Forskellige logfiler til gennemgang
Computeren er langsom både ved opstart og under brug. Der er kørt HJT, SuperAntiSpyware, ComboFix og CCleaner. Computerens AVG (Norton Trial) er udløbet - har I nogle forslag til en gratis AVG? Har fået anbefalet Avira AntiVirLogfile of HijackThis v1.99.1
Scan saved at 18:46:09, on 09-12-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Malle\Skrivebord\sikkerhed\alternativ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar3.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programmer\MyWebSearch\bar\1.bin\MWSBAR.DLL (file missing)
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PCMService] "C:\Programmer\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\Programmer\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LemmingsRevolutionSetup.exe] C:\DOWNLO~1\LEMMIN~1.EXE /r
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = C:\Programmer\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm022YYDK
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmer\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Programmer\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1.0.0.15-3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.click4foto.dk/aurigma/ImageUploader4.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://asp06.photoprintit.de/microsite/5702/defaults/activex/IPSUploader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
ComboFix 07-12-09.1 - Malle 2007-12-09 18:06:41.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.495 [GMT 1:00]
Running from: C:\Documents and Settings\Malle\Skrivebord\sikkerhed\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Programmer\FunWebProducts
C:\Programmer\FunWebProducts\PopSwatr\History\allowed
C:\Programmer\FunWebProducts\PopSwatr\History\notallow
C:\Programmer\FunWebProducts\Shared\Cache\AvatarSmallBtn-new.html
C:\Programmer\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\MyFunCardsIMBtn-new.html
C:\Programmer\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Programmer\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Programmer\internet explorer\msimg32.dll
C:\Programmer\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Programmer\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Programmer\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Programmer\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Programmer\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Programmer\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Programmer\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Programmer\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Programmer\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Programmer\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Programmer\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Programmer\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Programmer\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Programmer\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Programmer\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Programmer\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Programmer\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Programmer\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Programmer\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Programmer\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Programmer\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Programmer\MyWebSearch\bar\Cache\0012ADAD
C:\Programmer\MyWebSearch\bar\Cache\0128D15A
C:\Programmer\MyWebSearch\bar\Cache\0128D3CB.bin
C:\Programmer\MyWebSearch\bar\Cache\0128F26E.bin
C:\Programmer\MyWebSearch\bar\Cache\0129173C.bin
C:\Programmer\MyWebSearch\bar\Cache\012918C3.bin
C:\Programmer\MyWebSearch\bar\Cache\01292601.bin
C:\Programmer\MyWebSearch\bar\Cache\01416A88.bin
C:\Programmer\MyWebSearch\bar\Cache\01417863.bin
C:\Programmer\MyWebSearch\bar\Cache\01417A37.bin
C:\Programmer\MyWebSearch\bar\Cache\01418757.bin
C:\Programmer\MyWebSearch\bar\Cache\014195DD.bin
C:\Programmer\MyWebSearch\bar\Cache\042F00C2.bin
C:\Programmer\MyWebSearch\bar\Cache\042F0277.bin
C:\Programmer\MyWebSearch\bar\Cache\042F0546.bin
C:\Programmer\MyWebSearch\bar\Cache\042F069E
C:\Programmer\MyWebSearch\bar\Cache\files.ini
C:\Programmer\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Programmer\MyWebSearch\bar\Game\CHESS.F3S
C:\Programmer\MyWebSearch\bar\Game\REVERSI.F3S
C:\Programmer\MyWebSearch\bar\History\search2
C:\Programmer\MyWebSearch\bar\icons\CM.ICO
C:\Programmer\MyWebSearch\bar\icons\MFC.ICO
C:\Programmer\MyWebSearch\bar\icons\PSS.ICO
C:\Programmer\MyWebSearch\bar\icons\SMILEY.ICO
C:\Programmer\MyWebSearch\bar\icons\WB.ICO
C:\Programmer\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Programmer\MyWebSearch\bar\Message\COMMON.F3S
C:\Programmer\MyWebSearch\bar\Message\COMMON\ask_logo.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\autoup.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\autoup.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\center.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\index.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\mid_dots.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\mws_logo.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\protect.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\shocked.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\stop.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\systray.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\systrayp.htm
C:\Programmer\MyWebSearch\bar\Message\COMMON\tp_grad.gif
C:\Programmer\MyWebSearch\bar\Message\COMMON\warn.gif
C:\Programmer\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Programmer\MyWebSearch\bar\Notifier\DOG.F3S
C:\Programmer\MyWebSearch\bar\Notifier\FISH.F3S
C:\Programmer\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Programmer\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Programmer\MyWebSearch\bar\Notifier\MAID.F3S
C:\Programmer\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Programmer\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Programmer\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Programmer\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Programmer\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Programmer\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Programmer\MyWebSearch\bar\Settings\s_pid.dat
C:\Programmer\MyWebSearch\bar\Settings\setting2.htm
C:\Programmer\MyWebSearch\bar\Settings\settings.dat
C:\Programmer\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\WINDOWS\system32\autorun.ini
C:\WINDOWS\system32\f3PSSavr.scr
C:\Programmer\MyWebSearch
.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-09 18:03 . 2007-12-09 18:03 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2007-12-09 18:03 . 2007-12-09 18:03 <DIR> d-------- C:\Documents and Settings\Malle\Application Data\SUPERAntiSpyware.com
2007-12-09 18:03 . 2007-12-09 18:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-09 18:02 . <DIR> C:\Programmer\Fælles filer\Wise Installation Wizard
2007-12-09 17:59 . 2007-12-09 17:59 <DIR> d-------- C:\Programmer\CCleaner
2007-11-28 14:20 . 2007-11-28 14:20 <DIR> d-------- C:\Documents and Settings\Malle\Application Data\CyberLink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 16:43 8,472,064 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-23 20:33 --------- d-----w C:\Programmer\Full Tilt Poker
2006-05-30 20:23 9,409,736 ----a-w C:\Programmer\Install_MSN_Messenger.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 05:00]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"LemmingsRevolutionSetup.exe"="C:\DOWNLO~1\LEMMIN~1.exe" []
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-05 18:36]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"SynTPLpr"="C:\Programmer\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44]
"SynTPEnh"="C:\Programmer\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 18:13 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-07 19:50 C:\WINDOWS\AGRSMMSG.exe]
"SiSPower"="Rundll32.exe" [2004-08-27 05:00 C:\WINDOWS\system32\rundll32.exe]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13]
"PCMService"="C:\Programmer\Arcade\PCMService.exe" [2005-03-09 18:59]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-27 05:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-27 05:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-27 05:00]
"LManager"="C:\Programmer\Launch Manager\QtZgAcer.EXE" [2005-10-12 15:16]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 16:54]
"ccApp"="C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" []
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 15:07]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 05:00]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2005-01-04 16:52:52]
Smart Wizard Wireless Settings.lnk - C:\Programmer\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2006-05-20 19:47:46]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R2 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys
*Newly Created Service* - INT15.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 19:49:18 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Malle.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
"2007-12-09 12:37:02 C:\WINDOWS\Tasks\Søg efter opdateringer til Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 18:11:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-09 18:13:11 - machine was rebooted
.
--- E O F ---
********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh
09-12-2007 18:05:12,32
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 18:05:13
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
hidden processes: 0
hidden services: 0
hidden files: 0
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 12/09/2007 at 06:45 PM
Application Version : 3.7.1018
Core Rules Database Version : 3358
Trace Rules Database Version: 1357
Scan type : Complete Scan
Total Scan Time : 00:27:08
Memory items scanned : 163
Memory threats detected : 0
Registry items scanned : 4622
Registry threats detected : 13
File items scanned : 25561
File threats detected : 169
Adware.MyWebSearch
HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
C:\PROGRAMMER\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL
HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
C:\PROGRAMMER\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-1482121612-1023852549-2475382190-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Adware.Tracking Cookie
C:\Documents and Settings\Malle\Cookies\malle@overture[1].txt
C:\Documents and Settings\Malle\Cookies\malle@qnsr[2].txt
C:\Documents and Settings\Malle\Cookies\malle@m1.webstats.motigo[1].txt
C:\Documents and Settings\Malle\Cookies\malle@webstat[1].txt
C:\Documents and Settings\Malle\Cookies\malle@centrebet.advertserve[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adrevolver[1].txt
C:\Documents and Settings\Malle\Cookies\malle@as1.falkag[1].txt
C:\Documents and Settings\Malle\Cookies\malle@audit.median[1].txt
C:\Documents and Settings\Malle\Cookies\malle@revsci[2].txt
C:\Documents and Settings\Malle\Cookies\malle@hitbox[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ehg-bskyb.hitbox[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adserver.banneradministration[4].txt
C:\Documents and Settings\Malle\Cookies\malle@adbrite[1].txt
C:\Documents and Settings\Malle\Cookies\malle@tradedoubler[5].txt
C:\Documents and Settings\Malle\Cookies\malle@media.adrevolver[2].txt
C:\Documents and Settings\Malle\Cookies\malle@den[1].txt
C:\Documents and Settings\Malle\Cookies\malle@muzikmedia[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adlegend[1].txt
C:\Documents and Settings\Malle\Cookies\malle@tribalfusion[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adv.surinter[2].txt
C:\Documents and Settings\Malle\Cookies\malle@trafficmp[1].txt
C:\Documents and Settings\Malle\Cookies\malle@fastclick[3].txt
C:\Documents and Settings\Malle\Cookies\malle@cgi-bin[3].txt
C:\Documents and Settings\Malle\Cookies\malle@xiti[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ehg-advertisementbv.hitbox[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.click4foto[2].txt
C:\Documents and Settings\Malle\Cookies\malle@azjmp[3].txt
C:\Documents and Settings\Malle\Cookies\malle@ehg.hitbox[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[2].txt
C:\Documents and Settings\Malle\Cookies\malle@statcounter[1].txt
C:\Documents and Settings\Malle\Cookies\malle@atdmt[1].txt
C:\Documents and Settings\Malle\Cookies\malle@serving-sys[4].txt
C:\Documents and Settings\Malle\Cookies\malle@e2.emediate[2].txt
C:\Documents and Settings\Malle\Cookies\malle@brightcove.112.2o7[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.gratiscounter[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adtech[3].txt
C:\Documents and Settings\Malle\Cookies\malle@click4foto[3].txt
C:\Documents and Settings\Malle\Cookies\malle@hotbar[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.yieldmanager[4].txt
C:\Documents and Settings\Malle\Cookies\malle@ehg-fifa.hitbox[2].txt
C:\Documents and Settings\Malle\Cookies\malle@cgi-bin[2].txt
C:\Documents and Settings\Malle\Cookies\malle@tracking.notabenestats[1].txt
C:\Documents and Settings\Malle\Cookies\malle@mediamac.comon[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.arto[2].txt
C:\Documents and Settings\Malle\Cookies\malle@yourmedia[1].txt
C:\Documents and Settings\Malle\Cookies\malle@msnportal.112.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adfarm1.adition[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ehg-nokiafin.hitbox[2].txt
C:\Documents and Settings\Malle\Cookies\malle@nextstat[2].txt
C:\Documents and Settings\Malle\Cookies\malle@doubleclick[2].txt
C:\Documents and Settings\Malle\Cookies\malle@advertising[1].txt
C:\Documents and Settings\Malle\Cookies\malle@www.click4foto[1].txt
C:\Documents and Settings\Malle\Cookies\malle@c5.zedo[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad1.emediate[4].txt
C:\Documents and Settings\Malle\Cookies\malle@2o7[5].txt
C:\Documents and Settings\Malle\Cookies\malle@track.adform[3].txt
C:\Documents and Settings\Malle\Cookies\malle@zedo[3].txt
C:\Documents and Settings\Malle\Cookies\malle@fortunecity[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.ofir[3].txt
C:\Documents and Settings\Malle\Cookies\malle@questionmarket[1].txt
C:\Documents and Settings\Malle\Cookies\malle@casalemedia[2].txt
C:\Documents and Settings\Malle\Cookies\malle@mediaplex[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.zanox[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adfair[4].txt
C:\Documents and Settings\Malle\Cookies\malle@cgi-bin[1].txt
C:\Documents and Settings\Malle\Cookies\malle@indextools[3].txt
C:\Documents and Settings\Malle\Cookies\malle@www.etracker[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.web-stat[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.dailyrush[2].txt
C:\Documents and Settings\Malle\Cookies\malle@login.tracking101[2].txt
C:\Documents and Settings\Malle\Cookies\malle@statse.webtrendslive[3].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.itv[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adverticum[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.realtechnetwork[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.muzikmedia[2].txt
C:\Documents and Settings\Malle\Cookies\malle@eas.apm.emediate[1].txt
C:\Documents and Settings\Malle\Cookies\malle@videoegg.adbureau[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[9].txt
C:\Documents and Settings\Malle\Cookies\malle@server.iad.liveperson[2].txt
C:\Documents and Settings\Malle\Cookies\malle@media.adrevolver[4].txt
C:\Documents and Settings\Malle\Cookies\malle@ebookers[1].txt
C:\Documents and Settings\Malle\Cookies\malle@media.hotels[1].txt
C:\Documents and Settings\Malle\Cookies\malle@bs.serving-sys[5].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[3].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[4].txt
C:\Documents and Settings\Malle\Cookies\malle@edsa.122.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ncom.banneradministration[2].txt
C:\Documents and Settings\Malle\Cookies\malle@track.webtrekk[1].txt
C:\Documents and Settings\Malle\Cookies\malle@politiken.112.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.pubmatic[2].txt
C:\Documents and Settings\Malle\Cookies\malle@www.sex-sex-sex[2].txt
C:\Documents and Settings\Malle\Cookies\malle@apmebf[2].txt
C:\Documents and Settings\Malle\Cookies\malle@stat.postdanmark[1].txt
C:\Documents and Settings\Malle\Cookies\malle@sexdebut[2].txt
C:\Documents and Settings\Malle\Cookies\malle@hotelscom.122.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[10].txt
C:\Documents and Settings\Malle\Cookies\malle@de.sitestat[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.glispa[2].txt
C:\Documents and Settings\Malle\Cookies\malle@roiservice[1].txt
C:\Documents and Settings\Malle\Cookies\malle@shinystat[1].txt
C:\Documents and Settings\Malle\Cookies\malle@click4foto[1].txt
C:\Documents and Settings\Malle\Cookies\malle@www.googleadservices[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adultfriendfinder[1].txt
C:\Documents and Settings\Malle\Cookies\malle@rocku.adbureau[2].txt
C:\Documents and Settings\Malle\Cookies\malle@watagame.banneradministration[2].txt
C:\Documents and Settings\Malle\Cookies\malle@eas4.emediate[1].txt
C:\Documents and Settings\Malle\Cookies\malle@www1.addfreestats[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads2.jubii[1].txt
C:\Documents and Settings\Malle\Cookies\malle@atwola[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.as4x.tmcs[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.dk-kogebogen[1].txt
C:\Documents and Settings\Malle\Cookies\malle@mywebsearch[3].txt
C:\Documents and Settings\Malle\Cookies\malle@smileycentral[2].txt
C:\Documents and Settings\Malle\Cookies\malle@outrider.112.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@metacafe.122.2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.adbrite[1].txt
C:\Documents and Settings\Malle\Cookies\malle@serving-sys[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.ofir[1].txt
C:\Documents and Settings\Malle\Cookies\malle@2o7[1].txt
C:\Documents and Settings\Malle\Cookies\malle@doubleclick[1].txt
C:\Documents and Settings\Malle\Cookies\malle@statcounter[2].txt
C:\Documents and Settings\Malle\Cookies\malle@tradedoubler[3].txt
C:\Documents and Settings\Malle\Cookies\malle@tradedoubler[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ad1.emediate[2].txt
C:\Documents and Settings\Malle\Cookies\malle@indextools[1].txt
C:\Documents and Settings\Malle\Cookies\malle@bs.serving-sys[1].txt
C:\Documents and Settings\Malle\Cookies\malle@e2.emediate[1].txt
C:\Documents and Settings\Malle\Cookies\malle@hitbox[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adfair[1].txt
C:\Documents and Settings\Malle\Cookies\malle@adtech[1].txt
C:\Documents and Settings\Malle\Cookies\malle@tracker[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adultfriendfinder[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adserver.banneradministration[2].txt
C:\Documents and Settings\Malle\Cookies\malle@advertising[2].txt
C:\Documents and Settings\Malle\Cookies\malle@track.adform[1].txt
C:\Documents and Settings\Malle\Cookies\malle@serving-sys[3].txt
C:\Documents and Settings\Malle\Cookies\malle@track.adform[2].txt
C:\Documents and Settings\Malle\Cookies\malle@tradedoubler[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad1.emediate[3].txt
C:\Documents and Settings\Malle\Cookies\malle@bs.serving-sys[3].txt
C:\Documents and Settings\Malle\Cookies\malle@adrevolver[2].txt
C:\Documents and Settings\Malle\Cookies\malle@2o7[2].txt
C:\Documents and Settings\Malle\Cookies\malle@trafficmp[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adfair[3].txt
C:\Documents and Settings\Malle\Cookies\malle@qnsr[1].txt
C:\Documents and Settings\Malle\Cookies\malle@media.adrevolver[1].txt
C:\Documents and Settings\Malle\Cookies\malle@statse.webtrendslive[2].txt
C:\Documents and Settings\Malle\Cookies\malle@advertising[3].txt
C:\Documents and Settings\Malle\Cookies\malle@serving-sys[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.yieldmanager[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adserver.banneradministration[1].txt
C:\Documents and Settings\Malle\Cookies\malle@ad1.emediate[1].txt
C:\Documents and Settings\Malle\Cookies\malle@eas4.emediate[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adbrite[2].txt
C:\Documents and Settings\Malle\Cookies\malle@track.adform[4].txt
C:\Documents and Settings\Malle\Cookies\malle@revsci[1].txt
C:\Documents and Settings\Malle\Cookies\malle@2o7[3].txt
C:\Documents and Settings\Malle\Cookies\malle@azjmp[1].txt
C:\Documents and Settings\Malle\Cookies\malle@mywebsearch[2].txt
C:\Documents and Settings\Malle\Cookies\malle@fastclick[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ads.dk-kogebogen[2].txt
C:\Documents and Settings\Malle\Cookies\malle@mediaservices.myspace[2].txt
C:\Documents and Settings\Malle\Cookies\malle@zedo[2].txt
C:\Documents and Settings\Malle\Cookies\malle@ad.yieldmanager[1].txt
C:\Documents and Settings\Malle\Cookies\malle@bs.serving-sys[2].txt
C:\Documents and Settings\Malle\Cookies\malle@adfair[2].txt
C:\Documents and Settings\Malle\Cookies\malle@advertising[4].txt
