ComboFix 11-03-24.06 - Søren 25-03-2011 16:32:16.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1535.907 [GMT 1:00]
Kører fra: c:\documents and settings\Søren\Skrivebord\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Søren\Skrivebord\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Lene\Application Data\PriceGong
c:\documents and settings\Lene\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Lene\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Søren\Application Data\Microsoft\~DFK36f304.tmp
c:\documents and settings\Søren\Application Data\Microsoft\1eaadjc.dll
c:\documents and settings\Søren\Application Data\Microsoft\engine_vx.dll
c:\documents and settings\Søren\Application Data\Microsoft\kfgresk.dll
c:\documents and settings\Søren\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Søren\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Søren\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Søren\Application Data\Microsoft\rsaadjd.dll
c:\documents and settings\Søren\Application Data\PriceGong
c:\documents and settings\Søren\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Søren\Application Data\PriceGong\Data\z.xml
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.3.inf
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\system32\_000122_.tmp.dll
c:\windows\system32\msvcsv60.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-02-25 til 2011-03-25 )))))))))))))))))))))))))))))))))))
.
.
2011-03-25 15:22 . 2011-03-25 15:22 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C1747C6D-BB7A-4DD5-B2E8-C4F700403259}\MpKsl44e63cbb.sys
2011-03-25 15:22 . 2011-03-15 04:05 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C1747C6D-BB7A-4DD5-B2E8-C4F700403259}\mpengine.dll
2011-03-25 14:12 . 2011-03-25 14:12 -------- d-----w- c:\documents and settings\Søren\Application Data\Malwarebytes
2011-03-25 14:12 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-25 14:12 . 2011-03-25 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-25 14:12 . 2011-03-25 14:12 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-03-25 14:12 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-25 09:44 . 2011-03-25 14:26 -------- d-----w- c:\documents and settings\All Users\Application Data\lLfMnFkGnGn25600
2011-03-25 06:15 . 2011-03-25 06:15 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software
2011-03-24 20:34 . 2011-03-24 20:34 -------- d-----w- c:\documents and settings\Lene\Application Data\TuneUp Software
2011-03-24 06:14 . 2011-03-04 16:28 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2011-03-24 06:08 . 2011-03-04 16:32 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-03-24 06:07 . 2011-03-24 06:07 -------- d-----w- c:\documents and settings\Søren\Application Data\TuneUp Software
2011-03-24 06:07 . 2011-03-24 06:14 -------- d-----w- c:\programmer\TuneUp Utilities 2011
2011-03-24 06:07 . 2011-03-24 06:13 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-03-24 06:06 . 2011-03-24 06:06 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-03-07 08:26 . 2011-03-07 08:26 -------- dc----w- c:\documents and settings\All Users\Application Data\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
2011-03-06 18:18 . 2011-03-06 18:18 -------- d-----w- c:\windows\system32\wbem\Repository
2011-03-06 18:14 . 2011-03-06 18:14 -------- d-----w- c:\programmer\iZotope
2011-03-06 18:14 . 2011-03-06 18:14 -------- d-----w- c:\programmer\Sonic Foundry
2011-03-06 18:14 . 2011-03-06 18:14 -------- d-----w- c:\programmer\NCH Swift Sound
2011-03-04 20:45 . 2011-03-04 20:45 -------- d-----w- c:\documents and settings\Søren\Lokale indstillinger\Application Data\Innovative Solutions
2011-03-04 20:45 . 2011-03-04 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Innovative Solutions
2011-03-04 19:54 . 2011-03-04 20:46 -------- d-----w- c:\documents and settings\Søren\Lokale indstillinger\Application Data\AskToolbar
2011-03-04 19:53 . 2011-03-06 18:14 -------- d-----w- c:\programmer\Ask.com
2011-03-04 19:53 . 2011-03-04 19:53 -------- d-----w- c:\documents and settings\Søren\Application Data\DeviceDoctorSoftware
2011-03-04 18:50 . 2011-03-06 18:14 -------- d-----w- c:\documents and settings\Søren\Application Data\Dropbox
2011-03-01 08:56 . 2011-03-02 10:40 130048 ----a-w- c:\windows\Psynya.exe
2011-02-24 18:13 . 2011-02-24 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\MasterWriter 2.0
2011-02-24 18:13 . 2011-02-24 18:19 -------- d-----w- c:\documents and settings\Søren\MasterWriter 2.0
2011-02-24 18:12 . 2011-03-07 08:23 -------- d-----w- c:\programmer\MasterWriter 2.0
2011-02-24 10:07 . 2011-02-24 10:07 -------- d-----w- c:\programmer\MediaFeed
2011-02-24 09:45 . 2011-03-24 06:25 -------- d-----w- c:\programmer\VersePerfect
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-11 06:54 . 2010-12-26 00:56 5943120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-09 13:53 . 2004-08-26 15:53 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-26 15:53 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-02-18 17:01 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-02-18 17:01 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-26 15:53 439808 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-26 15:52 290048 ----a-w- c:\windows\system32\atmfd.dll
2011-01-06 20:29 . 2011-01-06 20:18 218496 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-06 20:12 . 2011-01-06 20:12 138056 ----a-w- c:\documents and settings\Søren\Application Data\PnkBstrK.sys
2010-12-31 14:03 . 2004-08-26 15:49 1854976 ----a-w- c:\windows\system32\win32k.sys
2006-11-13 16:17 . 2006-11-13 16:17 224040 ----a-w- c:\programmer\richink.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\programmer\DAEMON Tools Pro\DTAgent.exe" [2010-04-15 427328]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-13 8466432]
"nwiz"="nwiz.exe" [2007-07-13 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-13 81920]
"GrooveMonitor"="c:\programmer\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Photo Downloader"="c:\programmer\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 67752]
"AdobeAAMUpdater-1.0"="c:\programmer\Fælles filer\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-12-01 497648]
"SwitchBoard"="c:\programmer\Fælles filer\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\programmer\Fælles filer\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"TkBellExe"="c:\programmer\Real\RealPlayer\update\realsched.exe" [2010-12-20 274608]
"MSC"="c:\programmer\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"AppleSyncNotifier"="c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Lene\Menuen Start\Programmer\Start\
Screen Clipper and Launcher til OneNote 2007.lnk - c:\programmer\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - c:\programmer\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\programmer\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\programmer\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Søren^Menuen Start^Programmer^Start^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Søren\Menuen Start\Programmer\Start\Picture Motion Browser Media Check Tool.lnk
backupExtension=.Startup
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnk.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-09-22 16:11 640440 ----a-w- c:\programmer\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-01-30 23:36 38840 ----a-w- c:\programmer\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2010-04-27 14:37 611712 ----a-w- c:\programmer\Fælles filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0ENQBO]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 00:41 49152 ----a-w- c:\programmer\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 16:16 421160 ----a-w- c:\programmer\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\programmer\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 09:43 248040 ----a-w- c:\programmer\Fælles filer\Java\Java Update\jusched.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AdobeBridge"=
"LKGGOPABUH"=c:\docume~1\SREN~1\LOKALE~1\Temp\Prd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\programmer\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="c:\programmer\iTunes\iTunesHelper.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmer\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programmer\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Programmer\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Programmer\\Fælles filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programmer\\Fælles filer\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Programmer\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Programmer\\WM Recorder\\WMR90.exe"=
"c:\\Programmer\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programmer\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\Programmer\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Programmer\\MasterWriter 2.0\\jre6\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23-08-2010 19:14 697328]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [05-06-2010 20:22 11264]
R1 MpKsl44e63cbb;MpKsl44e63cbb;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C1747C6D-BB7A-4DD5-B2E8-C4F700403259}\MpKsl44e63cbb.sys [25-03-2011 16:22 28752]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\programmer\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [06-09-2010 02:19 169408]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [04-03-2011 17:30 1523008]
R3 RRNetCapMP;RRNetCapMP;c:\windows\system32\drivers\rrnetcap.sys [30-03-2010 15:43 31848]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [07-10-2010 13:34 10064]
S0 engesc;engesc;c:\windows\system32\drivers\qktk.sys --> c:\windows\system32\drivers\qktk.sys [?]
S1 MpKslb9371d3f;MpKslb9371d3f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E06EB71A-F7F8-4400-8BE5-85F297FCC0DC}\MpKslb9371d3f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E06EB71A-F7F8-4400-8BE5-85F297FCC0DC}\MpKslb9371d3f.sys [?]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [11-04-2010 17:08 135664]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\programmer\Fælles filer\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15-08-2008 04:46 288112]
S3 L6UX2;Service - Line 6 UX2;c:\windows\system32\Drivers\L6UX2.sys --> c:\windows\system32\Drivers\L6UX2.sys [?]
S3 RRNetCap;RRNetCap Service;c:\windows\system32\drivers\rrnetcap.sys [30-03-2010 15:43 31848]
S3 SwitchBoard;SwitchBoard;c:\programmer\Fælles filer\Adobe\SwitchBoard\SwitchBoard.exe [19-02-2010 12:37 517096]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys --> c:\windows\system32\drivers\SynasUSB.sys [?]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [28-11-2010 10:28 41984]
S3 ysusb32;Yamaha Steinberg USB Audio;c:\windows\system32\drivers\ysusb32.sys [11-06-2009 17:44 64968]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 17:02 114688 ----a-w- c:\programmer\PixiePack Codec Pack\InstallerHelper.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-04-11 16:08]
.
2011-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-04-11 16:08]
.
2011-03-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\programmer\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 11:26]
.
2011-03-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1202660629-117609710-839522115-1003.job
- c:\programmer\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-03-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1202660629-117609710-839522115-1004.job
- c:\programmer\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-03-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1202660629-117609710-839522115-1003.job
- c:\programmer\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-03-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1202660629-117609710-839522115-1004.job
- c:\programmer\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-03-25 c:\windows\Tasks\User_Feed_Synchronization-{65703C5B-C272-4E24-9AE9-35F84CDB7C8C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
2011-03-25 c:\windows\Tasks\User_Feed_Synchronization-{9A9B5D13-F58C-4164-8C87-A63136B99D28}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/mStart Page =
hxxp://danish.ilsc.org/da/index.php?rvs=hompag/uInternet Settings,ProxyServer =
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Føj linkdestinationen til en eksisterende PDF-fil - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Føj til en eksisterende PDF-fil - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Google Sidewiki ... - c:\programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Konverter linkdestinationen til en Adobe PDF-fil - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Konverter til Adobe PDF - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
Trusted Zone: danid.dk
Trusted Zone: danid.dk
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} -
hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab.
- - - - TOMME GENVEJE FJERNET - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-Adobe Reader Speed Launcher - c:\programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-25 16:45
Windows 5.1.2600 Service Pack 3 NTFS
.
scanner skjulte processer ...
.
scanner skjulte autostarter ...
.
scanner skjulte filer ...
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs startet under kørende Processer ---------------------
.
- - - - - - - > 'winlogon.exe'(1604)
c:\programmer\Fælles filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(2884)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmer\Stardock\Fences\FencesMenu.dll
c:\programmer\stardock\fences\DesktopDock.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\programmer\Fælles filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\programmer\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\RunDll32.exe
c:\programmer\HP\Digital Imaging\bin\hpqimzone.exe
c:\programmer\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Gennemført tid: 2011-03-25 16:52:27 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-03-25 15:52
.
Pre-Kørsel: 13.005.275.136 byte ledig
Post-Kørsel: 13.513.691.136 byte ledig
.
Current=1 Default=1 Failed=6 LastKnownGood=2 Sets=1,2,3,4,5,6
- - End Of File - - 71D2D584C6BED28DB902B107EE4009D6