ComboFix 09-01-21.04 - ddi 2009-01-26 21:20:15.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1030.18.2815.1825 [GMT 1:00]
Kører fra: c:\users\ddi\Desktop\ComboFix.exe
AV: BullGuard Antivirus *On-access scanning enabled* (Updated)
FW: BullGuard Firewall *enabled*
* Dannede nyt systemgendannelsespunkt
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\winsched.exe
.
((((((((((((((((((((((((((((( Filer skabt fra 2008-12-26 til 2009-01-26 )))))))))))))))))))))))))))))))))))
.
2009-01-14 02:12 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-11 15:52 . 2009-01-12 02:19 <DIR> d-------- c:\users\ddi\AppData\Roaming\Download Manager
2009-01-11 15:10 . 2008-12-24 16:16 401,720 --a------ c:\users\ddi\HiJackThis.exe
2009-01-01 16:56 . 1999-12-17 10:13 86,016 --a------ c:\windows\unvise32.exe
2009-01-01 16:55 . 2009-01-01 16:56 <DIR> d-------- c:\program files\Postal2STP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-26 20:18 --------- d-----w c:\users\ddi\AppData\Roaming\Azureus
2009-01-26 20:08 --------- d-----w c:\programdata\BullGuard
2009-01-26 20:07 --------- d-----w c:\users\ddi\AppData\Roaming\BullGuard
2009-01-25 20:11 --------- d-----w c:\programdata\NVIDIA
2009-01-23 20:30 55,504 ----a-w c:\windows\system32\drivers\BdFileSpy.sys
2009-01-22 18:09 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 02:02 --------- d-----w c:\program files\Windows Mail
2008-12-24 14:06 --------- d-----w c:\programdata\DVD Shrink
2008-12-23 18:15 --------- d-----w c:\programdata\Microsoft Help
2008-12-23 16:32 --------- d-----w c:\program files\Microsoft Works
2008-12-23 16:31 --------- d-----w c:\program files\Microsoft.NET
2008-12-23 15:41 --------- d-----w c:\program files\Bonjour
2008-12-22 21:45 --------- d-----w c:\users\ddi\AppData\Roaming\Apple Computer
2008-12-22 21:45 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:45 --------- d-----w c:\program files\iTunes
2008-12-22 21:44 --------- d-----w c:\programdata\Apple Computer
2008-12-22 21:44 --------- d-----w c:\program files\QuickTime
2008-12-22 21:44 --------- d-----w c:\program files\iPod
2008-12-22 21:44 --------- d-----w c:\program files\Common Files\Apple
2008-12-22 21:42 --------- d-----w c:\program files\Apple Software Update
2008-12-22 21:41 --------- d-----w c:\programdata\Apple
2008-12-16 07:09 --------- d-----w c:\programdata\WindowsSearch
2008-12-15 21:59 --------- d-----w c:\programdata\e-Safekey
2008-12-13 12:56 --------- d-----w c:\users\ddi\AppData\Roaming\BSplayer
2008-12-13 02:00 --------- d-----w c:\program files\MSXML 4.0
2008-12-12 22:44 --------- d-----w c:\users\ddi\AppData\Roaming\vlc
2008-12-12 22:40 --------- d-----w c:\program files\DVD Shrink
2008-12-12 22:36 --------- d-----w c:\users\ddi\AppData\Roaming\BSplayer Pro
2008-12-12 22:36 --------- d-----w c:\program files\Webteh
2008-12-12 22:35 --------- d-----w c:\program files\VideoLAN
2008-12-12 22:35 --------- d-----w c:\program files\SLD Codec Pack
2008-12-12 22:34 --------- d-----w c:\program files\Haali
2008-12-12 22:33 --------- d-----w c:\program files\DVD Decrypter
2008-12-12 21:57 --------- d-----w c:\programdata\Skype
2008-12-12 21:02 --------- d-----w c:\users\ddi\AppData\Roaming\Malwarebytes
2008-12-12 21:02 --------- d-----w c:\programdata\Malwarebytes
2008-12-12 10:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-12-12 10:11 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-12-10 21:55 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-12-10 21:55 --------- d-----w c:\program files\Windows Live
2008-12-10 21:51 --------- d-----w c:\programdata\WLInstaller
2008-12-10 21:41 174 --sha-w c:\program files\desktop.ini
2008-12-10 21:34 --------- d-----w c:\program files\Windows Sidebar
2008-12-10 21:34 --------- d-----w c:\program files\Windows Calendar
2008-12-10 21:33 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-10 21:33 --------- d-----w c:\program files\Windows Journal
2008-12-10 21:33 --------- d-----w c:\program files\Windows Defender
2008-12-10 21:33 --------- d-----w c:\program files\Windows Collaboration
2008-12-10 20:34 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-10 20:33 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-10 19:06 269,312 ----a-w c:\windows\System32\es.dll
2008-12-10 18:14 --------- d-----w c:\program files\Runtime Software
2008-12-10 17:49 --------- d-----w c:\programdata\Azureus
2008-12-10 17:47 --------- d-----w c:\program files\Vuze
2008-12-10 17:41 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-12-10 17:41 --------- d-----w c:\program files\Java
2008-12-09 22:13 61,440 ----a-w c:\windows\System32\winipsec.dll
2008-12-09 22:13 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2008-12-09 22:13 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2008-12-09 22:13 272,896 ----a-w c:\windows\System32\polstore.dll
2008-12-09 22:09 94,720 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-12-09 22:09 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-12-09 22:09 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-12-09 22:02 428,544 ----a-w c:\windows\System32\EncDec.dll
2008-12-09 22:02 293,376 ----a-w c:\windows\System32\psisdecd.dll
2008-12-09 21:57 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-12-09 21:56 212,480 ----a-w c:\windows\system32\drivers\mrxsmb10.sys
2008-12-09 21:54 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-12-09 21:54 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-12-09 21:54 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-09 21:54 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-09 21:54 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-12-09 21:54 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-12-09 21:54 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-12-09 21:54 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-09 21:54 1,695,744 ----a-w c:\windows\System32\gameux.dll
2008-12-09 21:53 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2008-12-09 21:52 2,048 ----a-w c:\windows\System32\msxml3r.dll
2008-12-09 21:52 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-12-09 21:52 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-12-09 21:48 2,048 ----a-w c:\windows\System32\tzres.dll
2008-12-09 21:43 2,927,104 ----a-w c:\windows\explorer.exe
2008-12-09 21:39 827,392 ----a-w c:\windows\System32\wininet.dll
2008-12-09 21:36 9,847,296 ----a-w c:\windows\System32\NlsData000a.dll
2008-12-09 21:34 988,216 ----a-w c:\windows\System32\winload.exe
2008-12-09 21:34 927,288 ----a-w c:\windows\System32\winresume.exe
2008-12-09 21:34 615,992 ----a-w c:\windows\System32\ci.dll
2008-12-09 21:34 6,656 ----a-w c:\windows\System32\kbd106n.dll
2008-12-09 21:34 46,592 ----a-w c:\windows\System32\setbcdlocale.dll
2008-12-09 21:34 40,960 ----a-w c:\windows\System32\srclient.dll
2008-12-09 21:34 378,368 ----a-w c:\windows\System32\srcore.dll
2008-12-09 21:34 318,464 ----a-w c:\windows\System32\rstrui.exe
2008-12-09 21:34 19,000 ----a-w c:\windows\System32\kd1394.dll
2008-12-09 21:34 14,848 ----a-w c:\windows\System32\srdelayed.exe
2008-12-09 21:31 712,704 ----a-w c:\windows\System32\WindowsCodecs.dll
2008-12-09 21:31 425,472 ----a-w c:\windows\System32\PhotoMetadataHandler.dll
2008-12-09 21:31 347,136 ----a-w c:\windows\System32\WindowsCodecsExt.dll
2008-12-09 21:29 443,392 ----a-w c:\windows\System32\win32spl.dll
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2009-01-22 304464]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-08-01 547360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-01 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-01 92704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2008-10-02 6335008]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2009-01-22 304464]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-10 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3282772502-311691218-292615738-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{542DC000-07CA-4661-8154-AD1C20A6810C}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{AB8A051F-DAC7-453B-8F1C-13C8CF79DE9E}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{CD0EA6EA-AEA8-4193-8794-47954AB4A2EB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{7AF6A2AC-F5E3-4D97-996A-70CDB2FDB6E6}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B0261F3C-447E-441D-82B4-AE1AC9313761}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{868C4944-3142-4CFE-ABB2-F3F6F206BFF0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1AA2AED8-3283-44D6-9DAF-CEE01F6A4197}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4AF2E6AD-CAEA-4FAB-9A02-489AD5529C4D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0484FFB7-C17C-4484-8C25-015B8D76DA00}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\afw.sys [2008-11-10 28696]
R3 AfwCore;Agnitum Firewall Core Driver;c:\windows\System32\drivers\AfwCore.sys [2008-12-09 263192]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [2008-08-05 44576]
R3 Reconn;BullGuard Email Monitor;c:\program files\BullGuard Ltd\BullGuard\Reconn.sys [2008-07-29 16984]
R4 BdFileSpy;BullGuard File Monitor Driver;c:\windows\System32\drivers\BdFileSpy.sys [2008-12-09 55504]
R4 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe -k BullGuard [2008-12-10 21504]
R4 BsFire;BullGuard Firewall Service;c:\windows\System32\svchost.exe -k BullGuard [2008-12-10 21504]
R4 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\System32\svchost.exe -k BullGuard [2008-12-10 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy BsFire
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: danskebank.dk
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-26 21:22:23
Windows 6.0.6001 Service Pack 1 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2009-01-26 21:24:15
ComboFix-quarantined-files.txt 2009-01-26 20:24:13
Pre-Kørsel: 110.986.231.808 byte ledig
Post-Kørsel: 111,110,950,912 byte ledig
196 --- E O F --- 2009-01-19 22:50:48