jeg var for hurtig Den skulle have lidt mere tid til at søge
"Marianne" - 07-03-13 13:48:13 Service Pack 2
ComboFix 07-03-13.11 - Running from: "C:\Documents and Settings\Marianne\Skrivebord"
((((((((((((((((((((((((((((((( Files Created from 2007-02-13 to 2007-03-13 ))))))))))))))))))))))))))))))))))
2007-03-13 08:08 4,675,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-03-13 08:08 10,272 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-03-13 08:08 <DIR> d-------- C:\Programmer\Kaspersky Lab
2007-03-12 21:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-03-12 21:16 <DIR> d-------- C:\kav
2007-03-12 17:27 <DIR> d--hs---- C:\found.000
2007-03-12 17:13 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2007-02-27 20:01 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-25 20:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-05 21:16 -------- d-------- C:\Programmer\spywareblaster
2007-03-05 12:56 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\skype
2007-03-04 15:30 -------- d-------- C:\Programmer\soulseek
2007-03-01 17:30 -------- d-------- C:\Programmer\incredimail
2007-02-28 14:30 -------- d-------- C:\Programmer\skolekom
2007-02-25 20:51 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\adobeum
2007-02-23 14:23 -------- d-------- C:\Programmer\polob32
2007-02-15 15:28 48094 --a------ C:\WINDOWS\system32\perfc006.dat
2007-02-15 15:28 327690 --a------ C:\WINDOWS\system32\perfh006.dat
2007-02-11 16:36 -------- d-------- C:\Programmer\windows defender
2007-02-11 13:25 -------- d---s---- C:\DOCUME~1\Marianne\APPLIC~1\microsoft
2007-02-11 13:25 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\superantispyware.com
2007-02-11 13:25 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\superadblocker.com
2007-02-11 13:25 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\officeupdate12
2007-02-11 13:24 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\fujifilm-dk-photo-manager
2007-02-11 13:24 -------- d-------- C:\DOCUME~1\Marianne\APPLIC~1\firstclass
2007-02-11 12:53 -------- d-------- C:\Programmer\microsoft activesync
2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpamBully 3 for Outlook Express"="\"C:\\Programmer\\Axaware\\Spam Bully 3 for OE\\sb3oe.exe\" install"
"IE Privacy Keeper"="\"C:\\Programmer\\UnH Solutions\\IE Privacy Keeper\\IEPrivacyKeeper.exe\" -startup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"HostsMan"="C:\\Programmer\\abelhadigital.com\\HostsMan\\hm.exe -s"
"TrueImageMonitor.exe"="C:\\Programmer\\Acronis\\TrueImageHome\\TrueImageMonitor.exe"
"AcronisTimounterMonitor"="C:\\Programmer\\Acronis\\TrueImageHome\\TimounterMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Programmer\\Fælles filer\\Acronis\\Schedule2\\schedhlp.exe\""
"HostsServer"="C:\\Programmer\\abelhadigital.com\\HostsMan\\hostssrv.exe --start"
"Windows Defender"="\"C:\\Programmer\\Windows Defender\\MSASCui.exe\" -hide"
"kav"="\"C:\\Programmer\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Gamma Loader.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
"location"="Common Startup"
"command"="\"C:\\Programmer\\Fælles filer\\Adobe\\Calibration\\Adobe Gamma Loader.exe\" "
"item"="Adobe Gamma Loader"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menuen Start^Programmer^Start^Adobe Reader Hurtigstart.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Hurtigstart.lnkCommon Startup"
"location"="Common Startup"
"command"="\"C:\\Programmer\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe\" "
"item"="Adobe Reader Hurtigstart"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="!AVG Anti-Spyware"
"hkey"="HKLM"
"command"="\"C:\\Programmer\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="schedhlp"
"hkey"="HKLM"
"command"="\"C:\\Programmer\\Fælles filer\\Acronis\\Schedule2\\schedhlp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TimounterMonitor"
"hkey"="HKLM"
"command"="C:\\Programmer\\Acronis\\TrueImageHome\\TimounterMonitor.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="H/PC Connection Agent"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="oss_reinstall"
"hkey"="HKLM"
"command"="C:\\Programmer\\Fælles filer\\Acronis\\Acronis Disk Director\\oss_reinstall.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Programmer\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SunJavaUpdateSched"
"hkey"="HKLM"
"command"="C:\\Programmer\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TrueImageMonitor"
"hkey"="HKLM"
"command"="C:\\Programmer\\Acronis\\TrueImageHome\\TrueImageMonitor.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\{276C47C8-2287-4038-A42B-11D93E50D1FB}_MARIANNE-GG9DNE_Marianne.job
C:\WINDOWS\tasks\{98AF202D-5659-4AA9-8AB0-CB70C87EC2CA}_MARIANNE-GG9DNE_Marianne.job
C:\WINDOWS\tasks\{CE148A73-5A45-4634-B402-4BC34D18976C}_MARIANNE-GG9DNE_Marianne.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-13 13:51:16
C:\ComboFix2.txt ... 07-03-13 13:38
C:\ComboFix3.txt ... 07-03-13 13:34