Check af logs
Kan ikke inst. Wlsetup-web ...Får at vide, det IKKE er et gyldigt Win32-program.
Styresystem XP.
***************************************************************
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8302
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04-12-2011 12:11:37
mbam-log-2011-12-04 (12-11-37).txt
Skanningstype: Fuldstændig skanning (C:\|)
Objekter skannet: 222993
Tid gået: 2 time(e), 24 minut(ter), 38 sekund(er)
Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 1
Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)
Inficerede Mapper:
(Ingen skadelige objekter blev fundet)
Inficerede Filer:
c:\documents and settings\Yez\skrivebord\start up run.exe (PUP.StartUpManager) -> Quarantined and deleted successfully.
****************************************************************
ComboFix 11-12-04.04 - Yez 04-12-2011 23:29:28.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.1023.649 [GMT 1:00]
Kører fra: c:\documents and settings\Yez\Skrivebord\Combofix\ComboFix.exe
Kommandoer benyttet :: c:\documents and settings\Yez\Skrivebord\Combofix\CFScript.txt
.
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\compat.ini
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\Yez\WINDOWS
c:\windows\IsUn0406.exe
c:\windows\unin0406.exe
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-11-04 til 2011-12-04 )))))))))))))))))))))))))))))))))))
.
.
2011-12-04 22:20 . 2011-12-04 22:20 -------- d-sh--w- c:\documents and settings\Yez\IECompatCache
2011-12-04 01:54 . 2011-12-04 01:54 388096 ----a-r- c:\documents and settings\Yez\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-04 01:46 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-04 01:46 . 2011-12-04 01:46 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-12-01 00:11 . 2011-12-01 00:11 -------- d-sh--w- c:\documents and settings\Yez\PrivacIE
2011-12-01 00:08 . 2011-12-01 00:08 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-12-01 00:07 . 2011-12-01 00:07 -------- d-sh--w- c:\documents and settings\Yez\IETldCache
2011-11-30 23:51 . 2011-11-30 23:57 -------- dc-h--w- c:\windows\ie8
2011-11-30 23:43 . 2011-11-30 23:43 -------- d-----w- c:\programmer\Fælles filer\Windows Live
2011-11-30 23:39 . 2011-12-01 00:26 -------- d-----w- c:\programmer\Microsoft Silverlight
2011-11-30 23:30 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-11-30 23:29 . 2011-08-22 23:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-11-30 23:29 . 2011-08-22 23:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-30 23:29 . 2011-08-22 23:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-22 00:26 . 2011-11-22 00:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2011-11-22 00:26 . 2011-11-22 00:26 -------- d-----w- c:\windows\system32\drivers\NSS
2011-11-22 00:26 . 2011-11-22 00:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2011-11-09 23:54 . 2011-11-22 00:33 -------- d-----w- c:\programmer\TimeTool
2011-11-09 18:25 . 2011-11-09 18:25 -------- d-----w- c:\documents and settings\Yez\Application Data\AVG
2011-11-08 23:45 . 2011-11-08 23:45 -------- d-----w- c:\programmer\Trend Micro
2011-11-08 22:46 . 2011-11-08 22:46 -------- d-----w- c:\programmer\VS Revo Group
2011-11-08 22:45 . 2011-11-08 22:45 -------- d-----w- c:\documents and settings\Yez\Application Data\Malwarebytes
2011-11-08 22:44 . 2011-11-08 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-07 15:42 . 2011-12-04 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2011-11-07 15:42 . 2011-12-04 22:13 -------- d-----w- c:\windows\system32\drivers\AVG
2011-11-07 15:24 . 2011-12-04 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-11-05 12:45 . 2011-11-05 12:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2011-11-05 12:45 . 2011-11-05 12:45 -------- d-----w- c:\documents and settings\Yez\Application Data\Canneverbe Limited
2011-11-05 12:44 . 2009-11-12 13:48 5504 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2011-11-05 12:44 . 2011-11-05 12:44 -------- d-----w- c:\programmer\CDBurnerXP
2011-11-05 12:22 . 2011-11-16 23:31 -------- d-----w- c:\programmer\Defraggler
2011-11-05 12:18 . 2011-11-05 12:18 -------- d-----w- c:\documents and settings\Yez\Application Data\FastStone
2011-11-05 12:18 . 2011-11-05 12:18 -------- d-----w- c:\programmer\FastStone Image Viewer
2011-11-05 12:15 . 2011-11-24 23:54 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-05 03:37 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-11-05 03:36 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-11-05 03:34 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-11-05 03:25 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-11-05 03:25 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-11-05 03:23 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-11-05 03:23 . 2011-02-08 13:33 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-11-05 03:22 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-11-05 01:26 . 2011-11-05 01:26 -------- d-----w- c:\windows\l2schemas
2011-11-05 01:26 . 2011-11-05 01:26 -------- d-----w- c:\windows\system32\da
2011-11-05 01:26 . 2011-11-05 01:26 -------- d-----w- c:\windows\system32\bits
2011-11-04 23:57 . 2011-11-04 23:57 -------- d-----w- c:\programmer\CCleaner
2011-11-04 22:54 . 2011-11-04 22:54 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-30 20:43 . 2011-10-30 20:43 1409 ----a-w- c:\windows\QTFont.for
2011-10-10 14:22 . 2007-03-24 16:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-06-21 12:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2009-06-24 05:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2002-09-16 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2002-09-16 12:00 21504 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 2002-09-16 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10 . 2002-09-16 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\programmer\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\All Users\Menuen Start\Programmer\Start\~Disabled
Adobe Gamma Loader.lnk - c:\programmer\Fælles filer\Adobe\Calibration\Adobe Gamma Loader.exe [2010-4-9 113664]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Dokumenter\\Insane - Unzipped\\Game.exe"=
"c:\\Programmer\\DNA\\btdna.exe"=
"c:\\Documents and Settings\\Yez\\Dokumenter\\Downloads\\Battlefield.1942.PC.Game(djDEVASTATE™)\\Battlefield.1942.PC.Game(djDEVASTATE™)\\Battlefield.1942.PC.Game(djDEVASTATE™)\\BF1942.exe"=
"c:\\Programmer\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Programmer\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57888:TCP"= 57888:TCP:Pando Media Booster
"57888:UDP"= 57888:UDP:Pando Media Booster
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25-07-2010 19:49 691696]
R2 MBAMService;MBAMService;c:\programmer\Malwarebytes' Anti-Malware\mbamservice.exe [04-12-2011 02:46 366152]
R2 WUSB54GSVC;WUSB54GSVC;c:\programmer\WUSB54G Wireless-G Adapter\WLService.exe [08-02-2010 19:36 41027]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [04-12-2011 02:46 22216]
S2 gupdate;Tjenesten Google Update (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [08-03-2010 14:56 135664]
S2 nvtvSND;nVidia WDM TVAudio Crossbar;c:\windows\system32\DRIVERS\nvtvsnd.sys --> c:\windows\system32\DRIVERS\nvtvsnd.sys [?]
S3 gupdatem;Google Update Tjeneste (gupdatem);c:\programmer\Google\Update\GoogleUpdate.exe [08-03-2010 14:56 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rt70x86;%WUSB54Gv4.Service.DispName%;c:\windows\system32\drivers\netr70.sys [29-12-2006 02:01 243200]
S4 Msfvsc0pi;Msfvsc0pi; [x]
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-03-08 13:55]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2010-03-08 13:55]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1708537768-854245398-1003Core.job
- c:\documents and settings\Yez\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-06-10 13:12]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1708537768-854245398-1003UA.job
- c:\documents and settings\Yez\Lokale indstillinger\Application Data\Google\Update\GoogleUpdate.exe [2009-06-10 13:12]
.
2011-12-04 c:\windows\Tasks\User_Feed_Synchronization-{26C29320-1185-4D7C-BD6A-27962136AADE}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Yderligere scanning -------
.
uStart Page = hxxp://www.google.dk/
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJ&fl=0&ptb=JO_nlfZBva29ur2HIlZCZQ&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki ... - c:\programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{C066AE65-373D-4384-86F0-5A2797A4E4FE}: NameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - TOMME GENVEJE FJERNET - - - -
.
HKLM-Run-NvCplDaemon - :RUNDLL32.EXE
HKLM-Run-nwiz - :nwiz.exe
HKLM-Run-NvMediaCenter - :RUNDLL32.EXE
HKLM-Run-QuickTime Task - :c:\programmer\QuickTime\qttask.exe
HKLM-Run-amd_dc_opt - :c:\programmer\AMD\Dual-Core Optimizer\amd_dc_opt.exe
HKLM-Run-SunJavaUpdateSched - :c:\programmer\Fælles filer\Java\Java Update\jusched.exe
HKLM-Run-Adobe Reader Speed Launcher - :c:\programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-Adobe ARM - :c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe
Notify-AtiExtEvent - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 23:44
Windows 5.1.2600 Service Pack 3 NTFS
.
scanner skjulte processer ...
.
scanner skjulte autostarter ...
.
scanner skjulte filer ...
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-1004336348-1708537768-854245398-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:9a,9b,ca,5c,bd,1e,9a,b0,62,5e,0e,0f,dc,64,14,91,d1,a2,22,31,91,2d,95,
2a,f6,46,29,e6,08,ab,ca,76,58,5e,d7,28,ac,6e,53,c5,b7,ce,02,a1,7c,e1,c3,f1,\
"??"=hex:92,5f,c0,34,3e,60,eb,63,e2,21,dd,2d,e2,48,32,12
.
[HKEY_USERS\S-1-5-21-1004336348-1708537768-854245398-1003\Software\SecuROM\License information*]
"datasecu"=hex:45,87,7f,08,c7,dd,ea,1f,15,42,7e,ba,5c,c3,47,7e,2c,f3,df,7b,29,
14,b9,bd,e3,9c,34,a4,6a,a1,5f,83,4d,45,b9,b5,76,35,ce,f8,28,8c,80,fc,ba,e6,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs startet under kørende Processer ---------------------
.
- - - - - - - > 'explorer.exe'(444)
c:\windows\system32\webcheck.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\nvsvc32.exe
c:\programmer\WUSB54G Wireless-G Adapter\WUSB54G.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Gennemført tid: 2011-12-04 23:53:58 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-12-04 22:53
.
Pre-Kørsel: 55.624.663.040 byte ledig
Post-Kørsel: 55.615.877.120 byte ledig
.
- - End Of File - - 379BBF6DEC92F4916DC1887124DF3EEC
*****************************************************************
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:29:10, on 05-12-2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Programmer\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Programmer\AVG\AVG2012\avgtray.exe
C:\Programmer\AVG\AVG2012\avgfws.exe
C:\Programmer\AVG\AVG2012\avgwdsvc.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\Programmer\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Programmer\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WUSB54G Wireless-G Adapter\WLService.exe
C:\Programmer\WUSB54G Wireless-G Adapter\WUSB54G.exe
C:\Programmer\AVG\AVG2012\AVGIDSAgent.exe
C:\Programmer\AVG\AVG2012\avgnsx.exe
C:\Programmer\AVG\AVG2012\avgemcx.exe
C:\Programmer\AVG\AVG2012\avgcsrvx.exe
C:\Programmer\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG2012\avgssie.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Programmer\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Programmer\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\FLLESF~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ~Disabled
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/da/uno1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C066AE65-373D-4384-86F0-5A2797A4E4FE}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG2012\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Programmer\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Programmer\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Programmer\CDBurnerXP\NMSAccessU.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54GSVC - GEMTEKS - C:\Programmer\WUSB54G Wireless-G Adapter\WLService.exe
--
End of file - 6272 bytes