nå det var mærkeligt, når jeg startede c-fix skrev den for det første at jeg skulle lukke MWB og Avast, hvilket så knap nok kunne lade sig gøre da jeg havde afsluttet MWB og umiddelbart skulle Avast ikke køre.
Jeg gik ind i processeer og fik lukket nogle ting.
Derefter skrev c-fix så at WindowsGgenoprettelses Consol ikke var installeret, hvilket undrer mig da jeg ikke har fjernet den( basis del af Windows)
kunne så ikke hente den da c-fix ikke kunne finde linket så WGC kunne blive installeret.
c-fix log:
ComboFix 11-08-27.01 - Kim 28-08-2011 15:32:29.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.2047.1394 [GMT 2:00]
Kører fra: c:\documents and settings\Kim\Skrivebord\banan.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Kim\Application Data\EurekaLog
c:\documents and settings\Kim\Application Data\EurekaLog\EurekaLog.ini
c:\documents and settings\Kim\Application Data\InstallProxy.exe
c:\documents and settings\Kim\WINDOWS
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\ehome\medctrro.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-07-28 til 2011-08-28 )))))))))))))))))))))))))))))))))))
.
.
2011-08-28 13:48 . 2011-08-28 13:48 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{304F2781-07DB-4768-BA37-AEB13C2E7385}\MpKsldbac84d3.sys
2011-08-27 09:25 . 2011-08-12 02:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{304F2781-07DB-4768-BA37-AEB13C2E7385}\mpengine.dll
2011-08-25 14:40 . 2011-08-25 14:40 -------- d-----w- c:\programmer\iPod
2011-08-25 14:40 . 2011-08-25 14:41 -------- d-----w- c:\programmer\iTunes
2011-08-20 18:03 . 2011-08-20 18:24 -------- d-----w- c:\documents and settings\Kim\Lokale indstillinger\Application Data\MediaGet2
2011-08-15 18:56 . 2011-08-15 18:56 -------- d-----w- c:\programmer\Market Samurai
2011-08-12 12:44 . 2011-08-15 06:16 -------- d-----w- c:\documents and settings\Kim\.mobione
2011-08-12 12:43 . 2011-08-12 12:44 -------- d-----w- c:\programmer\MobiOne Studio
2011-08-10 08:56 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-10 06:54 . 2011-08-10 06:54 -------- d-----w- c:\programmer\Youtube Downloader HD
2011-08-10 06:52 . 2011-08-10 06:52 -------- d-----w- c:\documents and settings\All Users\Application Data\YouTube Downloader
2011-08-10 06:52 . 2011-08-10 06:52 -------- d-----w- c:\programmer\YouTube Downloader
2011-08-03 15:19 . 2011-08-03 15:47 -------- d-----w- c:\windows\system32\NtmsData
2011-08-02 14:45 . 2011-08-10 07:02 -------- d-----w- c:\documents and settings\Kim\Application Data\Youtube Downloader HD
2011-08-02 14:29 . 2011-08-02 14:36 -------- d-----w- c:\documents and settings\Kim\Application Data\xVideoServiceThief
2011-08-02 14:28 . 2011-08-02 14:28 -------- d-----w- c:\programmer\Xesc & Technology
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-23 03:45 . 2011-05-18 05:45 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-12 02:44 . 2010-03-14 09:50 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-27 19:01 . 2011-07-27 19:01 3584 ----a-r- c:\documents and settings\Kim\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2011-07-15 13:29 . 2004-08-03 21:15 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-13 03:39 . 2011-07-27 17:39 6881616 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-08 14:02 . 2001-10-09 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 17:52 . 2010-04-17 10:56 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 17:52 . 2010-04-17 10:55 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-05 16:37 . 2011-07-05 16:37 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 16:37 . 2011-07-05 16:37 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-06-24 14:10 . 2002-01-01 23:09 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2004-08-26 15:53 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2004-08-26 15:53 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 18:31 . 2004-08-26 15:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 12:05 . 2004-08-26 15:48 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2004-08-26 15:53 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2004-08-26 15:49 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-22 12:16 . 2011-03-26 19:04 142296 ----a-w- c:\programmer\mozilla firefox\components\browsercomps.dll
2010-04-17 15:39 . 2010-04-17 15:38 119808 ----a-w- c:\programmer\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\programmer\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kim\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kim\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kim\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Kim\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\programmer\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-06-09 107000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-17 17508864]
"LogitechQuickCamRibbon"="c:\programmer\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]
"sfagent"="c:\programmer\Fighters\sfagent.exe" [2010-10-21 760968]
"nwiz"="c:\programmer\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\programmer\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^HP Digital Imaging Monitor.lnk]
backupExtension=.CommonStartup
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Kim^Menuen Start^Programmer^Start^Dropbox.lnk]
backup=c:\windows\pss\Dropbox.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-09-22 16:11 640440 ----a-w- c:\programmer\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-06-07 18:54 40376 ----a-w- c:\programmer\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-29 19:59 937920 ----a-w- c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 ----a-w- c:\programmer\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 05:58 611712 ----a-w- c:\programmer\Fælles filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0ENQBO]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-phishing Domain Advisor]
2011-01-31 22:29 232104 ----a-w- c:\documents and settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 16:05 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
2007-02-25 23:01 437160 ----a-w- c:\progra~1\FLLESF~1\MICROS~1\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-04-17 15:39 30192 ----a-w- c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-07-15 16:15 133104 ----atw- c:\documents and settings\Kim\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 16:17 1289000 ----a-w- c:\programmer\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\programmer\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-07 17:58 13880424 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-07 17:58 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 16:36 421888 ----a-w- c:\programmer\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-03-31 12:30 39408 ----a-w- c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
2005-07-15 21:48 479232 ----a-w- c:\programmer\Google\Gmail Notifier\gnotify.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Fælles filer\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programmer\\Fælles filer\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\programmer\Microsoft ActiveSync\rapimgr.exe"= c:\programmer\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\programmer\Microsoft ActiveSync\wcescomm.exe"= c:\programmer\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\programmer\Microsoft ActiveSync\WCESMgr.exe"= c:\programmer\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\server\\xampp\\MercuryMail\\mercury.exe"=
"c:\\Programmer\\Java\\jre6\\bin\\java.exe"=
"c:\\Programmer\\Adobe\\Adobe Dreamweaver CS4\\Dreamweaver.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Programmer\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Programmer\\Adobe\\Adobe Flash CS4\\Flash.exe"=
"c:\\Documents and Settings\\Kim\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programmer\\StreamTorrent NE 1.0\\StreamTorrent.exe"=
"c:\\Programmer\\GlobalSCAPE\\CuteFTP 8 Home\\ftpte.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\Skype\\Phone\\Skype.exe"=
"c:\\Programmer\\MobiOne Studio\\MobiOne 1.2.2\\mobione.exe"=
"c:\\Programmer\\Fælles filer\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [26-06-2010 12:05 28552]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16-06-2011 05:29 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [02-06-2009 18:43 307928]
R1 MpKsldbac84d3;MpKsldbac84d3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{304F2781-07DB-4768-BA37-AEB13C2E7385}\MpKsldbac84d3.sys [28-08-2011 15:48 28752]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [02-06-2009 18:43 19544]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [29-03-2011 19:59 22504]
R2 MBAMService;MBAMService;c:\programmer\Malwarebytes' Anti-Malware\mbamservice.exe [17-04-2010 12:56 366640]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\programmer\Fighters\sfus.exe service --> c:\programmer\Fighters\sfus.exe service [?]
R2 Suite Service;Suite Service;c:\programmer\Fighters\FighterSuiteService.exe [21-10-2010 14:44 1130120]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [02-06-2009 18:38 36864]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [17-04-2010 12:55 22712]
S1 MpKslce552f31;MpKslce552f31;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDBB1BC-895B-440D-8DA5-032344033BF2}\MpKslce552f31.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CFDBB1BC-895B-440D-8DA5-032344033BF2}\MpKslce552f31.sys [?]
S1 MpKslf41d76fe;MpKslf41d76fe;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{703A2FA9-B550-4FCA-818B-BACFB29EEF78}\MpKslf41d76fe.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{703A2FA9-B550-4FCA-818B-BACFB29EEF78}\MpKslf41d76fe.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18-03-2010 13:16 130384]
S2 gupdate;Google Update Service (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [03-02-2010 14:17 135664]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\programmer\Fælles filer\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15-08-2008 05:46 284016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys [05-06-2009 11:45 1684736]
S3 DCamUSBOvt;AVerMedia InterCam-Elite;c:\windows\system32\drivers\elitecam.sys [04-08-2009 17:54 156484]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\programmer\Google\Google Desktop Search\GoogleDesktop.exe [17-04-2010 17:38 30192]
S3 gupdatem;Google Update Tjeneste (gupdatem);c:\programmer\Google\Update\GoogleUpdate.exe [03-02-2010 14:17 135664]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys --> c:\windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [17-04-2010 12:56 41272]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [27-07-2011 19:28 42496]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18-03-2010 13:16 753504]
S4 Apache2.2;Apache2.2;c:\server\xampp\apache\bin\httpd.exe [17-11-2009 12:07 24640]
.
--- Andre Services/Drivers i Hukommelsen ---
.
*NewlyCreated* - MPKSLDBAC84D3
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-02-03 12:17]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-02-03 12:17]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-179605362-839522115-1003Core1cb6cf4728cac8.job
- c:\documents and settings\Kim\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 16:15]
.
2011-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-179605362-839522115-1003UA.job
- c:\documents and settings\Kim\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 16:15]
.
2011-08-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Yderligere scanning -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = http=;ftp=;https=;
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Gem formularer -
file://c:\programmer\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: RF værktøjslinie -
file://c:\programmer\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Sothink SWF Catcher - c:\programmer\Fælles filer\SourceTec\SWF Catcher\InternetExplorer.htm
IE: Tilpas RF menu -
file://c:\programmer\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Udfyld formularer -
file://c:\programmer\Siber Systems\AI RoboForm\RoboFormComFillForms.html
Trusted Zone: twitter.com
FF - ProfilePath - c:\documents and settings\Kim\Application Data\Mozilla\Firefox\Profiles\db4c564s.default\
FF - prefs.js: browser.search.selectedEngine - Web Search (powered by Google)
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL -
hxxp://search.toolbars.alexa.com/?ver=alxf-2.14&src=ab&aid=EbV3c1mhjd00GV&q=FF - prefs.js: network.proxy.type - 4
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - TOMME GENVEJE FJERNET - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-vProt - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-08-28 15:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanner skjulte processer ...
.
scanner skjulte autostarter ...
.
scanner skjulte filer ...
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
.
- - - - - - - > 'explorer.exe'(5700)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\msi.dll
c:\documents and settings\Kim\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\programmer\Fælles filer\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\programmer\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\programmer\Fighters\sfus.exe
c:\windows\RTHDCPL.EXE
c:\programmer\Fælles filer\Logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\msiexec.exe
c:\programmer\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
**************************************************************************
.
Gennemført tid: 2011-08-28 15:57:51 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-08-28 13:57
ComboFix2.txt 2010-04-19 16:04
.
Pre-Kørsel: 310.071.009.280 byte ledig
Post-Kørsel: 310.239.715.328 byte ledig
.
- - End Of File - - 241F246EC7CD769DC72DFCCE179F4732