -------- d-----w- c:\users\Lau\AppData\Local\Mozilla
2011-02-20 23:56 . 2011-02-27 07:33 -------- d-----w- c:\programdata\Kaspersky Lab
2011-02-18 23:44 . 2011-02-18 23:44 -------- d-----w- c:\users\Lau\AppData\Local\{DC2A156A-DF57-424D-9666-653EC449C5C2}
2011-02-18 11:44 . 2011-02-18 11:44 -------- d-----w- c:\users\Lau\AppData\Local\{16873F32-C5A1-40AD-AA83-342DD64296B3}
2011-02-17 23:14 . 2011-02-17 23:15 -------- d-----w- c:\users\Lau\AppData\Local\{C664C750-0F55-405C-BE72-88BF7BC7BEA3}
2011-02-17 11:14 . 2011-02-17 11:14 -------- d-----w- c:\users\Lau\AppData\Local\{E20EAE91-F2C9-475A-AF5E-090A99DA0943}
2011-02-16 15:45 . 2011-02-16 15:45 -------- d-----w- c:\users\Lau\AppData\Local\{D4634294-A1F8-494F-80F6-F0D7F66739A8}
2011-02-16 00:08 . 1998-07-29 17:00 266293 ----a-w- c:\windows\SysWow64\temp.00D
2011-02-16 00:07 . 1999-05-12 23:00 1064456 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2011-02-16 00:07 . 1999-05-09 23:00 1384448 ----a-w- c:\windows\SysWow64\temp.000
2011-02-16 00:07 . 1999-05-06 23:00 204296 ----a-w- c:\windows\SysWow64\RICHTX32.OCX
2011-02-16 00:07 . 1999-05-06 23:00 140288 ----a-w- c:\windows\SysWow64\COMDLG32.OCX
2011-02-16 00:07 . 1999-05-05 21:22 17920 ----a-w- c:\windows\SysWow64\temp.001
2011-02-16 00:07 . 1999-05-05 21:22 16384 ----a-w- c:\windows\SysWow64\temp.005
2011-02-16 00:07 . 1999-03-08 11:02 598288 ----a-w- c:\windows\SysWow64\temp.002
2011-02-16 00:07 . 1999-03-08 11:02 164112 ----a-w- c:\windows\SysWow64\temp.003
2011-02-16 00:07 . 1999-03-08 11:02 147728 ----a-w- c:\windows\SysWow64\temp.004
2011-02-16 00:07 . 2011-02-16 00:09 -------- d-----w- c:\program files (x86)\Databog
2011-02-15 11:50 . 2011-02-15 11:50 -------- d-----w- c:\users\Lau\AppData\Local\{C184A75A-47FF-45E7-83E5-F436FD05108F}
2011-02-14 12:55 . 2011-02-14 12:55 -------- d-----w- c:\users\Lau\AppData\Local\{E485A9FE-7F23-4707-B1ED-587A51F19AB1}
2011-02-13 13:28 . 2011-02-13 13:28 -------- d-----w- c:\users\Lau\AppData\Local\{B83E3536-48B7-4D3F-9EC9-0E300C467A56}
2011-02-12 17:39 . 2011-02-12 17:40 -------- d-----w- c:\users\Lau\AppData\Local\{A1EE9203-58FD-4D10-B8AB-481A99BBC011}
2011-02-12 13:36 . 2011-02-12 13:36 -------- d-----w- c:\users\Lau\AppData\Local\{72D9ED47-769D-4537-9724-E7CFB3283B25}
2011-02-11 11:32 . 2011-02-11 23:45 -------- d-----w- c:\users\Lau\AppData\Local\{4FD5E187-34CC-4721-8B37-F1D6DCCDCD08}
2011-02-10 22:51 . 2011-02-10 22:52 -------- d-----w- c:\users\Lau\AppData\Local\{A35C2EC3-EDA3-4A93-A6A5-C4C0676CF3DC}
2011-02-10 11:08 . 2011-02-10 11:08 -------- d-----w- c:\users\Lau\AppData\Roaming\SUPERAntiSpyware.com
2011-02-10 11:08 . 2011-02-10 11:08 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-02-10 11:08 . 2011-02-10 11:08 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-10 10:54 . 2011-02-10 10:55 -------- d-----w- c:\users\Lau1
2011-02-10 10:51 . 2011-02-10 10:51 -------- d-----w- c:\users\Lau\AppData\Local\{2560174D-13E1-40C4-B912-4D994A0FDE3F}
2011-02-09 16:31 . 2011-02-09 16:31 -------- d-----w- c:\users\Lau\AppData\Local\{01ACBD17-B8DA-458B-80E2-36F1ED74DB02}
2011-02-09 16:26 . 2011-02-09 16:26 -------- d-----w- c:\users\Lau\AppData\Local\{C3575FB2-9DE6-47BD-88C0-A6A7DAE323C2}
2011-02-08 11:40 . 2011-02-08 11:40 -------- d-----w- c:\users\Lau\AppData\Local\{F4BF02C5-FB50-4DF6-97BA-F03764265BB3}
2011-02-07 23:39 . 2011-02-07 23:40 -------- d-----w- c:\users\Lau\AppData\Local\{72E97142-86BC-437B-AE06-BA4E82CD411D}
2011-02-07 11:39 . 2011-02-07 11:39 -------- d-----w- c:\users\Lau\AppData\Local\{BB2B4DD3-21E3-4025-835A-574F1CA55165}
2011-02-06 23:38 . 2011-02-06 23:38 -------- d-----w- c:\users\Lau\AppData\Local\{4629FFDC-D5B8-4499-B918-892171023A8D}
2011-02-06 11:38 . 2011-02-06 11:38 -------- d-----w- c:\users\Lau\AppData\Local\{40530597-8622-415E-92FA-F29E6EEBF8DD}
2011-02-05 12:43 . 2011-02-05 12:43 -------- d-----w- c:\users\Lau\AppData\Local\{7103D706-3713-4AA4-9755-715B8279DA7B}
2011-02-04 11:04 . 2011-02-04 23:05 -------- d-----w- c:\users\Lau\AppData\Local\{3DA949ED-F1B5-4B7B-9BBD-1BFD2872E392}
2011-02-03 13:00 . 2011-02-03 13:00 -------- d-----w- c:\users\Lau\AppData\Local\{2C4068CC-A749-4F7D-8813-BFEB6A0FB045}
2011-02-03 12:23 . 2011-02-03 12:23 -------- d-----w- c:\users\Lau\AppData\Local\{E7C5DCEE-FD9E-430E-B759-4BF509A0A1FC}
2011-02-02 15:12 . 2011-02-02 15:12 -------- d-----w- c:\users\Lau\AppData\Local\{0157F438-CBF7-418A-A042-2E926CC9A683}
2011-02-01 17:33 . 2011-02-01 17:33 -------- d-----w- c:\users\Lau\.oces
2011-02-01 11:34 . 2011-02-01 11:35 -------- d-----w- c:\users\Lau\AppData\Local\{027B6A7D-01C8-4CCF-98DE-84A5CEAADD94}
2011-01-31 11:13 . 2011-01-31 11:13 -------- d-----w- c:\users\Lau\AppData\Local\{343123B3-2672-4F05-8ED6-187200D88788}
2011-01-30 12:38 . 2011-01-30 12:39 -------- d-----w- c:\users\Lau\AppData\Local\{42ADFF4E-6634-4F2C-8093-43D1A7A557BA}
2011-01-29 10:10 . 2011-01-29 10:10 -------- d-----w- c:\users\Lau\AppData\Local\{6DAB57B0-7520-4DA8-8F44-7F4651CDFF84}
2011-01-28 21:13 . 2011-01-28 21:14 -------- d-----w- c:\users\Lau\AppData\Local\{4C519719-5536-40B5-9915-9DFDBF5B6AE0}
2011-01-28 08:48 . 2011-01-28 08:48 -------- d-----w- c:\users\Lau\AppData\Local\{BE63F3CA-09EF-4709-8F76-5AD0B434307D}
2011-01-28 08:48 . 2011-01-28 08:48 -------- d-----w- c:\users\Lau\AppData\Local\{C888E71E-BCF2-4C01-8115-A984F80DD2E6}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-23 22:52 . 2010-12-12 14:57 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2010-09-20 16:05 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-01-13 18:29 . 2010-12-03 04:33 335168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-01-12 01:01 . 2010-12-29 00:41 89840 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-01-12 01:01 . 2010-12-29 00:41 39888 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-01-12 01:01 . 2010-12-29 00:41 250008 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-01-12 01:01 . 2010-12-29 00:41 14184 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-12-29 00:42 . 2010-12-29 00:42 285480 ----a-w- c:\windows\SysWow64\guard32.dll
2010-12-29 00:42 . 2010-12-29 00:42 362784 ----a-w- c:\windows\system32\guard64.dll
2010-12-23 17:59 . 2010-12-23 17:59 335168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-12-20 17:08 . 2010-12-10 06:16 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-07 09:05 . 2010-12-07 09:05 49752 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-12-06 22:42 . 2010-12-03 04:33 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-12-05 00:46 . 2010-12-05 00:46 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-12-03 09:05 . 2010-12-12 00:33 69152 ----a-w- c:\windows\system32\drivers\Lbd.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\program files (x86)\Veetle\plugins\npVeetle.dll ---
Company: Veetle Inc
File Description: Version 0.9.18, Copyright 2006-2009 Veetle Inc<br><a href=http://www.veetle.com/>
http://www.veetle.com/</a>File Version: 0.9.18
Product Name: Veetle TV Core
Copyright: Copyright © 2006-2009 Veetle Inc
Original Filename: npveetle.dll
File size: 667352
Created time: 2010-10-16 00:00
Modified time: 2010-10-16 00:00
MD5: C50B22C8D91A76069A993A2B5197A296
SHA1: DC2551AE1C6317BD5369F8AD86727B5605A0E39A
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"LogitechVideoRepair"="c:\program files (x86)\Logitech\Video\ISStart.exe" [1601-01-01 0]
"LogitechVideoTray"="c:\program files (x86)\Logitech\Video\LogiTray.exe" [1601-01-01 0]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2011-02-22 352976]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll c:\progra~2\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~1\sbhook.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 136176]
R3 FLASHSYS;FLASHSYS;c:\program files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [2008-02-15 15192]
R3 MsibiosDevice;MsibiosDevice;c:\program files (x86)\MSI\Live Update 4\LU4\msibios64.sys [2008-12-10 33080]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-20 1255736]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-12-03 69152]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-01-12 250008]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-01-12 39888]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11864]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 27736]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2009-12-10 65536]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-01-10 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-01-10 399416]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 22544]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-01-28 86120]
.
Indhold af mappen 'Planlagte Opgaver'
2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 10:08]
2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-08 10:08]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-19 8866120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
hxxp://fck.dk/mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Føj til Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: {{4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - c:\poker\Betway\Poker\MPPoker.exe
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
TCP: {1E05C2C8-E716-4F2C-9A7B-34FA1C85F9D7} = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\users\Lau\AppData\Roaming\Mozilla\Firefox\Profiles\9lch2ji1.default\
FF - prefs.js: browser.startup.homepage -
hxxp://fck.dk/FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
.
- - - - TOMME GENVEJE FJERNET - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-PartyPoker - c:\poker\PartyPoker\PartyPoker\Uninstall.exe
AddRemove-vShare - c:\program files (x86)\vShare\UNINSTALL.exe
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
[HKEY_USERS\S-1-5-21-4109743488-1576573958-2140537889-1000\Software\SecuROM\License information*]
"datasecu"=hex:70,5b,37,8f,3f,a0,ba,67,8b,38,4e,9d,86,ca,ce,aa,37,a4,12,8a,3b,
5b,03,40,d3,2e,fa,6b,e3,69,26,07,cc,ee,98,d0,f9,bd,42,e3,80,64,b8,fe,2e,1f,\
"rkeysecu"=hex:25,6e,26,75,92,ce,4f,64,cb,53,79,fc,02,ed,22,d1
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
.
**************************************************************************
.
Gennemført tid: 2011-02-27 08:35:28 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-02-27 07:35
Pre-Kørsel: 437.628.383.232 byte ledig
Post-Kørsel: 437.508.710.400 byte ledig
- - End Of File - - 1FB395B3803052326D3CCCAAEFEE9135