DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by SharkGaming at 14:40:41 on 2012-06-07
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
mWinlogon: Userinit=userinit.exe,
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBitT.dll
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\SHARKG~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
LSP: mswsock.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cabTCP: DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{6834E65A-7F9F-4DD9-99C8-554CBD1F3C1B} : DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{B51D99C5-4F50-4A03-AD8F-988476EB2453} : DhcpNameServer = 193.162.153.164 194.239.134.83
TCP: Interfaces\{C79EE60E-ECE6-47FC-8C47-987D38951497} : DhcpNameServer = 193.162.153.164 194.239.134.83
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
mRun-x64: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\SharkGaming\AppData\Roaming\Mozilla\Firefox\Profiles\44xz14t6.default\
FF - prefs.js: keyword.URL -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\SharkGaming\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\SharkGaming\AppData\Roaming\Mozilla\Firefox\Profiles\44xz14t6.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\plugins\np-mswmp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-06-06 16:57:47 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62639E17-F023-4F5E-B1F6-E4DBFA58B608}\mpengine.dll
2012-06-06 14:12:26 770384 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-06 14:12:26 421200 ----a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-06 00:09:59 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-05 21:11:52 -------- d-----w- C:\Program Files (x86)\ESET
2012-06-02 23:51:54 -------- d-----w- C:\Users\SharkGaming\AppData\Roaming\Malwarebytes
2012-06-02 23:51:47 -------- d-----w- C:\ProgramData\Malwarebytes
2012-06-02 23:51:46 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-02 23:51:46 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-02 23:41:58 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2422CA51-F472-4A19-8EE0-0E637DFA145B}\gapaengine.dll
2012-06-02 23:39:50 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-06-02 23:39:48 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-05-31 00:50:09 -------- d-sh--w- C:\ProgramData\DSS
2012-05-30 09:34:02 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-05-30 09:33:58 -------- d-----w- C:\Users\SharkGaming\AppData\Roaming\DAEMON Tools Lite
2012-05-30 09:33:56 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
2012-05-30 09:32:02 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2012-05-29 18:23:17 -------- d-----w- C:\Users\SharkGaming\AppData\Local\Google
2012-05-29 18:23:17 -------- d-----w- C:\Users\SharkGaming\AppData\Local\CRE
2012-05-29 18:23:13 -------- d-----w- C:\Program Files (x86)\BitTorrentBar
2012-05-25 17:44:20 447752 ----a-w- C:\Windows\SysWow64\vp6vfw.dll
2012-05-25 17:44:14 -------- d-----w- C:\Program Files (x86)\Microsoft WSE
2012-05-22 17:26:21 -------- d-----w- C:\Users\SharkGaming\AppData\Roaming\Awesomium
2012-05-15 14:55:13 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2012-05-15 14:55:13 -------- d-----w- C:\Program Files (x86)\Diablo III
2012-05-15 14:42:34 -------- d-----w- C:\ProgramData\Battle.net
2012-05-15 10:11:57 -------- d-----w- C:\Users\SharkGaming\Diablo-III-8370-enGB-Installer
2012-05-14 19:39:41 -------- d-----w- C:\Users\SharkGaming\Incomplete
2012-05-11 16:12:07 -------- d-----w- C:\Program Files (x86)\Diablo II
2012-05-11 15:32:34 -------- d-----w- C:\Users\SharkGaming\D2LOD-1.12A-enGB
2012-05-11 13:59:53 -------- d-----w- C:\Users\SharkGaming\D2-1.12A-enGB
2012-05-11 13:59:48 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2012-05-09 12:23:03 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-05-09 12:23:03 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-05-09 12:23:01 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-09 12:23:01 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-05-09 12:23:00 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-09 12:23:00 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-09 12:22:42 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-05-09 12:22:31 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-05-09 12:22:30 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-05-09 12:22:30 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-05-09 12:22:30 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2012-05-09 12:22:30 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2012-05-09 12:22:30 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-05-08 20:52:24 -------- d-----w- C:\Program Files (x86)\AMD
2012-05-08 20:52:23 -------- d-----w- C:\Users\SharkGaming\AppData\Local\Downloaded Installations
2012-05-08 20:50:31 -------- d-----w- C:\Windows\SysWow64\xlive
2012-05-08 20:50:27 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2012-05-08 12:43:10 -------- d-----w- C:\Users\SharkGaming\AppData\Roaming\.minecraft
.
==================== Find3M ====================
.
2012-06-06 14:48:02 283416 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-06-06 14:48:02 283416 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-06-05 20:32:15 283416 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-06-04 17:50:20 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2012-05-05 12:35:56 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 12:35:56 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 12:35:47 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-03-20 18:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 18:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
.
============= FINISH: 14:40:59,38 ===============
Attatch.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe AIR
APB Reloaded
Batman: Arkham City™
BitTorrent
BitTorrentBar Toolbar
Borderlands
Brawl Busters
Champions Online: Free For All
Counter-Strike: Condition Zero
DAEMON Tools Lite
Dead Island
Deus Ex: Human Revolution
Diablo II
Diablo III
Dual-Core Optimizer
Dungeons & Dragons Online ®: Eberron Unlimited ™ v01.17.01.801
EA Installer
EA Shared Game Component: Activation
ERUNT 1.1j
ESET Online Scanner v3
Forsaken World
Grand Theft Auto III
Intel(R) Management Engine Components
Java Auto Updater
Java(TM) 6 Update 29
JMicron JMB36X Driver
Kingdoms of Amalur: Reckoning Demo
League of Legends
Left 4 Dead 2
Malwarebytes Anti-Malware version 1.61.0.1400
marvell 91xx driver
Mass Effect
Mass Effect 2
Mass Effect™ 3
Microsoft .NET Framework 1.1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 4.0
Mount & Blade: Warband
Mozilla Firefox 13.0 (x86 da)
Mozilla Maintenance Service
MP3 Rocket
NETGEAR WNDA3100v2 wireless USB 2.0 adapter
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
Origin
Pando Media Booster
PunkBuster Services
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Renesas Electronics USB 3.0 Host Controller Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Skype™ 5.8
Steam
System Requirements Lab CYRI
Terraria
The Battle for Middle-earth (tm) II
The Lord of the Rings, The Rise of the Witch-king
The Sims Medieval
The Sims™ 3
The Sims™ 3 Verdenseventyr
The Witcher 2
Unity Web Player
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VC80CRTRedist - 8.0.50727.6195
Windows Media Player Firefox Plugin
.
==== End Of File ===========================
08. juni 2012 - 16:47
#19
ComboFix 12-06-08.01 - SharkGaming 08-06-2012 15:58:31.1.8 - x64
Kører fra: c:\users\SharkGaming\Desktop\ComboFix.exe
* Dannede nyt systemgendannelsespunkt
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-05-08 til 2012-06-08 )))))))))))))))))))))))))))))))))))
.
.
2012-06-08 14:01 . 2012-06-08 14:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-08 14:01 . 2012-06-08 14:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-07 22:19 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E428FCA6-EF40-497B-B5DE-625B2D29358D}\mpengine.dll
2012-06-07 22:18 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-06 19:59 . 2012-06-06 19:59 -------- d-----w- c:\program files (x86)\ERUNT
2012-06-06 14:12 . 2012-06-06 14:12 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-06 14:12 . 2012-06-06 14:12 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-05 21:11 . 2012-06-05 21:11 -------- d-----w- c:\program files (x86)\ESET
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\programdata\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-02 23:51 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 23:41 . 2012-06-02 23:41 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2422CA51-F472-4A19-8EE0-0E637DFA145B}\gapaengine.dll
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files\Microsoft Security Client
2012-05-31 00:50 . 2012-05-31 00:50 -------- d-sh--w- c:\programdata\DSS
2012-05-30 09:34 . 2012-05-30 09:34 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-30 09:33 . 2012-05-30 09:39 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\DAEMON Tools Lite
2012-05-30 09:33 . 2012-05-30 09:34 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-05-30 09:32 . 2012-05-30 09:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\Google
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\CRE
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\program files (x86)\BitTorrentBar
2012-05-25 17:44 . 2012-05-30 23:20 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2012-05-25 17:44 . 2012-05-25 17:44 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-05-22 17:26 . 2012-05-22 18:08 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Awesomium
2012-05-15 14:55 . 2012-05-15 15:04 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-05-15 14:42 . 2012-05-15 14:42 -------- d-----w- c:\programdata\Battle.net
2012-05-15 10:11 . 2012-05-15 14:43 -------- d-----w- c:\users\SharkGaming\Diablo-III-8370-enGB-Installer
2012-05-14 19:39 . 2012-06-07 17:55 -------- d-----w- c:\users\SharkGaming\Incomplete
2012-05-11 16:12 . 2012-05-15 10:12 -------- d-----w- c:\program files (x86)\Diablo II
2012-05-11 15:32 . 2012-05-11 15:59 -------- d-----w- c:\users\SharkGaming\D2LOD-1.12A-enGB
2012-05-11 13:59 . 2012-05-11 15:30 -------- d-----w- c:\users\SharkGaming\D2-1.12A-enGB
2012-05-11 13:59 . 2012-05-15 15:04 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-06 14:48 . 2012-02-18 20:45 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-06-06 14:48 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-06-05 20:32 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-06-04 17:50 . 2012-02-18 20:42 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-05-08 20:55 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-05-08 20:55 . 2009-08-18 09:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-05 12:35 . 2012-04-16 12:11 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 12:35 . 2012-01-20 00:31 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 12:35 . 2012-04-16 12:35 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-03-31 06:05 . 2012-05-09 12:23 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-09 12:23 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-09 12:23 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-09 12:23 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-09 12:22 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 18:44 . 2012-03-20 18:44 98688 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2012-03-20 18:44 203888 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-17 07:58 . 2012-05-09 12:22 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\BitTorrentBar\prxtbBitT.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2012-01-20 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\users\SharkGaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-1-20 4577760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 badmghpp;badmghpp;c:\windows\system32\drivers\badmghpp.sys [x]
R1 cqbvreew;cqbvreew;c:\windows\system32\drivers\cqbvreew.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R2 WSWNDA3100;WSWNDA3100;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2010-08-19 272864]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-06 113120]
R3 MSICDSetup;MSICDSetup;D:\CDriver64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Netværksinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 X6va005;X6va005;c:\users\SHARKG~1\AppData\Local\Temp\005CB.tmp [x]
R3 X6va006;X6va006;c:\users\SHARKG~1\AppData\Local\Temp\0067FAC.tmp [x]
R3 X6va008;X6va008;c:\users\SHARKG~1\AppData\Local\Temp\008B3F.tmp [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
--- Andre Services/Drivers i Hukommelsen ---
.
*NewlyCreated* - IPNAT
*NewlyCreated* - WS2IFSL
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 12:35]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-01-04 6602856]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"combofix"="c:\combofix\CF26763.3XE" [2010-11-21 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 193.162.153.164 194.239.134.83
FF - ProfilePath - c:\users\SharkGaming\AppData\Roaming\Mozilla\Firefox\Profiles\44xz14t6.default\
FF - prefs.js: keyword.URL -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=.
- - - - TOMME GENVEJE FJERNET - - - -
.
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
AddRemove-{B931FB80-537A-4600-00AD-AC5DEDB6C25B} - c:\program files (x86)\Electronic Arts\The Lord of the Rings
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\SHARKG~1\AppData\Local\Temp\005CB.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va006]
"ImagePath"="\??\c:\users\SHARKG~1\AppData\Local\Temp\0067FAC.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va008]
"ImagePath"="\??\c:\users\SHARKG~1\AppData\Local\Temp\008B3F.tmp"
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-3696142184-1702543921-4226803488-1000\Software\SecuROM\License information*]
"datasecu"=hex:1c,f8,6f,62,ff,c6,f6,c2,69,f5,dd,92,83,ec,85,0b,b2,ac,92,c2,84,
18,df,6f,3d,93,1e,19,e3,e8,eb,05,ba,ad,e0,21,a0,a5,e4,63,7f,90,83,de,47,22,\
"rkeysecu"=hex:fc,73,1d,9f,82,cf,76,8b,1f,16,88,e0,c2,87,65,f7
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Gennemført tid: 2012-06-08 16:07:08 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-06-08 14:07
.
Pre-Kørsel: 250.080.923.648 byte ledig
Post-Kørsel: 251.138.170.880 byte ledig
.
- - End Of File - - 4AC937EE1A52CB1D357F9C450C4EDB11
_______
Da den var færdig, havde den yderligere åbnet 2 logs "DDS" & "Attach" vil du også have de logs?
08. juni 2012 - 21:39
#21
ComboFix 12-06-08.02 - SharkGaming 08-06-2012 21:27:07.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.8160.6873 [GMT 2:00]
Kører fra: c:\users\SharkGaming\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\SharkGaming\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\SHARKG~1\AppData\Local\Temp\005CB.tmp"
"c:\users\SHARKG~1\AppData\Local\Temp\0067FAC.tmp"
"c:\users\SHARKG~1\AppData\Local\Temp\008B3F.tmp"
"c:\users\SharkGaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk"
"c:\windows\system32\drivers\badmghpp.sys"
"c:\windows\system32\drivers\cqbvreew.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\BitTorrentBar
c:\program files (x86)\BitTorrentBar\BitTorrentBarToolbarHelper.exe
c:\program files (x86)\BitTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\ldrtbBitT.dll
c:\program files (x86)\BitTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\prxtbBitT.dll
c:\program files (x86)\BitTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\tbBitT.dll
c:\program files (x86)\BitTorrentBar\toolbar.cfg
c:\program files (x86)\BitTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\BitTorrentBar\uninstall.exe
c:\users\SharkGaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MSICDSETUP
-------\Legacy_X6VA005
-------\Legacy_X6VA006
-------\Legacy_X6VA008
-------\Service_badmghpp
-------\Service_cqbvreew
-------\Service_MSICDSetup
-------\Service_X6va005
-------\Service_X6va006
-------\Service_X6va008
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-05-08 til 2012-06-08 )))))))))))))))))))))))))))))))))))
.
.
2012-06-08 19:31 . 2012-06-08 19:31 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-08 19:31 . 2012-06-08 19:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-08 16:46 . 2012-06-08 16:46 -------- d-----w- c:\programdata\Battle.net
2012-06-08 15:30 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4DB37226-649B-4A8D-8B0B-B8502EAE11A8}\mpengine.dll
2012-06-07 22:18 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-06 19:59 . 2012-06-06 19:59 -------- d-----w- c:\program files (x86)\ERUNT
2012-06-06 14:12 . 2012-06-06 14:12 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-06 14:12 . 2012-06-06 14:12 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-05 21:11 . 2012-06-05 21:11 -------- d-----w- c:\program files (x86)\ESET
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\programdata\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-02 23:51 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 23:41 . 2012-06-02 23:41 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2422CA51-F472-4A19-8EE0-0E637DFA145B}\gapaengine.dll
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files\Microsoft Security Client
2012-05-31 00:50 . 2012-05-31 00:50 -------- d-sh--w- c:\programdata\DSS
2012-05-30 09:34 . 2012-05-30 09:34 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-30 09:33 . 2012-05-30 09:39 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\DAEMON Tools Lite
2012-05-30 09:33 . 2012-05-30 09:34 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-05-30 09:32 . 2012-05-30 09:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\Google
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\CRE
2012-05-25 17:44 . 2012-05-30 23:20 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2012-05-25 17:44 . 2012-05-25 17:44 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-05-22 17:26 . 2012-05-22 18:08 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Awesomium
2012-05-15 14:55 . 2012-06-08 17:00 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-05-14 19:39 . 2012-06-08 16:49 -------- d-----w- c:\users\SharkGaming\Incomplete
2012-05-11 16:12 . 2012-05-15 10:12 -------- d-----w- c:\program files (x86)\Diablo II
2012-05-11 15:32 . 2012-05-11 15:59 -------- d-----w- c:\users\SharkGaming\D2LOD-1.12A-enGB
2012-05-11 13:59 . 2012-05-11 15:30 -------- d-----w- c:\users\SharkGaming\D2-1.12A-enGB
2012-05-11 13:59 . 2012-06-08 17:00 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-06 14:48 . 2012-02-18 20:45 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-06-06 14:48 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-06-05 20:32 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-06-04 17:50 . 2012-02-18 20:42 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-05-08 20:55 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-05-08 20:55 . 2009-08-18 09:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-05 12:35 . 2012-04-16 12:11 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 12:35 . 2012-01-20 00:31 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 12:35 . 2012-04-16 12:35 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-03-31 06:05 . 2012-05-09 12:23 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-09 12:23 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-09 12:23 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-09 12:23 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-09 12:22 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 18:44 . 2012-03-20 18:44 98688 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2012-03-20 18:44 203888 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-17 07:58 . 2012-05-09 12:22 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-08_14.03.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2012-06-08 16:13 34156 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-01-19 19:30 . 2012-06-08 16:13 9718 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3696142184-1702543921-4226803488-1000_UserData.bin
- 2012-06-08 14:03 . 2012-06-08 14:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-08 19:32 . 2012-06-08 19:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-08 14:03 . 2012-06-08 14:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-08 19:32 . 2012-06-08 19:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2012-06-02 23:39 662980 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-06-08 16:16 662980 c:\windows\system32\perfh009.dat
- 2010-11-21 08:43 . 2012-06-02 23:39 517990 c:\windows\system32\perfh006.dat
+ 2010-11-21 08:43 . 2012-06-08 16:16 517990 c:\windows\system32\perfh006.dat
+ 2009-07-14 02:36 . 2012-06-08 16:16 126070 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-06-02 23:39 126070 c:\windows\system32\perfc009.dat
- 2010-11-21 08:43 . 2012-06-02 23:39 103408 c:\windows\system32\perfc006.dat
+ 2010-11-21 08:43 . 2012-06-08 16:16 103408 c:\windows\system32\perfc006.dat
- 2009-07-14 05:01 . 2012-06-08 14:02 228720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-06-08 19:31 228720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-01-19 22:58 . 2012-06-08 19:31 27661316 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3696142184-1702543921-4226803488-1000-12288.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2012-01-20 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-1-20 4577760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R2 WSWNDA3100;WSWNDA3100;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2010-08-19 272864]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-06 113120]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Netværksinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 12:35]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-01-04 6602856]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"combofix"="c:\combofix\CF25504.3XE" [2010-11-21 345088]
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 193.162.153.164 194.239.134.83
FF - ProfilePath - c:\users\SharkGaming\AppData\Roaming\Mozilla\Firefox\Profiles\44xz14t6.default\
FF - prefs.js: keyword.URL -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=.
- - - - TOMME GENVEJE FJERNET - - - -
.
AddRemove-BitTorrentBar Toolbar - c:\program files (x86)\BitTorrentBar\uninstall.exe
.
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-3696142184-1702543921-4226803488-1000\Software\SecuROM\License information*]
"datasecu"=hex:1c,f8,6f,62,ff,c6,f6,c2,69,f5,dd,92,83,ec,85,0b,b2,ac,92,c2,84,
18,df,6f,3d,93,1e,19,e3,e8,eb,05,ba,ad,e0,21,a0,a5,e4,63,7f,90,83,de,47,22,\
"rkeysecu"=hex:fc,73,1d,9f,82,cf,76,8b,1f,16,88,e0,c2,87,65,f7
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Gennemført tid: 2012-06-08 21:36:10 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-06-08 19:36
ComboFix2.txt 2012-06-08 14:07
.
Pre-Kørsel: 259.253.043.200 byte ledig
Post-Kørsel: 258.940.944.384 byte ledig
.
- - End Of File - - 914F78B1609A7AEEE34BEF3E56E9D05B
______
Den startede med at brokke sig over at mit Antivirus ikke var slået fra - selvom det var, det er jeg i hvert fald ret sikker på.
08. juni 2012 - 22:17
#23
ComboFix 12-06-08.02 - SharkGaming 08-06-2012 21:27:07.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.8160.6873 [GMT 2:00]
Kører fra: c:\users\SharkGaming\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\SharkGaming\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\SHARKG~1\AppData\Local\Temp\005CB.tmp"
"c:\users\SHARKG~1\AppData\Local\Temp\0067FAC.tmp"
"c:\users\SHARKG~1\AppData\Local\Temp\008B3F.tmp"
"c:\users\SharkGaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk"
"c:\windows\system32\drivers\badmghpp.sys"
"c:\windows\system32\drivers\cqbvreew.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\BitTorrentBar
c:\program files (x86)\BitTorrentBar\BitTorrentBarToolbarHelper.exe
c:\program files (x86)\BitTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\ldrtbBitT.dll
c:\program files (x86)\BitTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\prxtbBitT.dll
c:\program files (x86)\BitTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\tbBitT.dll
c:\program files (x86)\BitTorrentBar\toolbar.cfg
c:\program files (x86)\BitTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\BitTorrentBar\uninstall.exe
c:\users\SharkGaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MSICDSETUP
-------\Legacy_X6VA005
-------\Legacy_X6VA006
-------\Legacy_X6VA008
-------\Service_badmghpp
-------\Service_cqbvreew
-------\Service_MSICDSetup
-------\Service_X6va005
-------\Service_X6va006
-------\Service_X6va008
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-05-08 til 2012-06-08 )))))))))))))))))))))))))))))))))))
.
.
2012-06-08 19:31 . 2012-06-08 19:31 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-08 19:31 . 2012-06-08 19:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-08 16:46 . 2012-06-08 16:46 -------- d-----w- c:\programdata\Battle.net
2012-06-08 15:30 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4DB37226-649B-4A8D-8B0B-B8502EAE11A8}\mpengine.dll
2012-06-07 22:18 . 2012-05-08 08:02 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-06 19:59 . 2012-06-06 19:59 -------- d-----w- c:\program files (x86)\ERUNT
2012-06-06 14:12 . 2012-06-06 14:12 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-06 14:12 . 2012-06-06 14:12 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-05 21:11 . 2012-06-05 21:11 -------- d-----w- c:\program files (x86)\ESET
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\programdata\Malwarebytes
2012-06-02 23:51 . 2012-06-02 23:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-02 23:51 . 2012-04-04 13:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 23:41 . 2012-06-02 23:41 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2422CA51-F472-4A19-8EE0-0E637DFA145B}\gapaengine.dll
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-06-02 23:39 . 2012-06-02 23:39 -------- d-----w- c:\program files\Microsoft Security Client
2012-05-31 00:50 . 2012-05-31 00:50 -------- d-sh--w- c:\programdata\DSS
2012-05-30 09:34 . 2012-05-30 09:34 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-30 09:33 . 2012-05-30 09:39 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\DAEMON Tools Lite
2012-05-30 09:33 . 2012-05-30 09:34 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-05-30 09:32 . 2012-05-30 09:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\Google
2012-05-29 18:23 . 2012-05-29 18:23 -------- d-----w- c:\users\SharkGaming\AppData\Local\CRE
2012-05-25 17:44 . 2012-05-30 23:20 447752 ----a-w- c:\windows\SysWow64\vp6vfw.dll
2012-05-25 17:44 . 2012-05-25 17:44 -------- d-----w- c:\program files (x86)\Microsoft WSE
2012-05-22 17:26 . 2012-05-22 18:08 -------- d-----w- c:\users\SharkGaming\AppData\Roaming\Awesomium
2012-05-15 14:55 . 2012-06-08 17:00 -------- d-----w- c:\programdata\Blizzard Entertainment
2012-05-14 19:39 . 2012-06-08 16:49 -------- d-----w- c:\users\SharkGaming\Incomplete
2012-05-11 16:12 . 2012-05-15 10:12 -------- d-----w- c:\program files (x86)\Diablo II
2012-05-11 15:32 . 2012-05-11 15:59 -------- d-----w- c:\users\SharkGaming\D2LOD-1.12A-enGB
2012-05-11 13:59 . 2012-05-11 15:30 -------- d-----w- c:\users\SharkGaming\D2-1.12A-enGB
2012-05-11 13:59 . 2012-06-08 17:00 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-06 14:48 . 2012-02-18 20:45 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-06-06 14:48 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-06-05 20:32 . 2012-02-18 20:42 283416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-06-04 17:50 . 2012-02-18 20:42 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-05-08 20:55 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2012-05-08 20:55 . 2009-08-18 09:24 19352 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-05 12:35 . 2012-04-16 12:11 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 12:35 . 2012-01-20 00:31 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 12:35 . 2012-04-16 12:35 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-03-31 06:05 . 2012-05-09 12:23 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-09 12:23 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-09 12:23 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-09 12:23 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-09 12:22 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 18:44 . 2012-03-20 18:44 98688 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2012-03-20 18:44 203888 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-17 07:58 . 2012-05-09 12:22 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-08_14.03.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2012-06-08 16:13 34156 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-01-19 19:30 . 2012-06-08 16:13 9718 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3696142184-1702543921-4226803488-1000_UserData.bin
- 2012-06-08 14:03 . 2012-06-08 14:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-06-08 19:32 . 2012-06-08 19:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-08 14:03 . 2012-06-08 14:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-08 19:32 . 2012-06-08 19:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2012-06-02 23:39 662980 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-06-08 16:16 662980 c:\windows\system32\perfh009.dat
- 2010-11-21 08:43 . 2012-06-02 23:39 517990 c:\windows\system32\perfh006.dat
+ 2010-11-21 08:43 . 2012-06-08 16:16 517990 c:\windows\system32\perfh006.dat
+ 2009-07-14 02:36 . 2012-06-08 16:16 126070 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-06-02 23:39 126070 c:\windows\system32\perfc009.dat
- 2010-11-21 08:43 . 2012-06-02 23:39 103408 c:\windows\system32\perfc006.dat
+ 2010-11-21 08:43 . 2012-06-08 16:16 103408 c:\windows\system32\perfc006.dat
- 2009-07-14 05:01 . 2012-06-08 14:02 228720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-06-08 19:31 228720 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-01-19 22:58 . 2012-06-08 19:31 27661316 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3696142184-1702543921-4226803488-1000-12288.dat
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2012-01-20 1242448]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-1-20 4577760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R2 WSWNDA3100;WSWNDA3100;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2010-08-19 272864]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-06 113120]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Netværksinspektion;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 mv91cons;Marvell 91xx Config Device Driver;c:\windows\system32\DRIVERS\mv91cons.sys [x]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 12:35]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-01-04 6602856]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"combofix"="c:\combofix\CF25504.3XE" [2010-11-21 345088]
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 193.162.153.164 194.239.134.83
FF - ProfilePath - c:\users\SharkGaming\AppData\Roaming\Mozilla\Firefox\Profiles\44xz14t6.default\
FF - prefs.js: keyword.URL -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=2&q=.
- - - - TOMME GENVEJE FJERNET - - - -
.
AddRemove-BitTorrentBar Toolbar - c:\program files (x86)\BitTorrentBar\uninstall.exe
.
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_USERS\S-1-5-21-3696142184-1702543921-4226803488-1000\Software\SecuROM\License information*]
"datasecu"=hex:1c,f8,6f,62,ff,c6,f6,c2,69,f5,dd,92,83,ec,85,0b,b2,ac,92,c2,84,
18,df,6f,3d,93,1e,19,e3,e8,eb,05,ba,ad,e0,21,a0,a5,e4,63,7f,90,83,de,47,22,\
"rkeysecu"=hex:fc,73,1d,9f,82,cf,76,8b,1f,16,88,e0,c2,87,65,f7
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Gennemført tid: 2012-06-08 21:36:10 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-06-08 19:36
ComboFix2.txt 2012-06-08 14:07
.
Pre-Kørsel: 259.253.043.200 byte ledig
Post-Kørsel: 258.940.944.384 byte ledig
.
- - End Of File - - 914F78B1609A7AEEE34BEF3E56E9D05B
_____
Windows Firewall ser ud til at virke, men det har den gjort i et stykke tid, jeg tror Microsoft Security Essentials har taget over.
Windows Defender - jeg kan stadig ikke slå det til, jeg får beskeden "Handlingen returnerede fordi timeout-perioden udløb. (Fejlkode 0x800705b4)
09. juni 2012 - 14:34
#29
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\WinDefend]
"DisplayName"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,65,00,63,00,73,00,76,00,63,00,73,00,00,00
"Start"=dword:00000003
"Type"=dword:00000020
"Description"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-1176"
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
"ObjectName"="LocalSystem"
"ServiceSidType"=dword:00000001
"RequiredPrivileges"=hex(7):53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,\
00,6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\
65,00,00,00,53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,\
74,00,6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
00,00,00,53,00,65,00,44,00,65,00,62,00,75,00,67,00,50,00,72,00,69,00,76,00,\
69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,\
00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,\
6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,65,00,63,00,75,00,72,00,69,\
00,74,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
53,00,65,00,53,00,68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,63,00,\
72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,\
69,00,67,00,6e,00,50,00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,\
00,65,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
00,00
"DelayedAutoStart"=dword:00000000
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\WinDefend\Parameters]
"ServiceDllUnloadOnStop"=dword:00000001
"ServiceDll"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,\
00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,6d,00,70,00,73,\
00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\WinDefend\Security]
"Security"=hex:01,00,14,80,dc,00,00,00,e8,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,ac,00,06,00,00,00,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,\
05,50,00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,\
00,0b,28,00,00,00,00,10,01,06,00,00,00,00,00,05,50,00,00,00,b5,89,fb,38,19,\
84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,14,00,fd,01,02,00,01,01,\
00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\
04,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,\
01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\WinDefend\TriggerInfo]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\WinDefend\TriggerInfo\0]
"Type"=dword:00000005
"Action"=dword:00000001
"GUID"=hex:e6,ca,9f,65,db,5b,a9,4d,b1,ff,ca,2a,17,8d,46,e0