Tak - foreløbigt.
Ovenstående procedure gennemført. Her kommer logs:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 01/16/2008 at 09:55 PM
Application Version : 3.7.1018
Core Rules Database Version : 3380
Trace Rules Database Version: 1374
Scan type : Complete Scan
Total Scan Time : 00:17:04
Memory items scanned : 178
Memory threats detected : 0
Registry items scanned : 4907
Registry threats detected : 0
File items scanned : 24514
File threats detected : 0
Logfile of HijackThis v1.99.0
Scan saved at 22:04:50, on 16-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmer\Retrospect\Retrospect Express HD 2.0\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programmer\RegSweep\RegSweep.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jan Fangel\Dokumenter\Computeren\PC Programmer\hjt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RegSweep] C:\Programmer\RegSweep\RegSweep.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) -
http://downol.dr.dk/download/netradio/Rawflow.cabO16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -
http://support.f-secure.com/ols/fscax.cabO16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exeO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://spinpalace.microgaming.com/spinpalace/FlashAX.cabO16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) -
http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocxO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Retrospect Express HD Helper - EMC Corporation - C:\Programmer\Retrospect\Retrospect Express HD 2.0\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher - EMC Corporation - C:\Programmer\Retrospect\Retrospect Express HD 2.0\retrorun.exe
********************************* ROOTCHK-(28-12-07)-LOG, by ejvindh
16-01-2008 22:05:12,76
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-16 22:05:13
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
IPC error: 2 Den angivne fil blev ikke fundet.
scanning hidden services & system hive ...
IPC error: 2 Den angivne fil blev ikke fundet.
scanning hidden registry entries ...
scanning hidden files ...
IPC error: 2 Den angivne fil blev ikke fundet.
hidden processes: 0
hidden services: 0
hidden files: 0
ComboFix 08-01-16.4 - Jan Fangel 2008-01-16 22:06:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.262 [GMT 1:00]
Running from: C:\Documents and Settings\Jan Fangel\Dokumenter\Computeren\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.
2008-01-16 22:06 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 21:32 . 2008-01-16 21:37 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2008-01-16 21:32 . 2008-01-16 21:32 <DIR> d-------- C:\Documents and Settings\Jan Fangel\Application Data\SUPERAntiSpyware.com
2008-01-16 21:32 . 2008-01-16 21:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-14 16:39 . 2008-01-14 16:39 <DIR> d-------- C:\Documents and Settings\Jan Fangel\Application Data\Sports Interactive
2008-01-14 16:39 . 2008-01-14 16:39 <DIR> dr-h----- C:\Documents and Settings\Jan Fangel\Application Data\SecuROM
2008-01-14 16:39 . 2008-01-14 16:39 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-01-14 16:36 . 2008-01-14 16:38 <DIR> d--h----- C:\Programmer\Zero G Registry
2008-01-14 16:36 . 2008-01-14 16:36 <DIR> d-------- C:\Programmer\Sports Interactive
2008-01-14 16:35 . 2008-01-14 16:35 <DIR> d--h----- C:\Documents and Settings\Jan Fangel\InstallAnywhere
2008-01-08 15:12 . 2008-01-08 15:12 <DIR> d-------- C:\Documents and Settings\Jan Fangel\CDCARDS
2008-01-08 15:12 . 2008-01-08 15:12 <DIR> d-------- C:\Documents and Settings\Jan Fangel\.oces
2008-01-08 13:54 . 2008-01-15 22:20 <DIR> d-------- C:\Programmer\SpywareBlaster
2008-01-08 13:54 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2007-12-25 16:35 . 2007-12-25 16:35 <DIR> d-------- C:\Programmer\MSXML 4.0
2007-12-25 10:54 . 2007-12-25 10:54 <DIR> d-------- C:\SXS
2007-12-25 10:54 . 2007-12-25 10:54 <DIR> d-------- C:\Programmer\Logitech
2007-12-25 10:54 . 2007-12-25 10:54 <DIR> d-------- C:\Programmer\Fælles filer\Labtec
2007-12-25 10:54 . 2004-01-21 02:26 360,448 --a------ C:\WINDOWS\system32\LVUI2RC.dll
2007-12-25 10:54 . 2004-01-21 02:14 271,360 --a------ C:\WINDOWS\system32\drivers\LV302AV.SYS
2007-12-25 10:54 . 2004-01-21 02:25 172,032 --a------ C:\WINDOWS\system32\lvcodec2.dll
2007-12-25 10:54 . 2004-01-21 02:24 135,214 --a------ C:\WINDOWS\system32\LVComS.exe
2007-12-25 10:54 . 2004-01-21 02:26 122,880 --a------ C:\WINDOWS\system32\LVUI2.dll
2007-12-25 10:54 . 2004-01-21 02:28 86,016 --a------ C:\WINDOWS\system32\lvcoinst.dll
2007-12-25 10:54 . 2004-01-21 02:24 57,344 --a------ C:\WINDOWS\system32\LVComC.dll
2007-12-25 10:54 . 2004-01-21 01:51 17,191 --a------ C:\WINDOWS\system32\lvcoinst.ini
2007-12-25 10:54 . 2004-01-21 02:16 12,080 --a------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2007-12-25 10:54 . 2004-01-21 02:14 5,915 --a------ C:\WINDOWS\system32\drivers\lv302af.sys
2007-12-25 10:53 . 1998-11-13 12:59 307,200 --a------ C:\WINDOWS\IsUn0406.exe
2007-12-25 10:53 . 2007-12-25 10:53 272 --a------ C:\WINDOWS\_delis32.ini
2007-12-24 10:31 . 2007-12-27 15:36 1,660 --a------ C:\WINDOWS\desctemp.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 20:32 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-16 16:23 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\AVG7
2008-01-10 22:06 --------- d-----w C:\Programmer\RegSweep
2008-01-10 22:06 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\RegSweep
2008-01-08 15:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\RetroExp
2007-12-19 11:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-13 17:15 --------- d-----w C:\Programmer\Retrospect
2007-12-13 12:31 --------- d-----w C:\Programmer\Windows Defender
2007-12-13 11:44 --------- d-----w C:\Programmer\WinClamAVShield
2007-12-13 11:31 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\AdwareAlert
2007-12-13 07:57 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\DivX
2007-12-12 19:11 --------- d-----w C:\Programmer\DivX
2007-12-11 20:13 --------- d-----w C:\Programmer\TDC
2007-12-11 20:13 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\Cryptomathic
2007-12-10 13:06 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\IrfanView
2007-12-10 11:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2007-12-10 11:48 --------- d-----w C:\Programmer\IVT Corporation
2007-12-09 23:13 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\CyberLink
2007-12-09 18:27 --------- d-----w C:\Programmer\IrfanView
2007-12-09 17:55 --------- d-----w C:\Programmer\Fælles filer\Adobe
2007-12-09 17:49 --------- d-----w C:\Documents and Settings\Jan Fangel\Application Data\AdobeUM
2007-12-09 17:24 --------- d-----w C:\Programmer\MSN Messenger
2007-12-09 17:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 16:56 --------- d-----w C:\Programmer\GPLGS
2007-12-09 16:56 --------- d-----w C:\Programmer\CCleaner
2007-12-09 16:56 --------- d-----w C:\Programmer\Acro Software
2007-12-09 16:50 --------- d-----w C:\Programmer\Windows Media Connect 2
2007-12-09 14:43 --------- d--h--w C:\Programmer\InstallShield Installation Information
2007-12-09 14:43 --------- d-----w C:\Programmer\CyberLink
2007-12-09 14:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-12-09 14:25 --------- d-----w C:\Programmer\Fælles filer\Nero
2007-12-09 14:23 --------- d-----w C:\Programmer\Fælles filer\Ahead
2007-12-09 14:23 --------- d-----w C:\Programmer\Ahead
2007-12-09 14:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-09 14:16 --------- d-----w C:\Programmer\Java
2007-12-09 14:15 --------- d-----w C:\Programmer\Fælles filer\Java
2007-12-09 14:07 --------- d-----w C:\Programmer\Fælles filer\InstallShield
2007-12-08 17:56 --------- d-----w C:\Programmer\ATI Technologies
2007-12-07 11:01 --------- d-----w C:\Programmer\microsoft frontpage
2007-12-07 10:59 --------- d-----w C:\Programmer\Onlinetjenester
2007-12-07 10:59 --------- d-----w C:\Programmer\Fælles filer\Tjenester
2007-12-07 10:59 --------- d-----w C:\Programmer\Fælles filer\MSSoap
2007-12-07 02:28 --------- d-----w C:\Programmer\Fælles filer\SpeechEngines
2007-12-07 02:28 --------- d-----w C:\Programmer\Fælles filer\ODBC
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-29 22:30 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-07 09:28 723,456 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-02 04:57 9,314,304 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-11-02 04:24 176,128 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-11-02 04:10 364,544 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-11-02 04:09 268,288 ------w C:\WINDOWS\system32\ati2dvag.dll
2007-11-02 04:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-11-02 04:01 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-11-02 04:01 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-11-02 04:00 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-11-02 04:00 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-11-02 03:59 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-11-02 03:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-11-02 03:50 3,133,728 ------w C:\WINDOWS\system32\ati3duag.dll
2007-11-02 03:39 1,602,176 ------w C:\WINDOWS\system32\ativvaxx.dll
2007-11-02 03:35 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-11-02 03:26 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-11-02 03:24 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-11-02 03:22 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-11-02 03:16 499,712 ------w C:\WINDOWS\system32\ati2cqag.dll
2007-11-01 20:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-10-29 22:44 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-04-23 15:46 1318128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-07-26 10:16 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 10:08 579072]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"RemoteControl"="C:\Programmer\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Windows Defender"="C:\Programmer\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"RegSweep"="C:\Programmer\RegSweep\RegSweep.exe" [2007-10-18 18:51 6309112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 13:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-09 15:21 219136]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-13 12:28:50 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Programmer\AdwareAlert\AdwareAlert.ex
- C:\Programmer\AdwareAlert
"2008-01-16 21:05:33 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programmer\Windows Defender\MpCmdRun.exe
"2007-12-13 11:26:15 C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job"
- C:\Programmer\RegSweep\RegSweep.ex
- C:\Programmer\RegSweep
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-16 22:08:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-16 22:08:52
.
2008-01-11 09:19:45 --- E O F ---
Takker pænt på forhånd.....