Her er der så alle de logs som jeg skulle gemme .. Håber i kan finde en løsning ..
OTL:
OTL logfile created on: 16-09-2012 13:42:19 - Run 2
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Roneklindt\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
952,13 Mb Total Physical Memory | 354,22 Mb Available Physical Memory | 37,20% Memory free
2,12 Gb Paging File | 0,93 Gb Available in Paging File | 43,72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 69,65 Gb Total Space | 39,80 Gb Free Space | 57,14% Space Free | Partition Type: NTFS
Drive D: | 69,64 Gb Total Space | 45,33 Gb Free Space | 65,10% Space Free | Partition Type: NTFS
Drive F: | 7,20 Gb Total Space | 7,12 Gb Free Space | 98,81% Space Free | Partition Type: FAT32
Computer Name: RONEKLINDT-PC | User Name: Roneklindt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012-09-09 18:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Roneklindt\Desktop\OTL.com
PRC - [2012-09-03 20:07:57 | 000,722,528 | ---- | M] () -- C:\Programmer\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
PRC - [2012-09-03 20:07:32 | 000,947,808 | ---- | M] () -- C:\Programmer\AVG Secure Search\vprot.exe
PRC - [2012-08-13 03:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgidsagent.exe
PRC - [2012-07-31 03:37:02 | 002,596,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgtray.exe
PRC - [2012-07-26 03:23:08 | 000,758,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgrsx.exe
PRC - [2012-07-18 18:14:18 | 000,204,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\RONEKL~1\AppData\Local\Temp\RtkBtMnt.exe
PRC - [2012-06-13 03:48:24 | 001,255,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgnsx.exe
PRC - [2012-03-19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgemcx.exe
PRC - [2012-02-14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgwdsvc.exe
PRC - [2012-02-14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG2012\avgcsrvx.exe
PRC - [2011-11-03 17:20:58 | 000,803,144 | ---- | M] (AVG) -- C:\Programmer\AVG\AVG PC Tuneup\BoostSpeed.exe
PRC - [2010-11-26 15:36:32 | 001,762,688 | ---- | M] () -- C:\Programmer\Connect it\BecHelperService.exe
PRC - [2010-11-26 15:34:52 | 000,294,400 | ---- | M] () -- C:\Programmer\Connect it\LoggerServer.exe
PRC - [2009-04-11 08:28:15 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009-04-11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008-06-10 01:36:14 | 000,870,920 | ---- | M] (Dritek System Inc.) -- C:\Programmer\Launch Manager\LManager.exe
PRC - [2008-05-21 04:06:00 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008-04-30 19:02:40 | 000,397,312 | ---- | M] (Acer Inc.) -- C:\Programmer\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2008-03-21 13:22:52 | 000,024,576 | ---- | M] () -- C:\Programmer\Acer\Empowering Technology\Service\ETService.exe
PRC - [2008-03-21 13:22:32 | 000,376,832 | ---- | M] (acer) -- C:\Programmer\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
PRC - [2008-01-16 11:01:30 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007-12-06 16:15:28 | 000,110,592 | ---- | M] () -- C:\Acer\Mobility Center\MobilityService.exe
PRC - [2007-02-13 02:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Programmer\O2Micro Flash Memory Card Driver\o2flash.exe
PRC - [2006-10-31 00:00:00 | 000,139,264 | ---- | M] (Brother Industries,ltd) -- C:\Windows\System32\bsplmf01.exe
PRC - [2006-10-27 00:47:42 | 000,031,016 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2006-09-09 01:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programmer\Apoint2K\Hidfind.exe
========== Modules (No Company Name) ========== MOD - [2012-09-03 20:08:22 | 000,564,832 | ---- | M] () -- C:\Programmer\Common Files\AVG Secure Search\DNTInstaller\12.2.6\avgdttbx.dll
MOD - [2012-09-03 20:07:59 | 000,132,704 | ---- | M] () -- C:\Programmer\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\SiteSafety.dll
MOD - [2012-09-03 20:07:32 | 000,947,808 | ---- | M] () -- C:\Programmer\AVG Secure Search\vprot.exe
MOD - [2012-07-13 20:33:48 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012-07-13 20:33:27 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012-07-13 20:30:43 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012-07-13 20:27:51 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012-07-13 20:26:25 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012-07-13 20:06:30 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012-07-13 19:54:39 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012-07-13 19:54:17 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011-11-03 17:21:06 | 000,350,024 | ---- | M] () -- C:\Programmer\AVG\AVG PC Tuneup\madExcept_.bpl
MOD - [2011-11-03 17:21:06 | 000,184,136 | ---- | M] () -- C:\Programmer\AVG\AVG PC Tuneup\madBasic_.bpl
MOD - [2011-11-03 17:21:06 | 000,050,504 | ---- | M] () -- C:\Programmer\AVG\AVG PC Tuneup\madDisAsm_.bpl
MOD - [2009-04-11 08:28:22 | 000,223,232 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2009-03-31 20:05:00 | 000,299,008 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_da_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008-09-12 00:28:43 | 000,569,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.UIComponent\3.0.3006.0__739b31b1908c49e5\Framework.UIComponent.dll
MOD - [2008-09-12 00:28:43 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3006.0__3036420f80dd6947\Framework.Library.dll
MOD - [2008-09-12 00:28:43 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3006.0__4df5dcab8860d239\Framework.Utility.dll
MOD - [2008-09-12 00:28:43 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3006.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll
MOD - [2008-04-30 16:00:02 | 000,204,800 | ---- | M] () -- C:\Windows\System32\SysHook.dll
MOD - [2003-06-07 23:30:08 | 000,057,344 | ---- | M] () -- C:\Programmer\Launch Manager\PowerUtl.dll
========== Services (SafeList) ========== SRV - [2012-09-05 21:24:44 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programmer\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-09-03 20:07:57 | 000,722,528 | ---- | M] () [Auto | Running] -- C:\Programmer\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe -- (vToolbarUpdater12.2.6)
SRV - [2012-09-03 19:15:02 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-08-13 03:24:48 | 005,167,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Programmer\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012-02-14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Programmer\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010-11-26 15:36:32 | 001,762,688 | ---- | M] () [Auto | Running] -- C:\Programmer\Connect it\BecHelperService.exe -- (BecHelperService)
SRV - [2008-03-21 13:22:52 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Programmer\Acer\Empowering Technology\Service\ETService.exe -- (ETService)
SRV - [2008-01-21 04:35:20 | 000,896,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2008-01-16 11:01:30 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programmer\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007-12-06 16:15:28 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService)
SRV - [2007-08-24 03:19:12 | 000,443,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2007-02-13 02:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Programmer\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
SRV - [2006-10-27 00:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006-04-14 10:07:20 | 028,933,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$MSSMLBIZ)
SRV - [2006-04-14 10:05:58 | 000,240,416 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programmer\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2006-04-14 10:04:54 | 000,087,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programmer\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2005-10-14 03:50:20 | 000,045,272 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programmer\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012-09-03 20:08:02 | 000,027,496 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2012-08-24 15:43:18 | 000,301,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012-07-26 03:21:30 | 000,237,408 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2012-04-19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2012-01-31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011-12-23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011-12-23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2011-12-23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)
DRV - [2011-12-23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2010-11-26 16:21:56 | 000,072,832 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010-11-26 16:21:52 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010-11-26 16:21:52 | 000,106,880 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010-11-26 16:21:52 | 000,011,136 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2010-11-26 16:21:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2008-06-05 03:54:22 | 000,113,664 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2008-04-15 20:13:14 | 000,051,160 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2media.sys -- (O2MDRDR)
DRV - [2008-04-08 20:46:02 | 000,043,736 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\o2sd.sys -- (O2SDRDR)
DRV - [2008-04-06 04:56:08 | 000,908,800 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008-03-21 10:48:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15)
DRV - [2008-02-01 09:14:36 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007-12-26 08:23:10 | 000,017,968 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TpChoice.sys -- (TpChoice)
DRV - [2006-11-29 02:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&l=0406&s=2&o=vb32&d=0612&m=extensa_5230IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig?hl=daIE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}IE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAWIE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
https://isearch.avg.com/search?cid={FED86ED8-575D-453F-9313-A27840DBA7BD}&mid=297acc72ec3547d0966bd154343c1f21-fab9e376f2db6063f21074670f3e748cbe54e38d&lang=da&ds=AVG&pr=fr&d=2012-06-19 18:52:14&v=12.2.5.32&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-1940343515-965900618-618164863-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "
http://www.google.dk/ig"FF - prefs.js..extensions.enabledAddons: avg@toolbar:12.2.5.32
FF - prefs.js..keyword.URL: "
https://isearch.avg.com/search?cid=%7B379ce5f9-e061-427e-a3ab-46694dec1fff%7D&mid=297acc72ec3547d0966bd154343c1f21-fab9e376f2db6063f21074670f3e748cbe54e38d&ds=AVG&v=12.2.5.32&lang=da&pr=fr&d=2012-06-19%2018%3A52%3A14&sap=ku&q="FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012-09-10 16:38:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\12.2.5.32\ [2012-09-03 20:08:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-09-05 21:24:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-09-05 21:24:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012-06-19 18:43:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Roneklindt\AppData\Roaming\mozilla\Extensions
[2012-09-02 18:34:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Roneklindt\AppData\Roaming\mozilla\Firefox\Profiles\p72hkaug.default\extensions
[2012-06-19 18:40:21 | 000,000,000 | ---D | M] (No name found) -- C:\Programmer\Mozilla Firefox\extensions
[2012-09-03 20:08:50 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\12.2.5.32
[2012-09-05 21:24:44 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-06-15 00:39:13 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-co-uk.xml
[2012-09-03 20:07:21 | 000,003,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-09-05 21:24:42 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-06-15 00:39:14 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-da.xml
O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Programmer\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmer\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmer\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Programmer\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll ()
O3 - HKU\S-1-5-21-1940343515-965900618-618164863-1003\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ePower_DMC] C:\Programmer\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [HF_G_Jul] C:\Program Files\AVG Secure Search\HF_G_Jul.exe ()
O4 - HKLM..\Run: [LManager] C:\Programmer\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [ROC_ROC_JULY_P1] C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O8 - Extra context menu item: E&ksporter til Microsoft Excel - C:\Programmer\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmer\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmer\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programmer\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - %SystemRoot%\System32\winrnr.dll File not found
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3F279FA5-B709-435A-B245-95B2B1F69457}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Programmer\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll ()
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programmer\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009-12-26 13:59:40 | 000,000,513 | ---- | M] () - D:\Autodata CD2.lnk -- [ NTFS ]
O32 - AutoRun File - [2004-11-13 22:47:12 | 000,000,063 | ---- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{d92b55ae-c2be-11e1-8250-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d92b55ae-c2be-11e1-8250-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\{d92b56ff-c2be-11e1-8250-001e101f4e71}\Shell - "" = AutoRun
O33 - MountPoints2\{d92b56ff-c2be-11e1-8250-001e101f4e71}\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\{ef4174bf-c2ca-11e1-a6ed-001e101fe5e1}\Shell - "" = AutoRun
O33 - MountPoints2\{ef4174bf-c2ca-11e1-a6ed-001e101fe5e1}\Shell\AutoRun\command - "" = F:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[CREATERESTOREPOINT]
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012-09-16 13:41:33 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Roneklindt\Desktop\OTL.com
[2012-09-10 16:38:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012-09-03 20:08:02 | 000,027,496 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012-08-29 23:27:46 | 000,000,000 | --SD | C] -- C:\BANANEN
[2012-08-29 23:27:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-08-29 21:32:56 | 000,000,000 | ---D | C] -- C:\Users\Roneklindt\Desktop\backups
[2012-08-29 12:57:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-08-24 15:43:18 | 000,301,920 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2012-08-21 20:49:43 | 000,000,000 | ---D | C] -- C:\Users\Roneklindt\AppData\Roaming\Malwarebytes
[2012-08-21 20:49:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012-08-21 20:49:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-08-21 20:49:15 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012-08-21 20:49:15 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012-08-21 20:35:53 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
========== Files - Modified Within 30 Days ========== [2012-09-16 13:45:19 | 000,642,704 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-09-16 13:45:19 | 000,519,100 | ---- | M] () -- C:\Windows\System32\perfh006.dat
[2012-09-16 13:45:19 | 000,121,592 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012-09-16 13:45:19 | 000,097,908 | ---- | M] () -- C:\Windows\System32\perfc006.dat
[2012-09-16 13:34:13 | 094,961,329 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2012-09-16 13:28:51 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-09-16 13:28:50 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-09-16 13:28:45 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-09-16 13:28:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-09-15 20:09:43 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2012-09-15 20:08:43 | 999,157,760 | -HS- | M] () -- C:\hiberfil.sys
[2012-09-09 18:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Roneklindt\Desktop\OTL.com
[2012-09-08 17:58:01 | 000,280,905 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm
[2012-09-03 20:08:02 | 000,027,496 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2012-09-03 19:14:59 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012-09-03 19:14:59 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-08-29 21:37:33 | 000,024,576 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2012-08-24 15:43:18 | 000,301,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2012-08-21 20:49:25 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-08-21 20:35:56 | 000,000,808 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ========== [2012-09-03 18:28:17 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-09-02 00:27:25 | 000,013,312 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@
[2012-09-02 00:27:24 | 000,002,048 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@
[2012-09-02 00:27:24 | 000,001,632 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@
[2012-09-01 21:49:45 | 000,232,960 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@
[2012-09-01 21:49:44 | 000,091,136 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000032.@
[2012-09-01 18:22:37 | 999,157,760 | -HS- | C] () -- C:\hiberfil.sys
[2012-08-21 20:49:25 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-08-21 20:35:56 | 000,000,808 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-07-21 00:57:59 | 000,000,804 | ---- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\L\00000004.@
[2012-07-12 14:38:29 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@
[2012-07-12 14:38:29 | 000,002,048 | -HS- | C] () -- C:\Users\Roneklindt\AppData\Local\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@
[2012-06-30 16:26:30 | 000,067,156 | ---- | C] () -- C:\Windows\Huawei ModemsUninstall.exe
[2012-06-27 14:24:18 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012-06-27 14:24:17 | 000,000,425 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012-06-27 14:24:16 | 000,000,030 | ---- | C] () -- C:\Windows\System32\brss01a.ini
[2012-06-27 14:22:21 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf05a.dat
[2012-06-25 22:22:47 | 000,008,704 | ---- | C] () -- C:\Users\Roneklindt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-06-24 15:54:22 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012-06-24 15:54:21 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012-06-20 03:19:13 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[2012-06-20 03:07:49 | 002,192,024 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2012-06-20 03:07:49 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1502.dll
[2012-06-20 03:07:49 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2012-06-20 03:07:48 | 000,492,496 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2012-06-20 03:07:48 | 000,147,172 | ---- | C] () -- C:\Windows\System32\igfcg550.bin
[2012-06-19 20:54:50 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012-06-19 17:54:22 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll
[2012-06-19 17:49:29 | 000,000,000 | ---- | C] () -- C:\Windows\setup.INI
[2012-06-19 17:41:34 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini
[2012-06-19 17:41:34 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat
[2012-06-19 17:41:34 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2012-06-19 17:41:34 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\rtkhdaud.dat
========== Custom Scans ========== < :otl > < @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0B4227B4 > < @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0B4227B4 > < > < :files > < ipconfig /flushdns /c >Windows IP-konfiguration
DNS Resolver Cache blev t›mt.
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@ >[2012-09-02 00:27:25 | 000,013,312 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@ >[2012-09-02 00:27:24 | 000,002,048 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@ >[2012-09-02 00:27:24 | 000,001,632 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@ >[2012-09-01 21:49:45 | 000,232,960 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000032.@ >[2012-09-14 20:02:28 | 000,091,136 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000032.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\L\00000004.@ >[2012-09-15 20:09:48 | 000,000,804 | ---- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\L\00000004.@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@ >[2011-11-18 22:23:34 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@
< C:\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179} > < C:\Users\Roneklindt\AppData\Local\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@ >[2012-07-21 23:26:07 | 000,002,048 | -HS- | M] () -- C:\Users\Roneklindt\AppData\Local\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@
< C:\Users\Roneklindt\AppData\Local\{5fe39fe5-5c5f-abd8-783c-3092b01c6179} > < > < :Commands > < [purity] > < [resethosts] > < [EMPTYFLASH] > < [Reboot] > ========== Alternate Data Streams ========== @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report >
COMBOFIX:
ComboFix 12-09-15.02 - Roneklindt 16-09-2012 14:25:43.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.45.1030.18.952.268 [GMT 2:00]
Kører fra: c:\users\Roneklindt\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Roneklindt\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\L\00000004.@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\L\201d3dde
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@
c:\windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000032.@
D:\autorun.inf
.
.
--------------- FCopy ---------------
.
c:\windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe --> c:\windows\System32\services.exe
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-08-16 til 2012-09-16 )))))))))))))))))))))))))))))))))))
.
.
2012-09-05 19:24 . 2012-09-05 19:24 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-09-03 18:08 . 2012-09-03 18:08 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-08-29 21:27 . 2012-08-29 21:27 -------- d-----w- C:\BANANEN
2012-08-29 10:57 . 2012-08-29 10:57 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-24 13:43 . 2012-08-24 13:43 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2012-08-21 18:49 . 2012-08-21 18:49 -------- d-----w- c:\users\Roneklindt\AppData\Roaming\Malwarebytes
2012-08-21 18:49 . 2012-08-21 18:49 -------- d-----w- c:\programdata\Malwarebytes
2012-08-21 18:49 . 2012-09-02 01:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-21 18:49 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-21 18:35 . 2012-09-02 01:19 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-03 17:14 . 2012-06-19 17:05 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-03 17:14 . 2012-06-19 17:05 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-26 01:21 . 2012-07-26 01:21 237408 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2012-07-13 16:30 . 2012-07-13 16:30 161792 ----a-w- c:\windows\system32\msls31.dll
2012-07-13 16:30 . 2012-07-13 16:30 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-07-13 16:30 . 2012-07-13 16:30 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-07-13 16:30 . 2012-07-13 16:30 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-07-13 16:30 . 2012-07-13 16:30 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-07-13 16:30 . 2012-07-13 16:30 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-07-13 16:30 . 2012-07-13 16:30 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-07-13 16:30 . 2012-07-13 16:30 367104 ----a-w- c:\windows\system32\html.iec
2012-07-13 16:30 . 2012-07-13 16:30 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-07-13 16:30 . 2012-07-13 16:30 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-13 16:30 . 2012-07-13 16:30 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-13 16:30 . 2012-07-13 16:30 152064 ----a-w- c:\windows\system32\wextract.exe
2012-07-13 16:30 . 2012-07-13 16:30 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-07-13 16:30 . 2012-07-13 16:30 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-07-13 16:30 . 2012-07-13 16:30 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-13 16:30 . 2012-07-13 16:30 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-07-13 16:30 . 2012-07-13 16:30 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-07-13 16:30 . 2012-07-13 16:30 11776 ----a-w- c:\windows\system32\mshta.exe
2012-07-13 16:30 . 2012-07-13 16:30 101888 ----a-w- c:\windows\system32\admparse.dll
2012-07-13 16:30 . 2012-07-13 16:30 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-07-13 16:30 . 2012-07-13 16:30 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-07-13 16:28 . 2012-07-13 16:28 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2012-07-13 16:28 . 2012-07-13 16:28 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2012-07-13 16:28 . 2012-07-13 16:28 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2012-07-13 16:28 . 2012-07-13 16:28 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2012-07-13 16:28 . 2012-07-13 16:28 98816 ----a-w- c:\windows\system32\mfps.dll
2012-07-13 16:28 . 2012-07-13 16:28 2873344 ----a-w- c:\windows\system32\mf.dll
2012-07-13 16:28 . 2012-07-13 16:28 209920 ----a-w- c:\windows\system32\mfplat.dll
2012-07-13 16:28 . 2012-07-13 16:28 586240 ----a-w- c:\windows\system32\stobject.dll
2012-07-13 16:28 . 2012-07-13 16:28 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2012-07-13 16:28 . 2012-07-13 16:28 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2012-07-13 16:28 . 2012-07-13 16:28 478720 ----a-w- c:\windows\system32\dxgi.dll
2012-07-13 16:28 . 2012-07-13 16:28 189952 ----a-w- c:\windows\system32\d3d10core.dll
2012-07-13 16:28 . 2012-07-13 16:28 1029120 ----a-w- c:\windows\system32\d3d10.dll
2012-07-13 16:28 . 2012-07-13 16:28 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-07-13 16:28 . 2012-07-13 16:28 37376 ----a-w- c:\windows\system32\cdd.dll
2012-07-13 16:28 . 2012-07-13 16:28 258048 ----a-w- c:\windows\system32\winspool.drv
2012-07-13 16:28 . 2012-07-13 16:28 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2012-07-13 16:28 . 2012-07-13 16:28 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2012-07-13 16:28 . 2012-07-13 16:28 847360 ----a-w- c:\windows\system32\OpcServices.dll
2012-07-13 16:28 . 2012-07-13 16:28 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2012-07-13 16:26 . 2012-07-13 16:26 4096 ----a-w- c:\windows\system32\drivers\da-DK\dxgkrnl.sys.mui
2012-07-13 16:26 . 2012-07-13 16:26 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-07-13 16:26 . 2012-07-13 16:26 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-07-13 16:26 . 2012-07-13 16:26 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-07-13 16:26 . 2012-07-13 16:26 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-07-13 16:26 . 2012-07-13 16:26 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-07-13 16:26 . 2012-07-13 16:26 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-07-13 16:26 . 2012-07-13 16:26 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-30 14:26 . 2012-06-30 14:26 67156 ----a-w- c:\windows\Huawei ModemsUninstall.exe
2012-06-20 18:55 . 2012-06-20 18:56 772592 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-20 18:55 . 2012-06-20 18:56 687600 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-20 01:10 . 2012-06-20 01:10 6656 ----a-w- c:\windows\system32\kbd106n.dll
2012-06-19 15:41 . 2012-06-19 15:41 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-06-19 15:41 . 2012-06-19 15:41 315392 ----a-w- c:\windows\HideWin.exe
2012-09-05 19:24 . 2012-06-19 16:40 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-09-03 18:07 1734240 ----a-w- c:\program files\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll" [2012-09-03 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-17 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-21 6144000]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-01-25 159744]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-06-09 870920]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-30 397312]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-31 2596984]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-09-03 947808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-02-15 622592]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-07-19 65536]
"HF_G_Jul"="c:\program files\AVG Secure Search\HF_G_Jul.exe" [2012-07-18 36960]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"ROC_ROC_JULY_P1"="c:\program files\AVG Secure Search\ROC_ROC_JULY_P1.exe" [2012-09-03 1022048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
2008-01-29 07:03 303104 ----a-w- c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-09-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-19 17:15]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.com/ig?hl=damStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0406&s=2&o=vb32&d=0612&m=extensa_5230IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
FF - ProfilePath - c:\users\Roneklindt\AppData\Roaming\Mozilla\Firefox\Profiles\p72hkaug.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.dk/igFF - prefs.js: keyword.URL -
hxxps://isearch.avg.com/search?cid=%7B379ce5f9-e061-427e-a3ab-46694dec1fff%7D&mid=297acc72ec3547d0966bd154343c1f21-fab9e376f2db6063f21074670f3e748cbe54e38d&ds=AVG&v=12.2.5.32&lang=da&pr=fr&d=2012-06-19%2018%3A52%3A14&sap=ku&q=.
- - - - TOMME GENVEJE FJERNET - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-09-16 14:38
Windows 6.0.6002 Service Pack 2 NTFS
.
scanner skjulte processer ...
.
scanner skjulte autostarter ...
.
scanner skjulte filer ...
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Andre kørende processer ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\brsvc01a.exe
c:\windows\system32\brss01a.exe
c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe
c:\program files\AVG\AVG2012\avgwdsvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Connect it\BecHelperService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Connect it\LoggerServer.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\AVG\AVG2012\avgidsagent.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Gennemført tid: 2012-09-16 14:45:35 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-09-16 12:45
.
Pre-Kørsel: 42.326.761.472 byte ledig
Post-Kørsel: 42.514.075.648 byte ledig
.
- - End Of File - - B50041C8547DF9BEEDAE88738808217D
MALWARE FØR SLETNING:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.orgDatabase version: v2012.09.16.04
Windows Vista Service Pack 2 x86 FAT32
Internet Explorer 9.0.8112.16421
Roneklindt :: RONEKLINDT-PC [administrator]
16-09-2012 14:49:18
mbam-log-2012-09-16 (15-40-14).txt
Skanningstype: Fuldstændig skanning (C:\|D:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 288939
Tid gået: 46 minut(ter), 50 sekund(er)
Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)
Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)
Inficerede Filer: 5
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@.vir (Rootkit.Zaccess) -> Ingen handling valgt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@.vir (Trojan.Dropper.BCMiner) -> Ingen handling valgt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@.vir (Rootkit.0Access) -> Ingen handling valgt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@.vir (Trojan.Small) -> Ingen handling valgt.
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Ingen handling valgt.
(færdig)
MALWARE EFTER SLETNING:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.orgDatabase version: v2012.09.16.04
Windows Vista Service Pack 2 x86 FAT32
Internet Explorer 9.0.8112.16421
Roneklindt :: RONEKLINDT-PC [administrator]
16-09-2012 14:49:18
mbam-log-2012-09-16 (14-49-18).txt
Skanningstype: Fuldstændig skanning (C:\|D:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 288939
Tid gået: 46 minut(ter), 50 sekund(er)
Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)
Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)
Inficerede Filer: 5
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000004.@.vir (Rootkit.Zaccess) -> Sat i karantæne og slettet succesfuldt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\00000008.@.vir (Trojan.Dropper.BCMiner) -> Sat i karantæne og slettet succesfuldt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\000000cb.@.vir (Rootkit.0Access) -> Sat i karantæne og slettet succesfuldt.
C:\Qoobox\Quarantine\C\Windows\Installer\{5fe39fe5-5c5f-abd8-783c-3092b01c6179}\U\80000000.@.vir (Trojan.Small) -> Sat i karantæne og slettet succesfuldt.
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Sat i karantæne og slettet succesfuldt.
(færdig)